pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: [pkgsrc-2026Q3] pkgsrc/devel/pcre2



Module Name:    pkgsrc
Committed By:   bsiegert
Date:           Sat Oct  3 19:37:16 UTC 2026

Modified Files:
        pkgsrc/devel/pcre2 [pkgsrc-2026Q3]: Makefile buildlink3.mk distinfo
Added Files:
        pkgsrc/devel/pcre2/patches [pkgsrc-2026Q3]: patch-configure

Log Message:
Pullup ticket #7261 - requested by taca
devel/pcre2: build fix, security fix

Revisions pulled up:
- devel/pcre2/Makefile                                          1.33,1.35-1.36
- devel/pcre2/PLIST                                             1.14
- devel/pcre2/buildlink3.mk                                     1.9
- devel/pcre2/distinfo                                          1.30-1.32
- devel/pcre2/patches/patch-configure                           1.1

---
   Module Name: pkgsrc
   Committed By:        tnn
   Date:                Sun Sep 27 10:34:46 UTC 2026

   Modified Files:
        pkgsrc/devel/pcre2: Makefile buildlink3.mk distinfo
   Added Files:
        pkgsrc/devel/pcre2/patches: patch-configure

   Log Message:
   pcre2: fix broken symbol versioning test in configure

   Recursive bump will likely be needed.

---
   Module Name: pkgsrc
   Committed By:        wiz
   Date:                Tue Sep 29 05:55:04 UTC 2026

   Modified Files:
        pkgsrc/devel/pcre2: Makefile distinfo

   Log Message:
   pcre2: update to 10.49.

   Version 10.49 28-September-2026
   -------------------------------

   1. (GHSA-r9hj-j2rw-4q3m) Security fix to prevent an out-of-bounds write with
   arbitrary data. Applications are only affected if using the
   pcre2_jit_stack_create() and pcre2_jit_stack_assign() APIs to provide a growable
   JIT stack, and then matching against a pattern with unusually high JIT stack
   usage, such as a large number of capturing groups.

   The implications of an out-of-bounds write could include arbitrary code
   execution.

   The issue is not a regression and affects releases 10.48 and earlier.


To generate a diff of this commit:
cvs rdiff -u -r1.34 -r1.34.2.1 pkgsrc/devel/pcre2/Makefile
cvs rdiff -u -r1.8 -r1.8.2.1 pkgsrc/devel/pcre2/buildlink3.mk
cvs rdiff -u -r1.30 -r1.30.2.1 pkgsrc/devel/pcre2/distinfo
cvs rdiff -u -r0 -r1.1.2.2 pkgsrc/devel/pcre2/patches/patch-configure

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/devel/pcre2/Makefile
diff -u pkgsrc/devel/pcre2/Makefile:1.34 pkgsrc/devel/pcre2/Makefile:1.34.2.1
--- pkgsrc/devel/pcre2/Makefile:1.34    Wed Sep  2 18:51:38 2026
+++ pkgsrc/devel/pcre2/Makefile Sat Oct  3 19:37:16 2026
@@ -1,10 +1,10 @@
-# $NetBSD: Makefile,v 1.34 2026/09/02 18:51:38 wiz Exp $
+# $NetBSD: Makefile,v 1.34.2.1 2026/10/03 19:37:16 bsiegert Exp $
 #
 # NOTE: basically every update will require a recursive bump,
 # otherwise you'll see errors like:
 # /usr/lib/libpcre2-8.so.0: version PCRE2_10.47 required by /usr/lib/libglib-2.0.so.0 not defined
 
-DISTNAME=      pcre2-10.48
+DISTNAME=      pcre2-10.49
 CATEGORIES=    devel
 MASTER_SITES=  ${MASTER_SITE_GITHUB:=PhilipHazel/}
 GITHUB_RELEASE=        ${DISTNAME}

Index: pkgsrc/devel/pcre2/buildlink3.mk
diff -u pkgsrc/devel/pcre2/buildlink3.mk:1.8 pkgsrc/devel/pcre2/buildlink3.mk:1.8.2.1
--- pkgsrc/devel/pcre2/buildlink3.mk:1.8        Wed Sep  2 19:00:41 2026
+++ pkgsrc/devel/pcre2/buildlink3.mk    Sat Oct  3 19:37:16 2026
@@ -1,4 +1,4 @@
-# $NetBSD: buildlink3.mk,v 1.8 2026/09/02 19:00:41 wiz Exp $
+# $NetBSD: buildlink3.mk,v 1.8.2.1 2026/10/03 19:37:16 bsiegert Exp $
 
