Commit Graph

495167 Commits

Author SHA1 Message Date
Bernard Spil
11c8e7ed41 security/openssl: Fix Epoch
Reported by:	Dan McGrath <danmcgrath ca gmail com>
Approved by:	ports-secteam (joneum)
2020-02-11 07:19:16 +00:00
Kubilay Kocak
e0bed5b944 MFH: r525691 net-im/prosody: Update to 0.11.4
Changelog:

  https://blog.prosody.im/prosody-0.11.4-released/

PR:		243460
Submitted by:	Thomas Morper <thomas beingboiled info>
Approved by:	portmgr (maintainer timeout: > 14 days)

Approved by:	ports-secteam (blanket: bugfix release)
2020-02-11 03:40:19 +00:00
Kubilay Kocak
e01d5c9ec9 MFH: r525523 misc/brs: Update to 4.3.0
misc/brs currently builds with many warnings and segfaults at runtime,
likely a missing prototypes issue as that's what most of the warnings
are.

A much more recent version (4.30 as opposed to 4.03) of this is
widely available on linux under the name "bible-kjv", which also exists
as an OpenBSD port.

This change updates brs to 4.30, switching upstream to DEBIAN [1], and the
first step commit to renaming the port.

While here:

  - Include the "randverse" program
  - Wordsmith pkg-descr: It's all very well saying that the port
    includes libraries, but it doesn't install them.
  - Remove patches: no longer relevent

[1] Use a temporary MASTER_SITES workaround, instead of 'DEBIAN' directly
    because it does not currently use or support DISTNAME.

PR:		243886
Submitted by:	Andrew <andrew tao11.riddles.org.uk>
Approved by:	<user unknown nu> (implicit, approves maintainer change)
Approved by:	portmgr (blanket: run (crash) fixes)

Approved by:	ports-secteam (blanket: run (crash) fixes)
2020-02-11 03:37:47 +00:00
Jan Beich
72084d1010 MFH: r525766
security/nss: disable AltiVec on 32-bit powerpc

Crypto acceleration is only implemented for powerpc64 but build flags
leak to other powerpc targets. Disable via a variable introduced in 3.50.

PR:		242523
Reported by:	many
Approved by:	ports-secteam blanket
2020-02-10 23:52:08 +00:00
Jan Beich
3bf4987e3f MFH: r523059 r525757
security/nss: update to 3.50

Changes:	https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.50_release_notes
Changes:	https://hg.mozilla.org/projects/nss/shortlog/NSS_3_50_RTM
ABI:		https://abi-laboratory.pro/tracker/timeline/nss/
Reported by:	Repology
Approved by:	ports-secteam blanket (required by Firefox 74)
2020-02-10 22:38:37 +00:00
Jan Beich
0005fb1bf3 MFH: r525179
www/firefox: apply upstream powerpc64 fixes

Many of these are stalled on review for various reasons but the intent
of each seems clear enough to keep rebasing or ask upstream for help.
pkg-fallout@ would identify rebase mistakes while atomic changes would
identify when a particular patch is no longer useful.

Submitted by:	mikael (via D21765)
Approved by:	ports-secteam blanket
2020-02-10 17:04:44 +00:00
Jan Beich
3a80afeba6 MFH: r525108 r525155 r525478 r525512
www/firefox: update to 73.0

Changes:	https://www.mozilla.org/firefox/73.0/releasenotes/
PR:		243295
Security:	802e3138-b8af-4a89-a908-f103107e64b4
Approved by:	ports-secteam blanket
Differential Revision:	https://reviews.freebsd.org/D23146
2020-02-10 17:02:33 +00:00
Jan Beich
581ab60645 MFH: r525107 r525477
www/firefox-esr: update to 68.5.0

Changes:	https://www.mozilla.org/firefox/68.5.0/releasenotes/
Security:	802e3138-b8af-4a89-a908-f103107e64b4
Approved by:	ports-secteam blanket
2020-02-10 16:57:41 +00:00
Jan Beich
8d5e3ae4b2 MFH: r525683
textproc/nuspell: update pkg-descr after r508372

Reported by:	upstream
Approved by:	ports-secteam blanket
2020-02-09 23:28:25 +00:00
Piotr Kubaj
1279313ad8 MFH: r525677
math/flint2: fix build on non-x86

Merge upstream patches for non-x86 architectures.

