summaryrefslogtreecommitdiff
path: root/net
AgeCommit message (Collapse)AuthorFilesLines
2021-11-24Pullup ticket #6537 - requested by tacatm3-10/+34
net/samba4: security fix Revisions pulled up: - net/samba4/Makefile 1.130-1.132 - net/samba4/PLIST 1.39-1.40 - net/samba4/distinfo 1.67,1.69 --- Module Name: pkgsrc Committed By: adam Date: Wed Sep 29 19:01:31 UTC 2021 Modified Files: pkgsrc/archivers/ark: Makefile pkgsrc/archivers/innoextract: Makefile pkgsrc/archivers/libcomprex: Makefile buildlink3.mk pkgsrc/archivers/libzip: Makefile buildlink3.mk pkgsrc/archivers/php-pecl-zip: Makefile pkgsrc/archivers/php-zip: Makefile pkgsrc/audio/ardour: Makefile pkgsrc/audio/ario: Makefile pkgsrc/audio/audacious-plugins: Makefile pkgsrc/audio/bmp-scrobbler: Makefile pkgsrc/audio/cmusfm: Makefile pkgsrc/audio/csound6: Makefile pkgsrc/audio/din: Makefile pkgsrc/audio/flactag: Makefile pkgsrc/audio/forked-daapd: Makefile pkgsrc/audio/gbemol: Makefile pkgsrc/audio/glyr: Makefile buildlink3.mk pkgsrc/audio/grip: Makefile pkgsrc/audio/herrie: Makefile pkgsrc/audio/hydrogen: Makefile pkgsrc/audio/icecast: Makefile pkgsrc/audio/jack-rack: Makefile pkgsrc/audio/libmusicbrainz: Makefile buildlink3.mk pkgsrc/audio/libmusicbrainz5: Makefile buildlink3.mk pkgsrc/audio/libofa: Makefile pkgsrc/audio/mad123: Makefile pkgsrc/audio/moc: Makefile pkgsrc/audio/mp3diags: Makefile pkgsrc/audio/mpdas: Makefile pkgsrc/audio/musicpd: Makefile pkgsrc/audio/ncmpcpp: Makefile pkgsrc/audio/pianobar: Makefile pkgsrc/audio/pragha: Makefile pkgsrc/audio/qmmp: Makefile pkgsrc/audio/sound-juicer: Makefile pkgsrc/audio/strawberry: Makefile pkgsrc/audio/streamtuner: Makefile buildlink3.mk pkgsrc/audio/terminatorx: Makefile pkgsrc/audio/tremor-tools: Makefile pkgsrc/audio/vimpc: Makefile pkgsrc/audio/vorbis-tools: Makefile pkgsrc/biology/canu: Makefile pkgsrc/biology/coordgenlibs: Makefile buildlink3.mk pkgsrc/biology/htslib: Makefile pkgsrc/biology/maeparser: Makefile buildlink3.mk pkgsrc/biology/ncbi-blast+: Makefile pkgsrc/biology/openbabel: Makefile pkgsrc/cad/kicad: Makefile pkgsrc/cad/librecad: Makefile pkgsrc/cad/openscad: Makefile pkgsrc/chat/anope: Makefile pkgsrc/chat/bitlbee: Makefile pkgsrc/chat/centerim: Makefile pkgsrc/chat/ctrlproxy: Makefile pkgsrc/chat/ekg: Makefile pkgsrc/chat/farstream: Makefile pkgsrc/chat/gloox: Makefile pkgsrc/chat/ircd-hybrid: Makefile pkgsrc/chat/konversation: Makefile pkgsrc/chat/ktp-accounts-kcm: Makefile pkgsrc/chat/ktp-approver: Makefile pkgsrc/chat/ktp-auth-handler: Makefile pkgsrc/chat/ktp-common-internals: Makefile buildlink3.mk pkgsrc/chat/ktp-contact-list: Makefile pkgsrc/chat/ktp-contact-runner: Makefile pkgsrc/chat/ktp-desktop-applets: Makefile pkgsrc/chat/ktp-filetransfer-handler: Makefile pkgsrc/chat/ktp-kded-integration-module: Makefile pkgsrc/chat/ktp-send-file: Makefile pkgsrc/chat/ktp-text-ui: Makefile pkgsrc/chat/libgadu: Makefile buildlink3.mk pkgsrc/chat/libpurple: Makefile pkgsrc/chat/mumble: Makefile pkgsrc/chat/profanity: Makefile pkgsrc/chat/scrollz: Makefile pkgsrc/chat/spectrum: Makefile pkgsrc/chat/swift: Makefile pkgsrc/chat/telepathy-gabble: Makefile pkgsrc/chat/unrealircd: Makefile pkgsrc/chat/weechat: Makefile pkgsrc/chat/znc: Makefile pkgsrc/comms/asterisk13: Makefile pkgsrc/comms/asterisk16: Makefile pkgsrc/comms/asterisk18: Makefile pkgsrc/comms/gammu: Makefile pkgsrc/converters/libabw: Makefile buildlink3.mk pkgsrc/converters/libcdr: Makefile buildlink3.mk pkgsrc/converters/libe-book: Makefile buildlink3.mk pkgsrc/converters/libepubgen: Makefile buildlink3.mk pkgsrc/converters/libetonyek: Makefile buildlink3.mk pkgsrc/converters/libfreehand: Makefile buildlink3.mk pkgsrc/converters/libmspub: Makefile buildlink3.mk pkgsrc/converters/libmwaw: Makefile buildlink3.mk pkgsrc/converters/libpagemaker: Makefile buildlink3.mk pkgsrc/converters/libqxp: Makefile buildlink3.mk pkgsrc/converters/librevenge: Makefile buildlink3.mk pkgsrc/converters/libstaroffice: Makefile pkgsrc/converters/libvisio: Makefile buildlink3.mk pkgsrc/converters/libwpd: Makefile buildlink3.mk pkgsrc/converters/libwpg: Makefile buildlink3.mk pkgsrc/converters/libwps: Makefile buildlink3.mk pkgsrc/converters/libzmf: Makefile pkgsrc/converters/orcus: Makefile pkgsrc/converters/rss2html: Makefile pkgsrc/databases/couchdb: Makefile pkgsrc/databases/freetds: Makefile buildlink3.mk pkgsrc/databases/libcassandra: Makefile pkgsrc/databases/mariadb104-client: Makefile pkgsrc/databases/mariadb104-server: Makefile pkgsrc/databases/mariadb105-client: Makefile pkgsrc/databases/mariadb105-server: Makefile pkgsrc/databases/mariadb106-client: Makefile pkgsrc/databases/mariadb106-server: Makefile pkgsrc/databases/mongodb: Makefile pkgsrc/databases/mongodb3: Makefile pkgsrc/databases/mysql-workbench: Makefile pkgsrc/databases/mysql57-client: Makefile pkgsrc/databases/mysql57-server: Makefile pkgsrc/databases/p5-DBD-Sybase: Makefile pkgsrc/databases/p5-sqlrelay: Makefile pkgsrc/databases/p5-sybperl: Makefile pkgsrc/databases/php-mssql: Makefile pkgsrc/databases/php-pdo_dblib: Makefile pkgsrc/databases/php-sqlrelay: Makefile pkgsrc/databases/postgresql-postgis2: Makefile pkgsrc/databases/py-mssql: Makefile pkgsrc/databases/py-sqlrelay: Makefile pkgsrc/databases/py-sybase: Makefile pkgsrc/databases/qore-freetds-module: Makefile pkgsrc/databases/ruby-sqlrelay: Makefile pkgsrc/databases/ruby-tiny_tds: Makefile pkgsrc/databases/soci: Makefile pkgsrc/databases/sqlrelay: Makefile buildlink3.mk pkgsrc/databases/sqlrelay-freetds: Makefile pkgsrc/databases/sqlrelay-mysql: Makefile pkgsrc/databases/sqlrelay-nodejs: Makefile pkgsrc/databases/sqlrelay-odbc: Makefile pkgsrc/databases/sqlrelay-pgsql: Makefile pkgsrc/databases/sqlrelay-sqlite: Makefile pkgsrc/databases/sqsh: Makefile pkgsrc/databases/virtuoso: Makefile pkgsrc/devel/aegis: Makefile pkgsrc/devel/cfitsio: Makefile pkgsrc/devel/cmake: Makefile pkgsrc/devel/cmake-gui: Makefile pkgsrc/devel/darcs: Makefile pkgsrc/devel/ecore: Makefile buildlink3.mk pkgsrc/devel/eio: Makefile buildlink3.mk pkgsrc/devel/exempi: Makefile pkgsrc/devel/fifengine: Makefile pkgsrc/devel/gearmand: Makefile buildlink3.mk pkgsrc/devel/git-base: Makefile pkgsrc/devel/gnustep-base: Makefile pkgsrc/devel/kdesdk-kioslaves: Makefile pkgsrc/devel/kdesdk-strigi-analyzers: Makefile pkgsrc/devel/kdesdk-thumbnailers: Makefile pkgsrc/devel/kdevelop4: Makefile pkgsrc/devel/kdevplatform: Makefile pkgsrc/devel/kio-extras: Makefile pkgsrc/devel/libcutl: Makefile pkgsrc/devel/libftdi1: Makefile pkgsrc/devel/libgit2: Makefile pkgsrc/devel/libkgapi: Makefile pkgsrc/devel/librelp: Makefile buildlink3.mk pkgsrc/devel/libthrift: Makefile pkgsrc/devel/libxenserver: Makefile buildlink3.mk pkgsrc/devel/mad-flute: Makefile pkgsrc/devel/mdds: Makefile pkgsrc/devel/mdds1.2: Makefile pkgsrc/devel/netcdf: Makefile buildlink3.mk pkgsrc/devel/netcdf-cxx: Makefile buildlink3.mk pkgsrc/devel/netcdf-fortran: Makefile buildlink3.mk pkgsrc/devel/okteta: Makefile pkgsrc/devel/php-gearman: Makefile pkgsrc/devel/radare2: Makefile buildlink3.mk pkgsrc/devel/radare2-cutter: Makefile pkgsrc/devel/rudiments: Makefile buildlink3.mk pkgsrc/devel/sdcc3: Makefile pkgsrc/devel/ucommon: Makefile buildlink3.mk pkgsrc/devel/vera++: Makefile pkgsrc/editors/Sigil: Makefile pkgsrc/editors/TeXmacs: Makefile pkgsrc/editors/abiword: Makefile buildlink3.mk pkgsrc/editors/abiword-plugins: Makefile pkgsrc/editors/codelite: Makefile pkgsrc/editors/emacs25: Makefile pkgsrc/editors/emacs26: Makefile pkgsrc/editors/emacs27: Makefile pkgsrc/editors/gobby: Makefile pkgsrc/editors/lyx: Makefile pkgsrc/editors/obby: Makefile buildlink3.mk pkgsrc/editors/poedit: Makefile pkgsrc/editors/xournalpp: Makefile pkgsrc/emulators/cannonball: Makefile pkgsrc/emulators/ckmame: Makefile pkgsrc/emulators/dolphin-emu: Makefile pkgsrc/emulators/emulationstation: Makefile pkgsrc/emulators/libretro-dolphin: Makefile pkgsrc/emulators/mgba: Makefile pkgsrc/emulators/qemu: Makefile pkgsrc/emulators/wine: Makefile pkgsrc/filesystems/cloudfuse: Makefile pkgsrc/filesystems/fuse-curlftpfs: Makefile pkgsrc/filesystems/fuse-wdfs: Makefile pkgsrc/finance/QuantLib: Makefile pkgsrc/finance/bitcoin: Makefile pkgsrc/finance/cpuminer: Makefile pkgsrc/finance/gnucash: Makefile pkgsrc/finance/ledger: Makefile pkgsrc/finance/libofx: Makefile pkgsrc/fonts/ghostscript-cidfonts-ryumin: Makefile pkgsrc/games/7kaa: Makefile pkgsrc/games/amor: Makefile pkgsrc/games/asc: Makefile pkgsrc/games/assaultcube: Makefile pkgsrc/games/bastet: Makefile pkgsrc/games/bzflag: Makefile pkgsrc/games/criticalmass: Makefile pkgsrc/games/crossfire-client: Makefile pkgsrc/games/crossfire-server: Makefile pkgsrc/games/dhewm3: Makefile pkgsrc/games/dopewars: Makefile pkgsrc/games/enigma: Makefile pkgsrc/games/etlegacy: Makefile pkgsrc/games/etlegacy-server: Makefile pkgsrc/games/flightgear: Makefile pkgsrc/games/freeciv-client: Makefile pkgsrc/games/freeciv-server: Makefile pkgsrc/games/freeciv-share: Makefile pkgsrc/games/ggz-client-libs: Makefile buildlink3.mk pkgsrc/games/holtz: Makefile pkgsrc/games/ioquake3: Makefile pkgsrc/games/iortcw: Makefile pkgsrc/games/klavaro: Makefile pkgsrc/games/lgogdownloader: Makefile pkgsrc/games/libggz: Makefile buildlink3.mk pkgsrc/games/manaplus: Makefile pkgsrc/games/megaglest: Makefile pkgsrc/games/minetest: Makefile pkgsrc/games/naev: Makefile pkgsrc/games/openmw: Makefile pkgsrc/games/openrct2: Makefile pkgsrc/games/pingus: Makefile pkgsrc/games/powder-toy: Makefile pkgsrc/games/quakeforge: Makefile pkgsrc/games/scummvm: Makefile pkgsrc/games/scummvm-tools: Makefile pkgsrc/games/simgear: Makefile buildlink3.mk pkgsrc/games/supertux: Makefile pkgsrc/games/supertuxkart: Makefile pkgsrc/games/taisei: Makefile pkgsrc/games/ufoai: Makefile pkgsrc/games/violetland: Makefile pkgsrc/games/warmux: Makefile pkgsrc/games/warzone2100: Makefile pkgsrc/games/wesnoth: Makefile pkgsrc/games/widelands: Makefile pkgsrc/games/yquake2: Makefile pkgsrc/geography/R-rgdal: Makefile pkgsrc/geography/R-sf: Makefile pkgsrc/geography/gdal-lib: Makefile buildlink3.mk pkgsrc/geography/mapserver: Makefile pkgsrc/geography/merkaartor: Makefile pkgsrc/geography/opencpn: Makefile pkgsrc/geography/osm2pgsql: Makefile pkgsrc/geography/pdal-lib: Makefile buildlink3.mk pkgsrc/geography/py-gdal: Makefile pkgsrc/geography/qgis: Makefile pkgsrc/geography/qlandkartegt: Makefile pkgsrc/geography/qlandkartem: Makefile pkgsrc/geography/viking: Makefile pkgsrc/graphics/GMT: Makefile pkgsrc/graphics/GraphicsMagick: Makefile buildlink3.mk pkgsrc/graphics/ImageMagick: Makefile buildlink3.mk pkgsrc/graphics/ImageMagick6: Makefile buildlink3.mk pkgsrc/graphics/aqsis: Makefile pkgsrc/graphics/autotrace: Makefile pkgsrc/graphics/blender: Makefile pkgsrc/graphics/blender-lts: Makefile pkgsrc/graphics/camlimages: Makefile pkgsrc/graphics/darktable: Makefile pkgsrc/graphics/digikam: Makefile pkgsrc/graphics/drawpile: Makefile pkgsrc/graphics/dx: Makefile pkgsrc/graphics/edje: Makefile buildlink3.mk pkgsrc/graphics/enblend-enfuse: Makefile pkgsrc/graphics/feh: Makefile pkgsrc/graphics/gimmage: Makefile pkgsrc/graphics/gmic: Makefile pkgsrc/graphics/gource: Makefile pkgsrc/graphics/gpick: Makefile pkgsrc/graphics/graphviz: Makefile pkgsrc/graphics/gri: Makefile pkgsrc/graphics/hugin: Makefile pkgsrc/graphics/jp2a: Makefile pkgsrc/graphics/kde-base-artwork: Makefile pkgsrc/graphics/kdegraphics-strigi-analyzer: Makefile pkgsrc/graphics/kgamma: Makefile pkgsrc/graphics/koverartist: Makefile pkgsrc/graphics/kqtquickcharts4: Makefile pkgsrc/graphics/krita: Makefile pkgsrc/graphics/libgltf: Makefile pkgsrc/graphics/libkexiv2-kde4: Makefile pkgsrc/graphics/libsixel: Makefile pkgsrc/graphics/lsix: Makefile pkgsrc/graphics/luminance-hdr: Makefile pkgsrc/graphics/ncview: Makefile pkgsrc/graphics/openimageio: Makefile buildlink3.mk pkgsrc/graphics/osg: Makefile buildlink3.mk pkgsrc/graphics/p5-GraphicsMagick: Makefile pkgsrc/graphics/p5-PerlMagick: Makefile pkgsrc/graphics/pcl: Makefile buildlink3.mk pkgsrc/graphics/pfstools: Makefile pkgsrc/graphics/php-imagick: Makefile pkgsrc/graphics/pstoedit: Makefile pkgsrc/graphics/ruby-RMagick: Makefile pkgsrc/graphics/sane-airscan: Makefile pkgsrc/graphics/shotwell: Makefile pkgsrc/graphics/tango-icon-theme: Makefile pkgsrc/graphics/vtk: Makefile buildlink3.mk pkgsrc/graphics/zbar: Makefile pkgsrc/graphics/zphoto: Makefile pkgsrc/ham/fldigi: Makefile pkgsrc/ham/gnuradio-channels: Makefile pkgsrc/ham/gnuradio-companion: Makefile pkgsrc/ham/gnuradio-core: Makefile pkgsrc/ham/gnuradio-ctrlport: Makefile pkgsrc/ham/gnuradio-digital: Makefile pkgsrc/ham/gnuradio-doxygen: Makefile pkgsrc/ham/gnuradio-dtv: Makefile pkgsrc/ham/gnuradio-fec: Makefile pkgsrc/ham/gnuradio-network: Makefile pkgsrc/ham/gnuradio-qtgui: Makefile pkgsrc/ham/gnuradio-soapy-sdr: Makefile pkgsrc/ham/gnuradio-trellis: Makefile pkgsrc/ham/gnuradio-uhd: Makefile pkgsrc/ham/gnuradio-utils: Makefile pkgsrc/ham/gnuradio-video-sdl: Makefile pkgsrc/ham/gnuradio-vocoder: Makefile pkgsrc/ham/gnuradio-wavelet: Makefile pkgsrc/ham/gnuradio-zeromq: Makefile pkgsrc/ham/gpredict: Makefile pkgsrc/ham/gr-fcdproplus: Makefile pkgsrc/ham/gr-osmosdr: Makefile pkgsrc/ham/trustedQSL: Makefile pkgsrc/ham/uhd: Makefile pkgsrc/inputmethod/fcitx5-chinese-addons: Makefile pkgsrc/inputmethod/fcitx5-mozc: Makefile pkgsrc/inputmethod/fcitx5-table-extra: Makefile pkgsrc/inputmethod/fcitx5-table-other: Makefile pkgsrc/inputmethod/ibus-mozc: Makefile pkgsrc/inputmethod/libime: Makefile pkgsrc/inputmethod/librime: Makefile pkgsrc/inputmethod/mozc-elisp: Makefile pkgsrc/inputmethod/mozc-renderer: Makefile pkgsrc/inputmethod/mozc-server: Makefile pkgsrc/inputmethod/mozc-tool: Makefile pkgsrc/inputmethod/uim-mozc: Makefile pkgsrc/lang/konoha: Makefile pkgsrc/lang/nodejs10: Makefile buildlink3.mk pkgsrc/lang/nodejs12: Makefile buildlink3.mk pkgsrc/lang/openjdk11: Makefile pkgsrc/lang/openjdk8: Makefile pkgsrc/lang/rust: Makefile pkgsrc/mail/akonadi: Makefile pkgsrc/mail/balsa: Makefile pkgsrc/mail/claws-mail: Makefile pkgsrc/mail/claws-mail-archive: Makefile pkgsrc/mail/claws-mail-attachwarner: Makefile pkgsrc/mail/claws-mail-attremover: Makefile pkgsrc/mail/claws-mail-bogofilter: Makefile pkgsrc/mail/claws-mail-dillo: Makefile pkgsrc/mail/claws-mail-fetchinfo: Makefile pkgsrc/mail/claws-mail-libravatar: Makefile pkgsrc/mail/claws-mail-mailmbox: Makefile pkgsrc/mail/claws-mail-managesieve: Makefile pkgsrc/mail/claws-mail-newmail: Makefile pkgsrc/mail/claws-mail-notification: Makefile pkgsrc/mail/claws-mail-pgpcore: Makefile pkgsrc/mail/claws-mail-pgpinline: Makefile pkgsrc/mail/claws-mail-pgpmime: Makefile pkgsrc/mail/claws-mail-rssyl: Makefile pkgsrc/mail/claws-mail-smime: Makefile pkgsrc/mail/claws-mail-spamassassin: Makefile pkgsrc/mail/claws-mail-spamreport: Makefile pkgsrc/mail/claws-mail-tnef: Makefile pkgsrc/mail/claws-mail-vcalendar: Makefile pkgsrc/mail/cone: Makefile pkgsrc/mail/evolution-data-server: Makefile pkgsrc/mail/libetpan: Makefile buildlink3.mk pkgsrc/mail/mailfront: Makefile pkgsrc/mail/milter-greylist: Makefile pkgsrc/mail/mpop: Makefile pkgsrc/mail/msmtp: Makefile pkgsrc/mail/mutt: Makefile pkgsrc/mail/nmh: Makefile pkgsrc/mail/nullmailer: Makefile pkgsrc/mail/wmbiff: Makefile pkgsrc/mail/xfce4-mailwatch-plugin: Makefile pkgsrc/math/R: Makefile pkgsrc/math/R-CGIwithR: Makefile pkgsrc/math/R-RNetCDF: Makefile pkgsrc/math/R-ncdf: Makefile pkgsrc/math/R-ncdf4: Makefile pkgsrc/math/cantor: Makefile pkgsrc/math/cgal: Makefile buildlink3.mk pkgsrc/math/grace: Makefile pkgsrc/math/libixion: Makefile pkgsrc/math/octave: Makefile pkgsrc/math/py-Scientific: Makefile pkgsrc/math/py-libixion: Makefile pkgsrc/math/py-netCDF4: Makefile pkgsrc/math/qalculate: Makefile buildlink3.mk pkgsrc/math/qalculate-gtk: Makefile pkgsrc/math/sc-im: Makefile pkgsrc/math/volk: Makefile pkgsrc/math/vowpal_wabbit: Makefile pkgsrc/math/xmgr: Makefile pkgsrc/misc/bibletime: Makefile pkgsrc/misc/esniper: Makefile pkgsrc/misc/fbreader: Makefile pkgsrc/misc/gwaei: Makefile pkgsrc/misc/kaccessible: Makefile pkgsrc/misc/kchmviewer: Makefile pkgsrc/misc/kde-wallpapers4: Makefile pkgsrc/misc/kdeartwork4: Makefile pkgsrc/misc/kdepim-runtime4: Makefile