Ludovic Courtès <ludo@HIDDEN>
to control <at> debbugs.gnu.org
.
Full text available.Received: (at 48655) by debbugs.gnu.org; 26 May 2021 14:37:45 +0000 From debbugs-submit-bounces <at> debbugs.gnu.org Wed May 26 10:37:45 2021 Received: from localhost ([127.0.0.1]:49686 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>) id 1llufI-00007R-Sq for submit <at> debbugs.gnu.org; Wed, 26 May 2021 10:37:45 -0400 Received: from wp224.webpack.hosteurope.de ([80.237.132.231]:43608) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <mike@HIDDEN>) id 1llufG-00007F-0h for 48655 <at> debbugs.gnu.org; Wed, 26 May 2021 10:37:43 -0400 Received: from www.rohleder.de ([37.61.204.227]); authenticated by wp224.webpack.hosteurope.de running ExIM with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) id 1llufD-0005fw-V4; Wed, 26 May 2021 16:37:39 +0200 Received: from [192.168.1.3] (helo=micha) by www.rohleder.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94) (envelope-from <mike@HIDDEN>) id 1llufA-0005gL-PJ; Wed, 26 May 2021 16:37:39 +0200 From: Michael Rohleder <mike@HIDDEN> To: Solene Rapenne <solene@HIDDEN> Subject: Re: [bug#48655] [PATCH] gnu: synapse: Update to 1.33.2. References: <20210525183656.4d41ae04@HIDDEN> Date: Wed, 26 May 2021 16:37:33 +0200 In-Reply-To: <20210525183656.4d41ae04@HIDDEN> (Solene Rapenne via Guix-patches via's message of "Tue, 25 May 2021 18:36:56 +0200") Message-ID: <87im351ryq.fsf@HIDDEN> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux) MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-bounce-key: webpack.hosteurope.de;mike@HIDDEN;1622039862;f964e1e6; X-HE-SMSGID: 1llufD-0005fw-V4 X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 48655 Cc: 48655 <at> debbugs.gnu.org X-BeenThere: debbugs-submit <at> debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: <debbugs-submit.debbugs.gnu.org> List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe> List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/> List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org> List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help> List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe> Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org> X-Spam-Score: -1.7 (-) --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Hi Solene, Thank you for the patch! Solene Rapenne via Guix-patches via <guix-patches@HIDDEN> writes: > This fixes the DoS [CVE-2021-29471] and many other improvements > > I didn't try it, I don't have a matrix server. synapse > 1.30 needs a newer python-cryptography (I think >=3D3.4) at runtime, so I think this version would not run on current guix. (My homeserver runs guix synapse, but from my channel...) Regards mike =2D-=20 Life begins where fear ends. - Osho --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQFFBAEBCAAvFiEEdV4t5dDVhcUueCgwfHr/vv7yyyUFAmCuXS4RHG1pa2VAcm9o bGVkZXIuZGUACgkQfHr/vv7yyyViRwf/SOcxlXvUFMDcsTUsJfJUzd9Scp/jw7D2 eggS76/xoDUhOZAoQycx9MPVgMuaE/BRCP1FvHbYeBm7XgKehYRi2VwvC3anDU1z AqmZcN57nONd6OCdgOdXnWh3i2r2HmyvkyJy2A2LJM9EbHBKLHasUBHBefETuFqy 1yQSvMgjdtOt5mY++S0Z9dMQ+9acggv8fZLFT0Knqw1yz61Fy+sVTEOEFMUWmU19 250P0VK4/uqNgGRUpr5eLwHAXqpRW3UbV9PP/8xoNaiyvP5KDE6TXRAAqSoVKlPy dJRWLB8Bhi8eDCwc86JyHEIFJlXVZy1wIosDwx1Rc4unSkSs+0nkTA== =9+OP -----END PGP SIGNATURE----- --=-=-=--
guix-patches@HIDDEN
:bug#48655
; Package guix-patches
.
