From patchwork Wed May 22 14:53:00 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ian Eure X-Patchwork-Id: 2580 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id D5F3727BBE2; Wed, 22 May 2024 15:54:15 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.7 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,SPF_HELO_PASS,URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id EB8E527BBE9 for ; Wed, 22 May 2024 15:54:14 +0100 (BST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1s9nLr-00052C-CB; Wed, 22 May 2024 10:53:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1s9nLp-00051s-Ad for guix-patches@gnu.org; Wed, 22 May 2024 10:53:57 -0400 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1s9nLp-0007SS-0e for guix-patches@gnu.org; Wed, 22 May 2024 10:53:57 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1s9nLu-0003tF-ME for guix-patches@gnu.org; Wed, 22 May 2024 10:54:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#71121] [PATCH 0/3] Update LibreWolf to 126.0-1 [security fixes] Resent-From: Ian Eure Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Wed, 22 May 2024 14:54:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 71121 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 71121@debbugs.gnu.org Cc: Ian Eure X-Debbugs-Original-To: guix-patches@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.171638963814940 (code B ref -1); Wed, 22 May 2024 14:54:02 +0000 Received: (at submit) by debbugs.gnu.org; 22 May 2024 14:53:58 +0000 Received: from localhost ([127.0.0.1]:56408 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1s9nLp-0003su-M0 for submit@debbugs.gnu.org; Wed, 22 May 2024 10:53:58 -0400 Received: from lists.gnu.org ([209.51.188.17]:59892) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1s9nLm-0003so-27 for submit@debbugs.gnu.org; Wed, 22 May 2024 10:53:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1s9nLf-0004vN-MU for guix-patches@gnu.org; Wed, 22 May 2024 10:53:47 -0400 Received: from wfhigh7-smtp.messagingengine.com ([64.147.123.158]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1s9nLd-0007RE-TX for guix-patches@gnu.org; Wed, 22 May 2024 10:53:47 -0400 Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailfhigh.west.internal (Postfix) with ESMTP id 640C2180011A; Wed, 22 May 2024 10:53:41 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute4.internal (MEProxy); Wed, 22 May 2024 10:53:41 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:message-id:mime-version:reply-to :subject:subject:to:to; s=fm3; t=1716389621; x=1716476021; bh=Q+ OWWG5+dD6gH//q0BMJomnsBBCRYu7CNc18eoJUK40=; b=S5ZYCIYHq6nT7anREY hQ0c0t7vIMh4y19ft45rq7+lSU+rqipYmz93NzSPvvVZCtJL1pgHviAwS9jXCgzC XDF++hDNGQ9g800kxDfQB+zcm2lgzw4Ai5RcNbJrbO/fnRWxVeqvnYAjwiBRmkdJ whQ02kvy0X2AmJdlumE0xvmC2hU9reppLCWKo6PtOwWTZOA1r/DOzT96kmoG373A J7y2704Da5YMRzFtsD5ddH+xiP0kpsHrj83tMi1fdVwXwxxDTrxrjl7jdbC2hwWm zeCybTqEZHVq5kDemI6jHeErAMbTNUtmXxjCySciRaWyrHWFRNaHkfPRFZ5bw750 pBPQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:message-id:mime-version:reply-to:subject :subject:to:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm1; t=1716389621; x=1716476021; bh=Q+OWWG5+dD6gH //q0BMJomnsBBCRYu7CNc18eoJUK40=; b=F2fYDRpXMNN2Rhf9etRfEtOC+3tqJ 6GjdzoxDuPjNTSBvNn8IIT6CWKqerlRn12nW7y0z/IlyOqL261eW/lEnUV/88RRU gHxRC6VqPvTVywaVd+WzcYbL1ypNe4kZcjLMbv6nAe0GfaBowFzn50jyvEnxkpS5 btTXpq5pTCAe0wf5ME34HA04FxCvSUhvtisQD2ZHfZ0i9f17Py/hEBDU3OjSC0tU EydY5k2JVcX4Jq4RtYlro9sT7yzZhfnezCs7S53bg469dMtqMHi8qCi1+O+hPImF RM95uDmkXJaD24B6YbsSb7YOwkTzndz7Ituuqg6w3hSVxhwL3vlqxOxmg== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvledrvdeigedgvddtucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefhvfevufffkffogggtgfesthekre dtredtjeenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhesrhgvthhrohhsphgvtgdr thhvqeenucggtffrrghtthgvrhhnpefgueekffejudfgvdevteelteeitdeuuddufffhue fhiefhjeetuefhgfettedvteenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhep mhgrihhlfhhrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvh X-ME-Proxy: Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 22 May 2024 10:53:40 -0400 (EDT) From: Ian Eure Date: Wed, 22 May 2024 07:53:00 -0700 Message-ID: <20240522145300.31060-1-ian@retrospec.tv> X-Mailer: git-send-email 2.41.0 MIME-Version: 1.0 Received-SPF: pass client-ip=64.147.123.158; envelope-from=ian@retrospec.tv; helo=wfhigh7-smtp.messagingengine.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches This patch series changes how LibreWolf is built, and updates it to 126.0-1, which contains fixes for: CVE-2024-4367, CVE-2024-4764, CVE-2024-4765, CVE-2024-4766, CVE-2024-4767, CVE-2024-4768, CVE-2024-4769, CVE-2024-4770, CVE-2024-4771, CVE-2024-4772, CVE-2024-4773, CVE-2024-4774, CVE-2024-4775, CVE-2024-4776, CVE-2024-4777, CVE-2024-4778. Previously, LibreWolf has built from the upstream source release tarballs, which are generated with an automated process: a script downloads the Firefox source, patches it, and repacks it into the LibreWolf source tarball. This process is now automated into the Guix package builds, so things are built directly from the LibreWolf source repo and Firefox upstream release tarball. This is how IceCat builds, and means we don't have to trust the results of an external build process. This necessitated making all-mozilla-locales public in (gnu packages gnuzilla), and adding the Santali locale to it. LibreWolf 126.0-1 backports a fix for the encoding_rs library, needed to make it build on newer versions of Rust. Unfortunately, this also fails to build on Rust 1.75, which is what's currently in Guix. It was necessary to back this out to get things building, and it'll likely need to be reapplied once the rust-team branch merges. Ian Eure (3): gnu: all-mozilla-locales: Add Santali locale; make public. gnu: librewolf: Rebuild source tarball gnu: librewolf: Update to 126.0-1. gnu/packages/gnuzilla.scm | 3 +- gnu/packages/librewolf.scm | 127 +++++++++++++++++++++++++++++++++---- 2 files changed, 116 insertions(+), 14 deletions(-)