summaryrefslogtreecommitdiff
path: root/net
AgeCommit message (Collapse)AuthorFilesLines
2018-02-19Update to 0.8.11triaxx10-27/+156
Remove patches/patch-aa: code no longer used Fix Makefile.unix: from FreeBSD ports Add documentation to package Add rcd script Changes: -------- 19.10.2017 Releasing as 0.8.11 Minor bugfixes / improvements: ! Fixed: deadlock on insufficient resources ! Fixed: race condition in ssl_plugin ! Fixed: minor memory leak on configuration reload ! Fixed: recursion detection was not working ! Fixed: %n for IPv6 in logging terminates log record ! Fixed: reverse PTR validation (required for dnsauth) ! Fixed: error on external 0.0.0.0 for NOIPV6 (light version) + Better support for IPv6 in ftppr 25.06.2017 Releasing as 0.8.10 !Fix: parent proxy can be used in some cases where it shouldn't !Fix: bandlimiters may not work for older connections on configuration reload 01.02.2017 Releasing as 0.8.9 !Fix: tcppm may fail if used with parent proxy 16.12.2016 Releasing as 0.8.8 !! Fix resolver for non-compressed reply parsing (on mixed-case sensitive resolvers) ! Fix plugins export on OpenWatcom compiler (light version) ! Fix SOCKSv5 parent over IPv6 network 04.09.2016 Releasing as 0.8.7 ! Fix 'daemon' command for Linux ! Fix 'extip' redirections 00009 errors ! Fix counters for older Win platforms ! Resolve logging race conditions ! attempt to fix pam_auth race conditions ! FTP proxy workaround for broken gethostname() on some libc limplementations ! authcache IP matching corrected ! fix SOCKSv5 BIND/UDP ASSOC ! use setreuid/setregid instead of setuid / setgid - OpenWatcom makefiles for Windows - -u2 support for proxy - support %i in logformat - force/noforce configuration commands to disconnect / do not disconnect clients if nolonger match ACL after configuration change - support longer external passwords Lite version of Windows binaries is switched to OpenWatcom. It will hopefully remove int64-related msvcrt.dll issues on old Windows versions. 07.03.2016 Releasing as 0.8.6 ! Fix: random 00012 errors in some configurations 02.03.2016 Releasing as 0.8.5 !Fix: mutex was used prior to initialization on 'log' command processing 28.02.2016 Releasing as 0.8.4 + Build PamPlugin on *nix - stacksize and -S options, stacksize defaults changed for FreeBSD - extip redirection type added ! SSL plugin fix to correct handling of certificates path ! fixed random errors on IPv6 connect 26.01.2016 Releasing as 0.8.3 ! fixed: use SASIZE() instead of sizeof() in connect() for FreeBSD compatibility 3proxy-0.8.3-lite.zip - Windows binaries, Lite version compatible with old Windows versions 3proxy-0.8.3.zip / 3proxy-0.8.3-x64.zip - 32/64 Windows binraries, compatible with Windows Vista / 2008 server and above 23.01.2016 Releasing as 0.8.2 !! Fix transparent flag not reset after keep-alive connection, can lead to DoS by authenticated user. ! Do not use SO_REUSEADDR by default (leads to random 00013 errors under some glibc versions) ! Use SASIZE() instead of sizeof() in bind() for FreeBSD compatibility 23.01.2016 Releasing as 0.7.1.4 !! Fix transparent flag not reset after keep-alive connection, can lead to DoS from authenticated user. 21.01.2016 Releasing as 0.8.1 !!Fix: destination IP may be not checked against ACL 19.01.2016 Releasing as 0.8.0 + IPv6 support - back connect support - name resolution over TCP, parent proxy support for dnspr ! multiple race conditions fixed ! reduced memory usage ! Generate Forwarded: header instead of X-Forwarded-For: ! Default name resolution is non-blocking in *nix Read HowTo for new functionality description Update from 0.7 is recommended if you use 3proxy under high load 12.01.2016 Releasing as 0.8-pre + IPv6 support - Connect back (reverse connect) proxy - DNS requests redirection via parent proxy over TCP (including UDP->TCP mapping) - SSLPlugin for TLS/SSL traffic decryption - multiple race conditions fixed on configuration reload 15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication15.09.2015 Releasing as 0.7.1.3 ! traffic displayed incorrectly ! archiver doesn't add suffix if logname contains macro ! fix potential race condition on configuration reload ! fix FTP over HTTP authentication
2018-02-19net/powerdns: Update to 4.1.1.fhajny2-7/+7
- Backport: forbid label compression in alias wire format - Include unistd.h for chroot(2) et al. - Auth: fix out of bounds exception in caa processing - Add the missing include to mplexer.hh for struct timeval - Auth: init openssl and libsodium before chrooting in pdnsutil - Auth: always bind the results array after executing a mysql statement - Ldap: fix getdomaininfo() to set this as di.backend - Ldapbackend: fix listing zones incl. axfr - Ixfr: correct behavior of dealing with dns name with multiple records
2018-02-18syncthing: update to 0.14.44.wiz2-7/+7
Bugfixes: #4634: Panic when connecting to device with auto accept and paused folders #4636: List of files needed on remote is not wrapped at word boundaries #4644: Impossible to run non-release builds without deadlock detectors #4649: UTF-8 normalization does not work correctly on ZFS. #4654: Upgrade system shows an error on RCs in some cases #4657: Sparse files with zero blocks are not closed when pulling #4668: Remote device out of sync items shows "0 items, ~0 B" Enhancements: #2599: GUI for .stversion restoration #4499: Log entries showing IP addresses should show connection type #4628: Set background priority / niceness Other issues: #4567: Arguments to fs.CreateSymlink are mixed up #4618: More scalable global discovery #4653: lib/model test fails with "ThreadSanitizer failed to allocate 0x200000 (2097152) bytes" with Go 1.9.2 #4663: Spurious "é" in GUI #4706: Should clean out generated testdata in lib/model/testdata
2018-02-18ruby-slack-api: update to 1.6.1.tsutsui3-8/+12
No upstream changelog.