pkgsrc/misc/kdepim4: Makefile pkgsrc/misc/kdepimlibs4: Makefile buildlink3.mk pkgsrc/misc/kdeplasma-addons4: Makefile pkgsrc/misc/kremotecontrol: Makefile pkgsrc/misc/kstars: Makefile pkgsrc/misc/ktux: Makefile pkgsrc/misc/libcarddav: Makefile pkgsrc/misc/libkdeedu: Makefile buildlink3.mk pkgsrc/misc/libreoffice: Makefile pkgsrc/misc/ocaml-opam: Makefile pkgsrc/misc/parley: Makefile pkgsrc/misc/rocs: Makefile pkgsrc/misc/step: Makefile pkgsrc/misc/superkaramba: Makefile pkgsrc/misc/sweeper: Makefile pkgsrc/misc/sword: Makefile buildlink3.mk pkgsrc/misc/usbprog: Makefile pkgsrc/misc/wandio: Makefile buildlink3.mk pkgsrc/multimedia/audiocd-kio: Makefile pkgsrc/multimedia/dvdauthor: Makefile pkgsrc/multimedia/ffmpeg2: Makefile pkgsrc/multimedia/ffmpeg3: Makefile pkgsrc/multimedia/ffmpeg4: Makefile pkgsrc/multimedia/ffmpegthumbs: Makefile pkgsrc/multimedia/gnome-mplayer: Makefile pkgsrc/multimedia/gpac: Makefile pkgsrc/multimedia/kscd: Makefile pkgsrc/multimedia/libkcddb: Makefile buildlink3.mk pkgsrc/multimedia/lightspark: Makefile pkgsrc/multimedia/mediatomb: Makefile pkgsrc/multimedia/mkvtoolnix: Makefile pkgsrc/multimedia/mkvtoolnix-old: Makefile pkgsrc/multimedia/mplayerthumbs: Makefile pkgsrc/multimedia/nostt: Makefile pkgsrc/multimedia/obs-studio: Makefile pkgsrc/multimedia/omxplayer: Makefile pkgsrc/multimedia/totem: Makefile pkgsrc/multimedia/transcode: Makefile pkgsrc/multimedia/vlc: Makefile pkgsrc/multimedia/xine-lib: Makefile pkgsrc/multimedia/xine-ui: Makefile pkgsrc/net/aiccu: Makefile pkgsrc/net/bbk_cli: Makefile pkgsrc/net/btget: Makefile pkgsrc/net/cclive: Makefile pkgsrc/net/ccrtp: Makefile buildlink3.mk pkgsrc/net/choqok: Makefile pkgsrc/net/chrony: Makefile pkgsrc/net/dc_gui2: Makefile pkgsrc/net/deforaos-vncviewer: Makefile pkgsrc/net/doh: Makefile pkgsrc/net/ettercap: Makefile pkgsrc/net/ettercap-gtk: Makefile pkgsrc/net/filezilla: Makefile pkgsrc/net/flickcurl: Makefile pkgsrc/net/freeDiameter: Makefile pkgsrc/net/freeradius-freetds: Makefile pkgsrc/net/freeradius-rest: Makefile pkgsrc/net/glib-networking: Makefile pkgsrc/net/grilo: Makefile buildlink3.mk pkgsrc/net/grilo-plugins: Makefile pkgsrc/net/grive2: Makefile pkgsrc/net/gst-plugins0.10-rtmp: Makefile pkgsrc/net/gst-plugins1-rtmp: Makefile pkgsrc/net/gtk-gnutella: Makefile pkgsrc/net/gtk-vnc: Makefile buildlink3.mk pkgsrc/net/guacamole-server: Makefile pkgsrc/net/icinga2: Makefile pkgsrc/net/jigdo: Makefile pkgsrc/net/kdenetwork-filesharing: Makefile pkgsrc/net/kdenetwork-strigi-analyzers: Makefile pkgsrc/net/kget: Makefile pkgsrc/net/kmldonkey: Makefile pkgsrc/net/knot: Makefile pkgsrc/net/kopete: Makefile pkgsrc/net/kppp: Makefile pkgsrc/net/krdc: Makefile pkgsrc/net/krfb: Makefile pkgsrc/net/ktorrent: Makefile pkgsrc/net/lftp: Makefile pkgsrc/net/libcmis: Makefile pkgsrc/net/libfilezilla: Makefile pkgsrc/net/libgdata: Makefile buildlink3.mk pkgsrc/net/libktorrent: Makefile buildlink3.mk pkgsrc/net/libquvi: Makefile pkgsrc/net/libtorrent-rasterbar: Makefile buildlink3.mk pkgsrc/net/libtrace: Makefile pkgsrc/net/libvncserver: Makefile buildlink3.mk pkgsrc/net/libzrtpcpp: Makefile buildlink3.mk pkgsrc/net/megatools: Makefile pkgsrc/net/nanotodon: Makefile pkgsrc/net/ncdc: Makefile pkgsrc/net/net6: Makefile buildlink3.mk pkgsrc/net/netatalk22: Makefile pkgsrc/net/netatalk3: Makefile pkgsrc/net/ntopng: Makefile pkgsrc/net/ocamlnet: Makefile pkgsrc/net/ocsync: Makefile buildlink3.mk pkgsrc/net/openvpn: Makefile pkgsrc/net/podcastdl: Makefile pkgsrc/net/powerdns: Makefile pkgsrc/net/py-smbc: Makefile pkgsrc/net/qbittorrent: Makefile pkgsrc/net/quvi: Makefile pkgsrc/net/rdesktop: Makefile pkgsrc/net/remmina: Makefile pkgsrc/net/rtmpdump: Makefile buildlink3.mk pkgsrc/net/rtorrent: Makefile pkgsrc/net/samba: Makefile pkgsrc/net/samba4: Makefile buildlink3.mk pkgsrc/net/snort: Makefile pkgsrc/net/synergy: Makefile pkgsrc/net/taskserver: Makefile pkgsrc/net/tcpflow: Makefile pkgsrc/net/tigervnc: Makefile pkgsrc/net/transmission: Makefile pkgsrc/net/transmission-gtk: Makefile pkgsrc/net/transmission-qt: Makefile pkgsrc/net/unbound: Makefile buildlink3.mk pkgsrc/net/urlgfe: Makefile pkgsrc/net/vinagre: Makefile pkgsrc/net/vino: Makefile pkgsrc/net/wget: Makefile pkgsrc/net/wireshark: Makefile pkgsrc/net/wmget: Makefile pkgsrc/net/zeroconf-ioslave: Makefile pkgsrc/news/neix: Makefile pkgsrc/news/newsbeuter: Makefile pkgsrc/news/pan: Makefile pkgsrc/parallel/slurm-wlm: Makefile pkgsrc/print/auctex: Makefile pkgsrc/print/brlaser: Makefile pkgsrc/print/cups: Makefile pkgsrc/print/cups-base: Makefile buildlink3.mk pkgsrc/print/cups-drivers-Magicolor5440DL: Makefile pkgsrc/print/cups-filters: Makefile buildlink3.mk pkgsrc/print/cups-pdf: Makefile pkgsrc/print/dspdfviewer: Makefile pkgsrc/print/epdfview: Makefile pkgsrc/print/ghostscript: Makefile buildlink3.mk pkgsrc/print/ghostscript-gpl: Makefile buildlink3.mk pkgsrc/print/gtklp: Makefile pkgsrc/print/gutenprint-lib: Makefile pkgsrc/print/hplip: Makefile pkgsrc/print/libcups: Makefile buildlink3.mk pkgsrc/print/mupdf: Makefile buildlink3.mk pkgsrc/print/okular: Makefile pkgsrc/print/p5-Net-CUPS: Makefile pkgsrc/print/pdf2djvu: Makefile pkgsrc/print/py-cups: Makefile pkgsrc/print/qpdfview: Makefile pkgsrc/print/scribus-qt4: Makefile pkgsrc/print/scribus-qt5: Makefile pkgsrc/print/xpdf4: Makefile pkgsrc/print/xpp: Makefile pkgsrc/print/zathura-pdf-mupdf: Makefile pkgsrc/security/ap-modsecurity2: Makefile pkgsrc/security/botan-devel: Makefile buildlink3.mk pkgsrc/security/clamav: Makefile pkgsrc/security/dirb: Makefile pkgsrc/security/gnupg: Makefile pkgsrc/security/gnupg-pkcs11-scd: Makefile pkgsrc/security/gnupg2: Makefile pkgsrc/security/gnutls: Makefile buildlink3.mk pkgsrc/security/gsasl: Makefile pkgsrc/security/kgpg: Makefile pkgsrc/security/lastpass-cli: Makefile pkgsrc/security/libfprint: Makefile pkgsrc/security/liboauth: Makefile buildlink3.mk pkgsrc/security/libprelude: Makefile buildlink3.mk pkgsrc/security/libprelude-lua: Makefile pkgsrc/security/libprelude-perl: Makefile pkgsrc/security/libprelude-python: Makefile pkgsrc/security/libpreludedb: Makefile buildlink3.mk pkgsrc/security/libpreludedb-mysql: Makefile pkgsrc/security/libpreludedb-perl: Makefile pkgsrc/security/libpreludedb-pgsql: Makefile pkgsrc/security/libpreludedb-python: Makefile pkgsrc/security/libpreludedb-sqlite3: Makefile pkgsrc/security/libykneomgr: Makefile pkgsrc/security/opendnssec2: Makefile pkgsrc/security/opensaml: Makefile pkgsrc/security/openvas-libnasl: Makefile pkgsrc/security/openvas-libraries: Makefile pkgsrc/security/openvas-plugins: Makefile pkgsrc/security/openvas-server: Makefile pkgsrc/security/pam-yubico: Makefile pkgsrc/security/php-oauth: Makefile pkgsrc/security/php-oauth1: Makefile pkgsrc/security/pkcs11-helper: Makefile buildlink3.mk pkgsrc/security/prelude-lml: Makefile pkgsrc/security/prelude-manager: Makefile pkgsrc/security/prelude-pflogger: Makefile pkgsrc/security/rvault: Makefile pkgsrc/security/softhsm2: Makefile buildlink3.mk pkgsrc/security/ykclient: Makefile buildlink3.mk pkgsrc/sysutils/baloo: Makefile pkgsrc/sysutils/cfengine3: Makefile pkgsrc/sysutils/collectd-curl: Makefile pkgsrc/sysutils/collectd-riemann: Makefile pkgsrc/sysutils/collectd-virt: Makefile pkgsrc/sysutils/collectd-write_prometheus: Makefile pkgsrc/sysutils/conky: Makefile pkgsrc/sysutils/edbus: Makefile buildlink3.mk pkgsrc/sysutils/efreet: Makefile buildlink3.mk pkgsrc/sysutils/gkrellm: Makefile pkgsrc/sysutils/gnome-control-center: Makefile pkgsrc/sysutils/gnome-settings-daemon: Makefile pkgsrc/sysutils/gvfs: Makefile pkgsrc/sysutils/k3b: Makefile pkgsrc/sysutils/kcron: Makefile pkgsrc/sysutils/kfilemetadata: Makefile pkgsrc/sysutils/kfilemetadata5: Makefile pkgsrc/sysutils/kuser: Makefile pkgsrc/sysutils/libbaloo4: Makefile pkgsrc/sysutils/mc: Makefile pkgsrc/sysutils/openxenmanager: Makefile pkgsrc/sysutils/riemann-client: Makefile buildlink3.mk pkgsrc/sysutils/rsyslog: Makefile pkgsrc/sysutils/rsyslog-dbi: Makefile pkgsrc/sysutils/rsyslog-elasticsearch: Makefile pkgsrc/sysutils/rsyslog-gnutls: Makefile pkgsrc/sysutils/rsyslog-gssapi: Makefile pkgsrc/sysutils/rsyslog-kafka: Makefile pkgsrc/sysutils/rsyslog-libgcrypt: Makefile pkgsrc/sysutils/rsyslog-mysql: Makefile pkgsrc/sysutils/rsyslog-omprog: Makefile pkgsrc/sysutils/rsyslog-pgsql: Makefile pkgsrc/sysutils/rsyslog-rabbitmq: Makefile pkgsrc/sysutils/rsyslog-relp: Makefile pkgsrc/sysutils/rsyslog-snmp: Makefile pkgsrc/sysutils/strigi: Makefile buildlink3.mk pkgsrc/sysutils/syslog-ng-curl: Makefile pkgsrc/sysutils/virt-viewer: Makefile pkgsrc/sysutils/zabbix: Makefile pkgsrc/sysutils/zabbix50-agent: Makefile pkgsrc/sysutils/zabbix50-proxy: Makefile pkgsrc/sysutils/zabbix50-server: Makefile pkgsrc/textproc/FlightCrew: Makefile pkgsrc/textproc/dikt: Makefile pkgsrc/textproc/ebook-tools: Makefile buildlink3.mk pkgsrc/textproc/iksemel: Makefile pkgsrc/textproc/libclucene: Makefile buildlink3.mk pkgsrc/textproc/libkolabxml: Makefile buildlink3.mk pkgsrc/textproc/liblrdf: Makefile buildlink3.mk pkgsrc/textproc/libnxml: Makefile buildlink3.mk pkgsrc/textproc/libodfgen: Makefile buildlink3.mk pkgsrc/textproc/lucene++: Makefile pkgsrc/textproc/multimarkdown: Makefile pkgsrc/textproc/odt2tex: Makefile pkgsrc/textproc/p5-Syntax-SourceHighlight: Makefile pkgsrc/textproc/raptor: Makefile buildlink3.mk pkgsrc/textproc/raptor2: Makefile buildlink3.mk pkgsrc/textproc/rasqal: Makefile buildlink3.mk pkgsrc/textproc/redland: Makefile buildlink3.mk pkgsrc/textproc/soprano: Makefile buildlink3.mk pkgsrc/textproc/source-highlight: Makefile buildlink3.mk pkgsrc/textproc/translate-shell: Makefile pkgsrc/textproc/xmlrpc-c: Makefile buildlink3.mk pkgsrc/textproc/xmltooling: Makefile pkgsrc/time/taskwarrior: Makefile pkgsrc/wm/compiz: Makefile pkgsrc/www/R-RCurl: Makefile pkgsrc/www/R-curl: Makefile pkgsrc/www/SOGo: Makefile pkgsrc/www/SOGo4: Makefile pkgsrc/www/ap-auth-openidc: Makefile pkgsrc/www/ap-authnz-crowd: Makefile pkgsrc/www/ap2-auth-mellon: Makefile pkgsrc/www/ap2-passenger: Makefile pkgsrc/www/apache24: Makefile pkgsrc/www/aws: Makefile pkgsrc/www/aws-demos: Makefile pkgsrc/www/cadaver: Makefile pkgsrc/www/curl: Makefile buildlink3.mk pkgsrc/www/elinks: Makefile pkgsrc/www/felinks: Makefile pkgsrc/www/htdavlock: Makefile pkgsrc/www/htmldoc: Makefile pkgsrc/www/kore: Makefile pkgsrc/www/libmicrohttpd: Makefile buildlink3.mk pkgsrc/www/libmrss: Makefile buildlink3.mk pkgsrc/www/lighttpd: Makefile pkgsrc/www/litmus: Makefile pkgsrc/www/lua-curl: Makefile pkgsrc/www/lynx: Makefile pkgsrc/www/neon: Makefile buildlink3.mk pkgsrc/www/netsurf: Makefile pkgsrc/www/nghttp2: buildlink3.mk pkgsrc/www/nspluginwrapper: Makefile pkgsrc/www/ocaml-curl: Makefile pkgsrc/www/p5-Net-Curl: Makefile pkgsrc/www/passenger: Makefile pkgsrc/www/php-curl: Makefile pkgsrc/www/php-http: Makefile pkgsrc/www/php-http3: Makefile pkgsrc/www/py-curl: Makefile pkgsrc/www/rekonq: Makefile pkgsrc/www/ruby-patron: Makefile pkgsrc/www/shibboleth-sp: Makefile pkgsrc/www/sitecopy: Makefile pkgsrc/www/snownews: Makefile pkgsrc/www/squid4: Makefile pkgsrc/www/wwwoffle: Makefile pkgsrc/www/yahttp: Makefile pkgsrc/x11/elementary: Makefile buildlink3.mk pkgsrc/x11/enlightenment: Makefile buildlink3.mk pkgsrc/x11/gtk2: Makefile pkgsrc/x11/gtk3: Makefile pkgsrc/x11/gtk4: Makefile pkgsrc/x11/kactivities: Makefile buildlink3.mk pkgsrc/x11/kactivities-stats: Makefile pkgsrc/x11/kactivities5: Makefile pkgsrc/x11/kde-baseapps4: Makefile pkgsrc/x11/kde-runtime4: Makefile buildlink3.mk pkgsrc/x11/kde-workspace4: Makefile buildlink3.mk pkgsrc/x11/kdelibs4: Makefile buildlink3.mk pkgsrc/x11/libkactivities4: Makefile buildlink3.mk pkgsrc/x11/qt4-libs: Makefile pkgsrc/x11/qt5-qtbase: Makefile pkgsrc/x11/qt5-qtwebengine: Makefile pkgsrc/x11/vte3: Makefile pkgsrc/x11/wmweather: Makefile pkgsrc/x11/x11vnc: Makefile pkgsrc/x11/x2go-client: Makefile pkgsrc/x11/xfce4-tumbler: Makefile pkgsrc/x11/xlockmore: Makefile Log Message: revbump for boost-libs --- Module Name: pkgsrc Committed By: adam Date: Fri Oct 8 13:20:34 UTC 2021 Modified Files: pkgsrc/net/samba4: Makefile PLIST distinfo Log Message: samba4: updated to 4.13.12 Changes since 4.13.11 --------------------- * BUG 14806: Address a signifcant performance regression in database access in the AD DC since Samba 4.12. * BUG 14807: Fix performance regression in lsa_LookupSids3/LookupNames4 since Samba 4.9 by using an explicit database handle cache. * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ. * BUG 14818: Address flapping samba_tool_drs_showrepl test. * BUG 14819: Address flapping dsdb_schema_attributes test. * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ. * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ. * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ. * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ. * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ. * BUG 14784: Fix CTDB flag/status update race conditions. * BUG 14817: An unuthenticated user can crash the AD DC KDC by omitting the server name in a TGS-REQ. --- Module Name: pkgsrc Committed By: adam Date: Wed Nov 10 13:33:20 UTC 2021 Modified Files: pkgsrc/net/samba4: Makefile PLIST distinfo Log Message: samba4: updated to 4.13.14 Changes since 4.13.13 --------------------- o Douglas Bagnall <douglas.bagnall@catalyst.net.nz> * CVE-2020-25722 o Andrew Bartlett <abartlet@samba.org> * CVE-2020-25718 * CVE-2020-25719 * CVE-2020-25721 * CVE-2020-25722 o Ralph Boehme <slow@samba.org> * CVE-2020-25717 o Alexander Bokovoy <ab@samba.org> * CVE-2020-25717 o Samuel Cabrero <scabrero@samba.org> * CVE-2020-25717 o Nadezhda Ivanova <nivanova@symas.com> * CVE-2020-25722 o Stefan Metzmacher <metze@samba.org> * CVE-2016-2124 * CVE-2020-25717 * CVE-2020-25719 * CVE-2020-25722 * CVE-2021-23192 * CVE-2021-3738 * ldb: version 2.2.3 o Andreas Schneider <asn@samba.org> * CVE-2020-25719 o Joseph Sutton <josephsutton@catalyst.net.nz> * CVE-2020-17049 * CVE-2020-25718 * CVE-2020-25719 * CVE-2020-25721 * CVE-2020-25722 * MS CVE-2020-17049 Changes since 4.13.12 --------------------- o Douglas Bagnall <douglas.bagnall@catalyst.net.nz> * BUG 14868: rodc_rwdc test flaps. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Andrew Bartlett <abartlet@samba.org> * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal. * BUG 14836: Python ldb.msg_diff() memory handling failure. * BUG 14845: "in" operator on ldb.Message is case sensitive. * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9. * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED. * BUG 14874: Allow special chars like "@" in samAccountName when generating the salt. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Isaac Boukris <iboukris@gmail.com> * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Viktor Dukhovni <viktor@twosigma.com> * BUG 12998: Fix transit path validation. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Luke Howard <lukeh@padl.com> * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Stefan Metzmacher <metze@samba.org> * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o David Mulder <dmulder@suse.com> * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Andreas Schneider <asn@samba.org> * BUG 14870: Prepare to operate with MIT krb5 >= 1.20. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Joseph Sutton <josephsutton@catalyst.net.nz> * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal. * BUG 14645: rpcclient NetFileEnum and net rpc file both cause lock order violation: brlock.tdb, share_entries.tdb. * BUG 14836: Python ldb.msg_diff() memory handling failure. * BUG 14845: "in" operator on ldb.Message is case sensitive. * BUG 14848: Release LDB 2.3.1 for Samba 4.14.9. * BUG 14868: rodc_rwdc test flaps. * BUG 14871: Fix Samba support for UF_NO_AUTH_DATA_REQUIRED. * BUG 14874: Allow special chars like "@" in samAccountName when generating the salt. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements. o Nicolas Williams <nico@twosigma.com> * BUG 14642: Provide a fix for MS CVE-2020-17049 in Samba [SECURITY] 'Bronze bit' S4U2Proxy Constrained Delegation bypass in Samba with embedded Heimdal. * BUG 14881: Backport bronze bit fixes, tests, and selftest improvements.
