From debbugs-submit-bounces@debbugs.gnu.org Tue May 25 12:37:14 2021 Received: (at submit) by debbugs.gnu.org; 25 May 2021 16:37:14 +0000 Received: from localhost ([127.0.0.1]:46627 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lla3O-0003Qg-0V for submit@debbugs.gnu.org; Tue, 25 May 2021 12:37:14 -0400 Received: from lists.gnu.org ([209.51.188.17]:43748) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lla3M-0003QZ-GI for submit@debbugs.gnu.org; Tue, 25 May 2021 12:37:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:51840) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lla3M-0007BO-6x for guix-patches@gnu.org; Tue, 25 May 2021 12:37:12 -0400 Received: from perso.pw ([163.172.223.238]:13154) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lla3J-0006Kk-3r for guix-patches@gnu.org; Tue, 25 May 2021 12:37:11 -0400 Received: from perso.pw (localhost [127.0.0.1]) by perso.pw (OpenSMTPD) with ESMTP id 1ccaa425 for ; Tue, 25 May 2021 18:36:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=perso.pw; h=date:from:to :subject:message-id:mime-version:content-type :content-transfer-encoding; s=1337; bh=FcFmNL4Hmyz/Hf/D6g5sSXM+U wU=; b=Mq+cd740aKmPaASdPCr06V5bcILA4l7y2RMlMCDim5Vq/niPrrkaUlNOM MMS6n8OuzBVVxgxBe8+dosLHITY8tyGf3e9P/UqG1/LOBTJHUKerxcE18j7kkx/y 3JTOPdhcDbsQTsUWxdI1N0wXcpB/aFugUyaF0yM8Jp5dcebYiQ= DomainKey-Signature: a=rsa-sha1; c=nofws; d=perso.pw; h=date:from:to :subject:message-id:mime-version:content-type :content-transfer-encoding; q=dns; s=1337; b=GMGnyRr8Mi7OjLYtqzS 9jfIOfJQvN/kWBg5fWU9K/UDRSjPlEFMhkwIfeUSKT7t457gehKYUd//3uzvicHQ Vb8v/B5KaOdrnR5p0EZbcOi9p8zo8oTZAPQpx66OM0YY190hF2RCtCmO499L6l+A 46ND1Tjg7PvWQQHRmLlJEKyE= X-Spam-Checker-Version: SpamAssassin 3.4.5 (2021-03-20) on perso.pw X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=ALL_TRUSTED,BAYES_00 autolearn=ham autolearn_force=no version=3.4.5 Received: from localhost (176-154-164-34.abo.bbox.fr [176.154.164.34]) by perso.pw (OpenSMTPD) with ESMTPSA id c53ead02 (TLSv1.3:AEAD-AES256-GCM-SHA384:256:NO) for ; Tue, 25 May 2021 18:36:57 +0200 (CEST) Date: Tue, 25 May 2021 18:36:56 +0200 From: Solene Rapenne To: guix-patches@gnu.org Subject: [PATCH] gnu: synapse: Update to 1.33.2. Message-ID: <20210525183656.4d41ae04@perso.pw> X-Mailer: Claws Mail 3.17.8 (GTK+ 2.24.32; x86_64-pc-linux-gnu) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Received-SPF: pass client-ip=163.172.223.238; envelope-from=solene@perso.pw; helo=perso.pw X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.4 (-) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.4 (--) This fixes the DoS [CVE-2021-29471] and many other improvements I didn't try it, I don't have a matrix server. --- gnu/packages/matrix.scm | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/gnu/packages/matrix.scm b/gnu/packages/matrix.scm index 5c2b194d07..0c0fc26705 100644 --- a/gnu/packages/matrix.scm +++ b/gnu/packages/matrix.scm @@ -3,6 +3,7 @@ ;;; Copyright =C2=A9 2020 Tobias Geerinckx-Rice ;;; Copyright =C2=A9 2020, 2021 Michael Rohleder ;;; Copyright =C2=A9 2020 Giacomo Leidi +;;; Copyright =C2=A9 2021 Solene Rapenne ;;; ;;; This file is part of GNU Guix. ;;; @@ -86,13 +87,13 @@ an LDAP server.") (define-public synapse (package (name "synapse") - (version "1.29.0") + (version "1.33.2") (source (origin (method url-fetch) (uri (pypi-uri "matrix-synapse" version)) (sha256 (base32 - "0if2yhpz8psg0661401mvxznldbfhk2j9rhbs25jdaqm9jsv6907")))) + "14qalqy5h51qdv88wxj7h7cibxkbwdvk3pn8sj8k19ynbfwn6rpm")))) (build-system python-build-system) ;; TODO Run tests with =E2=80=98PYTHONPATH=3D. trial3 tests=E2=80=99. (propagated-inputs --=20 2.31.1 From debbugs-submit-bounces@debbugs.gnu.org Wed May 26 10:37:45 2021 Received: (at 48655) by debbugs.gnu.org; 26 May 2021 14:37:45 +0000 Received: from localhost ([127.0.0.1]:49686 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1llufI-00007R-Sq for submit@debbugs.gnu.org; Wed, 26 May 2021 10:37:45 -0400 Received: from wp224.webpack.hosteurope.de ([80.237.132.231]:43608) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1llufG-00007F-0h for 48655@debbugs.gnu.org; Wed, 26 May 2021 10:37:43 -0400 Received: from www.rohleder.de ([37.61.204.227]); authenticated by wp224.webpack.hosteurope.de running ExIM with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) id 1llufD-0005fw-V4; Wed, 26 May 2021 16:37:39 +0200 Received: from [192.168.1.3] (helo=micha) by www.rohleder.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94) (envelope-from ) id 1llufA-0005gL-PJ; Wed, 26 May 2021 16:37:39 +0200 From: Michael Rohleder To: Solene Rapenne Subject: Re: [bug#48655] [PATCH] gnu: synapse: Update to 1.33.2. References: <20210525183656.4d41ae04@perso.pw> Date: Wed, 26 May 2021 16:37:33 +0200 In-Reply-To: <20210525183656.4d41ae04@perso.pw> (Solene Rapenne via Guix-patches via's message of "Tue, 25 May 2021 18:36:56 +0200") Message-ID: <87im351ryq.fsf@rohleder.de> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-bounce-key: webpack.hosteurope.de;mike@rohleder.de;1622039862;f964e1e6; X-HE-SMSGID: 1llufD-0005fw-V4 X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 48655 Cc: 48655@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Hi Solene, Thank you for the patch! Solene Rapenne via Guix-patches via writes: > This fixes the DoS [CVE-2021-29471] and many other improvements > > I didn't try it, I don't have a matrix server. synapse > 1.30 needs a newer python-cryptography (I think >=3D3.4) at runtime, so I think this version would not run on current guix. (My homeserver runs guix synapse, but from my channel...) Regards mike =2D-=20 Life begins where fear ends. - Osho --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQFFBAEBCAAvFiEEdV4t5dDVhcUueCgwfHr/vv7yyyUFAmCuXS4RHG1pa2VAcm9o bGVkZXIuZGUACgkQfHr/vv7yyyViRwf/SOcxlXvUFMDcsTUsJfJUzd9Scp/jw7D2 eggS76/xoDUhOZAoQycx9MPVgMuaE/BRCP1FvHbYeBm7XgKehYRi2VwvC3anDU1z AqmZcN57nONd6OCdgOdXnWh3i2r2HmyvkyJy2A2LJM9EbHBKLHasUBHBefETuFqy 1yQSvMgjdtOt5mY++S0Z9dMQ+9acggv8fZLFT0Knqw1yz61Fy+sVTEOEFMUWmU19 250P0VK4/uqNgGRUpr5eLwHAXqpRW3UbV9PP/8xoNaiyvP5KDE6TXRAAqSoVKlPy dJRWLB8Bhi8eDCwc86JyHEIFJlXVZy1wIosDwx1Rc4unSkSs+0nkTA== =9+OP -----END PGP SIGNATURE----- --=-=-=-- From debbugs-submit-bounces@debbugs.gnu.org Sat Jun 05 17:30:28 2021 Received: (at control) by debbugs.gnu.org; 5 Jun 2021 21:30:28 +0000 Received: from localhost ([127.0.0.1]:50222 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lpdsC-0005FM-EJ for submit@debbugs.gnu.org; Sat, 05 Jun 2021 17:30:28 -0400 Received: from eggs.gnu.org ([209.51.188.92]:41198) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1lpdsB-0005FA-7j for control@debbugs.gnu.org; Sat, 05 Jun 2021 17:30:27 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:59746) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lpds6-0002ub-1S for control@debbugs.gnu.org; Sat, 05 Jun 2021 17:30:22 -0400 Received: from [2a01:e0a:1d:7270:af76:b9b:ca24:c465] (port=54032 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1lpds5-0002Zf-PJ for control@debbugs.gnu.org; Sat, 05 Jun 2021 17:30:21 -0400 Date: Sat, 05 Jun 2021 23:30:20 +0200 Message-Id: <87v96sknir.fsf@gnu.org> To: control@debbugs.gnu.org From: =?utf-8?Q?Ludovic_Court=C3=A8s?= Subject: control message for bug #48655 MIME-version: 1.0 Content-type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -3.3 (---) tags 48655 + moreinfo quit