GNU bug report logs

#47144 security patching of 'patch' package

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #100 received at 47144-done@debbugs.gnu.org (full text, mbox, reply):

Received: (at 47144-done) by debbugs.gnu.org; 24 Jun 2024 05:16:27 +0000
From debbugs-submit-bounces@debbugs.gnu.org Mon Jun 24 01:16:27 2024
Received: from localhost ([127.0.0.1]:39684 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1sLc42-0005K8-MX
	for submit@debbugs.gnu.org; Mon, 24 Jun 2024 01:16:27 -0400
Received: from mail-qk1-f173.google.com ([209.85.222.173]:43472)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <maxim.cournoyer@gmail.com>) id 1sLbZX-0003tV-D3
 for 47144-done@debbugs.gnu.org; Mon, 24 Jun 2024 00:44:56 -0400
Received: by mail-qk1-f173.google.com with SMTP id
 af79cd13be357-79bc769b014so277952085a.1
 for <47144-done@debbugs.gnu.org>; Sun, 23 Jun 2024 21:44:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=gmail.com; s=20230601; t=1719204229; x=1719809029; darn=debbugs.gnu.org;
 h=mime-version:message-id:date:user-agent:references:in-reply-to
 :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to;
 bh=kyKpmt9HOAdJx5rAYeaAZSnkhAxAr3foEK9wYNZK8Do=;
 b=UdPjMMAkjTpIOj4KUy9JC4JEfMcNJ0ys6S7/H83q9NK2Djwc308g/yDiYnhBj+6Lxc
 rLvhHT14RUZbDE+qvfKOUZ1MM2IVMSO2QeNGaJkjr8k9kIfB1zzGFTfG4M3ML0lpQaWw
 KJeuA4miEBqBFjJPAv+K/jSxlc8NW/+jpkuc3iqf0heZwjWxYU6S5ry0yiBlBek19VDo
 rXbPSu/NkxQCx293rP9gFGNklGXPo9LEPhcVkgX8Wr7ATms4X+qSkL4ATsLBRhTY4XF8
 DlsoFo1DjjiIlpeV971x/Md8OFW5tfP9dEJ4VOHAh7j89WgoTrY9fZYZ7dzIjK2uocVX
 5qdA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20230601; t=1719204229; x=1719809029;
 h=mime-version:message-id:date:user-agent:references:in-reply-to
 :subject:cc:to:from:x-gm-message-state:from:to:cc:subject:date
 :message-id:reply-to;
 bh=kyKpmt9HOAdJx5rAYeaAZSnkhAxAr3foEK9wYNZK8Do=;
 b=toWDJxIZHK4G84AvzL2M3wwYoiuzPfA1byCGk47fD3N7Hih2PYaNH1KlSaefhB82DN
 lFoJMV1+ckxZ1thKUHWciAorlsBNM+MQsueJ69xghmZgf5PigIPc3b9wjLFrKyHZ2UfC
 80AA/rR6a03c+jUGrNWFPeYMjjIaKd9mvItpxWDbxZnZmgdBfuJTaBjijxeFYIIejOZo
 DGD3KeWD/usOhDOg2ItLcmhzrVi1nW4gH5NMesOE4bzdc+jYkrieI5AFfZdqbbXcM/18
 jUe0Nz/pWQWvd/rs6IKZ5MBvjeXww4x+u1Ia+5sjmvAW0LU54DdDzIi43y3X8KR1F9Sk
 lMog==
X-Gm-Message-State: AOJu0YxBxGC5zSkblSEBIP3MuSs5XYuypHLn5amGahZV8suNg9VlNI5w
 6HBPQR567JYUq0U7VveQT6iH41Abq45lo72g5l7rgc21cjzyjwz1
X-Google-Smtp-Source: AGHT+IHX1ZY3RLv/V34gwNjNaMpnpsT15+yUGH/4xi08rRJzQdn/iFFD9NaFKHm5AWLRhJbPhzK6zw==
X-Received: by 2002:a05:620a:4503:b0:795:be11:c626 with SMTP id
 af79cd13be357-79bded4d5f0mr755515585a.26.1719204228939; 
 Sun, 23 Jun 2024 21:43:48 -0700 (PDT)
Received: from hurd (dsl-205-233-124-241.b2b2c.ca. [205.233.124.241])
 by smtp.gmail.com with ESMTPSA id
 af79cd13be357-79bce942edasm280838585a.128.2024.06.23.21.43.46
 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
 Sun, 23 Jun 2024 21:43:48 -0700 (PDT)
From: Maxim Cournoyer <maxim.cournoyer@gmail.com>
To: 47144-done@debbugs.gnu.org
Subject: Re: bug#47144: security patching of 'patch' package
In-Reply-To: <7663177c58ca72f54b6c715561701952b35910ec.1717634752.git.maxim.cournoyer@gmail.com>
 (Maxim Cournoyer's message of "Wed, 5 Jun 2024 20:46:21 -0400")
References: <a3641c8501b839cb4490edca279bf15a8141b8ea.1717634752.git.maxim.cournoyer@gmail.com>
 <7663177c58ca72f54b6c715561701952b35910ec.1717634752.git.maxim.cournoyer@gmail.com>
User-Agent: Gnus/5.13 (Gnus v5.13)
Date: Mon, 24 Jun 2024 00:43:46 -0400
Message-ID: <87cyo70x31.fsf_-_@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain
X-Spam-Score: 3.0 (+++)
X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 the administrator of that system for details.
 Content preview:  Hi,
 Maxim Cournoyer writes: > * gnu/packages/base.scm (patch):
 Rename to... > (patch/pinned): ... this. Hide package. > (patch): New
 variable.
 > * gnu/packages/commencement.scm (patch-mesboot): Inherit from patch/pinned.
 > (patc [...] 
 Content analysis details:   (3.0 points, 10.0 required)
 pts rule name              description
 ---- ---------------------- --------------------------------------------------
 3.0 MANY_TO_CC             Sent to 10+ recipients
 -0.0 SPF_PASS               SPF: sender matches SPF record
 0.0 FREEMAIL_FROM          Sender email is commonly abused enduser mail
 provider (maxim.cournoyer[at]gmail.com)
 0.0 SPF_HELO_NONE          SPF: HELO does not publish an SPF Record
 -0.0 RCVD_IN_MSPIKE_H2      RBL: Average reputation (+2)
 [209.85.222.173 listed in wl.mailspike.net]
 -0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at https://www.dnswl.org/,
 no trust [209.85.222.173 listed in list.dnswl.org]
 -0.0 T_SCC_BODY_TEXT_LINE   No description available.
X-Debbugs-Envelope-To: 47144-done
X-Mailman-Approved-At: Mon, 24 Jun 2024 01:16:20 -0400
Cc: Josselin Poiret <dev@jpoiret.xyz>, Tobias Geerinckx-Rice <me@tobias.gr>,
 Sharlatan Hellseher <sharlatanus@gmail.com>,
 Ekaitz Zarraga <ekaitz@elenq.tech>, Simon Tournier <zimon.toutoune@gmail.com>,
 Guillaume Le Vaillant <glv@posteo.net>, Mark H Weaver <mhw@netris.org>,
 Ludovic Courtès <ludo@gnu.org>,
 Katherine Cox-Buday <cox.katherine.e+guix@gmail.com>,
 Efraim Flashner <efraim@flashner.co.il>, Leo Famulari <leo@famulari.name>,
 Ricardo Wurmus <rekado@elephly.net>, Munyoki Kilyungi <me@bonfacemunyoki.com>,
 jgart <jgart@dismail.de>, Mathieu Othacehe <othacehe@gnu.org>,
 Christopher Baines <guix@cbaines.net>,
 Léo Le Bouter <lle-bout@zaclys.net>
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: 2.0 (++)
X-Spam-Report: Spam detection software, running on the system "debbugs.gnu.org",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 the administrator of that system for details.
 
