Re: Maintenance or successors? (was Re: Buffer overflow in the StringQuotedWord() function)

William Bader <[email protected]> Fri, 18 Dec 2020 23:52:07 +0000
Newsgroups gmane.comp.type-setting.lout
Message-ID <DB6PR0201MB24713932FCF82FFD7EEB1E11C4C30@DB6PR0201MB2471.eurprd02.prod.outlook.com>
--_000_DB6PR0201MB24713932FCF82FFD7EEB1E11C4C30DB6PR0201MB2471_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable


>Building Lout means you have to edit the Makefile.
>This isn't difficult as such but you have to be _very_ careful since
>some of the directories you must specify must exist -- and some must not e=
xist.

I think that you can build lout with 'make all' without any edits, but for =
the install, I usually change PREFIX  from /home/jeff to /usr/local and the=
n change LOUTLIBDIR, LOUTDOCDIR and MANDIR from $(PREFIX)/... to $(PREFIX)/=
lib/... , and I think that the makefile needs a few places that use 'mkdir =
-p'.
If you have any specific places that you change, let me know.
Now that https://github.com/william8000/lout hasn't had any problems, I hav=
e about 1000 lines of my own fixes and small enhancements that I can commit=
. It includes changes to the makefile, fixes for crashes on pages that crea=
te complicated geometries, fixes for a calculation that could leave images =
in a Graph misaligned by a few points on a letter or A4 page, and support f=
or embedding PDFs and bitmapped images.
So in that repository, 3.40 is the last release by Dr. Kingston. 3.41 is 3.=
40 + the CVE fixes (that will hopefully have distributions keep lout). 3.42=
 will be 3.41 + my changes (which should not break the processing or appear=
ance of any existing lout files, except for placing some objects more accur=
ately).
Regards, William

________________________________
From: Lout-users <[email protected]>=
 on behalf of Mark Summerfield <[email protected]>
Sent: Friday, December 18, 2020 10:41 AM
To: Yannig Robert via "Users of the Lout document typesetting system." <lou=
[email protected]>
Subject: Re: Maintenance or successors? (was Re: Buffer overflow in the Str=
ingQuotedWord() function)

Building Lout means you have to edit the Makefile.
This isn't difficult as such but you have to be _very_ careful since
some of the directories you must specify must exist -- and some must not
exist.

