Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (7m)  pkgsrc-2024Q1 (15d)  pkgsrc-2023Q4 (42d)  pkgsrc-2023Q2 (75d)  pkgsrc-2023Q3 (154d) 

2024-05-13 14:29:41 UTC Now

2021-10-20 16:28:28 UTC MAIN commitmail json YAML

doc: Updated mail/pst-utils to 0.6.76

(tm)

2021-10-20 16:28:17 UTC MAIN commitmail json YAML

mail/pst-utils: Update to 0.6.76

LibPST 0.6.76 (2021-03-27)
*  Stuart C. Naifeh - fix rfc2231 encoding when saving messages
    to both .eml and .msg formats.

(tm)

2021-10-20 16:16:49 UTC MAIN commitmail json YAML

doc: Updated mail/postgrey to 1.37

(tm)

2021-10-20 16:15:53 UTC MAIN commitmail json YAML

mail/postgrey: Update to 1.37

* 2016-09-22: version 1.37
  - added initial test suite
  - testing using travis-ci (https://travis-ci.org/schweikert/postgrey)
  - removed IP pool-detection code for --lookup-by-net, because it matched
    also the naming of some big hosters like facebook (#32, Michal Petrucha,
    Andrew Ayer, Jon Sailor)
  - fix early logging of errors and warnings to syslog
  - simplified IP matching code
  - added support for IPv6 whitelists with netmask
  - add network-range based whitelist for Office 365 (Holger Stember)
  - updated whitelist

(tm)

2021-10-20 14:05:26 UTC MAIN commitmail json YAML

doc: Updated mail/mime-construct to 1.11

(tm)

2021-10-20 14:04:41 UTC MAIN commitmail json YAML

2021-10-20 13:50:11 UTC MAIN commitmail json YAML

doc: Updated mail/imapfilter to 2.7.5

(tm)

2021-10-20 13:49:18 UTC MAIN commitmail json YAML

mail/imapfilter: Update to 2.7.5

IMAPFilter 2.7.5 - 5 Dec 2020
- New "hostnames" option can be used to disable hostname validation.
- Bug fix; "certificates" option incorrectly controlled hostname validation.

(tm)

2021-10-20 13:07:46 UTC MAIN commitmail json YAML

sysutils/tiramisu: change version numbering

suggested by leot.
Thanks.

(pin)

2021-10-20 12:29:19 UTC MAIN commitmail json YAML

doc: Added textproc/hgrep version 0.1.5

(pin)

2021-10-20 12:28:51 UTC MAIN commitmail json YAML

Add textproc/hgrep

(pin)

2021-10-20 12:27:49 UTC MAIN commitmail json YAML

textproc/hgrep: import package

hgrep is a grep tool to search files with given pattern and print the matched
code snippets with human-friendly syntax highlighting.
In short, it's a fusion of bat and grep or other alternatives like ripgrep.

This is similar to -C option of grep command, but hgrep focuses on human
readable outputs. hgrep is useful to survey the matches with contexts around
them.
When some matches are near enough, hgrep prints the lines within one code
snippet. Unlike grep -C, hgrep adopts some heuristics around blank lines to
determine efficient number of context lines.

As an optional feature, hgrep has builtin grep implementation thanks to ripgrep
as library. It's a subset of rg command. And it's faster when there are so many
matches since everything is done in the same process.

(pin)

2021-10-20 10:30:25 UTC MAIN commitmail json YAML

doc: Updated sysutils/tiramisu to 20211019

(pin)

2021-10-20 10:30:03 UTC MAIN commitmail json YAML

sysutils/tiramisu: update to 2.0-20211019

-The project has been re-written in vala, which is now required to build the
package.

(pin)

2021-10-20 10:28:12 UTC MAIN commitmail json YAML

Updated lang/nodejs, devel/yarn

(adam)

2021-10-20 10:27:54 UTC MAIN commitmail json YAML

yarn: updated 1.22.17

1.22.17:
Unknown changes

(adam)

2021-10-20 10:27:17 UTC MAIN commitmail json YAML

nodejs12: updated to 12.22.7

Version 12.22.7 'Erbium' (LTS)

This is a security release.

Notable changes

CVE-2021-22959: HTTP Request Smuggling due to spaced in headers (Medium)
The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). More details will be available at CVE-2021-22959 after publication.
CVE-2021-22960: HTTP Request Smuggling when parsing the body (Medium)
The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. More details will be available at CVE-2021-22960 after publication.

(adam)

2021-10-20 09:15:21 UTC MAIN commitmail json YAML

Updated net/rabbitmq, lang/nodejs

(adam)

2021-10-20 09:14:19 UTC MAIN commitmail json YAML

nodejs: updated to 14.18.1

Version 14.18.1 'Fermium' (LTS)

This is a security release.

Notable changes

CVE-2021-22959: HTTP Request Smuggling due to spaced in headers (Medium)
The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). More details will be available at CVE-2021-22959 after publication.
CVE-2021-22960: HTTP Request Smuggling when parsing the body (Medium)
The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. More details will be available at CVE-2021-22960 after publication.

(adam)

2021-10-20 09:13:02 UTC MAIN commitmail json YAML

rabbitmq: updated to 3.9.8

3.9.8:

Core Server

Bug Fixes

* When the mandatory flag was used when publishing to classic queues,
  but publisher confirms were not, channels memory usage would grow indefinitely.

* `rabbitmq-diagnostics memory_breakdown` failed to read memory of connection
  reader, writer and channel processes.

* In some environments, Stream replicas advertised IP addresses that could not be reached by cluster peers
  (eg. IP addresses behind a NAT in a Docker deployment). RabbitMQ node hostnames are now advertised as well
  so that other peers can resolve them to get an externally visible IP address.

(adam)

2021-10-20 08:19:07 UTC MAIN commitmail json YAML

doc: Updated pkgtools/pkgin to 21.10.1

(jperkin)

2021-10-20 08:18:57 UTC MAIN commitmail json YAML

pkgin: Update to 21.10.1.

## Version 21.10.1 (2021-10-20)

* Free memory correctly when building package lists for printing.  Reduces
  memory usage considerably when operating on a large number of packages.

* Avoid infinite loop in package linked list when handling pkg_install.

(jperkin)

2021-10-19 21:24:36 UTC MAIN commitmail json YAML

doc: Updated mail/offlineimap to 7.3.4

(tm)

2021-10-19 21:23:32 UTC MAIN commitmail json YAML

mail/offlineimap: Update to 7.3.4

v7.3.4 (2021-08-03)
  Fixes
    - folder: IMAP: fix issue when the response of searchforheaders is
      the same UID multiple times. [Nicolas Sebrecht]
    - Fix hooks for IDLE sync. [Reto Schnyder]
    - Changed wrong comparison equal. [Rodolfo Garc鱈a Pe単as (kix)]
    - Comparison error. [Rodolfo Garc鱈a Pe単as (kix)]
    - remove outdated links to travis. [Nicolas Sebrecht]
    - ui init is lintian clean. [Rodolfo Garc鱈a Pe単as (kix)]
    - Require the minimal dependencies in python package. [Martin Di Paola]
  Changes
    - README: update regarding the offlineimap3 fork. [Nicolas Sebrecht]
    - redirect the users to offlineimap3. [Nicolas Sebrecht]
    - threadutil imports not used. [Rodolfo Garc鱈a Pe単as (kix)]
    - Move out pkg attributes from __init__.py. [Martin Di Paola]

v7.3.3 (2020-04-11)
  Features
    - export env. variables when running account hooks. [Frank LENORMAND]
  Fixes
    - Fix stale gss api authentication security context. [Herton R. Krzesinski]
    - Handle [ALREADYEXISTS] and Mailbox already exists!. [Chris Coleman]
  Changes
    - exec() the tunnel command. [martin f. krafft]

v7.3.2 (2019-12-17)
  Fixes
    - Revert "fix check for unsupported sep character". [Nicolas Sebrecht]
    - Fixing the Arch Linux name. [Jaroslav Lichtblau]

v7.3.1 (2019-12-15)
  Features
    - Additional address for sysloghandler to handle mac. [Chris Coutinho]
    - Added financial contributors to the README. [Jess]
    - Introduce FUNDING.yml for opencollective. [Nicolas Sebrecht]
  Fixes
    - Fix check for unsupported sep character. [Nicolas Sebrecht]
    - Contrib: use yaml.safe_load() instead of load(). [Nicolas Sebrecht]
    - Ensure python2 in the release workflow. [Nicolas Sebrecht]
    - Make docs: ensure py2 when running sphinx. [Nicolas Sebrecht]
  Changes
    - Update README.md. [Chris Coleman]

v7.3.0 (2019-08-19)
  Features
    - Implement Happy Eyeballs. [Olivier Mehani]
    - imaplib2 v2.101. [Nicolas Sebrecht]
    - imaplib2 v2.100. [Nicolas Sebrecht]
  Changes
    - Update readme to give an hint about Linux distros. [Dario Maiocchi]
    - travis: remove python3.6. [Nicolas Sebrecht]
    - README: add required dependency to rfc6555. [Nicolas Sebrecht]
  imaplib2
    - Do not use TIMEOUT_MAX for Condition.wait(). [Ilias Tsitsimpis]
    - Use SSLContext if available so we send SNI. [Julien Cristau]
    - Don't expect trailing space on command completion. [Ben Cotterell]

v7.2.4 (2019-06-08)
  Features
    - mkdir -p alike folder creation. [Kyle Altendorf]
  Fixes
    - Use portable locker to support cygwin in Windows. [kimim]
    - contrib/release.py: don't break if sphinx-build is missing. [Nicolas Sebrecht]
  Changes
    - Update FSF postal address. [Jelmer Vernoo蝶]
    - repository/IMAP: update copyright header date. [Nicolas Sebrecht]
    - PULL_REQUEST_TEMPLATE: add space between brackets to enable the edition
      in the gui. [Nicolas Sebrecht]

(tm)

2021-10-19 20:34:48 UTC MAIN commitmail json YAML

emulators/simh: now hopefully works on MacOS.

Networking seemed to not crash for my test case (MacOS 11.6).

(rhialto)

2021-10-19 19:00:17 UTC MAIN commitmail json YAML

Updated databases/mysql57-client, databases/mysql57-server, x11/py-sip, x11/py-qt5

(adam)

2021-10-19 18:59:54 UTC MAIN commitmail json YAML

py-qt5: updated to 5.15.5

PyQt v5.15.5 has been released. This is a bug-fix release. There are corresponding releases of PyQtNetworkAuth and PyQtWebEngine.

Added the missing QPdfWriter.setPageSize() overload.
pylupdate5 now assumes that the default codec is UTF-8 and specifies v2.1 as the .ts file format.

PyQt v5.15.4 has been released. This is a minor bug-fix release. There are corresponding releases of the other PyQt5-related packages.

PyQt v5.15.3 has been released. This is a minor feature and bug-fix release. There are corresponding releases of the other PyQt5-related packages.

Added the missing QImage.setAlphaChannel().
Support for the QtNetworkAuth library has been moved to a separate PyQtNetworkAuth package.
Wheels no longer bundle the corresponding Qt libraries and instead automatically install them from an external wheel.

(adam)

2021-10-19 18:59:01 UTC MAIN commitmail json YAML

py-sip: updated to 4.19.25

4.19.15:
Added support for Py_ssize_t (required by PyQt v5.15.3).

(adam)

2021-10-19 18:57:37 UTC MAIN commitmail json YAML

mysql57: updated to 5.7.36

Changes in MySQL 5.7.36

Security Notes

Bugs Fixed

Security Notes

The linked OpenSSL library for MySQL Server has been updated to version 1.1.1l. Issues fixed in the new OpenSSL version are described at https://www.openssl.org/news/cl111.txt and and http://www.openssl.org/news/vulnerabilities.html.

Bugs Fixed

Incompatible Change: For all SELECT statements on a view, the query digest was based on the view definition. As a result, different queries had the same digest and aggregated together in the Performance Schema table events_statements_summary_by_digest, so statistics in that table were not usable for distinguishing distinct SELECT statements.

The query digest for each SELECT statement on a view now is based on the SELECT, not the view definition. This enables distinguishing distinct SELECT statements in the events_statements_summary_by_digest table. However, tools that use query digests may need some adjustment to account for this change. For example, MySQL Enterprise Firewall and query rewrite plugins rely on query digests and existing rules for them that are associated with views may need to be updated.

InnoDB: With undo log truncation enabled (innodb_undo_log_truncate=ON), it was possible for a deadlock and eventual failure to occur when an undo log truncate operation was initiated after a version upgrade from MySQL 5.6 to MySQL 5.7.34 or earlier. A patch introduced in MySQL 5.7.35

[Note] InnoDB: Found duplicate reference rseg: 33 space: 1 page: 3
[Note] InnoDB: Reset pre-5.7.2 rseg: 1 after duplicate is found.
If pre-5.7.2 rollback segment slots have no undo data to purge, a message similar to the following is emitted:

[Note] InnoDB: Successfully reset 32 pre-5.7.2 rseg slots.
If undo data is found in pre-5.7.2 rollback segment slots, a message similar to the following is emitted recommending a slow shutdown and restart:

[Note] InnoDB: pre-5.7.2 rseg: 2 holds data to be purged.
History length: 1. Recommend slow shutdown with innodb_fast_shutdown=0 and restart

InnoDB: Truncation of an undo tablespace during use by an active transaction raised an assertion failure. The transaction was prematurely marked as complete, permitting the truncation operation.

InnoDB: Deleting or updating a row from a parent table initiated a cascading SET NULL operation on the child table that set a virtual column value to NULL. The virtual column value should have been derived from the base column value.

Thanks to Yin Peng at Tencent for the contribution.

InnoDB: The InnoDB recovery process did not recognize that page compression had been applied to data that was being recovered, causing the tablespace data file to increase in size during the redo log apply phase, which could lead to a recovery failure for systems approaching a disk-full state.

Replication: The error messages issued by MySQL Replication when GTIDs required for auto-positioning have been purged could be incorrectly assigned or scrambled in some situations.

Replication: The contents of the gtid_executed and gtid_purged GTID sets were not persisted after restoring a dump taken using mysqldump. The dump file sequence has now been changed so that the mysql schema (which contains the mysql.gtid_executed table) is not dropped after the gtid_purged GTID set is written. A new option --skip-mysql-schema is added for mysqldump which lets you choose not to drop the mysql schema at all.

JSON: Conversion of JSON values to text caused linear growth of the destination string, resulting in an unnecessarily high number of reallocations. Now this process uses exponential growth instead, to reduce the number of allocations required.

This fix originally appeared in MySQL 8.0 and was backported to MySQL 5.7 by Annirudh Prasad, whom we thank for the contribution.

Concurrent insert operations on multiple tables with full-text indexes caused a large number of full-text index synchronization requests, resulting in an out of memory condition.

When a query uses a temporary table for aggregation, the group by item is used as a unique constraint on the temporary table: If the item value is already present, the row is updated; otherwise, a new row is inserted into the temporary table. If the item has a result field or reference item, it it evaluated twice, once to check whether the result exists in the temporary table and, if not, again while constructing the row to be inserted. When the group by item was nondeterministic, the result value used to check for existence differed from that with which an insert was attempted, causing the insert to be rejected if the value already existed in the table.

We fix this by using the hash of any nondeterministic items as the unique constraint, so that the hash is evaluated once only.

Quote handling was improved for the SHOW GRANTS statement.

(adam)

2021-10-19 11:23:25 UTC MAIN commitmail json YAML

doc: Updated mail/isync to 1.4.3

(schmonz)

2021-10-19 11:23:17 UTC MAIN commitmail json YAML

Update to 1.4.3. From the changelog:

- limit maildir nesting depth
- enable embedding arbitrarily long strings into IMAP commands
- CVE-2021-3578: fix handling of unexpected APPENDUID response code
- don't crash on malformed CAPABILITY responses
- tolerate INBOX mis-casing in Path
- make UIDVALIDITY recovery more strict about vanished messages
- improve error messages about irrecoverably changed UIDVALIDITY
- CVE-2021-20247: reject funny mailbox names from IMAP LIST/LSUB
- be more tolerant of formally malformed response codes
- fix bogus continuation of IMAP list parsing
- accept unsolicited FETCH responses (without payload) after all
- use correct <poll.h> header

(schmonz)

2021-10-19 08:39:15 UTC MAIN commitmail json YAML

doc: Updated graphics/imlib2 to 1.7.4

(nia)

2021-10-19 08:39:05 UTC MAIN commitmail json YAML

imlib2: update to 1.7.4

v1.7.4 - 2021-09-16
-------------------
Kim Woelders (14):
      imlib2_view: Move property stuff to separate file
      imlib2_view: Cleanups
      imlib2_view: By default scale large images to fit on screen
      imlib2_view: Add some debug
      imlib2_view: Fix issue with new default scaling
      WEBP loader: Remove forgotten debug printout
      WEBP loader: Rename fd variable to be same as everywhere else
      LBM loader: Fix potential out-of-bounds memory access
      GIF, TIFF, WEBP loaders: Fix loading if filename does not have usual suffix
      Revert "GIF, TIFF, WEBP loaders: Fix loading if filename does not have usual suffix"
      GIF, TIFF, WEBP loaders: Fix loading if filename does not have usual suffix - take 2
      Add script to generate Changelog
      Update Changelog to new format
      image.c: Use the LOAD_... macros to check loader return values

(nia)

2021-10-19 08:17:18 UTC MAIN commitmail json YAML

doc: Updated chat/hexchat to 2.16.0

(nia)

2021-10-19 08:17:06 UTC MAIN commitmail json YAML

hexchat: update to 2.16.0

2.16.0 (2021-10-01)

    * add support for IRCv3 SETNAME, invite-notify, account-tag, standard
      replies, and UTF8ONLY
    * add support for strikethrough formatting
    * update network list (including Libera.Chat as the default)
    * update OpenSSL on Windows
    * fix text clipping issues by respecting font line height
    * fix URLs not being escaped when opened
    * fix misc IRC message parsing issues
    * remove libnotify dependency on Linux, fixing hangs when notifications
      are shown
    * remove libproxy dependency on Linux
    * print ChanServ notices in the front tab by default
    * fishlim: add support for CBC mode
    * python: rewrite plugin in python with CFFI This lowers memory usage
      and fixed conflicts with many C Python modules including pygobject

(nia)

2021-10-19 07:37:47 UTC MAIN commitmail json YAML

doc: Updated sysutils/htop to 3.1.1

(nia)

2021-10-19 07:37:36 UTC MAIN commitmail json YAML

htop: update to 3.1.1

What's new in version 3.1.1

* Update license headers to explicitly say GPLv2+
* Document minimum version for libcap (thanks to James Brown)
* Fix mouse wheel collision with autogroups nice adjustment
* Adjust Makefile.am macro definitions for older automake versions
* Ensure consistent reporting of MemoryMeter 'used' memory
* Report hugepage memory as real and used memory (as before)
* Handle procExeDeleted, usesDeletedLib without mergedCommandline mode
* Validate meter configuration before proceeding beyond htoprc parsing
* Properly release memory on partially read configuration
* Handle interrupted sampling from within libpcp PDU transfers
* On Linux, provide O_PATH value if not defined
* On Linux, always compute procExeDeleted if already set
* Workaround for Rosetta 2 on Darwin (thanks to Alexander Momchilov)
* Fix FreeBSD cmdline memory leak in Process_updateCmdline, and
* Plug a Disk I/O meter memory leak on FreeBSD (thanks to Ximalas)

(nia)

2021-10-18 14:33:14 UTC MAIN commitmail json YAML

doc: Updated security/libretls to 3.4.1

(schmonz)

2021-10-18 14:33:04 UTC MAIN commitmail json YAML

Update to 3.4.1. From the changelog:

The shared library major version of libtls has been bumped to 22.

tls_connect(3) and friends now strip a trailing dot from servername.

This patch imports the missing scripts/wrap-compiler-for-flag-check
file, which was incorrectly causing compiler flags to not be used.

>From the upstream LibreSSL changelog:

* New Features
  - Added support for OpenSSL 1.1.1 TLSv1.3 APIs.
  - Enabled the new X.509 validator to allow verification of
    modern certificate chains.
* Portable Improvements
  - Added Universal Windows Platform (UWP) build support.
  - Fixed mingw-w64 builds on newer versions with missing SSP support.
* API and Documentation Enhancements
  - Added the following APIs from OpenSSL
    BN_bn2binpad BN_bn2lebinpad BN_lebin2bn EC_GROUP_get_curve
    EC_GROUP_order_bits EC_GROUP_set_curve
    EC_POINT_get_affine_coordinates
    EC_POINT_set_affine_coordinates
    EC_POINT_set_compressed_coordinates EVP_DigestSign
    EVP_DigestVerify SSL_CIPHER_find SSL_CTX_get0_privatekey
    SSL_CTX_get_max_early_data SSL_CTX_get_ssl_method
    SSL_CTX_set_ciphersuites SSL_CTX_set_max_early_data
    SSL_CTX_set_post_handshake_auth SSL_SESSION_get0_cipher
    SSL_SESSION_get_max_early_data SSL_SESSION_is_resumable
    SSL_SESSION_set_max_early_data SSL_get_early_data_status
    SSL_get_max_early_data SSL_read_early_data SSL_set0_rbio
    SSL_set_ciphersuites SSL_set_max_early_data
    SSL_set_post_handshake_auth
    SSL_set_psk_use_session_callback
    SSL_verify_client_post_handshake SSL_write_early_data
  - Added AES-GCM constants from RFC 7714 for SRTP.
* Compatibility Changes
  - Implement flushing for TLSv1.3 handshakes behavior, needed for Apache.
  - Call the info callback on connect/accept exit in TLSv1.3,
    needed for p5-Net-SSLeay.
  - Default to using named curve parameter encoding from
    pre-OpenSSL 1.1.0, adding OPENSSL_EC_EXPLICIT_CURVE.
  - Do not ignore SSL_TLSEXT_ERR_FATAL from the ALPN callback.
* Testing and Proactive Security
  - Added additional state machine test coverage.
  - Improved integration test support with ruby/openssl tests.
  - Error codes and callback support in new X.509 validator made
    compatible with p5-Net_SSLeay tests.
* Internal Improvements
  - Numerous fixes and improvements to the new X.509 validator to
    ensure compatible error codes and callback support compatible
    with the legacy OpenSSL validator.

(schmonz)

2021-10-18 14:25:55 UTC MAIN commitmail json YAML

jack: Fixup Darwin library install names.

(jperkin)

2021-10-18 13:56:37 UTC MAIN commitmail json YAML

doc: Updated editors/nano to 5.9

(nia)

2021-10-18 13:56:26 UTC MAIN commitmail json YAML

nano: update to 5.9

2021.10.06 - GNU nano 5.9 "El manicomio ha decidido: mañana sol!"
• The extension of a filename is added to the name of a corresponding
  temporary file, so that spell checking a C file, for example, will
  check only the comments and strings (when using 'aspell').
• The process number is added to the name of an emergency save file,
  so that when multiple nanos die they will not fight over a filename.
• Undoing a cutting operation will restore an anchor that was located
  in the cut area to its original line.
• When using --locking, saving a new buffer will create a lock file.
• Syntax highlighting for YAML files has been added.

(nia)

2021-10-18 13:36:57 UTC MAIN commitmail json YAML

doc: Updated sysutils/mc to 4.8.27

(nia)

2021-10-18 13:36:45 UTC MAIN commitmail json YAML

mc: 4.8.27

Version 4.8.27

- Core

    * Minimal version of Autoconf is 2.64
    * Minimal version of Automake is 1.12
    * Minimal version of Gettext is 0.18.2
    * Minimal version of libssh2 is 1.2.8
    * Reimplement version detection
    * Significantly reduce rebuilt time after version change
    * Drop automatic migration of configuration from ~/.mc to XDG-based directories
    * zsh: support custom configuration file: ~/.local/share/mc/.zshrc
    * Widgets: implement WST_VISIBLE state to show/hide widgets
    * "Find File": add "Follow symlinks" option

- VFS

    * extfs: support unrar-6
    * extfs: support official 7z binary
    * ftpfs: apply file list parser from lftp project

- Editor

    * Word completion: get candidates from all open files
    * etags: get rid of hardcoded list length and window width
    * Update syntax files:
        - Python
    * Add syntax highlighting:
        - Verilog and SystemVerilog header files
        - JSON
        - openrc-run scripts

- Misc

    * Code clean up
    * Filehighlight of c++ and h++ files as sources
    * Filehighlight of JSON files as documents
    * Support of alacritty terminal emulator (https://github.com/alacritty/alacritty)
    * Support of foot terminal emulator (https://codeberg.org/dnkl/foot)
    * Support of (alt+)shift+arrow keys in st terminal emulator (st.suckless.org)
    * Mouse support in screen: don't check $DISPLAY variable
    * mc.ext: support fb2 e-books
    * ext.d: use mediainfo to view info about various media files
    * Remove OS/distro-specific package-related stuff from source tree

- Fixes

    * FTBFS against NCurses on OS X 10.9.5
    * Segfault on dialog before panels get visible
    * Crash if shadow is out of screen (build against NCurses)
    * Crash in search
    * Crash on startup with enabled subshell in FreeBSD (workaround)
    * Hang on start randomly with zsh as subshell
    * If command line is invisible it's partially displayed
    * Broken handling of zip archives
    * Broken handling of jar files as zip archives
    * Timestamps of symlinks, sockets, fifos, etc are not preserved after copy/move
    * %view action in the user menu doesn't work on no-exec filesystem
    * Hardlinks are not colored by file type or extension
    * mcedit: silent macro makes terminal disrupted
    * mcedit: disrupting of TAGS file path
    * vfs: unable to browse compressed tar archives
    * sftpfs vfs: CVE-2021-36370: server fingerprint isn't verified (discovered by AUT-milCERT during an audit of open source software)
    * ftpfs vfs: month of file is always January
    * Tests: log files are written by libcheck and automake simultaneously

(nia)

2021-10-18 13:00:48 UTC MAIN commitmail json YAML

glib2: Pull in python tool.mk

Required to find the correct meson python version.  Fixes build on e.g. Darwin
that ships with /usr/bin/python version 2.7.

(jperkin)

2021-10-18 11:53:21 UTC MAIN commitmail json YAML

doc: Updated devel/pcre2 to 10.38

(nia)

2021-10-18 11:53:10 UTC MAIN commitmail json YAML

pcre2: update to 10.38

Version 10.38 01-October-2021
-----------------------------

As well as some bug fixes and tidies (as always, see ChangeLog for details),
the documentation is updated to list the new URLs, following the move of the
source repository to GitHub and the mailing list to Google Groups.

* The CMake build system can now build both static and shared libraries in one
go.

* Following Perl's lead, \K is now locked out in lookaround assertions by
default, but an option is provided to re-enable the previous behaviour.

(nia)

2021-10-18 11:42:46 UTC MAIN commitmail json YAML

doc: Updated x11/rofi to 1.7.0

(nia)

2021-10-18 11:42:35 UTC MAIN commitmail json YAML

rofi: update to 1.7.0

v1.7.0: Iggy 2024
  - ADD: -steal-focus option.
  - ADD: [Config] Add nested configuration option support.
  - ADD: [Config] Support for handling dynamic config options.
  - ADD: [IconFetcher] Find images shipped with the theme.
  - ADD: [DRun] Add support for passing file (using file-browser) completer for desktop files that support his.
  - ADD: [DRun] Support for service files.
  - ADD: [FileBrowser] Allow setting startup directory (#1325)
  - ADD: [FileBrowser]: Add sorting-method. (#1340)
  - ADD: [FileBrowser] Add option to group directories ahead of files. (#1352)
  - ADD: [Filtering] Add prefix matching method. (#1237)
  - ADD: [Icon] Add option to square the widget.
  - ADD: [Icon|Button] Make action available on icon, button and keybinding name.
  - ADD: [KeyBinding] Add Ctrl-Shift-Enter option. (#874)
  - ADD: [ListView]-hover-select option. (#1234)
  - ADD: [Run] Add support for passing file (using file-browser) completer.
  - ADD: [Textbox] Allow theme to force markup on text widget.
  - ADD: [Theme] theme validation option. (`-rasi-validate`)
  - ADD: [View] Add support for user timeout and keybinding action.
  - ADD: [Widget] Add cursor property (#1313)
  - ADD: [Widget] Add scaling option to background-image.
  - ADD: [Widget] Add support background-image and lineair gradient option.
  - ADD: [Window] Add pango markup for window format (#1288)
  - ADD: [Window] Allow rofi to stay open after closing window.
  - FIX: [DSL] Move theme reset into grammar parser from lexer.
  - FIX: [Drun]: fix sorting on broken desktop files. (thanks to nick87720z)
  - FIX: [File Browser]: Fix escaping of paths.
  - FIX: [ListView] Fix wrong subwidget name.
  - FIX: [Script] Don't enable custom keybindings by default.
  - FIX: [TextBox] Fix height estimation.
  - FIX: [Theme] widget state and inherited properties. This should help fixing some old themes with changes from 1.6.1.
  - FIX: [Widget] Fix rendering of border and dashes. (Thanks to nick87720z)
  - FIX: [Build] Fix CI.
  - FIX: [Theme] Discard old theme, when explicitly passing one on command line.
  - REMOVE: -dump-xresources
  - REMOVE: -fullscreen
  - REMOVE: -show-match
  - REMOVE: Old xresources based configuration file.
  - REMOVE: fake transparency/background option, part of theme now.
  - REMOVE: xresources parsing via Xserver
  - Remove: [Theme] Remove backwards compatiblity hack.
  - DOC: Update changes to manpages

(nia)

2021-10-18 11:25:24 UTC MAIN commitmail json YAML

doc: Updated www/snownews to 1.9

(nia)

2021-10-18 11:25:11 UTC MAIN commitmail json YAML

snownews: remove dependency on libiconv

(nia)

2021-10-18 11:24:51 UTC MAIN commitmail json YAML

snownew: update to 1.9

  msharov released this Oct 2, 2021

    * Make the UI more compact.
    * Simplify HTML detagging and rewrapping.
    * Store feed cache content detagged.
    * New translation for Serbian.
    * Support ncurses without widechars.
    * Quit normally on non-fatal signals.
    * Stop using libiconv because only UTF8 is supported.
    * Remove the need to configure html_entities.
    * Ignore atom link tags where rel != alternate.
    * Fix saving of changes to smart feeds.

(nia)

2021-10-18 11:17:35 UTC MAIN commitmail json YAML

doc: Updated sysutils/vifm to 0.12

(nia)

2021-10-18 11:17:24 UTC MAIN commitmail json YAML

vifm: update to 0.12

Vifm v0.12
September 29, 2021

  New version makes textual preview asynchronous, provides support for
  24-bit colors, improves tree-view and introduces experimental Lua plugins
  support.

  Thanks to everyone who tried out the beta.

  Main changes
    * Color schemes and preview now support 24-bit colors.
    * Depth of tree-view can now be limited and directories in it can be
      folded.
    * Textual preview of files is now done asynchronously.
    * List of files can now be directly piped to programs via new macros.
    * External editing now asks for a re-edit after a failure.
    * Status line can now take up several lines.
    * Vifm has received a more advanced, but currently experimental,
      extension interface in a form of Lua plugins.
    * New keys for controlling viewer while in view mode.
    * View column separators.
    * New logo.

