From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp11.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms5.migadu.com with LMTPS id KKf/OjF4hGJiKgAAbAwnHQ (envelope-from ) for ; Wed, 18 May 2022 06:38:10 +0200 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp11.migadu.com with LMTPS id 0G7vOjF4hGJGEQEA9RJhRA (envelope-from ) for ; Wed, 18 May 2022 06:38:09 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 68ADA23D8 for ; Wed, 18 May 2022 06:38:09 +0200 (CEST) Received: from localhost ([::1]:45592 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1nrBRn-00012w-Ua for larch@yhetil.org; Wed, 18 May 2022 00:38:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:37924) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nrBRi-00012n-EC for guix-patches@gnu.org; Wed, 18 May 2022 00:38:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:36465) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1nrBRi-0007tO-3K for guix-patches@gnu.org; Wed, 18 May 2022 00:38:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1nrBRi-0004Nh-1E for guix-patches@gnu.org; Wed, 18 May 2022 00:38:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#55437] [PATCH] gnu: clamav: Update to 0.103.6 [fixes CVE-2022-{20803, 20770, 20796, 20771, 20785, 20792}]. Resent-From: Maxim Cournoyer Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Wed, 18 May 2022 04:38:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55437 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: kiasoc5@disroot.org Cc: 55437@debbugs.gnu.org Received: via spool by 55437-submit@debbugs.gnu.org id=B55437.165284863016781 (code B ref 55437); Wed, 18 May 2022 04:38:01 +0000 Received: (at 55437) by debbugs.gnu.org; 18 May 2022 04:37:10 +0000 Received: from localhost ([127.0.0.1]:58595 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nrBQs-0004Ma-IC for submit@debbugs.gnu.org; Wed, 18 May 2022 00:37:10 -0400 Received: from mail-qv1-f44.google.com ([209.85.219.44]:41866) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nrBQq-0004MK-D2 for 55437@debbugs.gnu.org; Wed, 18 May 2022 00:37:09 -0400 Received: by mail-qv1-f44.google.com with SMTP id c9so40391qvx.8 for <55437@debbugs.gnu.org>; Tue, 17 May 2022 21:37:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:references:date:in-reply-to:message-id :user-agent:mime-version; bh=Np8IkJfD0PvVxiH9TbVFCPpAxDHRwJD5xukjDXXP1is=; b=edU4xMuR9T1xBDoiWh3jatgnOkDyqTRapAdq/HTlOBrcgw5XhWBTEmwGBbR8RiyjyY 8zMCCzuTyHSqfVQ2ipEeScdJXKYuNfkkUVhe95oo+ZYZ2FKvwA9MV/DXBlndFhAi2J5h /3ORa5eul/n8GYkQbjKZ/iaoHTMlrp0M5q73y53Bfjeg7n4vObmO+Ay8UawKFgj3Nzsy SHFiTXiY5VsGvUZPqDHoJ6BMyZbeBRtlsA5eWOp8RF0XdN0ntsXshNO5ycSu3n4R9eTV aA4KLjM4laa1m2y+tiy4bS31rJC9VHhffQxXXFHTgKCVHpDax5t4lc2aNIhIJXjq2mOF Dbcw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:references:date:in-reply-to :message-id:user-agent:mime-version; bh=Np8IkJfD0PvVxiH9TbVFCPpAxDHRwJD5xukjDXXP1is=; b=Wk1e7FXPmlNHkztxN5O2UfwapNLef7S6/MAWc9dF9rSrF81B1gCZf3Vl9KcpBKdxKW CyeLPYq9hV5x63sA1MRfp9G2MghnyEXlen3v9x/6GOEXDbgpqS+rODZnNMxcANgCZvve Y4ZOmdZuuoIkwBhxHNcfhjXTsaC8BIt72G50T9SxatVb1Fy/x6r5B0ndt+17iicX9FvG MTEB35HlZaa80r4PCKK4HygLcPLaQqiSqwauxr1SBLY1+MiDGUM9lKs0qhMEeEUSKZ4U Lt2Jgt/owPEtFRBnktY+s3oTHJbW5eOwB5LFWe+bH6xwaXpEPt+GnvVUsm8SHIIISXz4 GASg== X-Gm-Message-State: AOAM533ot3zUeZHs5lyLpdy57TpquOOLlmfoDL/lZGQNJr9XrBOWOOTh OTvvYNxoig3u7/n+QD3nTVrtcOODs9FZ49NZ X-Google-Smtp-Source: ABdhPJybJlGFacfST+L4wRDXT/NTZYXiJ2zp2HkQQHWBRuwJQN3YUXysIp+LghCI59nrBkRzGxFo+w== X-Received: by 2002:a05:6214:1c43:b0:45b:b4:3e18 with SMTP id if3-20020a0562141c4300b0045b00b43e18mr23507725qvb.56.1652848622750; Tue, 17 May 2022 21:37:02 -0700 (PDT) Received: from hurd (dsl-205-233-124-104.b2b2c.ca. [205.233.124.104]) by smtp.gmail.com with ESMTPSA id n64-20020a37bd43000000b0069fdbe43a5asm869180qkf.41.2022.05.17.21.37.