head 1.36; access; symbols pkgsrc-2026Q3:1.36.0.2 pkgsrc-2026Q3-base:1.36 pkgsrc-2026Q2:1.34.0.2 pkgsrc-2026Q2-base:1.34 pkgsrc-2026Q1:1.33.0.2 pkgsrc-2026Q1-base:1.33 pkgsrc-2025Q4:1.32.0.2 pkgsrc-2025Q4-base:1.32 pkgsrc-2025Q3:1.28.0.2 pkgsrc-2025Q3-base:1.28 pkgsrc-2025Q2:1.25.0.2 pkgsrc-2025Q2-base:1.25 pkgsrc-2025Q1:1.20.0.2 pkgsrc-2025Q1-base:1.20 pkgsrc-2024Q4:1.15.0.2 pkgsrc-2024Q4-base:1.15 pkgsrc-2024Q3:1.12.0.2 pkgsrc-2024Q3-base:1.12 pkgsrc-2024Q2:1.8.0.2 pkgsrc-2024Q2-base:1.8 pkgsrc-2024Q1:1.5.0.2 pkgsrc-2024Q1-base:1.5 pkgsrc-2023Q4:1.1.0.2 pkgsrc-2023Q4-base:1.1; locks; strict; comment @# @; 1.36 date 2026.07.31.04.49.00; author taca; state Exp; branches; next 1.35; commitid s3m47HXB3yCPlLPG; 1.35 date 2026.07.04.06.21.01; author taca; state Exp; branches; next 1.34; commitid DsUGVFioYbudJiMG; 1.34 date 2026.05.08.02.04.25; author taca; state Exp; branches 1.34.2.1; next 1.33; commitid gbqqRVvrJQcL8XEG; 1.33 date 2026.01.19.15.34.18; author taca; state Exp; branches 1.33.2.1; next 1.32; commitid gfYgppPAZpIQ71rG; 1.32 date 2025.12.19.14.31.20; author taca; state Exp; branches; next 1.31; commitid e5IB8Hfi2g22M1nG; 1.31 date 2025.11.23.12.38.01; author taca; state Exp; branches; next 1.30; commitid x3japG2i5KpXYFjG; 1.30 date 2025.10.24.05.29.44; author taca; state Exp; branches; next 1.29; commitid 4jvHaJr1EEjOzMfG; 1.29 date 2025.09.26.13.53.03; author taca; state Exp; branches; next 1.28; commitid 50nODpsuKTvigecG; 1.28 date 2025.08.29.14.21.53; author taca; state Exp; branches; next 1.27; commitid 8iSicmE4u7qZjD8G; 1.27 date 2025.08.02.03.11.45; author taca; state Exp; branches; next 1.26; commitid kwJR6T6HLD6Ut65G; 1.26 date 2025.07.04.01.25.48; author taca; state Exp; branches; next 1.25; commitid CDRWYu5jgiwiPm1G; 1.25 date 2025.06.11.14.58.27; author taca; state Exp; branches 1.25.2.1; next 1.24; commitid kK3M1Ujj4BWR3uYF; 1.24 date 2025.06.08.16.27.30; author taca; state Exp; branches; next 1.23; commitid YF4omPo6k19vE6YF; 1.23 date 2025.05.19.15.00.56; author taca; state Exp; branches; next 1.22; commitid HmwHT9omu70FOwVF; 1.22 date 2025.04.13.15.56.18; author taca; state Exp; branches; next 1.21; commitid JcjOrLczHBzphUQF; 1.21 date 2025.04.07.17.33.36; author taca; state Exp; branches; next 1.20; commitid hVRav9XFpLuJ09QF; 1.20 date 2025.03.13.15.16.17; author taca; state Exp; branches; next 1.19; commitid 3CdOYvRxNbDr3VMF; 1.19 date 2025.02.17.15.28.31; author taca; state Exp; branches; next 1.18; commitid fxoUoH610iStTPJF; 1.18 date 2025.02.08.02.59.57; author taca; state Exp; branches; next 1.17; commitid vaOX9SFIWw9C2CIF; 1.17 date 2025.01.19.13.57.17; author taca; state Exp; branches; next 1.16; commitid BoWLHnupwNdYj6GF; 1.16 date 2024.12.24.14.35.10; author taca; state Exp; branches; next 1.15; commitid 6KirwlehcCFMmLCF; 1.15 date 2024.11.25.14.36.20; author taca; state Exp; branches; next 1.14; commitid JLG9VAGy3h2Zi2zF; 1.14 date 2024.11.10.22.09.50; author prlw1; state Exp; branches; next 1.13; commitid inKInzK1sZOci9xF; 1.13 date 2024.10.24.13.52.06; author taca; state Exp; branches; next 1.12; commitid hSeu0Fh9O1hz5VuF; 1.12 date 2024.09.28.15.03.38; author taca; state Exp; branches; next 1.11; commitid ixQcusgWKCgSjArF; 1.11 date 2024.08.31.04.36.24; author taca; state Exp; branches; next 1.10; commitid nSQnbngxamAyKVnF; 1.10 date 2024.08.02.15.29.30; author taca; state Exp; branches; next 1.9; commitid xwmo6AhR0FVoigkF; 1.9 date 2024.07.05.03.32.40; author taca; state Exp; branches; next 1.8; commitid CCQ1IKowrjgeeBgF; 1.8 date 2024.06.07.13.57.24; author taca; state Exp; branches; next 1.7; commitid 4KypLSC2AH9oA3dF; 1.7 date 2024.05.10.15.50.34; author taca; state Exp; branches; next 1.6; commitid ObJkJfhysKNK6t9F; 1.6 date 2024.04.13.02.51.54; author taca; state Exp; branches; next 1.5; commitid BfzclCfAYlFGFV5F; 1.5 date 2024.03.17.16.48.19; author taca; state Exp; branches 1.5.2.1; next 1.4; commitid 3vdCkoQxwl6sax2F; 1.4 date 2024.02.16.13.15.19; author taca; state Exp; branches; next 1.3; commitid 2xhqi9jn4lFaXEYE; 1.3 date 2024.01.21.07.53.53; author taca; state Exp; branches; next 1.2; commitid nycOaXADzMhI0iVE; 1.2 date 2024.01.05.02.08.41; author taca; state Exp; branches; next 1.1; commitid QWzLnEokX8maCcTE; 1.1 date 2023.11.30.16.14.50; author taca; state Exp; branches; next ; commitid