The NetBSD Project

CVS log for pkgsrc/lang/php74/distinfo

[BACK] Up to [cvs.NetBSD.org] / pkgsrc / lang / php74

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.37.4.2 / (download) - annotate - [select for diffs], Mon Nov 7 17:37:05 2022 UTC (10 months, 2 weeks ago) by bsiegert
Branch: pkgsrc-2022Q3
Changes since 1.37.4.1: +4 -4 lines
Diff to previous 1.37.4.1 (colored) to branchpoint 1.37 (colored) next main 1.38 (colored)

Pullup ticket #6701 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.380
- lang/php56/Makefile                                           1.30
- lang/php74/Makefile                                           1.17
- lang/php74/distinfo                                           1.39
- lang/php80/Makefile                                           1.10
- lang/php81/Makefile                                           1.8

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sun Oct 30 10:50:01 UTC 2022

   Modified Files:
   	pkgsrc/lang/php56: Makefile
   	pkgsrc/lang/php74: Makefile
   	pkgsrc/lang/php80: Makefile
   	pkgsrc/lang/php81: Makefile

   Log Message:
   lang/php: post-install clean up

   Do not manually install executable files and manual.
   These are already done by php's Makefile from some time ago.

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Fri Nov  4 00:40:58 UTC 2022

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.33

   7.4.33 (2022-11-03)

   - GD:
     . Fixed bug #81739: OOB read due to insufficient input validation in
       imageloadfont(). (CVE-2022-31630) (cmb)

   - Hash:
     . Fixed bug #81738: buffer overflow in hash_update() on long parameter.
       (CVE-2022-37454) (nicky at mouha dot be)

Revision 1.39 / (download) - annotate - [select for diffs], Fri Nov 4 00:40:58 2022 UTC (10 months, 3 weeks ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2023Q3-base, pkgsrc-2023Q3, pkgsrc-2023Q2-base, pkgsrc-2023Q2, pkgsrc-2023Q1-base, pkgsrc-2023Q1, pkgsrc-2022Q4-base, pkgsrc-2022Q4, HEAD
Changes since 1.38: +4 -4 lines
Diff to previous 1.38 (colored)

lang/php74: update to 7.4.33

7.4.33 (2022-11-03)

- GD:
  . Fixed bug #81739: OOB read due to insufficient input validation in
    imageloadfont(). (CVE-2022-31630) (cmb)

- Hash:
  . Fixed bug #81738: buffer overflow in hash_update() on long parameter.
    (CVE-2022-37454) (nicky at mouha dot be)

Revision 1.37.4.1 / (download) - annotate - [select for diffs], Mon Oct 3 14:17:25 2022 UTC (11 months, 3 weeks ago) by bsiegert
Branch: pkgsrc-2022Q3
Changes since 1.37: +4 -4 lines
Diff to previous 1.37 (colored)

Pullup ticket #6675 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.375
- lang/php74/distinfo                                           1.38

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat Oct  1 00:25:22 UTC 2022

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   29 Sep 2022, PHP 7.4.32

   - Core:
     . Fixed bug #81726: phar wrapper: DOS when using quine gzip file.
       (CVE-2022-31628). (cmb)
     . Fixed bug #81727: Don't mangle HTTP variable names that clash with ones
       that have a specific semantic meaning. (CVE-2022-31629). (Derick)

Revision 1.38 / (download) - annotate - [select for diffs], Sat Oct 1 00:25:22 2022 UTC (11 months, 3 weeks ago) by taca
Branch: MAIN
Changes since 1.37: +4 -4 lines
Diff to previous 1.37 (colored)

29 Sep 2022, PHP 7.4.32

- Core:
  . Fixed bug #81726: phar wrapper: DOS when using quine gzip file.
    (CVE-2022-31628). (cmb)
  . Fixed bug #81727: Don't mangle HTTP variable names that clash with ones
    that have a specific semantic meaning. (CVE-2022-31629). (Derick)

Revision 1.37 / (download) - annotate - [select for diffs], Thu Jun 9 15:00:38 2022 UTC (15 months, 2 weeks ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2022Q3-base, pkgsrc-2022Q2-base, pkgsrc-2022Q2
Branch point for: pkgsrc-2022Q3
Changes since 1.36: +4 -4 lines
Diff to previous 1.36 (colored)

lang/php74: update to 7.4.30

09 Jun 2022, PHP 7.4.30

- mysqlnd:
  . Fixed bug #81719: mysqlnd/pdo password buffer overflow. (CVE-2022-31626)
    (c dot fol at ambionics dot io)

- pgsql
  . Fixed bug #81720: Uninitialized array in pg_query_params().
    (CVE-2022-31625) (cmb)

Revision 1.36 / (download) - annotate - [select for diffs], Sat Apr 16 00:52:28 2022 UTC (17 months, 1 week ago) by taca
Branch: MAIN
Changes since 1.35: +4 -4 lines
Diff to previous 1.35 (colored)

lang/php74: update to 7.4.29

14 Apr 2022, PHP 7.4.29

- Core:
  . No source changes to this release.
    Version number added for reproduction of Windows builds.

- Date:
  . Updated to latest IANA timezone database (2022a). (Derick)

Revision 1.34.2.1 / (download) - annotate - [select for diffs], Thu Mar 3 19:29:07 2022 UTC (18 months, 3 weeks ago) by bsiegert
Branch: pkgsrc-2021Q4
Changes since 1.34: +4 -4 lines
Diff to previous 1.34 (colored) next main 1.35 (colored)

Pullup ticket #6593 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.356
- lang/php74/distinfo                                           1.35

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sun Feb 20 13:03:01 UTC 2022

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.28

   17 Feb 2022, PHP 7.4.28

   - Filter:
     . Fix #81708: UAF due to php_filter_float() failing for ints

Revision 1.35 / (download) - annotate - [select for diffs], Sun Feb 20 13:03:01 2022 UTC (19 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2022Q1-base, pkgsrc-2022Q1
Changes since 1.34: +4 -4 lines
Diff to previous 1.34 (colored)

lang/php74: update to 7.4.28

17 Feb 2022, PHP 7.4.28

- Filter:
  . Fix #81708: UAF due to php_filter_float() failing for ints

Revision 1.34 / (download) - annotate - [select for diffs], Sun Dec 19 05:01:06 2021 UTC (21 months, 1 week ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2021Q4-base
Branch point for: pkgsrc-2021Q4
Changes since 1.33: +4 -4 lines
Diff to previous 1.33 (colored)

lang/php74: update to 7.4.27

16 Dec 2021, PHP 7.4.27

- Core:
  . Fixed bug #81626 (Error on use static:: in __callStatic() wrapped to
    Closure::fromCallable()). (Nikita)

- FPM:
  . Fixed bug #81513 (Future possibility for heap overflow in FPM zlog).
    (Jakub Zelenka)

- GD:
  . Fixed bug #71316 (libpng warning from imagecreatefromstring). (cmb)

- OpenSSL:
  . Fixed bug #75725 (./configure: detecting RAND_egd). (Dilyan Palauzov)

- PCRE:
  . Fixed bug #74604 (Out of bounds in php_pcre_replace_impl). (cmb, Dmitry)

- Standard:
  . Fixed bug #81618 (dns_get_record fails on FreeBSD for missing type).
    (fsbruva)
  . Fixed bug #81659 (stream_get_contents() may unnecessarily overallocate).
    (cmb)

Revision 1.28.2.2 / (download) - annotate - [select for diffs], Tue Nov 23 22:47:04 2021 UTC (22 months ago) by tm
Branch: pkgsrc-2021Q3
Changes since 1.28.2.1: +6 -6 lines
Diff to previous 1.28.2.1 (colored) to branchpoint 1.28 (colored) next main 1.29 (colored)

Pullup ticket #6541 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.345
- lang/php74/distinfo                                           1.33
- lang/php74/patches/patch-ext_intl_breakiterator_codepointiterator__internal.cpp 1.3

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Fri Nov 19 14:26:29 UTC 2021

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo
   	pkgsrc/lang/php74/patches:
   	    patch-ext_intl_breakiterator_codepointiterator__internal.cpp

   Log Message:
   lang/php74: udpate to 7.4.26

   This release contains security fix.

   18 Nov 2021, PHP 7.4.26

   - Core:
     . Fixed bug #81518 (Header injection via default_mimetype / default_charset).
       (cmb)

   - Date:
     . Fixed bug #81500 (Interval serialization regression since 7.3.14 / 7.4.2).
       (cmb)

   - MBString:
     . Fixed bug #76167 (mbstring may use pointer from some previous request).
       (cmb, cataphract)

   - MySQLi:
     . Fixed bug #81494 (Stopped unbuffered query does not throw error). (Nikita)

   - PCRE:
     . Fixed bug #81424 (PCRE2 10.35 JIT performance regression). (cmb)

   - Streams:
     . Fixed bug #54340 (Memory corruption with user_filter). (Nikita)

   - XML:
     . Fixed bug #79971 (special character is breaking the path in xml function).
       (CVE-2021-21707) (cmb)

Revision 1.33 / (download) - annotate - [select for diffs], Fri Nov 19 14:26:28 2021 UTC (22 months, 1 week ago) by taca
Branch: MAIN
Changes since 1.32: +5 -5 lines
Diff to previous 1.32 (colored)

lang/php74: udpate to 7.4.26

This release contains security fix.

18 Nov 2021, PHP 7.4.26

- Core:
  . Fixed bug #81518 (Header injection via default_mimetype / default_charset).
    (cmb)

- Date:
  . Fixed bug #81500 (Interval serialization regression since 7.3.14 / 7.4.2).
    (cmb)

- MBString:
  . Fixed bug #76167 (mbstring may use pointer from some previous request).
    (cmb, cataphract)

- MySQLi:
  . Fixed bug #81494 (Stopped unbuffered query does not throw error). (Nikita)

- PCRE:
  . Fixed bug #81424 (PCRE2 10.35 JIT performance regression). (cmb)

- Streams:
  . Fixed bug #54340 (Memory corruption with user_filter). (Nikita)

- XML:
  . Fixed bug #79971 (special character is breaking the path in xml function).
    (CVE-2021-21707) (cmb)

Revision 1.28.2.1 / (download) - annotate - [select for diffs], Tue Nov 2 18:20:51 2021 UTC (22 months, 3 weeks ago) by tm
Branch: pkgsrc-2021Q3
Changes since 1.28: +5 -5 lines
Diff to previous 1.28 (colored)

Pullup ticket #6527 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.343
- lang/php74/distinfo                                           1.31

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Fri Oct 22 15:14:24 UTC 2021

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.25

   This is a security fix release.

   21 Oct 2021, PHP 7.4.25

   - DOM:
     . Fixed bug #81433 (DOMElement::setIdAttribute() called twice may remove ID).
       (Viktor Volkov)

   - FFI:
     . Fixed bug #79576 ("TYPE *" shows unhelpful message when type is not
       defined). (Dmitry)

   - Fileinfo:
     . Fixed bug #78987 (High memory usage during encoding detection). (Anatol)

   - Filter:
     . Fixed bug #61700 (FILTER_FLAG_IPV6/FILTER_FLAG_NO_PRIV|RES_RANGE failing).
       (cmb, Nikita)

   - FPM:
     . Fixed bug #81026 (PHP-FPM oob R/W in root process leading to privilege
       escalation) (CVE-2021-21703). (Jakub Zelenka)

   - SPL:
     . Fixed bug #80663 (Recursive SplFixedArray::setSize() may cause double-free).
       (cmb, Nikita, Tyson Andre)

   - Streams:
     . Fixed bug #81475 (stream_isatty emits warning with attached stream wrapper).
       (cmb)

   - XML:
     . Fixed bug #70962 (XML_OPTION_SKIP_WHITE strips embedded whitespace).
       (Aliaksandr Bystry, cmb)

   - Zip:
     . Fixed bug #81490 (ZipArchive::extractTo() may leak memory). (cmb, Remi)
     . Fixed bug #77978 (Dirname ending in colon unzips to wrong dir). (cmb)

Revision 1.32 / (download) - annotate - [select for diffs], Tue Oct 26 10:51:48 2021 UTC (23 months ago) by nia
Branch: MAIN
Changes since 1.31: +2 -2 lines
Diff to previous 1.31 (colored)

lang: Replace RMD160 checksums with BLAKE2s checksums

All checksums have been double-checked against existing RMD160 and
SHA512 hashes

The following distfiles could not be fetched (possibly fetched
conditionally?):

./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-aarch64-unknown-linux-gnu.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-aarch64-unknown-linux-musl.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-aarch64-unknown-netbsd.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-armv7-unknown-netbsd-eabihf.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-i686-unknown-linux-gnu.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-powerpc-unknown-netbsd90.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-sparc64-unknown-netbsd.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-x86_64-apple-darwin.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-x86_64-unknown-freebsd.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-x86_64-unknown-linux-gnu.tar.gz
./lang/rust-bin/distinfo rust-bin-1.54.0/rust-1.54.0-x86_64-unknown-linux-musl.tar.gz
./lang/smlnj/distinfo smlnj-110.73/boot.ppc-unix.tgz
./lang/smlnj/distinfo smlnj-110.73/boot.sparc-unix.tgz
./lang/oracle-jre8/distinfo jce_policy-8.zip
./lang/oracle-jre8/distinfo jre-8u202-linux-i586.tar.gz
./lang/oracle-jre8/distinfo jre-8u202-linux-x64.tar.gz
./lang/oracle-jre8/distinfo jre-8u202-macosx-x64.tar.gz
./lang/oracle-jre8/distinfo jre-8u202-solaris-x64.tar.gz
./lang/oracle-jdk8/distinfo jdk-8u202-linux-i586.tar.gz
./lang/oracle-jdk8/distinfo jdk-8u202-linux-x64.tar.gz
./lang/oracle-jdk8/distinfo jdk-8u202-solaris-x64.tar.gz
./lang/ghc80/distinfo ghc-7.10.3-boot-x86_64-unknown-solaris2.tar.xz
./lang/ghc80/distinfo ghc-8.0.2-boot-i386-unknown-freebsd.tar.xz
./lang/ghc80/distinfo ghc-8.0.2-boot-x86_64-unknown-freebsd.tar.xz
./lang/gcc5-aux/distinfo ada-bootstrap.i386.freebsd.100B.tar.bz2
./lang/gcc5-aux/distinfo ada-bootstrap.i386.freebsd.84.tar.bz2
./lang/gcc5-aux/distinfo ada-bootstrap.x86_64.dragonfly.41.tar.bz2
./lang/gcc5-aux/distinfo ada-bootstrap.x86_64.freebsd.100B.tar.bz2
./lang/gcc5-aux/distinfo ada-bootstrap.x86_64.freebsd.84.tar.bz2
./lang/gcc5-aux/distinfo ada-bootstrap.x86_64.solaris.511.tar.bz2
./lang/rust/distinfo rust-1.53.0-aarch64-apple-darwin.tar.gz
./lang/rust/distinfo rust-1.53.0-aarch64-unknown-linux-gnu.tar.gz
./lang/rust/distinfo rust-1.53.0-aarch64-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-1.53.0-aarch64_be-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-1.53.0-arm-unknown-linux-gnueabihf.tar.gz
./lang/rust/distinfo rust-1.53.0-armv7-unknown-linux-gnueabihf.tar.gz
./lang/rust/distinfo rust-1.53.0-i686-unknown-linux-gnu.tar.gz
./lang/rust/distinfo rust-1.53.0-powerpc-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-1.53.0-powerpc-unknown-netbsd90.tar.gz
./lang/rust/distinfo rust-1.53.0-sparc64-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-1.53.0-x86_64-apple-darwin.tar.gz
./lang/rust/distinfo rust-1.53.0-x86_64-unknown-freebsd.tar.gz
./lang/rust/distinfo rust-1.53.0-x86_64-unknown-illumos.tar.gz
./lang/rust/distinfo rust-1.53.0-x86_64-unknown-linux-gnu.tar.gz
./lang/rust/distinfo rust-std-1.53.0-aarch64-apple-darwin.tar.gz
./lang/rust/distinfo rust-std-1.53.0-aarch64-unknown-linux-gnu.tar.gz
./lang/rust/distinfo rust-std-1.53.0-aarch64-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-std-1.53.0-aarch64_be-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-std-1.53.0-arm-unknown-linux-gnueabihf.tar.gz
./lang/rust/distinfo rust-std-1.53.0-armv7-unknown-linux-gnueabihf.tar.gz
./lang/rust/distinfo rust-std-1.53.0-i686-unknown-linux-gnu.tar.gz
./lang/rust/distinfo rust-std-1.53.0-powerpc-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-std-1.53.0-powerpc-unknown-netbsd90.tar.gz
./lang/rust/distinfo rust-std-1.53.0-sparc64-unknown-netbsd.tar.gz
./lang/rust/distinfo rust-std-1.53.0-x86_64-apple-darwin.tar.gz
./lang/rust/distinfo rust-std-1.53.0-x86_64-unknown-freebsd.tar.gz
./lang/rust/distinfo rust-std-1.53.0-x86_64-unknown-linux-gnu.tar.gz
./lang/smlnj11072/distinfo smlnj-110.72/boot.ppc-unix.tgz
./lang/smlnj11072/distinfo smlnj-110.72/boot.sparc-unix.tgz
./lang/ghc84/distinfo ghc-8.0.2-boot-x86_64-unknown-solaris2.tar.xz
./lang/ghc84/distinfo ghc-8.4.4-boot-i386-unknown-freebsd.tar.xz
./lang/ghc84/distinfo ghc-8.4.4-boot-x86_64-apple-darwin.tar.xz
./lang/ghc84/distinfo ghc-8.4.4-boot-x86_64-unknown-freebsd.tar.xz
./lang/ghc7/distinfo ghc-7.10.3-boot-i386-unknown-freebsd.tar.xz
./lang/ghc7/distinfo ghc-7.6.3-boot-i386-unknown-solaris2.tar.xz
./lang/ghc7/distinfo ghc-7.6.3-boot-powerpc-apple-darwin.tar.xz
./lang/ghc7/distinfo ghc-7.6.3-boot-x86_64-unknown-solaris2.tar.xz
./lang/ghc90/distinfo ghc-8.10.4-boot-x86_64-unknown-solaris2.tar.xz
./lang/ghc90/distinfo ghc-9.0.1-boot-aarch64-unknown-netbsd.tar.xz
./lang/ghc90/distinfo ghc-9.0.1-boot-i386-unknown-freebsd.tar.xz
./lang/ghc90/distinfo ghc-9.0.1-boot-x86_64-apple-darwin.tar.xz
./lang/ghc90/distinfo ghc-9.0.1-boot-x86_64-unknown-freebsd.tar.xz
./lang/openjdk8/distinfo openjdk7/bootstrap-jdk-1.7.76-freebsd-10-amd64-20150301.tar.xz
./lang/openjdk8/distinfo openjdk7/bootstrap-jdk-1.7.76-netbsd-7-sparc64-20150301.tar.xz
./lang/openjdk8/distinfo openjdk7/bootstrap-jdk-1.8.181-netbsd-8-aarch64-20180917.tar.xz
./lang/openjdk8/distinfo openjdk7/bootstrap-jdk7u60-bin-dragonfly-3.6-amd64-20140719.tar.bz2
./lang/openjdk8/distinfo openjdk7/bootstrap-jdk7u60-bin-dragonfly-3.8-amd64-20140719.tar.bz2
./lang/go-bin/distinfo go1.14.2.darwin-amd64.tar.gz
./lang/go-bin/distinfo go1.14.2.linux-386.tar.gz
./lang/go-bin/distinfo go1.14.2.linux-amd64.tar.gz
./lang/go-bin/distinfo go1.14.2.linux-arm64.tar.gz
./lang/go-bin/distinfo go1.14.2.linux-armv6l.tar.gz
./lang/go-bin/distinfo go1.14.2.netbsd-arm64.tar.gz
./lang/go-bin/distinfo go1.16beta1.darwin-arm64.tar.gz
./lang/gcc6-aux/distinfo ada-bootstrap.i386.freebsd.100B.tar.bz2
./lang/gcc6-aux/distinfo ada-bootstrap.x86_64.dragonfly.41.tar.bz2
./lang/gcc6-aux/distinfo ada-bootstrap.x86_64.freebsd.100B.tar.bz2
./lang/gcc6-aux/distinfo ada-bootstrap.x86_64.freebsd.84.tar.bz2
./lang/gcc6-aux/distinfo ada-bootstrap.x86_64.solaris.511.tar.bz2
./lang/ghc810/distinfo ghc-8.8.4-boot-x86_64-unknown-solaris2.tar.xz
./lang/sun-jre7/distinfo UnlimitedJCEPolicyJDK7.zip
./lang/sun-jre7/distinfo jre-7u80-linux-x64.tar.gz
./lang/sun-jre7/distinfo jre-7u80-solaris-i586.tar.gz
./lang/sun-jre7/distinfo jre-7u80-solaris-x64.tar.gz
./lang/ghc88/distinfo ghc-8.4.4-boot-i386-unknown-freebsd.tar.xz
./lang/ghc88/distinfo ghc-8.4.4-boot-x86_64-apple-darwin.tar.xz
./lang/ghc88/distinfo ghc-8.4.4-boot-x86_64-unknown-freebsd.tar.xz
./lang/ghc88/distinfo ghc-8.4.4-boot-x86_64-unknown-solaris2.tar.xz
./lang/gcc-aux/distinfo ada-bootstrap.i386.dragonfly.36A.tar.bz2
./lang/gcc-aux/distinfo ada-bootstrap.i386.freebsd.100B.tar.bz2
./lang/gcc-aux/distinfo ada-bootstrap.i386.freebsd.84.tar.bz2
./lang/gcc-aux/distinfo ada-bootstrap.x86_64.dragonfly.36A.tar.bz2
./lang/gcc-aux/distinfo ada-bootstrap.x86_64.freebsd.100B.tar.bz2
./lang/gcc-aux/distinfo ada-bootstrap.x86_64.freebsd.84.tar.bz2
./lang/gcc-aux/distinfo ada-bootstrap.x86_64.solaris.511.tar.bz2
./lang/gcc6/distinfo ecj-4.5.jar
./lang/openjdk11/distinfo bootstrap-jdk-1.11.0.7.10-netbsd-9-aarch64-20200509.tar.xz
./lang/sun-jdk7/distinfo jdk-7u80-linux-x64.tar.gz
./lang/sun-jdk7/distinfo jdk-7u80-solaris-i586.tar.gz
./lang/sun-jdk7/distinfo jdk-7u80-solaris-x64.tar.gz

Revision 1.31 / (download) - annotate - [select for diffs], Fri Oct 22 15:14:24 2021 UTC (23 months ago) by taca
Branch: MAIN
Changes since 1.30: +4 -4 lines
Diff to previous 1.30 (colored)

lang/php74: update to 7.4.25

This is a security fix release.

21 Oct 2021, PHP 7.4.25

- DOM:
  . Fixed bug #81433 (DOMElement::setIdAttribute() called twice may remove ID).
    (Viktor Volkov)

- FFI:
  . Fixed bug #79576 ("TYPE *" shows unhelpful message when type is not
    defined). (Dmitry)

- Fileinfo:
  . Fixed bug #78987 (High memory usage during encoding detection). (Anatol)

- Filter:
  . Fixed bug #61700 (FILTER_FLAG_IPV6/FILTER_FLAG_NO_PRIV|RES_RANGE failing).
    (cmb, Nikita)

- FPM:
  . Fixed bug #81026 (PHP-FPM oob R/W in root process leading to privilege
    escalation) (CVE-2021-21703). (Jakub Zelenka)

- SPL:
  . Fixed bug #80663 (Recursive SplFixedArray::setSize() may cause double-free).
    (cmb, Nikita, Tyson Andre)

- Streams:
  . Fixed bug #81475 (stream_isatty emits warning with attached stream wrapper).
    (cmb)

- XML:
  . Fixed bug #70962 (XML_OPTION_SKIP_WHITE strips embedded whitespace).
    (Aliaksandr Bystry, cmb)

- Zip:
  . Fixed bug #81490 (ZipArchive::extractTo() may leak memory). (cmb, Remi)
  . Fixed bug #77978 (Dirname ending in colon unzips to wrong dir). (cmb)

Revision 1.30 / (download) - annotate - [select for diffs], Thu Oct 7 14:21:06 2021 UTC (23 months, 3 weeks ago) by nia
Branch: MAIN
Changes since 1.29: +1 -2 lines
Diff to previous 1.29 (colored)

lang: Remove SHA1 hashes for distfiles

Revision 1.29 / (download) - annotate - [select for diffs], Tue Sep 28 13:50:15 2021 UTC (23 months, 4 weeks ago) by jperkin
Branch: MAIN
Changes since 1.28: +2 -1 lines
Diff to previous 1.28 (colored)

php74: Support OpenSSL 3.

Revision 1.28 / (download) - annotate - [select for diffs], Fri Sep 24 02:27:04 2021 UTC (2 years ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2021Q3-base
Branch point for: pkgsrc-2021Q3
Changes since 1.27: +5 -5 lines
Diff to previous 1.27 (colored)

lang/php74: update to 7.4.24

This is security release fixing CVE-2021-21706.

23 Sep 2021, PHP 7.4.24

- Core:
  . Fixed bug #81302 (Stream position after stream filter removed). (cmb)
  . Fixed bug #81346 (Non-seekable streams don't update position after write).
    (cmb)
  . Fixed bug #73122 (Integer Overflow when concatenating strings). (cmb)

-GD:
  . Fixed bug #53580 (During resize gdImageCopyResampled cause colors change).
    (cmb)

- Opcache:
  . Fixed bug #81353 (segfault with preloading and statically bound closure).
    (Nikita)

- Shmop:
  . Fixed bug #81407 (shmop_open won't attach and causes php to crash). (cmb)

- Standard:
  . Fixed bug #71542 (disk_total_space does not work with relative paths). (cmb)
  . Fixed bug #81400 (Unterminated string in dns_get_record() results). (cmb)

- SysVMsg:
  . Fixed bug #78819 (Heap Overflow in msg_send). (cmb)

- XML:
  . Fixed bug #81351 (xml_parse may fail, but has no error code). (cmb, Nikita)

- Zip:
  . Fixed bug #81420 (ZipArchive::extractTo extracts outside of destination).
    (CVE-2021-21706) (cmb)

Revision 1.27 / (download) - annotate - [select for diffs], Sat Aug 28 06:22:42 2021 UTC (2 years, 1 month ago) by taca
Branch: MAIN
Changes since 1.26: +5 -5 lines
Diff to previous 1.26 (colored)

lang/php74: update to 7.4.23

26 Aug 2021, PHP 7.4.23

- Core:
  . Fixed bug #72595 (php_output_handler_append illegal write access). (cmb)
  . Fixed bug #66719 (Weird behaviour when using get_called_class() with
    call_user_func()). (Nikita)
  . Fixed bug #81305 (Built-in Webserver Drops Requests With "Upgrade" Header).
    (cmb)

- BCMath:
  . Fixed bug #78238 (BCMath returns "-0"). (cmb)

- CGI:
  . Fixed bug #80849 (HTTP Status header truncation). (cmb)

- GD:
  . Fixed bug #51498 (imagefilledellipse does not work for large circles). (cmb)

- MySQLi:
  . Fixed bug #74544 (Integer overflow in mysqli_real_escape_string()). (cmb,
    johannes)

- OpenSSL:
  . Fixed bug #81327 (Error build openssl extension on php 7.4.22). (cmb)

- PDO_ODBC:
  . Fixed bug #81252 (PDO_ODBC doesn't account for SQL_NO_TOTAL). (cmb)

- Phar:
  . Fixed bug #81211: Symlinks are followed when creating PHAR archive.(cmb)

- Shmop:
  . Fixed bug #81283 (shmop can't read beyond 2147483647 bytes). (cmb, Nikita)

- Standard:
  . Fixed bug #72146 (Integer overflow on substr_replace). (cmb)
  . Fixed bug #81265 (getimagesize returns 0 for 256px ICO images).
    (George Dietrich)
  . Fixed bug #74960 (Heap buffer overflow via str_repeat). (cmb, Dmitry)

- Streams:
  . Fixed bug #81294 (Segfault when removing a filter). (cmb)

Revision 1.26 / (download) - annotate - [select for diffs], Mon Aug 2 14:08:01 2021 UTC (2 years, 1 month ago) by taca
Branch: MAIN
Changes since 1.25: +5 -5 lines
Diff to previous 1.25 (colored)

lang/php74: update to 7.4.22

29 Jul 2021, PHP 7.4.22

- Core:
  . Fixed bug #81145 (copy() and stream_copy_to_stream() fail for +4GB files).
    (cmb, Nikita)
  . Fixed bug #81163 (incorrect handling of indirect vars in __sleep).
    (krakjoe)
  . Fixed bug #80728 (PHP built-in web server resets timeout when it can kill
    the process). (Calvin Buckley)
  . Fixed bug #73630 (Built-in Weberver - overwrite $_SERVER['request_uri']).
    (cmb)
  . Fixed bug #80173 (Using return value of zend_assign_to_variable() is not
    safe). (Nikita)
  . Fixed bug #73226 (--r[fcez] always return zero exit code). (cmb)

