Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (2m)  pkgsrc-2024Q1 (15d)  pkgsrc-2023Q4 (42d)  pkgsrc-2023Q2 (75d)  pkgsrc-2023Q3 (154d) 

2024-05-13 09:43:12 UTC Now

2019-07-13 15:41:41 UTC MAIN commitmail json YAML

doc: Updated textproc/gtkspell to 2.0.16nb30

(wiz)

2019-07-13 15:41:27 UTC MAIN commitmail json YAML

2019-07-13 14:28:40 UTC MAIN commitmail json YAML

doc: Updated databases/ruby-sequel to 5.22.0

(taca)

2019-07-13 14:28:18 UTC MAIN commitmail json YAML

databases/ruby-sequel: update to 5.22.0

=== 5.22.0 (2019-07-01)

* Fix Dataset#multi_insert and #import with return: :primary_key on MSSQL when the dataset has a row_proc (jeremyevans) (#1627)

* Support Dataset#with :materialized option on PostgreSQL 12 for [NOT] MATERIALIZED (jeremyevans)

* Make Database#primary_key_sequence work on tables without serial sequences on PostgreSQL 12 (jeremyevans)

* Support ruby 2.7+ startless ranges in the pg_range extension (jeremyevans)

* Support ruby 2.7+ startless, endless ranges in filters, using an always true condition for them (jeremyevans)

* Support ruby 2.7+ startless ranges in filters, using just a <= or < operator for them (jeremyevans)

(taca)

2019-07-13 11:29:06 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup tickets #5990 to #5997

(bsiegert)

2019-07-13 11:28:30 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5997 - requested by taca
fonts/ricty-ttf: build fix

Revisions pulled up:
- fonts/ricty-ttf/Makefile                                      1.24

---
  Module Name: pkgsrc
  Committed By: tsutsui
  Date: Fri Jul  5 16:24:08 UTC 2019

  Modified Files:
  pkgsrc/fonts/ricty-ttf: Makefile

  Log Message:
  ricty-ttf: follow move of inconsolata-ttf installation path.

  Also explicitly require moved version:
    http://mail-index.netbsd.org/pkgsrc-changes/2019/04/06/msg190085.html
    > inconsolata-ttf: update to 20090207nb2.
    > Use fonts.mk: Fixes installation path.

(bsiegert)

2019-07-13 11:12:03 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5996 - requested by nia
audio/faad2: security fix

Revisions pulled up:
- audio/faad2/Makefile                                          1.53
- audio/faad2/distinfo                                          1.27
- audio/faad2/patches/patch-CVE-2018-20194                      1.1
- audio/faad2/patches/patch-CVE-2018-20362                      1.1
- audio/faad2/patches/patch-libfaad_bits.c                      1.1

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Thu Jul 11 09:03:35 UTC 2019

  Modified Files:
  pkgsrc/audio/faad2: Makefile distinfo
  Added Files:
  pkgsrc/audio/faad2/patches: patch-CVE-2018-20194 patch-CVE-2018-20362
      patch-libfaad_bits.c

  Log Message:
  faad2: Backport some security fixes from upstream.

  CVE-2018-20194:
  https://github.com/knik0/faad2/commit/6b4a7cde30f2e2cb03e78ef476cc73179cfffda3.patch

  CVE-2018-20362:
  https://github.com/knik0/faad2/commit/466b01d504d7e45f1e9169ac90b3e34ab94aed14.patch

  Misc buffer overflows:
  https://github.com/knik0/faad2/commit/942c3e0aee748ea6fe97cb2c1aa5893225316174.patch

(bsiegert)

2019-07-13 11:09:46 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5995 - requested by nia
audio/libmad: security fix

Revisions pulled up:
- audio/libmad/Makefile                                        1.22
- audio/libmad/distinfo                                        1.5
- audio/libmad/patches/patch-bit.c                              1.1
- audio/libmad/patches/patch-frame.c                            1.1
- audio/libmad/patches/patch-layer12.c                          1.1
- audio/libmad/patches/patch-layer3.c                          1.1

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Wed Jul 10 20:01:57 UTC 2019

  Modified Files:
  pkgsrc/audio/libmad: Makefile distinfo
  Added Files:
  pkgsrc/audio/libmad/patches: patch-bit.c patch-frame.c patch-layer12.c
      patch-layer3.c

  Log Message:
  libmad: Add patches for CVE-2017-8372, CVE-2017-8373, CVE-2017-8374.

  >From Kurt Roeckx / Debian.

  Tested with cmus and moc.

(bsiegert)

2019-07-13 10:00:45 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5994 - requested by schmonz
net/fehqlibs: bugfix
net/djbdnscurve6, net/ucspi-ssl, net/ucspi-tcp6: bump revision

Revisions pulled up:
- net/djbdnscurve6/Makefile                                    1.6
- net/fehqlibs/Makefile                                        1.5
- net/fehqlibs/distinfo                                        1.4
- net/ucspi-ssl/Makefile                                        1.32
- net/ucspi-tcp6/Makefile                                      1.14

---
  Module Name:    pkgsrc
  Committed By:  schmonz
  Date:          Wed Jul 10 10:35:11 UTC 2019

  Modified Files:
          pkgsrc/net/fehqlibs: Makefile distinfo

  Log Message:
  .9.12 has a serious regression in dns_ipq.c: only AAAA records are
  looked up, instead of AAAA and A. Revert to previous 0.9.10 (as
  "0.9.12.10").

---
  Module Name:    pkgsrc
  Committed By:  schmonz
  Date:          Wed Jul 10 10:49:36 UTC 2019

  Modified Files:
          pkgsrc/net/djbdnscurve6: Makefile
          pkgsrc/net/ucspi-ssl: Makefile
          pkgsrc/net/ucspi-tcp6: Makefile

  Log Message:
  Bump PKGREVISION for fehqlibs-using packages.

(bsiegert)

2019-07-13 09:58:52 UTC MAIN commitmail json YAML

doc: Updated editors/nano to 4.3

(wiedi)

2019-07-13 09:58:15 UTC MAIN commitmail json YAML

nano: update to 4.3

2019.06.18 - GNU nano 4.3 "Musa Kart"
• The ability to read from and write to a FIFO has been regained.
• Startup time is reduced by fully parsing a syntax only when needed.
• Asking for help (^G) when using --operatingdir does not crash.
• The reading of a huge or slow file can be stopped with ^C.
• Cut, zap, and copy operations are undone separately when intermixed.
• M-D reports the correct number of lines (zero for an empty buffer).

(wiedi)

2019-07-13 09:43:56 UTC MAIN commitmail json YAML

clisp: make PS file generation dependent on the "doc" option.

It turns out disabling docs also disables generating the ps files.
Found while dealing with pullup ticket #5993 by he@.

(bsiegert)

2019-07-13 09:32:44 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5993 - requested by he
lang/clisp: build fix

Revisions pulled up:
- lang/clisp/Makefile                                          1.112

---
  Module Name: pkgsrc
  Committed By: he
  Date: Tue Jul  9 22:55:41 UTC 2019

  Modified Files:
  pkgsrc/lang/clisp: Makefile

  Log Message:
  Patterned after electric-fence, turn off builtins for calloc, malloc,
  memalign, realloc, valloc and free.  Makes clisp work with modern compilers.
  Bump PKGREVISION.

(bsiegert)

2019-07-13 09:32:29 UTC MAIN commitmail json YAML

Updated www/py-flask, archivers/py-zipp

(adam)

2019-07-13 09:32:04 UTC MAIN commitmail json YAML

py-zipp: updated to 0.5.2

v0.5.2
Parent of a directory now actually returns the parent.

(adam)

2019-07-13 09:28:59 UTC MAIN commitmail json YAML

py-flask: updated to 1.1.1

Version 1.1.1

The flask.json_available flag was added back for compatibility with some extensions. It will raise a deprecation warning when used, and will be removed in version 2.0.0.

Version 1.1.0

Bump minimum Werkzeug version to >= 0.15.
Drop support for Python 3.4.
Error handlers for InternalServerError or 500 will always be passed an instance of InternalServerError. If they are invoked due to an unhandled exception, that original exception is now available as e.original_exception rather than being passed directly to the handler. The same is true if the handler is for the base HTTPException. This makes error handler behavior more consistent.
Flask.finalize_request() is called for all unhandled exceptions even if there is no 500 error handler.
Flask.logger takes the same name as Flask.name (the value passed as Flask(import_name). This reverts 1.0窶冱 behavior of always logging to "flask.app", in order to support multiple apps in the same process. A warning will be shown if old configuration is detected that needs to be moved.
flask.RequestContext.copy() includes the current session object in the request context copy. This prevents session pointing to an out-of-date object.
Using built-in RequestContext, unprintable Unicode characters in Host header will result in a HTTP 400 response and not HTTP 500 as previously.
send_file() supports PathLike objects as described in PEP 0519, to support pathlib in Python 3.
send_file() supports BytesIO partial content.
open_resource() accepts the 窶徨t窶� file mode. This still does the same thing as 窶徨窶�.
The MethodView.methods attribute set in a base class is used by subclasses.
Flask.jinja_options is a dict instead of an ImmutableDict to allow easier configuration. Changes must still be made before creating the environment.
Flask窶冱 JSONMixin for the request and response wrappers was moved into Werkzeug. Use Werkzeug窶冱 version with Flask-specific support. This bumps the Werkzeug dependency to >= 0.15.
The flask command entry point is simplified to take advantage of Werkzeug 0.15窶冱 better reloader support. This bumps the Werkzeug dependency to >= 0.15.
Support static_url_path that ends with a forward slash.
Support empty static_folder without requiring setting an empty static_url_path as well.
jsonify() supports dataclasses.dataclass objects.
Allow customizing the Flask.url_map_class used for routing.
The development server port can be set to 0, which tells the OS to pick an available port.
The return value from cli.load_dotenv() is more consistent with the documentation. It will return False if python-dotenv is not installed, or if the given path isn窶冲 a file.
Signaling support has a stub for the connect_via method when the Blinker library is not installed.
Add an --extra-files option to the flask run CLI command to specify extra files that will trigger the reloader on change.
Allow returning a dictionary from a view function. Similar to how returning a string will produce a text/html response, returning a dict will call jsonify to produce a application/json response.
Blueprints have a cli Click group like app.cli. CLI commands registered with a blueprint will be available as a group under the flask command..
When using the test client as a context manager (with client:), all preserved request contexts are popped when the block exits, ensuring nested contexts are cleaned up correctly.
Show a better error message when the view return type is not supported.
flask.testing.make_test_environ_builder() has been deprecated in favour of a new class flask.testing.EnvironBuilder.
The flask run command no longer fails if Python is not built with SSL support. Using the --cert option will show an appropriate error message.
URL matching now occurs after the request context is pushed, rather than when it窶冱 created. This allows custom URL converters to access the app and request contexts, such as to query a database for an id.

(adam)

2019-07-13 09:22:20 UTC MAIN commitmail json YAML

Updated devel/yarn, textproc/py-deepdiff

(adam)

2019-07-13 09:21:59 UTC MAIN commitmail json YAML

py-deepdiff: updated to 4.0.7

4.0.7:
Hashing of the number 1 vs. True

(adam)

2019-07-13 09:18:53 UTC MAIN commitmail json YAML

yarn: updated to 1.17.3

1.17.3
Enforces https for the Yarn and npm registries.

1.17.2
Adds support for reading yarnPath from v2-produced .yarnrc.yml files.

1.17.0
Adds prereleases flags and prerelease identifier to yarn version.
Fixes audits when used with yarn add & yarn upgrade
Adds support for the --offline flag to yarn global add
Yarn will tolerate Yaml at parse time. Full support isn't ready yet and will only come at the next major.
Fixes a bug when using the link: protocol with a folder that doesn't contain a package.json

(adam)

2019-07-13 08:43:00 UTC MAIN commitmail json YAML

doc: Updated mail/msmtp to 1.8.5

(leot)

2019-07-13 08:42:47 UTC MAIN commitmail json YAML

msmtp: Update to 1.8.5

Changes:
1.8.5
-----
- Fixed OAUTHBEARER.
- Support for TLS client certificates via PKCS11 devices, e.g. smart cards.
- Various small bug fixes and improvements.

(leot)

2019-07-13 02:28:04 UTC MAIN commitmail json YAML

doc: Updated meta-pkgs/xfce4-extras to 4.14pre2

(gutteridge)

2019-07-13 02:27:38 UTC MAIN commitmail json YAML

xfce4-extras: also reflect version 4.14pre2 properly

(gutteridge)

2019-07-13 01:05:12 UTC MAIN commitmail json YAML

doc: Updated meta-pkgs/xfce4 to 4.14pre2

(gutteridge)

2019-07-13 01:05:02 UTC MAIN commitmail json YAML

2019-07-13 00:41:29 UTC MAIN commitmail json YAML

doc: Updated sysutils/xfce4-power-manager to 1.6.3

(gutteridge)

2019-07-13 00:40:32 UTC MAIN commitmail json YAML

doc: Updated sysutils/xfce4-cpugraph-plugin to 1.1.0

(gutteridge)

2019-07-13 00:40:22 UTC MAIN commitmail json YAML

xfce4-cpugraph-plugin: update to 1.1.0 (2/7/2019)

Change log:

1.1.0 (2/7/2019)
=====
- Updated translations

1.0.91 (22/6/2019)
=====
- Add option to disable the graph (Bug #15163)
- Use css to change bar colors (Bug #15186)
- Fix bars in horizontal mode
- Updated translations

(gutteridge)

2019-07-13 00:36:40 UTC MAIN commitmail json YAML

doc: Updated sysutils/xfce4-appfinder to 4.13.4

(gutteridge)

2019-07-13 00:36:30 UTC MAIN commitmail json YAML

xfce4-appfinder: update to 4.13.4

Change log:

4.13.4
======
- Improve xfce4-run comment (Bug #15473)
- Translation updates: Armenian, Belarusian, Bulgarian, Catalan,
  Chinese (Taiwan), Croatian, Czech, Danish, Dutch (Flemish), French, Galician,
  German, Hungarian, Interlingue, Italian, Lithuanian, Malay, Polish,
  Portuguese, Russian, Spanish

(gutteridge)

2019-07-13 00:35:15 UTC MAIN commitmail json YAML

doc: Updated sysutils/xfce4-thunar to 1.8.7

(gutteridge)

2019-07-13 00:35:06 UTC MAIN commitmail json YAML

xfce4-thunar: update to 1.8.7

Change log:

1.8.7
=====
- Fix crash on unmounted volume in tree pane right click (Bug #15452)
- Do not check G_FILE_ATTRIBUTE_ACCESS_CAN_WRITE anymore (Bug #15367)
- Deactivate "Move to Trash" menu entry on volumes without trash (Bug #15352)
- thunar-sendto-email.desktop: use xdg mail-send icon
- Restore "Empty File" menu icon (Bug #15540)
- Rename Camelcase to Title Case (Bug #15579)
- Update mimeapps.list only when necessary (Bug #15533)
- Prevent new bookmarks on sidebar when dragging files (Bug #14921)
- Translation updates: Albanian, Armenian (Armenia), Belarusian, Catalan,
Chinese (China), Chinese (Taiwan), Croatian, Czech, Danish,
English (Australia), Finnish, French, Galician, German, Hebrew, Hungarian,
Interlingue, Italian, Japanese, Malay, Norwegian Nynorsk, Portuguese, Russian,
Serbian, Spanish, Thai, Turkish

(gutteridge)

2019-07-13 00:32:57 UTC MAIN commitmail json YAML

xfce4-power-manager: update to 1.6.3

Change log:

1.6.3
=====
- Revert "Read from actual_brightness instead of brightness"
- Translation updates:
  Danish, English (Australia), Portuguese, Serbian, Turkish

(gutteridge)

2019-07-13 00:29:02 UTC MAIN commitmail json YAML

doc: Updated x11/xfce4-desktop to 4.13.5

(gutteridge)

2019-07-13 00:28:51 UTC MAIN commitmail json YAML

xfce4-desktop: update to 4.13.5

Change log:

4.13.5
======
- Highlight drag target when hovering it (Bug #12695)
- Fix drag data being received multiple times (Bug #14471)
- Allow to load non-theme icons (Bug #15294)
- Add Next Background option (Bug #12261)
- Do not cycle backdrop twice
- Ensure that CSD is not applied to desktop window (Bug #15241)
- Use async dbus proxy initialization (Bug #15418)
- Open all selected icons on key press (Bug #15420)
- Improve fallback CSS
- Fix warning about ignoring return value (Bug #15410)
- Update README.xfconf (Bug #15457)
- Translation Updates: Albanian, Armenian (Armenia), Belarusian, Bulgarian,
  Catalan, Chinese (Taiwan), Croatian, Danish, Dutch, English (Australia),
  Finnish, French, Galician, German, Hebrew, Hungarian, Interlingue, Italian,
  Lithuanian, Malay, Persian (Iran), Polish, Portuguese, Russian, Serbian,
  Spanish, Thai, Turkish

(gutteridge)

2019-07-13 00:24:41 UTC MAIN commitmail json YAML

doc: Updated x11/xfce4-tumbler to 0.2.5

(gutteridge)

2019-07-13 00:24:21 UTC MAIN commitmail json YAML

xfce4-tumbler: update to 0.2.5

Change log:

0.2.5
=====
- Translation Updates: Armenian, Danish

(gutteridge)

2019-07-13 00:21:17 UTC MAIN commitmail json YAML

doc: Updated x11/xfce4-session to 4.13.3

(gutteridge)

2019-07-13 00:21:07 UTC MAIN commitmail json YAML

xfce4-session: update to 4.13.3

Change log:

4.13.3
======
- Reset font-size of logout dialog to default (Bug #15505)
- Report optional dependency on polkit (Bug #12761)
- Read data from correct group when editing autostart entry (Bug
  #10423)
- Improve layout of autostart add/edit dialogs
- Improve column layout of autostart tab (Bug #15448)
- settings: Fix crash when terminating programs (Bug #15489)
- Translation updates:
  Belarusian, Danish, English (Australia), Finnish, French, German,
  Hebrew, Hungarian, Kazakh, Malay, Portuguese, Portuguese (Brazilian),
  Turkish

(gutteridge)

2019-07-13 00:19:08 UTC MAIN commitmail json YAML

doc: Updated x11/xfce4-settings to 4.13.7

(gutteridge)

2019-07-13 00:18:56 UTC MAIN commitmail json YAML

xfce4-settings: update to 4.13.7

Change log:

4.13.7
======
- Bugfixes and other small changes:
  - color:
    - Fix crash when launching gcm in plugged dialog (Bug #15426)
    - Set correct icon in color dialogs
  - display:
    - Replace deprecated icon (Bug #15416)
    - Add mnemonics to minimal dialog buttons (Bug #15449)
    - Disable auto-enabling profiles by default
  - settings-manager: Fix missing icons on resize/add/remove (Bugs #15428, #15613)
  - xfsettingsd: Fix numlock state restoration (Bug #15642)
- Translation Updates:
    Belarusian, Danish, English (Australia), Finnish, French, Indonesian,
    Lithuanian, Portuguese (Brazilian), Serbian, Turkish

(gutteridge)

2019-07-13 00:16:43 UTC MAIN commitmail json YAML

doc: Updated x11/xfce4-panel to 4.13.6

(gutteridge)

2019-07-13 00:15:56 UTC MAIN commitmail json YAML

xfce4-panel: update to 4.13.6

Change log:

4.13.6
======
- Update default panel layout
- Bugfixes:
  - Retain original GDK_CORE_DEVICE_EVENTS setting for plugins (Bug
  #15044)
  - directorymenu: Fix plugin menu autohide behaviour
  - prefs: Add missing mnemonic accelerators (Bug #15652)
  - prefs: Improve window title (Bug #15653)
  - prefs: Correct capitalization of labels (Bug #15651)
  - arrow-button: Allow connect_after signals on draw
  - tasklist: Draw grouped windows count indicator (Bug #10844)
  - tasklist: Only base bg color of group indicator on Gtk theme
  - tasklist: Avoid draw signal loop
  - tasklist: Don't show actionsmenu in grouped windows (Bug #15622)
  - Add more accelerators to dialog buttons (Bug #15490)
  - AC_CONFIG_MACRO_DIR -> AC_CONFIG_MACRO_DIRS
  - Fix typo in debug output
- Translation updates:
    Albanian, Bulgarian, Catalan, Chinese (China), Chinese (Taiwan),
    Croatian, Czech, Danish, Dutch (Flemish), English (Australia), French,
    German, Italian, Lithuanian, Polish, Portuguese, Portuguese
    (Brazilian), Serbian, Spanish, Turkish

(gutteridge)

2019-07-13 00:06:03 UTC MAIN commitmail json YAML

doc: Updated devel/xfce4-conf to 4.13.8

(gutteridge)

2019-07-13 00:05:50 UTC MAIN commitmail json YAML

xfce4-conf: update to 4.13.8

XXX GObject introspection and Vala support has not yet been enabled in
pkgsrc. This is probably an optional dependency, TBD.

Change log:

4.13.8
======
- Add support for GObject introspection and vala
- Tests: Explicitly handle error reply from Ping method call
- Disable perl bindings by default
- Translation Updates: Danish, Armenian (Armenia)

(gutteridge)

2019-07-13 00:01:08 UTC MAIN commitmail json YAML

doc: Updated x11/xfce4-garcon to 0.6.3

(gutteridge)

2019-07-13 00:00:57 UTC MAIN commitmail json YAML

xfce4-garcon: update to 0.6.3

Change log:

0.6.3
=====
- Fix g_type_class_add_private deprecation in recent GLib
- Translation Updates:
  Albanian, Basque, Bengali, Czech, Danish, Hebrew, Icelandic, Italian,
  Kazakh, Polish, Russian, Spanish

(gutteridge)

2019-07-12 23:57:06 UTC MAIN commitmail json YAML

doc: Updated wm/xfce4-wm to 4.13.3

(gutteridge)

2019-07-12 23:56:54 UTC MAIN commitmail json YAML

xfce4-wm: update to 4.13.3

Change log:

4.13.3
======
- Update CSS for tabwinb only on theme change (Viktor Odintsev)
- HiDPI: Use GTK3 scaling attributes for window titles (Viktor Odintsev)
- HiDPI: Adjust default theme with scale
- Fix initial pointer location when zooming
- Fix double-click distance setting (Adam K)
- Allow the top of the frame to be cropped when maximised (Adam K,
  bug #14470)
- Update default theme to use maximized cropping
- Fix build without compositor (bug #15432)
- Improved GLX support with NVIDIA proprietary/closed source driver
  (bug #15453)
- Compositor updates with GLX
- Small optimization with zoom on GLX
- Increase X11 client priority of xfwm4
- Change default compositor background to plain black
- Fallback to resource class name for icons (Iharob Al Asimi, bug #15510)
- Clear shortcut in settings-dialog when removed (bug #12802)
- Remove icons from window menu
- Fix regression with maximized window (bug #15638)
- I18n: Update translations: bg, ca, cs, da, de, es, fr, gl, hr, hu,
  hy_AM, id, ie, it, lt, ms, nl, pl, pt, pt_BR, ru, sr, tr, zh_CN, zh_TW

(gutteridge)

2019-07-12 23:53:20 UTC MAIN commitmail json YAML

doc: Updated x11/libxfce4ui to 4.13.6

(gutteridge)

2019-07-12 23:53:07 UTC MAIN commitmail json YAML

libxfce4ui: update to 4.13.6

Change log:

4.13.6
======
- Update active contributors
- Translation Updates:
  Albanian, Belarusian, Catalan, Danish, Dutch (Flemish), English
  (Australia), Finnish, Galician, Hebrew, Hungarian, Italian, Japanese,
  Kazakh, Malay, Portuguese, Portuguese (Brazilian), Russian, Serbian,
  Spanish, Thai, Turkish

(gutteridge)

2019-07-12 23:51:07 UTC MAIN commitmail json YAML

doc: Updated x11/libxfce4util to 4.13.4

(gutteridge)

2019-07-12 23:50:34 UTC MAIN commitmail json YAML

libxfce4util: update to 4.13.4

Change log:

4.13.4
======
- Bump the Xfce version to 4.14pre2
- Translation Updates: Danish, Galician

(gutteridge)

2019-07-12 23:45:06 UTC MAIN commitmail json YAML

doc: Updated devel/xfce4-dev-tools to 4.13.0

(gutteridge)

2019-07-12 23:44:43 UTC MAIN commitmail json YAML

xfce4-dev-tools: update to 4.13.0

Change log:

4.13.0
======
- Merge exo-csource modifications in xdt-csource
- xdt-csource will replace exo-csource (projects using exo-csource needs to be updated)
- The work started in issue #6449 but the full migration has never been done.
- Remove svn support in xdt-autogen
- Simplify a bit the XDT_AUTOGEN_REQUIRED_VERSION detection
- Remove the check of the unused doc submodule
- Remove useless macros: m4macros/xdt-python.m4 and m4macros/xdt-xfce.m4 are not used
- Remove xdt-commit, used to generate Changelog, now done via make distcheck
- No -Wshadow flag for enable_debug=full (bug #11637). Use it only for enable_debug=yes.

(gutteridge)

2019-07-12 19:58:03 UTC MAIN commitmail json YAML

Updated devel/protobuf, devel/py-protobuf

(adam)

2019-07-12 19:57:37 UTC MAIN commitmail json YAML

py-protobuf: updated to 3.9.0

Protocol Buffers v3.9.0

Python

Change implementation of Name() for enums that allow aliases in proto2 in Python
to be in line with claims in C++ implementation (to return first value).
Explicitly say what field cannot be set when the new value fails a type check.
Duplicate register in descriptor pool will raise errors
Add slots to all well_known_types classes, custom attributes are not allowed anymore.
text_format only present 8 valid digits for float fields by default

(adam)

2019-07-12 19:57:03 UTC MAIN commitmail json YAML

protobuf: updated to 3.9.0

Protocol Buffers v3.9.0

C++

Optimize and simplify implementation of RepeatedPtrFieldBase
Don't create unnecessary unknown field sets.
Remove branch from accessors to repeated field element array.
Added delimited parse and serialize util.
Reduce size by not emitting constants for fieldnumbers
Fix a bug when comparing finite and infinite field values with explicit tolerances.
TextFormat::Parser should use a custom Finder to look up extensions by number if one is provided.
Add MessageLite::Utf8DebugString() to make MessageLite more compatible with Message.
Fail fast for better performance in DescriptorPool::FindExtensionByNumber() if descriptor has no defined extensions.
Adding the file name to help debug colliding extensions
Added FieldDescriptor::PrintableNameForExtension() and DescriptorPool::FindExtensionByPrintableName().
The latter will replace Reflection::FindKnownExtensionByName().
Replace NULL with nullptr
Created a new Add method in repeated field that allows adding a range of elements all at once.
Enabled enum name-to-value mapping functions for C++ lite
Avoid dynamic initialization in descriptor.proto generated code
Move stream functions to MessageLite from Message.
Move all zero_copy_stream functionality to io_lite.
Do not create array of matched fields for simple repeated fields
Enabling silent mode by default to reduce make compilation noise.

(adam)

2019-07-12 19:07:36 UTC MAIN commitmail json YAML

Updated databases/py-orderedmultidict, sysutils/py-crontab, devel/py-meson, time/py-aniso8601

(adam)

2019-07-12 19:07:09 UTC MAIN commitmail json YAML

py-aniso8601: updated to 7.0.0

Changes 7.0.0
Handle all fractional components as an integer number of microseconds, eliminating rounding issues

(adam)

2019-07-12 19:03:40 UTC MAIN commitmail json YAML

py-meson: updated to 0.51.1

0.51.1:
Unknown changes

(adam)

2019-07-12 18:57:58 UTC MAIN commitmail json YAML

py-crontab: updated to 2.3.8

Version 2.3.8
- Updated RADME and special time setting fixes.
- Attempt a fix of issue 27 (no test suite test)
- Merge branch 'master' into 'master'
- update README.rst file
- Fix 48, specials can't be changed to another time.
- Bump version for pypi update
- Fix 41 dead link to github
- Ignore mypy_cache
- Fix 39 - Tab next to username will parse correctly
- Merge remote-tracking branch 'flotus/patch-1'
- Improve explaination about using the write function
- fixed environment

(adam)

2019-07-12 18:53:58 UTC MAIN commitmail json YAML

2019-07-12 15:41:04 UTC MAIN commitmail json YAML

doc: Updated security/mit-krb5 to 1.16.2nb2

(jperkin)

2019-07-12 15:40:55 UTC MAIN commitmail json YAML

mit-krb5: Support LDAP, fix plugin shared library naming.

The libtool-ification caused plugins to have a "lib" prefix, causing a mismatch
with what the code was trying to dlopen(), and failures.  Bump PKGREVISION.

(jperkin)

2019-07-12 15:34:55 UTC MAIN commitmail json YAML

LDFLAGS.SunOS+=-lnsl -lsocket to fix SmartOS.

(schmonz)

2019-07-12 13:29:31 UTC MAIN commitmail json YAML

Add PNG support.

Fixes PR pkg/54371

(hauke)

2019-07-12 12:50:05 UTC MAIN commitmail json YAML

Updated databases/repmgr

(adam)

2019-07-12 12:49:27 UTC MAIN commitmail json YAML

repmgr: updated to 4.4.0

4.4.0:
repmgr client enhancements
--------------------------

repmgr standby clone: prevent a standby from being cloned from a witness server (PostgreSQL 9.6 and later only).

repmgr witness register: prevent a witness server from being registered on the replication cluster primary server (PostgreSQL 9.6 and later only).

Registering a witness on the primary node would defeat the purpose of having a witness server, which is intended to remain running even if the cluster's primary goes down.

repmgr standby follow: note that an active, reachable cluster primary is required for this command; and provide a more helpful error message if no reachable primary could be found.

repmgr: when executing repmgr standby switchover, if --siblings-follow is not supplied, list all nodes which repmgr considers to be siblings (this will include the witness server, if in use), and which will remain attached to the old primary.

repmgr: when executing repmgr standby switchover, ignore nodes which are unreachable and marked as inactive. Previously it would abort if any node was unreachable, as that means it was unable to check if repmgrd is running.

However if the node has been marked as inactive in the repmgr metadata, it's reasonable to assume the node is no longer part of the replication cluster and does not need to be checked.

repmgr standby switchover and repmgr standby promote: when executing with the --dry-run option, continue checks as far as possible even if errors are encountered.

repmgr standby promote: add --siblings-follow (similar to repmgr standby switchover).

repmgr daemon status: make output similar to that of repmgr cluster show for consistency and to make it easier to identify nodes not in the expected state.

repmgr cluster show: display each node's timeline ID (PostgreSQL 9.6 and later only).

repmgr cluster show and repmgr daemon status: show the upstream node name as reported by each individual node - this helps visualise situations where the cluster is in an unexpected state, and provide a better idea of the actual cluster state.

For example, if a cluster has divided somehow and a set of nodes are following a new primary, when running either of these commands, repmgr will now show the name of the primary those nodes are actually following, rather than the now outdated node name recorded on the other side of the "split". A warning will also be issued about the unexpected situation.

repmgr cluster show and repmgr daemon status: check if a node is attached to its advertised upstream node, and issue a warning if the node is not attached.

repmgrd enhancements
--------------------

On the primary node, repmgrd is now able to monitor standby connections and, if the number of nodes connected falls below a certain (configurable) value, execute a custom script.

This provides an additional method for fencing an isolated primary node, and/or taking other action if one or more standys become disconnected.

See section Monitoring standby disconnections on the primary node for more details.

In a failover situation, repmgrd nodes on the standbys of the failed primary are now able confirm among themselves that none can still see the primary before continuing with the failover.

The repmgr.conf option primary_visibility_consensus must be set to true to enable this functionality.

See section Primary visibility consensus for more details.

Bug fixes
---------
Ensure BDR2-specific functionality cannot be used on BDR3 and later.

The BDR support present in repmgr is for specific BDR2 use cases.

repmgr: when executing repmgr standby clone in --dry-run mode, ensure provision of the --force option does not result in an existing data directory being modified in any way.

repmgr: when executing repmgr primary register with the --force option, if another primary record exists but the associated node is unreachable (or running as a standby), set that node's record to inactive to enable the current node to be registered as a primary.

repmgr: when executing repmgr standby clone with the --upstream-conninfo, ensure that application_name is set correctly in primary_conninfo.

repmgr: when executing repmgr standby switchover, don't abort if one or more nodes are not reachable and they are marked as inactive.

repmgr: canonicalize the data directory path when parsing the configuration file, so the provided path matches the path PostgreSQL reports as its data directory. Otherwise, if e.g. the data directory is configured with a trailing slash, repmgr node check --data-directory-config will return a spurious error.

repmgrd: fix memory leak which occurs while the monitored PostgreSQL node is not running.

Other
-----
The repmgr documentation has been converted to DocBook XML format, as currently used by the main PostgreSQL project. This means it can now be built against any PostgreSQL version from 9.5 (previously it was not possible to build the documentation against PostgreSQL 10 or later), and makes it easier to provide the documentation in other formats such as PDF.

(adam)

2019-07-12 10:05:10 UTC MAIN commitmail json YAML

Updated databases/sqlite3 and friends

(adam)

2019-07-12 10:04:27 UTC MAIN commitmail json YAML

sqlite3: updated to 3.29.0

SQLite Release 3.29.0:
Added the SQLITE_DBCONFIG_DQS_DML and SQLITE_DBCONFIG_DQS_DDL actions to sqlite3_db_config() for activating and deactivating the double-quoted string literal misfeature. Both default to "on" for legacy compatibility, but developers are encouraged to turn them "off", perhaps using the -DSQLITE_DQS=0 compile-time option.
-DSQLITE_DQS=0 is now a recommended compile-time option.

Improvements to the query planner:
Improved optimization of AND and OR operators when one or the other operand is a constant.
Enhancements to the LIKE optimization for cases when the left-hand side column has numeric affinity.
Added the "sqlite_dbdata" virtual table for extracting raw low-level content from an SQLite database, even a database that is corrupt.

Enhancements to the CLI:
Add the ".recover" command which tries to recover as much content as possible from a corrupt database file.
Add the ".filectrl" command useful for testing.
Add the long-standing ".testctrl" command to the ".help" menu.
Added the ".dbconfig" command

(adam)

2019-07-12 09:33:39 UTC MAIN commitmail json YAML

Updated net/ndpi, net/ntopng

(adam)

2019-07-12 09:33:22 UTC MAIN commitmail json YAML

ntopng: updated to 3.8

3.8 Stable

New features
* Remote assistance to temporarily grant encrypted ntopng access to remote
parties
* Custom URLs and IP addresses mappings to traffic categories
* Continuous traffic recording
* User activities logging
* Extended chart metrics

Improvements
* Alerts
* Improved InfluxDB support
* Handles slow and aborted queries
* Uses authentication
* Adds RADIUS and HTTP authenticators
* Options to allow users login via RADIUS and HTTP
* Lua 5.3 support
* Improved performance
* Better memory management
* Native support for 64-bit integers
* Native support for bitwise operations
* Adds the new libmaxminddb geolocation library
* Storage utilization indicators
* Global storage indicator to show the disk used by each interface
* Per-interface storage indicator to show the disk used to store timeseries and flows
* Support for Sonicwall PEN field names
* Option to disable LDAP referrals
* Requests and configures Keepalive support for ZMQ sockets
* Three-way-handshake detection
* Adds SNMP mac addresses to the search function

nEdge
* Implement nEdge policies test page
* Implement device presets
* DNS

Fixes
* Fixes missing flows dump on shutdown
* HTTP dissection fixes
* SNMP
* Properly handles endianness over ZMQ

(adam)

2019-07-12 09:30:34 UTC MAIN commitmail json YAML

ndpi: updated to 2.8

2.8 Stable

New Supported Protocols and Services
* Added Modbus over TCP dissector

Improvements
* Wireshark Lua plugin compatibility with Wireshark 3
* Improved MDNS dissection
* Improved HTTP response code handling
* Full dissection of HTTP responses

Fixes
* Fixed false positive mining detection
* Fixed invalid TCP DNS dissection
* Releasing buffers upon realloc failures
* ndpiReader: Prevents references after free
* Endianness fixes
* Fixed IPv6 HTTP traffic dissection
* Fixed H.323 detection

Other
* Disabled ookla statistics which need to be improved
* Support for custom protocol files of arbitrary length
* Update radius.c to RFC2865

(adam)

2019-07-12 05:16:52 UTC MAIN commitmail json YAML

Note addition of u-boot-a20-olinuxino-lime2 and u-boot-a20-olinuxino-lime2-emmc.

(thorpej)

2019-07-12 05:08:38 UTC MAIN commitmail json YAML

2019-07-12 04:14:19 UTC MAIN commitmail json YAML

doc: Updated textproc/aspell-en to 2018.04.16.0nb1

(gutteridge)

2019-07-12 04:04:38 UTC MAIN commitmail json YAML

aspell-en: fix PLIST issue

Addresses PR pkg/54359. (Bumping PKGREVISION since this is a PLIST
change.)

(gutteridge)

2019-07-12 03:52:37 UTC MAIN commitmail json YAML

Remove www/php-nextcloud

(ryoon)

2019-07-12 03:52:13 UTC MAIN commitmail json YAML

firefox: note new cbindgen and NSS minimum dependencies

cbindgen is now >= 0.8.7 and NSS is now >= 3.44.1.

(gutteridge)

2019-07-12 01:17:33 UTC MAIN commitmail json YAML

firefox: note Rust dependency is now >= 1.34.0

(gutteridge)

2019-07-11 18:56:33 UTC MAIN commitmail json YAML

doc: Updated net/youtube-dl to 20190712

(leot)

2019-07-11 18:56:16 UTC MAIN commitmail json YAML

youtube-dl: Update to 20190712

Changes:
2019.07.12
----------
Core
+ [adobepass] Add support for AT&T U-verse (mso ATT) (#13938, #21016)

Extractors
+ [mgtv] Pass Referer HTTP header for format URLs (#21726)
+ [beeg] Add support for api/v6 v2 URLs without t argument (#21701)
* [voxmedia:volume] Improvevox embed extraction (#16846)
* [funnyordie] Move extraction to VoxMedia extractor (#16846)
* [gameinformer] Fix extraction (#8895, #15363, #17206)
* [funk] Fix extraction (#17915)
* [packtpub] Relax lesson URL regular expression (#21695)
* [packtpub] Fix extraction (#21268)
* [philharmoniedeparis] Relax URL regular expression (#21672)
* [peertube] Detect embed URLs in generic extraction (#21666)
* [mixer:vod] Relax URL regular expression (#21657, #21658)
+ [lecturio] Add support id based URLs (#21630)
+ [go] Add site info for disneynow (#21613)
* [ted] Restrict info regular expression (#21631)
* [twitch:vod] Actualize m3u8 URL (#21538, #21607)
* [vzaar] Fix videos with empty title (#21606)
* [tvland] Fix extraction (#21384)
* [arte] Clean extractor (#15583, #21614)

(leot)

2019-07-11 18:46:51 UTC MAIN commitmail json YAML

devel/git: Clarify DESCR and hint at git-base

(gdt)

2019-07-11 17:04:20 UTC MAIN commitmail json YAML

doc: Updated sysutils/flashrom to 1.1

(nia)

2019-07-11 17:04:04 UTC MAIN commitmail json YAML

flashrom: Update to 1.1

New major user-visible features

    4-byte address support for many SPI programmers
    New option to use a reference file for flash contents (--flash-contents)
    Layout support for coreboot's FMAP format (--fmap, --fmap-file)
    BAUD rate selection for Buspirate SPI
    Support for the ENE Embedded Debug Interface (EDI), probably our first non-jedec SPI target
    On Intel ME enabled systems, internal flashing is allowed by default

New programmers

    ENE Embedded Debug Interface EDI
    Linux' MTD interface
    Digilent SPI for the iCEblink40 development board
    Developerbox/CP2104 bit banging
    J-Link SPI
    Dediprog firmwares >= 7.2.30
    Dediprog SF200
    Intel Kabylake PCHs

New chips

    AT25DF021A
    AT25SF041
    AT25SF081
    AT25SF161
    AT25SL128A
    KB9012 (EDI)
    GD25B128B
    IS25LP064
    IS25LP128
    IS25LP256
    IS25WP032
    IS25WP064
    IS25WP128
    IS25WP256
    MX25L6473F
    MX25L25635F
    MX66L51235F
    MX25U8032E
    MX25U51245G
    MX25R6435F
    N25Q256..3E/MT25QL256
    N25Q512..3E/MT25QL512
    LE25FU106B
    LE25FU206
    LE25FU206A
    S25FL256S......0
    SST26VF016B
    SST26VF032B
    SST26VF064B
    W25Q128.V..M
    W25Q256.V
    W25Q256JV_M
    W25Q40BW
    W25Q80BW
    W25Q40EW
    W25Q80EW
    W25P80
    W25P16
    W25P32
    ZD25D20
    ZD25D40

(nia)

2019-07-11 15:16:12 UTC MAIN commitmail json YAML

Don't need it on Lion

(sevan)

2019-07-11 14:54:48 UTC MAIN commitmail json YAML

2019-07-11 14:53:36 UTC MAIN commitmail json YAML

Update to v3.6.8

Changes
=======

* Version 3.6.8 (released 2019-05-28)

** libgnutls: Added gnutls_prf_early() function to retrieve early keying
  material (#329)

** libgnutls: Added support for AES-XTS cipher (#354)

** libgnutls: Fix calculation of Streebog digests (incorrect carry operation in
  512 bit addition)

** libgnutls: During Diffie-Hellman operations in TLS, verify that the peer's
  public key is on the right subgroup (y^q=1 mod p), when q is available (under
  TLS 1.3 and under earlier versions when RFC7919 parameters are used).

** libgnutls: the gnutls_srp_set_server_credentials_function can now be used
  with the 8192 parameters as well (#995).

** libgnutls: Fixed bug preventing the use of gnutls_pubkey_verify_data2() and
  gnutls_pubkey_verify_hash2() with the GNUTLS_VERIFY_DISABLE_CA_SIGN flag (#754)

** libgnutls: The priority string option %ALLOW_SMALL_RECORDS was added to allow
  clients to communicate with the server advertising smaller limits than 512

** libgnutls: Apply STD3 ASCII rules in gnutls_idna_map() to prevent
  hostname/domain crafting via IDNA conversion (#720)

** certtool: allow the digital signature key usage flag in CA certificates.
  Previously certtool would ignore this flag for CA certificates even if
  specified (#767)

** gnutls-cli/serv: added the --keymatexport and --keymatexportsize options.
  These allow testing the RFC5705 using these tools.

** API and ABI modifications:
gnutls_prf_early: Added
gnutls_record_set_max_recv_size: Added
gnutls_dh_params_import_raw3: Added
gnutls_ffdhe_2048_group_q: Added
gnutls_ffdhe_3072_group_q: Added
gnutls_ffdhe_4096_group_q: Added
gnutls_ffdhe_6144_group_q: Added
gnutls_ffdhe_8192_group_q: Added

(sevan)

2019-07-11 14:26:09 UTC MAIN commitmail json YAML

Correction of PLIST with chrooted build. *.dot -> *.map/*.png

(mef)

2019-07-11 12:56:04 UTC MAIN commitmail json YAML

devilutionx: Spell the name of the package properly.

nia needs to learn to type properly.

(nia)

2019-07-11 12:09:33 UTC MAIN commitmail json YAML

2019-07-11 12:07:39 UTC MAIN commitmail json YAML

Remove devel/xulrunner192 and devel/swt.

xulrunner192 was the last remains of Firefox 3.6 in pkgsrc.

The last package depending on xulrunner192 was devel/swt. swt isn't used by
anything in pkgsrc (old versions of eclipse which weren't imported, maybe),
and was originally added by jmcneill, who says it can be removed now.

(nia)

2019-07-11 12:05:35 UTC MAIN commitmail json YAML

Update to 16.0.3

Changelog:
16.0.3
Changes
    Do not fail hard on new user mail error (server#16189)
    Fix redirect after rescanFailedIntegrityCheck to "Overview" page (server#16244)
    Fix permissions for drag-n-drop uploads (server#16249)
    Try to delete the cypress folder of the viewer app (server#16297)
    Send browser notifications again (notifications#373)

16.0.2
Changes
    Update ca bundle (server#15553)
    Update ca bundle checker (server#15554)
    User management/subadmin: rephrase ambiguous error message (server#15575)
    Update shipped.json to include privacy and recommendations (server#15592)
    Show supported apps in app management (server#15593)
    Update CRL due to revoked cookbook.crt (server#15628)
    Only show sharing section if it has content (server#15649)
    Remove quota feedback if no link set (server#15666)
    Allow redis cluster to use password (server#15686)
    Don't run repair step for every individual user, outsource that to background job (server#15718)
    Check the actual status code for 204 and 304 (server#15724)
    [Security] Bump tar from 2.2.1 to 2.2.2 (server#15728)
    Don't notify admins if no potentially over exposing links found (server#15745)
    Also allow dragging below the file list (server#15754)
    Change text color in search box in darktheme, ref #15598 (server#15768)
    Check for free space on touch (server#15772)
    Search files by id in shared storages last (server#15799)
    Hide newFile menu if quota is set to 0B (server#15856)
    Add core/js/dist/ to l10nignore (server#15948)
    Add LDAP integr. test for receiving share candidates with group limitation (server#15984)
    Remove auto focus of share input field on dialog open, fix #15261 (server#16010)
    LDAP) API: return one base properly when multiple are configured (server#16015)
    Handle storage exceptions when trying to set mtime (server#16038)
    Fix LDAP Wizard forgetting groups on select with search (server#16051)
    Revert "Fix userid casting in notifications" (server#16068)
    Fix appid argument for integrity:check-app (server#16080)
    Fix full text search for groupfolders (server#16082)
    Fall back to black for non-color values (server#16089)
    Check if uploading to lookup server is enabled before verifying (server#16091)
    Allow apps to store longer messages in the comments API (server#16105)
    Invalidates user when plugin reported deletion success (server#16112)
    Fix download link included in public share page with hidden download (server#16125)
    Better check reshare permissions (server#16127)
    Verify that paths are valid for recursive local move (server#16128)
    Don't allow to disable encryption via the API (server#16133)
    Do not show a internet connectivity warning if internet access is dis… (server#16146)
    Update Nextcloud version in docs link (server#16157)
    Allow apps to overwrite the maximum length when reading from database (server#16177)
    RefreshWebcalJob: replace ugly Regex with standard php utils (server#16201)
    Better check reshare permissions part2 (server#16211)
    Fix "unshare group share from self" activity (activity#380)
    Fix load of character maps (files_pdfviewer#141)
    [Security] Bump axios from 0.18.0 to 0.18.1 (firstrunwizard#192)
    Correctly show errors when setting the password (gallery#529)
    Blacklist using .noimage (gallery#533)
    Update dependabot deps in stable16 (notifications#359)
    Increase size of icon bubble for more visibility (notifications#368)
    Add app description to readme and appinfo (privacy#133)
    Catch and filter share that can't be found (recommendations#79)
    [Security] Bump axios from 0.18.0 to 0.18.1 (recommendations#92)
    [Security] Bump tar from 2.2.1 to 2.2.2 (viewer#113)
    [Security] Bump axios from 0.18.0 to 0.19.0 (viewer#117)

(ryoon)

2019-07-11 11:58:22 UTC MAIN commitmail json YAML

Updated mail/thunderbird-l10n to 60.8.0

(ryoon)

2019-07-11 11:58:00 UTC MAIN commitmail json YAML

Update to 60.8.0

* Sync with mail/thunderbird-60.8.0

(ryoon)

2019-07-11 11:57:25 UTC MAIN commitmail json YAML

Updated mail/thunderbird to 60.8.0

(ryoon)

2019-07-11 11:57:00 UTC MAIN commitmail json YAML

Update to 60.8.0

Changelog:
changed
    Calendar: Problems when editing event times, some related to AM/PM setting in non-English locales

(ryoon)

2019-07-11 11:34:59 UTC MAIN commitmail json YAML

Updated www/firefox-l10n to 68.0

(ryoon)

2019-07-11 11:34:31 UTC MAIN commitmail json YAML

2019-07-11 11:33:45 UTC MAIN commitmail json YAML

Updated www/firefox to 68.0

(ryoon)

2019-07-11 11:32:40 UTC MAIN commitmail json YAML

Update to 68.0

Changelog:

New
    Dark mode in reader view expands so that windows are also dark on the controls, sidebars and toolbars.

    Improved extension security and discovery:
        New reporting feature in about:addons allows you to report security and performance issues with extensions and themes.
        Redesigned extensions dashboard in about:addons provides easy access to information about your extensions, including data and settings access required by each extension.
        Find high quality, secure extensions via the Recommended Extensions program in about:addons, which now displays user count and ratings for each extension. "Recommended” badges for these extensions also appear on AMO. More extensions will be added over time.

    Cryptomining and fingerprinting protections are added to strict content blocking settings in Privacy & Security preferences.

    WebRender will roll out to Windows 10 users with AMD graphics cards.

    Windows Background Intelligent Transfer Service (BITS) update download support, which allows Firefox update downloads to continue when Firefox is closed.

Fixed

    Various security fixes

    Local files can no longer access other files in the same directory.

Security fixes:
#CVE-2019-9811: Sandbox escape via installation of malicious language pack
#CVE-2019-11711: Script injection within domain through inner window reuse
#CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects
#CVE-2019-11713: Use-after-free with HTTP/2 cached stream
#CVE-2019-11714: NeckoChild can trigger crash when accessed off of main thread
#CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault
#CVE-2019-11715: HTML parsing error can contribute to content XSS
#CVE-2019-11716: globalThis not enumerable until accessed
#CVE-2019-11717: Caret character improperly escaped in origins
#CVE-2019-11718: Activity Stream writes unsanitized content to innerHTML
#CVE-2019-11719: Out-of-bounds read when importing curve25519 private key
#CVE-2019-11720: Character encoding XSS vulnerability
#CVE-2019-11721: Domain spoofing through unicode latin 'kra' character
#CVE-2019-11730: Same-origin policy treats all files in a directory as having the same-origin
#CVE-2019-11723: Cookie leakage during add-on fetching across private browsing boundaries
#CVE-2019-11724: Retired site input.mozilla.org has remote troubleshooting permissions
#CVE-2019-11725: Websocket resources bypass safebrowsing protections
#CVE-2019-11727: PKCS#1 v1.5 signatures can be used for TLS 1.3
#CVE-2019-11728: Port scanning through Alt-Svc header
#CVE-2019-11710: Memory safety bugs fixed in Firefox 68
#CVE-2019-11709: Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8

(ryoon)

2019-07-11 11:20:06 UTC MAIN commitmail json YAML

2019-07-11 11:17:24 UTC MAIN commitmail json YAML

2019-07-11 10:24:14 UTC MAIN commitmail json YAML

rust: Make building the internal LLVM optional for everyone

(not just Darwin and SunOS).

This was posted to tech-pkg@ a while ago with no objections,
I've been using it for a while too.

(nia)

2019-07-11 10:11:26 UTC MAIN commitmail json YAML

musepack: Let CMake manage the RPATH by adding an INSTALL statement in the
CMakeLists.txt of the library.

from Clement Bouvier
PR pkg/54367

(nia)

2019-07-11 09:36:34 UTC MAIN commitmail json YAML

doc: Removed multimedia/mplayer-plugin

(nia)

2019-07-11 09:35:30 UTC MAIN commitmail json YAML

2019-07-11 09:33:43 UTC MAIN commitmail json YAML

doc: Removed misc/yelp successor misc/yelp3

(nia)

2019-07-11 09:32:20 UTC MAIN commitmail json YAML

Remove misc/yelp - replaced by misc/yelp3.

Discussed on pkgsrc-users@ last week.

(nia)

2019-07-11 09:28:44 UTC MAIN commitmail json YAML

2019-07-11 09:25:26 UTC MAIN commitmail json YAML

2019-07-11 09:03:35 UTC MAIN commitmail json YAML

2019-07-11 04:51:14 UTC MAIN commitmail json YAML

2019-07-11 04:46:05 UTC MAIN commitmail json YAML

doc: Updated audio/solfege to 3.22.2

(schmonz)

2019-07-11 04:45:53 UTC MAIN commitmail json YAML

Update to 3.22.2. From the changelog:

* Updated Esperanto, Portugese and Turkish translations to the users manual
* Updated Spannish and Turkish messages
* distribute solfege/tests/lesson-files/*
* help/C/scales/modes.html are never translated. So we must link to the
C-locale file in every translation.
* gettext tweaks to make the test suite work both when run as "test.py" and
"test.py test_lessonfile". There is still something wrong because we have
to disable the test to run debuild
* distribute solfege/tests/lib/* and solfege/test/include/*

3.22.1:
* Adjust some of the short interval names used when selecting intervals to
practise:
  u->P1 4->P4, 5->P5, tt->TT, p11->P11, p12->P12, tt8->d12. Added long name
for
  intervals from Eleventh to Double Octave.
* Fix the bug where we could not select the Default profile
* Updated Esperanto, Spannish, Polish, Turkish, Vietnamese, Norwegian
bokm奪l,
  Brazilian Portugese and Vietnamese translations.

3.22.0:
Improvements
  * interval exercises: added larger intervals, up to double octave
  * elembuilder: make the answer buttons insensitive when the user is
not supposed to click on them.
  * added the header.statistics_matrices lesson file variable
  * mpd: try to avoid crashing noteheads when displaying two noteheads
at the same step, but with different accidentals.
  * the statistics page for each exercise now have a button that let
us delete the statistics for the exercise.
  * The --debug option will also show the module name as a tooltip for
the link button that starts the exercise.
  * Make the "Guess answer" button be sensitive only when the user
have entered an answer.
  * Statistics viewer: added a row to the percentages table showing
count and percentage correct for all questions asked in the session,
day, week and all-time.
  * The frontpage will show the filename if the app is started with
the ``--debug`` command line option.
  * idtone exercise: show statistics when the user configure the
module himself. And remember the config.
  * We can now place exercise modules written in Python in
~/.solfege/exercises/dirname/modules/

New modules:
  * added the ``toneincontext`` exercise module
  * added ``solmisation`` exercise module. Thanks to Jan Baumgart and
Folkwang Universitaet der Kuenste

Build fixes:
  * version_info build fix
  * test.py: move some code so that running a subset of tests also
will create and remove tmp directory
  * make dist: include the files in exercises/regression-lesson-files/share/
  * build fix to avoid problem with too long list of files
  * add INSTALLDIR/exercises/standard/lesson-files to the include()
functions search path

Bug fixes
  * elembuilder: fix the backspace accel
  * fix bug #237
  * rhythmtapping and rhythmtapping2: rest handling bugfix
  * HarmonicProgressionLabel: set_alignment bugfix.
  * compareintervals: fix "Repeat first" and "Repeat last" sensitivity
  * SolfegeApp: don't sync the statistics database until the last
exercise is shut down.

Lesson file writing:
  * added import and rimport statement
  * remove all support for file formats that depent on lesson_id. Did
not remove the lesson_id variable from lesson files since this would
reset the statistics.
  * dataparser will parse to a parsetree that we interpret.
  * lesson file modules: tmp hack to let different lesson file modules
have different default values to variables.

* documentation: the intervals lesson file variable was documented wrongly.
* Linux -> GNU/Linux search-and-replace
* 140% line-height in the generated user manual
* the elembuilder module changed how it stored its statistics. So all
elembuilder statistics will be lost. We will save a backup of the
statistics database the first time 3.21.2 is run.
* gu.FlashBar: display extra strings (set by kwargs) in the same font
as the rest of the string.
* Put a deprecation notice in the chord modules gui.
* small fixes here and there...

3.20.7:
* Updates to Persian, Czeck, Danish and Norwegian translation.
* Added Kroatian translation

3.20.4:
* Fix rest handling in the rhythmtapping and rhythmtapping2 modules
* Bug fix to interval tests: select tones that are within the range of
the input widgets. (Closes bug #247)
* Translation updates
* Downloading of ALSA modules will download 1.0.24 instead of 1.0.22

3.20.2:
* Add a gtk.ScrolledWindow to the dialog showing file locations to
make sure the dialog is smaller than the screen.
* minor build fixes
* mark a few more strings for translation and grammar fixes (by Ruslan Fedyarov)
* Alt-Left will go to the previous menu while navigating exercises.
* bug fix: make strings in lesson files that use format strings translatable.
* "Accordion (Belgian Do 2)" interval input widget.
* Show alsa sequencers that register as alsaseq.SEQ_PORT_TYPE_APPLICATION
* Updated translations: French, Spanish, Turkish, Russian, German
* interval_in_key_min: lesson_heading spelling fix
* make "90%" the the default value if test_requirement is missing.

3.20.1:
* automate 0install binary tarball creating and script to update solfege.xml
* Bugfix to generate_lessonfiles.py: Believe it or not, but we defined
minor second as 16/12 and not 16/15.
* Search bar: decode the strings we get from the gtk.Entry into unicode.
* Always let the staff lines be as wide as the MusicDisplayer
* Add "Lock to key" feature. This is an experimental feature. Actual
GUI solution may improve later.
* polish folk songs: Fix singlequoted strings that where written as
multiline strings.
  It works, but it does not mean you should do it. Use triple-quoted
strings for multiline strings.
* simplify and rename to get a more precise name:
`mpdutils.int_to_notename` -> `int_to_octave_notename`,
`mpdutils.int_to_user_notename` -> `int_to_user_octave_notename` and
simplified `mpdutils.notename_to_int`
* String fixes:
  * Python should be capitalized
  * Fix bad english thanks to Ruslan Fedyarov
  * Mark one more string for translation
* the test target will check for bad spellings for "user manual":
"users manual" and "user's manual"
* Updated Russian, French, Dutch and Polish translations
* configwindow: handle soundcard.alsa_sequencer.get_connection_list()
returning an empty list. I think this fixes `bug #234
<http://bugs.solfege.org/234>`_
* set branch to 3.20 in configure.ac
* Removing things from the test: target of Makefile.in since
tools/make-release.py will do more
* docbook xml markup bug fixes to help/fr and help/pl
* autogen.sh: remove old gandiserver exception

3.20.0:
Improvements and changes:

* New exercise modules: rhythmdictation and rhythmdictation2
* New middle layer code in the mpd module. The parser now generates
objects from the mpd.elems module. This API is also used by the rhythm
editor widget.
* Initial ALSA sequencer support. Added a tool (available on the Help
menu) that downloads and compiles ALSA drivers.
* identifybpm: play rhythms with the normal mpd API instead of
gobject.timeout_add
* singinterval: select violin or bass clef depending on the pitch of
the highest and lowest tone.
* the config window is built with a gtk.TreeView instead of a
gtk.Notebok, and interval input accels are now configurable
* added some missing interval exercise configurations and reorder the
sections making them uniform.
* Change FlashBar to handle labelobjects
* `0install </zeroinstall/solfege.xml>`_ package for Linux
* Timidity is the default midi player on linux.

Bug fixes:

* front page editor: escape titles and file names in saved files, so
that ', " and  \ are handled correctly.
* Fix rnc so that it works with the sharp symbol, and the unicode
version of both flat and sharp.
* Make sure the optimisation for very large front page files are used.
This is required for very large files, like the Bach choral package.
* solfege_c_midimodule: don't link libm unless we also link agains
librfftw and libffrw
* Don't rebuild generated music theory images if skipmanual=yes (bug #222)
* midifilesynth: filter out duplicate %s in the midi player args.
Duplicate %s would make the music play twice.
* Fix the Rhythm music object class so that it uses the percussion
instruments selected in the preferences window, as the user manual say
it should.
* RhythmDictation2Lessonfile: fix it so that it uses the percussion
instruments selected in the preferences window.
* don't crash on unicode BOM in lesson files.
* bug fixes to the instrument selection code in the preferences window.
* Use different API querying the screen resolution to avoid segfaul on
debian lenny.
* Make elembuilder handle questions where the answer is only one
element. Fixed by Andre Maute
* statistics: handle the deletion of the tests table correctly.
* win32: fix importing of old format front page files.
* Lots of other small fixes.

3.18.8:
* fix bug #209 (http://bugs.solfege.org/209). Thanks to Ralf Hain for
reporting this.
* Add 3 missing "second to octave" exercises: compare intervals, both
melodic and harmonic, and sing-intervals. Small reorder so some
sections, so all interval exercises present the lessons in the same
order.
* sing-intervals: the "Second to octave" exercise had a bug only
asking for ascending intervals up to octave, not tenth.
* mpd.parser: bugfix to relative mode. The following code would have
wrong octaves:

      \staff
      \transpose d
      \relative c''{
      c d e e'
      }
* Merge solfege.dev revno 1852: show_exercise_theory fix

3.18.7:
3.18.7 October 29, 2010

* Updated Dutch and Italian translations
* idbyname: fix it so that tests work when expert mode is selected.
* Upgrade debugtree.txt to the latest file format.
* lessonfile.py: set exercise_dir in a portable way. Fixes bug on ms windows.
* ExerciseView: Don't use gtk.SizeGroup when we display many exercises
since there are performance issues with it.

3.18.6 October 24, 2010

* win32: strftime did not accept unicode strings causing a traceback
when the statistics was shown.
* validate_stored_statistics: don't try to delete from the 'tests'
table, since it should be removed by now. Fixes
http://www.solfege.org/SITS-Incoming/NoDescription-YF
* Show dialog explaining things if the database is locked.
* frontpage: Escape backslash and apostrophe used in titles.
* Make elembuilder handle questions where the answer is only one
element. Fixed by Andre Maute.

3.18.5 October 18, 2010

* Use different api to get the screen width and height. This to avoid
segfault on debian lenny.
* Make the install target skip compiling the .py files if nopycompile=YES
* Change to use htmldoc for generating the PDF version of the user
manual. We still have encoding troubles for some languages, but doing
it manually with openoffice is too much work.
* Workaround for the bug where 'None' is stored as the key in
singinterval exercises. http://bugs.solfege.org/205
* Updates to the russian translation of the user manual

3.18.4 October 12, 2010

* Should work with swig 2.0 now. http://bugs.solfege.org/202
* Fix bug in the preferences window code that let us select accels for
the idtone exercises.
* Updated Danish, Russian, Vietnamese and Chinese translations

3.18.2 & 3.18.3 October 5, 2010

* Fix import error in the prefernces window. (http://bugs.solfege.org/201)
* Updated Italian and Vietnamese translations

3.18.1:
* Updated Esperanto, Polish and Italian translation.
* Don't import tuner.py when running solfege with the --debug option.
* Windows sound driver: Fix winmidi.reset so that it will reset the
correct dev num. Thanks to Krzysztof Foltman for telling me how to fix
this. This fix let us use external midi synths on MS Windows.
* Give the synth a little time to process program changes by calling
an extra note_off. The default is 100ms, but this is configurable from
the users solfegerc file.

Changes in 3.18.0 (compared to the 3.16 release). Included here since
3.18.0 was not that widely announced:
* Profile manager
* Preferences window: Add gui to delete statistics.
* Resize main window when selecting exercises to use the scrollbars less.
* The statistics page of exercises will show the 10 latest test results.
* Front page editor: option to search for strings in lesson file
titles when selecting lesson files.
* Export Exercises to Audio Files: add checkbutton that names the
generated audio files after the answer of the question.
* Add missing "Repeat Arpeggio" button to sing-the-fifth
* Updated Esperanto, Brazilian Portugese, Turkish and Persian translation.
* Spelling fixes by Ruslan Fedyarov and dougkerns
* Works with Swig 2.0
* Bug fix to the statistics table, and documented the statistics
tables in the user manual.
* Lots of minor bug fixes and improvements to the code.

3.16.3:
3.16.3
* Fix front page editor bug: failed while moving sections
* cfg.parse_file_info_dict: strip each line to avoid newline problems on win32
* Revert back to Python 2.5.4 since we want to let CSound use our
included python interpreter, and the recommended CSound installer is
built for Python 2.5
* French and Polish translation updates.
* win32: moved some files around and set the PYTHONHOME environment variable.

3.16.2
* Interval.get_cname should return "Tritone" and not "Diminished Fifth"
* Remove some debugging code that accidentally was left in
get_percentage_correct(). This broke the "Identify Tone" exercise.

3.16.0:
New features:
* Added 'atonal' transposition mode.
* More harmonic progressions from Ruslan Fedyarov.
* Added "Compare melodic intervals" exercise
* Statistics are now stored in a sqlite database instead of lots and
lots of small files.
* New main window where we select exercises without the menu bar. Gui
editor that let us edit this.
* Support LilyPond 2.12 in addition to 2.10
* Internally we now refer to lesson files by filename and not
lesson_id. So lesson_id should not be added to new lesson files. But
don't modify old files if you care about loosing your statistics.

News:
* Require Python 2.5. Module reorg. Enable absolute import in all modules.
* User generated lesson files have moved from $HOME/lesson-files to
$HOME/.solfege/exercises/user/lesson-files. The user manual has doc
explaining this change.
* win32: don't show terminal window when running timidity and friends.

3.14.11 February 8, 2010
revno: 1065
* IntervalCheckBox had a bug that caused the Major Decim to be
missing. Reported by Andre Maute.
* Decim->Tenth replace. How could this ever get in???
* make default.config rcfile version 16 compatible. Thanks to
Krause.Chr for fixing this.

3.14.10 December 17, 2009
* Fix bug #149: make keyboard accels work for descending melodic intervals.
* Fix win32 upgrades from 3.11.1 and earlier
* right-click on piano/guitar/accordion widget got the direction wrong.
* rcfile: don't loose xxx_player_options

3.14.9 October 10, 2009
* bugfix: install and uninstall when swig is not installed
* don't loose the interval and csound statistics if upgrading from
older releases.

3.14.8 September 29, 2009
* Simplified Chinese translations for by Fan Rui and Ji ZhengYu
* Mark a few more strings and the music theory pages for translation.
* Add harmonics to the csound exercises. Contributed by Tarmo Johannes
* Some build fixes: handle missing swig and lilypond better
* Translation updates.
* Remove more debug print statements that I believe causes "bad
filedescriptor" errors

3.14.5 June 29, 2009

    * Unicode error during build fixed by using the codecs module to
load learning trees.
    * Updated fr, nl, pt_BR and tr messages.
    * Updated fr and pt_BR user manual translation.

3.14.4 June 9, 2009
    * Fix broken link to the related music theory. It was broken in
some exercises.
    * ConflictResolveDialog: set use_underline to False so that
filenames containing a underscore ('_') are displayed correctly.
    * Update src/runtime.py to check that we have at least Python 2.4
and PyGTK 2.12
    * Updated Danish, Polish, Brazilian Portugues and Russion translations.

3.14.3 April 27, 2009
The secret release. Forgot to announce it.
    * Don't print debug statements, since we get IOErrors because of
it when the stdout buffer is full on win32
    * bugfix: the small buttons representing parts of the dictation
where all playing the whole music.
    * Updated Russian and Finnish translation.

3.14.2:
Changes since 3.14.1:
* Fix http://www.solfege.org/SITS-Incoming/NoDescription-HA
* It should now be possible to build without a X display.
* Updated translations

(schmonz)

2019-07-10 22:36:50 UTC MAIN commitmail json YAML

2019-07-10 20:28:21 UTC MAIN commitmail json YAML

doc: Updated graphics/libraw to 0.19.3

(nia)

2019-07-10 20:27:59 UTC MAIN commitmail json YAML

libraw: Update to 0.19.3

2019-07-02  Alex Tutubalin <lexa@lexa.ru>
* Several fixes inspired by OSS-Fuzz
* LibRaw 0.19.3
* Note: ABI slightly changed, new variable added at end of class LibRaw
  Generally, all old code should run w/o recompile, but you're warned...

2018-12-24  Alex Tutubalin <lexa@lexa.ru>
* Fixed possible buffer overrun at Fuji makernotes parser
* Fixed possible write to NULL pointer at raw2image/raw2image_ex calls.
  Details:
    a) Three different CVE numbers was assigned for single problem:
      CVE-2018-20363, CVE-2018-20364, CVE-2018-20365
    b) The POCs exploits inconsistency in Sinar-4Shot files handling.
    LibRaw 0.19 does not support this files format, so it is not
    subject of exactly same problem
    c) However, additional checks for bayer raw data presence are
    backported from LibRaw-master (development) branch.

* LibRaw 0.19.2

2018-11-22  Alex Tutubalin <lexa@lexa.ru>
* Finally: got Sinar 4shot sample, works fine now
* OpenMP critical sections for malloc/free; extra #ifdefs removed; bin/dcraw_dist could be built again using Makefile.devel
* additional checks in parse_phase_one()
* more checks on file offsets/tag len in parse_minolta
* more checks in parse_ciff
* Mempool check reworked
* Old Leaf (16bit/3color/TIFF) support
* Fix cameraWB->autoWB fallback
* Polaroid x530 channel swap; get metadata pointer for Foveon files
* Fixed Secunia Advisory SA86384
  - possible infinite loop in unpacked_load_raw()
  - possible infinite loop in parse_rollei()
  - possible infinite loop in parse_sinar_ia()
  Credits: Laurent Delosieres, Secunia Research at Flexera

* LibRaw 0.19.1-Release

2018-06-28  Alex Tutubalin <lexa@lexa.ru>
* changed wrong fix for Canon D30 white balance
* fixed possible stack overrun while reading zero-sized strings
* fixed possible integer overflow
* LibRaw 0.19.0-Release

2018-06-11  Alex Tutubalin <lexa@lexa.ru>
* Sony uncompressed/untiled DNGs: do not set bits-per-sample to 14 bit
* Do not change tiff_bps for DNG files
* Another possible stack overflow in kodak radc reader
* Secunia Advisory SA83507, credits Kasper Leigh Haabb,
  Secunia Research at Flexera"
  - parse_qt: possible integer overflow
  - reject broken/crafted NOKIARAW files
* LibRaw 0.19-Beta6

2018-05-10  Alex Tutubalin <lexa@lexa.ru>
* Put rogue printf's behind #ifdef DCRAW_VERBOSE
* Exceptions was not caught in x3f_new_from_file resulting in x3f handle leak
* packed_load_raw(): EOF check on each row
* define LIBRAW_USE_CALLOC_INSTEAD_OF_MALLOC to use ::calloc instead of
  ::malloc in LibRaw_mem_mgr malloc calls;
  Note: realloc is not changed, so only partial fix
* Fixed possible div by zero in EOS D30 WB data parse
* U-suffix for filter-var manipulation consts
* restored static specifier for utf2char() lost in previous bugfix
* Fixed stack overrun in kodak_radc_load_raw
* Secunia Advisory SA83050: possible infinite loop in parse_minolta()
* LibRaw 0.19-Beta5

2018-05-03  Alex Tutubalin <lexa@lexa.ru>
* CVE-2018-10529 fixed: out of bounds read in X3F parser
* CVE-2018-10528 fixed: possible stack overrun in X3F parser
* LibRaw 0.19-Beta4

2018-04-24 Alex Tutubalin <lexa@lexa.ru>
* LibRaw 0.19-Beta3
* fixed lot of bugs reported by ImageMagic/oss-fuzz
* fixed several bugs reported by Secunia team (adv 81800,
  Credit: Laurent Delosieres, Secunia Research at Flexera)

2018-03-22 Alex Tutubalin <lexa@lexa.ru>
* LibRaw 0.19-Beta2
* Better handling of broken JPEG thumbnails
* Panasonic GH5S/G9-hires decoder, thanks to Alexey Danilchenko
  Note: ABI has changed due to this patch, so shlib version increased
* Fujifilm X-A5/A20 metadata parsing fix
* New error code LIBRAW_TOO_BIG: image data size excess LIBRAW_MAX_ALLOC_MB
* winsock2 included before windows.h to make MinGW happy

2018-02-23 Alex Tutubalin <lexa@lexa.ru>

* LibRaw 0.19-Beta1

* 84 cameras added compared to 0.18 (1014 total):
    Apple
iPhone 8(*), iPhone 8 plus, iPhone X
    BlackMagic
URSA Mini 4k, URSA Mini 4.6k, URSA Mini Pro 4.6k
    Canon CHDK hack
PowerShot A410, A540, D10, ELPH 130 IS, ELPH 160 IS, SD750,
    SX100 IS,SX130 IS, SX160 IS, SX510 HS, SX10 IS, IXUS 900Ti
    Canon
PowerShot G1 X Mark III, G9 X Mark II, EOS 6D Mark II, EOS 77D,
EOS 200D, EOS 800D, EOS M6, EOS M100
    Casio EX-ZR4100/5100
    DJI
Phantom4 Pro/Pro+, Zenmuse X5, Zenmuse X5R
    FujiFilm
S6500fd, GFX 50S, X100f, X-A3, X-A5, X-A10, X-A20, X-E3, X-H1, X-T20
    GITUP GIT2P
    Hasselblad
H6D-100c, A6D-100c
    Huawei
P9 (EVA-L09/AL00), Honor6a, Honor9, Mate10 (BLA-L29)
    Leica
CL, M10, TL2
    LG
V20 (F800K), VS995,
    Nikon
D850, D5600, D7500, Coolpix B700
    Olympus
E-PL9, E-M10 Mark III, TG-5
    OnePlus
One, A3303, A5000
    Panasonic
DMC-FZ45, DMC-FZ72, DC-FZ80/82, DC-G9 (std. res mode only), DC-GF10/GF90,
  DC-GH5, DC-GX9, DC-GX800/850/GF9, DMC-LX1, DC-ZS70 (DC-TZ90/91/92, DC-T93),
DC-TZ100/101/ZS100, DC-TZ200/ZS200
    PARROT
Bebop 2, Bebop Drone
    Pentax KP
    PhaseOne IQ3 100MP Trichromatic
    Samsung
Galaxy Nexus, Galaxy S3, S6 (SM-G920F), S7, S7 Edge, S8 (SM-G950U),
    Sony
A7R III, A9, DSC-RX0, DSC-RX10IV
    Yi M1
    YUNEEC
CGO3, CGO3P
    Xiaoyi YIAC3 (YI 4k)

  Note(*): for mobile phones with DNG format recording, only really tested cameras
  are added to supported camera list. Really LibRaw should support any correct DNG.

* No more built-in support for LibRaw demosaic packs (GPL2/GPL3).
  We're unable to support this (very old code), so we'll be happy to transfer this
  code to some maintainer who wish to work with it.

  In LibRaw 0.19 we provide extension API: user-settable callbacks to be called in
  code points where demosaic pack code was called.

  -  int callbacks.pre_identify_cb(void *) => to be called in LibRaw::open_datastream
      before call to (standard) identify() function. If this call returns 1, this means
      that RAW file is identified and all metadata fields are set, so no need to run
      standard identify code.
  - void callbacks.post_identify_cb(void*) => called just after identify(), but before
      any cleanup code;
  - dcraw_process() callbacks are called before dcraw_process phases (name speaks for itself):
      pre_subtractblack_cb, pre_scalecolors_cb, pre_preinterpolate_cb, pre_interpolate_cb,
interpolate_bayer_cb, interpolate_xtrans_cb, post_interpolate_cb, pre_converttorgb_cb,
post_converttorgb_cb

  All these new callbacks are called with (this) as the only arg.
  To continue LibRaw-demosaic-pack-GPLx support one need to subclass LibRaw, set needed
  callbacks in (e.g.) constructor code, than these callbacks to be called

* Better DNG parser:
    - support for DefaultCrop Origin/Size tags (add LIBRAW_PROCESSING_USE_DNG_DEFAULT_CROP to raw_processing_options to enable)
    - better parsing for nested DNG tags (use tag from RAW IFD, fallback to IFD0 if no tag in current IFD)
    - DNG PreviewColorspace extracted into dng_levels.preview_colorspace

* Metadata extraction:
  - Better extraction of camera measured balance (LIBRAW_WBI_Auto and WBI_Measured),
    this not the same as 'as shot' if some preset/manual tune is used.
  - Extraction of camera custom balances (LIBRAW_WBI_CustomN)
  - Nikon data compression tag extracted into  makernotes.nikon.NEFCompression
  - Hasselblad BaseISO and Gain extracted into makernotes.hasselblad
  - Canon multishot params extracted into makernotes.canon.multishot
  - lot of other vendor-specific makernotes data (see data structures definitions for details).

* New LibRaw::open_bayer call allows to pass sensor dump w/o metadata directly to LibRaw:
    virtual int open_bayer(unsigned char *data, unsigned datalen,
  ushort _raw_width, ushort _raw_height, ushort _left_margin, ushort _top_margin,
  ushort _right_margin, ushort _bottom_margin,
  unsigned char procflags, unsigned char bayer_pattern, unsigned unused_bits, unsigned otherflags,
  unsigned black_level);
    Parameters:
    data, datalen - buffer passed
    width/height/margins - speaks for itself
    procflags:
    for 10-bit format:
      1: "4 pixels in 5 bytes" packing is used
      0: "6 pixels in 8 bytes" packing is used
    for 16-bit format:
      1: Big-endian data
    bayer_pattern: one of LIBRAW_OPENBAYER_RGGB,LIBRAW_OPENBAYER_BGGR,
                          LIBRAW_OPENBAYER_GRBG,LIBRAW_OPENBAYER_GBRG
    unused_bits: count of upper zero bits
    otherflags:
      Bit 1 - filter (average neighbors) for pixels with values of zero
      Bits 2-4 - the orientation of the image (0=do not rotate, 3=180, 5=90CCW, 6=90CW)
    black_level: file black level (it also may be specified via imgdata.params)

    see samples/openbayer_sample.cpp for usage sample (note, this sample is 'sample only', suited for
    Kodak KAI-0340 sensor, you'll need change open_bayer() params for your data).

* Color data added/updated/fixed for many cameras

* Correct data maximum for Fuji X-* cameras

* Thumbnail processing:
  - JPEG thumbnails: if compiled with libjpeg, color count is extracted into imgdata.thumbnail.tcolors
  - PPM (bitmap) thumbnails: color count is set according to thumbnail IFD tag
  - PPM16 thumbnails: if LIBRAW_PROCESSING_USE_PPM16_THUMBS set in raw_processing_options, than thumbnail will be extracted
    as is, not converted to 8 bit. thumbnail.tformat is set to LIBRAW_THUMBNAIL_BITMAP16 in this case.
    Untested, because it is hard to find RAWs with 16-bit bitmaps.

== Compatibility fixes

* struct tiff_tag renamed to libraw_tiff_tag
* pow64f renamed to libraw_pow64f

== Bugs fixed:

* COLOR(r,c) works correctly on X-Trans files

== Security fixes:
Secunia #81000:
Credit: Laurent Delosieres, Secunia Research at Flexera
* leaf_hdr_load_raw: check for image pointer for demosaiced raw
* NOKIARAW parser: check image dimensions readed from file
* quicktake_100_load_raw: check width/height limits

Secunia #79000:
Credit: Laurent Delosieres, Secunia Research at Flexera
* All legacy (RGB raw) image loaders checks for imgdata.image is not NULL
* kodak_radc_load_raw: check image size before processing
* legacy memory allocator: allocate max(widh,raw_width)*max(height,raw_height)

Secunia #76000:
* Fixed fuji_width handling if file is neither fuji nor DNG
* Fixed xtrans interpolate for broken xtrans pattern
* Fixed panasonic decoder
* LibRaw 0.18.6

Other fixes:
* Checks for width+left_margin/height+top_margin not larger than 64k
* LIBRAW_MAX_ALLOC_MB define limits maximum image/raw_image allocation
  (default is 2048 so 2Gb per array)
* LibRaw::read_shorts item count is now unsigned
* Fixed possible out of bound access in Kodak 65000 loader
* CVE-2017-14348: Fix for possible heap overrun in Canon makernotes parser
  Credit: Henri Salo from Nixu Corporation
* Fix for CVE-2017-13735
* CVE-2017-14265: Additional check for X-Trans CFA pattern data
* Fixed several errors (Secunia advisory SA75000)
* ACES colorspace output option included in dcraw_emu help page
* Avoided possible 32-bit overflows in Sony metadata parser
* Phase One flat field code called even for half-size

(nia)

2019-07-10 20:01:57 UTC MAIN commitmail json YAML

2019-07-10 18:02:59 UTC MAIN commitmail json YAML

doc: Updated net/hub to 2.12.2

(leot)

2019-07-10 18:02:46 UTC MAIN commitmail json YAML

hub: Update to 2.12.2

Changes:
2.12.2
------
* Improve `pull-request` push target detection for `git config push.default`
  is "upstream", but when the current branch does not have upstream
  configuration

(leot)

2019-07-10 17:53:39 UTC MAIN commitmail json YAML

2019-07-10 17:45:58 UTC MAIN commitmail json YAML

2019-07-10 17:15:27 UTC MAIN commitmail json YAML

Avoid pulling in libnbcompat on every platform, mark the specific builds of
Darwin which libnbcompat should be pulled in on to provide strnlen instead.

(sevan)

2019-07-10 15:15:40 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5992 - requested by nia
lang/npm: build fix

Revisions pulled up:
- lang/npm/Makefile                                            1.24

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Tue Jul  9 14:10:54 UTC 2019

  Modified Files:
  pkgsrc/lang/npm: Makefile

  Log Message:
  npm: Add bash to USE_TOOLS.

(bsiegert)

2019-07-10 15:15:36 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5991 - requested by nia
security/libtomcrypt: security fix

Revisions pulled up:
- security/libtomcrypt/Makefile                                1.8
- security/libtomcrypt/PLIST                                    1.3
- security/libtomcrypt/distinfo                                1.8
- security/libtomcrypt/patches/patch-aa                        deleted
- security/libtomcrypt/patches/patch-ab                        1.4
- security/libtomcrypt/patches/patch-ac                        deleted
- security/libtomcrypt/patches/patch-src_headers_tomcrypt__macros.h deleted
- security/libtomcrypt/patches/patch-src_pk_rsa_rsa__verify__hash.c deleted

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Tue Jul  9 11:20:58 UTC 2019

  Modified Files:
  pkgsrc/security/libtomcrypt: Makefile PLIST distinfo
  pkgsrc/security/libtomcrypt/patches: patch-ab
  Removed Files:
  pkgsrc/security/libtomcrypt/patches: patch-aa patch-ac
      patch-src_headers_tomcrypt__macros.h
      patch-src_pk_rsa_rsa__verify__hash.c

  Log Message:
  libtomcrypt: Update to 1.18.2

  July 1st, 2018
  v1.18.2
        -- Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408)
        -- Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373)
        -- Fix two-key 3DES (PR #390)
        -- Fix accelerated CTR mode (PR #359)
        -- Fix Fortuna PRNG (PR #363)
        -- Fix compilation on platforms where cc doesn't point to gcc (PR #382)
        -- Fix using the wrong environment variable LT instead of LIBTOOL (PR #392)
        -- Fix build on platforms where the compiler provides __WCHAR_MAX__ but wchar.h is not available (PR #390)
        -- Fix & re-factor crypt_list_all_sizes() and crypt_list_all_constants() (PR #414)
        -- Minor fixes (PR's #350 #351 #375 #377 #378 #379)

  January 22nd, 2018
  v1.18.1
        -- Fix wrong SHA3 blocksizes, thanks to Claus Fischer for reporting this via Mail (PR #329)
        -- Fix NULL-pointer dereference in `ccm_memory()` with LTC_CLEAN_STACK enabled (PR #327)
        -- Fix `ccm_process()` being unable to process input buffers longer than 256 bytes (PR #326)
        -- Fix the `register_all_{ciphers,hashes,prngs}()` return values (PR #316)
        -- Fix some typos, warnings and duplicate prototypes in code & doc (PR's #310 #320 #321 #335)
        -- Fix possible undefined behavior with LTC_PTHREAD (PR #337)
        -- Fix some DER bugs (PR #339)
        -- Fix CTR-mode when accelerator is used (OP-TEE/optee_os #2086)
        -- Fix installation procedure (Issue #340)

  October 10th, 2017
  v1.18.0
        -- Bugfix multi2
        -- Bugfix Noekeon
        -- Bugfix XTEA
        -- Bugfix rng_get_bytes() on windows where we could read from c:\dev\random
        -- Fixed the Bleichbacher Signature attack in PKCS#1 v1.5 EMSA, thanks to Alex Dent
        -- Fixed a potential cache-based timing attack in CCM, thanks to Sebastian Verschoor
        -- Fix GCM counter reuse and potential timing attacks in EAX, OCB and OCBv3,
            thanks to Rapha谷l Jamet
        -- Implement hardened RSA operations when CRT is used
        -- Enabled timing resistant calculations of ECC and RSA operations per default
        -- Applied some patches from the OLPC project regarding PKCS#1 and preventing
            the hash algorithms from overflowing
        -- Larry Bugbee contributed the necessary stuff to more easily call libtomcrypt
            from a dynamic language like Python, as shown in his pyTomCrypt
        -- Nikos Mavrogiannopoulos contributed RSA blinding and export of RSA and DSA keys
            in OpenSSL/GnuTLS compatible format
        -- Patrick Pelletier contributed a smart volley of patches
        -- Christopher Brown contributed some patches and additions to ASN.1/DER
        -- Pascal Brand of STMicroelectronics contributed patches regarding CCM, the
            XTS mode and RSA private key operations with keys without CRT parameters
        -- RC2 now also works with smaller key-sizes
        -- Improved/extended several tests & demos
        -- Hardened DSA and RSA by testing (through Karel's perl-CryptX)
            against Google's "Wycheproof" and Kudelski Security's "CDF"
        -- Fixed all compiler warnings
        -- Fixed several build issues on FreeBSD, NetBSD, Linux x32 ABI, HP-UX/IA64,
            Mac OS X, Windows (32&64bit, Cygwin, MingW & MSVC) ...
        -- Re-worked all makefiles
        -- Re-worked most PRNG's
        -- The code is now verified by a linter, thanks to Francois Perrad
        -- Documentation (crypt.pdf) is now built deterministically, thanks to Michael Stapelberg
        -- Add Adler32 and CRC32 checksum algorithms
        -- Add Base64-URL de-/encoding and some strict variants
        -- Add Blake2b & Blake2s (hash & mac), thanks to Kelvin Sherlock
        -- Add Camellia block cipher
        -- Add ChaCha (stream cipher), Poly1305 (mac), ChaCha20Poly1305 (encauth)
        -- Add constant-time mem-compare mem_neq()
        -- Add DER GeneralizedTime de-/encoding
        -- Add DSA and ECC key generation FIPS-186-4 compliance
        -- Add HKDF, thanks to RyanC (especially for also providing documentation :-) )
        -- Add OCBv3
        -- Add PKCS#1 v1.5 mode of SSL3.0
        -- Add PKCS#1 testvectors from RSA
        -- Add PKCS#8 & X.509 import for RSA keys
        -- Add stream cipher API
        -- Add SHA3 & SHAKE
        -- Add SHA512/256 and SHA512/224
        -- Add Triple-DES 2-key mode, thanks to Paul Howarth
        -- Brought back Diffie-Hellman

(bsiegert)

2019-07-10 15:15:31 UTC pkgsrc-2019Q2 commitmail json YAML

Pullup ticket #5990 - requested by nia
graphics/SDL2_image: security fix

Revisions pulled up:
- graphics/SDL2_image/Makefile                                  1.12
- graphics/SDL2_image/distinfo                                  1.6

---
  Module Name: pkgsrc
  Committed By: nia
  Date: Sun Jul  7 05:46:51 UTC 2019

  Modified Files:
  pkgsrc/graphics/SDL2_image: Makefile distinfo

  Log Message:
  SDL2_image: Update to 2.0.5

  Changes:
    * Updated external libraries libpng-1.6.32, libwebp-1.0.2
    * Fixed a number of security issues:
      TALOS-2019-0820
      TALOS-2019-0821
      TALOS-2019-0841
      TALOS-2019-0842
      TALOS-2019-0843
      TALOS-2019-0844
    * Ported SDL_image to emscripten

(bsiegert)

2019-07-10 12:59:54 UTC MAIN commitmail json YAML

2019-07-10 12:56:50 UTC MAIN commitmail json YAML

Add include/sodium to BUILDLINK_INCDIRS.libsodium.

(schmonz)

2019-07-10 11:23:35 UTC MAIN commitmail json YAML

2019-07-10 11:20:07 UTC MAIN commitmail json YAML

doc: Updated net/fehqlibs to 0.9.12.10nb1

(schmonz)

2019-07-10 11:20:02 UTC MAIN commitmail json YAML

2019-07-10 11:12:16 UTC MAIN commitmail json YAML

catdoc: fix sysconfdir for location of system-wide configuration file.

(markd)

2019-07-10 10:51:29 UTC MAIN commitmail json YAML

dconf: PKGREVISION bump for sysconfdir fix in py-meson/build.mk

also remove no longer used SUBST for /etc -> ${PKG_SYSCONFDIR}

(markd)

2019-07-10 10:49:36 UTC MAIN commitmail json YAML

2019-07-10 10:40:35 UTC MAIN commitmail json YAML

py-meson: make sure meson called with correct sysconfdir.

(markd)

2019-07-10 10:38:18 UTC MAIN commitmail json YAML

2019-07-10 10:37:13 UTC MAIN commitmail json YAML

2019-07-10 10:35:17 UTC MAIN commitmail json YAML

doc: Updated net/fehqlibs to 0.9.12.10

(schmonz)

2019-07-10 10:35:11 UTC MAIN commitmail json YAML

.9.12 has a serious regression in dns_ipq.c: only AAAA records are
looked up, instead of AAAA and A. Revert to previous 0.9.10 (as
"0.9.12.10").

(schmonz)

2019-07-10 10:32:57 UTC MAIN commitmail json YAML

2019-07-10 10:32:05 UTC MAIN commitmail json YAML

Use https for swi-prolog.org.

(nia)

2019-07-10 10:24:06 UTC MAIN commitmail json YAML

2019-07-10 09:28:39 UTC MAIN commitmail json YAML

Updated multimedia/x265, security/gnupg2

(adam)

2019-07-10 09:28:24 UTC MAIN commitmail json YAML

gnupg2: updated to 2.2.17

Noteworthy changes in version 2.2.17:
* gpg: Ignore all key-signatures received from keyservers.  This
  change is required to mitigate a DoS due to keys flooded with
  faked key-signatures.  The old behaviour can be achieved by adding
    keyserver-options no-self-sigs-only,no-import-clean
  to your gpg.conf.
* gpg: If an imported keyblocks is too large to be stored in the
  keybox (pubring.kbx) do not error out but fallback to an import
  using the options "self-sigs-only,import-clean".
* gpg: New command --locate-external-key which can be used to
  refresh keys from the Web Key Directory or via other methods
  configured with --auto-key-locate.
* gpg: New import option "self-sigs-only".
* gpg: In --auto-key-retrieve prefer WKD over keyservers.
* dirmngr: Support the "openpgpkey" subdomain feature from
  draft-koch-openpgp-webkey-service-07.
* dirmngr: Add an exception for the "openpgpkey" subdomain to the
  CSRF protection.
* dirmngr: Fix endless loop due to http errors 503 and 504.
* dirmngr: Fix TLS bug during redirection of HKP requests.
* gpgconf: Fix a race condition when killing components.

(adam)

2019-07-10 09:00:57 UTC MAIN commitmail json YAML

x265: updated to 3.1.1

Version 3.1

New features
* x265 can invoke SVT-HEVC library for encoding through --svt.
* x265 can now accept interlaced inputs directly (no need to separate fields), and sends it to the encoder with proper fps and frame-size through --field.
* --fades can detect and handle fade-in regions. This option will force I-slice and initialize RC history for the brightest frame after fade-in.

API changes
* A new flag to signal MasterDisplayParams and maxCll/Fall separately

Encoder enhancements
* Improved the performance of inter-refine level 1 by skipping the evaluation of smaller CUs when the current block is decided as ���skip��� by the save mode.
* New AVX2 primitives to improve the performance of encodes that enable --ssim-rd.
* Improved performance in medium preset with negligible loss in quality.

Bug fixes
* Bug fixes for zones.
* Fixed wrap-around from MV structure overflow occurred around 8K pixels or over.
* Fixed issues in configuring cbQpOffset and crQpOffset for 444 input
* Fixed cutree offset computation in 2nd pass encodes.

Known issues
* AVX512 main12 asm disabling.
* Inconsistent output with 2-pass due to cutree offset sharing.

(adam)

2019-07-10 08:44:46 UTC MAIN commitmail json YAML

Note update of devel/go-protobuf to 1.3.2.

(he)

2019-07-10 08:41:26 UTC MAIN commitmail json YAML

Update to go-protobuf version 1.3.2.

Pkgsrc changes:
* Update PLIST

Upstream notable changes:
* #785: grpc code generation: add an UnimplementedServer type
  implementing each server interface, returning an unimplemented
  error for each method
* #851: convert prints to `os.Stderr` to use `log.Printf`
* #883: jsonpb: fix marshaling of Duration with negative nanoseconds

(he)

2019-07-10 01:32:28 UTC MAIN commitmail json YAML

doc: Updated devel/librdkafka to 1.0.1

(minskim)

2019-07-10 01:31:21 UTC MAIN commitmail json YAML

devel/librdkafka: Update to 1.0.1

Notable changes in 1.0:
- Idempotent producer - guaranteed ordering, exactly-once producing.
- Sparse/on-demand connections - connections are no longer maintained
  to all brokers in the cluster.
- KIP-62 - max.poll.interval.ms for high-level consumers.

(minskim)

2019-07-09 23:02:29 UTC MAIN commitmail json YAML

2019-07-09 22:56:31 UTC MAIN commitmail json YAML

Note update of lang/clisp to 2.49nb25.

(he)

2019-07-09 22:55:41 UTC MAIN commitmail json YAML

Patterned after electric-fence, turn off builtins for calloc, malloc,
memalign, realloc, valloc and free.  Makes clisp work with modern compilers.
Bump PKGREVISION.

(he)

2019-07-09 20:36:21 UTC MAIN commitmail json YAML

uncrustify: ... actually, PYTHON_VERSIONS_ACCEPTED is better here

(nia)

2019-07-09 20:31:33 UTC MAIN commitmail json YAML

2019-07-09 20:23:07 UTC MAIN commitmail json YAML

uncrustify: Needs python to build, set PYTHON_FOR_BUILD_ONLY etc

(nia)

2019-07-09 18:50:40 UTC MAIN commitmail json YAML

dolphin-emu: OpenAL support was removed.

(nia)

2019-07-09 18:24:08 UTC MAIN commitmail json YAML

doc: Added mail/qconfirm version 0.14.3

(schmonz)

2019-07-09 18:23:46 UTC MAIN commitmail json YAML

Add and enable qconfirm.

(schmonz)

2019-07-09 18:23:15 UTC MAIN commitmail json YAML

Initial import of qconfirm, an implementation of a delivery confirmation
process for a mailing list or mail address. It is invoked by qmail-local
through a dot-qmail file, and can reduce the amount of junk mail hitting
a mailbox or the mailboxes of mailing list subscribers. qconfirm
performs this delivery confirmation process either sender based or
message based.

When used for a public mail address, not a mailing list, qconfirm is
capable of detecting follow-ups on mail messages originated from this
mail address, and doesn't request delivery confirmation is this case.
qconfirm also is able to identify delivery confirmation requests from
recipients of mail messages, and automatically confirms the delivery
if desired.

(schmonz)

2019-07-09 17:38:55 UTC MAIN commitmail json YAML

doc: Updated multimedia/adobe-flash-player to 32.0.0.223

(tsutsui)

2019-07-09 17:38:23 UTC MAIN commitmail json YAML

2019-07-09 16:34:16 UTC MAIN commitmail json YAML

TODO: remove lightspark.

(nia)

2019-07-09 16:33:52 UTC MAIN commitmail json YAML

doc: Added multimedia/lightspark version 0.8.1

(nia)

2019-07-09 16:33:30 UTC MAIN commitmail json YAML

2019-07-09 16:23:04 UTC MAIN commitmail json YAML

weechat: Turn on "python lua wide-curses perl ruby" by default.

Should enable users to run most scripts available on weechat.org.

If you're using pkgsrc you probably have python/perl/lua installed already,
and ruby apparently even works on VAX, so this shouldn't be much of a hard
requirement.

joyent has been building with these settings for a while.

(nia)

2019-07-09 16:09:06 UTC MAIN commitmail json YAML

doc: Updated lang/spidermonkey52 to 52.7.4nb10

(maya)

2019-07-09 16:08:38 UTC MAIN commitmail json YAML

2019-07-09 15:46:42 UTC MAIN commitmail json YAML

2019-07-09 15:46:10 UTC MAIN commitmail json YAML

TOOL_DEPENDS, not BUILD_DEPENDS, for a tool we run at build-time.

(riastradh)

2019-07-09 15:46:02 UTC MAIN commitmail json YAML

aarch64 has no compiler flag for ABI=64.

(riastradh)

2019-07-09 15:45:46 UTC MAIN commitmail json YAML

Avoid passing _CC as cross-compiler to recursive makes.

This way we don't inadvertently tell a native dependency that it is
supposed to be compiled with the cross-compiler.

No functional change intended for USE_CROSS_COMPILE=no.

(riastradh)

2019-07-09 15:45:35 UTC MAIN commitmail json YAML

Note that USE_CWRAPPERS=no is needed for now in cross-compiling.

This is a bug, just need to teach cwrappers about passing sysroot.

(riastradh)

2019-07-09 15:45:26 UTC MAIN commitmail json YAML

Sync cross-libtool-base with libtool-base.  Eliminate CROSSBASE.

cross-libtool-base now installs into $PREFIX/cross-$TARGET_ARCH
unconditionally.

(riastradh)

2019-07-09 15:38:23 UTC MAIN commitmail json YAML

grafx2: Needs pkg-config.

(nia)

2019-07-09 15:35:48 UTC MAIN commitmail json YAML

2019-07-09 14:10:54 UTC MAIN commitmail json YAML

npm: Add bash to USE_TOOLS.

(nia)

2019-07-09 13:21:41 UTC MAIN commitmail json YAML

Updated devel/quilt to 0.66

(ryoon)

2019-07-09 13:21:05 UTC MAIN commitmail json YAML

Update to 0.66

Changelog:
0.66
User-visible changes since 0.65 are as follows:

- Add support for lzip archives and patches
- Document QUILT_PC as user-settable
- configure: Don't require md5sum
- Test suite: Allow keeping the working directory on failure
- Test suite: Fix regex for recent versions of perl ...

0.65
User-visible changes since 0.64 are as follows:

- Translation fixes
- Project settings have priority
- Reject binary files in patches
- Fix a race condition in diff_file
- Performance: Optimizations to the setup command
- Performance: Optimizations to the bash completion script ...

(ryoon)

2019-07-09 12:42:42 UTC MAIN commitmail json YAML

py-dbfread: better Makefile

(adam)

2019-07-09 12:39:02 UTC MAIN commitmail json YAML

Updated devel/py-flake8, graphics/py-graphviz

(adam)

2019-07-09 12:38:44 UTC MAIN commitmail json YAML

py-graphviz: updated to 0.11.1

Version 0.11.1
Include stderr in str() of raised subprocess.CalledProcessError.

(adam)

2019-07-09 11:55:57 UTC MAIN commitmail json YAML

2019-07-09 11:35:15 UTC MAIN commitmail json YAML

2019-07-09 11:34:09 UTC MAIN commitmail json YAML

doc: Updated math/ltm to 1.1.0

(nia)

2019-07-09 11:29:30 UTC MAIN commitmail json YAML

2019-07-09 11:27:51 UTC MAIN commitmail json YAML

devilutionx: Needs pkg-config to find libsodium.

(nia)

2019-07-09 11:27:16 UTC MAIN commitmail json YAML

ltm: Update to 1.1.0

Jan 28th, 2019
v1.1.0
      -- Christoph Zurnieden contributed FIPS 186.4 compliant
          prime-checking (PR #113), several other fixes and a load of documentation
      -- Daniel Mendler provided two's-complement functions (PR #124)
          and mp_{set,get}_double() (PR #123)
      -- Francois Perrad took care of linting the sources, provided all fixes and
          a astylerc to auto-format the sources.
      -- A bunch of patches by Kevin B Kenny have been back-ported from TCL
      -- Jan Nijtmans provided the patches to `const`ify all API
          function arguments (also from TCL)
      -- mp_rand() has now several native random provider implementations
          and doesn't rely on `rand()` anymore
      -- Karel Miko provided fixes when building for MS Windows
          and re-worked the makefile generating process
      -- The entire environment and build logic has been extended and improved
          regarding auto-detection of platforms, libtool and a lot more
      -- Prevent some potential BOF cases
      -- Improved/fixed mp_lshd() and mp_invmod()
      -- A load more bugs were fixed by various contributors

(nia)

2019-07-09 11:21:13 UTC MAIN commitmail json YAML

doc: Updated security/libtomcrypt to 1.18.2

(nia)

2019-07-09 11:20:58 UTC MAIN commitmail json YAML

libtomcrypt: Update to 1.18.2

July 1st, 2018
v1.18.2
      -- Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408)
      -- Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373)
      -- Fix two-key 3DES (PR #390)
      -- Fix accelerated CTR mode (PR #359)
      -- Fix Fortuna PRNG (PR #363)
      -- Fix compilation on platforms where cc doesn't point to gcc (PR #382)
      -- Fix using the wrong environment variable LT instead of LIBTOOL (PR #392)
      -- Fix build on platforms where the compiler provides __WCHAR_MAX__ but wchar.h is not available (PR #390)
      -- Fix & re-factor crypt_list_all_sizes() and crypt_list_all_constants() (PR #414)
      -- Minor fixes (PR's #350 #351 #375 #377 #378 #379)

January 22nd, 2018
v1.18.1
      -- Fix wrong SHA3 blocksizes, thanks to Claus Fischer for reporting this via Mail (PR #329)
      -- Fix NULL-pointer dereference in `ccm_memory()` with LTC_CLEAN_STACK enabled (PR #327)
      -- Fix `ccm_process()` being unable to process input buffers longer than 256 bytes (PR #326)
      -- Fix the `register_all_{ciphers,hashes,prngs}()` return values (PR #316)
      -- Fix some typos, warnings and duplicate prototypes in code & doc (PR's #310 #320 #321 #335)
      -- Fix possible undefined behavior with LTC_PTHREAD (PR #337)
      -- Fix some DER bugs (PR #339)
      -- Fix CTR-mode when accelerator is used (OP-TEE/optee_os #2086)
      -- Fix installation procedure (Issue #340)

October 10th, 2017
v1.18.0
      -- Bugfix multi2
      -- Bugfix Noekeon
      -- Bugfix XTEA
      -- Bugfix rng_get_bytes() on windows where we could read from c:\dev\random
      -- Fixed the Bleichbacher Signature attack in PKCS#1 v1.5 EMSA, thanks to Alex Dent
      -- Fixed a potential cache-based timing attack in CCM, thanks to Sebastian Verschoor
      -- Fix GCM counter reuse and potential timing attacks in EAX, OCB and OCBv3,
        thanks to Rapha谷l Jamet
      -- Implement hardened RSA operations when CRT is used
      -- Enabled timing resistant calculations of ECC and RSA operations per default
      -- Applied some patches from the OLPC project regarding PKCS#1 and preventing
        the hash algorithms from overflowing
      -- Larry Bugbee contributed the necessary stuff to more easily call libtomcrypt
        from a dynamic language like Python, as shown in his pyTomCrypt
      -- Nikos Mavrogiannopoulos contributed RSA blinding and export of RSA and DSA keys
        in OpenSSL/GnuTLS compatible format
      -- Patrick Pelletier contributed a smart volley of patches
      -- Christopher Brown contributed some patches and additions to ASN.1/DER
      -- Pascal Brand of STMicroelectronics contributed patches regarding CCM, the
        XTS mode and RSA private key operations with keys without CRT parameters
      -- RC2 now also works with smaller key-sizes
      -- Improved/extended several tests & demos
      -- Hardened DSA and RSA by testing (through Karel's perl-CryptX)
        against Google's "Wycheproof" and Kudelski Security's "CDF"
      -- Fixed all compiler warnings
      -- Fixed several build issues on FreeBSD, NetBSD, Linux x32 ABI, HP-UX/IA64,
        Mac OS X, Windows (32&64bit, Cygwin, MingW & MSVC) ...
      -- Re-worked all makefiles
      -- Re-worked most PRNG's
      -- The code is now verified by a linter, thanks to Francois Perrad
      -- Documentation (crypt.pdf) is now built deterministically, thanks to Michael Stapelberg
      -- Add Adler32 and CRC32 checksum algorithms
      -- Add Base64-URL de-/encoding and some strict variants
      -- Add Blake2b & Blake2s (hash & mac), thanks to Kelvin Sherlock
      -- Add Camellia block cipher
      -- Add ChaCha (stream cipher), Poly1305 (mac), ChaCha20Poly1305 (encauth)
      -- Add constant-time mem-compare mem_neq()
      -- Add DER GeneralizedTime de-/encoding
      -- Add DSA and ECC key generation FIPS-186-4 compliance
      -- Add HKDF, thanks to RyanC (especially for also providing documentation :-) )
      -- Add OCBv3
      -- Add PKCS#1 v1.5 mode of SSL3.0
      -- Add PKCS#1 testvectors from RSA
      -- Add PKCS#8 & X.509 import for RSA keys
      -- Add stream cipher API
      -- Add SHA3 & SHAKE
      -- Add SHA512/256 and SHA512/224
      -- Add Triple-DES 2-key mode, thanks to Paul Howarth
      -- Brought back Diffie-Hellman

(nia)

2019-07-09 11:19:33 UTC MAIN commitmail json YAML

py-flake8: updated to 3.7.8

3.7.8:
Bugs Fixed
- Fix handling of Application.parse_preliminary_options_and_args when
  argv is an empty list
- Fix crash when a file parses but fails to tokenize
- Log the full traceback on plugin exceptions
- Fix # noqa: ... comments with multi-letter codes

(adam)

2019-07-09 10:43:17 UTC MAIN commitmail json YAML

doc: Updated security/libssh2 to 1.9.0

(nia)

2019-07-09 10:42:59 UTC MAIN commitmail json YAML

libssh2: Update to 1.9.0

Changes:
- adds ECDSA keys and host key support when using OpenSSL
- adds ED25519 key and host key support when using OpenSSL 1.1.1
- adds OpenSSH style key file reading
- adds AES CTR mode support when using WinCNG
- adds PEM passphrase protected file support for Libgcrypt and WinCNG
- adds SHA256 hostkey fingerprint
- adds libssh2_agent_get_identity_path() and libssh2_agent_set_identity_path()
- adds explicit zeroing of sensitive data in memory
- adds additional bounds checks to network buffer reads
- adds the ability to use the server default permissions when creating sftp directories
- adds support for building with OpenSSL no engine flag
- adds support for building with LibreSSL
- increased sftp packet size to 256k
- fixed oversized packet handling in sftp
- fixed building with OpenSSL 1.1
- fixed a possible crash if sftp stat gets an unexpected response
- fixed incorrect parsing of the KEX preference string value
- fixed conditional RSA and AES-CTR support
- fixed a small memory leak during the key exchange process
- fixed a possible memory leak of the ssh banner string
- fixed various small memory leaks in the backends
- fixed possible out of bounds read when parsing public keys from the server
- fixed possible out of bounds read when parsing invalid PEM files
- no longer null terminates the scp remote exec command
- now handle errors when diffie hellman key pair generation fails
- fixed compiling on Windows with the flag STDCALL=ON
- improved building instructions
- improved unit tests

(nia)

2019-07-09 10:32:51 UTC MAIN commitmail json YAML

hexchat: Remove libsexy option, it isn't used any more.

(nia)

2019-07-09 09:51:55 UTC MAIN commitmail json YAML

Need strnlen(3), obtain it from libnbcompat if not provided by host OS

(sevan)

2019-07-09 09:43:32 UTC MAIN commitmail json YAML

Use the correct prototype - thanks <gutteridge>

(sevan)

2019-07-09 07:47:03 UTC MAIN commitmail json YAML

Updated lang/python37, lang/py37-html-docs

(adam)

2019-07-09 07:46:37 UTC MAIN commitmail json YAML

python37: updated to 3.7.4

Python 3.7.4 final

Core and Builtins
bpo-37500: Due to unintended side effects, revert the change introduced by bpo-1875 in 3.7.4rc1 to check for syntax errors in dead conditional code blocks.
Documentation
bpo-37149: Replace the dead link to the Tkinter 8.5 reference by John Shipman, New Mexico Tech, with a link to the archive.org copy.

Python 3.7.4 release candidate 2

Security
bpo-37463: ssl.match_hostname() no longer accepts IPv4 addresses with additional text after the address and only quad-dotted notation without trailing whitespaces. Some inet_aton() implementations ignore whitespace and all data after whitespace, e.g. ‘127.0.0.1 whatever’.

Core and Builtins
bpo-24214: Improved support of the surrogatepass error handler in the UTF-8 and UTF-16 incremental decoders.

Library
bpo-37440: http.client now enables TLS 1.3 post-handshake authentication for default context or if a cert_file is passed to HTTPSConnection.
bpo-37437: Update vendorized expat version to 2.2.7.
bpo-37428: SSLContext.post_handshake_auth = True no longer sets SSL_VERIFY_POST_HANDSHAKE verify flag for client connections. Although the option is documented as ignored for clients, OpenSSL implicitly enables cert chain validation when the flag is set.
bpo-32627: Fix compile error when _uuid headers conflicting included.

Windows
bpo-37369: Fixes path for sys.executable when running from the Microsoft Store.
bpo-35360: Update Windows builds to use SQLite 3.28.0.

macOS
bpo-34602: Avoid test suite failures on macOS by no longer calling resource.setrlimit to increase the process stack size limit at runtime. The runtime change is no longer needed since the interpreter is being built with a larger default stack size.

(adam)

2019-07-09 07:29:46 UTC MAIN commitmail json YAML

Updated multimedia/ffmpeg4, databases/mongodb3

(adam)