Re: git security update
On Fri, Aug 11, 2017 at 11:10:30AM +0300, Paul Irofti wrote: > On Fri, Aug 11, 2017 at 12:41:45AM -0400, Daniel Jakots wrote: > > Hello && coucou Benoit, > > > > Git's upstream released a couple of git releases to fix > > CVE-2017-1000117. Here's diff that update old-stable, stable and > > current. > > > > I went the lazy way which is 'update to latest bugfix release' and not > > just backporting patches. This was the easiest thing for me and it > > "sounds like the correct approach to" sthen :) > > > > Test, comments and ok? > > OK for -current, -stable still building... OK -stable.
Re: git security update
On Fri, Aug 11, 2017 at 12:41:45AM -0400, Daniel Jakots wrote: > Hello && coucou Benoit, > > Git's upstream released a couple of git releases to fix > CVE-2017-1000117. Here's diff that update old-stable, stable and > current. > > I went the lazy way which is 'update to latest bugfix release' and not > just backporting patches. This was the easiest thing for me and it > "sounds like the correct approach to" sthen :) > > Test, comments and ok? OK for -current, -stable still building... > > Cheers, > Daniel > Index: Makefile > === > RCS file: /cvs/ports/devel/git/Makefile,v > retrieving revision 1.178 > diff -u -p -r1.178 Makefile > --- Makefile 5 Aug 2017 19:09:05 - 1.178 > +++ Makefile 11 Aug 2017 04:24:54 - > @@ -4,7 +4,7 @@ COMMENT-main =GIT - Tree History Storag > COMMENT-svn =GIT - subversion interoperability tools > COMMENT-x11 =GIT - graphical tools > > -V = 2.14.0 > +V = 2.14.1 > DISTNAME = git-${V} > PKGNAME-main = ${DISTNAME} > PKGNAME-svn =git-svn-${V} > Index: distinfo > === > RCS file: /cvs/ports/devel/git/distinfo,v > retrieving revision 1.135 > diff -u -p -r1.135 distinfo > --- distinfo 5 Aug 2017 19:09:05 - 1.135 > +++ distinfo 11 Aug 2017 04:24:54 - > @@ -1,4 +1,4 @@ > -SHA256 (git-2.14.0.tar.gz) = yaZmRdacZ6dCGDGa/j1sVQf7kdq4AUYF34luk58Gvkg= > -SHA256 (git-manpages-2.14.0.tar.gz) = > riEZ/5I1BTlpHxOhHyqU5iVtzOY+CYMswWA2XdBQY2s= > -SIZE (git-2.14.0.tar.gz) = 6987666 > -SIZE (git-manpages-2.14.0.tar.gz) = 665143 > +SHA256 (git-2.14.1.tar.gz) = AZJTSbloOUDlOmIe5I3Z2aw/nlnAeYBrWDIcLPhaRGQ= > +SHA256 (git-manpages-2.14.1.tar.gz) = > jFgQzmXUTNMzMn06EVxbRicSovgSJdFC4HvYia2NwOA= > +SIZE (git-2.14.1.tar.gz) = 6987933 > +SIZE (git-manpages-2.14.1.tar.gz) = 665202 > Index: Makefile > === > RCS file: /cvs/ports/devel/git/Makefile,v > retrieving revision 1.158 > diff -u -p -r1.158 Makefile > --- Makefile 28 Jun 2016 07:27:14 - 1.158 > +++ Makefile 11 Aug 2017 04:33:41 - > @@ -4,7 +4,7 @@ COMMENT-main =GIT - Tree History Storag > COMMENT-svn =GIT - subversion interoperability tools > COMMENT-x11 =GIT - graphical tools > > -V = 2.9.0 > +V = 2.9.5 > DISTNAME = git-${V} > PKGNAME-main = ${DISTNAME} > PKGNAME-svn =git-svn-${V} > Index: distinfo > === > RCS file: /cvs/ports/devel/git/distinfo,v > retrieving revision 1.121 > diff -u -p -r1.121 distinfo > --- distinfo 28 Jun 2016 07:27:14 - 1.121 > +++ distinfo 11 Aug 2017 04:33:41 - > @@ -1,4 +1,4 @@ > -SHA256 (git-2.9.0.tar.gz) = v/dWD1YC/Njjdmng9l7wjG7cmW5PMk5O1ruKhHZeML0= > -SHA256 (git-manpages-2.9.0.tar.gz) = > NbppqFYFKaqDfjlabWyNQvTSm0CjwcxuPcabsfqtszI= > -SIZE (git-2.9.0.tar.gz) = 5903371 > -SIZE (git-manpages-2.9.0.tar.gz) = 629249 > +SHA256 (git-2.9.5.tar.gz) = j6V1M4E31thQtS0gfPcVXNH0AD69aY8Pt19l77hi738= > +SHA256 (git-manpages-2.9.5.tar.gz) = > tRWULoGiv68bJDehV8Qig+lzHS2YaU4n9vItaZypKSw= > +SIZE (git-2.9.5.tar.gz) = 5928730 > +SIZE (git-manpages-2.9.5.tar.gz) = 633471 > Index: Makefile > === > RCS file: /cvs/ports/devel/git/Makefile,v > retrieving revision 1.168 > diff -u -p -r1.168 Makefile > --- Makefile 26 Mar 2017 19:07:10 - 1.168 > +++ Makefile 11 Aug 2017 04:27:51 - > @@ -4,7 +4,7 @@ COMMENT-main =GIT - Tree History Storag > COMMENT-svn =GIT - subversion interoperability tools > COMMENT-x11 =GIT - graphical tools > > -V = 2.12.2 > +V = 2.12.4 > DISTNAME = git-${V} > PKGNAME-main = ${DISTNAME} > PKGNAME-svn =git-svn-${V} > Index: distinfo > === > RCS file: /cvs/ports/devel/git/distinfo,v > retrieving revision 1.129 > diff -u -p -r1.129 distinfo > --- distinfo 26 Mar 2017 19:07:10 - 1.129 > +++ distinfo 11 Aug 2017 04:27:51 - > @@ -1,4 +1,4 @@ > -SHA256 (git-2.12.2.tar.gz) = 2cbXh6JGcNflEA2yNnwlCtl1bvgIT7FTpGuC8dGG+Ng= > -SHA256 (git-manpages-2.12.2.tar.gz) = > bn7VA/EZBzTlfJQn3zVrQgIPEl+jarBHh3eWCmgq31A= > -SIZE (git-2.12.2.tar.gz) = 6389118 > -SIZE (git-manpages-2.12.2.tar.gz) = 653673 > +SHA256 (git-2.12.4.tar.gz) = sleG8KE+OalVjuylbADHWHA8gDvekPm8WrVPS+Lrsf8= > +SHA256 (git-manpages-2.12.4.tar.gz) = > 4OashhshzmBHNnTYj48+GvbifVugzt3vL4z/Am8ux9I= > +SIZE (git-2.12.4.tar.gz) = 6407661 > +SIZE (git-manpages-2.12.4.tar.gz) = 654944 > Index: patches/patch-Makefile > === > RCS file: /cvs/ports/devel/git/patches/patch-Makefile,v > retrieving revision 1.69 > diff -u -p -r1.69 patch-Makefile > --- patches/patch
Re: git security update
On Fri, Aug 11, 2017 at 6:41 AM, Daniel Jakots wrote: > Hello && coucou Benoit, > > Git's upstream released a couple of git releases to fix > CVE-2017-1000117. Here's diff that update old-stable, stable and > current. > > I went the lazy way which is 'update to latest bugfix release' and not > just backporting patches. This was the easiest thing for me and it > "sounds like the correct approach to" sthen :) > > Test, comments and ok? > > Cheers, > Daniel ok with me for the -current one. Ciao! David
git security update
Hello && coucou Benoit, Git's upstream released a couple of git releases to fix CVE-2017-1000117. Here's diff that update old-stable, stable and current. I went the lazy way which is 'update to latest bugfix release' and not just backporting patches. This was the easiest thing for me and it "sounds like the correct approach to" sthen :) Test, comments and ok? Cheers, Daniel Index: Makefile === RCS file: /cvs/ports/devel/git/Makefile,v retrieving revision 1.178 diff -u -p -r1.178 Makefile --- Makefile 5 Aug 2017 19:09:05 - 1.178 +++ Makefile 11 Aug 2017 04:24:54 - @@ -4,7 +4,7 @@ COMMENT-main = GIT - Tree History Storag COMMENT-svn = GIT - subversion interoperability tools COMMENT-x11 = GIT - graphical tools -V = 2.14.0 +V = 2.14.1 DISTNAME = git-${V} PKGNAME-main = ${DISTNAME} PKGNAME-svn = git-svn-${V} Index: distinfo === RCS file: /cvs/ports/devel/git/distinfo,v retrieving revision 1.135 diff -u -p -r1.135 distinfo --- distinfo 5 Aug 2017 19:09:05 - 1.135 +++ distinfo 11 Aug 2017 04:24:54 - @@ -1,4 +1,4 @@ -SHA256 (git-2.14.0.tar.gz) = yaZmRdacZ6dCGDGa/j1sVQf7kdq4AUYF34luk58Gvkg= -SHA256 (git-manpages-2.14.0.tar.gz) = riEZ/5I1BTlpHxOhHyqU5iVtzOY+CYMswWA2XdBQY2s= -SIZE (git-2.14.0.tar.gz) = 6987666 -SIZE (git-manpages-2.14.0.tar.gz) = 665143 +SHA256 (git-2.14.1.tar.gz) = AZJTSbloOUDlOmIe5I3Z2aw/nlnAeYBrWDIcLPhaRGQ= +SHA256 (git-manpages-2.14.1.tar.gz) = jFgQzmXUTNMzMn06EVxbRicSovgSJdFC4HvYia2NwOA= +SIZE (git-2.14.1.tar.gz) = 6987933 +SIZE (git-manpages-2.14.1.tar.gz) = 665202 Index: Makefile === RCS file: /cvs/ports/devel/git/Makefile,v retrieving revision 1.158 diff -u -p -r1.158 Makefile --- Makefile 28 Jun 2016 07:27:14 - 1.158 +++ Makefile 11 Aug 2017 04:33:41 - @@ -4,7 +4,7 @@ COMMENT-main = GIT - Tree History Storag COMMENT-svn = GIT - subversion interoperability tools COMMENT-x11 = GIT - graphical tools -V = 2.9.0 +V = 2.9.5 DISTNAME = git-${V} PKGNAME-main = ${DISTNAME} PKGNAME-svn = git-svn-${V} Index: distinfo === RCS file: /cvs/ports/devel/git/distinfo,v retrieving revision 1.121 diff -u -p -r1.121 distinfo --- distinfo 28 Jun 2016 07:27:14 - 1.121 +++ distinfo 11 Aug 2017 04:33:41 - @@ -1,4 +1,4 @@ -SHA256 (git-2.9.0.tar.gz) = v/dWD1YC/Njjdmng9l7wjG7cmW5PMk5O1ruKhHZeML0= -SHA256 (git-manpages-2.9.0.tar.gz) = NbppqFYFKaqDfjlabWyNQvTSm0CjwcxuPcabsfqtszI= -SIZE (git-2.9.0.tar.gz) = 5903371 -SIZE (git-manpages-2.9.0.tar.gz) = 629249 +SHA256 (git-2.9.5.tar.gz) = j6V1M4E31thQtS0gfPcVXNH0AD69aY8Pt19l77hi738= +SHA256 (git-manpages-2.9.5.tar.gz) = tRWULoGiv68bJDehV8Qig+lzHS2YaU4n9vItaZypKSw= +SIZE (git-2.9.5.tar.gz) = 5928730 +SIZE (git-manpages-2.9.5.tar.gz) = 633471 Index: Makefile === RCS file: /cvs/ports/devel/git/Makefile,v retrieving revision 1.168 diff -u -p -r1.168 Makefile --- Makefile 26 Mar 2017 19:07:10 - 1.168 +++ Makefile 11 Aug 2017 04:27:51 - @@ -4,7 +4,7 @@ COMMENT-main = GIT - Tree History Storag COMMENT-svn = GIT - subversion interoperability tools COMMENT-x11 = GIT - graphical tools -V = 2.12.2 +V = 2.12.4 DISTNAME = git-${V} PKGNAME-main = ${DISTNAME} PKGNAME-svn = git-svn-${V} Index: distinfo === RCS file: /cvs/ports/devel/git/distinfo,v retrieving revision 1.129 diff -u -p -r1.129 distinfo --- distinfo 26 Mar 2017 19:07:10 - 1.129 +++ distinfo 11 Aug 2017 04:27:51 - @@ -1,4 +1,4 @@ -SHA256 (git-2.12.2.tar.gz) = 2cbXh6JGcNflEA2yNnwlCtl1bvgIT7FTpGuC8dGG+Ng= -SHA256 (git-manpages-2.12.2.tar.gz) = bn7VA/EZBzTlfJQn3zVrQgIPEl+jarBHh3eWCmgq31A= -SIZE (git-2.12.2.tar.gz) = 6389118 -SIZE (git-manpages-2.12.2.tar.gz) = 653673 +SHA256 (git-2.12.4.tar.gz) = sleG8KE+OalVjuylbADHWHA8gDvekPm8WrVPS+Lrsf8= +SHA256 (git-manpages-2.12.4.tar.gz) = 4OashhshzmBHNnTYj48+GvbifVugzt3vL4z/Am8ux9I= +SIZE (git-2.12.4.tar.gz) = 6407661 +SIZE (git-manpages-2.12.4.tar.gz) = 654944 Index: patches/patch-Makefile === RCS file: /cvs/ports/devel/git/patches/patch-Makefile,v retrieving revision 1.69 diff -u -p -r1.69 patch-Makefile --- patches/patch-Makefile 26 Mar 2017 19:07:10 - 1.69 +++ patches/patch-Makefile 11 Aug 2017 04:27:51 - @@ -1,7 +1,7 @@ $OpenBSD: patch-Makefile,v 1.69 2017/03/26 19:07:10 benoit Exp $ Makefile.orig Fri Mar 24 21:50:52 2017 -+++ Makefile Sun Mar 26 15:03:52 2017 -@@ -2287,7 +2287,7 @@ export TEST_NO_MALLOC_CHECK +--- Makefile.orig Wed Aug 9 15:52:01 2017 Makefile Fri Aug 11 00:19:11 2017 +@@ -2290,7 +2290,7 @@ export TEST_NO_MALLOC_CHECK ### Testing rules Index: patches/patch-t_t9200-git-cvsexportcommit_sh =