git: 03159bd673b4 - main - www/freenginx-devel: third-party modules management
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Wed, 02 Sep 2026 15:56:20 UTC
The branch main has been updated by osa:
URL: https://cgit.FreeBSD.org/ports/commit/?id=03159bd673b4876c5b014b32b7c6bf9963b7824a
commit 03159bd673b4876c5b014b32b7c6bf9963b7824a
Author: Sergey A. Osokin <osa@FreeBSD.org>
AuthorDate: 2026-09-02 15:55:10 +0000
Commit: Sergey A. Osokin <osa@FreeBSD.org>
CommitDate: 2026-09-02 15:56:14 +0000
www/freenginx-devel: third-party modules management
- njs module security update to 1.0.1
Bump PORTREVISION.
Sponsored by: tipi.work
<ChangeLog>
nginx modules:
*) Security: fixed an access control bypass in js_access when an
asynchronous request body continuation threw an exception or
produced an unhandled rejection. Previously, nginx could continue
processing the request as though the js_access check had succeeded.
Thanks to Ta Duc Thien.
*) Security: fixed a worker process crash when reading
Response.statusText after an upstream server returned a status
line with an empty reason phrase.
*) Bugfix: fixed unhandled promise rejection tracking in reused
QuickJS contexts.
*) Bugfix: fixed SharedDict.pop() returning undefined for unexpired
entries in shared dictionaries with a timeout.
*) Bugfix: fixed validation and replacement of Fetch Headers values.
This also fixed dangling header names in the QuickJS engine.
*) Bugfix: fixed missing validation of r.headersOut names and values,
and of redirect targets passed to r.return().
*) Bugfix: fixed use-after-free, worker aborts, and leaks caused by
cyclic references involving Fetch, HTTP request, and Stream session
objects in the QuickJS engine.
*) Bugfix: fixed QuickJS context reuse after internal redirects and
when pending jobs remained after request teardown.
*) Bugfix: fixed cleanup of partially initialized JavaScript contexts
when request setup failed.
Core:
*) Security: fixed a heap buffer overflow while parsing namespace
prefix lists passed to XML exclusive canonicalization.
Thanks to Vladimir Vulnerability Research Tech Lead @ Cyera,
evilgensec.
*) Bugfix: fixed a stack buffer overflow when exporting RSA keys
larger than 4096 bits to JWK in WebCrypto.
Thanks to Vaibhav Rajput.
*) Bugfix: fixed RSA-OAEP encryption and decryption with SHA-256 and
SHA-384 digests in WebCrypto.
*) Bugfix: fixed compatibility with quickjs-ng 0.16.0 and later.
*) Bugfix: fixed empty stack traces for QuickJS errors created by
host callbacks.
*) Feature: added btoa() and atob() global functions to the QuickJS
engine and aligned their behavior between both engines.
<ChangeLog>
---
www/freenginx-devel/Makefile | 1 +
www/freenginx-devel/Makefile.extmod | 2 +-
www/freenginx-devel/distinfo | 6 +++---
3 files changed, 5 insertions(+), 4 deletions(-)
diff --git a/www/freenginx-devel/Makefile b/www/freenginx-devel/Makefile
index 883717bb409d..1b5eab628383 100644
--- a/www/freenginx-devel/Makefile
+++ b/www/freenginx-devel/Makefile
@@ -1,6 +1,7 @@
PORTNAME= freenginx
PORTVERSION= ${NGINX_VERSION}
.include "version.mk"
+PORTREVISION= 1
CATEGORIES= www
MASTER_SITES= https://freenginx.org/download/ \
LOCAL/osa
diff --git a/www/freenginx-devel/Makefile.extmod b/www/freenginx-devel/Makefile.extmod
index 3b1fd8998d76..81fd2a587a29 100644
--- a/www/freenginx-devel/Makefile.extmod
+++ b/www/freenginx-devel/Makefile.extmod
@@ -254,7 +254,7 @@ NAXSI_EXTRA_PATCHES= ${PATCHDIR}/extra-patch-naxsi-libinjection__sqli_c \
${PATCHDIR}/extra-patch-naxsi_config
NAXSI_VARS= DSO_EXTMODS+=naxsi NAXSI_SUBDIR=/naxsi_src
-NJS_GH_TUPLE= nginx:njs:1.0.0:njs
+NJS_GH_TUPLE= nginx:njs:1.0.1:njs
NJS_CFLAGS= -I ${LOCALBASE}/include/quickjs
NJS_CONFIGURE_ARGS= --cc-opt="${CFLAGS}" --ld-opt="${LDFLAGS}" --with-quickjs
NJS_IMPLIES= HTTP STREAM
diff --git a/www/freenginx-devel/distinfo b/www/freenginx-devel/distinfo
index d30268687402..506a3025456d 100644
--- a/www/freenginx-devel/distinfo
+++ b/www/freenginx-devel/distinfo
@@ -1,4 +1,4 @@
-TIMESTAMP = 1788277288
+TIMESTAMP = 1788363982
SHA256 (freenginx-1.31.4.tar.gz) = 23d784d93e13ac8febf6dd209631e056bc8c4046769804c6ef3c56d401734e27
SIZE (freenginx-1.31.4.tar.gz) = 1256428
SHA256 (nginx_mogilefs_module-1.0.4.tar.gz) = 7ac230d30907f013dff8d435a118619ea6168aa3714dba62c6962d350c6295ae
@@ -115,8 +115,8 @@ SHA256 (wargio-naxsi-1.7_GH0.tar.gz) = adee817da71913f64a9fb0fca142d9520bb0e5014
SIZE (wargio-naxsi-1.7_GH0.tar.gz) = 1132392
SHA256 (libinjection-libinjection-b9fcaaf_GH0.tar.gz) = 7812e1316b61a7a7d3a65a57a07c6d5235ac40fe35e6edda983f31a44661a38e
SIZE (libinjection-libinjection-b9fcaaf_GH0.tar.gz) = 2218207
-SHA256 (nginx-njs-1.0.0_GH0.tar.gz) = 56fe6560549cbcb7fb5740534b541bb153250d8772aa16ac18bc30eb0cc498dd
-SIZE (nginx-njs-1.0.0_GH0.tar.gz) = 1011616
+SHA256 (nginx-njs-1.0.1_GH0.tar.gz) = 74372cfcbf11eb0a71bc555e19dc785f61d561d5663d254474da6c8c9e50a6a7
+SIZE (nginx-njs-1.0.1_GH0.tar.gz) = 1003218
SHA256 (osokin-nginx-otel-ed35139_GH0.tar.gz) = ae35317e2f01481b6511f4b4b6366233193cab19db2cc8fe0da4f2d3529efe68
SIZE (osokin-nginx-otel-ed35139_GH0.tar.gz) = 28117
SHA256 (konstruxi-ngx_postgres-8aa7359_GH0.tar.gz) = c69ad4495de7c7883ebc23e1e6c4cc83a4ac6a7fddd4d5c12e49d33b65f7c50b