--- - branch: MAIN date: Sun Jun 17 11:24:12 UTC 2018 files: - new: '1.23' old: '1.22' path: pkgsrc/devel/py-mercurial/Makefile pathrev: pkgsrc/devel/py-mercurial/Makefile@1.23 type: modified - new: '1.62' old: '1.61' path: pkgsrc/devel/py-mercurial/Makefile.version pathrev: pkgsrc/devel/py-mercurial/Makefile.version@1.62 type: modified - new: '1.66' old: '1.65' path: pkgsrc/devel/py-mercurial/distinfo pathrev: pkgsrc/devel/py-mercurial/distinfo@1.66 type: modified - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-mercurial_bundle2.py pathrev: pkgsrc/devel/py-mercurial/patches/patch-mercurial_bundle2.py@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-bundle.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-bundle.t@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-clonebundles.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-clonebundles.t@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-http-bad-server.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-http-bad-server.t@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-lfs-serve-access.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-lfs-serve-access.t@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-obsolete-changeset-exchange.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-obsolete-changeset-exchange.t@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-patchbomb.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-patchbomb.t@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-rebase-conflicts.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-rebase-conflicts.t@0 type: deleted - new: '0' old: '1.1' path: pkgsrc/devel/py-mercurial/patches/patch-tests_test-strip.t pathrev: pkgsrc/devel/py-mercurial/patches/patch-tests_test-strip.t@0 type: deleted id: 20180617T112412Z.e9cc1b8fcb00d65d5ecb84f4f50422efa88c3e4d log: | py-mercurial: update to 4.6.1. Mercurial 4.6.1 (2018-06-06) This is a regularly-scheduled bugfix release that also contains security fixes. 1.1. Security Fixes Multiple issues found in mpatch.c with a fuzzer: OVE-20180430-0001 OVE-20180430-0002 OVE-20180430-0004 With the following fixes: mpatch: be more careful about parsing binary patch data (SEC) mpatch: protect against underflow in mpatch_apply (SEC) mpatch: ensure fragment start isn't past the end of orig (SEC) mpatch: fix UB in int overflows in gather() (SEC) mpatch: fix UB integer overflows in discard() (SEC) mpatch: avoid integer overflow in mpatch_decode (SEC) mpatch: avoid integer overflow in combine() (SEC) No exploits are known at the time, however, it is highly recommended that all users upgrade. 1.2. Bug Fixes Also included in this release are the following, zstandard: pull in bug fixes from upstream 0.9.1 (issue5884) bundle2: fix old clients from reading newer format (issue5872) bdiff: fix xdiff long/int64 conversion (issue5885) push: continue without locking on lock failure other than EEXIST (issue5882) lfs: fix crash in command server (issue5902) hghave: fix deadlock in test runner rebase: fix error when computing obsoletenotrebased (issue5907) rebase: prioritize indicating an interrupted rebase over update (issue5838) revset: pass in lookup function to matchany() (issue5879) module: pkgsrc subject: 'CVS commit: pkgsrc/devel/py-mercurial' unixtime: '1529234652' user: wiz