<feed xmlns='http://www.w3.org/2005/Atom'>
<title>pkgsrc, branch pkgsrc-2022Q1</title>
<subtitle>[no description]</subtitle>
<id>https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc-2022Q1</id>
<link rel='self' href='https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc-2022Q1'/>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/'/>
<updated>2022-06-13T16:14:00Z</updated>
<entry>
<title>Pullup ticket #6646</title>
<updated>2022-06-13T16:14:00Z</updated>
<author>
<name>bsiegert</name>
<email>bsiegert@pkgsrc.org</email>
</author>
<published>2022-06-13T16:14:00Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=37041fbe5bc56b90c2fd1e220ec41c44b4e1528b'/>
<id>urn:sha1:37041fbe5bc56b90c2fd1e220ec41c44b4e1528b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Pullup ticket #6646 - requested by nia</title>
<updated>2022-06-13T16:13:38Z</updated>
<author>
<name>bsiegert</name>
<email>bsiegert@pkgsrc.org</email>
</author>
<published>2022-06-13T16:13:38Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=e0a342e0e41726d477b264cba04ef2371f075b5e'/>
<id>urn:sha1:e0a342e0e41726d477b264cba04ef2371f075b5e</id>
<content type='text'>
graphics/gdk-pixbuf2: security fix

Revisions pulled up:
- graphics/gdk-pixbuf2/Makefile                                 1.53
- graphics/gdk-pixbuf2/PLIST                                    1.22
- graphics/gdk-pixbuf2/distinfo                                 1.51

---
   Module Name:	pkgsrc
   Committed By:	nia
   Date:		Sat Jun 11 12:46:06 UTC 2022

   Modified Files:
   	pkgsrc/graphics/gdk-pixbuf2: Makefile PLIST distinfo

   Log Message:
   gdk-pixbuf2: update to 2.42.8

   2.42.8 (stable)
   ===

   - Clear the pixbuf's memory buffer to avoid returning uninitialized memory
   - Turn GdkPixbufModule functions into typed callbacks
   - tiff: Use non-deprecated C99 integer types
   - gif: Check for overflow when compositing or clearing frames
   - Change png/jpeg/tiff build options from boolean to feature
   - jpeg: Do not rely on UB around setjmp/longjmp
   - Build fixes
   - Documentation fixes
   - Translation updates</content>
</entry>
<entry>
<title>Pullup tickets #6643 to #6645</title>
<updated>2022-06-11T10:42:24Z</updated>
<author>
<name>bsiegert</name>
<email>bsiegert@pkgsrc.org</email>
</author>
<published>2022-06-11T10:42:24Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=532d7a5351a8ef8fed7c8997f8ce91fdeb09f6a9'/>
<id>urn:sha1:532d7a5351a8ef8fed7c8997f8ce91fdeb09f6a9</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Pullup ticket #6645 - requested by taca</title>
<updated>2022-06-11T10:42:04Z</updated>
<author>
<name>bsiegert</name>
<email>bsiegert@pkgsrc.org</email>
</author>
<published>2022-06-11T10:42:04Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=b146404203131e729630ebcac37febfb614ac257'/>
<id>urn:sha1:b146404203131e729630ebcac37febfb614ac257</id>
<content type='text'>
www/apache24: security fix

Revisions pulled up:
- www/apache24/Makefile                                         1.111
- www/apache24/distinfo                                         1.53

---
   Module Name:	pkgsrc
   Committed By:	adam
   Date:		Thu Jun  9 18:15:51 UTC 2022

   Modified Files:
   	pkgsrc/www/apache24: Makefile distinfo

   Log Message:
   apache24: updated to 2.4.54

   Changes with Apache 2.4.54

   *) SECURITY: CVE-2022-31813: mod_proxy X-Forwarded-For dropped by
      hop-by-hop mechanism (cve.mitre.org)
      Apache HTTP Server 2.4.53 and earlier may not send the
      X-Forwarded-* headers to the origin server based on client side
      Connection header hop-by-hop mechanism.
      This may be used to bypass IP based authentication on the origin
      server/application.
      Credits: The Apache HTTP Server project would like to thank
      Gaetan Ferry (Synacktiv) for reporting this issue

   *) SECURITY: CVE-2022-30556: Information Disclosure in mod_lua with
      websockets (cve.mitre.org)
      Apache HTTP Server 2.4.53 and earlier may return lengths to
      applications calling r:wsread() that point past the end of the
      storage allocated for the buffer.
      Credits: The Apache HTTP Server project would like to thank
      Ronald Crane (Zippenhop LLC) for reporting this issue

   *) SECURITY: CVE-2022-30522: mod_sed denial of service
      (cve.mitre.org)
      If Apache HTTP Server 2.4.53 is configured to do transformations
      with mod_sed in contexts where the input to mod_sed may be very
      large, mod_sed may make excessively large memory allocations and
      trigger an abort.
      Credits: This issue was found by Brian Moussalli from the JFrog
      Security Research team

   *) SECURITY: CVE-2022-29404: Denial of service in mod_lua
      r:parsebody (cve.mitre.org)
      In Apache HTTP Server 2.4.53 and earlier, a malicious request to
      a lua script that calls r:parsebody(0) may cause a denial of
      service due to no default limit on possible input size.
      Credits: The Apache HTTP Server project would like to thank
      Ronald Crane (Zippenhop LLC) for reporting this issue

   *) SECURITY: CVE-2022-28615: Read beyond bounds in
      ap_strcmp_match() (cve.mitre.org)
      Apache HTTP Server 2.4.53 and earlier may crash or disclose
      information due to a read beyond bounds in ap_strcmp_match()
      when provided with an extremely large input buffer.  While no
      code distributed with the server can be coerced into such a
      call, third-party modules or lua scripts that use
      ap_strcmp_match() may hypothetically be affected.
      Credits: The Apache HTTP Server project would like to thank
      Ronald Crane (Zippenhop LLC) for reporting this issue

   *) SECURITY: CVE-2022-28614: read beyond bounds via ap_rwrite()
      (cve.mitre.org)
      The ap_rwrite() function in Apache HTTP Server 2.4.53 and
      earlier may read unintended memory if an attacker can cause the
      server to reflect very large input using ap_rwrite() or
      ap_rputs(), such as with mod_luas r:puts() function.
      Credits: The Apache HTTP Server project would like to thank
      Ronald Crane (Zippenhop LLC) for reporting this issue

   *) SECURITY: CVE-2022-28330: read beyond bounds in mod_isapi
      (cve.mitre.org)
      Apache HTTP Server 2.4.53 and earlier on Windows may read beyond
      bounds when configured to process requests with the mod_isapi
      module.
      Credits: The Apache HTTP Server project would like to thank
      Ronald Crane (Zippenhop LLC) for reporting this issue

   *) SECURITY: CVE-2022-26377: mod_proxy_ajp: Possible request
      smuggling (cve.mitre.org)
      Inconsistent Interpretation of HTTP Requests ('HTTP Request
      Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server
      allows an attacker to smuggle requests to the AJP server it
      forwards requests to.  This issue affects Apache HTTP Server
      Apache HTTP Server 2.4 version 2.4.53 and prior versions.
      Credits: Ricter Z @ 360 Noah Lab

   *) mod_ssl: SSLFIPS compatible with OpenSSL 3.0.

   *) mod_proxy_http: Avoid 417 responses for non forwardable 100-continue.

   *) mod_md:  a bug was fixed that caused very large MDomains
      with the combined DNS names exceeding ~7k to fail, as
      request bodies would contain partially wrong data from
      uninitialized memory. This would have appeared as failure
      in signing-up/renewing such configurations.

   *) mod_proxy_http: Avoid 417 responses for non forwardable 100-continue.

   *) MPM event: Restart children processes killed before idle maintenance.

   *) ab: Allow for TLSv1.3 when the SSL library supports it.

