From debbugs-submit-bounces@debbugs.gnu.org Mon May 08 15:07:38 2017 Received: (at submit) by debbugs.gnu.org; 8 May 2017 19:07:38 +0000 Received: from localhost ([127.0.0.1]:60067 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7o0P-00024u-Td for submit@debbugs.gnu.org; Mon, 08 May 2017 15:07:38 -0400 Received: from eggs.gnu.org ([208.118.235.92]:56927) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7o0N-00024h-RZ for submit@debbugs.gnu.org; Mon, 08 May 2017 15:07:36 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1d7o0H-00086H-Rw for submit@debbugs.gnu.org; Mon, 08 May 2017 15:07:30 -0400 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=-0.5 required=5.0 tests=BAYES_05,T_DKIM_INVALID autolearn=disabled version=3.3.2 Received: from lists.gnu.org ([2001:4830:134:3::11]:41951) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1d7o0H-000862-PO for submit@debbugs.gnu.org; Mon, 08 May 2017 15:07:29 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:47893) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1d7o0G-0001wy-QD for guix-patches@gnu.org; Mon, 08 May 2017 15:07:29 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1d7o0C-00081q-0k for guix-patches@gnu.org; Mon, 08 May 2017 15:07:28 -0400 Received: from lb1.openmailbox.org ([5.79.108.160]:51901 helo=mail.openmailbox.org) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1d7o0B-00080V-PQ for guix-patches@gnu.org; Mon, 08 May 2017 15:07:23 -0400 Received: by mail.openmailbox.org (Postfix, from userid 20002) id 62792511164; Mon, 8 May 2017 21:07:22 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=openmailbox.org; s=openmailbox; t=1494270442; bh=QZKXFj3QRaCjy0frmKqBwjYyBZDyzwVWTMbEPx4sy8I=; h=From:To:Cc:Subject:Date:From; b=c6dtuBKS4/I/oIT8L/G/Ah5U+gsYdZyGZq+IROZZMV7/4Dwpmiuzcqz7hti0wtBbs ujMQcxNM3MgQvozIJRWobeTxAE9QEytyMhx05l+067jVGDjAIFYqa1oxplJrnscgKf QJ+/e7852XLP94DKr23KrNnd4GJZ3mcuigeTUwFk= From: Kei Kebreau DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=openmailbox.org; s=openmailbox; t=1494270442; bh=QZKXFj3QRaCjy0frmKqBwjYyBZDyzwVWTMbEPx4sy8I=; h=From:To:Cc:Subject:Date:From; b=c6dtuBKS4/I/oIT8L/G/Ah5U+gsYdZyGZq+IROZZMV7/4Dwpmiuzcqz7hti0wtBbs ujMQcxNM3MgQvozIJRWobeTxAE9QEytyMhx05l+067jVGDjAIFYqa1oxplJrnscgKf QJ+/e7852XLP94DKr23KrNnd4GJZ3mcuigeTUwFk= To: guix-patches@gnu.org Subject: [PATCH] gnu: libarchive: Update to 3.3.1. Date: Mon, 8 May 2017 15:07:14 -0400 Message-Id: <20170508190714.15902-1-kei@openmailbox.org> X-Mailer: git-send-email 2.12.2 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6.x X-Received-From: 2001:4830:134:3::11 X-Spam-Score: -4.0 (----) X-Debbugs-Envelope-To: submit Cc: Kei Kebreau X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -4.0 (----) Fixes CVE-2016-{10209,10350} and CVE-2017-5601. * gnu/packages/backup.scm (libarchive): Update to 3.3.1. --- gnu/packages/backup.scm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/gnu/packages/backup.scm b/gnu/packages/backup.scm index f9c0a22a0..569d5d64b 100644 --- a/gnu/packages/backup.scm +++ b/gnu/packages/backup.scm @@ -186,7 +186,7 @@ backups (called chunks) to allow easy burning to CD/DVD.") (define-public libarchive (package (name "libarchive") - (version "3.2.2") + (version "3.3.1") (source (origin (method url-fetch) @@ -194,7 +194,7 @@ backups (called chunks) to allow easy burning to CD/DVD.") version ".tar.gz")) (sha256 (base32 - "03q6y428rg723c9fj1vidzjw46w1vf8z0h95lkvz1l9jw571j739")))) + "1rr40hxlm9vy5z2zb5w7pyfkgd1a4s061qapm83s19accb8mpji9")))) (build-system gnu-build-system) ;; TODO: Add -L/path/to/nettle in libarchive.pc. (inputs -- 2.12.2 From debbugs-submit-bounces@debbugs.gnu.org Mon May 08 15:25:53 2017 Received: (at 26836) by debbugs.gnu.org; 8 May 2017 19:25:53 +0000 Received: from localhost ([127.0.0.1]:60171 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7oI4-0002bh-Rt for submit@debbugs.gnu.org; Mon, 08 May 2017 15:25:53 -0400 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:59613) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7oI2-0002bY-8q for 26836@debbugs.gnu.org; Mon, 08 May 2017 15:25:51 -0400 Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id B4EF120BA3; Mon, 8 May 2017 15:25:49 -0400 (EDT) Received: from frontend1 ([10.202.2.160]) by compute4.internal (MEProxy); Mon, 08 May 2017 15:25:49 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=cc:content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=cH2Af/qEPOKIACWPCLgBNV+kMeaGOg6+Zj6T0O U4DUw=; b=LrTheVyl2XpBI9uyblwTE2yFtW5zC9Xml273/2iEbcI0FWq+lz+OmW wqCRP4fiDVQvYLex5mRNiaiVijQI0Yomi05g1qKVB3Nxm3YYV1NNcAmIZ1MYBV+u ek1AOHbK9Kg4CHQY44xEIbhwhChwTw9pogLLD6B7QbtCmiteVukyk= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-sender :x-me-sender:x-sasl-enc:x-sasl-enc; s=fm1; bh=cH2Af/qEPOKIACWPCL gBNV+kMeaGOg6+Zj6T0OU4DUw=; b=kbEf+/+sGwJ89VvjAbDaXH71PdCcw+X1aF By5PtxXyHq+mLnLt5uAEkf+lkff0wsMMzRM/uYGxwn1yULZ90lwT+UtnPvK9tUXa XBlzf3ZYToz/mypwZnV+mK+aRDwL8uWQLMAXflg4pIpEJdZ9oZyMsNbkdrvAJEBl zERuKVwUIpEIPDHCUqDGHkEqJUyqJSHy0QteOOa+y0U96BPDnkieNSR5UCCNvQs0 QZ9y9bQ91Ys/SPXIjcXvDIp6e7Zr39oa1zOEA/QLNaOVckUq5mS8ZprcmEvBBH/r YyQNDIaH+l9JmePUaeZUVSCMNzRpih+PU7WISIl/8dkQnde2Ijjg== X-ME-Sender: X-Sasl-enc: Hs4jWZKen6F8wjqY3MRnogC6HqHn3aTcAHQ7BTMRhOs4 1494271549 Received: from localhost (c-73-165-108-70.hsd1.pa.comcast.net [73.165.108.70]) by mail.messagingengine.com (Postfix) with ESMTPA id 706AC7E9F4; Mon, 8 May 2017 15:25:49 -0400 (EDT) Date: Mon, 8 May 2017 15:25:48 -0400 From: Leo Famulari To: Kei Kebreau Subject: Re: bug#26836: [PATCH] gnu: libarchive: Update to 3.3.1. Message-ID: <20170508192548.GA20051@jasmine> References: <20170508190714.15902-1-kei@openmailbox.