1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-11-24 00:45:52 +00:00
Commit Graph

495277 Commits

Author SHA1 Message Date
Kubilay Kocak
bab5719cdd MFH: r528619 devel/py-virtualenvwrapper: Fix virtualenvwrapper_lazy.sh wrapper
Fix the virtualenvwrapper_lazy.sh wrapper to invoke the Python
versions-specific virtualenvwrapper.sh script that the port/package was
built with, preventing the following error:

  ERROR: virtualenvwrapper_lazy.sh: Could not find virtualenvwrapper.sh

While I'm here:

  - Update pkg-descr WWW: URL to match setup.py:homepage
  - Update COMMENT to match setup.py:summary

Approved by:	portmgr (blanket: ports (python) compliance, run-time bugfix)

Approved by:	ports-secteam (blanket: ports (python) compliance, run-time bugfix)
2020-03-18 00:51:59 +00:00
Craig Leres
f57f99ffdc MFH: r528508
security/bro: Update to 3.0.3 and address a number of potential
denial of service issues:

   https://github.com/zeek/zeek/releases/tag/v3.0.2
   https://github.com/zeek/zeek/releases/tag/v3.0.3

 - Potential Denial of Service due to memory leak in DNS TSIG message
   parsing.

 - Potential Denial of Service due to memory leak (or assertion
   when compiling with assertions enabled) when receiving a second
   SSH KEX message after a first.

 - Potential Denial of Service due to buffer read overflow and/or
   memory leaks in Kerberos analyzer.  The buffer read overflow
   could occur when the Kerberos message indicates it contains an
   IPv6 address, but does not send enough data to parse out a full
   IPv6 address.  A memory leak could occur when processing KRB_KDC_REQ
   KRB_KDC_REP messages for message types that do not match a
   known/expected type.

 - Potential Denial of Service when sending many zero-length SSL/TLS
   certificate data.  Such messages underwent the full Zeek file
   analysis treatment which is expensive (and meaninguless here)
   compared to how cheaply one can "create" or otherwise indicate
   many zero-length contained in an SSL message.

 - Potential Denial of Service due to buffer read overflow in SMB
   transaction data string handling.  The length of strings being
   parsed from SMB messages was trusted to be whatever the message
   claimed instead of the actual length of data found in the message.

 - Potential Denial of Service due to null pointer dereference in
   FTP ADAT Base64 decoding.

 - Potential Denial of Service due buffer read overflow in FTP
   analyzer word/whitespace handling.  This typically won't be a
   problem in most default deployments of Zeek since the FTP analyzer
   receives data from a ContentLine (NVT) support analyzer which
   first null-terminates the buffer used for further FTP parsing.

Approved by:	ler (mentor, implicit)
Security:	4ae135f7-85cd-4c32-ad94-358271b31f7f

Approved by:	ports-secteam (joneum)
2020-03-18 00:24:50 +00:00
Koichiro Iwao
0e87813769 MFH: r528561
security/softether5: fix build on aarch64

Tested on Amazon EC2 A1 instances with FreeBSD/ARM 12 image[1].
Build on mips also should be fixed (not actually tested).

[1] https://aws.amazon.com/marketplace/pp/B081NF7BY7

Sponsored by:	HAW International

Approved by:	portmgr branket (fix build)
2020-03-17 06:34:24 +00:00
Kubilay Kocak
aa87c0680c MFH: r526348 sysutils/py-diffoscope: Update to 136
Merge ports r526348 (update to 136, bugfix release) which should have
been merged with ports r528329

PR:		244750

Approved by:	ports-secteam (blanket: bugfix release, fix quarterly regression)
2020-03-14 02:20:07 +00:00
Jan Beich
d5c45306b1 MFH: r528394
emulators/citra: update to s20200312

Changes:	2c0bd0f2a...ad3c464e2
Approved by:	ports-secteam (swills, implicit for snapshots)
2020-03-14 00:45:30 +00:00
Kubilay Kocak
94a99eb425 MFH: r528327 sysutils/py-diffoscope: Restore portability of zipinfo call
/dev/stdin is a non-portable non-POSIX extension having different
semantics on different operating systems. zininfo(1) exits with 9 when
/dev/stdin is supplied on FreeBSD. In fact, unzip(1) explicitly documents
that it does not support reading from stdin.

