From owner-freebsd-stable@freebsd.org Tue Mar 30 15:39:01 2021 Return-Path: Delivered-To: freebsd-stable@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 62D2B57ABC3 for ; Tue, 30 Mar 2021 15:39:01 +0000 (UTC) (envelope-from tech-lists@zyxst.net) Received: from wout5-smtp.messagingengine.com (wout5-smtp.messagingengine.com [64.147.123.21]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4F8tsJ6MsTz4td3 for ; Tue, 30 Mar 2021 15:39:00 +0000 (UTC) (envelope-from tech-lists@zyxst.net) Received: from compute2.internal (compute2.nyi.internal [10.202.2.42]) by mailout.west.internal (Postfix) with ESMTP id 7367423A3 for ; Tue, 30 Mar 2021 11:38:59 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute2.internal (MEProxy); Tue, 30 Mar 2021 11:38:59 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zyxst.net; h= date:from:to:subject:message-id:references:mime-version :content-type:in-reply-to; s=fm2; bh=ABsoB7Buym6Q1BzDWV6qY6PG3WD Itpc/N/K6v0xSkA4=; b=VpWoWnZ3gYFQEz8/ag3M9q8m+Tr+dyf0RqlIX734WtV NmYl2sCfxWaAU1h+9N5h+4yDIhs2OjI5wg6OqiO7ExsVBZ+qQ0RjTWa7vHzP46yR rSxl7OWGGNfR+t990x9DemnPJtoEH0EevSkuav458FzmrimUXDmWIyBR31D/uHZo enxB3IBGAApJgXLl+SMKmWzrqSeO4CRJzmT05ZQByR/Zvp7P1Sz1Z7fB2jZdTnXG MtyS33I1mcJ+IhtqyibDCJZ1/3u58bNufUoITofi6glXt1/TUpvwfjxeKFA5P9SH kLpAGwH6Z5GJKxy6IBrirEBV1Ecwu3x40ggadZkxyHg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; bh=ABsoB7 Buym6Q1BzDWV6qY6PG3WDItpc/N/K6v0xSkA4=; b=kWDEOYOXqdkxw6HtTvfcKq L8hxdRp4KNd3gkQ7EcRCsT0UXYwcd6cUgNJYZyQNXoA2usvf9jTKN1x/Lrz5kzNg 9oTnLWtXcr9Wi0sTa2fDFXvvFIEz4rv2bYerxJqF75YyXDBcxOiod65gm+KEb3wB SpbUknEY/+rWH2FiQbaj5CySP8m7SS0ddJuTPXpuuxew7K5OM/oPNs7fy5UAC4Eg cWwIOYDK0scH6zW8NLndniIrvdHzEJ26yVtJVsOw/yjPXY0nHS5Jg6/dRqu1jUL1 541ilvVnixhZnDRSBJpuK96SSAmWIA3YBb1qMq1cFY96KjRR+PjCd+L7MY6Hf8vw == X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduledrudeitddgleduucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpeffhffvuffkfhggtggujgesghdtre ertddtvdenucfhrhhomhepthgvtghhqdhlihhsthhsuceothgvtghhqdhlihhsthhsseii hiigshhtrdhnvghtqeenucggtffrrghtthgvrhhnpeettddtudeugfeggefhkeekteekje elfeffleehjeffgffftdeffedtjeegueeiffenucffohhmrghinhepfhhrvggvsghsugdr ohhrghenucfkphepkeelrddugeehrddutddtrddufeelnecuvehluhhsthgvrhfuihiivg eptdenucfrrghrrghmpehmrghilhhfrhhomhepthgvtghhqdhlihhsthhsseiihiigshht rdhnvght X-ME-Proxy: Received: from cloud.zyxst.net (v007.zyxst.net [89.145.100.139]) by mail.messagingengine.com (Postfix) with ESMTPA id A94A7108005F for ; Tue, 30 Mar 2021 11:38:58 -0400 (EDT) Date: Tue, 30 Mar 2021 16:38:57 +0100 From: tech-lists To: freebsd-stable@freebsd.org Subject: Re: possibly silly question regarding freebsd-update Message-ID: Mail-Followup-To: freebsd-stable@freebsd.org References: MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="86sTB+i6CEzL6SKD" Content-Disposition: inline In-Reply-To: X-Rspamd-Queue-Id: 4F8tsJ6MsTz4td3 X-Spamd-Bar: ----- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=zyxst.net header.s=fm2 header.b=VpWoWnZ3; dkim=pass