From unknown Wed Aug 20 01:19:54 2025 X-Loop: help-debbugs@gnu.org Subject: bug#26390: Guitarix: Don't use webkitgtk-2.4 Resent-From: Leo Famulari Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Fri, 07 Apr 2017 11:59:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 26390 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: To: 26390@debbugs.gnu.org Cc: Ricardo Wurmus X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.149156629119235 (code B ref -1); Fri, 07 Apr 2017 11:59:01 +0000 Received: (at submit) by debbugs.gnu.org; 7 Apr 2017 11:58:11 +0000 Received: from localhost ([127.0.0.1]:35794 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwSWo-00050B-Ry for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:11 -0400 Received: from eggs.gnu.org ([208.118.235.92]:50153) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwSWm-0004zy-Nt for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:09 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cwSWg-00050e-As for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:03 -0400 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,T_DKIM_INVALID autolearn=disabled version=3.3.2 Received: from lists.gnu.org ([2001:4830:134:3::11]:58305) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cwSWg-00050V-6l for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:02 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:41111) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cwSWe-0002Um-NU for guix-patches@gnu.org; Fri, 07 Apr 2017 07:58:01 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cwSWb-0004xT-Lm for guix-patches@gnu.org; Fri, 07 Apr 2017 07:58:00 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:42760) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cwSWb-0004wp-3T for guix-patches@gnu.org; Fri, 07 Apr 2017 07:57:57 -0400 Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 537142093D; Fri, 7 Apr 2017 07:57:56 -0400 (EDT) Received: from frontend1 ([10.202.2.160]) by compute4.internal (MEProxy); Fri, 07 Apr 2017 07:57:56 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=cc:content-type:date:from:message-id:mime-version:subject:to :x-me-sender:x-me-sender:x-sasl-enc:x-sasl-enc; s=mesmtp; bh=dHQ OAyZ/j7iI35lzZtaXYd1/69PbTMJQ5S9MG7UageI=; b=p23tCMqCu3a9Oi2tlhq CFI+Z4axXPssThm5GmaJzenWANNMyeeLnI2IO0phgVA1u0tZeidrhJlbSlXeRdLy 9sbfjEJ2HxlBTcgDWSllMisvt5Ah4oFAcTj6dQyTXWIWsZZYKDuDbacymQLOg4a2 plVb9vMrXHpGDAfqCS0i4BWg= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:message-id :mime-version:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=fm1; bh=dHQOAyZ/j7iI35lzZtaXYd1/69PbTMJQ5S9MG7Uag eI=; b=c8JyRlJTXQ7pyiWURLiqmEKa+rY7UUiPkIGwMQ6bJdD36efEa0WOjP0Kf o2VdxcwVYWmQk40uEM488+htPhGWc5fqOnz9HSZ8h4ezcGBZARTcI17z1bTV8/0t vI7zFTMkfOSkr/ghnpLVpGW1CIscCs+wi6JdsVgNydlA2JTiiiw99k7xdcESpXol pMM+PtyTDCygpC+NhcR45pHQAradHi+gDuUMIoUcg45CTepo/Fnf4OwUGBYIERmc pg9cHNtgw9nTiwDO7eS9jHqdZmTJkFQBhy9gjvzB10dR36jFnc7KLf63mUH0/PMn oMVSMF/hb4Kr/H2l7I6rJ9R1+D3YA== X-ME-Sender: X-Sasl-enc: tAAq7a1fxwFamB4AJFiJi7kBU8OmOjkytqfb9fo53amG 1491566276 Received: from localhost (unknown [65.210.80.3]) by mail.messagingengine.com (Postfix) with ESMTPA id 197997E626; Fri, 7 Apr 2017 07:57:56 -0400 (EDT) Date: Fri, 7 Apr 2017 07:57:54 -0400 From: Leo Famulari Message-ID: <20170407115754.GA21115@jasmine> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="wq9mPyueHGvFACwf" Content-Disposition: inline User-Agent: Mutt/1.8.0 (2017-02-23) X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-Received-From: 2001:4830:134:3::11 X-Spam-Score: -4.1 (----) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -4.1 (----) --wq9mPyueHGvFACwf Content-Type: multipart/mixed; boundary="bp/iNruPH9dso1Pn" Content-Disposition: inline --bp/iNruPH9dso1Pn Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Webkitgtk-2.4 is unmaintained upstream and contains a large number of security vulnerabilities. The webkitgtk developers have asked distributions to stop offering it. [0] This patch removes webkitgtk-2.4 from guitarix. Guitarix builds and starts without; I don't know what features are disabled. Ricardo, what do you think? [0] https://blogs.gnome.org/mcatanzaro/2016/02/01/on-webkit-security-updates/ --bp/iNruPH9dso1Pn Content-Type: text/plain; charset=us-ascii Content-Disposition: attachment; filename="0001-gnu-guitarix-Disable-webkit-features.patch" Content-Transfer-Encoding: quoted-printable =46rom b19ec539033acdbdbf1d99989d39528e7350646c Mon Sep 17 00:00:00 2001 =46rom: Leo Famulari Date: Fri, 7 Apr 2017 07:44:05 -0400 Subject: [PATCH] gnu: guitarix: Disable webkit features. The only version of webkit supported by guitarix is unmaintained and contai= ns a large number of security vulnerabilities, and is due to be removed from Gui= x. * gnu/packages/audio.scm (guitarix)[inputs]: Remove webkitgtk/gtk+-2. --- gnu/packages/audio.scm | 1 - 1 file changed, 1 deletion(-) diff --git a/gnu/packages/audio.scm b/gnu/packages/audio.scm index 9dc679734..9acccaf11 100644 --- a/gnu/packages/audio.scm +++ b/gnu/packages/audio.scm @@ -1166,7 +1166,6 @@ patches that can be used with softsynths such as Timi= dity and WildMidi.") ("jack" ,jack-1) ("gtkmm" ,gtkmm-2) ("gtk+" ,gtk+-2) - ("webkitgtk/gtk+-2" ,webkitgtk/gtk+-2) ("fftwf" ,fftwf) ("lrdf" ,lrdf) ("zita-resampler" ,zita-resampler) --=20 2.12.2 --bp/iNruPH9dso1Pn-- --wq9mPyueHGvFACwf Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAljnfr8ACgkQJkb6MLrK fwgPXBAAywZf9wDCAXagpFdJWMHPLIHc5dTkyRvQ7XdJtrqYxh1Ujy2bkOaV2dGv oMLoaQ2KdEqIAOiaaqwg1Mhul0z77UTp920loUBPzL6ESl1RVJWkjskP+c+wL+OE ZY22coE0ZyeOupprwFZPZ3XuNpUic6noCi0fhLw7V999DYeK4mZCoAt+RQ4NOdrB y+RBbF7IY12psv32mXzpiRdA3A0bPTX7M5vMkQoufC8bfW682FDXDD98ldFJsF2Q 80RvAwP4cmReOyEG8v11yY+pyE6YL5i4WLnzy8wDUQmh/mYbc0ADdUpLyj8owBAt ClsMfjXtiUxXinEgARjmW/9XKLZLj+7gBSDwz1a/0jMfFbbMPM4CCcLSwfXTmhqY wWQjlRx+z+1FZXbTiJhuQPKVA98Alhth6HrrBmv7CZgB62IiGwFHPkE07oMqlcWX BZokqxJNSDf0BfeVSLID0UbxLvvCkz7Qnx3YKjcIE0zLe+17wi9WVMNIL5z8+nCD 4YJGcge4D84Q3Bz9lghASanIDQSLMrWefwArSVQ6ws0RSCcIJGIXrkXW9uh7XeXr 8V1RWLyhXaUSly2ObPI16bUe7h3XmLnBBIN9yG6nOtENLUmJOsKisVlK2NhLhMzc 6IrJgQ09Vkg8s+1iArb4thH2gIA+vH9vlYG/HZ57vZ97oykMm6M= =fSWF -----END PGP SIGNATURE----- --wq9mPyueHGvFACwf-- From unknown Wed Aug 20 01:19:54 2025 X-Loop: help-debbugs@gnu.org Subject: bug#26390: Guitarix: Don't use webkitgtk-2.4 Resent-From: Ricardo Wurmus Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Fri, 07 Apr 2017 12:32:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 26390 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: To: Leo Famulari Cc: 26390@debbugs.gnu.org X-Debbugs-Original-Cc: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.149156828622318 (code B ref -1); Fri, 07 Apr 2017 12:32:02 +0000 Received: (at submit) by debbugs.gnu.org; 7 Apr 2017 12:31:26 +0000 Received: from localhost ([127.0.0.1]:35818 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwT30-0005nu-Is for submit@debbugs.gnu.org; Fri, 07 Apr 2017 08:31:26 -0400 Received: from eggs.gnu.org ([208.118.235.92]:58727) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwT2y-0005ne-5M for submit@debbugs.gnu.org; Fri, 07 Apr 2017 08:31:24 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cwT2r-0000oD-NN for submit@debbugs.gnu.org; Fri, 07 Apr 2017 08:31:18 -0400 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=0.8 required=5.0 tests=BAYES_50 autolearn=disabled version=3.3.2 Received: from lists.gnu.org ([2001:4830:134:3::11]:47128) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cwT2r-0000o9-Kf for submit@debbugs.gnu.org; Fri, 07 Apr 2017 08:31:17 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:49689) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cwT2q-0000CE-IK for guix-patches@gnu.org; Fri, 07 Apr 2017 08:31:17 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cwT2n-0000nY-G0 for guix-patches@gnu.org; Fri, 07 Apr 2017 08:31:16 -0400 Received: from sender-of-o51.zoho.com ([135.84.80.216]:21012) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cwT2n-0000nQ-9i for guix-patches@gnu.org; Fri, 07 Apr 2017 08:31:13 -0400 Received: from localhost (141.80.148.212 [141.80.148.212]) by mx.zohomail.com with SMTPS id 1491568269787934.2873907286037; Fri, 7 Apr 2017 05:31:09 -0700 (PDT) References: <20170407115754.GA21115@jasmine> User-agent: mu4e 0.9.18; emacs 25.1.1 From: Ricardo Wurmus In-reply-to: <20170407115754.GA21115@jasmine> X-URL: https://elephly.net X-PGP-Key: https://elephly.net/rekado.pubkey X-PGP-Fingerprint: BCA6 89B6 3655 3801 C3C6 2150 197A 5888 235F ACAC Date: Fri, 07 Apr 2017 14:31:06 +0200 Message-ID: <87fuhk1jsl.fsf@elephly.net> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-ZohoMailClient: External X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x [fuzzy] X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-Received-From: 2001:4830:134:3::11 X-Spam-Score: -4.0 (----) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -4.0 (----) Leo Famulari writes: > Webkitgtk-2.4 is unmaintained upstream and contains a large number of > security vulnerabilities. The webkitgtk developers have asked > distributions to stop offering it. [0] > > This patch removes webkitgtk-2.4 from guitarix. Guitarix builds and > starts without; I don't know what features are disabled. > > Ricardo, what do you think? Sounds good to me! Webkitgtk was added only somewhat recently to the dependencies. When I added it some time ago it was not optional AFAIR. If you’ve built it successfully without webkitgtk that’s great. It was used for a built-in plugin browser, I think. -- Ricardo GPG: BCA6 89B6 3655 3801 C3C6 2150 197A 5888 235F ACAC https://elephly.net From unknown Wed Aug 20 01:19:54 2025 MIME-Version: 1.0 X-Mailer: MIME-tools 5.505 (Entity 5.505) X-Loop: help-debbugs@gnu.org From: help-debbugs@gnu.org (GNU bug Tracking System) To: Leo Famulari Subject: bug#26390: closed (Re: Guitarix: Don't use webkitgtk-2.4) Message-ID: References: <20170407133818.GA26088@jasmine> <20170407115754.GA21115@jasmine> X-Gnu-PR-Message: they-closed 26390 X-Gnu-PR-Package: guix-patches Reply-To: 26390@debbugs.gnu.org Date: Fri, 07 Apr 2017 13:39:02 +0000 Content-Type: multipart/mixed; boundary="----------=_1491572342-28154-1" This is a multi-part message in MIME