Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] [Fwd: xorg-x11 [6.7.0-r2, 6.8.0-r1] security updates: Ref Bugs 64152, 63994]
Date: Sun, 19 Sep 2004 16:57:42
Message-Id: 1095613013.26130.4719.camel@simple
1 -----Forwarded Message-----
2 From: Ferris McCormick <fmccor@g.o>
3 To: gentoo-sparc@l.g.o
4 Cc: sparc@g.o, x11@g.o, solar@g.o, koon@g.o, seemant@g.o
5 Subject: xorg-x11 [6.7.0-r2, 6.8.0-r1] security updates: Ref Bugs 64152, 63994
6 Date: Sun, 19 Sep 2004 16:43:00 +0000
7
8 -----BEGIN PGP SIGNED MESSAGE-----
9 Hash: SHA1
10
11 Security upgrades to xorg-x11 are available for testing.
12
13 For details, please see the Referenced Bugs, then continue below {/me puts
14 on his lawyer hat: "Referenced Bugs 64152, 63994, and supplementary
15 documentation re 63994 at
16 http://dev.gentoo.org/~fmccor/files/xorg-x11-6.7.99.903-build_notes.txt
17 http://dev.gentoo.org/~fmccor/files/xorg-status-tests.txt
18 incorporated herein by reference."}
19
20 OK. Back with me? Let's go on.
21
22 You should upgrade to 6.7.0-r2 or 6.8.0-r1 if you use X11. Ultimately,
23 6.8.0-r1 & on is your better choice, but there are other considerations.
24 Briefly, the following all seem to be correct:
25
26 1. xorg.conf between the two might differ slightly, based on what you
27 have now.
28 2. If you are running hardened, you MUST use 6.8.0-r1 to upgrade (and
29 patch ebuild by hand -- see below, that's why 6.8.0-r1 is not the
30 only option).
31 3. If you are any of the following, to upgrade to 6.8.0-r1, you MUST
32 apply by hand the patch at Bug 63994 to the ebuild.
33 a. Hardened
34 b. kernel-2.4.xx
35 c. sparc32 (included in b)
36 d. Adventurous and wish to play with ffb_dri (or maybe mach64_dri)
37 4. Except that if you are running kernel-2.6.6,7 not hardened, you
38 might not need the patch for 6.8.0-r1, and with kernel-2.6.6 (but
39 NOT with 2.6.7) you can still play with ffb_dri.
40
41 Why the patch? Well, you need it for reasons explained at great length
42 in the incorporated documents, but briefly: (1) There seems to be
43 a problem someplace in the new keyboard driver+kernel-2.4.xx+sun-keyboard;
44 (2) sparc32 can run into the "compiler gets lost" syndrome while
45 building r128_drv video driver. (3) You can't build xorg-x11 hardened
46 for sparc because of some xorg loader problems, so if you are hardened
47 you need a way to make the build work.
48
49 Since most sparc systems are (I believe) currently kernel-2.4.26,7, no
50 6.8.0 xorg release can have a sparc keyword because we know it won't
51 work without this patch (or equivalent, or until someone tells me what
52 I am doing wrong with specifying the keyboard. At best, xorg.conf
53 between the two is quite incompatible.)
54
55 So, until x11 integrates the sparc-specific tweaks with the official
56 ebuild, you have to do it yourself.
57
58 This is all the information I have. Please consider one alternative
59 for upgrade and testing and feed back the results. If you choose to
60 try 6.8.0-r1, PLEAEE also record your results at Bug 63994 --- that's
61 one reason it's there.
62
63 If you are still with me, thanks for reading this far.
64 Regards,
65 Ferris
66
67 - --
68 Ferris McCormick (P44646, MI) <fmccor@g.o>
69 Developer, Gentoo Linux (sparc)
70 -----BEGIN PGP SIGNATURE-----
71 Version: GnuPG v1.2.4 (GNU/Linux)
72
73 iD8DBQFBTbcYQa6M3+I///cRAsXKAKDl1XVtfHwaE3ln0ixIY80FZbDOnACfdoeN
74 bVcx47SsmH0HuOdYa2++/WY=
75 =QEe5
76 -----END PGP SIGNATURE-----
77 --
78 Ned Ludd <solar@g.o>
79 Gentoo (hardened,security,infrastructure,embedded,toolchain) Developer

Attachments

File name MIME type
signature.asc application/pgp-signature