guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

xwayland security updates, to mesa- or core-updates or ?


From: John Kehayias
Subject: xwayland security updates, to mesa- or core-updates or ?
Date: Fri, 15 Dec 2023 06:21:44 +0000

Hi Guix,

In light of (more) CVEs in xwayland, see
<https://lists.x.org/archives/xorg-announce/2023-December/003435.html>,
with already pending security updates, see
<https://issues.guix.gnu.org/67136>, I would like to prioritize
getting that fixed in master. The tricky thing is that, according to
67136, the xwayland update needs newer xorgproto, which corresponds to
many rebuilds. (The related CVEs in xorg-server have been pushed
already as effectively minor version bumps.)

Where is the most efficient branch for this, that could take these
rebuilds to be merged to master soon (whatever soon is for a scope of
something like 22k affected packages)?

I was thinking to put that update and mesa, since it had a new stable
release after the current one never got updates, on mesa-updates and
merge once builds are done assuming no issues. Again, the potential
sore spot is xorgproto I would say. I could see about any other
pending/urgent related changes, but I'm not aware of any off the top
of my head and want to let this move quickly. I also don't want to
jump the queue sending other branches to rebuild everything again.

I'll test things locally in the meantime, but please chime in. If I
don't hear anything too urgent I'll update the mesa-updates branch to
start builds at least. I've also cc'ed some names I think will be
knowledgeable about some current branches.

And thanks to Kaelyn (also cc'ed) for the pending xwayland patches!

Thanks!
John




reply via email to

[Prev in Thread] Current Thread [Next in Thread]