From: Efraim Flashner <efraim@flashner.co.il>
To: Josselin Poiret <dev@jpoiret.xyz>
Cc: "Ludovic Courtès" <ludo@gnu.org>,
"Maxim Cournoyer" <maxim.cournoyer@gmail.com>,
"Steve George" <steve@futurile.net>,
Kaelyn <kaelyn.alexi@protonmail.com>,
guix-devel@gnu.org
Subject: Re: Core updates status
Date: Mon, 13 May 2024 11:49:28 +0300 [thread overview]
Message-ID: <ZkHUGBh9YWdB4qwN@3900XT> (raw)
In-Reply-To: <87seys4qwp.fsf@jpoiret.xyz>
[-- Attachment #1: Type: text/plain, Size: 1459 bytes --]
On Wed, May 08, 2024 at 11:03:02AM +0200, Josselin Poiret wrote:
>
> The one thing that we need to do right now is update glibc 2.39 with all
> the fixes from the upstream release/2.39/master branch. I don't think
> we've done this before significantly, but since we have an occasion this
> time we might as well. We can't really use git-fetch for glibc, so imo
> the only feasible option is like what Debian does [1], which is keeping
> a diff of the 2.39 tag and the release branch and applying it as a
> patch. We'll then probably need to add autotools to glibc builds, but
> this is doable even in commencement because we have them already
> available at that point.
>
> The own downside of this is that the patch name will not include the
> fixed CVEs, so guix lint won't be aware that the CVEs have been patched.
>
> [1] https://salsa.debian.org/glibc-team/glibc/-/blob/sid/debian/patches/git-updates.diff
>
> WDYT?
>
> Best,
> --
> Josselin Poiret
I think that's a good idea, and probably something we should do for the
other copies of glibc we have. We can also use the package-property
lint-hidden-cves to list the CVEs which are covered by the diff, and
that'll hide the CVEs from 'guix lint'.
--
Efraim Flashner <efraim@flashner.co.il> רנשלפ םירפא
GPG key = A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351
Confidentiality cannot be guaranteed on emails sent or received unencrypted
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]
next prev parent reply other threads:[~2024-05-13 8:50 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-04-24 6:08 Core updates status Steve George
2024-04-24 9:56 ` Christina O'Donnell
2024-04-24 13:17 ` Steve George
2024-04-24 14:21 ` Christina O'Donnell
2024-04-25 14:06 ` Christina O'Donnell
2024-04-25 14:06 ` bug#40316: " Christina O'Donnell
2024-04-25 17:01 ` nss not reproducible Christina O'Donnell
2024-04-25 18:45 ` Core updates status Kaelyn
2024-04-26 12:56 ` Steve George
2024-04-26 15:58 ` Efraim Flashner
2024-05-05 20:45 ` Josselin Poiret
2024-05-06 2:38 ` Maxim Cournoyer
2024-05-06 8:47 ` Josselin Poiret
2024-05-06 10:21 ` Ludovic Courtès
2024-05-08 9:03 ` Josselin Poiret
2024-05-08 21:42 ` [PATCH] gnu: glibc: Update patches following upstream's master branch Josselin Poiret
2024-05-14 9:22 ` Ludovic Courtès
2024-05-09 15:41 ` Core updates status Maxim Cournoyer
2024-05-13 8:49 ` Efraim Flashner [this message]
2024-05-08 10:05 ` Andreas Enge
2024-05-08 17:46 ` Felix Lechner via Development of GNU Guix and the GNU System distribution.
2024-05-09 15:38 ` Maxim Cournoyer
2024-05-10 8:08 ` Andreas Enge
2024-05-13 8:51 ` Efraim Flashner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZkHUGBh9YWdB4qwN@3900XT \
--to=efraim@flashner.co.il \
--cc=dev@jpoiret.xyz \
--cc=guix-devel@gnu.org \
--cc=kaelyn.alexi@protonmail.com \
--cc=ludo@gnu.org \
--cc=maxim.cournoyer@gmail.com \
--cc=steve@futurile.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this external index
https://git.savannah.gnu.org/cgit/guix.git
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.