gnu: optipng: Fix CVE-2017-1000229.
[jackhill/guix/guix.git] / gnu / local.mk
index f3baadd..19db3c4 100644 (file)
@@ -11,6 +11,7 @@
 # Copyright © 2016 Ben Woodcroft <donttrustben@gmail.com>
 # Copyright © 2016, 2017 Alex Vong <alexvong1995@gmail.com>
 # Copyright © 2016, 2017 Efraim Flashner <efraim@flashner.co.il>
+# Copyright © 2016, 2017 Jan Nieuwenhuizen <janneke@gnu.org>
 # Copyright © 2017 Tobias Geerinckx-Rice <me@tobias.gr>
 # Copyright © 2017 Clément Lassieur <clement@lassieur.org>
 # Copyright © 2017 Mathieu Othacehe <m.othacehe@gmail.com>
@@ -66,6 +67,7 @@ GNU_SYSTEM_MODULES =                          \
   %D%/packages/autotools.scm                   \
   %D%/packages/avahi.scm                       \
   %D%/packages/avr.scm                         \
+  %D%/packages/axoloti.scm                     \
   %D%/packages/backup.scm                      \
   %D%/packages/base.scm                                \
   %D%/packages/bash.scm                                \
@@ -87,6 +89,7 @@ GNU_SYSTEM_MODULES =                          \
   %D%/packages/check.scm                       \
   %D%/packages/chez.scm                                \
   %D%/packages/ci.scm                          \
+  %D%/packages/cinnamon.scm                    \
   %D%/packages/cmake.scm                       \
   %D%/packages/cobol.scm                       \
   %D%/packages/code.scm                                \
@@ -198,6 +201,9 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/gv.scm                          \
   %D%/packages/gxmessage.scm                   \
   %D%/packages/haskell.scm                     \
+  %D%/packages/haskell-check.scm               \
+  %D%/packages/haskell-crypto.scm              \
+  %D%/packages/haskell-web.scm                 \
   %D%/packages/ham-radio.scm                   \
   %D%/packages/hexedit.scm                     \
   %D%/packages/hugs.scm                                \
@@ -319,6 +325,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/pdf.scm                         \
   %D%/packages/pem.scm                         \
   %D%/packages/perl.scm                                \
+  %D%/packages/perl-check.scm                  \
   %D%/packages/perl-web.scm                    \
   %D%/packages/photo.scm                       \
   %D%/packages/php.scm                         \
@@ -334,6 +341,8 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/protobuf.scm                    \
   %D%/packages/pv.scm                          \
   %D%/packages/python.scm                      \
+  %D%/packages/python-crypto.scm               \
+  %D%/packages/python-web.scm                  \
   %D%/packages/tryton.scm                      \
   %D%/packages/qt.scm                          \
   %D%/packages/ragel.scm                       \
@@ -382,6 +391,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/packages/suckless.scm                    \
   %D%/packages/swig.scm                                \
   %D%/packages/sync.scm                        \
+  %D%/packages/syncthing.scm                   \
   %D%/packages/synergy.scm                     \
   %D%/packages/syndication.scm                 \
   %D%/packages/task-management.scm             \
@@ -434,6 +444,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/services/audio.scm                        \
   %D%/services/avahi.scm                       \
   %D%/services/base.scm                                \
+  %D%/services/certbot.scm                     \
   %D%/services/configuration.scm               \
   %D%/services/cuirass.scm                     \
   %D%/services/cups.scm                                \
@@ -458,6 +469,7 @@ GNU_SYSTEM_MODULES =                                \
   %D%/services/spice.scm                               \
   %D%/services/ssh.scm                         \
   %D%/services/sysctl.scm                      \
+  %D%/services/telephony.scm                   \
   %D%/services/version-control.scm              \
   %D%/services/vpn.scm                         \
   %D%/services/web.scm                         \
@@ -531,6 +543,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/ath9k-htc-firmware-binutils.patch       \
   %D%/packages/patches/ath9k-htc-firmware-gcc.patch            \
   %D%/packages/patches/ath9k-htc-firmware-objcopy.patch                \
+  %D%/packages/patches/audacity-build-with-system-portaudio.patch \
   %D%/packages/patches/automake-skip-amhello-tests.patch       \
   %D%/packages/patches/automake-regexp-syntax.patch            \
   %D%/packages/patches/automake-test-gzip-warning.patch                \
@@ -543,7 +556,6 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/binutils-ld-new-dtags.patch             \
   %D%/packages/patches/binutils-loongson-workaround.patch      \
   %D%/packages/patches/blast+-fix-makefile.patch               \
-  %D%/packages/patches/bluez-CVE-2017-1000250.patch            \
   %D%/packages/patches/byobu-writable-status.patch             \
   %D%/packages/patches/cairo-CVE-2016-9082.patch                       \
   %D%/packages/patches/calibre-no-updates-dialog.patch         \
@@ -577,6 +589,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/crawl-upgrade-saves.patch               \
   %D%/packages/patches/crda-optional-gcrypt.patch              \
   %D%/packages/patches/crossmap-allow-system-pysam.patch       \
+  %D%/packages/patches/crypto++-fix-dos-in-asn.1-decoders.patch \
   %D%/packages/patches/clucene-contribs-lib.patch               \
   %D%/packages/patches/cube-nocheck.patch                      \
   %D%/packages/patches/cursynth-wave-rand.patch                        \
@@ -596,12 +609,17 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/einstein-build.patch                    \
   %D%/packages/patches/emacs-exec-path.patch                   \
   %D%/packages/patches/emacs-fix-scheme-indent-function.patch  \
+  %D%/packages/patches/emacs-highlight-stages-add-gexp.patch   \
   %D%/packages/patches/emacs-scheme-complete-scheme-r5rs-info.patch    \
   %D%/packages/patches/emacs-source-date-epoch.patch           \
   %D%/packages/patches/erlang-man-path.patch                   \
   %D%/packages/patches/eudev-rules-directory.patch             \
   %D%/packages/patches/evilwm-lost-focus-bug.patch             \
+  %D%/packages/patches/exim-CVE-2017-16943.patch               \
+  %D%/packages/patches/exim-CVE-2017-16944.patch               \
   %D%/packages/patches/exim-CVE-2017-1000369.patch             \
+  %D%/packages/patches/exiv2-CVE-2017-14860.patch              \
+  %D%/packages/patches/exiv2-CVE-2017-14859-14862-14864.patch  \
   %D%/packages/patches/fastcap-mulGlobal.patch                 \
   %D%/packages/patches/fastcap-mulSetup.patch                  \
   %D%/packages/patches/fasthenry-spAllocate.patch              \
@@ -631,6 +649,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/gcc-cross-environment-variables.patch   \
   %D%/packages/patches/gcc-libvtv-runpath.patch                        \
   %D%/packages/patches/gcc-strmov-store-file-names.patch       \
+  %D%/packages/patches/gcc-4-compile-with-gcc-5.patch           \
   %D%/packages/patches/gcc-4.6-gnu-inline.patch                        \
   %D%/packages/patches/gcc-4.9.3-mingw-gthr-default.patch      \
   %D%/packages/patches/gcc-5.0-libvtv-runpath.patch            \
@@ -638,13 +657,12 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/gcc-5-source-date-epoch-2.patch         \
   %D%/packages/patches/gcc-6-arm-none-eabi-multilib.patch      \
   %D%/packages/patches/gcc-6-cross-environment-variables.patch \
+  %D%/packages/patches/gcc-6-source-date-epoch-1.patch         \
+  %D%/packages/patches/gcc-6-source-date-epoch-2.patch         \
   %D%/packages/patches/gcr-disable-failing-tests.patch         \
   %D%/packages/patches/gcr-fix-collection-tests-to-work-with-gpg-21.patch      \
-  %D%/packages/patches/gdk-pixbuf-list-dir.patch               \
-  %D%/packages/patches/gd-fix-gd2-read-test.patch              \
   %D%/packages/patches/gd-fix-tests-on-i686.patch              \
   %D%/packages/patches/gd-freetype-test-failure.patch          \
-  %D%/packages/patches/gd-php-73968-Fix-109-XBM-reading.patch          \
   %D%/packages/patches/gegl-CVE-2012-4433.patch                        \
   %D%/packages/patches/gemma-intel-compat.patch                        \
   %D%/packages/patches/geoclue-config.patch                    \
@@ -666,6 +684,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/glibc-CVE-2017-1000366-pt1.patch                \
   %D%/packages/patches/glibc-CVE-2017-1000366-pt2.patch                \
   %D%/packages/patches/glibc-CVE-2017-1000366-pt3.patch                \
+  %D%/packages/patches/glibc-CVE-2017-15670-15671.patch                \
   %D%/packages/patches/glibc-bootstrap-system.patch            \
   %D%/packages/patches/glibc-ldd-x86_64.patch                  \
   %D%/packages/patches/glibc-locales.patch                     \
@@ -706,6 +725,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/guile-present-coding.patch              \
   %D%/packages/patches/guile-relocatable.patch                 \
   %D%/packages/patches/guile-rsvg-pkgconfig.patch              \
+  %D%/packages/patches/guile-emacs-fix-configure.patch         \
   %D%/packages/patches/gtk2-respect-GUIX_GTK2_PATH.patch       \
   %D%/packages/patches/gtk2-respect-GUIX_GTK2_IM_MODULE_FILE.patch \
   %D%/packages/patches/gtk2-theme-paths.patch                  \
@@ -733,13 +753,17 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/hurd-fix-eth-multiplexer-dependency.patch        \
   %D%/packages/patches/hydra-disable-darcs-test.patch          \
   %D%/packages/patches/icecat-avoid-bundled-libraries.patch    \
+  %D%/packages/patches/icecat-bug-1348660-pt5.patch            \
+  %D%/packages/patches/icecat-bug-1415133.patch                        \
   %D%/packages/patches/icu4c-CVE-2017-7867-CVE-2017-7868.patch \
+  %D%/packages/patches/icu4c-CVE-2017-14952.patch              \
   %D%/packages/patches/icu4c-reset-keyword-list-iterator.patch \
   %D%/packages/patches/id3lib-CVE-2007-4460.patch                      \
   %D%/packages/patches/ilmbase-fix-tests.patch                 \
   %D%/packages/patches/intltool-perl-compatibility.patch       \
   %D%/packages/patches/isl-0.11.1-aarch64-support.patch        \
   %D%/packages/patches/jacal-fix-texinfo.patch                 \
+  %D%/packages/patches/java-powermock-fix-java-files.patch             \
   %D%/packages/patches/jbig2dec-ignore-testtest.patch          \
   %D%/packages/patches/jbig2dec-CVE-2016-9601.patch            \
   %D%/packages/patches/jbig2dec-CVE-2017-7885.patch            \
@@ -759,6 +783,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/kobodeluxe-manpage-minus-not-hyphen.patch       \
   %D%/packages/patches/kobodeluxe-midicon-segmentation-fault.patch     \
   %D%/packages/patches/kobodeluxe-graphics-window-signed-char.patch    \
+  %D%/packages/patches/ktexteditor-5.39.0-autotests-dependencies.patch \
   %D%/packages/patches/laby-make-install.patch                 \
   %D%/packages/patches/lcms-CVE-2016-10165.patch               \
   %D%/packages/patches/ldc-disable-tests.patch                 \
@@ -776,7 +801,6 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/libcroco-CVE-2017-7960.patch            \
   %D%/packages/patches/libcroco-CVE-2017-7961.patch            \
   %D%/packages/patches/libdrm-symbol-check.patch               \
-  %D%/packages/patches/libetonyek-build-with-mdds-1.2.patch     \
   %D%/packages/patches/libevent-dns-tests.patch                        \
   %D%/packages/patches/libevent-2.0-CVE-2016-10195.patch       \
   %D%/packages/patches/libevent-2.0-CVE-2016-10196.patch       \
@@ -797,7 +821,6 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/libmad-armv7-thumb-pt2.patch            \
   %D%/packages/patches/libmad-frame-length.patch               \
   %D%/packages/patches/libmad-mips-newgcc.patch                        \
-  %D%/packages/patches/libmwaw-CVE-2017-9433.patch             \
   %D%/packages/patches/libsndfile-armhf-type-checks.patch      \
   %D%/packages/patches/libsndfile-CVE-2017-8361-8363-8365.patch        \
   %D%/packages/patches/libsndfile-CVE-2017-8362.patch          \
@@ -812,12 +835,15 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/libtiff-tiffycbcrtorgb-integer-overflow.patch   \
   %D%/packages/patches/libtiff-tiffycbcrtorgbinit-integer-overflow.patch       \
   %D%/packages/patches/libtirpc-CVE-2017-8779.patch            \
-  %D%/packages/patches/libtorrent-rasterbar-boost-compat.patch \
   %D%/packages/patches/libtool-skip-tests2.patch               \
   %D%/packages/patches/libunistring-gnulib-multi-core.patch    \
   %D%/packages/patches/libusb-0.1-disable-tests.patch          \
+  %D%/packages/patches/libusb-for-axoloti.patch                        \
+  %D%/packages/patches/libvirt-CVE-2017-1000256.patch          \
   %D%/packages/patches/libvpx-CVE-2016-2818.patch              \
   %D%/packages/patches/libxcb-python-3.5-compat.patch          \
+  %D%/packages/patches/libxfont-CVE-2017-13720.patch           \
+  %D%/packages/patches/libxfont-CVE-2017-13722.patch           \
   %D%/packages/patches/libxml2-CVE-2016-4658.patch             \
   %D%/packages/patches/libxml2-CVE-2016-5131.patch             \
   %D%/packages/patches/libxml2-CVE-2017-0663.patch             \
@@ -866,6 +892,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/mingw-w64-5.0rc2-gcc-4.9.3.patch                \
   %D%/packages/patches/mpc123-initialize-ao.patch              \
   %D%/packages/patches/module-init-tools-moduledir.patch       \
+  %D%/packages/patches/mongodb-support-unknown-linux-distributions.patch       \
   %D%/packages/patches/mozjs17-aarch64-support.patch           \
   %D%/packages/patches/mozjs24-aarch64-support.patch           \
   %D%/packages/patches/mozjs38-pkg-config-version.patch                \
@@ -874,8 +901,11 @@ dist_patch_DATA =                                          \
   %D%/packages/patches/mozjs38-version-detection.patch         \
   %D%/packages/patches/mumps-build-parallelism.patch           \
   %D%/packages/patches/mupdf-build-with-openjpeg-2.1.patch     \
+  %D%/packages/patches/mupdf-CVE-2017-14685.patch              \
+  %D%/packages/patches/mupdf-CVE-2017-14686.patch              \
+  %D%/packages/patches/mupdf-CVE-2017-14687.patch              \
+  %D%/packages/patches/mupdf-CVE-2017-15587.patch              \
   %D%/packages/patches/mupen64plus-ui-console-notice.patch     \
-  %D%/packages/patches/musl-CVE-2016-8859.patch                        \
   %D%/packages/patches/mutt-store-references.patch             \
   %D%/packages/patches/ncurses-CVE-2017-10684-10685.patch      \
   %D%/packages/patches/net-tools-bitrot.patch                  \
@@ -888,6 +918,7 @@ dist_patch_DATA =                                           \
   %D%/packages/patches/newsbeuter-CVE-2017-14500.patch         \
   %D%/packages/patches/ngircd-handle-zombies.patch             \
   %D%/packages/patches/ninja-zero-mtime.patch                  \
+  %D%/packages/patches/node-test-http2-server-rst-stream.patch \
   %D%/packages/patches/nss-increase-test-timeout.patch         \
   %D%/packages/patches/nss-pkgconfig.patch                     \
   %D%/packages/patches/nvi-assume-preserve-path.patch          \
@@ -904,26 +935,23 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/openscenegraph-ffmpeg3.patch             \
   %D%/packages/patches/openexr-missing-samples.patch           \
   %D%/packages/patches/openfoam-4.1-cleanup.patch                      \
-  %D%/packages/patches/openjpeg-CVE-2017-12982.patch           \
-  %D%/packages/patches/openjpeg-CVE-2017-14040.patch           \
-  %D%/packages/patches/openjpeg-CVE-2017-14041.patch           \
-  %D%/packages/patches/openjpeg-CVE-2017-14151.patch           \
-  %D%/packages/patches/openjpeg-CVE-2017-14152.patch           \
-  %D%/packages/patches/openjpeg-CVE-2017-14164.patch           \
   %D%/packages/patches/openldap-CVE-2017-9287.patch            \
   %D%/packages/patches/openocd-nrf52.patch                     \
   %D%/packages/patches/openssl-runpath.patch                   \
   %D%/packages/patches/openssl-1.1.0-c-rehash-in.patch         \
   %D%/packages/patches/openssl-c-rehash-in.patch               \
+  %D%/packages/patches/optipng-CVE-2017-1000229.patch          \
   %D%/packages/patches/orpheus-cast-errors-and-includes.patch  \
   %D%/packages/patches/osip-CVE-2017-7853.patch                        \
   %D%/packages/patches/ots-no-include-missing-file.patch       \
+  %D%/packages/patches/owncloud-disable-updatecheck.patch      \
   %D%/packages/patches/p7zip-CVE-2016-9296.patch                       \
   %D%/packages/patches/p7zip-remove-unused-code.patch          \
   %D%/packages/patches/patchelf-page-size.patch                        \
   %D%/packages/patches/patchelf-rework-for-arm.patch           \
   %D%/packages/patches/patchutils-xfail-gendiff-tests.patch    \
   %D%/packages/patches/patch-hurd-path-max.patch               \
+  %D%/packages/patches/pcmanfm-CVE-2017-8934.patch             \
   %D%/packages/patches/pcre-CVE-2017-7186.patch                        \
   %D%/packages/patches/pcre2-CVE-2017-7186.patch               \
   %D%/packages/patches/pcre2-CVE-2017-8786.patch               \
@@ -957,7 +985,11 @@ dist_patch_DATA =                                          \
   %D%/packages/patches/portmidi-modular-build.patch            \
   %D%/packages/patches/procmail-ambiguous-getline-debian.patch  \
   %D%/packages/patches/procmail-CVE-2014-3618.patch            \
+  %D%/packages/patches/procmail-CVE-2017-16844.patch           \
   %D%/packages/patches/proot-test-fhs.patch                    \
+  %D%/packages/patches/psm-arch.patch                          \
+  %D%/packages/patches/psm-ldflags.patch                       \
+  %D%/packages/patches/psm-repro.patch                         \
   %D%/packages/patches/pt-scotch-build-parallelism.patch       \
   %D%/packages/patches/pulseaudio-fix-mult-test.patch          \
   %D%/packages/patches/pulseaudio-longer-test-timeout.patch    \
@@ -984,6 +1016,7 @@ dist_patch_DATA =                                          \
   %D%/packages/patches/python-genshi-isstring-helper.patch     \
   %D%/packages/patches/python-genshi-stripping-of-unsafe-script-tags.patch     \
   %D%/packages/patches/python2-larch-coverage-4.0a6-compatibility.patch \
+  %D%/packages/patches/python-networkx2-reproducible-build.patch       \
   %D%/packages/patches/python-nose-timer-drop-ordereddict.patch \
   %D%/packages/patches/python-parse-too-many-fields.patch      \
   %D%/packages/patches/python2-rdflib-drop-sparqlwrapper.patch \
@@ -999,6 +1032,12 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/python2-pygobject-2-gi-info-type-error-domain.patch \
   %D%/packages/patches/python-pygpgme-fix-pinentry-tests.patch \
   %D%/packages/patches/python2-subprocess32-disable-input-test.patch   \
+  %D%/packages/patches/python2-unittest2-remove-argparse.patch \
+  %D%/packages/patches/qemu-CVE-2017-15038.patch               \
+  %D%/packages/patches/qemu-CVE-2017-15118.patch               \
+  %D%/packages/patches/qemu-CVE-2017-15119.patch               \
+  %D%/packages/patches/qemu-CVE-2017-15268.patch               \
+  %D%/packages/patches/qemu-CVE-2017-15289.patch               \
   %D%/packages/patches/qt4-ldflags.patch                       \
   %D%/packages/patches/qtscript-disable-tests.patch            \
   %D%/packages/patches/quagga-reproducible-build.patch          \
@@ -1038,7 +1077,6 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/spice-CVE-2017-7506.patch               \
   %D%/packages/patches/steghide-fixes.patch                    \
   %D%/packages/patches/superlu-dist-scotchmetis.patch          \
-  %D%/packages/patches/supertuxkart-angelscript-ftbfs.patch            \
   %D%/packages/patches/swish-e-search.patch                    \
   %D%/packages/patches/swish-e-format-security.patch           \
   %D%/packages/patches/synfigstudio-fix-ui-with-gtk3.patch     \
@@ -1064,6 +1102,7 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/ttf2eot-cstddef.patch                   \
   %D%/packages/patches/ttfautohint-source-date-epoch.patch     \
   %D%/packages/patches/tophat-build-with-later-seqan.patch     \
+  %D%/packages/patches/totem-meson-easy-codec.patch            \
   %D%/packages/patches/tuxpaint-stamps-path.patch              \
   %D%/packages/patches/unrtf-CVE-2016-10091.patch              \
   %D%/packages/patches/unzip-CVE-2014-8139.patch               \
@@ -1094,9 +1133,6 @@ dist_patch_DATA =                                         \
   %D%/packages/patches/vte-CVE-2012-2738-pt1.patch                     \
   %D%/packages/patches/vte-CVE-2012-2738-pt2.patch                     \
   %D%/packages/patches/weechat-python.patch                    \
-  %D%/packages/patches/wget-CVE-2017-6508.patch                        \
-  %D%/packages/patches/wget-fix-504-test-timeout.patch                 \
-  %D%/packages/patches/wget-perl-5.26.patch                    \
   %D%/packages/patches/wicd-bitrate-none-fix.patch             \
   %D%/packages/patches/wicd-get-selected-profile-fix.patch     \
   %D%/packages/patches/wicd-urwid-1.3.patch                    \
@@ -1107,6 +1143,11 @@ dist_patch_DATA =                                                \
   %D%/packages/patches/wordnet-CVE-2008-2149.patch                     \
   %D%/packages/patches/wordnet-CVE-2008-3908-pt1.patch                 \
   %D%/packages/patches/wordnet-CVE-2008-3908-pt2.patch                 \
+  %D%/packages/patches/wpa-supplicant-CVE-2017-13082.patch     \
+  %D%/packages/patches/wpa-supplicant-fix-key-reuse.patch      \
+  %D%/packages/patches/wpa-supplicant-fix-zeroed-keys.patch    \
+  %D%/packages/patches/wpa-supplicant-fix-nonce-reuse.patch    \
+  %D%/packages/patches/wpa-supplicant-krack-followups.patch    \
   %D%/packages/patches/xcb-proto-python3-print.patch           \
   %D%/packages/patches/xcb-proto-python3-whitespace.patch      \
   %D%/packages/patches/xdotool-fix-makefile.patch               \