[Bug 2000839] Re: rustc 1.65 and cargo 0.66 required by firefox 110

Launchpad Bug Tracker 2000839 at bugs.launchpad.net
Wed Jan 18 15:16:05 UTC 2023


This bug was fixed in the package cargo - 0.66.0+ds1-1ubuntu1

---------------
cargo (0.66.0+ds1-1ubuntu1) lunar; urgency=medium

  * Merge from Debian unstable (LP: #2000839):
    Remaining changes:
    - Add an explicit mechanism to customize the vendoring process
    - d/p/proxy-skip-tests.patch: skip a test when there's a proxy configured
      to accommodate Ubuntu autopkgtest setup
    - d/p/i386-crossbuild-tests.patch: disable some failing tests for
      cross-building from i386
    - d/p/remove-badges.patch: remove badges from documentation for privacy
      reasons (refreshed)
    - autopkgtests: test on all arches on Ubuntu
    - d/control: update the Vcs fields to point to Launchpad
    - make_orig_multi.sh: fix orig tarball compression to xz on Ubuntu
    - Track vendored dependencies
    - Bump the libgit2-related crates to get libgit2 1.5.0 bindings
    - make_orig_multi.sh: only use xz for vendor orig tarball on Ubuntu
  * Update vendored sources information

cargo (0.66.0+ds1-1) unstable; urgency=medium

  [ Fabian Grünbichler ]
  * fix CVE-2022-46176 (Thanks Peter Green!)
  * repack vendored sources with required libgit2-sys/git2/git2-curl versions
  * update unsuspicious files

cargo (0.66.0-1) unstable; urgency=medium

  * new upstream version 0.66

  [ Blair Noctis ]
  * Update debcargo-conf.patch, unapply tempfile patch to match vendored
  * Refresh patches and remove upstream applied CVE patches
  * Patch test macro to work around qemu vfork bug when command not found

  [ Fabian Grünbichler ]
  * no longer pin git2/libgit2-sys
  * update debcargo-conf.patch (concolor, clap)
  * update unsuspicious files
  * d/control: depend on rustc 1.63
  * drop armel workaround

  [ Rob Shearman ]
  * d/control: update minimum cargo, rustc and libstd-rust-dev versions

 -- Simon Chopin <schopin at ubuntu.com>  Tue, 17 Jan 2023 14:48:37 +0100

** Changed in: cargo (Ubuntu Lunar)
       Status: New => Fix Released

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-46176

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to rustc in Ubuntu.
https://bugs.launchpad.net/bugs/2000839

Title:
   rustc 1.65 and cargo 0.66 required by firefox 110

Status in cargo package in Ubuntu:
  Fix Released
Status in rustc package in Ubuntu:
  New
Status in cargo source package in Bionic:
  New
Status in rustc source package in Bionic:
  New
Status in cargo source package in Focal:
  New
Status in rustc source package in Focal:
  New
Status in cargo source package in Jammy:
  New
Status in rustc source package in Jammy:
  New
Status in cargo source package in Kinetic:
  New
Status in rustc source package in Kinetic:
  New
Status in cargo source package in Lunar:
  Fix Released
Status in rustc source package in Lunar:
  New

Bug description:
  Firefox 110+ requires rustc 1.65 and cargo 0.66 to build¹.

  The beta phase for Firefox 110.0 begins on 2023-01-16 and release
  candidates will be available from 2023-02-06.

  We will need these in Ubuntu 23.04 and all supported releases: bionic,
  focal, jammy, kinetic.

  ¹ https://bugzilla.mozilla.org/show_bug.cgi?id=1807761

  Rust toolchain upgrades are usually relatively safe from a FTBFS point
  of view, since new releases are subjected to a crater run, crater
  being a tool that compiles the entirety of the crates.io packages.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cargo/+bug/2000839/+subscriptions




More information about the foundations-bugs mailing list