format... ------------=_1491572342-28154-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your bug report #26390: Guitarix: Don't use webkitgtk-2.4 which was filed against the guix-patches package, has been closed. The explanation is attached below, along with your original report. If you require more details, please reply to 26390@debbugs.gnu.org. --=20 26390: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=3D26390 GNU Bug Tracking System Contact help-debbugs@gnu.org with problems ------------=_1491572342-28154-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 26390-done) by debbugs.gnu.org; 7 Apr 2017 13:38:22 +0000 Received: from localhost ([127.0.0.1]:35839 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwU5m-0007JE-3B for submit@debbugs.gnu.org; Fri, 07 Apr 2017 09:38:22 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:38581) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwU5k-0007J6-7S for 26390-done@debbugs.gnu.org; Fri, 07 Apr 2017 09:38:21 -0400 Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 9D09420BF5; Fri, 7 Apr 2017 09:38:19 -0400 (EDT) Received: from frontend2 ([10.202.2.161]) by compute4.internal (MEProxy); Fri, 07 Apr 2017 09:38:19 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=cc:content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=kBvCJ0CzaiWJEpWmFaqlE/07v3J58UEi/MPEkW Gq+AI=; b=hP3GWZDEArafiOwTqjS3N3KN9GpQnvFn2STum0Yn0pCRodcHCDztSC /dksZeHEtmWSxj6N315FptsawlOtQZkhAJwY6rPi16I4ud1Ja5242IHa0RHlWOUH fYefCfbXqQvE3j7iNrRJzlL5kfZeykRzYK9gdTSXTLumr86eRjDNs= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-sender :x-me-sender:x-sasl-enc:x-sasl-enc; s=fm1; bh=kBvCJ0CzaiWJEpWmFa qlE/07v3J58UEi/MPEkWGq+AI=; b=RmsHgX+HY13PhOKbGEQxUkokyJb0fi5dgS nqQMdWE7xVjL1J4pgeh00y1fJ+JeHMuO1y8+EyJwhHusLnzcTBB/TFqgU4xmEiTA PVGmzI+s/vP7lBQ+ShsZt+CAeHVSMXhKJ0OeplJmcbbKASNT2obTpBBR9Nk21UVV LGHLfT4qhc11kSoDt1N5Vw48GphK7IHdewNeVaoun1oEEXLKaL5nBd7/U4xgK2r0 ypBMuaciEcCa6PzV/Y+dplPwTsqUeeMcZGm/cL+B6UlK+iyoorwH3oTpIm2SUlhy vkcrJiC2F5ZAxd2uGtZa9X6VQdGaC0QwnM5+eG48Saf96gl/nDzw== X-ME-Sender: X-Sasl-enc: scOZivC2Ym82q+xkGc8bf92LUKVQMZZpV68jV/R7/QeW 1491572299 Received: from localhost (unknown [65.210.80.3]) by mail.messagingengine.com (Postfix) with ESMTPA id 5B19D2436B; Fri, 7 Apr 2017 09:38:19 -0400 (EDT) Date: Fri, 7 Apr 2017 09:38:18 -0400 From: Leo Famulari To: Ricardo Wurmus Subject: Re: Guitarix: Don't use webkitgtk-2.4 Message-ID: <20170407133818.GA26088@jasmine> References: <20170407115754.GA21115@jasmine> <87fuhk1jsl.fsf@elephly.net> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="bp/iNruPH9dso1Pn" Content-Disposition: inline In-Reply-To: <87fuhk1jsl.fsf@elephly.net> User-Agent: Mutt/1.8.0 (2017-02-23) X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 26390-done Cc: 26390-done@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) --bp/iNruPH9dso1Pn Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Apr 07, 2017 at 02:31:06PM +0200, Ricardo Wurmus wrote: > Leo Famulari writes: > > This patch removes webkitgtk-2.4 from guitarix. Guitarix builds and > > starts without; I don't know what features are disabled. >=20 > Sounds good to me! >=20 > Webkitgtk was added only somewhat recently to the dependencies. When I > added it some time ago it was not optional AFAIR. If you=E2=80=99ve buil= t it > successfully without webkitgtk that=E2=80=99s great. Okay, I've pushed the change. > It was used for a built-in plugin