Best wishes,

On Fri, 18 Dec 2020 16:17:34 +0100
Yannig Robert via "Users of the Lout document typesetting system."
<[email protected]> wrote:
> Hello all,
>
>
> Even if I just started using it a year ago (a bit late to the party!), I
> am really glad that Lout is living on as unlike Latex I seem to be able
> to use it without loosing my sanity!
>
> There were talks earlier that Debian was dropping Lout. Does this means
> that those of us who use a Debian based OS soon will need to compile it
> ? Are there instructions somewhere for those like me who aren't experts?
>
> Regards
>
> Yannig
>
>
> On 18/12/2020 06:01, William Bader wrote:
> > I have a version of lout with the CVEs fixed at
> > https://github.com/william8000/lout
> > <https://github.com/william8000/lout> The repository has commits for
> > all of the lout 3.xx releases that I could find and then a final
> > commit that fixes the CVEs and updates the release to 3.41.
> > I can try to fix future bugs and CVEs as they are reported.
> > Regards, William
> >
> >
> > -----------------------------------------------------------------------=
-
> > *From:* Lout-users
> > <[email protected]> on behalf of
> > Ludovic Court=E8s <[email protected]>
> > *Sent:* Wednesday, December 16, 2020 5:59 AM
> > *To:* Mark Carroll <[email protected]>
> > *Cc:* [email protected] <[email protected]>
> > *Subject:* Re: Maintenance or successors? (was Re: Buffer overflow in
> > the StringQuotedWord() function)
> > Hi,
> >
> > Mark Carroll <[email protected]> skribis:
> >
> > > Thank you very much indeed for all the work already done on Lout,
> > > it's a real gem, both in software and documentation. Unfortunately,
> > > I have not used C (or C++) much since the nineties so I rather doubt
> > > that I am suited to attempt to safely address outstanding CVEs; my
> > > recent history is in fixing Java ones instead! Might somebody else
> > > be up for the catchup and ongoing maintenance work? Otherwise, I
> > > hope that this is not badly off-topic: If Basser Lout is no longer
> > > maintained then I suppose it raises the question of if anyone here
> > > has migrated to anything that does not pale in comparison, is there
> > > any agreeable successor? Maybe there is some other mailing list
> > > worth following about the wider state of document formatters?
> > >
> > > I've used Lout for my own documents but, in using things like XeTeX
> > > with TikZ in the day job and such, I've yet to find a match for
> > > Lout's sheer cleanliness, it is positively a pleasure to use; I
> > > guess the functional approach really works, a worthwhile research
> > > experiment indeed. At least after I have employed tips from others
> > > about getting it to recognize various kinds of fonts, Basser Lout is
> > > one of the few pieces of software I use where the surprises tend to
> > > be more pleasant than not. "I wonder if this would work? Yes, it
> > > does!"
> >
> > I=92m late to the discussion but I agree with everything you wrote:
> > having used LaTeX (+ Beamer, etc.) for some time now, it always feels
> > clunky and brittle compared to Lout.  The functional approach of Lout
> > makes it much more pleasant to work with, and more predictable too.
> >
> > I=92m not aware of any other functional document formatting tool.
> >
> > > I wonder if I'll end up seeing how far I can get with Haskell's
> > > bindings to Cairo and if useful guidance would come from the text
> > > about Nonpareil which, admittedly, it's a long time since I looked
> > > at. Some combination of Lout's Expert's Guide and other "lessons
> > > learned" could be valuable inspiration; as you've previously
> > > observed, "Text handling is a maze where many have lost their way,"
> > > so it would be great to at least continue to benefit from how Lout
> > > advances the field.
> >
> > That=92s probably the way to go even though, like you write, this may b=
e
> > an endless quest.  :-)
> >
> > Thanks,
> > Ludo=92.
> >



--
Mark Summerfield, Qtrac Ltd.
    DiffPDF - easy to use PDF comparison application
        http://www.qtrac.eu/diffpdf.html