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="u3/rZRmxL6MmkK24" Content-Disposition: inline In-Reply-To: <20170508190714.15902-1-kei@openmailbox.org> User-Agent: Mutt/1.8.2 (2017-04-18) X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 26836 Cc: 26836@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) --u3/rZRmxL6MmkK24 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote: > Fixes CVE-2016-{10209,10350} and CVE-2017-5601. >=20 > * gnu/packages/backup.scm (libarchive): Update to 3.3.1. Thanks! Can you use a graft instead? Then, the commit message can be like this: gnu: libarchive: Replace with 3.3.1 [security fixes]. Fixes CVE-2016-{10209,10350}, CVE-2017-5601. * gnu/packages/backup.scm (libarchive)[replacement]: New field. (libarchive-3.3.1): New variable. --u3/rZRmxL6MmkK24 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlkQxjsACgkQJkb6MLrK fwixIA/+L1wXFfeW7f8Xc4xOBKN0Z03rH0IiSQ5TYLwQrzAgbjqH/LIj3NyTonMf jD5r2amhSdaeI1OTRY6g3SZYn2t6Rns73ItKpn07QJ0rTbSLJHgaFUpUeK8zZJyl mKpS19LHPvpqPwj1BasmrIJiwkWxrP5z/nuaj8shsVPyCb3RaqCVJf55iPtj7Mhv dXmS5v1Y4d2pub/f/xr2zFy5lkcae4HvaSCHEohphCyz4yBOcDs46fIeV29Djt+L DbAt1IXyOhJwDUnq4bcQp+EPo2nmSMI15yq6taI7N4N+Cw6srD44D5fDQEJpUNrm vTDmsjbtsXO7x8K+F7beG9NiaxD5OIWTBxF4AYRLeIPR5c4oi8mOvVjnflTXoYpX IsFKV4untlAgDtrovN/5F7XQp9MtvadjbUGiMNbNIed8B6nHr8W7DbmurnkbI1ou p/sQP4P18ahmnBQE3ylhGKEi2zr816ARkOB1y8QUB01UsLTvdOb8L0OW5qUTtMqq 1ScergQ3yAZewgOzFQGehBPl+bdLRbAIG2/jnMiO/9ClsItAzs6Y5DwxfKu+mkg8 VVGijtqUOWbNeiCf0qghsEdaGPLtE2T/QQR+bhSxt6fxa89D410/hmmLPobnv+7k H0kg/5y7kDD2GV6rq9nH1+tGvx8lqYPKS0bm9wtOSuapDTyc67M= =p72G -----END PGP SIGNATURE----- --u3/rZRmxL6MmkK24-- From debbugs-submit-bounces@debbugs.gnu.org Mon May 08 17:10:44 2017 Received: (at 26836) by debbugs.gnu.org; 8 May 2017 21:10:44 +0000 Received: from localhost ([127.0.0.1]:60335 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7pvR-0000Ur-4Y for submit@debbugs.gnu.org; Mon, 08 May 2017 17:10:44 -0400 Received: from lb1.openmailbox.org ([5.79.108.160]:57763 helo=mail.openmailbox.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7pvP-0000Ui-8o for 26836@debbugs.gnu.org; Mon, 08 May 2017 17:10:36 -0400 Received: by mail.openmailbox.org (Postfix, from userid 20002) id A123750207E; Mon, 8 May 2017 23:10:33 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=openmailbox.org; s=openmailbox; t=1494277834; bh=CvkH8reD6ZInCc88tpWJayzxj1etLg1zQKIc/8RpD2w=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=H4flPqv6vvANMQa7Ll2Nne6UrPN0Hw6/EOc+v/cGJIK8MFWDacPNlYXHp//1DlJBl Na4+SwszcnuyFJ1Z9yD3v1G28vjPiXTHrblpdDO00z0/F6ZcIX0qzn2sVBJ+iWRmt7 3aC6G0TWMJBiYHw18NeAiO0T25hI/oOv21N/JLaI= From: Kei Kebreau DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=openmailbox.org; s=openmailbox; t=1494277833; bh=CvkH8reD6ZInCc88tpWJayzxj1etLg1zQKIc/8RpD2w=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=dB3JYlA0pnegBBKCKK6MfB+p1MPesfv35XqQQR92QxcCkn2QhMsGYjWsbnFVBPfPS rtsPXc0qyOJ7ndzZJjoZepZuc4KIaQD6C2NJBFGP8qIqpA+QskE+ceGxlgwOOpDcfW 6WOKVwOpH7jV7VFrvPeupuJyUxV/Rb/a/QeKREoc= To: Leo Famulari Subject: Re: bug#26836: [PATCH] gnu: libarchive: Update to 3.3.1. References: <20170508190714.15902-1-kei@openmailbox.org> <20170508192548.GA20051@jasmine> Date: Mon, 08 May 2017 17:10:28 -0400 In-Reply-To: <20170508192548.GA20051@jasmine> (Leo Famulari's message of "Mon, 8 May 2017 15:25:48 -0400") Message-ID: <878tm7kqbf.fsf@openmailbox.