Link [ pkgsrc | NetBSD | pkgsrc git mirror | PR fulltext-search | netbsd commit viewer ]


   
        usage: [branch:branch] [user:user] [path[@revision]] keyword [... [-excludekeyword [...]]] (e.g. branch:MAIN pkgtools/pkg)




switch to index mode

recent branches: MAIN (17m)  pkgsrc-2024Q1 (15d)  pkgsrc-2023Q4 (43d)  pkgsrc-2023Q2 (75d)  pkgsrc-2023Q3 (154d) 

2024-05-13 16:18:08 UTC Now

2017-04-14 08:00:26 UTC MAIN commitmail json YAML

Import ruby-activesupport-4.2.8 as devel/ruby-activesupport42

Notable changes since 3.2:
- Replace deprecated memcache-client gem with dalli in
  ActiveSupport::Cache::MemCacheStore.
- Optimize ActiveSupport::Cache::Entry to reduce memory and processing
  overhead.
- Inflections can now be defined per locale. singularize and pluralize
  accept locale as an extra argument.
- Object#try will now return nil instead of raise a NoMethodError if
  the receiving object does not implement the method, but you can still
  get the old behavior by using the new Object#try!.
- String#to_date now raises ArgumentError: invalid date instead of
  NoMethodError: undefined method 'div' for nil:NilClass when given an
  invalid date. It is now the same as Date.parse, and it accepts more
  invalid dates than 3.x.

See the release notes of 4.0, 4.1, and 4.2 for the full list:
- http://edgeguides.rubyonrails.org/4_0_release_notes.html
- http://edgeguides.rubyonrails.org/4_1_release_notes.html
- http://edgeguides.rubyonrails.org/4_2_release_notes.html

(minskim)

2017-04-14 07:13:51 UTC MAIN commitmail json YAML

BUILD_DEPEND on setuptools_scm for joerg.

(wiz)

2017-04-14 07:03:51 UTC MAIN commitmail json YAML

Note update of the "mutt" package to version 1.8.1

(tron)

2017-04-14 07:00:45 UTC MAIN commitmail json YAML

Note update of the "mutt" package to version 1.8.0nb2

(tron)

2017-04-14 07:00:02 UTC MAIN commitmail json YAML

Update "mutt" package to version 1.8.1:
This is a bug fix release.  In particular, it has fixes for setenv,
sidebar_whitelist, some refresh issues, and a potential segfault.

(tron)

2017-04-14 05:34:33 UTC MAIN commitmail json YAML

Prepare for the import of Ruby on Rails 4.2

(minskim)

2017-04-14 00:40:29 UTC MAIN commitmail json YAML

2017-04-14 00:36:25 UTC MAIN commitmail json YAML

2017-04-14 00:31:41 UTC MAIN commitmail json YAML

js2-mode works perfectly fine on emacs25

(pho)

2017-04-13 19:05:01 UTC MAIN commitmail json YAML

Updated chat/ejabberd to 17.04

(fhajny)

2017-04-13 19:04:53 UTC MAIN commitmail json YAML

Update chat/ejabberd to 17.04.
Make the Redis support unconditional (no extra dependencies).

Changes in 17.04:

Admin
- Add more examples on config template
- Generate ejabberd lib dir when not available in code server
- Set default prefix to /usr/local
- Start supervisors after ext_mod
- Don't log warning on successful ping reply
- New muc_register_nick command

Core
- Deprecate jlib.erl in favor of misc.erl
- Add support for file-based queues
- ejabberd_sm: Fix routing of headline and groupchat messages
- Fix c2s connection close on demand
- Improve overloaded S2S queue processing

Databases
- Improve Redis related code
- Add Redis pool support
- Improve logging of Redis errors
- Add Redis and SQL as mod_proxy65 RAM backends
- Add Redis and SQL as mod_carboncopy RAM backends
- Add Redis and SQL as mod_bosh RAM backends
- Add Redis and SQL as router RAM backends
- Add SQL as mod_muc RAM backend
- Remove obsolete Pubsub mnesia migration calls

Miscellany
- ejabberd_http: Expand @VERSION@ in custom headers
- ejabberd_http: Add "custom_headers" option
- mod_client_state: Queue stanzas of each full JID
- mod_http_upload: Don't add "Server" header line
- Pubsub: Refactor pubsub's get_last_items
- Pubsub: Fix PEP issues

(fhajny)

2017-04-13 19:03:38 UTC MAIN commitmail json YAML

Updated misc/erlang-p1_utils to 1.0.8

(fhajny)

2017-04-13 19:03:28 UTC MAIN commitmail json YAML

Update misc/erlang-p1_utils to 1.0.8.

- Add p1_queue
- Only perform destructive operations in p1_file_queue:in/2
- Add garbage collector for file queues
- Add ram_to_file/1 and file_to_ram/1
- Improve exception names
- Implement limited queues
- Add ownership protection
- Add get_limit/1 and set_limit/2

(fhajny)

2017-04-13 18:43:34 UTC MAIN commitmail json YAML

2017-04-13 18:43:04 UTC MAIN commitmail json YAML

Python 3.x gets a different name for boost-numpy as well, so
conditionalize the entries accordingly.

(joerg)

2017-04-13 18:27:30 UTC MAIN commitmail json YAML

Updated converters/erlang-iconv to 1.0.4

(fhajny)

2017-04-13 18:27:21 UTC MAIN commitmail json YAML

Update converters/erlang-iconv to 1.0.4.

- Update rebar.config.script
- Use p1_utils 1.0.7

(fhajny)

2017-04-13 18:24:45 UTC MAIN commitmail json YAML

Use USE_GLOBAL_DEPS that some Erlang packages seem to use to rely on system dependencies.

(fhajny)

2017-04-13 17:48:27 UTC MAIN commitmail json YAML

Use a more explicit libgcrypt reference, fixes joyent/pkgsrc#483. PKGREVISION++

(fhajny)

2017-04-13 16:58:14 UTC MAIN commitmail json YAML

2017-04-13 15:30:04 UTC pkgsrc-2017Q1 commitmail json YAML

2017-04-13 15:12:07 UTC MAIN commitmail json YAML

2017-04-13 15:04:42 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5275 - requested by taca
mail/dovecot2-pigeonhole: point update

Revisions pulled up:
- mail/dovecot2-pigeonhole/Makefile                            1.34
- mail/dovecot2-pigeonhole/distinfo                            1.25

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Apr 13 02:00:44 UTC 2017

  Modified Files:
  pkgsrc/mail/dovecot2-pigeonhole: Makefile distinfo

  Log Message:
  Update dovecot2-pigeonhole to 0.4.18 for dovecot2 2.2.28.

  v0.4.18 12-04-2017 Stephan Bosch <stephan@rename-it.nl>

  + imapsieve plugin: Implemented the copy_source_after rule action. When this
    is enabled for a mailbox rule, the specified Sieve script is executed for
    the message in the source mailbox during a "COPY" event. This happens only
    after the Sieve script that is executed for the corresponding message in the
    destination mailbox finishes running successfully.
  + imapsieve plugin: Added non-standard Sieve environment items for the source
    and destination mailbox.
  - multiscript: The execution of the discard script had an implicit "keep",
    rather than an implicit "discard".

(bsiegert)

2017-04-13 15:04:31 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5274 - requested by taca
mail/dovecot2: security fix
mail/dovecot2-sqlite: security fix

Revisions pulled up:
- mail/dovecot2-sqlite/Makefile                                1.5
- mail/dovecot2/Makefile.common                                1.6
- mail/dovecot2/PLIST                                          1.53
- mail/dovecot2/distinfo                                        1.72

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Apr 13 01:59:08 UTC 2017

  Modified Files:
  pkgsrc/mail/dovecot2: Makefile.common PLIST distinfo
  pkgsrc/mail/dovecot2-sqlite: Makefile

  Log Message:
  Update dovecot2 to 2.2.29.1.  This release contains security fixes.

  v2.2.29.1 2017-04-12  Timo Sirainen <tss@iki.fi>

  - imapc reconnection fix was forgotten from 2.2.29 release, which also
    made "make check" fail in a unit test
  - dict-sql: Merging multiple UPDATEs to a single statement wasn't
    actually working.
  - Fixed building with vpopmail

  v2.2.29 2017-04-10  Timo Sirainen <tss@iki.fi>

  * passdb/userdb dict: Don't double-expand %variables in keys. If dict
    was used as the authentication passdb, using specially crafted
    %variables in the username could be used to cause DoS (CVE-2017-2669)
  * When Dovecot encounters an internal error, it logs the real error and
    usually logs another line saying what function failed. Previously the
    second log line's error message was a rather uninformative "Internal
    error occurred. Refer to server log for more information." Now the
    real error message is duplicated in this second log line.
  * lmtp: If a delivery has multiple recipients, run autoexpunging only
    for the last recipient. This avoids a problem where a long
    autoexpunge run causes LMTP client to timeout between the DATA
    replies, resulting in duplicate mail deliveries.
  * config: Don't stop the process due to idling. Otherwise the
    configuration is reloaded when the process restarts.
  * mail_log plugin: Differentiate autoexpunges from regular expunges
  * imapc: Use LOGOUT to cleanly disconnect from server.
  * lib-http: Internal status codes (>9000) are no longer visible in logs
  * director: Log vhost count changes and HOST-UP/DOWNte autoexpunges from regular expunges
  * imapc: Use LOGOUT to cleanly disconnect from server.
  * lib-http: Internal status codes (>9000) are no longer visible in logs
  * director: Log vhost count changes and HOST-UP/DOWN

  + quota: Add plugin { quota_max_mail_size } setting to limit the
    maximum individual mail size that can be saved.
  + imapc: Add imapc_features=delay-login. If set, connecting to the
    remote IMAP server isn't done until it's necessary.
  + imapc: Add imapc_connection_retry_count and
    imapc_connection_retry_interval settings.
  + imap, pop3, indexer-worker: Add (deinit) to process title before
    autoexpunging runs.
  + Added %{encrypt} and %{decrypt} variables
  + imap/pop3 proxy: Log proxy state in errors as human-readable string.
  + imap/pop3-login: All forward_* extra fields returned by passdb are
    sent to the next hop when proxying using ID/XCLIENT commands. On the
    receiving side these fields are imported and sent to auth process
    where they're accessible via %{passdb:forward_*}. This is done only
    if the sending IP address matches login_trusted_networks.
  + imap-login: If imap_id_retain=yes, send the IMAP ID string to
    auth process. %{client_id} expands to it in auth process. The ID
    string is also sent to the next hop when proxying.
  + passdb imap: Use ssl_client_ca_* settings for CA validation.
  - fts-tika: Fixed crash when parsing attachment without
    Content-Disposition header. Broken by 2.2.28.
  - trash plugin was broken in 2.2.28
  - auth: When passdb/userdb lookups were done via auth-workers, too much
    data was added to auth cache. This could have resulted in wrong
    replies when using multiple passdbs/userdbs.
  - auth: passdb { skip & mechanisms } were ignored for the first passdb
  - oauth2: Various fixes, including fixes to crashes
  - dsync: Large Sieve scripts (or other large metadata) weren't always
    synced.
  - Index rebuild (e.g. doveadm force-resync) set all mails as \Recent
  - imap-hibernate: %{userdb:*} wasn't expanded in mail_log_prefix
  - doveadm: Exit codes weren't preserved when proxying commands via
    doveadm-server. Almost all errors used exit code 75 (tempfail).
  - ACLs weren't applied to not-yet-existing autocreated mailboxes.
  - Fixed a potential crash when parsing a broken message header.
  - cassandra: Fallback consistency settings weren't working correctly.
  - doveadm director status <user>: "Initial config" was always empty
  - imapc: Various reconnection fixes.

(bsiegert)

2017-04-13 14:37:18 UTC MAIN commitmail json YAML

2017-04-13 14:36:46 UTC MAIN commitmail json YAML

Update mksh to R55.

R55 is mostly a feature release with summary bugfixes:

  * [komh] Fix OS/2 search_access() and UNC path logic
  * [tg] Undocument printf(1) to avoid user confusion
  * [Jean Delvare, tg] Fix printf builtin -R option
  * [tg] Make ${var@x}, unknown x, fail (thanks izabera)
  * [tg] ${var=x} must evaluate x in scalar context (10x Martijn Dekker)
  * [tg] Fixup relation between lksh and mksh, reduce delta
  * [tg] Improve manpage display; add OS/2 $PATH FAQ
  * [Jean Delvare] Fix bugs in manpage
  * [tg] Review tilde expansion, removing ?odd use of KEEPASN? and introduce
    POSIX ?declaration utility? concept; wait isn?t one
  * [tg] Add \builtin utility, declaration utility forwarder
  * [tg] Make $'\xz' expand to xz, not \0
  * [tg] Use fixed string pooling (requires the above change in host mksh)
  * [tg] POSIX declaration commands can have varassign and redirections
  * [Martijn Dekker] Add typeset -g, replacing homegrown ?global?
  * [Harvey-OS] Disable NOPROSPECTOFWORK, APEX is reportedly fixed now
  * [tg] Display ulimit -a output with flags; improve Haiku
  * [tg] Drop old let] hack, use \builtin internally
  * [tg] Fix padding in Lb64encode in dot.mkshrc
  * [tg] Move FAQ content to a separate, new FAQ section in the manpage
  * [tg] Add new standard variable PATHSEP (?:?, ?;? on OS/2)
  * [Martijn Dekker] Fix LINENO in eval and alias
  * [komh] Fix ?\builtin? on OS/2
  * [tg] Improve (internal) character classes code for speed
  * [tg] Fix: the underscore is no drive letter
  * [tg] No longer hard-disable persistent history support in lksh
  * [tg] Introduce build flag -T for enabling ?textmode? on OS/2 (supporting
    CR+LF line endings, but incompatible with mksh proper)
  * [tg] Merge mksh-os2
  * [tg] Permit changing $OS2_SHELL during a running shell
  * [tg] Fix multibyte handling in ^R (Emacs search-history)
  * [tg] Allow ?typeset -p arrname[2]? to work
  * [tg] Make some error messages more consistent
  * [tg, komh] Disable UTF-8 detection code for OS/2 as unrealistic
  * [tg, sdaoden] Limit alias name chars to POSIX plus non-leading ?-?
  * [tg, Martijn Dekker] Expand aliases at COMSUB parse time
  * [tg] Make ?typeset -f? output alias-resistent
  * [tg, Martijn Dekker] Permit ?eval break? and ?eval continue?
  * [tg] Make -masm=intel safe on i386
  * [tg] Disambiguate $((?)) vs. $((?)?) in ?typeset -f? output
  * [Jean Delvare] Clarify the effect of exit and return in a subshell
  * [tg] Simplify compile-time asserts and make them actually compile-time
  * [tg] Fix ^O in Emacs mode if the line was modified (LP#1675842)
  * [tg] Address Coverity Scan? stuff? now that it builds again
  * [Martijn Dekker, tg] Add test -v
  * [tg] Document set -o posix/sh completely

R54 is a bugfix release with moderate new features:

  * [tg] Simplify and improve code and manual page
  * [tg] Try GCC 5?s new -malign-data=abi
  * [tg] Allow interrupting builtin cat even on fast devices (LP#1616692)
  * [tg] Update to Unicode 9.0.0
  * [Andreas Buschka] Correct English spelling
  * [tg] Handle set -e-related error propagation in || and && constructs
    correctly
  * [tg] Initialise memory for RNG even when not targeting Valgrind
  * [tg] Shrink binary size
  * [Brian Callahan] Improve support for the contemporary pcc compiler
  * [tg] Fix side effects with lazy evaluation; spotted by ormaaj
  * [tg] New flags -c (columnise), -l, -N for the print builtin
  * [Larry Hynes] Fix English, spelling mistakes, typos in the manpage
  * [tg, ormaah] Return 128+SIGALRM if read -t times out, like GNU bash
  * [Martijn Dekker] Install both manpages from Build.sh
  * [Martijn Dekker] Document case changes are ASCII-only
  * [Ronald G. Minnich, Elbing Miss, ?lvaro Jurado, tg] Begin porting to
    Harvey-OS and APEX (similar to Plan 9 and APE)
  * [KO Myung-Hun] More infrastructure for the OS/2 (EMX, KLIBC) port

R53a is a snapshot/feature release:

  * [lintian] Fix spelling
  * [tg] Unbreak multi-line command history broken by history flush
  * [tg] Fix redefining POSIX functions that were Korn functions before
  * [tg, TNF] Fix bounds checks in Vi editing mode
  * [tg] Handle combining characters at end of string or output correctly
  * [tg] Fix ${!#} ${!?} ${!-} (POSIX, prompted by izabera)
  * [tg] Fix shf.c-internal buffer overread on printing digits
  * [J?rg] Fix a typo in the testsuite
  * [arekm] Increase default edit line size (unless MKSH_SMALL)
  * [tg] Improve description of Emacs mode keybindings, especially ^U
  * [tg, arekm, jilles] Abort read builtin in case of read(2) errors
  * [tg, izabera, carstenh] Fix most of the ambiguous corner cases related to $
    {[pfx]var[op[word]]} (${@:-1} still unsupported)
  * [carstenh] Contribute some more testsuite coverage
  * [tg] WDS_TPUTS now emits QCHAR newline reentrant-safe
  * [tg] Fix var=<< implementation (LP#1380389)
  * [tg, FreeBSD] Make XSI test(1) extensions behave as if they were POSIX
  * [tg, izabera] Add $(<<<x) and $(<<EOF?) implementation
  * [tg] Lower minimum screen size accepted as ?sane? from the OS to 4?2
  * [tg, Torsten Sillke] Simplify tilde-expanded parameters
  * [tg, Torsten Sillke] Fix default PS1 for substring matches
  * [tg] Apply defer-builtin-with-arguments logic to realpath builtin
  * [tg] Rework string pooling (own vs. compiler?s) (LP#1580348)
  * [tg] Feature: print -A, prints arguments as characters
  * [tg, izabera] Replace <<< and >>> as ROL and ROR operators with their new ^
    < and ^> spelling as per this proposal
  * [tg, slagtc] Clear-to-EOL under tmux to work around its anti-feature
  * [tg, p120ph37] Remove support for using file descriptors with more than a
    single digit, in preparation for named file descriptors
  * [tg] Correct, but simplify (at the potential cost of more tty I/O than
    strictly necessary, though never redundant and (probably) not more than
    before when it was miscalculated), line clearing and redrawing
  * [slagtc, tg] Implement new evaluate-region editing command Esc+Ctrl-E
  * [tg] Prefer external rename utility over the recovery builtin
  * [tg] Remove redundant full-line redraws
  * [tg, Natureshadow] Fix errorlevel of ?.? (?dot? special builtin) when the
    sourced script does not run any commands, for POSIX compliance
  * [tg] Refactor op tokens and edchars to shave off some more bytes
  * [tg] Fix some bugs in the manpage and some occasional/minor code bugs
  * [tg, Brian Callahan] Mark tests requiring new perl as !need-pass
  * [tg, slagtc] Add $KSH_MATCH and, to make it usable, ${foo@/bar/baz}
  * [tg, Score_Under] Fix bogus patch from OpenBSD: only NULL the global source
    in unwind when actually reclaiming its Area
  * [izabera] Mention in the manpage that integer bases go up to 36
  * [Natureshadow] Fix /= operator broken during refactoring

R52c is a bugfix-only release:

  * [tg] Shave 200 bytes off .text by revisiting string pooling
  * [tg, J?rg] Fix manpage for ditroff on Schillix
  * [tg, wbx] Use sed 1q instead of unportable head(1)
  * [tg] Implement underrun debugging tool for area-based memory allocator
  * [tg] Fix history underrun when first interactive command is entered
  * [tg, bef0rd] Do not misinterpret ?${0/}? as ?${0//?, fixes segfault
  * [tg, St?phane Chazelas] Fix display problems with special parameters
  * [tg, St?phane Chazelas] Catch attempt to trim $* and $@ with ?, fixes
    segfault (Todd Miller did this in 2004 for ${x[*]} already, so just sync)
  * [Martijn Dekker] Fix ?command -p? with -Vv to behave as POSIX requires
  * [tg, jilles, Oleg Bulatov] Fix recusive parser with active heredocs
  * [tg] Flush even syntax-failing or interrupted commands to history
  * [tg, fmunozs] Fix invalid memory access for ?'\0'? in arithmetics
  * [tg] Explicitly reserve SIGEXIT and SIGERR for ksh
  * [tg, izabera] Catch missing here documents at EOF even under ?set -n?
  * [kre, tg] Document Austin#1015 handling (not considered a violation)
  * [tg, fmunozs] Fix buffer overread for empty nameref targets
  * [tg] Fix warnings pointed out by latest Debian gcc-snapshot
  * [tg, Martijn Dekker] Document upcoming set +o changes
  * [Martijn Dekker] Expand testsuite for command/whence

R52b is a strongly recommended bugfix-only release:

  * [tg] Recognise ksh93 compiled scripts and LZIP compressed files as binary
    (i.e. to not run as mksh plaintext script)
  * [tg] Document that we will implement locale tracking later
  * [tg] Add EEXIST to failback strerror(3)
  * [jilles] Make set -C; :>foo race-free
  * [tg] Don?t use unset in portable build script
  * [tg] Plug warning on GNU/kFreeBSD, GNU/Hurd
  * [tg] Document read -a resets the integer base
  * [J?rg] Fix manpage: time is not a builtin but a reserved word
  * [J?rg, tg] Make exit (and return) eat -1
  * [tg] parse ?$( (( ? ) ? ) ? )? correctly (LP#1532621), Jan Palus
  * [tg] reduce memory footprint by free(3)ing more aggressively
  * [tg] fix buffer overrun (LP#1533394), bugreport by izabera
  * [tg] correctly handle nested ADELIM parsing (LP#1453827), Teckids
  * [tg] permit ?read -A/-a arr[idx]? as long as only one element is read; fix
    corruption of array indic?s with this construct (LP#1533396), izabera
  * [tg] Sanitise OS-provided signal number in even more places
  * [tg] As requested by J?rg, be clear manpage advice is for mksh
  * [tg] Revert (as it was a regression) POSIX bugfix from R52/2005 related to
    accent gravis-style command substitution until POSIX decides either way
  * [tg] Handle export et al. after command (Austin#351)
  * [tg] Catch EPIPE in built-in cat and return as SIGPIPE (LP#1532621)
  * [tg] Fix errno in print/echo builtin; optimise that and unbksl
  * [tg] Update documentation, point out POSIX violation (Austin#1015)

R52 is a strongly recommended bugfix release:

  * [_0bitcount] Move moving external link from mksh(1) to the #ksh channel
    homepage linked therein
  * [tg] Make setenv ?set -u?-safe and fix when invoked with no args
  * [tg] Make ?typeset -f? output reentrant if name is a reserved word
  * [oksh] Zero-pad seconds in ?time? output to align columns
  * [tg] Check signals and errorlevels from OS to be within bounds
  * [komh, tg] Quote and document ?;? as PATH separator in some places
  * [oksh, tg] Simplify code to call afree() even if arg is NULL
  * [tg] Fix tree-printing and reentrancy of multiple here documents
  * [tg] Work around LP#1030581 by permitting exactly one space after
  * [tg, oksh] Code quality work, cleanups
  * [tg] New code for here documents/strings with several bugfixes
  * [tg] Stop using issetugid(2) for ?p checks, wrong tool for the job
  * [tg] Reintroduce some -o posix changes lost in 2005, plus fixes
  * [tg] Make ?source? into a built-in command
  * [tg] Drop ?stop? alias, lksh(1) functionality to auto-unalias
  * [tg] Fix \u0000 ignored in $'?' and print
  * [tg] Improve portability of Build.sh
  * [Jilles Tjoelker] Improve portability of testsuite
  * [tg] Fix tilde expansion for some substitutions (izabera, Chet, Geoff)
  * [tg] Improve reparsing of ((?) |?) as ( (?) |?)
  * [Martijn Dekker] Fix test(1) not returning evaluation errors
  * [tg] Fix ${*:+x} constructs (carstenh)
  * [tg] Make (( ? )) into a compound command (ormaaj)
  * [tg] Repair a few parameter substitution expansion mistakes

(bsiegert)

2017-04-13 14:35:53 UTC MAIN commitmail json YAML

#define CUPS API compatibility options so we can build against newer
CUPS versions, and switch dependency away from cups15.

Update conflicts list.

(hauke)

2017-04-13 14:35:31 UTC MAIN commitmail json YAML

Update to FriCAS 1.3.1
Detailed changes are not known and not clear (besides regular cleanup).

(asau)

2017-04-13 14:19:55 UTC MAIN commitmail json YAML

Note updated of lang/php70 package to 7.0.18.

(taca)

2017-04-13 14:19:19 UTC MAIN commitmail json YAML

Update php70 to 7.0.18.

13 Apr 2017 PHP 7.0.18

- Core:
  . Fixed bug #73370 (falsely exits with "Out of Memory" when using
    USE_ZEND_ALLOC=0). (Nikita)
  . Fixed bug #73960 (Leak with instance method calling static method with
    referenced return). (Nikita)
  . Fixed bug #74265 (Build problems after 7.0.17 release: undefined reference
    to `isfinite'). (Nikita)
  . Fixed bug #74302 (yield fromLABEL is over-greedy). (Sara)

- Apache:
  . Reverted patch for bug #61471, fixes bug #74318. (Anatol)

- Date:
  . Fixed bug #72096 (Swatch time value incorrect for dates before 1970). (mcq8)

- DOM:
  . Fixed bug #74004 (LIBXML_NOWARNING flag ingnored on loadHTML*).
    (somedaysummer)

- iconv:
  . Fixed bug #74230 (iconv fails to fail on surrogates). (Anatol)

- OpenSSL:
  . Fixed bug #72333 (fwrite() on non-blocking SSL sockets doesn't work).
    (Jakub Zelenka)

- PDO MySQL:
  . Fixed bug #71003 (Expose MYSQLI_CLIENT_SSL_DONT_VERIFY_SERVER_CERT to PDO
    interface). (Thomas Orozco)

- Streams:
  . Fixed bug #74216 (Correctly fail on invalid IP address ports). (Sara)

- Zlib:
  . Fixed bug #74240 (deflate_add can allocate too much memory). (Matt Bonneau)

(taca)

2017-04-13 14:17:19 UTC MAIN commitmail json YAML

Updated devel/p5-BSD-Resource to 1.29.11
Updated devel/p5-CPAN-Perl-Releases to 3.12
Updated devel/p5-CPANPLUS to 0.9166
Updated devel/p5-Class-InsideOut to 1.14

(mef)

2017-04-13 14:15:04 UTC MAIN commitmail json YAML

Updated devel/p5-Class-InsideOut to 1.14
----------------------------------------
1.14      2017-04-02 13:52:18-04:00 America/New_York
    Fixed:
    - Passes tests when '.' is not in @INC.

(mef)

2017-04-13 14:12:53 UTC MAIN commitmail json YAML

Updated devel/p5-CPANPLUS to 0.9166
-----------------------------------
0.9166      Wed Apr 12 09:37:20 BST 2017
  * make Autoflush do STDOUT and STDERR
  * switch from PERLWRAPPER to Autoflush

(mef)

2017-04-13 14:05:28 UTC MAIN commitmail json YAML

Updated devel/p5-CPAN-Perl-Releases to 3.12
-------------------------------------------
version 3.12 at 2017-03-20 21:04:41 +0000
-----------------------------------------
    Updated for v5.25.11

(mef)

2017-04-13 14:02:38 UTC MAIN commitmail json YAML

Updated devel/p5-BSD-Resource to 1.29.11
----------------------------------------
2017-04-07  Jarkko Hietaniemi  <jhi@iki.fi>
        * Prepend "./" to require-d pathnames in tests,
          in preparation of Perl 5.26.0. [cpan #120993]
        * Add RLIMIT_POSIXLOCKS from DragonFly BSD.
        * Release 1.2911.

(mef)

2017-04-13 13:45:19 UTC MAIN commitmail json YAML

Updated databases/mysql51-client to 5.1.73

(mef)

2017-04-13 13:44:49 UTC MAIN commitmail json YAML

Updated databases/mysql51-{client,server} to 5.1.73
------------------------------------------------------------
The ChangeLog since 5.1.72 is too huge, so the beginning some
lines are listed here:
  ------------------------------------------------------------
  timestamp: Fri 2013-11-01 16:39:19 +0100
  message:
    Bug#17617945 BUFFER OVERFLOW IN GET_MERGE_MANY_BUFFS_COST WITH SMALL SORT_BUFFER_SIZE

    get_cost_calc_buff_size() could return wrong value for the size of imerge_cost_buff.
  ------------------------------------------------------------
  timestamp: Thu 2013-10-31 22:53:56 +0000
  message:
    BUG#17662398: REMOVE DUPLICATE TEST CASES

    Remove duplicate test cases.
  ------------------------------------------------------------
  timestamp: Thu 2013-10-31 23:02:44 +0530
  message:
    Bug #12917164 DROP USER CAN'T DROP USERS WITH LEGACY
        UPPER CASE HOST NAME ANYMORE

    Description:
    It is not possible to drop users with host names with upper case
    letters in them. i.e DROP USER 'root'@'Tmp_Host_Name'; is failing
    with error.

    Analysis: Since the fix 11748570 we came up with lower case hostnames
    as standard. But in the current bug the hostname is created by
    mysql_install_db script is still having upper case hostnames.
    So, if we have the hostname with upper case letters like(Tmp_Host_Name)
    then we will have as it is stored in the mysql.user table.
    In this case if use "'DROP USER 'root'@'Tmp_Host_Name';" it gives
    error because we do compare with the lower case of hostname since the
    11748570 fix.

    Fix: We need to convert the hostname to lower case before storing into
    the mysql.user table when we run the mysql_install_db script.
------------------------------------------------------------

(mef)

2017-04-13 13:08:34 UTC MAIN commitmail json YAML

2017-04-13 13:00:43 UTC MAIN commitmail json YAML

Handle MACHINE_GNU_PLATFORM when generating PLIST.

(asau)

2017-04-13 12:11:41 UTC pkgsrc-2017Q1 commitmail json YAML

Record latest branch updates.

(bsiegert)

2017-04-13 11:54:13 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5273 - requested by taca
net/bind99: security fix

Revisions pulled up:
- net/bind99/Makefile                                          1.66
- net/bind99/distinfo                                          1.44

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Apr 13 01:53:35 UTC 2017

  Modified Files:
  pkgsrc/net/bind99: Makefile distinfo

  Log Message:
  Update bind99 to 9.9.9pl8 (BIND 9.9.9-P8).

  Quote from release announce:

      BIND 9.9.9-P8 addresses the security issues described in CVE-2017-3136,
      CVE-2017-3137, and CVE-2017-3138, and updates the built-in trusted keys
      for the root zone.

  Quote from CHANGELOG:

  --- 9.9.9-P8 released ---

  4582. [security] 'rndc ""' could trigger a assertion failure in named.
  (CVE-2017-3138) [RT #44924]

  4580. [bug] 4578 introduced a regression when handling CNAME to
  referral below the current domain. [RT #44850]

  --- 9.9.9-P7 released ---

  4578. [security] Some chaining (CNAME or DNAME) responses to upstream
  queries could trigger assertion failures.
  (CVE-2017-3137) [RT #44734]

  4575. [security] DNS64 with "break-dnssec yes;" can result in an
  assertion failure. (CVE-2017-3136) [RT #44653]

  4564. [maint] Update the built in managed keys to include the
  upcoming root KSK. [RT #44579]

(bsiegert)

2017-04-13 11:46:33 UTC MAIN commitmail json YAML

Updated lang/sbcl to 1.3.16

(asau)

2017-04-13 11:35:31 UTC MAIN commitmail json YAML

Update to SBCL 1.3.16

changes in sbcl-1.3.16 relative to sbcl-1.3.15:
  * optimization: various small tweaks give around 5% faster garbage
    collection
  * bug fix: better detection of when an impossible code path does
    not need a warning.  (lp#1668619)
  * bug fix: stronger attempts to disable position-independent
    executable building.  (lp#1668986, patch from Mark Wright)
  * bug fix: OPEN :IF-EXISTS NIL signalled a condition on Windows.
    (lp#1674437, reported by Jan Idzikowski)

changes in sbcl-1.3.15 relative to sbcl-1.3.14:
  * minor incompatible change: the reader will when feasible create
    new symbols using a BASE-STRING for the print name.  Additionally,
    string literals can favor the base-string type if desired, though
    the default is to always return UTF-32 strings for compatibility.
    A preference for base-string does not disable reading Unicode.
    The choice is controlled via (SETF READTABLE-BASE-CHAR-PREFERENCE).
    If Unicode was disabled at build time, this setting does nothing.
  * enhancement: SBCL generates more debug information by default.
  * enhancement: type errors provide context information, such as which
    variable is being bound, which slot of which structure is being set.
  * enhancement: if #+immobile-symbols is in build-time *FEATURES* (not
    enabled by default), then symbols will never be moved in memory
    except by SAVE-LISP-AND-DIE. Immobility has helpful implications for
    code generation as well as interaction with foreign routines.
    This feature can only be enabled if #+immobile-space is enabled.
  * enhancement: undefined function errors can be restarted on x86-64, to
    either retry calling the function again or call a user supplied function.
  * enhancement: sb-ext:restrict-compiler-policy accepts an upper bound in
    addition to a lower bound.
  * enhancement: #+immobile-code improves the speed of function calling.
    Some delay may be noticed when redefining an existing function
    from a saved core file however.
  * defaults change: sb-ext:*disassemble-annotate* default to NIL, due to its
    poor reliability.
  * new feature: SB-LINKABLE-RUNTIME, allowing linking with extra object
    files to help with delivery of executables.  (Thanks to Francois-Rene
    Rideau)
  * bug fix: data race in GENTEMP fixed - it can no longer return the
    same interned symbol to multiple threads if called concurrently
  * bug fix: interrupting LOADing of FASLs does not leave functions without
    source locations. (lp#540276)
  * bug fix: DYNAMIC-EXTENT-declared results of NOTINLINE local functions were
    treated as if they were actually stack allocated (lp#1659964)
  * bug fix: correctly handle the case of a non-local exit within a function
    terminating the extent of dynamic-extent, dynamic-bound variables in the
    presence of multiple-values (lp#1655011)
  * bug fix: handling of SB-SYS:WITH-PINNED-OBJECTS in the interpreters (both
    sb-eval and sb-fasteval) now actually pins objects on gencgc.
  * bug fix: AVX registers are preserved during exceptions on x86-64 macOS.
  * bug fix: (directory "SOMETHING/*/**/MORE") is no longer equivalent to
    (directory "SOMETHING/**/MORE")
  * bug fix: better console IO on Windows (lp#1660906)

changes in sbcl-1.3.14 relative to sbcl-1.3.13:
  * minor incompatible change: the SB-PCL walker no longer recognizes
    macros expanding into a DECLARE expression. This is not a language change,
    since ANSI forbids such usage (X3J13 issue DECLARE-MACROS:FLUSH).
  * enhancement: for several macros such as MULTIPLE-VALUE-{BIND,SETQ}, COND,
    DO{,*,LIST}, {RESTART,HANDLER}-{BIND,CASE}, *CASE, conditions signaled
    during macroexpansion point to the form that caused the problem more
    accurately.
  * enhancement: the "--noinform" command-line option inhibits output from
    save-lisp-and-die in addition to removing the startup banner.
  * bug fix: PROCESS-KILL failed to return errno if the system call failed
  * optimization: slightly more comprehensive treatment of the keyword
    arguments to MAKE-ARRAY in compiler transformations.

changes in sbcl-1.3.13 relative to sbcl-1.3.12:
  * enhancement: SET triggers package locks on undefined variables.
    (lp#1645152)
  * enhancement: new Windows specific option to run-program, :escape-arguments
    (lp#1503496)
  * enhancement: recompiling a MAKE-INSTANCE form with an initarg :INITARG
    CONSTANT where CONSTANT names a constant variable picks up the new value
    of CONSTANT in case it has been redefined. (lp#1644944)
  * optimization: faster TYPEP on undefined at compile-time types and upcoming
    class definitions. (lp#1082967)
  * optimization: memory consumption of each STANDARD-OBJECT instance is
    reduced by 2 words if the compact-instance-header feature is enabled.
  * optimization: CONDITION instances are quicker to allocate.
  * optimization: unoptimized calls to FILL on specialized vectors are now
    just as fast as T vectors.
  * bug fix: get-timezone returns corret DST on 64-bit Windows. (lp#1641058)
  * bug fix: cross reference information in fasls is no longer incompatible
    between different cores (lp#1648186)

(asau)

2017-04-13 11:29:32 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5272 - requested by taca
net/bind910: security fix

Revisions pulled up:
- net/bind910/Makefile                                          1.32
- net/bind910/distinfo                                          1.23

---
  Module Name: pkgsrc
  Committed By: taca
  Date: Thu Apr 13 01:52:42 UTC 2017

  Modified Files:
  pkgsrc/net/bind910: Makefile distinfo

  Log Message:
  Update bind910 to 9.10.4pl8 (BIND 9.10.4-P8).

  Quote from release announce:

      BIND 9.10.4-P8 addresses the security issues described in
      CVE-2017-3136, CVE-2017-3137, and CVE-2017-3138, and updates the
      built-in trusted keys for the root zone.

  From CHANGELOG:

  --- 9.10.4-P8 released ---

  4582. [security] 'rndc ""' could trigger a assertion failure in named.
  (CVE-2017-3138) [RT #44924]

  4580. [bug] 4578 introduced a regression when handling CNAME to
  referral below the current domain. [RT #44850]

  --- 9.10.4-P7 released ---

  4578. [security] Some chaining (CNAME or DNAME) responses to upstream
  queries could trigger assertion failures.
  (CVE-2017-3137) [RT #44734]

  4575. [security] DNS64 with "break-dnssec yes;" can result in an
  assertion failure. (CVE-2017-3136) [RT #44653]

  4564. [maint] Update the built in managed keys to include the
  upcoming root KSK. [RT #44579]

(bsiegert)

2017-04-13 11:26:32 UTC MAIN commitmail json YAML

Updated comms/deforaos-phone to 0.5.1

(khorben)

2017-04-13 11:26:19 UTC MAIN commitmail json YAML

Update DeforaOS Phone to version 0.5.1

This release brings:
- parameter database for mobile data access
- additional USSD codes for T-Mobile (Germany)
- build fixes

(khorben)

2017-04-13 11:25:37 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5270 - requested by maya
audio/libsamplerate: security fix

Revisions pulled up:
- audio/libsamplerate/Makefile                                  1.26
- audio/libsamplerate/distinfo                                  1.11

---
  Module Name:    pkgsrc
  Committed By:  maya
  Date:          Wed Apr 12 18:47:39 UTC 2017

  Modified Files:
          pkgsrc/audio/libsamplerate: Makefile distinfo

  Log Message:
  libsamplerate: update to 0.1.9

  Version 0.1.9 (2016-09-23)
    * Relicense under 2 clause BSD license.
    * Minor bug fixes and upates.

  Also fixes CVE-2017-7697: global buffer overflow in calc_output_single

(bsiegert)

2017-04-13 11:22:06 UTC MAIN commitmail json YAML

Listen on localhost by default.  Patch from plluksie in joyent/pkgsrc#482.

(jperkin)

2017-04-13 11:20:21 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5269 - requested by sevan
multimedia/adobe-flash-player: security fix

Revisions pulled up:
- multimedia/adobe-flash-player/Makefile                        1.3
- multimedia/adobe-flash-player/distinfo                        1.3

---
  Module Name:    pkgsrc
  Committed By:  tsutsui
  Date:          Wed Apr 12 15:31:13 UTC 2017

  Modified Files:
          pkgsrc/multimedia/adobe-flash-player: Makefile distinfo

  Log Message:
  Update adobe-flash-player to 25.0.0.148.

  Upstream announcements:

    https://helpx.adobe.com/security/products/flash-player/apsb17-10.html

  Adobe Security Bulletin

  Security updates available for Adobe Flash Player

  Release date: April 11, 2017

  Vulnerability identifier: APSB17-10

  CVE number: CVE-2017-3058, CVE-2017-3059, CVE-2017-3060, CVE-2017-3061,
    CVE-2017-3062, CVE-2017-3063, CVE-2017-3064

  Platform: Windows, Macintosh, Linux and Chrome OS

(bsiegert)

2017-04-13 11:15:41 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5243 (second part) - requested by sevan
(various packages): build fix

Revisions pulled up:
- benchmarks/phoronix-test-suite/Makefile                      1.8
- finance/magento/Makefile                                      1.9
- mail/roundcube/Makefile                                      1.87
- meta-pkgs/php56-extensions/Makefile                          1.7
- meta-pkgs/php70-extensions/Makefile                          1.2
- meta-pkgs/php71-extensions/Makefile                          1.2
- mk/defaults/options.description                              1.526
- net/php-baikal/Makefile                                      1.10
- textproc/php-xsl/MESSAGE                                      deleted
- textproc/php-xsl/Makefile                                    1.10
- www/contao35/Makefile                                        1.28
- www/contao43/Makefile                                        1.10
- www/drupal7/Makefile                                          1.44
- www/drupal7/options.mk                                        1.4
- www/fengoffice/Makefile                                      1.38
- www/horde/Makefile                                            1.81
- www/mediawiki/Makefile                                        1.63
- www/moodle/Makefile                                          1.55
- www/php-concrete5/MESSAGE                                    1.8
- www/php-concrete5/Makefile                                    1.16
- www/php-nextcloud/MESSAGE                                    1.2
- www/php-nextcloud/Makefile                                    1.4
- www/php-owncloud/MESSAGE                                      1.20
- www/php-owncloud/Makefile                                    1.63
- www/php-tt-rss/MESSAGE                                        1.6
- www/php-tt-rss/Makefile                                      1.11
- www/phraseanet/MESSAGE                                        1.4
- www/phraseanet/Makefile                                      1.20

---
  Module Name:    pkgsrc
  Committed By:  fhajny
  Date:          Wed Apr  5 12:33:49 UTC 2017

  Modified Files:
          pkgsrc/benchmarks/phoronix-test-suite: Makefile
          pkgsrc/finance/magento: Makefile
          pkgsrc/mail/roundcube: Makefile
          pkgsrc/meta-pkgs/php56-extensions: Makefile
          pkgsrc/meta-pkgs/php70-extensions: Makefile
          pkgsrc/meta-pkgs/php71-extensions: Makefile
          pkgsrc/mk/defaults: options.description
          pkgsrc/net/php-baikal: Makefile
          pkgsrc/textproc/php-xsl: Makefile
          pkgsrc/www/contao35: Makefile
          pkgsrc/www/contao43: Makefile
          pkgsrc/www/drupal7: Makefile options.mk
          pkgsrc/www/fengoffice: Makefile
          pkgsrc/www/horde: Makefile
          pkgsrc/www/mediawiki: Makefile
          pkgsrc/www/moodle: Makefile
          pkgsrc/www/php-concrete5: MESSAGE Makefile
          pkgsrc/www/php-nextcloud: MESSAGE Makefile
          pkgsrc/www/php-owncloud: MESSAGE Makefile
          pkgsrc/www/php-tt-rss: MESSAGE Makefile
          pkgsrc/www/phraseanet: MESSAGE Makefile
  Removed Files:
          pkgsrc/textproc/php-xsl: MESSAGE

  Log Message:
  Remove traces of textproc/php-dom which is not needed anymore, now that
  dom is built into PHP. Bump resp. PKGREVISION.

(bsiegert)

2017-04-13 11:10:08 UTC MAIN commitmail json YAML

Updated audio/deforaos-mixer to 0.2.2

(khorben)

2017-04-13 11:09:21 UTC MAIN commitmail json YAML

Update DeforaOS Mixer to version 0.2.2

This release brings:
- license switch to BSD
- build fix for embedded mode
- minor improvements

(khorben)

2017-04-13 10:17:25 UTC MAIN commitmail json YAML

Add a bunch more compatibility defines.  Fixes SunOS.

(jperkin)

2017-04-13 09:40:37 UTC MAIN commitmail json YAML

Don't assume _BIG_ENDIAN and _LITTLE_ENDIAN have values.  Fixes SunOS.

(jperkin)

2017-04-13 06:45:16 UTC MAIN commitmail json YAML

2017-04-13 04:29:05 UTC MAIN commitmail json YAML

Fix PLIST for the nls option: he_IL.UTF-8 was missing

(pho)

2017-04-13 03:21:44 UTC MAIN commitmail json YAML

Updated devel/nss to 3.30.1

(ryoon)

2017-04-13 03:21:05 UTC MAIN commitmail json YAML

Update to 3.30.1

Changelog:
Not available.

(ryoon)

2017-04-13 02:03:30 UTC MAIN commitmail json YAML

Note update of dovecot2 and related pacakges:

mail/dovecot2 2.2.29.1
mail/dovecot2-gssapi 2.2.29.1
mail/dovecot2-ldap 2.2.29.1
mail/dovecot2-mysql 2.2.29.1
mail/dovecot2-pgsql 2.2.29.1
mail/dovecot2-sqlite 2.2.29.1
mail/dovecot2-pigeonhole 0.4.18

(taca)

2017-04-13 02:00:44 UTC MAIN commitmail json YAML

Update dovecot2-pigeonhole to 0.4.18 for dovecot2 2.2.28.

v0.4.18 12-04-2017 Stephan Bosch <stephan@rename-it.nl>

+ imapsieve plugin: Implemented the copy_source_after rule action. When this
  is enabled for a mailbox rule, the specified Sieve script is executed for
  the message in the source mailbox during a "COPY" event. This happens only
  after the Sieve script that is executed for the corresponding message in the
  destination mailbox finishes running successfully.
+ imapsieve plugin: Added non-standard Sieve environment items for the source
  and destination mailbox.
- multiscript: The execution of the discard script had an implicit "keep",
  rather than an implicit "discard".

(taca)

2017-04-13 01:59:08 UTC MAIN commitmail json YAML

Update dovecot2 to 2.2.29.1.  This release contains security fixes.

v2.2.29.1 2017-04-12  Timo Sirainen <tss@iki.fi>

- imapc reconnection fix was forgotten from 2.2.29 release, which also
  made "make check" fail in a unit test
- dict-sql: Merging multiple UPDATEs to a single statement wasn't
  actually working.
- Fixed building with vpopmail

v2.2.29 2017-04-10  Timo Sirainen <tss@iki.fi>

* passdb/userdb dict: Don't double-expand %variables in keys. If dict
  was used as the authentication passdb, using specially crafted
  %variables in the username could be used to cause DoS (CVE-2017-2669)
* When Dovecot encounters an internal error, it logs the real error and
  usually logs another line saying what function failed. Previously the
  second log line's error message was a rather uninformative "Internal
  error occurred. Refer to server log for more information." Now the
  real error message is duplicated in this second log line.
* lmtp: If a delivery has multiple recipients, run autoexpunging only
  for the last recipient. This avoids a problem where a long
  autoexpunge run causes LMTP client to timeout between the DATA
  replies, resulting in duplicate mail deliveries.
* config: Don't stop the process due to idling. Otherwise the
  configuration is reloaded when the process restarts.
* mail_log plugin: Differentiate autoexpunges from regular expunges
* imapc: Use LOGOUT to cleanly disconnect from server.
* lib-http: Internal status codes (>9000) are no longer visible in logs
* director: Log vhost count changes and HOST-UP/DOWN

+ quota: Add plugin { quota_max_mail_size } setting to limit the
  maximum individual mail size that can be saved.
+ imapc: Add imapc_features=delay-login. If set, connecting to the
  remote IMAP server isn't done until it's necessary.
+ imapc: Add imapc_connection_retry_count and
  imapc_connection_retry_interval settings.
+ imap, pop3, indexer-worker: Add (deinit) to process title before
  autoexpunging runs.
+ Added %{encrypt} and %{decrypt} variables
+ imap/pop3 proxy: Log proxy state in errors as human-readable string.
+ imap/pop3-login: All forward_* extra fields returned by passdb are
  sent to the next hop when proxying using ID/XCLIENT commands. On the
  receiving side these fields are imported and sent to auth process
  where they're accessible via %{passdb:forward_*}. This is done only
  if the sending IP address matches login_trusted_networks.
+ imap-login: If imap_id_retain=yes, send the IMAP ID string to
  auth process. %{client_id} expands to it in auth process. The ID
  string is also sent to the next hop when proxying.
+ passdb imap: Use ssl_client_ca_* settings for CA validation.
- fts-tika: Fixed crash when parsing attachment without
  Content-Disposition header. Broken by 2.2.28.
- trash plugin was broken in 2.2.28
- auth: When passdb/userdb lookups were done via auth-workers, too much
  data was added to auth cache. This could have resulted in wrong
  replies when using multiple passdbs/userdbs.
- auth: passdb { skip & mechanisms } were ignored for the first passdb
- oauth2: Various fixes, including fixes to crashes
- dsync: Large Sieve scripts (or other large metadata) weren't always
  synced.
- Index rebuild (e.g. doveadm force-resync) set all mails as \Recent
- imap-hibernate: %{userdb:*} wasn't expanded in mail_log_prefix
- doveadm: Exit codes weren't preserved when proxying commands via
  doveadm-server. Almost all errors used exit code 75 (tempfail).
- ACLs weren't applied to not-yet-existing autocreated mailboxes.
- Fixed a potential crash when parsing a broken message header.
- cassandra: Fallback consistency settings weren't working correctly.
- doveadm director status <user>: "Initial config" was always empty
- imapc: Various reconnection fixes.

(taca)

2017-04-13 01:54:28 UTC MAIN commitmail json YAML

Note update of BIND packages:

net/bind910 9.10.4pl8
net/bind99 9.9.9pl8

(taca)

2017-04-13 01:53:35 UTC MAIN commitmail json YAML

Update bind99 to 9.9.9pl8 (BIND 9.9.9-P8).

Quote from release announce:

  BIND 9.9.9-P8 addresses the security issues described in CVE-2017-3136,
  CVE-2017-3137, and CVE-2017-3138, and updates the built-in trusted keys
  for the root zone.

Quote from CHANGELOG:

--- 9.9.9-P8 released ---

4582. [security] 'rndc ""' could trigger a assertion failure in named.
(CVE-2017-3138) [RT #44924]

4580. [bug] 4578 introduced a regression when handling CNAME to
referral below the current domain. [RT #44850]

--- 9.9.9-P7 released ---

4578. [security] Some chaining (CNAME or DNAME) responses to upstream
queries could trigger assertion failures.
(CVE-2017-3137) [RT #44734]

4575. [security] DNS64 with "break-dnssec yes;" can result in an
assertion failure. (CVE-2017-3136) [RT #44653]

4564. [maint] Update the built in managed keys to include the
upcoming root KSK. [RT #44579]

(taca)

2017-04-13 01:52:42 UTC MAIN commitmail json YAML

Update bind910 to 9.10.4pl8 (BIND 9.10.4-P8).

Quote from release announce:

  BIND 9.10.4-P8 addresses the security issues described in
  CVE-2017-3136, CVE-2017-3137, and CVE-2017-3138, and updates the
  built-in trusted keys for the root zone.

>From CHANGELOG:

--- 9.10.4-P8 released ---

4582. [security] 'rndc ""' could trigger a assertion failure in named.
(CVE-2017-3138) [RT #44924]

4580. [bug] 4578 introduced a regression when handling CNAME to
referral below the current domain. [RT #44850]

--- 9.10.4-P7 released ---

4578. [security] Some chaining (CNAME or DNAME) responses to upstream
queries could trigger assertion failures.
(CVE-2017-3137) [RT #44734]

4575. [security] DNS64 with "break-dnssec yes;" can result in an
assertion failure. (CVE-2017-3136) [RT #44653]

4564. [maint] Update the built in managed keys to include the
upcoming root KSK. [RT #44579]

(taca)

2017-04-13 01:00:23 UTC MAIN commitmail json YAML

Updated x11/deforaos-keyboard to 0.3.1

(khorben)

2017-04-13 01:00:09 UTC MAIN commitmail json YAML

Updated x11/deforaos-libdesktop to 0.2.2

(khorben)

2017-04-13 00:59:37 UTC MAIN commitmail json YAML

Update DeforaOS Keyboard to version 0.3.1

This release brings:
- license update to BSD
- fix for widget mode

(khorben)

2017-04-13 00:48:38 UTC MAIN commitmail json YAML

Update DeforaOS libDesktop to version 0.2.2

This release brings:
- support for SOURCE_DATE_EPOCH in tests
- minor fixes and improvements

(khorben)

2017-04-13 00:42:21 UTC MAIN commitmail json YAML

Updated devel/deforaos-libsystem to 0.3.1

(khorben)

2017-04-13 00:41:02 UTC MAIN commitmail json YAML

Update DeforaOS libSystem to version 0.3.1

This release brings:
- build fixes with OBJDIR
- minor API update in <System/string.h>
- support for SOURCE_DATE_EPOCH in tests
- minor fixes and improvements

(khorben)

2017-04-12 18:48:39 UTC MAIN commitmail json YAML

Note libsamplerate.

(maya)

2017-04-12 18:47:39 UTC MAIN commitmail json YAML

libsamplerate: update to 0.1.9

Version 0.1.9 (2016-09-23)
  * Relicense under 2 clause BSD license.
  * Minor bug fixes and upates.

Also fixes CVE-2017-7697: global buffer overflow in calc_output_single

(maya)

2017-04-12 18:22:20 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5243 - requested by sevan
lang/php56: build fix
lang/php70: build fix
lang/php71: build fix

Revisions pulled up:
- lang/php56/Makefile                                          1.13
- lang/php56/Makefile.php                                      1.2
- lang/php56/PLIST                                              1.3
- lang/php56/distinfo                                          1.41
- lang/php56/patches/patch-ext_xsl_php__xsl.h                  1.1
- lang/php70/Makefile                                          1.6
- lang/php70/Makefile.php                                      1.3
- lang/php70/PLIST                                              1.3
- lang/php70/distinfo                                          1.31
- lang/php70/patches/patch-ext_xsl_php__xsl.h                  1.1
- lang/php71/Makefile                                          1.9
- lang/php71/Makefile.php                                      1.2
- lang/php71/PLIST                                              1.3
- lang/php71/distinfo                                          1.17
- lang/php71/patches/patch-ext_xsl_php__xsl.h                  1.1
- textproc/Makefile                                            1.918
- textproc/php-dom/DESCR                                        deleted
- textproc/php-dom/Makefile                                    deleted

---
  Module Name:    pkgsrc
  Committed By:  fhajny
  Date:          Wed Apr  5 12:28:59 UTC 2017

  Modified Files:
          pkgsrc/lang/php56: Makefile Makefile.php PLIST distinfo
          pkgsrc/lang/php70: Makefile Makefile.php PLIST distinfo
          pkgsrc/lang/php71: Makefile Makefile.php PLIST distinfo
  Added Files:
          pkgsrc/lang/php56/patches: patch-ext_xsl_php__xsl.h
          pkgsrc/lang/php70/patches: patch-ext_xsl_php__xsl.h
          pkgsrc/lang/php71/patches: patch-ext_xsl_php__xsl.h

  Log Message:
  Build the dom extension embedded. This enables full functionality in xmlreader and fixes joyent/pkgsrc/issues/477. Bump PKREVISION.

---
  Module Name:    pkgsrc
  Committed By:  fhajny
  Date:          Wed Apr  5 12:34:47 UTC 2017

  Modified Files:
          pkgsrc/textproc: Makefile
  Removed Files:
          pkgsrc/textproc/php-dom: DESCR Makefile

  Log Message:
  Remove textproc/php-dom, the module is now built into the resp. PHP packages.

(bsiegert)

2017-04-12 17:46:07 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5247 - requested by sevan
pkgtools/pkglint: bugfix

Revisions pulled up:
- pkgtools/pkglint/Makefile                                    1.513
- pkgtools/pkglint/files/vardefs.go                            1.23

---
  Module Name:    pkgsrc
  Committed By:  rillig
  Date:          Wed Apr  5 19:17:19 UTC 2017

  Modified Files:
          pkgsrc/pkgtools/pkglint: Makefile
          pkgsrc/pkgtools/pkglint/files: vardefs.go

  Log Message:
  Updated pkglint to 5.4.20.

  Changes since 5.4.19:
  * Updated allowed Python versions to include py36.

(bsiegert)

2017-04-12 17:29:41 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5241 - requested by sevan
www/serf: build fix

Revisions pulled up:
- www/serf/Makefile                                            1.37

---
  Module Name:    pkgsrc
  Committed By:  gdt
  Date:          Tue Apr  4 23:40:06 UTC 2017

  Modified Files:
          pkgsrc/www/serf: Makefile

  Log Message:
  Fix permissions after extraction

  The upstream distfile incorrectly has world-writable files.

(bsiegert)

2017-04-12 15:32:03 UTC MAIN commitmail json YAML

Updated multimedia/adobe-flash-player to 25.0.0.148

(tsutsui)

2017-04-12 15:31:13 UTC MAIN commitmail json YAML

Update adobe-flash-player to 25.0.0.148.

Upstream announcements:

https://helpx.adobe.com/security/products/flash-player/apsb17-10.html

Adobe Security Bulletin

Security updates available for Adobe Flash Player

Release date: April 11, 2017

Vulnerability identifier: APSB17-10

CVE number: CVE-2017-3058, CVE-2017-3059, CVE-2017-3060, CVE-2017-3061,
CVE-2017-3062, CVE-2017-3063, CVE-2017-3064

Platform: Windows, Macintosh, Linux and Chrome OS

(tsutsui)

2017-04-12 14:33:29 UTC pkgsrc-2017Q1 commitmail json YAML

Retroactively record the first batch of pullup tickets.

(bsiegert)

2017-04-12 13:25:24 UTC MAIN commitmail json YAML

Updated www/vimb to 2.12

(leot)

2017-04-12 13:25:11 UTC MAIN commitmail json YAML

Update www/vimb to 2.12

Changes:
## 2.12 - 2017-04-11
### Added
* Queueing of key events - fixes swalled chars in case of some imap bindings
  #258 (thanks to Michael Mackus)
* Allow to disable xembed by `FEATURE_NO_XEMBED` to compile on wayland only
  platforms (thanks to Patrick Steinhardt)
* Custom default_zoom setting disables HIGH_DPI logic (thanks to Robert Timm)
* Allow link activation from search result via `<CR>` #131

### Changed
* Allow shortcuts without parameters #329
* Write soup cache to disk after each page load to allow other instances to
  pick this up.
* Use the beginning position of links for hinting (thanks to Yutao Yuan)

### Fixed
* Fix path expansion to accept only valid POSIX.1-2008 usernames (thanks to
  Manzur Mukhitdinov)
* Fix default previouspattern (thanks to Nicolas Porcel)

Please note that this is the last release of the vimb for WebKit1. WebKit1 is not
supported anymore and is considered unsecure.
So this release is a way to end the WebKit1 version of vimb gracefully.
I hope the WebKit2 branch will be in alpha state soon. Hope some developer
will help to migrate the known features to the new WebKit2 process model.
Help is appreciated.

(leot)

2017-04-12 13:17:35 UTC MAIN commitmail json YAML

Updated devel/p5-Path-FindDev to 0.5.3

(wen)

2017-04-12 13:16:15 UTC MAIN commitmail json YAML

2017-04-12 13:09:18 UTC MAIN commitmail json YAML

Update to 0.5.3

Upstream changes:
v0.5.3 2017-03-10T07:02:09Z c9c9198
- Bugfix: Avoid test failures due to -Ddefault_inc_excludes_dot
- Add "v" to version due to upstream requirements
- Tests made more portable to older Test::More

(wen)

2017-04-12 13:04:38 UTC MAIN commitmail json YAML

Updated print/zathura-pdf-mupdf to 0.3.1nb4

(leot)

2017-04-12 13:04:21 UTC MAIN commitmail json YAML

Bump PKGREVISION for mupdf-1.11 update

(leot)

2017-04-12 13:03:24 UTC MAIN commitmail json YAML

Updated print/mupdf to 1.11

(leot)

2017-04-12 13:03:09 UTC MAIN commitmail json YAML

Update print/mupdf to 1.11

Changes:
List of changes in MuPDF 1.11
-----------------------------
* This is primarily a bug fix release.
* Split Android and iOS viewers into separate projects:
  - mupdf-viewer-ios.git has the iOS viewer.
  - mupdf-viewer-android-old.git has the Android viewer.
  - mupdf-viewer-android-nui.git has a new advanced Android viewer.
  - mupdf-viewer-android-mini.git has a new minimalist Android viewer.
* PDF portfolio support with command line tool "mutool portfolio".
* Add callbacks to load fallback fonts from the system.
* Use system fonts in Android to reduce install size.
* Flag to disable publisher styles in EPUB layout.
* Improved SVG output.

(leot)

2017-04-12 12:57:18 UTC MAIN commitmail json YAML

Fix build, spotted by joerg@

(wen)

2017-04-12 12:57:03 UTC MAIN commitmail json YAML

Updated graphics/glfw to 3.2.1

(leot)

2017-04-12 12:56:46 UTC MAIN commitmail json YAML

Update graphics/glfw to 3.2.1

Changes:
3.2.1
=====
Vulkan improvements
-------------------
Add support for statically linking the Vulkan loader

Misc improvements and bug fixes
-------------------------------
Fixes for a number of bugs that together affect all supported platforms.

3.2
===
Support for Vulkan
------------------
GLFW now supports basic integration with Vulkan with glfwVulkanSupported,
glfwGetRequiredInstanceExtensions, glfwGetInstanceProcAddress,
glfwGetPhysicalDevicePresentationSupport and glfwCreateWindowSurface.
Vulkan header inclusion can be selected with
GLFW_INCLUDE_VULKAN.

Window mode switching
---------------------
GLFW now supports switching between windowed and full screen modes and updating
the monitor and desired resolution and refresh rate of full screen windows with
glfwSetWindowMonitor.

Window maxmimization support
----------------------------
GLFW now supports window maximization with glfwMaximizeWindow and the
GLFW_MAXIMIZED hint and attribute.

Window input focus control
--------------------------
GLFW now supports giving windows input focus with glfwFocusWindow.

Window size limit support
-------------------------
GLFW now supports setting both absolute and relative window size limits with
glfwSetWindowSizeLimits and glfwSetWindowAspectRatio.

Localized key names
-------------------
GLFW now supports querying the localized name of printable keys with
glfwGetKeyName, either by key token or by scancode.

Wait for events with timeout
----------------------------
GLFW now supports waiting for events for a set amount of time with
glfwWaitEventsTimeout.

Window icon support
-------------------
GLFW now supports setting the icon of windows with glfwSetWindowIcon.

Raw timer access
----------------
GLFW now supports raw timer values with glfwGetTimerValue and
glfwGetTimerFrequency.

Joystick connection callback
----------------------------
GLFW now supports notifying when a joystick has been connected or disconnected
with glfwSetJoystickCallback.

Context-less windows
--------------------
GLFW now supports creating windows without a OpenGL or OpenGL ES context with
GLFW_NO_API.

Run-time context creation API selection
---------------------------------------
GLFW now supports selecting the context creation API at run-time with the
GLFW_CONTEXT_CREATION_API window hint value.

Error-free context creation
---------------------------
GLFW now supports creating OpenGL and OpenGL ES contexts that do not emit errors
with the GLFW_CONTEXT_NO_ERROR window hint, provided
the machine supports the `GL_KHR_no_error` extension.

CMake config-file package support
---------------------------------
GLFW now supports being used as a
config-file package from other projects for
easy linking with the library and its dependencies.

(leot)

2017-04-12 12:01:25 UTC MAIN commitmail json YAML

Added devel/py-blessings version 1.6; devel/py-curtsies version 0.2.11. Updated devel/py-greenlet to 0.4.12; devel/bpython to 0.16.

(adam)

2017-04-12 12:00:36 UTC MAIN commitmail json YAML

Changes 0.16

New features:
* 466: Improve handling of completion box height.

Fixes:
* Fix various spelling mistakes.
* 601: Fix Python 2 issues on Windows.
* 614: Fix issues when view source.
* 625: Fix issues when runnings scripts with non-ASCII characters.
* 639: Fix compatbility issues with pdb++.

Support for Python 2.6 has been dropped.

(adam)

2017-04-12 11:49:06 UTC MAIN commitmail json YAML

Restore build dependency on p5-File-ShareDir-Install, spotted by wiz@.

(schmonz)

2017-04-12 11:44:20 UTC MAIN commitmail json YAML

Added devel/py-blessings version 1.6; devel/py-curtsies version 0.2.11

(adam)

2017-04-12 11:42:45 UTC MAIN commitmail json YAML

Curtsies is a Python 2.6+ & 3.3+ compatible library for interacting with
the terminal.

FmtStr objects are strings formatted with colors and styles displayable in
a terminal with ANSI escape sequences. FSArray objects contain multiple such
strings with each formatted string on its own row, and can be superimposed
onto each other to build complex grids of colored and styled characters.

Such grids of characters can be efficiently rendered to the terminal in
alternate screen mode (no scrollback history, like Vim, top etc.) by
FullscreenWindow objects or to the normal history-preserving screen by
CursorAwareWindow objects. User keyboard input events like pressing the up
arrow key are detected by an Input object. See the Quickstart to get started
using all of these classes.

(adam)

2017-04-12 11:41:44 UTC MAIN commitmail json YAML

Blessings lifts several of curses' limiting assumptions, and it makes your
code pretty, too:
* Use styles, color, and maybe a little positioning without necessarily
  clearing the whole screen first.
* Leave more than one screenful of scrollback in the buffer after your program
  exits, like a well-behaved command-line app should.
* Get rid of all those noisy, C-like calls to tigetstr and tparm, so your code
  doesn't get crowded out by terminal bookkeeping.
* Act intelligently when somebody redirects your output to a file, omitting
  the terminal control codes the user doesn't want to see (optional).

(adam)

2017-04-12 11:40:08 UTC MAIN commitmail json YAML

2017-04-12 11:27:03 UTC MAIN commitmail json YAML

Updated lang/nodejs to 7.9.0

(fhajny)

2017-04-12 11:26:52 UTC MAIN commitmail json YAML

Update lang/nodejs to 7.9.0.

- util: console is now closer to what is supported in all major browsers

(fhajny)

2017-04-12 02:49:24 UTC MAIN commitmail json YAML

Updated time/p5-DateTime-Locale to 1.16nb1

(schmonz)

2017-04-12 02:49:10 UTC MAIN commitmail json YAML

Fix dependency on File::ShareDir. Bump PKGREVISION.

(schmonz)

2017-04-11 20:50:05 UTC MAIN commitmail json YAML

Updated devel/cmake to 3.8.0; databases/mysql56 to 5.6.36; databases/mysql57 to 5.7.18

(adam)

2017-04-11 20:49:15 UTC MAIN commitmail json YAML

Changes 5.7.18:
* Windows builds now use the default runtime libraries (builds use the /MD flag).
* CMake support was added for compiling with Developer Studio 12.6.
* MySQL failed to compile if -DENABLE_DEBUG_SYNC=OFF AND -DWITH_DEBUG=ON were both given. The ENABLE_DEBUG_SYNC option has been removed and enabling WITH_DEBUG enables Debug Sync.
* The --temp-pool server option is deprecated and will be removed in MySQL 8.0.
* Support for DTrace is deprecated and is removed in MySQL 8.0.
* Changes in RPM package structure require a larger set of packages to be removed to install MySQL Server cleanly.
* To avoid potential race conditions, Debian packages now use the GNU install utility rather than a combination of mkdir, touch, and chown.
* The my-default.cnf.sh file (used to produce a default my-default.cnf or my-default.ini file) is no longer included in source distributions and my-default.cnf and my-default.ini are no longer included in or installed by distribution packages.
* Reminder: MySQL 5.7 requires the Microsoft Visual C++ 2013 Redistributable Package to run on Windows platforms. Users should make sure the package has been installed on the system before starting the server. The package is available at the Microsoft Download Center.
* PROCEDURE ANALYSE() syntax is now deprecated and is removed in MySQL 8.0.
* The use of \N as a synonym for NULL in SQL statements is deprecated and is removed in MySQL 8.0. Use NULL instead.
* The linked OpenSSL library for the MySQL Commercial Server has been updated to version 1.0.2k.

(adam)

2017-04-11 20:21:03 UTC MAIN commitmail json YAML

Changes 5.6.36:
* Windows builds now use the default runtime libraries (builds use the /MD flag).
* CMake support was added for compiling with Developer Studio 12.6.
MySQL failed to compile if -DENABLE_DEBUG_SYNC=OFF AND -DWITH_DEBUG=ON were both given. The ENABLE_DEBUG_SYNC option has been removed and enabling WITH_DEBUG enables Debug Sync.
* Changes in RPM package structure require a larger set of packages to be removed to install MySQL Server cleanly.
* To avoid potential race conditions, Debian packages now use the GNU install utility rather than a combination of mkdir, touch, and chown.
* CMake-generated packaging for Debian/Ubuntu packages was refactored for improved maintainability. The change includes updated logic for correctly replacing native distribution packaging in Debian and Ubuntu.
* Reminder: MySQL 5.6 requires the Microsoft Visual C++ 2010 Redistributable Package to run on Windows platforms. Users should make sure the package has been installed on the system before starting the server. The package is available at the Microsoft Download Center.
* The linked OpenSSL library for the MySQL Commercial Server has been updated to version 1.0.2k. For a description of issues fixed in this version, see http://www.openssl.org/news/vulnerabilities.html.
* The mysql_options() C API function now supports a MYSQL_OPT_SSL_MODE option.

(adam)

2017-04-11 20:18:54 UTC MAIN commitmail json YAML

Changes 3.8.0:
CMake learned to support CSharp (C#) as a first-class language that can be enabled via the project() and enable_language() commands. It is currently supported by the Visual Studio Generators for VS 2010 and above.

C# assemblies and programs can be added just like common C++ targets using the add_library() and add_executable() commands. References between C# targets in the same source tree may be specified by target_link_libraries() like for C++. References to system or 3rd-party assemblies may be specified by the target properties VS_DOTNET_REFERENCE_<refname> and VS_DOTNET_REFERENCES.

More fine tuning of C# targets may be done using target and source file properties. Specifically the target properties related to Visual Studio (VS_*) are worth a look (for setting toolset versions, root namespaces, assembly icons, ...).

CMake learned to support CUDA as a first-class language that can be enabled via the project() and enable_language() commands.
CUDA is currently supported by the Makefile Generators and the Ninja generator on Linux, macOS, and Windows. Support for the Visual Studio IDE is under development but not included in this release.
The NVIDIA CUDA Toolkit compiler (nvcc) is supported.

The Compile Features functionality now offers meta-features that request compiler modes for specific language standard levels (e.g. cxx_std_11). See CMAKE_C_KNOWN_FEATURES and CMAKE_CXX_KNOWN_FEATURES.
The Compile Features functionality is now aware of C++ 17. No specific features are yet enumerated besides the cxx_std_17 meta-feature.
The Compile Features functionality is now aware of the availability of C99 in gcc since version 3.4.

A new minimal platform file for Fuchsia was added.

The CodeBlocks extra generator may now be used to generate with NMake Makefiles JOM.
The Visual Studio Generators for VS 2013 and above learned to support a host=x64 option in the CMAKE_GENERATOR_TOOLSET value (e.g. via the cmake(1) -T option) to request use of a VS 64-bit toolchain on 64-bit hosts.
The Visual Studio Generators learned to treat files passed to target_link_libraries() whose names end in .targets as MSBuild ���targets��� files to be imported into generated project files.

...more...

(adam)

2017-04-11 18:38:18 UTC MAIN commitmail json YAML

Updated textproc/p5-XML-Feed to 0.53nb2

(schmonz)

2017-04-11 18:38:11 UTC MAIN commitmail json YAML

Promote p5-{HTML-Parser,libwww} to runtime DEPENDS to match META.json.
Bump PKGREVISION.

(schmonz)

2017-04-11 15:18:24 UTC MAIN commitmail json YAML

Updated databases/mysql55-client to 5.5.55

(mef)

2017-04-11 15:18:12 UTC MAIN commitmail json YAML

Updated databases/mysql55-{client,server} to 5.5.55
---------------------------------------------------
Picks securiy part from
  https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-55.html
-----
Security Notes

  The mysql_options() C API function now supports a
MYSQL_OPT_SSL_MODE option. The only permitted option value is
SSL_MODE_REQUIRED, to require a secure connection to the server. It
causes mysql_real_connect() to fail if an encrypted connection cannot
be obtained, without falling back to an unencrypted connection. Thus,
mysql_real_connect() returns an error if the server does not support
SSL or the client is not configured to use SSL. The client/server
exchange terminates immediately after the initial server packet has
been received if the server indicates that it does not support SSL.

  To require an encrypted connection in MySQL 5.5, the standard MySQL
client programs call mysql_options() to set MYSQL_OPT_SSL_MODE if the
--ssl-mode=REQUIRED command-line option was specified. Third-party
applications that must be able to require encrypted connections can
use the same technique. For details, see mysql_ssl_set().

  The minor C API version number was not incremented for this
change. Application programs compiled for MySQL 5.5 that require
MYSQL_OPT_SSL_MODE may fail to operate properly if the dynamic loader
provides an older client library without MYSQL_OPT_SSL_MODE. Such
applications must be written to handle this possibility by checking
whether the mysql_options() call succeeds or fails. (Bug #25575605)

(mef)

2017-04-11 14:23:48 UTC MAIN commitmail json YAML

Updated archivers/zstd to 1.1.4

(mef)

2017-04-11 14:23:35 UTC MAIN commitmail json YAML

Update archivers/zstd to 1.1.4
-------------------------------
v1.1.4
cli : new : can compress in *.gz format, using --format=gzip command, by
      Przemyslaw Skibinski
cli : new : advanced benchmark command --priority=rt
cli : fix : write on sparse-enabled file systems in 32-bits mode, by @ds77
cli : fix : --rm remains silent when input is stdin
cli : experimental : xzstd, with support for xz/lzma decoding, by Przemyslaw
      Skibinski
speed : improved decompression speed in streaming mode for single shot scenarios (+5%)
memory : DDict (decompression dictionary) memory usage down from 150 KB to 20 KB
arch : 32-bits variant able to generate and decode very long matches (>32 MB),
      by Sean Purcell
API : new : ZSTD_findFrameCompressedSize(),
      ZSTD_getFrameContentSize(), ZSTD_findDecompressedSize()
API : changed : dropped support of legacy versions <= v0.3 (can be changed by
      modifying ZSTD_LEGACY_SUPPORT value)
build: new: meson build system in contrib/meson, by Dima Krasner
build: improved cmake script, by @Majlen
build: added -Wformat-security flag, as recommended by Padraig Brady
doc : new : educational decoder, by Sean Purcell

(pkgsrc changes)
+ MAKE_JOBS_SAFE= no

(mef)

2017-04-11 14:04:38 UTC MAIN commitmail json YAML

If qmailqread runs on a custom host and port, have qmail-qread-client
find it there. Bump version.

(schmonz)

2017-04-11 14:00:57 UTC MAIN commitmail json YAML

Updated devel/p5-Devel-CheckLib to 1.10nb1

(schmonz)

2017-04-11 14:00:50 UTC MAIN commitmail json YAML

2017-04-11 13:48:45 UTC MAIN commitmail json YAML

Updated archivers/p5-Compress-Bzip2 to 2.26
Updated archivers/advancecomp to 1.23

(mef)

2017-04-11 13:47:08 UTC MAIN commitmail json YAML

Updated archivers/advancecomp 1.19 to 1.23
------------------------------------------
ADVANCECOMP VERSION 1.23 2016/11
================================
* Fixed build issue from source code due missing libdeflate header.

ADVANCECOMP VERSION 1.22 2016/11
================================
* Enabled again the command line wildcard expansion in the Windows
  builds. The new MingW compiler was disabling it by default.

ADVANCECOMP VERSION 1.21 2016/11
================================
* Added libdeflate support. It's the new default because it provides
  better performance and compression than 7z.
  From https://github.com/ebiggers/libdeflate
  at commit 28cc14994b8b57f590d31a7340c8fffc5cc37d88
* Update to te latest zopfli library.
  From https://github.com/google/zopfli
  at commit 6818a0859063b946094fb6f94732836404a0d89a.
* Windows binaries built with MingW 4.9.3 using the MXE cross compiler at
  commit 62bcdbee56e87c81f1faa105b8777a5879d4e2e with targets
  i686-w64-mingw32 and x86_64-w64-mingw32.
* DOS binaries built with DJGPP 4.8.5 from
  https://github.com/andrewwutw/build-djgpp

ADVANCECOMP VERSION 1.20 2015/08
================================
* Fixed .gz recompression of data bigger than 400 MB.
* Fixed .gz recompression with -0 and -1 options.
* Updated to the latest zopfli [Aaron Kaluszka].
* Preserve the EFS flag in .zip files [Jason Penney].

(mef)

2017-04-11 13:43:58 UTC MAIN commitmail json YAML

Updated archivers/p5-Compress-Bzip2 to 2.26
-------------------------------------------
2.26 2017-04-10 rurban
  - . in @INC test fixes for perl5.26 (RT #121020)

(mef)

2017-04-11 10:31:14 UTC MAIN commitmail json YAML

2017-04-11 09:33:30 UTC MAIN commitmail json YAML

Fix installation on Darwin:
LD_LIBRARY_PATH is not propagated when set with env, e.g.:
env LD_LIBRARY_PATH=path/to/lib ./script.sh
will not work (other variable names work correctly).

(adam)

2017-04-11 07:12:15 UTC MAIN commitmail json YAML

Updated x11/libdrm to 2.4.79

(wiz)

2017-04-11 07:12:02 UTC MAIN commitmail json YAML

This libdrm-2.4.78 fixes some minor cosmetics, a build issue for
GNU/kFreeBSD, and adds a new page_flip_handler2 event handler, which
when run on a suitably capable kernel, can provide the CRTC ID to
userspace for atomic completion events.

Cheers,
Daniel

Ander Conselvan de Oliveira (1):
      Add CRTC ID to vblank event

Daniel Stone (2):
      Headers: Sync drm{,_mode}.h with the kernel
      configure.ac: bump version for release

Emil Velikov (1):
      configure.ac: pthread-stubs is not a thing on GNU/kFreeBSD

Eric Engestrom (4):
      man/drm(7): fix typo
      man: fix bug report instruction
      man: fix bug report instructions (for real this time)
      man: fix bug report instructions (third time's the charm)

2.4.79:

Marek Olšák (1):
      configure.ac: bump version for release

Samuel Pitoiset (1):
      amdgpu: allow to query GPU sensor related information

(wiz)

2017-04-11 06:32:32 UTC MAIN commitmail json YAML

Fix py-requests dependency version

(fhajny)

2017-04-10 21:15:02 UTC MAIN commitmail json YAML

Updated security/botan-devel to 2.1.0

(joerg)

2017-04-10 21:14:45 UTC MAIN commitmail json YAML

Update to Botan 2.1.0, the new stable branch.

Some of the more important changes:

- Fix incorrect truncation in Bcrypt. Passwords in length between 56 and
  72 characters were truncated at 56 characters. Found and reported by
  Solar Designer. (CVE-2017-7252) (GH #938)
- Fix a bug in X509 DN string comparisons that could result in out of
  bound reads. This could result in information leakage, denial of
  service, or potentially incorrect certificate validation results.
  Found independently by Cisco Talos team and OSS-Fuzz. (CVE-2017-2801)
- Correct minimum work factor for Bcrypt password hashes. All other
  implementations require the work factor be at least 4. Previously
  Botan simply required it be greater than zero. (GH #938)
- Converge on a single side channel silent EC blinded multiply
  algorithm. Uses Montgomery ladder with order/2 bits scalar blinding
  and point randomization now by default. (GH #893)
- Add ability to search for certificates using the SHA-256 of the
  distinguished name. (GH #900)
- Support a 0-length IV in ChaCha stream cipher. Such an IV is treated
  identically to an 8-byte IV of all zeros.
- Previously Botan forbid any use of times past 2037 to avoid Y2038
  issues. Now this restriction is only in place on systems which have a
  32-bit time_t. (GH #933 fixing #917)
- Fix a longstanding bug in modular exponentiation which caused most
  exponentiations modulo an even number to have an incorrect result;
  such moduli occur only rarely in cryptographic contexts. (GH #754)
- Fix a bug in BigInt multiply operation, introduced in 1.11.30, which
  could cause incorrect results. Found by OSS-Fuzz fuzzing the ressol
  function, where the bug manifested as an incorrect modular
  exponentiation. OSS-Fuzz bug #287
- Fix a bug that meant the ���ietf/modp/6144��� and ���ietf/modp/8192���
  discrete log groups used an incorrect value for the generator,
  specifically the value (p-1)/2 was used instead of the correct value
  of 2.
- DL_Group strong generation previously set the generator to 2. However
  sometimes 2 generates the entire group mod p, rather than the subgroup
  mod q. This is invalid by X9.42 standard, and exposes incautious
  applications to small subgroup attacks. Now DL_Group uses the smallest
  g which is a quadratic residue. (GH #818)
- The default TLS policy now requires 2048 or larger DH groups by
  default.
- The default Path_Validation_Restrictions constructor has changed to
  require at least 110 bit signature strength. This means 1024 bit RSA
  certificates and also SHA-1 certificates are rejected by default. Both
  settings were already the default for certificate validation in TLS
  handshake, but this changes it for applications also.
- Fix integer overflow during BER decoding, found by Falko Strenzke.
  This bug is not thought to be directly exploitable but upgrading ASAP
  is advised. (CVE-2016-9132)
- Add post-quantum signature scheme XMSS. Provides either 128 or 256 bit
  (post-quantum) security, with small public and private keys, fast
  verification, and reasonably small signatures (2500 bytes for 128-bit
  security). Signature generation is very slow, on the order of seconds.
  And very importantly the signature scheme is stateful: each leaf index
  must only be used once, or all security is lost. In the appropriate
  system where signatures are rarely generated (such as code signing)
  XMSS makes an excellent choice. (GH #717 #736)
- Add support for client-side OCSP stapling to TLS. (GH #738)
- Previously both public and private keys performed automatic self
  testing after generation or loading. However this often caused
  unexpected application performance problems, and so has been removed.
  Instead applications must call check_key explicitly. (GH #704)
- Fix TLS session resumption bugs which caused resumption failures if an
  application used a single session cache for both TLS and DTLS. (GH
  #688)
- The default TLS policy now disables static RSA ciphersuites, all DSA
  ciphersuites, and the AES CCM-8 ciphersuites. Disabling static RSA by
  default protects servers from oracle attacks, as well as enforcing a
  forward secure ciphersuite. Some applications may be forced to
  re-enable RSA for interop reasons. DSA and CCM-8 are rarely used, and
  likely should not be negotiated outside of special circumstances.
- The default TLS policy now prefers ChaCha20Poly1305 cipher over any
  AES mode.
- The default TLS policy now orders ECC curve preferences in order by
  performance, with x25519 first, then P-256, then P-521, then the rest.

(joerg)

2017-04-10 20:30:30 UTC MAIN commitmail json YAML

Updated misc/rlwrap to 0.43

(leot)

2017-04-10 20:30:15 UTC MAIN commitmail json YAML

Update misc/rlwrap to 0.43

pkgsrc changes:
- depends on python3* now that filters can be written in Python
- update MASTER_SITES and HOMEPAGE (old homepage seems no longer available)
- take MAINTAINERship

Changes:
0.43
----
- Added Hisanobu Okuda's rlwrapfilter.py python3 module
  and example filters. Filters can now be written in python
  as well as perl.
- If a filter was used, rlwrap would pass all input, output,
  history items, prompts, ... through the filter, even if it
  wouldn't change them. Now, at startup, filters (even filter
  pipelines) tell rlwrap which messages they handle, after which
  rlwrap won't bother them with anything else.
- Added bindable readline command rlwrap-direct-keypress
  that bypasses readline editing and sends its keypress directly
  to the rlwrapped command (like CTRL-G for the Erlang shell)
- Added bindable readline command rlwrap-hotkey that passes
  the current input buffer and history to the filter (or
  filter pipeline) specified with the '-z' option. This can
  be used e.g. to insert the current selection at the cursor
  position, or to edit (re-write) the history.
  This uncovered quite a few bugs and inconsistencies:
      - My ncurses' termcap emulation misses some codes (like
        term_cursor_hpos) that its terminfo has. rlwrap now
        always searches terminfo before termcap.
      - rlwrap was confused about the role of history_offset,
        resulting in muddled and unclear (although correct) code.
      - rlwrap --history-size -0 would clobber the history file
        (as per the manual - that has been updated as well)
      - rlwrap's ad hoc way of sending lists of strings to filters
        by interspersing them with TABS or spaces is becoming
        unwieldy, it has been replaced by a standard encoding
        <length1><string1><length2><string2>.... (where the
        <lengths> are fixed length hexadecimal numbers (this is a
        contribution by Hisanobu Okuda)
- Playing back a readline macro consisting of more than one line
  would crash with SIGSEGV
- rlwrap with negative --histsize would fail when there is no
  history file yet.
- An empty prompt would make $filter->{cumulative_output} miss
  its last line
- Pre-given (-P) input would only be put in input line after
  cooking timeout (usually 40 msec)
- One-shot (-o) rlwrap could accept more than one line when input
  in quick succession.
- rlwrap didn't delete the tempfiles used in a multi-line
  edit
- configure.ac now works even when cross-compiling (skipping some
  tests, but providing sensible defaults)
- --enable-pedantic-ansi is a new configure option separate from
  --enable-debug (it used to be implied by --enable-debug)
- --complete-filenames (-c) will now work on OS X and FreeBSD as well

(leot)

2017-04-10 20:26:54 UTC MAIN commitmail json YAML

Updated security/botan to 1.10.16

(joerg)

2017-04-10 20:26:31 UTC MAIN commitmail json YAML

Update Botan to 1.10.16:
    Fix a bug in X509 DN string comparisons that could result in out of
    bound reads. This could result in information leakage, denial of
    service, or potentially incorrect certificate validation results.
    (CVE-2017-2801)

    Avoid throwing during a destructor since this is undefined in
    C++11 and rarely a good idea. (GH #930)

    Fix a bug causing modular exponentiations done modulo even numbers
    to almost always be incorrect, unless the values were small. This
    bug is not known to affect any cryptographic operation in Botan. (GH
    #754)

    Avoid use of C++11 std::to_string in some code added in 1.10.14
    (GH #747 #834)

    Fix integer overflow during BER decoding, found by Falko Strenzke.
    This bug is not thought to be directly exploitable but upgrading ASAP
    is advised. (CVE-2016-9132)

    Fix two cases where (in error situations) an exception would be thrown
    from a destructor, causing a call to std::terminate.

    When RC4 is disabled in the build, also prevent it from being included
    in the OpenSSL provider. (GH #638)

(joerg)

2017-04-10 19:49:59 UTC MAIN commitmail json YAML

libLLVM: use ln -sf, not ln -s. helps rebuilds, as the previous link
already exists

(maya)

2017-04-10 15:27:22 UTC MAIN commitmail json YAML

Add pkg-config to USE_TOOLS, which is needed to find gnutls.
Problem found in a bulk build.  Not bumping PKGREVISION since it
shouldn't change the binary package when it built.

(jnemeth)

2017-04-10 15:05:04 UTC MAIN commitmail json YAML

Updated mail/qmail-run to 20170410

(schmonz)

2017-04-10 15:04:56 UTC MAIN commitmail json YAML

2017-04-10 13:24:55 UTC MAIN commitmail json YAML

Updated fonts/noto-ttf to 20170410

(ryoon)

2017-04-10 13:23:49 UTC MAIN commitmail json YAML

Update to 20170410

* Add NotoSerifCJK fonts
* Use latest NotoSansCJK fonts
* Use latest fonts for non-CJK

(ryoon)

2017-04-10 13:10:19 UTC MAIN commitmail json YAML

Avoid picking up epoll on illumos.

(jperkin)

2017-04-10 12:31:16 UTC MAIN commitmail json YAML

Updated time/py-mxDateTime to 3.2.9

(mef)

2017-04-10 12:31:05 UTC MAIN commitmail json YAML

Updated time/py-mxDateTime to 3.2.9
-----------------------------------
          (Changes to 3.2.9 is unknown)
Changes from 3.2.6 to 3.2.8
    Protected delta.strftime() against segfaults on Windows, which
    only allows day values <= 31 and segfaults for higher
    values. Thanks to Frank Boje for reporting this problem.

(mef)

2017-04-10 12:22:07 UTC MAIN commitmail json YAML

Let GCC 4.4 handle requests for GCC 4.[0-4] to ensure we are consistent in
using the closest match for each request, as well as fixing platforms where
GCC 6 does not yet build or is unsupported.

(jperkin)

2017-04-10 11:43:13 UTC MAIN commitmail json YAML

Long double math libraries now build on older Darwin too.

(jperkin)

2017-04-10 11:35:40 UTC MAIN commitmail json YAML

Since devel/py-boost will pick up py-numpy when installed and fail,
just depend on it explicitly and adjust PLIST for the new library.

(joerg)

2017-04-10 10:44:46 UTC MAIN commitmail json YAML

Add apache-tomcat85

(ryoon)

2017-04-10 10:43:57 UTC MAIN commitmail json YAML

Added www/apache-tomcat85 version 8.5.13

(ryoon)

2017-04-10 10:43:49 UTC MAIN commitmail json YAML

2017-04-10 10:43:22 UTC MAIN commitmail json YAML

Import apache-tomcat-8.5.13 as www/apache-tomcat85.

Apache Tomcat is an implementation of the Java Servlet and JavaServer Pages
technologies. The Java Servlet and JavaServer Pages specifications are
developed under the Java Community Process.

Apache Tomcat is developed in an open and participatory environment and
released under the Apache Software License. Apache Tomcat is intended to
be a collaboration of the best-of-breed developers from around the world.
We invite you to participate in this open development project.

Apache Tomcat powers numerous large-scale, mission-critical web applications
across a diverse range of industries and organizations.

This package tracks 8.5.x release branch.

(ryoon)

2017-04-10 10:38:20 UTC MAIN commitmail json YAML

apache-tomcat8 is for 8.0.x

(ryoon)

2017-04-10 10:34:07 UTC MAIN commitmail json YAML

Updated www/apache-tomcat8 to 8.0.43

(ryoon)

2017-04-10 10:33:43 UTC MAIN commitmail json YAML

Update to 8.0.43

Changelog:
Tomcat 8.0.43 (violetagg)
Catalina

    Add: 54618: Add support to the HttpHeaderSecurityFilter for the HSTS preload parameter. (markt)
    Fix: 60876: Ensure that Set-Cookie headers generated by the Rfc6265CookieProcessor are aligned with the specification. Patch provided by Jim Griswold. (markt)
    Fix: 60911: Ensure NPE will not be thrown when looking for SSL session ID. Based on a patch by Didier Gutacker. (violetagg)

Coyote

    Fix: When using the NIO2 connector, ensure a WebSocket close frame is processed before the end of stream is processed to ensure that the end of stream is processed correctly. (markt)
    Fix: 60852: Correctly spell compressible when used in configuration attributes and internal code. Based on a patch by Michael Osipov. (markt)
    Fix: Improve sendfile handling when requests are pipelined. (markt)

Jasper

    Fix: Improve the error handling for simple tags to ensure that the tag is released and destroyed once used. (remm, violetagg)
    Fix: 60844: Correctly handle the error when fewer parameter values than required by the method are used to invoke an EL method expression. Patch provided by Daniel Gray. (markt)

jdbc-pool

    Fix: 60764: Implement equals() and hashCode() in the StatementFacade in order to enable these methods to be called on the closed statements if any statement proxy is set. This behavior can be changed with useStatementFacade attribute. (kfujino)

Other

    Fix: Refactor the build script and the NSIS installer script so that either NSIS 2.x or NSIS 3.x can be used to build the installer. This is primarily to re-enable building the installer on the Linux based CI system where the combination of NSIS 3.x and wine leads to failed installer builds. (markt)

2017-03-14 Tomcat 8.0.42 (markt)
Catalina

    Update: 60596: Improve performance of DefaultServlet when sendfile feature is disabled on connector. (kkolinko)
    Fix: Reduce the contention in the default InstanceManager implementation when multiple threads are managing objects and need to reference the annotation cache. (markt)
    Add: Extend the JreMemoryLeakPreventionListener to provide protection against ForkJoinPool.commonPool() related memory leaks. (markt)
    Code: 60674: Remove final marker from CorsFilter to enable sub-classing. (markt)
    Fix: 60683: Security manager failure causing NPEs when doing IO on some JVMs. (csutherl)
    Fix: 60688: Update the internal fork of Apache Commons BCEL to r1782855 to add early access Java 9 support to the annotation scanning code. (markt)
    Fix: When HTTP TRACE requests are disabled on the Connector, ensure that the HTTP OPTIONS response from the WebDAV servlet does not include TRACE in the returned Allow header. (markt)
    Fix: 60718: Improve error handling for asynchronous processing and correct a number of cases where the requestDestroyed() event was not being fired and an entry wasn't being made in the access logs. (markt)
    Fix: 60722: Take account of the dispatchersUseEncodedPaths setting on the current Context when generating paths for dispatches triggered by AsyncContext.dispatch(). (markt)
    Fix: 60728: Make the separator Tomcat uses in the Tomcat specific war:file:... URL protocol customizable via a system property. The separator is equivalent to the use of the ! character in jar:file:... URLs. The default separator of * remains unchanged. (markt)
    Fix: 60798: Correct a bug in the handling of JARs in unpacked WARs that meant multiple attempts to read the same entry from a JAR in succession would fail for the second and subsequent attempts. (markt)
    Fix: 60808: Ensure that the Map returned by ServletRequest.getParameterMap() is fully immutable. Based on a patch provided by woosan. (markt)
    Fix: 60824: Correctly cache the Subject in the session - if there is a session - when running under a SecurityManager. Patch provided by Jan Engehausen. (markt)
    Fix: Ensure request and response facades are used when firing application listeners. (markt/remm)

Coyote

    Fix: Ensure that executor thread pools used with connectors pre-start the configured minimum number of idle threads. (markt)
    Add: 60594: Allow some invalid characters that were recently restricted to be processed in requests by using the system property tomcat.util.http.parser.HttpParser.requestTargetAllow. (csutherl)
    Fix: Modify the cookie header generated by the Rfc6265CookieProcessor so it always sends an Expires attribute as well as a Max-Age attribute to avoid problems with Microsoft browsers that do not support the Max-Age attribute. (markt)

Jasper

    Fix: Follow up to the fix for 58178. When creating the ELContext for a tag file, ensure that any registered ELContextListeners are fired. (markt)
    Fix: Refactor code generated for JSPs to reduce the size of the code required for tags. (markt)
    Update: Update to the Eclipse JDT Compiler 4.6.1. (markt)

Cluster

    Add: Make the accessTimeout configurable in ClusterSingleSignOn. The accessTimeout is used as a timeout period for PING in replication map. (kfujino)
    Fix: 60806: To avoid ClassNotFoundException, make sure that the web application class loader is passed to ReplicatedContext. (kfujino)

WebSocket

    Fix: 60617: Correctly create a CONNECT request when establishing a WebSocket connection via a proxy. Patch provided by Svetlin Zarev. (markt)

Tribes

    Fix: Ensure that NoRpcChannelReply messages are not received on RpcCallback. (kfujino)

Other

    Update: Update the packaged version of the Tomcat Native Library to 1.2.12 to pick up the latest Windows binaries built with OpenSSL 1.0.2k. (violetagg)
    Add: 60784: Update all unit tests that test the HTTP status line to check for the required space after the status code. Patch provided by Michael Osipov. (markt)
    Update: Update the NSIS Installer used to build the Windows installer to version 3.01. (markt)

(ryoon)

2017-04-10 10:33:16 UTC MAIN commitmail json YAML

Updated www/apache-tomcat7 to 7.0.77

(ryoon)

2017-04-10 10:32:47 UTC MAIN commitmail json YAML

Update to 7.0.77

Changelog:
Tomcat 7.0.77 (violetagg)

    Catalina

        add 54618: Add support to the HttpHeaderSecurityFilter for the HSTS preload parameter. (markt)
        fix 60911: Ensure NPE will not be thrown when looking for SSL session ID. Based on a patch by Didier Gutacker. (violetagg)

    Coyote

        fix When using the NIO2 connector, ensure a WebSocket close frame is processed before the end of stream is processed to ensure that the end of stream is processed correctly. (markt)
        fix 60852: Correctly spell compressible when used in configuration attributes and internal code. Based on a patch by Michael Osipov. (markt)
        fix Improve sendfile handling when requests are pipelined. (markt)

    Jasper

        fix Improve the error handling for simple tags to ensure that the tag is released and destroyed once used. (remm, violetagg)
        fix 60844: Correctly handle the error when fewer parameter values than required by the method are used to invoke an EL method expression. Patch provided by Daniel Gray. (markt)

    jdbc-pool

        fix 60764: Implement equals() and hashCode() in the StatementFacade in order to enable these methods to be called on the closed statements if any statement proxy is set. This behavior can be changed with useStatementFacade attribute. (kfujino)

Tomcat 7.0.76 (markt) released 2017-03-16

    Catalina

        code Make it easier for sub-classes of Tomcat to modify the default web.xml settings by over-riding getDefaultWebXmlListener(). Patch provided by Aaron Anderson. (markt)
        fix Reduce the contention in the default InstanceManager implementation when multiple threads are managing objects and need to reference the annotation cache. (markt)
        code 60674: Remove final marker from CorsFilter to enable sub-classing. (markt)
        fix 60683: Security manager failure causing NPEs when doing IO on some JVMs. (csutherl)
        fix 60688: Update the internal fork of Apache Commons BCEL to r1782855 to add early access Java 9 support to the annotation scanning code. (markt)
        fix 60718: Improve error handling for asynchronous processing and correct a number of cases where the requestDestroyed() event was not being fired and an entry wasn't being made in the access logs. (markt)
        fix 60808: Ensure that the Map returned by ServletRequest.getParameterMap() is fully immutable. Based on a patch provided by woosan. (markt)
        fix 60824: Correctly cache the Subject in the session - if there is a session - when running under a SecurityManager. Patch provided by Jan Engehausen. (markt)
        fix Ensure request and response facades are used when firing application listeners. (markt/remm)
        fix When HTTP TRACE requests are disabled on the Connector, ensure that the HTTP OPTIONS response from the WebDAV servlet does not include TRACE in the returned Allow header. (markt)

    Coyote

        fix Ensure that executor thread pools used with connectors pre-start the configured minimum number of idle threads. (markt)
        add 60594: Allow some invalid characters that were recently restricted to be processed in requests by using the system property tomcat.util.http.parser.HttpParser.requestTargetAllow. (csutherl)

    Jasper

        fix Refactor code generated for JSPs to reduce the size of the code required for tags. (markt)

    Cluster

        add Make the accessTimeout configurable in ClusterSingleSignOn. The accessTimeout is used as a timeout period for PING in replication map. (kfujino)
        fix 60806: To avoid ClassNotFoundException, make sure that the web application class loader is passed to ReplicatedContext. (kfujino)

    WebSocket

        fix 60617: Correctly create a CONNECT request when establishing a WebSocket connection via a proxy. Patch provided by Svetlin Zarev. (markt)

    Tribes

        fix Ensure that NoRpcChannelReply messages are not received on RpcCallback. (kfujino)
        fix 60722: Take account of the dispatchersUseEncodedPaths setting on the current Context when generating paths for dispatches triggered by AsyncContext.dispatch(). (markt)

    Other

        fix 60620: Fix configuration of Eclipse projects, broken by introduction of SafeForkJoinWorkerThreadFactory helper class. This class cannot be built with Java 6. (kkolinko)
        update Update the packaged version of the Tomcat Native Library to 1.2.12 to pick up the latest Windows binaries built with OpenSSL 1.0.2k. (violetagg)
        add 60784: Update all unit tests that test the HTTP status line to check for the required space after the status code. Patch provided by Michael Osipov. (markt)
        update Update the NSIS Installer used to build the Windows installer to version 3.01. (markt)
        fix Refactor the build script and the NSIS installer script so that either NSIS 2.x or NSIS 3.x can be used to build the installer. This is primarily to re-enable building the installer on the Linux based CI system where the combination of NSIS 3.x and wine leads to failed installer builds. (markt)

Tomcat 7.0.75 (violetagg) released 2017-01-24

    Cluster

        add Make the accessTimeout configurable in BackupManager. The accessTimeout is used as a timeout period for PING in replication map. (kfujino)

    Web applications

        fix Ensure the ASF logo image is correctly displayed in docs and host-manager applications. (violetagg)

Tomcat 7.0.74 (violetagg) not released

    Catalina

        add 53602: Add HTTP status code 451 (RFC 7725) to the list of HTTP status codes recognised by Tomcat. (markt)
        fix Correctly handle the configClass attribute of a Host when embedding Tomcat. (markt)
        fix 60379: Dispose of the GSS credential once it is no longer required. Patch provided by Michael Osipov. (markt)
        fix 60380: Ensure that a call to HttpServletRequest#logout() triggers a call to TomcatPrincipal#logout(). Based on a patch by Michael Osipov. (markt)
        fix 60387: Correct the javadoc for o.a.catalina.AccessLog.setRequestAttributesEnabled. The default value is different for the different implementations. (violetagg)
        code 60393: Use consistent parameter naming in implementations of Realm#authenticate(GSSContext, boolean). (markt)
        fix 60395: Log when an Authenticator passes an incomplete GSSContext to a Realm since it indicates a bug in the Authenticator. Patch provided by Michael Osipov. (markt)
        update Update the warnings that reference required options for running on Java 9 to use the latest syntax for those options. (markt)
        fix 60513: Fix thread safety issue with RMI cleanup code. (remm)
        add 60620: Extend thed memory leaks. (markt)

    Coyote

        fix Ensure that the endpoint is able to unlock the acceptor thread during shutdown if the endpoint is configured to listen to any local address of a specific type such as 0.0.0.0 or ::. (markt)
        fix Ensue is enabled by default for APR. (markt)
        fix Prevent read time out when the file is deleted while serving the response. The issue was observed only with APR Connector and sendfile enabled. (violetagg)
        fix Improve the logic that selects an  to unlock the Acceptor to take account of platforms what do not listen on all local addresses when configured with an address of 0.0.0.0 or ::. (markt)
        fix 60409: When unable to complete sendfile request, ensure the Processor will be added to the(markt)
        fix 60431: Improve handling of varargs in UEL expressions. Based on a patch by Ben Wolfe. (markt)
        fix 60497: Restore previous tag reuse behavior following the use of try/finally. (remm)
        fix Improve the error handling for simple tags to ensure that the tag is released and destroyed once used. (remm)
        fix 60497: Follow up fix using a better variable name for the tag reuse flag. (remm)
        fix Revert use of try/finally for simple tags. (remm)

    Web applications

        fix Correct a typo in Host Configuration Reference. Issue reported via comments.apache.org. (violetagg)
        add In the documentation web application, be explicit that clustering requires a secure network for all of the cluster network traffic. (markt)
        update Update the ASF logos to the new versions.

    Tribes

        fix Reduce the warning logs for a message received from a different domain in order to avoid excessive log outputs. (kfujino)
        add Add log message that PING message has received beyond the timeout period. (kfujino)
        fix When a PING message that beyond the time-out period has been received, make sure that valid member is added to the map membership. (kfujino)

    WebSocket

        fix 60437: Avoid possible handshake overflows in the websocket client. (remm)

    jdbc-pool

        add 58816: Implement the statistics of jdbc-pool. The stats infos are borrowedCount, returnedCount, createdCount, releasedCount, reconnectedCount, releasedIdleCount and removeAbandonedCount. (kfujino)
        fix 60194: If validationQuery is not specified, connection validation is done by calling the isValid() method. (kfujino)
        fix 60398: Fix testcase of TestSlowQueryReport. (kfujino)
        add Enable reset the statistics without restarting the pool. (kfujino)

    Other

        fix 60366: Change catalina.bat to use directly LOGGING_MANAGER and LOGGING_CONFIG variables in order to configure logging, instead of modifying JAVA_OPTS. Patch provided by Petter Isberg. (violetagg)
        add New property is added test.verbose in order to control whether the output of the tests is displayed on the console or not. Patch provided by Emmanuel Bourg. (violetagg)
        update Update the ASF logos used in the Apache Tomcat installer for Windows to use the new versions.
        fix Spelling corrections provided by Josh Soref. (violetagg)

Tomcat 7.0.73 (violetagg) released 2016-11-14

    Catalina

        fix 60117: Ensure that the name of LogLevel is localized when using OneLineFormatter. Patch provided by Tatsuya Bessho. (kfujino)
        add 60151: Improve the exception error messages when a ResourceLink fails to specify the type, specifies an unknown type or specifies the wrong type. (markt)
        fix 60167: Ignore empty lines in /etc/passwd files when using the PasswdUserDatabase. (markt)
        fix Improve the access checks for linked global resources to handle the case where the current class loader is a child of the web application class loader. (markt)
        fix 60199: Log a warning if deserialization issues prevent a session attribute from being loaded. (markt)
        fix Correctly test for control characters when reading the provided shutdown password. (markt)
        fix When configuring the JMX remote listener, specify the allowed types for the credentials. (markt)

    Coyote

        fix 60123: Avoid potential threading issues that could cause excessively large vales to be returned for the processing time of a current request. (markt)
        fix 60174: Log instances of HeadersTooLargeException during request processing. (markt)
        fix Correct the HTTP header parser so that DEL is not treated as a valid token character. (markt)
        fix 60319: When using an Executor, disconnect it from the Connector attributes maxThreads, minSpareThreads and threadPriority to enable the configuration settings to be consistently reported. These Connector attributes will be reported as -1 when an Executor is in use. The values used by the executor may be set and obtained via the Executor. (markt)
        fix If an I/O error occurs during async processing on a non-container thread, ensure that the onError() event is triggered. (markt)
        fix Improve detection of I/O errors during async processing on non-container threads and trigger async error handling when they are detected. (markt)
        add Add additional checks for valid characters to the HTTP request line parsing so invalid request lines are rejected sooner. (markt)

    Web applications

        add Add an example of using the classesToInitialize attribute of the JreMemoryLeakPreventionListener to the documentation web application. Based on a patch by Cris Berneburg. (markt)
        fix 60192: Correct a typo in the status output of the Manager application. Patch provided by Radhakrishna Pemmasani. (markt)
        fix Correct a typo in HTTP Connector How-To. Issue reported via comments.apache.org. (violetagg)
        fix Fix default value of validationInterval attribute in jdbc-pool. (kfujino)
        fix Correct a typo in CGI How-To. Issue reported via comments.apache.org. (violetagg)
        fix 60344: Add a note to BUILDING.txt regarding using the source bundle with the correct line endings. (markt)

    Tribes

        fix When the proxy node sends a backup retrieve message, ensure that using the channelSendOptions that has been set rather than the default channelSendOptions. (kfujino)

    jdbc-pool

        fix 60099: Ensure that use all method arguments as a cache key when using StatementCache. (kfujino)
        fix 60139: Correct Javadocs for PoolConfiguration.getValidationInterval and setValidationInterval. Reported by Phillip Webb. (kfujino)

    Other

        add Add documentation to the bin/catalina.bat script to remind users that environment variables don't affect the configuration of Tomcat when run as a Windows Service. Based upon a documentation patch by James H.H. Lampert. (schultz)

Tomcat 7.0.72 (violetagg) released 2016-09-19

    Catalina

        fix Ensure Digester.useContextClassLoader is considered in case the class loader is used. (violetagg)

    Jasper

        fix 60101: Remove preloading of the class that was deleted. (violetagg)

    jdbc-pool

        fix Notify jmx when returning the connection that has been marked suspect. (kfujino)
        fix Ensure that the POOL_EMPTY notification has been added to the jmx notification types. (kfujino)

    Other

        update Update the packaged version of the Tomcat Native Library to 1.2.10 to pick up the latest Windows binaries built with OpenSSL 1.0.2j. (markt)

Tomcat 7.0.71 (violetagg) not released

    Catalina

        fix 57705: Add debug logging for requests denied by the remote host and remote address valves and filters. Based on a patch by Graham Leggett. (markt)
        update Change the default of the sessionCookiePathUsesTrailingSlash attribute of the Context element to false since the problems caused when a Servlet is mapped to /* are more significant than the security risk of not enabling this option by default. (markt)
        fix 59708: Modify the LockOutRealm logic. Valid authentication attempts during the lock out period will no longer reset the lock out timer to zero. (markt)
        fix Improve error handling around user code prior to calling InstanceManager.destroy() to ensure that the method is executed. (markt)
        fix Ensure that reading the singleThreadModel attribute of a StandardWrapper via JMX does not trigger initialisation of the associated servlet. With some frameworks this can trigger an unexpected initialisation thread and if initilisation is not thread-safe the initialisation can then fail. (markt)
        fix By default, treat paths used to obtain a request dispatcher as encoded. This behaviour can be changed per web application via the dispatchersUseEncodedPaths attribute of the Context. (markt)
        fix 59839: Apply roleSearchAsUser to all nested searches in JNDIRealm. (fschumacher)
        add Provide a mechanism that enables the container to check if a component (typically a web application) has been granted a given permission when running under a SecurityManager without the current execution stack having to have passed through the component. Use this new mechanism to extend SecurityManager protection to the system property replacement feature of the digester. (markt)
        add When retrieving an object via a ResourceLink, ensure that the object obtained is of the expected type. (markt)
        fix 59866: When scanning WEB-INF/classes for annotations, don't scan the contents of WEB-INF/classes/META-INF (if present) since classes will never be loaded from that location. (markt)
        fix 59912: Fix an edge case in input stream handling where an IOException could be thrown when reading a POST body. (markt)
        fix 59966: Do not start the web application if the error page configuration in web.xml is invalid. (markt)
        fix Switch the CGI servlet to the standard logging mechanism and remove support for the debug attribute. (markt)
        add Add a new initialisation parameter, envHttpHeaders, to the CGI Servlet to mitigate httpoxy (CVE-2016-5388) by default and to provide a mechanism that can be used to mitigate any future, similar issues. (markt)
        add When adding and removing ResourceLinks dynamically, ensure that the global resource is only visible via the ResourceLinkFactory when it is meant to be. (markt)
        fix 60008: When processing CORs requests, treat any origin with a URI scheme of file as a valid origin. (markt)
        fix Improve handling of exceptions during a Lifecycle events triggered by a state transition. The exception is now caught and the component is now placed into the FAILED state. (markt)
        fix Fix a file descriptor leak when reading the global web.xml. (markt)
        fix 60041: Better error message if a JAR is deleted while a web application is running. Note: Deleting a JAR while the application is running is not supported and errors are expected. Based on a patch by gehui. (markt)

    Coyote

        fix Improve error handling around user code prior to calling InstanceManager.destroy() to ensure that the method is executed. (markt)
        fix 59904: Add a limit (default 200) for the number of cookies allowed per request. Based on a patch by gehui. (markt)
        fix Make timing attacks against the Realm implementations harder. (schultz)
        add Refactor the code that implements the requirement that a call to complete() or dispatch() made from a non-container thread before the container initiated thread that called startAsync() completes must be delayed until the container initiated thread has completed. Rather than implementing this by blocking the non-container thread, extend the internal state machine to track this. This removes the possibility that blocking the non-container thread could trigger a deadlock. (markt)

    Jasper

        fix Improve error handling around user code prior to calling InstanceManager.destroy() to ensure that the method is executed. (markt)
        fix Improve the error handling for custom tags to ensure that the tag is returned to the pool or released and destroyed once used. (markt)
        fix Fixed StringIndexOutOfBoundsException. Based on a patch provided by wuwen via Github. (violetagg)

    WebSocket

        fix Improve error handling around user code prior to calling InstanceManager.destroy() to ensure that the method is executed. (markt)
        fix 59868: Clarify the documentation for the Manager web application to make clearer that the host name and IP address in the server section are the primary host name and IP address. (markt)
        fix 59908: Ensure that a reason phrase is included in the close message if a session is closed due to a timeout. (markt)

    Web Applications

        fix Do not log an additional case of IOExceptions in the error handler for the Drawboard WebSocket example when the root cause is the client disconnecting since the logs add no value. (markt)
        fix 59642: Mention the localDataSource in the DataSourceRealm section of the Realm How-To. (markt)
        fix Follow-up to the fix for 59399. Ensure that the new attribute transportGuaranteeRedirectStatus is documented for all Realms. Also document the NullRealm and when it is automatically created for an Engine. (markt)
        fix MBeans Descriptors How-To is moved to mbeans-descriptors-howto.html. Patch provided by Radoslav Husar. (violetagg)
        fix 60034: Correct a typo in the Manager How-To page of the documentation web application. (markt)

    Tribes

        add Add log message when the ping has timed-out. (kfujino)
        fix If the ping message has been received at the AbstractReplicatedMap#leftOver method, ensure that notify the member is alive than ignore it. (kfujino)

    jdbc-pool

        fix Fix the duplicated connection release when connection verification failed. (kfujino)
        fix Ensure that do not remove the abandoned connection that has been already released. (kfujino)
        fix In order to avoid the unintended skip of PoolCleaner, remove the check code of the execution interval in the task that has been scheduled. (kfujino)
        fix 59849: Ensure that the connection verification is executed by initSQL (if required) if the borrowing PooledConnection has not been initialized. (kfujino)
        fix 59850: Ensure that the ResultSet is closed when enabling the StatementCache interceptor. (kfujino)
        fix 59923: Reduce the default value of validationInterval in order to avoid the potential issue that continues to return an invalid connection after database restart. (kfujino)
        fix Ensure that the ResultSet is returned as Proxy object when enabling the StatementDecoratorInterceptor. (kfujino)
        fix 60043: Ensure that the suspectTimeout works without removing connection when the removeAbandoned is disabled. (kfujino)
        fix Add log message of when returning the connection that has been marked suspect. (kfujino)
        fix Correct Javadoc for ConnectionPool.suspect(). Based on a patch by Yahya Cahyadi. (markt)

    Other

        add Use the mirror network rather than the ASF master site to download the current ASF dependencies. (markt)
        update Update the packaged version of the Tomcat Native Library to 1.2.8 to pick up the latest fixes and make 1.2.8 the minimum recommended version. (markt)
        fix Fixed typos in mbeans-descriptors.xml files. (violetagg)
        update Update the internal fork of Commons BCEL to r1757132 to align with the BCEL 6 release. (markt)
        update Update the internal fork of Commons Codec to r1757174. Code formatting changes only. (markt)
        update Update the internal fork of Commons FileUpload to afdedc9. This pulls in a fix to improve the performance with large multipart boundaries. (markt)
        fix Update the download location for Objenesis. (violetagg)

Tomcat 7.0.70 (violetagg) released 2016-06-20

    Catalina

        fix 59219: Ensure AsyncListener.onError() is called if an Exception is thrown during async processing. (markt)
        fix 59220: Ensure that AsyncListener.onComplete() is called if the async request times out and the response is already committed. (markt)
        fix 59261: ServletRequest.getAsyncContext() now throws an IllegalStateException as required by the Servlet specification if the request is not in asynchronous mode when called. (markt)
        fix 59310: Do not add a Content-Length: 0 header for custom responses to HEAD requests that do not set a Content-Length value. (markt)
        fix When normalizing paths, improve the handling when paths end with /. or /.. and ensure that input and output are consistent with respect to whether or not they end with /. (markt)
        fix 59317: Ensure that HttpServletRequest.getRequestURI() returns an encoded URI rather than a decoded URI after a dispatch. (markt)
        fix Ensure that the value for the header X-Frame-Options is constructed correctly according to the specification when ALLOW-FROM option is used. (violetagg)
        add 59399: Add a new option to the Realm implementations that ship with Tomcat that allows the HTTP status code used for HTTP -> HTTPS redirects to be controlled per Realm. (markt)
        fix 59449: In ContainerBase, ensure that the process to remove a child container is the reverse of the process to add one. Patch provided by Huxing Zhang. (markt)
        fix RMI Target related memory leaks are avoidable which makes them an application bug that needs to be fixed rather than a JRE bug to work around. Therefore, start logging RMI Target related memory leaks on web application stop. Add an option that controls if the check for these leaks is made. Log a warning if running on Java 9 with this check enabled but without the command line option it requires. (markt)
        fix Fix a potential concurrency issue with the web application class loader and concurrent reads and writes of the resource cache. (markt)
        fix 59619: Within the web application class loader, always use path as the key for the resource cache to improve the hit ratio. This also fixes a problem exposed by the fix for 56777 that enabled file based configuration resources to be loaded from the class path. (markt)
        fix Fix error message when failed to register MBean. (kfujino)

    Coyote

        fix 58970: Fix a connection counting bug in the NIO connector that meant some dropped connections were not removed from the current connection count. (markt)
        fix 59289: Do not recycle upgrade processors in unexpected close situations. (remm)
        fix Ensure that requests with HTTP method names that are not tokens (as required by RFC 7231) are rejected with a 400 response. (markt)
        fix When an asynchronous request is processed by the AJP connector, ensure that request processing has fully completed before starting the next request. (markt)
        fix If an async dispatch results in the completion of request processing, ensure that any remaining request body is swallowed before starting the processing of the next request else the remaining body may be read as the start of the next request leading to a 400 response. (markt)

    Jasper

        fix Fix a memory leak in the expression language implementation that caused the class loader of the first web application to use expressions to be pinned in memory. (markt)
        fix 59654: Enforce the requirements of section 7.3.1 of the JSP specification regarding the permitted locations for TLD files. Patch provided by Huxing Zhang. (markt)

    WebSocket

        fix Ensure that a client disconnection triggers the error handling for the associated WebSocket end point. (markt)

    Web Applications

        fix Correct a typo in SSL/TLS Configuration How-To. Issue reported via comments.apache.org. (violetagg)
        fix 58891: Update the SSL how-to. Based on a suggestion by Alexander Kjè¾°ll. (markt)

    Tribes

        fix Fix potential NPE that depends on the setting order of attributes of static member when using the static cluster. (kfujino)
        add Add get/set method for the channel that is related to ChannelInterceptorBase. (kfujino)
        fix As with the multicast cluster environment, in the static cluster environment, the local member inherits properties from the cluster receiver. (kfujino)
        add Add get/set method for the channel that is related to each Channel services. (kfujino)
        add Add name to channel in order to identify channels. In tomcat cluster environment, it is set the cluster name + "-Channel" as default value. (kfujino)
        add Add the channel name to the thread which is invoked by channel services in order to identify the associated channel. (kfujino)
        fix Ensure that clear the channel instance from channel services when stopping channel. (kfujino)
        add Implement map state in the replication map. (kfujino)
        fix Ensure that the ping is not executed during the start/stop of the replication map. (kfujino)
        fix In ping processing in the replication map, send not the INIT message but the newly introduced PING message. (kfujino)

    jdbc-pool

        fix Fix a memory leak with the pool cleaner thread that retained a reference to the web application class loader for the first web application to use a connection pool. (markt)

    Other

        update Update the packaged version of the Tomcat Native Library to 1.2.7 to pick up the Windows binaries that are based on OpenSSL 1.0.2h and APR 1.5.2. (violetagg/markt)
        update Remove native code (Windows Service Wrapper, APR/native connector) support for Windows Itanium. (markt)
        update Update the internal fork of Commons File Upload to r1743698 (1.3.1 plus additional fixes). (markt)
        fix 58626: Add support for a new environment variable (USE_NOHUP) that causes nohup to be used when starting Tomcat. It is disabled by default except on HP-UX where it is enabled by default since it is required when starting Tomcat at boot on HP-UX. (markt)

(ryoon)

2017-04-10 10:29:38 UTC MAIN commitmail json YAML

Fix stale and missing dependencies in py-acme and py-certbot. PKGREVISION++

(fhajny)

2017-04-10 09:35:01 UTC MAIN commitmail json YAML

Fix package name. No cookie for mef.

(joerg)

2017-04-10 09:01:14 UTC MAIN commitmail json YAML

Updated graphics/pngcrush to 1.8.11

(adam)

2017-04-10 08:59:34 UTC MAIN commitmail json YAML

Version 1.8.11 (built with libpng-1.6.28 and zlib-1.2.11)
  Use png_set_option(PNG_IGNORE_ADLER32) to control ADLER32 handling.
  Changed LD=gcc to LD=$(CC) in Makefile and Makefile-nolib
PkgSrc:
  Removed patch-aa as build and installation are done from the main Makefile.

(adam)

2017-04-10 01:27:22 UTC MAIN commitmail json YAML

Updated devel/lcov to 1.13

(minskim)

2017-04-10 01:26:26 UTC MAIN commitmail json YAML

Update lcov to 1.13

Major changes and fixes since 1.9:
- fix parsing of gcc 4.7 gcov format
- make empty data directories non-fatal
- fix bug when converting function data in --diff operation
- fix handling of user-specified prefixes with trailing /
- fix whitespace handling in --rc command line option
- fix --config-file not being passed to geninfo
- fix --no-external not working with --initial
- Fix handling of non-english locales
- add exclude marker for branch coverage
- make geninfo compatible with LLVM's gcov
- Fix error when using --demangle-cpp
- Implement option to specify coverage rate precision
- make line exclusion markers configurable
- support a comma separated list of prefixes
- Allow prefix paths with spaces
- Fix --remove pattern matching
- Fix gcov version detection for XCode 8.0

(minskim)

2017-04-09 20:44:41 UTC MAIN commitmail json YAML

xz is a valid compression algorithm.

(joerg)

2017-04-09 17:57:59 UTC pkgsrc-2017Q1 commitmail json YAML

2017-04-09 17:55:03 UTC pkgsrc-2017Q1 commitmail json YAML

Pullup ticket #5257 - requested by wen
www/mediawiki: security update

Revisions pulled up:
- www/mediawiki/Makefile                                        1.64
- www/mediawiki/PLIST                                          1.31
- www/mediawiki/distinfo                                        1.49

-------------------------------------------------------------------
  Module Name:    pkgsrc
  Committed By:  wen
  Date:          Sun Apr  9 01:26:46 UTC 2017

  Modified Files:
          pkgsrc/www/mediawiki: Makefile PLIST distinfo

  Log Message:
  Update to 1.18.1

  Upstream changes:
  MediaWiki 1.28.1
  Changes since 1.28.0

      $wgRunJobsAsync is now false by default (T142751). This change
  only affects wikis with $wgJobRunRate > 0.
      Fix fatal from "WaitConditionLoop" not being found, experienced
  when a wiki has more than one database server setup.
      (T152717) Better escaping for PHP mail() command
      (T154670) A missing method causing the MySQL installer to fatal in
  rare circumstances was restored.
      (T154672) Un-deprecate ArticleAfterFetchContentObject hook.
      (T158766) Avoid SQL error on MSSQL when using selectRowCount()
      (T145635) Fix too long index error when installing with MSSQL
      (T156184) $wgRawHtml will no longer apply to internationalization messages.
      (T160519) CACHE_ANYTHING will not be CACHE_ACCEL if no accelerator
  is installed.
      (T154872) Fix incorrect ar_usertext_timestamp index names in new
  1.28 installs.
      (T109140) (T122209) SECURITY: Special:UserLogin and Special:Search
  allow redirect to interwiki links.
      (T144845) SECURITY: XSS in SearchHighlighter::highlightText() when
  $wgAdvancedSearchHighlighting is true.
      (T125177) SECURITY: API parameters may now be marked as
  "sensitive" to keep their values out of the logs.
      (T150044) SECURITY: "Mark all pages visited" on the watchlist now
  requires a CSRF token.
      (T156184) SECURITY: Escape content model/format url parameter in message.
      (T151735) SECURITY: SVG filter evasion using default attribute
  values in DTD declaration.
      (T161453) SECURITY: LocalisationCache will no longer use the
  temporary directory in it's fallback chain when trying to work out
  where to write the cache.
      (T48143) SECURITY: Spam blacklist ineffective on encoded URLs
  inside file inclusion syntax's link parameter.

  To generate a diff of this commit:
  cvs rdiff -u -r1.63 -r1.64 pkgsrc/www/mediawiki/Makefile
  cvs rdiff -u -r1.30 -r1.31 pkgsrc/www/mediawiki/PLIST
  cvs rdiff -u -r1.48 -r1.49 pkgsrc/www/mediawiki/distinfo

(spz)

2017-04-09 17:38:30 UTC MAIN commitmail json YAML

Updated parallel/py-billiard to 3.5.0.2; net/py-amqp to 2.1.4; net/py-kombu to 4.0.2; net/py-celery to 4.0.2; Added devel/py-vine version 1.1.3

(adam)

2017-04-09 17:37:18 UTC MAIN commitmail json YAML

Changes 4.0.2:
* Requirements: Now depends on Kombu 4.0.2.
* Tasks: Fixed problem with JSON serialization of group
* Worker: Fixed JSON serialization issue when using inspect active and friends
* App: Fixed saferef errors when using signals
* Prefork: Fixed bug with pack requiring bytes argument on Python 2.7.5 and earlier
* Tasks: Saferepr did not handle unicode in bytestrings on Python 2
* Testing: Added new celery_worker_paremeters fixture.
* Tasks: Added new app argument to GroupResult.restore
  This makes the restore method behave the same way as the GroupResult constructor.
* Tasks: Fixed type checking crash when task takes *args on Python 3
* Documentation and examples improvements

(adam)

2017-04-09 17:14:41 UTC MAIN commitmail json YAML

Changes 4.0.2:
- Now depends on :mod:`amqp` 2.1.4

    This new version takes advantage of TCP Keepalive settings on Linux,
    making it better at detecting closed connections, also in failover
    conditions.

- Redis: Priority was reversed so, e.g. priority 0 became priority 9.

(adam)

2017-04-09 17:07:09 UTC MAIN commitmail json YAML

Quickly added missing DEPENDS

(adam)

2017-04-09 17:04:29 UTC MAIN commitmail json YAML

2017-04-09 16:49:23 UTC MAIN commitmail json YAML

Changes 2.1.4:
Removes byte string comparison warnings when running under python -b.
Fix contributed by Jon Dufresne.
Linux version parsing broke when the version included a ‘+’ character (Issue 119).
Now sets default TCP settings for platforms that support them (e.g. Linux).

(adam)

2017-04-09 16:43:03 UTC MAIN commitmail json YAML

Changes 3.5.0.2:

- max_memory_per_child was measured in kilobytes on Linux, but bytes on
*BSD/MacOS, it's now always kilobytes.

- Windows: Adds support for max_memory_per_child, but requires the
``psutil`` package to be installed.

- Fixed bug in ForkingPickler.loadbuf, where it tried to pass
a BytesIO instance directly to ``pickle.loads`` on Python 2.7.

(adam)

2017-04-09 16:04:35 UTC MAIN commitmail json YAML

Updated databases/p5-SQL-Abstract to 1.84

(wen)

2017-04-09 16:03:06 UTC MAIN commitmail json YAML

Update to 1.84

Upstream changes:
1.84 - 2017-04-03
    - Restore 'dynamic_config => 0' missed in the Distar port

1.83 - 2017-04-03
    - Support for DELETE ... RETURNING (GH#9)
    - Port to Distar

revision 1.82  2017-03-20
-------------------------
    - Add explicit dependency on Sub::Quote (GH#8)
    - Fix syntax errors in ORDER BY docs (GH#7)

revision 1.81_01  2017-02-28
----------------------------
    - Fix order clauses with bind parameters in ->where
    - Fix ->insert($table, \@values) with >26 values (RT#112684)
    - Teach ::Tree that ILIKE (PostgreSQL) and REGEXP (MySQL) are binary ops
    - Support for UPDATE ... RETURNING
    - Documentation improvements for ORDER BY

(wen)

2017-04-09 16:00:04 UTC MAIN commitmail json YAML

Note update of ruby23-base and related pacakges:

lang/ruby23-base 2.3.4
databases/ruby-gdbm 2.3.4
devel/ruby-fiddle 2.3.4
devel/ruby-readline 2.3.4nb1
x11/ruby-tk 2.3.4nb4
lang/ruby23 2.3.4
devel/ruby-mode 2.3.4

(taca)

2017-04-09 15:57:01 UTC MAIN commitmail json YAML

Update ruby23-base and related packages to 2.3.4.

Ruby 2.3.4 Released 2017/3/30

Ruby 2.3.4 has been released.

This release contains about 80 bug fixes after the previous release. See the
commit logs for details.

And this release contains a bug fix of Symbol#hash to be non-deterministic.
This is a regression on the 2.3 series before 2.3.4.  See Bug #13376 for more
details.

(taca)

2017-04-09 15:54:28 UTC MAIN commitmail json YAML

Fix accidently modified RUBY23_VERSION.

(taca)

2017-04-09 15:50:35 UTC MAIN commitmail json YAML

Note upadte of lang/ruby22-base and lang/ruby22 to 2.2.7.

(taca)

2017-04-09 15:49:50 UTC MAIN commitmail json YAML

Update ruby22-base and ruby22 to 2.2.7.

Ruby 2.2.7 Released 2017/3/28

Ruby 2.2.7 has been released.

This release includes about 70 bug fixes after the previous release. See the
ChangeLog for details.

After this release, we will end the normal maintenance phase of Ruby 2.2, and
start the security maintenance phase of it.  This means that after the release
of 2.2.7 we will never backport any bug fixes to 2.2 except security fixes.
The term of the security maintenance phase is scheduled for 1 year.  By the
end of this term, official support of Ruby 2.2 will be over.  Therefore, we
recommend that you start planning to upgrade to Ruby 2.4 or 2.3.

(taca)

2017-04-09 15:34:20 UTC MAIN commitmail json YAML

Updated www/nghttp2 to 1.21.1; www/h2o to 2.2.0; www/libsass to 3.4.4; www/sassc to 3.4.2

(adam)

2017-04-09 15:33:02 UTC MAIN commitmail json YAML

This is the SassC for LibSass 3.4.2.

(adam)

2017-04-09 15:31:34 UTC MAIN commitmail json YAML

Changes 3.4.4:
Features
* Update Visual Studio build facade
* Update read me
* Performance improvements for @extend
* Performance improvements

Fixes
Disable FMA3 when compiling with Visual Studio 2013
Fix for loop variable to be referenced
Fix number compare issues when used as map keys with old gcc
Fix results of map-get not being evaluated
Fix null pointer access
Fix bug with media queries and @extend

Misc
Cleanup initial shared ptr interface
Refactor selector list and schema handling
Cleanup context usage and extend code
Cleanup misc
Cleanup issues detected by clangs static analyser
Remove Textual intermediate AST node
Add libsass-python to README

(adam)

2017-04-09 15:30:07 UTC MAIN commitmail json YAML

Changes 2.2.0:
[core] add crash-handler.wait-pipe-close parameter 1092 (Frederik Deweerdt)
[core] introduce an option to bypass the server header sent from upstream 1226 (Frederik Deweerdt)
[core] apply global- and host-level configuration to requests not applicable to any of the path-level configurations 1231 (Kazuho Oku)
[access-log] add %{remote}p for logging the remote port 1166 (Kazuho Oku)
[access-log] add support for JSON-style escapes and null 1208 (Kazuho Oku)
[access-log] add specifier for logging per-request environment variables 1221 (Yannick Koechlin)
[access-log] add support for <, > modifiers for logging either the original or the final response 1238 (Kazuho Oku)
[access-log] do not emit request-total-time twice 1017 (Kazuho Oku)
[fastcgi] fix a bug that closes the FastCGI listener socket during startup 1203 (Frederik Deweerdt)
[file] add directive for serving gzipped files, decompressing them on-the-fly 1140 (Ichito Nagata)
[headers] fix buffer overrun during startup 1180 (Frederik Deweerdt)
[http1][proxy] preserve the cases of characters used in header names 1194 (Frederik Deweerdt)
[http1][proxy] fix undefined behavior in HTTP/1 parser 1189 (Frederik Deweerdt)
[http1] stop reading from socket after sending 400 to avoid the risk of assertion failure 1223 (Frederik Deweerdt)
[http2] recognize x-http2-push-only attribute on link header 1169 (Frederik Deweerdt)
[http2] add optional timeout for closing connections upon graceful shutdown 1108 (Frederik Deweerdt)
[http2] do not ack an acked PING frame 1175 (Moto Ishisawa)
[http2] reject requests exceeding the maximum allowed size more efficiently 1183 (Frederik Deweerdt)
[mruby] remove dependenty to mkmf 1197 (Yuki Kurihara)
[mruby] correct the line number reported on an exception 1239 (Ichito Nagata)
[proxy] add directives for tweaking headers sent to upstream 1126 (Justin Zhu)
[proxy] retain case-sensitivity of unix socket paths 1131 (Frederik Deweerdt)
[proxy] add directive for controlling the via request header 1225 (Frederik Deweerdt)
[ssl] add directive for logging session ID 1164 (Yannick Koechlin)
[ssl] add support for TLS 1.3 draft-18 1204 (Kazuho Oku)
[ssl] stop evicting session entries in memcached when they are removed from internal cache 1185 (Ichito Nagata)
[ssl] fix crash when a secp384r1, secp521r1 certificate is used with TLS 1.3 1214 (Kazuho Oku)
[ssl] fix build failure with OpenSSL 1.1.0 1216 (Kazuho Oku)
[ssl] add doc for handshake-timeout 1233 (Kazuho Oku)
[status] fix race condition during start-up 1242 (Frederik Deweerdt)
[libh2o] implement h2o_evloop_destroy 1200 (kazan417)
[misc] add test code for fuzzing 1174 1182 1191 1192 (Frederik Deweerdt, Jonathan Foote)
[misc] fix issues reported by Coverity 1168 1172 1179 (Harrison Bowden, Frederik Deweerdt)

(adam)

2017-04-09 15:29:40 UTC MAIN commitmail json YAML

Updated databases/p5-DBIx-Class-Cursor-Cached to 1.1.4

(wen)

2017-04-09 15:28:20 UTC MAIN commitmail json YAML

Update to 1.1.4

Upstream changes:
1.1.4 6 October 2016 17:26:00
        - make sure Makefile.PL is included in the dist

1.1.3 6 October 2016 10:56:00
        - Refactor slightly to enable useful subclassing (RT#102223, Tim Bunce)

(wen)

2017-04-09 15:24:02 UTC MAIN commitmail json YAML

Changes 1.21.1:
The bug which causes libnghttp2_asio client to crash has been fixed.
The bug which causes nghttpx to respond to a client with 502 status code if it receives 204 status code from HTTP/1 backend has been fixed.

(adam)

2017-04-09 13:02:32 UTC MAIN commitmail json YAML

Describe qmail-run-ofmipd.

(schmonz)

2017-04-09 12:58:51 UTC MAIN commitmail json YAML

Updated mail/qmail-run to 20170409

(schmonz)

2017-04-09 12:58:46 UTC MAIN commitmail json YAML

Add "qmail-run-ofmipd" option that controls the dependency on
mess822. Turn it off by default. This should let us once again
publish binary packages.

To use another ofmipd, set qmailofmipd_ofmipdcmd in rc.conf. Likewise
for qmail-smtpd and qmail-pop3d.

Bump version.

(schmonz)

2017-04-09 11:49:17 UTC MAIN commitmail json YAML

+ afl-2.40b, dbus-1.10.18, khal-0.9.5, libdrm-2.4.79, libnice-0.1.14,
  libsndfile-1.0.28, p5-CGI-4.36, p5-Clone-0.39, p5-File-HomeDir-1.002,
  p5-List-MoreUtils-0.419, p5-MIME-Charset-1.012.1, p5-MIME-tools-5.509,
  p5-Mojolicious-7.30, p5-Params-ValidationCompiler-0.24,
  protobuf-3.2.1, py-mercurial-4.1.2, py-setuptools-34.4.0,
  py-setuptools_scm-1.15.5, py-tortoisehg-4.1.2, syncthing-0.14.26,
  vim-8.0.0553, vim-share-8.0.0553, x264-devel-20170408.

(wiz)

2017-04-09 11:46:04 UTC MAIN commitmail json YAML

Updated devel/p5-Contextual-Return to 0.004.011

(mef)

2017-04-09 11:45:51 UTC MAIN commitmail json YAML

Updated devel/p5-Contextual-Return to 0.004011
----------------------------------------------
0.004011  Sat Apr  8 15:23:14 2017
    - Patched memory leak from use of @DB::args
      (thanks, Jay!)

(mef)

2017-04-09 11:39:30 UTC MAIN commitmail json YAML

Updated archivers/zutils to 1.6

(mef)

2017-04-09 11:39:19 UTC MAIN commitmail json YAML

Updated archivers/zutils to 1.6
-------------------------------
2017-04-05  Antonio Diaz Diaz  <antonio@gnu.org>

        * Version 1.6 released.
        * zcmp.cc: Accept 'B' suffix in '--ignore-initial=1kB:1234B'.
        * zutils.cc (feed_data): Show input filename in error messages.

(mef)

2017-04-09 10:46:11 UTC MAIN commitmail json YAML

Updated net/youtube-dl to 20170409

(leot)

2017-04-09 10:45:53 UTC MAIN commitmail json YAML

Update net/youtube-dl to 20170409.

Changes:
version 2017.04.09

Extractors
+ [medici] Add support for medici.tv (#3406)
+ [rbmaradio] Add support for redbullradio.com URLs (#12687)
+ [npo:live] Add support for default URL (#12555)
* [mixcloud:playlist] Fix title, description and view count extraction (#12582)
+ [thesun] Add suport for thesun.co.uk (#11298, #12674)
+ [ceskateleveize:porady] Add support for porady (#7411, #12645)
* [ceskateleveize] Improve extraction and remove URL replacement hacks
+ [kaltura] Add support for iframe embeds (#12679)
* [airmozilla] Fix extraction (#12670)
* [wshh] Extract html5 entries and delegate to generic extractor (12676)
+ [raiplay] Extract subtitles
+ [xfileshare] Add support for vidlo.us (#12660)
+ [xfileshare] Add support for vidbom.com (#12661)
+ [aenetworks] Add more video URL regular expressions (#12657)
+ [odnoklassniki] Fix format sorting for 1080p quality
+ [rtl2] Add support for you.rtl2.de (#10257)
+ [vshare] Add support for vshare.io (#12278)

version 2017.04.03

Core
+ [extractor/common] Add censorship check for TransTelekom ISP
* [extractor/common] Move censorship checks to a separate method

Extractors
+ [discoveryvr] Add support for discoveryvr.com (#12578)
+ [tv5mondeplus] Add support for tv5mondeplus.com (#11386)
+ [periscope] Add support for pscp.tv URLs (#12618, #12625)

version 2017.04.02

Core
* [YoutubeDL] Return early when extraction of url_transparent fails

Extractors
* [rai] Fix and improve extraction (#11790)
+ [vrv] Add support for series pages
* [limelight] Improve extraction for audio only formats
* [funimation] Fix extraction (#10696, #11773)
+ [xfileshare] Add support for vidabc.com (#12589)
+ [xfileshare] Improve extraction and extract hls formats
+ [crunchyroll] Pass geo verifcation proxy
+ [cwtv] Extract ISM formats
+ [tvplay] Bypass geo restriction
+ [vrv] Add support for vrv.co
+ [packtpub] Add support for packtpub.com (#12610)
+ [generic] Pass base_url to _parse_jwplayer_data
+ [adn] Add support for animedigitalnetwork.fr (#4866)
+ [allocine] Extract more metadata
* [allocine] Fix extraction (#12592)
* [openload] Fix extraction

version 2017.03.26

Core
* Don't raise an error if JWPlayer config data is not a Javascript object
  literal. _find_jwplayer_data now returns a dict rather than an str. (#12307)
* Expand environment variables for options representing paths (#12556)
+ [utils] Introduce expand_path
* [downloader/hls] Delegate downloading to ffmpeg immediately for live streams

Extractors
* [afreecatv] Fix extraction (#12179)
+ [atvat] Add support for atv.at (#5325)
+ [fox] Add metadata extraction (#12391)
+ [atresplayer] Extract DASH formats
+ [atresplayer] Extract HD manifest (#12548)
* [atresplayer] Fix login error detection (#12548)
* [franceculture] Fix extraction (#12547)
* [youtube] Improve URL regular expression (#12538)
* [generic] Do not follow redirects to the same URL

version 2017.03.24

Extractors
- [9c9media] Remove mp4 URL extraction request
+ [bellmedia] Add support for etalk.ca and space.ca (#12447)
* [channel9] Fix extraction (#11323)
* [cloudy] Fix extraction (#12525)
+ [hbo] Add support for free episode URLs and new formats extraction (#12519)
* [condenast] Fix extraction and style (#12526)
* [viu] Relax URL regular expression (#12529)

version 2017.03.22

Extractors
- [pluralsight] Omit module title from video title (#12506)
* [pornhub] Decode obfuscated video URL (#12470, #12515)
* [senateisvp] Allow https URL scheme for embeds (#12512)

(leot)

2017-04-09 10:40:08 UTC MAIN commitmail json YAML

Updated multimedia/intel-vaapi-driver to 1.8.0

(leot)

2017-04-09 10:39:52 UTC MAIN commitmail json YAML

Update multimedia/intel-vaapi-driver to 1.8.0

pkgsrc changes:
- Delete patches/patch-src_i965__decoder__utils.c: applied upstream

Changes:
Version 1.8.0 - 31.Mar.2017
* Improve the quality of the H.264 encoder on SKL+ for CQP and CBR mode
* Improve the quality of the VP8 encoder on BSW+ for CQP and CBR mode
* Add support for H.264 VBR mode on SKL+
* Add support for VP8 VBR mode on BSW+
* Add support for low-power H.264 encoder on BXT and KBL
* Add support for CBR / VBR with low-power H.264 encoder on SKL+ (A HuC Firmware and
  a HuC supported Linux kernel are required)
* Add support for CSC and scaling with 10bit P010/I010 surface
* Optimize CSC and scaling with 8bit NV12 and I420 surface
* Fix the wrong memory object cache setting on SKL+
* Fix the EU number in media pipeline
* Fix the wrong bit shift in H.264 encoder
* Fix the 48bit graphics address on BSW+
* Fix building on NetBSD
* Known issues
  - The new AVC encoder doesn't support MVC/SVC encoding
  - The new AVC encoder doesn't support ROI encoding
  - The new AVC encoder doesn't support multiple slice encoding

(leot)

2017-04-09 08:30:40 UTC MAIN commitmail json YAML

Updated devel/p5-Config-Any to 0.30

(wen)

2017-04-09 08:29:48 UTC MAIN commitmail json YAML

Update to 0.30

Upstream changes:
0.30 - 2017-03-28
    - don't use YAML::Syck on perl 5.8.8 or below, where it is broken
    - ensure tarball does not contain SCHILY headers

(wen)

2017-04-09 08:24:51 UTC MAIN commitmail json YAML

Updated lang/go to 1.8.1

(wen)

2017-04-09 08:23:43 UTC MAIN commitmail json YAML

Update to 1.8.1

Upstream changes:
go1.8.1 (released 2017/04/07) includes fixes to the compiler, linker, runtime, documentation, go command and the crypto/tls, encoding/xml, image/png, net, net/http, reflect, text/template, and time packages. See the Go 1.8.1 milestone on our issue tracker for details.

(wen)

2017-04-09 07:46:05 UTC MAIN commitmail json YAML

Updated devel/p5-Test-Dir to 1.15

(wen)

2017-04-09 07:45:10 UTC MAIN commitmail json YAML

Update to 1.15

Upstream changes:
2017-04-01  Kingpin  <martin@martin-M17x>

* Makefile.PL: fixed for newest perls

(wen)

2017-04-09 07:40:40 UTC MAIN commitmail json YAML

Updated devel/p5-Test-API to 0.008

(wen)

2017-04-09 07:39:20 UTC MAIN commitmail json YAML

Update to 0.008

Upstream changes:
0.008    2017-04-02 13:30:12-04:00 America/New_York

    - No changes from 0.007-TRIAL

0.007    2017-02-27 09:50:45-05:00 America/New_York (TRIAL RELEASE)

    [TESTS]

    - Fixed tests for perls without '.' in @INC

(wen)

2017-04-09 07:35:33 UTC MAIN commitmail json YAML

Updated time/p5-Time-Progress to 2.12

(wen)