bug#27429: Stack clash (CVE-2017-1000366 etc)

2017-06-21 Thread Mark H Weaver
Leo Famulari writes: > On Wed, Jun 21, 2017 at 07:52:27PM -0400, Leo Famulari wrote: >> On Wed, Jun 21, 2017 at 12:50:45PM +0300, Efraim Flashner wrote: >> > Had to make a small change to the patch, it turns out it couldn't build >> > the source for glibc@2.21, so I changed the source to inherit

bug#27437: Source downloader accepts X.509 certificate for incorrect domain

2017-06-21 Thread Leo Famulari
On Wed, Jun 21, 2017 at 12:50:15PM +0200, Ludovic Courtès wrote: > Leo Famulari skribis: > > While working on some package updates, I found that the source code > > downloader will accept an X.509 certificate for an incorrect site. [...] > IOW, since we’re checking the integrity of the tarball a

bug#27429: Stack clash (CVE-2017-1000366 etc)

2017-06-21 Thread Leo Famulari
On Wed, Jun 21, 2017 at 07:52:27PM -0400, Leo Famulari wrote: > On Wed, Jun 21, 2017 at 12:50:45PM +0300, Efraim Flashner wrote: > > Had to make a small change to the patch, it turns out it couldn't build > > the source for glibc@2.21, so I changed the source to inherit from > > glibc@2.22 and not

bug#27429: Stack clash (CVE-2017-1000366 etc)

2017-06-21 Thread Leo Famulari
On Wed, Jun 21, 2017 at 12:50:45PM +0300, Efraim Flashner wrote: > Had to make a small change to the patch, it turns out it couldn't build > the source for glibc@2.21, so I changed the source to inherit from > glibc@2.22 and not just from glibc. It doesn't change anything for the > actual glibc@2.2

bug#27425: closing

2017-06-21 Thread Mekeor Melire

bug#27425: substitute queries never finish

2017-06-21 Thread Mekeor Melire
Joshua Sierles writes: > Since a couple days ago, many attempts to run 'guix package' or 'guix > pack' lead to: > substitute: updating list of substitutes from > 'https://mirror.hydra.gnu.org'... 100.0% > This fetching stops after a few lines and never finishes, even after > leaving it running

bug#27418: `guix pull` gets stuck at "updating substitutes from 'https://mirror.hydra.gnu.org'... 100.0%"

2017-06-21 Thread Ricardo Wurmus
Mekeor Melire writes: > Ludovic Courtès writes: >> Ricardo Wurmus skribis: >>> Mekeor Melire writes: >>> >>> I’m not sure but it may have been caused by a hung “guix publish” >>> process. >> >> Indeed, yesterday I realized ‘guix publish’ on hydra.gnu.org was stuck >> for unknown reasons, mean

bug#27418: `guix pull` gets stuck at "updating substitutes from 'https://mirror.hydra.gnu.org'... 100.0%"

2017-06-21 Thread Mekeor Melire
Ludovic Courtès writes: > Ricardo Wurmus skribis: >> Mekeor Melire writes: >> >> I’m not sure but it may have been caused by a hung “guix publish” >> process. > > Indeed, yesterday I realized ‘guix publish’ on hydra.gnu.org was stuck > for unknown reasons, meaning that it would not reply to HTT

bug#27437: Source downloader accepts X.509 certificate for incorrect domain

2017-06-21 Thread Ludovic Courtès
Hi, Leo Famulari skribis: > While working on some package updates, I found that the source code > downloader will accept an X.509 certificate for an incorrect site. > > Here is what happens: > > -- > $ ./pre-inst-env guix build -S opus-tools --check > @ build-started > /gnu/store/nn93hkik8k

bug#27430: linux-libre 4.4.47 is no longer available upstream

2017-06-21 Thread Ludovic Courtès
Hi Leo, Leo Famulari skribis: > Starting download of > /gnu/store/x8x9s119g1xhdxrzaka35lx4p45qd3vg-linux-libre-4.4.47-gnu.tar.xz > From ftp://alpha.gnu.org/gnu/guix/mirror/linux-libre-4.4.47-gnu.tar.xz... > ERROR: Throw to key `ftp-error' with args `(# "RETR > linux-libre-4.4.47-gnu.tar.xz" 55

bug#27418: `guix pull` gets stuck at "updating substitutes from 'https://mirror.hydra.gnu.org'... 100.0%"

2017-06-21 Thread Ludovic Courtès
Hello, Ricardo Wurmus skribis: > Mekeor Melire writes: > >> Following rekado's friendly advice, I was able to downgrade guix with: >> >> guix pull >> --url=https://git.savannah.gnu.org/cgit/guix.git/snapshot/01049bb0c1f3f69afb8d1782f99ca5c0adaed946.tar.gz >> --no-substitutes > > […] > >>

bug#27429: Stack clash (CVE-2017-1000366 etc)

2017-06-21 Thread Efraim Flashner
Had to make a small change to the patch, it turns out it couldn't build the source for glibc@2.21, so I changed the source to inherit from glibc@2.22 and not just from glibc. It doesn't change anything for the actual glibc@2.25. -- Efraim Flashner אפרים פלשנר GPG key = A28B F40C 3E55 1372 66

bug#27429: Stack clash (CVE-2017-1000366 etc)

2017-06-21 Thread Efraim Flashner
On Tue, Jun 20, 2017 at 05:44:42PM -0400, Mark H Weaver wrote: > Hi Efraim, > > Thanks so much for working on this! > > Grafting glibc is something we haven't done before to my knowledge, and > it is a bit tricky because of all of the inherited versions of glibc. > At present, those inherited ver

bug#27311: Acknowledgement (Enlightenment: 'cpufreq binary needs suid or has to be owned by root')

2017-06-21 Thread Ricardo Wurmus
ng0 writes: > Nix solved this particular issue (cpufreq) with a hack. > It's okay for me, but do some of you agree with applying this: > > # this is a hack and without this cpufreq module is not working. does the > following: > # 1. moves the "freqset" binary to "e_freqset", > # 2. li

bug#27418: `guix pull` gets stuck at "updating substitutes from 'https://mirror.hydra.gnu.org'... 100.0%"

2017-06-21 Thread Ricardo Wurmus
Mekeor Melire writes: > Following rekado's friendly advice, I was able to downgrade guix with: > > guix pull > --url=https://git.savannah.gnu.org/cgit/guix.git/snapshot/01049bb0c1f3f69afb8d1782f99ca5c0adaed946.tar.gz > --no-substitutes […] > Still, I wonder > * what caused this issue;