[PATCH] gnu: libarchive: Update to 3.3.1.

  • Done
  • quality assurance status badge
Details
2 participants
  • Kei Kebreau
  • Leo Famulari
Owner
unassigned
Submitted by
Kei Kebreau
Severity
normal

Debbugs page

Kei Kebreau wrote 8 years ago
(address . guix-patches@gnu.org)(name . Kei Kebreau)(address . kei@openmailbox.org)
20170508190714.15902-1-kei@openmailbox.org
Fixes CVE-2016-{10209,10350} and CVE-2017-5601.

* gnu/packages/backup.scm (libarchive): Update to 3.3.1.
---
gnu/packages/backup.scm | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)

Toggle diff (24 lines)
diff --git a/gnu/packages/backup.scm b/gnu/packages/backup.scm
index f9c0a22a0..569d5d64b 100644
--- a/gnu/packages/backup.scm
+++ b/gnu/packages/backup.scm
@@ -186,7 +186,7 @@ backups (called chunks) to allow easy burning to CD/DVD.")
(define-public libarchive
(package
(name "libarchive")
- (version "3.2.2")
+ (version "3.3.1")
(source
(origin
(method url-fetch)
@@ -194,7 +194,7 @@ backups (called chunks) to allow easy burning to CD/DVD.")
version ".tar.gz"))
(sha256
(base32
- "03q6y428rg723c9fj1vidzjw46w1vf8z0h95lkvz1l9jw571j739"))))
+ "1rr40hxlm9vy5z2zb5w7pyfkgd1a4s061qapm83s19accb8mpji9"))))
(build-system gnu-build-system)
;; TODO: Add -L/path/to/nettle in libarchive.pc.
(inputs
--
2.12.2
Leo Famulari wrote 8 years ago
(name . Kei Kebreau)(address . kei@openmailbox.org)(address . 26836@debbugs.gnu.org)
20170508192548.GA20051@jasmine
On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote:
Toggle quote (4 lines)
> Fixes CVE-2016-{10209,10350} and CVE-2017-5601.
>
> * gnu/packages/backup.scm (libarchive): Update to 3.3.1.

Thanks!

Can you use a graft instead? Then, the commit message can be like this:

gnu: libarchive: Replace with 3.3.1 [security fixes].

Fixes CVE-2016-{10209,10350}, CVE-2017-5601.

* gnu/packages/backup.scm (libarchive)[replacement]: New field.
(libarchive-3.3.1): New variable.
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlkQxjsACgkQJkb6MLrK
fwixIA/+L1wXFfeW7f8Xc4xOBKN0Z03rH0IiSQ5TYLwQrzAgbjqH/LIj3NyTonMf
jD5r2amhSdaeI1OTRY6g3SZYn2t6Rns73ItKpn07QJ0rTbSLJHgaFUpUeK8zZJyl
mKpS19LHPvpqPwj1BasmrIJiwkWxrP5z/nuaj8shsVPyCb3RaqCVJf55iPtj7Mhv
dXmS5v1Y4d2pub/f/xr2zFy5lkcae4HvaSCHEohphCyz4yBOcDs46fIeV29Djt+L
DbAt1IXyOhJwDUnq4bcQp+EPo2nmSMI15yq6taI7N4N+Cw6srD44D5fDQEJpUNrm
vTDmsjbtsXO7x8K+F7beG9NiaxD5OIWTBxF4AYRLeIPR5c4oi8mOvVjnflTXoYpX
IsFKV4untlAgDtrovN/5F7XQp9MtvadjbUGiMNbNIed8B6nHr8W7DbmurnkbI1ou
p/sQP4P18ahmnBQE3ylhGKEi2zr816ARkOB1y8QUB01UsLTvdOb8L0OW5qUTtMqq
1ScergQ3yAZewgOzFQGehBPl+bdLRbAIG2/jnMiO/9ClsItAzs6Y5DwxfKu+mkg8
VVGijtqUOWbNeiCf0qghsEdaGPLtE2T/QQR+bhSxt6fxa89D410/hmmLPobnv+7k
H0kg/5y7kDD2GV6rq9nH1+tGvx8lqYPKS0bm9wtOSuapDTyc67M=
=p72G
-----END PGP SIGNATURE-----


