On 2023-01-16 10:20, Kokkonda, Sundeep via lists.openembedded.org wrote:
Rust community said the security fixes are only for the current stable
relases.
https://internals.rust-lang.org/t/cargo-cve-2022-46176-fix-for-older-releases/18152/3?u=sundeep-kokkonda
For old release we've to backport the patches ourselves.
The other alternatives are
1. upgrade to 1.66.1 on older branches,
2. add 1.66.1, which will be the PREFERRED_VERSION but keep the older
version for those who are risk averse,
3. add a mix-in layer (1) with the upgrade to 1.66.1.
For langdale, we'd update from 1.63 and for kirkstone, we'd update from
1.59
See the link above for a discussion about what Fedora/RHEL and other
distros are doing
and a description of the rust / crates.io test system known as crater
that builds the
world for any significant rust change.
Is there any objection to doing 2 and if we don't see any problems after
some time,
then removing the older version?
Sundeep,
If no one object, please update kirkstone and see if librsvg or
python-cryptography or
anything else encounters a problem.
../Randy
1)
https://wiki.yoctoproject.org/wiki/Stable_Release_and_LTS#LTS_.E2.80.9CMixin.E2.80.9D_repositories
So, for the Kirkstone & Langdale we've to back port the CVE fix.
--
# Randy MacLeod
# Wind River Linux
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#176061):
https://lists.openembedded.org/g/openembedded-core/message/176061
Mute This Topic: https://lists.openembedded.org/mt/96218038/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-