DELTA 432888 0 26597 SVN† † ƒv ‚B€ƒt†™J‚;ƒt202: AFFECTS: users of www/uwsgi AUTHOR: feld@FreeBSD.org The previous disruptive changes to uwsgi for security have been remediated through creation of a dedicated uwsgi user/group and utilizing the uwsgi feature to set socket ownership. The uwsgi daemon by default now has the following properties: * Process runs as uwsgi user and group (UID/GID 165) * Socket mode is 660, still protecting unauthorized access from "other" * Socket ownership is www:www, restoring compatibility† † †  ƒ}€ƒ{†œƒ{ems where the /bin/sh -> /bin/bash. FreeBSD users were not exposed except in the most unusual and unsupported circumstances. However, this is an important update for security. This change could break your configuration as Henrik describes here: > NOTE: Replacing the shell script wrappers means that the cgioptions.cfg > file is no longer processed as a shell script. The new wrapper works > fine with the default version of cgioptions.cfg, but it you have > modified it in a way that it reŒΐ† †  ƒ}€ƒ{†œƒ{ teTeX-based ports and TeXLive are mutually exclusive. This means TeXLive ports cannot be installed when teTeX is already installed. You need to remove all of the TeX-related packages based on teTeX to try TeXLive. Migration procedure will be announced when conversion of the port dependency is completed. * Meta port - print/texlive-full: meta port to install all of the TeXLive components * Libraries - devel/tex-kpathsea: kpathsea library - devel/tex-web2c: WEB2C toolchain and T’ΰ† †  ƒ}€ƒ{†œƒ{f security/libgcrypt and any port that depends on it AUTHOR: swills@FreeBSD.org The libgcrypt port has been updated to 1.5.0 and all shared libraries versions have been bumped. So you need to rebuild all applications that depend on libgcrypt. Do something like: # portmaster -r libgcrypt or # portupgrade -rf libgcrypt 20110703: AFFECTS: users of print/lyx and print/lyx-devel AUTHOR: makc@FreeBSD.org print/lyx has been updated to 2.0. print/lyx16 has been added to ports tree f™€„©$„­ ƒ}€ƒ{„©$ƒ{estarting bacula. 20090410: AFFECTS: users of www/trac-email2trac AUTHOR: brooks@FreeBSD.org bin/email2trac.py and bin/delete_spam.py are now installed without the .py extension to make the suid run_email2trac work and match the online documentation. If you were using them in scripts or alias entries, you will need to update paths accordingly. 20090401: AFFECTS: users of Fedora 8 Linux infrastructure ports AUTHOR: bsam@FreeBSD.org ATTENTION! Those ports are not default for any veENDREP id: 1-102685.0.r433174/2678 type: file pred: 1-102685.0.r432888/27088 count: 2017 text: 433174 0 2650 480927 5c926a715f2593f263b5a35697abdd70 1e81476299f51e54e1d06f5cb2c8a61039b2282e 433173-9a8m/_2 props: 300914 71 103 0 bb58aa814bbdf5f7c1ab04a05656f5a5 cpath: /head/UPDATING copyroot: 0 / PLAIN K 10 .arcconfig V 26 file 1-354154.0.r422906/41 K 14 .gitattributes V 27 file 1-411777.0.r411777/210 K 10 .gitignore V 26 file 1-348322.0.r376072/79 K 7 CHANGES V 27 file 1-99373.0.r431681/1700 K 15 CONTRIBUTING.md V 27 file 1-348323.0.r348323/344 K 9 COPYRIGHT V 26 file 1-146787.0.r430107/51 K 4 GIDs V 27 file 1-168311.0.r433172/672 K 8 Keywords V 27 dir 1-314142.0.r419368/1305 K 5 LEGAL V 25 file 1-748.0.r432620/2257 K 5 MOVED V 27 file 1-69878.0.r432955/1941 K 8 Makefile V 24 file 1-6.0.r424411/75633 K 2 Mk V 22 dir 1-5.0.r433084/2247 K 6 README V 25 file 1-2408.0.r340854/956 K 9 Templates V 24 dir 1-2932.0.r414724/906 K 5 Tools V 26 dir 3-15302.0.r430495/3344 K 4 UIDs V 27 file 4-168311.0.r433172/954 