From nobody Tue Aug 16 16:18:57 2022 X-Original-To: dev-commits-ports-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4M6btn5L9fz4Ym40; Tue, 16 Aug 2022 16:18:57 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4M6btn4pt4z3cpC; Tue, 16 Aug 2022 16:18:57 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1660666737; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=jtKm3naO/4XD+VhEZnK9+QJ/8xW9hkinpSJIq+EZXnY=; b=AkJc9RLc4rboLE6ZJ1u6vnJfTdrCX6gD6WNB/OMwjRXvWH+cVTLhaPP3kNX+naiPkFp26W 7htL0JXZcMZ4/OzhPAlcjDWIa8xos1PWe3hbMGYOr5xa+1NVyI2Pa+RGDjnPNnFit2X5FA 4XvEuUGnpsmW9M4fPYe7veP0BdxepNFennN4+teHUMr4139haSxNYHm5U74ke2LyUmQ3/0 tg3bhsOknHa/Ezx73IketwKcGt3bz676wROOZHnrYVquhiOPdAnT+Qof60nFafrMGVeJuC Y2YO2U1E8FNUEuRFGDVi+GVD+xZ8o8X/Uzdy+V53P91pBEyKenoCPSpDGvrCug== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4M6btn3Y3tzGCn; Tue, 16 Aug 2022 16:18:57 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 27GGIvi1047483; Tue, 16 Aug 2022 16:18:57 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 27GGIvkb047482; Tue, 16 Aug 2022 16:18:57 GMT (envelope-from git) Date: Tue, 16 Aug 2022 16:18:57 GMT Message-Id: <202208161618.27GGIvkb047482@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Rodrigo Osorio Subject: git: af0a5e4af6e2 - 2022Q3 - net/rsync: Update to 3.2.5 List-Id: Commits to the quarterly branches of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-branches@freebsd.org X-BeenThere: dev-commits-ports-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: rodrigo X-Git-Repository: ports X-Git-Refname: refs/heads/2022Q3 X-Git-Reftype: branch X-Git-Commit: af0a5e4af6e253bc3f9ca1f5dd3154656bf3525e Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1660666737; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=jtKm3naO/4XD+VhEZnK9+QJ/8xW9hkinpSJIq+EZXnY=; b=R02sLTEVSbOsRmvFdjYtR+9c+wkXjcE7mOUm68uyxqAL9lxYuAjcz0M3uDN1gTZbNq2KfF cEL+uTvOE919ckJNJbsrXgJoY64UqJe48JnEuFiiOEfwcrf1IpgwoRZuDMNJl9aIaupLiM YpWxv//c+DT9DxAm3ukNZghURD+NMzkL0jyWnS+fiP94mJM9PbHjweUk8IXnZkAQgSik8v XVCeCbymcKoTycc0B71oLvxNg1Wtz9nNJyLX+cucbo7JF187KIP0TvpOLADCdy8/D6f3D+ YHC2EIA7690CPkxm7wHAnvjaB/nT3+jhlcF5XQ+cUC35gK7NwVuP/9QqMRcmIg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1660666737; a=rsa-sha256; cv=none; b=Uvw1Oje7OCdN4r0YGH2l3h8KCUH/g+F4RhTvy8uCX8Rp1ceqig9UspLOgCJ/9bwD57narg 9hmry2F8RHMBhCBv0bvCyrV0ETfsetZe3By9+NyqV5wKFNUsL+oo7x15HpTL4Y3wuyp9EO 1tUIBFEobvVggrgVLSq4p+X5/Gsab3RILwOAlQfxvuviZe5SeyO6vIDAwG3ll0wYcFfvkR 19k/MUq78s6H5kHegpXHITmW/h9gZn60IciXjAuZGeN98RQhZJTcTW8SIslDK/KME91IZh aqhVUV/+GgEao5DqClUsRzrDhEBp0p1rvZEX2ey9kz3r+HBoJ1O53D7UbZx2kg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch 2022Q3 has been updated by rodrigo: URL: https://cgit.FreeBSD.org/ports/commit/?id=af0a5e4af6e253bc3f9ca1f5dd3154656bf3525e commit af0a5e4af6e253bc3f9ca1f5dd3154656bf3525e Author: Rodrigo Osorio AuthorDate: 2022-08-16 15:45:13 +0000 Commit: Rodrigo Osorio CommitDate: 2022-08-16 16:04:13 +0000 net/rsync: Update to 3.2.5 Major changes: * CVE-2022-29154 Added some file-list safety checking * CVE-2022-37434 Fix in the bundled zlib (buffer overflow issue) * Fix the handling of filenames specified with backslash-quoted wildcards whith the remote-arg-escaping * Fix configure check for signed char that causes bogus checksums * rsync is compiled with an xxhash 0.8 library * New --trust-sender option to bypass the extra file-list safety checking Full changelog: https://github.com/WayneD/rsync/blob/master/NEWS.md PR: 265633 Reported by: rob2g2 Relnotes: yes Security: CVE-2022-29154 Security: CVE-2022-37434 (cherry picked from commit d7990faa348a894f6d8c4563abcaadc2cebaafc7) --- net/rsync/Makefile | 3 +-- net/rsync/distinfo | 14 +++++++++----- 2 files changed, 10 insertions(+), 7 deletions(-) diff --git a/net/rsync/Makefile b/net/rsync/Makefile index a5a72f8246e9..247729a6bc1c 100644 --- a/net/rsync/Makefile +++ b/net/rsync/Makefile @@ -1,8 +1,7 @@ # Created by: David O'Brien (obrien@cs.ucdavis.edu) PORTNAME= rsync -DISTVERSION= 3.2.4 -PORTREVISION= 2 +DISTVERSION= 3.2.5 CATEGORIES= net MASTER_SITES= https://www.mirrorservice.org/sites/rsync.samba.org/src/ \ http://rsync.mirror.garr.it/src/ \ diff --git a/net/rsync/distinfo b/net/rsync/distinfo index febadd2a8a24..8044044d080f 100644 --- a/net/rsync/distinfo +++ b/net/rsync/distinfo @@ -1,5 +1,9 @@ -TIMESTAMP = 1650365056 -SHA256 (rsync-3.2.4.tar.gz) = 6f761838d08052b0b6579cf7f6737d93e47f01f4da04c5d24d3447b7f2a5fad1 -SIZE (rsync-3.2.4.tar.gz) = 1114853 -SHA256 (rsync-patches-3.2.4.tar.gz) = 70a597590af6c61cf3d05d663429ff9f60ffe24e44f9c73a4cdc69ebdc1322a4 -SIZE (rsync-patches-3.2.4.tar.gz) = 133580 +TIMESTAMP = 1660557599 +SHA256 (rsync-3.2.5.tar.gz) = 2ac4d21635cdf791867bc377c35ca6dda7f50d919a58be45057fd51600c69aba +SIZE (rsync-3.2.5.tar.gz) = 1129957 +SHA256 (rsync-patches-3.2.5.tar.gz) = e7b1fdf1fc0fca68fd254246c2dc04f6ac90241e665dcf9dfc21dccd8270b6bb +SIZE (rsync-patches-3.2.5.tar.gz) = 141521 +SHA256 (rsync-patches-3.2.5.tar.gz) = e7b1fdf1fc0fca68fd254246c2dc04f6ac90241e665dcf9dfc21dccd8270b6bb +SIZE (rsync-patches-3.2.5.tar.gz) = 141521 +SHA256 (rsync-patches-3.2.5.tar.gz) = e7b1fdf1fc0fca68fd254246c2dc04f6ac90241e665dcf9dfc21dccd8270b6bb +SIZE (rsync-patches-3.2.5.tar.gz) = 141521