- Intl:
  . Fixed bug #72809 (Locale::lookup() wrong result with canonicalize option).
    (cmb)
  . Fixed bug #68471 (IntlDateFormatter fails for "GMT+00:00" timezone). (cmb)
  . Fixed bug #74264 (grapheme_strrpos() broken for negative offsets). (cmb)

- OpenSSL:
  . Fixed bug #52093 (openssl_csr_sign truncates $serial). (cmb)

- PCRE:
  . Fixed bug #81101 (PCRE2 10.37 shows unexpected result). (Anatol)
  . Fixed bug #81243 (Too much memory is allocated for preg_replace()). (cmb)

- Standard:
  . Fixed bug #81223 (flock() only locks first byte of file). (cmb)

Revision 1.24.2.1 / (download) - annotate - [select for diffs], Sun Jul 4 19:16:05 2021 UTC (2 years, 2 months ago) by bsiegert
Branch: pkgsrc-2021Q2
Changes since 1.24: +5 -5 lines
Diff to previous 1.24 (colored) next main 1.25 (colored)

Pullup ticket #6478 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.331
- lang/php74/distinfo                                           1.25

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Fri Jul  2 17:28:28 UTC 2021

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.21

   01 Jul 2021, PHP 7.4.21

   - Core:
     . Fixed bug #81068 (Double free in realpath_cache_clean()). (Dimitry Andric)
     . Fixed bug #76359 (open_basedir bypass through adding ".."). (cmb)
     . Fixed bug #81090 (Typed property performance degradation with .= operator).
       (Nikita)
     . Fixed bug #81070 (Integer underflow in memory limit comparison).
       (Peter van Dommelen)
     . Fixed bug #81122 (SSRF bypass in FILTER_VALIDATE_URL).
       (CVE-2021-21705) (cmb)

   - Bzip2:
     . Fixed bug #81092 (fflush before stream_filter_remove corrupts stream).
       (cmb)

   - OpenSSL:
     . Fixed bug #76694 (native Windows cert verification uses CN as sever name).
       (cmb)

   - PDO_Firebird:
     . Fixed bug #76448 (Stack buffer overflow in firebird_info_cb).
       (CVE-2021-21704) (cmb)
     . Fixed bug #76449 (SIGSEGV in firebird_handle_doer).
       (CVE-2021-21704) (cmb)
     . Fixed bug #76450 (SIGSEGV in firebird_stmt_execute).
       (CVE-2021-21704) (cmb)
     . Fixed bug #76452 (Crash while parsing blob data in firebird_fetch_blob).
       (CVE-2021-21704) (cmb)

   - Standard:
     . Fixed bug #81048 (phpinfo(INFO_VARIABLES) "Array to string conversion").
       (cmb)

Revision 1.25 / (download) - annotate - [select for diffs], Fri Jul 2 17:28:28 2021 UTC (2 years, 2 months ago) by taca
Branch: MAIN
Changes since 1.24: +5 -5 lines
Diff to previous 1.24 (colored)

lang/php74: update to 7.4.21

01 Jul 2021, PHP 7.4.21

- Core:
  . Fixed bug #81068 (Double free in realpath_cache_clean()). (Dimitry Andric)
  . Fixed bug #76359 (open_basedir bypass through adding ".."). (cmb)
  . Fixed bug #81090 (Typed property performance degradation with .= operator).
    (Nikita)
  . Fixed bug #81070 (Integer underflow in memory limit comparison).
    (Peter van Dommelen)
  . Fixed bug #81122 (SSRF bypass in FILTER_VALIDATE_URL).
    (CVE-2021-21705) (cmb)

- Bzip2:
  . Fixed bug #81092 (fflush before stream_filter_remove corrupts stream).
    (cmb)

- OpenSSL:
  . Fixed bug #76694 (native Windows cert verification uses CN as sever name).
    (cmb)

- PDO_Firebird:
  . Fixed bug #76448 (Stack buffer overflow in firebird_info_cb).
    (CVE-2021-21704) (cmb)
  . Fixed bug #76449 (SIGSEGV in firebird_handle_doer).
    (CVE-2021-21704) (cmb)
  . Fixed bug #76450 (SIGSEGV in firebird_stmt_execute).
    (CVE-2021-21704) (cmb)
  . Fixed bug #76452 (Crash while parsing blob data in firebird_fetch_blob).
    (CVE-2021-21704) (cmb)

- Standard:
  . Fixed bug #81048 (phpinfo(INFO_VARIABLES) "Array to string conversion").
    (cmb)

Revision 1.24 / (download) - annotate - [select for diffs], Thu Jun 3 15:28:49 2021 UTC (2 years, 3 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2021Q2-base
Branch point for: pkgsrc-2021Q2
Changes since 1.23: +6 -6 lines
Diff to previous 1.23 (colored)

lang/php74: update to 7.4.20

03 Jun 2021, PHP 7.4.20

- Core:
  . Fixed bug #80929 (Method name corruption related to repeated calls to
    call_user_func_array). (twosee)
  . Fixed bug #80960 (opendir() warning wrong info when failed on Windows).
    (cmb)
  . Fixed bug #67792 (HTTP Authorization schemes are treated as case-sensitive).
    (cmb)
  . Fixed bug #80972 (Memory exhaustion on invalid string offset). (girgias)

- FPM:
  . Fixed bug #65800 (Events port mechanism). (psumbera)

- FTP:
  . Fixed bug #80901 (Info leak in ftp extension). (cmb)
  . Fixed bug #79100 (Wrong FTP error messages). (cmb)

- GD:
  . Fixed bug #81032 (GD install is affected by external libgd installation).
    (Flavio Heleno, cmb)

- MBString:
  . Fixed bug #81011 (mb_convert_encoding removes references from arrays). (cmb)

- ODBC:
  . Fixed bug #80460 (ODBC doesn't account for SQL_NO_TOTAL indicator). (cmb)

- PDO_MySQL:
  . Fixed bug #81037 (PDO discards error message text from prepared
    statement). (Kamil Tekiela)

- PDO_ODBC:
  . Fixed bug #44643 (bound parameters ignore explicit type definitions). (cmb)

- pgsql:
  . Fixed php_pgsql_fd_cast() wrt. php_stream_can_cast(). (cmb)

- SPL:
  . Fixed bug #80933 (SplFileObject::DROP_NEW_LINE is broken for NUL and CR).
    (cmb, Nikita)

- Opcache:
  . Fixed bug #80900 (switch statement behavior inside function). (twosee)
  . Fixed bug #81015 (Opcache optimization assumes wrong part of ternary
    operator in if-condition). (Nikita)

- XMLReader:
  . Fixed bug #73246 (XMLReader: encoding length not checked). (cmb)

- Zip:
  . Fixed bug #80863 (ZipArchive::extractTo() ignores references). (cmb)

Revision 1.23 / (download) - annotate - [select for diffs], Thu May 6 13:52:29 2021 UTC (2 years, 4 months ago) by taca
Branch: MAIN
Changes since 1.22: +5 -5 lines
Diff to previous 1.22 (colored)

lang/php74: update to 7.4.19

06 May 2021, PHP 7.4.19

- PDO_pgsql:
  . Reverted bug fix for #80892 (PDO::PARAM_INT is treated the same as
    PDO::PARAM_STR). (Matteo)

Revision 1.22 / (download) - annotate - [select for diffs], Fri Apr 30 14:56:26 2021 UTC (2 years, 4 months ago) by taca
Branch: MAIN
Changes since 1.21: +5 -5 lines
Diff to previous 1.21 (colored)

lang/php74: update to 7.4.18

29 Apr 2021, PHP 7.4.18

- Core:
  . Fixed bug #80781 (Error handler that throws ErrorException infinite loop).
    (Nikita)
  . Fixed bug #75776 (Flushing streams with compression filter is broken). (cmb)

- Dba:
  . Fixed bug #80817 (dba_popen() may cause segfault during RSHUTDOWN). (cmb)

- DOM:
  . Fixed bug #66783 (UAF when appending DOMDocument to element). (cmb)

- FPM:
  . Fixed bug #80024 (Duplication of info about inherited socket after pool
    removing). (Jakub Zelenka)

- FTP:
  . Fixed bug #80880 (SSL_read on shutdown, ftp/proc_open). (cmb, Jakub
    Zelenka)

- Imap:
  . Fixed bug #80710 (imap_mail_compose() header injection). (cmb, Stas)

- Intl:
  . Fixed bug #80763 (msgfmt_format() does not accept DateTime references).
    (cmb)

- LibXML:
  . Fixed bug #51903 (simplexml_load_file() doesn't use HTTP headers). (cmb)
  . Fixed bug #73533 (Invalid memory access in php_libxml_xmlCheckUTF8). (cmb)

- MySQLnd:
  . Fixed bug #80713 (SegFault when disabling ATTR_EMULATE_PREPARES and
    MySQL 8.0). (Nikita)
  . Fixed bug #80837 (Calling stmt_store_result after fetch doesn't throw an
    error). (Kamil Tekiela)

- Opcache:
  . Fixed bug #80805 (create simple class and get error in opcache.so). (Nikita)
  . Fixed bug #80950 (Variables become null in if statements). (Nikita)

- Pcntl:
  . Fixed bug #79812 (Potential integer overflow in pcntl_exec()). (cmb)

- PCRE:
  . Fixed bug #80866 (preg_split ignores limit flag when pattern with \K has
    0-width fullstring match). (Kamil Tekiela)

- PDO_ODBC:
  . Fixed bug #80783 (PDO ODBC truncates BLOB records at every 256th byte).
    (cmb)

- PDO_pgsql:
  . Fixed bug #80892 (PDO::PARAM_INT is treated the same as PDO::PARAM_STR).
    (Matteo)

- phpdbg:
  . Fixed bug #80757 (Exit code is 0 when could not open file). (Felipe)

- Session:
  . Fixed bug #80774 (session_name() problem with backslash). (cmb)
  . Fixed bug #80889 (Cannot set save handler when save_handler is invalid).
    (cmb)

- SOAP:
  . Fixed bug #69668 (SOAP special XML characters in namespace URIs not
    encoded). (cmb)

- Standard:
  . Fixed bug #78719 (http wrapper silently ignores long Location headers).
    (cmb)
  . Fixed bug #80771 (phpinfo(INFO_CREDITS) displays nothing in CLI). (cmb)
  . Fixed bug #80838 (HTTP wrapper waits for HTTP 1 response after HTTP 101).
    (manuelm)
  . Fixed bug #80915 (Taking a reference to $_SERVER hides its values from
    phpinfo()). (Rowan Tommins)

Revision 1.21 / (download) - annotate - [select for diffs], Sun Mar 7 13:11:06 2021 UTC (2 years, 6 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2021Q1-base, pkgsrc-2021Q1
Changes since 1.20: +2 -1 lines
Diff to previous 1.20 (colored)

lang/php74: reduce warnings

Reduce warnings on build time.

Revision 1.20 / (download) - annotate - [select for diffs], Sat Mar 6 13:29:02 2021 UTC (2 years, 6 months ago) by taca
Branch: MAIN
Changes since 1.19: +5 -5 lines
Diff to previous 1.19 (colored)

lang/php74: update to 7.4.16

04 Mar 2021, PHP 7.4.16

- Core:
  . Fixed #80706 (mail(): Headers after Bcc headers may be ignored). (cmb)

- MySQLnd:
  . Fixed bug #78680 (mysqlnd's mysql_clear_password does not transmit
    null-terminated password). (Daniel Black)

- MySQLi:
  . Fixed bug #74779 (x() and y() truncating floats to integers). (cmb)

- OPcache:
  . Fixed bug #80682 (opcache doesn't honour pcre.jit option). (Remi)

- OpenSSL:
  . Fixed bug #80747 (Providing RSA key size < 512 generates key that crash
    PHP). (Nikita)

- Phar:
  . Fixed bug #75850 (Unclear error message wrt. __halt_compiler() w/o
    semicolon) (cmb)
  . Fixed bug #70091 (Phar does not mark UTF-8 filenames in ZIP archives). (cmb)
  . Fixed bug #53467 (Phar cannot compress large archives). (cmb, lserni)

- SPL:
  . Fixed bug#80719 (Iterating after failed ArrayObject::setIteratorClass()
    causes Segmentation fault). (Nikita)

- Standard:
  . Fixed bug #80654 (file_get_contents() maxlen fails above (2**31)-1 bytes).
    (cmb)

- Zip:
  . Fixed bug #80648 (Fix for bug 79296 should be based on runtime version).
    (cmb, Remi)

Revision 1.17.2.2 / (download) - annotate - [select for diffs], Tue Feb 16 08:36:26 2021 UTC (2 years, 7 months ago) by bsiegert
Branch: pkgsrc-2020Q4
Changes since 1.17.2.1: +5 -5 lines
Diff to previous 1.17.2.1 (colored) to branchpoint 1.17 (colored) next main 1.18 (colored)

Pullup ticket #6426 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.319
- lang/php74/distinfo                                           1.19

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Fri Feb  5 14:45:20 UTC 2021

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.15

   04 Feb 2021, PHP 7.4.15

   - Core:
     . Fixed bug #80523 (bogus parse error on >4GB source code). (Nikita)
     . Fixed bug #80384 (filter buffers entire read until file closed). (Adam
       Seitz, cmb)

   - Curl:
     . Fixed bug #80595 (Resetting POSTFIELDS to empty array breaks request). (cmb)

   - Date:
     . Fixed bug #80376 (last day of the month causes runway cpu usage. (Derick)

   - MySQLi:
     . Fixed bug #67983 (mysqlnd with MYSQLI_OPT_INT_AND_FLOAT_NATIVE fails to
       interpret bit columns). (Nikita)
     . Fixed bug #64638 (Fetching resultsets from stored procedure with cursor
       fails). (Nikita)
     . Fixed bug #72862 (segfault using prepared statements on stored procedures
       that use a cursor). (Nikita)
     . Fixed bug #77935 (Crash in mysqlnd_fetch_stmt_row_cursor when calling an SP
       with a cursor). (Nikita)

   - Phar:
     . Fixed bug #77565 (Incorrect locator detection in ZIP-based phars). (cmb)
     . Fixed bug #69279 (Compressed ZIP Phar extractTo() creates garbage files).
       (cmb)

   - SOAP:
     . Fixed bug #80672 (Null Dereference in SoapClient). (CVE-2021-21702) (cmb,
       Stas)

Revision 1.19 / (download) - annotate - [select for diffs], Fri Feb 5 14:45:20 2021 UTC (2 years, 7 months ago) by taca
Branch: MAIN
Changes since 1.18: +5 -5 lines
Diff to previous 1.18 (colored)

lang/php74: update to 7.4.15

04 Feb 2021, PHP 7.4.15

- Core:
  . Fixed bug #80523 (bogus parse error on >4GB source code). (Nikita)
  . Fixed bug #80384 (filter buffers entire read until file closed). (Adam
    Seitz, cmb)

- Curl:
  . Fixed bug #80595 (Resetting POSTFIELDS to empty array breaks request). (cmb)

- Date:
  . Fixed bug #80376 (last day of the month causes runway cpu usage. (Derick)

- MySQLi:
  . Fixed bug #67983 (mysqlnd with MYSQLI_OPT_INT_AND_FLOAT_NATIVE fails to
    interpret bit columns). (Nikita)
  . Fixed bug #64638 (Fetching resultsets from stored procedure with cursor
    fails). (Nikita)
  . Fixed bug #72862 (segfault using prepared statements on stored procedures
    that use a cursor). (Nikita)
  . Fixed bug #77935 (Crash in mysqlnd_fetch_stmt_row_cursor when calling an SP
    with a cursor). (Nikita)

- Phar:
  . Fixed bug #77565 (Incorrect locator detection in ZIP-based phars). (cmb)
  . Fixed bug #69279 (Compressed ZIP Phar extractTo() creates garbage files).
    (cmb)

- SOAP:
  . Fixed bug #80672 (Null Dereference in SoapClient). (CVE-2021-21702) (cmb,
    Stas)

Revision 1.17.2.1 / (download) - annotate - [select for diffs], Sat Jan 16 19:48:15 2021 UTC (2 years, 8 months ago) by bsiegert
Branch: pkgsrc-2020Q4
Changes since 1.17: +5 -5 lines
Diff to previous 1.17 (colored)

Pullup ticket #6399 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.318
- lang/php74/distinfo                                           1.18

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Thu Jan  7 13:39:09 UTC 2021

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: udpate to 7.4.14

   Update php74 pacakge to 7.4.14 (PHP 7.4.14).

   07 Jan 2021, PHP 7.4.14

   - Core:
     . Fixed bug #74558 (Can't rebind closure returned by Closure::fromCallable()).
       (cmb)
     . Fixed bug #80345 (PHPIZE configuration has outdated PHP_RELEASE_VERSION).
       (cmb)
     . Fixed bug #72964 (White space not unfolded for CC/Bcc headers). (cmb)
     . Fixed bug #80362 (Running dtrace scripts can cause php to crash).
       (al at coralnet dot name)
     . Fixed bug #80393 (Build of PHP extension fails due to configuration gap
       with libtool). (kir dot morozov at gmail dot com)
     . Fixed bug #80402 (configure filtering out -lpthread). (Nikita)
     . Fixed bug #77069 (stream filter loses final block of data). (cmb)

   - Fileinfo:
     . Fixed bug #77961 (finfo_open crafted magic parsing SIGABRT). (cmb)

   - FPM:
     . Fixed bug #69625 (FPM returns 200 status on request without
       SCRIPT_FILENAME env). (Jakub Zelenka)

   - Intl:
     . Fixed bug #80425 (MessageFormatAdapter::getArgTypeList redefined). (Nikita)

   - OpenSSL:
     . Fixed bug #80368 (OpenSSL extension fails to build against LibreSSL due to
       lack of OCB support). (Nikita)

   - Phar:
     . Fixed bug #73809 (Phar Zip parse crash - mmap fail). (cmb)
     . Fixed bug #75102 (`PharData` says invalid checksum for valid tar). (cmb)
     . Fixed bug #77322 (PharData::addEmptyDir('/') Possible integer overflow).
       (cmb)

   - PDO MySQL:
     . Fixed bug #80458 (PDOStatement::fetchAll() throws for upsert queries).
       (Kamil Tekiela)
     . Fixed bug #63185 (nextRowset() ignores MySQL errors with native prepared
       statements). (Nikita)
     . Fixed bug #78152 (PDO::exec() - Bad error handling with multiple commands).
       (Nikita)
     . Fixed bug #70066 (Unexpected "Cannot execute queries while other unbuffered
       queries"). (Nikita)
     . Fixed bug #71145 (Multiple statements in init command triggers unbuffered
       query error). (Nikita)
     . Fixed bug #76815 (PDOStatement cannot be GCed/closeCursor-ed when a
       PROCEDURE resultset SIGNAL). (Nikita)

   - Standard:
     . Fixed bug #77423 (FILTER_VALIDATE_URL accepts URLs with invalid userinfo).
       (CVE-2020-7071) (cmb)
     . Fixed bug #80366 (Return Value of zend_fstat() not Checked). (sagpant, cmb)
     . Fixed bug #80411 (References to null-serialized object break serialize()).
       (Nikita)

   - Tidy:
     . Fixed bug #77594 (ob_tidyhandler is never reset). (cmb)

   - Zlib:
     . Fixed #48725 (Support for flushing in zlib stream). (cmb)

Revision 1.18 / (download) - annotate - [select for diffs], Thu Jan 7 13:39:09 2021 UTC (2 years, 8 months ago) by taca
Branch: MAIN
Changes since 1.17: +5 -5 lines
Diff to previous 1.17 (colored)

lang/php74: udpate to 7.4.14

Update php74 pacakge to 7.4.14 (PHP 7.4.14).


07 Jan 2021, PHP 7.4.14

- Core:
  . Fixed bug #74558 (Can't rebind closure returned by Closure::fromCallable()).
    (cmb)
  . Fixed bug #80345 (PHPIZE configuration has outdated PHP_RELEASE_VERSION).
    (cmb)
  . Fixed bug #72964 (White space not unfolded for CC/Bcc headers). (cmb)
  . Fixed bug #80362 (Running dtrace scripts can cause php to crash).
    (al at coralnet dot name)
  . Fixed bug #80393 (Build of PHP extension fails due to configuration gap
    with libtool). (kir dot morozov at gmail dot com)
  . Fixed bug #80402 (configure filtering out -lpthread). (Nikita)
  . Fixed bug #77069 (stream filter loses final block of data). (cmb)

- Fileinfo:
  . Fixed bug #77961 (finfo_open crafted magic parsing SIGABRT). (cmb)

- FPM:
  . Fixed bug #69625 (FPM returns 200 status on request without
    SCRIPT_FILENAME env). (Jakub Zelenka)

- Intl:
  . Fixed bug #80425 (MessageFormatAdapter::getArgTypeList redefined). (Nikita)

- OpenSSL:
  . Fixed bug #80368 (OpenSSL extension fails to build against LibreSSL due to
    lack of OCB support). (Nikita)

- Phar:
  . Fixed bug #73809 (Phar Zip parse crash - mmap fail). (cmb)
  . Fixed bug #75102 (`PharData` says invalid checksum for valid tar). (cmb)
  . Fixed bug #77322 (PharData::addEmptyDir('/') Possible integer overflow).
    (cmb)

- PDO MySQL:
  . Fixed bug #80458 (PDOStatement::fetchAll() throws for upsert queries).
    (Kamil Tekiela)
  . Fixed bug #63185 (nextRowset() ignores MySQL errors with native prepared
    statements). (Nikita)
  . Fixed bug #78152 (PDO::exec() - Bad error handling with multiple commands).
    (Nikita)
  . Fixed bug #70066 (Unexpected "Cannot execute queries while other unbuffered
    queries"). (Nikita)
  . Fixed bug #71145 (Multiple statements in init command triggers unbuffered
    query error). (Nikita)
  . Fixed bug #76815 (PDOStatement cannot be GCed/closeCursor-ed when a
    PROCEDURE resultset SIGNAL). (Nikita)

- Standard:
  . Fixed bug #77423 (FILTER_VALIDATE_URL accepts URLs with invalid userinfo).
    (CVE-2020-7071) (cmb)
  . Fixed bug #80366 (Return Value of zend_fstat() not Checked). (sagpant, cmb)
  . Fixed bug #80411 (References to null-serialized object break serialize()).
    (Nikita)

- Tidy:
  . Fixed bug #77594 (ob_tidyhandler is never reset). (cmb)

- Zlib:
  . Fixed #48725 (Support for flushing in zlib stream). (cmb)

Revision 1.17 / (download) - annotate - [select for diffs], Thu Nov 26 14:45:15 2020 UTC (2 years, 10 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2020Q4-base
Branch point for: pkgsrc-2020Q4
Changes since 1.16: +5 -5 lines
Diff to previous 1.16 (colored)

lang/php74: update to 7.4.13

26 Nov 2020, PHP 7.4.13

- Core:
  . Fixed bug #80280 (ADD_EXTENSION_DEP() fails for ext/standard and ext/date).
    (cmb)
  . Fixed bug #80258 (Windows Deduplication Enabled, randon permission errors).
    (cmb)

- COM:
  . Fixed bug #62474 (com_event_sink crashes on certain arguments). (cmb)

- DOM:
  . Fixed bug #80268 (loadHTML() truncates at NUL bytes). (cmb)

- FFI:
  . Fixed bug #79177 (FFI doesn't handle well PHP exceptions within callback).
    (cmb, Dmitry, Nikita)

- IMAP:
  . Fixed bug #64076 (imap_sort() does not return FALSE on failure). (cmb)
  . Fixed bug #76618 (segfault on imap_reopen). (girgias)
  . Fixed bug #80239 (imap_rfc822_write_address() leaks memory). (cmb)
  . Fixed minor regression caused by fixing bug #80220. (cmb)
  . Fixed bug #80242 (imap_mail_compose() segfaults for multipart with rfc822).
    (cmb)

- MySQLi:
  . Fixed bug #79375 (mysqli_store_result does not report error from lock wait
    timeout). (Kamil Tekiela, Nikita)
  . Fixed bug #76525 (mysqli::commit does not throw if MYSQLI_REPORT_ERROR
    enabled and mysqlnd used). (Kamil Tekiela)
  . Fixed bug #72413 (mysqlnd segfault (fetch_row second parameter
    typemismatch)). (Kamil Tekiela)

- ODBC:
  . Fixed bug #44618 (Fetching may rely on uninitialized data). (cmb)

- Opcache:
  . Fixed bug #79643 (PHP with Opcache crashes when a file with specific name
    is included). (twosee)
  . Fixed run-time binding of preloaded dynamically declared function. (Dmitry)

- OpenSSL:
  . Fixed bug #79983 (openssl_encrypt / openssl_decrypt fail with OCB mode).
    (Nikita)

- PDO MySQL:
  . Fixed bug #66528 (No PDOException or errorCode if database becomes
    unavailable before PDO::commit). (Nikita)
  . Fixed bug #65825 (PDOStatement::fetch() does not throw exception on broken
    server connection). (Nikita)

- SNMP:
  . Fixed bug #70461 (disable md5 code when it is not supported in net-snmp).
    (Alexander Bergmann, cmb)

- Standard:
  . Fixed bug #80266 (parse_url silently drops port number 0). (cmb, Nikita)

Revision 1.16 / (download) - annotate - [select for diffs], Sun Nov 8 23:55:43 2020 UTC (2 years, 10 months ago) by otis
Branch: MAIN
Changes since 1.15: +7 -7 lines
Diff to previous 1.15 (colored)

php74: Document patches for ext/intl

Revision 1.15 / (download) - annotate - [select for diffs], Sun Nov 8 23:51:18 2020 UTC (2 years, 10 months ago) by otis
Branch: MAIN
Changes since 1.14: +7 -1 lines
Diff to previous 1.14 (colored)

php74: Fix build with ICU 68

Revision 1.14 / (download) - annotate - [select for diffs], Fri Oct 30 07:14:16 2020 UTC (2 years, 10 months ago) by taca
Branch: MAIN
Changes since 1.13: +5 -5 lines
Diff to previous 1.13 (colored)

lang/php74: update to 7.4.12

PHP                                                                        NEWS
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
29 Oct 2020, PHP 7.4.12

- Core:
  . Fixed bug #80061 (Copying large files may have suboptimal performance).
    (cmb)
  . Fixed bug #79423 (copy command is limited to size of file it can copy).
    (cmb)
  . Fixed bug #80126 (Covariant return types failing compilation). (Nikita)
  . Fixed bug #80186 (Segfault when iterating over FFI object). (Nikita)

- Calendar:
  . Fixed bug #80185 (jdtounix() fails after 2037). (cmb)

- IMAP:
  . Fixed bug #80213 (imap_mail_compose() segfaults on certain $bodies). (cmb)
  . Fixed bug #80215 (imap_mail_compose() may modify by-val parameters). (cmb)
  . Fixed bug #80220 (imap_mail_compose() may leak memory). (cmb)
  . Fixed bug #80223 (imap_mail_compose() leaks envelope on malformed bodies).
    (cmb)
  . Fixed bug #80216 (imap_mail_compose() does not validate types/encodings).
    (cmb)
  . Fixed bug #80226 (imap_sort() leaks sortpgm memory). (cmb)

- MySQLnd:
  . Fixed bug #80115 (mysqlnd.debug doesn't recognize absolute paths with
    slashes). (cmb)
  . Fixed bug #80107 (mysqli_query() fails for ~16 MB long query when
    compression is enabled). (Nikita)

- ODBC:
  . Fixed bug #78470 (odbc_specialcolumns() no longer accepts $nullable). (cmb)
  . Fixed bug #80147 (BINARY strings may not be properly zero-terminated).
    (cmb)
  . Fixed bug #80150 (Failure to fetch error message). (cmb)
  . Fixed bug #80152 (odbc_execute() moves internal pointer of $params). (cmb)
  . Fixed bug #46050 (odbc_next_result corrupts prepared resource). (cmb)

- OPcache:
  . Fixed bug #80083 (Optimizer pass 6 removes variables used for ibm_db2 data
    binding). (Nikita)
  . Fixed bug #80194 (Assertion failure during block assembly of unreachable
    free with leading nop). (Nikita)

- PCRE:
  . Updated to PCRE 10.35. (cmb)
  . Fixed bug #80118 (Erroneous whitespace match with JIT only). (cmb)

- PDO_ODBC:
  . Fixed bug #67465 (NULL Pointer dereference in odbc_handle_preparer). (cmb)

- Standard:
  . Fixed bug #80114 (parse_url does not accept URLs with port 0). (cmb, twosee)
  . Fixed bug #76943 (Inconsistent stream_wrapper_restore() errors). (cmb)
  . Fixed bug #76735 (Incorrect message in fopen on invalid mode). (cmb)

- Tidy:
  . Fixed bug #77040 (tidyNode::isHtml() is completely broken). (cmb)

Revision 1.12.2.1 / (download) - annotate - [select for diffs], Wed Oct 21 19:23:29 2020 UTC (2 years, 11 months ago) by spz
Branch: pkgsrc-2020Q3
Changes since 1.12: +5 -5 lines
Diff to previous 1.12 (colored) next main 1.13 (colored)

Pullup ticket #6334 - requested by taca
lang/php74: security update

Revisions pulled up:
- lang/php/phpversion.mk                                        1.310
- lang/php74/distinfo                                           1.13

-------------------------------------------------------------------
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sun Oct  4 03:12:46 UTC 2020

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.11

   Update php74 to 7.4.11.

