all messages for Guix-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
From: "pelzflorian (Florian Pelz)" <pelzflorian@pelzflorian.de>
To: Denis 'GNUtoo' Carikli <GNUtoo@cyberdimension.org>
Cc: 70022@debbugs.gnu.org
Subject: [bug#70022] [PATCH 0/2] Binary Installation: Add more distros
Date: Fri, 05 Apr 2024 17:23:25 +0200	[thread overview]
Message-ID: <878r1ru93m.fsf@pelzflorian.de> (raw)
In-Reply-To: <20240405004424.2e0b5389@primary_laptop> (Denis Carikli's message of "Fri, 5 Apr 2024 00:44:24 +0200")

Hello Denis,

Denis 'GNUtoo' Carikli <GNUtoo@cyberdimension.org> writes:
> Hi,
>
> About the local privilege escalation, is there any hints on how to fix
> it beside updating guix with 'guix pull'?

Thinking more about it, I guess the Binary Installation documentation
should inform that one can install from distribution packages or from
guix-install.sh, depending on who should be responsible for security
updates.

> For instance were there distributions that somehow backported the
> patch, in order not to have a security issue when you do 'apt install
> guix' or pamcan -S guix for instance?
>
> I'm asking because while I'm not the AUR maintainer of the 'guix'
> package, I know PKGBUILDs well enough to be able to send a patch if I
> find the time (and also update the Parabola package along the way).

Thank you for your offer.  Following hyperlinks from
<https://security-tracker.debian.org/tracker/CVE-2024-27297>, I find on
<https://udd.debian.org/patches.cgi?src=guix&version=1.4.0-6> security
patches that Vagrant cherry-picked from the Guix commits that address
the vulnerability.  Similar to how Guix often takes patches from Debian,
you could take the patches from Guix too or indirectly from Debian.

Regards,
Florian




  reply	other threads:[~2024-04-05 15:24 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-03-26 23:45 [bug#70022] [PATCH 0/2] Binary Installation: Add more distros Denis 'GNUtoo' Carikli
2024-03-27  0:17 ` [bug#70022] [PATCH 1/2] doc: Binary Installation: mention Trisquel package Denis 'GNUtoo' Carikli
2024-03-27  0:17 ` [bug#70022] [PATCH 2/2] doc: Binary Installation: add Parabola packages Denis 'GNUtoo' Carikli
2024-03-27 16:09 ` [bug#70022] [PATCH 0/2] Binary Installation: Add more distros pelzflorian (Florian Pelz)
2024-04-04 22:44 ` Denis 'GNUtoo' Carikli
2024-04-05 15:23   ` pelzflorian (Florian Pelz) [this message]
2024-04-12 12:00 ` [bug#70022] [PATCH v2 1/3] doc: Warn about foreign distro Guix packages' security Florian Pelz
2024-04-12 12:00   ` [bug#70022] [PATCH v2 2/3] doc: Binary Installation: Mention Trisquel package Florian Pelz
2024-04-12 12:00   ` [bug#70022] [PATCH v2 3/3] doc: Binary Installation: Add Parabola packages Florian Pelz
2024-04-13  7:18 ` [bug#70022] [PATCH v3 1/3] doc: Warn about foreign distro Guix packages' security Florian Pelz
2024-04-13  7:18   ` [bug#70022] [PATCH v3 2/3] doc: Binary Installation: Mention Trisquel package Florian Pelz
2024-04-13  7:18   ` [bug#70022] [PATCH v3 3/3] doc: Binary Installation: Add Parabola packages Florian Pelz

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=878r1ru93m.fsf@pelzflorian.de \
    --to=pelzflorian@pelzflorian.de \
    --cc=70022@debbugs.gnu.org \
    --cc=GNUtoo@cyberdimension.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/guix.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.