Friday, October 02, 2026

Re: UPDATE: add -java subpackage to sysutils/sleuthkit

This updated version, without SUBPACKAGE, but like the others, installing *jars in ${MODJAVA_SHARE_DIR}/classes

any testing, feedback etc. welcome.

cheers,
Sebastian

On Sat, Sep 19, 2026 at 10:09 PM Sebastian Reitenbach <sebastia@l00-bugdead-prods.de> wrote:
Hi,



On Sat, Sep 19, 2026 at 9:42 PM Stuart Henderson <stu@spacehopper.org> wrote:


iirc this can bappen if you work on a copy of the port in mystuff
rather than the main dir (or maybe if you work in the main dir
but have an older one in mystuff)


yeah, I am indeed working under mystuff, but have sysutils/sleuthkit deleted.

In any case, I dropped the SUBPACKAGE, and I have incorporated all your suggestions. 
Getting the paths stripped was the most entertaining, didn't know about the {} feature. 
Finally I found seamonkey port, looking at that helped.

Besides all that, I also put all those dependencies versions into variables. That will hopefully
make updates easier.

If this looks good to you, I'll update the other related ports in the same way.

cheers,
Sebastian


--


--

Re: NEW: java/sevenzipjbinding

This is the cleaned-up, updated version, installing the .jars in $MODJAVA_JAR_DIR
It's needed dependency for Autopsy.

obviously, for after unlock.

any testing, feedback etc. welcome.

cheers,
Sebastian

On Sat, Sep 19, 2026 at 10:07 AM Sebastian Reitenbach <sebastia@l00-bugdead-prods.de> wrote:
Hi,

this could also go under archivers, if preferred.

7-Zip-JBinding is a free cross-platform java binding of 7-Zip free
compress/decompress library.

this is the fork from sleuthkit, as they have some specific patches, that 
sleuthkit/autopsy needs.

testing, feedback of any sort welcome.

cheers,
Sebastian

--


--

Re: UPDATE: net/tailscale-1.102.5

You are correct. > Em 2 de out. de 2026, à(s) 08:00, Stuart Henderson <stu@spacehopper.org> escreveu: > > no change for us I think, only for containers? > > On 2026/10/02 07:28, Adriano Barbosa wrote: >> Hi. >> >> Update for net/tailscale v1.102.5 >> Changelog: >> https://tailscale.com/changelog >> >> Obrigado! >> -- >> Adriano >> >> >> Index: Makefile >> =================================================================== >> RCS file: /cvs/ports/net/tailscale/Makefile,v >> diff -u -p -r1.73 Makefile >> --- Makefile 17 Sep 2026 01:40:48 -0000 1.73 >> +++ Makefile 1 Oct 2026 12:35:46 -0000 >> @@ -2,7 +2,7 @@ BROKEN-i386 = unix.EPROTO not defined >> >> COMMENT = modern overlay-like VPN built on top of WireGuard >> >> -V = 1.102.4 >> +V = 1.102.5 >> MODGO_MODNAME = tailscale.com >> MODGO_VERSION = v${V} >> >> Index: distinfo >> =================================================================== >> RCS file: /cvs/ports/net/tailscale/distinfo,v >> diff -u -p -r1.70 distinfo >> --- distinfo 17 Sep 2026 01:40:48 -0000 1.70 >> +++ distinfo 1 Oct 2026 12:35:47 -0000 >> @@ -3365,7 +3365,7 @@ SHA256 (go_modules/tags.cncf.io/containe >> SHA256 (go_modules/tailscale.com/@v/v1.81.0-pre.0.20250303195457-5449aba94c51.mod) = uHvK4t5U8irH0H2uysqCjYGyka9XwJTcUbGkiU/xGhY= >> SHA256 (go_modules/tailscale.com/client/tailscale/v2/@v/v2.9.0.mod) = 51wk0RAzCJHq6dnTk+H/QB5QJ8AlXBO6Q/aEb4i7w9A= >> SHA256 (go_modules/tailscale.com/client/tailscale/v2/@v/v2.9.0.zip) = 98fHbNgqYo2JuhUD9lwY4yBsKC0dxR4EO2bXfSlNApc= >> -SHA256 (tailscale.com-v1.102.4.zip) = 06SEbOGxWygsnJcKl1DMmqRgbamwTJjbQHzxjt1rXOI= >> +SHA256 (tailscale.com-v1.102.5.zip) = SUmUL0E0nRhzaUN70REMgf8t06fZAWCqQDtqDnpN5CI= >> SIZE (go_modules/4d63.com/gocheckcompilerdirectives/@v/v1.2.1.mod) = 173 >> SIZE (go_modules/4d63.com/gocheckcompilerdirectives/@v/v1.2.1.zip) = 7059 >> SIZE (go_modules/4d63.com/gochecknoglobals/@v/v0.2.1.mod) = 77 >> @@ -6733,4 +6733,4 @@ SIZE (go_modules/tags.cncf.io/container- >> SIZE (go_modules/tailscale.com/@v/v1.81.0-pre.0.20250303195457-5449aba94c51.mod) = 19965 >> SIZE (go_modules/tailscale.com/client/tailscale/v2/@v/v2.9.0.mod) = 342 >> SIZE (go_modules/tailscale.com/client/tailscale/v2/@v/v2.9.0.zip) = 58407 >> -SIZE (tailscale.com-v1.102.4.zip) = 6805728 >> +SIZE (tailscale.com-v1.102.5.zip) = 6807902 >>

