Re: [oe-core][PATCH 1/1] go: fix CVE-2022-41724, 41725

2023-04-13 Thread Joe Slater


> -Original Message-
> From: Luca Ceresoli 
> Sent: Wednesday, April 12, 2023 1:39 PM
> To: Slater, Joseph 
> Cc: openembedded-core@lists.openembedded.org; MacLeod, Randy
> 
> Subject: Re: [oe-core][PATCH 1/1] go: fix CVE-2022-41724, 41725
> 
> Hello Joe,
> 
> On Wed, 12 Apr 2023 11:32:06 -0700
> "Joe Slater"  wrote:
> 
> > Backport from go-1.19.  The godebug package is needed by the fix to
> > CVE-2022-41725.
> >
> > Mostly a cherry-pick but exceptions are noted in comments marked
> > "backport".
> >
> > Signed-off-by: Joe Slater 
> > ---
> >  ...01-go-fix-CVE-2022-41723-41724-41725.patch | 3373 +
> >  meta/recipes-devtools/go/go-1.17.13.inc   |5 +-
> 
> I understand this patch is wrong, being mased on kirkstone, so you sent a 
> fixed
> versions with the '[kirkstone]' subject tag shortly after, and this one 
> should be
> ignored. Is this correct?

[Slater, Joseph] Yes, sorry for the noise.  I forgot the kirkstone label.  I 
think this patch also includes a bogus file I somehow committed while switching 
branches and generating patches for my internal use.

Joe


> 
> Best regards,
> Luca
> 
> --
> Luca Ceresoli, Bootlin
> Embedded Linux and Kernel engineering
> https://bootlin.com

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#179979): 
https://lists.openembedded.org/g/openembedded-core/message/179979
Mute This Topic: https://lists.openembedded.org/mt/98225605/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-



Re: [oe-core][PATCH 1/1] go: fix CVE-2022-41724, 41725

2023-04-12 Thread Luca Ceresoli via lists.openembedded.org
Hello Joe,

On Wed, 12 Apr 2023 11:32:06 -0700
"Joe Slater"  wrote:

> Backport from go-1.19.  The godebug package is needed by
> the fix to CVE-2022-41725.
> 
> Mostly a cherry-pick but exceptions are noted in comments
> marked "backport".
> 
> Signed-off-by: Joe Slater 
> ---
>  ...01-go-fix-CVE-2022-41723-41724-41725.patch | 3373 +
>  meta/recipes-devtools/go/go-1.17.13.inc   |5 +-

I understand this patch is wrong, being mased on kirkstone, so you sent
a fixed versions with the '[kirkstone]' subject tag shortly after, and
this one should be ignored. Is this correct?

Best regards,
Luca

-- 
Luca Ceresoli, Bootlin
Embedded Linux and Kernel engineering
https://bootlin.com

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#179951): 
https://lists.openembedded.org/g/openembedded-core/message/179951
Mute This Topic: https://lists.openembedded.org/mt/98225605/21656
Group Owner: openembedded-core+ow...@lists.openembedded.org
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-