2018-02-18ruby-public_suffix: update to 3.0.2.tsutsui2-7/+7
Upstream changelog (from CHANGELOG.md): #### Release 3.0.2 - CHANGED: Updated definitions. #### Release 3.0.1 - CHANGED: Updated definitions. - CHANGED: Improve performance and avoid allocation (GH-146). [Thanks @robholland]
2018-02-17gallery-dl: Update net/gallery-dl to 1.2.0leot4-19/+22
Changes: 1.2.0 ----- * Added support for: - `paheal` (#69) - `komikcast` (#70) - `subapics` (#70) * Added `--download-archive` to record downloaded files in an archive file * Added `--write-log` to write logging output to a file * Added a filetype check on download completion to fix incorrectly assigned filename extensions (#63) * Added the `tumblr:...` pseudo URI scheme to support custom domains for Tumblr blogs (#71) * Added fallback URLs for `tumblr` images (#64) * Added support for `reddit`-hosted images (#68) * Improved the input file format by allowing comments and per-URL options * Fixed OAuth 1.0 signature generation for Python 3.3 and 3.4 (#75) * Fixed smaller issues for `luscious`, `hentai2read`, `hentaihere` and `imgur` * Removed the `batoto` module
2018-02-17ruby-tw: update to 1.3.0.tsutsui2-7/+7
Upstream changes (from History.txt): === 1.3.0 2018-02-18 * 280 chars tweet (#75)
2018-02-16transmission*: fix build with openssl-1.1.wiz5-7/+123
From upstream via Peter Hjalmarsson via https://bugzilla.redhat.com/show_bug.cgi?id=1468077 Bump PKGREVISION.
2018-02-16py-awscli: updated to 1.14.40adam2-9/+9
1.14.40 api-change:gamelift: Update gamelift command to latest version api-change:mediaconvert: Update mediaconvert command to latest version 1.14.39 api-change:appsync: Update appsync command to latest version api-change:lex-models: Update lex-models command to latest version 1.14.38 api-change:route53: Update route53 command to latest version api-change:glacier: Update glacier command to latest version 1.14.37 api-change:cognito-idp: Update cognito-idp command to latest version api-change:ec2: Update ec2 command to latest version api-change:rds: Update rds command to latest version api-change:guardduty: Update guardduty command to latest version api-change:kms: Update kms command to latest version 1.14.36 api-change:lex-runtime: Update lex-runtime command to latest version api-change:ec2: Update ec2 command to latest version api-change:lex-models: Update lex-models command to latest version 1.14.35 api-change:budgets: Update budgets command to latest version api-change:gamelift: Update gamelift command to latest version api-change:ds: Update ds command to latest version api-change:mediastore: Update mediastore command to latest version api-change:appstream: Update appstream command to latest version api-change:dynamodb: Update dynamodb command to latest version api-change:medialive: Update medialive command to latest version api-change:dms: Update dms command to latest version
2018-02-16py-boto3: updated to 1.5.30adam2-8/+8
1.5.30 api-change:mediaconvert: [botocore] Update mediaconvert client to latest version api-change:gamelift: [botocore] Update gamelift client to latest version 1.5.29 api-change:appsync: [botocore] Update appsync client to latest version api-change:lex-models: [botocore] Update lex-models client to latest version 1.5.28 api-change:glacier: [botocore] Update glacier client to latest version api-change:route53: [botocore] Update route53 client to latest version 1.5.27 api-change:guardduty: [botocore] Update guardduty client to latest version api-change:cognito-idp: [botocore] Update cognito-idp client to latest version api-change:rds: [botocore] Update rds client to latest version api-change:ec2: [botocore] Update ec2 client to latest version api-change:kms: [botocore] Update kms client to latest version 1.5.26 api-change:lex-runtime: [botocore] Update lex-runtime client to latest version api-change:ec2: [botocore] Update ec2 client to latest version api-change:lex-models: [botocore] Update lex-models client to latest version 1.5.25 api-change:ds: [botocore] Update ds client to latest version api-change:appstream: [botocore] Update appstream client to latest version api-change:medialive: [botocore] Update medialive client to latest version api-change:budgets: [botocore] Update budgets client to latest version api-change:gamelift: [botocore] Update gamelift client to latest version api-change:dynamodb: [botocore] Update dynamodb client to latest version api-change:dms: [botocore] Update dms client to latest version api-change:mediastore: [botocore] Update mediastore client to latest version
2018-02-16py-s3transfer: updated to 0.1.13:adam2-7/+7
0.1.13 bugfix:RequestPayer: Plumb RequestPayer argument to the CompleteMultipartUpload operation
2018-02-16py-botocore: updated to 1.8.44adam3-254/+256
1.8.44 api-change:mediaconvert: Update mediaconvert client to latest version api-change:gamelift: Update gamelift client to latest version 1.8.43 api-change:appsync: Update appsync client to latest version api-change:lex-models: Update lex-models client to latest version 1.8.42 api-change:glacier: Update glacier client to latest version api-change:route53: Update route53 client to latest version 1.8.41 api-change:guardduty: Update guardduty client to latest version api-change:cognito-idp: Update cognito-idp client to latest version api-change:rds: Update rds client to latest version api-change:ec2: Update ec2 client to latest version api-change:kms: Update kms client to latest version 1.8.40 api-change:lex-runtime: Update lex-runtime client to latest version api-change:ec2: Update ec2 client to latest version api-change:lex-models: Update lex-models client to latest version 1.8.39 api-change:ds: Update ds client to latest version api-change:appstream: Update appstream client to latest version api-change:medialive: Update medialive client to latest version api-change:budgets: Update budgets client to latest version api-change:gamelift: Update gamelift client to latest version api-change:dynamodb: Update dynamodb client to latest version api-change:dms: Update dms client to latest version api-change:mediastore: Update mediastore client to latest version
2018-02-14haproxy: updated to 1.8.4adam2-16/+16
1.8.4 - BUG/MEDIUM: h2: properly handle the END_STREAM flag on empty DATA frames - BUILD: ssl: silence a warning when building without NPN nor ALPN support - BUG/MEDIUM: ssl: cache doesn't release shctx blocks - BUG/MINOR: lua: Fix default value for pattern in Socket.receive - DOC: lua: Fix typos in comments of hlua_socket_receive - BUG/MEDIUM: lua: Fix IPv6 with separate port support for Socket.connect - BUG/MINOR: lua: Fix return value of Socket.settimeout - MINOR: dns: Handle SRV record weight correctly. - BUG/MEDIUM: mworker: execvp failure depending on argv[0] - MINOR: hathreads: add support for gcc < 4.7 - BUILD/MINOR: ancient gcc versions atomic fix - BUG/MEDIUM: stream: properly handle client aborts during redispatch - DOC: clarify the scope of ssl_fc_is_resumed - CONTRIB: debug: fix a few flags definitions - BUG/MINOR: poll: too large size allocation for FD events - BUG/MEDIUM: peers: fix expire date wasn't updated if entry is modified remotely. - MINOR: servers: Don't report duplicate dyncookies for disabled servers. - MINOR: global/threads: move cpu_map at the end of the global struct - MINOR: threads: add a MAX_THREADS define instead of LONGBITS - MINOR: global: add some global activity counters to help debugging - MINOR: threads/fd: Use a bitfield to know if there are FDs for a thread in the FD cache - BUG/MEDIUM: threads/polling: Use fd_cache_mask instead of fd_cache_num - BUG/MEDIUM: fd: maintain a per-thread update mask - MINOR: fd: add a bitmask to indicate that an FD is known by the poller - BUG/MEDIUM: epoll/threads: use one epoll_fd per thread - BUG/MEDIUM: kqueue/threads: use one kqueue_fd per thread - BUG/MEDIUM: threads/mworker: fix a race on startup - BUG/MINOR: mworker: only write to pidfile if it exists - MINOR: threads: Fix build when we're not compiling with threads. - BUG/MINOR: threads: always set an owner to the thread_sync pipe - BUG/MEDIUM: threads/server: Fix deadlock in srv_set_stopping/srv_set_admin_flag - BUG/MEDIUM: checks: Don't try to release undefined conn_stream when a check is freed - BUG/MINOR: kqueue/threads: Don't forget to close kqueue_fd[tid] on each thread - MINOR: threads: Use __decl_hathreads instead of #ifdef/#endif - BUILD: epoll/threads: Add test on MAX_THREADS to avoid warnings when complied without threads - BUILD: kqueue/threads: Add test on MAX_THREADS to avoid warnings when complied without threads - CLEANUP: sample: Fix comment encoding of sample.c - CLEANUP: sample: Fix outdated comment about sample casts functions - BUG/MINOR: sample: Fix output type of c_ipv62ip - CLEANUP: Fix typo in ARGT_MSK6 comment - BUG/MINOR: cli: use global.maxsock and not maxfd to list all FDs - BUG/MINOR: threads: Update labels array because of changes in lock_label enum - BUG/MINOR: epoll/threads: only call epoll_ctl(DEL) on polled FDs - BUG/MEDIUM: spoe: Always try to receive or send the frame to detect shutdowns - BUG/MEDIUM: spoe: Allow producer to read and to forward shutdown on request side - BUG/MINOR: time/threads: ensure the adjusted time is always correct - BUG/MEDIUM: standard: Fix memory leak in str2ip2() - MINOR: init: emit warning when -sf/-sd cannot parse argument - DOC: Describe routing impact of using interface keyword on bind lines - DOC: Mention -Ws in the list of available options - BUG/MINOR: config: don't emit a warning when global stats is incompletely configured
2018-02-13Actually bump PKGREVISION for CVE-2017-1000232 as well.he1-2/+2
2018-02-13Apply fix for CVE-2017-1000232 fromhe3-4/+24
https://git.nlnetlabs.nl/ldns/commit/?id=3bdeed02 Also correct previous CVE, it's CVE-2017-100231... Bump PKGREVISION.
2018-02-13Apply fix for CVE-2017-10002, viahe3-3/+22
https://git.nlnetlabs.nl/ldns/commit/?id=c8391790 Bump PKGREVISION.
2018-02-13Fix RELRO buildryoon2-7/+11
2018-02-12net/Makefile: Add R-pbdZMQminskim1-1/+2
2018-02-12net/R-pbdZMQ: Import version 0.3.2minskim3-0/+39
This package provides high level R wrapper functions to easily utilize ZeroMQ. We mainly focus on interactive client/server programming frameworks. A few wrapper functions compatible with 'rzmq' are also provided.
2018-02-12Add some more protection against miscoded/corrupted OIDs.he3-6/+24
Bump PKGREVISION.
2018-02-11sysmon: comment out dead site.wiz1-3/+2
2018-02-11youtube-dl: Update net/youtube-dl to 20180208leot2-7/+7
Changes: version 2018.02.08 Extractors + [myvi] Extend URL regular expression + [myvi:embed] Add support for myvi.tv embeds (#15521) + [prosiebensat1] Extend URL regular expression (#15520) * [pokemon] Relax URL regular expression and extend title extraction (#15518) + [gameinformer] Use geo verification headers * [la7] Fix extraction (#15501, #15502) * [gameinformer] Fix brightcove id extraction (#15416) + [afreecatv] Pass referrer to video info request (#15507) + [telebruxelles] Add support for live streams * [telebruxelles] Relax URL regular expression * [telebruxelles] Fix extraction (#15504) * [extractor/common] Respect secure schemes in _extract_wowza_formats version 2018.02.04 Core * [downloader/http] Randomize HTTP chunk size + [downloader/http] Add ability to pass downloader options via info dict * [downloader/http] Fix 302 infinite loops by not reusing requests + Document http_chunk_size Extractors + [brightcove] Pass embed page URL as referrer (#15486) + [youtube] Enforce using chunked HTTP downloading for DASH formats version 2018.02.03 Core + Introduce --http-chunk-size for chunk-based HTTP downloading + Add support for IronPython * [downloader/ism] Fix Python 3.2 support Extractors * [redbulltv] Fix extraction (#15481) * [redtube] Fix metadata extraction (#15472) * [pladform] Respect platform id and extract HLS formats (#15468) - [rtlnl] Remove progressive formats (#15459) * [6play] Do no modify asset URLs with a token (#15248) * [nationalgeographic] Relax URL regular expression * [dplay] Relax URL regular expression (#15458) * [cbsinteractive] Fix data extraction (#15451) + [amcnetworks] Add support for sundancetv.com (#9260)
2018-02-10mikutter: update to 3.6.3.tsutsui2-7/+7
Upstream changes: mikutter 3.6.3 * "reply" of mikutter commands doesn't appear in non Twitter Worlds * crashed on registrating already registered World again * fix use of deperecated methods of Pango (thanks: akkiesoft)
2018-02-09vsftpd: updated to 3.0.3triaxx7-48/+59
v2.3.5 ====== - Try and force glibc to cache zoneinfo files in an attempt to work around glibc parsing vulnerability. Thanks to Kingcope. - Only report CHMOD in SITE HELP if it's enabled. Thanks to Martin Schwenke <martin@meltin.net>. - Some simple fixes and cleanups from Thorsten Brehm <tbrehm@dspace.de>. - Only advertise "AUTH SSL" if one of SSLv2, SSLv3 is enabled. Thanks to steve willing <eiji-gravion@hotmail.com>. - Handle connect() failures properly. Thanks to Takayuki Nagata <tnagata@redhat.com>. - Add stronger checks for the configuration error of running with a writeable root directory inside a chroot(). This may bite people who carelessly turned on chroot_local_user