From nobody Sun Dec 22 12:53:01 2024 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4YGLgS140Bz5Wy0x for ; Sun, 22 Dec 2024 12:53:40 +0000 (UTC) (envelope-from sunpoet@freebsd.org) Received: from smtp.freebsd.org (smtp.freebsd.org [IPv6:2610:1c1:1:606c::24b:4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "smtp.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4YGLgS0rDZz4LYw for ; Sun, 22 Dec 2024 12:53:40 +0000 (UTC) (envelope-from sunpoet@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1734872020; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=hWQVZ71O0tOewaUHlstF++Mn43OEUAdkEg2gKcNrUJ0=; b=GmPZc7ISYLFqaigFPfAY3HtUECnG4YwUqNqxZpycxFWeuluOHsI2Rl0TPifgLxC2AaJ3Vq IHCyelR1/k/L+9Fkdel5QNSrgOpJFSVRpk0aNWl3p6ClpwHUZrXmi4TnrdrQKZ/5W+hrWy Lpqy4FREstORSOrdAeXvak9Ap3K447QubYsSc3+wZzex9JY3jiRrJW+E56r796qykRW3or jcZk+bR5cGAshg+tvhvv7y6iaBKNVFzcGiYai3G1dMime08mECRXHR0XQb4UurKg+iadih Am2hk+PArj5rhgLPWAwT0vvvvWyWFTT87JHwO9CrGueNYeLHeHNpORyvkgmqBg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1734872020; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=hWQVZ71O0tOewaUHlstF++Mn43OEUAdkEg2gKcNrUJ0=; b=I1XeKcYUD7EYe3G0rDHobXi+3giogaW8Y3H0wOkvDfI4g+OmympX4Uh48nQc74I25Vo6mt 5x7LY//e/6WMtcgUAmbJYVkadUtOh7HPEL3UgBxUKyW40TlJRvz6nNLEG/bVu76v5fwrMZ ytz4rMT8uPQC3pcOqbF/JwJH7GyhFwRzuB+QcPJOAJQkOxwX+QUFPAP5wPf/mYTrkDtbP7 DtXVHiOLKqDEdbw6vLG46lJAcRCmFvOaxZZ6OEG6Ykl0TgdIFasGUiQIzlR04oUmbz1/5A TF842uNlKg31XsLr3kxKiubX+WM6AArJPJfCfIa78l5nnH+EgH13Ocd98wu4fg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1734872020; a=rsa-sha256; cv=none; b=bjWxchsWok8mEnH6lWdxZ7r4YDrKwZJ8SvTxZk30ZKpyFcmyVMGIIO4dVyMacXMCNuWTX4 fsbzTF/n2NBew+Xp9qvR8OLnJWXO3zNVbSqNdbCgVGjXF0XUlyWYNHC7aJyEg5EtrUs9l+ YoBCCGVpt6ZenT9yg5Ekp6lBHHVvdlHTjtnSAUKhTcK/GNTTSUnIBAZamBPWxjKIgzChG5 gm0030A1IT1lyovb6ckRudVXVJnl4uFMsfoQlcS+f/H70dtJ9LX5E9U7F7ZNujerquUAQc RCMgXBbJ55r+HGMpx62fqbb2uoyQPV2GtuMM+7JusfaDSYIz/ogNT+jmWMMlIw== Received: from mail-ed1-f47.google.com (mail-ed1-f47.google.com [209.85.208.47]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) (Authenticated sender: sunpoet) by smtp.freebsd.org (Postfix) with ESMTPSA id 4YGLgS09xhz1HJ1 for ; Sun, 22 Dec 2024 12:53:40 +0000 (UTC) (envelope-from sunpoet@freebsd.org) Received: by mail-ed1-f47.google.com with SMTP id 4fb4d7f45d1cf-5cec9609303so4438600a12.1 for ; Sun, 22 Dec 2024 04:53:39 -0800 (PST) X-Forwarded-Encrypted: i=1; AJvYcCVky0YewhE1JrRyqw7JEAJjrWb2iYHw84M/Zeul72p+lCvXIpE7nNeNaHjr/xTXdbe9SvEbwMO/Wm68BoGu2YmXtNrWYPAF@freebsd.org X-Gm-Message-State: AOJu0YyhydX6N6j5Pd60azZrkvBEmQd+1rkBa9RTRef98DSzMHaBg1YK OCd2w60f8o0bcfVPWb520ntpwGMD3D31WjggUpbaQ3C6M43yaVkolzPVuiOrQxClFJt3PwYT2pL 5hKgEdzu9Fv9GFuffPJoMJucw/OoEbIYqNyX3nQ== X-Google-Smtp-Source: AGHT+IE9GU5hMJUfu8Bl7VWjsnlWTXAuxxCyMi/c6HEwxwSm9WaSrQpBiFqQo7IEhyZTIhuXcnhq/00PFkERO9PAdSE= X-Received: by 2002:a05:6402:278f:b0:5d0:c9e6:30bc with SMTP id 4fb4d7f45d1cf-5d81dd89401mr7965915a12.10.1734872018303; Sun, 22 Dec 2024 04:53:38 -0800 (PST) List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 References: <202412221122.4BMBMes6032613@gitrepo.freebsd.org> <9c247e0246a1a5cbb5620c0aa79c0f8e@mail.infomaniak.com> In-Reply-To: <9c247e0246a1a5cbb5620c0aa79c0f8e@mail.infomaniak.com> From: Po-Chuan Hsieh Date: Sun, 22 Dec 2024 20:53:01 +0800 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: git: 2a3bac310439 - main - ftp/curl: Update to 8.11.1 To: Daniel Engberg Cc: ports-committers@freebsd.org, dev-commits-ports-all@freebsd.org, dev-commits-ports-main@freebsd.org Content-Type: multipart/alternative; boundary="00000000000061e2970629db5e10" --00000000000061e2970629db5e10 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Sun, Dec 22, 2024 at 7:35=E2=80=AFPM Daniel Engberg < daniel.engberg.lists@pyret.net> wrote: > On 2024-12-22T12:22:55.000+01:00, Po-Chuan Hsieh > wrote: > > > The branch main has been updated by sunpoet: > > URL: https://cgit.FreeBSD.org/ports/commit/?id=3D2a3bac310439f8de03b945ae= 6b596ddf6384d411 > > commit 2a3bac310439f8de03b945ae6b596ddf6384d411 > Author: Po-Chuan Hsieh > AuthorDate: 2024-12-22 11:21:05 +0000 > Commit: Po-Chuan Hsieh > CommitDate: 2024-12-22 11:21:15 +0000 > > ftp/curl: Update to 8.11.1 > > Changes: https://curl.se/changes.html > Security: CVE-2024-11053 > --- > ftp/curl/Makefile | 8 +++++--- > ftp/curl/distinfo | 8 +++++--- > ftp/curl/files/extra-patch-gssapi | 11 ----------- > ftp/curl/pkg-plist | 2 ++ > 4 files changed, 12 insertions(+), 17 deletions(-) > > diff --git a/ftp/curl/Makefile b/ftp/curl/Makefile > index 42e6fa4f27dc..26a1ee93cde6 100644 > --- a/ftp/curl/Makefile > +++ b/ftp/curl/Makefile > @@ -1,10 +1,12 @@ > PORTNAME=3D curl > -PORTVERSION=3D 8.11.0 > -PORTREVISION=3D 1 > +PORTVERSION=3D 8.11.1 > CATEGORIES=3D ftp net www > MASTER_SITES=3D https://curl.se/download/ \ > https://github.com/curl/curl/releases/download/curl-${PORTVERSION:S|.|= _|g}/ > > +PATCH_SITES=3D https://github.com/curl/curl/commit/ > +PATCHFILES=3D ff5091aa9f73802e894b1cbdf24ab84e103200e2.patch:-p1 > + > MAINTAINER=3D sunpoet@FreeBSD.org > COMMENT=3D Command line tool and library for transferring data with URLs > WWW=3D https://curl.se/ \ > @@ -24,6 +26,7 @@ CONFIGURE_ARGS=3D --disable-test-bundles \ > --enable-headers-api \ > --enable-hsts \ > --enable-http-auth \ > + --enable-manual \ > --enable-mime \ > --enable-netrc \ > --enable-openssl-auto-load-config \ > @@ -100,7 +103,6 @@ GNUTLS_LIB_DEPENDS=3D libgnutls.so:security/gnutls \ > GOPHER_CONFIGURE_ENABLE=3Dgopher > GSSAPI_BASE_CONFIGURE_ON=3D --with-gssapi=3D${GSSAPIBASEDIR} ${GSSAPI_CO= NFIGURE_ARGS} > GSSAPI_BASE_CPPFLAGS=3D ${GSSAPICPPFLAGS} > -GSSAPI_BASE_EXTRA_PATCHES=3D ${PATCHDIR}/extra-patch-gssapi > GSSAPI_BASE_LDFLAGS=3D ${GSSAPILDFLAGS} > GSSAPI_BASE_LIBS=3D ${GSSAPILIBS} > GSSAPI_BASE_USES=3D gssapi > diff --git a/ftp/curl/distinfo b/ftp/curl/distinfo > index d6ed0ab70c0c..0122660f4409 100644 > --- a/ftp/curl/distinfo > +++ b/ftp/curl/distinfo > @@ -1,3 +1,5 @@ > -TIMESTAMP =3D 1731679162 > -SHA256 (curl-8.11.0.tar.xz) =3D db59cf0d671ca6e7f5c2c5ec177084a33a79e04c= 97e71cf183a5cdea235054eb > -SIZE (curl-8.11.0.tar.xz) =3D 2750684 > +TIMESTAMP =3D 1734769461 > +SHA256 (curl-8.11.1.tar.xz) =3D c7ca7db48b0909743eaef34250da02c19bc61d4f= 1dcedd6603f109409536ab56 > +SIZE (curl-8.11.1.tar.xz) =3D 2751236 > +SHA256 (ff5091aa9f73802e894b1cbdf24ab84e103200e2.patch) =3D 297a61cc260f= 4bf9e60e5b939e559d5e50df8484328f92d06ffcc256e538d998 > +SIZE (ff5091aa9f73802e894b1cbdf24ab84e103200e2.patch) =3D 1074 > diff --git a/ftp/curl/files/extra-patch-gssapi b/ftp/curl/files/extra-pat= ch-gssapi > deleted file mode 100644 > index 285b5086bc71..000000000000 > --- a/ftp/curl/files/extra-patch-gssapi > +++ /dev/null > @@ -1,11 +0,0 @@ > ---- configure.orig 2024-11-06 07:09:19 UTC > -+++ configure > -@@ -26192,7 +26197,7 @@ printf "%s\n" "found" >&6; } > - if test -n "$gnu_gss"; then > - LIBCURL_PC_REQUIRES_PRIVATE=3D"$LIBCURL_PC_REQUIRES_PRIVATE gss" > - elif test "x$not_mit" =3D "x1"; then > -- LIBCURL_PC_REQUIRES_PRIVATE=3D"$LIBCURL_PC_REQUIRES_PRIVATE heimdal= -gssapi" > -+ LIBCURL_PC_REQUIRES_PRIVATE=3D"$LIBCURL_PC_REQUIRES_PRIVATE" > - else > - LIBCURL_PC_REQUIRES_PRIVATE=3D"$LIBCURL_PC_REQUIRES_PRIVATE mit-krb= 5-gssapi" > - fi > diff --git a/ftp/curl/pkg-plist b/ftp/curl/pkg-plist > index a88d7f9dc61e..a940df55cbf3 100644 > --- a/ftp/curl/pkg-plist > +++ b/ftp/curl/pkg-plist > @@ -18,6 +18,7 @@ lib/libcurl.so.4 > lib/libcurl.so.4.8.0 > libdata/pkgconfig/libcurl.pc > share/aclocal/libcurl.m4 > +%%PORTDOCS%%%%DOCSDIR%%/ALTSVC.md > %%PORTDOCS%%%%DOCSDIR%%/BINDINGS.md > %%PORTDOCS%%%%DOCSDIR%%/BUG-BOUNTY.md > %%PORTDOCS%%%%DOCSDIR%%/BUGS.md > @@ -38,6 +39,7 @@ share/aclocal/libcurl.m4 > %%PORTDOCS%%%%DOCSDIR%%/GOVERNANCE.md > %%PORTDOCS%%%%DOCSDIR%%/HELP-US.md > %%PORTDOCS%%%%DOCSDIR%%/HISTORY.md > +%%PORTDOCS%%%%DOCSDIR%%/HSTS.md > %%PORTDOCS%%%%DOCSDIR%%/HTTP-COOKIES.md > %%PORTDOCS%%%%DOCSDIR%%/HTTP3.md > %%PORTDOCS%%%%DOCSDIR%%/INSTALL > > Hi, > > Fails to build due to patch checksum mismatch. > > =3D> Attempting to fetch https://curl.se/download/curl-8.11.1.tar.xz > curl-8.11.1.tar.xz 2686 kB 16 MBps > 00s > =3D> ff5091aa9f73802e894b1cbdf24ab84e103200e2.patch doesn't seem to exist= in > /usr/ports/distfiles/. > =3D> Attempting to fetch > https://github.com/curl/curl/commit/ff5091aa9f73802e894b1cbdf24ab84e10320= 0e2.patch > fetch: > https://github.com/curl/curl/commit/ff5091aa9f73802e894b1cbdf24ab84e10320= 0e2.patch: > size mismatch: expected 1074, actual 1068 > =3D> Attempting to fetch > http://distcache.FreeBSD.org/ports-distfiles/ff5091aa9f73802e894b1cbdf24a= b84e103200e2.patch > fetch: > http://distcache.FreeBSD.org/ports-distfiles/ff5091aa9f73802e894b1cbdf24a= b84e103200e2.patch: > Not Found > =3D> Couldn't fetch it - please try to retrieve this > > Best regards, > Daniel > Hello, Thanks for the notification. It should be fixed in 051f1d77a9579ef4de5f408186fccbcb4fd75775. I've also checked with your patch [1] in PR 283266 in case I messed it up. The patch file was OK before but somehow it changes. [1] https://bugs.freebsd.org/bugzilla/attachment.cgi?id=3D255812&action=3Dd= iff Best regards, sunpoet --00000000000061e2970629db5e10 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
On Sun, Dec 22, 2024 at 7:35=E2=80=AFPM Daniel Engber= g <daniel.engberg.list= s@pyret.net> wrote:
On 2024-12-22T12:22:55.000+01:00, Po-Chuan Hsieh <sunpoet@FreeBSD= .org> wrote:

