Bug 2142405

Summary: xz-5.4.0 is available
Product: [Fedora] Fedora Reporter: Upstream Release Monitoring <upstream-release-monitoring>
Component: xzAssignee: Richard W.M. Jones <rjones>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: jnovy, mmuzila, odubaj, panovotn, pkubat, praiskup, rjones, xose.vazquez
Target Milestone: ---Keywords: FutureFeature, Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: xz-5.4.1-1.fc37 xz-5.4.1-1.fc36 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-01-26 01:21:42 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Update to 5.2.8 (#2142405)
none
Update to 5.2.9 (#2142405)
none
Update to 5.4.0 (#2142405) none

Description Upstream Release Monitoring 2022-11-13 20:05:54 UTC
Releases retrieved: 5.2.8
Upstream release that is considered latest: 5.2.8
Current version/release in rawhide: 5.2.7-1.fc38
URL: http://tukaani.org/xz/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/5277/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/xz

Comment 1 Upstream Release Monitoring 2022-11-13 20:06:01 UTC
Created attachment 1924075 [details]
Update to 5.2.8 (#2142405)

Comment 2 Upstream Release Monitoring 2022-11-13 20:14:11 UTC
the-new-hotness/release-monitoring.org's scratch build of xz-5.2.8-1.fc36.src.rpm for rawhide failed http://koji.fedoraproject.org/koji/taskinfo?taskID=94138831

Comment 3 Upstream Release Monitoring 2022-11-30 21:53:56 UTC
Releases retrieved: 5.2.9
Upstream release that is considered latest: 5.2.9
Current version/release in rawhide: 5.2.7-1.fc38
URL: http://tukaani.org/xz/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/5277/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/xz

Comment 4 Upstream Release Monitoring 2022-11-30 21:54:03 UTC
Created attachment 1928950 [details]
Update to 5.2.9 (#2142405)

Comment 5 Upstream Release Monitoring 2022-11-30 22:07:57 UTC
the-new-hotness/release-monitoring.org's scratch build of xz-5.2.9-1.fc36.src.rpm for rawhide completed http://koji.fedoraproject.org/koji/taskinfo?taskID=94758414

Comment 6 Richard W.M. Jones 2022-12-01 08:19:46 UTC
Rawhide build: https://koji.fedoraproject.org/koji/taskinfo?taskID=94776012

Comment 7 Upstream Release Monitoring 2022-12-13 22:19:13 UTC
Releases retrieved: 5.2.10, 5.4.0
Upstream release that is considered latest: 5.4.0
Current version/release in rawhide: 5.2.9-1.fc38
URL: https://tukaani.org/xz/

Please consult the package updates policy before you issue an update to a stable branch: https://docs.fedoraproject.org/en-US/fesco/Updates_Policy/


More information about the service that created this bug can be found at: https://docs.fedoraproject.org/en-US/package-maintainers/Upstream_Release_Monitoring


Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.


Based on the information from Anitya: https://release-monitoring.org/project/5277/


To change the monitoring settings for the project, please visit:
https://src.fedoraproject.org/rpms/xz

Comment 8 Upstream Release Monitoring 2022-12-13 22:19:22 UTC
Created attachment 1932449 [details]
Update to 5.4.0 (#2142405)

Comment 9 Upstream Release Monitoring 2022-12-13 22:30:19 UTC
the-new-hotness/release-monitoring.org's scratch build of xz-5.4.0-1.fc36.src.rpm for rawhide failed http://koji.fedoraproject.org/koji/taskinfo?taskID=95328187

Comment 10 fedora.dm0 2023-01-09 17:22:36 UTC
*** Bug 2025309 has been marked as a duplicate of this bug. ***

Comment 11 Xose Vazquez Perez 2023-01-12 18:07:23 UTC
(In reply to Upstream Release Monitoring from comment #7)

> Releases retrieved: 5.2.10, 5.4.0
> Upstream release that is considered latest: 5.4.0
> Current version/release in rawhide: 5.2.9-1.fc38
> URL: https://tukaani.org/xz/
> Based on the information from Anitya: https://release-monitoring.org/project/5277/

Could it be updated to 5.2.10?, to fix this bug: https://git.tukaani.org/?p=xz.git;a=blob;f=NEWS;hb=HEAD#l632

* xz: Don't modify argv[] when parsing the --memlimit* and
  --block-list command line options. This fixes confusing
  arguments in process listing (like "ps auxf").

Thank you.

Comment 12 fedora.dm0 2023-01-22 15:33:01 UTC
Can we get a 5.4 version in rawhide before the f38 branch for MicroLZMA support?  Every other distro I see already has it in testing if not stable, so it's unlikely to have major issues (Arch, Gentoo, Debian bookworm, Ubuntu lunar, openSUSE Tumbleweed).

Comment 13 Richard W.M. Jones 2023-01-23 09:38:15 UTC
> Can we get a 5.4 version in rawhide before the f38 branch for MicroLZMA support?

Sure, I can do 5.4.0 now.  Seems like there was a bit of confusion
in the bug.

> Could it be updated to 5.2.10?, to fix this bug: https://git.tukaani.org/?p=xz.git;a=blob;f=NEWS;hb=HEAD#l632

Hopefully updating all branches will fix this too.

Comment 14 Richard W.M. Jones 2023-01-23 10:00:43 UTC
I update F36 & F37 branches too, since I cannot see how having
an old, insecure version of xz there helps us, and the lzma API
appears unchanged.

Comment 15 Fedora Update System 2023-01-23 10:10:38 UTC
FEDORA-2023-8362bcf475 has been submitted as an update to Fedora 37. https://bodhi.fedoraproject.org/updates/FEDORA-2023-8362bcf475

Comment 16 Fedora Update System 2023-01-23 10:14:45 UTC
FEDORA-2023-d823c8dfb8 has been submitted as an update to Fedora 36. https://bodhi.fedoraproject.org/updates/FEDORA-2023-d823c8dfb8

Comment 17 fedora.dm0 2023-01-23 14:28:39 UTC
Thanks!

Comment 18 Fedora Update System 2023-01-25 02:53:03 UTC
FEDORA-2023-d823c8dfb8 has been pushed to the Fedora 36 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-d823c8dfb8`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-d823c8dfb8

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 19 Fedora Update System 2023-01-25 03:17:57 UTC
FEDORA-2023-8362bcf475 has been pushed to the Fedora 37 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2023-8362bcf475`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2023-8362bcf475

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 20 Fedora Update System 2023-01-26 01:21:42 UTC
FEDORA-2023-8362bcf475 has been pushed to the Fedora 37 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 21 Fedora Update System 2023-02-09 09:21:19 UTC
FEDORA-2023-d823c8dfb8 has been pushed to the Fedora 36 stable repository.
If problem still persists, please make note of it in this bug report.