2021-11-20Pullup ticket #6532 - requested by bsiegerttm5-21/+21
net/zeromq: security fix Revisions pulled up: - net/zeromq/Makefile 1.32 - net/zeromq/PLIST 1.11 - net/zeromq/distinfo 1.34 - net/zeromq/patches/patch-src_ipc__listener.cpp 1.5 - net/zeromq/patches/patch-src_tcp__listener.cpp 1.6 --- Module Name: pkgsrc Committed By: adam Date: Sun Nov 14 20:15:46 UTC 2021 Modified Files: pkgsrc/net/zeromq: Makefile PLIST distinfo pkgsrc/net/zeromq/patches: patch-src_ipc__listener.cpp patch-src_tcp__listener.cpp Log Message: zeromq: updated to 4.3.4 libzmq 4.3.4 New DRAFT (see NEWS for 4.2.0) socket option: ZMQ_PRIORITY will set the SO_PRIORITY socket option on the underlying sockets. Only supported on Linux. See doc/zmq_setsockopt.txt and doc/zmq_getsockopt.txt for details. Fixed 4113 - compilation errors on kFreeBSD and GNU/Hurd Fixed 4086 - excessive amount of socket files left behind in Windows TMP directory Fixed 4108 - regression that breaks using IPv6 link-local addresses on Linux Fixed 4078 - compilation errors on Android Fixed 4074 - compilation error with ulibc and libbsd Fixed 4060 - stack overflow on Windows x64 Fixed 4051 - various compilation errors on Windows ARM 32bit Fixed 4043 - various compilation warnings with XCode Fixed 4038 - return value of zmq_ctx_get changed unintentionally libzmq 4.3.3 Security advisories: CVE-2020-15166: Denial-of-Service on CURVE/ZAP-protected servers by unauthenticated clients. If a raw TCP socket is opened and connected to an endpoint that is fully configured with CURVE/ZAP, legitimate clients will not be able to exchange any message. Handshakes complete successfully, and messages are delivered to the library, but the server application never receives them. For more information see the security advisory: GHSA-25wp-cf8g-938m Stack overflow on server running PUB/XPUB socket (CURVE disabled). The PUB/XPUB subscription store (mtrie) is traversed using recursive function calls. In the remove (unsubscription) case, the recursive calls are NOT tail calls, so even with optimizations the stack grows linearly with the length of a subscription topic. Topics are under the control of remote clients - they can send a subscription to arbitrary length topics. An attacker can thus cause a server to create an mtrie sufficiently large such that, when unsubscribing, traversal will cause a stack overflow. For more information see the security advisory: GHSA-qq65-x72m-9wr8 Memory leak in PUB server induced by malicious client(s) without CURVE/ZAP. Messages with metadata are never processed by PUB sockets, but the metadata is kept referenced in the PUB object and never freed. For more information see the security advisory: GHSA-4p5v-h92w-6wxw Memory leak in client induced by malicious server(s) without CURVE/ZAP. When a pipe processes a delimiter and is already not in active state but still has an unfinished message, the message is leaked. For more information see the security advisory: GHSA-wfr2-29gj-5w87 Heap overflow when receiving malformed ZMTP v1 packets (CURVE disabled). By crafting a packet which is not valid ZMTP v2/v3, and which has two messages larger than 8192 bytes, the decoder can be tricked into changing the recorded size of the 8192 bytes static buffer, which then gets overflown by the next message. The content that gets written in the overflown memory is entirely decided by the sender. For more information see the security advisory: GHSA-fc3w-qxf5-7hp6 Note for packagers: an external, self-contained sha1 library is now included in the source tree under external/sha1/ - it is licensed under BSD-3-Clause and thus it is fully compatible with libzmq's license. It is only used if WebSockets support is enabled, and if neither GnuTLS nor NSS are available. Note for packagers: an internal reimplementation of strlcpy is now included, for wider platform compatibility. libbsd can be used and is enabled by default if available instead of the internal implementation, for better security maintenance in distros. Note for packagers: ZeroMQConfig.cmake is now installed in the arch-dependent subdirectory - eg: /usr/lib/x86_64-linux-gnu/cmake/ New DRAFT (see NEWS for 4.2.0) socket type: ZMQ_CHANNEL is a thread-safe alternative to ZMQ_PAIR. See doc/zmq_socket.txt for details. New DRAFT (see NEWS for 4.2.0) socket option: ZMQ_ONLY_FIRST_SUBSCRIBE will cause only the first part of a multipart message to be processed as a subscribe/unsubscribe message, and the rest will be forwarded as user data to the application. ZMQ_RECONNECT_STOP will cause a connecting socket to stop trying to reconnect in specific circumstances. See the manpage for details. ZMQ_HELLO_MSG to set a message that will be automatically sent to a new connection. ZMQ_DISCONNECT_MSG to set a message that will be automatically received when a peer disconnects. See doc/zmq_setsockopt.txt and doc/zmq_getsockopt.txt for details. New DRAFT (see NEWS for 4.2.0) zmq_ctx_get_ext/zmq_ctx_set_ext APIs were added to allow enhancing the context options with variable data inputs. See doc/zmq_ctx_get_ext.txt and doc/zmq_ctx_set_ext.txt for details. New DRAFT (see NEWS for 4.2.0) transport options WS and WSS added for support of WebSockets (and secure WebSockets via TLS) via the ZWS 2.0 protocol. WSS requires the GnuTLS library for TLS support. ZMQ_WSS_ specific socket options were added to support TLS. WebSockets support is disabled by default if DRAFT APIs are disabled. New DRAFT (see NEWS for 4.2.0) socket type, PEER, which is thread safe and a related zmq_connect_peer function which atomically and thread-safely connects and returns a routing-id. New DRAFT (see NEWS for 4.2.0) zmq_msg_init_buffer API was added to allow the construction of a message by copying from an existing buffer. New DRAFT (see NEWS for 4.2.0) zmq_poller_size API was added to allow querying the number of sockets/fds registered in a zmq_poller. ZMTP 3.1 peers will receive subscribe/cancel on PUB/SUB via commands rather than using the first byte of the payload. zmq_z85_decode now checks that the input string's length is at least 5 characters and always a multiple of 5 as per API specification. Fixed 3566 - malformed CURVE message can cause memory leak Fixed 3567 - missing ZeroMQ_INCLUDE_DIR in ZeroMQConfig.cmake when only static lib is built Fixed 3576 - CURVE plaintext secrets now stored in libsodium's secure memory Fixed 3588 - install debug libraries for debug msvc builds with CMake Fixed 3591 - incorrect ZMQ_MAX_SOCKETS default value in doc Fixed 3594 - fixed stream_engine use after free due to concurrent heartbeats Fixed 3586 - error when compiling with MinGW due to usage of MS-specific __except keyword Fixed 3603 - fixed CMake build on SL6.9 Fixed 3607 - added scripts to ease performance graph generation Fixed 3608 - fix for IPv4 mapping not supported in DragonFlyBSD Fixed 3636 - added ENABLE_PRECOMPILED CMake option to fix build with Ninja Fixed 2862 - UDP engine aborts on networking-related errors from socket syscalls Fixed 3656 - segfault on sending data from XSUB to XPUB Fixed 3646 - static-only test run fails Fixed 3668 - fixed CMAKE_CXX_FLAGS_* regexes on MSVC Fixed 110 - do not include winsock2.h in public zmq.h header Fixed 3683 - allow "configure --disable-maintainer-mode" Fixed 3686 - fix documentation about sockets blocking on send operations Fixed 3323 - fix behavior of ZMQ_CONFLATE on PUB sockets Fixed 3698 - fix build on IBM i/PASE/os400 Fixed 3705 - zero-sized messages cause assertion when glibc assertion are on Fixed 3713 - remove dependency on math library by avoiding std::ceil Fixed 3694 - build targeting Windows XP is broken Fixed 3691 - added support for IPC on Windows 10 via AF_UNIX Fixed 3725 - disable by default test that requires sudo on CMake Fixed 3727 - fix zmq_poller documentation example Fixed 3729 - do not check for FD_OOB when using WSAEventSelect on Windows Fixed 3738 - allow renaming the library in CMake Fixed 1808 - use AF_UNIX instead of TCP for the internal socket on Windows 10 Fixed 3758 - fix pthread_set_affinity detection in CMake Fixed 3769 - fix undefined behaviour in array.hpp Fixed 3772 - fix compiling under msys2-mingw Fixed 3775 - add -latomic to the private libs flag in pkg-config if needed Fixed 3778 - fix documentation of zmq_poller's thread safety Fixed 3792 - do not allow creation of new sockets after zmq_ctx_shutdown Fixed 3805 - improve performance of CURVE by reducing copies Fixed 3814 - send subscribe/cancel as commands to ZMTP 3.1 peers Fixed 3847 - fix building without PGM and NORM Fixed 3849 - install .cmake file in arch-dependent subdirectory Fixed 4005 - allow building on Windows ARM/ARM64
2021-11-01Pullup ticket #6525 - requested by tacatm24-226/+2485
net/bind916: security fix Revisions pulled up: - net/bind916/Makefile 1.28-1.29 - net/bind916/distinfo 1.24,1.26 - net/bind916/patches/patch-bin_named_unix_os.c 1.1 - net/bind916/patches/patch-bin_tools_arpaname.c deleted - net/bind916/patches/patch-contrib_dlz_modules_wildcard_dlz__wildcard__dynamic.c deleted - net/bind916/patches/patch-lib_dns_client.c 1.1 - net/bind916/patches/patch-lib_dns_dnsrps.c deleted - net/bind916/patches/patch-lib_dns_include_dns_client.h 1.1 - net/bind916/patches/patch-lib_dns_include_dns_zone.h 1.3 - net/bind916/patches/patch-lib_dns_peer.c deleted - net/bind916/patches/patch-lib_dns_rbt.c 1.3 - net/bind916/patches/patch-lib_dns_rdata.c 1.1 - net/bind916/patches/patch-lib_dns_zone.c 1.5 - net/bind916/patches/patch-lib_isc_app.c 1.1 - net/bind916/patches/patch-lib_isc_netmgr_netmgr-int.h 1.1 - net/bind916/patches/patch-lib_isc_netmgr_netmgr.c 1.2 - net/bind916/patches/patch-lib_isc_siphash.c 1.3 - net/bind916/patches/patch-lib_isc_timer.c 1.1 - net/bind916/patches/patch-lib_isc_unix_include_isc_align.h deleted - net/bind916/patches/patch-lib_isc_unix_include_isc_stdatomic.h 1.1 - net/bind916/patches/patch-lib_isc_unix_socket.c 1.6 - net/bind916/patches/patch-lib_ns_Makefile.in 1.3 - net/bind916/patches/patch-lib_ns_client.c 1.5 - net/bind916/patches/patch-lib_ns_interfacemgr.c deleted --- Module Name: pkgsrc Committed By: taca Date: Sun Oct 24 06:40:28 UTC 2021 Modified Files: pkgsrc/net/bind916: Makefile distinfo pkgsrc/net/bind916/patches: patch-lib_dns_include_dns_zone.h patch-lib_dns_rbt.c patch-lib_dns_zone.c patch-lib_isc_netmgr_netmgr.c patch-lib_isc_unix_socket.c patch-lib_ns_Makefile.in patch-lib_ns_client.c Added Files: pkgsrc/net/bind916/patches: patch-bin_named_unix_os.c patch-lib_dns_client.c patch-lib_dns_include_dns_client.h patch-lib_dns_rdata.c patch-lib_isc_app.c patch-lib_isc_netmgr_netmgr-int.h patch-lib_isc_siphash.c patch-lib_isc_timer.c patch-lib_isc_unix_include_isc_stdatomic.h Removed Files: pkgsrc/net/bind916/patches: patch-bin_tools_arpaname.c patch-contrib_dlz_modules_wildcard_dlz__wildcard__dynamic.c patch-lib_dns_dnsrps.c patch-lib_dns_peer.c patch-lib_isc_unix_include_isc_align.h patch-lib_ns_interfacemgr.c Log Message: net/bind916: update pkgsrc changes from NetBSD Catch up changes from NetBSD; update them for BIND 9.16. Bump PKGREVISION. --- Module Name: pkgsrc Committed By: taca Date: Fri Oct 29 06:01:19 UTC 2021 Modified Files: pkgsrc/net/bind916: Makefile distinfo Log Message: net/bind916: update to 9.16.22 This release contains security fix. --- 9.16.22 released --- 5736. [security] The "lame-ttl" option is now forcibly set to 0. This effectively disables the lame server cache, as it could previously be abused by an attacker to significantly degrade resolver performance. (CVE-2021-25219) [GL #2899] 5724. [bug] Address a potential deadlock when checking zone content consistency. [GL #2908] 5723. [bug] Change 5709 broke backward compatibility for the "check-names master ..." and "check-names slave ..." options. This has been fixed. [GL #2911] 5720. [contrib] Old-style DLZ drivers that had to be enabled at build-time have been marked as deprecated. [GL #2814] 5719. [func] The "map" zone file format has been marked as deprecated. [GL #2882] 5717. [func] The "cache-file" option, which was documented as "for testing purposes only" and not to be used, has been removed. [GL #2903] 5716. [bug] Multiple library names were mistakenly passed to the krb5-config utility when ./configure was invoked with the --with-gssapi=[/path/to/]krb5-config option. This has been fixed by invoking krb5-config separately for each required library. [GL #2866] 5715. [func] Add a check for ports specified in "*-source(-v6)" options clashing with a global listening port. Such a configuration was already unsupported, but it failed silently; it is now treated as an error. [GL #2888] 5714. [bug] Remove the "adjust interface" mechanism which was responsible for setting up listeners on interfaces when the "*-source(-v6)" address and port were the same as the "listen-on(-v6)" address and port. Such a configuration is no longer supported; under certain timing conditions, that mechanism could prevent named from listening on some TCP ports. This has been fixed. [GL #2852] 5712. [doc] Add deprecation notice about removing native PKCS#11 support in the next major BIND 9 release. [GL #2691]
2021-11-01Pullup ticket #6524 - requested by tacatm3-25/+15
net/bind911: security fix Revisions pulled up: - net/bind911/Makefile 1.51 - net/bind911/distinfo 1.37 - net/bind911/patches/patch-configure 1.6 --- Module Name: pkgsrc Committed By: taca Date: Fri Oct 29 06:02:26 UTC 2021 Modified Files: pkgsrc/net/bind911: Makefile distinfo pkgsrc/net/bind911/patches: patch-configure Log Message: net/bind911: update to 9.11.36 --- 9.11.36 released --- 5736. [security] The "lame-ttl" option is now forcibly set to 0. This effectively disables the lame server cache, as it could previously be abused by an attacker to significantly degrade resolver performance. (CVE-2021-25219) [GL #2899] 5716. [bug] Multiple library names were mistakenly passed to the krb5-config utility when ./configure was invoked with the --with-gssapi=[/path/to/]krb5-config option. This has been fixed by invoking krb5-config separately for each required library. [GL #2866]
2021-10-08Pullup ticket #6507 - requested by tmbsiegert3-2/+20
net/rsync: security fix Revisions pulled up: - net/rsync/Makefile 1.116 - net/rsync/distinfo 1.52 - net/rsync/patches/patch-rsync-ssl 1.1 --- Module Name: pkgsrc Committed By: wiz Date: Wed Oct 6 08:15:57 UTC 2021 Modified Files: pkgsrc/net/rsync: Makefile distinfo Added Files: pkgsrc/net/rsync/patches: patch-rsync-ssl Log Message: rsync: fix CVE-2020-14387 using upstream patch. Bump PKGREVISION.
2021-10-05Pullup ticket #6501 - requested by bsiegerttm2-2/+3
net/tigervnc: Bugfix for X11R7 fonts Revisions pulled up: - net/tigervnc/Makefile 1.43 - net/tigervnc/files/vncserver.pl 1.2 --- Module Name: pkgsrc Committed By: wiz Date: Thu Sep 30 21:38:23 UTC 2021 Modified Files: pkgsrc/net/tigervnc: Makefile pkgsrc/net/tigervnc/files: vncserver.pl Log Message: tigervnc: look in /usr/X11R7 for fonts From Chavdar Ivanov in PR 56427. Bump PKGREVISION.
2021-09-27guacamole-server: Allow NOOP for PKG_SYSCONFBASE=/etc.jperkin1-1/+2
2021-09-23py-gevent: another PLIST fix for Python 2.7adam1-2/+2
2021-09-23amazon-ecs-cli: fix builds with recent Go versionsgutteridge1-2/+4
This package (which hasn't had a subsequent release from upstream) will no longer build when being treated as a "module" by recent Go versions (and related pkgsrc definitions). It seems non-trivial to address this (simply trying to add go.mod and such then leads to other errors, e.g., recent Go objecting to API versioning practices in code bundled by upstream), so to get this building again for now, use the old "package" approach instead.
2021-09-22net-snmp: allow build on newer Darwin; fix #55927adam1-8/+5
2021-09-22py-gevent: fix PLIST for Python 2.7adam1-6/+8
2021-09-19net/bind916: update to 9.16.21taca2-16/+7
--- 9.16.21 released --- 5711. [bug] "map" files exceeding 2GB in size failed to load due to a size comparison that incorrectly treated the file size as a signed integer. [GL #2878] 5710. [port] win32: incorrect parentheses resulted in the wrong sizeof() tests being used to pick the appropriate Windows atomic operations for the object's size. [GL #2891] 5709. [cleanup] Enum values throughout the code have been updated to use the terms "primary" and "secondary" instead of "master" and "slave", respectively. [GL #1944] 5708. [bug] The thread-local isc_tid_v variable was not properly initialized when running BIND 9 as a Windows Service, leading to a crash on startup. [GL #2837] 5705. [bug] Change #5686 altered the internal memory structure of zone databases, but neglected to update the MAPAPI value for zone files in "map" format. This caused named to attempt to load incompatible map files, triggering an assertion failure on startup. The MAPAPI value has now been updated, so named rejects outdated files when encountering them. [GL #2872] 5704. [bug] Change #5317 caused the EDNS TCP Keepalive option to be ignored inadvertently in client requests. It has now been fixed and this option is handled properly again. [GL #1927] 5701. [bug] named-checkconf failed to detect syntactically invalid values of the "key" and "tls" parameters used to define members of remote server lists. [GL #2461] 5700. [bug] When a member zone was removed from a catalog zone, journal files for the former were not deleted. [GL #2842] 5699. [func] Data structures holding DNSSEC signing statistics are now grown and shrunk as necessary upon key rollover events. [GL #1721] 5698. [bug] When a DNSSEC-signed zone which only has a single signing key available is migrated to use KASP, that key is now treated as a Combined Signing Key (CSK). [GL #2857] 5696. [protocol] Support for HTTPS and SVCB record types has been added. (This does not include ADDITIONAL section processing for these record types, only basic support for RR type parsing and printing.) [GL #1132] 5694. [bug] Stale data in the cache could cause named to send non-minimized queries despite QNAME minimization being enabled. [GL #2665] 5691. [bug] When a dynamic zone was made available in another view using the "in-view" statement, running "rndc freeze" always reported an "already frozen" error even though the zone was successfully frozen. [GL #2844] 5690. [func] dnssec-signzone now honors Predecessor and Successor metadata found in private key files: if a signature for an RRset generated by the inactive predecessor exists and does not need to be replaced, no additional signature is now created for that RRset using the successor key. This enables dnssec-signzone to gradually replace RRSIGs during a ZSK rollover. [GL #1551]
2021-09-19gcloud-golang-metadata: remove.bsiegert6-73/+1
Its last dependency, net/obfs4proxy, was just upgraded to a module build.
2021-09-19Update obfs4proxy to 0.0.11. Now a Go module build.bsiegert4-80/+164
Changes in version 0.0.11 - 2019-06-21: - Update my e-mail address. - Change the obfs4 behavior for handling handshake failure to be more uniform. Thanks to Sergey Frolov for assistance. - Bump the version of the utls fork. Changes in version 0.0.10 - 2019-04-12: - Disable behavior distinctive to crypto/tls when using utls. - Bump the version of the utls fork. Changes in version 0.0.9 - 2019-02-05: - Various meek_lite code cleanups and bug fixes. - Bug 29077: uTLS for ClientHello camouflage (meek_lite). - More fixes to HTTP Basic auth. - (meek_lite) Pin the certificate chain public keys for the default Tor Browser Azure bridge (meek_lite).
2021-09-19Update py-gsutil to 4.68. Now Python 3 only.bsiegert4-115/+70
Release 4.68 (release date: 2021-09-14) ======================================= Bug Fixes ------------------ - Improve content type inference for some common extensions. - Copy Content-Encoding from first object in compose command. - Support generation querying for ls command. Other Changes ------------------ - Add a message encouraging py3 upgrade. - Update mock library version. - Several documentation updates and clarifications. Release 4.67 (release date: 2021-08-16) ======================================= Bug Fixes ------------------ - Update pyu2f to latest version to fix a security key reauth bug Other Changes ------------------ - Several documentation updates and clarifications. Release 4.66 (release date: 2021-07-29) ======================================= New Features ------------------ - Onboard mTLS support with AIP-4114 for gsutil Other Changes ------------------ - Several documentation updates and clarifications. Release 4.65 (release date: 2021-07-02) ======================================= New Features ------------------ - Add gsutil support for Public Access Prevention Bug Fixes ------------------ - Fix raising-bad-type yapf errors. Other Changes ------------------ - Link fix pointing to CGC docs again . - Backfill some small doc changes - Small text tweak - Update CHECKSUM and VERSION for 4.64 release. - Update CHANGES.md for 4.64 release. - Delete encryption addhelp page - Putting cl/381035251 into github - Backfill cl/381932961 Release 4.64 (release date: 2021-06-18) ======================================= Bug Fixes ------------------ - None Other Changes ------------------ - Link fix pointing to CGC docs. Release 4.63 (release date: 2021-06-09) ======================================= Bug Fixes ------------------ - Update warning text on KMS access denied - Make ** to represent zero or more folders for cloud urls - Raise error if final destination path ends with a delimiter. Other Changes ------------------ - Fix flaky test for rm using preconditions - Fix pyenv issue for macOS - Fix rewrite tests - Remove unused progress callback. - Several documentation updates and clarifications. Release 4.62 (release date: 2021-05-13) ======================================= New Features ------------------ - Add ignore-existing option for rsync . - Show satisifiesPZS info in bucket info listing (ls -Lb). - Support composite uploads with KMS. - Enforce custom endpoints through multipart copies and complex downloads. Bug Fixes ------------------ - rm will continue on object 404s. - Update boto submodule to include a fix for integrity checks with KMS. - iam ch is now case-insensitive for public members and member types. - Support skipping integrity checks in daisy chain transfers. - Ensure the correct content-length is provided for incomplete downloads. - Fix daisy chain for windows. - Fix stats crashing because of nanosecs in custom-time. - Delete connections after fork. - Patch md5 import for compliance on Red Hat FIPS mode distributions. - Handle case where there are too many slashes after CloudUrl scheme. - Allow specifying object generations in compose. - Raise error in setmeta if no headers are provided. - Fix encoding issue for rfc822 messages. - Fix StreamExhausted Error handling for Resumable uploads. - Fix wildcard ** bug. - Fix alignment of ls -l output. - Fix newlines around lists. Other Changes ------------------ - Fix sonatype errors. - gslib: boto\_util: implement a HasUserSpecifiedGsHost() helper. - Adding warning to rsync if streams or named paths are included in a folder. - Improve parallelism warnings. - Several documentation updates and clarifications. Release 4.61 (release date: 2021-04-06) ======================================= Bug Fixes ------------------ - Update to RSA v4.5. - CopyHelper accepts kms check bypass. Other Changes ------------------ - Doc updates. Release 4.60 (release date: 2021-03-11) ======================================= Bug Fixes ------------------ - Fixed proxy connections when using the GCS XML API. - Improve reliability when multiple instances of gsutil transfer to the same destination. Other Changes ------------------ - Remove TravisCI and update "check for CI" references to use GitHub CI. - Several documentation updates and clarifications. Release 4.59 (release date: 2021-02-10) ====================================== New Features ------------------ - Add ignore-existing option for rsync . - Show satisifiesPZS info in bucket info listing (ls -Lb) . Bug Fixes ------------------ - Register integration test failures in kokoro script . Other Changes ------------------ - Use respectful code . - Several documentation updates and clarifications. Release 4.58 (release date: 2021-01-21) ====================================== Bug Fixes ------------------ - Fix more occurrences of encodestring/decodestring - Ignore the .github directory for updates - Make signurl use generation information. - Fix UnicodeEncodeError in Python2 for help metadata command - Open files in non-append mode to make stripe functionality work in Lustre file systems - Persist request reason header for resumable uploads and downloads. - improve upload speed significantly when it runs on Windows - Add perf-trace-token support for resumable uploads. - Improve error message when a bucket's name collides with another. - Fix formatting for empty CORS JSON document Other Changes ------------------ - Several documentation updates and clarifications. - Add CI checks for Python 3.8 Release 4.57 (release date: 2020-12-08) ====================================== Bug Fixes ------------------ - Remove Unicode character from config command that was causing Python 2 issues. - Sync docs with web. Release 4.56 (release date: 2020-12-03) ====================================== New Features ------------------ - mTLS/DCA Authentication - Add GitHub Actions CI Bug Fixes ------------------ - Delete the projects.py help topic - Format fix for cp.py Release 4.55 (release date: 2020-11-12) ====================================== Bug Fixes ------------------ - Prevent trailing spaces in json output of iam get - Fix deprecation warnings due to invalid escape sequences. - Use is_alive in favour of isAlive for Python 3.9 compatibility. - Fix for base64.{encode/decode}string in python 3.9 Other Changes ------------------ - Several documentation updates and clarifications. Release 4.54 (release date: 2020-10-22) ====================================== New Features ------------------ - Add userProject support to signurl Bug Fixes ------------------ - Explicitly set multiprocessing start method to 'fork' - Headers can now be removed - Fix CommandException.informational attribute error - Fix broken signurl error message. Other Changes ------------------ - Warn when disabling parallel composite uploads for KMS encryption. - Handle SAML reauth challenge. - Several documentation updates and clarifications.