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.2 (gnu/linux) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="==-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 26836 Cc: 26836@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: 0.0 (/) --==-=-= Content-Type: multipart/mixed; boundary="=-=-=" --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Leo Famulari writes: > On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote: >> Fixes CVE-2016-{10209,10350} and CVE-2017-5601. >>=20 >> * gnu/packages/backup.scm (libarchive): Update to 3.3.1. > > Thanks! > > Can you use a graft instead? Then, the commit message can be like this: > > gnu: libarchive: Replace with 3.3.1 [security fixes]. > > Fixes CVE-2016-{10209,10350}, CVE-2017-5601. > > * gnu/packages/backup.scm (libarchive)[replacement]: New field. > (libarchive-3.3.1): New variable. Like the patch I've attached? --=-=-= Content-Type: text/plain; charset=utf-8 Content-Disposition: attachment; filename=0001-gnu-libarchive-Replace-with-3.3.1-security-fixes.patch Content-Transfer-Encoding: quoted-printable From=2045d3157bb61bb8b5f26ff13feb672759b6043e6f Mon Sep 17 00:00:00 2001 From: Kei Kebreau Date: Mon, 8 May 2017 14:58:07 -0400 Subject: [PATCH] gnu: libarchive: Replace with 3.3.1 [security fixes]. To: 26836@debbugs.gnu.org Fixes CVE-2016-{10209,10350} and CVE-2017-5601. * gnu/packages/backup.scm (libarchive)[replacement]: New field. (libarchive-3.3.1): New variable. =2D-- gnu/packages/backup.scm | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/gnu/packages/backup.scm b/gnu/packages/backup.scm index f9c0a22a0..d5cb5783a 100644 =2D-- a/gnu/packages/backup.scm +++ b/gnu/packages/backup.scm @@ -5,6 +5,7 @@ ;;; Copyright =C2=A9 2017 Tobias Geerinckx-Rice ;;; Copyright =C2=A9 2017 Thomas Danckaert ;;; Copyright =C2=A9 2017 Arun Isaac +;;; Copyright =C2=A9 2017 Kei Kebreau ;;; ;;; This file is part of GNU Guix. ;;; @@ -186,6 +187,7 @@ backups (called chunks) to allow easy burning to CD/DVD= .") (define-public libarchive (package (name "libarchive") + (replacement libarchive-3.3.1) (version "3.2.2") (source (origin @@ -241,6 +243,20 @@ archive. In particular, note that there is currently = no built-in support for random access nor for in-place modification.") (license license:bsd-2))) =20 +(define libarchive-3.3.1 + (package + (inherit libarchive) + (name "libarchive") + (version "3.3.1") + (source + (origin + (method url-fetch) + (uri (string-append "http://libarchive.org/downloads/libarchive-" + version ".tar.gz")) + (sha256 + (base32 + "1rr40hxlm9vy5z2zb5w7pyfkgd1a4s061qapm83s19accb8mpji9")))))) + (define-public rdup (package (name "rdup") =2D-=20 2.12.2 --=-=-=-- --==-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEg7ZwOtzKO2lLzi2m5qXuPBlGeg0FAlkQ3sUACgkQ5qXuPBlG eg3itw//Tac6M7DbEYI4GF14bSvk3iV4+Pe9Qekcc6sh7aaflyANhD9rvpNDDJ+W /B25XUpe1YagW7tywlfIt61teFqlO+LazDhKjgo0W8GQv51qOPcP0bb1BkD1u/d1 pW11gacFKhwPIO4ZjFroatCR3f1f4tI+/mg9KedfWaZADEaKMTl+8T2lxAsSzcji VEThgp321TE7krjfTrabzTpfsuZUwvXyti1y+RvAf82eGvG4ukkZMoYLIhHB9USV L+STL7rJox0dU6TaRBvH0htPwPQLcl28IugXQ4FrrDzxMDwjtlUY0v0elpk+urlg