   *) core: Disable TCP_NOPUSH optimization on OSX since it might introduce
      transmission delays.

   *) MPM event: Fix accounting of active/total processes on ungraceful restart,

   *) core: make ap_escape_quotes() work correctly on strings
      with more than MAX_INT/2 characters, counting quotes double.
      Credit to &lt;generalbugs@zippenhop.com&gt; for finding this.

   *) mod_md: the `MDCertificateAuthority` directive can take more than one URL/name of
      an ACME CA. This gives a failover for renewals when several consecutive attempts
      to get a certificate failed.
      A new directive was added: `MDRetryDelay` sets the delay of retries.
      A new directive was added: `MDRetryFailover` sets the number of errored
      attempts before an alternate CA is selected for certificate renewals.

   *) mod_http2: remove unused and insecure code.

   *) mod_proxy: Add backend port to log messages to
      ease identification of involved service.

   *) mod_http2: removing unscheduling of ongoing tasks when
      connection shows potential abuse by a client. This proved
      counter-productive and the abuse detection can false flag
      requests using server-side-events.
      Fixes &lt;https://github.com/icing/mod_h2/issues/231&gt;.

   *) mod_md: Implement full auto status ("key: value" type status output).
      Especially not only status summary counts for certificates and
      OCSP stapling but also lists. Auto status format is similar to
      what was used for mod_proxy_balancer.

   *) mod_md: fixed a bug leading to failed transfers for OCSP
      stapling information when more than 6 certificates needed
      updates in the same run.

   *) mod_proxy: Set a status code of 502 in case the backend just closed the
      connection in reply to our forwarded request.

   *) mod_md: a possible NULL pointer deref was fixed in
      the JSON code for persisting time periods (start+end).
      Fixes #282 on mod_md's github.
      Thanks to @marcstern for finding this.

   *) mod_heartmonitor: Set the documented default value
      "10" for HeartbeatMaxServers instead of "0". With "0"
      no shared memory slotmem was initialized.

   *) mod_md: added support for managing certificates via a
      local tailscale daemon for users of that secure networking.
      This gives trusted certificates for tailscale assigned
      domain names in the *.ts.net space.</content>
</entry>
<entry>
<title>Pullup ticket #6644 - requested by taca</title>
<updated>2022-06-11T10:36:38Z</updated>
<author>
<name>bsiegert</name>
<email>bsiegert@pkgsrc.org</email>
</author>
<published>2022-06-11T10:36:38Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=6a3d128382cd9ff43e43a56b018faf19d4702159'/>
<id>urn:sha1:6a3d128382cd9ff43e43a56b018faf19d4702159</id>
<content type='text'>
www/ruby-rack: security fix

Revisions pulled up:
- www/ruby-rack/Makefile                                        1.30
- www/ruby-rack/distinfo                                        1.28

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat May 28 09:55:51 UTC 2022

   Modified Files:
   	pkgsrc/www/ruby-rack: Makefile distinfo

   Log Message:
   www/ruby-rack: update to 2.2.3.1

   2.2.3.1 (2022-05-27)

   * [CVE-2022-30123] Fix shell escaping issue in Common Logger
   * [CVE-2022-30122] Restrict parsing of broken MIME attachments</content>
</entry>
<entry>
<title>Pullup ticket #6643 - requested by taca</title>
<updated>2022-06-11T10:33:10Z</updated>
<author>
<name>bsiegert</name>
<email>bsiegert@pkgsrc.org</email>
</author>
<published>2022-06-11T10:33:10Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=aa6b8b4c68103df3157ba0059e49ee843d607d4b'/>
<id>urn:sha1:aa6b8b4c68103df3157ba0059e49ee843d607d4b</id>
<content type='text'>
security/clamav-doc: build fix after pullup #6625

Revisions pulled up:
- security/clamav-doc/Makefile                                  1.7
- security/clamav-doc/PLIST                                     1.9

---
   Module Name:	pkgsrc
   Committed By:	wiz
   Date:		Sun May 15 04:46:32 UTC 2022