(nia)

2021-10-18 11:15:20 UTC MAIN commitmail json YAML

doc: Updated chat/weechat to 3.3

(nia)

2021-10-18 11:15:09 UTC MAIN commitmail json YAML

weechat: update to 3.3

pkgsrc changes:
- re-enable man page generation
- remove patch that upstream fixed in a different way

== Version 3.3 (2021-09-19)

New features::

  * core: change key kbd:[Alt+h] to kbd:[Alt+h], kbd:[Alt+c] (clear hotlist)
  * core: add options "hotlist_remove_buffer", "hotlist_restore_buffer" and "hotlist_restore_all" in command /input, add default keys kbd:[Alt+h], kbd:[Alt+m] (remove buffer), kbd:[Alt+h], kbd:[Alt+r] (restore hotlist in current buffer) and kbd:[Alt+h], kbd:[Alt+Shift+R] (restore hotlist in all buffers)
  * core: add option "certs" in command /debug
  * core: add options "-o", "-ol", "-i" and "-il" in command "/plugin list"
  * api: add split of string and shell arguments in evaluation of expressions with "split:number,seps,flags,xxx" and "split_shell:number,xxx"
  * api: add `${re:repl_index}` to get the index of replacement in function string_eval_expression (issue #1689)
  * api: add random integer number in evaluation of expressions with "random:min,max"
  * api: add function string_cut
  * api: add function file_copy (issue #1667)
  * api: remember insertion order in hashtables
  * api: add keys/values with tags in output of irc_message_parse_to_hashtable (issue #1654)
  * irc: add option "-parted" in command /allchan (issue #1685)
  * irc: allow signals "irc_raw_in" and "irc_in" to eat messages (issue #1657)
  * irc: implement IRCv3.2 SASL authentication, add command /auth, reconnect by default to the server in case of SASL authentication failure (issue #413)
  * irc: add support of capability "message-tags" and TAGMSG messages (issue #1654)
  * irc: enable all capabilities by default (if supported by server and WeeChat), change default value of option irc.server_default.capabilities to "*" (issue #320)
  * irc: add options irc.look.display_account_message and irc.look.display_extended_join (issue #320)
  * irc: add command /setname, add support of message and capability "setname" (issue #1653)
  * irc: always set realname in nicks even when extended-join capability is not enabled (issue #1653)
  * irc: add support of FAIL/WARN/NOTE messages (issue #1653)
  * irc: drop support of DH-BLOWFISH and DH-AES SASL mechanisms (issue #175)
  * typing: new plugin "typing": display users currently writing messages on IRC channel/private buffers

Bug fixes::

  * core: fix decoding of attributes in basic ANSI colors (issue #1678)
  * api: fix function string_match with joker in the string if multiple words matched in input string
  * irc: fix send of empty JOIN when connecting to a server with only parted channels (issue #1638)
  * irc: fix SASL authentication when AUTHENTICATE message is received with a server name (issue #1679)
  * irc: remove unneeded message about Diffie-Hellman shared secret exchange during SSL connection to server (issue #857)
  * irc: escape/unescape IRC message tags values (issue #1654)
  * irc: set notify level to "private" for received WALLOPS
  * script: fix move of installed script on another filesystem (issue #1667)

Documentation::

  * add Spanish FAQ (issue #1656)
  * add Serbian translations (issue #1655)

Tests::

  * core: switch to PHP 8.0 in CI
  * core: add build on macOS in CI

Build::

  * core: fix build on macOS (issue #1662)
  * lua: add detection of Lua 5.4
  * php: add support of PHP 8.0 and 8.1 (issue #1599, issue #1668)

(nia)

2021-10-18 11:13:49 UTC MAIN commitmail json YAML

doc: Updated chat/unrealircd to 5.2.2

(nia)

2021-10-18 11:13:34 UTC MAIN commitmail json YAML

unrealircd: update to 5.2.2

UnrealIRCd 5.2.2 Release Notes
===============================

This 5.2.2 release only contains some minor changes.

Fixes:
* Fix issues with Let's Encrypt certificates for
  [remote includes](https://www.unrealircd.org/docs/Remote_includes) (quite
  common) and with linking to servers with link::verify-certificate enabled
  (more rare). Both issues only happen with:
  * OpenSSL 1.0.2 and older, which is officially unsupported, but still in
    use on e.g. Debian 8 and Ubuntu 16.04.
  * LibreSSL, such as with UnrealIRCd on Windows
* OpenBSD compile issue when using shipped c-ares

Enhancements:
* [set::allowed-nickchars](https://www.unrealircd.org/docs/Nick_Character_Sets):
  added ```arabic-utf8```
* [set::server-linking](https://www.unrealircd.org/docs/Set_block#set::server-linking):
  add another autoconnect-strategy called ```sequential-fallback```.

Module coders / IRC protocol:
* S2S: Allow ```SVSLOGIN``` also when
[set::sasl-server](https://www.unrealircd.org/docs/Set_block#set::sasl-server)
is not set.
* Some minor ```CHATHISTORY``` fixes, for example the subcommand is now
  case-insensitive.
* You can use the new ```UNREAL_VERSION``` macro. It is easier than the
  old individual UNREAL_VERSION_MAJOR/MINOR/etc macros.

(nia)

2021-10-18 09:17:45 UTC MAIN commitmail json YAML

doc: Updated sysutils/macchina to 2.0.0

(pin)

2021-10-18 09:17:26 UTC MAIN commitmail json YAML

sysutils/macchina: update to 2.0.0

Breaking change:
-The palette option, previously taking a boolean value, now accepts the
following:
-Dark: Display darker color variants.
-Light: Display lighter color variants.
-Full: Display all color variants.

(pin)

2021-10-18 09:16:18 UTC MAIN commitmail json YAML

doc: Updated benchmarks/hyperfine to 1.12.0

(pin)

2021-10-18 09:15:58 UTC MAIN commitmail json YAML

benchmarks/hyperfine: update to 1.12.0

Features:
--command-name can now take parameter names from --parameter-* options, see #351
and #391 (@silathdiir)
-Exit codes (or signals) are now printed in cases of command failures, see #342
(@KaindlJulian)
-Exit codes are now part of the JSON output, see #371 (@JordiChauzi)
-Colorized output should now be enabled on Windows by default, see #427

Changes:
-When --export-* commands are used, result files are created before benchmark
execution
-to fail early in case of, e.g., wrong permissions. See #306 (@s1ck).
-When --export-* options are used, result files are written after each
individual
-benchmark command instead of writing after all benchmarks have finished. See
#306 (@s1ck).
-Reduce number of shell startup time measurements from 200 to 50, generally
speeding up benchmarks. See #378
-User and system time are now in consistent time units, see #408 and #409
(@film42)

(pin)

2021-10-18 08:23:14 UTC MAIN commitmail json YAML

doc: Updated net/httpstat to 1.3.0

(tm)

2021-10-18 08:22:42 UTC MAIN commitmail json YAML

net/httpstat: Update to 1.3.0

v1.3.0 - Oct 15, 2020
- Add HTTPSTAT_METRICS_ONLY env.
  If set to true, httpstat will only output metrics in json format,
  this is useful if you want to parse the data instead of reading it.

(tm)

2021-10-18 08:17:17 UTC MAIN commitmail json YAML

doc: Updated net/rbldnsd to 0.998

(tm)

2021-10-18 08:16:49 UTC MAIN commitmail json YAML

net/rbldnsd: Update to 0.998

0.998 (05 Dec 2015)
- bugfix: correctly handle V4MAPPED (v4 in v6) addresses, the
  original v6 prefix was wrong.  Thanks to Alex Lasoriti for
  finding the issue
- bugfix: sometimes IP4-based datasets gave false positives when
  an IP6 dataset were present, and it was also possible to have
  false positive in IP6 datasets.  Both has been fixed.

(tm)

2021-10-18 06:52:20 UTC MAIN commitmail json YAML

doc: Updated mail/sieve-connect to 0.9

(tm)

2021-10-18 06:51:43 UTC MAIN commitmail json YAML

mail/sieve-connect: Update to 0.90

0.90: minor cleanups
- Update various regular expressions to not break under a future
  Perl 5.30 release
- Use a .sieve filename extension for temporary files, to assist
  text-editors with mode selection.

(tm)

2021-10-17 22:01:16 UTC MAIN commitmail json YAML

doc: Updated audio/mpg123-pulse to 1.29.1

(thor)

2021-10-17 22:01:06 UTC MAIN commitmail json YAML

doc: Updated audio/mpg123-nas to 1.29.1

(thor)

2021-10-17 22:00:56 UTC MAIN commitmail json YAML

doc: Updated audio/mpg123-jack to 1.29.1nb1

(thor)

2021-10-17 22:00:23 UTC MAIN commitmail json YAML

doc: Updated audio/mpg123 to 1.29.1

(thor)

2021-10-17 22:00:11 UTC MAIN commitmail json YAML

mpg123: version 1.29.1

Upstream changelog:

.29.1
------
- mpg123:
-- Keep default output encoding of s16 for raw and file outputs
  also with the new resampler. This reverts the unintentional change in
  1.26.0 of switching to f32 for forced output rate unless the NtoM
  resampler is selected. In any case, you should make sure to specify
  your desired --encoding if you depend on it.
-- Catch error in indexing (mpg123_scan() return value was ignored
  before, bug 322).
- mpg123-strip: Lift the resync limit, as it should be to clean up really
  dirty streams.
- mpg123-id3dump: Also lift resync limit for the same reasons.
- libout123: fix reporting of device property flags for buffer
- libmpg123: more safeguarding against attempts to decode if decoder
  setup failed and user ignored the returned error code (bug 322)

(thor)

2021-10-17 18:14:51 UTC MAIN commitmail json YAML

doc: Updated chat/icbirc to 2.1

(tm)

2021-10-17 18:14:04 UTC MAIN commitmail json YAML

chat/icbirc: Update to 2.1

2.1:
  Return *** as nick in IRC error messages (where missing), add
  pledge(2) call on OpenBSD, from semarie@.

2.0:
  Merge OpenBSD port patches, originally from ray@ in 2009:
  Fix corruption that occurs when connecting and reconnecting to icbirc
  repeatedly. After a while, icbirc starts reusing the command buffer
  from a previous connection, causing all further connections to
  incorrectly parse commands.

(tm)

2021-10-17 17:53:57 UTC MAIN commitmail json YAML

doc: Updated sysutils/ts to 1.0.1

(tm)

2021-10-17 17:53:08 UTC MAIN commitmail json YAML

sysutils/ts: Update to 1.0.1

v1.0.1:
- Fix possible buffer overflow (Alexander Inyukhin)
v1.0:
- Respect TMPDIR for output files.
v0.7.6:
- Add -k (send SIGTERM to process group). Replacement for "kill -- -`ts -p`".

(tm)

2021-10-17 17:28:38 UTC MAIN commitmail json YAML

doc: Updated sysutils/ioping to 1.2

(tm)

2021-10-17 17:27:49 UTC MAIN commitmail json YAML

sysutils/ioping: Update to 1.2

v1.2 / 2020-02-02
* makefile: merge compiling and linking
* ioping: add -r, -rate-limit
* ioping: reformat usage
* Merge pull request #42 from kohju/patch-Solaris
* Support for Solaris.
* ioping: option -J|-json for printing JSON
* ioping: add option -a|-warmup <count>
* ioping: add long options
* ioping: print filesystem size for file or directory target
* Merge pull request #39 from justinpitts/patch-1
* Fix grammar mistake.

(tm)

2021-10-17 16:41:44 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6521

(tm)

2021-10-17 16:41:33 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6521 - requested by nia
mail/alpine: security fix

Revisions pulled up:
- mail/alpine/Makefile                                          1.48
- mail/alpine/distinfo                                          1.27
- mail/alpine/patches/patch-imap_src_mtest_mtest.c              deleted

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Sun Oct 17 09:49:10 UTC 2021

  Modified Files:
  pkgsrc/mail/alpine: Makefile distinfo
  Removed Files:
  pkgsrc/mail/alpine/patches: patch-imap_src_mtest_mtest.c

  Log Message:
  alpine: Update to 2.25.

  pkgsrc changes and notes:

  - According to the release notes, this fixes CVE-2021-38370 by
    Damian Poddebniak.
  - I have added the maildir patch, as FreeBSD does, because it seems
    useful.
  - I have removed the non-trivial patch for OpenBSD, because going by
    OpenBSD's ports repository it's no longer necessary at all.

      Version 2.25 includes several new features and bug fixes.

      Additions include:
        * Unix Alpine: New configuration variable ssl-ciphers that allows users
          to list the ciphers to use when connecting to a SSL server. Based on a
          collaboration with Professor Martin Trusler.
        * New hidden feature enable-delete-before-writing to add support for
          terminals that need lines to be deleted before being written. Based on
          a collaboration with Professor Martin Trusler.
        * Experimental: The instruction to remove the double quotes from the
          processing of customized headers existed in pine, but it was removed
          in alpine. Restoring old Alpine behavior. See this
        * Add the capability to record http debug. This is necessary to debug
          XOAUTH2 authentication, and records sensitive login information. Do
          not share your debug file if you use this form of debug.
        * Remove the ability to choose between the device and authorize methods
          to login to outlook, since the original client-id can only be used for
          the device method. One needs a special client-id and client-secret to
          use the authorize method in Outlook.
        * PC-Alpine only: Some service providers produce access tokens that are
          too long to save in the Windows Credentials, so the access tokens will
          be split and saved as several pieces. This means that old versions of
          Alpine will NOT be able to use saved passwords once this new version
          of Alpine is used.
        * PC-Alpine: Debug files used to be created with extension .txt1, .txt2,
          etc. Rename those files so that they have extension .txt.
        * Always follow **suppress-asterisks-in-password-prompt** setting in
          the various password prompts. Submitted by tienne Deparis.
        * Use 'alpine -F' instead of 'pine -F' as the browser default pager.
          Submitted by tienne Deparis.
        * Introduction of OTHER CMDS menu for the browser/pilot to let people
          discover the two new commands: "1" is a toggle that switches between 1
          column and multicolumn mode. The "." command toggles between hiding or
          showing hidden files, and the "G" command to travel between
          directories. Contributed by tienne Deparis.
        * Add option -xoauth2-flow to the command line, so that users can
          specify the parameters to set up an xoauth2 connection through the
          command line.
        * Alpine deletes, from its internal memory and external cache, passwords
          that do not work, even if they were saved by the user.
        * New format for saving passwords in the windows credential manager for
          PC-Alpine. Upon starting this new version of Alpine the passwords
          saved in the credential manager are converted to the new format and
          they will not be recognized by old versions of Alpine, but only by
          this and newer versions of Alpine.
        * Enabled encryption protocols in PC-Alpine are based on those enabled
          in the system, unless one is specified directly.

      Bugs that have been addressed include:
        * The c-client library parses information from an IMAP server during
          non-authenticated state which could lead to denial of service.
          Reported by Damian Poddebniak from Mnster University of Applied
          Sciences.
        * Memory corruption when alpine searches for a string that is an
          incomplete utf8 string in a local folder. This could happen by
          chopping a string to make it fit a buffer without regard to its
          content. We fix the string so that chopping it does not damage it.
          Reported by Andrew.
        * Crash in the ntlm authenticator when the user name does not include a
          domain. Reported and fixed by Anders Skargren.
        * When forwarding a message, replacing an attachment might make Alpine
          re-attach the original attachment. Reported by Michael Traxler.
        * When an attachment is deleted, the saved message with the deleted
          attachment contains extra null characters after the end of the
          attachment boundary.
        * Tcp and http debug information is not printed unless the default debug
          level is set to 1. Print this if requested, regardless of what the
          default debug level is.
        * When trying to select a folder for saving a message, one can only
          enter a subfolder by pressing the ">" command, rather than the normal
          navigation by pressing "Return". Reported by Ulf-Dietrich Braunmann.
        * Crash when attempting to remove a configuration for a XOAUTH2 server
          that has no usernames configured.
        * Crash caused by saving (and resaving) XOAUTH2 refresh and access
          tokens in PC-Alpine. Reported by Karl Lindauer.