nfvAttS/17yNXfAnrAZkKfRS2yv1aqYiWzHPVOwselq0w+rQqHuKtRLbMBrapGjS 92eXoLUikBqRyS63Q791u5E6+ybWsX9I+oXdxPxopz9/Wpj7x+capZIOrxKCB+Sv VpnZGXmUYLksowNzhdygWjKSNr0mVIYp7RXtTVvUdLkjr4GrwKs7yjA2wmJUn7Zi 6DKtYqDxMr5bqt7L6kq2RnE+Sjy+gZjL9lLKGVQJOXTloXHulAFxI4SkIFikKPst SYnAprDEx1//oB53B1XOVmZZ+Owqg1TBxruvkK8Xbduh4wu3fvBQ7V4GF4VXOqAn IwfdombCf4b/q70p9DeFZ5kKwQUpgiuraX+iuxO1KtUq4Qz8O3A= =pCJ8 -----END PGP SIGNATURE----- --==-=-=-- From debbugs-submit-bounces@debbugs.gnu.org Mon May 08 17:56:17 2017 Received: (at 26836) by debbugs.gnu.org; 8 May 2017 21:56:17 +0000 Received: from localhost ([127.0.0.1]:60364 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7qdd-0001XG-JD for submit@debbugs.gnu.org; Mon, 08 May 2017 17:56:17 -0400 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:57523) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7qda-0001X6-6r for 26836@debbugs.gnu.org; Mon, 08 May 2017 17:56:15 -0400 Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id C896A208D6; Mon, 8 May 2017 17:56:13 -0400 (EDT) Received: from frontend1 ([10.202.2.160]) by compute4.internal (MEProxy); Mon, 08 May 2017 17:56:13 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name; h=cc:content-type:date:from:in-reply-to:message-id:mime-version :references:subject:to:x-me-sender:x-me-sender:x-sasl-enc :x-sasl-enc; s=mesmtp; bh=gZt2VavQNAodn+luJw6dWsDvQHdk0LRG8f/uEd eSAOA=; b=S2mMU0Wgv3QlJvi2TrKX9LXSG2VcGNLLEkjpExqD57EwuP8KiP6pcC 0uSjABkHwYrn2aK5MLsSo5tVc6v8/Zu4nBNhalD6tMYeihmH1DtuMdOKdz4y4xWJ bRz6CCnuR9rxq5WBWloj/b2FKZGPlIsxyUIwX53OesJsm7ttSvOWc= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-sender :x-me-sender:x-sasl-enc:x-sasl-enc; s=fm1; bh=gZt2VavQNAodn+luJw 6dWsDvQHdk0LRG8f/uEdeSAOA=; b=Nl+tquK8uzJId27s2sVY+J2B37pgzH5qwJ iXUtCL3nkJRgDSdSPKV4e+UCWfWiriWUrvDwbrRgAwCG5FAmBzu+lA9hqzTMyj9A P8JR7F8ofRTNGyjqhNQhagzFJkGzSBeoCvWHVJJlBzf/sefLJiHM9Jb+s6wffjwL ldH8xYSKNEvhP2Xk2/j1TQBK/tGVIwRVeU2dOhEAiSfbdl71TERlXJxnwXaFuIkB NXeicQU5ywslI4ycQlMUWbdhrJPSdGNfwJ3qd1A10x7PFUq8k4i+jz2rp7x9ewJp b1ycHbS5ikp43ECaGtSgobNYWLqYf7ygdbCWu3iV8oVxW15uqDWA== X-ME-Sender: X-Sasl-enc: 0Io4bjETmTQdrc/QL303edr9vfhwGFTB5Th7YhH9jQan 1494280573 Received: from localhost (c-73-165-108-70.hsd1.pa.comcast.net [73.165.108.70]) by mail.messagingengine.com (Postfix) with ESMTPA id 876FA7E9E6; Mon, 8 May 2017 17:56:13 -0400 (EDT) Date: Mon, 8 May 2017 17:56:11 -0400 From: Leo Famulari To: Kei Kebreau Subject: Re: bug#26836: [PATCH] gnu: libarchive: Update to 3.3.1. Message-ID: <20170508215611.GA3476@jasmine> References: <20170508190714.15902-1-kei@openmailbox.org> <20170508192548.GA20051@jasmine> <878tm7kqbf.fsf@openmailbox.