Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Question about GURU's dev-ml/ollama
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Unsupported Software
View previous topic :: View next topic  
Author Message
redblade7
Tux's lil' helper
Tux's lil' helper


Joined: 11 Jan 2018
Posts: 106

PostPosted: Tue Jun 25, 2024 11:35 pm    Post subject: Question about GURU's dev-ml/ollama Reply with quote

Hi,

Recently dev-ml/ollama was added to the GURU repository. Today I heard of a serious security bug in the news with ollama, fixed in version 0.1.34. But the dev-ml/ollama is version "9999" and running "ollama --version" reports version number "0.0.0" Does anyone know anything about this ebuild or what version it is, or whether the security bug will be fixed?

Thank you!
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 21978

PostPosted: Wed Jun 26, 2024 12:21 am    Post subject: Reply with quote

Normally, a version -9999 ebuild is whatever was current in master at the moment you built it. Therefore, whether it includes the fix of interest depends on whether that fix was in master when you last built that version.

The internally reported version of 0.0.0 is probably because the upstream project does not maintain a proper version number in source control, and instead patches that in as part of the release process. If so, the reported version is meaningless.

I cannot comment on when or if the upstream project will fix the bug. Since you did not link to any of the news, I do not know what security bug you mean.
Back to top
View user's profile Send private message
redblade7
Tux's lil' helper
Tux's lil' helper


Joined: 11 Jan 2018
Posts: 106

PostPosted: Wed Jun 26, 2024 1:05 am    Post subject: Reply with quote

Hu wrote:
Normally, a version -9999 ebuild is whatever was current in master at the moment you built it. Therefore, whether it includes the fix of interest depends on whether that fix was in master when you last built that version.

The internally reported version of 0.0.0 is probably because the upstream project does not maintain a proper version number in source control, and instead patches that in as part of the release process. If so, the reported version is meaningless.

I cannot comment on when or if the upstream project will fix the bug. Since you did not link to any of the news, I do not know what security bug you mean.


https://www.theregister.com/2024/06/24/rce_ollama_wiz/
Back to top
View user's profile Send private message
Banana
Moderator
Moderator


Joined: 21 May 2004
Posts: 1514
Location: Germany

PostPosted: Wed Jun 26, 2024 7:00 am    Post subject: Reply with quote

The commits from the mentioned tag in the news, are merged into the main branch, which is the default branch in the repo. The ebuild does use this repo and its default branch. So the fix should be in there.
_________________
Forum Guidelines

PFL - Portage file list - find which package a file or command belongs to.
My delta-labs.org snippets do expire
Back to top
View user's profile Send private message
eugene-bright
n00b
n00b


Joined: 23 Sep 2018
Posts: 2

PostPosted: Thu Jun 27, 2024 5:15 pm    Post subject: Re: Question about GURU's dev-ml/ollama Reply with quote

redblade7 wrote:

"ollama --version" reports version number "0.0.0"


Here is the ebuild fix, the version will be reported correctly as soon as it's accepted (for the new builds of course)
https://github.com/gentoo/guru/pull/205
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Unsupported Software All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum