From nobody Thu Dec 07 04:55:43 2023 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Sm25z0979z53bB0; Thu, 7 Dec 2023 04:55:51 +0000 (UTC) (envelope-from philip@freebsd.org) Received: from smtp.freebsd.org (smtp.freebsd.org [IPv6:2610:1c1:1:606c::24b:4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "smtp.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Sm25y6PsMz3SFb; Thu, 7 Dec 2023 04:55:50 +0000 (UTC) (envelope-from philip@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1701924950; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=wtiZCZZWeVo17DWi/wniOYba+r5JBiDRaQuy6CjqoMc=; b=j044v/ZKy/WR3nLbGanJGJu27Asb2mNEYcHHBMtjw31lHy8G9zkiA6HrpBspkxiB4oHwH9 Zrv9j+CpfbV98UACBdz8JnA2kk9CsaVilE2xv/KSDoEgT0xS39yQS900uuVyQDBDXpxkKG P6o8+bYnpET3A9zjQBAWexX9MnIPZcvbejoi/lycyA6eTG1ffVUAApjHxxn/tjGCtmcZWj K0QVdj+LNkaDQ7SCJrRr1d3kjOBcwkHZQAsXxuAhaKM6QfOc8TbTermdYmEuo2Fx1105jk IHBG4M8UB5YrQJMVW4RFspxoF62FhgxzczewZZPhg0IMfK+Np1IsaN6nLkdK5g== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1701924950; a=rsa-sha256; cv=none; b=fVoqS0b+p8/IDgr8FuSHmCk/5BiZ34FTvd9P0+rnC9XH+/3GZh9G7Qo3z7AECZ6U3TLxHG /LnTTshiNSa0hrBK+TZQ/CcgTqQ3ppLDVcbfv8UkR037leYaB7+ou76tNFA3kB433xymUL UsD3XMrsR3CGnu3pksbJao7npeauE5av6jgNQ/TXajIm8fI9o08VDN9X/Jke82gJpvjOVf XtIoQc0FpfpDdLySUiQynS+CV4VQl2vkP2NV0Z7oCBCX//xNvjPS2hhxotsSAa+OraEjk+ h449CVrj2Rpwwvc8o5ZUrxfLaD82x44loxTaNe4h3Ct/+mC1FQksXhe6THTgPg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1701924950; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=wtiZCZZWeVo17DWi/wniOYba+r5JBiDRaQuy6CjqoMc=; b=v6f1sdjVze+4PAW2TBpLBrM8kwnKw01lSo1v8Ys9p1qo/baN01BfdZH/GjLERnqiPlrJzs ZBveWrlDHxDAAtvFAA7/Am2W9tbbDBqCqn6IeyWVI62LHJzo3JLK2twzrL0blv+CbW5ie1 ZNh8Dsjptcmj9/OTIMRUkTM0WRVGrsgbXo7LQPOYt/CxX7CsNhiLKoDH25XiUZxrNQ5khW VLwHI1P5FhSOYjsH5rw+4QuSUf/504XAnuu418DWXkx96TOy+yeBIHHJRzr0uKtASssas6 MveahPFTb40XGPfOfDp9rWEPwg91ui/laNoldM57nhjtWQp/a3M6TvwHiveWLQ== Received: from auth2-smtp.messagingengine.com (auth2-smtp.messagingengine.com [66.111.4.228]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) (Authenticated sender: philip/mail) by smtp.freebsd.org (Postfix) with ESMTPSA id 4Sm25y52NYz1Qh3; Thu, 7 Dec 2023 04:55:50 +0000 (UTC) (envelope-from philip@freebsd.org) Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailauth.nyi.internal (Postfix) with ESMTP id 30DDD27C005B; Wed, 6 Dec 2023 23:55:50 -0500 (EST) Received: from mailfrontend2 ([10.202.2.163]) by compute5.internal (MEProxy); Wed, 06 Dec 2023 23:55:50 -0500 X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvkedrudekuddgjeeiucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpefhvfevufffoffkjghfgggtsehttd hmtdertddtnecuhfhrohhmpefrhhhilhhiphcurfgrvghpshcuoehphhhilhhiphesfhhr vggvsghsugdrohhrgheqnecuggftrfgrthhtvghrnhepgffgfeeigeettdeltdfgvedtff dtgedvheeuieetheetfeeifeevveetvddvkeegnecuvehluhhsthgvrhfuihiivgeptden ucfrrghrrghmpehmrghilhhfrhhomhepphhhihhlihhpodhmvghsmhhtphgruhhthhhpvg hrshhonhgrlhhithihqdduudeiiedviedvgeekqddvfeehudektddtkedqphhhihhlihhp peepfhhrvggvsghsugdrohhrghesthhrohhusghlvgdrihhs X-ME-Proxy: Feedback-ID: ia691475d:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 6 Dec 2023 23:55:48 -0500 (EST) From: Philip Paeps To: Dan Langille Cc: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: Re: git: a580d36be4c7 - main - security/vuxml: add FreeBSD SA released on 2023-12-05 Date: Thu, 07 Dec 2023 12:55:43 +0800 X-Mailer: MailMate (1.14r6005) Message-ID: <1A46BB39-EBBA-4E02-97A4-860DD9608000@freebsd.org> In-Reply-To: <01372e6b-0e2d-4249-9f36-fdb24b380c71@app.fastmail.com> References: <202312052304.3B5N4IOf078862@gitrepo.freebsd.org> <4c967ca4-bfa1-4e30-b330-feb94d6c765b@app.fastmail.com> <38DAC2D1-58B0-43C5-9F1E-97281068AFD5@freebsd.org> <01372e6b-0e2d-4249-9f36-fdb24b380c71@app.fastmail.com> List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-main@freebsd.org X-BeenThere: dev-commits-ports-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; format=flowed On 2023-12-07 09:10:31 (+0800), Dan Langille wrote: > On Wed, Dec 6, 2023, at 7:52 PM, Philip Paeps wrote: >> On 2023-12-07 08:43:21 (+0800), Dan Langille wrote: >>> Why don't we check them and record them separately? >> >> I already record them separately in vuxml. If a vulnerability only >> affects userland, I record >> FreeBSD[...]. >> If the kernel is affected I record >> FreeBSD-kernel[...]. >> >> Hmm ... is that the problem? Should I set the versions to the >> *kernel* >> patch level for FreeBSD-kernel vulnerabilities? > > First, let's test if that fixes it. > > This fixes it for me: > > 13.213.2_4 > > [...] > >> Is something going to get upset if I change the most recent entry to >> 12.2_4? > > That I don't know. > > VUXML entries have AMENDED values don't they? Thanks for testing this out. I've pushed a vuxml entry in 4826396e5d15. Philip -- Philip Paeps Senior Reality Engineer Alternative Enterprises