From debbugs-submit-bounces@debbugs.gnu.org Tue Aug 18 10:53:34 2015 Received: (at submit) by debbugs.gnu.org; 18 Aug 2015 14:53:34 +0000 Received: from localhost ([127.0.0.1]:59112 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1ZRiGc-0001fR-5P for submit@debbugs.gnu.org; Tue, 18 Aug 2015 10:53:34 -0400 Received: from eggs.gnu.org ([208.118.235.92]:41740) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1ZRiGa-0001fJ-Ca for submit@debbugs.gnu.org; Tue, 18 Aug 2015 10:53:32 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ZRiGY-0003pJ-Nj for submit@debbugs.gnu.org; Tue, 18 Aug 2015 10:53:31 -0400 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=-2.3 required=5.0 tests=BAYES_00,RP_MATCHES_RCVD autolearn=disabled version=3.3.2 Received: from lists.gnu.org ([2001:4830:134:3::11]:50259) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZRiGY-0003pF-KR for submit@debbugs.gnu.org; Tue, 18 Aug 2015 10:53:30 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:51736) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZRiGX-0008O4-Ef for bug-guix@gnu.org; Tue, 18 Aug 2015 10:53:30 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ZRiGS-0003lJ-FE for bug-guix@gnu.org; Tue, 18 Aug 2015 10:53:29 -0400 Received: from fencepost.gnu.org ([2001:4830:134:3::e]:55954) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZRiGS-0003lF-Bo for bug-guix@gnu.org; Tue, 18 Aug 2015 10:53:24 -0400 Received: from reverse-83.fdn.fr ([80.67.176.83]:33878 helo=pluto) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_128_CBC_SHA1:128) (Exim 4.82) (envelope-from ) id 1ZRiGR-0008J0-NR for bug-guix@gnu.org; Tue, 18 Aug 2015 10:53:24 -0400 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) To: bug-guix@gnu.org Subject: Qt's bundled libraries must not be used X-URL: http://www.fdn.fr/~lcourtes/ X-Revolutionary-Date: 1 Fructidor an 223 de la =?utf-8?Q?R=C3=A9volution?= X-PGP-Key-ID: 0x3D9AEBB5 X-PGP-Key: http://www.fdn.fr/~lcourtes/ludovic.asc X-PGP-Fingerprint: 3CE4 6455 8A84 FDC6 9DB4 0CFB 090B 1199 3D9A EBB5 X-OS: x86_64-unknown-linux-gnu Date: Tue, 18 Aug 2015 16:53:21 +0200 Message-ID: <87r3n0sl5q.fsf@gnu.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: Error: Malformed IPv6 address (bad octet value). X-detected-operating-system: by eggs.gnu.org: Error: Malformed IPv6 address (bad octet value). X-Received-From: 2001:4830:134:3::11 X-Spam-Score: -5.4 (-----) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -5.4 (-----) The bundled libraries in Qt are an obvious security issues, among other concerns. This bug is to keep track of progress removing those bundled libraries (esp. in Qt 5.) For background, see: https://lists.gnu.org/archive/html/guix-devel/2015-06/msg00302.html https://lists.gnu.org/archive/html/guix-devel/2015-08/msg00018.html Ludo=E2=80=99. From debbugs-submit-bounces@debbugs.gnu.org Sun Oct 04 06:50:05 2015 Received: (at 21288) by debbugs.gnu.org; 4 Oct 2015 10:50:05 +0000 Received: from localhost ([127.0.0.1]:54238 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1Zigrk-0008Ep-5k for submit@debbugs.gnu.org; Sun, 04 Oct 2015 06:50:04 -0400 Received: from mout.kundenserver.de ([212.227.17.24]:49984) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1Zigrh-0008EK-2e for 21288@debbugs.gnu.org; Sun, 04 Oct 2015 06:50:01 -0400 Received: from debian ([81.64.238.92]) by mrelayeu.kundenserver.de (mreue103) with ESMTPSA (Nemesis) id 0MMHDp-1ZhL1141c5-0080Sd; Sun, 04 Oct 2015 12:49:59 +0200 Date: Sun, 4 Oct 2015 12:49:55 +0200 From: Andreas Enge To: Ludovic =?iso-8859-15?Q?Court=E8s?