FkhWCZvld5a3sEOE; 1.34.2.1 date 2026.07.13.17.25.57; author bsiegert; state Exp; branches; next 1.34.2.2; commitid JU5qLUrd5vrq7wNG; 1.34.2.2 date 2026.08.05.15.24.23; author maya; state Exp; branches; next ; commitid NyWeBJmfiIYSHsQG; 1.33.2.1 date 2026.05.09.19.01.50; author bsiegert; state Exp; branches; next ; commitid xwOjKjG6hAMQJaFG; 1.25.2.1 date 2025.07.04.14.43.38; author maya; state Exp; branches; next ; commitid xqfx5Lh4zUt5fr1G; 1.5.2.1 date 2024.04.22.12.49.08; author bsiegert; state Exp; branches; next 1.5.2.2; commitid NhEtlZg3zHVGG87F; 1.5.2.2 date 2024.06.13.13.47.10; author bsiegert; state Exp; branches; next 1.5.2.3; commitid F56WTbIfYhVXkPdF; 1.5.2.3 date 2024.06.13.14.34.05; author bsiegert; state Exp; branches; next ; commitid uN3gby1sA4T3BPdF; desc @@ 1.36 log @lang/php83: update to 8.3.33 PHP 8.3.33 (2026-07-30) - Date: . Fixed leak on double DatePeriod::__construct() call. (ilutov) - GD: . Upgrade libgd. (CVE-2026-9672) (Pierre Joye) - PGSQL: . Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout). (CVE-2026-17543) (ilutov) - Phar: . Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260) (Jakub Zelenka) @ text @$NetBSD: distinfo,v 1.35 2026/07/04 06:21:01 taca Exp $ BLAKE2s (php-8.3.33.tar.xz) = 1b62738e5268a04665f8c76d4f59be3df8a3d8bfae78f4dcfd098331d643a103 SHA512 (php-8.3.33.tar.xz) = e2340294b11ae47ba527018d700b6d896f73e04d06a8cdf099a60380f06b3899adaca01fe654bd9ac8e2dc5f3ff73c94ab1801a006a83558b222e448edd847dc Size (php-8.3.33.tar.xz) = 12613000 bytes SHA1 (patch-TSRM_TSRM.c) = 278007810b74fa7a9cd971dac051d6a2ea0ad90d SHA1 (patch-TSRM_TSRM.h) = 70ebc03a611124d76d6813f619ff18b3a8fbf1e8 SHA1 (patch-build_Makefile.global) = 25ee73157c012aa731a2979cb0546ea94aa5ee16 SHA1 (patch-build_php.m4) = 4a99c91785e7de3095cab08ed2fad6053b4a94e0 SHA1 (patch-configure.ac) = 11600400f69e0db2b429f4d37d70477550b0cd6a SHA1 (patch-ext_enchant_enchant.c) = 7d999de1b2fde2ea11e4a6e16e7b59c085924b9b SHA1 (patch-ext_opcache_jit_zend__jit__x86.dasc) = 4d0d368aa1fb8ec076b392b6b64d2cf5d742133a SHA1 (patch-ext_phar_Makefile.frag) = 53ea5c58b0bc27d236118d5750a74b1cba43e5dd SHA1 (patch-ext_standard_php__fopen__wrapper.c) = 0a2c19c18f089448a8d842e99738b292ab9e5640 SHA1 (patch-ext_tidy_config.m4) = 380f4e8927582b2781faf58b17ad81b6dc967ba7 SHA1 (patch-ext_xsl_php__xsl.h) = cf930c5d6d9dab29b12558d265c67d3534a006fd SHA1 (patch-main_streams_streams.c) = d699ce7d3a300ffb39494b3f1fa5e0958f714483 SHA1 (patch-php.ini-development) = 0eaf4a5d7c99dfe9ef55e6da2902a314535253cc SHA1 (patch-php.ini-production) = 849441a8218626a2e1b107c1a7670d2943ad2682 SHA1 (patch-sapi_apache2handler_config.m4) = 5de841440e35bda2bf82e7565c31d15fd3f263b2 SHA1 (patch-sapi_cgi_Makefile.frag) = f4cd64d334884c49787d8854115c8cd69cc79bb8 SHA1 (patch-sapi_cgi_config9.m4) = ee690f742c99e519755eb6489180795f7bc6df40 SHA1 (patch-sapi_cli_Makefile.frag) = 1cd29d09042863acbf5330e406410fdcf75d06b3 SHA1 (patch-sapi_fpm_fpm_fpm__conf.c) = 6056f97f5a60c16c9a95074c9d6f5fc941610377 SHA1 (patch-sapi_fpm_php-fpm.conf.in) = 675aab89d3ca3eb96b0c581819f9f0449df09f8a SHA1 (patch-sapi_fpm_www.conf.in) = 2299f6de1d4c0ead4fe41eca4af5ea3e8e7b3a35 SHA1 (patch-scripts_Makefile.frag) = 356c836c9f8fe26af9577583c9c461573efb1df0 SHA1 (patch-scripts_php-config.in) = 8706a0a78ddedcf5b0512483a021bb394bec4d0e SHA1 (patch-scripts_phpize.in) = aa4dfe11f270dae1fdf813a97d872b9a31516fcb @ 1.35 log @lang/php83: update to 8.3.32 PHP 8.3.32 (2026-07-02) - Streams: . Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). (CVE-2026-12184) (ndossche) - OpenSSL: . Fixed bug GH-22187 (Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD). (David Carlier) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.34 2026/05/08 02:04:25 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.32.tar.xz) = 89ccb2d71d9dd4c8aefa081ce0b2a8b9ecfeef3d307aa28b5a1e58f38e9f82bd SHA512 (php-8.3.32.tar.xz) = 125683403ae0a300b4537a4493568e06d79cb27c57739c1c37af4b0bf869b484633247d03c4df860d5ab0aa0ccc3a06c66ff0b01b4415ff6d4f6232324c60c88 Size (php-8.3.32.tar.xz) = 12606844 bytes @ 1.34 log @lang/php83: update to 8.3.31 PHP 8.3.31 (2026-05-07) - Curl: . Add support for brotli and zstd on Windows. (Shivam Mathur) - FPM: . Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) (Jakub Zelenka) - MBString: . Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) (vi3tL0u1s) - OpenSSL: . Fix compatibility issues with OpenSSL 4.0. (jordikroon, Remi) - PDO_Firebird: . Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) (SakiTakamachi) - SOAP: . Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) (ilutov) . Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) (ilutov) . Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) (ilutov) - Standard: . Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) (TimWolla) . Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) (ilutov) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.33 2026/01/19 15:34:18 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.31.tar.xz) = a27fa1f416d480e82aa35c276d156a52037d56f3b1d70bb68ffa10a120773a22 SHA512 (php-8.3.31.tar.xz) = 2341ce4061f5e654780c97145ea7bf92fa14f2d5c2ea83d38b8919ee5018c040a08c83c9b7cee97e4bba39267d412f5bf18c515f2001db1659a49449299cbeef Size (php-8.3.31.tar.xz) = 12603408 bytes @ 1.34.2.1 log @Pullup ticket #7164 - requested by taca lang/php83: security fix Revisions pulled up: - lang/php/phpversion.mk 1.504 - lang/php83/distinfo 1.35 --- Module Name: pkgsrc Committed By: taca Date: Sat Jul 4 06:21:01 UTC 2026 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php83: distinfo Log Message: lang/php83: update to 8.3.32 PHP 8.3.32 (2026-07-02) - Streams: . Fixed bug GH-21468 (Segfault in file_get_contents w/ a https URL and a proxy set). (CVE-2026-12184) (ndossche) - OpenSSL: . Fixed bug GH-22187 (Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD). (David Carlier) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.34 2026/05/08 02:04:25 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.32.tar.xz) = 89ccb2d71d9dd4c8aefa081ce0b2a8b9ecfeef3d307aa28b5a1e58f38e9f82bd SHA512 (php-8.3.32.tar.xz) = 125683403ae0a300b4537a4493568e06d79cb27c57739c1c37af4b0bf869b484633247d03c4df860d5ab0aa0ccc3a06c66ff0b01b4415ff6d4f6232324c60c88 Size (php-8.3.32.tar.xz) = 12606844 bytes @ 1.34.2.2 log @Pullup ticket #7218 - requested by taca lang/php83: Security fix Revisions pulled up: - lang/php/phpversion.mk 1.509 - lang/php83/distinfo 1.36 --- Module Name: pkgsrc Committed By: taca Date: Fri Jul 31 04:49:00 UTC 2026 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php83: distinfo Log Message: lang/php83: update to 8.3.33 PHP 8.3.33 (2026-07-30) - Date: . Fixed leak on double DatePeriod::__construct() call. (ilutov) - GD: . Upgrade libgd. (CVE-2026-9672) (Pierre Joye) - PGSQL: . Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout). (CVE-2026-17543) (ilutov) - Phar: . Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260) (Jakub Zelenka) @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (php-8.3.33.tar.xz) = 1b62738e5268a04665f8c76d4f59be3df8a3d8bfae78f4dcfd098331d643a103 SHA512 (php-8.3.33.tar.xz) = e2340294b11ae47ba527018d700b6d896f73e04d06a8cdf099a60380f06b3899adaca01fe654bd9ac8e2dc5f3ff73c94ab1801a006a83558b222e448edd847dc Size (php-8.3.33.tar.xz) = 12613000 bytes @ 1.33 log @lang/php83: update to 8.3.30 8.3.30 (2026-01-15) - Core: . Fix OSS-Fuzz #465488618 (Wrong assumptions when dumping function signature with dynamic class const lookup default argument). (ilutov) . Fixed bug GH-20695 (Assertion failure in normalize_value() when parsing malformed INI input via parse_ini_string()). (ndossche) . Fixed bug GH-20714 (Uncatchable exception thrown in generator). (ilutov) . Fixed bug GH-20352 (UAF in php_output_handler_free via re-entrant ob_start() during error deactivation). (ndossche) - Bz2: . Fixed bug GH-20620 (bzcompress overflow on large source size). (David Carlier) - DOM: . Fixed bug GH-20722 (Null pointer dereference in DOM namespace node cloning via clone on malformed objects). (ndossche) - GD: . Fixed bug GH-20622 (imagestring/imagestringup overflow). (David Carlier) - Intl: . Fix leak in umsg_format_helper(). (ndossche) - LDAP: . Fix memory leak in ldap_set_options(). (ndossche) - Mbstring: . Fixed bug GH-20674 (mb_decode_mimeheader does not handle separator). (Yuya Hamada) - Phar: . Fixed bug GH-20732 (Phar::LoadPhar undefined behavior when reading fails). (ndossche) . Fix SplFileInfo::openFile() in write mode. (ndossche) . Fix build on legacy OpenSSL 1.1.0 systems. (Giovanni Giacobbi) - POSIX: . Fixed crash on posix groups to php array creation on macos. (David Carlier) - SPL: . Fixed bug GH-20678 (resource created by GlobIterator crashes with fclose()). (David Carlier) - Sqlite3: . Fixed bug GH-20699 (SQLite3Result fetchArray return array|false, null returned). (ndossche, plusminmax) - Standard: . Fix error check for proc_open() command. (ndossche) . Fixed bug GH-20582 (Heap Buffer Overflow in iptcembed). (ndossche) - Zlib: . Fix OOB gzseek() causing assertion failure. (ndossche) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.32 2025/12/19 14:31:20 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.30.tar.xz) = 7190c112c3db9b20e5ecb2c1e2f05d8f9e4ecf5caf17e04e00e1ab7d5dadceb4 SHA512 (php-8.3.30.tar.xz) = 0d5ae6959d67762ab1e449b05042432cd94673d8e9407375821695e56cab125130556d553e5d98675f7d38c0195844c407f34268befc5b0cd06d1ea22dde26c7 Size (php-8.3.30.tar.xz) = 12609216 bytes @ 1.33.2.1 log @Pullup ticket #7108 - requested by taca lang/php83: security fix Revisions pulled up: - lang/php/phpversion.mk 1.497 - lang/php83/distinfo 1.34 --- Module Name: pkgsrc Committed By: taca Date: Fri May 8 02:04:25 UTC 2026 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php83: distinfo Log Message: lang/php83: update to 8.3.31 PHP 8.3.31 (2026-05-07) - Curl: . Add support for brotli and zstd on Windows. (Shivam Mathur) - FPM: . Fixed GHSA-7qg2-v9fj-4mwv (XSS within status endpoint). (CVE-2026-6735) (Jakub Zelenka) - MBString: . Fixed GHSA-wm6j-2649-pv75 (Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()). (CVE-2026-7259) (vi3tL0u1s) - OpenSSL: . Fix compatibility issues with OpenSSL 4.0. (jordikroon, Remi) - PDO_Firebird: . Fixed GHSA-w476-322c-wpvm (SQL injection via NUL bytes in quoted strings). (CVE-2025-14179) (SakiTakamachi) - SOAP: . Fixed GHSA-85c2-q967-79q5 (Stale SOAP_GLOBAL(ref_map) pointer with Apache Map). (CVE-2026-6722) (ilutov) . Fixed GHSA-m33r-qmcv-p97q (Use-after-free after header parsing failure with SOAP_PERSISTENCE_SESSION). (CVE-2026-7261) (ilutov) . Fixed GHSA-hmxp-6pc4-f3vv (Broken Apache map value NULL check). (CVE-2026-7262) (ilutov) - Standard: . Fixed GHSA-96wq-48vp-hh57 (Signed integer overflow of char array offset). (CVE-2026-7568) (TimWolla) . Fixed GHSA-m8rr-4c36-8gq4 (Consistently pass unsigned char to ctype.h functions). (CVE-2026-7258) (ilutov) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.33 2026/01/19 15:34:18 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.31.tar.xz) = a27fa1f416d480e82aa35c276d156a52037d56f3b1d70bb68ffa10a120773a22 SHA512 (php-8.3.31.tar.xz) = 2341ce4061f5e654780c97145ea7bf92fa14f2d5c2ea83d38b8919ee5018c040a08c83c9b7cee97e4bba39267d412f5bf18c515f2001db1659a49449299cbeef Size (php-8.3.31.tar.xz) = 12603408 bytes @ 1.32 log @lang/php83: update to 8.3.29 PHP 8.3.29 (2025-12-18) - Core: . Sync all boost.context files with release 1.86.0. (mvorisek) . Fixed bug GH-20435 (SensitiveParameter doesn't work for named argument passing to variadic parameter). (ndossche) . Fixed bug GH-20286 (use-after-destroy during userland stream_close()). (ndossche, David Carlier) - Bz2: . Fix assertion failures resulting in crashes with stream filter object parameters. (ndossche) - Date: . Fix crashes when trying to instantiate uninstantiable classes via date static constructors. (ndossche) - DOM: . Fix missing NUL byte check on C14NFile(). (ndossche) - Fibers: . Fixed bug GH-20483 (ASAN stack overflow with fiber.stack_size INI small value). (David Carlier) - FTP: . Fixed bug GH-20601 (ftp_connect overflow on timeout). (David Carlier) - GD: . Fixed bug GH-20511 (imagegammacorrect out of range input/output values). (David Carlier) . Fixed bug GH-20602 (imagescale overflow with large height values). (David Carlier) - Intl: . Fixed bug GH-20426 (Spoofchecker::setRestrictionLevel() error message suggests missing constants). (DanielEScherzer) - LibXML: . Fix some deprecations on newer libxml versions regarding input buffer/parser handling. (ndossche) - MbString: . Fixed bug GH-20491 (SLES15 compile error with mbstring oniguruma). (ndossche) . Fixed bug GH-20492 (mbstring compile warning due to non-strings). (ndossche) - MySQLnd: . Fixed bug GH-20528 (Regression breaks mysql connexion using an IPv6 address enclosed in square brackets). (Remi) - Opcache: . Fixed bug GH-20329 (opcache.file_cache broken with full interned string buffer). (Arnaud) - PDO: . Fixed GHSA-8xr5-qppj-gvwj (PDO quoting result null deref). (CVE-2025-14180) (Jakub Zelenka) - Phar: . Fixed bug GH-20442 (Phar does not respect case-insensitiveness of __halt_compiler() when reading stub). (ndossche, TimWolla) . Fix broken return value of fflush() for phar file entries. (ndossche) . Fix assertion failure when fseeking a phar file out of bounds. (ndossche) - PHPDBG: . Fixed ZPP type violation in phpdbg_get_executable() and phpdbg_end_oplog(). (Girgias) - SPL: . Fixed bug GH-20614 (SplFixedArray incorrectly handles references in deserialization). (ndossche) - Standard: . Fix memory leak in array_diff() with custom type checks. (ndossche) . Fixed bug GH-20583 (Stack overflow in http_build_query via deep structures). (ndossche) . Fixed GHSA-www2-q4fc-65wf (Null byte termination in dns_get_record()). (ndossche) . Fixed GHSA-h96m-rvf9-jgm2 (Heap buffer overflow in array_merge()). (CVE-2025-14178) (ndossche) . Fixed GHSA-3237-qqm7-mfv7 (Information Leak of Memory in getimagesize). (CVE-2025-14177) (ndossche) - Tidy: . Fixed bug GH-20374 (PHP with tidy and custom-tags). (ndossche) - XML: . Fixed bug GH-20439 (xml_set_default_handler() does not properly handle special characters in attributes when passing data to callback). (ndossche) - Zip: . Fix crash in property existence test. (ndossche) . Don't truncate return value of zip_fread() with user sizes. (ndossche) - Zlib: . Fix assertion failures resulting in crashes with stream filter object parameters. (ndossche) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.31 2025/11/23 12:38:01 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.29.tar.xz) = 2f2d12e16526698cd37c26b013f4c81f8527f0b38adfd035814a0c779c5623aa SHA512 (php-8.3.29.tar.xz) = d5739ff7f13638c60cd7e62bad9aec831282eca7c9e9487c12ca72f4ed4494e46eb45555a19fc5eccb43d36253d2bada12611c691e0edc6dbb8cc9908d449733 Size (php-8.3.29.tar.xz) = 12601944 bytes @ 1.31 log @PHP 8.3.28 (2025-11-20) - Core: . Fixed bug GH-19934 (CGI with auto_globals_jit=0 causes uouv). (ilutov) . Fixed bug GH-20073 (Assertion failure in WeakMap offset operations on reference). (nielsdos) . Fixed bug GH-19844 (Don't bail when closing resources on shutdown). (ilutov) . Fixed bug GH-20177 (Accessing overridden private property in get_object_vars() triggers assertion error). (ilutov) . Fixed bug GH-20183 (Stale EG(opline_before_exception) pointer through eval). (ilutov) - DOM: . Partially fixed bug GH-16317 (DOM classes do not allow __debugInfo() overrides to work). (nielsdos) - Exif: . Fix possible memory leak when tag is empty. (nielsdos) - FPM: . Fixed bug GH-19974 (fpm_status_export_to_zval segfault for parallel execution). (Jakub Zelenka, txuna) - FTP: . Fixed bug GH-20240 (FTP with SSL: ftp_fput(): Connection timed out on successful writes). (nielsdos) - GD: . Fixed bug GH-20070 (Return type violation in imagefilter when an invalid filter is provided). (Girgias) - Intl: . Fix memory leak on error in locale_filter_matches(). (nielsdos) - LibXML: . Fix not thread safe schema/relaxng calls. (SpencerMalone, nielsdos) - MySQLnd: . Fixed bug GH-8978 (SSL certificate verification fails (port doubled)). (nielsdos) . Fixed bug GH-20122 (getColumnMeta() for JSON-column in MySQL). (nielsdos) - Opcache: . Fixed bug GH-20081 (access to uninitialized vars in preload_load()). (Arnaud) . Fixed bug GH-20121 (JIT broken in ZTS builds on MacOS 15). (Arnaud, Shivam Mathur) - PgSql: . Fix memory leak when first string conversion fails. (nielsdos) . Fix segfaults when attempting to fetch row into a non-instantiable class name. (Girgias, nielsdos) - Phar: . Fix memory leak of argument in webPhar. (nielsdos) . Fix memory leak when setAlias() fails. (nielsdos) . Fix a bunch of memory leaks in phar_parse_zipfile() error handling. (nielsdos) . Fix file descriptor/memory leak when opening central fp fails. (nielsdos) . Fix memleak+UAF when opening temp stream in buildFromDirectory() fails. (nielsdos) . Fix potential buffer length truncation due to usage of type int instead of type size_t. (Girgias) . Fix memory leak when openssl polyfill returns garbage. (nielsdos) . Fix file descriptor leak in phar_zip_flush() on failure. (nielsdos) . Fix memory leak when opening temp file fails while trying to open gzip-compressed archive. (nielsdos) . Fixed bug GH-20302 (Freeing a phar alias may invalidate