browser, I think. Let me know if you notice any breakage. --bp/iNruPH9dso1Pn Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAljnlkoACgkQJkb6MLrK fwhOghAAwKEzdOvyBTkExG3QIwHCdVnwGR/lXU8TSw941q9B0dgj+MyJQnDWvI5Z qHN0wWZa/d8pA5L4dWN5kJMw3i21BhcAXaF7ciNMtJFsy0+B4AW0dOWd9/b6AuSi ND5OK7YuzwqRFRyJDxOxRF/wMk12GxgDQqJ6euMXP/VzufvkyQxL6ZnWawvCW9bn Wxc+tu42Sg828UW+YifaxniX6OrYQ3D+B0/pCmEZ4dSSCf7glrvj3nAu8ifk5K7B DfFZNrxPRipNDs2t5gkY5zFPDNeAAsJ7UyzpgV7kLRVMPDscpjg5KcngfGjV2Pti JFz6CWVKC39tZ8s7ZcsrAqBj+0rmI0R6H7xchPI6lKKljyQYVFtf4Ze4o6I4bJHk wdC0STUsUkT3EQMapNeVj8a2s9+3xyHLkj16BHAgVaXCOnmfdmI3jQSf3JrLBXCh 0oY7Qfdujma3x49cdEO0gSRn1JYeBKMNQCZ/xPn3aYLRsGOTvaSwoQE82/Ma3Ihs 81znQk3hQ6S626kGSpseWKj2PlwwgaCIrg97l3OxDMZbPxf6M+Qs4U3E7Hk9FQSr 54b1LaacZ0mk+ptxM3+CzozbqslrR7bTPz5LX/UlZCoAMS5LeuKsf63sNYEjgpMZ 6OupsSiD946QZuydgCqDi2C5cOnfZatQ9tdiO+A/tlruMidtxk8= =RWD3 -----END PGP SIGNATURE----- --bp/iNruPH9dso1Pn-- ------------=_1491572342-28154-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by debbugs.gnu.org; 7 Apr 2017 11:58:11 +0000 Received: from localhost ([127.0.0.1]:35794 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwSWo-00050B-Ry for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:11 -0400 Received: from eggs.gnu.org ([208.118.235.92]:50153) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cwSWm-0004zy-Nt for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:09 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cwSWg-00050e-As for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:03 -0400 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,T_DKIM_INVALID autolearn=disabled version=3.3.2 Received: from lists.gnu.org ([2001:4830:134:3::11]:58305) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cwSWg-00050V-6l for submit@debbugs.gnu.org; Fri, 07 Apr 2017 07:58:02 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:41111) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cwSWe-0002Um-NU for guix-patches@gnu.org; Fri, 07 Apr 2017 07:58:01 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cwSWb-0004xT-Lm for guix-patches@gnu.org; Fri, 07 Apr 2017 07:58:00 -0400 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:42760) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cwSWb-0004wp-3T for guix-patches@gnu.org; Fri, 07 Apr 2017 07:57:57 -0400 Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 537142093D; Fri, 7 Apr 2017 07:57:56 -0400 (EDT) Received: from frontend1 ([10.202.2.160]) by compute4.internal (MEProxy); Fri, 07 Apr 2017 07:57:56 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=cc:content-type:date:from:message-id:mime-version:subject:to :x-me-sender:x-me-sender:x-sasl-enc:x-sasl-enc; s=mesmtp; bh=dHQ OAyZ/j7iI35lzZtaXYd1/69PbTMJQ5S9MG7UageI=; b=p23tCMqCu3a9Oi2tlhq CFI+Z4axXPssThm5GmaJzenWANNMyeeLnI2IO0phgVA1u0tZeidrhJlbSlXeRdLy 9sbfjEJ2HxlBTcgDWSllMisvt5Ah4oFAcTj6dQyTXWIWsZZYKDuDbacymQLOg4a2 plVb9vMrXHpGDAfqCS0i4BWg= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:message-id :mime-version:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=fm1; bh=dHQOAyZ/j7iI35lzZtaXYd1/69PbTMJQ5S9MG7Uag eI=; b=c8JyRlJTXQ7pyiWURLiqmEKa+rY7UUiPkIGwMQ6bJdD36efEa0WOjP0Kf o2VdxcwVYWmQk40uEM488+htPhGWc5fqOnz9HSZ8h4ezcGBZARTcI17z1bTV8/0t vI7zFTMkfOSkr/ghnpLVpGW1CIscCs+wi6JdsVgNydlA2JTiiiw99k7xdcESpXol pMM+PtyTDCygpC+NhcR45pHQAradHi+gDuUMIoUcg45CTepo/Fnf4OwUGBYIERmc pg9cHNtgw9nTiwDO7eS9jHqdZmTJkFQBhy9gjvzB10dR36jFnc7KLf63mUH0/PMn