Report forwarded
to guix-patches@gnu.org: bug#33783; Package guix-patches.
(Tue, 18 Dec 2018 02:55:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Alex Vong <alexvong1995@gmail.com>:
New bug report received and forwarded. Copy sent to guix-patches@gnu.org.
(Tue, 18 Dec 2018 02:55:02 GMT) (full text, mbox, link).
Tag: security
Hello,
This patch grafts sqlite to its latest version. It also changes all the
sqlite-* packages to use 'package/inherit' so that they get the
replacement as well. See <https://bugs.gnu.org/33751> for details.
Added tag(s) security.
Request was from Alex Vong <alexvong1995@gmail.com>
to control@debbugs.gnu.org.
(Tue, 18 Dec 2018 03:00:02 GMT) (full text, mbox, link).
Information forwarded
to guix-patches@gnu.org: bug#33783; Package guix-patches.
(Tue, 18 Dec 2018 22:25:02 GMT) (full text, mbox, link).
Subject: Bug#33783: [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes].
Date: Tue, 18 Dec 2018 17:22:58 -0500
I applied your proposed patch to my private branch and updated my x86_64
GuixSD system with GNOME 3, and my user profiles including IceCat.
Everything seems to work well, and I've verified that IceCat is using
the new sqlite.
Please push this to master.
Thanks!
Mark
Information forwarded
to guix-patches@gnu.org: bug#33783; Package guix-patches.
(Wed, 19 Dec 2018 01:12:01 GMT) (full text, mbox, link).
Subject: Bug#33783: [PATCH] gnu: sqlite: Replace with 3.26.0 [security fixes].
Date: Tue, 18 Dec 2018 20:10:31 -0500
Actually, there's one small problem with the patch: you should not use
'package/inherit' to define the replacement itself. That leads to a
circular definition and an infinite series of replacements. I guess the
grafting machinery copes with this somehow, but I'd prefer to avoid it.
I will soon push a slightly modified version of this patch.
Mark
Information forwarded
to guix-patches@gnu.org: bug#33783; Package guix-patches.
(Wed, 19 Dec 2018 06:21:01 GMT) (full text, mbox, link).
Mark H Weaver <mhw@netris.org> writes:
> Actually, there's one small problem with the patch: you should not use
> 'package/inherit' to define the replacement itself. That leads to a
> circular definition and an infinite series of replacements. I guess
> the
> grafting machinery copes with this somehow, but I'd prefer to avoid
> it.
>
I thought 'package/inherit' is a generalization of the previous
construct, but as you pointed out, it is not.
> I will soon push a slightly modified version of this patch.
>
OK!
> Mark
Cheers,
Alex
Patch was pushed as 38abef124bc18d3834eb12352a974b6143f62e97
--
Efraim Flashner <efraim@flashner.co.il> אפרים פלשנר
GPG key = A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351
Confidentiality cannot be guaranteed on emails sent or received unencrypted
Debbugs is free software and licensed under the terms of the
GNU Public License version 2. The current version can be
obtained from https://bugs.debian.org/debbugs-source/.