PharFileInfo objects). (nielsdos) - Random: . Fix Randomizer::__serialize() w.r.t. INDIRECTs. (nielsdos) - SimpleXML: . Partially fixed bug GH-16317 (SimpleXML does not allow __debugInfo() overrides to work). (nielsdos) - Standard: . Fix shm corruption with coercion in options of unserialize(). (nielsdos) - Streams: . Fixed bug GH-19798: XP_SOCKET XP_SSL (Socket stream modules): Incorrect condition for Win32/Win64. (Jakub Zelenka) - Tidy: . Fixed GH-19021 (improved tidyOptGetCategory detection). (arjendekorte, David Carlier, Peter Kokot) . Fix UAF in tidy when tidySetErrorBuffer() fails. (nielsdos) - XMLReader: . Fix arginfo/zpp violations when LIBXML_SCHEMAS_ENABLED is not available. (nielsdos) - Windows: . Fix GH-19722 (_get_osfhandle asserts in debug mode when given a socket). (dktapps) - Zip: . Fix memory leak when passing enc_method/enc_password is passed as option for ZipArchive::addGlob()/addPattern() and with consecutive calls. (David Carlier) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.30 2025/10/24 05:29:44 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.28.tar.xz) = 5e4bb41b3ae4835df0f7f727730186040371eccf5c453144ec78faf5995eb92c SHA512 (php-8.3.28.tar.xz) = 8dc88361d59710e165239e16a8c976230d3e355c73c1c44126701591fcc02cf97e223dae51349319eca09191311a15f5596a3341ed09ed7b9cb40c1e230c6fd4 Size (php-8.3.28.tar.xz) = 12604244 bytes @ 1.30 log @lang/php83: update to 8.3.27 PHP 8.3.27 (2025-10-23) - Core: . Fixed bug GH-19765 (object_properties_load() bypasses readonly property checks). (timwolla) . Fixed hard_timeout with --enable-zend-max-execution-timers. (Appla) . Fixed bug GH-19792 (SCCP causes UAF for return value if both warning and exception are triggered). (nielsdos) . Fixed bug GH-19653 (Closure named argument unpacking between temporary closures can cause a crash). (nielsdos, Arnaud, Bob) . Fixed bug GH-19839 (Incorrect HASH_FLAG_HAS_EMPTY_IND flag on userland array). (ilutov) . Fixed bug GH-19480 (error_log php.ini cannot be unset when open_basedir is configured). (nielsdos) . Fixed bug GH-20002 (Broken build on *BSD with MSAN). (outtersg) - CLI: . Fix useless "Failed to poll event" error logs due to EAGAIN in CLI server with PHP_CLI_SERVER_WORKERS. (leotaku) - Curl: . Fix cloning of CURLOPT_POSTFIELDS when using the clone operator instead of the curl_copy_handle() function to clone a CurlHandle. (timwolla) . Fix curl build and test failures with version 8.16. (nielsdos, ilutov, Jakub Zelenka) - Date: . Fixed GH-17159: "P" format for ::createFromFormat swallows string literals. (nielsdos) - DBA: . Fixed GH-19885 (dba_fetch() overflow on skip argument). (David Carlier) - GD: . Fixed GH-19955 (imagefttext() memory leak). (David Carlier) - MySQLnd: . Fixed bug #67563 (mysqli compiled with mysqlnd does not take ipv6 adress as parameter). (nielsdos) - Phar: . Fix memory leak and invalid continuation after tar header writing fails. (nielsdos) . Fix memory leaks when creating temp file fails when applying zip signature. (nielsdos) - SimpleXML: . Fixed bug GH-19988 (zend_string_init with NULL pointer in simplexml (UB)). (nielsdos) - Soap: . Fixed bug GH-19784 (SoapServer memory leak). (nielsdos) . Fixed bug GH-20011 (Array of SoapVar of unknown type causes crash). (nielsdos) - Standard: . Fixed bug GH-12265 (Cloning an object breaks serialization recursion). (nielsdos) . Fixed bug GH-19701 (Serialize/deserialize loses some data). (nielsdos) . Fixed bug GH-19801 (leaks in var_dump() and debug_zval_dump()). (alexandre-daubois) . Fixed bug GH-20043 (array_unique assertion failure with RC1 array causing an exception on sort). (nielsdos) . Fixed bug GH-19926 (reset internal pointer earlier while splicing array while COW violation flag is still set). (alexandre-daubois) . Fixed bug GH-19570 (unable to fseek in /dev/zero and /dev/null). (nielsdos, divinity76) - Streams: . Fixed bug GH-19248 (Use strerror_r instead of strerror in main). (Jakub Zelenka) . Fixed bug GH-17345 (Bug #35916 was not completely fixed). (nielsdos) . Fixed bug GH-19705 (segmentation when attempting to flush on non seekable stream. (bukka/David Carlier) - XMLReader: . Fixed bug GH-20009 (XMLReader leak on RelaxNG schema failure). (nielsdos) - Zip: . Fixed bug GH-19688 (Remove pattern overflow in zip addGlob()). (nielsdos) . Fixed bug GH-19932 (Memory leak