Re: Maintenance or successors? (was Re: Buffer overflow in the StringQuotedWord() function)

William Bader <[email protected]> Fri, 18 Dec 2020 05:01:50 +0000
Newsgroups gmane.comp.type-setting.lout
Message-ID <DB6PR0201MB247172F5E5D5E230E229CAF5C4C30@DB6PR0201MB2471.eurprd02.prod.outlook.com>
--_000_DB6PR0201MB247172F5E5D5E230E229CAF5C4C30DB6PR0201MB2471_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

I have a version of lout with the CVEs fixed at https://github.com/william8=
000/lout
The repository has commits for all of the lout 3.xx releases that I could f=
ind and then a final commit that fixes the CVEs and updates the release to =
3.41.
I can try to fix future bugs and CVEs as they are reported.
Regards, William


________________________________
From: Lout-users <[email protected]>=
 on behalf of Ludovic Court=E8s <[email protected]>
Sent: Wednesday, December 16, 2020 5:59 AM
To: Mark Carroll <[email protected]>
Cc: [email protected] <[email protected]>
Subject: Re: Maintenance or successors? (was Re: Buffer overflow in the Str=
ingQuotedWord() function)

Hi,

Mark Carroll <[email protected]> skribis:

> Thank you very much indeed for all the work already done on Lout, it's a
> real gem, both in software and documentation. Unfortunately, I have not
> used C (or C++) much since the nineties so I rather doubt that I am
> suited to attempt to safely address outstanding CVEs; my recent history
> is in fixing Java ones instead! Might somebody else be up for the
> catchup and ongoing maintenance work? Otherwise, I hope that this is not
> badly off-topic: If Basser Lout is no longer maintained then I suppose
> it raises the question of if anyone here has migrated to anything that
> does not pale in comparison, is there any agreeable successor? Maybe
> there is some other mailing list worth following about the wider state
> of document formatters?
>
> I've used Lout for my own documents but, in using things like XeTeX with
> TikZ in the day job and such, I've yet to find a match for Lout's sheer
> cleanliness, it is positively a pleasure to use; I guess the functional
> approach really works, a worthwhile research experiment indeed. At least
> after I have employed tips from others about getting it to recognize
> various kinds of fonts, Basser Lout is one of the few pieces of software
> I use where the surprises tend to be more pleasant than not. "I wonder
> if this would work? Yes, it does!"

I=92m late to the discussion but I agree with everything you wrote: having
used LaTeX (+ Beamer, etc.) for some time now, it always feels clunky
and brittle compared to Lout.  The functional approach of Lout makes it
much more pleasant to work with, and more predictable too.

I=92m not aware of any other functional document formatting tool.

> I wonder if I'll end up seeing how far I can get with Haskell's bindings
> to Cairo and if useful guidance would come from the text about Nonpareil
> which, admittedly, it's a long time since I looked at. Some combination
> of Lout's Expert's Guide and other "lessons learned" could be valuable
> inspiration; as you've previously observed, "Text handling is a maze
> where many have lost their way," so it would be great to at least
> continue to benefit from how Lout advances the field.

That=92s probably the way to go even though, like you write, this may be
an endless quest.  :-)

Thanks,
Ludo=92.


--_000_DB6PR0201MB247172F5E5D5E230E229CAF5C4C30DB6PR0201MB2471_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
I have a version of lout with the CVEs fixed at&nbsp;<a href=3D"https://git=
hub.com/william8000/lout" id=3D"LPlnk">https://github.com/william8000/lout<=
/a></div>
<div>The repository has commits for all of the lout 3.xx releases that I co=
uld find and then a final commit that fixes the CVEs and updates the releas=
e to 3.41.</div>
<div>I can try to fix future bugs and CVEs as they are reported.</div>
<div>Regards, William</div>
<div class=3D"_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_=
1"></div>
<br>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
<br>
</div>
<div>
<hr tabindex=3D"-1" style=3D"display:inline-block; width:98%">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" co=
lor=3D"#000000" style=3D"font-size:11pt"><b>From:</b> Lout-users &lt;lout-u=
[email protected]&gt; on behalf of Ludovic=
 Court=E8s &lt;[email protected]&gt;<br>
<b>Sent:</b> Wednesday, December 16, 2020 5:59 AM<br>
<b>To:</b> Mark Carroll &lt;[email protected]&gt;<br>
<b>Cc:</b> [email protected] &lt;[email protected]&gt;<br>
<b>Subject:</b> Re: Maintenance or successors? (was Re: Buffer overflow in =
the StringQuotedWord() function)</font>
<div>&nbsp;</div>
</div>
<div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt"=
>
<div class=3D"PlainText">Hi,<br>
<br>
Mark Carroll &lt;[email protected]&gt; skribis:<br>
<br>
&gt; Thank you very much indeed for all the work already done on Lout, it's=
 a<br>
&gt; real gem, both in software and documentation. Unfortunately, I have no=
t<br>
&gt; used C (or C++) much since the nineties so I rather doubt that I am<br=
>
&gt; suited to attempt to safely address outstanding CVEs; my recent histor=
y<br>
&gt; is in fixing Java ones instead! Might somebody else be up for the<br>
&gt; catchup and ongoing maintenance work? Otherwise, I hope that this is n=
ot<br>
&gt; badly off-topic: If Basser Lout is no longer maintained then I suppose=
<br>
&gt; it raises the question of if anyone here has migrated to anything that=
<br>
&gt; does not pale in comparison, is there any agreeable successor? Maybe<b=
r>
&gt; there is some other mailing list worth following about the wider state=
<br>
&gt; of document formatters?<br>
&gt;<br>
&gt; I've used Lout for my own documents but, in using things like XeTeX wi=
th<br>
&gt; TikZ in the day job and such, I've yet to find a match for Lout's shee=
r<br>
&gt; cleanliness, it is positively a pleasure to use; I guess the functiona=
l<br>
&gt; approach really works, a worthwhile research experiment indeed. At lea=
st<br>
&gt; after I have employed tips from others about getting it to recognize<b=
r>
&gt; various kinds of fonts, Basser Lout is one of the few pieces of softwa=
re<br>
&gt; I use where the surprises tend to be more pleasant than not. &quot;I w=
onder<br>
&gt; if this would work? Yes, it does!&quot;<br>
<br>
I=92m late to the discussion but I agree with everything you wrote: having<=
br>
used LaTeX (+ Beamer, etc.) for some time now, it always feels clunky<br>
and brittle compared to Lout.&nbsp; The functional approach of Lout makes i=
t<br>
much more pleasant to work with, and more predictable too.<br>
<br>
I=92m not aware of any other functional document formatting tool.<br>
<br>
&gt; I wonder if I'll end up seeing how far I can get with Haskell's bindin=
gs<br>
&gt; to Cairo and if useful guidance would come from the text about Nonpare=
il<br>
&gt; which, admittedly, it's a long time since I looked at. Some combinatio=
n<br>
&gt; of Lout's Expert's Guide and other &quot;lessons learned&quot; could b=
e valuable<br>
&gt; inspiration; as you've previously observed, &quot;Text handling is a m=
aze<br>
&gt; where many have lost their way,&quot; so it would be great to at least=
<br>
&gt; continue to benefit from how Lout advances the field.<br>
<br>
That=92s probably the way to go even though, like you write, this may be<br=
>
an endless quest.&nbsp; :-)<br>
<br>
Thanks,<br>
Ludo=92.<br>
<br>
</div>
</span></font></div>
</div>
</body>
</html>

--_000_DB6PR0201MB247172F5E5D5E230E229CAF5C4C30DB6PR0201MB2471_--