From mboxrd@z Thu Jan 1 00:00:00 1970 From: ng0 Subject: Re: Fwd: [curl] Re: configure: --with-libidn or --with-libidn2? Date: Mon, 26 Dec 2016 17:10:50 +0000 Message-ID: <87k2amty3p.fsf@wasp.i-did-not-set--mail-host-address--so-tickle-me> References: <87bmvylrk5.fsf@wasp.i-did-not-set--mail-host-address--so-tickle-me> <20161226170056.GB9351@jasmine> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:46334) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cLYnN-00060b-DN for guix-devel@gnu.org; Mon, 26 Dec 2016 12:10:46 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cLYnJ-0001eE-97 for guix-devel@gnu.org; Mon, 26 Dec 2016 12:10:45 -0500 Received: from aibo.runbox.com ([91.220.196.211]:55199) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cLYnJ-0001dj-0Q for guix-devel@gnu.org; Mon, 26 Dec 2016 12:10:41 -0500 In-Reply-To: <20161226170056.GB9351@jasmine> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Leo Famulari Cc: guix-devel@gnu.org Leo Famulari writes: > On Mon, Dec 26, 2016 at 01:59:22PM +0000, ng0 wrote: >> It seems as if curl can be build with libidn2 now and they have >> addressed the bug which existed for a while. I will check with >> upstream and send in a fix for our curl package once I am sure >> that the old bug has been fixed. > > Which bug? > > In November 2016, the curl maintainers asked packagers to not link curl > with libidn or libidn2 at all, due to security issues: > > https://curl.haxx.se/mail/lib-2016-11/0033.html > Which has since then be fixed and in a recent (not in 7.52.1 included) commit the --with-libidn2 option has been added. My understanding of libidn2 is that there were problems with some usecases. For example a domain name like bäcker.de would give problems to applications such as curl. Of course this was months ago, and I would not trust my memory on this. -- ♥Ⓐ ng0 PGP keys and more: https://n0is.noblogs.org/ http://ng0.chaosnet.org