From owner-svn-ports-all@freebsd.org Tue Jan 28 16:45:54 2020 Return-Path: Delivered-To: svn-ports-all@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 1C095232EA0; Tue, 28 Jan 2020 16:45:54 +0000 (UTC) (envelope-from matthias.andree@tu-dortmund.de) Received: from unimail.uni-dortmund.de (mx1.hrz.uni-dortmund.de [129.217.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "unimail.tu-dortmund.de", Issuer "DFN-Verein Global Issuing CA" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 486XYY0Nlqz4C9t; Tue, 28 Jan 2020 16:45:52 +0000 (UTC) (envelope-from matthias.andree@tu-dortmund.de) Received: from [10.24.114.231] (tmo-123-158.customers.d1-online.com [80.187.123.158]) (authenticated bits=0) by unimail.uni-dortmund.de (8.16.0.41/8.16.0.41) with ESMTPSA id 00SGjjTm013406 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128 verify=NOT); Tue, 28 Jan 2020 17:45:46 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tu-dortmund.de; s=unimail; t=1580229950; bh=eBQmu9t3JCLpkQrnxDimOkyLev6b60IlWk7QdpxM2rM=; h=Date:In-Reply-To:References:Subject:To:CC:From; b=hg4+nnN9/b7b9kjIom5QWqyBwLvZCS0XHUVO7hA1DslGuAvyKyhkfXWJcv5WEmTnX IIQHcaS3Zy77Bj7PFIEIiJqtvih65sSzFogr3FGJF6+5n8Bvemx6Idu6TL7KV8kITC VA5RNA+REv1yeS/iJb0jM9GwcOJhFdjPuWRJca/8= Date: Tue, 28 Jan 2020 16:43:15 +0000 User-Agent: K-9 Mail for Android In-Reply-To: <1rrk-jzz9-wny@FreeBSD.org> References: <202001260020.00Q0K1cG087750@repo.freebsd.org> <35c29ce8-67ab-61ea-b895-f70d2b6044fa@FreeBSD.org> <1rrk-jzz9-wny@FreeBSD.org> MIME-Version: 1.0 Subject: Re: svn commit: r524147 - in head/security: ca_root_nss nss To: Jan Beich CC: Renato Botelho , ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org, Glen Barber From: Matthias Andree Message-ID: <6130DF4A-9A8A-4175-B79F-6DAAB63A8872@tu-dortmund.de> X-Rspamd-Queue-Id: 486XYY0Nlqz4C9t X-Spamd-Bar: / Authentication-Results: mx1.freebsd.org; dkim=fail (rsa verify failed) header.d=tu-dortmund.de header.s=unimail header.b=hg4+nnN9; dmarc=none; spf=pass (mx1.freebsd.org: domain of matthias.andree@tu-dortmund.de designates 129.217.128.51 as permitted sender) smtp.mailfrom=matthias.andree@tu-dortmund.de X-Spamd-Result: default: False [0.50 / 15.00]; ARC_NA(0.00)[]; RCVD_VIA_SMTP_AUTH(0.00)[]; NEURAL_HAM_MEDIUM(-0.12)[-0.122,0]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; R_DKIM_REJECT(1.00)[tu-dortmund.de:s=unimail]; R_SPF_ALLOW(-0.20)[+ip4:129.217.128.0/24]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; TO_MATCH_ENVRCPT_ALL(0.00)[]; DMARC_NA(0.00)[tu-dortmund.de]; RWL_MAILSPIKE_GOOD(0.00)[51.128.217.129.rep.mailspike.net : 127.0.0.18]; RCPT_COUNT_FIVE(0.00)[6]; DKIM_TRACE(0.00)[tu-dortmund.de:-]; RCVD_IN_DNSWL_MED(-0.20)[51.128.217.129.list.dnswl.org : 127.0.11.2]; NEURAL_SPAM_LONG(0.11)[0.110,0]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+,1:+,2:~]; IP_SCORE(0.01)[asn: 680(0.09), country: DE(-0.02)]; ASN(0.00)[asn:680, ipnet:129.217.0.0/16, country:DE]; MID_RHS_MATCH_FROM(0.00)[]; RCVD_TLS_ALL(0.00)[]; RCVD_COUNT_TWO(0.00)[2] Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.29 X-BeenThere: svn-ports-all@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: SVN commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 28 Jan 2020 16:45:54 -0000 Same story, I build each upstream release on head/ half a dozen times becau= se we package RCs without marking them so=2E Why the rush?=20 Am January 27, 2020 10:28:42 PM UTC schrieb Jan Beich : >Matthias Andree writes: > >> Am 27=2E01=2E20 um 19:32 schrieb Jan Beich: >> >>> Renato Botelho writes: >>>=20 >>>> On 25/01/20 21:20, Jan Beich wrote: >>>> >>>>> Author: jbeich >>>>> Date: Sun Jan 26 00:20:01 2020 >>>>> New Revision: 524147 >>>>> URL: https://svnweb=2Efreebsd=2Eorg/changeset/ports/524147 >>>>> Log: >>>>> security/nss: update to 3=2E49=2E2 >>>>> Changes: >>>>> >https://developer=2Emozilla=2Eorg/docs/Mozilla/Projects/NSS/NSS_3=2E49=2E= 2_release_notes >>>>> =20 >Changes: https://hg=2Emozilla=2Eorg/projects/nss/shortlog/NSS_3_49_2_RTM >>>>> ABI: https://abi-laboratory=2Epro/tracker/timeline/nss/ >>>>> Reported by: Repology >>>> >>>> After this change it started failing to build on 11=2E3-STABLE armv6 >>>> with the following error: >>> [=2E=2E=2E] >>>> In file included from gcm-arm32-neon=2Ec:16: >>>> /nxb-bin/usr/lib/clang/8=2E0=2E1/include/arm_neon=2Eh:28:2: error: "N= EON >>>> support not enabled" >>>> #error "NEON support not enabled" >>>> ^ >>>> 1 error generated=2E >>>=20 >>> Needs to be reported upstream=2E Only Tier1 architectures are critical >>> enough to delay or block updates=2E >>>=20 >> >> Jan, the upgrade isn't marked security, why the rush? > >Agree but only after checking upstream commits=2E Mozilla often delays >advisories for bundled libraries under the veil of "responsible >disclosure" >to align with Firefox releases=2E > >Note, Firefox 73 which should have RC1 on 2020-02-04 (1 week from now) >will require NSS 3=2E49=2E2=2E