Re: PATCH: www/librewolf update to v 157.0-1

On 2026/10/02 16:56, Leah Rowe wrote: > > well landry's 157 update went in already, like two days ago > > librewolf 157 is literally the same code as landry's, just with librewolf's > privacy tweaks > > no reason it can't go in. same code. however, this is only my personal > opinion. if we'd had it a few days ago, maybe, but it's now 3 days later and the release needs building... > personally, i think this should go in, to have parity with firefox in the > 8.0 release. that being said, there's nothing seriously wrong with 156 and > users can always just grab it and build if they want > > do mozilla projects generally get version updates in -stable? i was of the > mind that openbsd just freezes the versions and then they update again in > the next release, except if a bugfix is needed ---------------------------- revision 1.680.2.24 date: 2026/09/29 13:08:05; author: landry; state: Exp; lines: +1 -1; commitid: QD7IpivdHnB549HY; www/mozilla-firefox: MFC update to 157.0. see https://www.firefox.com/en-US/firefox/157.0/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/ ---------------------------- revision 1.680.2.23 date: 2026/09/22 13:05:06; author: landry; state: Exp; lines: +1 -1; commitid: erZXxGdLF402zUjI; www/mozilla-firefox: MFC update to 156.0.1. see https://www.firefox.com/en-US/firefox/156.0.1/releasenotes/ ---------------------------- revision 1.680.2.22 date: 2026/09/15 12:47:07; author: landry; state: Exp; lines: +1 -1; commitid: FFLzp48YeD0iU9cv; www/mozilla-firefox: MFC update to 156.0. see https://www.firefox.com/en-US/firefox/156.0/releasenotes/ fixes https://www.mozilla.org/fr/security/advisories/mfsa2026-90/ ---------------------------- revision 1.680.2.21 date: 2026/09/04 14:20:41; author: landry; state: Exp; lines: +1 -1; commitid: stt3Ve8JjQzQ9h0P; www/mozilla-firefox: MFC update to 155.0.1. see https://www.firefox.com/en-US/firefox/155.0.1/releasenotes/ ---------------------------- revision 1.680.2.20 date: 2026/09/01 12:35:08; author: landry; state: Exp; lines: +1 -1; commitid: E3F36nOWGKoxNxvE; www/mozilla-firefox: MFC update to 155.0. see https://www.firefox.com/en-US/firefox/155.0/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/ ---------------------------- revision 1.680.2.19 date: 2026/08/25 14:48:20; author: landry; state: Exp; lines: +1 -1; commitid: JM9Nx4iBIWccCVTG; www/mozilla-firefox: update to 154.0.1. see https://www.firefox.com/en-US/firefox/154.0.1/releasenotes/ ---------------------------- revision 1.680.2.18 date: 2026/08/18 13:07:07; author: landry; state: Exp; lines: +1 -1; commitid: eU6KsVw8tc379qj0; www/mozilla-firefox: MFC update to 154.0. see https://www.firefox.com/en-US/firefox/154.0/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/ - revert bits of https://phabricator.services.mozilla.com/D306631 to keep building against nss 3.123 - add patch from #2057158 to fix the build after angle update in #2035541 ---------------------------- revision 1.680.2.17 date: 2026/08/11 18:46:18; author: landry; state: Exp; lines: +1 -1; commitid: 4VMFFFkahbz4Dkz5; www/mozilla-firefox: MFC update to 153.0.4. see https://www.firefox.com/en-US/firefox/153.0.4/releasenotes/ ---------------------------- revision 1.680.2.16 date: 2026/08/05 06:08:40; author: landry; state: Exp; lines: +1 -1; commitid: Ewj0md1CmyEXgVnj; www/mozilla-firefox: MFC update to 153.0.3. see https://www.firefox.com/en-US/firefox/153.0.3/releasenotes/ ---------------------------- revision 1.680.2.15 date: 2026/07/28 13:25:23; author: landry; state: Exp; lines: +1 -1; commitid: ojxhq4pxKWiuoyMJ; www/mozilla-firefox: MFC update to 153.0.1. see https://www.firefox.com/en-US/firefox/153.0.1/releasenotes/ ---------------------------- revision 1.680.2.14 date: 2026/07/21 13:10:21; author: landry; state: Exp; lines: +2 -2; commitid: HYvw7mzkatQWAcl6; www/mozilla-firefox: MFC update to 153.0. see https://www.firefox.com/en-US/firefox/153.0/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/ - depend on latest cbindgen - update XSHM 1.2 patches from matthieu (cf #1702919) ---------------------------- revision 1.680.2.13 date: 2026/07/14 14:20:50; author: landry; state: Exp; lines: +1 -1; commitid: HlUMqTOH4awImPju; www/mozilla-firefox: MFC update to 152.0.6. see