GNU bug report logs

#47144 security patching of 'patch' package

PackageSource(s)Maintainer(s)
guix PTS Buildd Popcon
Full log

Message #65 received at 47144@debbugs.gnu.org (full text, mbox, reply):

Received: (at 47144) by debbugs.gnu.org; 4 Jun 2024 17:40:37 +0000
From debbugs-submit-bounces@debbugs.gnu.org Tue Jun 04 13:40:37 2024
Received: from localhost ([127.0.0.1]:41428 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces@debbugs.gnu.org>)
	id 1sEY9F-0002zd-C3
	for submit@debbugs.gnu.org; Tue, 04 Jun 2024 13:40:37 -0400
Received: from mail-wm1-f48.google.com ([209.85.128.48]:41001)
 by debbugs.gnu.org with esmtp (Exim 4.84_2)
 (envelope-from <zimon.toutoune@gmail.com>) id 1sEY9C-0002zI-5j
 for 47144@debbugs.gnu.org; Tue, 04 Jun 2024 13:40:36 -0400
Received: by mail-wm1-f48.google.com with SMTP id
 5b1f17b1804b1-421547faa0eso726565e9.0
 for <47144@debbugs.gnu.org>; Tue, 04 Jun 2024 10:40:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=gmail.com; s=20230601; t=1717522755; x=1718127555; darn=debbugs.gnu.org;
 h=content-transfer-encoding:mime-version:message-id:date:references
 :in-reply-to:subject:cc:to:from:from:to:cc:subject:date:message-id
 :reply-to; bh=Yp+r4ynYO2IpntdD7+BoMD3+J21D+IkxDq7Cran0r7I=;
 b=HiDjc54NA7Sk7uvcJeRXPA3CBCyE+WL/X//hwEl179KfaYz1OD241sCv2xhyDal/Rg
 +eYvjl8ZD60/nvc+YYuq8grBYOICrnF0vjewjS+egPEiM23akEvfY4BpGLYRtzUsoyrt
 G2SSQhIVDEefmGzRP3IuDl0fUHB9LKjsjqI4SWr2eLdTFINdoiRKlWDkLhhi5wKbLrpe
 cZC1+GXbp1CxsbgyaHJrZ5oLXrA26LmyLCdhTTlECC2q/eiEX+oaUyGqppGb10Ysip5/
 PxSFeTDav5yjf1/No3C/368DbU4+qYEtm7rZW+g3je1VYVRD3jIsoGsOrJeCrT/whug/
 hh5w==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20230601; t=1717522755; x=1718127555;
 h=content-transfer-encoding:mime-version:message-id:date:references
 :in-reply-to:subject:cc:to:from:x-gm-message-state:from:to:cc
 :subject:date:message-id:reply-to;
 bh=Yp+r4ynYO2IpntdD7+BoMD3+J21D+IkxDq7Cran0r7I=;
 b=LdMyIfrelrN3iksTYzSJYplz+YteKNM1aIIuBPqTJVzxo0JGcUecSBWJxZ7dH3LCkD
 pKaQaZmetJsz3YO70PA8906j5Ty58sh46E5U7f6llR2Eprxt0Mxwzj2yJfQV+tHBXinl
 MD1BoN6blLWwZdWf6ofwkj2M1ATev8CE8gUoqvnfxIsb+3+FJhDwKoQLrdIKk2vIbbgo
 7+dkc9JzfpzjkWmBt/4jCOU4phD3Fmywx/+a0GC1W5f61h/BB5xviUJ+Er43kkatvDuH
 bpj7gUX+D1/umO0cKskniBZKF3XBpyrChLooAz2WJ+fH/ameOwqbUoEuhZUNZpBElz6J
 cG/A==
X-Forwarded-Encrypted: i=1;
 AJvYcCUkcig4IF9cSiH6/Zjir4OppBhIJmQc1UT2DflAlesus6haRSmFDncbKxtfL4xXoeJSN3sd3OlFJTui79Uh56m2RycXLyw=
X-Gm-Message-State: AOJu0Yx04p4Y1vG3+dSyRJN9Dw/7L5jGxM2T/T7WkErZnu2bku28kNAf
 mrUiU+RY7tP8Ocu5U3LYJMSIfpyAZYkXSVhj9J5XiEjPCKLT39PjNYZMxg==
X-Google-Smtp-Source: AGHT+IElefNWfx1OknkeSkk6lwELAqNMs7bbeG5ERMVA+BWO0SgXqUXzrhYbkZA0B/gldLVaAqVr7Q==
X-Received: by 2002:a05:600c:3c8d:b0:421:2c02:9779 with SMTP id
 5b1f17b1804b1-42156357fddmr2084965e9.4.1717522754411; 
 Tue, 04 Jun 2024 10:39:14 -0700 (PDT)
Received: from lili (roam-nat-fw-prg-194-254-61-47.net.univ-paris-diderot.fr.
 [194.254.61.47]) by smtp.gmail.com with ESMTPSA id
 5b1f17b1804b1-4213a74f6dcsm99032445e9.18.2024.06.04.10.39.13
 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
 Tue, 04 Jun 2024 10:39:14 -0700 (PDT)
From: Simon Tournier <zimon.toutoune@gmail.com>
To: Maxim Cournoyer <maxim.cournoyer@gmail.com>
Subject: Re: bug#47144: [PATCH 3/3] gnu: patch: Graft to latest commit
 [security fixes].
In-Reply-To: <87ikytctzo.fsf@gmail.com>
References: <28b457771ab0e7ad87cb65600a5898f68be5074a.1717124361.git.maxim.cournoyer@gmail.com>
 <5eda21a09360653b198f1b0d7f52cf531dc97485.1717124361.git.maxim.cournoyer@gmail.com>
 <87zfs62c4z.fsf@gmail.com> <87ikytctzo.fsf@gmail.com>
Date: Tue, 04 Jun 2024 17:39:57 +0200
Message-ID: <87le3kyawi.fsf@gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: 0.0 (/)
X-Debbugs-Envelope-To: 47144
Cc: Mark H Weaver <mhw@netris.org>,
 Ludovic Courtès <ludo@gnu.org>, 47144@debbugs.gnu.org,
 Vivien Kraus <vivien@planete-kraus.eu>, Leo Famulari <leo@famulari.name>
X-BeenThere: debbugs-submit@debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit@debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request@debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request@debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces@debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces@debbugs.gnu.org>
X-Spam-Score: -1.0 (-)
Hi Maxim,

