gnu: tar: Fix CVE-2016-6321.
[jackhill/guix/guix.git] / gnu / local.mk
index 7937809..00f47e3 100644 (file)
@@ -7,6 +7,8 @@
 # Copyright © 2016 Kei Kebreau <kei@openmailbox.org>
 # Copyright © 2016 Rene Saavedra <rennes@openmailbox.org>
 # Copyright © 2016 Adonay "adfeno" Felipe Nogueira <https://libreplanet.org/wiki/User:Adfeno> <adfeno@openmailbox.org>
+# Copyright © 2016 Ricardo Wurmus <rekado@elephly.net>
+# Copyright © 2016 Ben Woodcroft <donttrustben@gmail.com>
 #
 # This file is part of GNU Guix.
 #
@@ -293,6 +295,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/pem.scm                         \
   %D%/packages/perl.scm                                \
   %D%/packages/photo.scm                       \
+  %D%/packages/php.scm                         \
   %D%/packages/pkg-config.scm                  \
   %D%/packages/plotutils.scm                   \
   %D%/packages/polkit.scm                      \
@@ -302,7 +305,6 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/pumpio.scm                      \
   %D%/packages/pretty-print.scm                        \
   %D%/packages/protobuf.scm                    \
-  %D%/packages/psyc.scm                         \
   %D%/packages/pv.scm                          \
   %D%/packages/python.scm                      \
   %D%/packages/qemu.scm                                \
@@ -347,6 +349,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/swig.scm                                \
   %D%/packages/sxiv.scm                                \
   %D%/packages/synergy.scm                     \
+  %D%/packages/syndication.scm                 \
   %D%/packages/task-management.scm             \
   %D%/packages/tbb.scm                         \
   %D%/packages/tcl.scm                         \
@@ -360,6 +363,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/tmux.scm                                \
   %D%/packages/tor.scm                         \
   %D%/packages/tv.scm                          \
+  %D%/packages/uml.scm                         \
   %D%/packages/unrtf.scm                       \
   %D%/packages/upnp.scm                                \
   %D%/packages/uucp.scm                                \
@@ -395,11 +399,13 @@ GNU_SYSTEM_MODULES =                              \
   %D%/services/admin.scm                       \
   %D%/services/avahi.scm                       \
   %D%/services/base.scm                                \
+  %D%/services/configuration.scm               \
   %D%/services/cups.scm                                \
   %D%/services/databases.scm                   \
   %D%/services/dbus.scm                                \
   %D%/services/desktop.scm                     \
   %D%/services/dict.scm                                \
+  %D%/services/kerberos.scm                    \
   %D%/services/lirc.scm                                \
   %D%/services/mail.scm                                \
   %D%/services/mcron.scm                       \
@@ -410,6 +416,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/services/sddm.scm                                \
   %D%/services/spice.scm                               \
   %D%/services/ssh.scm                         \
+  %D%/services/version-control.scm              \
   %D%/services/web.scm                         \
   %D%/services/xorg.scm                                \
                                                \
@@ -499,6 +506,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/cssc-missing-include.patch               \
   %D%/packages/patches/clucene-contribs-lib.patch               \
   %D%/packages/patches/cursynth-wave-rand.patch                        \
+  %D%/packages/patches/cyrus-sasl-CVE-2013-4122.patch          \
   %D%/packages/patches/dbus-helper-search-path.patch           \
   %D%/packages/patches/devil-CVE-2009-3994.patch               \
   %D%/packages/patches/devil-fix-libpng.patch                  \
@@ -528,7 +536,6 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/fasthenry-spFactor.patch                        \
   %D%/packages/patches/findutils-localstatedir.patch           \
   %D%/packages/patches/findutils-test-xargs.patch              \
-  %D%/packages/patches/flex-CVE-2016-6354.patch                        \
   %D%/packages/patches/flint-ldconfig.patch                    \
   %D%/packages/patches/fltk-shared-lib-defines.patch           \
   %D%/packages/patches/fltk-xfont-on-demand.patch              \
