Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

git: 2.16.2 -> 2.16.4 (for release-18.03) #41244

Merged
merged 1 commit into from May 30, 2018

Conversation

orivej
Copy link
Contributor

@orivej orivej commented May 30, 2018

Motivation for this change

This is a security update, see [1].

It is not backported from master because master is at 2.17.0 after #38636 and 2.17.1 after #41223.

[1] https://github.com/git/git/blob/master/Documentation/RelNotes/2.17.1.txt

Things done
  • Tested using sandboxing (nix.useSandbox on NixOS, or option build-use-sandbox in nix.conf on non-NixOS)
  • Built on platform(s)
    • NixOS
    • macOS
    • other Linux distributions
  • Tested via one or more NixOS test(s) if existing and applicable for the change (look inside nixos/tests)
  • Tested compilation of all pkgs that depend on this change using nix-shell -p nox --run "nox-review wip"
  • Tested execution of all binary files (usually in ./result/bin/)
  • Fits CONTRIBUTING.md.

This is a security update, see [1].

It is not backported from master because master is at 2.17.x after NixOS#38636.

[1] https://github.com/git/git/blob/master/Documentation/RelNotes/2.17.1.txt
@GrahamcOfBorg
Copy link

Failure on aarch64-linux (full log)

Attempted: git

Partial log (click to expand)

Hunk #3 succeeded at 255 (offset 34 lines).
applying patch /nix/store/39s7y2l1las6jpw36a1z257xzrwy1mj5-symlinks-in-bin.patch
patching file Makefile
Hunk #1 succeeded at 2590 (offset 271 lines).
applying patch /nix/store/qgb13c66qn0dp18rsnvy9ygbqassb0rk-git-sh-i18n.patch
patching file git-sh-i18n.sh
Hunk #1 FAILED at 15.
1 out of 1 hunk FAILED -- saving rejects to file git-sh-i18n.sh.rej
builder for '/nix/store/pwz791znfjy9r7kkxmiw4zzli5a52v16-git-2.16.4.drv' failed with exit code 1
�[31;1merror:�[0m build of '/nix/store/pwz791znfjy9r7kkxmiw4zzli5a52v16-git-2.16.4.drv' failed

@GrahamcOfBorg
Copy link

Failure on x86_64-linux (full log)

Attempted: git

Partial log (click to expand)

Hunk #3 succeeded at 255 (offset 34 lines).
applying patch /nix/store/39s7y2l1las6jpw36a1z257xzrwy1mj5-symlinks-in-bin.patch
patching file Makefile
Hunk #1 succeeded at 2590 (offset 271 lines).
applying patch /nix/store/qgb13c66qn0dp18rsnvy9ygbqassb0rk-git-sh-i18n.patch
patching file git-sh-i18n.sh
Hunk #1 FAILED at 15.
1 out of 1 hunk FAILED -- saving rejects to file git-sh-i18n.sh.rej
builder for '/nix/store/35hxg9qhi78v0l0k66b4xf47fagylpq4-git-2.16.4.drv' failed with exit code 1
error: build of '/nix/store/35hxg9qhi78v0l0k66b4xf47fagylpq4-git-2.16.4.drv' failed

@GrahamcOfBorg
Copy link

Failure on x86_64-darwin (full log)

Attempted: git

Partial log (click to expand)

Hunk #3 succeeded at 255 (offset 34 lines).
applying patch /nix/store/39s7y2l1las6jpw36a1z257xzrwy1mj5-symlinks-in-bin.patch
patching file Makefile
Hunk #1 succeeded at 2590 (offset 271 lines).
applying patch /nix/store/qgb13c66qn0dp18rsnvy9ygbqassb0rk-git-sh-i18n.patch
patching file git-sh-i18n.sh
Hunk #1 FAILED at 15.
1 out of 1 hunk FAILED -- saving rejects to file git-sh-i18n.sh.rej
builder for '/nix/store/bx862ckhp96mmd4a4d7c70k2ry02jy6h-git-2.16.4.drv' failed with exit code 1
�[31;1merror:�[0m build of '/nix/store/bx862ckhp96mmd4a4d7c70k2ry02jy6h-git-2.16.4.drv' failed

@andir
Copy link
Member

andir commented May 30, 2018

👍 thank you for working on this!

Please let me known if I can help. Was planning to do this during this morning anyway.

For reference this is about CVE 2018-11235.

@orivej
Copy link
Contributor Author

orivej commented May 30, 2018

@GrahamcOfBorg build git

(Forgot to include the updated patch.)

@andir Thanks!

@GrahamcOfBorg
Copy link

Success on x86_64-darwin (full log)

Attempted: git

Partial log (click to expand)

/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/buildsystems/engine.pl: interpreter directive changed from "/usr/bin/perl -w" to "/nix/store/fa84s5lidr4k4b44p5hxffmm15dk99gj-perl-5.24.3/bin/perl -w"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/buildsystems/generate: interpreter directive changed from "/usr/bin/perl -w" to "/nix/store/fa84s5lidr4k4b44p5hxffmm15dk99gj-perl-5.24.3/bin/perl -w"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/buildsystems/parse.pl: interpreter directive changed from "/usr/bin/perl -w" to "/nix/store/fa84s5lidr4k4b44p5hxffmm15dk99gj-perl-5.24.3/bin/perl -w"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/convert-grafts-to-replace-refs.sh: interpreter directive changed from "/bin/sh" to "/nix/store/rjglqbbmg27dwwyyqsnn62jcz6qwxkli-bash-4.4-p12/bin/sh"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/diff-highlight/t/t9400-diff-highlight.sh: interpreter directive changed from "/bin/sh" to "/nix/store/rjglqbbmg27dwwyyqsnn62jcz6qwxkli-bash-4.4-p12/bin/sh"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/remotes2config.sh: interpreter directive changed from "/bin/sh" to "/nix/store/rjglqbbmg27dwwyyqsnn62jcz6qwxkli-bash-4.4-p12/bin/sh"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/stats/packinfo.pl: interpreter directive changed from "/usr/bin/perl" to "/nix/store/fa84s5lidr4k4b44p5hxffmm15dk99gj-perl-5.24.3/bin/perl"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/stats/mailmap.pl: interpreter directive changed from "/usr/bin/perl" to "/nix/store/fa84s5lidr4k4b44p5hxffmm15dk99gj-perl-5.24.3/bin/perl"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4/share/git/contrib/stats/git-common-hash: interpreter directive changed from "/bin/sh" to "/nix/store/rjglqbbmg27dwwyyqsnn62jcz6qwxkli-bash-4.4-p12/bin/sh"
/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4

@GrahamcOfBorg
Copy link

Success on x86_64-linux (full log)

Attempted: git

Partial log (click to expand)

/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/remotes2config.sh: interpreter directive changed from "/bin/sh" to "/nix/store/zqh3l3lyw32q1ayb15bnvg9f24j5v2p0-bash-4.4-p12/bin/sh"
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/rerere-train.sh: interpreter directive changed from "/bin/sh" to "/nix/store/zqh3l3lyw32q1ayb15bnvg9f24j5v2p0-bash-4.4-p12/bin/sh"
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/stats/git-common-hash: interpreter directive changed from "/bin/sh" to "/nix/store/zqh3l3lyw32q1ayb15bnvg9f24j5v2p0-bash-4.4-p12/bin/sh"
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/stats/mailmap.pl: interpreter directive changed from "/usr/bin/perl" to "/nix/store/s029gmjpgvm776wfb56naqny9qja9339-perl-5.24.3/bin/perl"
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/stats/packinfo.pl: interpreter directive changed from "/usr/bin/perl" to "/nix/store/s029gmjpgvm776wfb56naqny9qja9339-perl-5.24.3/bin/perl"
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/thunderbird-patch-inline/appp.sh: interpreter directive changed from "/bin/sh" to "/nix/store/zqh3l3lyw32q1ayb15bnvg9f24j5v2p0-bash-4.4-p12/bin/sh"
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/update-unicode/update_unicode.sh: interpreter directive changed from "/bin/sh" to "/nix/store/zqh3l3lyw32q1ayb15bnvg9f24j5v2p0-bash-4.4-p12/bin/sh"
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4/share/git/contrib/workdir/git-new-workdir: interpreter directive changed from "/bin/sh" to "/nix/store/zqh3l3lyw32q1ayb15bnvg9f24j5v2p0-bash-4.4-p12/bin/sh"
checking for references to /build in /nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4...
/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4

@GrahamcOfBorg
Copy link

Success on x86_64-darwin (full log)

Attempted: git

Partial log (click to expand)

/nix/store/7cv9ldivb0v4qq070as3yxjmlijdpsjl-git-2.16.4

@GrahamcOfBorg
Copy link

Success on x86_64-linux (full log)

Attempted: git

Partial log (click to expand)

/nix/store/pkb9yjq2japg4sf0fzhfshkqsq7ygii2-git-2.16.4

@GrahamcOfBorg
Copy link

Success on aarch64-linux (full log)

Attempted: git

Partial log (click to expand)

/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/share/git/contrib/convert-grafts-to-replace-refs.sh: interpreter directive changed from "/bin/sh" to "/nix/store/1gk1g42x90yp3avlz3grxv917ppvqf5s-bash-4.4-p12/bin/sh"
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/share/git/contrib/contacts/git-contacts: interpreter directive changed from "/usr/bin/perl" to "/nix/store/inszkg183ykvif9rlz4bm3jbhzgyy4ax-perl-5.24.3/bin/perl"
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/share/git/contrib/buildsystems/parse.pl: interpreter directive changed from "/usr/bin/perl -w" to "/nix/store/inszkg183ykvif9rlz4bm3jbhzgyy4ax-perl-5.24.3/bin/perl -w"
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/share/git/contrib/buildsystems/generate: interpreter directive changed from "/usr/bin/perl -w" to "/nix/store/inszkg183ykvif9rlz4bm3jbhzgyy4ax-perl-5.24.3/bin/perl -w"
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/share/git/contrib/buildsystems/engine.pl: interpreter directive changed from "/usr/bin/perl -w" to "/nix/store/inszkg183ykvif9rlz4bm3jbhzgyy4ax-perl-5.24.3/bin/perl -w"
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/share/git-core/templates/hooks/fsmonitor-watchman.sample: interpreter directive changed from "/usr/bin/perl" to "/nix/store/inszkg183ykvif9rlz4bm3jbhzgyy4ax-perl-5.24.3/bin/perl"
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/libexec/git-core/git-subtree: interpreter directive changed from "/bin/sh" to "/nix/store/1gk1g42x90yp3avlz3grxv917ppvqf5s-bash-4.4-p12/bin/sh"
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4/libexec/git-core/git-gui--askpass: interpreter directive changed from "/bin/sh" to "/nix/store/1gk1g42x90yp3avlz3grxv917ppvqf5s-bash-4.4-p12/bin/sh"
checking for references to /build in /nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4...
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4

@GrahamcOfBorg
Copy link

Success on aarch64-linux (full log)

Attempted: git

Partial log (click to expand)

these derivations will be built:
  /nix/store/bx2yc56qimbabqxn7jvnbcyazckjr7v3-git-2.16.4.drv
waiting for locks or build slots...
/nix/store/0sfixadd91w9vp2p09rq0jq0npr9clf6-git-2.16.4

@orivej orivej merged commit 949cf43 into NixOS:release-18.03 May 30, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants