[Bug 2255477] CVE-2023-47100 perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255477 --- Comment #1 from Avinash Hanwate --- Use the following template to for the 'fedpkg update' request to submit an update for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all

[Bug 2255479] CVE-2023-47100 perl:5.36/perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255479 Avinash Hanwate changed: What|Removed |Added Blocks||2255476 (CVE-2023-47100)

[Bug 2255477] CVE-2023-47100 perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255477 Avinash Hanwate changed: What|Removed |Added Blocks||2255476 (CVE-2023-47100)

[Bug 2255479] CVE-2023-47100 perl:5.36/perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255479 --- Comment #1 from Avinash Hanwate --- Use the following template to for the 'fedpkg update' request to submit an update for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all

[Bug 2255478] CVE-2023-47100 perl:5.34/perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255478 Avinash Hanwate changed: What|Removed |Added Blocks||2255476 (CVE-2023-47100)

[Bug 2255479] New: CVE-2023-47100 perl:5.36/perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255479 Bug ID: 2255479 Summary: CVE-2023-47100 perl:5.36/perl: Perl security bypass [fedora-all] Product: Fedora Version: 39 Status: NEW Component: perl

[Bug 2255478] CVE-2023-47100 perl:5.34/perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255478 --- Comment #1 from Avinash Hanwate --- Use the following template to for the 'fedpkg update' request to submit an update for this issue as it contains the top-level parent bug(s) as well as this tracking bug. This will ensure that all

[Bug 2255477] New: CVE-2023-47100 perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255477 Bug ID: 2255477 Summary: CVE-2023-47100 perl: Perl security bypass [fedora-all] Product: Fedora Version: 39 Status: NEW Component: perl Keywords: Security,

[Bug 2255478] New: CVE-2023-47100 perl:5.34/perl: Perl security bypass [fedora-all]

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=2255478 Bug ID: 2255478 Summary: CVE-2023-47100 perl:5.34/perl: Perl security bypass [fedora-all] Product: Fedora Version: 39 Status: NEW Component: perl

Fedora Developer Portal Holiday Release

2023-12-20 Thread Jarek Prokop
Hi, we have new Fedora Developer Portal release. This is most probably the last release of 2023. In no particular order: Update rails.md to use packaged rbenv (#492) * https://developer.fedoraproject.org/start/sw/web-app/rails.html Remove cassandra from the database section. (#500) *

Heads up: Flask and Werkzeug 3.0

2023-12-20 Thread Frantisek Zatloukal
I have been working on the Pull Requests for Flask and Werkzeug rebases from 2.2.x versions to the 3.x in Fedora Rawhide. I am using the Werkzeug PR as the base one to post comments. Impact check is in the first comment: https://src.fedoraproject.org/rpms/python-werkzeug/pull-request/16# These

Re: F40 Change Proposal: F40 Change Proposal: Unify /usr/bin and /usr/sbin (System-Wide)

2023-12-20 Thread Neal Gompa
On Wed, Dec 20, 2023 at 2:55 PM Aoife Moloney wrote: > > ** Adjust `%_sbindir` in `/usr/lib/rpm/macros` (part of `rpm` > package). Packages will be updated automatically during the mass > rebuild. This should probably be set in redhat-rpm-config instead of modifying the core rpm package. --

F40 Change Proposal: Wifi MAC Randomization (System Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/WifiMACRandomization This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering

F40 Change Proposal: Wifi MAC Randomization (System Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/WifiMACRandomization This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering

F40 Change Proposal: F40 Change Proposal: Unify /usr/bin and /usr/sbin (System-Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering

F40 Change Proposal: F40 Change Proposal: Unify /usr/bin and /usr/sbin (System-Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/Unify_bin_and_sbin This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering

Re: Enabling GOPROXY and GOSUMDB in Fedora

2023-12-20 Thread Maxwell G
On Wed Dec 20, 2023 at 07:57 -0800, Brad Smith wrote: > The go.env file does not, as far as I can tell, contain the original > values from upstream. Just the modified values. Unless I modified the > file and cannot recall doing so! My suggestion was to include the > original upstream settings as

Re: F40 Change Proposal: Enable IPv4 Address Conflict Detection (Self-Contained)

2023-12-20 Thread Chris Adams
Once upon a time, Aoife Moloney said: > Enable IPv4 Address Conflict Detection by default in NetworkManager. Huh, I didn't realize NM didn't already do this... ye olde network-scripts did. > To the rescue comes [https://www.rfc-editor.org/rfc/rfc5227 RFC 5227] > (“IPv4 Address Conflict

F40 Change Proposal: Change Firefox Desktop File (System-Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/RenameFirefoxDesktopFile This is a proposed Change for Fedora Linux. This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be

F40 Change Proposal: Change Firefox Desktop File (System-Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/RenameFirefoxDesktopFile This is a proposed Change for Fedora Linux. This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be

F40 Change Proposal: Haskell GHC 9.6 and Stackage LTS 22 (Self-Contained)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/Haskell_GHC_9.6_and_Stackage_22 This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora

F40 Change Proposal: Haskell GHC 9.6 and Stackage LTS 22 (Self-Contained)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/Haskell_GHC_9.6_and_Stackage_22 This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora

F40 Change Proposal: Golang 1.22 (System-Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/golang1.22 This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering Steering

F40 Change Proposal: Golang 1.22 (System-Wide)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/golang1.22 This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the Fedora Engineering Steering

F40 Change Proposal: Enable IPv4 Address Conflict Detection (Self-Contained)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/Enable_IPv4_Address_Conflict_Detection This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the

F40 Change Proposal: Enable IPv4 Address Conflict Detection (Self-Contained)

2023-12-20 Thread Aoife Moloney
Wiki -> https://fedoraproject.org/wiki/Changes/Enable_IPv4_Address_Conflict_Detection This document represents a proposed Change. As part of the Changes process, proposals are publicly announced in order to receive community feedback. This proposal will only be implemented if approved by the

Re: how to package dconf configuration for different language environments

2023-12-20 Thread Michael Catanzaro
On Wed, Dec 20 2023 at 04:33:22 PM +01:00:00, Vojtěch Polášek wrote: Is it possible to somehow insert a different string in the dconf file depending on locale of the environment where the package is installed? So first of all, dconf overrides are for system administrators, not distro

Re: F40 Change Proposals Requiring Infra Changes - Deadline Today

2023-12-20 Thread Leslie Satenstein via devel
Sometimes it is overly burdensome to want to submit a suggestion. I have run the Rawhide Fedora 40 beta of Dec 19, 2023 and would like to propose an additional radio button for anaconda installer. There are currently three options, of which the third is not yet available. I would like to

Re: Enabling GOPROXY and GOSUMDB in Fedora

2023-12-20 Thread Brad Smith
Greetings - On Wed, Dec 20, 2023 at 7:35 AM Maxwell G wrote: > > Can someone clarify what they mean by this? The patch itself [1] makes > it pretty clear what the original values are. When I look at /usr/lib/golang/go.env I see: [bgsmith@pico newversionprep (main *%)]$ more

Re: Enabling GOPROXY and GOSUMDB in Fedora

2023-12-20 Thread Maxwell G
On Wed Dec 20, 2023 at 12:14 +0100, Ondrej Pohorelsky wrote: > On Tue, Dec 19, 2023 at 11:11 PM Neal Gompa wrote: > > > On Tue, Dec 19, 2023 at 4:14 PM Brad Smith > > wrote: > > > > > > At a minimum, I recommend that the patch include the original values > > > for GOPROXY, GOSUMDB, and

how to package dconf configuration for different language environments

2023-12-20 Thread Vojtěch Polášek
Hello, I am trying to package a dconf configuration which adds a keyboard shortcut to Mate environment. I am creating two language mutations of a Fedora remix where this package should be present. Currently, I have it in English. The spec file (probably very crude, sorry) is here:

F40 Change Proposals Requiring Infra Changes - Deadline Today

2023-12-20 Thread Aoife Moloney
Hi all, Today is the final day to submit Change Proposals that require *infrastructure changes* for Fedora Linux 40. Changes do not have to be accepted by this deadline, but they must be submitted. Thanks, Aoife --

Fedora rawhide compose report: 20231220.n.0 changes

2023-12-20 Thread Fedora Rawhide Report
OLD: Fedora-Rawhide-20231219.n.0 NEW: Fedora-Rawhide-20231220.n.0 = SUMMARY = Added images:1 Dropped images: 0 Added packages: 5 Dropped packages:1 Upgraded packages: 126 Downgraded packages: 0 Size of added packages: 5.89 MiB Size of dropped packages

Re: Enabling GOPROXY and GOSUMDB in Fedora

2023-12-20 Thread Ondrej Pohorelsky
I would personally go with the 2 and get closer to the upstream. I agree with the npm analogy that was made in the conversation. Furthermore, I don't think that most users, working on Go projects on Fedora, would even know that we provide different Go envars to the upstream ones. IMO, they would

Re: F40 Change Proposal: Unified Kernel Support Phase Two (System-Wide)

2023-12-20 Thread Vitaly Kuznetsov
Gerd Hoffmann writes: ... >> I'm talking about removing shim from the boot flow. > > That is not a goal of this change proposal, and it's not up for debate > for phase #2. Maybe an option in a later phase, once we have a signed > systemd-boot (see below). Also, we have one more

[Bug 1011333] PerlIO::via leaks a foreign memory

2023-12-20 Thread bugzilla
https://bugzilla.redhat.com/show_bug.cgi?id=1011333 AdamRiland changed: What|Removed |Added CC||therobo...@gmail.com --- Comment #23

[Test-Announce] Fedora 40 Rawhide 20231220.n.0 nightly compose nominated for testing

2023-12-20 Thread rawhide
Announcing the creation of a new nightly release validation test event for Fedora 40 Rawhide 20231220.n.0. Please help run some tests for this nightly compose if you have time. For more information on nightly release validation testing, see: https://fedoraproject.org/wiki