The branch m= ain has been updated by sunpoet:


commit 2a3bac310439f8de03b945ae6b596ddf6384d41= 1
Author: Po-Chuan Hsieh <sunpoet@FreeBSD.org>
Auth= orDate: 2024-12-22 11:21:05 +0000
Commit: Po-Chuan Hsieh = <sunpoet@FreeBS= D.org>
CommitDate: 2024-12-22 11:21:15 +0000
=

ftp/curl: Update to 8.11.1

Security: CVE-2024-11053
---
ftp/curl/Makefile | 8 +++++---
ftp/= curl/distinfo | 8 +++++---
ftp/curl/files/e= xtra-patch-gssapi | 11 -----------
ftp/curl/pkg-plist = | 2 ++
4 files changed, 12 insertions(+), 17 delet= ions(-)

diff --git a/ftp/curl/Makefile b/ftp/c= url/Makefile
index 42e6fa4f27dc..26a1ee93cde6 100644
--- a/ftp/curl/Makefile
+++ b/ftp/curl/Makefile
@@ -1,10 +1,12 @@
PORTNAME=3D curl
-POR= TVERSION=3D 8.11.0
-PORTREVISION=3D 1
+PORTVERS= ION=3D 8.11.1
CATEGORIES=3D ftp net www
MASTE= R_SITES=3D https://curl.se/download/ \

