Re: update devel/libyaml for CVE-2014-9130

2014-11-28 Thread Jeremy Evans
On Fri, Nov 28, 2014 at 9:44 PM, Jeremy Evans wrote: > On Fri, Nov 28, 2014 at 9:28 PM, Jonathan Gray wrote: > >> I found a yaml input with the afl fuzzer which causes libyaml to >> assert/abort. This is CVE-2014-9130. >> >> https://marc.info/?l=oss-security&m=141715462623662&w=2 >> >> The upst

Re: update devel/libyaml for CVE-2014-9130

2014-11-28 Thread Jonathan Gray
On Fri, Nov 28, 2014 at 09:44:23PM -0800, Jeremy Evans wrote: > On Fri, Nov 28, 2014 at 9:28 PM, Jonathan Gray wrote: > > > I found a yaml input with the afl fuzzer which causes libyaml to > > assert/abort. This is CVE-2014-9130. > > > > https://marc.info/?l=oss-security&m=141715462623662&w=2 >

Re: update devel/libyaml for CVE-2014-9130

2014-11-28 Thread Jeremy Evans
On Fri, Nov 28, 2014 at 9:28 PM, Jonathan Gray wrote: > I found a yaml input with the afl fuzzer which causes libyaml to > assert/abort. This is CVE-2014-9130. > > https://marc.info/?l=oss-security&m=141715462623662&w=2 > > The upstream repository has a commit to remove the assertion > but no re

update devel/p5-YAML-XS for CVE-2014-9130

2014-11-28 Thread Jonathan Gray
I found a yaml input with the afl fuzzer which causes libyaml to assert/abort. This is CVE-2014-9130. https://marc.info/?l=oss-security&m=141715462623662&w=2 The following updates p5-YAML-XS to a version that has the assertion commented out. Index: Makefile =

update devel/libyaml for CVE-2014-9130

2014-11-28 Thread Jonathan Gray
I found a yaml input with the afl fuzzer which causes libyaml to assert/abort. This is CVE-2014-9130. https://marc.info/?l=oss-security&m=141715462623662&w=2 The upstream repository has a commit to remove the assertion but no release has been made. https://bitbucket.org/xi/libyaml/commits/2b915

Re: UPDATE: py-werkzeug and python3 flavor, locale woes

2014-11-28 Thread frantisek holop
one of the failing tests, test_shared_data_middleware is in fact 2 issues. for python3, it fails also upstream and there is a ticket. however on openbsd it fails on python2 as well. here is the trace: == ERROR: test_shared_data

Re: new: mlite-20141121

2014-11-28 Thread James Turner
ping? Local port has been updated to 20141127. On Fri, Nov 21, 2014 at 10:14:15PM -0500, James Turner wrote: > Now with more port. > > On Fri, Nov 21, 2014 at 10:11:26PM -0500, James Turner wrote: > > New port of the mLite programming language. Tested on amd64. ok? > > > > Information for inst:

UPDATE: py-werkzeug and python3 flavor

2014-11-28 Thread frantisek holop
minor update and another classic gets the python3 makeover. 1 test fails in python2 3 tests fail in python3 the previous version also had failing tests, some of them different. i think the utf8 codec issue is a staying guest. redis and memcached are "hidden" TEST_DEPENDS, py-memcache got picked

NEW: net/icinga/icinga2-migration

2014-11-28 Thread Stuart Henderson
This is a migration tool from icinga1->icinga2 config formats. Not perfect but it's useful enough to show the way. OK to import? icinga2-migration.tgz Description: application/tar-gz

UPDATE: py-peewee, fix previous

2014-11-28 Thread frantisek holop
the update i have just sent was a quick dirty job :) i just noticed that the port's python3 flavor had some issues already present, but even worse, i have introduced a typo in the PLIST. i have also added documentation and examples. please test and commit and sorry. -f -- 43.3% of all statistic

UPDATE: py-pygments and python3 flavor

2014-11-28 Thread frantisek holop
all tests pass, and 8 are skipped that depend do something with pillow. pillow is not listed in TEST_DEPENDS, but i have it installed, so i think it is not an import issue (it would be in the python3 flavor, but the same tests are skipped in both versions, ). btw. pillow is python3 ready but i don

UPDATE: py-tz

2014-11-28 Thread frantisek holop
please test and commit. -f -- if practice makes perfect, and nobody's perfect, why practice? Index: Makefile === RCS file: /cvs/ports/devel/py-tz/Makefile,v retrieving revision 1.32 diff -u -p -u -p -r1.32 Makefile --- Makefile9

Re: www/p5-Mojo - 5.67

2014-11-28 Thread Mark Patruck
The example certificate resides under {P5SITE}/Mojo for a long time, so i didn't pay attention. According to sri, this topic is very low priority, so perhaps we could simply add a note to create your own certificate with proper permissions. On Thu, Nov 27, 2014 at 08:11:00PM +, Nigel Taylor w

UPDATE: py-MarkupSafe

2014-11-28 Thread frantisek holop
please test and commit. -f -- teaching is the art of assisting discovery. Index: Makefile === RCS file: /cvs/ports/textproc/py-MarkupSafe/Makefile,v retrieving revision 1.13 diff -u -p -u -p -r1.13 Makefile --- Makefile29 Sep 201

UPDATE py-peewee

2014-11-28 Thread frantisek holop
please test and commit. -f -- i'm a tagline. when i grow up i wanna be a novel. Index: Makefile === RCS file: /cvs/ports/databases/py-peewee/Makefile,v retrieving revision 1.1.1.1 diff -u -p -u -p -r1.1.1.1 Makefile --- Makefile

Re: NEW: ruby-sass

2014-11-28 Thread frantisek holop
ping? -f frantisek holop, 22 Nov 2014 18:55: > another go at this port, version 3.4.8 > this is a port for the http://sass-lang.com/ > ruby implementation. > > $ cat pkg/DESCR > Sass makes CSS fun again. Sass is an extension of CSS3, > adding nested rules, variables, mixins, selector inheritance

UPDATE: math/ginac 1.6.3

2014-11-28 Thread Paul Irofti
This updates GiNaC to it's current release. - major libarary bump - added doxygen documentation - perl scripts switched to python - ditched the PFRAG.shared file Okay? Index: Makefile === RCS file: /c

Re: Freeswitch

2014-11-28 Thread Stefan Sperling
On Wed, Nov 26, 2014 at 10:12:20PM -0700, Ted Bullock wrote: > On 2014-10-31 2:43 AM, Ted Bullock wrote: > >- The upstream hashing function uses internal sqlite API calls which I > >think is dumb; I tried to use the APR hashing api (which at least is > >public api) but I've done something bad and i