PR:		243851

Approved by:	portmgr (fix build blanket)
2020-02-09 21:36:43 +00:00
Koop Mast
009633e564 MFH: r524226
Update webkit-gtk3 to 2.26.3.

* Fix issues while trying to play a video on NextCloud.
* Make sure the GL video sink uses a valid WebKit shared GL context.
* Fix vertical alignment of text containing arabic diacritics.
* Fix build with icu 65.1.
* Fix page loading errors with websites using HSTS.
* Fix web process crash when displaying a KaTeX formula.
* Fix several crashes and rendering issues.

This release also fixes 3 CVE's.

Security:	dc8cff4c-4063-11ea-8a94-3497f6939fdd

Approved by:	ports-secteam@ (miwi@)
2020-02-09 17:51:48 +00:00
Emanuel Haupt
f724eefbf1 MFH: r525025
libpcre2 is only needed in combination with ncurses.

PR:		243834 (based on)
Submitted by:	terry-freebsd@glaver.org
Approved by:	ports-secteam (miwi)
2020-02-09 15:44:20 +00:00
Jochen Neumeister
afb0d9cb49 MFH: r525647
Add patch for CVE-2019-20372

NGINX before 1.17.7, with certain error_page configurations,
allows HTTP request smuggling, as demonstrated by the ability
of an attacker to read unauthorized web pages in environments
where NGINX is being fronted by a load balancer.

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20372

PR:		243952
Reported by:	koobs and many more
Security:	c1202de8-4b29-11ea-9673-4c72b94353b5
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (with hat)
2020-02-09 11:19:01 +00:00
Piotr Kubaj
0dfde32246 MFH: r525644
emulators/higan: unbreak on powerpc64, make ports tree compliant

Builds fine on powerpc64 without -march=native, which shouldn't be enabled anyway.

Approved by:	portmgr (fix build blanket)
2020-02-09 11:09:56 +00:00
Sunpoet Po-Chuan Hsieh
ed9b2e21e4 MFH: r525227 r525228 r525229
Update to 1.11.28

Changes:	https://docs.djangoproject.com/en/1.11/releases/
Security:	5a45649a-4777-11ea-bdec-08002728f74c

Update to 2.2.10

Changes:	https://docs.djangoproject.com/en/2.2/releases/
Security:	5a45649a-4777-11ea-bdec-08002728f74c

Update to 3.0.3

Changes:	https://docs.djangoproject.com/en/3.0/releases/
Security:	5a45649a-4777-11ea-bdec-08002728f74c

Approved by:	ports-secteam (miwi)
2020-02-09 08:37:07 +00:00
Kurt Jaeger
113b2b6186 MFH: r525450
security/clamav: upgrade 0.102.1 -> 0.102.2

- Remove MSPACK option and always use archivers/libmspack in
  accordance with policy about bundled library described in 6.2 of
  Porter's Handbook.
- Remove obsolete and no-op options from CONFIGURE_ARGS.

PR:		243914
Submitted by:	Yasuhiro KIMURA <yasu@utahime.org> (maintainer)
Relnotes:	https://blog.clamav.net/2020/02/clamav-01022-security-patch-released.html
Security:	CVE-2020-3123
Approved by:	portmgr (security blanket)
2020-02-06 21:05:07 +00:00
Piotr Kubaj
2c5ade9925 MFH: r525264
math/libflame: unbreak on powerpc

Builds fine.

