Mailing List Archive

[Fwd: xorg-x11 [6.7.0-r2, 6.8.0-r1] security updates: Ref Bugs 64152, 63994]
-----Forwarded Message-----
From: Ferris McCormick <fmccor@gentoo.org>
To: gentoo-sparc@lists.gentoo.org
Cc: sparc@gentoo.org, x11@gentoo.org, solar@gentoo.org, koon@gentoo.org, seemant@gentoo.org
Subject: xorg-x11 [6.7.0-r2, 6.8.0-r1] security updates: Ref Bugs 64152, 63994
Date: Sun, 19 Sep 2004 16:43:00 +0000

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Security upgrades to xorg-x11 are available for testing.

For details, please see the Referenced Bugs, then continue below {/me puts
on his lawyer hat: "Referenced Bugs 64152, 63994, and supplementary
documentation re 63994 at
http://dev.gentoo.org/~fmccor/files/xorg-x11-6.7.99.903-build_notes.txt
http://dev.gentoo.org/~fmccor/files/xorg-status-tests.txt
incorporated herein by reference."}

OK. Back with me? Let's go on.

You should upgrade to 6.7.0-r2 or 6.8.0-r1 if you use X11. Ultimately,
6.8.0-r1 & on is your better choice, but there are other considerations.
Briefly, the following all seem to be correct:

1. xorg.conf between the two might differ slightly, based on what you
have now.
2. If you are running hardened, you MUST use 6.8.0-r1 to upgrade (and
patch ebuild by hand -- see below, that's why 6.8.0-r1 is not the
only option).
3. If you are any of the following, to upgrade to 6.8.0-r1, you MUST
apply by hand the patch at Bug 63994 to the ebuild.
a. Hardened
b. kernel-2.4.xx
c. sparc32 (included in b)
d. Adventurous and wish to play with ffb_dri (or maybe mach64_dri)
4. Except that if you are running kernel-2.6.6,7 not hardened, you
might not need the patch for 6.8.0-r1, and with kernel-2.6.6 (but
NOT with 2.6.7) you can still play with ffb_dri.

Why the patch? Well, you need it for reasons explained at great length
in the incorporated documents, but briefly: (1) There seems to be
a problem someplace in the new keyboard driver+kernel-2.4.xx+sun-keyboard;
(2) sparc32 can run into the "compiler gets lost" syndrome while
building r128_drv video driver. (3) You can't build xorg-x11 hardened
for sparc because of some xorg loader problems, so if you are hardened
you need a way to make the build work.

Since most sparc systems are (I believe) currently kernel-2.4.26,7, no
6.8.0 xorg release can have a sparc keyword because we know it won't
work without this patch (or equivalent, or until someone tells me what
I am doing wrong with specifying the keyboard. At best, xorg.conf
between the two is quite incompatible.)

So, until x11 integrates the sparc-specific tweaks with the official
ebuild, you have to do it yourself.

This is all the information I have. Please consider one alternative
for upgrade and testing and feed back the results. If you choose to
try 6.8.0-r1, PLEAEE also record your results at Bug 63994 --- that's
one reason it's there.

If you are still with me, thanks for reading this far.
Regards,
Ferris

- --
Ferris McCormick (P44646, MI) <fmccor@gentoo.org>
Developer, Gentoo Linux (sparc)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBTbcYQa6M3+I///cRAsXKAKDl1XVtfHwaE3ln0ixIY80FZbDOnACfdoeN
bVcx47SsmH0HuOdYa2++/WY=
=QEe5
-----END PGP SIGNATURE-----
--
Ned Ludd <solar@gentoo.org>
Gentoo (hardened,security,infrastructure,embedded,toolchain) Developer