(tm)

2021-10-17 16:24:16 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6522

(tm)

2021-10-17 16:23:57 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6522 - requested by nia
mail/balsa: security fix

Revisions pulled up:
- mail/balsa/Makefile                                          1.169
- mail/balsa/distinfo                                          1.27
- mail/balsa/patches/patch-sounds_Makefile.in                  1.2
- mail/balsa/patches/patch-src_sendmsg-window.c                deleted

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Sun Oct 17 10:08:53 UTC 2021

  Modified Files:
  pkgsrc/mail/balsa: Makefile distinfo
  pkgsrc/mail/balsa/patches: patch-sounds_Makefile.in
  Removed Files:
  pkgsrc/mail/balsa/patches: patch-src_sendmsg-window.c

  Log Message:
  balsa: update to 2.6.3

  This fixes the STARTTLS-related crash bugs mentioned here:
  https://nostarttls.secvuln.info/

  * Balsa-2.6.3 release. Release date 2021-08-18

  - Improve Autocrypt-related error messages.
  - Improvements to communication with GnuPG key servers.
  - Create standard-compatible HTML messages.
  - Implement sender-dependent HTML message preferences.
  - Reuse HTTP connections when rendering HTML messages.
  - Do not send empty Reply-To, Cc, etc headers.
  - More robust IMAP parser and response handling.
  - Code cleanups, platform-dependent build fixes

(tm)

2021-10-17 11:22:57 UTC MAIN commitmail json YAML

xf86-video-intel: Builds extra program with timerfd. Add LICENSE.

(nia)

2021-10-17 11:01:05 UTC MAIN commitmail json YAML

doc: Updated graphics/feh to 3.7.2

(nia)

2021-10-17 11:00:54 UTC MAIN commitmail json YAML

feh: update to 3.7.2

Sat, 25 Sep 2021 09:21:25 +0200  Daniel Friesel <derf+feh@finalrewind.org>

* Release v3.7.2
    * Fix crash when running feh without stdin file descriptor

(nia)

2021-10-17 10:56:48 UTC MAIN commitmail json YAML

doc: Updated converters/fribidi to 1.0.11

(nia)

2021-10-17 10:56:37 UTC MAIN commitmail json YAML

fribidi: update to 1.0.11

Overview of changes between 1.0.10 and 1.0.11
=============================================

* Updated Unicode tables to version 14.
* Skip isolates in fribidi_get_par_direction().
* Various fuzzing fixes.
* Various build fixes.

(nia)

2021-10-17 10:12:19 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6520

(tm)

2021-10-17 10:12:03 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6520 - requested by wiz
databases/sqlite3: segfault fix

Revisions pulled up:
- databases/sqlite3/Makefile                                    1.142
- databases/sqlite3/distinfo                                    1.173
- databases/sqlite3/patches/patch-shell.c                      1.1

---
  Module Name: pkgsrc
  Committed By: wiz
  Date: Sun Oct 17 07:14:27 UTC 2021

  Modified Files:
  pkgsrc/databases/sqlite3: Makefile distinfo
  Added Files:
  pkgsrc/databases/sqlite3/patches: patch-shell.c

  Log Message:
  sqlite3: fix (disputed) CVE-2021-36690

  Bump PKGREVISION.

(tm)

2021-10-17 10:11:33 UTC MAIN commitmail json YAML

doc: Updated net/bftpd to 6.0

(nia)

2021-10-17 10:11:21 UTC MAIN commitmail json YAML

bftpd: update to 6.0

Jesse Smith <jessefrgsmith@yahoo.ca> -> 6.0
- Make extended passive mode respect the PASSIVE_PORTS variable
  in the bftpd configuration file. Previously random ports
  would be assigned.
- Minor code clean-up in mystrings library to avoid calculating
  string length multiple times.

Jesse Smith <jessefrgsmith@yahoo.ca> -> 5.9
- Fixed output of directory listing so that file size is right-justified
  which makes output look cleaner.
  Fix suggested by uomo ukko.
- Addressed some compiler warnings. Make sure we bail out
          of situations even if they should never realisticaly return
  an error.

Jesse Smith <jessefrgsmith@yahoo.ca> -> 5.8
- Many spelling errors in source code and documentation found and
  fixed by Jens of Fossies (fossies.org). Applied spelling corrections.
- Removed mark-up and special characters from COPYING, README, and INSTALL
  files.
- Fixed file size reporting on 32-bit ARM architecture when files are
  large (greater than 2GB).
  Problem and fix reported by uomo ukko.

Jesse Smith <jessefrgsmith@yahoo.ca> -> 5.7
- A malicious client could cause a buffer overflow with
  a lot of EPSV commands sent in a row. We now close
  the pasv socket before each new use to avoid accumulating
  more than 1023.
  Thanks to Shisong Qin for reporting this issue and suggesting
  a fix.

(nia)

2021-10-17 10:09:04 UTC MAIN commitmail json YAML

doc: Updated mail/balsa to 2.6.3

(nia)

2021-10-17 10:08:53 UTC MAIN commitmail json YAML

balsa: update to 2.6.3

This fixes the STARTTLS-related crash bugs mentioned here:
https://nostarttls.secvuln.info/

* Balsa-2.6.3 release. Release date 2021-08-18

- Improve Autocrypt-related error messages.
- Improvements to communication with GnuPG key servers.
- Create standard-compatible HTML messages.
- Implement sender-dependent HTML message preferences.
- Reuse HTTP connections when rendering HTML messages.
- Do not send empty Reply-To, Cc, etc headers.
- More robust IMAP parser and response handling.
- Code cleanups, platform-dependent build fixes

(nia)

2021-10-17 10:06:28 UTC MAIN commitmail json YAML

pkgin: Prefer gzip on more 32-bit archs.

(nia)

2021-10-17 09:49:21 UTC MAIN commitmail json YAML

doc: Updated mail/alpine to 2.25

(nia)

2021-10-17 09:49:10 UTC MAIN commitmail json YAML

alpine: Update to 2.25.

pkgsrc changes and notes:

- According to the release notes, this fixes CVE-2021-38370 by
  Damian Poddebniak.
- I have added the maildir patch, as FreeBSD does, because it seems
  useful.
- I have removed the non-trivial patch for OpenBSD, because going by
  OpenBSD's ports repository it's no longer necessary at all.

  Version 2.25 includes several new features and bug fixes.

  Additions include:
    * Unix Alpine: New configuration variable ssl-ciphers that allows users
      to list the ciphers to use when connecting to a SSL server. Based on a
      collaboration with Professor Martin Trusler.
    * New hidden feature enable-delete-before-writing to add support for
      terminals that need lines to be deleted before being written. Based on
      a collaboration with Professor Martin Trusler.
    * Experimental: The instruction to remove the double quotes from the
      processing of customized headers existed in pine, but it was removed
      in alpine. Restoring old Alpine behavior. See this
    * Add the capability to record http debug. This is necessary to debug
      XOAUTH2 authentication, and records sensitive login information. Do
      not share your debug file if you use this form of debug.
    * Remove the ability to choose between the device and authorize methods
      to login to outlook, since the original client-id can only be used for
      the device method. One needs a special client-id and client-secret to
      use the authorize method in Outlook.
    * PC-Alpine only: Some service providers produce access tokens that are
      too long to save in the Windows Credentials, so the access tokens will
      be split and saved as several pieces. This means that old versions of
      Alpine will NOT be able to use saved passwords once this new version
      of Alpine is used.
    * PC-Alpine: Debug files used to be created with extension .txt1, .txt2,
      etc. Rename those files so that they have extension .txt.
    * Always follow â**suppress-asterisks-in-password-promptâ** setting in
      the various password prompts. Submitted by Étienne Deparis.
    * Use 'alpine -F' instead of 'pine -F' as the browser default pager.
      Submitted by Étienne Deparis.
    * Introduction of OTHER CMDS menu for the browser/pilot to let people
      discover the two new commands: "1" is a toggle that switches between 1
      column and multicolumn mode. The "." command toggles between hiding or
      showing hidden files, and the "G" command to travel between
      directories. Contributed by Étienne Deparis.
    * Add option -xoauth2-flow to the command line, so that users can
      specify the parameters to set up an xoauth2 connection through the
      command line.
    * Alpine deletes, from its internal memory and external cache, passwords
      that do not work, even if they were saved by the user.
    * New format for saving passwords in the windows credential manager for
      PC-Alpine. Upon starting this new version of Alpine the passwords
      saved in the credential manager are converted to the new format and
      they will not be recognized by old versions of Alpine, but only by
      this and newer versions of Alpine.
    * Enabled encryption protocols in PC-Alpine are based on those enabled
      in the system, unless one is specified directly.

  Bugs that have been addressed include:
    * The c-client library parses information from an IMAP server during
      non-authenticated state which could lead to denial of service.
      Reported by Damian Poddebniak from Münster University of Applied
      Sciences.
    * Memory corruption when alpine searches for a string that is an
      incomplete utf8 string in a local folder. This could happen by
      chopping a string to make it fit a buffer without regard to its
      content. We fix the string so that chopping it does not damage it.
      Reported by Andrew.
    * Crash in the ntlm authenticator when the user name does not include a
      domain. Reported and fixed by Anders Skargren.
    * When forwarding a message, replacing an attachment might make Alpine
      re-attach the original attachment. Reported by Michael Traxler.
    * When an attachment is deleted, the saved message with the deleted
      attachment contains extra null characters after the end of the
      attachment boundary.
    * Tcp and http debug information is not printed unless the default debug
      level is set to 1. Print this if requested, regardless of what the
      default debug level is.
    * When trying to select a folder for saving a message, one can only
      enter a subfolder by pressing the ">" command, rather than the normal
      navigation by pressing "Return". Reported by Ulf-Dietrich Braunmann.
    * Crash when attempting to remove a configuration for a XOAUTH2 server
      that has no usernames configured.
    * Crash caused by saving (and resaving) XOAUTH2 refresh and access
      tokens in PC-Alpine. Reported by Karl Lindauer.

(nia)

2021-10-17 09:02:57 UTC MAIN commitmail json YAML

doc: Updated security/acmesh to 3.0.1

(nia)

2021-10-17 09:02:46 UTC MAIN commitmail json YAML

acmesh: update to 3.0.1

Changes:

- We don't have bugs for the DST roots, but we add a new useful command "--set-default-chain" for the users to fix the chains fast.
- More dns apis are added.
- More deploy hooks are added.
- Normal bug fixes.

(nia)

2021-10-17 08:58:29 UTC MAIN commitmail json YAML

doc: Updated audio/abcmidi to 20211015

(nia)

2021-10-17 08:58:17 UTC MAIN commitmail json YAML

abcmidi: update to 20211015

September 15 2021

abc2midi bug:
The last fix in June 27 2021 inserting a break introduced a new bug.
The chord associated with the 'b' gchord code was missing. b and f
codes were indistinguishable. Fix: removed the break in the switch
statement for case b:

October 11 2021

abc2midi new feature:
In compliance with the ABC draft standard 2.2, I introduced additional
K: and V: options for transposition. You can now indicate the number
of semitones to transpose by giving the original note and the
corresponding transposed note in the K: or V: field using either
shift = note1note2
sound = note1note2
instrument = note1/note2
The number of semitones is determined by the difference note2 - note1.

Abcm2ps and abc2svg recognize this command, but abc2abc, yaps, and
abcmatch ignore this new option.

http://abcnotation.com/wiki/abc:standard:v2.2#transposition

October 15 2021

Abc2abc -P bug

X:1
T: P bug
M:4/4
L:1/4
V:1 clef=treble
V:2 clef=bass
%%staves [1 2]
K:C
V:1
C2 D2  |  C4 |
V:2
C,2 G,2 | C,4|

The command
abc2abc t.abc -t 3 -P 1
fails to transpose voice 1

This bug has been around since this option was introduced in June 7 2011.
Fortunately, it has not bothered anyone until recently.
If you add another K:c after the first V:1 command in the body as
shown below.

X:1
T: P bug
M:4/4
L:1/4
V:1 clef=treble
V:2 clef=bass
%%staves [1 2]
K:C
V:1
K:C
C2 D2  |  C4 |
V:2
C,2 G,2 | C,4|

then voice 1 will be transposed correctly. Unfortunately, there is
no easy fix. When the -P option is present, abc2abc ignores the
first K: field command. (In toabc.c line 1643 event_key aborts
prior to setting up the arrays for a key transpose. Commenting
out this return statement introduces another problem.)

The main issue is that abc2abc only does one pass through the
input file. It does not know whether there is a K: field command
following V:1. If it assumes that there is none and forces a
call to event_key in event_voice, there may be another problem
when a different K: field command is found eventually. I have
decided to suspend support to the -P option because it would be
too complicated to fix this.

(nia)

2021-10-17 07:14:37 UTC MAIN commitmail json YAML

doc: Updated databases/sqlite3 to 3.36.0nb1

(wiz)

2021-10-17 07:14:27 UTC MAIN commitmail json YAML

2021-10-17 07:13:59 UTC MAIN commitmail json YAML

2021-10-17 07:12:28 UTC MAIN commitmail json YAML

doc/TODO: add some

+ ImageMagick-7.1.0.10, fzf-0.27.3, musicpd-0.23, poppler-data-0.4.11,
  py-uritemplate-4.1.1, py-yarl-1.7.0, texlab-3.3.0.

(wiz)

2021-10-16 20:55:38 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6519

(tm)

2021-10-16 20:55:16 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6519 - requested by nia
graphics/pfstools: build fix

Revisions pulled up:
- graphics/pfstools/Makefile                                    1.78
- graphics/pfstools/PLIST                                      1.6

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Sat Oct 16 08:16:07 UTC 2021

  Modified Files:
  pkgsrc/graphics/pfstools: Makefile PLIST

  Log Message:
  pfstools: OpenEXR support is broken. Fix PLIST for now.

(tm)

2021-10-16 20:29:50 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6518

(tm)

2021-10-16 20:29:42 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6518 - requested by wiz
devel/apache-maven: security fix

Revisions pulled up:
- devel/apache-maven/Makefile                                  1.18
- devel/apache-maven/PLIST                                      1.12
- devel/apache-maven/distinfo                                  1.20
- devel/apache-maven/patches/patch-bin_mvn                      1.9

---
  Module Name: pkgsrc
  Committed By: wiz
  Date: Fri Oct  8 15:08:21 UTC 2021

  Modified Files:
  pkgsrc/devel/apache-maven: Makefile PLIST distinfo
  pkgsrc/devel/apache-maven/patches: patch-bin_mvn

  Log Message:
  apache-maven: update to 3.8.3.

  3.8.3

  ** Bug
        * [MNG-7045] - Drop CDI API from Maven
        * [MNG-7214] - Bad transitive dependency parent from CDI API
        * [MNG-7215] - [Regression] Maven Site Plugin cannot resolve parent site descriptor without locale
        * [MNG-7216] - Revert MNG-7170
        * [MNG-7218] - [Regression] o.a.m.model.Build.getSourceDirectory() incorrectly returns absolute dir on 3.8.2
        * [MNG-7219] - [Regression] plexus-cipher missing from transitive dependencies
        * [MNG-7220] - [REGRESSION] test-classpath incorrectly resolved
        * [MNG-7251] - Fix threadLocalArtifactsHolder leaking into cloned project
        * [MNG-7253] - Relocation message is never shown

  ** New Feature
        * [MNG-7164] - Add constructor MojoExecutionException(Throwable)

  ** Improvement
        * [MNG-7235] - Speed improvements when calculating the sorted project graph
        * [MNG-7236] - The DefaultPluginVersionResolver should cache results for the session

  ** Task
        * [MNG-7252] - Fix warnings issued by dependency:analyze
        * [MNG-7254] - Expand Windows native libraries for Jansi due to JDK-8195129 (workaround)

  3.8.2

  ** Sub-task
        * [MNG-6281] - ArrayIndexOutOfBoundsException caused by pom.xml with invalid/duplicate XML

  ** Bug
        * [MNG-4706] - Multithreaded building can create bad files for downloaded artifacts in local repository
        * [MNG-5307] - NPE during resolution of dependencies - parallel mode
        * [MNG-5315] - Artifact resolution sporadically fails in parallel builds
        * [MNG-5838] - Maven on No-File-Lock Systems
        * [MNG-5868] - Adding serval times the same artifact via MavenProjectHelper (attachArtifact) keep adding to the List duplicate artifacts
        * [MNG-6071] - GetResource ('/) returns 'null' if build is started with -f
        * [MNG-6216] - ArrayIndexOutOfBoundsException when parsing POM
        * [MNG-6239] - Jansi messes up System.err and System.out
        * [MNG-6380] - Option -Dstyle.color=always doesn't force color output
        * [MNG-6604] - Intermittent failures while downloading GAVs from Nexus
        * [MNG-6648] - 'mavenrc_pre' script does not receive arguments like mavenrc in Bourne shell does
        * [MNG-6719] - mvn color output escape keys w/ "| tee xxx.log" on Win with git/bash
        * [MNG-6737] - StackOverflowError when version ranges are unsolvable and graph contains a cycle
        * [MNG-6767] - Plugin with ${project.groupId} resolved improperly
        * [MNG-6819] - NullPointerException for DefaultArtifactDescriptorReader.loadPom
        * [MNG-6828] - DependencyResolutionException breaks serialization
        * [MNG-6842] - ProjectBuilderTest uses Guava, but Guava is not defined in dependencies
        * [MNG-6843] - Parallel build fails due to missing JAR artifacts in compilePath
        * [MNG-6850] - Prevent printing the EXEC_DIR when it's just a disk letter
        * [MNG-6921] - Maven compile with properties ${artifactId} and ${project.build.finalName} occurs java.lang.NullPointerException
        * [MNG-6937] - StringSearchModelInterpolatorTest fails on symlinked paths
        * [MNG-6964] - Maven version sorting is internally inconsistent
        * [MNG-6983] - Plugin key can get out of sync with artifactId and groupId
        * [MNG-7000] - metadata.mdo contains invalid link to schema
        * [MNG-7032] - Option -B still showing formatting when used with --version
        * [MNG-7034] - StackOverflowError thrown if a cycle exists in BOM imports
        * [MNG-7090] - mvnDebug does not work on Java 11+
        * [MNG-7127] - NullPointerException in MavenCliTest.testStyleColors in JDK 16
        * [MNG-7155] - make sources jar reproducible (upgrade maven-source-plugin to 3.2.1)
        * [MNG-7161] - Error thrown during uninstalling of JAnsi

  ** New Feature
        * [MNG-7149] - Introduce MAVEN_DEBUG_ADDRESS in mvnDebug scripts

  ** Improvement
        * [MNG-2802] - Concurrent-safe access to local Maven repository
        * [MNG-6471] - Parallel builder should use  the module name as thread name
        * [MNG-6754] - Set the same timestamp in multi module builds
        * [MNG-6810] - Remove profiles in maven-model
        * [MNG-6811] - Remove unnecessary filtering configuration
        * [MNG-6816] - Prefer System.lineSeparator() over system properties
        * [MNG-6827] - Replace deprecated StringUtils#defaultString() from Plexus Utils
        * [MNG-6837] - Simplify detection of the MAVEN_HOME and make it fully qualified on Windows
        * [MNG-6844] - Use StandardCharsets and remove outdated @SuppressWarnings
        * [MNG-6853] - Don't box primitives where it's not needed
        * [MNG-6859] - Build not easily reproducible when built from source release archive
        * [MNG-6873] - Inconsistent library versions notice
        * [MNG-6967] - Improve the command line output from maven-artifact
        * [MNG-6987] - Reorder groupId before artifactId when writing an exclusion using maven-model
        * [MNG-7010] - Omit "NB: JAVA_HOME should point to a JDK not a JRE" except when that is the problem
        * [MNG-7064] - Use HTTPS for schema location in global settings.xml
        * [MNG-7080] - Add a --color option
        * [MNG-7170] - Allow to associate pomFile/${basedir} with DefaultProjectBuilder.build(ModelSource, ...)
        * [MNG-7180] - Make --color option behave more like BSD/GNU grep's --color option
        * [MNG-7181] - Make --version support -q
        * [MNG-7185] - Describe explicit and recommended version for VersionRange.createFromVersionSpec()
        * [MNG-7190] - Load mavenrc from /usr/local/etc also in Bourne shell script

  ** Task
        * [MNG-6598] - Maven 3.6.0 and Surefire problem
        * [MNG-6884] - Cleanup POM File after version upgrade
        * [MNG-7172] - Remove expansion of Jansi native libraries
        * [MNG-7184] - document .mavenrc/maven_pre.bat|cmd scripts and
  MAVEN_SKIP_RC environment variable

  3.8.1

  This release with CVE fixes is a result based on the findings and feedback of Jonathan Leitschuh
  and Olaf Flebbe.

  One of the changes that might impact your builds is the way custom repositories defined in
  dependency POMs will be handled.
  By default external insecure repositories will now be blocked (localhost over HTTP will still
  work).
  Configuration can be adjusted via the conf/settings.xml.

  Release Notes - Maven - Version 3.8.1

  ** Bug

      * [MNG-7128] - improve error message when blocked repository defined in build POM

  ** New Feature

      * [MNG-7116] - Add support for mirror selector on external:http:*
      * [MNG-7117] - Add support for blocking mirrors
      * [MNG-7118] - Block external HTTP repositories by default

  ** Dependency upgrade
      * [MNG-7119] - Upgrade Maven Wagon to 3.4.3
      * [MNG-7123] - Upgrade Maven Resolver to 1.6.2

(tm)

2021-10-16 19:50:55 UTC MAIN commitmail json YAML

doc: Updated security/fail2ban to 0.11.2

(tm)

2021-10-16 19:50:39 UTC MAIN commitmail json YAML

doc: Updated net/proftpd to 1.3.7c

(tm)

2021-10-16 19:48:57 UTC MAIN commitmail json YAML

doc: Updated net/proftpd to 1.3.7c

(tm)

2021-10-16 19:46:42 UTC MAIN commitmail json YAML

Update proftpd to 1.3.7c

1.3.7c
  + Fix memory disclosure to RADIUS servers by mod_radius (Issue #1284).
  + PCRE expressions with capture groups were not being handled properly
    (Issue #1300).

1.3.7b
  + Fixed occasional segfaults with FTPS data transfers using TLSv1.3, when
    session tickets cannot be decrypted (Issue #1063).
  + Passive transfers fail unexpectedly due to use of SO_REUSEPORT socket
    option (Issue #1171).
  + Implemented support for Redis 6.x AUTH semantics (Issue #1070).
  + Fixed memory use-after-free issue in mod_sftp which can cause unexpected
    login/authentication issues.
  + Fixed SQL syntax regression for some generated SQL statements
    (Issue #1149).
  + Fixed "Corrupted MAC on inptut" errors when SFTP uses the
    umac-64@openssh.com digest (Issue #1111).

1.3.7a
  + Fix build-time regression when using the --localstatedir configure option.

1.3.7
  + Support the SOURCE_DATE_EPOCH environment variable, for reproducible
    builds (Issue #1038).

1.3.7rc4
  + Implemented support for configuring certificate options for LDAP
    connections using SSL/TLS.
  + Fixed issue with FTPS uploads of large files using TLSv1.3 (Issue #959).
  + Fixed handling of IPv6 addresses in From directives (Issue #682).
  + Added -b and -n command-line options to ftptop.
  + Ignore supplemental groups when run as non-root user (Issue #808).
  + Use re-entrant versions of time functions where available (Issue #983).
  + New Configuration Directives
    BanOptions
      The BanOptions directive is used to tune mod_ban behavior, such as
      creating ban entries that match/apply to all <VirtualHost> sections.
      See doc/contrib/mod_ban.html#BanOptions for more details.
    LDAPUseSASL
      The LDAPUseSASL directive configures a list of SASL authentication
      mechanisms to use, when using the LDAPBindDN to bind to the LDAP
      server.  See doc/contrib/mod_ldap.html#LDAPUseSASL for details.
    LogOptions
      The LogOptions directive is used to modify the default logging format
      for ProFTPD syslog, debug, and module logging.  See
      doc/modules/mod_log.html#LogOptions for more information.
    SQLKeepAlive
      The SQLKeepAlive directive configures a periodic "keepalive" query
      for ensuring the connection between mod_sql and the backend database
      server.  See doc/contrib/mod_sql.html#SQLKeepAlive for more information.
  + Changed Configuration Directives
    LDAPServer
      The LDAPServer directive now supports configuring the trusted CA
      file, client certificate and key files, SSL ciphers, and verification
      policies for LDAP connections.  See doc/contrib/mod_ldap.html#LDAPServer
      for more details.
    TraceOptions
      The TraceOptions directive now supports a "Timestamp" option, for
      disabling inclusion of timestamps in Trace logs.
  + Developer notes
    When MaxLoginAttempts is reach, the POST_CMD_ERR/LOG_CMD_ERR command
    handler phases will now run.  This allows interested modules, such
    as mod_exec and others, to react to these events (Issue #718).

1.3.7rc3
  + Fixed regression in directory listing latency (Issue #863).
  + Fixed use-after-free vulnerability during data transfers (Issue #903).
  + Addressed out-of-bounds read in mod_cap by removing bundled libcap, and
    relying solely on the system-provided libcap (Issue #902).  Note that
    building ProFTPD from source will *not* automatically include the
    mod_cap module, unless the libcap library is available.
  + mod_sftp now supports OpenSSH-specific private host keys (Issue #793).
    Newer versions of OpenSSH ssh-keygen(1) automatically generate private
    keys formatted with this OpenSSH-specific format.
  + mod_sftp now supports Ed25519 keys (Bug #4221).
  + mod_sftp now supports RSA SHA-2 publickey signatures, per RFC 8332
    (Issue #907).
  + mod_tls now honors client-provided SNI as part of the TLS handshake,
    for implementing name-based virtual hosts via TLS SNI.
  + Changed Configuration Directives
    LogFormat %{transfer-port}
      The LogFormat directive supports a %{transfer-port} variable for
      logging the selected data transfer port.
    SFTPOptions NoExtensionNegotiation
      The mod_sftp module now supports SSH extension negotations (RFC 8332).
      If there any issues with this support, it can be disabled using:
        SFTPOptions NoExtensionNegotiation
    SQLAuthTypes bcrypt
      The mod_sql_passwd module now supports bcrypt-encrypted passwords.
      This can be enabled using:
        SQLAuthTypes bcrypt
      in your mod_sql configuration.  See doc/contrib/mod_sql_password.html
      for more information.
    TLSOption IgnoreSNI
      The TLSOption directive now supports an "IgnoreSNI" setting, to
      tell mod_tls to ignore/not use any SNI, provided by the client in the
      TLS handshake, for determining any name-based virtual hosts.  See
      doc/contrib/mod_tls.html#TLSOption for more details.
  + Added API
    FSIO pread(2), pwrite(2) (Issue#317)

1.3.7rc2
  + Fixed pre-authentication remote denial-of-service issue (Issue #846,
    CVE-2019-18217).

1.3.7rc1
  + RootRevoke is now on by default, meaning that once authentication succeeds,
    all root privileges are dropped by default, unless the UserOwner directive
    (which requires root privileges) is used (Bug#4241).
  + The mod_ident module is no longer automatically built by default.
    To include the mod_ident module in the build, it must be explicitly
    requested via --enable-ident or --with-shared=mod_ident.
    This means that configuration files using the IdentLookups directive
    will now want to using an enclosing <IfModule> section, like so:
      <IfModule mod_ident.c>
        IdentLookups off
      </IfModule>
  + The mod_tls module now performs basic sanity checks of configured TLS
    files on startup (Issue#491).
  + The mod_deflate module now supports MODE Z data transfers when TLS
    is used (Issue#505).
  + The mod_xfer module now supports the RANG FTP command; see
    https://tools.ietf.org/html/draft-bryan-ftp-range-08 (Issue#351).
  + The ftpasswd script now supports a --change-home option, for changing
    the home directory of a user in an AuthUserFile (Issue#566).
  + The ftpasswd script supports deleting a user from a group (Issue#620).
  + Refactored the LogFormat handling code so that it is not longer
    duplicated by mod_log, mod_sql, etc.  The new Jot API is the common API
    to be used by modules for LogFormat variables and logging.
  + Generated new DH parameters for mod_sftp, mod_tls.
  + New Configuration Directives
    AuthFileOptions
      The mod_auth_file module supports a configuration directive for disabling
      its requirement for secure permissions on configured
      AuthUserFile/AuthGroupFile.  See
      doc/modules/mod_auth_file.html#AuthFileOptions for information.
    RedisLogOnEvent
      The mod_redis module can be configured to log JSON messages based on
      specified events (Issue#392).  See the
      doc/modules/mod_redis.html#RedisLogOnEvent documentation for details.
    RedisOptions
      The mod_redis module now implements a RedisOptions directive, for tuning
      some of the module behavior (Issue#477).  The
      doc/modules/mod_redis.html#RedisOptions documentation has more details.
    RedisSentinel
      The mod_redis module now supports use of Redis Sentinels (Issue#396);
      see doc/modules/mod_redis.html#RedisSentinel.
  + Changed Configuration Directives
    AllowForeignAddress class-name
      The AllowForeignAddress directive supports a Class name, for finer-grained
      control over which clients are allowed to use foreign/mismatching IP
      addresses for transfers.  See
      doc/modules/mod_core.html#AllowForeignAddress for more information.
    ExecEnviron %b
      The ExecEnviron directive has been fixed to properly resolve the %b
      LogFormat variable (Issue#515).
    RedisServer db-index (Issue#550)
      The mod_redis module can now be configured to select a database index
      via the RedisServer directive (Issue#550).  See the
      doc/modules/mod_redis.html#RedisServer documentation for details.
    RewriteMap idnatrans
      The mod_rewrite module can now support rewriting `idn` to `idna`
      formats (Issue#231).  See the doc/modules/mod_rewrite#RewriteMap for
      details on how to do so.
    RootRevoke on
      The RootRevoke directive is now enabled by default (Bug#4241).  This
      makes for more secure configurations/sessions out-of-the-box.  See
      doc/modules/mod_auth.html#RootRevoke for more information.
    SFTPCiphers, SFTPDigests
      Some weak algorithms are now disabled by default in mod_sftp (Bug#4279).
      These algorithms, if need be, can be explicitly enabled by configuration;
      they are just not enabled automatically.  For list of the algorithms
      affected, see doc/contrib/mod_sftp.html#SFTPCiphers,
      doc/contrib/mod_sftp.html#SFTPDigests.
    SFTPOptions IncludeSFTPTimes
      The SFTOptions directive of mod_sftp now supports an option for explicitly
      including the timestamps of files when SFTP protocol 4 and higher are
      used, even if the SFTP client did not request these timestamps.  This
      works around a bug in the popular Rebex SFTP library; see
      doc/contrib/mod_sftp.html#SFTPOptions for details.
    TLSProtocol TLSv1.3
      The mod_tls module, and its TLSProtocol directive, now support TLSv1.3
      (Issue#536).  See doc/contrib/mod_tls.html#TLSProtocol for more
      information.
    TLSServerCipherPreference
      The TLSServerCipherPreference directive is now enabled by default.
      See doc/contrib/mod_tls.html#TLSServerCipherPrefrence.
    TLSStaplingOptions NoFakeTryLater
      Some TLS clients have trouble with the "fake" OCSP response that mod_tls
      might stable, when the client requested stapled OCSP responses and
      mod_tls is unable to contact the OCSP responder.  Use this option to
      disable such fake responses (Issue#518):
        TLSStaplingOptions NoFakeTryLater
      See doc/contrib/mod_tls.html#TLSStaplingOptions for details.
  + Removed Configuration Directives
    The following directives have been removed:
      GroupPassword
      LoginPasswordPrompt
      TransferPriority

(tm)

2021-10-16 19:38:49 UTC MAIN commitmail json YAML

doc: Updated security/fail2ban to 0.11.2

(tm)