oMVSMF/hb4Kr/H2l7I6rJ9R1+D3YA== X-ME-Sender: X-Sasl-enc: tAAq7a1fxwFamB4AJFiJi7kBU8OmOjkytqfb9fo53amG 1491566276 Received: from localhost (unknown [65.210.80.3]) by mail.messagingengine.com (Postfix) with ESMTPA id 197997E626; Fri, 7 Apr 2017 07:57:56 -0400 (EDT) Date: Fri, 7 Apr 2017 07:57:54 -0400 From: Leo Famulari To: guix-patches@gnu.org Subject: Guitarix: Don't use webkitgtk-2.4 Message-ID: <20170407115754.GA21115@jasmine> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="wq9mPyueHGvFACwf" Content-Disposition: inline User-Agent: Mutt/1.8.0 (2017-02-23) X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-Received-From: 2001:4830:134:3::11 X-Spam-Score: -4.1 (----) X-Debbugs-Envelope-To: submit Cc: Ricardo Wurmus X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -4.1 (----) --wq9mPyueHGvFACwf Content-Type: multipart/mixed; boundary="bp/iNruPH9dso1Pn" Content-Disposition: inline --bp/iNruPH9dso1Pn Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Webkitgtk-2.4 is unmaintained upstream and contains a large number of security vulnerabilities. The webkitgtk developers have asked distributions to stop offering it. [0] This patch removes webkitgtk-2.4 from guitarix. Guitarix builds and starts without; I don't know what features are disabled. Ricardo, what do you think? [0] https://blogs.gnome.org/mcatanzaro/2016/02/01/on-webkit-security-updates/ --bp/iNruPH9dso1Pn Content-Type: text/plain; charset=us-ascii Content-Disposition: attachment; filename="0001-gnu-guitarix-Disable-webkit-features.patch" Content-Transfer-Encoding: quoted-printable =46rom b19ec539033acdbdbf1d99989d39528e7350646c Mon Sep 17 00:00:00 2001 =46rom: Leo Famulari Date: Fri, 7 Apr 2017 07:44:05 -0400 Subject: [PATCH] gnu: guitarix: Disable webkit features. The only version of webkit supported by guitarix is unmaintained and contai= ns a large number of security vulnerabilities, and is due to be removed from Gui= x. * gnu/packages/audio.scm (guitarix)[inputs]: Remove webkitgtk/gtk+-2. --- gnu/packages/audio.scm | 1 - 1 file changed, 1 deletion(-) diff --git a/gnu/packages/audio.scm b/gnu/packages/audio.scm index 9dc679734..9acccaf11 100644 --- a/gnu/packages/audio.scm +++ b/gnu/packages/audio.scm @@ -1166,7 +1166,6 @@ patches that can be used with softsynths such as Timi= dity and WildMidi.") ("jack" ,jack-1) ("gtkmm" ,gtkmm-2) ("gtk+" ,gtk+-2) - ("webkitgtk/gtk+-2" ,webkitgtk/gtk+-2) ("fftwf" ,fftwf) ("lrdf" ,lrdf) ("zita-resampler" ,zita-resampler) --=20 2.12.2 --bp/iNruPH9dso1Pn-- --wq9mPyueHGvFACwf Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAljnfr8ACgkQJkb6MLrK fwgPXBAAywZf9wDCAXagpFdJWMHPLIHc5dTkyRvQ7XdJtrqYxh1Ujy2bkOaV2dGv oMLoaQ2KdEqIAOiaaqwg1Mhul0z77UTp920loUBPzL6ESl1RVJWkjskP+c+wL+OE ZY22coE0ZyeOupprwFZPZ3XuNpUic6noCi0fhLw7V999DYeK4mZCoAt+RQ4NOdrB y+RBbF7IY12psv32mXzpiRdA3A0bPTX7M5vMkQoufC8bfW682FDXDD98ldFJsF2Q 80RvAwP4cmReOyEG8v11yY+pyE6YL5i4WLnzy8wDUQmh/mYbc0ADdUpLyj8owBAt ClsMfjXtiUxXinEgARjmW/9XKLZLj+7gBSDwz1a/0jMfFbbMPM4CCcLSwfXTmhqY wWQjlRx+z+1FZXbTiJhuQPKVA98Alhth6HrrBmv7CZgB62IiGwFHPkE07oMqlcWX BZokqxJNSDf0BfeVSLID0UbxLvvCkz7Qnx3YKjcIE0zLe+17wi9WVMNIL5z8+nCD 4YJGcge4D84Q3Bz9lghASanIDQSLMrWefwArSVQ6ws0RSCcIJGIXrkXW9uh7XeXr 8V1RWLyhXaUSly2ObPI16bUe7h3XmLnBBIN9yG6nOtENLUmJOsKisVlK2NhLhMzc 6IrJgQ09Vkg8s+1iArb4thH2gIA+vH9vlYG/HZ57vZ97oykMm6M= =fSWF -----END PGP SIGNATURE----- --wq9mPyueHGvFACwf-- ------------=_1491572342-28154-1--