bug#47154: ungoogled-chromium@88.0.4324.182 package vulnerable to various severe CVEs

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
Fixed by 1155a88308df7649fe74bd5bb8279a4d103ce386 signature.asc Description: This is a digitally signed message part

bug#47228: Check binary consistency after grafting with e.g. ldd

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
On Thu, 2021-03-18 at 14:38 +0100, Ludovic Courtès wrote: > I don’t think all the testing that needs to be done when grafting can > be > automated. Not all but part of it? > In particular, packagers who want to introduce a replacement for a > library should use libabigail’s ‘abi-diff’ tool to che

bug#47230: Build phase to graft during build for better grafts QA

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
On Thu, 2021-03-18 at 21:41 +0100, Ludovic Courtès wrote: > I think it’s more of a discussion for guix-devel than a bug > report. :-) Yes but then I was thinking how do we track progress without losing it in the pile of emails from guix-devel people receive everyday which made me create a bug in

bug#47256: generic-html updater does not work for mediainfo package

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
Hello! $ ./pre-inst-env guix refresh mediainfo gnu/packages/video.scm:3852:2: warning: 'generic-html' updater failed to determine available releases for mediainfo I tried adding a release-monitoring-url and hardcoding the name into the url instead of using the variable 'name' but that did not hel

bug#47257: mariadb is vulnerable to CVE-2021-27928 (RCE)

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
CVE-2021-27928 04:15 A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection,

bug#47259: python-pillow-simd package vulnerable to at least CVE-2021-25293

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
Hello! pillow-simd is a fork of pillow ( https://github.com/uploadcare/pillow-simd), it's currently still at version 7.x and it does not seem like it backports security patches from pillow. $ ./pre-inst-env guix refresh -l python-pillow-simd No dependents other than itself: python-pillow-simd@7.1

bug#47228: Check binary consistency after grafting with e.g. ldd

2021-03-19 Thread Ludovic Courtès
Hi, Léo Le Bouter skribis: > On Thu, 2021-03-18 at 14:38 +0100, Ludovic Courtès wrote: >> I don’t think all the testing that needs to be done when grafting can >> be >> automated. > > Not all but part of it? Not even sure; at least I don’t have any ideas. >> In particular, packagers who want t

bug#47257: mariadb is vulnerable to CVE-2021-27928 (RCE)

2021-03-19 Thread Julien Lepiller
You need to graft: when building a package, the output hash depends on the inputs, sources and instructions, so even if the content of the lib output does not change, its store path does, leading to a rebuild. Le 19 mars 2021 06:25:31 GMT-04:00, "Léo Le Bouter via Bug reports for GNU Guix" a é

bug#47257: [PATCH 1/1] gnu: mariadb: Update to 10.5.9 [fixes CVE-2021-27928].

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
* gnu/packages/databases.scm (mariadb/fixed): New variable. (mariadb)[replacement]: Graft. --- gnu/packages/databases.scm | 33 + 1 file changed, 33 insertions(+) diff --git a/gnu/packages/databases.scm b/gnu/packages/databases.scm index 8be83f5cbe..6fdb22d7fb 1006

bug#47257: [PATCH 0/1] gnu: mariadb: Update to 10.5.9 [fixes CVE-2021-27928].

2021-03-19 Thread Léo Le Bouter via Bug reports for GNU Guix
I made a patch, please review and push if you think that's OK, I will otherwise push it myself after some time. The patch produces some test error, not sure if deterministic, looks related to networking disabled in build sandboxes, log: The servers were restarted 778 times Spent 6689.041 of 234 s

bug#47257: mariadb is vulnerable to CVE-2021-27928 (RCE)

