Re: GNU Automake 1.12.1 released

2012-07-09 Thread Jim Meyering
Stefano Lattarini wrote: > On 07/06/2012 12:10 AM, Diego Elio Pettenò wrote: >> Il 05/07/2012 11:26, Stefano Lattarini ha scritto: >>> How so? Removal of $(mkdir_p) is only planned for Automake 1.13, that is >>> still unreleased. >> >> Ehm Stefano, that's definitely not the case, I've been hitting

Re: GNU Automake 1.12.1 released

2012-07-09 Thread Stefano Lattarini
On 07/09/2012 09:22 AM, Jim Meyering wrote: > > Hi Stefano, > > I see that @mkdir_p@ is used in gettext's Makefile.in.in template: > > # We use $(mkdir_p). > # In automake <= 1.9.x, $(mkdir_p) is defined either as "mkdir -p --" or as > # "$(mkinstalldirs)" or as "$(install_sh) -d". For thes

Re: GNU Automake 1.12.1 released

2012-07-09 Thread Jim Meyering
Stefano Lattarini wrote: > On 07/09/2012 09:22 AM, Jim Meyering wrote: >> >> Hi Stefano, >> >> I see that @mkdir_p@ is used in gettext's Makefile.in.in template: >> >> # We use $(mkdir_p). >> # In automake <= 1.9.x, $(mkdir_p) is defined either as "mkdir -p --" or as >> # "$(mkinstalldirs)" o

Re: GNU Automake 1.12.1 released

2012-07-09 Thread Stefano Lattarini
On 07/09/2012 11:17 AM, Jim Meyering wrote: >> >> - - The long-obsolete (since automake 1.10) @mkdir_p@ configure-time >> -substitution and AM_PROG_MKDIR m4 macro will be removed in Automake >> -1.13. The $(mkdir_p) should still remain available for the moment >> -though. >> + - The

Re: GNU Automake 1.12.1 released

2012-07-09 Thread Stefano Lattarini
On 07/09/2012 11:45 AM, Stefano Lattarini wrote: > On 07/09/2012 11:17 AM, Jim Meyering wrote: >>> >>> - - The long-obsolete (since automake 1.10) @mkdir_p@ configure-time >>> -substitution and AM_PROG_MKDIR m4 macro will be removed in Automake >>> -1.13. The $(mkdir_p) should still remai

Re: GNU Automake 1.12.1 released

2012-07-09 Thread Jim Meyering
Stefano Lattarini wrote: > On 07/09/2012 11:45 AM, Stefano Lattarini wrote: >> On 07/09/2012 11:17 AM, Jim Meyering wrote: - - The long-obsolete (since automake 1.10) @mkdir_p@ configure-time -substitution and AM_PROG_MKDIR m4 macro will be removed in Automake -1.13.

Re: GNU Automake 1.12.1 released

2012-07-09 Thread Stefano Lattarini
On 07/09/2012 12:04 PM, Jim Meyering wrote: > Stefano Lattarini wrote: > >> - - Automake generated Makefiles define once again the $(mkdir_p) make >> -variable (simple ans an alias for $(MKDIR_P)), for better backward >> -compatibility. The '@mkdir_p@' substitution is however not en

GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Stefano Lattarini
This message announces the Automake 1.11.6 bug-fixing release. This release FIXES A SECURITY VULNERABILITY (CVE-2012-3386), so you are strongly encouraged to upgrade your existing Automake installation ASAP. With this release, the recipe of the 'distcheck' target no longer grants temporary world-

GNU Automake 1.12.2 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Stefano Lattarini
We are pleased to announce the Automake 1.12.2 maintenance release. This release FIXES A SECURITY VULNERABILITY (CVE-2012-3386; see the NEWS excerpt below for details), so you are strongly encouraged to upgrade your existing Automake installation ASAP. See below for the detailed list of changes s

CVE-2012-3386 Automake security fix for 'make distcheck'

2012-07-09 Thread Stefano Lattarini
GNU Automake 1.12.2 as well as 1.11.6 fix a locally-exploitable security-related race condition that affects "make distcheck" for all packages that use Automake. Before the fix, the recipe of the 'distcheck' target granted temporary world-write permissions on the extracted distdir. This introduce

Re: GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Stefano Lattarini
Hi Dmitry. On 07/09/2012 11:34 PM, Dmitry V. Levin wrote: > On Mon, Jul 09, 2012 at 06:14:03PM +0200, Stefano Lattarini wrote: >> This message announces the Automake 1.11.6 bug-fixing release. > > Could you push refs/heads/branch-1.11 > This branch is not active anymore, having been discontinued

Re: GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Eric Dorland
* Stefano Lattarini (stefano.lattar...@gmail.com) wrote: > This message announces the Automake 1.11.6 bug-fixing release. > > This release FIXES A SECURITY VULNERABILITY (CVE-2012-3386), so you are > strongly encouraged to upgrade your existing Automake installation ASAP. > > With this release, t

Re: GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Stefano Lattarini
On 07/10/2012 12:14 AM, Eric Dorland wrote: > > Are older versions of automake also vulnerable? > Yes, all those back to 1.4 (at least). Sorry for not stating that explicitly. Regards, Stefano

Re: GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Eric Dorland
* Stefano Lattarini (stefano.lattar...@gmail.com) wrote: > On 07/10/2012 12:14 AM, Eric Dorland wrote: > > > > Are older versions of automake also vulnerable? > > > Yes, all those back to 1.4 (at least). Sorry for not stating that > explicitly. Awesome :) Is there a diff or git commit I can loo

Re: GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Stefano Lattarini
On 07/10/2012 12:40 AM, Eric Dorland wrote: > * Stefano Lattarini (stefano.lattar...@gmail.com) wrote: >> On 07/10/2012 12:14 AM, Eric Dorland wrote: >>> >>> Are older versions of automake also vulnerable? >>> >> Yes, all those back to 1.4 (at least). Sorry for not stating that >> explicitly. >

Re: GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Dmitry V. Levin
On Mon, Jul 09, 2012 at 06:14:03PM +0200, Stefano Lattarini wrote: > This message announces the Automake 1.11.6 bug-fixing release. Could you push refs/heads/branch-1.11 and refs/tags/v1.11.6, please? -- ldv pgpSNpKS9vUsV.pgp Description: PGP signature

Re: GNU Automake 1.11.6 released (fixes a SECURITY VULNERABILITY!)

2012-07-09 Thread Dmitry V. Levin
Hi, On Tue, Jul 10, 2012 at 12:08:38AM +0200, Stefano Lattarini wrote: > Hi Dmitry. > > On 07/09/2012 11:34 PM, Dmitry V. Levin wrote: > > On Mon, Jul 09, 2012 at 06:14:03PM +0200, Stefano Lattarini wrote: > >> This message announces the Automake 1.11.6 bug-fixing release. > > > > Could you push