 Content preview:  Hi, Maxim Cournoyer writes: > * gnu/packages/base.scm (patch):
    Rename to... > (patch/pinned): ... this. Hide package. > (patch): New variable.
    > * gnu/packages/commencement.scm (patch-mesboot): Inherit from patch/pinned.
    > (patc [...] 
 
 Content analysis details:   (2.0 points, 10.0 required)
 
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  3.0 MANY_TO_CC             Sent to 10+ recipients
 -0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at https://www.dnswl.org/,
                              no trust
                             [209.85.222.173 listed in list.dnswl.org]
 -0.0 RCVD_IN_MSPIKE_H2      RBL: Average reputation (+2)
                             [209.85.222.173 listed in wl.mailspike.net]
 -0.0 SPF_PASS               SPF: sender matches SPF record
  0.0 FREEMAIL_FROM          Sender email is commonly abused enduser mail
                             provider (maxim.cournoyer[at]gmail.com)
  0.0 SPF_HELO_NONE          SPF: HELO does not publish an SPF Record
 -0.0 T_SCC_BODY_TEXT_LINE   No description available.
 -1.0 MAILING_LIST_MULTI     Multiple indicators imply a widely-seen list
                             manager
Hi,

Maxim Cournoyer <maxim.cournoyer@gmail.com> writes:

> * gnu/packages/base.scm (patch): Rename to...
> (patch/pinned): ... this.  Hide package.
> (patch): New variable.
> * gnu/packages/commencement.scm (patch-mesboot): Inherit from patch/pinned.
> (patch-boot0): Likewise.
> (%final-inputs): Replace patch with patch/pinned.
> * gnu/packages/lisp.scm (cl-asdf): Likewise.
> * guix/packages.scm (%standard-patch-inputs): Replace patch with patch/pinned.
>
> Fixes: https://issues.guix.gnu.org/47144
> Reported-by: Mark H Weaver <mhw@netris.org>
> Change-Id: I54ae41b735f5ba0ebad30ebdfaabe0ccdc3f9873

Applied locally and will push shortly.

-- 
Thanks,
Maxim




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 17:03:11 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.