Kei Kebreau wrote 8 years ago
(name . Leo Famulari)(address . leo@famulari.name)(address . 26836@debbugs.gnu.org)
878tm7kqbf.fsf@openmailbox.org
Leo Famulari <leo@famulari.name> writes:

Toggle quote (16 lines)
> On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote:
>> Fixes CVE-2016-{10209,10350} and CVE-2017-5601.
>>
>> * gnu/packages/backup.scm (libarchive): Update to 3.3.1.
>
> Thanks!
>
> Can you use a graft instead? Then, the commit message can be like this:
>
> gnu: libarchive: Replace with 3.3.1 [security fixes].
>
> Fixes CVE-2016-{10209,10350}, CVE-2017-5601.
>
> * gnu/packages/backup.scm (libarchive)[replacement]: New field.
> (libarchive-3.3.1): New variable.

Like the patch I've attached?
From 45d3157bb61bb8b5f26ff13feb672759b6043e6f Mon Sep 17 00:00:00 2001
From: Kei Kebreau <kei@openmailbox.org>
Date: Mon, 8 May 2017 14:58:07 -0400
Subject: [PATCH] gnu: libarchive: Replace with 3.3.1 [security fixes].
To: 26836@debbugs.gnu.org

Fixes CVE-2016-{10209,10350} and CVE-2017-5601.

* gnu/packages/backup.scm (libarchive)[replacement]: New field.
(libarchive-3.3.1): New variable.
---
gnu/packages/backup.scm | 16 ++++++++++++++++
1 file changed, 16 insertions(+)

Toggle diff (43 lines)
diff --git a/gnu/packages/backup.scm b/gnu/packages/backup.scm
index f9c0a22a0..d5cb5783a 100644
--- a/gnu/packages/backup.scm
+++ b/gnu/packages/backup.scm
@@ -5,6 +5,7 @@
;;; Copyright © 2017 Tobias Geerinckx-Rice <me@tobias.gr>
;;; Copyright © 2017 Thomas Danckaert <post@thomasdanckaert.be>
;;; Copyright © 2017 Arun Isaac <arunisaac@systemreboot.net>
+;;; Copyright © 2017 Kei Kebreau <kei@openmailbox.org>
;;;
;;; This file is part of GNU Guix.
;;;
@@ -186,6 +187,7 @@ backups (called chunks) to allow easy burning to CD/DVD.")
(define-public libarchive
(package
(name "libarchive")
+ (replacement libarchive-3.3.1)
(version "3.2.2")
(source
(origin
@@ -241,6 +243,20 @@ archive. In particular, note that there is currently no built-in support for
random access nor for in-place modification.")
(license license:bsd-2)))
+(define libarchive-3.3.1
+ (package
+ (inherit libarchive)
+ (name "libarchive")
+ (version "3.3.1")
+ (source
+ (origin
+ (method url-fetch)
+ (uri (string-append "http://libarchive.org/downloads/libarchive-"
+ version ".tar.gz"))
+ (sha256
+ (base32
+ "1rr40hxlm9vy5z2zb5w7pyfkgd1a4s061qapm83s19accb8mpji9"))))))
+
(define-public rdup
(package
(name "rdup")
--
2.12.2
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEg7ZwOtzKO2lLzi2m5qXuPBlGeg0FAlkQ3sUACgkQ5qXuPBlG
eg3itw//Tac6M7DbEYI4GF14bSvk3iV4+Pe9Qekcc6sh7aaflyANhD9rvpNDDJ+W
/B25XUpe1YagW7tywlfIt61teFqlO+LazDhKjgo0W8GQv51qOPcP0bb1BkD1u/d1
pW11gacFKhwPIO4ZjFroatCR3f1f4tI+/mg9KedfWaZADEaKMTl+8T2lxAsSzcji
VEThgp321TE7krjfTrabzTpfsuZUwvXyti1y+RvAf82eGvG4ukkZMoYLIhHB9USV
L+STL7rJox0dU6TaRBvH0htPwPQLcl28IugXQ4FrrDzxMDwjtlUY0v0elpk+urlg
nfvAttS/17yNXfAnrAZkKfRS2yv1aqYiWzHPVOwselq0w+rQqHuKtRLbMBrapGjS
92eXoLUikBqRyS63Q791u5E6+ybWsX9I+oXdxPxopz9/Wpj7x+capZIOrxKCB+Sv
VpnZGXmUYLksowNzhdygWjKSNr0mVIYp7RXtTVvUdLkjr4GrwKs7yjA2wmJUn7Zi
6DKtYqDxMr5bqt7L6kq2RnE+Sjy+gZjL9lLKGVQJOXTloXHulAFxI4SkIFikKPst
SYnAprDEx1//oB53B1XOVmZZ+Owqg1TBxruvkK8Xbduh4wu3fvBQ7V4GF4VXOqAn
IwfdombCf4b/q70p9DeFZ5kKwQUpgiuraX+iuxO1KtUq4Qz8O3A=
=pCJ8
-----END PGP SIGNATURE-----

Leo Famulari wrote 8 years ago
(name . Kei Kebreau)(address . kei@openmailbox.org)(address . 26836@debbugs.gnu.org)
20170508215611.GA3476@jasmine
On Mon, May 08, 2017 at 05:10:28PM -0400, Kei Kebreau wrote:
Toggle quote (31 lines)
> Leo Famulari <leo@famulari.name> writes:
>
> > On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote:
> >> Fixes CVE-2016-{10209,10350} and CVE-2017-5601.
> >>
> >> * gnu/packages/backup.scm (libarchive): Update to 3.3.1.
> >
> > Thanks!
> >
> > Can you use a graft instead? Then, the commit message can be like this:
> >
> > gnu: libarchive: Replace with 3.3.1 [security fixes].
> >
> > Fixes CVE-2016-{10209,10350}, CVE-2017-5601.
> >
> > * gnu/packages/backup.scm (libarchive)[replacement]: New field.
> > (libarchive-3.3.1): New variable.
>
> Like the patch I've attached?

> From 45d3157bb61bb8b5f26ff13feb672759b6043e6f Mon Sep 17 00:00:00 2001
> From: Kei Kebreau <kei@openmailbox.org>
> Date: Mon, 8 May 2017 14:58:07 -0400
> Subject: [PATCH] gnu: libarchive: Replace with 3.3.1 [security fixes].
> To: 26836@debbugs.gnu.org
>
> Fixes CVE-2016-{10209,10350} and CVE-2017-5601.
>
> * gnu/packages/backup.scm (libarchive)[replacement]: New field.
> (libarchive-3.3.1): New variable.

Thanks, LGTM!
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAlkQ6XcACgkQJkb6MLrK
fwi/ThAAjA6VOmdiNfDJUMbf8pjjOal+KmK3Mlkn2B+twMPAwOtJC/B2DPZ/7nIq
7kNUCSz+PpnwOSek5V0alLZxIeXdPDaNdwzpojptrmCvy8cYTRDzAg3AckIhDdlb
Y6YEs3UoMqOSDSnxwHUQpWUU+eQ1gGHB5UUXtuepiAmvHPlzuKVIWHCicvb/aXuv
ClM0Ui09VnA7/BDIdYUPsC7kJwH7UWjgGDjRzSuxWRUblPSybPShiBklGuu2Jq8w
A5MfUM3aCAZoCqc1t9og0dSC8yppoTx0IwCznd6A4m3h7uvTAxTCozSi48PxDHCv
p8n1ssdXEa3THi1hWp0dvI8cZci9AlPanRN2YKAcntFgm4Y0tJJkmtHEkHHs2LsB
yMQakKUXZnUrmm2OrIUTwVjllCD3mvo0ZxQNtEKGaQNFjJcX0d3CB/B/9NKlva4K
dpA71Unn3IoIxakaZycai2da4cwxToW4cOq06U+vB890EATQifUSHcN4F9Z0Lr2g
7+gT9KngpMEdBa0w8yIEK187AdizxJ4O8UMrXK1uEa2ZInObMVRyOSiRNnIA6PMp
1Cd0ZRqKaTv9+mloTD725kPSDAy3EMGu2olQpHBRQ57HBZ7/fBmLa0F+f+qoCbdi
G4j3djYHraUX1zsVr0zPXLWAGYlTJW6BWmELUA1fxQO4Bkcw5HM=
=P+qq
-----END PGP SIGNATURE-----


Kei Kebreau wrote 8 years ago
(name . Leo Famulari)(address . leo@famulari.name)(address . 26836-done@debbugs.gnu.org)
87r2zykh8x.fsf@openmailbox.org
Leo Famulari <leo@famulari.name> writes:

Toggle quote (34 lines)
> On Mon, May 08, 2017 at 05:10:28PM -0400, Kei Kebreau wrote:
>> Leo Famulari <leo@famulari.name> writes:
>>
>> > On Mon, May 08, 2017 at 03:07:14PM -0400, Kei Kebreau wrote:
>> >> Fixes CVE-2016-{10209,10350} and CVE-2017-5601.
>> >>
>> >> * gnu/packages/backup.scm (libarchive): Update to 3.3.1.
>> >
>> > Thanks!
>> >
>> > Can you use a graft instead? Then, the commit message can be like this:
>> >
>> > gnu: libarchive: Replace with 3.3.1 [security fixes].
>> >
>> > Fixes CVE-2016-{10209,10350}, CVE-2017-5601.
>> >
>> > * gnu/packages/backup.scm (libarchive)[replacement]: New field.
>> > (libarchive-3.3.1): New variable.
>>
>> Like the patch I've attached?
>
>> From 45d3157bb61bb8b5f26ff13feb672759b6043e6f Mon Sep 17 00:00:00 2001
>> From: Kei Kebreau <kei@openmailbox.org>
>> Date: Mon, 8 May 2017 14:58:07 -0400
>> Subject: [PATCH] gnu: libarchive: Replace with 3.3.1 [security fixes].
>> To: 26836@debbugs.gnu.org
>>
>> Fixes CVE-2016-{10209,10350} and CVE-2017-5601.
>>
>> * gnu/packages/backup.scm (libarchive)[replacement]: New field.
>> (libarchive-3.3.1): New variable.
>
> Thanks, LGTM!

Great! Pushed to master.
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEg7ZwOtzKO2lLzi2m5qXuPBlGeg0FAlkRDK4ACgkQ5qXuPBlG
eg3nRRAAqBQl2/cyUOsJEJ0tiej3G3CWG8Rnqe9aIk/h6U4vKvWYwZQAha9BSY4D
8xCVHuyhcsWKnO/VJsRFwYdF2f6e5PZWDCyrygMIqB75xQKAFu0/bONkxcqDxf2H
jxEK5CamjFetH7qNrmINXEX4dnkeBFR7gvHVZ8vsh+VdXf6AwRGgixw90/yx5cKv
0BtKi04b3WX4kr+kPjXdOghbQz7quMEJiPRG2pN9U442ci0Xm5BCQvSn4N2WYJtu
VV8eS/E59LqkCtSM+oQel/V+V69psO2moR+gc4Hcza+23gWRs5O5+iiqGScjCC5m
EPIoLq0k61LXO6K+OM0w6fDo3kEy7QEdxysqu8vAnEdMZfKlNBjypSM8f7SKSWgm
QgcFqmomS0ULJ8UhmqkeI1U8Zrftb3Lurf7IBvk0MYV612XH9A7be4qy3KAIievU
Ao4mCzogYkaSHJuo/WG6roRI6drsirhqwX7FY2fDi6folKT753EMMwc3ACI0Wqld
H2ygZ6Wo3Qm210Re2+jdtHFZze2m/DPTpRmLXgkxOMVZKUUVOVNRm6Hzni4PGpmA
DpJe98fkwEQHgc3GoaZkM6YweDfiaoCECaXNwlqhIBuvkCfOFGu+Y3Y6YUS+ABxN
mfYiHFebSyWDCAnm6RwLi+dDjaNR48NQW/EnEShj8DbANG5VD54=
=JCoZ
-----END PGP SIGNATURE-----

Closed
?
Your comment

This issue is archived.

To comment on this conversation send an email to 26836@debbugs.gnu.org

To respond to this issue using the mumi CLI, first switch to it
mumi current 26836
Then, you may apply the latest patchset in this issue (with sign off)
mumi am -- -s
Or, compose a reply to this issue
mumi compose
Or, send patches to this issue
mumi send-email *.patch
You may also tag this issue. See list of standard tags. For example, to set the confirmed and easy tags
mumi command -t +confirmed -t +easy
Or, remove the moreinfo tag and set the help tag
mumi command -t -moreinfo -t +help