but such is life. v3.0.0 ====== - Update vsf_findlibs.sh to work on Ubuntu 11.10+ - Make listen mode the default. - Add -Werror to build flags. - Fix missing "const" in ssl.c - Add seccompsandbox.c to support a seccomp filter sandbox; works against Ubuntu 12.04 ABI. - Rearrange ftppolicy.c a bit so the syscall list is easily comparable with seccompsandbox.c - Rename deprecated "sandbox" to "ptrace_sandbox". - Add a few more state checks to the privileged helper processes. - Add tunable "seccomp_sandbox", default on. - Use hardened build flags. Distros of course override these and provide their own build flags but no harm in showing how it could be done. - Retry creating a PASV socket upon port reuse race between bind() and listen(), patch from Ralph Wuerthner <ralph.wuerthner@de.ibm.com>. - Don't die() if recv() indicates a closed remote connection. Problem report on a Windows client from Herbert van den Bergh, <herbert.van.den.bergh@oracle.com>. - Add new config setting "allow_writeable_chroot" to help people in a bit of a spot with the v2.3.5 defensive change. Only applies to non-anonymous. - Remove a couple of fixed things from BUGS. - strlen() trunction fix -- no particular impact. - Apply some tidyups from mmoufid@yorku.ca. (vsftpd-3.0.0-pre1) - Fix delete_failed_uploads if there is a timeout. Report from Alejandro Hernández Hdez <aalejandrohdez@gmail.com>. - Fix other data channel bugs such as failure to log failure upon timeout. - Use exit codes a bit more consistently. - Fix bad interaction between SSL and trans_chunk_size. - Redo data timeout to fire properly for SSL sessions. - Redo idle timeout to fire properly for SSL sessions. - Make sure PROT_EXEC isn't allowed, thanks to Will Drewry for noticing. - Use 10 minutes as a max linger time just in case an alarm gets lost. (vsftpd-3.0.0-pre2) - Change PR_SET_NO_NEW_PRIVS define, from Kees Cook. - Add AES128-SHA to default SSL cipher suites for FileZilla compatibility. Unfortunately the default vsftpd SSL confiuration still doesn't fully work with FileZilla, because FileZilla has a data connection security problem: no client certificate presentation and no session reuse. At least the error message is now very clear. - Add restart_syscall to seccomp policy. Triggers reliably if you strace whilst a data transfer is in progress. - Fix delete_failed_uploads for anonymous sessions. - Don't listen for urgent data if the control connection is SSL, due to possible protocol synchronization issues. v3.0.1 ====== - Fix some seccomp related build errors on certain CentOS and Debian versions. - Seccomp filter sandbox: missing munmap() -- oops. Did you know that qsort() opens and maps /proc/meminfo but only for larger item counts? - Seccomp filter sandbox: deny socket() gracefully for text_userdb_names. - Fix various NULL crashes with nonsensical config settings. Noted by Tianyin Xu <tixu@cs.ucsd.edu>. - Force cast to unsigned char in is* char functions. - Fix harmless integer issues in strlist.c. - Started on a (possibly ill-advised?) crusade to compile cleanly with Wconversion. Decided to suspend the effort half-way through. v3.0.2 ====== - One more seccomp policy fix: mremap (denied). - Support STOU with no filename, uses a STOU. prefix. v3.0.3 ====== - Increase VSFTP_AS_LIMIT to 200MB; various reports. - Make the PWD response more RFC compliant; report from Barry Kelly <barry@modeltwozero.com>. - Remove the trailing period from EPSV response to work around BT Internet issues; report from Tim Bishop <tdb@mirrorservice.org>. - Fix syslog_enable issues vs. seccomp filtering. Report from Michal Vyskocil <mvyskocil@suse.cz>. At least, syslogging seems to work on my Fedora now. - Allow gettimeofday() in the seccomp sandbox. I can't repro failures, but I probably have a different distro / libc / etc. and there are multiple reports. - Some kernels support PR_SET_NO_NEW_PRIVS but not PR_SET_SECCOMP, so handle this case gracefully. Report from Vasily Averin <vvs@odin.com>. - List the TLS1.2 cipher AES128-GCM-SHA256 as first preference by default. - Make some compile-time SSL defaults (such as correct client shutdown handling) stricter. - Disable Nagle algorithm during SSL data connection shutdown, to avoid 200ms delays. From Tim Kosse <tim.kosse@filezilla-project.org>. - Kill the FTP session if we see HTTP protocol commands, to avoid cross-protocol attacks. A report from Jann Horn <jann@thejh.net>. - Kill the FTP session if we see session re-use failure. A report from Tim Kosse <tim.kosse@filezilla-project.org>. (vsftpd-3.0.3pre1) - Enable ECDHE, Tim Kosse <tim.kosse@filezilla-project.org>. - Default cipher list is now just ECDHE-RSA-AES256-GCM-SHA384. - Minor SSL logging improvements. - Un-default tunable_strict_ssl_write_shutdown again. We still have tunable_strict_ssl_read_eof defaulted now, which is the important one to prove upload integrity. (vsftpd-3.0.3pre2)