   Modified Files:
   	pkgsrc/security/clamav-doc: Makefile PLIST

   Log Message:
   clamav-doc: fix PLIST

   Bump PKGREVISION.</content>
</entry>
<entry>
<title>Forgot to commit the changelog for my last batch of pullups</title>
<updated>2022-06-11T10:32:00Z</updated>
<author>
<name>bsiegert</name>
<email>bsiegert@pkgsrc.org</email>
</author>
<published>2022-06-11T10:32:00Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=4daad0fcb7a37360f450d7099c797bbe183df20f'/>
<id>urn:sha1:4daad0fcb7a37360f450d7099c797bbe183df20f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>tickets #6635 #6636 #6639 #6640 #6641 #6642</title>
<updated>2022-06-05T15:22:50Z</updated>
<author>
<name>spz</name>
<email>spz@pkgsrc.org</email>
</author>
<published>2022-06-05T15:22:50Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=5b469b563bb2cd4920ea9fadfb681d2b6a7982e8'/>
<id>urn:sha1:5b469b563bb2cd4920ea9fadfb681d2b6a7982e8</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Pullup ticket #6642 - requested by nia</title>
<updated>2022-06-05T13:25:24Z</updated>
<author>
<name>spz</name>
<email>spz@pkgsrc.org</email>
</author>
<published>2022-06-05T13:25:24Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=110f942d4716fa2824dd8b36a63b604a11cbae0e'/>
<id>urn:sha1:110f942d4716fa2824dd8b36a63b604a11cbae0e</id>
<content type='text'>
lang/gcc6: build fix

Revisions pulled up:
- lang/gcc6/Makefile                                            1.36

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	nia
   Date:		Sat May 21 12:21:44 UTC 2022

   Modified Files:
   	pkgsrc/lang/gcc6: Makefile

   Log Message:
   gcc6: workaround: get this at least building by disabling RELRO


   To generate a diff of this commit:
   cvs rdiff -u -r1.35 -r1.36 pkgsrc/lang/gcc6/Makefile</content>
</entry>
<entry>
<title>Pullup ticket #6641 - requested by nia</title>
<updated>2022-06-05T10:42:39Z</updated>
<author>
<name>spz</name>
<email>spz@pkgsrc.org</email>
</author>
<published>2022-06-05T10:42:39Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=6f8ca022083f48a390a68b9a4813775ade98ad26'/>
<id>urn:sha1:6f8ca022083f48a390a68b9a4813775ade98ad26</id>
<content type='text'>
databases/mariadb105-client: security update
databases/mariadb105-server: security update

Revisions pulled up:
- databases/mariadb105-client/Makefile.common                   1.16
- databases/mariadb105-client/distinfo                          1.13
- databases/mariadb105-client/patches/patch-CMakeLists.txt      1.2
- databases/mariadb105-server/Makefile                          1.25
- databases/mariadb105-server/PLIST                             1.10

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	nia
   Date:		Sat May 21 10:38:26 UTC 2022

   Modified Files:
   	pkgsrc/databases/mariadb105-client: Makefile.common distinfo
   	pkgsrc/databases/mariadb105-client/patches: patch-CMakeLists.txt
   	pkgsrc/databases/mariadb105-server: Makefile PLIST

   Log Message:
   mariadb105: Update to 10.5.16

                            MariaDB 10.5.16 Release Notes

   Notable Items

     InnoDB

        * innodb_disallow_writes removed (MDEV-25975)
        * InnoDB gap locking fixes (MDEV-20605, MDEV-28422)
        * InnoDB performance improvements (MDEV-27557, MDEV-28185)