K 8 UPDATING V 28 file 1-102685.0.r433174/2678 K 13 accessibility V 27 dir 1-42583.0.r432953/24937 K 6 arabic V 27 dir 1-38973.0.r432960/49783 K 9 archivers V 25 dir 1-242.0.r433127/12920 K 5 astro V 24 dir 1-301.0.r432956/7498 K 5 audio V 25 dir 1-148.0.r433137/44276 K 4 base V 28 dir 1-420954.0.r431796/79632 K 10 benchmarks V 24 dir 1-62.0.r432897/64319 K 7 biology V 26 dir 1-9066.0.r432932/64626 K 3 cad V 24 dir 1-276.0.r433162/8677 K 7 chinese V 26 dir 1-3770.0.r432960/57349 K 5 comms V 24 dir 1-76.0.r433095/10964 K 10 converters V 26 dir 1-1561.0.r433108/10844 K 9 databases V 25 dir 1-771.0.r433123/55683 K 9 deskutils V 26 dir 1-2098.0.r432940/15299 K 5 devel V 25 dir 1-73.0.r433167/314579 K 3 dns V 27 dir 1-6145.0.r432953/470929 K 7 editors V 23 dir 4-6.0.r433143/17607 K 9 emulators V 25 dir 1-181.0.r433134/11491 K 7 finance V 26 dir 1-4110.0.r433081/12510 K 6 french V 28 dir 1-25673.0.r432960/141476 K 3 ftp V 24 dir 1-199.0.r433161/7661 K 5 games V 25 dir 1-104.0.r433135/59558 K 6 german V 27 dir 1-7451.0.r432960/143851 K 8 graphics V 24 dir 1-94.0.r433151/57291 K 6 hebrew V 28 dir 3-31142.0.r432960/145195 K 9 hungarian V 29 dir 1p-38973.0.r432960/146716 K 3 irc V 23 dir 1-42.0.r433021/8463 K 8 japanese V 26 dir 1-410.0.r432960/162818 K 4 java V 25 dir 1-2798.0.r433131/8048 K 6 korean V 27 dir 1-5873.0.r432960/165726 K 4 lang V 24 dir 1-15.0.r433164/19881 K 4 mail V 24 dir 1-57.0.r433142/42236 K 4 math V 25 dir 1-162.0.r433153/39598 K 4 misc V 24 dir 7-35.0.r433048/27250 K 10 multimedia V 25 dir d-333.0.r433165/28059 K 3 net V 24 dir 1-22.0.r433171/76063 K 6 net-im V 28 dir 15-11144.0.r433166/10835 K 8 net-mgmt V 26 dir r-1011.0.r433065/20857 K 7 net-p2p V 26 dir g-29106.0.r433100/7929 K 4 news V 24 dir 1-145.0.r432991/8935 K 4 palm V 25 dir 1-6646.0.r433092/4356 K 6 polish V 29 dir tv-38973.0.r432960/167620 K 10 ports-mgmt V 25 dir 1-5132.0.r432868/5866 K 10 portuguese V 28 dir 1-17842.0.r432960/170163 K 5 print V 25 dir 1-79.0.r432953/691426 K 7 russian V 27 dir 1-1559.0.r432960/173230 K 7 science V 26 dir n-5356.0.r433069/10747 K 8 security V 25 dir 1-269.0.r433169/64831 K 6 shells V 24 dir w-6.0.r432932/851599 K 8 sysutils V 25 dir b-339.0.r433168/68507 K 8 textproc V 25 dir 1-322.0.r433150/95651 K 9 ukrainian V 28 dir g-39704.0.r432960/174736 K 10 vietnamese V 25 dir 1-4812.0.r433098/2267 K 3 www V 26 dir 1-114.0.r433172/142421 K 3 x11 V 24 dir 1-16.0.r433063/27174 K 10 x11-clocks V 24 dir 1-931.0.r432714/5074 K 11 x11-drivers V 27 dir 1-157567.0.r432816/5676 K 6 x11-fm V 24 dir 1-691.0.r432904/3181 K 9 x11-fonts V 25 dir 1-543.0.r433087/14569 K 11 x11-servers V 26 dir 1n-710.0.r432804/58073 K 10 x11-themes V 29 dir 1-14410.0.r432937/1467365 K 12 x11-toolkits V 26 dir 1-120.0.r432953/918498 K 6 x11-wm V 23 dir 1-40.0.r433089/8529 END ENDREP id: 2-1.0.r433174/6492 type: dir pred: 2-1.0.r433172/146116 count: 429081 text: 433174 2969 3510 0 d627b0fb3bf545acdd3963500dbe42b5 props: 7322 2587 45 0 7a04b33bf8e35fd5c3d111baaf403dc5 cpath: /head copyroot: 0 / PLAIN K 8 branches V 24 dir 0-1.0.r433173/148385 K 4 head V 22 dir 2-1.0.r433174/6492 K 8 projects V 30 dir 0-377393.0.r378744/3577692 K 8 svnadmin V 22 dir 3-1.0.r432800/1657 K 4 tags V 22 dir 8-1.0.r430249/5125 END ENDREP id: 0.0.r433174/6931 type: dir pred: 0.0.r433173/148789 count: 433174 text: 433174 6707 211 0 ea764da1908c52f1f7d5a9940b767329 props: 341041 7130 346 0 8b695b9f61597e4917effffba3bbfaa3 cpath: / copyroot: 0 / minfo-cnt: 36 1-102685.0.t433173-9a8m modify-file true false /head/UPDATING 6931 7154