﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
18006	texlive: luatex security fix	ken@…	ken@…	"On Tuesday on the tlbuild list Karl Berry posted a mail starting
{{{
Hello TL builders,

Some issues have been found in luatex (obscure ways to work around some
security features; thanks to Max Chernoff), so we need to rebuild.
Luigi has committed fixes to the sources, and labeled the new luatex
version 1.17.0. All variants of the engine are affected, so there are
four binaries to update:
  luatex luahbtex luajitex luajithbtex

FYI, the change that's most likely to be noticeable is that the socket
library is now disabled by default; a new option --socket enables it, as
well as --shell-escape (not --shell-restricted). In addition, the mime
library is now always available, and new functions os.socketsleep and
os.socketgettime are also always available. I will put a summary at
https://tug.org/texlive/bugs.html after the binaries are committed.

We need to rebuild from branch2023 (committed in r66984),
because too many unrelated changes have been made to the trunk.
}}}

Looking at the git mirror of the source, the unrelated changes include moving stuff to 2024, various bug fixes including the uptex test, and other fixes where the main part is in svn master (not in the git mirror) - identifiable because the only change in the git mirror is a version change in linked_scripts.

I don't like patching multiple items in texmf-dist, so I started by creating only a security_fix patch for the source (two commits for luatex, v1.16.1 and 1.17.9, plus updated NEWS listing what had changed). Builds all my test files which use luatex variants. But then I tried my mkiv context test scripts, both failed.

Asked on texlive, following that Karl clarified a switch I'd asked about (it is used when luatex is invoked) and made a commit to one of the scripts. I've now got a (very messy) sed to update that in texmf-dist, and my context test files now complete.

I estimate this should be described as 'medium severity'. Raising the ticket now since it is publically mentioned at [ https://tug.org/texlive/bugs.html].

The binary will need a Note: for anyone using luatex (if version is less than 1.17.0, use tlmgr to update, and if using context (luametatex) a further tlmgr update may be required.

Will try to commit this in the next few days."	enhancement	closed	elevated	12.0	BOOK	git	medium	fixed		
