Dear colleagues,
I've just pushed a new OpenSSL build to rawhide.
The change compared to the previous one is incorporating the patch from
https://github.com/openssl/openssl/pull/13817. Some more details can be
found here:
https://github.com/openssl/openssl/issues/13421
Citing the change description,
We added and enabled by default implicit rejection in RSA PKCS#1 v1.5
decryption as a protection against Bleichenbacher-like attacks.
The RSA decryption API will now return a randomly generated deterministic
message instead of an error in case it detects an error when checking
padding during PKCS#1 v1.5 decryption. This is a general protection against
issues like CVE-2020-25659 and CVE-2020-25657. This protection can be
disabled by calling
`EVP_PKEY_CTX_ctrl_str(ctx, "rsa_pkcs1_implicit_rejection". "0")`
in the RSA decryption context.
--
Dmitry Belyavskiy
Two weeks ago we had:
> * 23184 spec files in Fedora
>
> * 29200 license tags in all spec files
>
> * 23682 tags have not been converted to SPDX yet
>
> * 9377 tags can be trivially converted using `license-fedora2spdx`
>
Today we have:
* 23030 spec files in Fedora
* 29390 license tags in all spec files
* 22766 tags have not been converted to SPDX yet
* 8986 tags can be trivially converted using `license-fedora2spdx`
The list of packages needed to be converted is again here:
https://pagure.io/copr/license-validate/blob/main/f/packages-without-spdx-f…
New version of fedora-license-data has been released.
I updated the progress in this spreadsheet:
https://docs.google.com/spreadsheets/d/1QVMEzXWML-6_Mrlln02axFAaRKCQ8zE807r…
Interresting things:
* The number of lines with License grow while number of spec file shrank. Is it because of bug in my script? Something else?
* You converted 1106 license tags in 14 days! You rock! This speed moved the ETA to finish to 2024-03-06.
* Due new licenses in fedora-license-data some packages that were notrivial to convert can be now trivially converted.
* Why Malanka? Because today is Malanka. https://en.wikipedia.org/wiki/Malanka
Do you hesitate how to proceed with the migration? Please follow
https://docs.fedoraproject.org/en-US/legal/update-existing-packages/
Miroslav
Hello.
the owners of SPDX Change proposal want to have this Change as smooth as possible. And we decided to setup Office hours.
Do you have any questions about SPDX migration?
Do you hesitate about what steps you should take?
How to proceed with your package? We will do our best to help you.
This is intended to be bi-weekly.
Every time in a different time, to match the time of different people in different time zones.
The first round will happen on Tuesday 2023-01-17 16:00-17:00 UTC. (17pm CET, 11am EST)
Google Meet joining info
Video call link: https://meet.google.com/xob-irug-qqd
Or dial: (CZ) +420 234 610 745 PIN: 559 590 845#
More phone numbers: https://tel.meet/xob-irug-qqd?pin=3490720094637
Or join via SIP: sip:3490720094637@gmeet.redhat.com
Miroslav
Hello all.
coeurl 0.3.0 will include a soversion bump from .0.2 to .0.3.
Affected packages:
- mtxclient
- nheko
I will rebuild the dependent packages for all supported Fedora releases.
--
Sincerely,
Vitaly Zaitsev (vitaly(a)easycoding.org)
Hey all,
The initial rebase of ImageMagick to v7 is landing in Rawhide now:
https://bodhi.fedoraproject.org/updates/FEDORA-2023-9d3e9afbfd
Most packages in the reverse dependency chain were rebuilt, though a
few are still left to fix and will be addressed separately.
The ones remaining are:
* autotrace (contacting upstream planned)
* q (dead upstream, orphaned)
* vdr-scraper2vdr (maybe dead upstream?)
* vdr-skinnopacity (dead upstream)
* vdr-tvguide (dead upstream)
Either these will switch to GraphicsMagick or we'll introduce an
ImageMagick6 compatibility package for them.
--
真実はいつも一つ!/ Always, there's only one truth!
It appears that all the dependent packages are now compatible (i.e., they
build).
The plan is to build them in a side tag over the next few days. The
dependencies are:
OpenImageIO
usd
blender
krita
luxcorerender
Thanks,
Richard
Dear all,
You are kindly invited to the meeting:
ELN SIG on 2023-01-13 from 12:00:00 to 13:00:00 US/Eastern
At fedora-meeting(a)irc.libera.chat
The meeting will be about:
Source: https://calendar.fedoraproject.org//meeting/10133/