     Replication

        * Server initialization time gtid_slave_pos purge related reason of
          crashing in binlog background thread is removed (MDEV-26473)
        * Shutdown of the semisync master can't produce inconsistent state
          anymore (MDEV-11853)
        * Binlogs disappear after rsync IST (MDEV-28583)
        * autocommit=0 slave hang is eliminated (DBAAS-7828)
        * master crash is eliminated in compressed semisync replication protocol
          with packet counting amendment (MDEV-25580)
        * OPTIMIZE on a sequence does not cause counterfactual
          ER_BINLOG_UNSAFE_STATEMENT anymore (MDEV-24617)
        * Automatically generated Gtid_log_list_event is made to recognize
          within replication event group as a formal member (MDEV-28550)
        * Replication unsafe INSERT .. ON DUPLICATE KEY UPDATE using two or more
          unique key values at a time with MIXED format binlogging is corrected
          (MDEV-28310)
        * Replication unsafe INSERT .. ON DUPLICATE KEY UPDATE stops issuing
          unnessary "Unsafe statement" with MIXED binlog format (MDEV-21810)
        * Incomplete replication event groups are detected to error out by the
          slave IO thread (MDEV-27697)
        * mysqlbinlog --stop-never --raw now flushes the result file to disk
          after each processed event so the file can be listed with the actual
          bytes (MDEV-14608)

     Backup

        * Incorrect binlogs after Galera SST using rsync and mariabackup
          (MDEV-27524)
        * mariabackup does not detect multi-source replication slave
          (MDEV-21037)
        * Useless warning "InnoDB: Allocated tablespace ID &lt;id&gt; for &lt;tablename&gt;,
          old maximum was 0" during backup stage (MDEV-27343)
        * mariabackup prepare fails for incrementals if a new schema is created
          after full backup is taken (MDEV-28446)

     Optimizer

        * A SEGV in Item_field::used_tables/update_depend_map_for_order...
          (MDEV-26402)
        * ANALYZE FORMAT=JSON fields are incorrect for UNION ALL queries
          (MDEV-27699)
        * Subquery in an UPDATE query uses full scan instead of range
          (MDEV-22377)
        * Assertion `item1-&gt;type() = Item::FIELD_ITEM ... (MDEV-19398)
        * Server crashes in Expression_cache_tracker::fetch_current_stats
          (MDEV-28268)
        * MariaDB server crash at Item_subselect::init_expr_cache_tracker
          (MDEV-26164, MDEV-26047)
        * Crash with union of my_decimal type in ORDER BY clause (MDEV-25994)
        * SIGSEGV in st_join_table::cleanup (MDEV-24560)
        * Assertion `!eliminated' failed in Item_subselect::exec (MDEV-28437)

     General

        * Server error messages are now available in Chinese (MDEV-28227)
        * For RHEL/CentOS 7, non x86_64 architectures are no longer supported
          upstream and so our support will also be dropped with this release

     Security

        * Fixes for the following security vulnerabilities:
             * CVE-2022-27376
             * CVE-2022-27377
             * CVE-2022-27378
             * CVE-2022-27379
             * CVE-2022-27380
             * CVE-2022-27381
             * CVE-2022-27382
             * CVE-2022-27383
             * CVE-2022-27384
             * CVE-2022-27386
             * CVE-2022-27387
             * CVE-2022-27444
             * CVE-2022-27445
             * CVE-2022-27446
             * CVE-2022-27447
             * CVE-2022-27448
             * CVE-2022-27449
             * CVE-2022-27451
             * CVE-2022-27452
             * CVE-2022-27455
             * CVE-2022-27456
             * CVE-2022-27457
             * CVE-2022-27458


   To generate a diff of this commit:
   cvs rdiff -u -r1.15 -r1.16 pkgsrc/databases/mariadb105-client/Makefile.common
   cvs rdiff -u -r1.12 -r1.13 pkgsrc/databases/mariadb105-client/distinfo
   cvs rdiff -u -r1.1 -r1.2 \
       pkgsrc/databases/mariadb105-client/patches/patch-CMakeLists.txt
   cvs rdiff -u -r1.24 -r1.25 pkgsrc/databases/mariadb105-server/Makefile
   cvs rdiff -u -r1.9 -r1.10 pkgsrc/databases/mariadb105-server/PLIST</content>
</entry>
</feed>