Approved by:	portmgr (fix build blanket)
2020-02-05 11:16:51 +00:00
Jan Beich
b51adf52fc MFH: r525255
games/openbor: unbreak build on 13.0 powerpc64

In file included from source/gfxlib/2xSaI.c:10:
source/gamelib/borendian.h:63:60: error: unsupported inline asm: input with type 'int' matching output with type 'UInt16' (aka 'unsigned short')
    __asm__("rlwimi %0,%2,8,16,23" : "=&r" (result) : "0" (x >> 8), "r" (x));
                                            ~~~~~~         ^~~~~~

PR:		243865
Reported by:	pkubaj
Approved by:	ports-secteam blanket
2020-02-05 03:28:55 +00:00
Koichiro Iwao
f600c7ffd8 MFH: r525245
devel/lazygit: Update distinfo

Some entry wasn't updated at r525116.

Approved by:	portmgr blanket
2020-02-05 00:43:57 +00:00
Kai Knoblich
1a9408c24a MFH: r524542
databases/py-redis: Update to 3.3.11

Changelog:

https://github.com/andymccurdy/redis-py/blob/3.3.11/CHANGES

PR:		243459
Approved by:	koobs (maintainer)

Approved by:	ports-secteam (miwi)
2020-02-04 08:47:37 +00:00
Koichiro Iwao
29e5882ff7 MFH: r525116
devel/lazygit: Update to 0.14

This release include a fix for the issue no keyboard input recognized [1].

[1] https://github.com/jesseduffield/lazygit/issues/563

PR:		242432

Approved by:	portmgr (blanket: critical runtime bugfix)
2020-02-04 05:41:34 +00:00
Emanuel Haupt
b6d7d77e11 MFH: r525023
Fix build on aarch64

PR:		243805
Submitted by:	mikael
Approved by:	portmgr blanket
2020-02-03 09:44:52 +00:00
Matthias Fechner
85bd0f8b69 MFH: r524700
Security update to 12.6.6.
Changelog:
https://about.gitlab.com/releases/2020/01/30/security-release-gitlab-12-7-4-released/

Security:	c5bd9068-440f-11ea-9cdb-001b217b3468

Approved by:	ports-secteam (miwi)
2020-02-02 17:37:25 +00:00
Matthias Fechner
cb239440d0 MFH: r524725
Fix breakage after r524697

- Change RUN_DEPENDS from rubygem-rubyzip to rubygem-rubyzip13
- Bump PORTREVISION for dependency change

Approved by:	ports-secteam (miwi)
2020-02-02 17:36:28 +00:00
Matthias Fechner
a95e8cb3af MFH: r524724
Add rubygem-rubyzip13 1.3.0 (copied from rubygem-rubyzip)

- Add PORTSCOUT

Approved by:	ports-secteam (miwi)
2020-02-02 17:35:44 +00:00
Matthias Fechner
0dc4a2796e MFH: r524699
Update to 8.20.0 which is required for gitlab-ce security update.

Approved by:	ports-secteam (miwi)
2020-02-02 17:34:44 +00:00
Matthias Fechner
011ff4d144 MFH: r524697
Update to 2.0.0 which is required for gitlab security update.

Approved by:	ports-secteam (miwi)
2020-02-02 17:33:59 +00:00
Matthias Fechner
45283de9e3 MFH: r524696
Update to 1.3.4 to be able to work with rubygem-rubyzip update which is required for gitlab security update.

Approved by:	ports-secteam (miwi)
2020-02-02 17:33:16 +00:00
Matthias Fechner
e92caf3451 MFH: r524695
Update to 1.0.6 which fixes CVE-2019-18978.

Approved by:	ports-secteam (miwi)
2020-02-02 17:32:32 +00:00
Thomas Zander
60fb222745 MFH: r524978
Update to upstream version 43.0.0

Details:
- Mostly bug fixes and moderate feature changes, see
  https://mkvtoolnix.download/doc/NEWS.md
- Includes fixes for an abort with some opus streams, and
  AVC / H264 parser fixes.

