Commit graph

434453 commits

Author SHA1 Message Date
Lars Engels
d00eea93a2 MFH: r459728
net-mgmt/icingaweb2:

Update to 2.5.1 (Mostly bugfixes)

Changelog: https://github.com/Icinga/icingaweb2/milestone/47?closed=1

Approved by:	portmgr (swills)
2018-01-23 16:02:52 +00:00
Kirill Ponomarev
b6db1cc997 Fix previous commit with mfh.
Approved by:	ports-secteam
2018-01-23 15:52:45 +00:00
Kirill Ponomarev
8107eaebc2 MFH: r459742
Update to version 4.1.1

- Fixes "PowerDNS Security Advisory 2018-01: Insufficient validation
  of DNSSEC signatures". An issue has been found in the DNSSEC
  validation component of PowerDNS Recursor, allowing an ancestor
  delegation NSEC or NSEC3 record to be used to wrongfully prove the
  non-existence of a RR below the owner name of that record. This
  would allow an attacker in position of man-in-the-middle to send a
  NXDOMAIN answer for a name that does exist.
  The 4.0.x branch is not vulnerable.

- Add support for algo16 and simplify Lua/LuaJIT engine choice.

PR:		225397
Submitted by:	maintainer
Security:	CVE-2018-1000003

Approved by:	ports-secteam
2018-01-23 15:45:26 +00:00
Guido Falsi
68c97ff276 MFH: r459693
Import code from mousepad development repository which fixes a dbus
messages storm causing heavy CPU usage, memory allocation and disk
usage when working with multiple windows.

While here also import a GTK3 specific fix.

Ref.:
https://bugzilla.xfce.org/show_bug.cgi?id=14184
https://bugzilla.xfce.org/show_bug.cgi?id=12134

Reported by:	Erich Dollansky <freebsd.ed.lists@sumeritec.com>
Obtained from:	https://git.xfce.org/apps/mousepad/

Approved by:	ports-secteam (swills)
2018-01-23 13:10:32 +00:00
Jan Beich
3d9e079705 MFH: r458997
x11-drivers/xf86-video-intel: update to 2.99.917.20180111

Changes:	https://cgit.freedesktop.org/xorg/driver/xf86-video-intel/log/?id=26f5406841f3
PR:		224621
Approved by:	maintainer timeout (2 weeks)
Approved by:	ports-secteam (swills)
2018-01-23 01:00:30 +00:00
Jan Beich
8ecd7a1fe9 MFH: r459717
emulators/citra: update to s20180122

Changes:	bf4e35b9...0e8c25fd
Approved by:	ports-secteam (swills, implicit for snapshots)
2018-01-23 00:52:40 +00:00
Jan Beich
4767702132 MFH: r459713
emulators/rpcs3: update to 0.0.4.275

Changes:	f908daf32...4f0179471
Approved by:	ports-secteam (junovitch, implicit for snapshots)
2018-01-23 00:35:21 +00:00
Jan Beich
03f25078a2 MFH: r459118 r459392
www/firefox: update to 58.0

Changes:	https://www.mozilla.org/firefox/58.0/releasenotes/
PR:		223425
Tested by:	Greg V, tobik
Security:	a891c5b4-3d7a-4de9-9c71-eef3fd698c77
Approved by:	ports-secteam (swills)
2018-01-23 00:02:59 +00:00
Jan Beich
b557a22b05 MFH: r459304 r459393
www/firefox-esr: update to 52.6.0

Changes:	https://www.mozilla.org/firefox/52.6.0/releasenotes/
Security:	a891c5b4-3d7a-4de9-9c71-eef3fd698c77
Approved by:	ports-secteam (swills)
2018-01-23 00:01:36 +00:00
Josh Paetzel
de9f55b885 MFH: r457864
Fix build with clang 6.0.0

Also avoids an endless loop in practice

PR:	224816
Submitted by:	dim

Approved by:	ports-secteam (swills)
2018-01-22 20:27:01 +00:00
Lars Engels
18e2956d44 MFH: r459410
net-mgmt/icinga2:

Update to 2.8.1
Changelog: https://github.com/Icinga/icinga2/blob/master/CHANGELOG.md

Approved by:	portmgr (swills)
2018-01-21 19:00:37 +00:00
Sunpoet Po-Chuan Hsieh
2acefb5955 MFH: r459349
Remove BROKEN, DEPRECATED and EXPIRATION_DATE

This port builds fine in poudriere.
This port depends on py-twisted and py-twistedCore has been removed from ports tree.

Approved by:	ports-secteam (swills)
2018-01-20 08:34:32 +00:00
Ben Woods
a2389f045c MFH: r459011 r459013 r459492
net-p2p/transmission-daemon: Mitigate DNS rebinding attack

Incorporate upstream pull request 468, proposed by Tavis Ormandy from
Google Project Zero, which mitigates this attack by requiring a host
whitelist for requests that cannot be proven to be secure, but it can
be disabled if a user does not want security.

PR:		225150
Submitted by:	Tavis Ormandy
Approved by:	crees (maintainer)
Obtained from:	https://github.com/transmission/transmission/pull/468#issuecomment-357098126
Security:	https://www.vuxml.org/freebsd/3e5b8bd3-0c32-452f-a60e-beab7b762351.html

Add note to UPDATING for net-p2p/transmission-daemon explaining how to
allow client access with the new DNS rebinding mitigations.

PR:		225150
Security:	https://www.vuxml.org/freebsd/3e5b8bd3-0c32-452f-a60e-beab7b762351.html

net-p2p/transmission-daemon: Improve UPDATING entry and add pkg-message

This will ensure users who do not read UPDATING are still presented with
the message about how to allow clients to connect to the daemon using
DNS when they upgrade the package.

PR:		225150
Reported by:	swills
Security:	https://www.vuxml.org/freebsd/3e5b8bd3-0c32-452f-a60e-beab7b762351.html

Approved by:	ports-secteam (swills)
2018-01-20 01:28:56 +00:00
Jan Beich
6739b20a60 MFH: r459487
emulators/citra: update to s20180119

Changes:	93cca23d...bf4e35b9
Approved by:	ports-secteam (swills, implicit for snapshots)
2018-01-20 00:25:19 +00:00
Jan Beich
66626cb559 MFH: r459488
emulators/rpcs3: update to 0.0.4.270

Changes:	71f69d1d4...f908daf32
Approved by:	ports-secteam (junovitch, implicit for snapshots)
2018-01-20 00:23:58 +00:00
Steve Wills
0258aea96c Merge missed commit needed by r459482
MFH: r458139

security/rubygem-rbnacl4: create port

4.x version required by gitlab

PR:		224931
Submitted by:	Matthias Fechner <idefix@fechner.net> (maintainer)

Approved by:	ports-secteam (implicit)
2018-01-19 23:32:30 +00:00
Steve Wills
2f446f5a98 Pull in GitLab security update and all commits needed for it to run properly
Approved by:	ports-secteam (implicit)

MFH: r457863 r457866 r457872 r457873 r457876 r457879 r457890 r457898 r457899 r458098 r458142 r458267 r458333 r458634 r458650 r458652 r459076 r459170 r459191 r459256 r459284 r459288 r459346

textproc/rubygem-twitter-text: add required dependency on rubygem-idn-ruby

PR:		224838
Submitted by:	Matthias Fechner <idefix@fechner.net>

www/gitlab: fix Gemfile for updated dependencies

PR:		224836
Submitted by:	Matthias Fechner <idefix@fechner.net> (maintainer)

Add rubygem-redis3 3.3.5 (copied from rubygem-redis)

- Add PORTSCOUT

Add rubygem-jwt1 1.5.6 (copied from rubygem-jwt)

- Add PORTSCOUT

Update to 4.0.1

Changes:	https://github.com/redis/redis-rb/blob/master/CHANGELOG.md

Update to 2.1.0

Changes:	https://github.com/jwt/ruby-jwt/releases

Change RUN_DEPENDS from rubygem-redis and rubygem-jwt to rubygem-redis3 and rubygem-jwt1

- Bump PORTREVISION for dependency change

devel/rubygem-licensee: update to 9.6.0

PR:		224758
Approved by:	Matthias Fechner <idefix@fechner.net> (maintainer

www/gitlab: remove spurious newline

Reported by:	sunpoet
Pointyhat to:	swills

security/rubygem-rbnacl: update to 5.0.0

www/gitlab: fix Gemfile for updated dependencies

PR:		224932
Submitted by:	Matthias Fechner <idefix@fechner.net> (maintainer)

