Since WebKitGTK 2.26 the single-process mode is considered a security
risk and the process limiting APIs have been completely disabled.
This change is transparent for most applications, but Geary and
particularly Evolution (see upstream bug #587) are known to have
problems in multi-process mode. This has already been fixed in Geary
3.33.91 and in Evolution 3.34.1.
Although the API to set the single-process model is no longer
available, it is still possible to do it internally. This patch does
that for Evolution and Geary.
This is a temporary workaround and it is especially meant for stable
distributions and security updates, where patching or updating the
affected apps is not an option.
===================================================================
Alberto Garcia [Wed, 28 Sep 2022 13:14:20 +0000 (14:14 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
* Rebuild for buster-security.
* debian/patches/force-single-process.patch:
- Force the single-process mode in Evolution and Geary
* debian/patches/support-old-cmake.patch:
- Fix build with cmake < 3.15
* debian/control.in:
- Remove build dependencies on ccache, libwpebackend-fdo-1.0-dev,
libmanette-0.2-dev and liblcms2-dev.
- Switch build dependency from libenchant-2-dev to libenchant-dev.
- Switch build dependencies on libgl-dev and libgles-dev with
libgl1-mesa-dev and libgles2-mesa-dev.
* Downgrade xdg-desktop-portal-gtk from a recommendation to a
suggestion (See #989307)
* debian/rules:
- Set ENABLE_SOUP3=NO, ENABLE_GTK4=NO and USE_PREBUILT_DOCS=YES. This
builds the 4.0 API packages only (soup2 build).
- Build with -DENABLE_GAMEPAD=OFF -DUSE_LCMS=OFF.
* Set the debhelper compatibility level back to 10. This fixes a dh_dwz
error ".debug_info section not present"
- Add debian/compat file.
- Update build dependency on debhelper.
Since WebKitGTK 2.26 the single-process mode is considered a security
risk and the process limiting APIs have been completely disabled.
This change is transparent for most applications, but Geary and
particularly Evolution (see upstream bug #587) are known to have
problems in multi-process mode. This has already been fixed in Geary
3.33.91 and in Evolution 3.34.1.
Although the API to set the single-process model is no longer
available, it is still possible to do it internally. This patch does
that for Evolution and Geary.
This is a temporary workaround and it is especially meant for stable
distributions and security updates, where patching or updating the
affected apps is not an option.
===================================================================
Alberto Garcia [Sun, 28 Aug 2022 17:52:24 +0000 (18:52 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
* Rebuild for buster-security.
* debian/patches/force-single-process.patch:
- Force the single-process mode in Evolution and Geary
* debian/control:
- Remove all 4.1 API packages (soup3 build).
- Remove Breaks for Evolution < 3.34.1.
- Remove build dependencies on ccache, libwpebackend-fdo-1.0-dev,
libmanette-0.2-dev, liblcms2-dev and libsoup-3.0-dev.
- Switch build dependency from libenchant-2-dev to libenchant-dev.
- Switch build dependencies on libgl-dev and libgles-dev with
libgl1-mesa-dev and libgles2-mesa-dev.
* Downgrade xdg-desktop-portal-gtk from a recommendation to a
suggestion (See #989307)
* debian/rules:
- Build with -DENABLE_GAMEPAD=OFF -DUSE_LCMS=OFF.
* Set the debhelper compatibility level back to 10. This fixes a dh_dwz
error ".debug_info section not present"
- Add debian/compat file.
- Update build dependency on debhelper.
Alberto Garcia [Wed, 24 Aug 2022 23:49:31 +0000 (00:49 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
Since WebKitGTK 2.26 the single-process mode is considered a security
risk and the process limiting APIs have been completely disabled.
This change is transparent for most applications, but Geary and
particularly Evolution (see upstream bug #587) are known to have
problems in multi-process mode. This has already been fixed in Geary
3.33.91 and in Evolution 3.34.1.
Although the API to set the single-process model is no longer
available, it is still possible to do it internally. This patch does
that for Evolution and Geary.
This is a temporary workaround and it is especially meant for stable
distributions and security updates, where patching or updating the
affected apps is not an option.
===================================================================
Alberto Garcia [Tue, 16 Aug 2022 07:57:32 +0000 (08:57 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
* Rebuild for buster-security.
* debian/patches/force-single-process.patch:
- Force the single-process mode in Evolution and Geary
* debian/control:
- Remove all 4.1 API packages (soup3 build).
- Remove Breaks for Evolution < 3.34.1.
- Remove build dependencies on ccache, libwpebackend-fdo-1.0-dev,
libmanette-0.2-dev, liblcms2-dev and libsoup-3.0-dev.
- Switch build dependency from libenchant-2-dev to libenchant-dev.
- Switch build dependencies on libgl-dev and libgles-dev with
libgl1-mesa-dev and libgles2-mesa-dev.
* Downgrade xdg-desktop-portal-gtk from a recommendation to a
suggestion (See #989307)
* debian/rules:
- Build with -DENABLE_GAMEPAD=OFF -DUSE_LCMS=OFF.
* Set the debhelper compatibility level back to 10. This fixes a dh_dwz
error ".debug_info section not present"
- Add debian/compat file.
- Update build dependency on debhelper.
Alberto Garcia [Wed, 10 Aug 2022 12:56:32 +0000 (13:56 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
Alberto Garcia [Wed, 10 Aug 2022 12:56:32 +0000 (13:56 +0100)]
webkit2gtk (2.36.6-1) unstable; urgency=high
* New upstream release.
* The WebKitGTK security advisory WSA-2022-0007 lists the following
security fixes in the latest versions of WebKitGTK:
- CVE identifiers: CVE-2022-32792, CVE-2022-32816 and CVE-2022-2294
(fixed in 2.36.5).
* debian/rules:
- Enable wpe on Ubuntu now that the MIR has been accepted (thanks,
Sebastien Bacher) (Closes: #1016585).
Since WebKitGTK 2.26 the single-process mode is considered a security
risk and the process limiting APIs have been completely disabled.
This change is transparent for most applications, but Geary and
particularly Evolution (see upstream bug #587) are known to have
problems in multi-process mode. This has already been fixed in Geary
3.33.91 and in Evolution 3.34.1.
Although the API to set the single-process model is no longer
available, it is still possible to do it internally. This patch does
that for Evolution and Geary.
This is a temporary workaround and it is especially meant for stable
distributions and security updates, where patching or updating the
affected apps is not an option.
===================================================================
Alberto Garcia [Thu, 14 Jul 2022 12:14:12 +0000 (13:14 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
* Rebuild for buster-security.
* debian/patches/force-single-process.patch:
- Force the single-process mode in Evolution and Geary
* debian/control:
- Remove all 4.1 API packages (soup3 build).
- Remove Breaks for Evolution < 3.34.1.
- Remove build dependencies on ccache, libwpebackend-fdo-1.0-dev,
libmanette-0.2-dev, liblcms2-dev and libsoup-3.0-dev.
- Switch build dependency from libenchant-2-dev to libenchant-dev.
- Switch build dependencies on libgl-dev and libgles-dev with
libgl1-mesa-dev and libgles2-mesa-dev.
* Downgrade xdg-desktop-portal-gtk from a recommendation to a
suggestion (See #989307)
* debian/rules:
- Build with -DENABLE_GAMEPAD=OFF -DUSE_LCMS=OFF.
* Set the debhelper compatibility level back to 10. This fixes a dh_dwz
error ".debug_info section not present"
- Add debian/compat file.
- Update build dependency on debhelper.
Alberto Garcia [Wed, 6 Jul 2022 11:54:15 +0000 (12:54 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
Alberto Garcia [Wed, 6 Jul 2022 11:54:15 +0000 (12:54 +0100)]
webkit2gtk (2.36.4-1) unstable; urgency=high
* New upstream release.
* The WebKitGTK security advisory WSA-2022-0006 lists the following
security fixes in the latest versions of WebKitGTK:
- CVE-2022-22662 (fixed in 2.36.0).
- CVE-2022-22677 and CVE-2022-26710 (fixed in 2.36.4).
* debian/control:
- Don't use ccache in i386 because Ubuntu doesn't have it and Debian
can live without it (webkit-team/webkit!14).
* Update format of lintian overrides (see #1007002).
* debian/control:
- Update Standards-Version to 4.6.1.0 (no changes).
Since WebKitGTK 2.26 the single-process mode is considered a security
risk and the process limiting APIs have been completely disabled.
This change is transparent for most applications, but Geary and
particularly Evolution (see upstream bug #587) are known to have
problems in multi-process mode. This has already been fixed in Geary
3.33.91 and in Evolution 3.34.1.
Although the API to set the single-process model is no longer
available, it is still possible to do it internally. This patch does
that for Evolution and Geary.
This is a temporary workaround and it is especially meant for stable
distributions and security updates, where patching or updating the
affected apps is not an option.
===================================================================
Alberto Garcia [Tue, 31 May 2022 08:54:46 +0000 (09:54 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
* Rebuild for buster-security.
- This fixes CVE-2022-26700, CVE-2022-26709, CVE-2022-26716,
CVE-2022-26717, CVE-2022-26719, CVE-2022-30293 and CVE-2022-30294.
* debian/patches/force-single-process.patch:
- Force the single-process mode in Evolution and Geary
* debian/control:
- Remove all 4.1 API packages (soup3 build).
- Remove Breaks for Evolution < 3.34.1.
- Remove build dependencies on ccache, libwpebackend-fdo-1.0-dev,
libmanette-0.2-dev, liblcms2-dev and libsoup-3.0-dev.
- Switch build dependency from libenchant-2-dev to libenchant-dev.
- Switch build dependencies on libgl-dev and libgles-dev with
libgl1-mesa-dev and libgles2-mesa-dev.
* Downgrade xdg-desktop-portal-gtk from a recommendation to a
suggestion (See #989307)
* debian/rules:
- Build with -DENABLE_GAMEPAD=OFF -DUSE_LCMS=OFF.
* Set the debhelper compatibility level back to 10. This fixes a dh_dwz
error ".debug_info section not present"
- Add debian/compat file.
- Update build dependency on debhelper.