https://www.firefox.com/en-US/firefox/152.0.6/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/ ---------------------------- revision 1.680.2.12 date: 2026/07/07 12:53:29; author: landry; state: Exp; lines: +1 -2; commitid: a2zsoc4Domgww7Yn; www/mozilla-firefox: MFC update to 152.0.5. see https://www.firefox.com/en-US/firefox/152.0.5/releasenotes/ ---------------------------- revision 1.680.2.11 date: 2026/07/01 12:53:44; author: landry; state: Exp; lines: +1 -0; commitid: lYn36sqq2oINu1eM; www/mozilla-firefox: MFC use the new AIControls policy to force-disable more AI nonsense supersedes GenerativeAI since 151.. with those new defaults, in about:preferences#ai you should get 'new and current AI enhancements are blocked by default. To unblock a specific feature, use the controls below'. i've left translations and PDFAltText unlocked so ppl can choose to opt-in and keep fucking up the world. others are locked (see about:policies), so one would need to manually edit /usr/local/lib/firefox/distribution/policies.json to fuck up its karma even more. again with inspiration from justthebrowser project who have the time and willingness to keep up with this whack-a-mole. ---------------------------- revision 1.680.2.10 date: 2026/06/30 14:09:49; author: landry; state: Exp; lines: +1 -1; commitid: eWfhcWero4CQbJcN; www/mozilla-firefox: MFC update to 152.0.4. see https://www.firefox.com/en-US/firefox/152.0.4/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-62/ ---------------------------- revision 1.680.2.9 date: 2026/06/25 13:58:13; author: landry; state: Exp; lines: +1 -1; commitid: SNS3PDHNgPBxubLZ; www/mozilla-firefox: MFC update to 152.0.3. see https://www.firefox.com/en-US/firefox/152.0.3/releasenotes/ Fixed an issue that could cause extreme memory usage and freezing on startup for users with language packs installed. (Bug 2049845) ---------------------------- revision 1.680.2.8 date: 2026/06/23 13:18:39; author: landry; state: Exp; lines: +1 -1; commitid: AxZZggjneJ2487T3; www/mozilla-firefox: MFC update to 152.0.2. see https://www.firefox.com/en-US/firefox/152.0.2/releasenotes/ ---------------------------- revision 1.680.2.7 date: 2026/06/18 14:13:27; author: landry; state: Exp; lines: +1 -1; commitid: TmHzgMKERrE34F0S; www/mozilla-firefox: MFC update to 152.0.1 see https://www.firefox.com/en-US/firefox/152.0.1/releasenotes/ ---------------------------- revision 1.680.2.6 date: 2026/06/16 12:38:25; author: landry; state: Exp; lines: +1 -1; commitid: IhHr1h64ve6WEkZR; www/mozilla-firefox: MFC update to 152.0. see https://www.firefox.com/en-US/firefox/152.0/releasenotes/ fixes https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/ add patch to loosen dep on the very latest nss ---------------------------- revision 1.680.2.5 date: 2026/06/09 14:04:28; author: landry; state: Exp; lines: +1 -1; commitid: YbYo2isB6QA6fJg4; www/mozilla-firefox: MFC update to 151.0.4. see https://www.firefox.com/en-US/firefox/151.0.4/releasenotes/ ---------------------------- revision 1.680.2.4 date: 2026/06/02 13:07:46; author: landry; state: Exp; lines: +1 -1; commitid: waox7Fv4py1gxEKZ; www/mozilla-firefox: MFC update to 151.0.3. see https://www.firefox.com/en-US/firefox/151.0.3/releasenotes/ ---------------------------- revision 1.680.2.3 date: 2026/05/26 14:05:20; author: landry; state: Exp; lines: +1 -1; commitid: TndElmEKnRQcflGY; www/mozilla-firefox: MFC update to 151.0.2. see https://www.firefox.com/en-US/firefox/151.0.2/releasenotes/ ---------------------------- revision 1.680.2.2 date: 2026/05/26 06:50:31; author: landry; state: Exp; lines: +1 -2; commitid: LyrnJVazitD06srG; www/mozilla-firefox: MFC update to 151.0.1. see https://www.firefox.com/en-US/firefox/151.0.1/releasenotes/ and https://www.firefox.com/en-US/firefox/151.0/releasenotes/ 151.0 fixed https://www.mozilla.org/security/advisories/mfsa2026-46 while here also merge robert's patch which neuters shared memory (shm*) in webrtc to unbreak screen sharing while using pledge ---------------------------- revision 1.680.2.1 date: 2026/05/21 15:50:40; author: sthen; state: Exp; lines: +1 -0; commitid: mO69D9E2A9B2uQIk; bump revision for firefox in -stable; 7.8-stable has 150.0p0 =============================================================================

