From debbugs-submit-bounces@debbugs.gnu.org Mon Oct 07 18:06:12 2024 Received: (at submit) by debbugs.gnu.org; 7 Oct 2024 22:06:12 +0000 Received: from localhost ([127.0.0.1]:49183 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sxvrn-00080b-Js for submit@debbugs.gnu.org; Mon, 07 Oct 2024 18:06:12 -0400 Received: from lists.gnu.org ([209.51.188.17]:58302) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1sxvrl-00080T-RU for submit@debbugs.gnu.org; Mon, 07 Oct 2024 18:06:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sxvrc-0000uU-Cv for guix-patches@gnu.org; Mon, 07 Oct 2024 18:06:00 -0400 Received: from 2.mo581.mail-out.ovh.net ([87.98.143.68]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1sxvrZ-0007PH-L0 for guix-patches@gnu.org; Mon, 07 Oct 2024 18:06:00 -0400 Received: from director7.ghost.mail-out.ovh.net (unknown [10.108.9.148]) by mo581.mail-out.ovh.net (Postfix) with ESMTP id 4XMtWj6gQPz1KXT for ; Mon, 7 Oct 2024 22:05:53 +0000 (UTC) Received: from ghost-submission-55b549bf7b-947gt (unknown [10.111.182.119]) by director7.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 960DF1FE4D; Mon, 7 Oct 2024 22:05:53 +0000 (UTC) Received: from ngraves.fr ([37.59.142.99]) by ghost-submission-55b549bf7b-947gt with ESMTPSA id 1FgXOkBbBGekiBUAlyRhlg (envelope-from ); Mon, 07 Oct 2024 22:05:53 +0000 Authentication-Results: garm.ovh; auth=pass (GARM-99G00366acfea8-0576-4cca-8423-62f0a9cb31df, 83E631236A2B63DF756DDFD3729F0B2EAC058DF1) smtp.auth=ngraves@ngraves.fr X-OVh-ClientIp: 86.246.19.221 From: Nicolas Graves To: guix-patches@gnu.org Subject: [PATCH] gnu: vips: Update to 8.15.3. [security fixes] Date: Tue, 8 Oct 2024 00:05:45 +0200 Message-ID: <20241007220550.6809-1-ngraves@ngraves.fr> X-Mailer: git-send-email 2.46.0 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 6575536933630042850 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeftddrvdeftddgtdeiucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfdpvefjgfevmfevgfenuceurghilhhouhhtmecuhedttdenucenucfjughrpefhvfevufffkffogggtgfesthekredtredtjeenucfhrhhomheppfhitgholhgrshcuifhrrghvvghsuceonhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrqeenucggtffrrghtthgvrhhnpeelueehgfevfeevhffftdetgedugeevveehteeileeuueejhfegffetteffhffhvdenucffohhmrghinhepghhithhhuhgsrdgtohhmnecukfhppeduvdejrddtrddtrddupdekiedrvdegiedrudelrddvvddupdefjedrheelrddugedvrdelleenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepihhnvghtpeduvdejrddtrddtrddupdhmrghilhhfrhhomhepnhhgrhgrvhgvshesnhhgrhgrvhgvshdrfhhrpdhnsggprhgtphhtthhopedupdhrtghpthhtohepghhuihigqdhprghttghhvghssehgnhhurdhorhhgpdfovfetjfhoshhtpehmohehkedupdhmohguvgepshhmthhpohhuth DKIM-Signature: a=rsa-sha256; bh=NWxBp89T29JaJ6COmjXvpAxTtZH+dvlsbYuqceNY52A=; c=relaxed/relaxed; d=ngraves.fr; h=From; s=ovhmo4487190-selector1; t=1728338754; v=1; b=EFjQuqEU2cCoBPq6b8bPzAp/LZPbMfvAgs3F0X5wxUcTTtTyLMskpkqwLpcaSE6UJqfyBgKD zZkqpzDZQ19tl/Mc4gsRWRO8jSGR6b7mjaJ3HGelcD5Pc6cXbUJ+0KnmD9+VKe+4EfT7d3cSxMJ UZnFjK4O/xjXb8eAupqFBXxVZ8CAHZg1Ohw+AtrdWSYOHAbOmutcWv7NVxkr/rk5Wn8/B38Y5ya ng867vP9IS30yRkaiw+QOKk0eunPRjQlc1gT8r5n6MqoQAYfx0hvSgiCL6L+a1eZr0OIaoGA/az 9Tv3yVh9xtYXMlZX4G2hxqvaqoI67HGa4Ipw1MPsW4MmA== Received-SPF: pass client-ip=87.98.143.68; envelope-from=ngraves@ngraves.fr; helo=2.mo581.mail-out.ovh.net X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.3 (-) X-Debbugs-Envelope-To: submit Cc: Nicolas Graves X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.3 (--) This fixes CVE-2023-40032. * gnu/packages/image-processing.scm (vips): Update to 8.15.3. [build-system]: Switch to meson-build-system. [inputs]: Add glib:bin. --- gnu/packages/image-processing.scm | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/gnu/packages/image-processing.scm b/gnu/packages/image-processing.scm index 033e006d06..1a24837ac8 100644 --- a/gnu/packages/image-processing.scm +++ b/gnu/packages/image-processing.scm @@ -23,6 +23,7 @@ ;;; Copyright © 2022 Tomasz Jeneralczyk ;;; Copyright © 2022 Paul A. Patience ;;; Copyright © 2023 Cairn +;;; Copyright © 2024 Nicolas Graves ;;; ;;; This file is part of GNU Guix. ;;; @@ -49,6 +50,7 @@ (define-module (gnu packages image-processing) #:use-module (guix build-system qt) #:use-module (guix build-system cmake) #:use-module (guix build-system gnu) + #:use-module (guix build-system meson) #:use-module (guix build-system python) #:use-module (guix build-system pyproject) #:use-module (gnu packages) @@ -776,16 +778,16 @@ (define-public opencv (define-public vips (package (name "vips") - (version "8.13.1") + (version "8.15.3") (source (origin (method url-fetch) (uri (string-append "https://github.com/libvips/libvips/releases/download/v" - version "/vips-" version ".tar.gz")) + version "/vips-" version ".tar.xz")) (sha256 - (base32 "00kp3439jcqv9l2gcjg88xzvlq8clv54z1m3x66i3chvarz7ndxd")))) - (build-system gnu-build-system) + (base32 "182j20dw38f1nyfx8cf7cjsr0k4nl7lfk3wm2d0ddypa6vsxj9ry")))) + (build-system meson-build-system) (native-inputs (list gobject-introspection pkg-config)) (inputs @@ -793,6 +795,7 @@ (define-public vips fftw giflib glib + (list glib "bin") hdf5 imagemagick lcms -- 2.46.0 From debbugs-submit-bounces@debbugs.gnu.org Sun Oct 13 22:21:09 2024 Received: (at 73683-done) by debbugs.gnu.org; 14 Oct 2024 02:21:09 +0000 Received: from localhost ([127.0.0.1]:33732 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t0Aho-0008Ba-M5 for submit@debbugs.gnu.org; Sun, 13 Oct 2024 22:21:09 -0400 Received: from smtp84.cstnet.cn ([159.226.251.84]:42100 helo=cstnet.cn) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1t0Ahl-0008AN-Ga for 73683-done@debbugs.gnu.org; Sun, 13 Oct 2024 22:21:07 -0400 Received: from m (unknown [107.174.64.25]) by APP-05 (Coremail) with SMTP id zQCowABHLWTvfwxnyAdBBw--.47938S2; Mon, 14 Oct 2024 10:20:38 +0800 (CST) From: Zheng Junjie To: Nicolas Graves via Guix-patches via Subject: Re: [bug#73683] [PATCH] gnu: vips: Update to 8.15.3. [security fixes] In-Reply-To: <20241007220550.6809-1-ngraves@ngraves.fr> (Nicolas Graves via Guix-patches via's message of "Tue, 8 Oct 2024 00:05:45 +0200") References: <20241007220550.6809-1-ngraves@ngraves.fr> Date: Mon, 14 Oct 2024 10:20:29 +0800 Message-ID: <87y12r5ssy.fsf@iscas.ac.cn> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-CM-TRANSID: zQCowABHLWTvfwxnyAdBBw--.47938S2 X-Coremail-Antispam: 1UD129KBjvJXoW7WFyUJr17Xw15CFy3KFyxuFg_yoW8urWfpa 4xAF1S9r18Gw4kXan2gFs2kr1ag39rtrW8u343Aw4xJw4avrZFkFW3tay3JF17A34fCw47 WryIq3WUWryUJrDanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUvGb7Iv0xC_Kw4lb4IE77IF4wAFF20E14v26r1j6r4UM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28lY4IEw2IIxxk0rw A2F7IY1VAKz4vEj48ve4kI8wA2z4x0Y4vE2Ix0cI8IcVAFwI0_Xr0_Ar1l84ACjcxK6xII jxv20xvEc7CjxVAFwI0_Gr0_Cr1l84ACjcxK6I8E87Iv67AKxVW8Jr0_Cr1UM28EF7xvwV C2z280aVCY1x0267AKxVWxJr0_GcWlnx0Ee4C267I2x7xF54xIwI0E7I0Y6sxI4wAS0I0E 0xvYzxvE52x082IY62kv0487M2AExVA0xI801c8C04v7Mc02F40EFcxC0VAKzVAqx4xG6I 80ewAv7VC0I7IYx2IY67AKxVWUGVWUXwAv7VC2z280aVAFwI0_Jr0_Gr1lOx8S6xCaFVCj c4AY6r1j6r4UM4x0Y48IcVAKI48JMxAIw28IcxkI7VAKI48JMxC20s026xCaFVCjc4AY6r 