X-Loop: help-debbugs@HIDDEN
Subject: [bug#48655] [PATCH] gnu: synapse: Update to 1.33.2.
Resent-From: Solene Rapenne <solene@HIDDEN>
Original-Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
Resent-CC: guix-patches@HIDDEN
Resent-Date: Tue, 25 May 2021 16:38:02 +0000
Resent-Message-ID: <handler.48655.B.162196063413191 <at> debbugs.gnu.org>
Resent-Sender: help-debbugs@HIDDEN
X-GNU-PR-Message: report 48655
X-GNU-PR-Package: guix-patches
X-GNU-PR-Keywords: patch
To: 48655 <at> debbugs.gnu.org
X-Debbugs-Original-To: guix-patches@HIDDEN
Received: via spool by submit <at> debbugs.gnu.org id=B.162196063413191
(code B ref -1); Tue, 25 May 2021 16:38:02 +0000
Received: (at submit) by debbugs.gnu.org; 25 May 2021 16:37:14 +0000
Received: from localhost ([127.0.0.1]:46627 helo=debbugs.gnu.org)
by debbugs.gnu.org with esmtp (Exim 4.84_2)
(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
id 1lla3O-0003Qg-0V
for submit <at> debbugs.gnu.org; Tue, 25 May 2021 12:37:14 -0400
Received: from lists.gnu.org ([209.51.188.17]:43748)
by debbugs.gnu.org with esmtp (Exim 4.84_2)
(envelope-from <solene@HIDDEN>) id 1lla3M-0003QZ-GI
for submit <at> debbugs.gnu.org; Tue, 25 May 2021 12:37:13 -0400
Received: from eggs.gnu.org ([2001:470:142:3::10]:51840)
by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
(Exim 4.90_1) (envelope-from <solene@HIDDEN>) id 1lla3M-0007BO-6x
for guix-patches@HIDDEN; Tue, 25 May 2021 12:37:12 -0400
Received: from perso.pw ([163.172.223.238]:13154)
by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
(Exim 4.90_1) (envelope-from <solene@HIDDEN>) id 1lla3J-0006Kk-3r
for guix-patches@HIDDEN; Tue, 25 May 2021 12:37:11 -0400
Received: from perso.pw (localhost [127.0.0.1])
by perso.pw (OpenSMTPD) with ESMTP id 1ccaa425
for <guix-patches@HIDDEN>; Tue, 25 May 2021 18:36:59 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=perso.pw; h=date:from:to
:subject:message-id:mime-version:content-type
:content-transfer-encoding; s=1337; bh=FcFmNL4Hmyz/Hf/D6g5sSXM+U
wU=; b=Mq+cd740aKmPaASdPCr06V5bcILA4l7y2RMlMCDim5Vq/niPrrkaUlNOM
MMS6n8OuzBVVxgxBe8+dosLHITY8tyGf3e9P/UqG1/LOBTJHUKerxcE18j7kkx/y
3JTOPdhcDbsQTsUWxdI1N0wXcpB/aFugUyaF0yM8Jp5dcebYiQ=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=perso.pw; h=date:from:to
:subject:message-id:mime-version:content-type
:content-transfer-encoding; q=dns; s=1337; b=GMGnyRr8Mi7OjLYtqzS
9jfIOfJQvN/kWBg5fWU9K/UDRSjPlEFMhkwIfeUSKT7t457gehKYUd//3uzvicHQ
Vb8v/B5KaOdrnR5p0EZbcOi9p8zo8oTZAPQpx66OM0YY190hF2RCtCmO499L6l+A
46ND1Tjg7PvWQQHRmLlJEKyE=
X-Spam-Checker-Version: SpamAssassin 3.4.5 (2021-03-20) on perso.pw
X-Spam-Level:
X-Spam-Status: No, score=-2.9 required=5.0 tests=ALL_TRUSTED,BAYES_00
autolearn=ham autolearn_force=no version=3.4.5
Received: from localhost (176-154-164-34.abo.bbox.fr [176.154.164.34])
by perso.pw (OpenSMTPD) with ESMTPSA id c53ead02
(TLSv1.3:AEAD-AES256-GCM-SHA384:256:NO) for <guix-patches@HIDDEN>;
Tue, 25 May 2021 18:36:57 +0200 (CEST)
Date: Tue, 25 May 2021 18:36:56 +0200
From: Solene Rapenne <solene@HIDDEN>
Message-ID: <20210525183656.4d41ae04@HIDDEN>
X-Mailer: Claws Mail 3.17.8 (GTK+ 2.24.32; x86_64-pc-linux-gnu)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Received-SPF: pass client-ip=163.172.223.238; envelope-from=solene@HIDDEN;
helo=perso.pw
X-Spam_score_int: -20
X-Spam_score: -2.1
X-Spam_bar: --
X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001,
SPF_PASS=-0.001 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: -1.4 (-)
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>,
<mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>,
<mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -2.4 (--)
This fixes the DoS [CVE-2021-29471] and many other improvements
I didn't try it, I don't have a matrix server.