[1] https://lists.reproducible-builds.org/pipermail/diffoscope/2020-March/002632.html

PR:		244750
Submitted by:	Michael Osipov <michael.osipov siemens com>

Approved by:	ports-secteam (blanket: runtime bugfix)
2020-03-13 04:48:57 +00:00
Christoph Moench-Tegeder
e36557295e MFH: r528231
mail/thunderbird: update to 68.6.0

Releasenotes https://www.thunderbird.net/en-US/thunderbird/68.6.0/releasenotes/

Approved by:	portmgr blanket "web browser alike"
2020-03-12 18:58:18 +00:00
Tobias C. Berner
8f6640acbe MFH: r528046
irc/bitlbee-discord: Update to 0.4.2-11

PR:		244392
Submitted by:	Arthur Pirika <arfy32@gmail.com> (maintainer)

Approved by:	ports-secteam (joneum)
2020-03-12 18:46:07 +00:00
Wen Heping
3623518daf MFH: r528261
- Update Django to 3.0.4, 2.2.11 and 1.11.29(security release)
Security:	CVE-2020-9402

Approved by:	ports-secteam@(joneum@)
2020-03-12 08:47:23 +00:00
Jochen Neumeister
25f1ebfadd MFH: r528272
This fix a Problem, when MySQL build with libressl

/var/ports/usr/ports/databases/mysql56-client/work/mysql-5.6.47/vio/viosslfactories.c:230:25: error: use of undeclared identifier 'SSL_OP_NO_TLSv1_3'
                        SSL_OP_NO_TLSv1_3 |
                        ^
/var/ports/usr/ports/databases/mysql56-client/work/mysql-5.6.47/vio/viosslfactories.c:275:12: warning: implicit declaration of function 'SSL_CTX_set_ciphersuites' is invalid in C99 [-Wimplicit-function-declaration]
  if (0 == SSL_CTX_set_ciphersuites(ssl_fd->ssl_context, ""))

Special thanks for his help to: fluffy

PR:		244320
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-03-12 07:47:46 +00:00
Jung-uk Kim
5cfd4e8b48 MFH: r528267
Update to 32.0.0.344.

Approved by:	ports-secteam (blanket)
2020-03-12 03:06:28 +00:00
Kyle Evans
ce97c25da2 MFH: r528258
emulators/virtualbox-ose: use contemporary GCC instead of old llvm

The bug in PR 236616 resulted in virtualbox getting pinned to llvm7. This is
less than ideal, and in-fact has been broken by improvements to
machine/atomic.h
on x86 that require a more modern compiler.

Switch the build to USE_GCC= any. The patches that were previously applied
if COMPILER_TYPE == clang are actually needed by newer GCCs as well, so make
those
standard patches instead, folding the Config.kmk patches together.

We should put some effort into testing llvm10 and working out why llvm
breaks
it, but fixing the build is more important at the moment.

Q/A:
* portlint (pre-existing issues; none in current patch)
* testport (-CURRENT, amd64)
* run testing by madpilot@

PR:		244603
Approved by:	koobs (mentor), bapt (mentor)
Approved by:	portmgr (blanket: build fix)
Differential Revision:	https://reviews.freebsd.org/D23967

Approved by:	ports-secteam (blanket: build fix)
2020-03-12 00:44:44 +00:00
Thomas Zander
70289c0a6e MFH: r528243
Update to upstream version 44.0.0

Details:
- Mostly bugfixes, see
  https://mkvtoolnix.download/doc/NEWS.md
  but also a helpful new feature:
- MKVToolNix GUI: header editor: the attachments can now
  be reordered via drag & drop.