Full text available.Received: (at submit) by debbugs.gnu.org; 25 May 2021 16:37:14 +0000 From debbugs-submit-bounces <at> debbugs.gnu.org Tue May 25 12:37:14 2021 Received: from localhost ([127.0.0.1]:46627 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>) id 1lla3O-0003Qg-0V for submit <at> debbugs.gnu.org; Tue, 25 May 2021 12:37:14 -0400 Received: from lists.gnu.org ([209.51.188.17]:43748) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <solene@HIDDEN>) id 1lla3M-0003QZ-GI for submit <at> debbugs.gnu.org; Tue, 25 May 2021 12:37:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:51840) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <solene@HIDDEN>) id 1lla3M-0007BO-6x for guix-patches@HIDDEN; Tue, 25 May 2021 12:37:12 -0400 Received: from perso.pw ([163.172.223.238]:13154) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <solene@HIDDEN>) id 1lla3J-0006Kk-3r for guix-patches@HIDDEN; Tue, 25 May 2021 12:37:11 -0400 Received: from perso.pw (localhost [127.0.0.1]) by perso.pw (OpenSMTPD) with ESMTP id 1ccaa425 for <guix-patches@HIDDEN>; Tue, 25 May 2021 18:36:59 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=perso.pw; h=date:from:to :subject:message-id:mime-version:content-type :content-transfer-encoding; s=1337; bh=FcFmNL4Hmyz/Hf/D6g5sSXM+U wU=; b=Mq+cd740aKmPaASdPCr06V5bcILA4l7y2RMlMCDim5Vq/niPrrkaUlNOM MMS6n8OuzBVVxgxBe8+dosLHITY8tyGf3e9P/UqG1/LOBTJHUKerxcE18j7kkx/y 3JTOPdhcDbsQTsUWxdI1N0wXcpB/aFugUyaF0yM8Jp5dcebYiQ= DomainKey-Signature: a=rsa-sha1; c=nofws; d=perso.pw; h=date:from:to :subject:message-id:mime-version:content-type :content-transfer-encoding; q=dns; s=1337; b=GMGnyRr8Mi7OjLYtqzS 9jfIOfJQvN/kWBg5fWU9K/UDRSjPlEFMhkwIfeUSKT7t457gehKYUd//3uzvicHQ Vb8v/B5KaOdrnR5p0EZbcOi9p8zo8oTZAPQpx66OM0YY190hF2RCtCmO499L6l+A 46ND1Tjg7PvWQQHRmLlJEKyE= X-Spam-Checker-Version: SpamAssassin 3.4.5 (2021-03-20) on perso.pw X-Spam-Level: X-Spam-Status: No, score=-2.9 required=5.0 tests=ALL_TRUSTED,BAYES_00 autolearn=ham autolearn_force=no version=3.4.5 Received: from localhost (176-154-164-34.abo.bbox.fr [176.154.164.34]) by perso.pw (OpenSMTPD) with ESMTPSA id c53ead02 (TLSv1.3:AEAD-AES256-GCM-SHA384:256:NO) for <guix-patches@HIDDEN>; Tue, 25 May 2021 18:36:57 +0200 (CEST) Date: Tue, 25 May 2021 18:36:56 +0200 From: Solene Rapenne <solene@HIDDEN> To: guix-patches@HIDDEN Subject: [PATCH] gnu: synapse: Update to 1.33.2. Message-ID: <20210525183656.4d41ae04@HIDDEN> X-Mailer: Claws Mail 3.17.8 (GTK+ 2.24.32; x86_64-pc-linux-gnu) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Received-SPF: pass client-ip=163.172.223.238; envelope-from=solene@HIDDEN; helo=perso.pw X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: -1.4 (-) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit <at> debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: <debbugs-submit.debbugs.gnu.org> List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe> List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/> List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org> List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help> List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe> Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org> X-Spam-Score: -2.4 (--) This fixes the DoS [CVE-2021-29471] and many other improvements I didn't try it, I don't have a matrix server. --- gnu/packages/matrix.scm | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/gnu/packages/matrix.scm b/gnu/packages/matrix.scm index 5c2b194d07..0c0fc26705 100644 --- a/gnu/packages/matrix.scm +++ b/gnu/packages/matrix.scm @@ -3,6 +3,7 @@ ;;; Copyright =C2=A9 2020 Tobias Geerinckx-Rice <me@HIDDEN> ;;; Copyright =C2=A9 2020, 2021 Michael Rohleder <mike@HIDDEN> ;;; Copyright =C2=A9 2020 Giacomo Leidi <goodoldpaul@HIDDEN> +;;; Copyright =C2=A9 2021 Solene Rapenne <solene@HIDDEN> ;;; ;;; This file is part of GNU Guix. ;;; @@ -86,13 +87,13 @@ an LDAP server.") (define-public synapse (package (name "synapse") - (version "1.29.0") + (version "1.33.2") (source (origin (method url-fetch) (uri (pypi-uri "matrix-synapse" version)) (sha256 (base32 - "0if2yhpz8psg0661401mvxznldbfhk2j9rhbs25jdaqm9jsv6907")))) + "14qalqy5h51qdv88wxj7h7cibxkbwdvk3pn8sj8k19ynbfwn6rpm")))) (build-system python-build-system) ;; TODO Run tests with =E2=80=98PYTHONPATH=3D. trial3 tests=E2=80=99. (propagated-inputs --=20 2.31.1
Solene Rapenne <solene@HIDDEN>
:guix-patches@HIDDEN
.
Full text available.guix-patches@HIDDEN
:bug#48655
; Package guix-patches
.
Full text available.
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997 nCipher Corporation Ltd,
1994-97 Ian Jackson.