---
gnu/packages/matrix.scm | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/gnu/packages/matrix.scm b/gnu/packages/matrix.scm
index 5c2b194d07..0c0fc26705 100644
--- a/gnu/packages/matrix.scm
+++ b/gnu/packages/matrix.scm
@@ -3,6 +3,7 @@
;;; Copyright =C2=A9 2020 Tobias Geerinckx-Rice <me@HIDDEN>
;;; Copyright =C2=A9 2020, 2021 Michael Rohleder <mike@HIDDEN>
;;; Copyright =C2=A9 2020 Giacomo Leidi <goodoldpaul@HIDDEN>
+;;; Copyright =C2=A9 2021 Solene Rapenne <solene@HIDDEN>
;;;
;;; This file is part of GNU Guix.
;;;
@@ -86,13 +87,13 @@ an LDAP server.")
(define-public synapse
(package
(name "synapse")
- (version "1.29.0")
+ (version "1.33.2")
(source (origin
(method url-fetch)
(uri (pypi-uri "matrix-synapse" version))
(sha256
(base32
- "0if2yhpz8psg0661401mvxznldbfhk2j9rhbs25jdaqm9jsv6907"))))
+ "14qalqy5h51qdv88wxj7h7cibxkbwdvk3pn8sj8k19ynbfwn6rpm"))))
(build-system python-build-system)
;; TODO Run tests with =E2=80=98PYTHONPATH=3D. trial3 tests=E2=80=99.
(propagated-inputs
--=20
2.31.1
Content-Disposition: inline Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Mailer: MIME-tools 5.505 (Entity 5.505) Content-Type: text/plain; charset=utf-8 X-Loop: help-debbugs@HIDDEN From: help-debbugs@HIDDEN (GNU bug Tracking System) To: Solene Rapenne <solene@HIDDEN> Subject: bug#48655: Acknowledgement ([PATCH] gnu: synapse: Update to 1.33.2.) Message-ID: <handler.48655.B.162196063413191.ack <at> debbugs.gnu.org> References: <20210525183656.4d41ae04@HIDDEN> X-Gnu-PR-Message: ack 48655 X-Gnu-PR-Package: guix-patches X-Gnu-PR-Keywords: patch Reply-To: 48655 <at> debbugs.gnu.org Date: Tue, 25 May 2021 16:38:02 +0000 Thank you for filing a new bug report with debbugs.gnu.org. This is an automatically generated reply to let you know your message has been received. Your message is being forwarded to the package maintainers and other interested parties for their attention; they will reply in due course. Your message has been sent to the package maintainer(s): guix-patches@HIDDEN If you wish to submit further information on this problem, please send it to 48655 <at> debbugs.gnu.org. Please do not send mail to help-debbugs@HIDDEN unless you wish to report a problem with the Bug-tracking system. --=20 48655: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=3D48655 GNU Bug Tracking System Contact help-debbugs@HIDDEN with problems
X-Loop: help-debbugs@HIDDEN
Subject: [bug#48655] [PATCH] gnu: synapse: Update to 1.33.2.
Resent-From: Michael Rohleder <mike@HIDDEN>
Original-Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
Resent-CC: guix-patches@HIDDEN
Resent-Date: Wed, 26 May 2021 14:38:02 +0000
Resent-Message-ID: <handler.48655.B48655.1622039865465 <at> debbugs.gnu.org>
Resent-Sender: help-debbugs@HIDDEN
X-GNU-PR-Message: followup 48655
X-GNU-PR-Package: guix-patches
X-GNU-PR-Keywords: patch
To: Solene Rapenne <solene@HIDDEN>
Cc: 48655 <at> debbugs.gnu.org
Received: via spool by 48655-submit <at> debbugs.gnu.org id=B48655.1622039865465
(code B ref 48655); Wed, 26 May 2021 14:38:02 +0000
Received: (at 48655) by debbugs.gnu.org; 26 May 2021 14:37:45 +0000
Received: from localhost ([127.0.0.1]:49686 helo=debbugs.gnu.org)
by debbugs.gnu.org with esmtp (Exim 4.84_2)
(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
id 1llufI-00007R-Sq
for submit <at> debbugs.gnu.org; Wed, 26 May 2021 10:37:45 -0400
Received: from wp224.webpack.hosteurope.de ([80.237.132.231]:43608)
by debbugs.gnu.org with esmtp (Exim 4.84_2)
(envelope-from <mike@HIDDEN>) id 1llufG-00007F-0h
for 48655 <at> debbugs.gnu.org; Wed, 26 May 2021 10:37:43 -0400
Received: from www.rohleder.de ([37.61.204.227]); authenticated
by wp224.webpack.hosteurope.de running ExIM with esmtpsa
(TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256)
id 1llufD-0005fw-V4; Wed, 26 May 2021 16:37:39 +0200
Received: from [192.168.1.3] (helo=micha)
by www.rohleder.de with esmtps (TLS1.3) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94)
(envelope-from <mike@HIDDEN>)
id 1llufA-0005gL-PJ; Wed, 26 May 2021 16:37:39 +0200
From: Michael Rohleder <mike@HIDDEN>
References: <20210525183656.4d41ae04@HIDDEN>
Date: Wed, 26 May 2021 16:37:33 +0200
In-Reply-To: <20210525183656.4d41ae04@HIDDEN> (Solene Rapenne via
Guix-patches via's message of "Tue, 25 May 2021 18:36:56 +0200")
Message-ID: <87im351ryq.fsf@HIDDEN>
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.2 (gnu/linux)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-=";
micalg=pgp-sha256; protocol="application/pgp-signature"
X-bounce-key: webpack.hosteurope.de;mike@HIDDEN;1622039862;f964e1e6;
X-HE-SMSGID: 1llufD-0005fw-V4
X-Spam-Score: -0.7 (/)
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>,
<mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>,
<mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -1.7 (-)
--=-=-=
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable
Hi Solene,
Thank you for the patch!