Approved by:	ports-secteam (riggs)
2020-03-11 20:34:49 +00:00
Jan Beich
c105b223bd MFH: r528139
www/firefox: switch to rc3

Changes:	https://hg.mozilla.org/releases/mozilla-release/rev/c6e493873ba5
Approved by:	ports-secteam blanket
2020-03-09 23:43:54 +00:00
Jan Beich
fc27847c1e MFH: r527914
security/nss: update to 3.51

Changes:	https://developer.mozilla.org/docs/Mozilla/Projects/NSS/NSS_3.51_release_notes
Changes:	https://hg.mozilla.org/projects/nss/shortlog/NSS_3_51_RTM
ABI:		https://abi-laboratory.pro/tracker/timeline/nss/
Approved by:	ports-secteam blanket (required by Firefox 75)
2020-03-09 18:28:05 +00:00
Jan Beich
d314cc9033 MFH: r524792
devel/nspr: update to 4.25

- Only run tests enabled on upstream CI

Changes:	http://mozilla.6506.n7.nabble.com/ANNOUNCE-NSPR-4-25-Release-td383750.html
ABI:		https://abi-laboratory.pro/tracker/timeline/nspr/
Reported by:	Repology
Approved by:	ports-secteam blanket
2020-03-09 18:25:06 +00:00
Jan Beich
710c86ae3f MFH: r522737 r524737 r525719
devel/rust-cbindgen: update to 0.13.1

Changes:	https://github.com/eqrion/cbindgen/compare/v0.12.1...v0.13.1
Reported by:	GitHub (watch releases)
Approved by:	ports-secteam blanket
2020-03-09 18:23:59 +00:00
Jan Beich
84e9e400f0 MFH: r527890
www/firefox: backport font selection regression fix

Requested by:	Andy New (on gecko@ list)
Approved by:	ports-secteam blanket
2020-03-07 19:07:20 +00:00
Jan Beich
1be80b5578 MFH: r527804
www/firefox: update to 74.0

Changes:	https://www.mozilla.org/firefox/74.0/releasenotes/
PR:		244310
Security:	9f900456-0bfa-4da4-ad59-14b2933259a2
Approved by:	ports-secteam blanket
Differential Revision:	https://reviews.freebsd.org/D23646
2020-03-07 19:06:38 +00:00
Jan Beich
adf4a6332a MFH: r527848
www/firefox-esr: update to 68.6.0

Changes:	https://www.mozilla.org/firefox/68.6.0/releasenotes/
Security:	9f900456-0bfa-4da4-ad59-14b2933259a2
Approved by:	ports-secteam blanket
2020-03-07 19:05:28 +00:00
Adam Weinberger
eee63c5b8b MFH: r526626 r527958
www/gitea: Update to 1.10.4

Changes:	https://github.com/go-gitea/gitea/releases/tag/v1.10.4
PR:		244246
Submitted by:	stb@lassitu.de (maintainer)

gitea: Update to 1.11.2, contains security fixes

https://blog.gitea.io/2020/02/gitea-1.11.0-is-released
https://blog.gitea.io/2020/02/gitea-1.11.1-is-released
https://blog.gitea.io/2020/02/gitea-1.11.2-is-released

PR:		244025
Submitted by:	maintainer
Security:	yes (see links above)

Approved by:	portmgr (with hat)
2020-03-07 18:42:56 +00:00
Jochen Neumeister
a88e27fda8 MFH: r527924
hand over Maintainership to Chris (portmaster@BSDforge.com)

Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-03-07 09:34:50 +00:00
Jochen Neumeister
e2135cee56 MFH: r527889
back to pool

Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-03-07 09:33:42 +00:00
Jochen Neumeister
e9a66f21ea MFH: r527888
hand over Maintainership to miwi

Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-03-07 09:32:46 +00:00
Jochen Neumeister
010eaf694c MFH: r527887
hand over Maintainership to miwi

Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-03-07 09:29:18 +00:00
Jochen Neumeister
c18175a133 MFH: r527886
hand over Maintainership to miwi

Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-03-07 09:25:39 +00:00
Jochen Neumeister
59ab042b01 MFH: r527885
hand over Maintainership to miwi

Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-03-07 09:21:48 +00:00
Antoine Brodin
1877f69536 Revert r527893 and unbreak the quarterly branch 2020-03-07 06:39:16 +00:00
Niclas Zeising
a232a04400 MFH: r527894
graphics/drm-legacy-kmod: Update snapshot

Update the graphics/drm-legacy-kmod port to the latest snapshot, fixing the
build with llvm 10

Approved by:	ports-secteam (implicit, drm-drivers blanket)
2020-03-06 21:46:07 +00:00
Matthias Fechner
dce4c2395b MFH: r527066 r527082
New port required for gitlab-ce 12.8.

New ports required for gitlab-ce 12.8 upgrade.

Approved by:	ports-secteam (joneum)
2020-03-06 19:29:52 +00:00
Jan Beich
5576fb9f4f MFH: r527874
multimedia/dav1d: update to 0.6.0

Changes:	https://code.videolan.org/videolan/dav1d/tags/0.6.0
Changes:	https://code.videolan.org/videolan/dav1d/blob/0.6.0/NEWS
Changes:	https://code.videolan.org/videolan/dav1d/compare/0.5.2...0.6.0
Approved by:	ports-secteam blanket (required by Firefox 76)
2020-03-06 14:22:16 +00:00
Piotr Kubaj
976efb3afa MFH: r527871
databases/postgresql12-server: fix build on GCC architectures

Use LLVM only if Clang is used.

PR:		244225
Approved by:	pgsql (maintainer timeout)

Approved by:	portmgr (fix build blanket)
2020-03-06 10:14:45 +00:00
Kai Knoblich
83eb67cb55 MFH: r527810
textproc/py-textfsm: Update to 1.1.1

This update resolves a package installation conflict with
textproc/py-texttable as both ports installs "texttable.py" into the same
place. [1]

Also while I'm here:

* Switch to GitHub for a while as no sdist tarballs are available at PyPi.

* Make the port concurrent safe because it installs scripts outside of the
  site-lib directory.

* Remove the "testdata" directory to prevent possible package conflicts as
  it's only required for the test suite.

* Add a "do-test" target to make future QA easier.

Changelog:

https://github.com/google/textfsm/releases/tag/v1.1.0
https://github.com/google/textfsm/releases/tag/v1.1.1

PR:		244257
Reported by:	John Hein <jcfyecrayz@liamekaens.com> [1]

Approved by:	ports-secteam (joneum)
2020-03-05 07:32:54 +00:00
Antoine Brodin
925e010fc9 MFH: r527808
Bump after FORBIDDEN
2020-03-05 06:44:42 +00:00
Cy Schubert
0f5ed4b120 MFH: r527758
Flag ntp-devel FORBIDDEN due to
http://support.ntp.org/bin/view/Main/SecurityNotice#\
March_2020_ntp_4_2_8p14_NTP_Rele

Approved by:	portmgr (joneum)
2020-03-05 06:22:47 +00:00
Cy Schubert
085d4c9c98 MFH: r527800
Update ntp-4.2.8p13 --> 4.2.8p14.

The advisory can be found at:
http://support.ntp.org/bin/view/Main/SecurityNotice#\
March_2020_ntp_4_2_8p14_NTP_Rele

No CVEs have been documented yet.

Security:	http://support.ntp.org/bin/view/Main/NtpBug3610
		http://support.ntp.org/bin/view/Main/NtpBug3596
		http://support.ntp.org/bin/view/Main/NtpBug3592

Approved by:	portmgr (joneum)
2020-03-05 06:21:11 +00:00
Koop Mast
2dea593305 MFH: r527732
Update librsvg2 to 2.40.21.

* Add license while here

Security:	b66583ae-5aee-4cd5-bb31-b2d397f8b6b3

Approved by:	ports-secteam@ (joneum@)
2020-03-04 19:04:26 +00:00
Tobias Kortkamp
795f7aa36e MFH: r523512
lang/rust-nightly: Unbreak with lld on 12.1/13.0 i386

 = note: ld: error: relocation R_386_PC32 cannot be used against symbol __rust_probestack; recompile with -fPIC
          >>> defined in /wrkdirs/usr/ports/lang/rust-nightly/work/rustc-nightly-src/build/i686-unknown-freebsd/stage1/lib/rustlib/i686-unknown-freebsd/lib/libcompiler_builtins-6570a75fe85f0e1a.rlib(compiler_builtins-6570a75fe85f0e1a.compiler_builtins.2i519eqi-cgu.15.rcgu.o)
          >>> referenced by std.4xivr03c-cgu.14
          >>>               std-9bd70afd58e204b7.std.4xivr03c-cgu.14.rcgu.o:(_$LT$alloc..boxed..Box$LT$F$GT$$u20$as$u20$core..ops..function..FnOnce$LT$A$GT$$GT$::call_once::h1c78ed6e734a2bfc (.llvm.10122419023709863394)) in archive /wrkdirs/usr/ports/lang/rust-nightly/work/rustc-nightly-src/build/i686-unknown-freebsd/stage1/lib/rustlib/i686-unknown-freebsd/lib/libstd-9bd70afd58e204b7.rlib

          ld: error: relocation R_386_PC32 cannot be used against symbol __rust_probestack; recompile with -fPIC
          >>> defined in /wrkdirs/usr/ports/lang/rust-nightly/work/rustc-nightly-src/build/i686-unknown-freebsd/stage1/lib/rustlib/i686-unknown-freebsd/lib/libcompiler_builtins-6570a75fe85f0e1a.rlib(compiler_builtins-6570a75fe85f0e1a.compiler_builtins.2i519eqi-cgu.15.rcgu.o)
          >>> referenced by std.4xivr03c-cgu.14
          >>>               std-9bd70afd58e204b7.std.4xivr03c-cgu.14.rcgu.o:(std::io::util::copy::h9115f048f2203467) in archive /wrkdirs/usr/ports/lang/rust-nightly/work/rustc-nightly-src/build/i686-unknown-freebsd/stage1/lib/rustlib/i686-unknown-freebsd/lib/libstd-9bd70afd58e204b7.rlib
          clang-cpp: error: linker command failed with exit code 1 (use -v to see invocation)

error: aborting due to previous error

http://beefy17.nyi.freebsd.org/data/head-i386-default/p523508_s356869/logs/rust-nightly-1.42.0.20200118.log
http://beefy4.nyi.freebsd.org/data/121i386-quarterly/527662/logs/rust-nightly-1.42.0.20191222.log

Approved by:	ports-secteam blanket
2020-03-04 17:56:57 +00:00
Kubilay Kocak
2562ff257c MFH: r527737 devel/py-futures: Update to 3.3.0
Changelog:

  https://github.com/agronholm/pythonfutures/blob/3.3.0/CHANGES.rst

Reported by:	ngie

Approved by:	ports-secteam (blanket: bugfix release)
2020-03-04 05:17:11 +00:00
Jan Beich
8a5e18f48c MFH: r527660
emulators/citra: update to s20200301

Changes:	cd46e62ad...2c0bd0f2a
Approved by:	ports-secteam (swills, implicit for snapshots)
2020-03-03 00:46:31 +00:00
Mateusz Piotrowski
f6042aba3a MFH: r527618 r527619
- Update audio/timidity++ to 2.15.0. [1]
- Mark audio/timidity++-tcltk as BROKEN due to build failures.