header.d=messagingengine.com header.s=fm2 header.b=kWDEOYOX; dmarc=none; spf=pass (mx1.freebsd.org: domain of tech-lists@zyxst.net designates 64.147.123.21 as permitted sender) smtp.mailfrom=tech-lists@zyxst.net X-Spamd-Result: default: False [-5.70 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; ARC_NA(0.00)[]; R_DKIM_ALLOW(-0.20)[zyxst.net:s=fm2,messagingengine.com:s=fm2]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; FROM_HAS_DN(0.00)[]; RWL_MAILSPIKE_VERYGOOD(0.00)[64.147.123.21:from]; R_SPF_ALLOW(-0.20)[+ip4:64.147.123.21:c]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.20)[multipart/signed,text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-stable@freebsd.org]; TO_DN_NONE(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; NEURAL_HAM_LONG(-1.00)[-1.000]; RCVD_COUNT_THREE(0.00)[4]; DMARC_NA(0.00)[zyxst.net]; DKIM_TRACE(0.00)[zyxst.net:+,messagingengine.com:+]; NEURAL_HAM_SHORT(-1.00)[-1.000]; SIGNED_PGP(-2.00)[]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:11403, ipnet:64.147.123.0/24, country:US]; MAILMAN_DEST(0.00)[freebsd-stable]; RCVD_IN_DNSWL_LOW(-0.10)[64.147.123.21:from] X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 30 Mar 2021 15:39:01 -0000 --86sTB+i6CEzL6SKD Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Mar 30, 2021 at 05:22:30PM +0200, Guido Falsi via freebsd-stable wr= ote: > >No, as you can see in the commit in the official git [1] while for >current and stable the new upstream version of openssl was imported for >the release the fix was applied without importing the new release and >without changing the reported version of the library. > >So with 12.2p5 you do get the fix but don't get a new version of the >library. > > >[1] >https://cgit.freebsd.org/src/commit/?h=3Dreleng/12.2&id=3Daf61348d61f51a88= b438d41c3c91b56b2b65ed9b On this url, near the top, there's this: "Fix multiple OpenSSL vulnerabilities. Add UPDATING and bump version." next to that, we have "releng/12.2". So, I'm expecting the version information pertaining to=20 opensslto be bumped. Is this expectation unreasonable?=20 I'm not a developer. --=20 J. --86sTB+i6CEzL6SKD Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEE8n3tWhxW11Ccvv9/s8o7QhFzNAUFAmBjRgkACgkQs8o7QhFz NAWrBw//THpi/CPY0HrU3jnYA6/j5LcBYY2W4Qn++qArvz1z6popMJEQkiOkYlaQ KeNFqxJIkJsRR0mycI0fQLxmSnW8dh3bHegy4f2GGrUbY9r4q+RlnyLZiln8Etq2 aYCp/lAT953aRHoo0JoXE3VkSsQQQCZwcpsfCgD4qKMeCEGzfTMx+ijwAg6AzHpx h5P4MmpcHPOTS4aYLdVM2zoH9Jc8TM0bJTmD1+1O2gNBeFPz/i99z+AmWobJED48 PoNyv8s2MjsZBCbKp/7/A0wCh+VCOd0QRXRD5U2PkfPdtcirF8Ko0vYc0Mbum7Fa 90eNqp3kRl+ssTjSon2YNZamRdA28LduUi0JqK/B+U5NgigLeoS+ZtaHF6ToY9Jw zqYbthEFCrQURen0dbpUCGkdP8VQ4jCCgo1WCWrJebsgdInuTRHPki3aYaVV59NI oAStqS596G3LsCAINhTd4TOwzlCD6gKVOXAdD6ovZNetCRKUqhWJ2n9jsud3pX+g GR4SFStmachAlEsegCze3vwDpjkXsB1cVKO8LYg+O1dwATfoszL2PzJat2nkSUU1 Xv/ixxm1WifxS3EDJhGD0oxc1bxYafTCsby3iM4OVNz9zsut7exUizfy5H2c06J3 2LwqWeSHpSD8QPRJWsUDtiW9Ksj5uCZccCsKp16qen1ChR42OeU= =/U6y -----END PGP SIGNATURE----- --86sTB+i6CEzL6SKD--