Re: SSL not required for setup.exe download

2019-03-10 Thread Mark Geisert
Brian Inglis wrote: On 2019-03-10 10:40, Archie Cobbs wrote: [...] In any case, the problem I'm talking about is trivial to verify. Just start up Chrome or Firefox and enter http://www.cygwin.com. You can then confirm that (a) the page you are looking at has an http:// URL, and (b) the link to

Re: SSL not required for setup.exe download

2019-03-10 Thread Archie Cobbs
On Sun, Mar 10, 2019 at 6:20 PM L A Walsh wrote: > >> It would be safer if http://www.cygwin.com always redirected you to > >> https://www.cygwin.com, where the page and the link are SSL. > >> Is there any reason not to force this redirect and close this security > >> hole? > > I think the po

Re: SSL not required for setup.exe download

2019-03-10 Thread Brian Inglis
On 2019-03-10 10:40, Archie Cobbs wrote: > On Sun, Mar 10, 2019 at 9:16 AM Brian Inglis wrote: >>> Is there any reason not to force this redirect and close this security hole? There are apparently reasons not to force this redirect as it can also cause a security hole. >> The whole sourceware.org

Re: Patch request to qt 5.9.4 (Re: [ANNOUNCEMENT] Qt 5.9.4)

2019-03-10 Thread Tatsuro MATSUOKA
- Original Message - > From: Yaakov Selkowitz To: cygwin > Cc: > Date: 2019/3/11, Mon 09:53 > Subject: Re: Patch request to qt 5.9.4 (Re: [ANNOUNCEMENT] Qt 5.9.4) > > On Mon, 2019-03-11 at 09:28 +0900, Tatsuro MATSUOKA wrote: >> > On Mon, 2019-03-04 at 07:43 +0900, Tatsuro MATSUOKA wro

compiler-rt-5.0.1-1.tar.xz contains llvm-objdump.exe.stackdump

2019-03-10 Thread Ken
Greetings! This is simply to report that the compiler-rt-5.0.1-1.tar.xz package contains, what I believe is, an extraneous file 'llvm-objdump.exe.stackdump' which is installed in the root of the cygwin64 structure by setup.exe. A tar listing of the package: $ tar tvJf compiler-rt-5.0.1-1.ta

Re: OpenSSL 1.1

2019-03-10 Thread Yaakov Selkowitz
On Sun, 2019-03-10 at 14:47 -0700, Steven Penny wrote: > Current Cygwin OpenSSL is 1.0.2r. However OpenSSL 1.1 has been available for > several years now: > > https://github.com/openssl/openssl/releases/tag/OpenSSL_1_1_0 We are well aware, and this delay was planned. 1.1 broke API compatibility

Re: Patch request to qt 5.9.4 (Re: [ANNOUNCEMENT] Qt 5.9.4)

2019-03-10 Thread Yaakov Selkowitz
On Mon, 2019-03-11 at 09:28 +0900, Tatsuro MATSUOKA wrote: > > On Mon, 2019-03-04 at 07:43 +0900, Tatsuro MATSUOKA wrote: > > > I ask alpply a patch the below which enables to use qt terminal on > > > gnuplot > > for Cygwin. > > > (cygQt5Network-5.dll is affected.) > > > > > > --- > > > a/qt

Re: Patch request to qt 5.9.4 (Re: [ANNOUNCEMENT] Qt 5.9.4)

2019-03-10 Thread Andrey Repin
Greetings, Tatsuro MATSUOKA! > Very basic question. What is STC? > I googled but I cannot find what is it. https://cygwin.com/acronyms/#STC -- With best regards, Andrey Repin Monday, March 11, 2019 3:38:42 Sorry for my terrible english... -- Problem reports: http://cygwin.com/problems

Re: Patch request to qt 5.9.4 (Re: [ANNOUNCEMENT] Qt 5.9.4)

2019-03-10 Thread Tatsuro MATSUOKA
- Original Message - > From: Yaakov Selkowitz  > To: cygwin@cygwin.com > Cc: > Date: 2019/3/5, Tue 01:32 > Subject: Re: Patch request to qt 5.9.4 (Re: [ANNOUNCEMENT] Qt 5.9.4) > > On Mon, 2019-03-04 at 07:43 +0900, Tatsuro MATSUOKA wrote: >> Dear Yaakov Selkowitz >> >> I ask alpply a

Re: SSL not required for setup.exe download

2019-03-10 Thread L A Walsh
On 3/10/2019 7:16 AM, Brian Inglis wrote: > On 2019-03-09 21:54, Archie Cobbs wrote: >> It would be safer if http://www.cygwin.com always redirected you to >> https://www.cygwin.com, where the page and the link are SSL. >> Is there any reason not to force this redirect and close this security hole?

Re: win dirs don't handle lack of inherited rule(?): getfacl + tar dir Warning: Cannot acl_to_text: Invalid argument

2019-03-10 Thread L A Walsh
I'll have to try it, just haven't finished responding to the replies yet -- keep getting distracted... ;-) On 3/10/2019 3:37 PM, Andrey Repin wrote: >> I would not doubt that icacls would refuse to create >> mis-ordered ACL's, for example. > > Again, you'd be surprised. > >> I.e. its likely a no

Re: A workaround against Emacs crash when displaying images

2019-03-10 Thread Katsumi Yamaoka
On Fri, 08 Mar 2019 13:04:40 +0100, Corinna Vinschen wrote: > I could reproduce the hang and found a potential deadlock situation. > I pushed a fix and uploaded new developer snapshots to > https://cygwin.com/snapshots/ > Please test. All seems to work fine on 3.0.3. Thank you! -- Problem repor

Re: win dirs don't handle lack of inherited rule(?): getfacl + tar dir Warning: Cannot acl_to_text: Invalid argument

2019-03-10 Thread Andrey Repin
Greetings, L A Walsh! > On 3/10/2019 6:27 AM, Andrey Repin wrote: >> Greetings, L A Walsh! >> >>> On 3/8/2019 4:15 AM, Corinna Vinschen wrote: On Mar 7 19:35, L A Walsh wrote: > I ran tar on another directory and got a huge number** > of these: > tar: rules: Warning: Cannot acl_

OpenSSL 1.1

2019-03-10 Thread Steven Penny
Current Cygwin OpenSSL is 1.0.2r. However OpenSSL 1.1 has been available for several years now: https://github.com/openssl/openssl/releases/tag/OpenSSL_1_1_0 and certain libraries require OpenSSL 1.1: https://github.com/curl/curl-for-win -- Problem reports: http://cygwin.com/problems.ht

[ANNOUNCEMENT] emacs 26.1.92-3 (TEST)

2019-03-10 Thread Ken Brown
The following packages have been uploaded to the Cygwin distribution as test releases: * emacs-26.1.92-3 * emacs-common-26.1.92-3 * emacs-X11-26.1.92-3 * emacs-w32-26.1.92-3 * emacs-lucid-26.1.92-3 Emacs is a powerful, customizable, self-documenting, modeless text editor. Emacs contains special

Re: SSL not required for setup.exe download

2019-03-10 Thread Archie Cobbs
Hi Brian, On Sun, Mar 10, 2019 at 9:16 AM Brian Inglis wrote: > > Is there any reason not to force this redirect and close this security hole? > > The whole sourceware.org site include cygwin.com uses HSTS which compliant > supporting clients can use to switch to communicating over HTTPS. > Clien

Re: win dirs don't handle lack of inherited rule(?): getfacl + tar dir Warning: Cannot acl_to_text: Invalid argument

2019-03-10 Thread L A Walsh
On 3/10/2019 6:27 AM, Andrey Repin wrote: > Greetings, L A Walsh! > >> On 3/8/2019 4:15 AM, Corinna Vinschen wrote: >>> On Mar 7 19:35, L A Walsh wrote: I ran tar on another directory and got a huge number** of these: tar: rules: Warning: Cannot acl_to_text: Invalid argument >>>

Re: SSL not required for setup.exe download

2019-03-10 Thread Archie Cobbs
Hi Andrey, On Sun, Mar 10, 2019 at 8:35 AM Andrey Repin wrote: > > Is there any reason not to force this redirect and close this security hole? > > If you care that much, you would use https. > If not, then I see no reason to bend to hysteric crowd. You are correct: careful, diligent, knowledgea

Re: SSL not required for setup.exe download

2019-03-10 Thread Brian Inglis
On 2019-03-09 21:54, Archie Cobbs wrote: > The FAQ states: > The Cygwin website provides the setup program (setup-x86.exe or > setup-x86_64.exe) using HTTPS (SSL/TLS). > While this is true, it's not mandatory. > If one happens to go to HTTP://www.cygwin.com instead of > HTTPS://www.cygwin.com,

Re: SSL not required for setup.exe download

2019-03-10 Thread Brian Inglis
On 2019-03-09 21:54, Archie Cobbs wrote: > The FAQ states: > The Cygwin website provides the setup program (setup-x86.exe or > setup-x86_64.exe) using HTTPS (SSL/TLS). > While this is true, it's not mandatory. > If one happens to go to HTTP://www.cygwin.com instead of > HTTPS://www.cygwin.com,

Re: win dirs don't handle lack of inherited rule(?): getfacl + tar dir Warning: Cannot acl_to_text: Invalid argument

2019-03-10 Thread Brian Inglis
On 2019-03-10 04:48, L A Walsh wrote: > On 3/8/2019 4:15 AM, Corinna Vinschen wrote: >> On Mar 7 19:35, L A Walsh wrote: >>> I ran tar on another directory and got a huge number** >>> of these: >>> tar: rules: Warning: Cannot acl_to_text: Invalid argument >>> tar: adblockplus: Warning: Cannot acl_

Re: win dirs don't handle lack of inherited rule(?): getfacl + tar dir Warning: Cannot acl_to_text: Invalid argument

2019-03-10 Thread Andrey Repin
Greetings, L A Walsh! > On 3/8/2019 4:15 AM, Corinna Vinschen wrote: >> On Mar 7 19:35, L A Walsh wrote: >>> I ran tar on another directory and got a huge number** >>> of these: >>> tar: rules: Warning: Cannot acl_to_text: Invalid argument >>> tar: adblockplus: Warning: Cannot acl_to_text: Invali

Re: SSL not required for setup.exe download

2019-03-10 Thread Andrey Repin
Greetings, Archie Cobbs! > The FAQ states: > The Cygwin website provides the setup program (setup-x86.exe or > setup-x86_64.exe) using HTTPS (SSL/TLS). > While this is true, it's not mandatory. > If one happens to go to HTTP://www.cygwin.com instead of > HTTPS://www.cygwin.com, then neither

Re: win dirs don't handle lack of inherited rule(?): getfacl + tar dir Warning: Cannot acl_to_text: Invalid argument

2019-03-10 Thread Corinna Vinschen
On Mar 10 03:48, L A Walsh wrote: > > > On 3/8/2019 4:15 AM, Corinna Vinschen wrote: > > On Mar 7 19:35, L A Walsh wrote: > >> I ran tar on another directory and got a huge number** > >> of these: > >> tar: rules: Warning: Cannot acl_to_text: Invalid argument > >> tar: adblockplus: Warning: Cann

Re: win dirs don't handle lack of inherited rule(?): getfacl + tar dir Warning: Cannot acl_to_text: Invalid argument

2019-03-10 Thread L A Walsh
On 3/8/2019 4:15 AM, Corinna Vinschen wrote: > On Mar 7 19:35, L A Walsh wrote: >> I ran tar on another directory and got a huge number** >> of these: >> tar: rules: Warning: Cannot acl_to_text: Invalid argument >> tar: adblockplus: Warning: Cannot acl_to_text: Invalid argument >> tar: autopage

Re: [ANNOUNCEMENT] cygwin 3.0.3-1

2019-03-10 Thread Corinna Vinschen
On Mar 9 23:10, Houder wrote: > On Sat, 9 Mar 2019 21:26:32, Ken Brown wrote: > > > On 3/9/2019 2:32 PM, Corinna Vinschen wrote: > > > The following packages have been uploaded to the Cygwin distribution: > > > > > > * cygwin-3.0.3-1 > > > * cygwin-devel-3.0.3-1 > > > * cygwin-doc-3.0.3-1 > >