Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1360193 > unrolled thread
| Started by | Junio C Hamano <gitster@pobox.com> |
|---|---|
| First post | 2016-03-17 22:10 +0100 |
| Last post | 2016-03-18 09:40 +0100 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.kernel
[ANNOUNCE] Git v2.7.4 (and updates to older maintenance tracks) Junio C Hamano <gitster@pobox.com> - 2016-03-17 22:10 +0100
Re: [ANNOUNCE] Git v2.7.4 (and updates to older maintenance tracks) Torsten Bögershausen <tboegi@web.de> - 2016-03-18 09:40 +0100
| From | Junio C Hamano <gitster@pobox.com> |
|---|---|
| Date | 2016-03-17 22:10 +0100 |
| Subject | [ANNOUNCE] Git v2.7.4 (and updates to older maintenance tracks) |
| Message-ID | <rdNl8-4ir-7@gated-at.bofh.it> |
The latest maintenance release Git v2.7.4 is now available at the
usual places. The same set of bugfix patches from the current
'master' have been backported to older maintenance tracks and are
available as v2.4.11, v2.5.5 and v2.6.6. These are to fix a heap
corruption / buffer overflow bug and users are strongly encouraged
to upgrade. The fix has already been in the release candidate
v2.8.0-rc3 as well.
The tarballs are found at:
https://www.kernel.org/pub/software/scm/git/
The following public repositories all have a copy of the 'v2.7.4'
tag and the 'maint' branch that the tag points at:
url = https://kernel.googlesource.com/pub/scm/git/git
url = git://repo.or.cz/alt-git.git
url = git://git.sourceforge.jp/gitroot/git-core/git.git
url = git://git-core.git.sourceforge.net/gitroot/git-core/git-core
url = https://github.com/gitster/git
----------------------------------------------------------------
Git v2.7.4 Release Notes
========================
Fixes since v2.7.3
------------------
* Bugfix patches were backported from the 'master' front to plug heap
corruption holes, to catch integer overflow in the computation of
pathname lengths, and to get rid of the name_path API. Both of
these would have resulted in writing over an under-allocated buffer
when formulating pathnames while tree traversal.
----------------------------------------------------------------
Changes since v2.7.3 are as follows:
Jeff King (7):
add helpers for detecting size_t overflow
tree-diff: catch integer overflow in combine_diff_path allocation
http-push: stop using name_path
show_object_with_name: simplify by using path_name()
list-objects: convert name_path to a strbuf
list-objects: drop name_path entirely
list-objects: pass full pathname to callbacks
Junio C Hamano (4):
Git 2.4.11
Git 2.5.5
Git 2.6.6
Git 2.7.4
[toc] | [next] | [standalone]
| From | Torsten Bögershausen <tboegi@web.de> |
|---|---|
| Date | 2016-03-18 09:40 +0100 |
| Message-ID | <rdY6R-36M-1@gated-at.bofh.it> |
| In reply to | #1360193 |
> Git v2.7.4 Release Notes
> ========================
>
> Fixes since v2.7.3
> ------------------
>
> * Bugfix patches were backported from the 'master' front to plug heap
> corruption holes, to catch integer overflow in the computation of
> pathname lengths, and to get rid of the name_path API. Both of
> these would have resulted in writing over an under-allocated buffer
> when formulating pathnames while tree traversal.
>
> ----------------------------------------------------------------
>
> Changes since v2.7.3 are as follows:
>
> Jeff King (7):
> add helpers for detecting size_t overflow
> tree-diff: catch integer overflow in combine_diff_path allocation
> http-push: stop using name_path
> show_object_with_name: simplify by using path_name()
> list-objects: convert name_path to a strbuf
> list-objects: drop name_path entirely
> list-objects: pass full pathname to callbacks
>
If there is a new 2.7.x release, does it make sense to cherry-pick this one:
commit 7b6daf8d2fee1a9866b1d4eddbfaa5dbc42c5dbb
Author: Torsten Bögershausen <tboegi@web.de>
Date: Sun Feb 28 21:09:44 2016 +0100
config.mak.uname: use clang for Mac OS X 10.6
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web