--_000_DB6PR0201MB24713932FCF82FFD7EEB1E11C4C30DB6PR0201MB2471_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
<br>
</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
&gt;Building Lout means you have to edit the Makefile.<br>
<div>&gt;This isn't difficult as such but you have to be _very_ careful sin=
ce</div>
<div>&gt;some of the directories you must specify must exist -- and some mu=
st not exist.</div>
<br>
I think that you can build lout with 'make all' without any edits, but for =
the install, I usually change&nbsp;PREFIX&nbsp; from /home/jeff to&nbsp;/us=
r/local and then change LOUTLIBDIR,&nbsp;LOUTDOCDIR and&nbsp;MANDIR from $(=
PREFIX)/... to $(PREFIX)/lib/... , and I think that the makefile
 needs a few places that use 'mkdir -p'.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
If you have any specific places that you change, let me know.</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
Now that&nbsp;<a href=3D"https://github.com/william8000/lout" id=3D"LPlnk">=
https://github.com/william8000/lout</a>&nbsp;hasn't had any problems, I hav=
e about 1000 lines of my own fixes and small enhancements that I can commit=
. It includes changes to the makefile, fixes for
 crashes on pages that create complicated geometries, fixes for a calculati=
on that could leave images in a Graph misaligned by a few points on a lette=
r or A4 page, and support for embedding PDFs and bitmapped images.</div>
<div class=3D"_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_=
1"></div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
So in that repository, 3.40 is the last release by Dr. Kingston. 3.41 is 3.=
40 + the CVE fixes (that will hopefully have distributions keep lout). 3.42=
 will be 3.41 + my changes (which should not break the processing or appear=
ance of any existing lout files,
 except for placing some objects more accurately).</div>
<div style=3D"font-family: Calibri, Helvetica, sans-serif; font-size: 12pt;=
 color: rgb(0, 0, 0);">
Regards, William</div>
<div>
<div id=3D"appendonsend"></div>
<div style=3D"font-family:Calibri,Helvetica,sans-serif; font-size:12pt; col=
or:rgb(0,0,0)">
&nbsp;</div>
<hr tabindex=3D"-1" style=3D"display:inline-block; width:98%">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" co=
lor=3D"#000000" style=3D"font-size:11pt"><b>From:</b> Lout-users &lt;lout-u=
[email protected]&gt; on behalf of Mark Su=
mmerfield &lt;[email protected]&gt;<br>
<b>Sent:</b> Friday, December 18, 2020 10:41 AM<br>
<b>To:</b> Yannig Robert via &quot;Users of the Lout document typesetting s=
ystem.&quot; &lt;[email protected]&gt;<br>
<b>Subject:</b> Re: Maintenance or successors? (was Re: Buffer overflow in =
the StringQuotedWord() function)</font>
<div>&nbsp;</div>
</div>
<div class=3D"BodyFragment"><font size=3D"2"><span style=3D"font-size:11pt"=
>
<div class=3D"PlainText">Building Lout means you have to edit the Makefile.
<div>This isn't difficult as such but you have to be _very_ careful since</=
div>
<div>some of the directories you must specify must exist -- and some must n=
ot</div>
exist.<br>
<br>
Best wishes,<br>
<br>
On Fri, 18 Dec 2020 16:17:34 +0100<br>
Yannig Robert via &quot;Users of the Lout document typesetting system.&quot=
;<br>
&lt;[email protected]&gt; wrote:<br>
&gt; Hello all,<br>
&gt; <br>
&gt; <br>
&gt; Even if I just started using it a year ago (a bit late to the party!),=
 I <br>
&gt; am really glad that Lout is living on as unlike Latex I seem to be abl=
e <br>
&gt; to use it without loosing my sanity!<br>
&gt; <br>
&gt; There were talks earlier that Debian was dropping Lout. Does this mean=
s <br>
&gt; that those of us who use a Debian based OS soon will need to compile i=
t <br>
&gt; ? Are there instructions somewhere for those like me who aren't expert=
s?<br>
&gt; <br>
&gt; Regards<br>
&gt; <br>
&gt; Yannig<br>
&gt; <br>
&gt; <br>
&gt; On 18/12/2020 06:01, William Bader wrote:<br>
&gt; &gt; I have a version of lout with the CVEs fixed at <br>
&gt; &gt; <a href=3D"https://github.com/william8000/lout">https://github.co=
m/william8000/lout</a><br>
&gt; &gt; &lt;<a href=3D"https://github.com/william8000/lout">https://githu=
b.com/william8000/lout</a>&gt; The repository has commits for<br>
&gt; &gt; all of the lout 3.xx releases that I could find and then a final<=
br>
&gt; &gt; commit that fixes the CVEs and updates the release to 3.41.<br>
