pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/mail/thunderbird



Module Name:    pkgsrc
Committed By:   ryoon
Date:           Wed Jul 22 15:46:01 UTC 2026

Modified Files:
        pkgsrc/mail/thunderbird: Makefile distinfo
        pkgsrc/mail/thunderbird/patches: patch-python_sites_mach.txt
Removed Files:
        pkgsrc/mail/thunderbird/patches:
            patch-comm_build_moz.configure_gecko__source.configure

Log Message:
mail/thunderbird: Update to 152.0.1

Changelog:
152.0.1:
What's Fixed

fixed
Reply All button was missing for some EWS messages with multiple recipients

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2026-63
#CVE-2026-57962: Denial-of-service via malicious LDAP address-book server
#CVE-2026-57963: Chat UI manipulation by injection

152.0:
What's New

new
SecurityDevices enabled in enterprise policies

new
One-click account setup for Thundermail accounts

What's Changed

changed
Use 'Add' instead of 'New' for account, calendar, address book creation buttons

changed
GMail OAuth updated to use PKCE

changed
Mail server hostname also checked when detecting address books and calendars

changed
Updated about:rights to replace local with hosted url

changed
'Hide completed tasks' now also hides cancelled tasks

What's Fixed

fixed
New mail alerts appeared on wrong monitor in three-monitor setup

fixed
Spam messages triggered new mail notifications before being moved to Spam
folder

fixed
Filtered IMAP or NNTP subscriptions were lost after closing Subscribe dialog

fixed
'Download Headers' dialog for newsgroups failed to open

fixed
Messages nested deeper than 255 levels disappeared from threading view

fixed
Performing Delete followed by Undo on thread parent message could corrupt view

fixed
Single messages still appeared collapsible after thread members were deleted

fixed
Updated threads remained misordered until folder refresh or resort

fixed
Non-threaded subject sorting separated 'RE:' replies from original messages

fixed
BCC recipients were included in signed email headers

fixed
Filter search on Body missed draft messages containing German umlauts

fixed
Thunderbird could crash during local message search

fixed
Blocked file warning showed without 'Unblock File' button in compose window

fixed
Forwarding/Redirecting Exchange messages failed with NS_ERROR_OUT_OF_MEMORY

fixed
Compose window closed early and send progress dialog hung after NNTP failure

fixed
Compose window stayed open after sending when mailnews.sendInBackground set

fixed
Microsoft OAuth2 failed when HTTPS localhost redirect was not intercepted

fixed
Pasting contact photos stopped working when photo button had focus

fixed
Filter dialog lacked focus ring and had poorly distinguishable buttons

fixed
Subfolder kept stale accessibility unread count after unread messages were
deleted

fixed
'Edit as New Message' and inline 'Forward' not possible with PGP-signed
messages

fixed
Various MIME improvements

fixed
EWS messages could go missing from folder view

fixed
IMAP "Show only subscribed folders" could not be changed without restart

fixed
Unable to delete more than 1000 messages at a time on Microsoft 365

fixed
EWS folders in Trash were moved to Trash again instead of being hard deleted

fixed
IMAP notifications repeated for emails read on another device after sleep wake

fixed
POP3 deadlocked when server went silent without closing socket

fixed
Calendar acceptance no longer distinguished between single occurrence and
series

fixed
Transparent popups on macOS made calendar event editing difficult

fixed
Duplicate attendees were added to invitations instead of being filtered out

fixed
Task percentage complete was not preserved separately from status in tooltips

