Apache 2.0

Hye-Shik Chang perky at fallin.lv
Thu May 29 16:25:04 PDT 2003


On Thu, May 29, 2003 at 03:16:43PM +0200, Miguel Mendez wrote:
> On Thu, 29 May 2003 18:04:11 +0800
> "???? Xin LI" <delphij at freebsdchina.org> wrote:
> 
> > Please allow a reasonable time for maintainers and portmgr@ to
> > determine whether the port will be upgraded. During a port freeze, it
> > usually takes more time to have a port upgraded, even when the update
> 
> Hmm, either you didn't understand what I meant or I wasn't clear enough.
> I wasn't, by any means, demanding that this package is updated
> immediately. It was simply an honest question: Whether it can be updated
> before 5.1 gets out. I'm very aware of the fact that, during a ports
> freeze, portmgr@ are the ones to decide if a commit goes in or not. Even
> if the port is not updated, I think a message should be added, something
> like:
> 
> ***************************************************
> Warning: enabling mod_dav may pose a security risk.
> ***************************************************

Apache 2.0.46 fixed 2 more security bugs; CAN-2003-0134 and CAN-2003-0189.
Because apache 2.0.* is a bugfix-only branch nowadays and 2.0.46 has no
brand new features than 2.0.45. I see that updating to 2.0.46 before
5.1-RELEASE would be okay.

> 
> And let the admin decide whether she is willing to use it. Marking the
> port as FORBIDDEN is not a solution at all, IMHO.
> 
> > I have submitted a patch PR as ports/52768, you may want to access it
> > through the web:
> > http://www.freebsd.org/cgi/query-pr.cgi?pr=52768
> 
> Thanks, I'll have a look at it.

The patch on ports/52768 looks fine except that is malformed and missing
diff for pkg-plist. Thank you anyway! :)
A fixed patch is available at http://people.freebsd.org/~perky/apache-2.0.46.diff


Regards,
    Hye-Shik =)

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-ports/attachments/20030530/8726d5f9/attachment.bin


More information about the freebsd-ports mailing list