From nobody Wed Jul 13 06:52:27 2022 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 2F1251D0B3EB; Wed, 13 Jul 2022 06:52:28 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4LjSwr0xspz4Q1j; Wed, 13 Jul 2022 06:52:28 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1657695148; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=6b32Pb+/PJehZBPOrxWePcefdsMyIA85eazrBJZHwvA=; b=kxE/j0r7g6aLIt6IHpA8J1zuiKaeKqgRrk/GdsSYmqVXHHNTZTQAP9pMK/xUfL1buU61Er 7ksAiUW8t4jVwyvucTiDfC4ZglqqZf1HI5df3zih7aEobp0h9fNLK6Enyc3RMb2X2kDmIr N9diDjBj9oQJ6ZjxVlpks8IdOcSHGrxGdU3uHHzwoXndAOFxia3Z0ClouZgsup084nonse gUEGlCK2rVCkontnVycejb2FeqeocZaej0FScaYohVbFtkBRcb0xtajPdlgIR/r10YhfWj Qp1CMsji3579imauUHXPH9567bHNvc30YJ52T/UiEnxQGEr56gRtn4IKEPN9iA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4LjSwr01qhz1Cw1; Wed, 13 Jul 2022 06:52:28 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 26D6qRvh051606; Wed, 13 Jul 2022 06:52:27 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 26D6qRPs051605; Wed, 13 Jul 2022 06:52:27 GMT (envelope-from git) Date: Wed, 13 Jul 2022 06:52:27 GMT Message-Id: <202207130652.26D6qRPs051605@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-branches@FreeBSD.org From: Matthias Fechner Subject: git: e7817c3094af - 2022Q3 - devel/libgit2: security update to 1.3.2 List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: mfechner X-Git-Repository: ports X-Git-Refname: refs/heads/2022Q3 X-Git-Reftype: branch X-Git-Commit: e7817c3094afef2724e10aa4e6ad66b89200713e Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1657695148; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=6b32Pb+/PJehZBPOrxWePcefdsMyIA85eazrBJZHwvA=; b=oDHkzLdcytQrHpdBwrrEYGzq+e7EX+JV+hhvhqtqxx0HJfZs/V3u/iUVvfJJ6B6sRMzHyf V4UBPugAehRDa+vz8TShyRCLLyuEm2sYTwYxZUQHPRiHeqYHpi/SuG5kruO0ciCImLtHHs SATe0yuZ42a2pyWSEKC20YgO31DIA7c6LDWS/sLOzBEgpzQfnR1q9bQg+s02E4xva+MA3t PjHCNR2Lx8Wb/tButag93QDLMfGUZk5dlg9K+ha2Wqf1S++T10RHR4Yv/oVygZRUg1yxXs PEPCQIIYT0p45SyK2Obpy6WtCRkRxrh622JWkjUNPBgADLivGpvN32e0s5fxWg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1657695148; a=rsa-sha256; cv=none; b=fvLjMhXuRF/x/5bOdn3n2Em8OTBhNsu2iry+vsr9ujXdWMKmuNhNNhttl70IAFyOsp+bT+ yVN0AYRHfmnwUkBGrsF2puwWhn8H3XlOK2aducYEa9ceF4eqsaBF09h3G4BrduDDs9Gad9 YvGgx1D1136aUR8gKG5UmKFLTpQicO5lfJ1lrS6JjMoIZGJeLHANMnUFLdcz43dXTkWnrP 9wW1yY+EU0xHFsiIayvi7FuMBuLcQT6AenZWXbPNtRng3rcO69SW7htdn2z5RCkOw6IpHU tyUF0fGgWZaDiQgbdSx5YV/t2kRsMgQdnA54n212itaW7RQThH6RZwXtg2jb7Q== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch 2022Q3 has been updated by mfechner: URL: https://cgit.FreeBSD.org/ports/commit/?id=e7817c3094afef2724e10aa4e6ad66b89200713e commit e7817c3094afef2724e10aa4e6ad66b89200713e Author: Matthias Fechner AuthorDate: 2022-07-13 06:34:58 +0000 Commit: Matthias Fechner CommitDate: 2022-07-13 06:48:55 +0000 devel/libgit2: security update to 1.3.2 Changelog: https://github.com/libgit2/libgit2/releases/tag/v1.3.2 This is a security release with multiple changes. This provides compatibility with git's changes to address CVE 2022-29187. As a follow up to CVE 2022-24765, now not only is the working directory of a non-bare repository examined for its ownership, but the .git directory and the .git file (if present) are also examined for their ownership. A fix for compatibility with git's (new) behavior for CVE 2022-24765 allows users on POSIX systems to access a git repository that is owned by them when they are running in sudo. A fix for further compatibility with git's (existing) behavior for CVE 2022-24765 allows users on Windows to access a git repository that is owned by the Administrator when running with escalated privileges (using runas Administrator). The bundled zlib is updated to v1.2.12, as prior versions had memory corruption bugs. It is not known that there is a security vulnerability in libgit2 based on these bugs, but we are updating to be cautious. MFH: 2022Q3 (cherry picked from commit de1569c878b4a565f5bf35ad20a08ec8ec0ccb19) --- devel/libgit2/Makefile | 2 +- devel/libgit2/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/devel/libgit2/Makefile b/devel/libgit2/Makefile index 269fcf01efc2..e1a5adc474a3 100644 --- a/devel/libgit2/Makefile +++ b/devel/libgit2/Makefile @@ -5,7 +5,7 @@ PORTNAME= libgit2 DISTVERSIONPREFIX= v -DISTVERSION= 1.3.1 +DISTVERSION= 1.3.2 CATEGORIES= devel MAINTAINER= mfechner@FreeBSD.org diff --git a/devel/libgit2/distinfo b/devel/libgit2/distinfo index f862bbd2ecb9..9e0e5ff0cdf9 100644 --- a/devel/libgit2/distinfo +++ b/devel/libgit2/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1655709923 -SHA256 (libgit2-libgit2-v1.3.1_GH0.tar.gz) = a2a0a90d577f1771ba9f7e98042865c3f6386c896eeefa846c3fc0c37ce7c6e0 -SIZE (libgit2-libgit2-v1.3.1_GH0.tar.gz) = 5602265 +TIMESTAMP = 1657692035 +SHA256 (libgit2-libgit2-v1.3.2_GH0.tar.gz) = 3a4469b32b73d53f9dbb7bf17b61b0cfb7dae9020e199f928fa96f12d6eb29cb +SIZE (libgit2-libgit2-v1.3.2_GH0.tar.gz) = 5824473