On Sat, Jun 10, 2017 at 08:07:57PM +0200, Marius Bakke wrote: > Thinking further about this, replacing a string of a fixed length with > that of another sounds highly unsafe. So I'm not sure what the best > approach here is. Maybe some dummy version number like 3.5.a? Or simply > keep 3.5.9? We did something similar when grafting bash [0], changing 4.4.0 to 4.4.A. It's not great, but it worked. [0] commit 50b8a527efe375ac5377670ff0f159fbbce45312 (gnu: bash: Add graft for patch #7 [fixes CVE-2017-5932].). https://git.savannah.gnu.org/cgit/guix.git/commit/?id=50b8a527efe375ac5377670ff0f159fbbce45312