2018-02-08haproxy: Use C99.jperkin3-6/+17
2018-02-08mikutter: update to 3.6.2.tsutsui3-8/+60
Upstream changes: mikutter 3.6.2 * update translations * cannot send a carsh report but gets Segmentation Fault on crash during a Gtk event callback * crash when plugins written for 3.4 and prior try to access nonexistent images * crash on opening a URL using an external browser on Windows
2018-02-08net/bind910: Fix problem in configure where contents of $LIBS wouldfhajny2-5/+5
be lost when json-c support was enabled.
2018-02-07kde: SUBST_STAGE should be pre-configure, not post-patch.jperkin1-2/+2
Performing substitutions during *-patch phases makes it impossible to generate patches via mkpatches without introducing substitution noise.
2018-02-03Add a package for py-gcs-oauth2-boto-plugin.bsiegert5-1/+62
gcs-oauth2-boto-plugin is a Python application whose purpose is to behave as an auth plugin for the boto auth plugin framework for use with OAuth 2.0 credentials for the Google Cloud Platform. This plugin is compatible with both user accounts and service accounts, and its functionality is essentially a wrapper around oauth2client with the addition of automatically caching tokens for the machine in a thread- and process-safe fashion. Part of PR pkg/52941.
2018-02-02Update net/rabbitmq to 3.7.3.fhajny4-9/+28
- Bug fixes - Usability improvements Full release notes: https://github.com/rabbitmq/rabbitmq-server/releases/tag/v3.7.3
2018-02-02libbind: Fix SunOS/clang.jperkin2-1/+17
2018-02-02net/py-lexicon: Update to 2.1.19.fhajny4-28/+11
2.1.19 - Rackspace CloudDNS provider 2.1.18 - Make namecheap provider (and dependency) optional
2018-02-02Um, when backing out local patch, also back out distinfo checksum...he1-2/+2
2018-02-02Add a patch which does minimal validation when decoding OIDs.he3-6/+19
Bump PKGREVISION.
2018-02-02lldpd: Leave pkgsrc to handle security features.jperkin1-1/+3
2018-02-02arp-scan: Leave pkgsrc to handle security features.jperkin2-1/+17
2018-02-02istgt: Leave pkgsrc to handle security features.jperkin2-1/+17
2018-02-02sipsak: Leave pkgsrc to handle security features.jperkin2-7/+18
2018-02-02sysmon: Leave pkgsrc to handle security features.jperkin2-1/+17
2018-02-02haproxy: updated to 1.8.3adam2-7/+7
1.8.3: - BUG/MEDIUM: h2: properly handle and report some stream errors - BUG/MEDIUM: h2: improve handling of frames received on closed streams - DOC/MINOR: configuration: typo, formatting fixes - BUG/MEDIUM: h2: ensure we always know the stream before sending a reset - BUG/MEDIUM: mworker: don't close stdio several time - MINOR: don't close stdio anymore - BUG/MEDIUM: http: don't automatically forward request close - BUG/MAJOR: hpack: don't return direct references to the dynamic headers table - MEDIUM: h2: prepare a graceful shutdown when the frontend is stopped 1.8.2: - BUG/MINOR: action: Don't check http capture rules when no id is defined - BUG/MAJOR: hpack: don't pretend large headers fit in empty table - BUG/MINOR: ssl: support tune.ssl.cachesize 0 again - BUG/MEDIUM: mworker: also close peers sockets in the master - BUG/MEDIUM: ssl engines: Fix async engines fds were not considered to fix fd limit automatically. - BUG/MEDIUM: checks: a down server going to maint remains definitely stucked on down state. - BUG/MEDIUM: peers: set NOLINGER on the outgoing stream interface - BUG/MEDIUM: h2: fix handling of end of stream again - MINOR: mworker: Update messages referencing exit-on-failure - MINOR: mworker: Improve wording in `void mworker_wait()` - CONTRIB: halog: Add help text for -s switch in halog program - BUG/MEDIUM: email-alert: don't set server check status from a email-alert task - BUG/MEDIUM: threads/vars: Fix deadlock in register_name - MINOR: systemd: remove comment about HAPROXY_STATS_SOCKET - DOC: notifications: add precisions about thread usage - BUG/MEDIUM: lua/notification: memory leak - MINOR: conn_stream: add new flag CS_FL_RCV_MORE to indicate pending data - BUG/MEDIUM: stream-int: always set SI_FL_WAIT_ROOM on CS_FL_RCV_MORE - BUG/MEDIUM: h2: automatically set CS_FL_RCV_MORE when the output buffer is full - BUG/MEDIUM: h2: enable recv polling whenever demuxing is possible - BUG/MEDIUM: h2: work around a connection API limitation - BUG/MEDIUM: h2: debug incoming traffic in h2_wake() - MINOR: h2: store the demux padding length in the h2c struct - BUG/MEDIUM: h2: support uploading partial DATA frames - MINOR: h2: don't demand that a DATA frame is complete before processing it - BUG/MEDIUM: h2: don't switch the state to HREM before end of DATA frame - BUG/MEDIUM: h2: don't close after the first DATA frame on tunnelled responses - BUG/MEDIUM: http: don't disable lingering on requests with tunnelled responses - BUG/MEDIUM: h2: fix stream limit enforcement - BUG/MINOR: stream-int: don't try to receive again after receiving an EOS - BUG: MAJOR: lb_map: server map calculation broken - BUG: MINOR: http: don't check http-request capture id when len is provided - BUILD/MINOR: Makefile : enabling USE_CPU_AFFINITY - BUG/MEDIUM: mworker: Set FD_CLOEXEC flag on log fd - DOC/MINOR: intro: typo, wording, formatting fixes - MINOR: netscaler: respect syntax - MINOR: netscaler: remove the use of cip_magic only used once - MINOR: netscaler: rename cip_len to clarify its uage - BUG/MEDIUM: netscaler: use the appropriate IPv6 header size - BUG/MAJOR: netscaler: address truncated CIP header detection - CONTRIB: iprange: Fix compiler warning in iprange.c - CONTRIB: halog: Fix compiler warnings in halog.c - BUG/MINOR: h2: properly report a stream error on RST_STREAM - MINOR: mux: add flags to describe a mux's capabilities - MINOR: stream-int: set flag SI_FL_CLEAN_ABRT when mux supports clean aborts - BUG/MEDIUM: stream: don't consider abortonclose on muxes which close cleanly - MINOR: netscaler: check in one-shot if buffer is large enough for IP and TCP header - MEDIUM: netscaler: do not analyze original IP packet size - MEDIUM: netscaler: add support for standard NetScaler CIP protocol - BUG/MEDIUM: checks: a server passed in maint state was not forced down. - BUG/MEDIUM: lua: fix crash when using bogus mode in register_service() - MINOR: http: adjust the list of supposedly cacheable methods - MINOR: http: update the list of cacheable status codes as per RFC7231 - MINOR: http: start to compute the transaction's cacheability from the request - BUG/MINOR: http: do not ignore cache-control: public - BUG/MINOR: http: properly detect max-age=0 and s-maxage=0 in responses - BUG/MINOR: cache: do not force the TX_CACHEABLE flag before checking cacheability - MINOR: http: add a function to check request's cache-control header field - BUG/MEDIUM: cache: do not try to retrieve host-less requests from the cache - BUG/MEDIUM: cache: replace old object on store - BUG/MEDIUM: cache: respect the request cache-control header - BUG/MEDIUM: cache: don't cache the response on no-cache="set-cookie" - BUG/MAJOR: connection: refine the situations where we don't send shutw() - BUG/MEDIUM: checks: properly set servers to stopping state on 404
2018-02-02powerdns: Leave pkgsrc to handle security features.jperkin2-3/+13
2018-02-01php-sockets: Support newer GCC and clang on SunOS.jperkin1-1/+8
2018-01-31py-zeep: updated to 2.5.0adam3-13/+20
2.5.0: - Fix AnyType value rendering by guessing the xsd type for the value - Fix AnySimpleType.xmlvalue() not implemented exception - Add __dir__ method to value objects returned by Zeep - Don't require content for 201 and 202 status codes - Fix wheel package by cleaning the build directory correctly - Handle Nil values on complexType with SimpleContent elements - Add Client.namespaces method to list all namespaces available - Improve support for auto-completion
2018-01-30knewstuff: SUBST rather than patchmarkd3-17/+8
2018-01-29rsync: updated to 3.1.3adam8-157/+28