PR:		244429
Submitted by:	pi [1]
Security:	CVE-2017-11546
Security:	CVE-2017-11547
Security:	CVE-2017-11549

Approved by:	ports-secteam (joneum)
2020-03-02 14:02:08 +00:00
Mateusz Piotrowski
7f6a932a8e MFH: r527232
Add libarc to LIB_DEPENDS for audio/timidity++

Up until now, libarc was only being included in LIB_DEPENDS when
the Makefile of audio/timidity++ was being used by one of its slave ports.
audio/timidity++, however, may be also used as a standalone port in which
case it needs libarc to be available.

Reported by:	hselasky

Approved by:	portmgr blanket (runtime fix)
2020-03-02 09:25:36 +00:00
Christoph Moench-Tegeder
dcd1fe0196 MFH: r527565
switch kicad-doc from source to pre-built docs

The build process is rather unstable on our asciidoc toolchain, but
then the doc files are completely independent of OS and machine
architecture, so there's nothing which stops us from just taking the
ready-built files from upstream. At the same time this enables two
additional documentation languages (polnish and chinese) - their
build process was even more unstable than the rest in my environment.

PR:		241183

Approved by:	ports-secteam (joneum@)
2020-03-01 18:10:41 +00:00
Jan Beich
bbfffc9f42 MFH: r527425
emulators/citra: update to s20200229

Changes:	f106e7613...cd46e62ad
Approved by:	ports-secteam (swills, implicit for snapshots)
2020-02-29 15:54:56 +00:00
Matthias Fechner
b4013ae841 MFH: r527417
textproc/apache-solr: security related update to 8.4.1
Switch java version to current LTS version.

Security:	e59cb761-5ad8-11ea-abb7-001b217b3468

Approved by:	ports-secteam (joneum)
2020-02-29 14:48:12 +00:00
Jochen Neumeister
4f0db06072 MFH: r527391
Fix build on non-x86 and nun-aarch6

PR:		244073
Submitted by:	pkubaj
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (joneum)
2020-02-28 22:07:00 +00:00
Niclas Zeising
d9b554e4ec MFH: r527102
x11/xdm: Fix generation of etc/X11/xdm/Xresources

By some stupidity of autotools, spacing for a sed regexp used to generate
Xresources gets broken, and the sed command doen't match as it should.  This
results in an Xresources file with an extra '#endif /* XPM */', which breaks
the file.
Patch Makefile.in to fix the regexp and have Xresources generated properly.

PR:		244404
Reported by:	olgeni

Approved by:	ports-secteam (joenum)
2020-02-26 20:53:39 +00:00
Tijl Coosemans
c4b69fd407 MFH: r527000
Update to 2.16.5.

Security:	https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-advisory-2020-02
Approved by:	ports-secteam (joneum)
2020-02-25 10:00:08 +00:00
Dima Panov
8dfa9bdf81 MFH: r527012
mail/opensmtpd: update to 6.6.4p1 security releaase

SECURITY RELEASE

An out of bounds read in smtpd allows an attacker to inject arbitrary commands into the envelope file which are then executed as root. Separately, missing privilege revocation in smtpctl allows arbitrary commands to be run with the _smtpq group.

Approved by:	ports-secteam (joneum)
Security:	CVE-2020-8793, CVE-2020-8794
2020-02-25 03:22:59 +00:00
Dima Panov
5a3400175f MFH: r526973
net/freeradius-client: unbreak fetch, update to 1.1.7 release

Maintainer didn't unbreak the port over 3 months since it was marked unfetchable,
version 1.1.7 was released 26.05.2017

Approved by:	maintainer (timeout)

Approved by:	ports-secteam (joneum)
2020-02-25 03:20:58 +00:00