Gentoo Archives: gentoo-dev

From: Rolf Eike Beer <eike@×××××××.de>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Needs ideas: Upcoming circular dependency: expat <> CMake
Date: Thu, 19 Dec 2019 13:40:31
Message-Id: c9b3c0e9fb9d46973235431f10f6ff7f@sf-mail.de
In Reply to: Re: [gentoo-dev] Needs ideas: Upcoming circular dependency: expat <> CMake by Francesco Riosa
1 Am 2019-12-18 22:44, schrieb Francesco Riosa:
2 > Il giorno mer 18 dic 2019 alle ore 22:03 Sebastian Pipping
3 > <sping@g.o>
4 > ha scritto:
5 >
6 >>
7 >> CMake bundles a (previously outdated and vulnerable) copy of expat so
8 >> I'm not sure if re-activating that bundle — say with a new use flag
9 >> "system-expat" — would be a good thing to resort to for breaking the
10 >> cycle, with regard to security in particular.
11 >>
12 > Pushing gently upstream to upgrade bundled expat copy would (at least
13 > temporarily) fix the issue and also benefit other use cases. Maybe they
14 > are
15 > Gentoo friendly
16 > they also release quite often, which would fix the problem soon
17
18 This is in CMake 3.16.0:
19
20 commit 50bc359184472700e9776a0a9d6f7e06ea82b9ce
21 Author: Brad King <brad.king@×××××××.com>
22 Date: Mon Nov 11 10:44:17 2019 -0500
23
24 expat: Update CMake build for 2.2.9
25
26 commit b63a5c88a2089494e53f22f83db1925435161934
27 Merge: 512fabaa9d 1712885b4f
28 Author: Brad King <brad.king@×××××××.com>
29 Date: Mon Nov 11 10:42:32 2019 -0500
30
31 Merge branch 'upstream-expat' into update-expat
32
33 * upstream-expat:
34 expat 2019-09-25 (a7bc26b6)
35
36 These things _are_ updated regularly, but in case something is missed
37 just file a bug at gitlab.kitware.com. All these bundled thing bumps are
38 scripted as far as possible, so the actual overhead is quite small.
39
40 Eike

Replies