From debbugs-submit-bounces@debbugs.gnu.org Tue May 06 18:35:47 2025 Received: (at submit) by debbugs.gnu.org; 6 May 2025 22:35:47 +0000 Received: from localhost ([127.0.0.1]:35067 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1uCQt9-0002TY-DQ for submit@debbugs.gnu.org; Tue, 06 May 2025 18:35:47 -0400 Received: from lists.gnu.org ([2001:470:142::17]:45722) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1uCQt6-0002O7-GT for submit@debbugs.gnu.org; Tue, 06 May 2025 18:35:45 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uCQsU-0001pM-EE for guix-patches@gnu.org; Tue, 06 May 2025 18:35:06 -0400 Received: from cascadia.aikidev.net ([2600:3c01:e000:267:0:a171:de7:c]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uCQsS-00048w-8T for guix-patches@gnu.org; Tue, 06 May 2025 18:35:06 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=debian.org; s=1.vagrant.user; t=1746570900; bh=47mAUlYnrsFfQEyEfBW5YhNczZv9IXvTW6qeFVenN4Q=; h=From:To:Cc:Subject:Date:From; b=C9Hp4IfV+3GdIPKxWHS3cWmRiIDmIp42F4hS4+qIoHXuofOuwhaE4BnUH+SwilHRk kPtRSdkL+VpGXugweqgzEj0DQna9Oskc/q2PE9hJMLUf4vvy6m6Ko7Qp82nw9GLt5+ 9qbkvRXamz0EBKJzQCvgugk1BSNHSoCMpF4jaY9ax7X0Hn+I1zQfJ4PIcf3iNiZCxV +FVei04OTCmK7HgSZXbpRt8tiDoB0EDX+2Rg2+qmFeGl3XTbA68NT/y5rdTWuKGzZZ DPz117OaTOxXmBDcIFaYIAzffCgzbJUR3GjEiXt73SMAdoDASW3rTG0nNvvlCkIAyS iJPw5XvDXSgQg== Received: from localhost (unknown [IPv6:2600:3c01:e000:21:7:77:0:50]) by cascadia.aikidev.net (Postfix) with ESMTPSA id 022D174D4; Tue, 6 May 2025 15:34:59 -0700 (PDT) From: Vagrant Cascadian To: guix-patches@gnu.org Subject: Update arm-trusted-firmware to 2.12.2 Date: Tue, 06 May 2025 15:34:55 -0700 Message-ID: <875xidqsfk.fsf@wireframe> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="==-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Received-SPF: none client-ip=2600:3c01:e000:267:0:a171:de7:c; envelope-from=vagrant@debian.org; helo=cascadia.aikidev.net X-Spam_score_int: -34 X-Spam_score: -3.5 X-Spam_bar: --- X-Spam_report: (-3.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.414, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: submit Cc: gabriel@erlikon.ch, efraim@flashner.co.il X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --==-=-= Content-Type: multipart/mixed; boundary="=-=-=" --=-=-= Content-Type: text/plain The attached patch updates arm-trusted-firmware packages to 2.12.2. I believe this fixes a few minor CVE, although it is not immediately obvious from upstream commit logs... All dependents build on both x86_64-linux and aarch64-linux: guix build: computing dependents of package arm-trusted-firmware-imx8mq@2.12.2... /gnu/store/gg1gmqb89kjaqbq8f9ndzs3ll7niq56d-arm-trusted-firmware-imx8mq-2.12.2 guix build: computing dependents of package arm-trusted-firmware-rk3328@2.12.2... /gnu/store/wcqyaw6cqzlk8asv3vh4alsrd9a291m7-arm-trusted-firmware-rk3328-2.12.2 /gnu/store/zxs49a0msm4vff5szc7757k1s0lpszla-u-boot-orangepi-r1-plus-lts-rk3328-2025.01 /gnu/store/vap8w54l9kvi4179cy5w0kl2a5f9ixr9-u-boot-rock64-rk3328-2025.01 guix build: computing dependents of package arm-trusted-firmware-rk3399@2.12.2... /gnu/store/0z2c2dikv1d5avr6f0jga5gsq5pl2x69-arm-trusted-firmware-rk3399-2.12.2 /gnu/store/y0yzl9wccwmhhipblkrv370kafb7d30v-u-boot-rockpro64-rk3399-2025.01 /gnu/store/mw39784wjpbnxhc5arlwcqk93ml1m7pr-u-boot-firefly-rk3399-2025.01 /gnu/store/85rgpgic0vqziczgb92csavl0vxrwm0k-u-boot-puma-rk3399-2025.01 /gnu/store/mbijwvldbwzkscb79v1qqnhnlc93sqgf-u-boot-pinebook-pro-rk3399-2025.01 guix build: computing dependents of package arm-trusted-firmware-rk3588@2.12.2... /gnu/store/dx9b2ymbj3f7h77mf7b86jagiwkxrdlg-arm-trusted-firmware-rk3588-2.12.2 guix build: computing dependents of package arm-trusted-firmware-sun50i-a64@2.12.2... /gnu/store/10sx5h064fbjnhc2c6vvkqrp43sj23f0-arm-trusted-firmware-sun50i-a64-2.12.2 /gnu/store/m35rj7p3fjhkkbanj3i9xlw808byl8gp-u-boot-pine64-lts-2025.01 /gnu/store/090mm7g00cl6ws435lf97j7cfdbnnfki-u-boot-pinebook-2025.01 /gnu/store/8f7hn13g71a8cj6pqlj4qjrz5qcbam2s-u-boot-pine64-plus-2025.01 guix build: computing dependents of package arm-trusted-firmware-sun50i-h616@2.12.2... /gnu/store/jljnh49swdkax8fpl2xqpaag065vggai-arm-trusted-firmware-sun50i-h616-2.12.2 /gnu/store/kvh138wv7ri6fni3mcan7xdbw7i3p3j2-u-boot-orangepi-zero2w-2025.01 I also boot-tested a mnt/reform2 (which admittedly uses a custom u-boot). live well, vagrant --=-=-= Content-Type: text/x-diff Content-Disposition: inline; filename=0001-gnu-arm-trusted-firmware-Update-to-2.12.2.patch Content-Transfer-Encoding: quoted-printable From=20cea71c67bb2fc44c6109f2d15edfd2a14a127f30 Mon Sep 17 00:00:00 2001 From: Vagrant Cascadian Date: Tue, 6 May 2025 18:05:00 +0000 Subject: [PATCH] gnu: arm-trusted-firmware: Update to 2.12.2. * gnu/packages/firmware.scm (make-arm-trusted-firmware): Update to 2.12.2. Change-Id: Ib8077e63bd3df0fe6dce634d5b7278b9389c42db =2D-- gnu/packages/firmware.scm | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/gnu/packages/firmware.scm b/gnu/packages/firmware.scm index 9548bc2ff7..ef4978df57 100644 =2D-- a/gnu/packages/firmware.scm +++ b/gnu/packages/firmware.scm @@ -1144,7 +1144,7 @@ (define (native-build?) (string=3D? (%current-system) (gnu-triplet->nix-system triplet)))) (package (name (downstream-package-name "arm-trusted-firmware-" platform)) =2D (version "2.12.1") + (version "2.12.2") (source (origin (method git-fetch) @@ -1154,7 +1154,7 @@ (define (native-build?) (commit (string-append "lts-v" version)))) (file-name (git-file-name "arm-trusted-firmware" version)) (sha256 =2D (base32 "1vngwbjghgsh5i02zq66nmbxxr2d4p93rirsvh5jrhbcdn0v5xf8")) + (base32 "01i40asy9dsbx4l5kbvsvi55bdf308nnraf8kfli5d4cx8pxqmrj")) (patches (search-patches "8mq-enable-imx_hab_handler.patch" "8mq-move-stack-to-ocram_s.patch")) (modules '((guix build utils))) base-commit: fbf8b81971475ee712338f1c955be6ac44099fac =2D-=20 2.39.5 --=-=-=-- --==-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQRlgHNhO/zFx+LkXUXcUY/If5cWqgUCaBqOjwAKCRDcUY/If5cW qtUsAP0YXuc50R0EEbqTtkN+kzgvehmR8S5h/9ZheTw+rCN3SAD/ekTgyR5h6ytH 67DSm+aCOmWyMOOg9kusu1SP5vI9zg4= =aJo7 -----END PGP SIGNATURE----- --==-=-=-- From debbugs-submit-bounces@debbugs.gnu.org Wed May 07 01:42:37 2025 Received: (at submit) by debbugs.gnu.org; 7 May 2025 05:42:37 +0000 Received: from localhost ([127.0.0.1]:38757 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1uCXYD-0003wS-GB for submit@debbugs.gnu.org; Wed, 07 May 2025 01:42:37 -0400 Received: from lists.gnu.org ([2001:470:142::17]:60854) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1uCXYA-0003vg-DA for submit@debbugs.gnu.org; Wed, 07 May 2025 01:42:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uCXXw-0000fG-Cw for guix-patches@gnu.org; Wed, 07 May 2025 01:42:21 -0400 Received: from mail-wm1-x331.google.com ([2a00:1450:4864:20::331]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1uCXXu-000470-Bz for guix-patches@gnu.org; Wed, 07 May 2025 01:42:20 -0400 Received: by mail-wm1-x331.google.com with SMTP id 5b1f17b1804b1-43cf05f0c3eso39951855e9.0 for ; Tue, 06 May 2025 22:42:17 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1746596536; x=1747201336; darn=gnu.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:sender:from:to:cc:subject:date:message-id :reply-to; bh=doFTkd7lWyxL+DHwvpajoMioOHNiStTyHz4tmHmRjbs=; b=nBK7ZVXXwEDm20cAL7zWjYmBz0NKpKK2Yx24HHOJp6PVf78+VEShTptJpPoE5cFsVk qJtRevHNfFxuTQjW8YDwGgRjKRiK6luHMiylSv4w/wDPLY1QZtg6sRAFd7CrasVnJYG+ wFEm9FC020uTL3BBaVxgYa9o3NVDH6m07gUvzVhS4g8J7GIWIYYLGT3qCspOiz2Fm6fm 3gPsFOIosuC7V0Nv2fLJaTqWN/Mm8ByykehEuFPtGG58V5SJxxKl6VasYZJkqlqete/Y n8/K1K7SFnI/XCur/BFEPE6nHzqxI77T5U32rq2q+bEgiGYD06e/YFOo7T7I1R/F/soS aRTQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1746596536; x=1747201336; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:sender:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=doFTkd7lWyxL+DHwvpajoMioOHNiStTyHz4tmHmRjbs=; b=Suab/9hxmMDQ5pAbgkSfuNyzMFsiq/RetcMGwOPmX1RNZkk192I4z1yZfCpltWoIXU IbPbM4eTaplQEeutOq3f3w05Eno5Y6vWd2YWitH9UD40L9ZBLnuRjTfN/mdybGMoDE57 CReaedvZlF2rq1VypW3b4ufyU3hln1rL4MxWjYYP1PssFsDke7nKJFHCOTqTT76KVMFc mBac+SDadWWAqpgEznMH2pgYwXWL2kbGuE52o2kni+qioUY72XcHROZdVXV9Pao+hO/2 E7Jja7SrNaF3QVOoWigLYo2zDCoeFxsOlKqdyzZ3Y6e7cf6BiLBND3bW2+BHL/zPC/6K wgQA== X-Gm-Message-State: AOJu0YzU60GKfNzJ5LQDcOtRnR1+g0eyna459DXaYU2ln22SRlVpUHKg D3ON+RNBTwHKjcdMCKiteFyXWi0hxcrshg4GGvIr/qwpxP57VWOy6IJakE0D X-Gm-Gg: ASbGncssAqurlQyHo3c8uDHopbDdm1EQhfO4eKnmTkd52HwIRSw0YkCUH2TgBRmqfA3 xgeTs5DBq7fDvVxq2TEa8BK6Og12NQ/BCZdkGS5dJiQkYdmwE5ay1gsTWUJFRfYVA1pHL9qTFAj 8s9wI5QNIf431PTwTrRIvNmvd74fviM/OghYPqwsLc5K76BFeTzvaavuRpsJ2lzUmHsty5VVNCF ExZMB/tnp46HeCxxA0xtDSwMkfgdShg/ozptPX7pWISrxly80Cr0CSGx7DiheFI7VR70xGY2pwB XS2pEJkzInG6sM61hVUgeWqYdywc4FY2WHlBcFLQhQ== X-Google-Smtp-Source: AGHT+IGeCeHCzAW0fgxE5UIry4IcWFxqxlp6rffm/vEpOxQIAu1hsCOqepBY6mBY97ZDGnUTGXPB/Q== X-Received: by 2002:a05:600c:3d17:b0:43d:2313:7b4a with SMTP id 5b1f17b1804b1-441d44bc533mr14299515e9.3.1746596535812; Tue, 06 May 2025 22:42:15 -0700 (PDT) Received: from localhost ([188.120.128.159]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-441d15dd9c6sm31300315e9.1.2025.05.06.22.42.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 06 May 2025 22:42:15 -0700 (PDT) Date: Wed, 7 May 2025 08:42:13 +0300 From: Efraim Flashner To: Vagrant Cascadian Subject: Re: Update arm-trusted-firmware to 2.12.2 Message-ID: References: <875xidqsfk.fsf@wireframe> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="YoCsYI8zms8870dr" Content-Disposition: inline In-Reply-To: <875xidqsfk.fsf@wireframe> X-PGP-Key-ID: 0x41AAE7DCCA3D8351 X-PGP-Key: https://flashner.co.il/~efraim/efraim_flashner.asc X-PGP-Fingerprint: A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 Received-SPF: pass client-ip=2a00:1450:4864:20::331; envelope-from=efraim.flashner@gmail.com; helo=mail-wm1-x331.google.com X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 1.0 (+) X-Debbugs-Envelope-To: submit Cc: gabriel@erlikon.ch, guix-patches@gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.0 (/) --YoCsYI8zms8870dr Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, May 06, 2025 at 03:34:55PM -0700, Vagrant Cascadian wrote: > The attached patch updates arm-trusted-firmware packages to 2.12.2. >=20 > I believe this fixes a few minor CVE, although it is not immediately > obvious from upstream commit logs... >=20 > All dependents build on both x86_64-linux and aarch64-linux: >=20 > guix build: computing dependents of package arm-trusted-firmware-imx8mq@2= =2E12.2... > /gnu/store/gg1gmqb89kjaqbq8f9ndzs3ll7niq56d-arm-trusted-firmware-imx8mq-2= =2E12.2 > guix build: computing dependents of package arm-trusted-firmware-rk3328@2= =2E12.2... > /gnu/store/wcqyaw6cqzlk8asv3vh4alsrd9a291m7-arm-trusted-firmware-rk3328-2= =2E12.2 > /gnu/store/zxs49a0msm4vff5szc7757k1s0lpszla-u-boot-orangepi-r1-plus-lts-r= k3328-2025.01 > /gnu/store/vap8w54l9kvi4179cy5w0kl2a5f9ixr9-u-boot-rock64-rk3328-2025.01 > guix build: computing dependents of package arm-trusted-firmware-rk3399@2= =2E12.2... > /gnu/store/0z2c2dikv1d5avr6f0jga5gsq5pl2x69-arm-trusted-firmware-rk3399-2= =2E12.2 > /gnu/store/y0yzl9wccwmhhipblkrv370kafb7d30v-u-boot-rockpro64-rk3399-2025.= 01 > /gnu/store/mw39784wjpbnxhc5arlwcqk93ml1m7pr-u-boot-firefly-rk3399-2025.01 > /gnu/store/85rgpgic0vqziczgb92csavl0vxrwm0k-u-boot-puma-rk3399-2025.01 > /gnu/store/mbijwvldbwzkscb79v1qqnhnlc93sqgf-u-boot-pinebook-pro-rk3399-20= 25.01 > guix build: computing dependents of package arm-trusted-firmware-rk3588@2= =2E12.2... > /gnu/store/dx9b2ymbj3f7h77mf7b86jagiwkxrdlg-arm-trusted-firmware-rk3588-2= =2E12.2 > guix build: computing dependents of package arm-trusted-firmware-sun50i-a= 64@2.12.2... > /gnu/store/10sx5h064fbjnhc2c6vvkqrp43sj23f0-arm-trusted-firmware-sun50i-a= 64-2.12.2 > /gnu/store/m35rj7p3fjhkkbanj3i9xlw808byl8gp-u-boot-pine64-lts-2025.01 > /gnu/store/090mm7g00cl6ws435lf97j7cfdbnnfki-u-boot-pinebook-2025.01 > /gnu/store/8f7hn13g71a8cj6pqlj4qjrz5qcbam2s-u-boot-pine64-plus-2025.01 > guix build: computing dependents of package arm-trusted-firmware-sun50i-h= 616@2.12.2... > /gnu/store/jljnh49swdkax8fpl2xqpaag065vggai-arm-trusted-firmware-sun50i-h= 616-2.12.2 > /gnu/store/kvh138wv7ri6fni3mcan7xdbw7i3p3j2-u-boot-orangepi-zero2w-2025.01 >=20 > I also boot-tested a mnt/reform2 (which admittedly uses a custom u-boot). >=20 > live well, > vagrant Looks good to me! --=20 Efraim Flashner =D7=90=D7=A4=D7=A8=D7=99=D7=9D = =D7=A4=D7=9C=D7=A9=D7=A0=D7=A8 GPG key =3D A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 Confidentiality cannot be guaranteed on emails sent or received unencrypted --YoCsYI8zms8870dr Content-Type: application/pgp-signature; name=signature.asc -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEoov0DD5VE3JmLRT3Qarn3Mo9g1EFAmga8rEACgkQQarn3Mo9 g1HvUxAAsf52c9+FBneg4p8oWMMPD0CD40CImKYillzvwY8pEyC+sSF/k7QWGDcu AKkst8ja7chWvDn88hggYs2f+bZvg7fG8f1FX8CX9R0k4Om/d0uPBNTsWXzpbbne Kc9UGebNDZYsi7SeniqkWHJ473H7rq75OB6tJbg8NAnj6wpDFOjcYiF74Y0v4Ut/ Z6epD/YD8nGxITvduysq1wwj3o86e7vUZTZUvJ+V+kADBX4nALvVtucOq8+NZJ55 4uZy5JUJz8KHCsnJStQ0fX55TOhFbmWxQ8PG0Zvhx03v77bJXKHqjWtJR3zafMgr LxYhEFGb7CgPWxKHo2a0WvW8T8vzBog2GqNcEsr9wPwpHJLP4QMyjnscJEDfyerJ JoHOTHr2mrP2227h+82CeiA6QAF5whv1hukan8vs5V2E9XTqke39zFYPgprCoec4 MRmmBN8HLvYQ0mEzYJC1jwEyKJCwv8AMBCwSgk6C9tokeprRGVKp1TigZqz6ty7T RrscPN5pYVjQwPpN8xGB8SKoPar3mhJJ+wVEfjRt8tvvpvqcdonopbstViqNpz4C 4CF+RlqoSrFxjZ4wQpby+PY3znYZwqdiBbYaSbLBR2lmWBBMwaN4xpY3tEwzFJMr G2IlBmE+oXjCYm2sy54n1nGmrkxtprhfUg8Y93/iUJP2TcOm75o= =Gg6z -----END PGP SIGNATURE----- --YoCsYI8zms8870dr-- From debbugs-submit-bounces@debbugs.gnu.org Wed May 07 17:38:12 2025 Received: (at 78286-done) by debbugs.gnu.org; 7 May 2025 21:38:12 +0000 Received: from localhost ([127.0.0.1]:48867 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1uCmSy-0000fW-HT for submit@debbugs.gnu.org; Wed, 07 May 2025 17:38:12 -0400 Received: from cascadia.aikidev.net ([173.255.214.101]:47964) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1uCmSx-0000f4-3D for 78286-done@debbugs.gnu.org; Wed, 07 May 2025 17:38:11 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=debian.org; s=1.vagrant.user; t=1746653884; bh=pOFsHuBjnGXd6MHHaMtrxhB9fyAwZzIqeMWqQ9bHNxg=; h=From:To:Cc:Subject:In-Reply-To:References:Date:From; b=dqkGTeZTg9knUUGjDo2irDT7iEZjgDOfcJKKjgl5jM8tDkKnzjZLb3YgqMe3raQyf gHcbVe8jbEsYr+bzlgC/nfJXEjKlNg2DbDJHN0UmsA5M8wr8y3gQuk6RgeH8kCtKTN AmpYjc3tlh9jzMc9NzUdGh8FicyG2JDck0PKVzeipF07li055gX3c1TrH27SN91Ex/ C6TSpjwCZsTo53vK2d5QDQg106t9azlpwh+3mN2RvK4lcbBCfDXd07Lmu4SwcxR3S2 SduDm+DK9+rLtdjm+TvKNqlfJRwR/pSYr4vO4AxLIN8c8SceOE+vawdlFLh0wMtz0g ZBlPGTu9IHOlQ== Received: from localhost (unknown [IPv6:2600:3c01:e000:21:7:77:0:50]) by cascadia.aikidev.net (Postfix) with ESMTPSA id 9E54B8160; Wed, 7 May 2025 14:38:04 -0700 (PDT) From: Vagrant Cascadian To: Efraim Flashner Subject: Re: Update arm-trusted-firmware to 2.12.2 In-Reply-To: References: <875xidqsfk.fsf@wireframe> Date: Wed, 07 May 2025 14:37:59 -0700 Message-ID: <87cyckp0eg.fsf@wireframe> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 78286-done Cc: gabriel@erlikon.ch, 78286-done@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On 2025-05-07, Efraim Flashner wrote: > On Tue, May 06, 2025 at 03:34:55PM -0700, Vagrant Cascadian wrote: >> The attached patch updates arm-trusted-firmware packages to 2.12.2. >>=20 >> I believe this fixes a few minor CVE, although it is not immediately >> obvious from upstream commit logs... >>=20 >> All dependents build on both x86_64-linux and aarch64-linux: >>=20 >> guix build: computing dependents of package arm-trusted-firmware-imx8mq@= 2.12.2... >> /gnu/store/gg1gmqb89kjaqbq8f9ndzs3ll7niq56d-arm-trusted-firmware-imx8mq-= 2.12.2 ... >> guix build: computing dependents of package arm-trusted-firmware-sun50i-= h616@2.12.2... >> /gnu/store/jljnh49swdkax8fpl2xqpaag065vggai-arm-trusted-firmware-sun50i-= h616-2.12.2 >> /gnu/store/kvh138wv7ri6fni3mcan7xdbw7i3p3j2-u-boot-orangepi-zero2w-2025.= 01 >>=20 >> I also boot-tested a mnt/reform2 (which admittedly uses a custom u-boot). ... > Looks good to me! Thanks! Pushed as f3b2a79cb2355b9b9119723a667adaefc933e715. live well, vagrant --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQRlgHNhO/zFx+LkXUXcUY/If5cWqgUCaBvSuAAKCRDcUY/If5cW qkSuAQCi4uK0R6pwFKPjKxATEMnvYMyZ8/yLPFhOgPnUSq6xsAEA+oDHVl6/+gWm qwy2LaMIb4tbtpuEXdL5R8ntqFqQjQg= =Z1tj -----END PGP SIGNATURE----- --=-=-=-- From unknown Sat Jun 21 03:22:40 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Thu, 05 Jun 2025 11:24:15 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator