Commit Graph

503339 Commits

Author SHA1 Message Date
Torsten Zuehlsdorff
a6d877241f MFH: r535324
lang/php74: Update from 7.4.5 to 7.4.6

Changelog:

    Core:
        Fixed bug #78434 (Generator yields no items after valid() call).
        Fixed bug #79477 (casting object into array creates references).
        Fixed bug #79514 (Memory leaks while including unexistent file).
        Fixed bug #79470 (PHP incompatible with 3rd party file system on demand).
        Fixed bug #78784 (Unable to interact with files inside a VFS for Git repository).
        Fixed bug #78875 (Long variables cause OOM and temp files are not cleaned). (CVE-2019-11048).
        Fixed bug #78876 (Long variables in multipart/form-data cause OOM and temp files are not cleaned). (CVE-2019-11048).
    DOM:
        Fixed bug #78221 (DOMNode::normalize() doesn't remove empty text nodes).
    EXIF:
        Fixed bug #79336 (ext/exif/tests/bug79046.phpt fails on Big endian arch).
    FCGI:
        Fixed bug #79491 (Search for .user.ini extends up to root dir).
    MBString:
        Fixed bug #79441 (Segfault in mb_chr() if internal encoding is unsupported).
    OpenSSL:
        Fixed bug #79497 (stream_socket_client() throws an unknown error sometimes with <1s timeout).
    PCRE:
        Upgraded to PCRE2 10.34.
    Phar:
        Fixed bug #79503 (Memory leak on duplicate metadata).
    SimpleXML:
        Fixed bug #79528 (Different object of the same xml between 7.4.5 and 7.4.4).
    SPL:
        Fixed bug #69264 (__debugInfo() ignored while extending SPL classes).
        Fixed bug #67369 (ArrayObject serialization drops the iterator class).
    Standard:
        Fixed bug #79468 (SIGSEGV when closing stream handle with a stream filter appended).
        Fixed bug #79447 (Serializing uninitialized typed properties with __sleep should not throw).

Sponsored by:	Bounce Experts

Approved by:	ports-secteam (joneum, implicit for PHP Updates)
2020-05-15 19:49:09 +00:00
Torsten Zuehlsdorff
a232035b7e MFH: r535322
lang/php73: Update from 7.3.17 to 7.3.18

Changelog:

    Core:
        Fixed bug #78875 (Long filenames cause OOM and temp files are not cleaned). (CVE-2019-11048)
        Fixed bug #78876 (Long variables in multipart/form-data cause OOM and temp files are not cleaned). (CVE-2019-11048)
        Fixed bug #79434 (PHP 7.3 and PHP-7.4 crash with NULL-pointer dereference on !CS constant).
        Fixed bug #79477 (casting object into array creates references).
        Fixed bug #79470 (PHP incompatible with 3rd party file system on demand).
        Fixed bug #78784 (Unable to interact with files inside a VFS for Git repository).
    DOM:
        Fixed bug #78221 (DOMNode::normalize() doesn't remove empty text nodes).
    FCGI:
        Fixed bug #79491 (Search for .user.ini extends up to root dir).
    MBString:
        Fixed bug #79441 (Segfault in mb_chr() if internal encoding is unsupported).
    OpenSSL:
        Fixed bug #79497 (stream_socket_client() throws an unknown error sometimes with <1s timeout).
    Phar:
        Fixed bug #79503 (Memory leak on duplicate metadata).
    SimpleXML:
        Fixed bug #79528 (Different object of the same xml between 7.4.5 and 7.4.4).
    Standard:
        Fixed bug #79468 (SIGSEGV when closing stream handle with a stream filter appended).

Sponsored by:	Bounce Experts

Approved by:	ports-secteam (joneum, implicit for PHP Updates)
2020-05-15 19:47:09 +00:00
Torsten Zuehlsdorff
26c896a89f MFH: r535321
lang/php72: Upgrade from 7.2.30 to 7.2.31

Core:

    Fixed bug #78875 (Long filenames cause OOM and temp files are not cleaned). (CVE-2019-11048)
    Fixed bug #78876 (Long variables in multipart/form-data cause OOM and temp files are not cleaned). (CVE-2019-11048)

Sponsored by:	Bounce Experts

Approved by:	ports-secteam (joneum, implicit for PHP Updates)
2020-05-15 19:45:36 +00:00
Piotr Kubaj
fb69e0909c MFH: r535312
security/nss: fix build on powerpc and powerpc64 with gcc

PR:             246419
Approved by:    jbeich (maintainer)

Approved by:	portmgr (fix build blanket)
2020-05-15 18:31:16 +00:00
Mathieu Arnold
de9ab02f3e Remove expired ports:
dns/dnsperf: depends on expired dns/bind914, not compatible with dns/bind916
2020-04-30 dns/bind914: End of life, please migrate to a newer version of BIND9
2020-05-15 16:42:41 +00:00
Li-Wen Hsu
275cab25dd MFH: r535070
Update to 2020.1

Changes:	https://github.com/stub42/pytz/commits/master
PR:		246401
Submitted by:	sunpoet (myself)
Approved by:	lwhsu (maintainer)

Approved by:	ports-secteam (joneum)
2020-05-15 13:21:18 +00:00
Cy Schubert
2471b50731 MFH: r535196
Fix STATIC build.

Approved by:	portmgr (joneum)
2020-05-14 17:09:52 +00:00
Jan Beich
db9680bfd9 MFH: r534853
multimedia/handbrake: update to 1.3.2

Changes:	https://github.com/HandBrake/HandBrake/releases/tag/1.3.2
Submitted by:	Yuichiro NAITO (maintainer)
Tested by:	pkubaj (powerpc64)
Approved by:	ports-secteam (joneum)
Differential Revision:	https://reviews.freebsd.org/D24742
2020-05-14 17:07:36 +00:00
Jan Beich
00e9c734e8 MFH: r534935
Convert GitLab patches to simple diffs

GitLab unlike GitHub keeps the footer from git-format-patch(1) which
frequently changes on Git version upgrades. So, switch to git-diff(1)
which lacks header/footer.

Approved by:	x11 (zeising via Gitter)
Approved by:	ports-secteam (joneum)
Differential Revision:	https://reviews.freebsd.org/D24810
2020-05-14 17:06:18 +00:00
Sunpoet Po-Chuan Hsieh
078840f9f6 MFH: r535182
Update to 9.5.17

Changes:	https://get.typo3.org/release-notes/9.5.17
		https://typo3.org/article/typo3-1042-and-9517-security-releases-published
PR:		246435
Submitted by:	Helmut Ritter <freebsd-ports@charlieroot.de> (maintainer)
Security:	59fabdf2-9549-11ea-9448-08002728f74c

Approved by:	ports-secteam (joneum)
2020-05-14 16:59:58 +00:00
Danilo G. Baio
809b2bcc3a MFH: r534393
www/py-bleach: Update to 3.1.5, Fix security issue

Changelog:	https://github.com/mozilla/bleach/blob/v3.1.5/CHANGES

PR:		245943
Approved by:	koobs (maintainer)
Security:	4c52ec3c-86f3-11ea-b5b4-641c67a117d8

Approved by:	ports-secteam (joneum)
2020-05-14 11:52:06 +00:00
Xin LI
04a85fac9f MFH: r535198
www/dokuwiki: update to 2018-04-22c.

PR:		246454
Submitted by:	Yasuhiro KIMURA
Approved by:	ports-secteam
2020-05-14 03:40:11 +00:00
Jan Beich
915ae0e1cf MFH: r535193
emulators/citra: update to s20200513

Changes:	8d27b0714...213c956b7
Approved by:	ports-secteam (swills, implicit for snapshots)
2020-05-14 00:48:37 +00:00
Kirill Ponomarev
2c515ddb40 MFH: r535131
Update to 2019.2.5

Changes: https://docs.saltstack.com/en/2019.2/topics/releases/2019.2.5.html

PR:		246445
Approved by:	maintainer

Approved by:	portmgr (security blanket)
2020-05-13 19:48:07 +00:00
Piotr Kubaj
0e933255f3 MFH: r535096
audio/milkytracker: fix build on powerpc*

Merge upstream patch to fix build.

Approved by:	portmgr (fix build blanket)
2020-05-13 08:56:35 +00:00
Kai Knoblich
c64f527c5c MFH: r535092
net/py-ldappool: Update to 2.4.1

* Separate USES block from non-relevant variables.

* While I'm here: Add "do-test" target to make future QA easier.

Notable changes since 2.2.0:

* Allow pool status to be printed as a table
* Handle retry logic for timeouts with multiple LDAP servers
* Improve connection retry logging
* Fix ldappool bad password retry logic

PR:		246402
Submitted by:	sunpoet

Approved by:	ports-secteam bugfix blanket
2020-05-13 08:15:33 +00:00
Jung-uk Kim
152540434c MFH: r535004
Update to 32.0.0.371.

Approved by:	ports-secteam (blanket)
2020-05-12 19:18:21 +00:00
Rene Ladan
d0b8d33ba1 MFH: r534998
comms/telldus-core: fix fetch and unexpire.

PR:		242246
Submitted by:	norrland@nullbyte.se
Approved by:	maintainer

Approved by:	blanket (fix fetch)
2020-05-12 17:42:29 +00:00
Gerald Pfeifer
ce6d6a051d MFH: r532899
Backport r530401 | gerald | 2020-04-02 from our wine-devel companion:

  Explicitly configure --without-unwind so that the presence of the
  devel/libunwind port does not pull in an implicit dependency that
  is not tracked properly.

Reported by:	Andy Mender <andymenderunix@gmail.com>
PR:		245172
Approved by:	portmgr (blanket: dependency issue)
2020-05-12 07:44:12 +00:00
Jan Beich
30e131ed25 MFH: r534930
graphics/wayland: regen gitlab patches

-2.24.1
+2.26.2

Approved by:	ports-secteam blanket
2020-05-11 18:59:35 +00:00
Jan Beich
04a3e87f5b MFH: r534929
graphics/waffle: regen gitlab patches

-2.24.1
+2.26.2

Approved by:	ports-secteam blanket
2020-05-11 18:59:15 +00:00
Kyle Evans
2296ce1c07 MFH: r534921
www/gitea: Fix viewing of branches with a slash in the name

An issue[0] was filed upstream in January that branches with a slash in
their name (e.g. stable/11) result in a 500 error when attempting to view
them.

I tracked down the issue to the fact that read(2) on a directory fd in
FreeBSD will actually succeed, while it will not on Linux/other OS. I have
filed a PR[1] with go-git to remedy the problem there, and then we
(hopefully) convince gitea maintainers to accept the patch as well once it's
upstreamed.

The attached patch brings it into the ports tree as well, so that FreeBSD
users can more immediately get the fix. It should still apply to the version
in 2020Q2, more or less, with version numbers changed to protect the
innocent.

[0] https://github.com/go-gitea/gitea/issues/9938
[1] https://github.com/go-git/go-git/pull/39

PR:		245863
Approved by:	<stb lassitu de> (maintainer)
Aoorived by:	koobs (mentor, ports)

Approved by:	ports-secteam (blanket: minor bugfix patch)
2020-05-11 16:56:02 +00:00
Jan Beich
9eb65bf99b MFH: r534912 r534914
www/firefox: backport NSS 3.52 support after r533597

PR:		246363
Reported by:	Tomasz "CeDeROM" CEDRO, Roman
Approved by:	ports-secteam blanket
2020-05-11 14:18:49 +00:00
Gerald Pfeifer
da818c9f17 MFH: r534732
Explicitly configure --without-inotify so that the presence of the
devel/libinotify port does not pull in an implicit dependency that
is not tracked properly.

