Re: lua 5.1.5 CVEs / lua 5.3 with luci

2022-10-26 Thread Jo-Philipp Wich
Hi, > Can one be curious and ask what is gonna be used instead of lua, or is > that still not 100% decided yet? you can find more details at https://forum.openwrt.org/t/luci-rewrite-in-ucode-testers-wanted/137250 ~ Jo signature.asc Description: OpenPGP digital signature __

Re: lua 5.1.5 CVEs / lua 5.3 with luci

2022-10-26 Thread Luna Jernberg
Ah thanks On Wed, Oct 26, 2022 at 3:57 PM Jo-Philipp Wich wrote: > > Hi, > > > Can one be curious and ask what is gonna be used instead of lua, or is > > that still not 100% decided yet? > > you can find more details at > https://forum.openwrt.org/t/luci-rewrite-in-ucode-testers-wanted/137250 > >

Re: lua 5.1.5 CVEs / lua 5.3 with luci

2022-10-26 Thread Luna Jernberg
Can one be curious and ask what is gonna be used instead of lua, or is that still not 100% decided yet? On Wed, Oct 26, 2022 at 3:54 PM Jo-Philipp Wich wrote: > > Hi, > > all errors you quoted are occurring within Lua code. The view rendering etc. > mostly happens in JavaScript on the client side

Re: lua 5.1.5 CVEs / lua 5.3 with luci

2022-10-26 Thread Jo-Philipp Wich
Hi, all errors you quoted are occurring within Lua code. The view rendering etc. mostly happens in JavaScript on the client side, this is why things /seem/ to work. Many backend actions are implemented as rpcd plugins in Lua code though, and all those seem to fail (not register with rpcd in the fi

Re: lua 5.1.5 CVEs / lua 5.3 with luci

2022-10-26 Thread Peter Naulls
On 10/25/22 20:45, Reuben Dowle wrote: My opinion is that openwrt should try and move to a newer version of lua. This old 5.1.5 version appears to be unmaintained, and there does not seem to be the resources within the openwrt community to change that. So I naively adjusted the lua5.3 packa

RE: lua 5.1.5 CVEs

2022-10-25 Thread Reuben Dowle
be the resources within the openwrt community to change that. > -Original Message- > From: openwrt-devel On > Behalf Of Peter Naulls > Sent: Wednesday, 26 October 2022 12:06 pm > To: OpenWrt Development List > Subject: lua 5.1.5 CVEs > > > Lua 5.1.5 woul

lua 5.1.5 CVEs

2022-10-25 Thread Peter Naulls
Lua 5.1.5 would appear to have CVEs below against it. The patches to this in OpenWrt are significant, but dated, with the last bug fix seeming to be from 2019, so it's hard to say if these are addressed: https://github.com/openwrt/openwrt/tree/openwrt-22.03/package/utils/lua/patches https://