in zip setEncryptionName()/setEncryptionIndex()). (David Carlier) - Zlib: . Fixed bug GH-19922 (Double free on gzopen). (David Carlier) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.29 2025/09/26 13:53:03 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.27.tar.xz) = d83daab28b66dff1d3201901fef70276936edebe1a2c1a22116cb28b7a8fdaa5 SHA512 (php-8.3.27.tar.xz) = 845189f97063574ef1f677d6ceb39c5ef362cab7068f908d6d870a1ea52953d6ec00b3bf042ce2daa6c2a84038a64f2ae6027ede9ae5952028a94f781200e306 Size (php-8.3.27.tar.xz) = 12592316 bytes @ 1.29 log @lang/php83: update to 8.3.26 PHP 8.3.26 (2025-09-25) - Core: . Fixed bug GH-18850 (Repeated inclusion of file with __halt_compiler() triggers "Constant already defined" warning). (ilutov) . Partially fixed bug GH-19542 (Scanning of string literals >=2GB will fail due to signed int overflow). (ilutov) . Fixed bug GH-19544 (GC treats ZEND_WEAKREF_TAG_MAP references as WeakMap references). (Arnaud, timwolla) . Fixed bug GH-19613 (Stale array iterator pointer). (ilutov) . Fixed bug GH-19679 (zend_ssa_range_widening may fail to converge). (Arnaud) . Fixed bug GH-19681 (PHP_EXPAND_PATH broken with bash 5.3.0). (Remi) . Fixed bug GH-19720 (Assertion failure when error handler throws when accessing a deprecated constant). (nielsdos) - CLI: . Fixed bug GH-19461 (Improve error message on listening error with IPv6 address). (alexandre-daubois) - Date: . Fixed date_sunrise() and date_sunset() with partial-hour UTC offset. (ilutov) - DOM: . Fixed bug GH-19612 (Mitigate libxml2 tree dictionary bug). (nielsdos) - FPM: . Fixed failed debug assertion when php_admin_value setting fails. (ilutov) - GD: . Fixed bug GH-19579 (imagefilledellipse underflow on width argument). (David Carlier) - Intl: . Fixed bug GH-11952 (Fix locale strings canonicalization for IntlDateFormatter and NumberFormatter). (alexandre-daubois) - OpenSSL: . Fixed bug GH-19245 (Success error message on TLS stream accept failure). (Jakub Zelenka) - PGSQL: . Fixed bug GH-19485 (potential use after free when using persistent pgsql connections). (Mark Karpeles) - Phar: . Fixed memory leaks when verifying OpenSSL signature. (Girgias) . Fix memory leak in phar tar temporary file error handling code. (nielsdos) . Fix metadata leak when phar convert logic fails. (nielsdos) . Fix memory leak on failure in phar_convert_to_other(). (nielsdos) . Fixed bug GH-19752 (Phar decompression with invalid extension can cause UAF). (nielsdos) - Standard: . Fixed bug GH-16649 (UAF during array_splice). (alexandre-daubois) . Fixed bug GH-19577 (Avoid integer overflow when using a small offset and PHP_INT_MAX with LimitIterator). (alexandre-daubois) - Streams: . Remove incorrect call to zval_ptr_dtor() in user_wrapper_metadata(). (nielsdos) . Fix OSS-Fuzz #385993744. (nielsdos) - Tidy: . Fixed GH-19021 build issue with libtidy in regard of tidyOptIsReadonly deprecation and TidyInternalCategory being available later than tidyOptGetCategory. (arjendekorte) - Zip: . Fix memory leak in zip when encountering empty glob result. (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.28 2025/08/29 14:21:53 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.26.tar.xz) = 284c8dafe66f9fb285c4efef6e117713aa5701e2f38fd9082932f981e8a5d3b3 SHA512 (php-8.3.26.tar.xz) = 252c0c95bb2c4d6bf03e686c205777b529aaebe52f143754b369069d7a8aa5b45e8c2addb968287d6473cee507df62729e2527607b796fb764d3f036ba89fafb Size (php-8.3.26.tar.xz) = 12581368 bytes @ 1.28 log @lang/php83: update to 8.3.25 PHP 8.3.25 (2025-08-28) - Core: . Fixed GH-19169 build issue with C++17 and ZEND_STATIC_ASSERT macro. (psumbera) . Fixed bug GH-18581 (Coerce numeric string keys from iterators when argument unpacking). (ilutov) . Fixed OSS-Fuzz #434346548 (Failed assertion with throwing __toString in binary const expr). (ilutov) . Fixed bug GH-19305 (Operands may be being released during comparison). (Arnaud) . Fixed bug GH-19303 (Unpacking empty packed array into uninitialized array causes assertion failure). (nielsdos) . Fixed bug GH-19306 (Generator can be resumed while fetching next value from delegated Generator). (Arnaud) . Fixed bug GH-19326 (Calling Generator::throw() on a running generator with a non-Generator delegate crashes). (Arnaud) . Fixed bug GH-18736 (Circumvented type check with return by ref + finally). (ilutov) . Fixed