Reported by:	Andy Mender <andymenderunix@gmail.com>
PR:		245172
Approved by:	portmgr (blanket: dependency issue)
2020-05-11 09:00:10 +00:00
Guido Falsi
db6617a8a6 MFH: r534782
Fix build with openssl on 12.1-STABLE.

PR:		246289
Submitted by:	yds@Necessitu.de

Approved by:	ports-secteam (joneum)
2020-05-10 16:49:36 +00:00
Jochen Neumeister
4ff676a77a MFH: r534850
Update to 5.3.3

Add php-json support [1]

PR:		244382 [1]
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (with hat)
2020-05-10 13:56:17 +00:00
Gerald Pfeifer
3999ec8a0b MFH: r530401
Explicitly configure --without-unwind so that the presence of the
devel/libunwind port does not pull in an implicit dependency that
is not tracked properly.

Reported by:	Andy Mender <andymenderunix@gmail.com>
PR:		245172
Approved by:	portmgr (blanket: dependency issue)
2020-05-10 10:18:39 +00:00
Jochen Neumeister
2c119134bb MFH: r534833
Update to 9.4.5

ChangeLogs
- 9.4.5: https://github.com/glpi-project/glpi/milestone/38?closed=1
- 9.4.4: https://github.com/glpi-project/glpi/milestone/37?closed=1
- 9.4.3: https://github.com/glpi-project/glpi/milestone/36?closed=1

PR:		244971
Security:	d222241d-91cc-11ea-82b8-4c72b94353b5
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (with hat)
2020-05-10 08:55:06 +00:00
Jan Beich
9b624ead03 MFH: r534801
emulators/citra: update to s20200509

Changes:	36809b2e2...8d27b0714
Approved by:	ports-secteam (swills, implicit for snapshots)
2020-05-10 00:39:41 +00:00
Matthias Andree
8a8f2dabab MFH: r534788
graphics/darktable: fix broken build, data/kernels/ related

This patch is to fix this problem:

| CMake Error at data/kernels/CMakeLists.txt:34 (foreach):
|   Unknown argument:
| /usr/ports/graphics/darktable/work/darktable-3.0.0/data/kernels/atrous.cl

Approved by:	portmgr@ (blanket approval to fix broken builds)

Note that his revealed a Tools/scripts/mfh bug where it does not currently
check out the port directory, but only files/.
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=246336
2020-05-09 16:55:24 +00:00
Glen Barber
8655426159 MFH: r534739
Add MANIFEST files for 11.4-BETA1.

Sponsored by:	Rubicon Communications, LLC (netgate.com)
Approved by:	portmgr (implicit, re blanket)
2020-05-09 13:24:40 +00:00
Wen Heping
1c5ec980a3 MFH: r534040
- Update to 2.7.18 [1]
  (include security fix)
- Fix build with OPTION of DEBUG THREADS [2]

PR:		245776
Submitted by:	vvd@unislabs.com [1],
		takefu@airport.fm [2]
Exp-run by:	antoine@ [1]
Security:	CVE-2019-18348, CVE-2020-8492

Approved by:	ports-secteam@(joneum@)
2020-05-09 10:14:08 +00:00
Tobias C. Berner
b28094503f MFH: r534715
x11-fonts/fontconfig: webfonts on many sites crash www/firefox

A "bad" commit [1] included in the recent fontconfig upgrade to 2.13.92, lead to many
crashed tabs inside firefox. A fix has been provided upstream in [2], and fixed in fix [3].

Related Mozilla bugreport [4].

[1] https://cgit.freedesktop.org/fontconfig/commit/?id=61573ad5f7c4dd0860d613d99d0086433240eb75
[2] https://gitlab.freedesktop.org/fontconfig/fontconfig/-/issues/237
[3] 6edaaa4d18
[4] https://bugzilla.mozilla.org/show_bug.cgi?id=1629231

PR:		245915
Submitted by:	jbeich
Reported by:	Graham Perrin, jbeich, ehaupt, tcberner

Approved by:	ports-secteam (implicit)
2020-05-09 07:04:53 +00:00
Jan Beich
952004cb9b lang/intel-compute-runtime: unbreak on amd64 after r534402
CMake Error at level_zero/CMakeLists.txt:32 (project):
  VERSION "0.8." format invalid.