Re: Security update: www/apache-httpd

On 10/2/26 10:54 AM, Stuart Henderson wrote: > On 2026/10/01 16:52, Giovanni Bechis wrote: >> Hi, >> update to Apache httpd follows. >> 20 CVE fixed. >> CVE details at https://httpd.apache.org/security/vulnerabilities_24.html >> ok ? > > ok sthen (please commit asap). > > (I would drop patch-server_mpm_unix_c completely, the s/httpd/httpd2/ > in printf don't add anything, doesn't matter either way though). patch committed and patch-server_mpm_unix_c patch dropped. Thanks Giovanni

Re: dealing with some crap again (librewolf delayed)

On 2026/10/02 11:45, Leah Rowe wrote: > > ok, then just update the version there is no time to do that for release either.

Re: Security update: www/apache-httpd

On 2026/10/01 16:52, Giovanni Bechis wrote: > Hi, > update to Apache httpd follows. > 20 CVE fixed. > CVE details at https://httpd.apache.org/security/vulnerabilities_24.html > ok ? ok sthen (please commit asap). (I would drop patch-server_mpm_unix_c completely, the s/httpd/httpd2/ in printf don't add anything, doesn't matter either way though).

Re: games/stratagus: stop using bundled lua

> this switches to system lua and adds a new port (attached); toluacpp.tgz > (lang/toluacpp). er, tolua++ / toluapp, not toluac++.

games/stratagus: stop using bundled lua

ganes/stratagus has an ugly workaround for not having toluac++ in ports, which seems to have issues around system lua being installed and/or junked during build. this switches to system lua and adds a new port (attached); toluacpp.tgz (lang/toluacpp). lua/5.1 is hardcoded for simplicity - this codebase does not support newer lua major versions and toluac++ is archived upstream - so no need for extra complexity from the module. any ok's (at least to import toluacpp)? post unlock obviously Index: Makefile =================================================================== RCS file: /cvs/ports/games/stratagus/Makefile,v diff -u -p -r1.3 Makefile --- Makefile 4 Mar 2026 10:21:05 -0000 1.3 +++ Makefile 2 Oct 2026 08:31:53 -0000 @@ -3,6 +3,7 @@ COMMENT= free cross-platform real-time GH_ACCOUNT= Wargus GH_PROJECT= stratagus GH_TAGNAME= v3.3.2 +REVISION= 0 CATEGORIES= games HOMEPAGE= http://stratagus.com/stratagus.html @@ -10,8 +11,8 @@ HOMEPAGE= http://stratagus.com/stratagu # GPLv2+ PERMIT_PACKAGE= Yes -WANTLIB += ${COMPILER_LIBCXX} SDL2 SDL2_image SDL2_mixer bz2 c m \ - mng ogg png pthread theora vorbis z +WANTLIB += ${COMPILER_LIBCXX} SDL2 SDL2_image SDL2_mixer bz2 c +WANTLIB += lua5.1 m mng ogg png theora toluapp vorbis z MODULES= devel/cmake @@ -25,6 +26,7 @@ LIB_DEPENDS= archivers/bzip2 \ devel/sdl2-mixer \ devel/sdl2-image \ graphics/libmng \ + lang/toluapp \ multimedia/libtheora CONFIGURE_ARGS= -DGAMEDIR=${LOCALBASE}/bin/ \ @@ -32,17 +34,8 @@ CONFIGURE_ARGS= -DGAMEDIR=${LOCALBASE}/ -DENABLE_DEV=ON MODCMAKE_LDFLAGS+= -L${LOCALBASE}/lib -L${X11BASE}/lib -CXXFLAGS = -I${X11BASE}/include +CXXFLAGS+= -I${X11BASE}/include -# XXX Depends on tolua++, use bundled lua 51 -CONFIGURE_ARGS+= -DBUILD_VENDORED_LUA=ON -pre-build: - cd ${WRKBUILD} && exec ${SETENV} ${MAKE_ENV} \ - cmake --build ${WRKBUILD} ${_MAKE_VERBOSE} -j ${MAKE_JOBS} -t Lua51B - -pre-configure: - find ${WRKSRC}/ -name "CMakeLists.txt" -type f -exec sed -i \ - -E 's/cmake_minimum_required\([[:space:]]*VERSION[[:space:]]+[^)]+\)/cmake_minimum_required(VERSION 3.5)/g' \ - {} \; +MODCMAKE_POLICY_VERSION_OVERRIDE = Yes .include <bsd.port.mk> Index: patches/patch-CMakeLists_txt =================================================================== RCS file: /cvs/ports/games/stratagus/patches/patch-CMakeLists_txt,v diff -u -p -r1.1.1.1 patch-CMakeLists_txt --- patches/patch-CMakeLists_txt 13 Feb 2025 20:07:57 -0000 1.1.1.1 +++ patches/patch-CMakeLists_txt 2 Oct 2026 08:31:53 -0000 @@ -1,15 +1,7 @@ Index: CMakeLists.txt --- CMakeLists.txt.orig +++ CMakeLists.txt -@@ -71,6 +71,7 @@ endif() - # Stratagus sources - - include_directories( -+ /usr/X11R6/include - src/include - src/guichan/include - src/guichan/include/guichan -@@ -656,7 +657,7 @@ if(APPLE) +@@ -656,7 +656,7 @@ if(APPLE) list(APPEND CMAKE_PREFIX_PATH /opt/homebrew/) endif() Index: patches/patch-third-party_lua-5_1_5_src_CMakeLists_txt =================================================================== RCS file: patches/patch-third-party_lua-5_1_5_src_CMakeLists_txt diff -N patches/patch-third-party_lua-5_1_5_src_CMakeLists_txt --- patches/patch-third-party_lua-5_1_5_src_CMakeLists_txt 1 Jul 2025 15:39:03 -0000 1.1 +++ /dev/null 1 Jan 1970 00:00:00 -0000 @@ -1,9 +0,0 @@ -Index: third-party/lua-5.1.5/src/CMakeLists.txt ---- third-party/lua-5.1.5/src/CMakeLists.txt.orig -+++ third-party/lua-5.1.5/src/CMakeLists.txt -@@ -72,4 +72,4 @@ set_target_properties(lua51 PROPERTIES - RUNTIME_OUTPUT_DIRECTORY ${PROJECT_BINARY_DIR} - ) - --add_custom_command(TARGET lua51_static POST_BUILD COMMAND ${CMAKE_COMMAND} -E copy "${PROJECT_SOURCE_DIR}/src/lua.h" "${PROJECT_SOURCE_DIR}/src/luaconf.h" "${PROJECT_SOURCE_DIR}/src/lualib.h" "${PROJECT_SOURCE_DIR}/src/lauxlib.h" ${CMAKE_LIBRARY_OUTPUT_DIRECTORY}) -+add_custom_command(TARGET lua51_static PRE_LINK COMMAND ${CMAKE_COMMAND} -E copy "${PROJECT_SOURCE_DIR}/src/lua.h" "${PROJECT_SOURCE_DIR}/src/luaconf.h" "${PROJECT_SOURCE_DIR}/src/lualib.h" "${PROJECT_SOURCE_DIR}/src/lauxlib.h" ${CMAKE_LIBRARY_OUTPUT_DIRECTORY})

Re: aarch64 bulk build report

On 2026/10/01 18:50, phessler@openbsd.org wrote: > bulk build on arm64.ports.openbsd.org > started on Sun Sep 27 07:14:01 MDT 2026 > finished at Thu Oct 1 18:49:47 MDT 2026 > lasted 4D11h35m > done with kern.version=OpenBSD 8.0 (GENERIC.MP) #107: Sat Sep 26 19:52:02 MDT 2026 > > built packages:12990 > Sep 27:4767 > Sep 28:426 > Sep 29:667 > Sep 30:2188 > Oct 1:4941 > > > critical path missing pkgs: http://build-failures.rhaalovely.net/aarch64/2026-09-27/summary.log > > build failures: 5 > http://build-failures.rhaalovely.net/aarch64/2026-09-27/games/devilutionx.log asio issue, fixed now > http://build-failures.rhaalovely.net/aarch64/2026-09-27/games/stratagus.log "(Junk lock released for localhost at 1790884223.12) Woken up editors/texworks,-lua" and the error is with not finding lua.h - presumably picks something up from an installed lua that causes issues with the bundled stratagus-3.3.2/third-party/lua-5.1.5 I'll send a diff + new port that should improve this > http://build-failures.rhaalovely.net/aarch64/2026-09-27/math/py-scs.log > http://build-failures.rhaalovely.net/aarch64/2026-09-27/graphics/py-matplotlib.log both the same meson-python issue, fixed > http://build-failures.rhaalovely.net/aarch64/2026-09-27/www/ungoogled-chromium.log