&gt; &gt; I can try to fix future bugs and CVEs as they are reported.<br>
&gt; &gt; Regards, William<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt; -----------------------------------------------------------------=
-------<br>
&gt; &gt; *From:* Lout-users <br>
&gt; &gt; &lt;[email protected]&gt; =
on behalf of <br>
&gt; &gt; Ludovic Court=E8s &lt;[email protected]&gt;<br>
&gt; &gt; *Sent:* Wednesday, December 16, 2020 5:59 AM<br>
&gt; &gt; *To:* Mark Carroll &lt;[email protected]&gt;<br>
&gt; &gt; *Cc:* [email protected] &lt;[email protected]&gt;<br>
&gt; &gt; *Subject:* Re: Maintenance or successors? (was Re: Buffer overflo=
w in <br>
&gt; &gt; the StringQuotedWord() function)<br>
&gt; &gt; Hi,<br>
&gt; &gt;<br>
&gt; &gt; Mark Carroll &lt;[email protected]&gt; skribis:<br>
&gt; &gt;&nbsp; <br>
&gt; &gt; &gt; Thank you very much indeed for all the work already done on =
Lout,<br>
&gt; &gt; &gt; it's a real gem, both in software and documentation. Unfortu=
nately,<br>
&gt; &gt; &gt; I have not used C (or C++) much since the nineties so I rath=
er doubt<br>
&gt; &gt; &gt; that I am suited to attempt to safely address outstanding CV=
Es; my<br>
&gt; &gt; &gt; recent history is in fixing Java ones instead! Might somebod=
y else<br>
&gt; &gt; &gt; be up for the catchup and ongoing maintenance work? Otherwis=
e, I<br>
&gt; &gt; &gt; hope that this is not badly off-topic: If Basser Lout is no =
longer<br>
&gt; &gt; &gt; maintained then I suppose it raises the question of if anyon=
e here<br>
&gt; &gt; &gt; has migrated to anything that does not pale in comparison, i=
s there<br>
&gt; &gt; &gt; any agreeable successor? Maybe there is some other mailing l=
ist<br>
&gt; &gt; &gt; worth following about the wider state of document formatters=
?<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; I've used Lout for my own documents but, in using things lik=
e XeTeX<br>
&gt; &gt; &gt; with TikZ in the day job and such, I've yet to find a match =
for<br>
&gt; &gt; &gt; Lout's sheer cleanliness, it is positively a pleasure to use=
; I<br>
&gt; &gt; &gt; guess the functional approach really works, a worthwhile res=
earch<br>
&gt; &gt; &gt; experiment indeed. At least after I have employed tips from =
others<br>
&gt; &gt; &gt; about getting it to recognize various kinds of fonts, Basser=
 Lout is<br>
&gt; &gt; &gt; one of the few pieces of software I use where the surprises =
tend to<br>
&gt; &gt; &gt; be more pleasant than not. &quot;I wonder if this would work=
? Yes, it<br>
&gt; &gt; &gt; does!&quot;&nbsp; <br>
&gt; &gt;<br>
&gt; &gt; I=92m late to the discussion but I agree with everything you wrot=
e:<br>
&gt; &gt; having used LaTeX (+ Beamer, etc.) for some time now, it always f=
eels<br>
&gt; &gt; clunky and brittle compared to Lout.&nbsp; The functional approac=
h of Lout<br>
&gt; &gt; makes it much more pleasant to work with, and more predictable to=
o.<br>
&gt; &gt;<br>
&gt; &gt; I=92m not aware of any other functional document formatting tool.=
<br>
&gt; &gt;&nbsp; <br>
&gt; &gt; &gt; I wonder if I'll end up seeing how far I can get with Haskel=
l's<br>
&gt; &gt; &gt; bindings to Cairo and if useful guidance would come from the=
 text<br>
&gt; &gt; &gt; about Nonpareil which, admittedly, it's a long time since I =
looked<br>
&gt; &gt; &gt; at. Some combination of Lout's Expert's Guide and other &quo=
t;lessons<br>
&gt; &gt; &gt; learned&quot; could be valuable inspiration; as you've previ=
ously<br>
&gt; &gt; &gt; observed, &quot;Text handling is a maze where many have lost=
 their way,&quot;<br>
&gt; &gt; &gt; so it would be great to at least continue to benefit from ho=
w Lout<br>
&gt; &gt; &gt; advances the field.&nbsp; <br>
&gt; &gt;<br>
&gt; &gt; That=92s probably the way to go even though, like you write, this=
 may be<br>
&gt; &gt; an endless quest.&nbsp; :-)<br>
&gt; &gt;<br>
&gt; &gt; Thanks,<br>
&gt; &gt; Ludo=92.<br>
&gt; &gt;&nbsp; <br>
<br>
<br>
<br>
-- <br>
Mark Summerfield, Qtrac Ltd.<br>
&nbsp;&nbsp;&nbsp; DiffPDF - easy to use PDF comparison application<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <a href=3D"http://www.qtrac.eu/d=
iffpdf.html">http://www.qtrac.eu/diffpdf.html</a><br>
<br>
</div>
</span></font></div>
</div>
</body>
</html>

--_000_DB6PR0201MB24713932FCF82FFD7EEB1E11C4C30DB6PR0201MB2471_--