git: 03159bd673b4 - main - www/freenginx-devel: third-party modules management

From: Sergey A. Osokin <osa_at_FreeBSD.org>
Date: Wed, 02 Sep 2026 15:56:20 UTC
The branch main has been updated by osa:

URL: https://cgit.FreeBSD.org/ports/commit/?id=03159bd673b4876c5b014b32b7c6bf9963b7824a

commit 03159bd673b4876c5b014b32b7c6bf9963b7824a
Author:     Sergey A. Osokin <osa@FreeBSD.org>
AuthorDate: 2026-09-02 15:55:10 +0000
Commit:     Sergey A. Osokin <osa@FreeBSD.org>
CommitDate: 2026-09-02 15:56:14 +0000

    www/freenginx-devel: third-party modules management
    
    - njs module security update to 1.0.1
    
    Bump PORTREVISION.
    
    Sponsored by:   tipi.work
    
    <ChangeLog>
    
    nginx modules:
    
    *) Security: fixed an access control bypass in js_access when an
       asynchronous request body continuation threw an exception or
       produced an unhandled rejection.  Previously, nginx could continue
       processing the request as though the js_access check had succeeded.
       Thanks to Ta Duc Thien.
    
    *) Security: fixed a worker process crash when reading
       Response.statusText after an upstream server returned a status
       line with an empty reason phrase.
    
    *) Bugfix: fixed unhandled promise rejection tracking in reused
       QuickJS contexts.
    
    *) Bugfix: fixed SharedDict.pop() returning undefined for unexpired
       entries in shared dictionaries with a timeout.
    
    *) Bugfix: fixed validation and replacement of Fetch Headers values.
       This also fixed dangling header names in the QuickJS engine.
    
    *) Bugfix: fixed missing validation of r.headersOut names and values,
       and of redirect targets passed to r.return().
    
    *) Bugfix: fixed use-after-free, worker aborts, and leaks caused by
       cyclic references involving Fetch, HTTP request, and Stream session
       objects in the QuickJS engine.
    
    *) Bugfix: fixed QuickJS context reuse after internal redirects and
       when pending jobs remained after request teardown.
    
    *) Bugfix: fixed cleanup of partially initialized JavaScript contexts
       when request setup failed.
    
    Core:
    
    *) Security: fixed a heap buffer overflow while parsing namespace
       prefix lists passed to XML exclusive canonicalization.
       Thanks to Vladimir Vulnerability Research Tech Lead @ Cyera,
       evilgensec.
    
    *) Bugfix: fixed a stack buffer overflow when exporting RSA keys
       larger than 4096 bits to JWK in WebCrypto.
       Thanks to Vaibhav Rajput.
    
    *) Bugfix: fixed RSA-OAEP encryption and decryption with SHA-256 and
       SHA-384 digests in WebCrypto.
    
    *) Bugfix: fixed compatibility with quickjs-ng 0.16.0 and later.
    
    *) Bugfix: fixed empty stack traces for QuickJS errors created by
       host callbacks.
    
    *) Feature: added btoa() and atob() global functions to the QuickJS
       engine and aligned their behavior between both engines.
    
    <ChangeLog>
---
 www/freenginx-devel/Makefile        | 1 +
 www/freenginx-devel/Makefile.extmod | 2 +-
 www/freenginx-devel/distinfo        | 6 +++---
 3 files changed, 5 insertions(+), 4 deletions(-)

diff --git a/www/freenginx-devel/Makefile b/www/freenginx-devel/Makefile
index 883717bb409d..1b5eab628383 100644
--- a/www/freenginx-devel/Makefile
+++ b/www/freenginx-devel/Makefile
@@ -1,6 +1,7 @@
 PORTNAME=	freenginx
 PORTVERSION=	${NGINX_VERSION}
 .include "version.mk"
+PORTREVISION=	1
 CATEGORIES=	www
 MASTER_SITES=	https://freenginx.org/download/ \
 		LOCAL/osa
diff --git a/www/freenginx-devel/Makefile.extmod b/www/freenginx-devel/Makefile.extmod
index 3b1fd8998d76..81fd2a587a29 100644
--- a/www/freenginx-devel/Makefile.extmod
+++ b/www/freenginx-devel/Makefile.extmod
@@ -254,7 +254,7 @@ NAXSI_EXTRA_PATCHES=	${PATCHDIR}/extra-patch-naxsi-libinjection__sqli_c \
 			${PATCHDIR}/extra-patch-naxsi_config
 NAXSI_VARS=		DSO_EXTMODS+=naxsi NAXSI_SUBDIR=/naxsi_src
 
-NJS_GH_TUPLE=		nginx:njs:1.0.0:njs
+NJS_GH_TUPLE=		nginx:njs:1.0.1:njs
 NJS_CFLAGS=		-I ${LOCALBASE}/include/quickjs
 NJS_CONFIGURE_ARGS=	--cc-opt="${CFLAGS}" --ld-opt="${LDFLAGS}" --with-quickjs
 NJS_IMPLIES=		HTTP STREAM
diff --git a/www/freenginx-devel/distinfo b/www/freenginx-devel/distinfo
index d30268687402..506a3025456d 100644
--- a/www/freenginx-devel/distinfo
+++ b/www/freenginx-devel/distinfo
@@ -1,4 +1,4 @@
-TIMESTAMP = 1788277288
+TIMESTAMP = 1788363982
 SHA256 (freenginx-1.31.4.tar.gz) = 23d784d93e13ac8febf6dd209631e056bc8c4046769804c6ef3c56d401734e27
 SIZE (freenginx-1.31.4.tar.gz) = 1256428
 SHA256 (nginx_mogilefs_module-1.0.4.tar.gz) = 7ac230d30907f013dff8d435a118619ea6168aa3714dba62c6962d350c6295ae
@@ -115,8 +115,8 @@ SHA256 (wargio-naxsi-1.7_GH0.tar.gz) = adee817da71913f64a9fb0fca142d9520bb0e5014
 SIZE (wargio-naxsi-1.7_GH0.tar.gz) = 1132392
 SHA256 (libinjection-libinjection-b9fcaaf_GH0.tar.gz) = 7812e1316b61a7a7d3a65a57a07c6d5235ac40fe35e6edda983f31a44661a38e
 SIZE (libinjection-libinjection-b9fcaaf_GH0.tar.gz) = 2218207
-SHA256 (nginx-njs-1.0.0_GH0.tar.gz) = 56fe6560549cbcb7fb5740534b541bb153250d8772aa16ac18bc30eb0cc498dd
-SIZE (nginx-njs-1.0.0_GH0.tar.gz) = 1011616
+SHA256 (nginx-njs-1.0.1_GH0.tar.gz) = 74372cfcbf11eb0a71bc555e19dc785f61d561d5663d254474da6c8c9e50a6a7
+SIZE (nginx-njs-1.0.1_GH0.tar.gz) = 1003218
 SHA256 (osokin-nginx-otel-ed35139_GH0.tar.gz) = ae35317e2f01481b6511f4b4b6366233193cab19db2cc8fe0da4f2d3529efe68
 SIZE (osokin-nginx-otel-ed35139_GH0.tar.gz) = 28117
 SHA256 (konstruxi-ngx_postgres-8aa7359_GH0.tar.gz) = c69ad4495de7c7883ebc23e1e6c4cc83a4ac6a7fddd4d5c12e49d33b65f7c50b