Fix Gemfile for rubygem-fog-core 2.0.0 update

- Bump PORTREVISION for package change

Fix Gemfile for rubygem-jquery-atwho-rails 1.5.4 update

- Bump PORTREVISION for package change

Fix Gemfile for rubygem-fog-google 1.0.0 update

- Bump PORTREVISION for package change

Fix gitlab issue by creating rubygem-licensee8

PR:		225047
Submitted by:	Matthias Fechner <idefix@fechner.net> (maintainer)

devel/rubygem-licensee: update to 9.7.0

PR:		224999
Approved by:	Matthias Fechner <idefix@fechner.net> (maintainer)

textproc/rubygem-rouge: update to 3.1.0

PR:		224785
Approved by:	maintainer timeout (kuriyama, > 2 weeks)

textproc/rubygem-rouge2: create port for 2.x ver

Needed by GitLab

textproc/rubygem-rouge2: add missing PKGNAMESUFFIX

Pointyhat to:	swills
Reported by:	antoine

textproc/rubygem-rouge2: add conflict

www/rubygem-gollum-lib: depend on 2.x version of rouge

This version is required by gollum-lib

www/gitlab: update to 10.1.6

Approved by:	idefix@fechner.net (maintainer, via private email)
Obtained from:	http://gitlab.toco-domains.de/FreeBSD/GitLab/commits/10.1
Security:	65fab89f-2231-46db-8541-978f4e87f32a

Mark CONFLICTS_INSTALL with rubygems-rouge2
2018-01-19 23:03:40 +00:00
Thomas Zander
be8ec228aa MFH: r458963
Update to upstream version 0.20.15 (bug fix release)

Detailed changelog:
http://git.musicpd.org/cgit/master/mpd.git/plain/NEWS?h=v0.20.15

PR:		225115
Submitted by:	dg@syrec.org

Approved by:	ports-secteam (swills)
2018-01-19 22:32:34 +00:00
Thomas Zander
1827fa3ee1 MFH: r458965
Update to upstream release 0.5.70 (update scrapers for several countries)

PR:		225039
Submitted by:	tad@vif.com

Approved by:	ports-secteam (swills)
2018-01-19 22:29:53 +00:00
Bernard Spil
b43cc25706 MFH: r459413
databases/mariadb55-server: Security update to 5.5.59

Security:	e3445736-fd01-11e7-ac58-b499baebfeaf
Security:	CVE-2018-2562
Security:	CVE-2018-2622
Security:	CVE-2018-2640
Security:	CVE-2018-2665
Security:	CVE-2018-2668

Approved by:	ports-secteam (swills)
2018-01-19 20:17:58 +00:00
Jochen Neumeister
cff7ff0eaf MFH: r459414
Securityupdate to 3.2.2:

Changelog:
 https://wiki.phpbb.com/Release_Highlights/3.2.2
 https://www.phpbb.com/community/viewtopic.php?f=14&t=2453381

Approved by:	mentors (implicit)
Security:	8e89a89a-fd15-11e7-bdf6-00e04c1ea73d

Approved by:	ports-secteam (swills)
2018-01-19 19:54:09 +00:00
Tobias Kortkamp
eba12ec0a2 MFH: r458934
astro/viking: Fix LIB_DEPENDS and unbreak port

- While here reset MAINTAINER: The port has been marked as broken
  since 2017-05-10 and the maintainer has a history of timeouts.

PR:		224668
Submitted by:	Ting-Wei Lan <lantw44@gmail.com>
Approved by:	koalative@gmail.com (maintainer timeout, 2 weeks)

Approved by:	ports-secteam (swills)
2018-01-19 19:23:05 +00:00
Tobias Kortkamp
81df881fc8 MFH: r459034
www/youtube_dl: Update to 2018.01.14

PR:		225157
Approved by:	araujo (maintainer)

Approved by:	ports-secteam (swills)
2018-01-19 19:21:48 +00:00
Jan Beich
1b5d329b02 MFH: r459037
devel/renpy: update to 6.99.14

Changes:	https://www.renpy.org/doc/html/changelog.html#ren-py-6-99-14
Approved by:	ports-secteam (swills)
2018-01-19 18:56:42 +00:00
Danilo G. Baio
140e5d6173 MFH: r459435
dns/unbound: Update to 1.6.8, Fixes security vulnerability

PR:		225313
Submitted by:	jaap@NLnetLabs.nl (maintainer)
Security:	8d3bae09-fd28-11e7-95f2-005056925db4

Approved by:	ports-secteam (swills)
2018-01-19 18:06:11 +00:00
Kurt Jaeger
af396d7afe MFH: r458856
security/trousers: fix distinfo

- see the PR for the diff between the two distfiles

PR:		221105
Approved by:	hrs (maintainer timeout)
Approved by:	portmgr
2018-01-19 17:28:55 +00:00
Jochen Neumeister
2edc3208c9 MFH: r459399
Securityupdate to 4.9.2:

Changelog:
 https://codex.wordpress.org/Version_4.9.2
 https://wordpress.org/news/2018/01/wordpress-4-9-2-security-and-maintenance-release/

PR:		225243
Submitted by:	Mikhail Timofeev <9267096@gmail.com> (maintainer)
Approved by:	mentors (implicit)
Security:	c04dc18f-fcde-11e7-bdf6-00e04c1ea73d

Approved by:	ports-secteam (swills)
2018-01-19 15:50:21 +00:00
Jochen Neumeister
56683c65fd MFH: r459400
Securityupdate to 4.9.2:

Changelog:
 https://codex.wordpress.org/Version_4.9.2
 https://wordpress.org/news/2018/01/wordpress-4-9-2-security-and-maintenance-release/

Approved by:	mentors (implicit)
Security:	c04dc18f-fcde-11e7-bdf6-00e04c1ea73d

Approved by:	ports-secteam (swills)
2018-01-19 15:49:13 +00:00
Mark Felder
508b0f2fd3 MFH: r459420
databases/memcached: Fix user/group handling for running process

You can now set memcached_user and memcached_group in rc.conf and get
expected results of running process and socket ownership.

Differential Revision:	https://reviews.freebsd.org/D13967
2018-01-19 14:34:31 +00:00
Mark Felder
4489026e63 MFH: r459417
net-mgmt/librenms: Upstream re-rolled the distfile

Only change is the doc/General/Changelog.md file which *removed* the entry
for 1.35.
2018-01-19 14:26:47 +00:00
Mathieu Arnold
5ae6b5d8f1 MFH: r459406
Update named.root.

Sponsored by:	People afraid of a nuclear holocaust.
2018-01-19 12:33:27 +00:00
Jan Beich
c8a6639351 MFH: r459394
www/waterfox: apply more FF58 fixes

Security:	a891c5b4-3d7a-4de9-9c71-eef3fd698c77
Approved by:	ports-secteam blanket
2018-01-19 05:01:12 +00:00
Mark Felder
1e743bfc00 MFH: r459377
net-mgmt/librenms: Fix build

Leftover change crept into last commit
2018-01-18 20:47:49 +00:00
Mark Felder
852bb3581d MFH: r458431
databases/py-MySQLdb only supports Python 2, restrict ports that uses it.

Sponsored by:	Absolight
2018-01-18 20:27:37 +00:00
Mark Felder
c7794c96e4 MFH: r459372
net-mgmt/librenms: Update to 1.35, many improvements

Improvements:

-    All files should be owned root:wheel except logs and rrd which need to be writable by the app
-    Add missing php posix extension
-    Do not install config.php by default. This breaks the install process which won't run if this file exists
-    Clean up automatic PLIST creation: don't install .orig or .bak files, don't add @dir as they aren't needed
-    Patch LibreNMS to make /validate/ page not produce warnings about files not being writable (for git updates)
-    Remove the Updates validation check altogether as we won't be using git to update
-    Patch the User validation check to only check the logs and rrd dir and ensure the correct user owns them
-    Change the default user in the generated config to "www"
-    Patch the File Lock code to put the lock file in /tmp and not in the WWWDIR which should not be writable
-    Update message in installer to use WWWDIR as suggested path for config.php
-    Use shebangfix instead of patch where applicable
-    Fix APACHEMOD port option and declaration of the USES=php

PR:		225161
Differential Revision:	https://reviews.freebsd.org/D13907
2018-01-18 20:23:31 +00:00
Renato Botelho
1776f23d0e MFH: r459324
Update debian patch collection to version 17 since 16 is not available anymore

Reported by:	David Martin <dmartin@aisliny.com>
Sponsored by:	Rubicon Communications, LLC (Netgate)
Approved by:	ports-secteam (swills)
2018-01-18 14:24:36 +00:00
Dan Langille
df6605ff3c MFH: r459268
Fix build

was failing with:

Error: '/bin/bash' is an invalid shebang you need USES=shebangfix for 'lib/ruby/gems/2.4/gems/passenger-5.1.12/dev/ci/tests/debian/run'
Error: '/bin/bash' is an invalid shebang you need USES=shebangfix for 'lib/ruby/gems/2.4/gems/passenger-5.1.12/dev/ci/tests/rpm/run'
Error: '/usr/local/bin/python2' is an invalid shebang you need USES=shebangfix for 'lib/ruby/gems/2.4/gems/passenger-5.1.12/src/cxx_supportlib/vendor-copy/libuv/gyp_uv.py'