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 17 May 2022 21:37:02 -0700 (PDT) From: Maxim Cournoyer References: Date: Wed, 18 May 2022 00:37:01 -0400 In-Reply-To: (kiasoc5@disroot.org's message of "Sun, 15 May 2022 20:12:37 +0000") Message-ID: <87mtff1moi.fsf_-_@gmail.com> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/28.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" X-Migadu-Flow: FLOW_IN X-Migadu-To: larch@yhetil.org X-Migadu-Country: US ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1652848689; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:resent-cc:resent-from:resent-sender: resent-message-id:in-reply-to:in-reply-to:references:references: list-id:list-help:list-unsubscribe:list-subscribe:list-post: dkim-signature; bh=Np8IkJfD0PvVxiH9TbVFCPpAxDHRwJD5xukjDXXP1is=; b=bu7OfVTibaSG2Qaz/UQom3odvWxTSpyfm0Lfxc1M3XyZz+q8dzcsC7DHd10JOfzorg6Nzh nCl0bHoa/jkqp6Xl+ZnZ8qLRDWmlPFLr59mhIxTuYw9SxHXJnxHlwtxJttrGORVABdxbUb ptjVjKntAEvGjqWOUO0pNVRXieTlTp2RBTR6x5QMdUYfvKpuK8c1ZJABg6VKamYepMD7lD jdj1uauUAvpHcvyfshM0i+k4gpg9BWF7V/AHBHp594GcPi26bMS0AsbiJGS8X4rmcTZgus Bp//8VXNIVuBl12OcK5PTR3WMw+a8m4aS/cB7OA3yTvgiKbOQYcFJmQWeseB8w== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1652848689; a=rsa-sha256; cv=none; b=eOY2q+ADhI89b6Q0GsYbx8xeXkJIVQWQ+lpePPZfxJs8rPcYfbiS6h1HDRfpoXpCwId1wD 2jNYiZzRlQSvnx9j8Id5Y4V+HJ3NpUMYRfakFmlL7PrqsrNcDu7w0EnWVuhBw1Znw2KKFH 5aVR+F+F8imaCv9Ldn6jI7f5V5x6U1zj9kxHW5J9oZAviKhQLtv9J6rtlGQTr7Tp5w2/dv YWC5+TKmzQUeOQCqm6BixudmPdMq33NPj0BeclBb7vEuoeZSRh+gnVwVrbZg+0+XzzxtZU op9P8b4F8NBvNyEJX4H1fbCpHgw0vaWpqLPR1sHDzKpVKGFciqklwvphwx6Pjw== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20210112 header.b=edU4xMuR; dmarc=fail reason="SPF not aligned (relaxed)" header.from=gmail.com (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Spam-Score: 5.96 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=gmail.com header.s=20210112 header.b=edU4xMuR; dmarc=fail reason="SPF not aligned (relaxed)" header.from=gmail.com (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Queue-Id: 68ADA23D8 X-Spam-Score: 5.96 X-Migadu-Scanner: scn1.migadu.com X-TUID: U3/FRNaGK+SI Hi, kiasoc5@disroot.org writes: > This patch updates clamav to the latest LTS version. > Per the release notes [1], a future update of clamav to 0.105+ will take some effort: > > 1. 0.105+ needs Rust 1.57+ to build. > 2. The build should switch from tarball to git to avoid vendored crates. > 3. 0.105+ works with llvm 8-12 (no more llvm 3.7). > > I suggest we keep clamav on the LTS version until we update Rust. Sounds like a fine plan. > PS: As you can see from the email address, I am migrating from Tutanota to Disroot. > > [1] https://blog.clamav.net/2022/05/clamav-01050-01043-01036-released.html#more I see the following guix lint warnings: --8<---------------cut here---------------start------------->8--- clamav@0.103.6: label 'libcurl' does not match package name 'curl' clamav@0.103.6: label 'libjson' does not match package name 'json-c' clamav@0.103.6: label 'openssl' does not match package name 'libressl' clamav@0.103.6: label 'sasl' does not match package name 'cyrus-sasl' clamav@0.103.6: label 'xml' does not match package name 'libxml2' clamav@0.103.6: updater 'generic-html' failed to find upstream releases --8<---------------cut here---------------end--------------->8--- I'm not sure about the last one, but the other ones could be fixed simply by updating to the new style (list input1 input2 ...) instead of `(("input1" ,input1) ("input2" ,input2) ...). Would you mind updating the patch with such changes? Thanks! Maxim