Since WebKitGTK 2.26 the single-process mode is considered a security
risk and the process limiting APIs have been completely disabled.
This change is transparent for most applications, but Geary and
particularly Evolution (see upstream bug #587) are known to have
problems in multi-process mode. This has already been fixed in Geary
3.33.91 and in Evolution 3.34.1.
Although the API to set the single-process model is no longer
available, it is still possible to do it internally. This patch does
that for Evolution and Geary.
This is a temporary workaround and it is especially meant for stable
distributions and security updates, where patching or updating the
affected apps is not an option.
===================================================================
Alberto Garcia [Mon, 23 Nov 2020 17:43:07 +0000 (17:43 +0000)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
When building for x86 in a x86_64 host (e.g. with pbuilder) CMake
will set CMAKE_SYSTEM_PROCESSOR to x86_64, and WebKit will assume
that it's a 64-bit build. Let's use the C++ compiler architecture as
a temporary solution to detect x86 correctly.
===================================================================
* Rebuild for buster-security.
* The WebKitGTK security advisory WSA-2020-0008 lists the following
security fixes in the latest versions of WebKitGTK:
+ CVE-2020-9952 (fixed in 2.28.3).
+ CVE-2020-9948, CVE-2020-9951 (fixed in 2.30.0).
+ CVE-2020-9983, CVE-2020-13584 (fixed in 2.30.3).
* debian/patches/force-single-process.patch:
+ Force the single-process mode in Evolution and Geary
* debian/control:
+ Remove Breaks for Evolution < 3.34.1.
+ Remove build dependency on libwpebackend-fdo-1.0-dev.
+ Switch build dependency from libenchant-2-dev to libenchant-dev.
Alberto Garcia [Fri, 20 Nov 2020 14:24:07 +0000 (14:24 +0000)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
When building for x86 in a x86_64 host (e.g. with pbuilder) CMake
will set CMAKE_SYSTEM_PROCESSOR to x86_64, and WebKit will assume
that it's a 64-bit build. Let's use the C++ compiler architecture as
a temporary solution to detect x86 correctly.
===================================================================
Alberto Garcia [Fri, 23 Oct 2020 10:18:03 +0000 (11:18 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
When building for x86 in a x86_64 host (e.g. with pbuilder) CMake
will set CMAKE_SYSTEM_PROCESSOR to x86_64, and WebKit will assume
that it's a 64-bit build. Let's use the C++ compiler architecture as
a temporary solution to detect x86 correctly.
===================================================================
Alberto Garcia [Mon, 21 Sep 2020 13:34:07 +0000 (14:34 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
When building for x86 in a x86_64 host (e.g. with pbuilder) CMake
will set CMAKE_SYSTEM_PROCESSOR to x86_64, and WebKit will assume
that it's a 64-bit build. Let's use the C++ compiler architecture as
a temporary solution to detect x86 correctly.
===================================================================
Alberto Garcia [Mon, 27 Apr 2020 12:55:16 +0000 (13:55 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
When building for x86 in a x86_64 host (e.g. with pbuilder) CMake
will set CMAKE_SYSTEM_PROCESSOR to x86_64, and WebKit will assume
that it's a 64-bit build. Let's use the C++ compiler architecture as
a temporary solution to detect x86 correctly.
===================================================================
Alberto Garcia [Sun, 19 Apr 2020 23:50:19 +0000 (00:50 +0100)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
When building for x86 in a x86_64 host (e.g. with pbuilder) CMake
will set CMAKE_SYSTEM_PROCESSOR to x86_64, and WebKit will assume
that it's a 64-bit build. Let's use the C++ compiler architecture as
a temporary solution to detect x86 correctly.
===================================================================
Alberto Garcia [Sun, 19 Apr 2020 23:50:19 +0000 (00:50 +0100)]
webkit2gtk (2.28.1-2) unstable; urgency=high
* The WebKitGTK security advisory WSA-2020-0004 lists the following
security fixes in the latest versions of WebKitGTK:
+ CVE-2020-11793 (fixed in 2.28.1).
* fix-ftbfs-mips64el.patch:
+ Fix a FTBFS in mipsel64.
Alberto Garcia [Thu, 12 Mar 2020 19:35:21 +0000 (19:35 +0000)]
Use WTF_CPU_UNKNOWN when building for X32
Forwarded: no
WebKitGTK doesn't build on X32 even with the JIT disabled.
Treating the CPU as unknown is perhaps a bit severe, but it allows us
to get the build done until someone steps up to maintain this
properly.
===================================================================
When building for x86 in a x86_64 host (e.g. with pbuilder) CMake
will set CMAKE_SYSTEM_PROCESSOR to x86_64, and WebKit will assume
that it's a 64-bit build. Let's use the C++ compiler architecture as
a temporary solution to detect x86 correctly.
===================================================================
Alberto Garcia [Thu, 12 Mar 2020 19:35:21 +0000 (19:35 +0000)]
webkit2gtk (2.28.0-2) unstable; urgency=high
* The WebKitGTK security advisory WSA-2020-0003 lists the following
security fixes in the latest versions of WebKitGTK:
+ CVE-2020-10018 (fixed in 2.28.0).
* debian/rules:
+ Disable the WPE renderer on Ubuntu since the required backend is in
universe (thanks, Sebastien Bacher).
* debian/gbp.conf:
+ Update upstream branch name.
Alberto Garcia [Fri, 17 May 2019 14:40:52 +0000 (15:40 +0100)]
webkit2gtk (2.24.2-1) unstable; urgency=medium
* New upstream release.
+ This fixes CVE-2019-8595, CVE-2019-8607 and CVE-2019-8615.
* debian/patches/fix-redirected-streams.patch,
debian/patches/fix-cjk-white-space.patch:
+ Drop these patches.
* debian/libwebkit2gtk-4.0-37.symbols:
+ Update symbols.