malformed patch

On Thu Sep 24, 2026 at 11:47:48PM +0200, Anne Jan Brouwer wrote:
> Hi,
> 
> updated diff for security/qtpass, superseding the 1.8.1 one. Upstream
> released 1.8.2 on 2026-09-24, and as Rafael asked, the port now uses Qt6.
> 
> Changes from the port's current state (1.7.0):
> - Update to 1.8.2 (1.8.0 features, the 1.8.1 security fixes, and 1.8.2
>   bug fixes).
> - Qt5 -> Qt6: x11/qt6 module, Qt6 WANTLIB, x11/qt6/qtsvg at run time for
>   the SVG icon plugin.
> - Upstream now installs the desktop file, the hicolor icons and the
>   AppStream metainfo (as org.qtpass.QtPass.metainfo.xml since 1.8.2), so
>   PLIST gains those entries plus the update-desktop-database and
>   gtk-update-icon-cache tags, with the matching RUN_DEPENDS.
> 
> Security fixes since 1.7.0 that matter on OpenBSD (from 1.8.1):
> - every gpg encrypt call passes --no-encrypt-to, so an "encrypt-to" in
>   gpg.conf can no longer add a recipient the .gpg-id never listed
> - only http(s) URLs become clickable links
> - the re-encryption backup commit stages tracked files only, so stray
>   plaintext in the store is not committed and pushed
> - the single-instance socket is restricted to the owning user
> 
> Tested on OpenBSD 7.9 amd64 with the 7.9 ports tree and security/qtpass
> from -current: portcheck, makesum, build, fake, update-plist reproduces
> the PLIST, port-lib-depends-check, package, pkg_add.
> CI:
> https://github.com/annejan/qtpass-freebsd-port-test/actions/runs/36063361604
> 
> Changelog: https://github.com/IJHack/QtPass/blob/v1.8.2/CHANGELOG.md
> 
> The diff was prepared with AI assistance (Claude Code) and reviewed and
> edited a bit by me.
> 
> Greets,
>     Anne Jan
> 
> diff --git a/security/qtpass/Makefile b/security/qtpass/Makefile
> index 34a2de4a..16bd352c 100644
> --- a/security/qtpass/Makefile
> +++ b/security/qtpass/Makefile
> @@ -2,7 +2,7 @@ COMMENT=    multi-platform GUI for password-store
> 
>  GH_ACCOUNT=    IJHack
>  GH_PROJECT=    QtPass
> -GH_TAGNAME=    v1.7.0
> +GH_TAGNAME=    v1.8.2
>  PKGNAME=    ${DISTNAME:L}
> 
>  CATEGORIES=    security x11
> @@ -14,16 +14,19 @@ MAINTAINER=    Stefan Hagen <[email protected]>
>  # GPLv3+
>  PERMIT_PACKAGE=    Yes
> 
> -WANTLIB+=    ${COMPILER_LIBCXX} GL Qt5Core Qt5Gui Qt5Network Qt5Widgets
> +WANTLIB+=    ${COMPILER_LIBCXX} GL Qt6Core Qt6Gui Qt6Network Qt6Widgets
>  WANTLIB+=    c m
> 
>  MODULES=    devel/qmake \
> -        x11/qt5
> +        x11/qt6
> 
> -RUN_DEPENDS=    devel/git \
> +RUN_DEPENDS=    devel/desktop-file-utils \
> +        devel/git \
>          security/gnupg>=2.2.23p1 \
>          security/password-store \
> -        security/pwgen
> +        security/pwgen \
> +        x11/gtk+4,-guic \
> +        x11/qt6/qtsvg
> 
>  NO_TEST=    Yes
> 
> diff --git a/security/qtpass/distinfo b/security/qtpass/distinfo
> index 36d3863b..a719f096 100644
> --- a/security/qtpass/distinfo
> +++ b/security/qtpass/distinfo
> @@ -1,2 +1,2 @@
> -SHA256 (QtPass-1.7.0.tar.gz) = Fte/ARFKfxHC42G0bhUGP0GaJ77/VKlphbcG2nVnA8M=
> -SIZE (QtPass-1.7.0.tar.gz) = 1167619
> +SHA256 (QtPass-1.8.2.tar.gz) = /ZUF2fFw/SbJ9GBj0/4/o4ZV2A0KORFJuBAcssWmS+I=
> +SIZE (QtPass-1.8.2.tar.gz) = 1745365
> diff --git a/security/qtpass/pkg/PLIST b/security/qtpass/pkg/PLIST
> index da179ffc..3cd6f5f6 100644
> --- a/security/qtpass/pkg/PLIST
> +++ b/security/qtpass/pkg/PLIST
> @@ -1 +1,8 @@
>  @bin bin/qtpass
> +share/applications/qtpass.desktop
> +share/icons/hicolor/512x512/apps/qtpass-icon.png
> +share/icons/hicolor/scalable/apps/qtpass-icon.svg
> +share/metainfo/
> +share/metainfo/org.qtpass.QtPass.metainfo.xml
> +@tag update-desktop-database
> +@tag gtk-update-icon-cache %D/share/icons/hicolor
> 
> 
> On 9/22/26 10:18, Anne Jan Brouwer wrote:
> > On Wed Sep 17, 2026, Rafael Sadowski wrote:
> > > Would love to see a switch to Qt6.
