OpenBSD Ports — graphics/digikam-kde4 Makefile, graphics/digikam-kde4/patches patch-core_CMakeLists_txt patch-core_tests_imgqsort_detectcompression_CMakeLists_txt

Make sure no extra OpenCV libraries are picked up during linking.
Reduces WANTLIB-kipi back to something realistic. Went upstream already.

okay sthen@

OpenBSD Ports — tests/portcheck/t2 Makefile, tests/portcheck/t3 Makefile

Nitpicking: set actual test names. Doesn't affect actual testing.

committing under sthen@'s okay for portcheck

OpenBSD Ports — infrastructure/bin portcheck

Missing function name between "&&" and arguments.

okay sthen@ since portcheck doesn't affect actual release
OpenBSD Ports — infrastructure/bin portcheck

Fix FULLPKGNAME handling, it should be subpackage-dependent.

okay sthen@ since portcheck doesn't affect actual release
OpenBSD Ports — devel/quirks Makefile, devel/quirks/files Quirks.pm

Entry for cherokee CVE-2014-4668.

OpenBSD Ports — sysutils/ansible Makefile distinfo

Update ansible to 1.6.7 which fixes these CVEs:

- CVE-2014-4966 (lookup function)
- CVE-2014-4967 (action arguments)

Noted by and OK jasper@
OK naddy@

OpenBSD Ports — www/cherokee Makefile, www/cherokee/patches patch-cherokee_validator_ldap_c

MFC security fix for CVE-2014-4668.  ok jasper@

Original log message:
  The LDAP authenticator considered successful LDAP bindings as a proper
  authentication, without checking the length of the user's password.
  But the LDAP server configuration might allow password-less bindings
  to retrieve public information. ok naddy@

OpenBSD Ports — www/cherokee/patches patch-cherokee_validator_ldap_c

Add files from parent branch HEAD:

OpenBSD Ports — www/cherokee Makefile, www/cherokee/patches patch-cherokee_validator_ldap_c

SECURITY fix for CVE-2014-4668.  The LDAP authenticator considered
successful LDAP bindings as a proper authentication, without checking
the length of the user's password.  But the LDAP server configuration
might allow password-less bindings to retrieve public information.
ok naddy@

OpenBSD Ports — devel/quirks Makefile, devel/quirks/files Quirks.pm

add www/p5-CGI-Application CVE-2013-7329

OpenBSD Ports — www/p5-CGI-Application Makefile, www/p5-CGI-Application/patches patch-lib_CGI_Application_pm patch-t_basic_t

Update www/p5-CGI-Application for CVE-2013-7329
Fix RT 84403 - 'Security problem: missing "start" mode dumps ENV to output

While here remove groff and fix runtime depends.
www/p5-CGI-PSGI is optional, include it as people nowadays run PSGI and are
moving away from MOD_PERL.

From maintainer Ian McWilliam

OpenBSD Ports — devel/mingw Makefile

do not pick up gmkdir in configure; ok espie@
OpenBSD Ports — www/urlwatch Makefile

add a run dep for urlwatch on lynx, ok jasper@
OpenBSD Ports — devel/quirks Makefile, devel/quirks/files Quirks.pm

quirk for exim vuln fix, reminded by espie

OpenBSD Ports — textproc/asciidoc Makefile

w3m -> lynx

req. by naddy@
OpenBSD Ports — devel/kdevelop Makefile

OpenBSD Ports — mail/exim distinfo Makefile, mail/exim/patches patch-src_expand_c

update to Exim 4.83, fixes CVE-2014-2972 - more information at

ok naddy@

OpenBSD Ports — devel/monodevelop Makefile

This port needs a major update to work with Mono3; it seems we will not
have time to properly do this before lock so mark BROKEN.

ok jasper@ sthen@ robert@
OpenBSD Ports — infrastructure/mk bsd.port.mk

fix a remnant of MULTI_PACKAGES reorg, a few years ago: there's no reason
to count LIB_DEPENDS and WANTLIB in build-deps, only the actual subpackaged
version count (reminder: even single package ports are actually multi-packaged,
with SUBPACKAGE=-, hence we will count LIB_DEPENDS- and WANTLIB-).

This was actually a discrepancy between manual builds and dpb builds, as the
output of dump-vars won't show plain LIB_DEPENDS. This caused a bit of
confusion wrt multimedia/mlt. Hence the actual fix.
OpenBSD Ports — graphics/digikam-kde4/patches patch-extra_kipi-plugins_common_libkipiplugins_CMakeLists_txt

Better fix for missing dependency, similar to devel/kdevelop one.

OpenBSD Ports — devel/kdevelop/patches patch-languages_cpp_CMakeLists_txt

Even better patch for missing dependency, operating at source file level.

OpenBSD Ports — lang/mono Makefile, lang/mono/pkg PLIST

Install missing @sample files; this unbreaks mono-basic.

ok sthen@ robert@ (maintainer)
OpenBSD Ports — devel/cppcheck Makefile, devel/cppcheck/patches patch-cli_cppcheckexecutor_cpp

add -lexecinfo and remove the patch disabling backtrace() support, registering
the dependency (thus fixing an unregistered build dependency on execinfo.h and
adding support for the functionality). Build problem reported by naddy@,
ok jsg@ jasper@

OpenBSD Ports — graphics/pdfmod Makefile distinfo, graphics/pdfmod/pkg PLIST

Unbreak after mono update (from Arch Linux).

ok espie@

OpenBSD Ports — graphics/openimageio Makefile

Do not pick up OpenCV if found.

noticed by naddy@ and sthen@, ok naddy@
OpenBSD Ports — net/rtorrent Makefile, net/rtorrent/pkg README

Remove a dead link from the README.
From misc.nick at gmx dot com, ok dcoppa@ naddy@

OpenBSD Ports — multimedia/kdenlive Makefile

Missing LIB_DEPENDS on nepomuk-core.

Detailed explanation: port-lib-depends-check won't complain, because this
port have RDEP on kde-runtime, which in turn has itself nepomuk-core as
a dependency. But at the build time RDEPs aren't installed, and sooner or
later things would break... And this finally happened at naddy@'s.
OpenBSD Ports — www/sope Makefile, www/sope/patches patch-sope-appserver_NGObjWeb_Associations_WOKeyPathAssociation_m

    Fix accessing the calendar on i386, bug introduced when i386 was switched to use 
    OK jasper@

OpenBSD Ports — textproc/xmlto Makefile

Depend on lynx instead of w3m (which depends on boehm-gc that is broken
on some arches).

ok sthen@
OpenBSD Ports — www/minitube Makefile distinfo, www/minitube/pkg PLIST

Update minitube to 2.2 after the youtube API changes.
ok espie@ jca@.

OpenBSD Ports — audio/jack Makefile, audio/jack/pkg README

Tweak documentation according to recent rc changes.

ok jasper@

OpenBSD Ports — net/unbound Makefile distinfo, net/unbound/patches patch-doc_example_conf_in patch-Makefile_in

Remove net/unbound. It's been unlinked for a while and is now in base.

prodded by and ok sthen@, ok jasper@

OpenBSD Ports — devel/quirks Makefile, devel/quirks/files Quirks.pm

add bozohttpd

OpenBSD Ports — net/nagios/nrpe Makefile, net/nagios/nrpe/patches patch-src_nrpe_c

Prevent the nrpe children from cleaning up the pidfile on
accept(2)/getpeername(2) errors, from Ubuntu.  ok sthen@

OpenBSD Ports — www/bozohttpd Makefile, www/bozohttpd/patches patch-bozohttpd_c patch-auth-bozo_c

Security fix for CVE-2014-5015
bozohttpd: basic http authentication bypass

ok benoit@ (MAINTAINER), sthen@

OpenBSD Ports — www/bozohttpd Makefile distinfo

Security update to bozohttpd-20140708, addresses CVE-2014-5015

ok benoit@ (MAINTAINER), sthen@

OpenBSD Ports — net/transmission Makefile, net/transmission/patches patch-libtransmission_bitfield_c patch-libtransmission_peer-msgs_c

Security fix for CVE-2014-4909,
transmission peer communication vulnerability

OpenBSD Ports — net/wireshark Makefile

bdep on desktop-file-utils, ok landry
OpenBSD Ports — devel/kdevelop/patches patch-languages_cpp_CMakeLists_txt patch-debuggers_gdb_stty_cpp

Re-do the fix for "ui_custom_include_paths.h", should work now
(continues to work without problems on i386...)

Also, fix fallout from some recent headers tweaking in base.

Both fixes are build-time only, so no REVISION bump.

OpenBSD Ports — devel/quirks Makefile, devel/quirks/files Quirks.pm

add net/transmission to the cve list; prodded/ok espie@

OpenBSD Ports — x11/xscreensaver Makefile

Add a note about updating KDE artwork packages on xscreensaver update.

okay sthen@
OpenBSD Ports — textproc/ispell Makefile, textproc/ispell/pkg README-main MESSAGE-main

Do not output "Default dictionary has been set to `british'" each time the
pkg is updated; because that is not true.
Tweak the @exec line.

after a comment by guenther@ on icb

OpenBSD Ports — sysutils/ruby-facter Makefile, sysutils/ruby-facter/pkg PLIST

regen plist to include the openbsd implementation for the partitions fact...oops.

OpenBSD Ports — net/transmission Makefile distinfo

update to 2.84: fix peer communication vulnerability
also tested by gonzalo@

OpenBSD Ports — sysutils/augeas Makefile, sysutils/augeas/patches patch-lenses_xymon_alerting_aug

apply patch from upstream to effectively unbreak augtool, as the xymon_alerting
lens was failing.

OpenBSD Ports — sysutils/augeas Makefile, sysutils/augeas/patches patch-lenses_shellvars_aug patch-lenses_simplelines_aug

rc.conf* aren't shell scripts anymore, but don't match the simplevars lens'
format either, so just make them simplelines instead.

OpenBSD Ports — devel/hyena Makefile

Unbreak after recent mono upgrade.
OpenBSD Ports — devel/quilt/patches patch-test_remove-trailing-ws_test

Remove patch that should have been removed in previous, reminded by
nigel@ & kent spillner, dunno why it applied first i tried...

OpenBSD Ports — www/drupal6/core Makefile distinfo, www/drupal6/date Makefile distinfo

drupal6 updates: core 6.3.2 (security update), date 2.10, filefield 3.13
ok espie@

OpenBSD Ports — lang/mono-basic Makefile, lang/mono-basic/patches patch-vbnc_vbnc_setversion_sh

Drop some uneeded stuffs.