[bug#74176] gnu: libvpx: Update to 1.15.0.

Message ID 8d5e005a77ed870591b5e99349e5e3486b950bfd.1730554273.git.ashish.is@lostca.se
State New
Headers
Series [bug#74176] gnu: libvpx: Update to 1.15.0. |

Commit Message

tusharhero--- via Guix-patches via Nov. 2, 2024, 1:31 p.m. UTC
From: Ashish SHUKLA <ashish.is@lostca.se>

* gnu/packages/video.scm (libvpx): Update to 1.15.0.

Change-Id: I52213edadb56b8a65394281103dde528173cd7b3
---
 gnu/packages/video.scm | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)


base-commit: 20c7b8dd04e421a139a02438cf1ddfdfe544a446
  

Comments

Andreas Enge Nov. 20, 2024, 9:56 a.m. UTC | #1
Hello Ashish,

just a quick comment: When removing patches from a package, you also need
"git rm" the corresponding files, and to remove them from gnu/local.mk.

Well, just like in your commit 3c92a633c3f7aff0fe9fa3b056071bc7c9c72395 ;-)

So could you please send a version 2?

Indeed the number of dependent packages is a (separate) issue; unfortunately
we do not have a multimedia team or similar now.

Andreas
  
Ashish SHUKLA March 22, 2025, 1:28 p.m. UTC | #2
> Hello Ashish,
> 
> just a quick comment: When removing patches from a package, you also need
> "git rm" the corresponding files, and to remove them from gnu/local.mk.
> 
> Well, just like in your commit 3c92a633c3f7aff0fe9fa3b056071bc7c9c72395 ;-)
> 
> So could you please send a version 2?
> 
> Indeed the number of dependent packages is a (separate) issue; unfortunately
> we do not have a multimedia team or similar now.
> 
> Andreas

I'm sorry. It seems I missed your reply to this thread. I see my patch 
is committed[0], do we still need to keep this open ?

References:
[0] 
https://codeberg.org/guix/guix-mirror/commit/4c9d112831f49d69b4a90740f5e2fdd17f68fa17

Thanks!
  
Andreas Enge March 22, 2025, 1:47 p.m. UTC | #3
Hello,

Am Sat, Mar 22, 2025 at 01:28:31PM +0000 schrieb Ashish SHUKLA:
> I'm sorry. It seems I missed your reply to this thread. I see my patch is
> committed[0], do we still need to keep this open ?

I think I only learnt after sending my comment that debbugs does not
resend messages to the bug submitter and other people who have
contributed, so I did not cc you (usually I send all my messages "by hand"
to the bug number).

Very mysteriously, the CVE patch still applies, even to the latest git
checkout with a commit from ten days ago! So I think we should just keep
it in, and I am closing this bug.

Andreas
  

Patch

diff --git a/gnu/packages/video.scm b/gnu/packages/video.scm
index ff5dcd8daa..5d681f1c28 100644
--- a/gnu/packages/video.scm
+++ b/gnu/packages/video.scm
@@ -2959,7 +2959,7 @@  (define-public mpv-mpris
 (define-public libvpx
   (package
     (name "libvpx")
-    (version "1.12.0")
+    (version "1.15.0")
     (source (origin
               (method git-fetch)
               (uri (git-reference
@@ -2968,9 +2968,7 @@  (define-public libvpx
               (file-name (git-file-name name version))
               (sha256
                (base32
-                "1x12f2bd4jqd532rnixmwvcx8d29yxiacpcxqqh86qczc49la8gm"))
-              (patches (search-patches "libvpx-CVE-2016-2818.patch"
-                                       "libvpx-CVE-2023-5217.patch"))))
+                "1q2scpfiifhpilw6qqpqihk98plj57gwh0vyiqwsv991i7b322bv"))))
     (build-system gnu-build-system)
     (arguments
      `(#:configure-flags (list "--enable-shared"