> > 
> >  1. Done. Same update to 1.8.1, on x11/qt6:
> > 
> > 
> > - MODULES devel/qmake x11/qt6; WANTLIB Qt6Core Qt6Gui Qt6Network
> >   Qt6Widgets (port-lib-depends-check is clean).
> > - x11/qt6/qtsvg as a RUN_DEPENDS: the icons are SVG in the resources,
> >   rendered through the Qt SVG icon plugin; nothing links libQt6Svg.
> > - desktop-file-utils and gtk+4,-guic as before: 1.8.1 installs the
> >   desktop file, the AppStream metainfo and the hicolor icons itself.
> > - distinfo and PLIST unchanged from the earlier diff.
> > 
> > No source changes needed; QtPass 1.8 builds on Qt 5.15 and Qt 6 alike,
> > and the next release (2.0, in rc now) is Qt 6.8+ only, so this is the
> > line the port will stay on.
> > 
> > Tested on 7.9-release/amd64 with the -current port (qt6-qtbase 6.10.2):
> > portcheck is silent, makesum reproduces distinfo, build, fake,
> > update-plist reproduces the PLIST, port-lib-depends-check, package,
> > install; the installed binary links libQt6Core/Gui/Network/Widgets. A
> > build and a run on -current (6.11.2) would still be appreciated, I have
> > no -current box.
> > 
> > Greets,
> >   Anne Jan
> > 
> > Index: security/qtpass/Makefile
> > --- security/qtpass/Makefile.orig
> > +++ security/qtpass/Makefile
> > @@ -2,7 +2,7 @@ COMMENT=    multi-platform GUI for password-store
> > 
> >  GH_ACCOUNT=    IJHack
> >  GH_PROJECT=    QtPass
> > -GH_TAGNAME=    v1.7.0
> > +GH_TAGNAME=    v1.8.1
> >  PKGNAME=    ${DISTNAME:L}
> > 
> >  CATEGORIES=    security x11
> > @@ -14,16 +14,19 @@ MAINTAINER=    Stefan Hagen <[email protected]>
> >  # GPLv3+
> >  PERMIT_PACKAGE=    Yes
> > 
> > -WANTLIB+=    ${COMPILER_LIBCXX} GL Qt5Core Qt5Gui Qt5Network Qt5Widgets
> > +WANTLIB+=    ${COMPILER_LIBCXX} GL Qt6Core Qt6Gui Qt6Network Qt6Widgets
> >  WANTLIB+=    c m
> > 
> >  MODULES=    devel/qmake \
> > -        x11/qt5
> > +        x11/qt6
> > 
> > -RUN_DEPENDS=    devel/git \
> > +RUN_DEPENDS=    devel/desktop-file-utils \
> > +        devel/git \
> >          security/gnupg>=2.2.23p1 \
> >          security/password-store \
> > -        security/pwgen
> > +        security/pwgen \
> > +        x11/gtk+4,-guic \
> > +        x11/qt6/qtsvg
> > 
> >  NO_TEST=    Yes
> > 
> > Index: security/qtpass/distinfo
> > --- security/qtpass/distinfo.orig
> > +++ security/qtpass/distinfo
> > @@ -1,2 +1,2 @@
> > -SHA256 (QtPass-1.7.0.tar.gz) =
> > Fte/ARFKfxHC42G0bhUGP0GaJ77/VKlphbcG2nVnA8M=
> > -SIZE (QtPass-1.7.0.tar.gz) = 1167619
> > +SHA256 (QtPass-1.8.1.tar.gz) =
> > PTq5HdCg8JInE/LT9P1frWbsl8wtlE+55e1Nu5uVPkY=
> > +SIZE (QtPass-1.8.1.tar.gz) = 1742892
> > Index: security/qtpass/pkg/PLIST
> > --- security/qtpass/pkg/PLIST.orig
> > +++ security/qtpass/pkg/PLIST
> > @@ -1 +1,8 @@
> >  @bin bin/qtpass
> > +share/applications/qtpass.desktop
> > +share/icons/hicolor/512x512/apps/qtpass-icon.png
> > +share/icons/hicolor/scalable/apps/qtpass-icon.svg
> > +share/metainfo/
> > +share/metainfo/qtpass.appdata.xml
> > +@tag update-desktop-database
> > +@tag gtk-update-icon-cache %D/share/icons/hicolor
> > 
> > On 9/17/26 02:07, Rafael Sadowski wrote:
> > > On Wed Sep 16, 2026 at 01:42:28PM +0200, Anne Jan Brouwer wrote:
> > > > Hi,
> > > > 
> > > > Update security/qtpass to 1.8.1. I am the upstream author.