Approved by:	ports-secteam (riggs)
2020-02-02 17:01:02 +00:00
Bernard Spil
7bddf71257 MFH: r524837
databases/mariadb55-server: Security update to 5.5.67

Security:	a6cf65ad-37d2-11ea-a1c7-b499baebfeaf
Security:	CVE-2020-2574

Approved by:	ports-secteam (miwi)
2020-02-02 16:31:36 +00:00
Bernard Spil
e7238f192d MFH: r524833
databases/mariadb102-server: Security update to 10.2.31

Security:	a6cf65ad-37d2-11ea-a1c7-b499baebfeaf
Security: 	CVE-2020-2574

Approved by:	ports-secteam (miwi)
2020-02-02 16:30:50 +00:00
Tobias Kortkamp
db185df49d MFH: r524965
x11-toolkits/libhandy: Move e1c500dd02b1.patch to patch file

Checksum of it changed again.  It changes all the time because
GitLab insists on embedding the version of whatever Git packages
they have installed in the footer.

PR:		243797

Approved by:	ports-secteam blanket
2020-02-02 14:41:51 +00:00
Tobias Kortkamp
fd078d6fcb MFH: r524959
games/bzflag-server: Unbreak after ports r516845

===>  bzflag-server-2.4.10_4 need to specify xorg modules with USE_XORG.
*** Error code 1

PR:		243796

Approved by:	ports-secteam blanket
2020-02-02 14:31:17 +00:00
Tobias Kortkamp
05d12a95e6 MFH: r524960
databases/mongodb40-tools: Unbreak build with MONGOTOP=on, MONGOREPLAY=off

===>  Building package for mongodb40-tools-4.0.8_2
pkg-static: Unable to access file /wrkdirs/usr/ports/databases/mongodb40-tools/work/stage/usr/local/bin/mongoreplay:No such file or directory

PR:		243685

Approved by:	ports-secteam blanket
2020-02-02 14:30:43 +00:00
Bernard Spil
b9f4d16dce MFH: r524607
databases/mariadb103-server: Security update to 10.3.22

Security:	a6cf65ad-37d2-11ea-a1c7-b499baebfeaf
Security:	CVE-2020-2574

Approved by:	ports-secteam (miwi)
2020-02-02 09:07:45 +00:00
Bernard Spil
4ac244808a MFH: r524565
databases/mariadb104-server: Security update to 10.4.12

Security:	a6cf65ad-37d2-11ea-a1c7-b499baebfeaf
Security:	CVE-2020-2574

Approved by:	ports-secteam (joneum)
2020-02-02 09:06:47 +00:00
Danilo G. Baio
d8159ae5e8 MFH: r524702
net-mgmt/zabbix44-*: Update to 4.4.5

Changelog:	https://www.zabbix.com/rn/rn4.4.5

PR:		243732
Approved by:	Pakhom Golynga <pg@pakhom.spb.ru> (maintainer)

Approved by:	ports-secteam (miwi)
2020-02-01 13:41:27 +00:00
Danilo G. Baio
ed165fe78c MFH: r524701
net-mgmt/zabbix4-*: Update to 4.0.17

Changelog:	https://www.zabbix.com/rn/rn4.0.17

PR:		243731
Approved by:	Pakhom Golynga <pg@pakhom.spb.ru> (maintainer)

Approved by:	ports-secteam (miwi)
2020-02-01 13:39:43 +00:00
Cy Schubert
4ccf22b20a MFH: r524707
security/sudo update 1.8.30 --> 1.8.31

PR:		243745
Submitted by:	cy@
Reported by:	cy@
Approved by:	garga@
Security:	CVE-2019-18634

Approved by:	portmgr (miwi@)
2020-02-01 04:13:43 +00:00
Li-Wen Hsu
a20309f39c MFH: r524556
- Update to 2.204.2

Approved by:	swils (maintainer, implicitly)
Security:	a250539d-d1d4-4591-afd3-c8bdfac335d8
Sponsored by:	The FreeBSD Foundation

Approved by:	ports-secteam (miwi)
2020-02-01 01:53:50 +00:00
Li-Wen Hsu
1ef618dcb9 MFH: r524555
- Update to 2.219

Security:	a250539d-d1d4-4591-afd3-c8bdfac335d8
Sponsored by:	The FreeBSD Foundation

Approved by:	ports-secteam (miwi)
2020-02-01 01:52:26 +00:00
Alexandre C. Guimarães
6f4c60df4d MFH: r524632
audio/beets: add missing dependency.