fixed
Visual and UX improvements

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2026-60
#CVE-2026-12289: Privilege escalation in the Graphics: WebRender component
#CVE-2026-12290: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12291: Use-after-free in the Networking: HTTP component
#CVE-2026-12292: Incorrect boundary conditions in the Web Audio component
#CVE-2026-12293: Use-after-free in the Graphics: WebGPU component
#CVE-2026-12294: Sandbox escape in the DOM: Workers component
#CVE-2026-12295: Sandbox escape in the DOM: Navigation component
#CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component
#CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the
 Networking component
#CVE-2026-12298: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component
#CVE-2026-12300: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12301: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12302: Mitigation bypass in the DOM: Security component
#CVE-2026-12303: Information disclosure due to incorrect boundary conditions in
#CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component
#CVE-2026-12305: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12306: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12307: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12308: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12309: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12310: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12311: Information disclosure, sandbox escape in the Security:
 Process Sandboxing component
#CVE-2026-12312: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12313: Information disclosure, sandbox escape in the Security:
 Process Sandboxing component
#CVE-2026-12314: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12315: Mitigation bypass in the DOM: Security component
#CVE-2026-12316: Mitigation bypass in the DOM: Security component
#CVE-2026-12317: Memory safety bug fixed in Thunderbird 152
#CVE-2026-12318: Incorrect boundary conditions in the Libraries component in
 NSS
#CVE-2026-12319: Denial-of-service in the Audio/Video: Playback component
#CVE-2026-12320: Information disclosure in the Password Manager component
#CVE-2026-12321: JIT miscompilation in the JavaScript: WebAssembly component
#CVE-2026-12322: Clickjacking issue in the Widget: Gtk component
#CVE-2026-12323: Spoofing issue in the DOM: Core & HTML component
#CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL
 component
#CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component
#CVE-2026-12326: Memory safety bugs fixed in Firefox 152 and Thunderbird 152
#CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird
 ESR 140.12, Firefox 152 and Thunderbird 152
#CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR
 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152


To generate a diff of this commit:
cvs rdiff -u -r1.363 -r1.364 pkgsrc/mail/thunderbird/Makefile
cvs rdiff -u -r1.296 -r1.297 pkgsrc/mail/thunderbird/distinfo
cvs rdiff -u -r1.1 -r0 \
    pkgsrc/mail/thunderbird/patches/patch-comm_build_moz.configure_gecko__source.configure
cvs rdiff -u -r1.1 -r1.2 \
    pkgsrc/mail/thunderbird/patches/patch-python_sites_mach.txt

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/mail/thunderbird/Makefile
diff -u pkgsrc/mail/thunderbird/Makefile:1.363 pkgsrc/mail/thunderbird/Makefile:1.364
--- pkgsrc/mail/thunderbird/Makefile:1.363      Mon Jul 13 04:36:11 2026
+++ pkgsrc/mail/thunderbird/Makefile    Wed Jul 22 15:46:00 2026
@@ -1,9 +1,8 @@
-# $NetBSD: Makefile,v 1.363 2026/07/13 04:36:11 wiz Exp $
+# $NetBSD: Makefile,v 1.364 2026/07/22 15:46:00 ryoon Exp $
 
 DISTNAME=      thunderbird-${TB_VER}.source
 PKGNAME=       thunderbird-${TB_VER:S/esr//}
-PKGREVISION=   2
-TB_VER=                151.0.1
+TB_VER=                152.0.1
 CATEGORIES=    mail
 MASTER_SITES=  ${MASTER_SITE_MOZILLA:=thunderbird/releases/${TB_VER}/source/}
 EXTRACT_SUFX=  .tar.xz

Index: pkgsrc/mail/thunderbird/distinfo
diff -u pkgsrc/mail/thunderbird/distinfo:1.296 pkgsrc/mail/thunderbird/distinfo:1.297
--- pkgsrc/mail/thunderbird/distinfo:1.296      Sat Jun  6 14:51:30 2026
+++ pkgsrc/mail/thunderbird/distinfo    Wed Jul 22 15:46:00 2026
@@ -1,13 +1,12 @@
-$NetBSD: distinfo,v 1.296 2026/06/06 14:51:30 ryoon Exp $
+$NetBSD: distinfo,v 1.297 2026/07/22 15:46:00 ryoon Exp $
 
-BLAKE2s (thunderbird-151.0.1.source.tar.xz) = 5d048eb19e4698ddee169d0f998798fe5efbc4659182beaba092c7f51842efaa
-SHA512 (thunderbird-151.0.1.source.tar.xz) = a09c1e18faa8d7fdccf39e905542c21e817230e68c7cc6050beec048d0fec0f8eb92e51278d2ccd8d8cfa842762662235517e20238b555a4ad48ee5648dc3589
-Size (thunderbird-151.0.1.source.tar.xz) = 917255144 bytes
+BLAKE2s (thunderbird-152.0.1.source.tar.xz) = 5b97fd14b612319e48de5f2c1b9170f96f662626c6fdb6da10d238b422ebc900
+SHA512 (thunderbird-152.0.1.source.tar.xz) = f66c87de4dd73c3c45e420a55d76c3cb6ac091a61794ccf58ba59d1a40cf8001dee19a6a7f4c6bef7d36ea94ed4e4f677449d3006b2004abbd3fab42ad1c9228
+Size (thunderbird-152.0.1.source.tar.xz) = 936225660 bytes
 SHA1 (patch-browser_app_profile_firefox.js) = 1eaa674c0aa8279e2f9dc2eda582650a08156d65
 SHA1 (patch-build_gn__processor.py) = 078f773104bf4c1b30584564aefe365db6ba6daf
 SHA1 (patch-build_moz.configure_init.configure) = 65deb3c233df0aab81eb1fca05d708e5a4ed169a
 SHA1 (patch-build_moz.configure_rust.configure) = 25ddfacd29cebbc6db005dbe61a2a7446d480678
-SHA1 (patch-comm_build_moz.configure_gecko__source.configure) = ce7b668d632d6bad71bf97b14d237eacfb6bb6ab
 SHA1 (patch-comm_mailnews_compose_src_nsMsgCompUtils.cpp) = c3e38828803536879baf2934aa1bfa50cfba0112
 SHA1 (patch-comm_mailnews_search_src_nsMsgSearchNews.cpp) = 84624c6752de1f56848a202b3a2179a2d8098e4e
 SHA1 (patch-comm_third__party_libgcrypt_configure) = c5ca8a8b44c485f81139b54d341ac044189d98d3
@@ -42,7 +41,7 @@ SHA1 (patch-netwerk_protocol_http_nsHttp
 SHA1 (patch-nsprpub_pr_src_pthreads_ptsynch.c) = 753fd4d62088c870aefe7c4b739286259848446e
 SHA1 (patch-python_mozbuild_mozbuild_backend_recursivemake.py) = 5be4183d9075f5a3a3c6b3e0338473af185fb50e
 SHA1 (patch-python_sites_build.txt) = f60f28480179edb47c8dcf84e3247aa6704c2610
-SHA1 (patch-python_sites_mach.txt) = a4950e1b5ad66231b723eef8f9e7ecce9127d9d3
+SHA1 (patch-python_sites_mach.txt) = f1568a4a7e65a6811e97f8c9c76148c9cdb7e02a
 SHA1 (patch-security_nss_lib_freebl_mpi_mpi.c) = 6cac13bc120d52b2c3628938d2fc1cba628b3a31
 SHA1 (patch-third__party_abseil-cpp_absl_debugging_internal_elf__mem__image.cc) = cc68e46f1b98bbcc064a4c61fc96a3c7ede8e6ba
 SHA1 (patch-third__party_abseil-cpp_absl_debugging_internal_vdso__support.cc) = f9c44d0d6fd952296f23c24f56053958b30d8e5c

Index: pkgsrc/mail/thunderbird/patches/patch-python_sites_mach.txt
diff -u pkgsrc/mail/thunderbird/patches/patch-python_sites_mach.txt:1.1 pkgsrc/mail/thunderbird/patches/patch-python_sites_mach.txt:1.2
--- pkgsrc/mail/thunderbird/patches/patch-python_sites_mach.txt:1.1     Sat Jun  6 14:51:30 2026
+++ pkgsrc/mail/thunderbird/patches/patch-python_sites_mach.txt Wed Jul 22 15:46:01 2026
@@ -1,18 +1,18 @@
-$NetBSD: patch-python_sites_mach.txt,v 1.1 2026/06/06 14:51:30 ryoon Exp $
+$NetBSD: patch-python_sites_mach.txt,v 1.2 2026/07/22 15:46:01 ryoon Exp $
 
 * We are offline, so do not try to download from pypi.
   No need to wait a timeout.
 * Use pyyaml from vendored unconditionally.
 
---- python/sites/mach.txt.orig 2026-05-13 13:12:50.000000000 +0000
+--- python/sites/mach.txt.orig 2026-06-15 11:44:55.169043237 +0000
 +++ python/sites/mach.txt
 @@ -58,15 +58,16 @@ pth:xpcom/idl-parser
  pth:xpcom/idl-parser
  # glean-sdk may not be installable if a wheel isn't available
  # and it has to be built from source.
--pypi-optional:glean-sdk==67.2.0:telemetry will not be collected
+-pypi-optional:glean-sdk==67.3.2:telemetry will not be collected
 -pypi-optional:orjson>=3.10:json operations will be slower in various tools
-+#pypi-optional:glean-sdk==67.2.0:telemetry will not be collected
++#pypi-optional:glean-sdk==67.3.2:telemetry will not be collected
 +#pypi-optional:orjson>=3.10:json operations will be slower in various tools
  # Mach gracefully handles the case where `psutil` is unavailable.
  # We aren't (yet) able to pin packages in automation, so we have to



Home | Main Index | Thread Index | Old Index