> > > > 
> > > > 1.8.1 is a security release: the fixes from the 2.0 branch backported
> > > > to the 1.8 line. Among them: gpg encrypt calls now pass --no-encrypt-to
> > > > so an encrypt-to line in gpg.conf cannot add an unlisted recipient, the
> > > > re-encryption backup commit stages tracked files only, only http(s)
> > > > URLs become clickable, the key-generation dialog no longer shows the
> > > > passphrase in the batch template, and the single-instance socket is
> > > > restricted to the owning user. Full list:
> > > > https://github.com/IJHack/QtPass/blob/v1.8.1/CHANGELOG.md
> > > > 
> > > > Qt 5.15 is still supported; no code changes were needed on OpenBSD.
> > > Would love to see a switch to Qt6.
> > > 
> > > > Port changes: 1.8.1 installs the desktop file, the AppStream metainfo
> > > > and the hicolor icons itself, hence the PLIST additions and the
> > > > desktop-file-utils / gtk+4,-guic RUN_DEPENDS. WANTLIB unchanged.
> > > > 
> > > > Tested on amd64: builds, make update-plist reproduces the PLIST,
> > > > port-lib-depends-check is clean, portcheck is silent, package installs
> > > > and runs. (7.9-release with the -current port; I do not have a -current
> > > > box, so a -current build test would be appreciated.)
> > > > 
> > > > Greets,
> > > >    Anne Jan
> > > > 
> > > > Index: security/qtpass/Makefile
> > > > --- security/qtpass/Makefile.orig
> > > > +++ security/qtpass/Makefile
> > > > @@ -2,7 +2,7 @@ COMMENT=    multi-platform GUI for password-store
> > > > 
> > > >   GH_ACCOUNT=    IJHack
> > > >   GH_PROJECT=    QtPass
> > > > -GH_TAGNAME=    v1.7.0
> > > > +GH_TAGNAME=    v1.8.1
> > > >   PKGNAME=    ${DISTNAME:L}
> > > > 
> > > >   CATEGORIES=    security x11
> > > > @@ -20,10 +20,12 @@ WANTLIB+=    c m
> > > >   MODULES=    devel/qmake \
> > > >           x11/qt5
> > > > 
> > > > -RUN_DEPENDS=    devel/git \
> > > > +RUN_DEPENDS=    devel/desktop-file-utils \
> > > > +        devel/git \
> > > >           security/gnupg>=2.2.23p1 \
> > > >           security/password-store \
> > > > -        security/pwgen
> > > > +        security/pwgen \
> > > > +        x11/gtk+4,-guic
> > > > 
> > > >   NO_TEST=    Yes
> > > > 
> > > > Index: security/qtpass/distinfo
> > > > --- security/qtpass/distinfo.orig
> > > > +++ security/qtpass/distinfo
> > > > @@ -1,2 +1,2 @@
> > > > -SHA256 (QtPass-1.7.0.tar.gz) =
> > > > Fte/ARFKfxHC42G0bhUGP0GaJ77/VKlphbcG2nVnA8M=
> > > > -SIZE (QtPass-1.7.0.tar.gz) = 1167619
> > > > +SHA256 (QtPass-1.8.1.tar.gz) =
> > > > PTq5HdCg8JInE/LT9P1frWbsl8wtlE+55e1Nu5uVPkY=
> > > > +SIZE (QtPass-1.8.1.tar.gz) = 1742892
> > > > Index: security/qtpass/pkg/PLIST
> > > > --- security/qtpass/pkg/PLIST.orig
> > > > +++ security/qtpass/pkg/PLIST
> > > > @@ -1 +1,8 @@
> > > >   @bin bin/qtpass
> > > > +share/applications/qtpass.desktop
> > > > +share/icons/hicolor/512x512/apps/qtpass-icon.png
> > > > +share/icons/hicolor/scalable/apps/qtpass-icon.svg
> > > > +share/metainfo/
> > > > +share/metainfo/qtpass.appdata.xml
> > > > +@tag update-desktop-database
> > > > +@tag gtk-update-icon-cache %D/share/icons/hicolor
> > > > 

Reply via email to