2021-09-19py-responses: updated to 0.14.0adam3-8/+11
0.14.0 ------ * Added `responses.matchers`. * Moved `responses.json_params_matcher` to `responses.matchers.json_params_matcher` * Moved `responses.urlencoded_params_matcher` to `responses.matchers.urlencoded_params_matcher` * Added `responses.matchers.query_param_matcher`. This matcher allows you to match query strings with a dictionary. * Added `auto_calculate_content_length` option to `responses.add()`. When enabled, this option will generate a `Content-Length` header based on the number of bytes in the response body.
2021-09-19lagrange: update to 1.6.5nia2-8/+7
(v1.6.3) Input field improvements: highlight domain name in URLs, hide default Gemini scheme if narrow, selecting all text, retain focus in background. Fixed bugs: delay when splitting the view; initial split view background; line break modifier affecting all input fields; potential hang when aborting a connection. (v1.6.4) UTF-8 text files can be viewed in the app regardless of file extension. Added ENABLE_RESIZE_DRAW build option. Fixed bugs: cursor positioning and text insertion around variation selectors; "Unknown Status Code" in Page Information; network requests getting stuck before anything is sent; possible crash when clicking on sidebar items; freeze after a network request is cancelled (OpenBSD); page contents not reflowing during window resize. (v1.6.5) Audio init errors are no longer fatal. Fixed tab button appearance, cursor movement regression, right-clicking on sidebar tab buttons, crash with KMSDRM video driver, and minor text rendering artifacts.
2021-09-18mikutter: explicitly pull the latest ruby-gtk2 to avoid dependency woes.tsutsui1-2/+3
Bump PKGREVISION.
2021-09-17dnsmasq: updated to 2.86adam2-7/+7
version 2.86 Handle DHCPREBIND requests in the DHCPv6 server code. Thanks to Aichun Li for spotting this omission, and the initial patch. Fix bug which caused dnsmasq to lose track of processes forked to handle TCP DNS connections under heavy load. The code checked that at least one free process table slot was available before listening on TCP sockets, but didn't take into account that more than one TCP connection could arrive, so that check was not sufficient to ensure that there would be slots for all new processes. It compounded this error by silently failing to store the process when it did run out of slots. Even when this bug is triggered, all the right things happen, and answers are still returned. Only under very exceptional circumstances, does the bug manifest itself: see https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2021q2/014976.html Thanks to Tijs Van Buggenhout for finding the conditions under which the bug manifests itself, and then working out exactly what was going on. Major rewrite of the DNS server and domain handling code. This should be largely transparent, but it drastically improves performance and reduces memory foot-print when configuring large numbers domains of the form local=/adserver.com/ or local=/adserver.com/# Lookup times now grow as log-to-base-2 of the number of domains, rather than greater than linearly, as before. The change makes multiple addresses associated with a domain work address=/example.com/1.2.3.4 address=/example.com/5.6.7.8 It also handles multiple upstream servers for a domain better; using the same try/retry algorithms as non domain-specific servers. This also applies to DNSSEC-generated queries. Finally, some of the oldest and gnarliest code in dnsmasq has had a significant clean-up. It's far from perfect, but it _is_ better. Revise resource handling for number of concurrent DNS queries. This used to have a global limit, but that has a problem when using different servers for different upstream domains. Queries which are routed by domain to an upstream server which is not responding will build up and trigger the limit, which breaks DNS service for all other domains which could be handled by other servers. The change is to make the limit per server-group, where a server group is the set of servers configured for a particular domain. In the common case, where only default servers are declared, there is no effective change. Improve efficiency of DNSSEC. The sharing point for DNSSEC RR data used to be when it entered the cache, having been validated. After that queries requiring the KEY or DS records would share the cached values. There is a common case in dual-stack hosts that queries for A and AAAA records for the same domain are made simultaneously. If required keys were not in the cache, this would result in two requests being sent upstream for the same key data (and all the subsequent chain-of-trust queries.) Now we combine these requests and elide the duplicates, resulting in fewer queries upstream and better performance. To keep a better handle on what's going on, the "extra" logging mode has been modified to associate queries and answers for DNSSEC queries in the same way as ordinary queries. The requesting address and port have been removed from DNSSEC logging lines, since this is no longer strictly defined. Connection track mark based DNS query filtering. Thanks to Etan Kissling for implementing this It extends query filtering support beyond what is currently possible with the `--ipset` configuration option, by adding support for: 1) Specifying allowlists on a per-client basis, based on their associated Linux connection track mark. 2) Dynamic configuration of allowlists via Ubus. 3) Reporting when a DNS query resolves or is rejected via Ubus. 4) DNS name patterns containing wildcards. Disallowed queries are not forwarded; they are rejected with a REFUSED error code. Allow smaller than 64 prefix lengths in synth-domain, with caveats. --synth-domain=1234:4567::/56,example.com is now valid. Make domains generated by --synth-domain appear in replies when in authoritative mode. Ensure CAP_NET_ADMIN capability is available when conntrack is configured. Thanks to Yick Xie for spotting the lack of this. When --dhcp-hostsfile --dhcp-optsfile and --addn-hosts are given a directory as argument, define the order in which files within that directory are read (alphabetical order of filename). Thanks to Ed Wildgoose for the initial patch and motivation for this.
2021-09-17Revbump all Go packages after go117 updatebsiegert24-45/+48
2021-09-17qbittorrent: updated to 4.3.8adam2-7/+7
v4.3.8 - BUGFIX: Delay processing of watched folders - BUGFIX: Use the same icon for selecting folders/files (Chocobo1) - BUGFIX: Use default upper limits for ddns entries (Chocobo1) - WEBUI: Expose SSRF mitigation - WEBUI: Update webui libraries (Chocobo1) - WEBUI: Group trackers by hostname - WEBUI: Improve "last activity" calculation in WebAPI - WINDOWS: NSIS: Add Polish translation
2021-09-16mitmproxy: Update to 7.0.3leot2-7/+7
Changes: 7.0.3 ----- * CVE-2021-39214: Fix request smuggling vulnerabilities reported by @chinchila * Expose TLS 1.0 as possible minimum version on older pyOpenSSL releases * Fix compatibility with Python 3.10 7.0.2 ----- * Fix a WebSocket crash introduced in 7.0.1 7.0.1 ----- * Performance: Re-use OpenSSL contexts to enable TLS session resumption * Disable HTTP/2 CONNECT for Secure Web Proxies to fix compatibility with Firefox * Use local IP address as certificate subject if no other info is available * Make it possible to return multiple chunks for HTTP stream modification * Don't send WebSocket CONTINUATION frames when the peer does not send any * Fix HTTP stream modify example. * Fix a crash caused by no-op assignments to `Server.address` * Fix a crash when encountering invalid certificates * Fix a crash when pressing the Home/End keys in some screens * Fix a crash when reading corrupted flow dumps * Fix multiple crashes on flow export * Fix a bug where ASGI apps did not see the request body * Minor documentation improvements
2021-09-15grpc: updated to 1.40.0adam9-36/+36
Release v1.40.0 Core Update Envoy API to the latest version (2021-07-30). Enable retries by default. Add opentelemetry as a submodule for latest xDS API. Pointing the protobuf submodule to the new URL. Remove BUILD.gn. Prevent race causing early-destruction of grpc_winsocket object when creating a TCP connection. TLS Security Connector: Add an always-fail-handshaker when certificates are not ready. Enable layering checks in the Bazel build. Support user provided "scope" in JWT and GDC. C++ C++ opencensus filter: Fix point of creating context for overall call. Open census call attempt span name and attribute changes Open census filter: Use new internal stats API and record retry stats. Add OpenCensus measures and views for retries. Python Add retry example for gRPC Python. Remove Python 2.7 binary wheel generations. [Aio][fix] catch application exception in request iterators.
2021-09-15py-lexicon: updated to 3.7.0adam3-11/+20
3.7.0 Added Add the Vercel provider (formerly known as Zeit) Add the OpenShift Cloud Infrastructure (OCI) DNS provider Modified Keep old Zeit provider for compatibility purpose with deprecation notices Support multiple domain statuses for Joker provider
2021-09-15py-tldextract: updated to 3.1.2adam2-7/+7
3.1.2 (2021-09-01) * Misc. * Only run pylint in Tox environments, i.e. CI, not by default in tests
2021-09-13net/ncgopher: rev bump, fix broken buildspin3-409/+366
Both mef and jperkin have reported broken builds for ncgopher after rust update to 1.54.0 I've contacted upstream and they have updated the dependencies but, no new release. https://github.com/jansc/ncgopher/issues/35 The package builds fine on my 9.99.88 amd64 now.
2021-09-13mikutter: update to 4.1.6.tsutsui2-7/+7
Upstream changes mikutter 4.1.6 https://mikutter.hatenablog.com/entry/2021/09/13/215700 * ggrks (search by Google) used URI.escape removed on Ruby 3.0.0 * thanks Akira Ouchi
2021-09-13py-zeep: updated to 4.1.0adam2-13/+13
4.1.0 (2021-08-15) ------------------ - Remove last dependency on `six` - Use `platformdirs` instead of the `appsdirs` dependency - Pass digest method when signing timestamp node - Fix settings context manager when an exception is raised - Don't render decimals using scientific notation - Remove dependency on `defusedxml` (deprecated) - Improve handling of str values for Duration
2021-09-13samba4: updated to 4.3.11adam2-8/+7
Changes since 4.13.10 * BUG 14769: smbd panic on force-close share during offload write. * BUG 14731: Fix returned attributes on fake quota file handle and avoid hitting the VFS. * BUG 14783: smbd "deadtime" parameter doesn't work anymore. * BUG 14787: net conf list crashes when run as normal user. * BUG 14607: Work around special SMB2 READ response behavior of NetApp Ontap 7.3.7. * BUG 14793: Start the SMB encryption as soon as possible. * BUG 14792: Winbind should not start if the socket path for the privileged pipe is too long.
2021-09-12Fixes for earlier versions of appletalk and phase 1 interfaces.nat10-3/+196
Add option to disable afp session timeouts. Fix setting of phase1 addresses on NetBSD. Send replies to client when printing to prompt more data to be sent. ok markd@.