=
+PATCHFILES=3D ff5091aa9f73802e894b1cbdf24ab84e103200e2.patch:-p1
<= /div>
+
MAINTAINER=3D sunpoet@FreeBSD.org
COMMENT=3D Co= mmand line tool and library for transferring data with URLs
= WWW=3D https://curl.se/ \
@@ -24,6 +26,7 @@ CONFIGURE_AR= GS=3D --disable-test-bundles \
--enable-headers-api \
<= /div>
--enable-hsts \
--enable-http-auth \
+ --enable-manual \
--enable-mime \
= --enable-netrc \
--enable-openssl-auto-load-config \
=
@@ -100,7 +103,6 @@ GNUTLS_LIB_DEPENDS=3D lib= gnutls.so:security/gnutls \
GOPHER_CONFIGURE_ENABLE=3Dgo= pher
GSSAPI_BASE_CONFIGURE_ON=3D --with-gssapi=3D${GSSAPIBAS= EDIR} ${GSSAPI_CONFIGURE_ARGS}
GSSAPI_BASE_CPPFLAGS=3D ${GSS= APICPPFLAGS}
-GSSAPI_BASE_EXTRA_PATCHES=3D ${PATCHDIR}/extra-= patch-gssapi
GSSAPI_BASE_LDFLAGS=3D ${GSSAPILDFLAGS}
GSSAPI_BASE_LIBS=3D ${GSSAPILIBS}
GSSAPI_BASE_USES= =3D gssapi
diff --git a/ftp/curl/distinfo b/ftp/curl/distinfo=
index d6ed0ab70c0c..0122660f4409 100644
--- a/= ftp/curl/distinfo
+++ b/ftp/curl/distinfo
@@ -1= ,3 +1,5 @@
-TIMESTAMP =3D 1731679162
-SHA256 (c= url-8.11.0.tar.xz) =3D db59cf0d671ca6e7f5c2c5ec177084a33a79e04c97e71cf183a5= cdea235054eb
-SIZE (curl-8.11.0.tar.xz) =3D 2750684
=
+TIMESTAMP =3D 1734769461
+SHA256 (curl-8.11.1.tar.xz) = =3D c7ca7db48b0909743eaef34250da02c19bc61d4f1dcedd6603f109409536ab56
+SIZE (curl-8.11.1.tar.xz) =3D 2751236
+SHA256 (ff509= 1aa9f73802e894b1cbdf24ab84e103200e2.patch) =3D 297a61cc260f4bf9e60e5b939e55= 9d5e50df8484328f92d06ffcc256e538d998
+SIZE (ff5091aa9f73802e8= 94b1cbdf24ab84e103200e2.patch) =3D 1074
diff --git a/ftp/curl= /files/extra-patch-gssapi b/ftp/curl/files/extra-patch-gssapi
deleted file mode 100644
index 285b5086bc71..000000000000
--- a/ftp/curl/files/extra-patch-gssapi
+++ /dev/= null
@@ -1,11 +0,0 @@
---- configure.orig 2024-= 11-06 07:09:19 UTC
-+++ configure
-@@ -26192,7 = +26197,7 @@ printf "%s\n" "found" >&6; }
- if test -n "$gnu_gss"; then
- LIBCUR= L_PC_REQUIRES_PRIVATE=3D"$LIBCURL_PC_REQUIRES_PRIVATE gss"
- elif test "x$not_mit" =3D "x1"; then
-- LIBCURL_PC_REQUIRES_PRIVATE=3D"$LIBCURL_PC_REQUIRES_PRIV= ATE heimdal-gssapi"
-+ LIBCURL_PC_REQUIRES_PRIVATE=3D= "$LIBCURL_PC_REQUIRES_PRIVATE"
- else
- LIBCURL_PC_REQUIRES_PRIVATE=3D"$LIBCURL_PC_REQUIRES_PRIVATE m= it-krb5-gssapi"
- fi
diff --git a/ftp/cu= rl/pkg-plist b/ftp/curl/pkg-plist
index a88d7f9dc61e..a940df5= 5cbf3 100644
--- a/ftp/curl/pkg-plist
+++ b/ftp= /curl/pkg-plist
@@ -18,6 +18,7 @@ lib/libcurl.so.4
=
libdata/pkgconfi= g/libcurl.pc
share/aclocal/libcurl.m4
+%%PORTD= OCS%%%%DOCSDIR%%/ALTSVC.md
%%PORTDOCS%%%%DOCSDIR%%/BIN= DINGS.md
%%PORTDOCS%%%%DOCSDIR%%/BUG-BOUNTY.md
%%PORTDOCS%%%%DOCSDIR%%/BUGS.md
@@ -38,6 +39,= 7 @@ share/aclocal/libcurl.m4
%%PORTDOCS%%%%DOCSDIR%%/GO= VERNANCE.md
%%PORTDOCS%%%%DOCSDIR%%/HELP-US.md
<= /div>
%%PORTDOCS%%%%DOCSDIR%%/HISTORY.md
+%%PORTDOC= S%%%%DOCSDIR%%/HSTS.md
%%PORTDOCS%%%%DOCSDIR%%/HTTP-= COOKIES.md
%%PORTDOCS%%%%DOCSDIR%%/HTTP3.md
=
%%PORTDOCS%%%%DOCSDIR%%/INSTALL
Hi,

Fails to build due to patch checksum mismatch.

=3D> Attempting to fetch https://curl.se/download/curl-8.11.1.tar.xz
curl-8.11.1.tar.xz=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 2686 kB=C2=A0=C2=A0 16 MBps=C2=A0=C2=A0=C2= =A0 00s
=3D> ff5091aa9f73802e894b1cbdf24ab= 84e103200e2.patch doesn't seem to exist in /usr/ports/distfiles/.
=3D> Attempting to fetch http://distcache.FreeBSD.org= /ports-distfiles/ff5091aa9f73802e894b1cbdf24ab84e103200e2.patch
=3D> Couldn't fetch it - please try to retrieve thi= s

Best regards= ,
Daniel
Hello,

Thanks for the notification.
It should be fixed in=C2=A0051f1d77a9579ef4de5f408186fccbcb4fd75775= .
I've also checked with your patch [1] in PR=C2=A0283266 in = case I messed it up.
The patch file was OK before but somehow it = changes.


Best regards,
sunpoet=C2=A0
--00000000000061e2970629db5e10--