Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 18 Jul 2002 23:17:05 -0700 (PDT)
From:      Caitlen <aeonflux@trioptimum.com>
To:        freebsd-gnats-submit@FreeBSD.org
Subject:   ports/40757: by cvsupfile defaults
Message-ID:  <200207190617.g6J6H5Ut085334@www.freebsd.org>

next in thread | raw e-mail | index | archive | help

>Number:         40757
>Category:       ports
>Synopsis:       by cvsupfile defaults
>Confidential:   no
>Severity:       serious
>Priority:       high
>Responsible:    freebsd-ports
>State:          open
>Quarter:        
>Keywords:       
>Date-Required:
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Thu Jul 18 23:20:02 PDT 2002
>Closed-Date:
>Last-Modified:
>Originator:     Caitlen
>Release:        4.6
>Organization:
none
>Environment:
4.6p3 release
>Description:
The cvsupit port has a special user friendly application that builds a cvsupfile for you.  This file is flawed by default and does NOT include src-crypto or src-secure, meaning that openssl and openssh do NOT get updated when you run make world, and thus remain the older (READ: Vulnerable) versions of the software.
>How-To-Repeat:
install cvsupit and look at the file created in /etc/cvsupfile
notice how src-secure and src-crypto are NOT included.
>Fix:
Change the defaults to read src-all, instead of individually listing every category except the REALLY important ones like security and crypto :)

the port should also create an empty /usr/sup/refuse and tell the user of it's existence.  So the users know they can add "russian", or whatever other ports from the collection they dont want to it.  By default this isn't explained.
>Release-Note:
>Audit-Trail:
>Unformatted:

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ports" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200207190617.g6J6H5Ut085334>