2021-10-16 19:37:01 UTC MAIN commitmail json YAML

Update fail2ban to 0.11.2

ver. 0.11.2 (2020/11/23) - heal-the-world-with-security-tools

Fixes:
* [stability] prevent race condition - no ban if filter (backend) is continuously busy if
  too many messages will be found in log, e. g. initial scan of large log-file or journal (gh-2660)
* pyinotify-backend sporadically avoided initial scanning of log-file by start
* python 3.9 compatibility (and Travis CI support)
* restoring a large number (500+ depending on files ulimit) of current bans when using PyPy fixed
* manual ban is written to database, so can be restored by restart (gh-2647)
* `jail.conf`: don't specify `action` directly in jails (use `action_` or `banaction` instead)
* no mails-action added per default anymore (e. g. to allow that `action = %(action_mw)s` should be specified
  per jail or in default section in jail.local), closes gh-2357
* ensure we've unique action name per jail (also if parameter `actname` is not set but name deviates from standard name, gh-2686)
* don't use `%(banaction)s` interpolation because it can be complex value (containing `[...]` and/or quotes),
  so would bother the action interpolation
* fixed type conversion in config readers (take place after all interpolations get ready), that allows to
  specify typed parameters variable (as substitutions) as well as to supply it in other sections or as init parameters.
* `action.d/*-ipset*.conf`: several ipset actions fixed (no timeout per default anymore), so no discrepancy
  between ipset and fail2ban (removal from ipset will be managed by fail2ban only, gh-2703)
* `action.d/cloudflare.conf`: fixed `actionunban` (considering new-line chars and optionally real json-parsing
  with `jq`, gh-2140, gh-2656)
* `action.d/nftables.conf` (type=multiport only): fixed port range selector, replacing `:` with `-` (gh-2763)
* `action.d/firewallcmd-*.conf` (multiport only): fixed port range selector, replacing `:` with `-` (gh-2821)
* `action.d/bsd-ipfw.conf`: fixed selection of rule-no by large list or initial `lowest_rule_num` (gh-2836)
* `filter.d/common.conf`: avoid substitute of default values in related `lt_*` section, `__prefix_line`
  should be interpolated in definition section (inside the filter-config, gh-2650)
* `filter.d/dovecot.conf`:
  - add managesieve and submission support (gh-2795);
  - accept messages with more verbose logging (gh-2573);
* `filter.d/courier-smtp.conf`: prefregex extended to consider port in log-message (gh-2697)
* `filter.d/traefik-auth.conf`: filter extended with parameter mode (`normal`, `ddos`, `aggressive`) to handle
  the match of username differently (gh-2693):
  - `normal`: matches 401 with supplied username only
  - `ddos`: matches 401 without supplied username only
  - `aggressive`: matches 401 and any variant (with and without username)
* `filter.d/sshd.conf`: normalizing of user pattern in all RE's, allowing empty user (gh-2749)

New Features and Enhancements:
* fail2ban-regex:
  - speedup formatted output (bypass unneeded stats creation)
  - extended with prefregex statistic
  - more informative output for `datepattern` (e. g. set from filter) - pattern : description
* parsing of action in jail-configs considers space between action-names as separator also
  (previously only new-line was allowed), for example `action = a b` would specify 2 actions `a` and `b`
* new filter and jail for GitLab recognizing failed application logins (gh-2689)
* new filter and jail for Grafana recognizing failed application logins (gh-2855)
* new filter and jail for SoftEtherVPN recognizing failed application logins (gh-2723)
* `filter.d/guacamole.conf` extended with `logging` parameter to follow webapp-logging if it's configured (gh-2631)
* `filter.d/bitwarden.conf` enhanced to support syslog (gh-2778)
* introduced new prefix `{UNB}` for `datepattern` to disable word boundaries in regex;
* datetemplate: improved anchor detection for capturing groups `(^...)`;
* datepattern: improved handling with wrong recognized timestamps (timezones, no datepattern, etc)
  as well as some warnings signaling user about invalid pattern or zone (gh-2814):
  - filter gets mode in-operation, which gets activated if filter starts processing of new messages;
    in this mode a timestamp read from log-line that appeared recently (not an old line), deviating too much
    from now (up too 24h), will be considered as now (assuming a timezone issue), so could avoid unexpected
    bypass of failure (previously exceeding `findtime`);
  - better interaction with non-matching optional datepattern or invalid timestamps;
  - implements special datepattern `{NONE}` - allow to find failures totally without date-time in log messages,
    whereas filter will use now as timestamp (gh-2802)
* performance optimization of `datepattern` (better search algorithm in datedetector, especially for single template);
* fail2ban-client: extended to unban IP range(s) by subnet (CIDR/mask) or hostname (DNS), gh-2791;
* extended capturing of alternate tags in filter, allowing combine of multiple groups to single tuple token with new tag
  prefix `<F-TUPLE_`, that would combine value of `<F-V>` with all value of `<F-TUPLE_V?_n?>` tags (gh-2755)

(tm)

2021-10-16 18:52:17 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6517

(tm)

2021-10-16 18:52:07 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6517 - requested by wiz
devel/ncurses: security fix

Revisions pulled up:
- devel/ncurses/Makefile                                        1.111
- devel/ncurses/distinfo                                        1.48
- devel/ncurses/patches/patch-ncurses_tinfo_captoinfo.c        1.1

---
  Module Name: pkgsrc
  Committed By: wiz
  Date: Sat Oct  9 07:52:36 UTC 2021

  Modified Files:
  pkgsrc/devel/ncurses: Makefile distinfo
  Added Files:
  pkgsrc/devel/ncurses/patches: patch-ncurses_tinfo_captoinfo.c

  Log Message:
  ncurses: fix for CVE-2021-39537 from upstream

  Many thanks to Thomas Dickey for help in tracking down the bugfix patch!

  PKGREVISION++

(tm)

2021-10-16 18:10:15 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6516

(tm)

2021-10-16 18:09:25 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6516 - requested by wiz
multimedia/libmediainfo: security fix
multimedia/mediainfo: security fix

Revisions pulled up:
- multimedia/libmediainfo/Makefile                              1.8
- multimedia/mediainfo/Makefile                                1.15
- multimedia/mediainfo/distinfo                                1.17
- multimedia/mediainfo/patches/patch-MediaInfoLib_Source_MediaInfo_Multiple_File__Gxf.cpp 1.1
- multimedia/mediainfo/patches/patch-MediaInfoLib_Source_MediaInfo_Multiple_File__MpegPs.cpp 1.1

---
  Module Name: pkgsrc
  Committed By: wiz
  Date: Thu Oct 14 07:03:02 UTC 2021

  Modified Files:
  pkgsrc/multimedia/libmediainfo: Makefile
  pkgsrc/multimedia/mediainfo: Makefile distinfo
  Added Files:
  pkgsrc/multimedia/mediainfo/patches:
      patch-MediaInfoLib_Source_MediaInfo_Multiple_File__Gxf.cpp
      patch-MediaInfoLib_Source_MediaInfo_Multiple_File__MpegPs.cpp

  Log Message:
  medainfo: fix two CVEs using upstream patches

  Bump PKGREVISION

(tm)

2021-10-16 17:51:50 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6515

(tm)

2021-10-16 17:51:39 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6515 - requested by wiz
databases/p5-DBI: security fix

Revisions pulled up:
- databases/p5-DBI/Makefile                                    1.87
- databases/p5-DBI/distinfo                                    1.54
- databases/p5-DBI/patches/patch-lib_DBD_File.pm                1.1

---
  Module Name: pkgsrc
  Committed By: wiz
  Date: Thu Oct 14 07:08:58 UTC 2021

  Modified Files:
  pkgsrc/databases/p5-DBI: Makefile distinfo
  Added Files:
  pkgsrc/databases/p5-DBI/patches: patch-lib_DBD_File.pm

  Log Message:
  p5-DBI: fix CVE-2014-10402

  Bump PKGREVISION

(tm)

2021-10-16 17:46:43 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6514

(tm)

2021-10-16 17:44:34 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6514 - requested by wiz
mail/neomutt: security fix

Revisions pulled up:
- mail/neomutt/Makefile                                        1.69
- mail/neomutt/PLIST                                            1.23
- mail/neomutt/distinfo                                        1.53
- mail/neomutt/patches/patch-resize.c                          deleted

---
  Module Name: pkgsrc
  Committed By: wiz
  Date: Fri Oct 15 11:43:54 UTC 2021

  Modified Files:
  pkgsrc/mail/neomutt: Makefile PLIST distinfo
  Removed Files:
  pkgsrc/mail/neomutt/patches: patch-resize.c

  Log Message:
  neomutt: update to 20211015.

  * Security
    - Fix CVE-2021-32055
  * Features
    - threads: implement the `$use_threads` feature
      https://neomutt.org/feature/use-threads
    - hooks: allow a -noregex param to folder and mbox hooks
    - mailing lists: implement list-(un)subscribe using RFC2369 headers
    - mailcap: implement x-neomutt-nowrap flag
    - pager: add `$local_date_header` option
    - imap, smtp: add support for authenticating using XOAUTH2
    - Allow `<sync-mailbox`> to fail quietly
    - imap: speed up server-side searches
    - pager: improve skip-quoted and skip-headers
    - notmuch: open database with user's configuration
    - notmuch: implement `<vfolder-window-reset>`
    - config: allow += modification of my_ variables
    - notmuch: tolerate file renames behind neomutt's back
    - pager: implement `$pager_read_delay`
    - notmuch: validate `nm_query_window_timebase`
    - notmuch: make $nm_record work in non-notmuch mailboxes
    - compose: add `$greeting` - a welcome message on top of emails
    - notmuch: show additional mail in query windows
  * Changed Config
  - Renamed lots of config, e.g.  `askbcc` to `ask_bcc`.
  * Bug Fixes
    - imap: fix crash on external IMAP events
    - notmuch: handle missing libnotmuch version bumps
    - imap: add sanity check for qresync
    - notmuch: allow windows with 0 duration
    - index: fix index selection on `<collapse-all>`
    - imap: fix crash when sync'ing labels
    - search: fix searching by Message-Id in `<mark-message>`
    - threads: fix double sorting of threads
    - stats: don't check mailbox stats unless told
    - alias: fix crash on empty query
    - pager: honor mid-message config changes
    - mailbox: don't propagate read-only state across reopens
    - hcache: fix caching new labels in the header cache
    - crypto: set invalidity flags for gpgme/smime keys
    - notmuch: fix parsing of multiple `type=`
    - notmuch: validate $nm_default_url
    - messages: avoid unnecessary opening of messages
    - imap: fix seqset iterator when it ends in a comma
    - build: refuse to build without pcre2 when pcre2 is linked in ncurses
  * Translation updates

(tm)

2021-10-16 14:02:56 UTC MAIN commitmail json YAML

2021-10-16 11:47:49 UTC MAIN commitmail json YAML

doc: Updated audio/ncspot to 0.9.0

(pin)

2021-10-16 11:47:27 UTC MAIN commitmail json YAML

audio/ncspot: update to 0.9.0

Maintenance:
-Sort library after saving an album (#428)
-Add scoop instruction for installation (#602)
-Update librespot to 0.3.0, see also release notes

Features:
-Add command to show recommendations (#593)
-Enable binding multiple commands to a key (#598)
-Add "Share album" contextmenu entry (#606)
-Add redraw command and bind to CTRL+L (#609)
-Add initial_screen config variable (#616)
-Add userRating entity to MPRIS metadata, with 0 and 1 corresponding to
unliked/liked in Spotify (#624)

Note on the pkgsrc package:
As of version 0.8.0, pancurses in no longer a feature but, a full dependency,
regardless of the choosen UI backend.
Reflect this by moving the dependency ncursesw into the package Makefile and
drop it from options.mk.

(pin)

2021-10-16 08:16:07 UTC MAIN commitmail json YAML

pfstools: OpenEXR support is broken. Fix PLIST for now.

(nia)

2021-10-16 07:16:30 UTC MAIN commitmail json YAML

2021-10-16 00:51:51 UTC MAIN commitmail json YAML

doc: Updated sysutils/findutils to 4.8.0

(ryoon)

2021-10-16 00:51:18 UTC MAIN commitmail json YAML

findutils: Update to 4.8.0

Changelog:
* Noteworthy changes in release 4.8.0 (2020-01-09) [stable]

** Changes in xargs

'xargs -t' no longer outputs a trailing blank to stderr after the last argument
of each constructed command line to be executed.  [#57291]

xargs now warns when more than one of the conflicting options --max-lines (-L,
-l), --replace (-i/-I) and --max-args (-n) are specified on the command line.
[#52137]

** Bug Fixes

find no longer crashes when an XFS filesystem is heavily changed during the run.
Discussed at: <lib/2020-04/msg00068.html>">https://lists.gnu.org/r/bug-gnulib/2020-04/msg00068.html>

find -used works again.  This predicate was not working properly since adding
the support for sub-second timestamp resolution for various predicates in
FINDUTILS_4_3_3-1 back in 2007.
Discussed at: <https://lists.gnu.org/r/bug-findutils/2019-11/msg00010.html>

** Improvements

'find -D exec' now diagnoses all -exec, -execdir, -ok and -okdir runs including
the call arguments and the exit code of the launched process. [#59083]

** Documentation Changes

The documentation of 'find -printf %Ak' has been improved: it now refers to the
strftime(3) documentation for a complete list of supported conversion
specifiers, and documents the 'F' conversion specifier ('yyyy-mm-dd').

The man pages (find.1, locate.1, locatedb.5, updatedb.1, and xargs.1) now
consistently end with the sections "REPORTING BUGS", "COPYRIGHT" and "SEE ALSO",
with the latter referring to the online page on the GNU web server.

The "EXAMPLES" section in the find.1 man page now shows the examples in a better
structure and uses consistent formatting.

Various man page fixes - syntax issues and typos.
[#59745, #59330, #59012, #58193, #57807, #57775]

Other documentation changes:

#58654: doc: clarify that 'find -perm +MODE' is unrelated to umask

#58458: doc: improve section 'Hard links', especially fix the description
        regarding 'find -L -samefile FILE'.

#58205: find.1: clarify double dash '--' option

#58149: 'xargs --help' now mentions that --replace (-I, -i) splits the input
        at newline characters.

#57025: doc: enhance description of tests accepting numeric arguments in find.1
        [see also #49640].

#54730: Add additional valuable example of find -quit

#48135: Fix testsuite error on Hurd and BSD related to ln

#35253: Clarify descriptions of -printf %f, %h.

** Changes to the build process

The configure option --without-fts has been removed.  The attempt to use
it stopped configure with an error message since 4.5.18 (2015) anyway.

* Major changes in release 4.7.0, 2019-08-29

** Changes to locate / updatedb

Support for generating old-format databases (with updatedb
--old-format or updatedb --dbformat=old) has been removed.  The old
database format was deprecated in 2007 (and updatedb has warned about
this since that time).  The locate program will will read old-format
databases, though this support also will be removed.

The updatedb script now operates in the C locale only.  This means
that character encoding issues are now not likely to cause sort to
fail.  It also honours the TMPDIR environment variable if that was
set, and no longer sorts file names case-insensitively.

The (unspecified) order in which filenames are stored in the locate
database is now different to previous versions.  However, you should
not rely on locate's output appearing in any particular order in any
case.

** Improvements

All utilities now only show the full usage text when requested via
the --help option.  Previously, when the user passed invalid options
or arguments, the user's attention to the corresponding error
diagnostic was distracted by that lengthy text.

find now accepts multiple file type arguments to the -type and -xtype
options separated by comma ','.  For example, to search for symbolic
links and directories simply provide the shorter '-type l,d' instead
of the - yet more portable - '( -type l -o -type d )'.

find now diagnoses failures returned by readdir().  This bug was inherent
in the use of FTS.

find now exits in more cases immediately after the error diagnostic, i.e.,
without the following usage text, to make the former more eye-catching.

find now outputs a better hint in case the user passed an unquoted shell-
glob pattern to options like -name, i.e., when the offending argument is
an existing file.

find now supports the debug option '-D all' to include all of the other
debug options at once.

xargs now supports the -o, --open-tty option to reopen stdin as /dev/tty
in the child process before executing the command; useful to run an
interactive application.  Added for compatibility with BSD.

xargs now supports the GNU_FINDUTILS_FD_LEAK_CHECK environment
variable to enable/disable fd leak check.