Add devel/py-confuse to the tree since audio/beets needs it.

PR:		243601
Approved by:	portmgr (blanket: missing dependency), tcberner (mentor)
2020-02-01 01:25:05 +00:00
Piotr Kubaj
b8ae656f24 MFH: r524717
games/bastet: fix build on GCC architectures

Boost requires C++11 compiler.

Approved by:	portmgr (fix build blanket)
2020-01-31 15:50:23 +00:00
Dima Panov
07a56aab82 MFH: r524529
mail/opensmtpd: update to 6.6.2p1 relase

This update addressed LPE and RCE vulnerabilities in OpenSMTPD (CVE-2020-7247)
https://www.openwall.com/lists/oss-security/2020/01/28/3

This vulnerability is exploitable since May 2018 (commit a8e222352f, "switch
smtpd to new grammar") and allows an attacker to execute arbitrary shell
commands, as root:

- either locally, in OpenSMTPD's default configuration (which listens on
  the loopback interface and only accepts mail from localhost);

- or locally and remotely, in OpenSMTPD's "uncommented" default
  configuration (which listens on all interfaces and accepts external
  mail).

PR:		243686
Reported by:	authors via irc
Relnotes:	https://www.mail-archive.com/misc@opensmtpd.org/msg04850.html
Security:	CVE-2020-7247
Security:	08f5c27d-4326-11ea-af8b-00155d0a0200

Approved by:	ports-secteam (blanket, security issue)
2020-01-31 09:37:27 +00:00
Dima Panov
3c001379bc MFH: r524682
mail/opensmtpd-extras: extend mysql80 patch to cover fresh mariadb too

PR:		243749
Reported by:	Vikash Badal
Obtained from:	OpenSMTPd repo

Approved by:	ports-secteam (miwi)
2020-01-31 09:31:02 +00:00
Kyle Evans
db6ee0b9ed MFH: r524564
devel/elfutils: fix future build failure w.r.t. stdio _unlocked

Include <stdio.h> early so that the stdio.h function declarations come
first, then redefine fputs/fwrite/fread_unlocked to the locked versions.
fputc_unlocked will be a macro similar to putc_unlocked, so just hide that
one behind an #ifndef since it will be provided as a macro by <stdio.h>. The
other three will be using the technically-incorrect locked variants until
all supported releases provide the needed functions, at which point we can
switch them all at once.

No PORTREVISION bump as this is just a preemptive build fix that doesn't
change the output at all.

QA:
 * portlint not ran, no change outside of a single patch
 * testport (-CURRENT, amd64; 12.1-RELEASE, amd64; -CURRENT+patch, amd64)

Approved by:	koobs (ports), cem (maintainer)

Approved by:	ports-secteam (implicit; build fix)
2020-01-30 04:07:45 +00:00
Brooks Davis
6234c66b3f Fix plist that I somehow botched in the last merge.
This change syncs the plist with head.

Approved by:	ports-secteam (swills)
2020-01-29 18:16:28 +00:00
Baptiste Daroussin
f4ede0e8e3 MFH: r524543
Import the libfetch patch to the bundled libfetch

Approved by:	portmgr (implicit)
2020-01-29 13:10:14 +00:00
Jan Beich
bc3de934a4 MFH: r524531
games/openfodder: unbreak with GCC after r521658

In file included from Source/Utils/SimplexIslands.cpp:2:
Source/Utils/SimplexIslands.hpp:65:16: error: 'int32_t' does not name a type
   65 |  static inline int32_t fastfloor(double fp) {
      |                ^~~~~~~
Source/Utils/SimplexIslands.hpp: In member function 'double SimplexIslands::noise(double, double)':
Source/Utils/SimplexIslands.hpp:79:11: error: 'fastfloor' was not declared in this scope
   79 |   int i = fastfloor(xin + s);
      |           ^~~~~~~~~

PR:		243670
Submitted by:	pkubaj
Approved by:	ports-secteam blanket
2020-01-29 03:38:41 +00:00