Changes since 3.1.2: SECURITY FIXES: - Fixed a buffer overrun in the protocol's handling of xattr names and ensure that the received name is null terminated. - Fix an issue with --protect-args where the user could specify the arg in the protected-arg list and short-circuit some of the arg-sanitizing code. BUG FIXES: - Don't output about a new backup dir without appropriate info verbosity. - Fixed some issues with the sort functions in support/rsyncstats script. - Added a way to specify daemon config lists (e.g. users, groups, etc) that contain spaces (see "auth users" in the latest rsyncd.conf manpage). - If a backup fails (e.g. full disk) rsync exits with an error. - Fixed a problem with a doubled --fuzzy option combined with --link-dest. - Avoid invalid output in the summary if either the start or end time had an error. - We don't allow a popt alias to affect the --daemon or --server options. - Fix daemon exclude code to disallow attribute changes in addition to disallowing transfers. - Don't force nanoseconds to match if a non-transferred, non-checksummed file only passed the quick-check w/o comparing nanosecods. ENHANCEMENTS: - Added the ability for rsync to compare nanosecond times in its file-check comparisons, and added support nanosecond times on Mac OS X. - Added a short-option (-@) for --modify-window. - Added the --checksum-choice=NAME[,NAME] option to choose the checksum algorithms. - Added hashing of xattr names (with using -X) to improve the handling of files with large numbers of xattrs. - Added a way to filter xattr names using include/exclude/filter rules (see the --xattrs option in the manpage for details). - Added "daemon chroot|uid|gid" to the daemon config (in addition to the old chroot|uid|gid settings that affect the daemon's transfer process). - Added "syslog tag" to the daemon configuration. - Some manpage improvements. DEVELOPER RELATED: - Tweak the "make" output when yodl isn't around to create the man pages. - Changed an obsolete autoconf compile macro. - Support newer yodl versions when converting man pages.
2018-01-29Import dhcpcd-7.0.1 with the following changes:roy2-7/+7
* hooks: remove use of local builtin for better portability * Fix build issue when `__GNUC__ <= 2` (thanks to Chris Hathhorn) * dhcpcd: don't log errors working out carrier for departed interfaces * ipv4: allow configuration of static broadcast address * if: don't set MTU during interface discovery * if: don't activate non matching interfaces to commandline ones * configure: make `--includedir=/usr/src/foo` work * eloop-bench: fix hangs when using a large number of cycles * dhcp: don't bind when we've just probed an address to inform
2018-01-28Bump PKGREVISION for gdbm shlib major bumpwiz38-73/+76
2018-01-28gstreamer1 + plugins: update to 1.12.4wiz1-2/+1
### 1.12.4 The fourth 1.12 bug-fix release (1.12.4) was released on 7 December 2017. This release only contains bugfixes and it should be safe to update from 1.12.x. #### Major bugfixes in 1.12.4 - Dozens of fixes for various issues detected with the help of Google's OSS-Fuzz project: https://github.com/google/oss-fuzz Details to be found there in the bug tracker - Performance regressions with registering debug categories after gst_init() were fixed - Regression with seeking back to 0 in souphttpsrc was fixed - Regression with header rewriting in flacparse was fixed - Regression with playbin/playsink leaking sinks was fixed - Inconsistencies with DROPPED/HANDLED handling in pad probe handlers are fixed - gst_bin_iterate_sorted() always returns sources last now, as documented - gst_query_writable_structure() will never return NULL, for consistency with events - Removal of metas from gst_buffer_meta_foreach() works correctly now - OpenJPEG plugin builds with OpenJPEG >= 2.3 - CDIO plugin builds with CDIO >= 1.0 - gstreamer-vaapi works correctly with libva 1.0 - gst-libav was updated to ffmpeg 3.3.5 - Various fixes for memory leaks, deadlocks and crashes in all modules - ... and many, many more!
2018-01-28libsoup: update to 2.60.3.wiz2-8/+7
Changes in libsoup from 2.60.2 to 2.60.3: * heap-buffer-overflow in soup_ntlm_parse_challenge() [#788037, Milan Crha] * session: don't request Keep-Alive for upgraded connections [#788723, Lionel Landwerlin] * soup-headers: accept any 3 digit number as message status code [#792124, Carlos Garcia Campos]
2018-01-28filezilla: update to 3.30.0.wiz2-8/+7
3.30.0 (2018-01-08) - Add additional logging if autoupdate mechanism fails 3.30.0-rc1 (2017-12-29) + In the search dialog local files can now be deleted or opened + The root node in the remote directory tree is now expanded by default - Fix uploading from search dialog - Fix formatting of filename in rename dialog - MSW: Fix installer crash if an update installation is started with the updated version having been installed