@@ -539,14 +546,18 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/gcc-arm-bug-71399.patch                 \
   %D%/packages/patches/gcc-arm-link-spec-fix.patch             \
   %D%/packages/patches/gcc-cross-environment-variables.patch   \
+  %D%/packages/patches/gcc-libiberty-printf-decl.patch         \
   %D%/packages/patches/gcc-libvtv-runpath.patch                        \
+  %D%/packages/patches/gcc-strmov-store-file-names.patch       \
   %D%/packages/patches/gcc-5.0-libvtv-runpath.patch            \
   %D%/packages/patches/gcc-6-arm-none-eabi-multilib.patch      \
   %D%/packages/patches/gcc-6-cross-environment-variables.patch \
   %D%/packages/patches/gd-CVE-2016-7568.patch                  \
   %D%/packages/patches/gd-CVE-2016-8670.patch                  \
+  %D%/packages/patches/gd-fix-chunk-size-on-boundaries.patch   \
   %D%/packages/patches/gd-fix-gd2-read-test.patch              \
   %D%/packages/patches/gd-fix-tests-on-i686.patch              \
+  %D%/packages/patches/gd-fix-truecolor-format-correction.patch        \
   %D%/packages/patches/gegl-CVE-2012-4433.patch                        \
   %D%/packages/patches/geoclue-config.patch                    \
   %D%/packages/patches/ghostscript-CVE-2013-5653.patch         \
@@ -575,12 +586,17 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/grub-gets-undeclared.patch              \
   %D%/packages/patches/grub-freetype.patch                     \
   %D%/packages/patches/gsl-test-i686.patch                     \
+  %D%/packages/patches/gst-plugins-good-fix-crashes.patch      \
+  %D%/packages/patches/gst-plugins-good-fix-invalid-read.patch \
+  %D%/packages/patches/gst-plugins-good-fix-signedness.patch   \
+  %D%/packages/patches/gst-plugins-good-flic-bounds-check.patch        \
   %D%/packages/patches/guile-1.8-cpp-4.5.patch                 \
   %D%/packages/patches/guile-arm-fixes.patch                   \
   %D%/packages/patches/guile-default-utf8.patch                        \
   %D%/packages/patches/guile-linux-syscalls.patch              \
   %D%/packages/patches/guile-present-coding.patch              \
   %D%/packages/patches/guile-relocatable.patch                 \
+  %D%/packages/patches/guile-repl-server-test.patch            \
   %D%/packages/patches/guile-rsvg-pkgconfig.patch              \
   %D%/packages/patches/gtk2-respect-GUIX_GTK2_PATH.patch       \
   %D%/packages/patches/gtk2-respect-GUIX_GTK2_IM_MODULE_FILE.patch \
@@ -588,6 +604,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/gtk3-respect-GUIX_GTK3_PATH.patch       \
   %D%/packages/patches/gtk3-respect-GUIX_GTK3_IM_MODULE_FILE.patch \
   %D%/packages/patches/gtkglext-disable-disable-deprecated.patch \
+  %D%/packages/patches/handbrake-pkg-config-path.patch         \
   %D%/packages/patches/hdf4-architectures.patch                \
   %D%/packages/patches/hdf4-reproducibility.patch              \
   %D%/packages/patches/hdf4-shared-fortran.patch               \
@@ -605,6 +622,8 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/hypre-doc-tables.patch                  \
   %D%/packages/patches/hypre-ldflags.patch                     \
   %D%/packages/patches/icecat-avoid-bundled-libraries.patch    \
+  %D%/packages/patches/icecat-binutils.patch                   \
+  %D%/packages/patches/icecat-CVE-2016-9064.patch              \
   %D%/packages/patches/icu4c-CVE-2014-6585.patch               \
   %D%/packages/patches/icu4c-CVE-2015-1270.patch               \
   %D%/packages/patches/icu4c-CVE-2015-4760.patch               \
@@ -612,7 +631,6 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/ilmbase-fix-tests.patch                 \
   %D%/packages/patches/inkscape-drop-wait-for-targets.patch    \
   %D%/packages/patches/isl-0.11.1-aarch64-support.patch        \
-  %D%/packages/patches/jansson-CVE-2016-4425.patch             \
   %D%/packages/patches/jbig2dec-ignore-testtest.patch          \
   %D%/packages/patches/jq-CVE-2015-8863.patch                  \
   %D%/packages/patches/khmer-use-libraries.patch                \
@@ -629,16 +647,14 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/liba52-link-with-libm.patch             \
   %D%/packages/patches/liba52-set-soname.patch                 \
   %D%/packages/patches/liba52-use-mtune-not-mcpu.patch         \
-  %D%/packages/patches/libarchive-7zip-heap-overflow.patch     \
-  %D%/packages/patches/libarchive-fix-symlink-check.patch      \
-  %D%/packages/patches/libarchive-fix-filesystem-attacks.patch \
-  %D%/packages/patches/libarchive-safe_fprintf-buffer-overflow.patch   \
   %D%/packages/patches/libbonobo-activation-test-race.patch    \
   %D%/packages/patches/libcanberra-sound-theme-freedesktop.patch \
   %D%/packages/patches/libcmis-fix-test-onedrive.patch         \
   %D%/packages/patches/libdrm-symbol-check.patch               \
   %D%/packages/patches/libevent-dns-tests.patch                        \
   %D%/packages/patches/libextractor-ffmpeg-3.patch             \
+  %D%/packages/patches/libjxr-fix-function-signature.patch     \
+  %D%/packages/patches/libjxr-fix-typos.patch                  \
   %D%/packages/patches/liboop-mips64-deplibs-fix.patch         \
   %D%/packages/patches/libotr-test-auth-fix.patch              \
   %D%/packages/patches/liblxqt-include.patch                   \
@@ -649,17 +665,6 @@ dist_patch_DATA =                                          \
   %D%/packages/patches/libssh-0.6.5-CVE-2016-0739.patch                \
   %D%/packages/patches/libtar-CVE-2013-4420.patch \
   %D%/packages/patches/libtheora-config-guess.patch            \
-  %D%/packages/patches/libtiff-CVE-2015-8665+CVE-2015-8683.patch \
-  %D%/packages/patches/libtiff-CVE-2016-3623.patch             \
-  %D%/packages/patches/libtiff-CVE-2016-3945.patch             \
-  %D%/packages/patches/libtiff-CVE-2016-3990.patch             \
-  %D%/packages/patches/libtiff-CVE-2016-3991.patch             \
-  %D%/packages/patches/libtiff-CVE-2016-5314.patch             \
-  %D%/packages/patches/libtiff-CVE-2016-5321.patch             \
-  %D%/packages/patches/libtiff-CVE-2016-5323.patch             \
-  %D%/packages/patches/libtiff-CVE-2016-5652.patch             \
-  %D%/packages/patches/libtiff-oob-accesses-in-decode.patch    \
-  %D%/packages/patches/libtiff-oob-write-in-nextdecode.patch   \
   %D%/packages/patches/libtool-skip-tests2.patch               \
   %D%/packages/patches/libunwind-CVE-2015-3239.patch           \
   %D%/packages/patches/libupnp-CVE-2016-6255.patch             \
@@ -678,6 +683,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/libwmf-CVE-2015-4695.patch              \
   %D%/packages/patches/libwmf-CVE-2015-4696.patch              \
   %D%/packages/patches/libxslt-generated-ids.patch             \
+  %D%/packages/patches/libxslt-CVE-2016-4738.patch             \
   %D%/packages/patches/linux-pam-no-setfsuid.patch             \
   %D%/packages/patches/lirc-localstatedir.patch                        \
   %D%/packages/patches/llvm-for-extempore.patch                        \
@@ -686,11 +692,11 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/lua-pkgconfig.patch                      \
   %D%/packages/patches/lua51-liblua-so.patch                    \
   %D%/packages/patches/lua51-pkgconfig.patch                    \
-  %D%/packages/patches/lua52-liblua-so.patch                    \
+  %D%/packages/patches/lua-liblua-so.patch                      \
   %D%/packages/patches/luajit-no_ldconfig.patch                        \
   %D%/packages/patches/luajit-symlinks.patch                   \
   %D%/packages/patches/luit-posix.patch                                \
-  %D%/packages/patches/m4-gets-undeclared.patch                        \
+  %D%/packages/patches/lvm2-static-link.patch                  \
   %D%/packages/patches/make-impure-dirs.patch                  \
   %D%/packages/patches/mars-install.patch                      \
   %D%/packages/patches/mars-sfml-2.3.patch                     \
@@ -710,7 +716,14 @@ dist_patch_DATA =                                          \
   %D%/packages/patches/mupdf-build-with-openjpeg-2.1.patch     \
   %D%/packages/patches/mupdf-CVE-2016-6265.patch               \
   %D%/packages/patches/mupdf-CVE-2016-6525.patch               \
+  %D%/packages/patches/mupdf-CVE-2016-7504.patch               \
+  %D%/packages/patches/mupdf-CVE-2016-7505.patch               \
+  %D%/packages/patches/mupdf-CVE-2016-7506.patch               \
+  %D%/packages/patches/mupdf-CVE-2016-7563.patch               \
+  %D%/packages/patches/mupdf-CVE-2016-7564.patch               \
   %D%/packages/patches/mupdf-CVE-2016-8674.patch               \
+  %D%/packages/patches/mupdf-CVE-2016-9017.patch               \
+  %D%/packages/patches/mupdf-CVE-2016-9136.patch               \
   %D%/packages/patches/mupen64plus-ui-console-notice.patch     \
   %D%/packages/patches/musl-CVE-2016-8859.patch                        \
   %D%/packages/patches/mutt-store-references.patch             \
@@ -729,6 +742,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/nvi-db4.patch                           \
   %D%/packages/patches/ocaml-CVE-2015-8869.patch               \
   %D%/packages/patches/ocaml-findlib-make-install.patch        \
+  %D%/packages/patches/ola-readdir-r.patch                     \
   %D%/packages/patches/onionshare-fix-install-paths.patch              \
   %D%/packages/patches/openexr-missing-samples.patch           \
   %D%/packages/patches/openjpeg-CVE-2015-6581.patch            \
@@ -768,6 +782,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/pinball-src-deps.patch                  \
   %D%/packages/patches/pinball-system-ltdl.patch               \
   %D%/packages/patches/pingus-sdl-libs-config.patch            \
+  %D%/packages/patches/pixman-CVE-2016-5296.patch              \
   %D%/packages/patches/plink-1.07-unclobber-i.patch            \
   %D%/packages/patches/plink-endian-detection.patch            \
   %D%/packages/patches/plotutils-libpng-jmpbuf.patch           \
@@ -792,10 +807,8 @@ dist_patch_DATA =                                          \
   %D%/packages/patches/python-3.4-fix-tests.patch              \
   %D%/packages/patches/python-3.5-fix-tests.patch              \
   %D%/packages/patches/python-dendropy-exclude-failing-tests.patch \
-  %D%/packages/patches/python-django-fix-testcase.patch                \
   %D%/packages/patches/python-file-double-encoding-bug.patch   \
   %D%/packages/patches/python-fix-tests.patch                  \
-  %D%/packages/patches/python-ipython-inputhook-ctype.patch    \
   %D%/packages/patches/python-parse-too-many-fields.patch      \
   %D%/packages/patches/python-rarfile-fix-tests.patch          \
   %D%/packages/patches/python2-rdflib-drop-sparqlwrapper.patch \
@@ -812,6 +825,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/rapicorn-isnan.patch                    \
   %D%/packages/patches/ratpoison-shell.patch                   \
   %D%/packages/patches/readline-link-ncurses.patch             \
+  %D%/packages/patches/readline-6.2-CVE-2014-2524.patch                \
   %D%/packages/patches/ripperx-missing-file.patch              \
   %D%/packages/patches/rpm-CVE-2014-8118.patch                 \
   %D%/packages/patches/rsem-makefile.patch                     \
@@ -820,6 +834,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/ruby-rack-ignore-failing-test.patch      \
   %D%/packages/patches/ruby-symlinkfix.patch                    \
   %D%/packages/patches/ruby-tzinfo-data-ignore-broken-test.patch\
+  %D%/packages/patches/ruby-yard-fix-skip-of-markdown-tests.patch \
   %D%/packages/patches/sed-hurd-path-max.patch                 \
   %D%/packages/patches/scheme48-tests.patch                    \
   %D%/packages/patches/scotch-test-threading.patch             \
@@ -842,6 +857,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/t1lib-CVE-2010-2642.patch               \
   %D%/packages/patches/t1lib-CVE-2011-0764.patch               \
   %D%/packages/patches/t1lib-CVE-2011-1552+CVE-2011-1553+CVE-2011-1554.patch           \
+  %D%/packages/patches/tar-CVE-2016-6321.patch                 \
   %D%/packages/patches/tar-skip-unreliable-tests.patch         \
   %D%/packages/patches/tcl-mkindex-deterministic.patch         \
   %D%/packages/patches/tclxml-3.2-install.patch                        \
@@ -881,12 +897,7 @@ dist_patch_DATA =                                          \
   %D%/packages/patches/vte-CVE-2012-2738-pt1.patch                     \
   %D%/packages/patches/vte-CVE-2012-2738-pt2.patch                     \
   %D%/packages/patches/vtk-mesa-10.patch                       \
-  %D%/packages/patches/w3m-libgc.patch                         \
-  %D%/packages/patches/w3m-force-ssl_verify_server-on.patch    \
-  %D%/packages/patches/w3m-disable-sslv2-and-sslv3.patch       \
-  %D%/packages/patches/w3m-disable-weak-ciphers.patch          \
   %D%/packages/patches/weechat-python.patch                    \
-  %D%/packages/patches/weex-vacopy.patch                       \
   %D%/packages/patches/wicd-bitrate-none-fix.patch             \
   %D%/packages/patches/wicd-get-selected-profile-fix.patch     \
   %D%/packages/patches/wicd-urwid-1.3.patch                    \