Thursday, October 01, 2026

aarch64 bulk build report

bulk build on arm64.ports.openbsd.org started on Sun Sep 27 07:14:01 MDT 2026 finished at Thu Oct 1 18:49:47 MDT 2026 lasted 4D11h35m done with kern.version=OpenBSD 8.0 (GENERIC.MP) #107: Sat Sep 26 19:52:02 MDT 2026 built packages:12990 Sep 27:4767 Sep 28:426 Sep 29:667 Sep 30:2188 Oct 1:4941 critical path missing pkgs: http://build-failures.rhaalovely.net/aarch64/2026-09-27/summary.log build failures: 5 http://build-failures.rhaalovely.net/aarch64/2026-09-27/games/devilutionx.log http://build-failures.rhaalovely.net/aarch64/2026-09-27/games/stratagus.log http://build-failures.rhaalovely.net/aarch64/2026-09-27/graphics/py-matplotlib.log http://build-failures.rhaalovely.net/aarch64/2026-09-27/math/py-scs.log http://build-failures.rhaalovely.net/aarch64/2026-09-27/www/ungoogled-chromium.log recurrent failures failures/www/ungoogled-chromium.log new failures +++ ls-failures Thu Oct 1 18:50:02 2026 +failures/games/devilutionx.log +failures/games/stratagus.log +failures/graphics/py-matplotlib.log +failures/math/py-scs.log resolved failures --- ../old/aarch64/last//ls-failures Thu Sep 24 05:47:22 2026 -failures/net/matterhorn.log -failures/security/lastpass-cli.log -failures/sysutils/amazon-ecs-cli.log -failures/sysutils/borgmatic.log -failures/sysutils/gitlab-runner.log -failures/www/seamonkey,-main.log

Re: Security update: www/apache-httpd

don't have time to look closer this evening, full release notes are at https://dlcdn.apache.org/httpd/CHANGES_2.4.69 On 2026/10/01 16:52, Giovanni Bechis wrote: > Hi, > update to Apache httpd follows. > 20 CVE fixed. > CVE details at https://httpd.apache.org/security/vulnerabilities_24.html > ok ? > Cheers > Giovanni > > Index: Makefile > =================================================================== > RCS file: /cvs/ports/www/apache-httpd/Makefile,v > diff -u -p -r1.145 Makefile > --- Makefile 5 Aug 2026 09:16:35 -0000 1.145 > +++ Makefile 1 Oct 2026 14:44:48 -0000 > @@ -1,7 +1,6 @@ > COMMENT= apache HTTP server > > -V= 2.4.68 > -REVISION= 1 > +V= 2.4.69 > DISTNAME= httpd-${V} > PKGNAME= apache-httpd-${V} > > Index: distinfo > =================================================================== > RCS file: /cvs/ports/www/apache-httpd/distinfo,v > diff -u -p -r1.55 distinfo > --- distinfo 9 Jun 2026 22:03:37 -0000 1.55 > +++ distinfo 1 Oct 2026 14:44:48 -0000 > @@ -1,2 +1,2 @@ > -SHA256 (httpd-2.4.68.tar.gz) = 7ZqdRQD7SLso6v+zunHQbM+G1Jj6E6ufeB2gEMxIhJg= > -SIZE (httpd-2.4.68.tar.gz) = 10065436 > +SHA256 (httpd-2.4.69.tar.gz) = xVG5hh4m8Ub1fhsXZeaciaYLPbDsJSzKsNNig0hwFrs= > +SIZE (httpd-2.4.69.tar.gz) = 10822928 > Index: patches/patch-server_mpm_unix_c > =================================================================== > RCS file: /cvs/ports/www/apache-httpd/patches/patch-server_mpm_unix_c,v > diff -u -p -r1.7 patch-server_mpm_unix_c > --- patches/patch-server_mpm_unix_c 5 Aug 2026 09:16:35 -0000 1.7 > +++ patches/patch-server_mpm_unix_c 1 Oct 2026 14:44:48 -0000 > @@ -1,42 +1,7 @@ > Index: server/mpm_unix.c > --- server/mpm_unix.c.orig > +++ server/mpm_unix.c > -@@ -674,6 +674,34 @@ static apr_status_t dummy_connection(ap_pod_t *pod) > - } > - > - rv = apr_socket_connect(sock, lp->bind_addr); > -+#ifdef __OpenBSD__ > -+ /* OpenBSD's connect() returns EINVAL when the target address is the > -+ * wildcard address (INADDR_ANY / IN6ADDR_ANY), > -+ * Retry against the loopback address in that case. */ > -+ if (rv != APR_SUCCESS && APR_STATUS_IS_EINVAL(rv)) { > -+ int is_wildcard = 0; > -+ > -+ if (lp->bind_addr->family == APR_INET) { > -+ is_wildcard = (lp->bind_addr->sa.sin.sin_addr.s_addr == INADDR_ANY); > -+ } > -+#if APR_HAVE_IPV6 > -+ else if (lp->bind_addr->family == APR_INET6) { > -+ is_wildcard = IN6_IS_ADDR_UNSPECIFIED(&lp->bind_addr->sa.sin6.sin6_addr); > -+ } > -+

Security update: www/apache-httpd

Hi, update to Apache httpd follows. 20 CVE fixed. CVE details at https://httpd.apache.org/security/vulnerabilities_24.html ok ? Cheers Giovanni Index: Makefile =================================================================== RCS file: /cvs/ports/www/apache-httpd/Makefile,v diff -u -p -r1.145 Makefile --- Makefile 5 Aug 2026 09:16:35 -0000 1.145 +++ Makefile 1 Oct 2026 14:44:48 -0000 @@ -1,7 +1,6 @@ COMMENT= apache HTTP server -V= 2.4.68 -REVISION= 1 +V= 2.4.69 DISTNAME= httpd-${V} PKGNAME= apache-httpd-${V} Index: distinfo =================================================================== RCS file: /cvs/ports/www/apache-httpd/distinfo,v diff -u -p -r1.55 distinfo --- distinfo 9 Jun 2026 22:03:37 -0000 1.55 +++ distinfo 1 Oct 2026 14:44:48 -0000 @@ -1,2 +1,2 @@ -SHA256 (httpd-2.4.68.tar.gz) = 7ZqdRQD7SLso6v+zunHQbM+G1Jj6E6ufeB2gEMxIhJg= -SIZE (httpd-2.4.68.tar.gz) = 10065436 +SHA256 (httpd-2.4.69.tar.gz) = xVG5hh4m8Ub1fhsXZeaciaYLPbDsJSzKsNNig0hwFrs= +SIZE (httpd-2.4.69.tar.gz) = 10822928 Index: patches/patch-server_mpm_unix_c =================================================================== RCS file: /cvs/ports/www/apache-httpd/patches/patch-server_mpm_unix_c,v diff -u -p -r1.7 patch-server_mpm_unix_c --- patches/patch-server_mpm_unix_c 5 Aug 2026 09:16:35 -0000 1.7 +++ patches/patch-server_mpm_unix_c 1 Oct 2026 14:44:48 -0000 @@ -1,42 +1,7 @@ Index: server/mpm_unix.c --- server/mpm_unix.c.orig +++ server/mpm_unix.c -@@ -674,6 +674,34 @@ static apr_status_t dummy_connection(ap_pod_t *pod) - } - - rv = apr_socket_connect(sock, lp->bind_addr); -+#ifdef __OpenBSD__ -+ /* OpenBSD's connect() returns EINVAL when the target address is the -+ * wildcard address (INADDR_ANY / IN6ADDR_ANY), -+ * Retry against the loopback address in that case. */ -+ if (rv != APR_SUCCESS && APR_STATUS_IS_EINVAL(rv)) { -+ int is_wildcard = 0; -+ -+ if (lp->bind_addr->family == APR_INET) { -+ is_wildcard = (lp->bind_addr->sa.sin.sin_addr.s_addr == INADDR_ANY); -+ } -+#if APR_HAVE_IPV6 -+ else if (lp->bind_addr->family == APR_INET6) { -+ is_wildcard = IN6_IS_ADDR_UNSPECIFIED(&lp->bind_addr->sa.sin6.sin6_addr); -+ } -+