Solene Rapenne via Guix-patches via <guix-patches@HIDDEN> writes:
> This fixes the DoS [CVE-2021-29471] and many other improvements
>
> I didn't try it, I don't have a matrix server.
synapse > 1.30 needs a newer python-cryptography (I think >=3D3.4) at
runtime, so I think this version would not run on current guix.
(My homeserver runs guix synapse, but from my channel...)
Regards
mike
=2D-=20
Life begins where fear ends. - Osho
--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQFFBAEBCAAvFiEEdV4t5dDVhcUueCgwfHr/vv7yyyUFAmCuXS4RHG1pa2VAcm9o
bGVkZXIuZGUACgkQfHr/vv7yyyViRwf/SOcxlXvUFMDcsTUsJfJUzd9Scp/jw7D2
eggS76/xoDUhOZAoQycx9MPVgMuaE/BRCP1FvHbYeBm7XgKehYRi2VwvC3anDU1z
AqmZcN57nONd6OCdgOdXnWh3i2r2HmyvkyJy2A2LJM9EbHBKLHasUBHBefETuFqy
1yQSvMgjdtOt5mY++S0Z9dMQ+9acggv8fZLFT0Knqw1yz61Fy+sVTEOEFMUWmU19
250P0VK4/uqNgGRUpr5eLwHAXqpRW3UbV9PP/8xoNaiyvP5KDE6TXRAAqSoVKlPy
dJRWLB8Bhi8eDCwc86JyHEIFJlXVZy1wIosDwx1Rc4unSkSs+0nkTA==
=9+OP
-----END PGP SIGNATURE-----
--=-=-=--
Received: (at control) by debbugs.gnu.org; 5 Jun 2021 21:30:28 +0000 From debbugs-submit-bounces <at> debbugs.gnu.org Sat Jun 05 17:30:28 2021 Received: from localhost ([127.0.0.1]:50222 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>) id 1lpdsC-0005FM-EJ for submit <at> debbugs.gnu.org; Sat, 05 Jun 2021 17:30:28 -0400 Received: from eggs.gnu.org ([209.51.188.92]:41198) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from <ludo@HIDDEN>) id 1lpdsB-0005FA-7j for control <at> debbugs.gnu.org; Sat, 05 Jun 2021 17:30:27 -0400 Received: from fencepost.gnu.org ([2001:470:142:3::e]:59746) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from <ludo@HIDDEN>) id 1lpds6-0002ub-1S for control <at> debbugs.gnu.org; Sat, 05 Jun 2021 17:30:22 -0400 Received: from [2a01:e0a:1d:7270:af76:b9b:ca24:c465] (port=54032 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <ludo@HIDDEN>) id 1lpds5-0002Zf-PJ for control <at> debbugs.gnu.org; Sat, 05 Jun 2021 17:30:21 -0400 Date: Sat, 05 Jun 2021 23:30:20 +0200 Message-Id: <87v96sknir.fsf@HIDDEN> To: control <at> debbugs.gnu.org From: =?utf-8?Q?Ludovic_Court=C3=A8s?= <ludo@HIDDEN> Subject: control message for bug #48655 MIME-version: 1.0 Content-type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Spam-Score: -2.3 (--) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit <at> debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: <debbugs-submit.debbugs.gnu.org> List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe> List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/> List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org> List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help> List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe> Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org> X-Spam-Score: -3.3 (---) tags 48655 + moreinfo quit
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997 nCipher Corporation Ltd,
1994-97 Ian Jackson.