9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
* [9fans] kerTeX update: security fix
@ 2021-09-02 11:23 tlaronde
  2021-09-02 12:00 ` Matthew Singletary
  0 siblings, 1 reply; 3+ messages in thread
From: tlaronde @ 2021-09-02 11:23 UTC (permalink / raw)
  To: 9fans

Hello,

I'm currently finishing the implementation of the newly required LaTeX
primitives and there will be a new engine (extending TeX and e-TeX).

While reading the program, I found a bug in TeX (and thus e-TeX; and
METAFONT and thus MetaPost) in the filenames handling. So I commited
a security fix.

Even if the potential of the problem is remote, you should upgrade and,
after, if your using LaTeX, re-install the package so that it will use
the corrected etex engine.

Note: I hadn't taken the time to update my Plan9/9front installation nor
to test the new version on it. The changes should not... change
anything as far as the systems are concerned. If something goes weird,
you know whom to send complaints to...
-- 
        Thierry Laronde <tlaronde +AT+ polynum +dot+ com>
                     http://www.kergis.com/
                    http://kertex.kergis.com/
                       http://www.sbfa.fr/
Key fingerprint = 0FF7 E906 FBAF FE95 FD89  250D 52B1 AE95 6006 F40C

------------------------------------------
9fans: 9fans
Permalink: https://9fans.topicbox.com/groups/9fans/Tfe9d01dd917d8874-M6f6ed83c9a148366608253c0
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [9fans] kerTeX update: security fix
  2021-09-02 11:23 [9fans] kerTeX update: security fix tlaronde
@ 2021-09-02 12:00 ` Matthew Singletary
  2021-09-02 12:33   ` tlaronde
  0 siblings, 1 reply; 3+ messages in thread
From: Matthew Singletary @ 2021-09-02 12:00 UTC (permalink / raw)
  To: 9fans

[-- Attachment #1: Type: text/plain, Size: 1505 bytes --]

If you found a big in TeX, doesn't that mean you found an error in the TeX
book? Doesn't that mean you should get one of the famed checks from Knuth?

Anyways, thanks for your hard work!

On Thu, Sep 2, 2021, 7:25 AM <tlaronde@polynum.com> wrote:

> Hello,
> 
> I'm currently finishing the implementation of the newly required LaTeX
> primitives and there will be a new engine (extending TeX and e-TeX).
> 
> While reading the program, I found a bug in TeX (and thus e-TeX; and
> METAFONT and thus MetaPost) in the filenames handling. So I commited
> a security fix.
> 
> Even if the potential of the problem is remote, you should upgrade and,
> after, if your using LaTeX, re-install the package so that it will use
> the corrected etex engine.
> 
> Note: I hadn't taken the time to update my Plan9/9front installation nor
> to test the new version on it. The changes should not... change
> anything as far as the systems are concerned. If something goes weird,
> you know whom to send complaints to...
> --
> Thierry Laronde <tlaronde +AT+ polynum +dot+ com>
>              http://www.kergis.com/
>             http://kertex.kergis.com/
>                http://www.sbfa.fr/
> Key fingerprint = 0FF7 E906 FBAF FE95 FD89  250D 52B1 AE95 6006 F40C

------------------------------------------
9fans: 9fans
Permalink: https://9fans.topicbox.com/groups/9fans/Tfe9d01dd917d8874-M1ff17c863200cd5476049fa6
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

[-- Attachment #2: Type: text/html, Size: 3324 bytes --]

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [9fans] kerTeX update: security fix
  2021-09-02 12:00 ` Matthew Singletary
@ 2021-09-02 12:33   ` tlaronde
  0 siblings, 0 replies; 3+ messages in thread
From: tlaronde @ 2021-09-02 12:33 UTC (permalink / raw)
  To: 9fans

Le Thu, Sep 02, 2021 at 08:00:49AM -0400, Matthew Singletary a écrit :
> If you found a big in TeX, doesn't that mean you found an error in the TeX
> book? Doesn't that mean you should get one of the famed checks from Knuth?
> 

Normally, yes (the check being now a symbolic reward)---by the way, it's
not in the TeXbook but in "TeX: The Program" (and the same for METAFONT:
The Program, since it is shared code; so for the very same reason, e-TeX
and MetaPost).

But unfortunately, for the moment, people involved for 35 years or more
in the TeX community seem to be annoyed that this has escaped their
prolonged scrutiny and are trying to find convoluted explanations in
order to not classify it as a bug---D.E.K. has obviously better
things to do, so he is not involved.

IT give opportunity for social experiments too!
-- 
        Thierry Laronde <tlaronde +AT+ polynum +dot+ com>
                     http://www.kergis.com/
                    http://kertex.kergis.com/
                       http://www.sbfa.fr/
Key fingerprint = 0FF7 E906 FBAF FE95 FD89  250D 52B1 AE95 6006 F40C

------------------------------------------
9fans: 9fans
Permalink: https://9fans.topicbox.com/groups/9fans/Tfe9d01dd917d8874-Ma6e736d23d04583c6ededa8c
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2021-09-02 12:33 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-09-02 11:23 [9fans] kerTeX update: security fix tlaronde
2021-09-02 12:00 ` Matthew Singletary
2021-09-02 12:33   ` tlaronde

9fans - fans of the OS Plan 9 from Bell Labs

This inbox may be cloned and mirrored by anyone:

	git clone --mirror https://inbox.vuxu.org/9fans

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V1 9fans 9fans/ https://inbox.vuxu.org/9fans \
		9fans@9fans.net
	public-inbox-index 9fans

Example config snippet for mirrors.
Newsgroup available over NNTP:
	nntp://inbox.vuxu.org/vuxu.archive.9fans


AGPL code for this site: git clone https://public-inbox.org/public-inbox.git