   01 Oct 2020, PHP 7.4.11

   - Core:
     . Fixed bug #79699 (PHP parses encoded cookie names so malicious `__Host-`
       cookies can be sent). (CVE-2020-7070) (Stas)
     . Fixed bug #79979 (passing value to by-ref param via CUFA crashes). (cmb,
       Nikita)
     . Fixed bug #80037 (Typed property must not be accessed before initialization
       when __get() declared). (Nikita)
     . Fixed bug #80048 (Bug #69100 has not been fixed for Windows). (cmb)
     . Fixed bug #80049 (Memleak when coercing integers to string via variadic
       argument). (Nikita)

   - Calendar:
     . Fixed bug #80007 (Potential type confusion in unixtojd() parameter parsing).
       (Andy Postnikov)

   - COM:
     . Fixed bug #64130 (COM obj parameters passed by reference are not updated).
       (cmb)

   - OPcache:
     . Fixed bug #80002 (calc free space for new interned string is wrong).
       (t-matsuno)
     . Fixed bug #80046 (FREE for SWITCH_STRING optimized away). (Nikita)
     . Fixed bug #79825 (opcache.file_cache causes SIGSEGV when custom opcode
       handlers changed). (SammyK)

   - OpenSSL:
     . Fixed bug #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12
       bytes IV). (CVE-2020-7069) (Jakub Zelenka)

   - PDO:
     . Fixed bug #80027 (Terrible performance using $query->fetch on queries with
       many bind parameters (Matteo)

   - Standard:
     . Fixed bug #79986 (str_ireplace bug with diacritics characters). (cmb)
     . Fixed bug #80077 (getmxrr test bug). (Rainer Jung)
     . Fixed bug #72941 (Modifying bucket->data by-ref has no effect any longer).
       (cmb)
     . Fixed bug #80067 (Omitting the port in bindto setting errors). (cmb)


   To generate a diff of this commit:
   cvs rdiff -u -r1.309 -r1.310 pkgsrc/lang/php/phpversion.mk
   cvs rdiff -u -r1.12 -r1.13 pkgsrc/lang/php74/distinfo

Revision 1.13 / (download) - annotate - [select for diffs], Sun Oct 4 03:12:46 2020 UTC (2 years, 11 months ago) by taca
Branch: MAIN
Changes since 1.12: +5 -5 lines
Diff to previous 1.12 (colored)

lang/php74: update to 7.4.11

Update php74 to 7.4.11.


01 Oct 2020, PHP 7.4.11

- Core:
  . Fixed bug #79699 (PHP parses encoded cookie names so malicious `__Host-`
    cookies can be sent). (CVE-2020-7070) (Stas)
  . Fixed bug #79979 (passing value to by-ref param via CUFA crashes). (cmb,
    Nikita)
  . Fixed bug #80037 (Typed property must not be accessed before initialization
    when __get() declared). (Nikita)
  . Fixed bug #80048 (Bug #69100 has not been fixed for Windows). (cmb)
  . Fixed bug #80049 (Memleak when coercing integers to string via variadic
    argument). (Nikita)

- Calendar:
  . Fixed bug #80007 (Potential type confusion in unixtojd() parameter parsing).
    (Andy Postnikov)

- COM:
  . Fixed bug #64130 (COM obj parameters passed by reference are not updated).
    (cmb)

- OPcache:
  . Fixed bug #80002 (calc free space for new interned string is wrong).
    (t-matsuno)
  . Fixed bug #80046 (FREE for SWITCH_STRING optimized away). (Nikita)
  . Fixed bug #79825 (opcache.file_cache causes SIGSEGV when custom opcode
    handlers changed). (SammyK)

- OpenSSL:
  . Fixed bug #79601 (Wrong ciphertext/tag in AES-CCM encryption for a 12
    bytes IV). (CVE-2020-7069) (Jakub Zelenka)

- PDO:
  . Fixed bug #80027 (Terrible performance using $query->fetch on queries with
    many bind parameters (Matteo)

- Standard:
  . Fixed bug #79986 (str_ireplace bug with diacritics characters). (cmb)
  . Fixed bug #80077 (getmxrr test bug). (Rainer Jung)
  . Fixed bug #72941 (Modifying bucket->data by-ref has no effect any longer).
    (cmb)
  . Fixed bug #80067 (Omitting the port in bindto setting errors). (cmb)

Revision 1.12 / (download) - annotate - [select for diffs], Fri Sep 4 15:01:05 2020 UTC (3 years ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2020Q3-base
Branch point for: pkgsrc-2020Q3
Changes since 1.11: +5 -5 lines
Diff to previous 1.11 (colored)

lang/php74: udpate to 7.4.10

Update php74 to 7.4.10.


03 Sep 2020, PHP 7.4.10

- Core:
  . Fixed bug #79884 (PHP_CONFIG_FILE_PATH is meaningless). (cmb)
  . Fixed bug #77932 (File extensions are case-sensitive). (cmb)
  . Fixed bug #79806 (realpath() erroneously resolves link to link). (cmb)
  . Fixed bug #79895 (PHP_CHECK_GCC_ARG does not allow flags with equal sign).
    (Santiago M. Mola)
  . Fixed bug #79919 (Stack use-after-scope in define()). (cmb)
  . Fixed bug #79934 (CRLF-only line in heredoc causes parsing error).
    (Pieter van den Ham)
  . Fixed bug #79947 (Memory leak on invalid offset type in compound
    assignment). (Nikita)

- COM:
  . Fixed bug #48585 (com_load_typelib holds reference, fails on second call).
    (cmb)

- Exif:
  . Fixed bug #75785 (Many errors from exif_read_data).
    (Níckolas Daniel da Silva)

- Gettext:
  . Fixed bug #70574 (Tests fail due to relying on Linux fallback behavior for
    gettext()). (Florian Engelhardt)

- LDAP:
  . Fixed memory leaks. (ptomulik)

- OPcache:
  . Fixed bug #73060 (php failed with error after temp folder cleaned up).
    (cmb)
  . Fixed bug #79917 (File cache segfault with a static variable in inherited
    method). (Nikita)

- PDO:
  . Fixed bug #64705 (errorInfo property of PDOException is null when
    PDO::__construct() fails). (Ahmed Abdou)

- Session:
  . Fixed bug #79724 (Return type does not match in ext/session/mod_mm.c).
    (Nikita)

- Standard:
  . Fixed bug #79930 (array_merge_recursive() crashes when called with array
    with single reference). (Nikita)
  . Fixed bug #79944 (getmxrr always returns true on Alpine linux). (Nikita)
  . Fixed bug #79951 (Memory leak in str_replace of empty string). (Nikita)

- XML:
  . Fixed bug #79922 (Crash after multiple calls to xml_parser_free()). (cmb)

Revision 1.9.2.1 / (download) - annotate - [select for diffs], Sun Aug 23 18:42:13 2020 UTC (3 years, 1 month ago) by bsiegert
Branch: pkgsrc-2020Q2
Changes since 1.9: +5 -5 lines
Diff to previous 1.9 (colored) next main 1.10 (colored)

Pullup ticket #6299 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php74/distinfo                                           1.10-1.11

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Sat Jul 11 04:02:14 UTC 2020

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.8

   Update php74 to 7.4.8.

   09 Jul 2020, PHP 7.4.8

   - Core:
     . Fixed bug #79649 (Altering disable_functions from module init corrupts
       memory). (Laruence)
     . Fixed bug #79595 (zend_init_fpu() alters FPU precision). (cmb, Nikita)
     . Fixed bug #79650 (php-win.exe 100% cpu lockup). (cmb)
     . Fixed bug #79668 (get_defined_functions(true) may miss functions). (cmb,
       Nikita)
     . Fixed bug #79657 ("yield from" hangs when invalid value encountered).
       (Nikita)
     . Fixed bug #79683 (Fake reflection scope affects __toString()). (Nikita)
     . Fixed possibly unsupported timercmp() usage. (cmb)

   - Exif:
     . Fixed bug #79687 (Sony picture - PHP Warning - Make, Model, MakerNotes).
       (cmb)

   - Fileinfo:
     . Fixed bug #79681 (mime_content_type/finfo returning incorrect mimetype).
       (cmb)

   - Filter:
     . Fixed bug #73527 (Invalid memory access in php_filter_strip). (cmb)

   - GD:
     . Fixed bug #79676 (imagescale adds black border with IMG_BICUBIC). (cmb)

   - OpenSSL:
     . Fixed bug #62890 (default_socket_timeout=-1 causes connection to timeout).
       (cmb)

   - PDO SQLite:
     . Fixed bug #79664 (PDOStatement::getColumnMeta fails on empty result set).
       (cmb)

   - phpdbg:
     . Fixed bug #73926 (phpdbg will not accept input on restart execution). (cmb)
     . Fixed bug #73927 (phpdbg fails with windows error prompt at "watch array").
       (cmb)
     . Fixed several mostly Windows related phpdbg bugs. (cmb)

   - SPL:
     . Fixed bug #79710 (Reproducible segfault in error_handler during GC
       involved an SplFileObject). (Nikita)

   - Standard:
     . Fixed bug #74267 (segfault with streams and invalid data). (cmb)
     . Fixed bug #79579 (ZTS build of PHP 7.3.17 doesn't handle ERANGE for
       posix_getgrgid and others). (Böszörményi Zoltán)

---
   Module Name:    pkgsrc
   Committed By:   taca
   Date:           Sat Aug  8 13:31:19 UTC 2020

   Modified Files:
           pkgsrc/lang/php: phpversion.mk
           pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.9

   Update php74 to 7.4.9 (PHP 7.4.9).

   06 Aug 2020, PHP 7.4.9

   - Apache:
     . Fixed bug #79030 (Upgrade apache2handler's php_apache_sapi_get_request_time
       to return usec). (Herbert256)

   - COM:
     . Fixed bug #63208 (BSTR to PHP string conversion not binary safe). (cmb)
     . Fixed bug #63527 (DCOM does not work with Username, Password parameter).
       (cmb)

   - Core:
     . Fixed bug #79740 (serialize() and unserialize() methods can not be called
       statically). (Nikita)
     . Fixed bug #79783 (Segfault in php_str_replace_common). (Nikita)
     . Fixed bug #79778 (Assertion failure if dumping closure with unresolved
       static variable). (Nikita)
     . Fixed bug #79779 (Assertion failure when assigning property of string
       offset by reference). (Nikita)
     . Fixed bug #79792 (HT iterators not removed if empty array is destroyed).
       (Nikita)
     . Fixed bug #78598 (Changing array during undef index RW error segfaults).
       (Nikita)
     . Fixed bug #79784 (Use after free if changing array during undef var during
       array write fetch). (Nikita)
     . Fixed bug #79793 (Use after free if string used in undefined index warning
       is changed). (Nikita)
     . Fixed bug #79862 (Public non-static property in child should take priority
       over private static). (Nikita)
     . Fixed bug #79877 (getimagesize function silently truncates after a null
       byte) (cmb)

   - Fileinfo:
     . Fixed bug #79756 (finfo_file crash (FILEINFO_MIME)). (cmb)

   - FTP:
     . Fixed bug #55857 (ftp_size on large files). (cmb)

   - Mbstring:
     . Fixed bug #79787 (mb_strimwidth does not trim string). (XXiang)

   - Phar:
     . Fixed bug #79797 (Use of freed hash key in the phar_parse_zipfile
       function). (CVE-2020-7068) (cmb)

   - Reflection:
     . Fixed bug #79487 (::getStaticProperties() ignores property modifications).
       (cmb, Nikita)
     . Fixed bug #69804 (::getStaticPropertyValue() throws on protected props).
       (cmb, Nikita)
     . Fixed bug #79820 (Use after free when type duplicated into
       ReflectionProperty gets resolved). (Christopher Broadbent)

   - Standard:
     . Fixed bug #70362 (Can't copy() large 'data://' with open_basedir). (cmb)
     . Fixed bug #78008 (dns_check_record() always return true on Alpine).
       (Andy Postnikov)
     . Fixed bug #79839 (array_walk() does not respect property types). (Nikita)

Revision 1.11 / (download) - annotate - [select for diffs], Sat Aug 8 13:31:19 2020 UTC (3 years, 1 month ago) by taca
Branch: MAIN
Changes since 1.10: +5 -5 lines
Diff to previous 1.10 (colored)

lang/php74: update to 7.4.9

Update php74 to 7.4.9 (PHP 7.4.9).


