Hi Mark, Mark H Weaver <m...@netris.org> skribis:
> I've just rebuilt my x86_64 GuixSD system to use 'openjpeg' from git > (since I see many more fixes there that look security-relevant), and to > use this fresh openjpeg in both 'poppler' and 'tracker'. Unfortunately, > the 'poppler' change required a massive rebuild, but with these updates > my system seems to work just fine. > > I've attached my preliminary patches. > > Mark > > From abd9df8c4623cc44ef77be69977e2635c0fdd3bf Mon Sep 17 00:00:00 2001 > From: Mark H Weaver <m...@netris.org> > Date: Mon, 4 Sep 2017 23:48:55 -0400 > Subject: [PATCH 1/3] gnu: openjpeg: Update to 2.2.0-1.3a382d312. > > * gnu/packages/image.scm (openjpeg): Switch to using a git checkout, and > update to 2.2.0-1.3a382d312. Remove patches. > * gnu/packages/patches/openjpeg-CVE-2017-12982.patch, > gnu/packages/patches/openjpeg-CVE-2017-14040.patch, > gnu/packages/patches/openjpeg-CVE-2017-14041.patch, > gnu/packages/patches/openjpeg-CVE-2017-14151.patch, > gnu/packages/patches/openjpeg-CVE-2017-14152.patch: Delete files. > * gnu/local.mk (dist_patch_DATA): Remove them. Should we graft this openjpeg variant? “openjpeg@1” has 1,810 dependents. Thanks for the heads-up, and apologies for the delay! Ludo’.