Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

libarchive: pull the fix for a suspicious commit #300114

Merged

Conversation

LeSuisse
Copy link
Contributor

@LeSuisse LeSuisse commented Mar 29, 2024

Description of changes

This is a follow-up to the downgrade to version older than 5.6.x made in #300028 (also known as CVE-2024-3094).
A suspicious commit made by the same actor has been spotted in libarchive and following up discussions a change has been made by contributor and merged by another maintainer.

Things done

  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandboxing enabled in nix.conf? (See Nix manual)
    • sandbox = relaxed
    • sandbox = true
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • 24.05 Release Notes (or backporting 23.05 and 23.11 Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
  • Fits CONTRIBUTING.md.

Add a 馃憤 reaction to pull requests you find important.

This is a follow-up to the downgrade to version older than 5.6.x made in NixOS#300028
(also known as CVE-2024-3094).
A suspicious commit made by the same actor has been spotted in
libarchive and following up discussions a change has been made by
contributor and merged by another maintainer.
@LeSuisse LeSuisse force-pushed the libarchive-suspicious-commit-bad-actor branch from 2219caf to b3743f7 Compare March 29, 2024 23:20
@LeSuisse LeSuisse added the backport staging-23.11 Backport PR automatically label Mar 29, 2024
@LeSuisse LeSuisse marked this pull request as ready for review March 29, 2024 23:25
@LeSuisse
Copy link
Contributor Author

Likely too early, we might need to wait a bit to let the dust settle: libarchive/libarchive#1609 (comment)

@LeSuisse LeSuisse marked this pull request as draft March 29, 2024 23:48
@joepie91
Copy link
Contributor

AIUI, the issues mentioned in that comment are additional issues; and reverting the suspicious commit would be valuable regardless of whether those additional issues are valid and/or are fixed in the future.

@LeSuisse
Copy link
Contributor Author

Agreed, opened #300122 closing this one for now.

@tomfitzhenry
Copy link
Contributor

Likely too early, we might need to wait a bit to let the dust settle: libarchive/libarchive#1609 (comment)

Looks like the PR has settled on that patch being acceptable/sufficient: libarchive/libarchive#1609 (comment)

I see Debian have released this too: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068047

We should stick with upstream, since their change has gone through the right level of review. I'm happy to approve and merge this PR if it's re-opened.

@LeSuisse LeSuisse restored the libarchive-suspicious-commit-bad-actor branch April 1, 2024 11:13
@LeSuisse LeSuisse reopened this Apr 1, 2024
@tomfitzhenry
Copy link
Contributor

@LeSuisse, nice work on responding to this issue! :)

Please mark as ready for review, to allow this to be merged.

It's worth us waiting for CI to pass too, given libarchive is a dependency of Nix.

@LeSuisse LeSuisse marked this pull request as ready for review April 1, 2024 13:47
@tomfitzhenry tomfitzhenry merged commit 1287b64 into NixOS:staging Apr 1, 2024
36 of 38 checks passed
Copy link
Contributor

github-actions bot commented Apr 1, 2024

Successfully created backport PR for staging-23.11:

@LeSuisse LeSuisse deleted the libarchive-suspicious-commit-bad-actor branch April 1, 2024 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants