www/libxul issues

Peter Jeremy peter at rulingia.com
Mon Jun 4 23:42:42 UTC 2012


www/libxul has been broken for some time due to security
vulnerabilities.  This issue has been highlighted by the recent
portrevision bump caused by png.  As libxul is based on firefox-3.6
I presume this brokenness is terminal.  Since libxul is the only
remaining gecko, this presents an issue for a number of other ports.

Looking at the firefox-12 sources, it appears that libxul and
xulrunner are present (and www/firefox installs two identical
private copies of libxul.so).  How difficult would it be to either:
1) Modify www/libxul to be based on firefox-12 insead of ff3.6?
2) Modify www/firefox to (optionally) install libxul publicly?

For that matter, whilst it's not directly relevant to the subject,
why does www/firefox install two identical copies of the largest
file (by an order of magnitude) in the package?

-- 
Peter Jeremy
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 196 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-ports/attachments/20120604/321d0ee7/attachment.pgp


More information about the freebsd-ports mailing list