[libvirt] [PATCH] build: update to latest gnulib, for secure tarball

Eric Blake eblake at redhat.com
Fri Jul 27 18:43:53 UTC 2012


On 07/27/2012 11:18 AM, Eric Blake wrote:
> On 07/26/2012 07:52 AM, Eric Blake wrote:
>> On 07/26/2012 07:45 AM, Daniel P. Berrange wrote:
>>> On Fri, Jul 20, 2012 at 05:39:43PM -0600, Eric Blake wrote:
>>>> Pick up some build fixes in the latest gnulib.  In particular,
>>>> we want to ensure that official tarballs are secure, but don't
>>>> want to penalize people who don't run 'make dist', since fixed
>>>> automake still hasn't hit common platforms like Fedora 17.
>>>>
>>>> * .gnulib: Update to latest, for Automake CVE-2012-3386 detection.
> 
>>> ACK, since only 'make dist' people are forced to install new
>>> automake.
>>
>> Thanks, pushed, and I'm also backporting it to the maint branches.
> 
> Now pushed to v0.9.6-maint; I'm still working on v0.9.11.maint.

Done as well.

Cole, I also backported the fix for BZ 843836 to v0.9.11-maint; be aware
that when you cut a new build for Fedora 17, you will need a fixed
automake on your PATH.

-- 
Eric Blake   eblake at redhat.com    +1-919-301-3266
Libvirt virtualization library http://libvirt.org

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 620 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/libvir-list/attachments/20120727/f3063940/attachment-0001.sig>


More information about the libvir-list mailing list