pkgsrc-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
pkg/60821: editors/xwpe: update to 1.6.9
>Number: 60821
>Category: pkg
>Synopsis: editors/xwpe: update to 1.6.9
>Confidential: no
>Severity: non-critical
>Priority: medium
>Responsible: pkg-manager
>State: open
>Class: change-request
>Submitter-Id: net
>Arrival-Date: Tue Sep 29 03:15:01 +0000 2026
>Originator: Showta Ishizaki
>Release: pkgsrc-current
>Organization:
>Environment:
System: NetBSD 11.0 amd64
Architecture: x86_64
Machine: amd64
>Description:
editors/xwpe is at 1.5.30a, the last release from
identicalsoftware.com. Development picked up again this year
at https://codeberg.org/mendezr/xwpe, by the person who uploads
the Debian package, and 1.6.9 is current.
The build moved to autotools, so patch-aa (DESTDIR) is gone,
and upstream now ships its own desktop file, an SVG icon, a
metainfo file and a Texinfo manual, so files/ and the
post-install target go too. It needs GNU make (automake's
dependency tracking), json-c, and a wide-character curses, for
which it looks for get_wch; mk/curses.buildlink3.mk says a
package that needs ncurses should say so, so this does. With
INFO_FILES set, --infodir reaches configure and the manual
lands in info/.
None of the nine patches keeps its contents. Six are in 1.6.9
or made moot by autotools. The three that silenced compiler
diagnostics -- WeXterm.c, we_prog.c and we_xterm.c -- are
covered by -Wno-incompatible-pointer-types and
-Wno-implicit-function-declaration, which upstream now passes
in Makefile.am, and 1.6.9 builds without them under both gcc
12.5.0 and clang 21.1.8. Eight of the files go; the ninth,
patch-we__xterm.c, keeps its name because one of the new fixes
is in that same source file.
Five new patches, all for upstream defects. configure calls
Xft and Cairo optional, but the tree does not compile with X11
and no Xft (WeXterm.h declares the X11 back buffer inside
#ifdef HAVE_XFT; twelve uses in three files sit outside it),
does not link with X11 and no Cairo (we_render.h picks stub
hit-tests on NO_XWINDOWS while the real ones live in a file
compiled only under HAVE_CAIRO), and includes execinfo.h
unconditionally while configure only looks for the library.
Each patch says which.
x11 and xft are options, both on by default. Without x11 the
two X-named symlinks are not made, so they moved to PLIST.x11;
the rest of the PLIST is the same either way. xft is only
looked at when x11 is on, since configure only checks for it
then.
>How-To-Repeat:
Not a bug report; the current package builds.
>Fix:
The diff is against pkgsrc-current of 2026-09-29 (Makefile
1.19, distinfo 1.11, PLIST 1.4). Files appear and disappear;
they are named at the end.
Tried on NetBSD 11.0/amd64 against pkgsrc-current, with the
dependencies from the x86_64/11.0 binary set, in all four
combinations of the two options under both gcc 12.5.0 and clang
21.1.8. Each one installs, makes a package, and over a pty
opens a file, takes typed text, saves it with F2 and leaves on
Alt-X. The same, with the default options and with both off,
on NetBSD 9.4 and 10.1 amd64, and with the default options on
FreeBSD 14.4; and with both off on OpenBSD 7.9 amd64,
DragonFly 6.4, GhostBSD 26.1, Debian 13, Fedora 44 and macOS
26 (arm64).
The diff also adds a commented-out line to
doc/pkg-vulnerabilities. NVD carries CVE-2016-20037 against
"xwpe 1.5.30a-2.1 and prior", which is the version in the tree,
and the file has no xwpe line at all -- so the next person to
look finds nothing and starts from scratch, as I did. The CVE
itself is rejected: Debian's security tracker notes it as
"Bogus CVE assignment for xwpe", and upstream's CHANGELOG says
the same, that no vulnerable code path exists in argv handling,
while converting the sprintf calls that take a filename to
snprintf as defence in depth. 1.6.9 does fix a real overflow
found along the way -- a long LIBNAME= from a .prj copied into
a fixed library[80] with strcpy -- which has no CVE. So the
line goes in disabled, with the reason on it, in the shape the
file already uses for the other rejected and disputed ones.
New files: options.mk, PLIST.x11, and the patches
patch-WeXterm.h, patch-we__debug.c, patch-we__render.h and
patch-we__unix.c. Files that go, since a patch cannot remove
them: patch-WeXterm.c, patch-aa, patch-ab, patch-edit.h,
patch-we__fl__unix.c, patch-we__main.c, patch-we__prog.c and
patch-we__term.c under patches/, and files/xwpe.desktop and
files/xwpe.xpm.
--- editors/xwpe/Makefile.orig
+++ editors/xwpe/Makefile
@@ -1,35 +1,50 @@
# $NetBSD: Makefile,v 1.19 2025/06/02 12:54:30 vins Exp $
-#
-DISTNAME= xwpe-1.5.30a
-PKGREVISION= 1
+DISTNAME= xwpe-1.6.9
CATEGORIES= editors
-MASTER_SITES= http://www.identicalsoftware.com/xwpe/
+MASTER_SITES= ${MASTER_SITE_CODEBERG:=mendezr/xwpe/releases/download/v${PKGVERSION_NOREV}/}
MAINTAINER= vins%NetBSD.org@localhost
-HOMEPAGE= http://www.identicalsoftware.com/xwpe/
+HOMEPAGE= https://codeberg.org/mendezr/xwpe
COMMENT= Programming environment for UNIX systems
LICENSE= gnu-gpl-v2
GNU_CONFIGURE= yes
+# automake's dependency tracking needs GNU make. With bmake, config.status
+# stops in the depfiles step:
+#
+# config.status: error: Something went wrong bootstrapping makefile
+# fragments for automatic dependency tracking.
+#
+# 1.5.30a did not need this; its Makefile.in was hand-written.
+USE_TOOLS+= pkg-config gmake
-BUILD_TARGET= # the one from the Makefile
+# docs/Makefile.am has info_TEXINFOS, so an info file is installed.
+# Without INFO_FILES, mk/configure/gnu-configure.mk does not pass
+# --infodir at all -- the line is inside .if defined(INFO_FILES) --
+# so automake falls back to its own ${datarootdir}/info and the file
+# lands in share/info, with an unregistered dir file beside it.
+INFO_FILES= yes
-BUILDLINK_DEPMETHOD.libXt?= build
+# configure defaults both of these to "auto", so what gets built depends on
+# what happens to be installed on the build host. Pin them, or the PLIST
+# stops matching.
+CONFIGURE_ARGS+= --without-wayland
+CONFIGURE_ARGS+= --without-gpm
-INSTALLATION_DIRS+= share/applications
-INSTALLATION_DIRS+= share/pixmaps
+# The install-data-hook also renders PNG icons from the SVG when
+# rsvg-convert is available. Nothing here depends on librsvg, so it does
+# not run, but adding such a dependency would change the PLIST silently.
-post-install:
- ${INSTALL_DATA} ${FILESDIR}/xwpe.desktop \
- ${DESTDIR}${PREFIX}/share/applications
- ${INSTALL_DATA} ${FILESDIR}/xwpe.xpm \
- ${DESTDIR}${PREFIX}/share/pixmaps
+.include "options.mk"
.include "../../sysutils/desktop-file-utils/desktopdb.mk"
-.include "../../x11/libSM/buildlink3.mk"
-.include "../../x11/libX11/buildlink3.mk"
-.include "../../x11/libXt/buildlink3.mk"
+.include "../../graphics/hicolor-icon-theme/buildlink3.mk"
+.include "../../textproc/json-c/buildlink3.mk"
.include "../../devel/zlib/buildlink3.mk"
-.include "../../mk/curses.buildlink3.mk"
+
+# configure requires wide-character curses (it looks for get_wch) and stops
+# without it. mk/curses.buildlink3.mk says a package that genuinely needs
+# ncurses should include its buildlink3.mk directly, so do that.
+.include "../../devel/ncurses/buildlink3.mk"
.include "../../mk/bsd.pkg.mk"
--- editors/xwpe/distinfo.orig
+++ editors/xwpe/distinfo
@@ -1,14 +1,10 @@
$NetBSD: distinfo,v 1.11 2025/06/02 12:54:30 vins Exp $
-BLAKE2s (xwpe-1.5.30a.tar.gz) = 5e33b6cb1880b38dbf551138e807b18a952d282a41411704ada6fabdb34680d4
-SHA512 (xwpe-1.5.30a.tar.gz) = c5b182f798caeeaa7ba62bd3692690030623d317795d907e4fac3f524f53aa299af5d735d9b03185eaa07526f0146c4fa8d09efbbab6790f5e329fd52359b797
-Size (xwpe-1.5.30a.tar.gz) = 325043 bytes
-SHA1 (patch-WeXterm.c) = d60a373aafdcc586aad27f25d82b2af53e318e6b
-SHA1 (patch-aa) = cf7bc074e1dc8cda086dfe29ebfdca1c0f261c1d
-SHA1 (patch-ab) = c59dc6c530bbe21e0c22f2c258745ecb7730b156
-SHA1 (patch-edit.h) = 8fa47ec3d81a761a9c70e4ead6ab182b9c3eccb4
-SHA1 (patch-we__fl__unix.c) = 076a4dc92297ae8d13213ddaddc02c24b716851d
-SHA1 (patch-we__main.c) = 5112e6ce7ab4c11afd230f4709fcf1c6ed702fc0
-SHA1 (patch-we__prog.c) = e6de61bc04cf803e722c8f1ec596bb2f29be9693
-SHA1 (patch-we__term.c) = efaf0cdaa21d0370344cd8e89766265e8f9e6e23
-SHA1 (patch-we__xterm.c) = 5b63e0df612ffdff64838d1faf5b558d9179b3dc
+BLAKE2s (xwpe-1.6.9.tar.gz) = e516899d33478e864ef64f8889438e5415f7b94ef978c3642f86fe9e0f9a1e5c
+SHA512 (xwpe-1.6.9.tar.gz) = 9bac04ae59fd084e747be313cddd345b29336b4abb96fafe8664b8cef3749c93f364e4fc7187eee2fa5b2f0aa2a54c211358fafcfc5a158614062a75542c1b43
+Size (xwpe-1.6.9.tar.gz) = 1268565 bytes
+SHA1 (patch-WeXterm.h) = 72e441a1de5755ae266e79353368699ea0799ad0
+SHA1 (patch-we__debug.c) = 5c16f98b48e95c9f26442e27d94dd5337df45b31
+SHA1 (patch-we__render.h) = b5fcd8a7d25a25ed7920227c69e980e56b9790d1
+SHA1 (patch-we__unix.c) = 55f846e296a3037fedd1222b47c78f403b72d83e
+SHA1 (patch-we__xterm.c) = 0b9805f915be55faeeacfb8bade02a80f799a7f8
--- editors/xwpe/PLIST.orig
+++ editors/xwpe/PLIST
@@ -1,8 +1,7 @@
@comment $NetBSD: PLIST,v 1.4 2022/12/08 08:51:55 vins Exp $
bin/we
bin/wpe
-bin/xwe
-bin/xwpe
+info/xwpe.info
lib/xwpe/help.key
lib/xwpe/help.xwpe
lib/xwpe/syntax_def
@@ -11,4 +10,5 @@
man/man1/xwe.1
man/man1/xwpe.1
share/applications/xwpe.desktop
-share/pixmaps/xwpe.xpm
+share/icons/hicolor/scalable/apps/xwpe.svg
+share/metainfo/io.codeberg.mendezr.xwpe.metainfo.xml
--- editors/xwpe/options.mk.orig
+++ editors/xwpe/options.mk
@@ -0,0 +1,51 @@
+# $NetBSD$
+
+PKG_OPTIONS_VAR= PKG_OPTIONS.xwpe
+PKG_SUPPORTED_OPTIONS= x11 xft
+PKG_SUGGESTED_OPTIONS= x11 xft
+
+.include "../../mk/bsd.options.mk"
+
+PLIST_SRC+= PLIST
+
+# Without X, install-exec-hook does not make the two X-named symlinks, so
+# they cannot stay in the base PLIST:
+#
+# pkg_create: can't stat .../bin/xwe
+# pkg_create: can't stat .../bin/xwpe
+#
+# bin/we and bin/wpe are made either way, and so are the four man pages,
+# the desktop file, the icon and the metainfo.
+.if !empty(PKG_OPTIONS:Mx11)
+PLIST_SRC+= PLIST.x11
+BUILDLINK_DEPMETHOD.libXt?= build
+.include "../../x11/libSM/buildlink3.mk"
+.include "../../x11/libX11/buildlink3.mk"
+.include "../../x11/libXt/buildlink3.mk"
+# WeXterm.h includes <X11/extensions/sync.h> and the struct holds an
+# XSyncCounter, so libXext is a hard requirement of the X11 build. On
+# NetBSD it was found in /usr/X11R7/include, outside the buildlink
+# directory, so nothing complained; on a platform whose X comes from
+# pkgsrc the header is simply not there:
+#
+# ./WeXterm.h:22:10: fatal error: 'X11/extensions/sync.h' file not found
+.include "../../x11/libXext/buildlink3.mk"
+.else
+CONFIGURE_ARGS+= --without-x
+.endif
+
+# Xft is optional, as configure says, but the tree as shipped does not
+# compile without it: WeXterm.h declares WpeXInfo.backbuf only inside
+# #ifdef HAVE_XFT, and twelve uses in three files (we_debug.c,
+# we_xterm.c, we_render_cairo.c) sit outside that guard. backbuf is not
+# an Xft object -- the Cairo backend creates it in cr_resize() and draws
+# into it -- so patch-WeXterm.h moves the declaration out, and
+# patch-we__debug.c and patch-we__xterm.c handle the two Expose paths
+# that have nothing to copy from when neither backend is in. Reported
+# upstream.
+#
+# Xft needs X: configure only looks for it when have_x11 is yes, so
+# without x11 this option cannot do anything.
+.if !empty(PKG_OPTIONS:Mxft) && !empty(PKG_OPTIONS:Mx11)
+.include "../../x11/libXft/buildlink3.mk"
+.endif
--- editors/xwpe/PLIST.x11.orig
+++ editors/xwpe/PLIST.x11
@@ -0,0 +1,3 @@
+@comment $NetBSD$
+bin/xwe
+bin/xwpe
--- editors/xwpe/patches/patch-WeXterm.h.orig
+++ editors/xwpe/patches/patch-WeXterm.h
@@ -0,0 +1,37 @@
+$NetBSD$
+
+backbuf is not an Xft object. The Cairo backend creates it itself, in
+cr_resize(), and draws into it; Xft only happens to be the other user.
+Declaring it inside #ifdef HAVE_XFT breaks every build that has X11 but
+not Xft, at twelve sites in three files:
+
+ we_debug.c:1269
+ we_xterm.c:1090, 1269, 1283
+ we_render_cairo.c:160, 178, 188, 190, 196, 203, 215, 271
+
+ we_debug.c:1269:41: error: 'WpeXStruct' has no member named 'backbuf'
+
+configure calls both Xft and Cairo optional, so X11 with neither, and
+X11 with Cairo but no Xft, are both configurations it offers. Moving
+the one line out is enough for the eight Cairo sites; the other four
+need a runtime check as well, since with neither backend nothing
+creates the pixmap.
+
+--- WeXterm.h.orig
++++ WeXterm.h
+@@ -53,12 +53,14 @@
+ int colors[16];
+ WpeMouseShape shape_list[2];
+ char *selection;
++ Pixmap backbuf; /* the X11 back buffer: Xft draws into it, and so
++ does the Cairo backend, which creates it itself
++ in cr_resize(). It is not an Xft object. */
+ #ifdef HAVE_XFT
+ XftFont *xftfont;
+ XftDraw *xftdraw;
+ XftColor xftcolors[24]; /* 16 base + up to 8 LSP truecolor slots (we_lsp.h
+ LSP_SEM_TC_MAX): a fg index 16+slot picks a slot */
+- Pixmap backbuf;
+ FcPattern *xftpattern;
+ FcFontSet *xftfont_set;
+ #endif
--- editors/xwpe/patches/patch-we__debug.c.orig
+++ editors/xwpe/patches/patch-we__debug.c
@@ -0,0 +1,34 @@
+$NetBSD$
+
+With neither Xft nor Cairo there is no back buffer, so this Expose
+handler has nothing to copy from. Repaint the area instead, which is
+what we_xterm.c does at its own Expose case.
+
+See patch-WeXterm.h for why backbuf itself moved.
+
+--- we_debug.c.orig
++++ we_debug.c
+@@ -1266,10 +1266,19 @@
+ }
+ else if (_ev.type == Expose)
+ {
+- XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
+- WpeXInfo.gc, _ev.xexpose.x, _ev.xexpose.y,
+- _ev.xexpose.width, _ev.xexpose.height,
+- _ev.xexpose.x, _ev.xexpose.y);
++ if (WpeXInfo.backbuf)
++ XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
++ WpeXInfo.gc, _ev.xexpose.x, _ev.xexpose.y,
++ _ev.xexpose.width, _ev.xexpose.height,
++ _ev.xexpose.x, _ev.xexpose.y);
++ else
++ {
++ e_refresh_area(_ev.xexpose.x / WpeXInfo.font_width,
++ _ev.xexpose.y / WpeXInfo.font_height,
++ _ev.xexpose.width / WpeXInfo.font_width + 2,
++ _ev.xexpose.height / WpeXInfo.font_height + 2);
++ e_refresh();
++ }
+ }
+ }
+ }
--- editors/xwpe/patches/patch-we__render.h.orig
+++ editors/xwpe/patches/patch-we__render.h
@@ -0,0 +1,26 @@
+$NetBSD$
+
+X11 without Cairo does not link. The no-op stubs are chosen on
+NO_XWINDOWS, but the real ones live in we_render_cairo.c, whose whole
+body sits inside #ifdef HAVE_CAIRO / #ifdef HAVE_PANGO -- and configure
+calls both of those optional. So an X11 build with no Cairo takes the
+#else branch, declares the two functions, and nothing defines them:
+
+ we_mouse.c:(.text+0xd8e): undefined reference to `wpe_chrome_hit_vthumb'
+ we_mouse.c:(.text+0x2931): undefined reference to `wpe_chrome_hit_hthumb'
+
+we_mouse.c calls them from plain #if MOUSE code, which is why every X11
+build reaches them. Pick the stubs on what actually decides whether
+we_render_cairo.c is compiled.
+
+--- we_render.h.orig
++++ we_render.h
+@@ -49,7 +49,7 @@
+
+ int wpe_render_cairo_init(void);
+ void wpe_render_chrome(void);
+-#ifdef NO_XWINDOWS
++#if defined(NO_XWINDOWS) || !defined(HAVE_CAIRO) || !defined(HAVE_PANGO)
+ /* The Cairo chrome (the fluid scrollbar thumb) is X11-only; with no X11 there
+ is no chrome, so these hit-tests can never match. Inline no-op stubs let the
+ shared mouse code (we_mouse.c) link in a --without-x build, where
--- editors/xwpe/patches/patch-we__unix.c.orig
+++ editors/xwpe/patches/patch-we__unix.c
@@ -0,0 +1,55 @@
+$NetBSD$
+
+execinfo.h is included unconditionally, but configure only ever looks for
+the backtrace() library:
+
+ configure.ac:204 AC_SEARCH_LIBS([backtrace], [execinfo], ...)
+
+Nothing defines or tests HAVE_EXECINFO_H, so a system with the library but
+no header -- or with neither -- stops at the include:
+
+ we_unix.c:26:10: fatal error: 'execinfo.h' file not found
+
+__has_include keeps the test in the source, so configure does not have to be
+regenerated. The crash handler simply writes no backtrace where the
+facility is missing.
+
+--- we_unix.c.orig
++++ we_unix.c
+@@ -23,7 +23,23 @@
+ #include <sys/wait.h>
+ #include <dirent.h>
+ #include <signal.h>
++/*
++ * configure looks for the backtrace() *library* (AC_SEARCH_LIBS) but never
++ * for the header, and nothing defines or tests HAVE_EXECINFO_H, so this
++ * include is unconditional. On a system without execinfo.h the build stops
++ * here. __has_include keeps the test in the source, where it does not need
++ * configure to be regenerated.
++ */
++#if defined(__has_include)
++# if __has_include(<execinfo.h>)
++# define WPE_HAVE_EXECINFO 1
++# endif
++#elif defined(__GLIBC__)
++# define WPE_HAVE_EXECINFO 1
++#endif
++#ifdef WPE_HAVE_EXECINFO
+ #include <execinfo.h>
++#endif
+ #include <fcntl.h>
+ #include <unistd.h>
+ #include <locale.h>
+@@ -437,8 +453,12 @@
+
+ len = snprintf(line, sizeof(line), "CRASH: signal %d\n", sig);
+ write(fd, line, len);
++#ifdef WPE_HAVE_EXECINFO
+ n = backtrace(bt, 32);
+ backtrace_symbols_fd(bt, n, fd);
++#else
++ (void)bt; (void)n;
++#endif
+ len = snprintf(line, sizeof(line), "MAXSLNS=%d MAXSCOL=%d\n", MAXSLNS, MAXSCOL);
+ write(fd, line, len);
+ close(fd);
--- editors/xwpe/patches/patch-we__xterm.c.orig
+++ editors/xwpe/patches/patch-we__xterm.c
@@ -1,15 +1,47 @@
$NetBSD: patch-we__xterm.c,v 1.1 2022/12/08 08:51:56 vins Exp $
-Fix warning about incompatible pointer type.
+With neither Xft nor Cairo there is no back buffer, so these three
+whole-window blits after a resize have nothing to copy from. The
+repaint that follows (e_relayout_windows, e_x_repaint_desk) is what
+draws in that case.
---- we_xterm.c.orig 2005-07-07 01:53:09.000000000 +0000
+See patch-WeXterm.h for why backbuf itself moved.
+
+--- we_xterm.c.orig
+++ we_xterm.c
-@@ -95,7 +95,7 @@ int WpeDllInit(int *argc, char **argv)
- e_u_ini_size = e_ini_size;
- e_u_setlastpic = e_setlastpic;
- WpeMouseChangeShape = (void (*)(WpeMouseShape))WpeNullFunction;
-- WpeMouseRestoreShape = (void (*)(WpeMouseShape))WpeNullFunction;
-+ WpeMouseRestoreShape = WpeNullFunction;
- /* WpeMouseChangeShape = WpeXMouseChangeShape;
- WpeMouseRestoreShape = WpeXMouseRestoreShape;*/
- WpeDisplayEnd = WpeNullFunction;
+@@ -1087,8 +1087,9 @@
+ { int _pw, _ph, _old_scol, _old_slns;
+ if (e_x_apply_configure(&report, &_pw, &_ph, &_old_scol, &_old_slns))
+ {
+- XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
+- WpeXInfo.gc, 0, 0, _pw, _ph, 0, 0);
++ if (WpeXInfo.backbuf)
++ XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
++ WpeXInfo.gc, 0, 0, _pw, _ph, 0, 0);
+ e_relayout_windows(WpeEditor, _old_scol, _old_slns);
+ e_x_repaint_desk(WpeEditor->f[WpeEditor->mxedt]);
+ }
+@@ -1266,8 +1267,9 @@
+ { int _i, _pw, _ph, _old_scol, _old_slns;
+ if (e_x_apply_configure(&report, &_pw, &_ph, &_old_scol, &_old_slns))
+ {
+- XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
+- WpeXInfo.gc, 0, 0, _pw, _ph, 0, 0);
++ if (WpeXInfo.backbuf)
++ XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
++ WpeXInfo.gc, 0, 0, _pw, _ph, 0, 0);
+ XFlush(WpeXInfo.display);
+
+ /* If the last-view pic is not a live window's, drop it: the grid (and so
+@@ -1280,8 +1282,9 @@
+ if (!_is_win_pic)
+ (*e_u_setlastpic)(NULL);
+ }
+- XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
+- WpeXInfo.gc, 0, 0, _pw, _ph, 0, 0);
++ if (WpeXInfo.backbuf)
++ XCopyArea(WpeXInfo.display, WpeXInfo.backbuf, WpeXInfo.window,
++ WpeXInfo.gc, 0, 0, _pw, _ph, 0, 0);
+ e_relayout_windows(WpeEditor, _old_scol, _old_slns);
+ e_x_repaint_desk(WpeEditor->f[WpeEditor->mxedt]);
+ return WPE_RESIZE;
--- doc/pkg-vulnerabilities.orig
+++ doc/pkg-vulnerabilities
@@ -30454,3 +30454,4 @@
ruby{33,34,40}-zip<3.4.0 path-traversal https://www.cve.org/CVERecord?id=CVE-2026-85396
ruby{33,34,40}-zip24-[0-9]* path-traversal https://www.cve.org/CVERecord?id=CVE-2026-85396
ruby{33,34}-faraday1<1.10.5 server-side-request-forgery https://nvd.nist.gov/vuln/detail/CVE-2026-25765
+#xwpe-[0-9]* stack-overflow https://nvd.nist.gov/vuln/detail/CVE-2016-20037 # rejected, bogus CVE assignment; see https://security-tracker.debian.org/tracker/CVE-2016-20037
Home |
Main Index |
Thread Index |
Old Index