Reported by:	pkg-fallout
Approved by:	ports-secteam blanket
2020-05-09 06:47:28 +00:00
Gerald Pfeifer
5be854e313 MFH: r534205
Push USES=pkgconfig to the global level instead just contingent on the
VKD3D option.

This makes a real difference for the GNUTLS option (on by default) and
others.  Accordingly bump PORTREVISION.

Reported by:	Benny Goemans <benny.goemans@belgacom.net>
Approved by:	portmgr (blanket: missing dependency)
2020-05-08 18:29:50 +00:00
Jan Beich
eb977c666a MFH: r534401
lang/intel-compute-runtime: fix version after r529254

$ clinfo | fgrep 'Driver Version'
  Driver Version                                  1.0.0

https://github.com/intel/compute-runtime/commit/211375e898e3
https://github.com/intel/compute-runtime/commit/43016c65591b

Approved by:	ports-secteam blanket
2020-05-08 13:15:27 +00:00
Jan Beich
7642b9dd4c MFH: r534320
www/firefox: update to 76.0.1

Changes:	https://www.mozilla.org/firefox/76.0.1/releasenotes/
Approved by:	ports-secteam blanket
2020-05-08 04:47:21 +00:00
Jan Beich
989429695d MFH: r533806
games/openra: update to 20200503

Changes:	https://github.com/OpenRA/OpenRA/wiki/Changelog#release-20200503
Approved by:	ports-secteam (joneum)
2020-05-07 23:00:58 +00:00
Jan Beich
3a71b7911b MFH: r534299
net/waypipe: regen patches (gitlab bug)

-2.24.1
+2.26.2

Approved by:	ports-secteam blanket
2020-05-07 22:36:53 +00:00
Jan Beich
64475fd12d MFH: r534297
multimedia/dav1d: regen patches (gitlab bug)

-2.24.1
+2.26.2

Reported by:	pkubaj (via D24742)
Approved by:	ports-secteam blanket
2020-05-07 22:34:36 +00:00
Jan Beich
93c29bf258 MFH: r534295
x11-servers/xwayland-devel: regen patches (gitlab bug)

-2.24.1
+2.26.2

Reported by:	Grzegorz Junka (on ports@ list)
Approved by:	ports-secteam blanket
2020-05-07 22:07:35 +00:00
Matthias Andree
256087e126 mail/mailman: fix another content injection vuln via private archive login
This led up to mailman 2.1.33 today.
https://bugs.launchpad.net/mailman/+bug/1877379
https://launchpadlibrarian.net/478684932/private.diff
https://mail.python.org/archives/list/mailman-developers@python.org/thread/SYBIZ3MNSQZLKN6PVKO7ZKR7QMOBMS45/

Approved by:    ports-secteam@ (blanket for security fixes)
Security:       88760f4d-8ef7-11ea-a66d-4b2ef158be83
2020-05-07 19:56:38 +00:00
Craig Leres
da8f0c2bcd MFH: r534211
security/zeek: Update to 3.0.6 and address multiple vulnerabilites:

    https://raw.githubusercontent.com/zeek/zeek/v3.0.6/NEWS

 - Fix buffer over-read in Ident analyzer

 - Fix SSL scripting error leading to uninitialized field access
   and memory leak

 - Fix POP3 analyzer global buffer over-read

 - Fix potential stack overflows due to use of Variable-Length-Arrays

Other changes since 3.0.5 include:

 - Fix unusable `subscriber.poll()` method in Broker Python bindings

 - Fix uninitialized field access in `ssl/log-hostcerts-only.zeek`

 - Fix missing default function for Kerberos constant-lookup-tables

 - Fix cloning of `TypeType` values

 - Remove misleading error message on empty bloomfilter lookup

 - Fix `misc/stats.zeek` skipping log entry on termination

Approved by:	ports-secteam (joneum)
2020-05-07 17:17:17 +00:00
Matthias Andree
2364d7a428 MFH: r534272
security/openvpn: reliability fixes cherry-picked from upstream

Arne Schwabe's OpenSSL fix for Debian Bug#958296
"Fix tls_ctx_client/server_new leaving error on OpenSSL error stack"
<https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=958296> [1]

Selva Nair's auth-pam fixes
"Parse static challenge response in auth-pam plugin"
"Accept empty password and/or response in auth-pam plugin"

Re-diff (with make makepatch) older patches.