1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWlx4CE17CE b7AF67AKxVWUXVWUAwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1j6r1xMIIF0x vE2Ix0cI8IcVCY1x0267AKxVWUJVW8JwCI42IY6xAIw20EY4v20xvaj40_Jr0_JF4lIxAI cVC2z280aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVWUJVW8JbIYCTnIWIevJa 73UjIFyTuYvjxUh8u4DUUUU X-Originating-IP: [107.174.64.25] X-CM-SenderInfo: x2kh0wxmxqyx3h6l2u1dvotugofq/ X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 73683-done Cc: 73683-done@debbugs.gnu.org, Nicolas Graves X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Nicolas Graves via Guix-patches via writes: > This fixes CVE-2023-40032. > > * gnu/packages/image-processing.scm (vips): Update to 8.15.3. > [build-system]: Switch to meson-build-system. > [inputs]: Add glib:bin. > --- > gnu/packages/image-processing.scm | 11 +++++++---- > 1 file changed, 7 insertions(+), 4 deletions(-) > > diff --git a/gnu/packages/image-processing.scm b/gnu/packages/image-proce= ssing.scm > index 033e006d06..1a24837ac8 100644 > --- a/gnu/packages/image-processing.scm > +++ b/gnu/packages/image-processing.scm > @@ -23,6 +23,7 @@ > ;;; Copyright =C2=A9 2022 Tomasz Jeneralczyk > ;;; Copyright =C2=A9 2022 Paul A. Patience > ;;; Copyright =C2=A9 2023 Cairn > +;;; Copyright =C2=A9 2024 Nicolas Graves > ;;; > ;;; This file is part of GNU Guix. > ;;; > @@ -49,6 +50,7 @@ (define-module (gnu packages image-processing) > #:use-module (guix build-system qt) > #:use-module (guix build-system cmake) > #:use-module (guix build-system gnu) > + #:use-module (guix build-system meson) > #:use-module (guix build-system python) > #:use-module (guix build-system pyproject) > #:use-module (gnu packages) > @@ -776,16 +778,16 @@ (define-public opencv > (define-public vips > (package > (name "vips") > - (version "8.13.1") > + (version "8.15.3") > (source > (origin > (method url-fetch) > (uri (string-append > "https://github.com/libvips/libvips/releases/download/v" > - version "/vips-" version ".tar.gz")) > + version "/vips-" version ".tar.xz")) > (sha256 > - (base32 "00kp3439jcqv9l2gcjg88xzvlq8clv54z1m3x66i3chvarz7ndxd"))= )) > - (build-system gnu-build-system) > + (base32 "182j20dw38f1nyfx8cf7cjsr0k4nl7lfk3wm2d0ddypa6vsxj9ry"))= )) > + (build-system meson-build-system) > (native-inputs > (list gobject-introspection pkg-config)) > (inputs > @@ -793,6 +795,7 @@ (define-public vips > fftw > giflib > glib > + (list glib "bin") > hdf5 > imagemagick > lcms push, and add commit to fetch sources from git. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfr6klGDOXiwIdX/bO1qpk+Gi3/AFAmcMf+0ACgkQO1qpk+Gi 3/AeEA/9FVhJJhYScI6DG3M4yEICnwMfcu5bqhXoK067LxZBm/UXx68Gob9fpzJG aJvjrdjlAQ6NHrCG/bChac+sh9K1cDGLgu1luAPh4CslmWDf445BDIBeZmJEavL8 eUMEdZylCbAuBNyypRKUBjwgklLcuLoNghNRf83WiGcHAbzwYfPzcBYM6oCPLiZ0 TBQPAKGFhVJmtocsPh1TQEt1pYHZ9n7q6SCcBElUjpsxfwj4UasCnU+bLE5MzZC1 i9GfWrg03FgcjF+XDsrBiCx8sGy/LDB3ke9WS3S4/jt0Sd9K8b2GrvBSxcEZDWXj AA9m7wSilZcI/lbIZ871K6fD530/P4z7Wwp4IMpvsSLlmiGGUWdA0XKCmUcvwXrz xyPBJpsc9hGHF8lx/mnrsSyiwkMgG3zrTr8YajBZzX1Z/E1jThNqQ7hYEN4uPai2 +NYEACrI7x8hGzmA2sh1we4EGLZCZQoXzSQwj3HHp1RLlHqH4I8Hcz0wvmpmq64O 5ggsF64JMegqsjgRV+f+ADe0eQ0jvWwp25VMWz1s/13Uc7IFHhQdohVRjlHHN3Dk YIeWD/pBF01QxQFWEaL7XVexJVwlrQDGiCt8WwzUHwNu2zvepapUB/WBDxep4NN+ lqJVCUelScHDxfFqfZ+3AKsAE2qOTiB49kqyH9DK0dRq/y5v60Y= =SJMR -----END PGP SIGNATURE----- --=-=-=-- From unknown Thu Aug 14 17:29:20 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Mon, 11 Nov 2024 12:24:13 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator