X-Recipient: archive-cygwin AT delorie DOT com DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org DCE483858C62 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cygwin.com; s=default; t=1711959146; bh=Rw2z0Tz6q96B3MIavyx+JASqPEgceHOhl3MTWC6e5U0=; h=References:In-Reply-To:Date:Subject:To:Cc:List-Id: List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe: From:Reply-To:From; b=LjFjyDHWDqfXorFwGEv+SmLIgBTXx35hN0hqcqiaj1sRIh6sjHG4wbQa8Za/HpYbh fp59RA5bQHfF++tkEHgaJKOIQVGGZXqg0VSuMIWgo1lGYaRgpaXuSp9c+e983PXNK0 b5Ozo4LmvUDlvn9RuQDE1njU1gXyxGtHv4uBZ180= X-Original-To: cygwin AT cygwin DOT com Delivered-To: cygwin AT cygwin DOT com DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org A25E43858D32 ARC-Filter: OpenARC Filter v1.0.0 sourceware.org A25E43858D32 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1711959112; cv=none; b=Oyc1ynyCtOkFTPDOADFLs/O+NdBSxes998XvMEjLC0nmHnZVesy+AmxQS6r7KRnCQFHoRcEWIa9CIm3sCtl6bCox870s30uEoevbJzkEcqTwTnJwu3Ai8mbYMZ7dqbReeLuxLJ8wKrj1N/5rD66U+69oGIW4CRGwPFDgtRBIW1g= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1711959112; c=relaxed/simple; bh=QTggfl5fbHaH+Fj8BwRqea+aBr/yl5WxFTuJHBBgZbI=; h=DKIM-Signature:MIME-Version:From:Date:Message-ID:Subject:To; b=Xf6VbeFKmjHu0oe/nD3z11JB2aOBzoqDofvH1PYYwPC68E08HMea8Yr74lSrNxwxxD7JwlYoCODcbaFOgHnfEs/XbBDxSWU2LfYImu0YvTXZ5L2uxQoZsfdbxX/ro3TNtAFDIGFxyuHIyuVZJje7roPksajm68tEg7fCGP//r54= ARC-Authentication-Results: i=1; server2.sourceware.org X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1711959101; x=1712563901; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=SPLErwy6PfywsegAaBfviNvwVg8CvWBrQatsMG4PogQ=; b=KIG9FQ7jPHHcHEOy/2hlKD2MF+OdYQ2CEPXFTcimvvsyLlCj6EkCk486DFVoe4NoIf 5DXDcvGGirwU0e3C1AEPLU7Eo6BAZOoccCApMcRg8HzGbkKXTcj/7iTE+kiVnmLjySdM cr35Tx99rkBbz4QuOGFsrW749ez+U6HVs7+i0FTrC6JMcCbsvf9KHjPjIvTCcRpidxP/ p0EOFNH5r74d32ZhbY5Uq4viFkhThvgaapTGtCXRIPb3CW9VdWOMjY+YMX/7K7zsQqXd sf9Lo4JIknHNM0z5oC5ghfY8CZ2Y1oF5A8gGQvEpSPm5QQN9ZEsUCwa9Qf2i+zrivXhB TKqQ== X-Gm-Message-State: AOJu0YxYKA8KvjqvLoO3Tiado2M6VjgZ50daEUUWF4I9NQoFdKMCUTyr 0cZaoin26RoNcy1l6xNdjvD8EGcEJU2pKlar3rWNihRi/1jRKLvSgqicNJ/ziLmgdb4f5q4wCX5 +yGTmtgb4PTglwygvc/JNt+1bwJqyuD2dgF2Myw== X-Google-Smtp-Source: AGHT+IEbO3NdYm1gHtVs/72LJdRo6ijEwIkl+CmoO8BZBzXEtqcOWVcxqUYS9Xya96zhI5cvk+VAmGpDy91bR15QvE8= X-Received: by 2002:a17:906:4f92:b0:a4e:2ac2:cc67 with SMTP id o18-20020a1709064f9200b00a4e2ac2cc67mr5146147eju.9.1711959100698; Mon, 01 Apr 2024 01:11:40 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: Date: Mon, 1 Apr 2024 01:11:29 -0700 Message-ID: Subject: Re: Linux xz issue To: The Cygwin Mailing List Cc: Keith Thompson X-Spam-Status: No, score=-1.0 required=5.0 tests=BAYES_00, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, FREEMAIL_FROM, RCVD_IN_DNSWL_NONE, SPF_HELO_NONE, SPF_PASS, TXREP autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server2.sourceware.org X-BeenThere: cygwin AT cygwin DOT com X-Mailman-Version: 2.1.30 List-Id: General Cygwin discussions and problem reports List-Archive: List-Post: List-Help: List-Subscribe: , From: Keith Thompson via Cygwin Reply-To: Keith Thompson Content-Type: text/plain; charset="utf-8" Sender: "Cygwin" Content-Transfer-Encoding: 8bit X-MIME-Autoconverted: from base64 to 8bit by delorie.com id 4318CT651278076 On Sun, Mar 31, 2024 at 9:15 PM Keith Thompson wrote: > > Achim Gratz Stromeko AT Nexgo DOT DE wrote: > > Beyond that, the version 5.4.6 that everybody is currently reverting to > > (and is also still available for Cygwin if you want to go back) was > > already released when the presumed bad actor was co-maintainer and their > > involvement goes back even farther based on the Xz developer mailing > > list. The repository has been deactivated by GitHub so I can't check > > there, but there is already some discussion about rolling back to 5.3.1 > > or thereabouts. > > The GitHub repo at has been > deactivated, but there's another xz repo (likely the original one) > at . The most recent commit > in that repo is "CMake: Fix sabotaged Landlock sandbox check.". > > I have no inside knowledge about any of this. > > I'm running the Cygwin setup right now. It reverts the xz package > from 5.6.1-1 to 5.4.6-1. Only 5.4.2-1 and 5.4.6-1 are available. Sorry, I pasted the same link twice. The deactivated GitHub repo is: https://github.com/tukaani-project/xz The tukaani.org repo (still active) is: https://git.tukaani.org/xz.git Thanks to oskar for pointing out my error. -- Problem reports: https://cygwin.com/problems.html FAQ: https://cygwin.com/faq/ Documentation: https://cygwin.com/docs.html Unsubscribe info: https://cygwin.com/ml/#unsubscribe-simple