'xargs -t' (--verbose) now properly quotes each part of the command to the
executed if needed when printing it to stderr; likewise -p (--interactive).

** Documentation Changes

Prefer https:// over http:// links where possible, e.g. for '*.gnu.org' servers.

Both find.1 and the find texinfo manual now consistently document all of the
'N', 'L' and '?' possibilities in '-printf %Y' output when the determination of
the type of a symlink target fails.

find.1 now correctly states the -prune has no effect when the -depth option is
given.  Before, it wrongly stated that -prune would return false in that case.

Some minor documentation improvements are listed in "Bug Fixes" below.

** Bug Fixes

#56820: find: improve diagnostic when a global option like -maxdepth is
        specified after another argument like a test, thus hopefully avoiding
        translation issues (at least French, German).

#56142: doc: fix bug #56142 by specifying which actions inhibit the
        default -print.

#55272: find: improve diagnostic when -name or -iname is used with a pattern
        containing a directory separator ('/'), suggesting to use -wholename
        or -iwholename respectively.

#54859: doc: fix typo in 'xargs -l' examples in texinfo manual.
        Change from 'xargs -1' (minus one) to 'xargs -l' (minus El) in 3 places.

#54838: doc: fix the examples of the -perm option in the texinfo documentation.
        The example '-perm -g+w,o+w' was misplaced.
        Bug present since FINDUTILS_4_2_27-1.

#54262: 'find -printf "%Y"' now correctly outputs 'N' for broken symlinks
        (ENOENT or ENOTDIR).  Previously, it output 'l' in such a case.
        Bug introduced while attempting to fix #29460 in version v4.5.8.

#54171: 'find -depth' now outputs the name of unreadable directories.
        Previously, FTS-based find missed to output those entries.
        Bug present since the FTS implementation in FINDUTILS_4_3_0-1.

#52981: find: the '-delete' action no longer complains about disappeared files
        when the '-ignore_readdir_race' option is given, too.  That action will
        also returns true in such a case now.

#52220: 'find -D' without any further argument no longer crashes.
        Bug present since the implementation of -D in FINDUTILS_4_3_1-1.

#51304: doc: use correct IEC unit prefixes in the documentation of 'find -size'.
        find(1) uses binary-based units for the suffixes 'k', 'M', and 'G' of
        the argument of the '-size' option: 1024, 1024*1024 and 1024^3.
        Therefore, the documentation should use the correct IEC prefixes
        kibibyte, mebibyte and gibibyte respectively (or their abbreviations
        'KiB', 'MiB' and 'GiB').

#50758: doc: fix the description of the -perm examples matching the permission
        mode "022" in find's texinfo manual: the match is for the file's group
        and 'other' mode bits instead of for user and group.
        Bug introduced when adding the -perm examples in FINDUTILS-4.2.11.

#50326: find no longer leaks memory for a recently added member in gnulib's
        mount list structure.

#50259: find -printf '%h' now outputs the correct path for arguments with one or
        more trailing slashes.  Previously, it would e.g. output "foo" instead
        of "." when "foo/" was passed; likewise, it would output "/user/xxx/"
        instead of "/user" when "/user/xxx//" was passed.
        Bug introduced in FINDUTILS-4.2.19.

#48180: find -noop (an internal option not intended to be exposed to the user)
        no longer crashes.  Bug introduced in FINDUTILS-4.3.1.

#48030: find -exec + does not pass all arguments for certain specific filename
        lengths.  After the internal (usually 128k) buffer is full and find(1)
        executed the given command with these arguments, it would miss to run
        the command yet another time if only one other file argument has to be
        processed.  Bug introduced in FINDUTILS-4.2.12.

#46784: frcode drops last char if no final newline

** Changes to the build process

The configure option --enable-id-cache has been removed.  It has been
a no-op since findnutils-4.5.15.

The configure option --enable-debug has been removed.  Debugging in
find is now controlled by its -D option only.

The configure option --enable-silent-rules is the default now.
Use --disable-silent-rules or "make V=1" to get verbose build output.

"make dist" no longer builds .tar.gz files.
xz is portable enough and in wide-enough use that distributing
only .tar.xz files is enough.

Maintainer builds from the Git repository now derive the version string from
the version control system instead of using a fixed string (changed after each
release manually).  As a result, the inter-release builds can now be
distinguished: e.g. "4.6.0.152-fe9c" is the 152th commit after the tag "v4.6.0"
and has the Git short hash "fe9c".  Builds from an unclean tree are marked with
the suffix "-dirty".

The translation files in the PO directory are no longer version controlled;
instead bootstrap auto-updates them from "translationproject.org" during a
maintainer build.

A shell-style test framework borrowed from GNU coreutils has been added.
This allows better tests with more control over stdin, stdout, stderr,
signals, preparatory steps, cleanup, return code verification, root-only
tests, etc.

(ryoon)

2021-10-15 19:36:35 UTC MAIN commitmail json YAML

boost-libs: disable pch everywhere

Operating under the assumption that more and more platforms will be
RELRO enabled and this will keep breaking because the conditional is
not kept up-to-date. (it broke on aarch64 after RELRO enablement)

(tnn)

2021-10-15 15:06:32 UTC MAIN commitmail json YAML

gimp: needs gegl-0.4.32 or later

(bsiegert)

2021-10-15 15:06:14 UTC MAIN commitmail json YAML

Updated www/py-mechanize, textproc/py-html5-parser

(adam)

2021-10-15 15:05:59 UTC MAIN commitmail json YAML

py-html5-parser: updated to 0.4.10

0.4.10:
Unknown changes

(adam)

2021-10-15 15:04:47 UTC MAIN commitmail json YAML

glib2: Put back SunOS xattr fix.

For some reason this was removed in the last update.

(jperkin)

2021-10-15 15:02:25 UTC MAIN commitmail json YAML

py-mechanize: updated to 0.4.7

0.4.7 release
* Fix the ~ character being percent escaped when sending URLs to servers. See RFC 3986.

0.4.6 release
* Python 3.10 compatibility
* Fix a bug in the regex used to parse www-authenticate headers that could lead to Denial-of-Service

(adam)

2021-10-15 13:06:11 UTC MAIN commitmail json YAML

mozilla-rootcerts-openssl: ... and update PLIST for 2.7

(wiz)

2021-10-15 13:01:52 UTC MAIN commitmail json YAML

doc: Updated www/firefox-l10n to 93.0

(ryoon)

2021-10-15 13:01:18 UTC MAIN commitmail json YAML

firefox-l10n: Update to 93.0

* Sync with www/firefox-93.0.

(ryoon)

2021-10-15 13:00:38 UTC MAIN commitmail json YAML

doc: Updated www/firefox to 93.0

(ryoon)

2021-10-15 13:00:05 UTC MAIN commitmail json YAML

firefox: Update to 93.0

Changelog:
New

  * Firefox now supports the new AVIF image format, which is based on the
    modern and royalty free AV1 video codec. It offers significant bandwidth
    savings for sites compared to existing image formats. It also supports
    transparency and other advanced features.

  * Firefox PDF viewer now supports filling more forms (XFA-based forms, used
    by multiple governments and banks). Learn more.

  * When available system memory is critically low, Firefox on Windows will
    automatically unload tabs based on their last access time, memory usage,
    and other attributes. This should help reduce Firefox out-of-memory
    crashes. Switching to an unloaded tab automatically reloads it.

  * To prevent session loss for macOS users who are running Firefox from a
    mounted .dmg file, they??ll now be prompted to finish installation. This
    permission prompt only appears the first time these users run Firefox on
    their computer.

  * Firefox now blocks downloads that rely on insecure connections, protecting
    against potentially malicious or unsafe downloads. Learn more and see where
    to find downloads in Firefox.

  * Improved web compatibility for privacy protections with SmartBlock 3.0.
    Learn more

  * Introducing a new referrer tracking protection in Strict Tracking
    Protection and Private Browsing. Learn more

  * Introducing Firefox Suggest, a faster way to navigate the web. Learn more
    about the experience and locale-specific features.

Fixed

  * The VoiceOver screen reader now correctly reports checkable items in
    accessible tree controls as checked or unchecked.

  * The Orca screen reader now works correctly with Firefox, no longer
    requiring users to switch to another application after starting Firefox.

  * Various security fixes

Changed

  * TLS ciphersuites that use 3DES have been disabled. Such ciphersuites can
    only be enabled when deprecated versions of TLS are also enabled. Learn
    more.

  * The download panel now follows the Firefox visual styles.

Enterprise

  * Various bug fixes and new policies have been implemented in the latest
    version of Firefox. See more details in the Firefox for Enterprise 93
    Release Notes.

Developer

  * Developer Information

Web Platform

  * The UI for <input type="datetime-local"> has been implemented.

Security fixes:
#CVE-2021-38496: Use-after-free in MessageTask
#CVE-2021-38497: Validation message could have been overlaid on another origin
#CVE-2021-38498: Use-after-free of nsLanguageAtomService object
#CVE-2021-32810: Data race in crossbeam-deque
#CVE-2021-38500: Memory safety bugs fixed in Firefox 93, Firefox ESR 78.15, and
Firefox ESR 91.2
#CVE-2021-38501: Memory safety bugs fixed in Firefox 93 and Firefox ESR 91.2
#CVE-2021-38499: Memory safety bugs fixed in Firefox 93

(ryoon)

2021-10-15 12:35:13 UTC MAIN commitmail json YAML

doc: Updated sysutils/zoxide to 0.7.7

(pin)

2021-10-15 12:34:53 UTC MAIN commitmail json YAML

sysutils/zoxide: update to 0.7.7

-Fix PowerShell: Hook not initializing correctly.

(pin)

2021-10-15 12:33:34 UTC MAIN commitmail json YAML

doc: Updated mail/meli to 0.7.2

(pin)

2021-10-15 12:33:11 UTC MAIN commitmail json YAML

mail/meli: update to 0.7.2

Added:
-Add forward mail option
-Add url_launcher config setting
-Add add_addresses_to_contacts command
-Add show_date_in_my_timezone pager config flag
-docs: add pager filter documentation
-mail/view: respect per-folder/account pager filter override
-pager: add filter command, esc to clear filter
-Show compile time features in with command argument

Fixed:
-melib/email/address: quote display_name if it contains ","
-melib/smtp: fix Cc and Bcc ignored when sending mail
-melib/email/address: quote display_name if it contains "."

(pin)

2021-10-15 12:31:58 UTC MAIN commitmail json YAML

doc: Updated editors/featherpad to 1.0.1

(pin)

2021-10-15 12:31:37 UTC MAIN commitmail json YAML

editors/featherpad: update to 1.0.1

-Fixed the detection of UTF-16 in special cases.
-Fixed tab detaching when the window is closed with its last tab.
-Don't try to restore window position under Wayland.
-Better inertial scrolling with touchpad and sensitive devices.

(pin)

2021-10-15 12:30:24 UTC MAIN commitmail json YAML

doc: Updated archivers/arqiver to 0.9.0

(pin)

2021-10-15 12:30:01 UTC MAIN commitmail json YAML

archivers/arqiver: update to 0.9.0

V0.9.0
--------
-Show childless directories whose names contain the filtering string.
-Fixed viewing or removing of files that have wildcard characters in their names
with bsdtar (by escaping some wildcard characters that come after "--include").
-Better smooth scrolling from inside the view (especially with touchpad).
-Added read-only support for AppImage bundle through 7z.
-When viewing a file in a password protected archive, ask the password again if
a nonempty, wrong password is entered.
-When viewing files, warn the user of links without targets instead of trying to
open them.

(pin)

2021-10-15 12:21:02 UTC MAIN commitmail json YAML

Updated devel/py-slugify, devel/py-plumbum

(adam)

2021-10-15 12:20:27 UTC MAIN commitmail json YAML

py-plumbum: updated to 1.7.0

1.7.0

Commands: support .with_cwd()
Commands: make iter_lines deal with decoding errors during iteration
Commands: fix handling of env-vars passed to plumbum BoundEnvCommands
Commands: fix support for win32 in iter_lines
Paths: fix incorrect __getitem__ method in Path
Paths: Remote path stat had odd OSError
Paths: Fix RemotePath.copy()
Paths: missing __fspath__ added
SSH: better error reporting on SshSession error
Internal: redesigned CI, major cleanup to setuptools distribution, Black formatting, style checking throughout.

(adam)

2021-10-15 11:56:29 UTC MAIN commitmail json YAML

py-cookiecutter: not for Python 2.7 anymore

(adam)

2021-10-15 11:54:44 UTC MAIN commitmail json YAML

py-slugify: updated to 5.0.2

5.0.2
- Enable twine publish

5.0.1
- Drop support for python 2.7, 3.5 & tox, clean up

5.0.0
- Add support for Py 3.9 - added tox (@jon-betts - Thx)
- Drop support for python 2.7, 3.5 & friends

(adam)

2021-10-15 11:44:04 UTC MAIN commitmail json YAML

doc: Updated mail/neomutt to 20211015

(wiz)

2021-10-15 11:43:54 UTC MAIN commitmail json YAML

neomutt: update to 20211015.

* Security
  - Fix CVE-2021-32055
* Features
  - threads: implement the `$use_threads` feature
    https://neomutt.org/feature/use-threads
  - hooks: allow a -noregex param to folder and mbox hooks
  - mailing lists: implement list-(un)subscribe using RFC2369 headers
  - mailcap: implement x-neomutt-nowrap flag
  - pager: add `$local_date_header` option
  - imap, smtp: add support for authenticating using XOAUTH2
  - Allow `<sync-mailbox`> to fail quietly
  - imap: speed up server-side searches
  - pager: improve skip-quoted and skip-headers
  - notmuch: open database with user's configuration
  - notmuch: implement `<vfolder-window-reset>`
  - config: allow += modification of my_ variables
  - notmuch: tolerate file renames behind neomutt's back
  - pager: implement `$pager_read_delay`
  - notmuch: validate `nm_query_window_timebase`
  - notmuch: make $nm_record work in non-notmuch mailboxes
  - compose: add `$greeting` - a welcome message on top of emails
  - notmuch: show additional mail in query windows
* Changed Config
- Renamed lots of config, e.g.  `askbcc` to `ask_bcc`.
* Bug Fixes
  - imap: fix crash on external IMAP events
  - notmuch: handle missing libnotmuch version bumps
  - imap: add sanity check for qresync
  - notmuch: allow windows with 0 duration
  - index: fix index selection on `<collapse-all>`
  - imap: fix crash when sync'ing labels
  - search: fix searching by Message-Id in `<mark-message>`
  - threads: fix double sorting of threads
  - stats: don't check mailbox stats unless told
  - alias: fix crash on empty query
  - pager: honor mid-message config changes
  - mailbox: don't propagate read-only state across reopens
  - hcache: fix caching new labels in the header cache
  - crypto: set invalidity flags for gpgme/smime keys
  - notmuch: fix parsing of multiple `type=`
  - notmuch: validate $nm_default_url
  - messages: avoid unnecessary opening of messages
  - imap: fix seqset iterator when it ends in a comma
  - build: refuse to build without pcre2 when pcre2 is linked in ncurses
* Translation updates

(wiz)

2021-10-15 11:43:24 UTC MAIN commitmail json YAML

Updated graphics/py-leather, databases/py-pypika

(adam)

2021-10-15 11:42:45 UTC MAIN commitmail json YAML

py-pypika: updated to 0.48.8

0.48.8:
Unknown changes

(adam)

2021-10-15 11:41:23 UTC MAIN commitmail json YAML

py-leather: updated to 0.3.4

0.3.4:
* Add Python 3.10 support.

(adam)

2021-10-15 08:36:34 UTC MAIN commitmail json YAML

doc: Updated audio/libopenmpt to 0.5.12

(fcambus)

2021-10-15 08:36:22 UTC MAIN commitmail json YAML

libopenmpt: update to 0.5.12.

