From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mark H Weaver Subject: Re: [PATCH] gnu: libgcrypt: Update to 1.6.5. (security update) Date: Wed, 10 Feb 2016 15:46:03 -0500 Message-ID: <87io1wnvjo.fsf@netris.org> References: <87si11y83q.fsf@dustycloud.org> <87oabpljx1.fsf@netris.org> <20160210144659.GA7093@debian.eduroam.u-bordeaux.fr> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:60587) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1aTbeb-0004hr-5H for guix-devel@gnu.org; Wed, 10 Feb 2016 15:46:25 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1aTbeW-0001sl-Kc for guix-devel@gnu.org; Wed, 10 Feb 2016 15:46:25 -0500 Received: from world.peace.net ([50.252.239.5]:43323) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1aTbeW-0001qd-Fs for guix-devel@gnu.org; Wed, 10 Feb 2016 15:46:20 -0500 In-Reply-To: <20160210144659.GA7093@debian.eduroam.u-bordeaux.fr> (Andreas Enge's message of "Wed, 10 Feb 2016 15:46:59 +0100") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org To: Andreas Enge Cc: guix-devel@gnu.org Andreas Enge writes: > Hello, > > On Tue, Feb 09, 2016 at 03:15:38PM -0500, Mark H Weaver wrote: >> Alas, this will require at least 7000 rebuilds. After the current >> 'security-updates' branch is merged, this should go on the next >> 'security-updates' branch, together with more fixes for graphite2 and >> libsndfile. > > it looks like we are almost there. Do you think we could squeeze in an > evaluation and build of wip-pulseaudio after updating master and rebasing > the wip branch on master? I'm reluctant to delay a critical security update like this, which apparently allows a compromised web site to perform remote code execution in our graphical web browsers. I, for one, am running text-only for now, and am impatient to return back to the modern era. What's the nature of the pulseaudio update? Why is it important? What do other people think? Mark