Reported by:	Jonas Andradas via Debian BTS
Obtained from:	Arne Schwabe, Selva Nair <https://github.com/OpenVPN/openvpn/tree/release/2.4>

Approved by:	ports-secteam@ (blanket for backporting reliability fixes)
2020-05-07 16:37:44 +00:00
Jochen Neumeister
63c6959fe5 MFH: r534263
databases/mysql80-{client, server}: Update to latest release 8.0.20

- Performance: Certain queries against tables with spatial indexes were not performed as efficiently following an upgrade from MySQL 5.7 to MySQL 8.0.
- NDB Cluster: NDB defines one SPJ worker per node owning a primary partition of the root table. If this table used read from any replica, DBTC put all SPJ workers in the same DBSPJ instance, which effe
- NDB Cluster: Executing the SHOW command using an ndb_mgm client binary from NDB 8.0.16 or earlier to access a management node running NDB 8.0.17 or later produced the error message Unknown field: is_s
- On EL7 and EL8, CMake configuration was adjusted to look for GCC 9 before GCC 8. Because libmysqlclient ships with MySQL distributions, client applications built against libmysqlclient on those platfo
- The max_length_for_sort_data system variable is now deprecated due to optimizer changes that make it obsolete and of no effect.

More Infos: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-20.html

Special thanks to: fluffy

Security:	21d59ea3-8559-11ea-a5e2-d4c9ef517024 (MySQL - Server)
Security:       622b5c47-855b-11ea-a5e2-d4c9ef517024 (MySQL - Client)
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (with hat)
2020-05-07 11:54:47 +00:00
Rene Ladan
c743b767c1 MFH: r534206
www/chromium: update to 81.0.4044.138

Security:	https://chromereleases.googleblog.com/2020/05/stable-channel-update-for-desktop.html

Approved by:	ports-secteam (joneum)
2020-05-07 07:55:59 +00:00
Jan Beich
cabebebcb5 MFH: r534155
multimedia/wlrobs: unbreak on powerpc64

PR:		243659
Submitted by:	pkubaj
Approved by:	ports-secteam blanket
2020-05-06 09:06:49 +00:00
Matthias Andree
9e0d62bd3f 2020Q2 specific mail/mailman minimal security fix
Backporting 2.1.31 needs more consideration and more than just MFH r534101,
so forgo that and for the nonce, plug this information leak quickly with the
one-line fix by upstream, and hack additional translations to match into the
.po files with REINPLACE_CMD.

Approved by:	ports-secteam@ (blanket, trivial security fix)
Security:	88760f4d-8ef7-11ea-a66d-4b2ef158be83
2020-05-05 22:57:42 +00:00
Guido Falsi
e5a4d372da MFH: r534084
Change default MDNS backend to the more commonly used avahi one.

This avoids conflicting with KDE and other commonly used ports.

Reported by:	Chris Watson <bsdunix44@gmail.com>

Approved by:	ports-secteam (joneum)
2020-05-05 20:20:34 +00:00
Christoph Moench-Tegeder
04a5b1c586 MFH: r533707 r534066
update thunderbird to 68.8.0 (rc1)

Announcement (soon):
  https://www.thunderbird.net/en-US/thunderbird/68.8.0/releasenotes/

update thunderbird to 68.8.0 (rc2)

Announcement (soon):
  https://www.thunderbird.net/en-US/thunderbird/68.8.0/releasenotes/

Approved by:	ports-secteam (blanket: web browser alike)
2020-05-05 16:50:57 +00:00