2021-09-12net/unison-snapshot: Update to 2.51.4.70.2gdt2-9/+9
upstream changes: bugfixes and minor improvements
2021-09-12gallery-dl: Update to 1.18.4leot3-8/+11
Changes: 1.18.4 ------ ### Additions - [420chan] add `thread` and `board` extractors - [deviantart] add `tag` extractor - [deviantart] add `comments` option - [deviantart] implement a `auto-watch` option - [foolfuuka] add `gallery` extractor - [furaffinity] expand URL pattern for searches - [kemonoparty] automatically generate required DDoS-GUARD cookies - [nhentai] add `favorite` extractor - [shopify] support windsorstore.com - [twitter] add `url` to user objects - [twitter] expand t.co links in user descriptions - show a warning if an extractor doesn`t yield any results - add a `j` format string conversion - implement a `fallback` option - implement a `path-strip` option ### Changes - [shopify] use API for product listings - update default User-Agent headers ### Fixes - [deviantart] prevent exceptions for "empty" videos - [exhentai] improve image limits check - [inkbunny] fix extraction - [mangadex] prevent exceptions for manga without English title - [oauth] use defaults when config values are set to `null` - [pixiv] fix pixivision title extraction - [reddit] delay RedditAPI initialization - [twitter] improve error reporting - [twitter] fix issue when filtering quote tweets - [twitter] fix `logout` option ### Removals - [deviantart] remove the "you need session cookies to download mature scraps" warning - [foolslide] remove entry for kobato.hologfx.com
2021-09-12Update to 0.76wen2-8/+7
Upstream changes: 0.76 Mon Sep 14 14:20:41 PDT 2020 - correctly handle stderr output from rsync 3.2.3.
2021-09-12Update to 0.98wen2-8/+7
Upstream changes: 0.98 2021-03-22 - document how to use buckets with dots, Signature V4, and HTTPS together - fix Net::Amazon::S3::Client::Object::exists (#94) - improve compatibility with DigitalOcean Spaces (#95) 0.97 2020-10-09 - presigned object access uri supports also PUT/DELETE methods (#89) 0.96 2020-10-07 - Signature V4 didn't work properly for services on non-standard port (issue #88) 0.95 2020-10-06 - bugfix release, with new test coverage - small cleanups 0.94 2020-09-27 - fix undefined method call in still untested methods (thanks Russell Jenkins) 0.93 2020-09-27 - fix syntax failures on perl < v5.22 (thanks cpantesters) 0.92 2020-09-26 - misc cleanups, more tests - Net::Amazon::S3::Client now can be constructed with same arguments as Net::Amazon::S3 - Support explicit ACL in bucket/object/upload creation - Support set_acl on Client::Bucket / Client::Object (issue #83) - Add support for bucket/object tagging (issue #44)
2021-09-12wget: remove unused patch after updatewiz1-17/+0
2021-09-12wget: update to 1.21.2.wiz3-10/+9
* Noteworthy changes in release 1.21.2 (2021-09-07) ** Support for autoconf 2.71 ** Fix a double free in FTP when using an absolute path ** Release tarballs no longer have a dependency on Python. ** --page-requisites will now also download links marked as "alternate stylesheet" or "icon"
2021-09-12Update to 0.22wen2-8/+7
Upstream changes: 0.22 2021-04-04 - Security: IPv4 octets with leading zeroes are no longer allowed. https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/
2021-09-12Update to 0.49wen2-10/+7
Upstream changes: 2020-09-22 Todd Rinaldo <toddr@cpan.org> (0.49) * Perl 5.6 is the minimum required version now. * RIP Thread.pm it has not been relevant since 5.6 * Now using github CI to monitor the major platforms. * .gitignore for better management * Update the MANIFEST * Perltidy the code base. * use strict, warnings, no vars, our * Remove perl 4-ish subroutine calls * Require Sys::Syslog 0.29 to function properly. * t/base.t -> Test::More * Improve skipall messages and detection of ithreads/forks * Disable t/ithreadm.t for Windows See https://github.com/toddr/Net-Daemon/issues/19 * Only load threads if forks hasn't already been loaded and threads exist. * Update tracker location to github * Fix ReadConfigFile implementation traversing @INC
2021-09-12Update to 1.32wen2-8/+7
Upstream changes: **** 1.32 Jul 16, 2021 Text: Offer both Unicode and escaped-ASCII strings. Add LICENSE file to comply with Fedora/RedHat announcement. Fix rt.cpan.org #136666 Net::DNS::RR::ZoneFile parser erroneously strips line terminators in quoted string forming part of multiline RR. **** 1.31 May 2, 2021 Improve implementation of SVCB record.
2021-09-12Update to 1.02wen2-8/+7
Upstream changes: 1.02 2021-09-08 13:15:24 CST - Add support for reviews #108 (jrmash)
2021-09-12Update to 0.6.4wen2-9/+8
Upstream changes: 0.604 2021/02/26 - change bugtracker in Makefile.PL to github
2021-09-12Update to 1.02wen2-9/+7
Upstream changes: 1.02 2021-03-31 * Remove Net::IPv4Addr dependence * Disable base85 unless user installed Math::Base85
2021-09-12Update to 3.78wen2-7/+7
Upstream changes: Version 3.78 (2021-09-08) [BUG FIXES] * Fix undefined value error in Bridge.pm i_vlan
2021-09-10powerdns-recursor: needs atomic64nia1-1/+2
2021-09-08net/iperf2: Update to 2.1.4gdt4-68/+8
Drop two patches applied upstream. Take MAINTAINERship. upstream NEWS: perf 2.1.4 has many user visible changes since 2.0.13 and even more since 2.0.5 The below describes many of these user visible changes with a focus on 2.1.4 compared to 2.0.13 -e or --enhanced-reports configure '--enable-fast-sampling' This configuration causes the iperf binary to support units of microseconds. It casues iperf to use four units of precision in it's timing interval output, i.e. 1e-4, as one example iperf -c 192.168.1.64 -n 4 -C ------------------------------------------------------------ Client connecting to 192.168.1.64, TCP port 5001 TCP window size: 85.0 KByte (default) ------------------------------------------------------------ [ 1] local 192.168.1.133 port 56568 connected with 192.168.1.64 port 5001 [ ID] Interval Transfer Bandwidth [ 1] 0.0000-0.0172 sec 4.00 Bytes 1.86 Kbits/sec '--trip-times' on the client This option indicates to iperf a few things. First, that the user has syncrhonized the clients' and servers' clocks. A good way to do this is using Precision Time Protocol and a GPS atomic clock as a reference. This knowledge allows iperf to use many time stamps to be sender based, i.e. taken from the sender's write timestamp (which is carried in the payloads.) The connect message on both the server and the client will indicate that '--trip-times' has been enabled. Both UDP an TCP support '--trip-times' iperf -c 192.168.1.64 --trip-times ------------------------------------------------------------ Client connecting to 192.168.1.64, TCP port 5001 TCP window size: 85.0 KByte (default) ------------------------------------------------------------ [ 1] local 192.168.1.133 port 56580 connected with 192.168.1.64 port 5001 (trip-times) iperf -s ------------------------------------------------------------ Server listening on TCP port 5001 TCP window size: 128 KByte (default) ------------------------------------------------------------ [ 1] local 192.168.1.64%enp2s0 port 5001 connected with 192.168.1.133 port 56580 (MSS=1448) (trip-times) (sock=4) (peer 2.1.4) on 2021-08-22 11:12:08 (PDT) Iperf 2 new metrics NetPwr Network power: The network power (NetPwr) metric originates from Kleinrock and Jaffe circa 1980. It is a measure of a desirable property divided by an undesirable property. It is defined as throughput/delay. For TCP transmits, the delay is the sampled RTT times. For TCP receives, the delay is the write to read latency. For UDP the delay is the packet end/end latency. Note, one must use -i interval with TCP to get this as that's what sets the RTT sampling rate. The metric is scaled to assist with human readability. InP The InP metric is derived from Little's Law or Little's Lamma. LL in queuing theory is a theorem that determines the average number of items (L) in a stationary queuing system based on the average waiting time (W) of an item within a system and the average number of items arriving at the system per unit of time (lambda). Mathematically, it's L = lambda * W. As used here, the units are bytes. The arrival rate is taken from the writes.
2021-09-08Recursive revbump for audio/jacknia3-5/+6
2021-09-08net/frr: upgrade to bug-fix release 8.0.1kardel2-7/+7
2021-09-08haproxy: Update to 2.4.4.jperkin2-9/+8
The ChangeLog doesn't explicitly mention, but this fixes the CVE-2021-40346 vulnerability as described in: https://www.mail-archive.com/haproxy@formilux.org/msg41114.html While here switch to inserting CFLAGS via CPU_CFLAGS, as that feels a little more appropriate than DEBUG_CFLAGS after re-reading the Makefile. 2021/09/07 : 2.4.4 - BUG/MEDIUM: h2: match absolute-path not path-absolute for :path - REGTESTS: http_upgrade: fix incorrect expectation on TCP->H1->H2 - REGTESTS: abortonclose: after retries, 503 is expected, not close - MINOR: hlua: take the global Lua lock inside a global function - BUG/MINOR: stick-table: fix the sc-set-gpt* parser when using expressions - BUG/MEDIUM: base64: check output boundaries within base64{dec,urldec} - BUG/MINOR: base64: base64urldec() ignores padding in output size check - MINOR: compiler: implement an ONLY_ONCE() macro - BUG/MINOR: lua: use strlcpy2() not strncpy() to copy sample keywords - BUG/MINOR: time: fix idle time computation for long sleeps - MINOR: time: add report_idle() to report process-wide idle time - BUG/MINOR: ebtree: remove dependency on incorrect macro for bits per long - BUG/MINOR threads: Use get_(local|gm)time instead of (local|gm)time - BUG/MINOR: tools: Fix loop condition in dump_text() - CLEANUP: Add missing include guard to signal.h - BUG/MINOR: vars: fix set-var/unset-var exclusivity in the keyword parser - DOC: configuration: remove wrong tcp-request examples in tcp-response - BUG/MINOR: config: reject configs using HTTP with bufsize >= 256 MB - CLEANUP: htx: remove comments about "must be < 256 MB" - BUG/MAJOR: htx: fix missing header name length check in htx_add_header/trailer - Revert "BUG/MINOR: stream-int: Don't block reads in si_update_rx() if chn may receive"
2021-09-07net/tor: Workaround upstream "micro-revision.i" buggdt1-1/+6
There is something wrong in tor's makefiles which causes: src/lib/version/git_revision.c:21:10: fatal error: micro-revision.i: No such file or directory #include "micro-revision.i" ^~~~~~~~~~~~~~~~~~ compilation terminated. obviously by not having built micro-revision.i when that compilation is done. This happens reliably for some people and not for others. This commit adds a comment with the issue in tor's bug tracker, and a workaround that builds micro-revision.i and then does the normal build. No PKGREVISION as this is just a build fix, and should have zero effect if this built anyway. ok @wiz
2021-09-07net/unifi: Update to 6.2.26gdt3-3973/+3925
upstream changes are bugfixes and minor improvements plus: Improvements Allow dismissing UDM-Pro banner in dashboard page. Add "Firmware version" column to Devices page and change "Version" to "Firmware Status". Add alert that threat was detected or blocked. Add 'Sign Out' button for Software installation controller. Add USW-Enterprise-24-PoE images. Add USP-RPS panel overview and port diagram. Add status indicators to Clients table. Add date range to Statistics. Add L3 Switch routing support for Static Route. Live update performance improvements in all pages. Improve Statistics page performance. Improve Hotspot form performance. Improve alert client fingerprinting. Remove frequent alerts after 14 days. Update WiFiman Topology in property panel. Update admin role names (Administrator, Site Admin, View only, Hotspot Operator). Update VPN section. Column visibility for Device and Client tables. Save table columns only when leaving page. Updates to side navigation icons. Utilization-bar tooltip style updates. Capitalize MAC and WLAN text used in property panel. Always send connection alert for clients. Move table row actions to forms. Update UAP property panel. Remove survey modals from Dashboard and Settings. Traffic section design updates. Implement Device and Outlets sections for USP-RPS property panel.