From unknown Tue Jun 17 22:16:15 2025 X-Loop: help-debbugs@gnu.org Subject: [bug#76189] [PATCH] gnu: librewolf: Update to 135.0-1 [security fixes]. Resent-From: Ian Eure Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Tue, 11 Feb 2025 01:57:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 76189 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 76189@debbugs.gnu.org Cc: Ian Eure X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.173923898632442 (code B ref -1); Tue, 11 Feb 2025 01:57:01 +0000 Received: (at submit) by debbugs.gnu.org; 11 Feb 2025 01:56:26 +0000 Received: from localhost ([127.0.0.1]:53160 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1thfVh-0008RB-RI for submit@debbugs.gnu.org; Mon, 10 Feb 2025 20:56:26 -0500 Received: from lists.gnu.org ([2001:470:142::17]:57604) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1thfVc-0008Qq-86 for submit@debbugs.gnu.org; Mon, 10 Feb 2025 20:56:22 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1thfVV-0002T9-8B for guix-patches@gnu.org; Mon, 10 Feb 2025 20:56:13 -0500 Received: from fhigh-a8-smtp.messagingengine.com ([103.168.172.159]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1thfVR-0005ZO-O8 for guix-patches@gnu.org; Mon, 10 Feb 2025 20:56:13 -0500 Received: from phl-compute-01.internal (phl-compute-01.phl.internal [10.202.2.41]) by mailfhigh.phl.internal (Postfix) with ESMTP id 8E987114022F; Mon, 10 Feb 2025 20:56:07 -0500 (EST) Received: from phl-mailfrontend-02 ([10.202.2.163]) by phl-compute-01.internal (MEProxy); Mon, 10 Feb 2025 20:56:07 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to; s=fm2; t=1739238967; x=1739325367; bh=jbA5fkJAl/tEhzrfaYCRb OGy+H6DpFnPVaiHIuQBkJg=; b=isLqLsJ1f+Md3dCSjPE8K+ZDwrQhM2hMu/Fdf QxFanazEgrLhz62wF7/PoWWycY/vNYjoDpPgQQQqTLClePKcms4ugnb1SJ9dv/e/ LnSyMKpvmVTX02F8gVqOWKQhtKBsDQPo/s6AKskDBlp03Ifsr+jdkIvS9B5BoSko HQ/2wn7Rl9CvO3Y4m1L5aKSFvkTMpJi1/VCkOEp66unmHRNjYQvlJc8TMKPyrGSa XfVrcMLLAkaUE97BuIwl7TeYaDJlNA3pGPjQ31HsCNrYE130CG7TJbwN5Ctlt4Bm TcGAEZ+9VqMIk/yTp+zkpjbz/YmDSW7aoLGoUh+9fx1wITziQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:message-id:mime-version:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t= 1739238967; x=1739325367; bh=jbA5fkJAl/tEhzrfaYCRbOGy+H6DpFnPVai HIuQBkJg=; b=yzPK2duj7X7hHfnANYvXlCbEf04QMbP2Rv1d+49V4I+fLPGLt8a eTAGdVtIm3dY+gQnX1AH1ojNl1tDKe8jnCqfFRonLE/H5sOOWRfNunH2ztDvbgBX 4nzD1Sm+zJofy3TowB8j1zhTUQVfPlXqtQfQJM+bbXq9QVLiHW0pkz81lISJOIs5 xiKc38rOylsYQEBIJN0XayH+vdvlFKgscNBfK0DwwQlh7prc6T6z5VVunlfhqIVh 0hJQYAmVEmMWQ16bUVXEzRso62KzbToIe3i505UJ+lDSyeQBe6G1aarkBeVoZkU8 LZWc/VZo2dXS6TwybMTzYivMtayVl45sWkQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefvddrtddtgdefleejvdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhephffvve fufffkofgggfestdekredtredttdenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhes rhgvthhrohhsphgvtgdrthhvqeenucggtffrrghtthgvrhhnpefgvdejhfelhfeftdeile elfedvhfefffetfeeuteelgfdvleffleevgfefueekjeenucffohhmrghinhepmhhoiihi lhhlrgdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh hrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvhdpnhgspghrtghpthhtohepvddpmhho uggvpehsmhhtphhouhhtpdhrtghpthhtohepghhuihigqdhprghttghhvghssehgnhhurd horhhgpdhrtghpthhtohepihgrnhesrhgvthhrohhsphgvtgdrthhv X-ME-Proxy: Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 10 Feb 2025 20:56:06 -0500 (EST) From: Ian Eure Date: Mon, 10 Feb 2025 17:55:34 -0800 Message-ID: <20250211015602.4658-1-ian@retrospec.tv> X-Mailer: git-send-email 2.48.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=103.168.172.159; envelope-from=ian@retrospec.tv; helo=fhigh-a8-smtp.messagingengine.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 0.7 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.3 (/) New upstream version. Contains fixes for: CVE-2025-1009: Use-after-free in XSLT CVE-2025-1010: Use-after-free in Custom Highlight CVE-2025-1018: Fullscreen notification is not displayed when fullscreen is re-requested CVE-2025-1011: A bug in WebAssembly code generation could result in a crash CVE-2025-1012: Use-after-free during concurrent delazification CVE-2025-1019: Fullscreen notification not properly displayed CVE-2025-1013: Potential opening of private browsing tabs in normal browsing windows CVE-2025-1014: Certificate length was not properly checked CVE-2025-1016: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7 CVE-2025-1017: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7 CVE-2025-1020: Memory safety bugs fixed in Firefox 135 and Thunderbird 135 * gnu/packages/librewolf.scm (librewolf): Update to 135.0-1. Change-Id: I7054fc9df31d59bb0d42e02b1f359cf3e6c1a43d --- gnu/packages/librewolf.scm | 11 ++++++----- 1 file changed, 6 insertions(+), 5 deletions(-) diff --git a/gnu/packages/librewolf.scm b/gnu/packages/librewolf.scm index 59c7e3a4a3..e5e91fb91e 100644 --- a/gnu/packages/librewolf.scm +++ b/gnu/packages/librewolf.scm @@ -200,22 +200,23 @@ (define* (make-librewolf-source #:key version firefox-hash librewolf-hash l10n) ;;; but since in Guix only the latest packaged Rust is officially supported, ;;; it is a tradeoff worth making. ;;; 0: https://firefox-source-docs.mozilla.org/writing-rust-code/update-policy.html -(define rust-librewolf rust-1.81) +;; 135.0 wants 1.83, but it's not available in Guix yet. +(define rust-librewolf rust-1.82) ;; Update this id with every update to its release date. ;; It's used for cache validation and therefore can lead to strange bugs. ;; ex: date '+%Y%m%d%H%M%S' -(define %librewolf-build-id "20250121184331") +(define %librewolf-build-id "20250209210057") (define-public librewolf (package (name "librewolf") - (version "134.0.2-1") + (version "135.0-1") (source (make-librewolf-source #:version version - #:firefox-hash "09yxacfcklgjqbqvcac32llwmlb16d9jhfp2mif9qs7s2gzvfvkc" - #:librewolf-hash "1qa3crgazfvmsqx8dm0k78yk9cb11w1lf74x6x8ixjq5ifsdh1ws" + #:firefox-hash "0q5r2q6q56kyzl5pknrir9bzlhmzbvv9hi5gi4852izgcali4zl2" + #:librewolf-hash "0fg4vji5xb17pgvq7jnfz4dq08gi0rl998xhj37hfm5zxs19y8jk" #:l10n firefox-l10n)) (build-system gnu-build-system) (arguments -- 2.48.1 From debbugs-submit-bounces@debbugs.gnu.org Fri Feb 14 19:05:02 2025 Received: (at control) by debbugs.gnu.org; 15 Feb 2025 00:05:03 +0000 Received: from localhost ([127.0.0.1]:52357 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1tj5g6-00039f-A9 for submit@debbugs.gnu.org; Fri, 14 Feb 2025 19:05:02 -0500 Received: from fhigh-b2-smtp.messagingengine.com ([202.12.124.153]:34455) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1tj5g3-00038y-DW for control@debbugs.gnu.org; Fri, 14 Feb 2025 19:04:59 -0500 Received: from phl-compute-04.internal (phl-compute-04.phl.internal [10.202.2.44]) by mailfhigh.stl.internal (Postfix) with ESMTP id 0140A2540118 for ; Fri, 14 Feb 2025 19:04:53 -0500 (EST) Received: from phl-mailfrontend-01 ([10.202.2.162]) by phl-compute-04.internal (MEProxy); Fri, 14 Feb 2025 19:04:54 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:content-type:date:date:from:from:in-reply-to:message-id :reply-to:subject:subject:to:to; s=fm2; t=1739577893; x= 1739664293; bh=m9CGYBQarnyZ4ZvzqkanDbltx3BkHiWf/pX8/RLQ2QE=; b=d ouE2V9v/omX3yR4H/EIPq9/VFWSgkG3fG+4iaHblihxriScrDIEVXX/lB7NTQ+bs eGzCab67XzDM3dHtCIRlgrdk/BImPem2YuNQfkLEpprSvwQ1TxQ0/EhzTvOdEW8t p2OMCNy0D0TpYi0eY2cdwGG5E2gvgxoFF2C0xG2XkSnOTX5qONTTScqttJElqVvV 2VUjd34CEPOh3VbGftNXTZEPaDCzZlg2x7oqR7KfXP2krRgC6IexYLTupEVYEqAK bD33GZ+hm8dYNHfPDFR15d1rp/OIKXuMy4CxkPJhaBUDELUHJPvu9b/OMG3JhQtj UUYavIe9LaR0Zxcc1149w== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:date:feedback-id :feedback-id:from:from:in-reply-to:message-id:reply-to:subject :subject:to:to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm3; t=1739577893; x=1739664293; bh=m9CGYBQarnyZ4ZvzqkanDbltx3Bk HiWf/pX8/RLQ2QE=; b=lAx2o/QlFdJieIemz1L6mKPT8kteft/E7Cm3tIUuBvBA 7gciTJgFaCbnOaxDEhv7akAiGErPRHfaFxqyRI8D3EEO454w/Nc6NceA4VojDx8C hc81aYIJ3zrjnx0HDPS9S14VzmA7dRzAippoEDJnnEPmkOT0geiKAUbNP2+AZBZ2 wyrv90hl5DxETQHnpKvzSshH0TxolX/L/ziKoaW7CLTGBZl4VDk54mf6vG1NNBx6 p9xo00/I/nD896ki875lkD3EVuCmN6Xqd6Rn3+Ihrp9/bvOyOygSeXTIi+yrbpsb VHoQ2td3jlTdZWNlc6CpOHKjp03ulNCM30ONWC946g== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefvddrtddtgdehuddthecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhepfffkvf fhufestddtredttddttdenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhesrhgvthhr ohhsphgvtgdrthhvqeenucggtffrrghtthgvrhhnpeetkeejhfefhfetieegkeehheevvd efgffggeevffdtvddufeehiefgteeiueehkeenucevlhhushhtvghrufhiiigvpedtnecu rfgrrhgrmhepmhgrihhlfhhrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvhdpnhgspg hrtghpthhtohepuddpmhhouggvpehsmhhtphhouhhtpdhrtghpthhtoheptghonhhtrhho lhesuggvsggsuhhgshdrghhnuhdrohhrgh X-ME-Proxy: Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA for ; Fri, 14 Feb 2025 19:04:53 -0500 (EST) Date: Fri, 14 Feb 2025 16:04:52 -0800 Message-Id: <87ldu8oyxn.fsf@retrospec.tv> To: control@debbugs.gnu.org From: Ian Eure Subject: control message for bug #76189 X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) close 76189 quit