From nobody Wed Oct 19 13:56:10 2022 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4MsshV6VSlz4g276; Wed, 19 Oct 2022 13:56:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4MsshV5pnNz3MhN; Wed, 19 Oct 2022 13:56:10 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1666187770; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OdQNxNVNgC9hhynkv0AjXRIyJqhQ7PILDl3IEs9pgDg=; b=SD/DTgHUEImpoTH9dliY5gHQQNYh5uBHsU5ChL8+wfbDzT55oxDiHzw34IIkxaxGqxOqX+ wHGHzZju8WR+pTctrkkmiybAXBVBBKwzfIh523lBoeuiTJAQB+CMRc++cuAmdDBqRCm0Li KE5wq/6xCNknebPE0rtzwpOdRIZHBIxHlOEsKMnJgg7Fqtzs7fCwEWv/jGS6e3LhfGXvA1 17qbMWsZ700OWwMt5wVCAf9dGZh6hviZ59P7vjXFYW7NiHEbPdA08AmwAdeRddLkkmS49P AKzpds7RSP7Iw40oXR8zuxJSIWLE81BkoNLyLsNAeapB1Xu4eWOoj7oF3tDxBg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4MsshV4tRmzY93; Wed, 19 Oct 2022 13:56:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.16.1/8.16.1) with ESMTP id 29JDuAhF010360; Wed, 19 Oct 2022 13:56:10 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.16.1/8.16.1/Submit) id 29JDuAnY010359; Wed, 19 Oct 2022 13:56:10 GMT (envelope-from git) Date: Wed, 19 Oct 2022 13:56:10 GMT Message-Id: <202210191356.29JDuAnY010359@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: "Sergey A. Osokin" Subject: git: 186e88aeb1d0 - main - www/nginx-devel: security update from 1.23.1 to 1.23.2 List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: osa X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 186e88aeb1d055bf812a4d03f7ffd03bf16930c3 Auto-Submitted: auto-generated ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1666187770; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OdQNxNVNgC9hhynkv0AjXRIyJqhQ7PILDl3IEs9pgDg=; b=Pc+x+HHGq6v9Y/FI46cdx9LP4DiSCp+1q/6hMgyw80f3PxoNfdIsKD8INK8ADEKscOdJOG nWH1SIgm6nNfPdaqS+DzRCkdlKkOFkgBLZcGJyYlb6nhQJRtAYpW4ARAyLW6+x8OVZM5CW vpxzCBZnWbHYotPUl9rMcnNngnRPR0zqo1gyICJcNe1jTiIvnM6AiMLWsvQwHMqJMBhJ4p 4dghyIQJgxiftkblrbryb/YyNn6aBv3xwfGtiGjWNf43gY4taANa3ZOMnNUcHFI/VHdGDa +slS6VFl4URkkQx4FLWKQeiO26W38o+CCDWnttebDqn4JHU2dKx4QjEAL4xyJg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1666187770; a=rsa-sha256; cv=none; b=It6Epxx0qv87ezFFpChIv8hT0/KDHMIMYDOAt4OZWa3w3YPEXKCFZiUK9kXiub9DqAqDKc PJMDHN4cOvOFaVWuQ4A6MmY9/+OzKF08NJNKFa887Uf1CrBWcuQx0IuYIa6DHIQCorsO0l 77LhVQ0/PBkcUCbDiZPVTMQNiCdW1mD8/8Ayl0aIcoB8XM7pu2YupmqkH7/w5JGpxKtKi4 dd9kN5BuH2iLVlZY0mIB7K8+WlAiBDtHeoNzeB3R5tvlhm7oxxXgxchooksRSWO2xFMFAy WgAa4n+00IVBU9ecq2uaF/gXw1xBJeOtVzbnKbteV8eD0iK4IkI79ZArWsqzhA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none X-ThisMailContainsUnwantedMimeParts: N The branch main has been updated by osa: URL: https://cgit.FreeBSD.org/ports/commit/?id=186e88aeb1d055bf812a4d03f7ffd03bf16930c3 commit 186e88aeb1d055bf812a4d03f7ffd03bf16930c3 Author: Sergey A. Osokin AuthorDate: 2022-10-19 13:55:28 +0000 Commit: Sergey A. Osokin CommitDate: 2022-10-19 13:55:28 +0000 www/nginx-devel: security update from 1.23.1 to 1.23.2 *) Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash, worker process memory disclosure, or might have potential other impact (CVE-2022-41741, CVE-2022-41742). *) Feature: the "$proxy_protocol_tlv_..." variables. *) Feature: TLS session tickets encryption keys are now automatically rotated when using shared memory in the "ssl_session_cache" directive. *) Change: the logging level of the "bad record type" SSL errors has been lowered from "crit" to "info". Thanks to Murilo Andrade. *) Change: now when using shared memory in the "ssl_session_cache" directive the "could not allocate new session" errors are logged at the "warn" level instead of "alert" and not more often than once per second. *) Bugfix: nginx/Windows could not be built with OpenSSL 3.0.x. *) Bugfix: in logging of the PROXY protocol errors. Thanks to Sergey Brester. *) Workaround: shared memory from the "ssl_session_cache" directive was spent on sessions using TLS session tickets when using TLSv1.3 with OpenSSL. *) Workaround: timeout specified with the "ssl_session_timeout" directive did not work when using TLSv1.3 with OpenSSL or BoringSSL. --- www/nginx-devel/Makefile | 3 +-- www/nginx-devel/distinfo | 6 +++--- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/www/nginx-devel/Makefile b/www/nginx-devel/Makefile index 436c7c2fc69a..2a42f7fa9678 100644 --- a/www/nginx-devel/Makefile +++ b/www/nginx-devel/Makefile @@ -1,6 +1,5 @@ PORTNAME?= nginx -PORTVERSION= 1.23.1 -PORTREVISION= 9 +PORTVERSION= 1.23.2 CATEGORIES= www MASTER_SITES= https://nginx.org/download/ \ LOCAL/osa diff --git a/www/nginx-devel/distinfo b/www/nginx-devel/distinfo index 3570524d69ef..ccff05ca16c3 100644 --- a/www/nginx-devel/distinfo +++ b/www/nginx-devel/distinfo @@ -1,6 +1,6 @@ -TIMESTAMP = 1664902607 -SHA256 (nginx-1.23.1.tar.gz) = 5eee1bd1c23e3b9477a45532f1f36ae6178b43d571a9607e6953cef26d5df1e2 -SIZE (nginx-1.23.1.tar.gz) = 1104352 +TIMESTAMP = 1666186414 +SHA256 (nginx-1.23.2.tar.gz) = a80cc272d3d72aaee70aa8b517b4862a635c0256790434dbfc4d618a999b0b46 +SIZE (nginx-1.23.2.tar.gz) = 1108243 SHA256 (nginx_mogilefs_module-1.0.4.tar.gz) = 7ac230d30907f013dff8d435a118619ea6168aa3714dba62c6962d350c6295ae SIZE (nginx_mogilefs_module-1.0.4.tar.gz) = 11208 SHA256 (nginx_mod_h264_streaming-2.2.7.tar.gz) = 6d974ba630cef59de1f60996c66b401264a345d25988a76037c2856cec756c19