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="lrZ03NoBR/3+SXJZ" Content-Disposition: inline In-Reply-To: <878tm7kqbf.fsf@openmailbox.org> User-Agent: Mutt/1.8.2 (2017-04-18) X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 26836 Cc: 26836@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) --lrZ03NoBR/3+SXJZ Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, May 08, 2017 at 05:10:28PM -0400, Kei Kebreau wrote: > Leo Famulari writes: >=20 > > On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote: > >> Fixes CVE-2016-{10209,10350} and CVE-2017-5601. > >>=20 > >> * gnu/packages/backup.scm (libarchive): Update to 3.3.1. > > > > Thanks! > > > > Can you use a graft instead? Then, the commit message can be like this: > > > > gnu: libarchive: Replace with 3.3.1 [security fixes]. > > > > Fixes CVE-2016-{10209,10350}, CVE-2017-5601. > > > > * gnu/packages/backup.scm (libarchive)[replacement]: New field. > > (libarchive-3.3.1): New variable. >=20 > Like the patch I've attached? > From 45d3157bb61bb8b5f26ff13feb672759b6043e6f Mon Sep 17 00:00:00 2001 > From: Kei Kebreau > Date: Mon, 8 May 2017 14:58:07 -0400 > Subject: [PATCH] gnu: libarchive: Replace with 3.3.1 [security fixes]. > To: 26836@debbugs.gnu.org >=20 > Fixes CVE-2016-{10209,10350} and CVE-2017-5601. >=20 > * gnu/packages/backup.scm (libarchive)[replacement]: New field. > (libarchive-3.3.1): New variable. Thanks, LGTM! --lrZ03NoBR/3+SXJZ Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlkQ6XcACgkQJkb6MLrK fwi/ThAAjA6VOmdiNfDJUMbf8pjjOal+KmK3Mlkn2B+twMPAwOtJC/B2DPZ/7nIq 7kNUCSz+PpnwOSek5V0alLZxIeXdPDaNdwzpojptrmCvy8cYTRDzAg3AckIhDdlb Y6YEs3UoMqOSDSnxwHUQpWUU+eQ1gGHB5UUXtuepiAmvHPlzuKVIWHCicvb/aXuv ClM0Ui09VnA7/BDIdYUPsC7kJwH7UWjgGDjRzSuxWRUblPSybPShiBklGuu2Jq8w A5MfUM3aCAZoCqc1t9og0dSC8yppoTx0IwCznd6A4m3h7uvTAxTCozSi48PxDHCv p8n1ssdXEa3THi1hWp0dvI8cZci9AlPanRN2YKAcntFgm4Y0tJJkmtHEkHHs2LsB yMQakKUXZnUrmm2OrIUTwVjllCD3mvo0ZxQNtEKGaQNFjJcX0d3CB/B/9NKlva4K dpA71Unn3IoIxakaZycai2da4cwxToW4cOq06U+vB890EATQifUSHcN4F9Z0Lr2g 7+gT9KngpMEdBa0w8yIEK187AdizxJ4O8UMrXK1uEa2ZInObMVRyOSiRNnIA6PMp 1Cd0ZRqKaTv9+mloTD725kPSDAy3EMGu2olQpHBRQ57HBZ7/fBmLa0F+f+qoCbdi G4j3djYHraUX1zsVr0zPXLWAGYlTJW6BWmELUA1fxQO4Bkcw5HM= =P+qq -----END PGP SIGNATURE----- --lrZ03NoBR/3+SXJZ-- From debbugs-submit-bounces@debbugs.gnu.org Mon May 08 20:26:29 2017 Received: (at 26836-done) by debbugs.gnu.org; 9 May 2017 00:26:29 +0000 Received: from localhost ([127.0.0.1]:60430 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7syz-0004xk-5G for submit@debbugs.gnu.org; Mon, 08 May 2017 20:26:29 -0400 Received: from lb1.openmailbox.org ([5.79.108.160]:42832 helo=mail.openmailbox.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1d7syx-0004xd-Js for 26836-done@debbugs.gnu.org; Mon, 08 May 2017 20:26:28 -0400 Received: by mail.openmailbox.org (Postfix, from userid 20002) id 02D7B51138C; Tue, 9 May 2017 02:26:26 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=openmailbox.org; s=openmailbox; t=1494289587; bh=3OQnX8VsKC3hK5UF4Mdl1BtcVZO3+ihzvlAW+5z7CCk=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=adMY89Ttvtrr6vr8DGcT+mKMmyCnNmI2le4b14bMJ0YeXyNGXSPpAYFJty3h/EcGB +0eAeYf3hfftaNqNXTGjHsVg3dEtL47hgdbwO6/WrHYw5kFDeitoAkgejL9yJQdylf 4I6sUnKJlLZb61CbQf9xDkqWJwDbr+g2WonszCDg= From: Kei Kebreau DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=openmailbox.org; s=openmailbox; t=1494289586; bh=3OQnX8VsKC3hK5UF4Mdl1BtcVZO3+ihzvlAW+5z7CCk=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From; b=WvxR6UCN6FxIkuFiOhDw9BKlJLbHfbv2ff5y3StdbII92dsw+UlApeaIDjl1+CoV/ 3qy/yM4ACZeHZwXD4EbiWE0em02kdJPcbV4sgDHuROYZzdksV3UMimmVr7IksjlhYp Gq9KzR8XEGMqdvKguuVZ3nOuWAPWvaBYnIiL4bGs= To: Leo Famulari Subject: Re: bug#26836: [PATCH] gnu: libarchive: Update to 3.3.1. References: <20170508190714.15902-1-kei@openmailbox.org> <20170508192548.GA20051@jasmine> <878tm7kqbf.fsf@openmailbox.org> <20170508215611.GA3476@jasmine> Date: Mon, 08 May 2017 20:26:22 -0400 In-Reply-To: <20170508215611.GA3476@jasmine> (Leo Famulari's message of "Mon, 8 May 2017 17:56:11 -0400") Message-ID: <87r2zykh8x.fsf@openmailbox.org> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.2 (gnu/linux) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 26836-done Cc: 26836-done@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Leo Famulari writes: > On Mon, May 08, 2017 at 05:10:28PM -0400, Kei Kebreau wrote: >> Leo Famulari writes: >>=20 >> > On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote: >> >> Fixes CVE-2016-{10209,10350} and CVE-2017-5601. >> >>=20 >> >> * gnu/packages/backup.scm (libarchive): Update to 3.3.1. >> > >> > Thanks! >> > >> > Can you use a graft instead? Then, the commit message can be like this: >> > >> > gnu: libarchive: Replace with 3.3.1 [security fixes]. >> > >> > Fixes CVE-2016-{10209,10350}, CVE-2017-5601. >> > >> > * gnu/packages/backup.scm (libarchive)[replacement]: New field. >> > (libarchive-3.3.1): New variable. >>=20 >> Like the patch I've attached? > >> From 45d3157bb61bb8b5f26ff13feb672759b6043e6f Mon Sep 17 00:00:00 2001 >> From: Kei Kebreau >> Date: Mon, 8 May 2017 14:58:07 -0400 >> Subject: [PATCH] gnu: libarchive: Replace with 3.3.1 [security fixes]. >> To: 26836@debbugs.gnu.org >>=20 >> Fixes CVE-2016-{10209,10350} and CVE-2017-5601. >>=20 >> * gnu/packages/backup.scm (libarchive)[replacement]: New field. >> (libarchive-3.3.1): New variable. > > Thanks, LGTM! Great! Pushed to master. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEg7ZwOtzKO2lLzi2m5qXuPBlGeg0FAlkRDK4ACgkQ5qXuPBlG eg3nRRAAqBQl2/cyUOsJEJ0tiej3G3CWG8Rnqe9aIk/h6U4vKvWYwZQAha9BSY4D 8xCVHuyhcsWKnO/VJsRFwYdF2f6e5PZWDCyrygMIqB75xQKAFu0/bONkxcqDxf2H jxEK5CamjFetH7qNrmINXEX4dnkeBFR7gvHVZ8vsh+VdXf6AwRGgixw90/yx5cKv 0BtKi04b3WX4kr+kPjXdOghbQz7quMEJiPRG2pN9U442ci0Xm5BCQvSn4N2WYJtu VV8eS/E59LqkCtSM+oQel/V+V69psO2moR+gc4Hcza+23gWRs5O5+iiqGScjCC5m EPIoLq0k61LXO6K+OM0w6fDo3kEy7QEdxysqu8vAnEdMZfKlNBjypSM8f7SKSWgm QgcFqmomS0ULJ8UhmqkeI1U8Zrftb3Lurf7IBvk0MYV612XH9A7be4qy3KAIievU Ao4mCzogYkaSHJuo/WG6roRI6drsirhqwX7FY2fDi6folKT753EMMwc3ACI0Wqld H2ygZ6Wo3Qm210Re2+jdtHFZze2m/DPTpRmLXgkxOMVZKUUVOVNRm6Hzni4PGpmA DpJe98fkwEQHgc3GoaZkM6YweDfiaoCECaXNwlqhIBuvkCfOFGu+Y3Y6YUS+ABxN mfYiHFebSyWDCAnm6RwLi+dDjaNR48NQW/EnEShj8DbANG5VD54= =JCoZ -----END PGP SIGNATURE----- --=-=-=-- From unknown Tue Jun 24 05:14:44 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Tue, 06 Jun 2017 11:24:05 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator