X-Recipient: archive-cygwin@delorie.com
DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org DCE483858C62
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cygwin.com;
	s=default; t=1711959146;
	bh=Rw2z0Tz6q96B3MIavyx+JASqPEgceHOhl3MTWC6e5U0=;
	h=References:In-Reply-To:Date:Subject:To:Cc:List-Id:
	 List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe:
	 From:Reply-To:From;
	b=LjFjyDHWDqfXorFwGEv+SmLIgBTXx35hN0hqcqiaj1sRIh6sjHG4wbQa8Za/HpYbh
	 fp59RA5bQHfF++tkEHgaJKOIQVGGZXqg0VSuMIWgo1lGYaRgpaXuSp9c+e983PXNK0
	 b5Ozo4LmvUDlvn9RuQDE1njU1gXyxGtHv4uBZ180=
X-Original-To: cygwin@cygwin.com
Delivered-To: cygwin@cygwin.com
DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org A25E43858D32
ARC-Filter: OpenARC Filter v1.0.0 sourceware.org A25E43858D32
ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1711959112; cv=none;
 b=Oyc1ynyCtOkFTPDOADFLs/O+NdBSxes998XvMEjLC0nmHnZVesy+AmxQS6r7KRnCQFHoRcEWIa9CIm3sCtl6bCox870s30uEoevbJzkEcqTwTnJwu3Ai8mbYMZ7dqbReeLuxLJ8wKrj1N/5rD66U+69oGIW4CRGwPFDgtRBIW1g=
ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key;
 t=1711959112; c=relaxed/simple;
 bh=QTggfl5fbHaH+Fj8BwRqea+aBr/yl5WxFTuJHBBgZbI=;
 h=DKIM-Signature:MIME-Version:From:Date:Message-ID:Subject:To;
 b=Xf6VbeFKmjHu0oe/nD3z11JB2aOBzoqDofvH1PYYwPC68E08HMea8Yr74lSrNxwxxD7JwlYoCODcbaFOgHnfEs/XbBDxSWU2LfYImu0YvTXZ5L2uxQoZsfdbxX/ro3TNtAFDIGFxyuHIyuVZJje7roPksajm68tEg7fCGP//r54=
ARC-Authentication-Results: i=1; server2.sourceware.org
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20230601; t=1711959101; x=1712563901;
 h=content-transfer-encoding:cc:to:subject:message-id:date:from
 :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc
 :subject:date:message-id:reply-to;
 bh=SPLErwy6PfywsegAaBfviNvwVg8CvWBrQatsMG4PogQ=;
 b=KIG9FQ7jPHHcHEOy/2hlKD2MF+OdYQ2CEPXFTcimvvsyLlCj6EkCk486DFVoe4NoIf
 5DXDcvGGirwU0e3C1AEPLU7Eo6BAZOoccCApMcRg8HzGbkKXTcj/7iTE+kiVnmLjySdM
 cr35Tx99rkBbz4QuOGFsrW749ez+U6HVs7+i0FTrC6JMcCbsvf9KHjPjIvTCcRpidxP/
 p0EOFNH5r74d32ZhbY5Uq4viFkhThvgaapTGtCXRIPb3CW9VdWOMjY+YMX/7K7zsQqXd
 sf9Lo4JIknHNM0z5oC5ghfY8CZ2Y1oF5A8gGQvEpSPm5QQN9ZEsUCwa9Qf2i+zrivXhB
 TKqQ==
X-Gm-Message-State: AOJu0YxYKA8KvjqvLoO3Tiado2M6VjgZ50daEUUWF4I9NQoFdKMCUTyr
 0cZaoin26RoNcy1l6xNdjvD8EGcEJU2pKlar3rWNihRi/1jRKLvSgqicNJ/ziLmgdb4f5q4wCX5
 +yGTmtgb4PTglwygvc/JNt+1bwJqyuD2dgF2Myw==
X-Google-Smtp-Source: AGHT+IEbO3NdYm1gHtVs/72LJdRo6ijEwIkl+CmoO8BZBzXEtqcOWVcxqUYS9Xya96zhI5cvk+VAmGpDy91bR15QvE8=
X-Received: by 2002:a17:906:4f92:b0:a4e:2ac2:cc67 with SMTP id
 o18-20020a1709064f9200b00a4e2ac2cc67mr5146147eju.9.1711959100698; Mon, 01 Apr
 2024 01:11:40 -0700 (PDT)
MIME-Version: 1.0
References: <CAAHpriNXOQxk6JaWZZ9axn0Ndh7-+iYrUcNYPeB5hVZR7DcKzg@mail.gmail.com>
In-Reply-To: <CAAHpriNXOQxk6JaWZZ9axn0Ndh7-+iYrUcNYPeB5hVZR7DcKzg@mail.gmail.com>
Date: Mon, 1 Apr 2024 01:11:29 -0700
Message-ID: <CAAHpriOvxx41xU=8tdSMruLBighQDX28AtShGyriZ4hpxFLajA@mail.gmail.com>
Subject: Re: Linux xz issue
To: The Cygwin Mailing List <cygwin@cygwin.com>
Cc: Keith Thompson <Keith.S.Thompson@gmail.com>
X-Spam-Status: No, score=-1.0 required=5.0 tests=BAYES_00, DKIM_SIGNED,
 DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, RCVD_IN_DNSWL_NONE,
 SPF_HELO_NONE, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.6
X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on
 server2.sourceware.org
X-BeenThere: cygwin@cygwin.com
X-Mailman-Version: 2.1.30
List-Id: General Cygwin discussions and problem reports <cygwin.cygwin.com>
List-Archive: <https://cygwin.com/pipermail/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-request@cygwin.com?subject=help>
List-Subscribe: <https://cygwin.com/mailman/listinfo/cygwin>,
 <mailto:cygwin-request@cygwin.com?subject=subscribe>
From: Keith Thompson via Cygwin <cygwin@cygwin.com>
Reply-To: Keith Thompson <Keith.S.Thompson@gmail.com>
Content-Type: text/plain; charset="utf-8"
Sender: "Cygwin" <cygwin-bounces+archive-cygwin=delorie.com@cygwin.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from base64 to 8bit by delorie.com id 4318CT651278076

On Sun, Mar 31, 2024 at 9:15 PM Keith Thompson
<Keith.S.Thompson@gmail.com> wrote:
>
> Achim Gratz Stromeko@Nexgo.DE wrote:
> > Beyond that, the version 5.4.6 that everybody is currently reverting to
> > (and is also still available for Cygwin if you want to go back) was
> > already released when the presumed bad actor was co-maintainer and their
> > involvement goes back even farther based on the Xz developer mailing
> > list.  The repository has been deactivated by GitHub so I can't check
> > there, but there is already some discussion about rolling back to 5.3.1
> > or thereabouts.
>
> The GitHub repo at <https://github.com/tukaani-project/xz> has been
> deactivated, but there's another xz repo (likely the original one)
> at <https://github.com/tukaani-project/xz>.  The most recent commit
> in that repo is "CMake: Fix sabotaged Landlock sandbox check.".
>
> I have no inside knowledge about any of this.
>
> I'm running the Cygwin setup right now.  It reverts the xz package
> from 5.6.1-1 to 5.4.6-1.  Only 5.4.2-1 and 5.4.6-1 are available.

Sorry, I pasted the same link twice.

The deactivated GitHub repo is:
https://github.com/tukaani-project/xz

The tukaani.org repo (still active) is:
https://git.tukaani.org/xz.git

Thanks to oskar for pointing out my error.

-- 
Problem reports:      https://cygwin.com/problems.html
FAQ:                  https://cygwin.com/faq/
Documentation:        https://cygwin.com/docs.html
Unsubscribe info:     https://cygwin.com/ml/#unsubscribe-simple