= Subject: Re: bug#21288: Qt's bundled libraries must not be used Message-ID: <20151004104955.GA32592@debian> References: <87r3n0sl5q.fsf@gnu.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <87r3n0sl5q.fsf@gnu.org> User-Agent: Mutt/1.5.23 (2014-03-12) X-Provags-ID: V03:K0:qzQGFgJ8f6rIp3jF0IuoysFWZef7lqApgUPVaUtildDPhrSQX+p fPsCln+wW8oJcHD1hJa8vgVG+djmYZ91js9fMEB8h+1wvsRIM5CZ6eSdHZrQCvlhOsoJUwA 6h2lDAp2n6Ou/KLIw9Z6rIfbCgLhOaX8VVEfZcsdZYPkL1ymsCZz65F+T5SfUkfaHPbMwRr kSq3DuGxt+g6ehsRXDPew== X-UI-Out-Filterresults: notjunk:1;V01:K0:T74SVV0BxyA=:v5IdOtHV2X50t+tfGP6K1e C5EeeJ8ovvZ9VLtqU5jYmgRbmweTkpcA6OZ/0JGPu5Fi2Q3Xle+QnO3NVH00tSX3A1DtjKU1m r07vol2Dkn6XTqLqa5UcuDnY3a9WmHdJKK76mn9THTYNg+c5ZmzdkSlv/5JJRK759U1Rw6hNN Da3AuUBqm8jHAzqpz+YSfXQdxkowMGv9pllsj+libyjLtma2EItCKB/gM2eMkLsSBjlSmnZdg huRXi7KhFGbzKjhxSgJaiUh/outF69n29jrGqS+9U9+hLCEuKiNUKZvxwlYLj8DIESr8iY3fK 0V/9QTua/fazXMptGnU9juXSwlgcQU/KWtQQWqIZDlofiYYCzviqU2rCB7eD8XpiXVilVA0z5 idgL+xHJ+nPfpgIvsQF5dAimMeERJEFnH9WkX+B43td5jQCPYYrH6W1D5uhpMUxOlYiaNMwuf kPeFczlWwLSKTO9IrHzSkFhfjSlT22iyEpGRQv5cvCo1VWVbAd6CxzTKF9u5A0HiTX5+mGpJ5 ayJJ4zaiXqptNcLs6FUt3cTcRI154JITIF5fap3Lu1moIdNQ4EBugirsmNf8XRtqoGUvpGtvs gh+1Ob8W9gXhYHo4WQ8Z7xq8XI0RQN6+/8Yg9Rmd7oQoqNVhPnNdduDgCMQPyGhu4SU43mYdq JQs89frlEKBZ9SvdkOmvrgFHbDgsCljXTdTJb4k/i1XkYA9wQNOivyGocxgBhOv8bmIM= X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 21288 Cc: 21288@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) Commit 7431ede removes the webkit module from qt-4. Andreas From debbugs-submit-bounces@debbugs.gnu.org Sun Oct 04 17:05:52 2015 Received: (at 21288) by debbugs.gnu.org; 4 Oct 2015 21:05:52 +0000 Received: from localhost ([127.0.0.1]:54699 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1ZiqTg-0006sl-38 for submit@debbugs.gnu.org; Sun, 04 Oct 2015 17:05:52 -0400 Received: from mout.kundenserver.de ([212.227.17.10]:52170) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1ZiqTd-0006sd-Ps for 21288@debbugs.gnu.org; Sun, 04 Oct 2015 17:05:50 -0400 Received: from debian ([81.64.238.92]) by mrelayeu.kundenserver.de (mreue104) with ESMTPSA (Nemesis) id 0Lb2iX-1aSfo21knR-00keKz; Sun, 04 Oct 2015 23:05:48 +0200 Date: Sun, 4 Oct 2015 23:05:42 +0200 From: Andreas Enge To: Ludovic =?iso-8859-15?Q?Court=E8s?= Subject: Re: bug#21288: Qt's bundled libraries must not be used Message-ID: <20151004210542.GA831@debian> References: <87r3n0sl5q.fsf@gnu.org> <20151004104955.GA32592@debian> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20151004104955.GA32592@debian> User-Agent: Mutt/1.5.23 (2014-03-12) X-Provags-ID: V03:K0:d0ymLIPod0ib+DvPFqK6FvAR5Ij0Qr+15ZhH3ksMcgGni3VXbgp 8SOlnxWqUVGfQmSM32kqxG8QmZk/dX8dA4LW9kugxmcK+4xLIuc0eIqMCYMeMcPk1X2RhgB oqecnRXNP5wPb3xBWH//oBUHiGLM+mUY9wtjJHDgIgzDQbuPbydUDCRF+4fiH/oieQFJP2l +hWK88x/se4n/yXaBYOSA== X-UI-Out-Filterresults: notjunk:1;V01:K0:je9VDplTFrs=:2EfB1uppG6AI3+iZnDFBW1 yyifCGAK93JOA3F49iZR9uDIxNuwAsoAXIviIX+vXRAzCgikAqgC5eY9oVr3cEX4E1O7wlF0G SAFH5075vBSy71HoHCEZJ81WQO8AgXctt7yFnCP/0/KyKEnbYaagQ+k8/5FIW1nrbLoWI9jGz OXveWoNjktmmamL0mX+M1OddYS3epaVXTwXsmLBwIDkxHMQevFCVmCjtisIuRzB+6kSft0tpk ERHzTGRwrymVVza8lB9dBKeRAE29+OWmlvkKi9wgzVuu/8Vu7N9cvWLK8YpxzoUAlvr3RhLdu NgFA+a3LUKb98i7bkYVjpz3qZSjs27yvD5bVx0H0ZRBk7+Axy+hqU+g7t7+Pd59gt0N3hQXkI QKwbx4Xr+mTWb5zcajNzaUUX2DpzuclqMLxx4PZRqDL1eT6gqmCyI7qLtJPnkF4ScZFQmuvGo klQzXzn2MlDWTKcG1+i6vJzUIs92VvYd0W8CZerD7kfUOVb1OXG0GUUTzdhanESFnyuAwgzg/ /NbiwS7yk1UtmCyaEJkOpMDr92JMJqEGIfYeX6QxM3sO7Eh2iJNuOmGz7lhBgGLO+loYz1lEi XHtBSHwJ+TbwHCqVIUMT4tco08vxIfj8oA+7jev3CL8ziBNA1AZYjZGhxSUObwo+WiC3xN4fF PtSxcDa9mllgQLUNPWURvL+bsXCJ/1esdL7PUoRjnON0lszUtING1jerppyDRjADUNXk= X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 21288 Cc: 21288@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) Commit bc554b4 compiles qt-5 with the system harfbuzz and removes a bundled copy from our source code (the one called harfbuzz-ng; strangely, there is another one, called harfbuzz, without which the package does not compile). Commit 9c32e1f removes the bundled sqlite copy (the system sqlite was already used before). Some other system libraries are already used automatically; to make things clearer, we could also remove their source code (from the corresponding 3rdparty/ subdirectories). Andreas From debbugs-submit-bounces@debbugs.gnu.org Sun Oct 04 22:09:27 2015 Received: (at 21288) by debbugs.gnu.org; 5 Oct 2015 02:09:27 +0000 Received: from localhost ([127.0.0.1]:54745 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1ZivDS-0006lf-Mb for submit@debbugs.gnu.org; Sun, 04 Oct 2015 22:09:27 -0400 Received: from world.peace.net ([50.252.239.5]:53680) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1ZivDQ-0006lW-5w for 21288@debbugs.gnu.org; Sun, 04 Oct 2015 22:09:24 -0400 Received: from [10.1.10.31] (helo=yeeloong) by world.peace.net with esmtpsa (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.72) (envelope-from ) id 1ZivDJ-0007j6-Ln; Sun, 04 Oct 2015 22:09:17 -0400 From: Mark H Weaver To: Andreas Enge Subject: Re: bug#21288: Qt's bundled libraries must not be used References: <87r3n0sl5q.fsf@gnu.org> <20151004104955.GA32592@debian> <20151004210542.GA831@debian> Date: Sun, 04 Oct 2015 22:09:03 -0400 In-Reply-To: <20151004210542.GA831@debian> (Andreas Enge's message of "Sun, 4 Oct 2015 23:05:42 +0200") Message-ID: <87mvvyt6bk.fsf@netris.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.5 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 21288 Cc: 21288@debbugs.gnu.org, Ludovic =?utf-8?Q?Court=C3=A8s?= X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 0.0 (/) Hi Andreas, Andreas Enge writes: > Commit bc554b4 compiles qt-5 with the system harfbuzz and removes a bundled > copy from our source code (the one called harfbuzz-ng; strangely, there is > another one, called harfbuzz, without which the package does not compile). > > Commit 9c32e1f removes the bundled sqlite copy (the system sqlite was already > used before). Sounds good, thank you! > Some other system libraries are already used automatically; to make things > clearer, we could also remove their source code (from the corresponding > 3rdparty/ subdirectories). Yes, I think we should remove as many bundled libraries as possible. Even if the build system does not use the bundled libFOO today, a future version might start using it, and so when there's a security flaw found in libFOO, we will have to double-check to make sure it's really not being used. It's much easier to just remove the bundled copies. What do you think? Mark From debbugs-submit-bounces@debbugs.gnu.org Wed May 13 15:15:33 2020 Received: (at 21288-done) by debbugs.gnu.org; 13 May 2020 19:15:33 +0000 Received: from localhost ([127.0.0.1]:59595 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jYwqr-0005Q1-0r for submit@debbugs.gnu.org; Wed, 13 May 2020 15:15:33 -0400 Received: from flashner.co.il ([178.62.234.194]:51402) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jYwqp-0005Pl-KT for 21288-done@debbugs.gnu.org; Wed, 13 May 2020 15:15:32 -0400 Received: from localhost (unknown [188.120.128.132]) by flashner.co.il (Postfix) with ESMTPSA id 73D4640032 for <21288-done@debbugs.gnu.org>; Wed, 13 May 2020 19:15:25 +0000 (UTC) Date: Wed, 13 May 2020 22:14:53 +0300 From: Efraim Flashner To: 21288-done@debbugs.gnu.org Subject: Qt's bundled libraries must not be used Message-ID: <20200513191453.GI918@E5400> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="oplxJGu+Ee5xywIT" Content-Disposition: inline X-PGP-Key-ID: 0x41AAE7DCCA3D8351 X-PGP-Key: https://flashner.co.il/~efraim/efraim_flashner.asc X-PGP-Fingerprint: A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 X-Spam-Score: -0.0 (/) X-Debbugs-Envelope-To: 21288-done X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --oplxJGu+Ee5xywIT Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable I think in the intervening 4.5 years we've done a good job of removing the bundled libraries from qt-4 and qt-5 and then qtbase. I'm going to consider this bug a success. The note in the snippet says there are a few more bundled libraries, like md5 and sha3 (and harfbuzz) but we've otherwise done a great job on this one. --=20 Efraim Flashner =D7=90=D7=A4=D7=A8=D7=99=D7=9D = =D7=A4=D7=9C=D7=A9=D7=A0=D7=A8 GPG key =3D A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 Confidentiality cannot be guaranteed on emails sent or received unencrypted --oplxJGu+Ee5xywIT Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEoov0DD5VE3JmLRT3Qarn3Mo9g1EFAl68Ry0ACgkQQarn3Mo9 g1EUQxAAq5OtZDjduMpR2kIpCQeaNN1aQ1YCvHBKOMp82TY9RQeU35xqHroGYiQZ 4vvEKdimL/IdPgbAShD4hht+gV4996Izmy0eRIcyfkTDtZTI8nRd/TRiRX+XecsC S442RwrEwjgMKCIKvLA0gt47u9fsFDFd9eLuMUbSofXHUXGxrjsi2gz1ndffurSV 3biFh5RL4ekY3Sc8ubTOC8R2qGqpc5kDWQa6p52tdgNZLWHpsUbleGry87tC43ZS /9B+CdLrdCX29M2smAWCwh7HxfK38V0cuIgYCucHdiPBIUM6YPVqk6+zlQtvaC8X E87w9dvQCwu5BakahOqD04XPiulg/gwAJFrbZAwwRwUFSZsU5Eq7W6IBIIIfokoR yRU8LbtOA7ATzKcWx/i29wTTqVh6giy/aDx+RGVYwQNPOBFOH1pfFOB8BanhAOnG I2oRNEEd9XOM/+fOyJ760MUasDyd/sRbbaK/psoy3orjky2tbeLUISpJd7UVrmVo D9Mg2CeN7CPqxrJgjpWm/TDhl/NLHlbtVrZcytNShNXm02UP8+224HW8WH+Iz1+5 Z7iFQZ+FvQX5Bl8WJRDU9ZXF+4cCHQtsjFQ4bW6wqiGuoJfPGVWRUhvSh0aCMkv1 Ms3/8utN3BoCkJR+o3O7AILz0r7knfgmvnWjDk7IDjd+wG7/rzk= =6UtU -----END PGP SIGNATURE----- --oplxJGu+Ee5xywIT-- From unknown Fri Aug 15 20:57:11 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Thu, 11 Jun 2020 11:24:09 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator