GNU bug report logs

#32957 Python uses a bundled expat

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #12 received at 32957@debbugs.gnu.org (full text, mbox, reply):

Received: (at 32957) by debbugs.gnu.org; 10 Oct 2018 19:27:20 +0000
From debbugs-submit-bounces@debbugs.gnu.org Wed Oct 10 15:27:20 2018
Received: from localhost ([127.0.0.1]:43871 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1gAK8e-0001Go-AB
	for submit@debbugs.gnu.org; Wed, 10 Oct 2018 15:27:20 -0400
Received: from out3-smtp.messagingengine.com ([66.111.4.27]:37235)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <leo@famulari.name>) id 1gAK8c-0001Gg-NG
 for 32957@debbugs.gnu.org; Wed, 10 Oct 2018 15:27:18 -0400
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44])
 by mailout.nyi.internal (Postfix) with ESMTP id 8A59121D26;
 Wed, 10 Oct 2018 15:27:18 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163])
 by compute4.internal (MEProxy); Wed, 10 Oct 2018 15:27:18 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=famulari.name;
 h=date:from:to:cc:subject:message-id:references:mime-version
 :content-type:in-reply-to; s=mesmtp; bh=7yafLitxo+EldNuMVPG0UPU0
 TsYxDCdIyKxtjIZrKCw=; b=besMsMWEfaPvAvV2vhU24easofQa0S0rldX6KiDD
 NveyYeLMFJd4PPgI7mrIh7AO9MMGCwC4SAr/nsC29GmHsVx4FaE9GttoDqZiFuc4
 JAITjrJg412CMJF2y2nXXZtwug/FFxKAnd9h6pnzHRGoh7ayuYxljxdJRA10tbug
 5io=
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:content-type:date:from:in-reply-to
 :message-id:mime-version:references:subject:to:x-me-proxy
 :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; bh=7yafLi
 txo+EldNuMVPG0UPU0TsYxDCdIyKxtjIZrKCw=; b=qK/zyLYTz/OwJxFZQ6pzs+
 svJTkXvbyf35Ae4GA25lOHZOhPkHmYOHVgAmu5m3PQbLuc0PbNbJ6y9oVqA7eKSG
 uTbyEa/goiIf57QKgrvPHzN0JQED+TxXS9h4f9zNkQFl4zUGtV0l+EW7P8ZhE+pJ
 KsSal40rpFRZFBd4nrVN5R1dWF9NGgtpS9HCQzQFYNXJuvVS/J2E73xDxe3dmtGs
 YCN94TBajbW4BtCzXGePdjb/i5HxijlUfkP1G3pcyGhIYm0h3jBQcwExnnaTi6V1
 yw9Z5I8UIG/zoC57iwVx75Xv04GwUdhwS07h5VYaJ2Z8owouvWL8JZfQuuQPWVZQ
 ==
X-ME-Sender: <xms:lFK-WyPpXNtwWE5hjHmp9ZVRxshDdAbILaCtIUfX5WCPLOYoba6_GA>
X-ME-Proxy: <xmx:lFK-WzguMC3VMMlBfrjwj2XQHMXJojktx5gOfTXxpL0oeCMtXrMjFA>
 <xmx:lFK-WwP08uYJ6ZBUYKHriOF4vvW6_OTNd2hKeq3lRjaf8e-oE8YXyQ>
 <xmx:lFK-W07gSlHJyQRiAP-cadqyjmOckwZIsov9ADBUR7asF42gcv_Bwg>
 <xmx:lFK-W-0SFjip-zd8r9DEvfpPAlA-_WYVgvdBThVJbuJjdYfsSD59iQ>
 <xmx:lFK-W1boekyH2dbOIRhMF1QjLtUi4RTbwFiHaAlsCNhCWcCd4V8xwQ>
 <xmx:llK-W_Fuk5Ts9WAEqfnpz9d8U5l8ia6Jj7JpXbDiOAaLGp6n_wjDYA>
Received: from localhost (unknown [172.58.201.64])
 by mail.messagingengine.com (Postfix) with ESMTPA id C2577102ED;
 Wed, 10 Oct 2018 15:27:15 -0400 (EDT)
Date: Wed, 10 Oct 2018 15:27:14 -0400
From: Leo Famulari <leo@famulari.name>
To: Marius Bakke <mbakke@fastmail.com>
Subject: Re: bug#32957: Python uses a bundled expat
Message-ID: <20181010192714.GC22832@jasmine.lan>
References: <87o9c7i0l6.fsf@fastmail.com>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature"; boundary="uh9ZiVrAOUUm9fzH"
Content-Disposition: inline
In-Reply-To: <87o9c7i0l6.fsf@fastmail.com>
User-Agent: Mutt/1.10.1 (2018-07-13)
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 32957
Cc: 32957@debbugs.gnu.org
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
[Message part 1 (text/plain, inline)]
On Sat, Oct 06, 2018 at 04:58:13PM +0200, Marius Bakke wrote:
> Python 2 and 3 are using a bundled Expat (residing under Modules/).
> 
> This has been the cause of security vulnerabilities in the past and
> should be changed to use Expat from Guix.

Looks like Debian uses an external Expat to fill the dependency, so it
should be possible:

https://packages.debian.org/stretch/python3.5-minimal

We should look into the difference between the bundled Expat and
upstream Expat.
[signature.asc (application/pgp-signature, inline)]

Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sun Dec 22 11:55:56 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.