06 Aug 2020, PHP 7.4.9

- Apache:
  . Fixed bug #79030 (Upgrade apache2handler's php_apache_sapi_get_request_time
    to return usec). (Herbert256)

- COM:
  . Fixed bug #63208 (BSTR to PHP string conversion not binary safe). (cmb)
  . Fixed bug #63527 (DCOM does not work with Username, Password parameter).
    (cmb)

- Core:
  . Fixed bug #79740 (serialize() and unserialize() methods can not be called
    statically). (Nikita)
  . Fixed bug #79783 (Segfault in php_str_replace_common). (Nikita)
  . Fixed bug #79778 (Assertion failure if dumping closure with unresolved
    static variable). (Nikita)
  . Fixed bug #79779 (Assertion failure when assigning property of string
    offset by reference). (Nikita)
  . Fixed bug #79792 (HT iterators not removed if empty array is destroyed).
    (Nikita)
  . Fixed bug #78598 (Changing array during undef index RW error segfaults).
    (Nikita)
  . Fixed bug #79784 (Use after free if changing array during undef var during
    array write fetch). (Nikita)
  . Fixed bug #79793 (Use after free if string used in undefined index warning
    is changed). (Nikita)
  . Fixed bug #79862 (Public non-static property in child should take priority
    over private static). (Nikita)
  . Fixed bug #79877 (getimagesize function silently truncates after a null
    byte) (cmb)

- Fileinfo:
  . Fixed bug #79756 (finfo_file crash (FILEINFO_MIME)). (cmb)

- FTP:
  . Fixed bug #55857 (ftp_size on large files). (cmb)

- Mbstring:
  . Fixed bug #79787 (mb_strimwidth does not trim string). (XXiang)

- Phar:
  . Fixed bug #79797 (Use of freed hash key in the phar_parse_zipfile
    function). (CVE-2020-7068) (cmb)

- Reflection:
  . Fixed bug #79487 (::getStaticProperties() ignores property modifications).
    (cmb, Nikita)
  . Fixed bug #69804 (::getStaticPropertyValue() throws on protected props).
    (cmb, Nikita)
  . Fixed bug #79820 (Use after free when type duplicated into
    ReflectionProperty gets resolved). (Christopher Broadbent)

- Standard:
  . Fixed bug #70362 (Can't copy() large 'data://' with open_basedir). (cmb)
  . Fixed bug #78008 (dns_check_record() always return true on Alpine).
    (Andy Postnikov)
  . Fixed bug #79839 (array_walk() does not respect property types). (Nikita)

Revision 1.10 / (download) - annotate - [select for diffs], Sat Jul 11 04:02:14 2020 UTC (3 years, 2 months ago) by taca
Branch: MAIN
Changes since 1.9: +5 -5 lines
Diff to previous 1.9 (colored)

lang/php74: update to 7.4.8

Update php74 to 7.4.8.


09 Jul 2020, PHP 7.4.8

- Core:
  . Fixed bug #79649 (Altering disable_functions from module init corrupts
    memory). (Laruence)
  . Fixed bug #79595 (zend_init_fpu() alters FPU precision). (cmb, Nikita)
  . Fixed bug #79650 (php-win.exe 100% cpu lockup). (cmb)
  . Fixed bug #79668 (get_defined_functions(true) may miss functions). (cmb,
    Nikita)
  . Fixed bug #79657 ("yield from" hangs when invalid value encountered).
    (Nikita)
  . Fixed bug #79683 (Fake reflection scope affects __toString()). (Nikita)
  . Fixed possibly unsupported timercmp() usage. (cmb)

- Exif:
  . Fixed bug #79687 (Sony picture - PHP Warning - Make, Model, MakerNotes).
    (cmb)

- Fileinfo:
  . Fixed bug #79681 (mime_content_type/finfo returning incorrect mimetype).
    (cmb)

- Filter:
  . Fixed bug #73527 (Invalid memory access in php_filter_strip). (cmb)

- GD:
  . Fixed bug #79676 (imagescale adds black border with IMG_BICUBIC). (cmb)

- OpenSSL:
  . Fixed bug #62890 (default_socket_timeout=-1 causes connection to timeout).
    (cmb)

- PDO SQLite:
  . Fixed bug #79664 (PDOStatement::getColumnMeta fails on empty result set).
    (cmb)

- phpdbg:
  . Fixed bug #73926 (phpdbg will not accept input on restart execution). (cmb)
  . Fixed bug #73927 (phpdbg fails with windows error prompt at "watch array").
    (cmb)
  . Fixed several mostly Windows related phpdbg bugs. (cmb)

- SPL:
  . Fixed bug #79710 (Reproducible segfault in error_handler during GC
    involved an SplFileObject). (Nikita)

- Standard:
  . Fixed bug #74267 (segfault with streams and invalid data). (cmb)
  . Fixed bug #79579 (ZTS build of PHP 7.3.17 doesn't handle ERANGE for
    posix_getgrgid and others). (Böszörményi Zoltán)

Revision 1.9 / (download) - annotate - [select for diffs], Sun Jun 14 05:59:17 2020 UTC (3 years, 3 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2020Q2-base
Branch point for: pkgsrc-2020Q2
Changes since 1.8: +5 -5 lines
Diff to previous 1.8 (colored)

lang/php74: update to 7.4.7

Update update to 7.4.7.


11 Jun 2020, PHP 7.4.7

- Core:
  . Fixed bug #79599 (coredump in set_error_handler). (Laruence)
  . Fixed bug #79566 (Private SHM is not private on Windows). (cmb)
  . Fixed bug #79489 (.user.ini does not inherit). (cmb)
  . Fixed bug #79600 (Regression in 7.4.6 when yielding an array based
    generator). (Nikita)
  . Fixed bug #79657 ("yield from" hangs when invalid value encountered).
    (Nikita)

- FFI:
  . Fixed bug #79571 (FFI: var_dumping unions may segfault). (cmb)

- GD:
  . Fixed bug #79615 (Wrong GIF header written in GD GIFEncode). (sageptr, cmb)

- Opcache:
  . Fixed bug #79588 (Boolean opcache settings ignore on/off values). (cmb)
  . Fixed bug #79548 (Preloading segfault with inherited method using static
    variable). (Nikita)
  . Fixed bug #79603 (RTD collision with opcache). (Nikita)

- Standard:
  . Fixed bug #79561 (dns_get_record() fails with DNS_ALL). (cmb)

Revision 1.6.2.2 / (download) - annotate - [select for diffs], Fri May 15 16:54:48 2020 UTC (3 years, 4 months ago) by bsiegert
Branch: pkgsrc-2020Q1
Changes since 1.6.2.1: +5 -5 lines
Diff to previous 1.6.2.1 (colored) to branchpoint 1.6 (colored) next main 1.7 (colored)

Pullup ticket #6199 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.297
- lang/php74/distinfo                                           1.8

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Thu May 14 14:24:53 UTC 2020

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.6

   Update php74 to 7.4.6 (PHP 7.4.6).

   14 May 2020, PHP 7.4.6

   - Core:
     . Fixed bug #78434 (Generator yields no items after valid() call). (Nikita)
     . Fixed bug #79477 (casting object into array creates references). (Nikita)
     . Fixed bug #79514 (Memory leaks while including unexistent file). (cmb,
       Nikita)
     . Fixed bug #79470 (PHP incompatible with 3rd party file system on demand).
       (cmb)
     . Fixed bug #78784 (Unable to interact with files inside a VFS for Git
       repository). (cmb)
     . Fixed bug #78875 (Long variables cause OOM and temp files are not cleaned).
       (cmb) (CVE-2019-11048)
     . Fixed bug #78876 (Long variables cause OOM and temp files are not cleaned).
       (cmb) (CVE-2019-11048)

   - DOM:
     . Fixed bug #78221 (DOMNode::normalize() doesn't remove empty text nodes).
       (cmb)

   - EXIF:
     . Fixed bug #79336 (ext/exif/tests/bug79046.phpt fails on Big endian arch).
       (Nikita)

   - FCGI:
     . Fixed bug #79491 (Search for .user.ini extends up to root dir). (cmb)

   - MBString:
     . Fixed bug #79441 (Segfault in mb_chr() if internal encoding is unsupported).
       (Girgias)

   - OpenSSL:
     . Fixed bug #79497 (stream_socket_client() throws an unknown error sometimes
       with <1s timeout). (Joe Cai)

   - PCRE:
     . Upgraded to PCRE2 10.34. (cmb)

   - Phar:
     . Fixed bug #79503 (Memory leak on duplicate metadata). (cmb)

   - SimpleXML:
     . Fixed bug #79528 (Different object of the same xml between 7.4.5 and
       7.4.4). (cmb)

   - SPL:
     . Fixed bug #69264 (__debugInfo() ignored while extending SPL classes). (cmb)
     . Fixed bug #67369 (ArrayObject serialization drops the iterator class).
       (Alex Dowad)

   - Standard:
     . Fixed bug #79468 (SIGSEGV when closing stream handle with a stream filter
       appended). (dinosaur)
     . Fixed bug #79447 (Serializing uninitialized typed properties with __sleep
       should not throw). (nicolas-grekas)

Revision 1.8 / (download) - annotate - [select for diffs], Thu May 14 14:24:53 2020 UTC (3 years, 4 months ago) by taca
Branch: MAIN
Changes since 1.7: +5 -5 lines
Diff to previous 1.7 (colored)

lang/php74: update to 7.4.6

Update php74 to 7.4.6 (PHP 7.4.6).


14 May 2020, PHP 7.4.6

- Core:
  . Fixed bug #78434 (Generator yields no items after valid() call). (Nikita)
  . Fixed bug #79477 (casting object into array creates references). (Nikita)
  . Fixed bug #79514 (Memory leaks while including unexistent file). (cmb,
    Nikita)
  . Fixed bug #79470 (PHP incompatible with 3rd party file system on demand).
    (cmb)
  . Fixed bug #78784 (Unable to interact with files inside a VFS for Git
    repository). (cmb)
  . Fixed bug #78875 (Long variables cause OOM and temp files are not cleaned).
    (cmb) (CVE-2019-11048)
  . Fixed bug #78876 (Long variables cause OOM and temp files are not cleaned).
    (cmb) (CVE-2019-11048)

- DOM:
  . Fixed bug #78221 (DOMNode::normalize() doesn't remove empty text nodes).
    (cmb)

- EXIF:
  . Fixed bug #79336 (ext/exif/tests/bug79046.phpt fails on Big endian arch).
    (Nikita)

- FCGI:
  . Fixed bug #79491 (Search for .user.ini extends up to root dir). (cmb)

- MBString:
  . Fixed bug #79441 (Segfault in mb_chr() if internal encoding is unsupported).
    (Girgias)

- OpenSSL:
  . Fixed bug #79497 (stream_socket_client() throws an unknown error sometimes
    with <1s timeout). (Joe Cai)

- PCRE:
  . Upgraded to PCRE2 10.34. (cmb)

- Phar:
  . Fixed bug #79503 (Memory leak on duplicate metadata). (cmb)

- SimpleXML:
  . Fixed bug #79528 (Different object of the same xml between 7.4.5 and
    7.4.4). (cmb)

- SPL:
  . Fixed bug #69264 (__debugInfo() ignored while extending SPL classes). (cmb)
  . Fixed bug #67369 (ArrayObject serialization drops the iterator class).
    (Alex Dowad)

- Standard:
  . Fixed bug #79468 (SIGSEGV when closing stream handle with a stream filter
    appended). (dinosaur)
  . Fixed bug #79447 (Serializing uninitialized typed properties with __sleep
    should not throw). (nicolas-grekas)

Revision 1.6.2.1 / (download) - annotate - [select for diffs], Thu Apr 30 07:35:30 2020 UTC (3 years, 4 months ago) by bsiegert
Branch: pkgsrc-2020Q1
Changes since 1.6: +5 -5 lines
Diff to previous 1.6 (colored)

Pullup ticket #6174 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.294
- lang/php74/distinfo                                           1.7

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat Apr 18 05:01:45 UTC 2020

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.5

   Update php74 to 7.4.5.

   16 Apr 2020, PHP 7.4.5

   - Core:
     . Fixed bug #79364 (When copy empty array, next key is unspecified). (cmb)
     . Fixed bug #78210 (Invalid pointer address). (cmb, Nikita)

   - CURL:
     . Fixed bug #79199 (curl_copy_handle() memory leak). (cmb)

   - Date:
     . Fixed bug #79396 (DateTime hour incorrect during DST jump forward). (Nate
       Brunette)
     . Fixed bug #74940 (DateTimeZone loose comparison always true). (cmb)

   - FPM:
     . Implement request #77062 (Allow numeric [UG]ID in FPM listen.{owner,group})
       (Andre Nathan)

   - Iconv:
     . Fixed bug #79200 (Some iconv functions cut Windows-1258). (cmb)

   - OPcache:
     . Fixed bug #79412 (Opcache chokes and uses 100% CPU on specific script).
       (Dmitry)

   - Session:
     . Fixed bug #79413 (session_create_id() fails for active sessions). (cmb)

   - Shmop:
     . Fixed bug #79427 (Integer Overflow in shmop_open()). (cmb)

   - SimpleXML:
     . Fixed bug #61597 (SXE properties may lack attributes and content). (cmb)

   - SOAP:
     . Fixed bug #79357 (SOAP request segfaults when any request parameter is
       missing). (Nikita)

   - Spl:
     . Fixed bug #75673 (SplStack::unserialize() behavior). (cmb)
     . Fixed bug #79393 (Null coalescing operator failing with SplFixedArray).
       (cmb)

   - Standard:
     . Fixed bug #79330 (shell_exec() silently truncates after a null byte). (stas)
     . Fixed bug #79410 (system() swallows last chunk if it is exactly 4095 bytes
       without newline). (Christian Schneider)
     . Fixed bug #79465 (OOB Read in urldecode()). (stas)

   - Zip:
     . Fixed Bug #79296 (ZipArchive::open fails on empty file). (Remi)
     . Fixed bug #79424 (php_zip_glob uses gl_pathc after call to globfree).
       (Max Rees)

Revision 1.7 / (download) - annotate - [select for diffs], Sat Apr 18 05:01:44 2020 UTC (3 years, 5 months ago) by taca
Branch: MAIN
Changes since 1.6: +5 -5 lines
Diff to previous 1.6 (colored)

lang/php74: update to 7.4.5

Update php74 to 7.4.5.


16 Apr 2020, PHP 7.4.5

- Core:
  . Fixed bug #79364 (When copy empty array, next key is unspecified). (cmb)
  . Fixed bug #78210 (Invalid pointer address). (cmb, Nikita)

- CURL:
  . Fixed bug #79199 (curl_copy_handle() memory leak). (cmb)

- Date:
  . Fixed bug #79396 (DateTime hour incorrect during DST jump forward). (Nate
    Brunette)
  . Fixed bug #74940 (DateTimeZone loose comparison always true). (cmb)

- FPM:
  . Implement request #77062 (Allow numeric [UG]ID in FPM listen.{owner,group})
    (Andre Nathan)

- Iconv:
  . Fixed bug #79200 (Some iconv functions cut Windows-1258). (cmb)

- OPcache:
  . Fixed bug #79412 (Opcache chokes and uses 100% CPU on specific script).
    (Dmitry)

- Session:
  . Fixed bug #79413 (session_create_id() fails for active sessions). (cmb)

- Shmop:
  . Fixed bug #79427 (Integer Overflow in shmop_open()). (cmb)

- SimpleXML:
  . Fixed bug #61597 (SXE properties may lack attributes and content). (cmb)

- SOAP:
  . Fixed bug #79357 (SOAP request segfaults when any request parameter is
    missing). (Nikita)

- Spl:
  . Fixed bug #75673 (SplStack::unserialize() behavior). (cmb)
  . Fixed bug #79393 (Null coalescing operator failing with SplFixedArray).
    (cmb)

- Standard:
  . Fixed bug #79330 (shell_exec() silently truncates after a null byte). (stas)
  . Fixed bug #79410 (system() swallows last chunk if it is exactly 4095 bytes
    without newline). (Christian Schneider)
  . Fixed bug #79465 (OOB Read in urldecode()). (stas)


- Zip:
  . Fixed Bug #79296 (ZipArchive::open fails on empty file). (Remi)
  . Fixed bug #79424 (php_zip_glob uses gl_pathc after call to globfree).
    (Max Rees)

Revision 1.6 / (download) - annotate - [select for diffs], Fri Mar 20 08:13:55 2020 UTC (3 years, 6 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2020Q1-base
Branch point for: pkgsrc-2020Q1
Changes since 1.5: +5 -5 lines
Diff to previous 1.5 (colored)

lang/php74: update to 7.4.4

Update php74 to 7.4.4.


19 Mar 2020, PHP 7.4.4

- Core:
  . Fixed bug #79329 (get_headers() silently truncates after a null byte)
    (CVE-2020-7066) (cmb)
  . Fixed bug #79244 (php crashes during parsing INI file). (Laruence)
  . Fixed bug #63206 (restore_error_handler does not restore previous errors
    mask). (Mark Plomer)

- COM:
  . Fixed bug #66322 (COMPersistHelper::SaveToFile can save to wrong location).
    (cmb)
  . Fixed bug #79242 (COM error constants don't match com_exception codes on
    x86). (cmb)
  . Fixed bug #79247 (Garbage collecting variant objects segfaults). (cmb)
  . Fixed bug #79248 (Traversing empty VT_ARRAY throws com_exception). (cmb)
  . Fixed bug #79299 (com_print_typeinfo prints duplicate variables). (Litiano
    Moura)
  . Fixed bug #79332 (php_istreams are never freed). (cmb)
  . Fixed bug #79333 (com_print_typeinfo() leaks memory). (cmb)

- CURL:
  . Fixed bug #79019 (Copied cURL handles upload empty file). (cmb)
  . Fixed bug #79013 (Content-Length missing when posting a curlFile with
    curl). (cmb)

- DOM:
  . Fixed bug #77569: (Write Access Violation in DomImplementation). (Nikita,
    cmb)
  . Fixed bug #79271 (DOMDocumentType::$childNodes is NULL). (cmb)

- Enchant:
  . Fixed bug #79311 (enchant_dict_suggest() fails on big endian architecture).
    (cmb)

- EXIF:
  . Fixed bug #79282 (Use-of-uninitialized-value in exif) (CVE-2020-7064)
    (Nikita)

- Fileinfo:
  . Fixed bug #79283 (Segfault in libmagic patch contains a buffer
    overflow) (cmb)

- FPM:
  . Fixed bug #77653 (operator displayed instead of the real error message).
    (Jakub Zelenka)
  . Fixed bug #79014 (PHP-FPM & Primary script unknown). (Jakub Zelenka)

- MBstring:
  . Fixed bug #79371 (mb_strtolower (UTF-32LE): stack-buffer-overflow at
    php_unicode_tolower_full) (CVE-2020-7065) (cmb)

- MySQLi:
  . Fixed bug #64032 (mysqli reports different client_version). (cmb)

- MySQLnd:
  . Implemented FR #79275 (Support auth_plugin_caching_sha2_password on
    Windows). (cmb)

- Opcache:
  . Fixed bug #79252 (preloading causes php-fpm to segfault during exit).
    (Nikita)

- PCRE:
  . Fixed bug #79188 (Memory corruption in preg_replace/preg_replace_callback
    and unicode). (Nikita)
  . Fixed bug #79241 (Segmentation fault on preg_match()). (Nikita)
  . Fixed bug #79257 (Duplicate named groups (?J) prefer last alternative even
    if not matched). (Nikita)

- PDO_ODBC:
  . Fixed bug #79038 (PDOStatement::nextRowset() leaks column values). (cmb)

- Reflection:
  . Fixed bug #79062 (Property with heredoc default value returns false for
    getDocComment). (Nikita)

- SQLite3:
  . Fixed bug #79294 (::columnType() may fail after SQLite3Stmt::reset()). (cmb)

- Standard:
  . Fixed bug #79254 (getenv() w/o arguments not showing changes). (cmb)
  . Fixed bug #79265 (Improper injection of Host header when using fopen for
    http requests). (Miguel Xavier Penha Neto)

- Zip:
  . Fixed bug #79315 (ZipArchive::addFile doesn't honor start/length
    parameters). (Remi)

Revision 1.3.4.2 / (download) - annotate - [select for diffs], Sun Mar 8 10:24:19 2020 UTC (3 years, 6 months ago) by bsiegert
Branch: pkgsrc-2019Q4
Changes since 1.3.4.1: +4 -4 lines
Diff to previous 1.3.4.1 (colored) to branchpoint 1.3 (colored) next main 1.4 (colored)

Pullup ticket #6142 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.288
- lang/php74/distinfo                                           1.5

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Thu Feb 20 14:45:19 UTC 2020

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: distinfo

   Log Message:
   lang/php74: update to 7.4.3

   Update php74 to 7.4.3 (PHP 7.4.3).

   20 Feb 2020, PHP 7.4.3

   - Core:
     . Fixed bug #79146 (cscript can fail to run on some systems). (clarodeus)
     . Fixed bug #79155 (Property nullability lost when using multiple property
       definition). (Nikita)
     . Fixed bug #78323 (Code 0 is returned on invalid options). (Ivan Mikheykin)
     . Fixed bug #78989 (Delayed variance check involving trait segfaults).
       (Nikita)
     . Fixed bug #79174 (cookie values with spaces fail to round-trip). (cmb)
     . Fixed bug #76047 (Use-after-free when accessing already destructed
       backtrace arguments). (Nikita)

   - COM:
     . Fixed bug #79247 (Garbage collecting variant objects segfaults). (cmb)

   - CURL:
     . Fixed bug #79078 (Hypothetical use-after-free in curl_multi_add_handle()).
       (cmb)

   - FFI:
     . Fixed bug #79096 (FFI Struct Segfault). (cmb)

   - IMAP:
     . Fixed bug #79112 (IMAP extension can't find OpenSSL libraries at configure
       time). (Nikita)

    -Intl:
     . Fixed bug #79212 (NumberFormatter::format() may detect wrong type). (cmb)

   - Libxml:
     . Fixed bug #79191 (Error in SoapClient ctor disables DOMDocument::save()).
       (Nikita, cmb)

   - MBString:
     . Fixed bug #79149 (SEGV in mb_convert_encoding with non-string encodings).
       (cmb)

   - MySQLi:
     . Fixed bug #78666 (Properties may emit a warning on var_dump()). (kocsismate)

   - MySQLnd:
     . Fixed bug #79084 (mysqlnd may fetch wrong column indexes with MYSQLI_BOTH).
       (cmb)
     . Fixed bug #79011 (MySQL caching_sha2_password Access denied for password
       with more than 20 chars). (Nikita)

   - Opcache:
     . Fixed bug #79114 (Eval class during preload causes class to be only half
       available). (Laruence)
     . Fixed bug #79128 (Preloading segfaults if preload_user is used). (Nikita)
     . Fixed bug #79193 (Incorrect type inference for self::$field =& $field).
       (Nikita)

   - OpenSSL:
     . Fixed bug #79145 (openssl memory leak). (cmb, Nikita)

   - Phar:
     . Fixed bug #79082 (Files added to tar with Phar::buildFromIterator have
       all-access permissions). (CVE-2020-7063) (stas)
     . Fixed bug #79171 (heap-buffer-overflow in phar_extract_file).
       (CVE-2020-7061) (cmb)
     . Fixed bug #76584 (PharFileInfo::decompress not working). (cmb)

   - Reflection:
     . Fixed bug #79115 (ReflectionClass::isCloneable call reflected class
       __destruct). (Nikita)

   - Session:
     . Fixed bug #79221 (Null Pointer Dereference in PHP Session Upload Progress).
       (CVE-2020-7062) (stas)

   - Standard:
     . Fixed bug #78902 (Memory leak when using stream_filter_append). (liudaixiao)
     . Fixed bug #78969 (PASSWORD_DEFAULT should match PASSWORD_BCRYPT instead of being null). (kocsismate)

   - Testing:
     . Fixed bug #78090 (bug45161.phpt takes forever to finish). (cmb)

   - XSL:
     . Fixed bug #70078 (XSL callbacks with nodes as parameter leak memory). (cmb)

   - Zip:
     . Add ZipArchive::CM_LZMA2 and ZipArchive::CM_XZ constants (since libzip 1.6.0). (Remi)
     . Add ZipArchive::RDONLY (since libzip 1.0.0). (Remi)
     . Add ZipArchive::ER_* missing constants. (Remi)
     . Add ZipArchive::LIBZIP_VERSION constant. (Remi)
     . Fixed bug #73119 (Wrong return for ZipArchive::addEmptyDir Method). (Remi)

Revision 1.5 / (download) - annotate - [select for diffs], Thu Feb 20 14:45:19 2020 UTC (3 years, 7 months ago) by taca
Branch: MAIN
Changes since 1.4: +5 -5 lines
Diff to previous 1.4 (colored)

lang/php74: update to 7.4.3

Update php74 to 7.4.3 (PHP 7.4.3).

20 Feb 2020, PHP 7.4.3

- Core:
  . Fixed bug #79146 (cscript can fail to run on some systems). (clarodeus)
  . Fixed bug #79155 (Property nullability lost when using multiple property
    definition). (Nikita)
  . Fixed bug #78323 (Code 0 is returned on invalid options). (Ivan Mikheykin)
  . Fixed bug #78989 (Delayed variance check involving trait segfaults).
    (Nikita)
  . Fixed bug #79174 (cookie values with spaces fail to round-trip). (cmb)
  . Fixed bug #76047 (Use-after-free when accessing already destructed
    backtrace arguments). (Nikita)

- COM:
  . Fixed bug #79247 (Garbage collecting variant objects segfaults). (cmb)

- CURL:
  . Fixed bug #79078 (Hypothetical use-after-free in curl_multi_add_handle()).
    (cmb)

- FFI:
  . Fixed bug #79096 (FFI Struct Segfault). (cmb)

- IMAP:
  . Fixed bug #79112 (IMAP extension can't find OpenSSL libraries at configure
    time). (Nikita)

 -Intl:
  . Fixed bug #79212 (NumberFormatter::format() may detect wrong type). (cmb)

- Libxml:
  . Fixed bug #79191 (Error in SoapClient ctor disables DOMDocument::save()).
    (Nikita, cmb)

- MBString:
  . Fixed bug #79149 (SEGV in mb_convert_encoding with non-string encodings).
    (cmb)

- MySQLi:
  . Fixed bug #78666 (Properties may emit a warning on var_dump()). (kocsismate)

- MySQLnd:
  . Fixed bug #79084 (mysqlnd may fetch wrong column indexes with MYSQLI_BOTH).
    (cmb)
  . Fixed bug #79011 (MySQL caching_sha2_password Access denied for password
    with more than 20 chars). (Nikita)

- Opcache:
  . Fixed bug #79114 (Eval class during preload causes class to be only half
    available). (Laruence)
  . Fixed bug #79128 (Preloading segfaults if preload_user is used). (Nikita)
  . Fixed bug #79193 (Incorrect type inference for self::$field =& $field).
    (Nikita)

- OpenSSL:
  . Fixed bug #79145 (openssl memory leak). (cmb, Nikita)

- Phar:
  . Fixed bug #79082 (Files added to tar with Phar::buildFromIterator have
    all-access permissions). (CVE-2020-7063) (stas)
  . Fixed bug #79171 (heap-buffer-overflow in phar_extract_file).
    (CVE-2020-7061) (cmb)
  . Fixed bug #76584 (PharFileInfo::decompress not working). (cmb)

- Reflection:
  . Fixed bug #79115 (ReflectionClass::isCloneable call reflected class
    __destruct). (Nikita)

- Session:
  . Fixed bug #79221 (Null Pointer Dereference in PHP Session Upload Progress).
    (CVE-2020-7062) (stas)

- Standard:
  . Fixed bug #78902 (Memory leak when using stream_filter_append). (liudaixiao)
  . Fixed bug #78969 (PASSWORD_DEFAULT should match PASSWORD_BCRYPT instead of being null). (kocsismate)

- Testing:
  . Fixed bug #78090 (bug45161.phpt takes forever to finish). (cmb)

- XSL:
  . Fixed bug #70078 (XSL callbacks with nodes as parameter leak memory). (cmb)

- Zip:
  . Add ZipArchive::CM_LZMA2 and ZipArchive::CM_XZ constants (since libzip 1.6.0). (Remi)
  . Add ZipArchive::RDONLY (since libzip 1.0.0). (Remi)
  . Add ZipArchive::ER_* missing constants. (Remi)
  . Add ZipArchive::LIBZIP_VERSION constant. (Remi)
  . Fixed bug #73119 (Wrong return for ZipArchive::addEmptyDir Method). (Remi)

Revision 1.3.4.1 / (download) - annotate - [select for diffs], Wed Jan 29 13:34:46 2020 UTC (3 years, 7 months ago) by bsiegert
Branch: pkgsrc-2019Q4
Changes since 1.3: +5 -5 lines
Diff to previous 1.3 (colored)

Pullup ticket #6128 - requested by taca
lang/php74: security fix

Revisions pulled up:
- lang/php/phpversion.mk                                        1.285
- lang/php74/Makefile                                           1.3-1.5
- lang/php74/Makefile.php                                       1.2
- lang/php74/PLIST                                              1.2
- lang/php74/distinfo                                           1.4

---
   Module Name:	pkgsrc
   Committed By:	jperkin
   Date:		Sat Jan 18 21:51:16 UTC 2020

   Modified Files:
   	pkgsrc/lang/php74: Makefile

   Log Message:
   *: Recursive revision bump for openssl 1.1.1.

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Tue Jan 21 14:16:27 UTC 2020

   Modified Files:
   	pkgsrc/lang/php74: Makefile Makefile.php PLIST

   Log Message:
   lang/php74: switch to use external pcre

   Switch to use external pcre, fixing PR pkg/54793.

   Bump PKGREVISION.

---
   Module Name:	pkgsrc
   Committed By:	taca
   Date:		Sat Jan 25 17:22:49 UTC 2020

   Modified Files:
   	pkgsrc/lang/php: phpversion.mk
   	pkgsrc/lang/php74: Makefile distinfo

   Log Message:
   lang/php74: update to 7.4.2

   Update php74 to 7.4.2 (PHP 7.4.2).

   23 Jan 2020, PHP 7.4.2

   - Core:
     . Preloading support on Windows has been disabled. (Nikita)
     . Fixed bug #79022 (class_exists returns True for classes that are no=
   t ready
       to be used). (Laruence)
     . Fixed bug #78929 (plus signs in cookie values are converted to spac=
   es).
       (Alexey Kachalin)
     . Fixed bug #78973 (Destructor during CV freeing causes segfault if o=
   pline
       never saved). (Nikita)
     . Fixed bug #78776 (Abstract method implementation from trait does no=
   t check
       "static"). (Nikita)
     . Fixed bug #78999 (Cycle leak when using function result as temporar=
   y).
       (Dmitry)
     . Fixed bug #79008 (General performance regression with PHP 7.4 on Wi=
   ndows).
       (cmb)
     . Fixed bug #79002 (Serializing uninitialized typed properties with _=
   _sleep
       makes unserialize throw). (Nikita)

   - CURL:
     . Fixed bug #79033 (Curl timeout error with specific url and post). (=
   cmb)
     . Fixed bug #79063 (curl openssl does not respect PKG_CONFIG_PATH). (=
   Nikita)

   - Date:
     . Fixed bug #79015 (undefined-behavior in php_date.c). (cmb)

   - DBA:
     . Fixed bug #78808 ([LMDB] MDB_MAP_FULL: Environment mapsize limit re=
   ached).
       (cmb)

   - Exif:
     . Fixed bug #79046 (NaN to int cast undefined behavior in exif). (Nik=
   ita)

   - Fileinfo:
     . Fixed bug #74170 (locale information change after mime_content_type=
   ).
       (Sergei Turchanov)

   - GD:
     . Fixed bug #79067 (gdTransformAffineCopy() may use unitialized value=
   s). (cmb)
     . Fixed bug #79068 (gdTransformAffineCopy() changes interpolation met=
   hod).
       (cmb)

   - Libxml:
     . Fixed bug #79029 (Use After Free's in XMLReader / XMLWriter). (Laru=
   ence)

   - Mbstring:
     . Fixed bug #79037 (global buffer-overflow in `mbfl_filt_conv_big5_wc=
   har`).
       (CVE-2020-7060) (Nikita)

   - OPcache:
     . Fixed bug #78961 (erroneous optimization of re-assigned $GLOBALS). =
   (Dmitry)
     . Fixed bug #78950 (Preloading trait method with static variables). (=
   Nikita)
     . Fixed bug #78903 (Conflict in RTD key for closures results in crash=
   ).
       (Nikita)
     . Fixed bug #78986 (Opcache segfaults when inheriting ctor from immut=
   able
       into mutable class). (Nikita)
     . Fixed bug #79040 (Warning Opcode handlers are unusable due to ASLR)=
   . (cmb)
     . Fixed bug #79055 (Typed property become unknown with OPcache file c=
   ache).
       (Nikita)

   - Pcntl:
     . Fixed bug #78402 (Converting null to string in error message is bad=
    DX).
       (SAT=D2 Kentar=F2)

   - PDO_PgSQL:
     . Fixed bug #78983 (pdo_pgsql config.w32 cannot find libpq-fe.h). (SA=
   T=D2
       Kentar=F2)
     . Fixed bug #78980 (pgsqlGetNotify() overlooks dead connection). (SAT=
   =D2
       Kentar=F2)
     . Fixed bug #78982 (pdo_pgsql returns dead persistent connection). (S=
   AT=D2
       Kentar=F2)

   - Session:
     . Fixed bug #79091 (heap use-after-free in session_create_id()). (cmb=
   ,
       Nikita)
     . Fixed bug #79031 (Session unserialization problem). (Nikita)

   - Shmop:
     . Fixed bug #78538 (shmop memory leak). (cmb)

   - Sqlite3:
     . Fixed bug #79056 (sqlite does not respect PKG_CONFIG_PATH during
       compilation). (Nikita)

   - Spl:
     . Fixed bug #78976 (SplFileObject::fputcsv returns -1 on failure). (c=
   mb)

   - Standard:
     . Fixed bug #79099 (OOB read in php_strip_tags_ex). (CVE-2020-7059). =
   (cmb)
     . Fixed bug #79000 (Non-blocking socket stream reports EAGAIN as erro=
   r).
       (Nikita)
     . Fixed bug #54298 (Using empty additional_headers adding extraneous =
   CRLF).
       (cmb)

Revision 1.4 / (download) - annotate - [select for diffs], Sat Jan 25 17:22:49 2020 UTC (3 years, 8 months ago) by taca
Branch: MAIN
Changes since 1.3: +5 -5 lines
Diff to previous 1.3 (colored)

lang/php74: update to 7.4.2

Update php74 to 7.4.2 (PHP 7.4.2).

23 Jan 2020, PHP 7.4.2

- Core:
  . Preloading support on Windows has been disabled. (Nikita)
  . Fixed bug #79022 (class_exists returns True for classes that are not ready
    to be used). (Laruence)
  . Fixed bug #78929 (plus signs in cookie values are converted to spaces).
    (Alexey Kachalin)
  . Fixed bug #78973 (Destructor during CV freeing causes segfault if opline
    never saved). (Nikita)
  . Fixed bug #78776 (Abstract method implementation from trait does not check
    "static"). (Nikita)
  . Fixed bug #78999 (Cycle leak when using function result as temporary).
    (Dmitry)
  . Fixed bug #79008 (General performance regression with PHP 7.4 on Windows).
    (cmb)
  . Fixed bug #79002 (Serializing uninitialized typed properties with __sleep
    makes unserialize throw). (Nikita)

- CURL:
  . Fixed bug #79033 (Curl timeout error with specific url and post). (cmb)
  . Fixed bug #79063 (curl openssl does not respect PKG_CONFIG_PATH). (Nikita)

- Date:
  . Fixed bug #79015 (undefined-behavior in php_date.c). (cmb)

- DBA:
  . Fixed bug #78808 ([LMDB] MDB_MAP_FULL: Environment mapsize limit reached).
    (cmb)

- Exif:
  . Fixed bug #79046 (NaN to int cast undefined behavior in exif). (Nikita)

- Fileinfo:
  . Fixed bug #74170 (locale information change after mime_content_type).
    (Sergei Turchanov)

- GD:
  . Fixed bug #79067 (gdTransformAffineCopy() may use unitialized values). (cmb)
  . Fixed bug #79068 (gdTransformAffineCopy() changes interpolation method).
    (cmb)

- Libxml:
  . Fixed bug #79029 (Use After Free's in XMLReader / XMLWriter). (Laruence)

- Mbstring:
  . Fixed bug #79037 (global buffer-overflow in `mbfl_filt_conv_big5_wchar`).
    (CVE-2020-7060) (Nikita)

- OPcache:
  . Fixed bug #78961 (erroneous optimization of re-assigned $GLOBALS). (Dmitry)
  . Fixed bug #78950 (Preloading trait method with static variables). (Nikita)
  . Fixed bug #78903 (Conflict in RTD key for closures results in crash).
    (Nikita)
  . Fixed bug #78986 (Opcache segfaults when inheriting ctor from immutable
    into mutable class). (Nikita)
  . Fixed bug #79040 (Warning Opcode handlers are unusable due to ASLR). (cmb)
  . Fixed bug #79055 (Typed property become unknown with OPcache file cache).
    (Nikita)

- Pcntl:
  . Fixed bug #78402 (Converting null to string in error message is bad DX).
    (SAT Kentar)

- PDO_PgSQL:
  . Fixed bug #78983 (pdo_pgsql config.w32 cannot find libpq-fe.h). (SAT
    Kentar)
  . Fixed bug #78980 (pgsqlGetNotify() overlooks dead connection). (SAT
    Kentar)
  . Fixed bug #78982 (pdo_pgsql returns dead persistent connection). (SAT
    Kentar)

- Session:
  . Fixed bug #79091 (heap use-after-free in session_create_id()). (cmb,
    Nikita)
  . Fixed bug #79031 (Session unserialization problem). (Nikita)

- Shmop:
  . Fixed bug #78538 (shmop memory leak). (cmb)

- Sqlite3:
  . Fixed bug #79056 (sqlite does not respect PKG_CONFIG_PATH during
    compilation). (Nikita)

- Spl:
  . Fixed bug #78976 (SplFileObject::fputcsv returns -1 on failure). (cmb)

- Standard:
  . Fixed bug #79099 (OOB read in php_strip_tags_ex). (CVE-2020-7059). (cmb)
  . Fixed bug #79000 (Non-blocking socket stream reports EAGAIN as error).
    (Nikita)
  . Fixed bug #54298 (Using empty additional_headers adding extraneous CRLF).
    (cmb)

Revision 1.3 / (download) - annotate - [select for diffs], Sat Dec 21 07:00:55 2019 UTC (3 years, 9 months ago) by taca
Branch: MAIN
CVS Tags: pkgsrc-2019Q4-base
Branch point for: pkgsrc-2019Q4
Changes since 1.2: +5 -5 lines
Diff to previous 1.2 (colored)

lang/php74: update to 7.4.1

Update php74 to 7.4.1, including security fixes.

19 Dec 2019, PHP 7.4.1

- Bcmath:
  . Fixed bug #78878 (Buffer underflow in bc_shift_addsub). (CVE-2019-11046).
    (cmb)

- Core:
  . Fixed bug #78862 (link() silently truncates after a null byte on Windows).
    (CVE-2019-11044). (cmb)
  . Fixed bug #78863 (DirectoryIterator class silently truncates after a null
    byte). (CVE-2019-11045). (cmb)
  . Fixed bug #78943 (mail() may release string with refcount==1 twice).
    (CVE-2019-11049). (cmb)
  . Fixed bug #78810 (RW fetches do not throw "uninitialized property"
    exception). (Nikita)
  . Fixed bug #78868 (Calling __autoload() with incorrect EG(fake_scope) value).
    (Antony Dovgal, Dmitry)
  . Fixed bug #78296 (is_file fails to detect file). (cmb)
  . Fixed bug #78883 (fgets(STDIN) fails on Windows). (cmb)
  . Fixed bug #78898 (call_user_func(['parent', ...]) fails while other
    succeed). (Nikita)
  . Fixed bug #78904 (Uninitialized property triggers __get()). (Nikita)
  . Fixed bug #78926 (Segmentation fault on Symfony cache:clear). (Nikita)

- GD:
  . Fixed bug #78849 (GD build broken with -D SIGNED_COMPARE_SLOW). (cmb)
  . Fixed bug #78923 (Artifacts when convoluting image with transparency).
    (wilson chen)

- EXIF:
  . Fixed bug #78793 (Use-after-free in exif parsing under memory sanitizer).
    (CVE-2019-11050). (Nikita)
  . Fixed bug #78910 (Heap-buffer-overflow READ in exif). (CVE-2019-11047).
    (Nikita)

- FPM:
  . Fixed bug #76601 (Partially working php-fpm ater incomplete reload).
    (Maksim Nikulin)
  . Fixed bug #78889 (php-fpm service fails to start). (Jakub Zelenka)
  . Fixed bug #78916 (php-fpm 7.4.0 don't send mail via mail()).
    (Jakub Zelenka)

- Intl:
  . Implemented FR #78912 (INTL Support for accounting format). (cmb)

- Mysqlnd:
  . Fixed bug #78823 (ZLIB_LIBS not added to EXTRA_LIBS). (Arjen de Korte)

- OPcache:
  . Fixed $x = (bool)$x; with opcache (should emit undeclared variable notice).
    (Tyson Andre)
  . Fixed bug #78935 (Preloading removes classes that have dependencies).
    (Nikita, Dmitry)

- PCRE:
  . Fixed bug #78853 (preg_match() may return integer > 1). (cmb)

- Reflection:
  . Fixed bug #78895 (Reflection detects abstract non-static class as abstract
    static. IS_IMPLICIT_ABSTRACT is not longer used). (Dmitry)

- Standard:
  . Fixed bug #77638 (var_export'ing certain class instances segfaults). (cmb)
  . Fixed bug #78840 (imploding $GLOBALS crashes). (cmb)
  . Fixed bug #78833 (Integer overflow in pack causes out-of-bound access).
    (cmb)
  . Fixed bug #78814 (strip_tags allows / in tag name => whitelist bypass).
    (cmb)

Revision 1.2 / (download) - annotate - [select for diffs], Mon Dec 16 15:58:19 2019 UTC (3 years, 9 months ago) by taca
Branch: MAIN
Changes since 1.1: +1 -3 lines
Diff to previous 1.1 (colored)

lang/php*: clean up php langauges

Clean up php languages.

* Clean up php/phpversions.mk a little.
* Add php/replace.mk to provide common shebang line replace for PHP.
* Define USE_TOOLS before including <bsd.prefs.mk>.
* Fix most warnings of pkglint.

No functional change should be done.

Revision 1.1 / (download) - annotate - [select for diffs], Sun Dec 15 17:56:34 2019 UTC (3 years, 9 months ago) by taca
Branch: MAIN

lang/php74: Add php74 version 7.4.0 pacakge.

Add php74 version 7.4.0 pacakge based on php73.

PHP is a widely-used open source general-purpose scripting language
that is especially suited for web development and can be embedded
into HTML.  It is modular, and object-oriented.  Much of its syntax
is borrowed from C, Java and Perl with a couple of unique PHP-specific
features thrown in.  The language is designed to allow web developers
to write dynamically generated pages quickly.

PHP 7.4 comes with numerous improvements and new features such as

* Typed Properties
* Arrow Functions
* Limited Return Type Covariance and Argument Type Contravariance
* Unpacking Inside Arrays
* Numeric Literal Separator
* Weak References
* Allow Exceptions from __toString()
* Opcache Preloading
* Several Deprecations
* Extensions Removed from the Core

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.




CVSweb <webmaster@jp.NetBSD.org>