Approved by:	portmgr@ (blanket approval)
2018-01-18 14:09:10 +00:00
Jan Beich
57037af669 MFH: r459305
emulators/citra: update to s20180118

Changes:	79dca3d6...93cca23d
Approved by:	ports-secteam (swills, implicit for snapshots)
2018-01-18 00:59:14 +00:00
Jan Beich
2d9735c571 MFH: r459299
emulators/rpcs3: update to 0.0.4.259

Changes:	24e97b9e0...71f69d1d4
Approved by:	ports-secteam (junovitch, implicit for snapshots)
2018-01-18 00:25:42 +00:00
Mahdi Mokhtari
f72201b962 MFH: r459295
databases/mysql56-{client, server}: Update to 5.7.21
This update fixes bugs like CVE-2018-2696, CVE-2018-2562, CVE-2018-2640,
CVE-2018-2668, CVE-2017-3737 (and more) in MySQL protocol by upstream.

Delete local patches (CMake plugin macros) that are merged by upstream.

PR:		225195
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (feld)
2018-01-17 23:57:31 +00:00
Mahdi Mokhtari
5406cc80e0 MFH: r459293
databases/mysql56-{client, server}: Update to 5.6.39
This update fixes bugs like CVE-2018-2696, CVE-2018-2562,
and CVE-2018-2583 in MySQL protocol by upstream

PR:		225240
Sponsored by:	Netzkommune GmbH

Approved by:	ports-secteam (feld)
2018-01-17 23:30:05 +00:00
Jan Beich
9ea15fdd6f MFH: r459277
www/waterfox: apply more FF58 fixes

Approved by:	ports-secteam blanket
2018-01-17 18:39:38 +00:00
Thomas Abthorpe
350040b6e8 MFH: r459270
- Fix build for FreeBSD 11+

Approved by:	portmgr (swills)
2018-01-17 17:28:40 +00:00
Mark Felder
8b7a8953bb MFH: r459263
devel/arcanist: Fix QA warnings

- shebangfix
- regen port patch
- RUN_DEPENDS earlier for portlint
2018-01-17 15:12:45 +00:00
Tobias Kortkamp
1f92da925c MFH: r459259
ports-mgmt/fastest_sites: Fix runtime with modern bsd.sites.mk

fastest_sites currently can't parse entries like

https://archives.fedoraproject.org/pub/archive/fedora/linux/%SUBDIR%/:DEFAULT,SOURCE

 => Checking servers for MASTER_SITE_FEDORA_LINUX (6 servers)
Traceback (most recent call last):
  File "/usr/local/bin/fastest_sites", line 164, in <module>
    latency_list = FindFastest(varname, sitelist)
  File "/usr/local/bin/fastest_sites", line 110, in FindFastest
    AsyncConnect(url, callback)
  File "/usr/local/bin/fastest_sites", line 53, in __init__
    self.ParseURL()
  File "/usr/local/bin/fastest_sites", line 64, in ParseURL
    (scheme, remainder) = self._url.split(":", 2)
ValueError: too many values to unpack

PR:		224854

Approved by:	ports-secteam blanket
2018-01-17 14:30:51 +00:00
Jan Beich
689b2e8555 MFH: r459226
www/waterfox: unbreak HTTP auth dialog after r458873

PR:		225231
Reported by:	Graham Perrin
Approved by:	ports-secteam blanket
2018-01-17 08:59:58 +00:00
Mathieu Arnold
a2a6fc1c7d MFH: r459224
Update to latest commit.

Security:	CVE-2017-3145
Sponsored by:	Absolight
2018-01-17 08:39:20 +00:00
Mathieu Arnold
433187f7ab MFH: r459221
Update BIND9* to 9.9.11-P1, 9.10.6-P1, 9.11.2-P1 and 9.12.0rc3

Security:	CVE-2017-3145
Sponsored by:	Absolight
2018-01-17 08:06:01 +00:00
Mark Felder
283721af72 MFH: r459209
devel/libevent: Fix QA warning

Need shebangfix for Python script, but we will consciously avoid adding
Python as a build or run dependency for a script that is unlikely to be
used.

PR:		224575
2018-01-16 22:16:28 +00:00
Steve Wills
3ccef86c45 Again sync up with HEAD
MFH: r459205

Revert Intel URL to the correct location for microcode-20171117.tgz

PR:		225224
Reported by:	Gary <freebsd-bugzilla@in-addr.com>
Sponsored by:	Limelight Networks

Approved by:	ports-secteam (implicit)
2018-01-16 20:57:51 +00:00