From patchwork Thu Jan 10 21:08:19 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Kei Kebreau X-Patchwork-Id: 715 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 52DA216A58; Thu, 10 Jan 2019 21:19:03 +0000 (GMT) X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,T_DKIM_INVALID, URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.0 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTP id C5A2316A54 for ; Thu, 10 Jan 2019 21:19:00 +0000 (GMT) Received: from localhost ([127.0.0.1]:36867 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ghhjA-0006ze-1V for patchwork@mira.cbaines.net; Thu, 10 Jan 2019 16:19:00 -0500 Received: from eggs.gnu.org ([209.51.188.92]:52109) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ghhgF-0004oc-Lq for guix-patches@gnu.org; Thu, 10 Jan 2019 16:16:02 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ghhZa-0006cP-K4 for guix-patches@gnu.org; Thu, 10 Jan 2019 16:09:08 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:55028) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1ghhZW-0006bO-TU for guix-patches@gnu.org; Thu, 10 Jan 2019 16:09:05 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1ghhZW-00010W-HE for guix-patches@gnu.org; Thu, 10 Jan 2019 16:09:02 -0500 X-Loop: help-debbugs@gnu.org Subject: [bug#34036] [PATCH] gnu: irssi: Update to 1.1.2 [fixes CVE-2019-5882]. Resent-From: Kei Kebreau Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Thu, 10 Jan 2019 21:09:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 34036 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Leo Famulari Received: via spool by 34036-submit@debbugs.gnu.org id=B34036.15471545173840 (code B ref 34036); Thu, 10 Jan 2019 21:09:02 +0000 Received: (at 34036) by debbugs.gnu.org; 10 Jan 2019 21:08:37 +0000 Received: from localhost ([127.0.0.1]:54309 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ghhZ7-0000zs-Cs for submit@debbugs.gnu.org; Thu, 10 Jan 2019 16:08:37 -0500 Received: from mout01.posteo.de ([185.67.36.65]:57264) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1ghhZ1-0000zX-UT for 34036@debbugs.gnu.org; Thu, 10 Jan 2019 16:08:36 -0500 Received: from submission (posteo.de [89.146.220.130]) by mout01.posteo.de (Postfix) with ESMTPS id BE76F160069 for <34036@debbugs.gnu.org>; Thu, 10 Jan 2019 22:08:22 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.net; s=2017; t=1547154502; bh=u3yCOjZEOttG0auh4T9j6z/799mPPGJcaBrIPHuWbWs=; h=From:To:Cc:Subject:Date:From; b=jYwOZ1s4sLdkkrmEpTO0L9153kotlyki/p6eVs1CGck3485GZu0kjHHRwl/W3Ke1Z QluUAi6VxOTZctzEO5+Drp1W36VAhw7xwNsxoMPsJi1PtkFQfoUPfKLopAwx/3deiy 0BiGta402KKvrMVbpCf9dRVT6SjujFu7vSvTBS2cvjW4mhnjLAekCobkS3FFIGQV8u M7S7jn4B8rJrB/p+sHBOQRZnFq0306Mm5qGdsl08uTO7X1RgSRB1REj8cylC6Bsl1a mUYiT6NIB4RLcNFvPM4vUQDeqQUYQBwVFwQUAl5StNuHV5hZuyWLB2WTfrtdM3d4Ts h5mmsCFmh/HOw== Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 43bJW84c3rz6tmD; Thu, 10 Jan 2019 22:08:20 +0100 (CET) From: Kei Kebreau References: <20190110180320.26004-1-kkebreau@posteo.net> <20190110200501.GA14234@jasmine.lan> Date: Thu, 10 Jan 2019 16:08:19 -0500 In-Reply-To: <20190110200501.GA14234@jasmine.lan> (Leo Famulari's message of "Thu, 10 Jan 2019 15:05:01 -0500") Message-ID: <87lg3sdxvg.fsf@posteo.net> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.1 (gnu/linux) MIME-Version: 1.0 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 209.51.188.43 X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: 34036@debbugs.gnu.org Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: "Guix-patches" X-getmail-retrieved-from-mailbox: Patches Oh, it's not an auto-generated tarball! In that case I've attached the much simpler update patch. Leo Famulari writes: > On Thu, Jan 10, 2019 at 01:03:20PM -0500, Kei Kebreau wrote: >> * gnu/packages/irc.scm (irssi): Update to 1.1.2. >> [source]: Use 'git-fetch'. >> [arguments]: Add 'patch-scripts' phase. >> [native-inputs]: Add autoconf, automake, and libtool. > > Thanks! > > But why switch to git-fetch when they offer a tarball? All else being > equal, we should stick to tarballs when they are offered by upstream. > > Specifically, let's use this one: > > https://github.com/irssi/irssi/releases/download/1.1.2/irssi-1.1.2.tar.xz From c954fe6622660f1511ced2be955c35acfb8b124a Mon Sep 17 00:00:00 2001 From: Kei Kebreau Date: Thu, 10 Jan 2019 12:56:04 -0500 Subject: [PATCH] gnu: irssi: Update to 1.1.2 [fixes CVE-2019-5882]. * gnu/packages/irc.scm (irssi): Update to 1.1.2. --- gnu/packages/irc.scm | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/gnu/packages/irc.scm b/gnu/packages/irc.scm index ba31d36b9..ec1c4aae9 100644 --- a/gnu/packages/irc.scm +++ b/gnu/packages/irc.scm @@ -126,15 +126,15 @@ irssi, but graphical.") (define-public irssi (package (name "irssi") - (version "1.1.1") + (version "1.1.2") (source (origin - (method url-fetch) - (uri (string-append "https://github.com/irssi/irssi/" - "releases/download/" version "/irssi-" - version ".tar.xz")) - (sha256 - (base32 - "1gx1flfh4a09nb3b5pvf0ygnbl7rry3l4gph8wij29dsl7khfj3q")))) + (method url-fetch) + (uri (string-append "https://github.com/irssi/irssi/" + "releases/download/" version "/irssi-" + version ".tar.xz")) + (sha256 + (base32 + "0clppwqhllrmqjg1dd47v9v1qiqx7cf9afm81bm1pscllf4jpk2w")))) (build-system gnu-build-system) (arguments `(#:phases