Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (2h)  pkgsrc-2024Q1 (14d)  pkgsrc-2023Q4 (42d)  pkgsrc-2023Q2 (74d)  pkgsrc-2023Q3 (154d) 

2024-05-12 22:48:10 UTC Now

2017-08-16 06:59:36 UTC MAIN commitmail json YAML

Updated p5-Encode to 2.92.

$Revision: 2.92 $ $Date: 2017/07/18 07:15:29 $
! Encode.pm  MANIFEST lib/Encode/Alias.pm
+ t/use-Encode-Alias.t
  Pulled: Fix loading Encode::Alias before Encode
  https://github.com/dankogai/p5-encode/pull/118
! Makefile.PL
  Pulled: Fix gccversion Argument "630 20170516" isn't numeric
  https://github.com/dankogai/p5-encode/pull/118
! lib/Encode/MIME/Header.pm t/mime-header.t
  Pulled: Encode::MIME::Header: Fix parsing quoted-printable text
    in strict mode
  https://github.com/dankogai/p5-encode/pull/115
! Encode.pm
  use define_encoding() instead of tweaking $Encode::Encoding{utf8}.
  https://github.com/dankogai/p5-encode/commit/208d094b8cf82da488495400ea9a518841fd007a#commitcomment-22698036

2.91 2017/06/22 08:11:05
! Encode.pm
  Addressed: RT#122167: use parent q{Encode::Encoding}; fails:
    Can't locate object
  https://rt.cpan.org/Ticket/Display.html?id=122167
! Makefile.PL
  Pulled: fix gcc warnings for older gcc < 4.0
  https://github.com/dankogai/p5-encode/pull/114

2.90 2017/06/10 17:23:50
! Makefile.PL
  Pulled: Include all contributors into META
  https://github.com/dankogai/p5-encode/pull/111
! bin/enc2xs bin/ucmlint encoding.pm
  lib/Encode/Encoding.pm lib/Encode/GSM0338.pm t/CJKT.t
  Pulled: Where possible do not depend on value of $@,
    instead use return value of eval
  https://github.com/dankogai/p5-encode/pull/110
! Encode.xs
  Pulled: Fix more XS problems in Encode.xs file
  https://github.com/dankogai/p5-encode/pull/109
! encoding.pm lib/Encode/Encoding.pm t/guess.t
  Pulled: Small fixes
  https://github.com/dankogai/p5-encode/pull/108
! Encode.pm Makefile.PL
  Pulled: Load modules Encode::MIME::Name and Storable normally
  https://github.com/dankogai/p5-encode/pull/107
! Unicode/Unicode.pm lib/Encode/Alias.pm lib/Encode/Encoding.pm
  lib/Encode/Unicode/UTF7.pm
  Pulled: Remove no warnings 'redefine'; and correctly loaddependences
  https://github.com/dankogai/p5-encode/pull/106
! Encode.pm Encode.xs Unicode/Unicode.pm Unicode/Unicode.xs
  Pulled: Remove PP stubs and reformat predefine_encodings()
  https://github.com/dankogai/p5-encode/pull/104
! Encode.pm Encode.xs
  Pulled: Run Encode XS BOOT code at compile time
  https://github.com/dankogai/p5-encode/pull/103
! Encode.pm Unicode/Unicode.pm lib/Encode/Encoding.pm
  lib/Encode/Guess.pm lib/Encode/JP/JIS7.pm lib/Encode/MIME/Header.pm
  lib/Encode/MIME/Header/ISO_2022_JP.pm
  Pulled: Use Encode::define_encoding and propagate carp/croak message
  https://github.com/dankogai/p5-encode/pull/102
! t/truncated_utf8.t t/utf8messages.t
  Pulled: Fixes for older perl versions
  https://github.com/dankogai/p5-encode/pull/101
! Encode.xs encoding.pm t/enc_eucjp.t t/enc_utf8.t
  Pulled: cperl fixes: encoding undeprecated, no strict hashpairs
  https://github.com/dankogai/p5-encode/pull/100
! MANIFEST
  Pulled: Add missing tests into MANIFEST file
  https://github.com/dankogai/p5-encode/pull/99
! Encode.xs t/fallback.t
  Pulled: Cleanup code for handling fallback/replacement characters
  https://github.com/dankogai/p5-encode/pull/98

(wiz)

2017-08-16 06:58:07 UTC MAIN commitmail json YAML

Updated time/p5-DateTime-Format-Strptime to 1.7400

(wiz)

2017-08-16 06:57:57 UTC MAIN commitmail json YAML

Updated p5-DateTime-Format-Strptime to 1.7400.

1.74    2017-08-03

- Fix text to not rely on a very specific exception message from Specio. This
  was broken in 0.39. Reported by Slaven Rezić. GH #18.

(wiz)

2017-08-16 06:55:11 UTC MAIN commitmail json YAML

Updated archivers/unrar to 5.5.8

(wiz)

2017-08-16 06:55:02 UTC MAIN commitmail json YAML

Updated unrar to 5.5.8.

Only internal version numbers were changed.

(wiz)

2017-08-16 06:46:12 UTC MAIN commitmail json YAML

Updated print/cups-filters to 1.16.1

(wiz)

2017-08-16 06:45:58 UTC MAIN commitmail json YAML

Updated cups-filters to 1.16.1.

CHANGES IN V1.16.1

- cups-browsed: Make timeouts for HTTP access to the local
  CUPS daemon and remote IPP printers configurable. Thanks to
  Cedric Dufour (cedric dot dufour at idiap dot ch) for the
  patch (Bug #1387, Debian bug #852436).
- texttopdf: Allow bold and underline formatting to be used
  together when using "prettyprint". Thanks to Michael Moran
  (vampm at comcast dot net) for the patch.
- texttopdf: Allow to alter margins, and chars/lines per Inch
  when using "prettyprint". Thanks to Michael Moran (vampm at
  comcast dot net) for the patch.
- texttopdf: When "prettyprint" is used, do not drop out of
  C/shell comment mode too early. Thanks to Michael Moran
  (vampm at comcast dot net) for the patch.
- cups-browsed: Additional NULL checks for description and
          location.
- cups-browsed: Fixed crash which happens when using
  BrowsePoll (Debian bug #723835).

CHANGES IN V1.16.0

- cups-browsed: Let elements in arrays get stacked up in the
  order they are added, before, they were in the order how
  they are positioned in memory. This especially led to a
  random order of printer cluster definitions and of
  command-line-supplied configuration options.
- cups-browsed: On shutdown not all locally created queues got
          deleted.
- cups-browsed: Added support for manual definition of
  load-balancing printer clusters via the "Cluster" directive
  in cups-browsed.conf.

CHANGES IN V1.15.0

- cups-browsed: Removed the function to compare printer entries
  for sorting the printer entry list. This led to corruption
  of the list and so to crashes.
- cups-browsed: Fixed crashes when many printers (especially
  all printers of a load-balanced cluster) are removed at once.
- cups-browsed: Log the full list of handled remote printers
  whenever one is added or removed.
- cups-browsed: Renamed the handle_cups_queues() function to
  update_cups_queues() to better reflect what it is doing.
- cups-browsed: When clustering remote CUPS printers together
  do not call them duplicates but slaves asigned to a master.
- cups-browsed: Log the error if the network interface name of
  a DNS-SD event could not be determined.
- cups-browsed: Simplified printer entry removal procedure.
- cups-browsed: Log memeber printer list of a printer cluster
  (implicit class) when a member printer is added or removed.
- cups-browsed: Removed superfluous (and not correctly
          working) duplicate counter from the remote printer entry
          data structure.
- cups-browsed: Add "AutoClustering" directive to
  cups-browsed.conf to turn on and off automatically
  clustering equally named local print queues which point to
  remote CUPS printers. When automatic clustering is turned
  off, queue name clashes are prevented by adding "@<server
  name>" to local queue names based on the remote queue name
  or on make and model.
- cups-browsed: Skip callback functions and the CUPS queue
  creation/update/removal loop when cups-browsed is terminated
  by a SIGTERM signal. This avoids hanging on shutdown. Thanks
  to Edgar Fuss (ef at math dot uni-bonn dot de, Bug #1402).
- libcupsfilters: Added some fallbacks for incorrect
  resolution IPP attributes on IPP network printers (Debian
  bug #868360).
- pdftoopvp: Added missing "#include <math.h>" needed for
  cross-compiling for arm-v7a-linux-gnueabi (Bug #1232).
- cups-browsed: Prevent the creation of two remote printer
  entries for two IPP network printers or an IPP network
  printer and a remote CUPS printer with the same local queue
  name. This could easily happen with make/model-based naming.
- cups-browsed: Added the possibility to optionally not
  create local queues for remote printers for which CUPS
  (from 2.2.x on) auto-creates queues by itself (DNS-SD
  advertised driverless printers).
- cups-browsed: Removed repeated code for clean-up when
  generate_local_queue() function fails.
- cups-browsed: Take care of CUPS' temporary queues. Do not
  consider them when checking whether a queue with the same
  name as the one we are creating already exists and make
  temporary queues permanent (or remove them) before
  overwriting them with our local queue.
- cups-browsed: Make the naming scheme for locally created
  print queue configurable, especially allow for naming based
  on the DNS-SD service name (now default) as this is the same
  scheme as CUPS uses for its temporary queues. This way we
  prevent CUPS creating temporary queues when cups-browsed is
  already creating a queue.
- cups-browsed: Do not add "APRemoteQueueID" keyword to the
  local queue's PPD file if the queue is for an IPP network
  printer.
- cups-browsed: Skip multiple browse entries for the same
  printer with interface alias addresses.  Thanks to Edgar
  Fuss (ef at math dot uni-bonn dot de, Bug #1399).
- cups-browsed: Improved support for Description (Info) and
  Location fields of remote CUPS queues. Thanks to Edgar Fuss
  (ef at math dot uni-bonn dot de, Bug #1398).
- cups-browsed: Renamed variable names for better code
  readability.  Thanks to Edgar Fuss (ef at math dot uni-bonn
  dot de, Bug #1398).
- cups-browsed: Additional NULL checks in the
  create_local_queue() function. Thanks to Edgar Fuss (ef at
  math dot uni-bonn dot de, Bug #1398).

CHANGES IN V1.14.1

- cups-browsed: Do correct removal of printer entry handling
  duplicates correctly also when a legacy CUPS-broadcasted
  printer disappears or a printer remaining from the last
  session does not appear again.
- cups-browsed: Use getline() instead of fgets() to read saved
  option settings. This is less crash-prone (Ubuntu bug
  #1658833).
- cups-browsed: Improved error logging when saving option
          settings.
- cups-browsed: Added NULL checks for generate_local_queue()
  and create_local_queue() functions.
- cups-browsed: When accessing local CUPS queues use always
  the correct port of the CUPS daemon we are attached to.
- cups-browsed: Check whether a connection to the local CUPS
  daemon actually happened before using it (Ubuntu bug
  #1644049).
- cups-browsed: Set unused fields of printer record to NULL
  when tranfering data from the record of a duplicate printer
  to the record of a disappeared one.
- cups-browsed: Simplify removal of all queues on shutdown or
  stop of Avahi.
- cups-browsed: When creating a record for a discovered
  printer set it all zero before filling it in, to assure
  that no field is in an undefined state.
- cups-browsed: All functions which are called via Glib
  functions or otherwise event-triggered log now in which
  thread they are running. This way one can see whether
  problems can be caused by concurrent access to global
  resources.
- cups-browsed: Do not check whether the DNS-SD event is from
  the local machine in the browse_callback() function. We
  cannot check the port here.
- cups-browsed: Added more NULL checks to Avahi callback
          functions.
- cups-browsed: Added NULL check to avoid crashes in the Avahi
  resolver callback (Ubuntu bug #1696967).
- libcupsfilters: Let PPD generator do case-insensitive
  comparisons for PWG Raster color spaces, as some printers
  (Epson) do not use the standard-conforming all-lowercase
  form for them (CUPS Issue #4998).

(wiz)

2017-08-16 06:41:18 UTC MAIN commitmail json YAML

+ p5-DateTime-Format-Strptime-1.74, p5-Encode-2.92,
  p5-List-MoreUtils-XS-0.422.

(wiz)

2017-08-15 21:23:19 UTC MAIN commitmail json YAML

Updated archivers/unrar to 5.5.7

(wiz)

2017-08-15 21:23:09 UTC MAIN commitmail json YAML

2017-08-15 21:13:00 UTC MAIN commitmail json YAML

Remove two that were done.

(wiz)

2017-08-15 21:04:19 UTC MAIN commitmail json YAML

Updated archivers/py-libarchive-c to 2.4nb3

(wiz)

2017-08-15 21:04:09 UTC MAIN commitmail json YAML

Remove hack for finding libarchive that is not correct any longer.
Bump PKGREVISION.

(wiz)

2017-08-15 21:00:22 UTC MAIN commitmail json YAML

Updated editors/vim-share to 8.0.0921

(wiz)

2017-08-15 21:00:11 UTC MAIN commitmail json YAML

2017-08-15 19:37:11 UTC MAIN commitmail json YAML

Updated net/wireshark to 2.2.8

(wiz)

2017-08-15 19:37:01 UTC MAIN commitmail json YAML

Updated wireshark to 2.2.8.

  Bug Fixes

  The following vulnerabilities have been fixed:
    * [1]wnpa-sec-2017-13
      WBMXL dissector infinite loop ([2]Bug 13477, [3]Bug 13796)
      [4]CVE-2017-7702, cve-idlink:CVE-2017-11410[] Note: This is an
      update for a fix in Wireshark 2.2.6 and 2.0.12.

    * [5]wnpa-sec-2017-28
      openSAFETY dissector memory exhaustion ([6]Bug 13649, [7]Bug 13755)
      [8]CVE-2017-9350, [9]CVE-2017-11411 Note: This is an update for a
      fix in Wireshark 2.2.7.

    * [10]wnpa-sec-2017-34
      AMQP dissector crash. ([11]Bug 13780) [12]CVE-2017-11408
    * [13]wnpa-sec-2017-35
      MQ dissector crash. ([14]Bug 13792) [15]CVE-2017-11407
    * [16]wnpa-sec-2017-36
      DOCSIS infinite loop. ([17]Bug 13797) [18]CVE-2017-11406

  The following bugs have been fixed:
    * Y.1711 dissector reverses defect type order. ([19]Bug 8292)
    * Packet list keeps scrolling back to selected packet while names are
      being resolved. ([20]Bug 12074)
    * [REGRESSION] Export Objects do not show files from a SMB2 capture.
      ([21]Bug 13214)
    * LTE RRC: lte-rrc.q_RxLevMin filter fails on negative values.
      ([22]Bug 13481)
    * Hexpane showing in proportional font again. ([23]Bug 13638)
    * Regression in SCCP fragments handling. ([24]Bug 13651)
    * TCAP SRT incorrectly matches TC_BEGINs and TC_ENDs. ([25]Bug 13739)
    * Dissector for WSMP (IEEE 1609.3) not current. ([26]Bug 13766)
    * RANAP: possible issue in the heuristic code. ([27]Bug 13770)
    * [oss-fuzz] UBSAN: shift exponent 35 is too large for 32-bit type
      int in packet-btrfcomm.c:314:37. ([28]Bug 13783)
    * RANAP: false positives on heuristic algorithm. ([29]Bug 13791)
    * Automatic name resolution not saved to PCAP-NG NRB. ([30]Bug 13798)
    * DAAP dissector dissect_daap_one_tag recursion stack exhausted.
      ([31]Bug 13799)
    * Malformed DCERPC PNIO packet decode, exception handler invalid
      poionter reference. ([32]Bug 13811)
    * It seems SPVID was decoded from wrong field. ([33]Bug 13821)
    * README.dissectors: Add notes about predefined string structures not
      available to plugin authors. ([34]Bug 13828)
    * Statistics->Packet Lengths doesn't display details for 5120 or
      greater. ([35]Bug 13844)
    * cmake/modules/FindZLIB.cmake doesn't find inflatePrime. ([36]Bug
      13850)
    * BGP: incorrect decoding COMMUNITIES whose length is larger than
      255. ([37]Bug 13872)

  Updated Protocol Support

  AMQP, BGP, BSSMAP, BT RFCOMM, DAAP, DOCSIS, E.212, FDDI, GSM A GM, GSM
  BSSMAP, IEEE 802.11, IP, ISIS LSP, LTE RRC, MQ, OpenSafety, OSPF,
  PROFINET IO, RANAP, SCCP, SGSAP, SMB2, TCAP, TCP, UMTS FP, UMTS RLC,
  WBXML, WSMP, and Y.1711

(wiz)

2017-08-15 19:22:54 UTC MAIN commitmail json YAML

Updated net/tor to 0.3.0.10

(wiz)

2017-08-15 19:22:44 UTC MAIN commitmail json YAML

Updated tor to 0.3.0.10.

Changes in version 0.3.0.10 - 2017-08-02
  Tor 0.3.0.10 backports a collection of small-to-medium bugfixes
  from the current Tor alpha series. OpenBSD users and TPROXY users
  should upgrade; others are probably okay sticking with 0.3.0.9.

  o Major features (build system, continuous integration, backport from 0.3.1.5-alpha):
    - Tor's repository now includes a Travis Continuous Integration (CI)
      configuration file (.travis.yml). This is meant to help new
      developers and contributors who fork Tor to a Github repository be
      better able to test their changes, and understand what we expect
      to pass. To use this new build feature, you must fork Tor to your
      Github account, then go into the "Integrations" menu in the
      repository settings for your fork and enable Travis, then push
      your changes. Closes ticket 22636.

  o Major bugfixes (linux TPROXY support, backport from 0.3.1.1-alpha):
    - Fix a typo that had prevented TPROXY-based transparent proxying
      from working under Linux. Fixes bug 18100; bugfix on 0.2.6.3-alpha.
      Patch from "d4fq0fQAgoJ".

  o Major bugfixes (openbsd, denial-of-service, backport from 0.3.1.5-alpha):
    - Avoid an assertion failure bug affecting our implementation of
      inet_pton(AF_INET6) on certain OpenBSD systems whose strtol()
      handling of "0xfoo" differs from what we had expected. Fixes bug
      22789; bugfix on 0.2.3.8-alpha. Also tracked as TROVE-2017-007.

  o Minor features (backport from 0.3.1.5-alpha):
    - Update geoip and geoip6 to the July 4 2017 Maxmind GeoLite2
      Country database.

  o Minor bugfixes (bandwidth accounting, backport from 0.3.1.2-alpha):
    - Roll over monthly accounting at the configured hour and minute,
      rather than always at 00:00. Fixes bug 22245; bugfix on 0.0.9rc1.
      Found by Andrey Karpov with PVS-Studio.

  o Minor bugfixes (compilation warnings, backport from 0.3.1.5-alpha):
    - Suppress -Wdouble-promotion warnings with clang 4.0. Fixes bug 22915;
      bugfix on 0.2.8.1-alpha.
    - Fix warnings when building with libscrypt and openssl scrypt
      support on Clang. Fixes bug 22916; bugfix on 0.2.7.2-alpha.
    - When building with certain versions of the mingw C header files,
      avoid float-conversion warnings when calling the C functions
      isfinite(), isnan(), and signbit(). Fixes bug 22801; bugfix
      on 0.2.8.1-alpha.

  o Minor bugfixes (compilation, mingw, backport from 0.3.1.1-alpha):
    - Backport a fix for an "unused variable" warning that appeared
      in some versions of mingw. Fixes bug 22838; bugfix on
      0.2.8.1-alpha.

  o Minor bugfixes (coverity build support, backport from 0.3.1.5-alpha):
    - Avoid Coverity build warnings related to our BUG() macro. By
      default, Coverity treats BUG() as the Linux kernel does: an
      instant abort(). We need to override that so our BUG() macro
      doesn't prevent Coverity from analyzing functions that use it.
      Fixes bug 23030; bugfix on 0.2.9.1-alpha.

  o Minor bugfixes (directory authority, backport from 0.3.1.1-alpha):
    - When rejecting a router descriptor for running an obsolete version
      of Tor without ntor support, warn about the obsolete tor version,
      not the missing ntor key. Fixes bug 20270; bugfix on 0.2.9.3-alpha.

  o Minor bugfixes (linux seccomp2 sandbox, backport from 0.3.1.5-alpha):
    - Avoid a sandbox failure when trying to re-bind to a socket and
      mark it as IPv6-only. Fixes bug 20247; bugfix on 0.2.5.1-alpha.

  o Minor bugfixes (unit tests, backport from 0.3.1.5-alpha)
    - Fix a memory leak in the link-handshake/certs_ok_ed25519 test.
      Fixes bug 22803; bugfix on 0.3.0.1-alpha.

(wiz)

2017-08-15 19:07:44 UTC pkgsrc-2017Q2 commitmail json YAML

2017-08-15 19:06:53 UTC pkgsrc-2017Q2 commitmail json YAML

Pullup ticket #5533 - requested by maya
devel/py-mercurial: security fix

Revisions pulled up:
- devel/py-mercurial/Makefile                                  1.13-1.14
- devel/py-mercurial/Makefile.version                          1.51
- devel/py-mercurial/PLIST                                      1.16
- devel/py-mercurial/distinfo                                  1.51-1.52

---
  Module Name:    pkgsrc
  Committed By:  joerg
  Date:          Tue Jul 25 16:09:40 UTC 2017

  Modified Files:
          pkgsrc/devel/py-mercurial: Makefile distinfo
  Added Files:
          pkgsrc/devel/py-mercurial/patches: patch-mercurial_localrepo.py
              patch-mercurial_statichttprepo.py

  Log Message:
  Fix a memory leak, from upstream. Bump revision.

---
  Module Name:    pkgsrc
  Committed By:  maya
  Date:          Mon Aug 14 01:31:56 UTC 2017

  Modified Files:
          pkgsrc/devel/py-mercurial: Makefile Makefile.version PLIST distinfo
  Removed Files:
          pkgsrc/devel/py-mercurial/patches: patch-mercurial_localrepo.py
              patch-mercurial_statichttprepo.py

  Log Message:
  py-mercurial: update to 4.3.1

  1. Mercurial 4.3 / 4.3.1 (2017-08-10)

  (4.3.1 was released immediately after 4.3 to fix a release oversight.)

  An overview of new features available. This is a regularly-scheduled quarterly feature release.

  1.1. Notable changes

      experimental amend extension providing the amend command
      experimental sparse extension
      Support for Python 2.6 has been dropped.
      Bundles created by the strip extension now store phase information. It will be restored when unbundling.
      The strip extension now removes relevant obsmarkers. If a backup requested (the default), the obsmarkers are stored in the backup bundle and will be restored when unbundling.

      hg show work (from the experimental show extension) now displays more info

      hg show stack is a new view for the current, in-progress changeset and others around it
      Mitigation for two security vulnerabilities

  1.2. CVE-2017-1000115

  Mercurial's symlink auditing was incomplete prior to 4.3, and could be abused to write to files outside the repository.

  1.3. CVE-2017-1000116

  Mercurial was not sanitizing hostnames passed to ssh, allowing shell injection attacks on clients by specifying a hostname starting with -oProxyCommand. This is also present in Git (CVE-2017-1000117)
  and Subversion (CVE-2017-9800), so please patch those tools as well if you have them installed.

  2. Mercurial 4.2.3 (2017-08-10)

  This was an out-of-cycle backport of security fixes from 4.3 for users stuck on Python 2.6.-1000117)
  and Subversion (CVE-2017-9800), so please patch those tools as well if you have them installed.

  2. Mercurial 4.2.3 (2017-08-10)

  This was an out-of-cycle backport of security fixes from 4.3 for users stuck on Python 2.6.

  3. Mercurial 4.2.2 (2017-07-05)

  This is a regularly-scheduled bugfix release.

      largefiles: avoid a crash when archiving a subrepo with largefiles disabled
      rebase: also test abort from pretxnclose error

      rebase: backed out changes 2519994d25ca and cf8ad0e6c0e4 (issue5610)
      rebase: reinforce testing around precommit hook interrupting a rebase

(bsiegert)

2017-08-15 18:58:04 UTC MAIN commitmail json YAML

Updated mail/thunderbird-enigmail to 1.9.8.1

(wiz)

2017-08-15 18:57:54 UTC MAIN commitmail json YAML

Updated thunderbird-enigmail to 1.9.8.1.

Enigmail 1.9.8

Released 2017-06-30, works with Thunderbird 52.0 & newer and SeaMonkey 2.46 & newer.

Notable Changes

    This is a bugfix release. In addition, some locales were updated.

Bugs fixed

This version fixes a bug which blocks the mail sending process.

(wiz)

2017-08-15 18:41:26 UTC MAIN commitmail json YAML

Updated fonts/t1utils to 1.40

(wiz)

2017-08-15 18:41:16 UTC MAIN commitmail json YAML

Updated t1utils to 1.40.

Set LICENSE.

## Version 1.40 – 23.Jul.2017

* t1disasm: More security fixes reported by Jakub Wilk and Niels Thykier.

(wiz)

2017-08-15 17:24:03 UTC MAIN commitmail json YAML

Remove bogus libXp reference from buildlink3.mk.

From J旦rn Clausen in PR 50039.

(wiz)

2017-08-15 16:57:00 UTC MAIN commitmail json YAML

Updated textproc/py-m2r to 0.1.10

(wiz)

2017-08-15 16:56:50 UTC MAIN commitmail json YAML

Updated py-m2r to 0.1.10.

### Version 0.1.10 (2017-08-15)

* Include CHANGES and test files in source distribution

(wiz)

2017-08-15 15:54:06 UTC MAIN commitmail json YAML

Fix a problem with MAKE_VERSION being undefined on case-insentive filesystems.

On case-insensitive filesystems such as MacOS, two files (Makefile and makefile,
which is created by configure from makefile.in) collide.  Only the former
defines MAKE_VERSION, but it is replaced by the latter.  Consequently,
MAKE_VERSION is defined as an empty string on these systems.  This patch is
the result of a discussion on tech-pkg (see the thread following
pkg/2017/08/13/msg018629.html)">http://mail-index.netbsd.org/tech-pkg/2017/08/13/msg018629.html) and is
based upon code incorporated into bmake v20170812.

(brook)

2017-08-15 14:23:59 UTC MAIN commitmail json YAML

Updated net/sslh to 1.18nb1

(jperkin)

2017-08-15 14:23:50 UTC MAIN commitmail json YAML

Support documented command line options.  Bump PKGREVISION.

(jperkin)

2017-08-15 13:55:48 UTC MAIN commitmail json YAML

Updated audio/faac to 1.29.4

(adam)

2017-08-15 13:55:17 UTC MAIN commitmail json YAML

1.29.4:
- new option(--tag) to add named tags (iTunes '----')
- faster and better short/long window type switch
- Don't build DRM(Digital Radio Mondiale) by default.
  Use ./configure --enable-drm to build DRM version.
- fixed bugs
  * rounding in QuantizeReflectionCoeffs (tns.c)
  * use +60 value for scalefactor.
  * use clipped diff instead of original value (huffman.c)

(adam)

2017-08-15 13:22:29 UTC MAIN commitmail json YAML

Updated net/rancid to 3.6.2

(jperkin)

2017-08-15 13:22:20 UTC MAIN commitmail json YAML

Update net/rancid to 3.6.2.  Patch supplied by coyhile in
joyent/pkgsrc#2.  Changes since 3.6.1:

3.6.2
        Fix etc/Makefile for rancid.types.conf handling.

(jperkin)

2017-08-15 13:13:37 UTC MAIN commitmail json YAML

2017-08-15 12:23:33 UTC MAIN commitmail json YAML

Note update of databases/py-postgresql to 5.0.4.

(darcy)

2017-08-15 12:22:06 UTC MAIN commitmail json YAML

Version 5.0.4 (2017-07-23)
--------------------------
- This version officially supports the new Python 3.6 and PostgreSQL 9.6.
- query_formatted() can now be used without parameters.
- The automatic renaming of columns that are invalid as field names of
  named tuples now works more accurately in Python 2.6 and 3.0.
- Fixed error checks for unlink() and export() methods of large objects
  (bug report by Justin Pryzby).
- Fixed a compilation issue under OS X (bug report by Josh Johnston).

(darcy)

2017-08-15 12:13:15 UTC MAIN commitmail json YAML

Requires GNU m4 for -I support.

(jperkin)

2017-08-15 12:00:10 UTC MAIN commitmail json YAML

Revbump due to poppler update to version 0.57.0.

(nros)

2017-08-15 11:52:22 UTC MAIN commitmail json YAML

Revbump due to poppler update to verson 0.57.0.

(nros)

2017-08-15 11:46:51 UTC MAIN commitmail json YAML

2017-08-15 11:42:26 UTC MAIN commitmail json YAML

Fix DIST_SUBDIR to avoid unnecessary distfiles fetch

(ryoon)

2017-08-15 11:40:25 UTC MAIN commitmail json YAML

2017-08-15 11:19:56 UTC MAIN commitmail json YAML

2017-08-15 11:08:02 UTC MAIN commitmail json YAML

2017-08-15 10:59:43 UTC MAIN commitmail json YAML

2017-08-15 10:58:28 UTC MAIN commitmail json YAML

2017-08-15 10:57:35 UTC MAIN commitmail json YAML

2017-08-15 10:50:03 UTC MAIN commitmail json YAML

revbump due poppler update to verson 0.57.0

(nros)

2017-08-15 10:44:58 UTC MAIN commitmail json YAML

2017-08-15 10:00:35 UTC MAIN commitmail json YAML

Updated net/py-botocore to 1.6.1, net/py-awscli to 1.11.134, net/py-boto3 to 1.4.6

(adam)

2017-08-15 09:59:52 UTC MAIN commitmail json YAML

1.11.134
api-change:batch: Update batch command to latest version
api-change:cloudhsmv2: Update cloudhsmv2 command to latest version
api-change:efs: Update efs command to latest version
api-change:ssm: Update ssm command to latest version
api-change:storagegateway: Update storagegateway command to latest version
api-change:mgh: Update mgh command to latest version
api-change:glue: Update glue command to latest version

1.11.133
api-change:ec2: Update ec2 command to latest version
api-change:cognito-idp: Update cognito-idp command to latest version
api-change:codedeploy: Update codedeploy command to latest version

(adam)

2017-08-15 09:57:12 UTC MAIN commitmail json YAML

1.4.6
enhancement:Logging: Switch log levels from INFO to DEBUG

(adam)

2017-08-15 09:55:46 UTC MAIN commitmail json YAML

1.6.1
api-change:cloudhsmv2: Update cloudhsmv2 client to latest version
api-change:ssm: Update ssm client to latest version
api-change:glue: Update glue client to latest version
api-change:mgh: Update mgh client to latest version
api-change:efs: Update efs client to latest version
api-change:storagegateway: Update storagegateway client to latest version
api-change:batch: Update batch client to latest version

1.6.0
api-change:ec2: Update ec2 client to latest version
feature:retries: Add ability to configure the maximum amount of retry attempts a client call can make.
api-change:cognito-idp: Update cognito-idp client to latest version
api-change:codedeploy: Update codedeploy client to latest version

(adam)

2017-08-15 08:38:29 UTC MAIN commitmail json YAML

Updated misc/rhash to 1.3.5

(adam)

2017-08-15 08:37:47 UTC MAIN commitmail json YAML

Version 1.3.5:
* look for locales directory at PROGRAM_DIRECTORY\locale on Windows
* look for config at PROGRAM_DIRECTORY\rhashrc on Windows
* support LibRhash bindings to PHP7
* Bugfix: illegal instruction error on macOS
* improve utf-8 support on Windows
* Bugfix: fix access to long paths on Windows
* add ca, fr, ro translations
* full Spanish translation
* correct build/install command for freebsd
* compilation fixes for aarch64 and musl
* improve support of clang on macOS

(adam)

2017-08-15 08:35:34 UTC MAIN commitmail json YAML

2017-08-15 08:34:43 UTC MAIN commitmail json YAML

Added databases/pg_repack version 1.4.1

(fhajny)

2017-08-15 08:34:20 UTC MAIN commitmail json YAML

Add pg_repack-1.4.1 as databases/pg_repack.

pg_repack is a PostgreSQL extension which lets you remove bloat from
tables and indexes, and optionally restore the physical order of
clustered indexes.

(fhajny)

2017-08-15 07:47:37 UTC MAIN commitmail json YAML

With poppler-0.57 this now needs c++11 to build (nullptr).

(wiz)

2017-08-15 07:45:51 UTC MAIN commitmail json YAML

With poppler-0.57 this now needs c++11 to build (nullptr).

(wiz)

2017-08-15 07:42:11 UTC MAIN commitmail json YAML

Add missing PLIST commit for update.

(wiz)

2017-08-15 05:46:38 UTC MAIN commitmail json YAML

Updated www/curl to 7.55.1, graphics/libimagequant to 2.10.2

(adam)

2017-08-15 05:39:14 UTC MAIN commitmail json YAML

2017-08-15 05:35:58 UTC MAIN commitmail json YAML

Curl and libcurl 7.55.1

This release includes the following bugfixes:
o build: fix 'make install' with configure, install docs/libcurl/* too
o make install: add 8 missing man pages to the installation
o curl: do bounds check using a double comparison [1]
o dist: Add dictserver.py/negtelnetserver.py to release [2]
o digest_sspi: Don't reuse context if the user/passwd has changed [3]
o gitignore: ignore top-level .vs folder [4]
o build: check out *.sln files with Windows line endings [5]
o travis: verify "make install" [6]
o dist: fix the cmake build by shipping cmake_uninstall.cmake.in too [7]
o metalink: fix error: ‘*’ in boolean context, suggest ‘&&’ instead
o configure: use the threaded resolver backend by default if possible [8]
o mkhelp.pl: allow executing this script directly [9]
o maketgz: remove old *.dist files before making the tarball [10]
o openssl: remove CONST_ASN1_BIT_STRING [11]
o openssl: fix "error: this statement may fall through"
o proxy: fix memory leak in case of invalid proxy server name [12]
o curl/system.h: support more architectures (OpenRISC, ARC) [13]
o docs: fix typos [14]
o curl/system.h: add Oracle Solaris Studio [15]
o CURLINFO_TOTAL_TIME: could wrongly return 4200 seconds [16]
o docs: --connect-to clarified
o cmake: allow user to override CMAKE_DEBUG_POSTFIX [17]
o travis: test cmake build on tarball too
o redirect: make it handle absolute redirects to IDN names [18]
o curl/system.h: fix for gcc on PowerPC [19]
o curl --interface: fixed for IPV6 unique local addresses [20]
o cmake: threads detection improvements [21]

(adam)

2017-08-15 01:56:48 UTC MAIN commitmail json YAML

Updated www/apache-tomcat8 to 8.0.45

(ryoon)

2017-08-15 01:56:21 UTC MAIN commitmail json YAML

Update to 8.0.45

Changelog:
Tomcat 8.0.45 (violetagg)
Catalina

    Fix: 61101: CORS filter should set Vary header in response. Submitted by Rick Riemer. (remm)
    Add: 61105: Add a new JULI FileHandler configuration for specifying the maximum number of days to keep the log files. (violetagg)
    Fix: 61125: Ensure that WarURLConnection returns the correct value for calls to getLastModified() as this is required for the correct detection of JSP modifications when the JSP is packaged in a WAR file. (markt)
    Fix: Improve the SSLValve so it is able to handle client certificate headers from Nginx. Based on a patch by Lucas Ventura Carro. (markt)
    Fix: 61154: Allow the Manager and Host Manager web applications to start by default when running under a security manager. This was accomplished by adding a custom permission, org.apache.catalina.security.DeployXmlPermission, that permits an application to use a META-INF/context.xml file and then granting that permission to the Manager and Host Manager. (markt)
    Fix: 61173: Polish the javadoc for o.a.catalina.startup.Tomcat. Patch provided by peterhansson_se. (violetagg)
    Add: A new configuration property crawlerIps is added to the o.a.catalina.valves.CrawlerSessionManagerValve. Using this property one can specify a regular expression that will be used to identify crawlers based on their IP address. Based on a patch provided by Tetradeus. (violetagg)
    Fix: 61180: Log a warning message rather than an information message if it takes more than 100ms to initialised a SecureRandom instance for a web application to use to generate session identifiers. Patch provided by Piotr Chlebda. (markt)
    Fix: 61185: When an asynchronous request is dispatched via AsyncContext.dispatch() ensure that getRequestURI() for the dispatched request matches that of the original request. (markt)
    Fix: 61201: Ensure that the SCRIPT_NAME environment variable for CGI executables is populated in a consistent way regardless of how the CGI servlet is mapped to a request. (markt)
    Fix: 61215: Correctly define addConnectorPort and invalidAuthenticationWhenDeny in the mbean-descriptors.xml file for the org.apache.catalina.valves package so that the attributes are accessible via JMX. (markt)

Coyote

    Fix: 61086: Explicitly signal an empty request body for HTTP 205 responses. (markt)
    Fix: Revert a change introduced in the fix for bug 60718 that changed the status code recorded in the access log when the client dropped the connection from 200 to 500. (markt)
    Fix: Make asynchronous error handling more robust. In particular ensure that onError() is called for any registered AsyncListeners after an I/O error on a non-container thread. (markt)

Jasper

    Fix: 44787: Improve error message when JSP compiler configuration options are not valid. (markt)
    Fix: 61137: j.s.jsp.tagext.TagLibraryInfo#uri and j.s.jsp.tagext.TagLibraryInfo#prefix fields should not be final. Patch provided by Katya Todorova. (violetagg)

WebSocket

    Fix: Correct the log message when a MessageHandler for PongMessage does not implement MessageHandler.Whole. (rjung)
    Fix: Improve thread-safety of Futures used to report the result of sending WebSocket messages. (markt)
    Fix: 61183: Correct a regression in the previous fix for 58624 that could trigger a deadlock depending on the locking strategy employed by the client code. (markt)

Web applications

    Fix: Better document the meaning of the trimSpaces option for Jasper. (markt)
    Fix: 61150: Configure the Manager and Host-Manager web applications to permit serialization and deserialization of CRSFPreventionFilter related session objects to avoid warning messages and/or stack traces on web application stop and/or start when running under a security manager. (markt)

Other

    Add: 45832: Add HTTP DIGEST authentication support to the Catalina Ant tasks used to communicate with the Manager application. (markt)
    Fix: 45879: Add the RELEASE-NOTES file to the root of the installation created by the Tomcat installer for Windows to make it easier for users to identify the installed Tomcat version. (markt)
    Fix: 61055: Clarify the code comments in the rewrite valve to make clear that there are no plans to provide proxy support for this valve since Tomcat does not have proxy capbilities. (markt)
    Fix: 61076: Document the altDDName attribute for the Context element. (markt)
    Fix: Correct typo in Jar Scan Filter Configuration Reference. Issue reported via comments.apache.org. (violetagg)
    Fix: 61145: Add missing @Documented annotation to annotations in the annotations API. Patch provided by Katya Todorova. (markt)
    Fix: 61146: Add missing lookup() method to @EJB annotation in the annotations API. Patch provided by Katya Todorova. (markt)
    Fix: Correct typo in Context Container Configuration Reference. Patch provided by Katya Todorova. (violetagg)

(ryoon)

2017-08-15 01:54:50 UTC MAIN commitmail json YAML

Updated www/apache-tomcat7 to 7.0.79

(ryoon)

2017-08-15 01:54:25 UTC MAIN commitmail json YAML

Update to 7.0.79

Changelog:
Tomcat 7.0.79 (violetagg)

    Catalina

        fix 61101: CORS filter should set Vary header in response. Submitted by Rick Riemer. (remm)
        add 61105: Add a new JULI FileHandler configuration for specifying the maximum number of days to keep the log files. (violetagg)
        fix Improve the SSLValve so it is able to handle client certificate headers from Nginx. Based on a patch by Lucas Ventura Carro. (markt)
        fix 61154: Allow the Manager and Host Manager web applications to start by default when running under a security manager. This was accomplished by adding a custom permission, org.apache.catalina.security.DeployXmlPermission, that permits an application to use a META-INF/context.xml file and then granting that permission to the Manager and Host Manager. (markt)
        fix 61173: Polish the javadoc for o.a.catalina.startup.Tomcat. Patch provided by peterhansson_se. (violetagg)
        add A new configuration property crawlerIps is added to the o.a.catalina.valves.CrawlerSessionManagerValve. Using this property one can specify a regular expression that will be used to identify crawlers based on their IP address. Based on a patch provided by Tetradeus. (violetagg)
        fix 61180: Log a warning message rather than an information message if it takes more than 100ms to initialised a SecureRandom instance for a web application to use to generate session identifiers. Patch provided by Piotr Chlebda. (markt)
        fix 61185: When an asynchronous request is dispatched via AsyncContext.dispatch() ensure that getRequestURI() for the dispatched request matches that of the original request. (markt)
        fix 61201: Ensure that the SCRIPT_NAME environment variable for CGI executables is populated in a consistent way regardless of how the CGI servlet is mapped to a request. (markt)
        fix 61215: Correctly define addConnectorPort and invalidAuthenticationWhenDeny in the mbean-descriptors.xml file for the org.apache.catalina.valves package so that the attributes are accessible via JMX. (markt)

    Coyote

        fix 61086: Explicitly signal an empty request body for HTTP 205 responses. (markt)
        fix Revert a change introduced in the fix for bug 60718 that changed the status code recorded in the access log when the client dropped the connection from 200 to 500. (markt)
        fix Make asynchronous error handling more robust. In particular ensure that onError() is called for any registered AsyncListeners after an I/O error on a non-container thread. (markt)

    Jasper

        fix 44787: Improve error message when JSP compiler configuration options are not valid. (markt)

    WebSocket

        fix Correct the log message when a MessageHandler for PongMessage does not implement MessageHandler.Whole. (rjung)
        fix Improve thread-safety of Futures used to report the result of sending WebSocket messages. (markt)
        fix 61183: Correct a regression in the previous fix for 58624 that could trigger a deadlock depending on the locking strategy employed by the client code. (markt)

    Web applications

        fix Better document the meaning of the trimSpaces option for Jasper. (markt)
        fix 61150: Configure the Manager and Host-Manager web applications to permit serialization and deserialization of CRSFPreventionFilter related session objects to avoid warning messages and/or stack traces on web application stop and/or start when running under a security manager. (markt)

    Tribes

        add Add JMX support for Tribes components. (kfujino)

    Other

        add 45832: Add HTTP DIGEST authentication support to the Catalina Ant tasks used to communicate with the Manager application. (markt)
        fix 45879: Add the RELEASE-NOTES file to the root of the installation created by the Tomcat installer for Windows to make it easier for users to identify the installed Tomcat version. (markt)
        fix 61076: Document the altDDName attribute for the Context element. (markt)
        fix 61145: Add missing @Documented annotation to annotations in the annotations API. Patch provided by Katya Todorova. (markt)
        fix 61146: Add missing lookup() method to @EJB annotation in the annotations API. Patch provided by Katya Todorova. (markt)
        fix Correct typo in Context Container Configuration Reference. Patch provided by Katya Todorova. (violetagg)

(ryoon)

2017-08-15 01:52:13 UTC MAIN commitmail json YAML

Updated www/apache-tomcat85 to 8.5.20

(ryoon)

2017-08-15 01:50:46 UTC MAIN commitmail json YAML

Update to 8.5.20

Changelog:
Tomcat 8.5.20 (markt)
Catalina

    Fix: Revert the fix for 49464 since it continued to trigger regressions. (markt)
    Fix: Correct a bug in the PushBuilder implementation that meant push URLs containing %nn sequences were not correctly decoded. Identified by FindBugs. (markt)
    Add: 61164: Add support for the %X pattern in the AccessLogValve that reports the connection status at the end of the request. Patch provided by Zemian Deng. (markt)
    Fix: 61351: Correctly handle %nn decoding of URL patterns in web.xml and similar locations that may legitimately contain characters that are not permitted by RFC 3986. (markt)
    Add: 61366: Add a new attribute, localDataSource, to the JDBCStore that allows the Store to be configured to use a DataSource defined by the web application rather than the default of using a globally defined DataSource. Patch provided by Jonathan Horowitz. (markt)

Coyote

    Fix: 61086: Ensure to explicitly signal an empty request body for HTTP 205 responses. Additional fix to r1795278. Based on a patch provided by Alexandr Saperov. (violetagg)
    Update: 61345: Add a server listener that can be used to do system property replacement from the property source configured in the digester. (remm)
    Add: Add additional logging to record problems that occur while waiting for the NIO pollers to stop during the Connector stop process. (markt)

Jasper

    Fix: 61364: Ensure that files are closed after detecting encoding of JSPs so that files do not remain locked by the file system. (markt)

WebSocket

    Add: 57767: Add support to the WebSocket client for following redirects when attempting to establish a WebSocket connection. Patch provided by J Fernandez. (markt)

2017-07-28 Tomcat 8.5.19 (markt)
Catalina

    Fix: Performance improvements for service loader look-ups (and look-ups of other class loader resources) when the web application is deployed in a packed WAR file. (markt)
    Fix: 61253: Add warn message when Digester.updateAttributes throws an exception instead of ignoring it. (csutherl)
    Fix: Correct a further regression in the fix for 49464 that could cause an byte order mark character to appear at the start of content included by the DefaultServlet. (markt)
    Fix: 61313: Make the read timeout configurable in the JNDIRealm and ensure that a read timeout will result in an attempt to fail over to the alternateURL. Based on patches by Peter Maloney and Felix Schumacher. (markt)

Web applications

    Fix: Correct the documentation for how StandardRoot is configured. (markt)

Other

    Fix: 61316: Fix corruption of UTF-16 encoded source files in released source distributions. (markt)

Tomcat 8.5.18 (markt)
Catalina

    Fix: 61232: When log rotation is disabled only one separator will be used when generating the log file name. For example if the prefix is catalina. and the suffix is .log then the log file name will be catalina.log instead of catalina..log. Patch provided by Katya Stoycheva. (violetagg)
    Fix: 61264: Correct a regression in the refactoring to use Charset rather than String to store request character encoding that prevented getReader() throwing an UnsupportedEncodingException if the user agent specifies an unsupported character encoding. (markt)
    Fix: Correct a regression in the fix for 49464 that could cause an incorrect Content-Length header to be sent by the DefaultServlet if the encoding of a static is not consistent with the encoding of the response. (markt)

Coyote

    Fix: Enable TLS connectors to use Java key stores that contain multiple keys where each key has a separate password. Based on a patch by Frank Taffelt. (markt)
    Fix: Improve the handling of HTTP/2 stream resets due to excessive headers when a continuation frame is used. (markt)

Jasper

    Add: 53031: Add support for the fork option when compiling JSPs with the Jasper Ant task and javac. (markt)

Other

    Add: 52791: Add the ability to set the defaults used by the Windows installer from a configuration file. Patch provided by Sandra Madden. (markt)

Tomcat 8.5.17 (markt)
Catalina

    Fix: 49464: Improve the Default Servlet's handling of static files when the file encoding is not compatible with the required response encoding. (markt)
    Fix: 61214: Remove deleted attribute servlets from the Context MBean description. Patch provided by Alexis Hassler. (markt)
    Fix: 61215: Correctly define addConnectorPort and invalidAuthenticationWhenDeny in the mbean-descriptors.xml file for the org.apache.catalina.valves package so that the attributes are accessible via JMX. (markt)
    Fix: Make asynchronous error handling more robust. In particular ensure that onError() is called for any registered AsyncListeners after an I/O error on a non-container thread. (markt)
    Fix: Additional permission for deleting files is granted to JULI as it is required by FileHandler when running under a Security Manager. The thread that cleans the log files is marked as daemon thread. (violetagg)
    Fix: 61229: Correct a regression in 8.5.15 that broke WebDAV handling for resources with names that included a & character. (markt)

Coyote

    Fix: Restore the ability to configure support for SSLv3. Enabling this protocol will trigger a warning in the logs since it is known to be insecure. (markt)
    Fix: Do not log a warning when a null session is returned for an OpenSSL based TLS session since this is expected when session tickets are enabled. (markt)
    Fix: When the access log valve logs a TLS related request attribute and the NIO2 connector is used with OpenSSL, ensure that the TLS attric SSL session access for the APR connector. (remm)
    Add: To ease migration from 8.0.x to 8.5.x, if the HTTP or AJP BIO connector is explicitly configured, rather than failing to start the connector because BIO has been removed, automatically switch to tribute searchExternalFirst from the documentation since the attribute is no longer supported. (markt)

2017-06-26 Tomcat 8.5.16 (markt)
Catalina

    Fix: 61072: Respect the documentation statements that allow using the platform default secure random for session id generation. (remm)
    Fix: Correct the javadoc for o.a.c.connector.CoyoteAdapter#parseSessionCookiesId. Patch provided by John Andrew (XUZHOUWANG) via Github. (violetagg)
    Fix: 61101: CORS filter should set Vary header in response. Submitted by Rick Riemer. (remm)
    Add: 61105: Add a new JULI FileHandler configuration for specifying the maximum number of days to keep the log files. (violetagg)
    Fix: 61125: Ensure that WarURLConnection returns the correct value for calls to getLastModified() as this is required for the correct detection of JSP modifications when the JSP is packaged in a WAR file. (markt)
    Fix: Improve the SSLValve so it is able to handle client certificate headers from Nginx. Based on a patch by Lucas Ventura Carro. (markt)
    Fix: 61134: Do not use '[' and ']' symbols around substituted text fragments when generating the default error pages. Patch provided by Katya Todorova. (violetagg)
    Fix: 61154: Allow the Manager and Host Manager web applications to start by default when running under a security manager. This was accomplished by adding a custom permission, org.apache.catalina.security.DeployXmlPermission, that permits an application to use a META-INF/context.xml file and then granting that permission to the Manager and Host Manager. (markt)
    Fix: 61173: Polish the javadoc for o.a.catalina.startup.Tomcat. Patch provided by peterhansson_se. (violetagg)
    Add: A new configuration property crawlerIps is added to the o.a.catalina.valves.CrawlerSessionManagerValve. Using this property one can specify a regular expression that will be used to identify crawlers based on their IP address. Based on a patch provided by Tetradeus. (violetagg)
    Fix: 61180: Log a warning message rather than an information message if it takes more than 100ms to initialised a SecureRandom instance for a web application to use to generate session identifiers. Patch provided by Piotr Chlebda. (markt)
    Fix: 61185: When an asynchronous request is dispatched via AsyncContext.dispatch() ensure that getRequestURI() for the dispatched request matches that of the original request. (markt)
    Fix: 61197: Ensure that the charset name used in the Content-Type header has exactly the same form as that provided by the application. This reverts a behavioural change in 8.5.15 that caused problems for some clients. (markt)
    Fix: 61201: Ensure that the SCRIPT_NAME environment variable for CGI executables is populated in a consistent way regardless of how the CGI servlet is mapped to a request. (markt)

Coyote

    Fix: 61086: Explicitly signal an empty request body for HTTP 205 responses. (markt)
    Fix: 61120: Do not ignore path parameters when processing HTTP/2 requests. (markt)
    Fix: Revert a change introduced in the fix for bug 60718 that changed the status code recorded in the access log when the client dropped the connection from 200 to 500. (markt)
    Fix: Add additional syncs to the SSL session object provided by the OpenSSL engine so that a concurrent destruction cannot cause a JVM crash. (remm)
    Fix: 61195: Backport, with deprecation where appropriate, the endpoint and protocol property changes from 9.0.x to ease migration from 8.5.x to 9.0.x. (markt)

Jasper

    Fix: 44787: Improve error message when JSP compiler configuration options are not valid. (markt)
    Fix: 61137: j.s.jsp.tagext.TagLibraryInfo#uri and j.s.jsp.tagext.TagLibraryInfo#prefix fields should not be final. Patch provided by Katya Todorova. (violetagg)

WebSocket

    Fix: Correct the log message when a MessageHandler for PongMessage does not implement MessageHandler.Whole. (rjung)
    Add: Introduce new API o.a.tomcat.websocket.WsSession#suspend/ o.a.tomcat.websocket.WsSession#resume that can be used to suspend/resume reading of the incoming messages. (violetagg)
    Fix: Improve thread-safety of Futures used to report the result of sending WebSocket messages. (markt)
    Fix: 61183: Correct a regression in the previous fix for 58624 that could trigger a deadlock depending on the locking strategy employed by the client code. (markt)

Web applications

    Fix: Better document the meaning of the trimSpaces option for Jasper. (markt)
    Fix: 61150: Configure the Manager and Host-Manager web applications to permit serialization and deserialization of CRSFPreventionFilter related session objects to avoid warning messages and/or stack traces on web application stop and/or start when running under a security manager. (markt)
    Fix: Correct the TLS configuration documentation to remove SSLv2 and SSLv3 from the list of supported protocols. (markt)

Tribes

    Add: Add JMX support for Tribes components. (kfujino)

Other

    Add: 45832: Add HTTP DIGEST authentication support to the Catalina Ant tasks used to communicate with the Manager application. (markt)
    Fix: 45879: Add the RELEASE-NOTES file to the root of the installation created by the Tomcat installer for Windows to make it easier for users to identify the installed Tomcat version. (markt)
    Fix: 61055: Clarify the code comments in the rewrite valve to make clear that there are no plans to provide proxy support for this valve since Tomcat does not have proxy capabilities. (markt)
    Fix: 61076: Document the altDDName attribute for the Context element. (markt)
    Fix: Correct typo in Jar Scan Filter Configuration Reference. Issue reported via comments.apache.org. (violetagg)
    Fix: 61145: Add missing @Documented annotation to annotations in the annotations API. Patch provided by Katya Todorova. (markt)
    Fix: 61146: Add missing lookup() method to @EJB annotation in the annotations API. Patch provided by Katya Todorova. (markt)
    Fix: Correct typo in Context Container Configuration Reference. Patch provided by Katya Todorova. (violetagg)

(ryoon)

2017-08-15 01:24:47 UTC MAIN commitmail json YAML

2017-08-15 00:36:27 UTC MAIN commitmail json YAML

Updated devel/p5-App-perlbrew to 0.80

(mef)

2017-08-15 00:36:15 UTC MAIN commitmail json YAML

Updated devel/p5-App-perlbrew to 0.80
-------------------------------------
0.80: # 2017-06-30T07:40:45+0200
- Fix version in META.yml in CPAN distribution. See: https://rt.cpan.org/Public/Bug/Display.html?id=122279

0.79: # 2017-06-25T23:40:45+0200
- deal with perl-5.26 change about @INC in Makefile.PL
- "available" command now also shows the URLs

(mef)

2017-08-14 23:42:28 UTC MAIN commitmail json YAML

Updated devel/cpputest to 3.8nb1

(schmonz)

2017-08-14 23:42:08 UTC MAIN commitmail json YAML

Install MakefileWorker.mk. Bump PKGREVISION.

(schmonz)

2017-08-14 21:23:06 UTC MAIN commitmail json YAML

Updated textproc/miller to 5.2.2

(wiz)

2017-08-14 21:22:55 UTC MAIN commitmail json YAML

Updated miller to 5.2.2.

5.2.2

This bugfix release delivers a fix for #147 where a memory allocation failed beyond 4GB.

5.2.1

Fix non-x86/gcc7 build error

(wiz)

2017-08-14 21:22:18 UTC MAIN commitmail json YAML

Updated print/poppler to 0.57.0

(nros)

2017-08-14 21:19:33 UTC MAIN commitmail json YAML

Updated net/libfilezilla to 0.10.1

(wiz)

2017-08-14 21:19:23 UTC MAIN commitmail json YAML

Updated libfilezilla to 0.10.1.

2017-08-14 - libfilezilla 0.10.1 released
Bugfixes and minor changes:

    MSW: Improve handling of reparse points in fz::local_filesys

2017-07-10 - libfilezilla 0.10.0 released
New features:

    Added fz::percent_encode and fz::percent_encode
    Added fz::uri and fz::query_string
    Added fz::less_insensitive_ascii for case-insensitive strings in maps

Bugfixes and minor changes:

    Moved encoding functions from string.hpp to encode.hpp
    Use pkg-config instead of cppunit-config to look for cppunit.

(wiz)

2017-08-14 21:17:25 UTC MAIN commitmail json YAML

Updated x11/mcookie to 2.30.1

(wiz)

2017-08-14 21:17:14 UTC MAIN commitmail json YAML

Updated mcookie to 2.30.1.

Documentation improvements.

(wiz)

2017-08-14 21:15:52 UTC MAIN commitmail json YAML

Updated devel/lua-doc to 1.4.6

(triaxx)

2017-08-14 21:14:59 UTC MAIN commitmail json YAML

Updated audio/libmpdclient to 2.13

(wiz)

2017-08-14 21:14:49 UTC MAIN commitmail json YAML

Updated libmpdclient to 2.13.

Switch to meson build framework since autoconf one was removed.

libmpdclient 2.13 (2017/07/25)
* fix build with meson > 0.38.1
* fix connect error "Operation now in progress"

libmpdclient 2.12 (2017/07/21)
* support MPD protocol 0.21
  - support tag "OriginalDate"
  - command "tagtypes" plus "disable", "enable", "clear"
* support MPD protocol 0.20
  - support "plchanges" and "plchangesposid" with range
* support MPD protocol 0.19
  - commands "addtagid", "cleartagid"
  - command "listfiles"
  - grouping for "list" and "count"
  - tag "AlbumSort"
  - "seekid" with float time
* use relative #include paths to avoid clashes with other libmpdclient copies
* build with Meson instead of autotools

(wiz)

2017-08-14 21:14:36 UTC MAIN commitmail json YAML

2017-08-14 21:14:10 UTC MAIN commitmail json YAML

Add fragment for using meson to build and install.

(wiz)

2017-08-14 21:11:09 UTC MAIN commitmail json YAML

Add devel/lua-doc package version 1.4.6

Reviewed by maya@

Needed by wm/awesome for API doc generation.

(triaxx)

2017-08-14 21:08:29 UTC MAIN commitmail json YAML

Added devel/py-meson version 0.41.2

(wiz)

2017-08-14 21:08:16 UTC MAIN commitmail json YAML

2017-08-14 21:07:44 UTC MAIN commitmail json YAML

Import py-meson-0.41.2 as devel/py-meson, packaged for wip by myself.

Meson is a cross-platform build system designed to be both as fast
and as user friendly as possible. It supports many languages and
compilers, including GCC, Clang and Visual Studio. Its build
definitions are written in a simple non-turing complete DSL.

(wiz)

2017-08-14 20:51:52 UTC MAIN commitmail json YAML

Updated print/abcm2ps to 8.13.12

(wiz)

2017-08-14 20:51:42 UTC MAIN commitmail json YAML

Updated abcm2ps to 8.13.12.

---- Version 8.13.12 - 2017-07-03 ----

Fix bad height of SVG images when lyrics under the staff
(reported by Manavasu)
Don't display ottava decorations on secondary voices
(reported by Willem Vree)
Fix loss of measure bar when followed by %%score and voice absent
(reported by Simon Wascher)

(wiz)

2017-08-14 20:49:52 UTC MAIN commitmail json YAML

2017-08-14 20:49:42 UTC MAIN commitmail json YAML

Updated afl to 2.49b.

---------------------------
Version 2.49b (2017-07-18):
---------------------------

  - Added AFL_TMIN_EXACT to allow path constraint for crash minimization.

  - Added dates for releases (retroactively for all of 2017).

---------------------------
Version 2.48b (2017-07-17):
---------------------------

  - Added AFL_ALLOW_TMP to permit some scripts to run in /tmp.

  - Fixed cwd handling in afl-analyze (similar to the quirk in afl-tmin).

  - Made it possible to point -o and -f to the same file in afl-tmin.

---------------------------
Version 2.47b (2017-07-14):
---------------------------

  - Fixed cwd handling in afl-tmin. Spotted by Jakub Wilk.

---------------------------
Version 2.46b (2017-07-10):
---------------------------

  - libdislocator now supports AFL_LD_NO_CALLOC_OVER for folks who do not
    want to abort on calloc() overflows.

  - Made a minor fix to libtokencap. Reported by Daniel Stender.

  - Added a small JSON dictionary, inspired on a dictionary done by Jakub Wilk.

---------------------------
Version 2.45b (2017-07-04):
---------------------------

  - Added strstr, strcasestr support to libtokencap. Contributed by
    Daniel Hodson.

  - Fixed a resumption offset glitch spotted by Jakub Wilk.

  - There are definitely no bugs in afl-showmap -c now.

(wiz)

2017-08-14 20:48:13 UTC MAIN commitmail json YAML

Updated security/caff to 2.6

(wiz)

2017-08-14 20:48:02 UTC MAIN commitmail json YAML

2017-08-14 20:44:18 UTC MAIN commitmail json YAML

Updated games/ruby-squib to 0.13.4

(wiz)

2017-08-14 20:44:08 UTC MAIN commitmail json YAML

Updated ruby23-squib to 0.13.4.

Changes not found.

(wiz)

2017-08-14 20:42:33 UTC MAIN commitmail json YAML

Updated meld to 3.17.3.

2017-08-13 meld 3.17.3
======================

  Fixes:

  * Fix folder compare when using text filters (Alsan Wong)
  * Make activity spinner show when inline comparisons are running (Kai
    Willadsen)
  * Migrate back from threads to multiprocessing for inline diffs; unusual
    CPU contention caused this to harm interactivity (Kai Willadsen)
  * Manually refreshing a file comparison sometimes caused diff navigation
    to break (Kai Willadsen)
  * Folder comparisons that update their state no longer break navigation
    (Kai Willadsen)
  * Version-control comparison on missing files now work again (Kai
    Willadsen)
  * Fix regression in initial focus for folder comparisons (Kai Willadsen)
  * Fix handling for added, partially staged files in git (Kai Willadsen)

  * Bugs fixed: 784436, 785603, 785859, 786043

  Translations:

  * Daniel Mustieles (es)
  * Matej Urbančič (sl)

(wiz)

2017-08-14 20:41:31 UTC MAIN commitmail json YAML

Updated devel/meld to 3.17.3

(wiz)

2017-08-14 20:38:21 UTC MAIN commitmail json YAML

Updated sysutils/dbus to 1.10.22

(wiz)

2017-08-14 20:38:12 UTC MAIN commitmail json YAML

2017-08-14 20:38:10 UTC MAIN commitmail json YAML

Updated dbus to 1.10.22.

D-Bus 1.10.22 (2017-07-27)
==

The “roof terrace” release.

Fixes:

• dbus_message_iter_append_basic() no longer leaks memory if it fails to
  append a file descriptor to a message. (fd.o #101568, Simon McVittie)

• dbus_message_iter_open_container() no longer leaks memory if it runs out
  of memory. (fd.o #101568, Simon McVittie)

• dbus_message_append_args_valist() no longer leaks memory if given an
  unsupported type. This situation is still considered to be a programming
  error which needs to be corrected by the user of libdbus.
  (fd.o #101568, Simon McVittie)

• Wrap test-pending-call-disconnected with dbus-run-session so that it can
  pass in environments that are not already running a D-Bus session bus,
  fixing a build-time test regression in 1.10.20
  (fd.o #101698, Simon McVittie)

• Ensure that tests fail if they would otherwise have tried to connect to
  the real session bus (fd.o #101698, Simon McVittie)

• Make build-time tests cope with finding Python 3, but not Python 2
  (fd.o #101716, Simon McVittie)

(wiz)

2017-08-14 20:38:02 UTC MAIN commitmail json YAML

2017-08-14 20:36:02 UTC MAIN commitmail json YAML

Updated x11/libxkbcommon to 0.7.2

(wiz)

2017-08-14 20:35:52 UTC MAIN commitmail json YAML

Updated libxkbcommon to 0.7.2.

(package still uses autoconf)

libxkbcommon 0.7.2 - 2017-08-04
==================

- Added a Meson build system as an alternative to existing autotools build
  system.

  The intent is to remove the autotools build in one of the next releases.
  Please try to convert to it and report any problems.

  See http://mesonbuild.com/Quick-guide.html for basic usage, the
  meson_options.txt for the project-specific configuration options,
  and the PACKAGING file for more details.

  There are some noteworthy differences compared to the autotools build:

  - Feature auto-detection is not performed. By default, all features are
    enabled (currently: docs, x11, wayland). The build fails if any of
    the required dependencies are not available. To disable a feature,
    pass -Denable-<feature>=false to meson.

  - The libraries are either installed as shared or static, as specified
    by the -Ddefault_library=shared/static option. With autotools, both
    versions are installed by default.

  - xorg-util-macros is not used.

  - A parser generator (bison/byacc) is always required - there is no
    fallback to pre-generated output bundled in the tarball, as there is
    in autotools.

- Removed Android.mk support.

- Removed the *-uninstalled.pc pkgconfig files.

- Ported the interactive-wayland demo program to v6 of the xdg-shell
  protocol.

- Added new keysym definitions from xproto.

- New API:
  XKB_KEY_XF86Keyboard
  XKB_KEY_XF86WWAN
  XKB_KEY_XF86RFKill
  XKB_KEY_XF86AudioPreset

(wiz)

2017-08-14 20:32:16 UTC MAIN commitmail json YAML

Updated fonts/harfbuzz to 1.4.8

(wiz)

2017-08-14 20:32:06 UTC MAIN commitmail json YAML

Updated harfbuzz to 1.4.8.

Overview of changes leading to 1.4.8
Tuesday, August 8, 2017
====================================

- Major fix to avar table handling.
- Rename hb-shape --show-message to --trace.
- Build fixes.

Overview of changes leading to 1.4.7
Tuesday, July 18, 2017
====================================

- Multiple Indic, Tibetan, and Cham fixes.
- CoreText: Allow disabling kerning.
- Adjust Arabic feature order again.
- Misc build fixes.

(wiz)

2017-08-14 20:30:34 UTC MAIN commitmail json YAML

Updated fonts/fontconfig to 2.12.4

(wiz)

2017-08-14 20:30:24 UTC MAIN commitmail json YAML

Updated fontconfig to 2.12.4.

2.12.4

Akira TAGOH (5):
      Force regenerate fcobjshash.h when updating Makefile
      Fix the build failure when srcdir != builddir and have gperf 3.1 or later installed
      Add a testcase for Bug#131804
      Update libtool revision
      Fix distcheck error

Florent Rougon (6):
      FcCharSetHash(): use the 'numbers' values to compute the hash
      fc-lang: gracefully handle the case where the last language initial is < 'z'
      Fix an off-by-one error in FcLangSetIndex()
      Fix erroneous test on language id in FcLangSetPromote()
      FcLangSetCompare(): fix bug when two charsets come from different "buckets"
      FcCharSetFreezeOrig(), FcCharSetFindFrozen(): use all buckets of freezer->orig_hash_table

Helmut Grohne (1):
      fix cross compilation

Jan Alexander Steffens (heftig) (1):
      Fix testing PCF_CONFIG_OPTION_LONG_FAMILY_NAMES (CFLAGS need to be right)

Josselin Mouette (1):
      Treat C.UTF-8 and C.utf8 locales as built in the C library.

Masamichi Hosoda (1):
      Bug 99360 - Fix cache file update on MinGW

(wiz)

2017-08-14 20:26:46 UTC MAIN commitmail json YAML

Updated audio/libopenmpt to 0.2.8760

(wiz)

2017-08-14 20:26:36 UTC MAIN commitmail json YAML

Updated libopenmpt to 0.2.8760.

libopenmpt 0.2-beta27 (2017-08-12)

    [Bug] libmodplug: The CSoundFile::Read function in the emulated libmodplug C++ API returned the wrong value, causing qmmp (and possibly other software) to crash.
    The ProTracker note delay quirk should not retrigger already stopped samples (fixes "Subi loses the Cops" by Subi).
    ProTracker portamento between already stopped sample and another sample kept playing the old sample (fixes "anarchy-main" by Jester).
    Playback fix for instruments with custom tunings and transposed note maps in MPTM format.
    ProTracker quirk: If there is a note with a out-of-range note delay, it is played on the next row (with an instant portamento), unless there is a new note on that row.
    ProTracker quirk: Apply tempo changes after the first tick of the row.

libopenmpt 0.2-beta26 (2017-07-07)

    [Bug] Possible crashes with malformed PLM and PSM files.
    [Bug] mktime() and localtime() were used for song date parsing. These functions are not guaranteed to be thread-safe by the standard. Furthermore, some standard library implementations are buggy and may cause the program to abort in out-of-memory situations. These functions are now no longer used.
    Loops shorter than four sample points at the end of a sample could cause the sample data before the loop to become corrupted.

libopenmpt 0.2-beta25 (2017-07-02)

    PT36: Enable VBlank timing as specified in file and read song comment.
    M15: Loosen heuristics to allow a few more semi-damaged files to play.
    MT2: If there were instruments with both sample and plugin assignments, sample data was not read correctly.

(wiz)

2017-08-14 20:22:45 UTC MAIN commitmail json YAML

Update poppler and it's libraries to version 0.57.0.

Fixes CVE-2017-9865.

Changes from NEWS file:

core:
* Fix parsing of Type 1 fonts with newlines in encoding sequences. Bug #101728
* Fix crash in broken documents

utils:
* pdfunite: Fix crash with broken documents. Bug #101208
* pdftohtml: skip control characters Bug #101770
* pdfseparate: minor improvement to the documentation. Bug #101800

build system:
* cmake: Set RUNPATH for poppler shared libs. Bug #101945
* configure: fix --disable-FEATURE actually enabling the feature

(nros)

2017-08-14 20:18:22 UTC MAIN commitmail json YAML

Bump PKGREVISION for notmuch shlib bump.

(wiz)

2017-08-14 20:17:11 UTC MAIN commitmail json YAML

Updated mail/notmuch to 0.25

(wiz)

2017-08-14 20:17:00 UTC MAIN commitmail json YAML

Updated notmuch to 0.25.

Notmuch 0.25 (2017-07-25)
=========================

General
-------

Add regexp searching for mid, paths, and tags.

Skip HTML tags when indexing

  In particular this avoids indexing large inline images.

Command Line Interface
----------------------

Bash completion is now installed to /usr/share by default.

Allow space as separator for keyword arguments.

Emacs
-----

Support for stashing message timestamp in show and tree views

  Invoking `notmuch-show-stash-date` with a prefix argument
  stashes the unix timestamp of the current message instead of
  the date string.

Don't use 'function' as variable name, workaround emacs bug 26406.

Library Changes
---------------

Add workaround for date parsing of bad input in older GMime

  In certain circumstances, older GMime libraries could return
  negative numbers when parsing syntactically invalid dates.

Replace deprecated functions with status returning versions

  API of notmuch_query_{search,count}_{messages,threads} has
  changed.  notmuch_query_add_tag_exclude now returns a status
  value.

Add support for building against GMime 3.0.

Rename libutil.a to libnotmuch_util.a.

libnotmuch SONAME is incremented to libnotmuch.so.5.

(wiz)

2017-08-14 20:12:10 UTC MAIN commitmail json YAML

Updated security/gnupg to 1.4.22

(wiz)

2017-08-14 20:12:00 UTC MAIN commitmail json YAML

Updated gnupg to 1.4.22.

Noteworthy changes in version 1.4.22 (2017-07-19)
-------------------------------------------------

* Mitigate a flush+reload side-channel attack on RSA secret keys
  dubbed "Sliding right into disaster".  For details see
  <https://eprint.iacr.org/2017/627>.  [CVE-2017-7526]

* Fix some minor bugs.

(wiz)

2017-08-14 20:10:21 UTC MAIN commitmail json YAML

Updated devel/waf to 1.9.13

(wiz)

2017-08-14 20:10:11 UTC MAIN commitmail json YAML

Updated waf to 1.9.13.

NEW IN WAF 1.9.13
-----------------
* Fix a regression introduced by #1974 on Python2 with unicode characters in config.log
* Protobuf example update #2000
* Better detection for old msvc compilers #2002
* Better detection for old gcc compilers #2003

(wiz)

2017-08-14 20:09:22 UTC MAIN commitmail json YAML

Updated net/libsoup to 2.58.2

(wiz)

2017-08-14 20:09:02 UTC MAIN commitmail json YAML

Updated libsoup to 2.58.2.

Changes in libsoup from 2.58.1 to 2.58.2:

* CVE-2017-2885: Fixed a chunked decoding buffer overrun that
          could be exploited against either clients or servers.
          [#785774]

Changes in libsoup from 2.58.0 to 2.58.1:

* Reverts a change to SoupSession to close all open
          connections when the :proxy-resolver property is changed
          [#777326; this change was made in 2.58.0 but accidentally
          left out of the NEWS for that release]; although that
          behavior made :proxy-resolver more consistent with
          :proxy-uri, it ended up breaking Evolution EWS. [#781590]

* Fixed undefined behavior in tests/header-parsing that could
          make the test spuriously fail. [#777258]

* Updates to the configure tests for Apache for use in tests/:
* Dropped support for Apache 2.2
* Changed PHP support from PHP 5 to PHP 7
* mod_unixd can now be either built-in or dynamically
  loaded [#776478]

* Updated translations:
  Turkish

Changes in libsoup from 2.57.1 to 2.58.0:

* Fix authentication issues when the SOUP_MESSAGE_DO_NOT_USE_AUTH_CACHE
  flag is used. [#778497, #777936, Carlos Garcia Campos]

* MSVC build improvements (Chun-wei Fan)

* Updated translations:
  Basque, Belarusian, Brazilian Portuguese, Chinese (Taiwan), Danish,
  French, Galician, Greek, Indonesian, Italian, Korean, Latvian,
  Lithuanian, Norwegian bokmål, Russian, Serbian, Slovak, Slovenian,
  Spanish, zh_CN

Changes in libsoup from 2.56.0 to 2.57.1:

* Added SoupWebsocketConnection:keepalive-interval, to make a
          connection send regular pings. [#773253, Ignacio Casal
          Quinteiro]

* Added soup_auth_manager_clear_cached_credentials() and
          SOUP_MESSAGE_DO_NOT_USE_AUTH_CACHE, to allow greater control
          over the use of cached HTTP auth credentials. [#774031,
          #774033, Carlos Garcia Campos]

* Fixed the use of SoupSession:proxy-uri values containing
          passwords. [#772932, Jonathan Lebon]

* Various minor WebSocket fixes [Ignacio Casal Quinteiro]:
* Avoid sending data after we start closing the
  connection [#774957]
* Do not log a critical if the peer sends an invalid
  close status code
* Log a debug message when a "pong" is received

* Fixed introspection of
          soup_message_headers_get_content_range() [Jasper St. Pierre]

* Replaced Vala [Deprecated] annotations with [Version] to
          avoid build warnings [#773177, Evan Nemerson]

* MSVC build improvements (Chun-wei Fan)

* Updated error/message strings to use Unicode punctuation.
          [#772217, Piotr Drąg]

* Updated translations:
  Czech, Friulian, German, Hebrew, Hungarian,
  Norwegian bokmål, Polish, Swedish

Changes in libsoup from 2.55.90 to 2.56.0:

* Added SoupWebsocketConnection:max-incoming-payload-size
          property, to override the default maximum incoming payload
          size. [#770022, Ignacio Casal Quinteiro]

* Added soup-version.h symbols (in particular
          soup_check_version()) to introspection. [#771439, Rico
          Tzschichholz]

* Updated the copy of the public suffix list used by SoupTLD
  [#769650, Michael Catanzaro]

* Updated translations:
  British English, Greek, Polish

Changes in libsoup from 2.54.1 to 2.55.90:

* Removed support for SSLv3 fallback; sites that reject TLS
          1.x handshakes will now just fail with an error. (Firefox
          and Chrome have both already switched to this behavior.)
          [#765940, Dan Winship]

* Fixed the parsing of <double>s in the new GVariant-based
          XMLRPC code. [#767707, Dan Winship]

* Fixed soup_server_set_ssl_cert_file(), which was added in
          2.48 but didn't actually work... [patch on libsoup-list from
          Sean DuBois]

* Added GObject properties to SoupLogger to make it
          bindings-friendly. [#768053, Jonh Wendell]

* Fixed build error on FreeBSD [#765376, Ting-Wei Lan]

* Fixed build with certain new versions of glibc that define
          "EOF" as a macro. [#768731, Philip Withnall]

* Updated m4/ax_code_coverage.m4 with support for lcov 1.12
          [Philip Withnall]

* Updated po files for future gettext versions [Piotr Drąg]

* New/updated translations:
  Occitan, Scottish Gaelic

(wiz)

2017-08-14 20:00:29 UTC MAIN commitmail json YAML

Updated time/py-vdirsyncer to 0.16.1

(wiz)

2017-08-14 20:00:19 UTC MAIN commitmail json YAML

Updated py-vdirsyncer to 0.16.1.

Version 0.16.1
==============

*released on 8 August 2017*

- Removed remoteStorage support, see :gh:`647`.
- Fixed test failures caused by latest requests version, see :gh:`660`.

(wiz)

2017-08-14 19:55:05 UTC MAIN commitmail json YAML

Updated devel/py-tortoisehg to 4.3.1

(wiz)

2017-08-14 19:54:55 UTC MAIN commitmail json YAML

Updated py-tortoisehg to 4.3.1.

TortoiseHg 4.3.1

TortoiseHg 4.3.1 is a quarterly feature release; 4.3.0 was skipped
since Mercurial tagged 4.3.1 the day as 4.3

Bug Fixes

    fileview: fix marker dark theme background colors (refs #810)

Improvements

    repowidget: add custom tools support to pair selection menu
    repowidget: add custom tools support to multiple selection menu
    sync: use [hostsecurity] section instead of [hostfingerprints] (refs #4830)

Installer

    newest versions of hg-git, dulwich and evolve

TortoiseHg 4.2.2

TortoiseHg 4.2.2 is a regularly scheduled bug-fix release

Installer

    latest hg-git, evolve

(wiz)

2017-08-14 19:48:02 UTC MAIN commitmail json YAML

Updated devel/py-test-xdist to 1.19.1

(wiz)

2017-08-14 19:47:52 UTC MAIN commitmail json YAML

Updated py-test-xdist to 1.19.1.

pytest-xdist 1.19.1 (2017-08-10)
================================

Bug Fixes
---------

- Fix crash when transferring internal pytest warnings from workers to the
  master node. (`#214 <https://github.com/pytest-dev/pytest-
  xdist/issues/214>`_)

pytest-xdist 1.19.0 (2017-08-09)
================================

Deprecations and Removals
-------------------------

- ``--boxed`` functionality has been moved to a separate plugin, `pytest-forked
  <https://github.com/pytest-dev/pytest-forked>`_. This release now depends on
  `` pytest-forked`` and provides ``--boxed`` as a backward compatibility
  option. (`#1 <https://github.com/pytest-dev/pytest-xdist/issues/1>`_)

Features
--------

- New ``--dist=loadscope`` option: sends group of related tests to the same
  worker. Tests are grouped by module for test functions and by class for test
  methods. See ``README.rst`` for more information. (`#191 <https://github.com
  /pytest-dev/pytest-xdist/issues/191>`_)

- Warnings are now properly transferred from workers to the master node. (`#92
  <https://github.com/pytest-dev/pytest-xdist/issues/92>`_)

Bug Fixes
---------

- Fix serialization of native tracebacks (``--tb=native``). (`#196
  <https://github.com/pytest-dev/pytest-xdist/issues/196>`_)

(wiz)

2017-08-14 19:46:37 UTC MAIN commitmail json YAML

Added devel/py-test-forked version 0.2

(wiz)

2017-08-14 19:46:26 UTC MAIN commitmail json YAML

+ py-test-forked

(wiz)

2017-08-14 19:46:10 UTC MAIN commitmail json YAML

Import py-test-forked-0.2 as devel/py-test-forked.

Run tests in isolated forked subprocesses.

(wiz)

2017-08-14 19:40:24 UTC MAIN commitmail json YAML

Updated devel/py-nose-exclude to 0.5.0

(wiz)

2017-08-14 19:40:14 UTC MAIN commitmail json YAML

Updated py-nose-exclude to 0.5.0.

Changes not found.

(wiz)

2017-08-14 19:38:22 UTC MAIN commitmail json YAML

Updated textproc/py-m2r to 0.1.9

(wiz)

2017-08-14 19:38:12 UTC MAIN commitmail json YAML

Updated py-m2r to 0.1.9.

Version 0.1.9 (2017-08-12)

    Print help when input_file is not specified on command-line

Version 0.1.8 (2017-08-11)

    Update metadata on setup.py

(wiz)

2017-08-14 19:29:24 UTC MAIN commitmail json YAML

2017-08-14 19:29:14 UTC MAIN commitmail json YAML

Updated py-idna to 2.6.

2.6 (2017-08-08)
++++++++++++++++

- Allows generation of IDNA and UTS 46 table data for different
  versions of Unicode, by deriving properties directly from
  Unicode data.
- Ability to generate RFC 5892/IANA-style table data
- Diagnostic output of IDNA-related Unicode properties and
  derived calculations for a given codepoint
- Support for idna.__version__ to report version
- Support for idna.idnadata.__version__ and
  idna.uts46data.__version__ to report Unicode version of
  underlying IDNA and UTS 46 data respectively.

(wiz)

2017-08-14 19:27:37 UTC MAIN commitmail json YAML

Updated devel/py-flake8-import-order to 0.13

(wiz)

2017-08-14 19:27:27 UTC MAIN commitmail json YAML

Updated py-flake8-import-order to 0.13.

0.13 2017-07-29
---------------

* Added ``secrets`` to stdlib list.
* Allow for any style to use application-package grouping.

(wiz)

2017-08-14 19:26:04 UTC MAIN commitmail json YAML

Override the right pkgconfig file.

(nros)

2017-08-14 19:25:11 UTC MAIN commitmail json YAML

Updated games/py-easyAI to 1.0.0.4

(wiz)

2017-08-14 19:25:01 UTC MAIN commitmail json YAML

2017-08-14 19:23:16 UTC MAIN commitmail json YAML

Updated misc/py-anki2 to 2.0.46

(wiz)

2017-08-14 19:23:06 UTC MAIN commitmail json YAML

Updated py-anki2 to 2.0.46.

Changes in 2.0.46

Released 2017-08-02.

    Fix an issue where mplayer would not work for some Linux users.

    Fix an issue with the edit screen that may have lead to crashes later on.

(wiz)

2017-08-14 19:21:44 UTC MAIN commitmail json YAML

Updated devel/p5-autovivification to 0.17

(wiz)

2017-08-14 19:21:33 UTC MAIN commitmail json YAML

Updated p5-autovivification to 0.17.

0.17    2017-07-31 17:15 UTC
        + Chg : A large chunk of boilerplate XS code, which is also used in
                other XS modules, has been factored out of the main .xs file
                to a collection of .h files in the xsh subdirectory.
        + Fix : The new optimization in perl 5.27.3 for scalar(keys(%$hashref))
                is now correcty supported.

(wiz)

2017-08-14 19:20:23 UTC MAIN commitmail json YAML

Updated www/p5-WWW-Mechanize to 1.86

(wiz)

2017-08-14 19:20:13 UTC MAIN commitmail json YAML

Updated p5-WWW-Mechanize to 1.86.

1.86      2017-07-04 15:48:46Z
    [FIXED]
    - use 127.0.0.1 instead of 'localhost' in a test script to avoid the test
      hanging due to ipv6 issues (GH#31, see also changes in 1.85)

(wiz)

2017-08-14 19:16:50 UTC MAIN commitmail json YAML

Updated time/p5-Time-HiRes to 1.9744

(wiz)

2017-08-14 19:16:40 UTC MAIN commitmail json YAML

Updated p5-Time-HiRes to 1.9744.

1.9744 [2017-07-27]
  - add more potential clock constants, like CLOCK_MONOTONIC_FAST
    (available in FreeBSD), and not all potentially found clock
    constants were properly exported to be available from Perl,
    see your system's clock_gettime() documentation for the available ones

1.9743 [2017-07-20]
  - correct declared minimum Perl version (should be 5.6, was declared
    as 5.8 since 1.9727_03): blead af94b3ac
  - fix the fix for 'do file' to load hints in Makefile.PL: blead 3172fdbc

(wiz)

2017-08-14 19:11:26 UTC MAIN commitmail json YAML

Updated devel/p5-Tie-Cycle to 1.225

(wiz)

2017-08-14 19:11:16 UTC MAIN commitmail json YAML

Updated p5-Tie-Cycle to 1.225.

1.225 2017-07-09T17:49:10Z
* Bump the version to reindex (See https://github.com/andk/pause/issues/248 )

(wiz)

2017-08-14 19:10:14 UTC MAIN commitmail json YAML

Updated textproc/p5-Text-BibTeX to 0.81

(wiz)

2017-08-14 19:10:04 UTC MAIN commitmail json YAML

Updated p5-Text-BibTeX to 0.81.

0.81 2017-07-19
* Fix issue with NameFormat and unitialized join-tokens.
  (thanks to Karl Wette for the bug report).

(wiz)

2017-08-14 19:08:41 UTC MAIN commitmail json YAML

Updated devel/p5-Specio to 0.40

(wiz)

2017-08-14 19:08:31 UTC MAIN commitmail json YAML

Updated p5-Specio to 0.40.

0.40    2017-08-03

- Fixed more bugs with {any,object}_{can,does,isa}_type. When passed a glob
  (not a globref) they would die in their type check. On Perl 5.16 or earlier,
  passing a number to an any_* type would also die.

- Fixed subification overloading. If Sub::Quote was loaded, this would be
  used, but any environment variables needed for the closure would not be
  included. This broke enums, among other things.

0.39    2017-08-02

- Many bug fixes and improves to the types created by
  {any,object}_{can,does,isa}_type. In some cases, an invalid value could
  cause an exception in type check itself. In other cases, a value which
  failed a type check would cause an exception when generating a message
  describing the failure. These cases have all been fixed.

- The messages describing a failure for all of these types have been improved.

- You can now create anonymous *_does and *_isa types using the exports from
  Specio::Declare.

(wiz)

2017-08-14 19:03:42 UTC MAIN commitmail json YAML

Updated devel/p5-Perl4-CoreLibs to 0.004

(wiz)

2017-08-14 19:03:32 UTC MAIN commitmail json YAML

Updated p5-Perl4-CoreLibs to 0.004.

version 0.004; 2017-07-30

  * in doc, note when core versions started warning and were removed

  * no longer include a Makefile.PL in the distribution

  * in META.{yml,json}, point to public bug tracker

  * include META.json in distribution

  * correct a typo in documentation

  * convert .cvsignore to .gitignore

  * add MYMETA.json to .cvsignore

(wiz)

2017-08-14 19:00:25 UTC MAIN commitmail json YAML

Updated devel/p5-Module-Runtime to 0.015

(wiz)

2017-08-14 19:00:15 UTC MAIN commitmail json YAML

Updated p5-Module-Runtime to 0.015.

version 0.015; 2017-07-16

  * update test suite to not rely on . in @INC, which is no longer
    necessarily there from Perl 5.25.7

  * in documentation, warn about the security problem with
    use_package_optimistically()

  * declare correct version for Test::More dependency

  * generate "traditional" style of compatibility Makefile.PL, to
    permit building in environments that don't support Build.PL or
    configure_requires

(wiz)

2017-08-14 18:59:17 UTC MAIN commitmail json YAML

Updated devel/p5-List-SomeUtils-XS to 0.55

(wiz)

2017-08-14 18:59:06 UTC MAIN commitmail json YAML

Updated p5-List-SomeUtils-XS to 0.55.

0.55    2017-07-23

- Skip all the tests unless List::SomeUtils 0.56 is installed. This fixes the
  issue where trying to install the new List::SomeUtils ends up pulling this
  distribution, which then fails because an older LSU is installed but doesn't
  export mode(). Reported by John SJ Anderson. GH #1.

0.54    2017-07-22

- Added a new function, mode(), requested by Jerrad Pierce. GH #2.

(wiz)

2017-08-14 18:58:18 UTC MAIN commitmail json YAML

Updated devel/p5-List-SomeUtils to 0.56

(wiz)

2017-08-14 18:58:08 UTC MAIN commitmail json YAML

0.56    2017-07-22
    - Make sure we depend on the latest LSU::XS if the system support XS.

0.55    2017-07-22
    - Fixed incorrect comments in doc examples for uniq().
    - Added a new function, mode(), requested by Jerrad Pierce. GH #2.

(wiz)

2017-08-14 18:53:29 UTC MAIN commitmail json YAML

Updated graphics/p5-Image-Info to 1.41

(wiz)

2017-08-14 18:53:19 UTC MAIN commitmail json YAML

Updated p5-Image-Info to 1.41.

2017-07-12  Slaven Rezic  <slaven@rezic.de>

    Release 1.41

    Stable release with the change in 1.40_50

    Additionally more diagnostics in t/string.t

2017-06-30  Slaven Rezic  <slaven@rezic.de>

    Release 1.40_50

    Support iTXt chunks in PNGs (RT #122285) (by Nicholas Clark)

(wiz)

2017-08-14 18:52:01 UTC MAIN commitmail json YAML

Updated www/p5-HTTP-Cookies to 6.04

(wiz)

2017-08-14 18:51:51 UTC MAIN commitmail json YAML

Updated p5-HTTP-Cookies to 6.04.

6.04      2017-08-03 15:05:22Z
    - Fix package version numbers

(wiz)

2017-08-14 18:51:05 UTC MAIN commitmail json YAML

Updated devel/p5-Exception-Class to 1.43

(wiz)

2017-08-14 18:50:55 UTC MAIN commitmail json YAML

Updated p5-Exception-Class to 1.43.

1.43    2017-07-09

- The full_message() method in Exception::Class::Base now calls message()
  instead of accessing the object's hash key. This makes it easier to override
  message() in a subclass. Patch by Alexander Batyrshin. PR #11.

(wiz)

2017-08-14 18:49:48 UTC MAIN commitmail json YAML

Updated devel/p5-Error to 0.17025

(wiz)

2017-08-14 18:49:39 UTC MAIN commitmail json YAML

Updated p5-Error to 0.17025.

Aug 07 2017 <shlomif@shlomifish.org> (Shlomi Fish)

  Error.pm #0.17025
  - Fix 'use Error::Simple' overriding the $VERSION
    - https://rt.cpan.org/Public/Bug/Display.html?id=122713
    - Thanks to Matthew Horsfall for the report.

(wiz)

2017-08-14 18:44:38 UTC MAIN commitmail json YAML

Updated devel/p5-Data-Printer to 0.40

(wiz)

2017-08-14 18:44:29 UTC MAIN commitmail json YAML

Updated p5-Data-Printer to 0.40.

0.40 2017-08-01
    BUG FIXES:
        - fix tied hash test on blead perl (5.27.3)
          https://rt.perl.org/Ticket/Display.html?id=131824
          Thanks Jim Keenan, Dave Mitchell and Zefram for reporting
          and debugging!

(wiz)

2017-08-14 18:43:33 UTC MAIN commitmail json YAML

Updated devel/p5-Class-Inspector to 1.32

(wiz)

2017-08-14 18:43:23 UTC MAIN commitmail json YAML

Updated p5-Class-Inspector to 1.32.

1.32      2017-08-08 14:12:42 -0400
  - The installed method now supports @INC hooks of any type
    (coderef was supported as of 1.29, now arrayrefs and objects
    are supported)
  - Detect probably broken Perl on Cygwin in Makefile.PL (see gh#5)

(wiz)

2017-08-14 18:42:06 UTC MAIN commitmail json YAML

Updated net/syncthing to 0.14.36

(wiz)

2017-08-14 18:41:56 UTC MAIN commitmail json YAML

Updated syncthing to 0.14.36.

v0.14.36

This is an unscheduled release to fix a bug that slipped through the cracks in 0.14.34 & 0.14.35.

Resolved issues:

    #4297: Folders paths are no longer reset when editing a folder without a label

v0.14.35

This is an unscheduled release in panic mode to fix a significant problem in 0.14.34.

Resolved issues in 0.14.35:

    #4288: Symlinks are deleted from versioned folders on startup

Resolved issues in 0.14.34:

    #2157: The new folder dialog now suggests a default path. Adjustable via advanced config defaultFolderPath.
    #4272: The build script no longer sets -installsuffix by default.
    #4286: Prevents a vulnerability that allows file overwrite via versioned symlinks

Note that the last issue is a security vulnerability. Symlinks on Windows are not supported and have not been created by Syncthing for a while. Nonetheless, if you use symlinks on Windows and Syncthing versioning you may have symlinks in your versioning directory from earlier versions. You must remove these manually. Syncthing can not remove them automatically because there are other things that look to us like symlinks but are not - deduplicated files, primarily. (This is one of the reasons symlinks are not supported on Windows.)

On other platforms the versioning directory is cleaned from symlinks as part of the upgrade.

v0.14.34-rc.1

This is a release candidate for v0.14.34.

Resolved issues:

    #2157: The new folder dialog now suggests a default path. Adjustable via advanced config defaultFolderPath.
    #4272: The build script no longer sets -installsuffix by default.

v0.14.33

This is a regularly scheduled stable release.

Resolved issues:

    #4188: Relative version paths are now correctly relative to the folder path
    #4227: Remote devices now show bytes remaining to sync
    #4249: Editing ignore patterns no longer incorrectly shows included patterns

v0.14.33-rc.1

This is a release candidate for v0.14.33.

Resolved issues:

    #4188: Relative version paths are now correctly relative to the folder path
    #4227: Remote devices now show bytes remaining to sync
    #4249: Editing ignore patterns no longer incorrectly shows included patterns

v0.14.32

This is a regularly scheduled stable release.

Resolved issues:

    #4157: "Nearby devices" are now shown in the add device dialog, avoiding the need to type their device ID.
    #4219: Folders that were once ignored in a sharing request now actualproperly when later added manually.

v0.14.32-rc.2

This is a release candidate for v0.14.32.

v0.14.32-rc.1

This is a release candidate fo14.31:

    #4157: "Nearby devices" are now shown in the add device dialog, avoiding the need to type their device ID.
    #4219: Folders that were once ignored in a sharing request now actually work properly when later added manually.

(wiz)

2017-08-14 15:25:36 UTC MAIN commitmail json YAML

mail/cyrus-imapd{,23}: Remove work directory references in scripts.

The installed cyradm shell script contained the path to the shell
in the tools directory instead of the system /bin/sh.  This
happened as part of the build process by the Perl MakeMaker system
used to build the Cyrus Perl modules.  Make the replacement at
post-build time to change it back to /bin/sh.

This fix was mirrored from the identical fix to the cyrus-imapd24
module by jnemeth@pkgsrc.org.

Bump the PKGREVISION of the cyrus-imapd and cyrus-imapd23 packages
due to the change in the installed script.

(jlam)

2017-08-14 15:25:20 UTC MAIN commitmail json YAML

devel/php-xcache: Fix errors during stage-install.

The package Makefile redefines ${EGDIR}, which was already defined
and used in lang/php/ext.mk.  Rename the package variable to
"XCACHE_EGDIR" to avoid a symbol clash.

Arguably, the EGDIR in lang/php/ext.mk should have been namespaced
a bit better to avoid conflicts with likely variable names used in
package Makefiles, e.g., PHP_EGDIR.

(jlam)

2017-08-14 15:25:09 UTC MAIN commitmail json YAML

databases/sqlite3-docs: Update checksum and PLIST to match version.

This package uses sqlite3/Makefile.version to set the package
version, but the checksum was for the distfile of the previous
version.  Update the checksum to the correct distfile and fix the
resulting PLIST.

(jlam)

2017-08-14 15:24:58 UTC MAIN commitmail json YAML

www/siege: Remove files from PLIST that are were never installed.

The PLIST lists "siegerc" and "urls.txt" under two different
locations under ${PREFIX}/share/examples/siege, but stage-install
only installs them into one of those locations.  Remove the other
paths.

(jlam)

2017-08-14 15:24:42 UTC MAIN commitmail json YAML

net/nagios-plugin-milter: Create necessary users and groups.

This package installs a binary that is setuid-executable to the
"smmsp" user and it also needs to be owned by the "nagios" group.
Add hooks to create these users and groups in the package install
scripts when the binary package is installed.

Bump the PKGREVISION due to changes in the package install scripts.

(jlam)

2017-08-14 15:24:30 UTC MAIN commitmail json YAML

net/nagios-base: Remove rss-newsfeed.html from SPECIAL_PERMS.

The rss-newsfeed.html file was removed in the update to version
4.3.2, so we no longer need to change ownership and permissions on
the file after installation.

Arguably, nagios-base should have a postinstall check for the
rss-newsfeed.* files and remove them, as they were removed in
version 4.3.2 due to security concerns.

(jlam)

2017-08-14 15:24:11 UTC MAIN commitmail json YAML

math/ltm: Fix build caused by improper use of $(PREFIX).

The makefile.include fragment included by all of the project
makefiles unconditionally sets $(CC), $(LD), $(AR) and $(RANLIB)
to $(PREFIX){gcc,ld,ar,ranlib}.  Their intent was to provide a
facility for cross-compiling the code, but the use of $(PREFIX)
for this purpose was unfortunate.

This change adds a patch to set $(PREFIX) to the empty string in
the makefiles, which should fix the problem with the smallest
set of changes.

(jlam)

2017-08-14 12:00:35 UTC MAIN commitmail json YAML

Updated devel/p5-Algorithm-Permute to 0.16

(mef)

2017-08-14 12:00:23 UTC MAIN commitmail json YAML

Updated devel/p5-Algorithm-Permute to 0.16
------------------------------------------
0.16  Aug 3 2017
    - Really use ppport.h
    - Skip 'Can't goto out' test on Perl <= 5.8.8

0.15  Jul 11 2017
    - Fixed RT#122432
    - C90 compatibility.

0.14  Jul 8 2017
    - Some doc updates.
    - Cleaned up some files in distribution.

0.13  Jul 8 2017
    - SLOYD became co-maintainer.
    - Fixed build problem on Perl 5.24+. RT#112247
    - Refactored tests. RT#31541
    - Fixed issues with "r of n" permutations. RT#77031, RT#45434
(pkgsrc changes)
- Add following line to test
  BUILD_DEPENDS+=  p5-Test-LeakTrace-[0-9]*:../../devel/p5-Test-LeakTrace

(mef)

2017-08-14 09:21:45 UTC MAIN commitmail json YAML

Updated lang/python35 to 3.5.4, lang/python34 to 3.4.7

(adam)

2017-08-14 09:20:00 UTC MAIN commitmail json YAML

Python 3.4.7:

Security
* bpo-29591: Update expat copy from 2.1.1 to 2.2.0 to get fixes of CVE-2016-0718 and CVE-2016-4472. See https://sourceforge.net/p/expat/bugs/537/ for more information.
* bpo-30694: Upgrade expat copy from 2.2.0 to 2.2.1 to get fixes of multiple security vulnerabilities including: CVE-2017-9233 (External entity infinite loop DoS), CVE-2016-9063 (Integer overflow, re-fix), CVE-2016-0718 (Fix regression bugs from 2.2.0窶冱 fix to CVE-2016-0718) and CVE-2012-0876 (Counter hash flooding with SipHash). Note: the CVE-2016-5300 (Use os- specific entropy sources like getrandom) doesn窶冲 impact Python, since Python already gets entropy from the OS to set the expat secret using XML_SetHashSalt().
* bpo-26657: Fix directory traversal vulnerability with http.server on Windows. This fixes a regression that was introduced in 3.3.4rc1 and 3.4.0rc1. Based on patch by Philipp Hagemeister.
* bpo-30500: Fix urllib.parse.splithost() to correctly parse fragments. For example, splithost('//127.0.0.1#@evil.com/') now correctly returns the 127.0.0.1 host, instead of treating @evil.com as the host in an authentification (login@host).
* bpo-30730: Prevent environment variables injection in subprocess on Windows. Prevent passing other invalid environment variables and command arguments.

(adam)

2017-08-14 09:16:28 UTC MAIN commitmail json YAML

Python 3.5.4:

Security
* bpo-30730: Prevent environment variables injection in subprocess on Windows. Prevent passing other environment variables and command arguments.
* bpo-30694: Upgrade expat copy from 2.2.0 to 2.2.1 to get fixes of multiple security vulnerabilities including: CVE-2017-9233 (External entity infinite loop DoS), CVE-2016-9063 (Integer overflow, re-fix), CVE-2016-0718 (Fix regression bugs from 2.2.0窶冱 fix to CVE-2016-0718) and CVE-2012-0876 (Counter hash flooding with SipHash). Note: the CVE-2016-5300 (Use os- specific entropy sources like getrandom) doesn窶冲 impact Python, since Python already gets entropy from the OS to set the expat secret using XML_SetHashSalt().
* bpo-30500: Fix urllib.parse.splithost() to correctly parse fragments. For example, splithost('//127.0.0.1#@evil.com/') now correctly returns the 127.0.0.1 host, instead of treating @evil.com as the host in an authentification (login@host).
* bpo-29591: Update expat copy from 2.1.1 to 2.2.0 to get fixes of CVE-2016-0718 and CVE-2016-4472. See https://sourceforge.net/p/expat/bugs/537/ for more information.

(adam)

2017-08-14 08:33:15 UTC MAIN commitmail json YAML

Adjust webkit-gtk entry (was updated on pkgsrc-wip to 2.16.6)

(leot)

2017-08-14 06:50:07 UTC MAIN commitmail json YAML

+ ImageMagick-7.0.6.7, cups-filters-1.16.1, grafana-4.4.3,
  harfbuzz-1.4.8, meld-3.17.3, ocaml-cppo-1.6.0, py-idna-2.6,
  py-m2r-0.1.8, py-postgresql-5.0.4, py-test-xdist-1.19.1,
  py-tortoisehg-4.3.1, py-vdirsyncer-0.16.1, vim-8.0.0921,
  vim-share-8.0.0921, webkit-gtk-2.16.6, xpdf-4.0.

(wiz)

2017-08-14 06:49:51 UTC MAIN commitmail json YAML

Update HOMEPAGE, from Marc Baudoin.

(wiz)

2017-08-14 06:45:30 UTC MAIN commitmail json YAML

Fix build.

This special snowflake wants both Module::Install AND Module::Build.

(wiz)

2017-08-14 01:52:42 UTC MAIN commitmail json YAML

Updated devel/py-mercurial to 4.3.1

(maya)

2017-08-14 01:31:56 UTC MAIN commitmail json YAML

py-mercurial: update to 4.3.1

1. Mercurial 4.3 / 4.3.1 (2017-08-10)

(4.3.1 was released immediately after 4.3 to fix a release oversight.)

An overview of new features available. This is a regularly-scheduled quarterly feature release.

1.1. Notable changes

    experimental amend extension providing the amend command
    experimental sparse extension
    Support for Python 2.6 has been dropped.
    Bundles created by the strip extension now store phase information. It will be restored when unbundling.
    The strip extension now removes relevant obsmarkers. If a backup requested (the default), the obsmarkers are stored in the backup bundle and will be restored when unbundling.

    hg show work (from the experimental show extension) now displays more info

    hg show stack is a new view for the current, in-progress changeset and others around it
    Mitigation for two security vulnerabilities

1.2. CVE-2017-1000115

Mercurial's symlink auditing was incomplete prior to 4.3, and could be abused to write to files outside the repository.

1.3. CVE-2017-1000116

Mercurial was not sanitizing hostnames passed to ssh, allowing shell injection attacks on clients by specifying a hostname starting with -oProxyCommand. This is also present in Git (CVE-2017-1000117) and Subversion (CVE-2017-9800), so please patch those tools as well if you have them installed.

2. Mercurial 4.2.3 (2017-08-10)

This was an out-of-cycle backport of security fixes from 4.3 for users stuck on Python 2.6.

3. Mercurial 4.2.2 (2017-07-05)

This is a regularly-scheduled bugfix release.

    largefiles: avoid a crash when archiving a subrepo with largefiles disabled
    rebase: also test abort from pretxnclose error

    rebase: backed out changes 2519994d25ca and cf8ad0e6c0e4 (issue5610)
    rebase: reinforce testing around precommit hook interrupting a rebase

(maya)

2017-08-14 00:03:50 UTC MAIN commitmail json YAML

Updated lang/openjdk7 to 1.7.141

(ryoon)