 BUILDLINK_TREE+=       pcre2
 
@@ -6,7 +6,7 @@ BUILDLINK_TREE+=        pcre2
 PCRE2_BUILDLINK3_MK:=
 
 BUILDLINK_API_DEPENDS.pcre2+=  pcre2>=10.21
-BUILDLINK_ABI_DEPENDS.pcre2+=  pcre2>=10.48
+BUILDLINK_ABI_DEPENDS.pcre2+=  pcre2>=10.48nb1
 BUILDLINK_PKGSRCDIR.pcre2?=    ../../devel/pcre2
 .endif # PCRE2_BUILDLINK3_MK
 

Index: pkgsrc/devel/pcre2/distinfo
diff -u pkgsrc/devel/pcre2/distinfo:1.30 pkgsrc/devel/pcre2/distinfo:1.30.2.1
--- pkgsrc/devel/pcre2/distinfo:1.30    Tue Sep  1 08:59:33 2026
+++ pkgsrc/devel/pcre2/distinfo Sat Oct  3 19:37:16 2026
@@ -1,5 +1,6 @@
-$NetBSD: distinfo,v 1.30 2026/09/01 08:59:33 adam Exp $
+$NetBSD: distinfo,v 1.30.2.1 2026/10/03 19:37:16 bsiegert Exp $
 
-BLAKE2s (pcre2-10.48.tar.gz) = fac788212a947345cb441020b11affc6a025dfb7270151359e15d81353b9442a
-SHA512 (pcre2-10.48.tar.gz) = 7682828c8bf512406f3f1bff773830416e55750bec1cf4bb39a1238f5a61026df71817dbd2dd0fcd72a76fcfb15d7b386a64739b33ad99bad77170652248fa35
-Size (pcre2-10.48.tar.gz) = 2887260 bytes
+BLAKE2s (pcre2-10.49.tar.gz) = d00d7ef4d076667d90150fc2e4e8cb419d893b4d61d5aac73a9b326db7143c65
+SHA512 (pcre2-10.49.tar.gz) = 6cfd9f824837078bea959ea89c1494950987892ec9b8546691b1aa94fde37c60429c4711c55f9a629c8a6a86bb6ebae738b3a0ebf6e42c70ab008ec6c394aca0
+Size (pcre2-10.49.tar.gz) = 2880625 bytes
+SHA1 (patch-configure) = 9069921c895a57ad072f7c1564f34b173a144d63

Added files:

Index: pkgsrc/devel/pcre2/patches/patch-configure
diff -u /dev/null pkgsrc/devel/pcre2/patches/patch-configure:1.1.2.2
--- /dev/null   Sat Oct  3 19:37:16 2026
+++ pkgsrc/devel/pcre2/patches/patch-configure  Sat Oct  3 19:37:16 2026
@@ -0,0 +1,40 @@
+$NetBSD: patch-configure,v 1.1.2.2 2026/10/03 19:37:16 bsiegert Exp $
+
+Fix missing symbol versioning:
+
+Don't let CONFIGURE_ENV override libtool's internal CP/MV/RM.
+pkgsrc exports RM as "/bin/rm" but these tests really need "rm -f" because
+of how they are written.
+
+When creating a soname symlink the generated libtool runs
+$RM "$linkname" && $LN_S "$realname" "$linkname"
+which fails because $linkname does not exist yet.
+
+PCRE2_CHECK_VSCRIPT links a shared library to probe for
+-Wl,--version-script and the probe fails due to rm without -f even though
+the link itself succeeded. Symbol versioning is then silently dropped and
+configure says "with symbol versioning : n/a" rather than "yes".
+
+The root cause is in libtool and a similar issue was reported
+upstream in 2010:
+
+https://lists.gnu.org/archive/html/bug-libtool/2010-03/msg00017.html
+
+--- configure.orig     2026-08-31 13:49:04.000000000 +0000
++++ configure
+@@ -6335,9 +6335,12 @@ max_cmd_len=$lt_cv_sys_max_cmd_len
+ 
+ 
+ 
+-: ${CP="cp -f"}
+-: ${MV="mv -f"}
+-: ${RM="rm -f"}
++: ${CP="cp"}
++: ${MV="mv"}
++: ${RM="rm"}
++CP="${CP} -f"
++MV="${MV} -f"
++RM="${RM} -f"
+ 
+ if ( (MAIL=60; unset MAIL) || exit) >/dev/null 2>&1; then
+   lt_unset=unset



Home | Main Index | Thread Index | Old Index