Re: Hurd Security vulnerabilities, please upgrade!

2021-08-11 Thread Ludovic Courtès
Hi Samuel,

Samuel Thibault  skribis:

> Ricardo Wurmus, le mar. 10 août 2021 17:52:34 +0200, a ecrit:
>> I’m a little unclear on what this means for distributions like Guix.  Should
>> we just update to the latest version from git?  Are there specific commits
>> we should use if it’s not just the latest?
>
> Since Sergey's copyright assignment is not complete yet, it's not
> commited yet, so you have to pick up the patches from the debian
> repository.

It would be interesting to consider dropping the copyright assignment
requirement for Hurd/Mach/MiG.  For what remains primarily a hobby
project, this looks to me like a hindrance more than anything else.

Ludo’.



Re: Hurd Security vulnerabilities, please upgrade!

2021-08-10 Thread Samuel Thibault
Ricardo Wurmus, le mar. 10 août 2021 17:52:34 +0200, a ecrit:
> I’m a little unclear on what this means for distributions like Guix.  Should
> we just update to the latest version from git?  Are there specific commits
> we should use if it’s not just the latest?

Since Sergey's copyright assignment is not complete yet, it's not
commited yet, so you have to pick up the patches from the debian
repository.

Samuel



Re: Hurd Security vulnerabilities, please upgrade!

2021-08-10 Thread Ricardo Wurmus



Hi Samuel,

In the past months, Sergey Bugaev has been working on fixing 
some
Hurd security vulnerabilities. This is now fixed in the latest 
Debian

packages, so please upgrade and reboot!


Thanks for the fixes and the heads-up!


hurd >= 1:0.9.git20210404-9
libc0.3 >= 2.31-13+hurd.1
gnumach-image-1.8-* >= 2:1.8+git20210809-1


I’m a little unclear on what this means for distributions like 
Guix.  Should we just update to the latest version from git?  Are 
there specific commits we should use if it’s not just the latest?


Thanks!

--
Ricardo