On Fri, 31 May 2024 at 21:49, Maxim Cournoyer <maxim.cournoyer@gmail.com> wrote:

> I preferred inheritance to avoid having to manually sync things in the
> long run... (hopefully the graft gets ungrafted before 'patch' amasses
> new phatces, but we never know...)

What would be the long run? ;-)

Well, from my perspective, there is nothing to manually sync in the
future.

I mean, the only patch applied to release “2.7.6” will be still required
for patch/fixed; hence one will need to do what I am proposing if
’patch’ is removed.  Else if ’patch’ receives some security fixes, then
it seems expected to assume that the fix will be included in the latest
patch (here ’patch/fixed’).  Last, please note that ’patch’ is barely
modified.

--8<---------------cut here---------------start------------->8---
$ git log --format="%cd %s" -- gnu/packages/base.scm | grep 'gnu: patch'
Thu May 30 11:35:13 2024 -0400 gnu: patch: Fix indentation.
Sun Apr 22 22:40:48 2018 +0200 gnu: patch: Work around a cross-compilation issue.
Wed Mar 14 22:11:34 2018 +0100 gnu: patch: Update to 2.7.6.
Fri Jun 12 15:46:25 2015 +0300 gnu: patch: Set PATH_MAX for Hurd systems.
Mon Mar 9 22:56:50 2015 -0400 gnu: patch: Update to 2.7.5.
Sat Mar 7 20:34:50 2015 -0500 Revert "gnu: patch: Update to 2.7.5."
Sun Mar 8 00:32:11 2015 +0100 gnu: patch: Update to 2.7.5.
Wed Feb 11 11:23:46 2015 +0100 gnu: patch: Update to 2.7.4.
Fri Feb 6 13:53:28 2015 +0100 gnu: patch: Add 2.7.4 and make it a replacement for the default one.
Sat Apr 27 00:23:19 2013 +0200 gnu: patch: Update to 2.7.1.
--8<---------------cut here---------------end--------------->8---

I still think that it eases to have the patch close to the source
instead of coming from inheritance. Anyway. :-)

Cheers,
simon




Send a report that this bug log contains spam.


debbugs.gnu.org maintainers <help-debbugs@gnu.org>. Last modified: Sat Dec 21 16:55:11 2024; Machine Name: wallace-server

GNU bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.