Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 324953 - Packages still depending on vulnerable net-libs/xulrunner:1.8
Summary: Packages still depending on vulnerable net-libs/xulrunner:1.8
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Mozilla Gentoo Team
URL:
Whiteboard:
Keywords:
Depends on: 282162 316919
Blocks:
  Show dependency tree
 
Reported: 2010-06-21 14:43 UTC by Nirbheek Chauhan (RETIRED)
Modified: 2010-07-19 06:48 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nirbheek Chauhan (RETIRED) gentoo-dev 2010-06-21 14:43:24 UTC
Below is a full list (as far as I can tell) of packages which still depend on =xulrunner-1.8* or xulrunner:1.8.


dev-games/openscenegraph              (all versions)
dev-haskell/gtk2hs                    (all versions)
dev-java/swt-3.3.1.1-r1               (old version, kept around for fbsd)
dev-libs/libgeier-0.9                 (old version)
gnome-extra/yelp-2.24.0               (old version, kept around for mips & fbsd)
media-video/miro                      (all versions)
media-video/vlc                       (all versions, min xul ver should be upped)
net-news/liferea-1.4.15               (old version, kept around for sparc & fbsd)
www-client/epiphany-extensions-2.24.3 (old version, kept around for fbsd)
www-client/epiphany-2.24.3            (old version, kept around for fbsd)
www-client/kazehakase-0.5.6-r1        (old version, newer should be stabilized)
Comment 1 Samuli Suominen (RETIRED) gentoo-dev 2010-06-21 14:57:35 UTC
(In reply to comment #0)
> dev-libs/libgeier-0.9                 (old version)

removed from tree.
Comment 2 Tupone Alfredo gentoo-dev 2010-06-25 11:58:22 UTC
dev-games/openscenegraph no more depends on net-libs/xulrunner
Comment 3 Samuli Suominen (RETIRED) gentoo-dev 2010-06-26 07:49:46 UTC
(In reply to comment #0)
> media-video/miro                      (all versions)

Fixed. The depend was || ( xul:1.9 xul:1.8 ) so I've simply dropped the xul:1.8 from there. 
Comment 4 Samuli Suominen (RETIRED) gentoo-dev 2010-06-26 08:36:05 UTC
(In reply to comment #0)
> www-client/kazehakase-0.5.6-r1        (old version, newer should be stabilized)

nothing to stabilize, doesn't compile & work with xul192, fails to compile with gtk+-2.20 and so forth -> masked for removal
Comment 5 Samuli Suominen (RETIRED) gentoo-dev 2010-06-26 08:50:27 UTC
aballier, can you take care of vlc, please? i.e. force at least xulrunner-1.9 on vlc-1.0.6.ebuild (or stabilizing vlc-1.1.0 would so the trick as well)
Comment 6 Nirbheek Chauhan (RETIRED) gentoo-dev 2010-06-26 08:55:10 UTC
From the dusts of bugzilla, a glimmer was seen,
Ye olde bug from times unclean,
'tis was about some bug we'd seen,
a vulnerable removal we'd all foreseen.

Well, okay, bug 282162 isn't *that* old, but some of it's deps are. Adding to the dependency list.
Comment 7 Nirbheek Chauhan (RETIRED) gentoo-dev 2010-06-26 09:13:29 UTC
(In reply to comment #5)
> aballier, can you take care of vlc, please? i.e. force at least xulrunner-1.9
> on vlc-1.0.6.ebuild (or stabilizing vlc-1.1.0 would so the trick as well)
> 

He gave me permission a while back, and hence I've upped the version to 1.9:

(edited for clarity)
<aballier> nirbheek: feel free to change 1.0.6 to 1.9 if you wish, 1.1 requires 1.9 anyway
<nirbheek> aballier, okay
<aballier> nirbheek: the xul deps in vlc suck a bit though; it works with 1.8 and 1.9 and prefers 1.9 when available
<nirbheek> aballier, ah, so the deps should be fixed anyway :)
<aballier> nirbheek: not really, we should have a way to express this rather
<nirbheek> aballier, if 1.8 is leaving tree, we shouldn't bother, right?
<aballier> nirbheek: yep
Comment 8 Nirbheek Chauhan (RETIRED) gentoo-dev 2010-06-26 09:35:16 UTC
(In reply to comment #0)
> gnome-extra/yelp-2.24.0               (old version, kept around for mips &
> fbsd)
> media-video/vlc                       (all versions, min xul ver should be
> upped)
> www-client/epiphany-extensions-2.24.3 (old version, kept around for fbsd)
> www-client/epiphany-2.24.3            (old version, kept around for fbsd)

yelp/epiphany/epiphany-extensions removed
vlc xulrunner version fixed

At this point, swt & gtk2hs are the only ones left.
Comment 9 Nirbheek Chauhan (RETIRED) gentoo-dev 2010-06-26 09:49:35 UTC
(In reply to comment #8)
> At this point, swt & gtk2hs are the only ones left.
> 

Samuli pointed out that liferea-1.4.15 is also left. It is the only stable version of liferea on 'sparc', and the only version keyworded as '~x86-fbsd'.
Comment 10 Nirbheek Chauhan (RETIRED) gentoo-dev 2010-06-26 11:00:22 UTC
(In reply to comment #0)
> dev-java/swt-3.3.1.1-r1               (old version, kept around for fbsd)

Betelgeuse gave permission to remove this for xulrunner:1.8, but there's two new packages that depend on it, see bug 282289
Comment 11 Samuli Suominen (RETIRED) gentoo-dev 2010-07-19 06:48:47 UTC
gone