From owner-freebsd-gnome@FreeBSD.ORG Sun Oct 5 12:20:04 2008 Return-Path: Delivered-To: gnome@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 40D33106568E for ; Sun, 5 Oct 2008 12:20:04 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 2F1118FC1B for ; Sun, 5 Oct 2008 12:20:04 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.2/8.14.2) with ESMTP id m95CK43M085009 for ; Sun, 5 Oct 2008 12:20:04 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.2/8.14.1/Submit) id m95CK4vq084994; Sun, 5 Oct 2008 12:20:04 GMT (envelope-from gnats) Date: Sun, 5 Oct 2008 12:20:04 GMT Message-Id: <200810051220.m95CK4vq084994@freefall.freebsd.org> To: gnome@FreeBSD.org From: bf Cc: Subject: Re: ports/127661: [PATCH]textproc/libxml2: update to 2.7.1, which includes security fixes X-BeenThere: freebsd-gnome@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: bf List-Id: GNOME for FreeBSD -- porting and maintaining List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 05 Oct 2008 12:20:04 -0000 The following reply was made to PR ports/127661; it has been noted by GNATS. From: bf To: bug-followup@freebsd.org, mezz@freebsd.org Cc: Subject: Re: ports/127661: [PATCH]textproc/libxml2: update to 2.7.1, which includes security fixes Date: Sun, 5 Oct 2008 05:11:00 -0700 (PDT) --0-1041875847-1223208661=:3816 Content-Type: text/plain; charset=us-ascii Here is a patch like the previous one I submitted, but for the recently released 2.7.2. The primary author claims that it corrects some of the parsing and serialization problems in earlier 2.7.x versions. Of course there is still some behavior that is different from that of 2.6.x, some of which is the consequence of the security-related changes, but I have not encountered any problems with other dependent ports on my RELENG-7 i386 box so far. Please let me know if this is acceptable, or whether you still prefer to use a patched version of 2.6.32 instead. Regards, b. --0-1041875847-1223208661=:3816 Content-Type: text/plain; name="libxml2.272.txt" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="libxml2.272.txt" ZGlmZiAtcnVOIGxpYnhtbDIub3JpZy9NYWtlZmlsZSBsaWJ4bWwyL01ha2Vm aWxlCi0tLSBsaWJ4bWwyLm9yaWcvTWFrZWZpbGUJMjAwOC0wNS0yNCAwMToy NzoxNy4wMDAwMDAwMDAgLTA0MDAKKysrIGxpYnhtbDIvTWFrZWZpbGUJMjAw OC0xMC0wNSAwNzo0MzowNS43NTU0NDczMjIgLTA0MDAKQEAgLTEyLDcgKzEy LDcgQEAKICMKIAogUE9SVE5BTUU9CWxpYnhtbDIKLVBPUlRWRVJTSU9OPQky LjYuMzIKK1BPUlRWRVJTSU9OPQkyLjcuMgogUE9SVFJFVklTSU9OPz0JMAog Q0FURUdPUklFUz89CXRleHRwcm9jIGdub21lCiBNQVNURVJfU0lURVM9CWZ0 cDovL2ZyLnJwbWZpbmQubmV0L3B1Yi9saWJ4bWwvIFwKZGlmZiAtcnVOIGxp YnhtbDIub3JpZy9kaXN0aW5mbyBsaWJ4bWwyL2Rpc3RpbmZvCi0tLSBsaWJ4 bWwyLm9yaWcvZGlzdGluZm8JMjAwOC0wNS0yNCAwMToyNzoxNy4wMDAwMDAw MDAgLTA0MDAKKysrIGxpYnhtbDIvZGlzdGluZm8JMjAwOC0xMC0wNSAwNzo0 MzowNS43NTU0NDczMjIgLTA0MDAKQEAgLTEsMyArMSwzIEBACi1NRDUgKGdu b21lMi9saWJ4bWwyLTIuNi4zMi50YXIuZ3opID0gMjYyMWQzMjJjMTZmMDI1 N2UzMGYwZmYyYjEzMzg0ZGUKLVNIQTI1NiAoZ25vbWUyL2xpYnhtbDItMi42 LjMyLnRhci5neikgPSAxYjQ0MjhiODc5YWZjYWFlM2MyMDEzYjIxMjgzYmFh ZDA0MDY2MWZiZDUwMmU4OTNlODNhZGMzZDE1Yzg1ZDUzCi1TSVpFIChnbm9t ZTIvbGlieG1sMi0yLjYuMzIudGFyLmd6KSA9IDQ3MjIyMjcKK01ENSAoZ25v bWUyL2xpYnhtbDItMi43LjIudGFyLmd6KSA9IGRjNDNmZjdhZTZhZGVkNDVm NTc4Yzg3YjdiMGM4NzY2CitTSEEyNTYgKGdub21lMi9saWJ4bWwyLTIuNy4y LnRhci5neikgPSBjMDFiZDYyMWY3NzFjZGVlMzQ5ODc3ZjU1Y2M4NDFhMWJk ZmIyMDZiMmNmNWM5YWE2MmFhNmE5NjgwZTYxOTgwCitTSVpFIChnbm9tZTIv bGlieG1sMi0yLjcuMi50YXIuZ3opID0gNDc5MDYzOQpkaWZmIC1ydU4gbGli eG1sMi5vcmlnL2ZpbGVzL3BhdGNoLWFhIGxpYnhtbDIvZmlsZXMvcGF0Y2gt YWEKLS0tIGxpYnhtbDIub3JpZy9maWxlcy9wYXRjaC1hYQkyMDA4LTAxLTIy IDE1OjU5OjQyLjAwMDAwMDAwMCAtMDUwMAorKysgbGlieG1sMi9maWxlcy9w YXRjaC1hYQkyMDA4LTEwLTA1IDA3OjQzOjA1Ljc1NTQ0NzMyMiAtMDQwMApA QCAtMSw2ICsxLDYgQEAKLS0tLSBNYWtlZmlsZS5pbi5vcmlnCTIwMDgtMDEt MjIgMTU6NDc6NTYuMDAwMDAwMDAwIC0wNTAwCi0rKysgTWFrZWZpbGUuaW4J MjAwOC0wMS0yMiAxNTo0OToyMS4wMDAwMDAwMDAgLTA1MDAKLUBAIC00ODYs MTMgKzQ4NiwxMyBAQCBzeXNjb25mZGlyID0gQHN5c2NvbmZkaXJACistLS0g TWFrZWZpbGUuaW4ub3JpZwkyMDA4LTEwLTA1IDA3OjM2OjE1LjI5OTE0MTU2 MiAtMDQwMAorKysrIE1ha2VmaWxlLmluCTIwMDgtMTAtMDUgMDc6NDE6MTEu ODgzNjg3MzYzIC0wNDAwCitAQCAtNTEzLDEzICs1MTMsMTMgQEAKICB0YXJn ZXRfYWxpYXMgPSBAdGFyZ2V0X2FsaWFzQAogIHRvcF9idWlsZGRpciA9IEB0 b3BfYnVpbGRkaXJACiAgdG9wX3NyY2RpciA9IEB0b3Bfc3JjZGlyQApAQCAt MTIsMjAgKzEyLDIwIEBACiAgbGliX0xUTElCUkFSSUVTID0gbGlieG1sMi5s YQogIGxpYnhtbDJfbGFfTElCQUREID0gQFRIUkVBRF9MSUJTQCBAWl9MSUJT QCAkKElDT05WX0xJQlMpIEBNX0xJQlNAIEBXSU4zMl9FWFRSQV9MSUJBRERA CiAtbGlieG1sMl9sYV9MREZMQUdTID0gQENZR1dJTl9FWFRSQV9MREZMQUdT QCBAV0lOMzJfRVhUUkFfTERGTEFHU0AgLXZlcnNpb24taW5mbyBATElCWE1M X1ZFUlNJT05fSU5GT0AgQE1PRFVMRV9QTEFURk9STV9MSUJTQAotK2xpYnht bDJfbGFfTERGTEFHUyA9IEBDWUdXSU5fRVhUUkFfTERGTEFHU0AgQFdJTjMy X0VYVFJBX0xERkxBR1NAIC12ZXJzaW9uLWluZm8gNTowOjAgQE1PRFVMRV9Q TEFURk9STV9MSUJTQAorK2xpYnhtbDJfbGFfTERGTEFHUyA9IEBDWUdXSU5f RVhUUkFfTERGTEFHU0AgQFdJTjMyX0VYVFJBX0xERkxBR1NAIC12ZXJzaW9u LWluZm8gNToyOjAgQE1PRFVMRV9QTEFURk9STV9MSUJTQAogIEBXSVRIX1RS SU9fU09VUkNFU19GQUxTRUBsaWJ4bWwyX2xhX1NPVVJDRVMgPSBTQVguYyBl bnRpdGllcy5jIGVuY29kaW5nLmMgZXJyb3IuYyBwYXJzZXJJbnRlcm5hbHMu YyAgXAogIEBXSVRIX1RSSU9fU09VUkNFU19GQUxTRUAJCXBhcnNlci5jIHRy ZWUuYyBoYXNoLmMgbGlzdC5jIHhtbElPLmMgeG1sbWVtb3J5LmMgdXJpLmMg IFwKICBAV0lUSF9UUklPX1NPVVJDRVNfRkFMU0VACQl2YWxpZC5jIHhsaW5r LmMgSFRNTHBhcnNlci5jIEhUTUx0cmVlLmMgZGVidWdYTUwuYyB4cGF0aC5j ICBcCi1AQCAtNTkwLDcgKzU5MCw3IEBAIHRlc3RhcGlfTERGTEFHUyA9IAot IHRlc3RhcGlfREVQRU5ERU5DSUVTID0gJChERVBTKQotIHRlc3RhcGlfTERB REQgPSAkKExEQUREUykKLSBDTEVBTkZJTEVTID0geG1sMkNvbmYuc2gKK0BA IC02MzMsNyArNjMzLDcgQEAKKyBydW54bWxjb25mX0RFUEVOREVOQ0lFUyA9 ICQoREVQUykKKyBydW54bWxjb25mX0xEQUREID0gJChMREFERFMpCisgQ0xF QU5GSUxFUyA9IHhtbDJDb25mLnNoICouZ2NkYSAqLmdjbm8KIC1jb25mZXhl Y2RpciA9ICQobGliZGlyKQogK2NvbmZleGVjZGlyID0gJChzeXNjb25mZGly KQogIGNvbmZleGVjX0RBVEEgPSB4bWwyQ29uZi5zaAogIENWU19FWFRSQV9E SVNUID0gCiAgRVhUUkFfRElTVCA9IHhtbDItY29uZmlnLmluIHhtbDJDb25m LnNoLmluIGxpYnhtbC5zcGVjLmluIGxpYnhtbDIuc3BlYyBcCi1AQCAtNjEz LDggKzYxMyw4IEBAIHBrZ2NvbmZpZ19EQVRBID0gbGlieG1sLTIuMC5wYwor QEAgLTY1Niw4ICs2NTYsOCBAQAogICMgSW5zdGFsbCB0aGUgdGVzdHMgcHJv Z3JhbSBzb3VyY2VzIGFzIGV4YW1wbGVzIAogICMKICBCQVNFX0RJUiA9ICQo ZGF0YWRpcikvZG9jCkBAIC0zMywxMiArMzMsMTIgQEAKIC1FWEFNUExFU19E SVIgPSAkKEJBU0VfRElSKS8kKERPQ19NT0RVTEUpL2V4YW1wbGVzCiArRE9D X01PRFVMRSA9IGxpYnhtbDIKICtFWEFNUExFU19ESVIgPSAkKGRhdGFkaXIp L2V4YW1wbGVzL2xpYnhtbDIKLSBhbGw6IGNvbmZpZy5oCi0gCSQoTUFLRSkg JChBTV9NQUtFRkxBR1MpIGFsbC1yZWN1cnNpdmUKICAKLUBAIC0xMzQ0LDcg KzEzNDQsNyBAQCBkaXN0Y2xlYW5jaGVjazogZGlzdGNsZWFuCisgIworICMg Q292ZXJhZ2Ugc3VwcG9ydCwgbGFyZ2VseSBib3Jyb3dlZCBmcm9tIGxpYnZp cnQKK0BAIC0xNDE0LDcgKzE0MTQsNyBAQAorIAkgICAgICAgZXhpdCAxOyB9 ID4mMgogIGNoZWNrLWFtOiBhbGwtYW0KLSAJJChNQUtFKSAkKEFNX01BS0VG TEFHUykgY2hlY2stbG9jYWwKICBjaGVjazogY2hlY2stcmVjdXJzaXZlCiAt YWxsLWFtOiBNYWtlZmlsZSAkKExUTElCUkFSSUVTKSAkKFBST0dSQU1TKSAk KFNDUklQVFMpICQoTUFOUykgJChEQVRBKSBcCiArYWxsLWFtOiBNYWtlZmls ZSAkKExUTElCUkFSSUVTKSAkKFNDUklQVFMpICQoTUFOUykgJChEQVRBKSBc Cg== --0-1041875847-1223208661=:3816--