2021-03-19 Thread zimoun
Hi, On Fri, 19 Mar 2021 at 11:25, Léo Le Bouter via Bug reports for GNU Guix wrote: > Is it possible to graft mariadb you think? I am thinking this issue > doesnt need updating of the "lib" output which is what's causing the > high number of dependents AIUI. I am not sure we could actually upda

bug#47253: network-manager shepherd services does not wait to be online

2021-03-19 Thread Mark H Weaver
Hi, raid5atemyhomework via Bug reports for GNU Guix writes: > I have a small number of daemons that need access to the network at > startup. I have configured their Shepherd services to require > `networking`. > > However, to my puzzlement, I consistently find that they are unable to > access t

bug#47260: Package GNU MediaGoblin as a Guix service

2021-03-19 Thread Ben Sturmfels via Bug reports for GNU Guix
This is a "meta" bug to keep track of the progress of packaging GNU MediaGoblin, a platform for publishing images/audio/video etc. See https://mediagoblin.org/ We have a guix-env.scm in the upstream source which should always have the latest copy of our packaging progress and instructions to run i

bug#47258: guix pull bug: the program '/gnu/store/...-compute-guix-derivation' failed to compute the derivation for Guix

2021-03-19 Thread zimoun
Hi Pierre, On Fri, 19 Mar 2021 at 11:25, Pierre Neidhardt wrote: > --8<---cut here---start->8--- > $ guix pull [...] > @ substituter-succeeded > /gnu/store/1nxd28y29f0ksmbplbrshkc71bky2g8n-gnutls-3.6.15-debug > substitute: updating substitutes from 'https:/

bug#47258: guix pull bug: the program '/gnu/store/...-compute-guix-derivation' failed to compute the derivation for Guix

2021-03-19 Thread Maxime Devos
On Fri, 2021-03-19 at 14:01 +0100, Pierre Neidhardt wrote: > --fallback fails as well :( > As a work-around, maybe try --no-substitutes to *not* built any sources *at all*, in which case the network should only be consulted for downloading source code? signature.asc Description: This is a digi

bug#47020: [PATCH 1/4] gnu: gnu-make-boot0: Don't include debug output.

2021-03-19 Thread Efraim Flashner
On Thu, Mar 18, 2021 at 10:26:27PM +0100, Ludovic Courtès wrote: > Hi Efraim, > > Efraim Flashner skribis: > > > * gnu/packages/commencement.scm (gnu-make-boot0)[outputs]: Remove debug > > from inherited outputs. > > Make sure nothing inherits from these packages, in which case we might > inadv

bug#40442: [EXT] bug#40442: srt2vtt does not work

2021-03-19 Thread Thompson, David
Reviving this old issue. On Sat, Apr 4, 2020 at 6:59 PM sirgazil via Bug reports for GNU Guix wrote: > > I installed srt2vtt but it errors when I run it. > > > ## Steps to reproduce > > 1. Run "guix install srt2vtt" > 2. Run "srt2vtt --help" > > > ## Expected result > > I can see the help informa

bug#47253: network-manager shepherd services does not wait to be online

2021-03-19 Thread raid5atemyhomework via Bug reports for GNU Guix
Hello Mark, > > Of course, the big problem is that Shepherd is single-threadded and > > `nm-online` will block all other bootup. > > That's not good. For the sake of users who are not always connected to > the internet, I'd strongly prefer for the Guix boot process of a desktop > system to not be

bug#47265: Guix System: improve support for intentional statefullness.

2021-03-19 Thread Vitaliy Shatrov via Bug reports for GNU Guix
Recently i saw WebKit failing to build on Cuirass. For Guix System it ought to be in the Manual: "Setting up FHS for auxiliary applications obtained from upstream Free binaries". This way Joe has a base system which is obviously important to keep reprobuilt. Then Joe happily pile things on top o

bug#47192: issues.guix.org not showing patch series?

2021-03-19 Thread Joshua Branson via Bug reports for GNU Guix
I gather that this is not a very common bug. So I suppose we'll close this bug. Thanks for your quick response Tobias! -- Joshua Branson (joshuaBPMan in #guix) Sent from Emacs and Gnus https://gnucode.me https://video.hardlimit.com/accounts/joshua_branson/video-channels https://properna

bug#40442: srt2vtt does not work

2021-03-19 Thread sirgazil via Bug reports for GNU Guix
Problem solved. Thanks, Dave. P.S. I think you forgot to bump the version in the script. $ srt2vtt --version srt2vtt 0.1

bug#47260: Package GNU MediaGoblin as a Guix service

2021-03-19 Thread jgart
This sounds like a great project. I would love MediaGoblin to be in Guix also. > 6. Rewrite MediaGoblin's JavaScript code not to use jQuery. Maybe > improve the no-bundled-JavaScript video/audio playing experience. What are your thoughts on rewriting the jquery? Should MediaGoblin be using vani

bug#47266: guix pull: error (substituter)

2021-03-19 Thread Christoph Schumacher
Dear guix! I run guix on Debian stable, and guix asked me to report this error. I already tried to run the garbage collector and re-run guix pull, and that actually changed the error message to suggest --fallback. But that failed, too, and the resulting output is below. I am unsure how to proceed

bug#47266: guix pull: error (substituter)

2021-03-19 Thread Brian Zwahr
I was pointed to this issue from the IRC channel. I am also experiencing similar "bad response" errors during `guix pull` and `guix upgrade`. Thanks to help from IRC, I was able to sort of work around the issue by simply brute-forcing the commands, running them over and over again until they co

bug#47266: guix pull: error (substituter)

2021-03-19 Thread Ludovic Courtès
Hi Christoph, Christoph Schumacher skribis: > I run guix on Debian stable, and guix asked me to report this error. > I already tried to run the garbage collector and re-run guix pull, > and that actually changed the error message to suggest --fallback. > But that failed, too, and the resulting o

bug#47266: guix pull: error (substituter)

2021-03-19 Thread Christoph Schumacher
On Fri, Mar 19, 2021 at 09:12:24PM +0100, Ludovic Courtès wrote: > Hi Christoph, > > Christoph Schumacher > skribis: > > > I run guix on Debian stable, and guix asked me to report this error. > > I already tried to run the garbage collector and re-run guix pull, > > and that actually changed the

bug#46779: GnuTLS uses the hard-coded /etc/ssl/certs location for TLS certificates

2021-03-19 Thread Mark H Weaver
Ludovic Courtès writes: > Maxim Cournoyer skribis: > >> We should patch GnuTLS so that it also honors the SSL_* environment >> variables documented in the Guix manual. > > Note that (1) the SSL_* variables are originally from OpenSSL, and (2) > GnuTLS developers made the conscious decision to no

bug#47271: guix graph --path results in backtrace

2021-03-19 Thread Mark H Weaver
This is at commit 1955ef93b76e51cab5bed4c90f7eb9df7035355a on the master branch, plus some local patches on my private branch which I suspect are irrelevant to this: --8<---cut here---start->8--- mhw@jojen ~$ guix graph --path gtk+ imagemagick Backtrace: In ice-

bug#47257: [PATCH 1/1] gnu: mariadb: Update to 10.5.9 [fixes CVE-2021-27928].

2021-03-19 Thread Mark H Weaver
Hi Léo, Léo Le Bouter via Bug reports for GNU Guix writes: > * gnu/packages/databases.scm (mariadb/fixed): New variable. > (mariadb)[replacement]: Graft. > --- > gnu/packages/databases.scm | 33 + > 1 file changed, 33 insertions(+) > > diff --git a/gnu/packages/d

bug#47257: [PATCH 1/1] gnu: mariadb: Update to 10.5.9 [fixes CVE-2021-27928].

2021-03-19 Thread Mark H Weaver
Mark H Weaver writes: > 'package/inherit' is usually the right thing when defining other kinds > of package variants, however. One addendum to this guideline: if the package variant you're defining overrides the 'source' field[*], it's probably pointless to use 'package/inherit', because the fixe

bug#47271: guix graph --path results in backtrace

2021-03-19 Thread Julien Lepiller
Sounds like you might have stale .go files somewhere maybe? Le 19 mars 2021 20:01:44 GMT-04:00, Mark H Weaver a écrit : >This is at commit 1955ef93b76e51cab5bed4c90f7eb9df7035355a on the >master >branch, plus some local patches on my private branch which I suspect >are >irrelevant to this: > >--8