www/libxul has been broken for some time due to security vulnerabilities. This issue has been highlighted by the recent portrevision bump caused by png. As libxul is based on firefox-3.6 I presume this brokenness is terminal. Since libxul is the only remaining gecko, this presents an issue for a number of other ports.
Looking at the firefox-12 sources, it appears that libxul and xulrunner are present (and www/firefox installs two identical private copies of libxul.so). How difficult would it be to either: 1) Modify www/libxul to be based on firefox-12 insead of ff3.6? 2) Modify www/firefox to (optionally) install libxul publicly? For that matter, whilst it's not directly relevant to the subject, why does www/firefox install two identical copies of the largest file (by an order of magnitude) in the package? -- Peter Jeremy
pgpQiEk8p7TJe.pgp
Description: PGP signature