### libopenmpt 0.5.12 (2021-10-04)

*  [**Sec**] Possible crash when loading malformed MDL files. (r15603)

*  [**Bug**] Fixed various undefined behaviour found with ubsan.

*  Seeking with sample sync sometimes didn't compute the correct sample
    position with pingpong-looped samples.
*  IT: Tremor command I11 erroneously behaved like I00 (use previous
    parameter) unless IT Old Effects were enabled.
*  PTM: Panning was translated wrong in some edge cases.
*  IMF / PTM: Note Slide commands were sometimes slightly off.
*  OKT: Better support for fine note slides.
*  DBM: Echo enable effect parameter range checks were incorrect.
*  XM: Sample texts in XMs made with MadTracker are now also decoded using
    Windows-1252 encoding.

*  in_openmpt: Song metadata is no longer reverted when viewing file info.

(fcambus)

2021-10-14 20:37:58 UTC MAIN commitmail json YAML

emulators/simh: update PLIST too.

(rhialto)

2021-10-14 19:19:56 UTC MAIN commitmail json YAML

doc: Updated audio/termusic to 0.5.0

(pin)

2021-10-14 19:19:36 UTC MAIN commitmail json YAML

audio/termusic: update to 0.5.0

By default, termusic can display album cover in kitty or iterm2 (mac, not
tested). If you need album cover displayed on other terminals, please install
ueberzug.
-New: album photo for all kinds of terminals. Alacritty,kitty and st tested.
Require install ueberzug.

Note, this feature is not enabled by default.

(pin)

2021-10-14 19:13:12 UTC MAIN commitmail json YAML

doc: Updated emulators/simh to 4.0.0.20211012

(rhialto)

2021-10-14 19:12:56 UTC MAIN commitmail json YAML

emulators/simh: update to snapshot dated 2021-10-12.

Since there are no simh releases there are also no release notes to summarize.
The previous snapshot was over 3 years ago: 2018-09-19.

A somewhat controversial change with some people is that simh now
appends a "footer" block to disk image files, containing metadata
(struct simh_disk_footer).  ATTACH -r <disk_unit> <filename> will avoid
this but makes the device read-only.

New information from the README.md file:

    DO <stdin>                  Invokes a nested DO command with input from the
                                running console.
    RUNLIMIT Bound simulator execution time
    TAR                        Manipulate file archives
    CURL                        Access URLs from the web

Changes in the built emulator models:
- several new VAX models (vax8200, vaxstation{3100,4000}*, infoserver*)
- several new PDP-10 models (pdp10-{ka,ki,kl})
- new: pdp6
- Intel-Systems: Merge MDS, SDK, OEM simulators into Intel-MDS simulator

The files ka655x.bin and vmb.exe are no longer installed since they are
not required for operation (they are built into the VAX models that use
them), and it is strange to single out these ROM images out of over 30 to
install.  LOAD -r can load alternative versions.

(rhialto)

2021-10-14 18:58:39 UTC pkgsrc-2021Q3 commitmail json YAML

doc: removed duplicate entry, Pullup ticket #6513

(tm)

2021-10-14 16:49:59 UTC MAIN commitmail json YAML

shells/nushell: fix PLIST

(pin)

2021-10-14 13:09:26 UTC MAIN commitmail json YAML

doc: Updated geography/echomap to 0.6.1

(pin)

2021-10-14 13:09:03 UTC MAIN commitmail json YAML

geography/echomap: update to 0.6.1

-Updated dependencies
-Cleaned up newer clippy lints

(pin)

2021-10-14 12:42:43 UTC MAIN commitmail json YAML

mozilla-rootcerts-openssl: adapt for mozilla-rootcerts change

(wiz)

2021-10-14 12:42:16 UTC MAIN commitmail json YAML

mozilla-rootcerts: mention mozilla-rootcerts-openssl more prominently

(wiz)

2021-10-14 12:40:21 UTC MAIN commitmail json YAML

doc: Updated security/mozilla-rootcerts-openssl to 2.7

(wiz)

2021-10-14 12:40:10 UTC MAIN commitmail json YAML

mozilla-rootcerts-openssl: bump for 20211014.

(wiz)

2021-10-14 08:01:58 UTC MAIN commitmail json YAML

doc: Updated audio/librespot to 0.3.0

(pin)

2021-10-14 08:01:37 UTC MAIN commitmail json YAML

audio/librespot: update to 0.3.0

Added:
- [discovery] The crate `librespot-discovery` for discovery in LAN was created.
Its functionality was previously part of `librespot-connect`.
- [playback] Add support for dithering with `--dither` for lower requantization
error (breaking)
- [playback] Add `--volume-range` option to set dB range and control `log` and
`cubic` volume control curves
- [playback] `alsamixer`: support for querying dB range from Alsa softvol
- [playback] Add `--format F64` (supported by Alsa and GStreamer only)
- [playback] Add `--normalisation-gain-type auto` that switches between album
and track automatically

Changed:
- [audio, playback] Moved `VorbisDecoder`, `VorbisError`, `AudioPacket`,
`PassthroughDecoder`, `PassthroughError`, `DecoderError`, `AudioDecoder` and the
`convert` module from `librespot-audio` to `librespot-playback`. The underlying
crates `vorbis`, `librespot-tremor`, `lewton` and `ogg` should be used directly.
(breaking)
- [audio, playback] Use `Duration` for time constants and functions (breaking)
- [connect, playback] Moved volume controls from `librespot-connect` to
`librespot-playback` crate
- [connect] Synchronize player volume with mixer volume on playback
- [playback] Store and pass samples in 64-bit floating point
- [playback] Make cubic volume control available to all mixers with
`--volume-ctrl cubic`
- [playback] Normalize volumes to `[0.0..1.0]` instead of `[0..65535]` for
greater precision and performance (breaking)
- [playback] `alsamixer`: complete rewrite (breaking)
- [playback] `alsamixer`: query card dB range for the volume control unless
specified otherwise
- [playback] `alsamixer`: use `--device` name for `--mixer-card` unless
specified otherwise
- [playback] `player`: consider errors in `sink.start`, `sink.stop` and
`sink.write` fatal and `exit(1)` (breaking)
- [playback] `player`: make `convert` and `decoder` public so you can implement
your own `Sink`
- [playback] `player`: update default normalisation threshold to -2 dBFS
- [playback] `player`: default normalisation type is now `auto`

Deprecated:
- [connect] The `discovery` module was deprecated in favor of the
`librespot-discovery` crate
- [playback] `alsamixer`: renamed `mixer-card` to `alsa-mixer-device`
- [playback] `alsamixer`: renamed `mixer-name` to `alsa-mixer-control`
- [playback] `alsamixer`: renamed `mixer-index` to `alsa-mixer-index`

Removed:
- [connect] Removed no-op mixer started/stopped logic (breaking)
- [playback] Removed `with-vorbis` and `with-tremor` features
- [playback] `alsamixer`: removed `--mixer-linear-volume` option, now that
`--volume-ctrl {linear|log}` work as expected on Alsa

Fixed:
- [connect] Fix step size on volume up/down events
- [connect] Fix looping back to the first track after the last track of an album
or playlist
- [playback] Incorrect `PlayerConfig::default().normalisation_threshold` caused
distortion when using dynamic volume normalisation downstream
- [playback] Fix `log` and `cubic` volume controls to be mute at zero volume
- [playback] Fix `S24_3` format on big-endian systems
- [playback] `alsamixer`: make `cubic` consistent between cards that report
minimum volume as mute, and cards that report some dB value
- [playback] `alsamixer`: make `--volume-ctrl {linear|log}` work as expected
- [playback] `alsa`, `gstreamer`, `pulseaudio`: always output in native
endianness
- [playback] `alsa`: revert buffer size to ~500 ms
- [playback] `alsa`, `pipe`, `pulseaudio`: better error handling
- [metadata] Skip tracks whose Spotify ID's can't be found (e.g. local files,
which aren't supported)

(pin)

2021-10-14 07:38:17 UTC MAIN commitmail json YAML

Second attempt to correct the version number of the previous package update

(tron)

2021-10-14 07:35:55 UTC MAIN commitmail json YAML

mozilla-rootcerts: Use date of the last change as the version number

(tron)

2021-10-14 07:22:29 UTC MAIN commitmail json YAML

Note update of the "mozilla-rootcerts" package to version 1.0.20211014

(tron)

2021-10-14 07:21:43 UTC MAIN commitmail json YAML

2021-10-14 07:09:20 UTC MAIN commitmail json YAML

doc: Updated databases/p5-DBI to 1.643nb3

(wiz)

2021-10-14 07:09:11 UTC MAIN commitmail json YAML

doc: Updated multimedia/libmediainfo to 20.03nb1

(wiz)

2021-10-14 07:08:58 UTC MAIN commitmail json YAML

2021-10-14 07:03:02 UTC MAIN commitmail json YAML

2021-10-13 21:05:41 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6513

(tm)

2021-10-13 21:04:01 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6513 - requested by gutteridge
lang/python27: security fix

Revisions pulled up:
- lang/python27/Makefile                                        1.94
- lang/python27/distinfo                                        1.85
- lang/python27/patches/patch-Doc_library_cgi.rst              1.1
- lang/python27/patches/patch-Doc_library_urlparse.rst          1.1
- lang/python27/patches/patch-Lib_cgi.py                        1.1
- lang/python27/patches/patch-Lib_ctypes_test_test__parameters.py 1.1
- lang/python27/patches/patch-Lib_httplib.py                    1.4
- lang/python27/patches/patch-Lib_test_multibytecodec__support.py 1.1
- lang/python27/patches/patch-Lib_test_test__cgi.py            1.1
- lang/python27/patches/patch-Lib_test_test__httplib.py        1.4
- lang/python27/patches/patch-Lib_test_test__urlparse.py        1.1
- lang/python27/patches/patch-Lib_urllib2.py                    1.3
- lang/python27/patches/patch-Lib_urlparse.py                  1.1
- lang/python27/patches/patch-Modules___ctypes_callproc.c      1.2

---
  Module Name:    pkgsrc
  Committed By:  gutteridge
  Date:          Sun Oct 10 03:00:59 UTC 2021

  Modified Files:
          pkgsrc/lang/python27: Makefile distinfo
          pkgsrc/lang/python27/patches: patch-Lib_httplib.py
              patch-Lib_test_test__httplib.py patch-Lib_urllib2.py
              patch-Modules___ctypes_callproc.c
  Added Files:
          pkgsrc/lang/python27/patches: patch-Doc_library_cgi.rst
              patch-Doc_library_urlparse.rst patch-Lib_cgi.py
              patch-Lib_ctypes_test_test__parameters.py
              patch-Lib_test_multibytecodec__support.py
              patch-Lib_test_test__cgi.py patch-Lib_test_test__urlparse.py
              patch-Lib_urlparse.py

  Log Message:
  python27: fix various security issues

  Addresses CVE-2020-27619, CVE-2021-3177, CVE-2021-3733, CVE-2021-3737
  and CVE-2021-23336. Patches mostly sourced via Fedora.

(tm)

2021-10-13 20:51:04 UTC pkgsrc-2021Q3 commitmail json YAML

doc: Pullup ticket #6512

(tm)

2021-10-13 20:47:09 UTC pkgsrc-2021Q3 commitmail json YAML

Pullup ticket #6512 - requested by mlelstv
print/ghostscript-agpl: pullup and build fix

Revisions pulled up:
- print/ghostscript-agpl/Makefile.common          1.25
- print/ghostscript-agpl/PLIST                    1.20
- print/ghostscript-agpl/distinfo                  1.37
- print/ghostscript-agpl/patches/patch-configure    1.8

(tm)

2021-10-13 19:32:01 UTC MAIN commitmail json YAML

py-pythran: add buildlink3.mk

(adam)

2021-10-13 18:10:57 UTC MAIN commitmail json YAML

Set MKPIE_SUPPORTED to no, make them build again now that the default
changed to yes.

(bouyer)

2021-10-13 12:50:07 UTC MAIN commitmail json YAML

doc: Updated sysutils/zoxide to 0.7.6

(pin)

2021-10-13 12:49:45 UTC MAIN commitmail json YAML

sysutils/zoxide: update to 0.7.6

Changed:
-Nushell: upgrade minimum supported version to v0.37.0.

Fixed:
-Xonsh: error messages in zi.
-Xonsh: configuration environment variables not being handled correctly.

(pin)

2021-10-13 12:38:53 UTC MAIN commitmail json YAML

2021-10-13 12:35:39 UTC MAIN commitmail json YAML

doc: Updated devel/py-mercurial to 5.9.2

(wiz)

2021-10-13 12:35:29 UTC MAIN commitmail json YAML

2021-10-13 07:29:23 UTC MAIN commitmail json YAML

doc: Updated textproc/lowdown to 0.9.2

(fcambus)

2021-10-13 07:29:11 UTC MAIN commitmail json YAML

lowdown: update to 0.9.2.

Version 0.9.2, 2021-10-08

Significantly improve -Tterm output, both in terms of styles and layout.
Terminal output styles are easy to set as compile-time constants by editing
term.h. If you're going to edit this for a downstream installation of
lowdown, please let me know and I can stash it in a styles directory!

Add --term-no-ansi to disable all ANSI escapes in output. This produces a
clean, undecorated terminal-formatted document.

(fcambus)

2021-10-13 07:28:19 UTC MAIN commitmail json YAML

doc: Updated security/minisign to 0.10

(fcambus)

2021-10-13 07:28:08 UTC MAIN commitmail json YAML

minisign: update to 0.10.

- Minisign can be compiled with Zig instead of cmake+make+a C toolchain
- Minimal VERIFY_ONLY versions can be built again
- Prehashing is now enabled by default, regardless of the input size. Support
  for non-prehashed signatures will eventually be removed
- Legacy signatures can be rejected with the addition of the -H flag

(fcambus)

2021-10-13 07:24:40 UTC MAIN commitmail json YAML

doc: Updated x11/xterm to 369

(pin)

2021-10-13 07:24:11 UTC MAIN commitmail json YAML

x11/xterm: update to 369

-modify run-tic.sh to work around bug in development version of ncurses which
was packaged in FreeBSD ports.
-remove ifdef's for OPT_COLOR_RES and OPT_COLOR_RES2.
-improve performance over slow connections (report by Harald Dunkel).
-update cursor if restoring mode for DECTCEM.
-modify CharWidth macro to ensure that the shortcut for Latin-1 is only applied
when UTF-8 is not enabled, to fix a bug in handling soft-hyphen from patch #334
changes (patch by Martijn van Duren).
-improve terminfo:
-fill-in function-keys in terminfo which are not Sun/HP keyboards using
xterm+nopcfkeys building-block.
-add kbeg to xterm+keypad to accommodate termcap applications
-add smglp and smgrp to vt420+lrmm, to provide useful data for the "tabs"
+m option
-support shift-tab in Sun, HP and SCO keyboards.
-document some legacy features in ctlseqs.ms (prompted by discussion with Jimmy
Aguilar Mena "Ergus").
-add “trim” option to cdXtraScroll and tiXtraScroll.
-remove support for non-fifo save-lines configuration.
-extend cdXtraScroll to check if the cursor is at the upper-left of the
scrolling region when the erasure is for the remainder of the screen versus the
whole screen (prompted by discussion with Jörg Breitbart).
-add workaround for broken pcre2 package in Debian 10.
-change screen-refresh call used for DECCARA and DECRARA to ensure that trailing
blanks which are part of the rectangle are repainted (report/analysis by Dennis
Filder).
-when resetting the terminal, ensure that the cursor shape also is reset, e.g.,
if DECSCUSR has been used to modify the cursor shape for an xterm which was
started with the underlined cursor option (report/analysis by Luis Javier
Merino).
-prevent DECSCUSR from blinking the cursor if the cursorBlink resource is
“never” (report by Vladimir D Seleznev).
-invert the sense of DECSDM, to correspond with VT382 manuals (lsix #41).
-update tables in wcwidth.c based on Unicode 14.0.0

(pin)