zend call stack size for macOs/arm64. (David Carlier) . Fixed bug GH-19065 (Long match statement can segfault compiler during recursive SSA renaming). (nielsdos, Arnaud) - Calendar: . Fixed bug GH-19371 (integer overflow in calendar.c). (nielsdos) - FTP: . Fix theoretical issues with hrtime() not being available. (nielsdos) - GD: . Fix incorrect comparison with result of php_stream_can_cast(). (Girgias) - Hash: . Fix crash on clone failure. (nielsdos) - Intl: . Fixed GH-19261: msgfmt_parse_message leaks on message creation failure. (David Carlier) . Fix return value on failure for resourcebundle count handler. (Girgias) - LDAP: . Fixed bug GH-18529 (additional inheriting of TLS int options). (Jakub Zelenka) - LibXML: . Fixed bug GH-19098 (libxml<2.13 segmentation fault caused by php_libxml_node_free). (nielsdos) - MbString: . Fixed bug GH-19397 (mb_list_encodings() can cause crashes on shutdown). (nielsdos) - Opcache: . Reset global pointers to prevent use-after-free in zend_jit_status(). (Florian Engelhardt) - OpenSSL: . Fixed bug GH-18986 (OpenSSL backend: incorrect RAND_{load,write}_file() return value check). (nielsdos, botovq) . Fix error return check of EVP_CIPHER_CTX_ctrl(). (nielsdos) . Fixed bug GH-19428 (openssl_pkey_derive segfaults for DH derive with low key_length param). (Jakub Zelenka) - PDO Pgsql: . Fixed dangling pointer access on _pdo_pgsql_trim_message helper. (dixyes) - Readline: . Fixed bug GH-19250 and bug #51360 (Invalid conftest for rl_pending_input). (petk, nielsdos) - SOAP: . Fixed bug GH-18640 (heap-use-after-free ext/soap/php_encoding.c:299:32 in soap_check_zval_ref). (nielsdos) - Sockets: . Fix some potential crashes on incorrect argument value. (nielsdos) - Standard: . Fixed OSS Fuzz #433303828 (Leak in failed unserialize() with opcache). (ilutov) . Fix theoretical issues with hrtime() not being available. (nielsdos) . Fixed bug GH-19300 (Nested array_multisort invocation with error breaks). (nielsdos) - Windows: . Free opened_path when opened_path_len >= MAXPATHLEN. (dixyes) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.27 2025/08/02 03:11:45 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.25.tar.xz) = 2ece963418c0a32f0d2817bc82b75eaf5ca039df2101aeabd256a7731da92864 SHA512 (php-8.3.25.tar.xz) = 4853c3bcced4aa791fb3f08b8e3d20a9f83cdb00757a3e500247b0da98a5156c31fa73b9cde3c3773e17129ab931573d086c766177cb882c217d8af1b48e719f Size (php-8.3.25.tar.xz) = 12583528 bytes @ 1.27 log @lang/php83: update to 8.3.24 PHP 8.3.24 (2025-07-31) - Calendar: . Fixed jewishtojd overflow on year argument. (David Carlier) - Core: . Fixed bug GH-18833 (Use after free with weakmaps dependent on destruction order). (Daniil Gentili) . Fix OSS-Fuzz #427814456. (nielsdos) . Fix OSS-Fuzz #428983568 and #428760800. (nielsdos) . Fixed bug GH-17204 -Wuseless-escape warnings emitted by re2c. (Peter Kokot) - Curl: . Fix memory leaks when returning refcounted value from curl callback. (nielsdos) . Remove incorrect string release. (nielsdos) - LDAP: . Fixed GH-18902 ldap_exop/ldap_exop_sync assert triggered on empty request OID. (David Carlier) - MbString: . Fixed bug GH-18901 (integer overflow mb_split). (nielsdos) - OCI8: . Fixed bug GH-18873 (OCI_RETURN_LOBS flag causes oci8 to leak memory). (Saki Takamachi) - Opcache: . Fixed bug GH-18639 (Internal class aliases can break preloading + JIT). (nielsdos) . Fixed bug GH-14082 (Segmentation fault on unknown address 0x600000000018 in ext/opcache/jit/zend_jit.c). (nielsdos) - OpenSSL: . Fixed bug #80770 (It is not possible to get client peer certificate with stream_socket_server). (Jakub Zelenka) - PCNTL: . Fixed bug GH-18958 (Fatal error during shutdown after pcntl_rfork() or pcntl_forkx() with zend-max-execution-timers). (Arnaud) - Phar: . Fix stream double free in phar. (nielsdos, dixyes) . Fix phar crash and file corruption with SplFileObject. (nielsdos) - SOAP: . Fixed bug GH-18990, bug #81029, bug #47314 (SOAP HTTP socket not closing on object destruction). (nielsdos) . Fix memory leak when URL parsing fails in redirect. (Girgias) - SPL: . Fixed bug GH-19094 (Attaching class with no Iterator implementation to MultipleIterator causes crash). (nielsdos) - Standard: . Fix misleading errors in printf(). (nielsdos) . Fix RCN violations in array functions. (nielsdos) . Fixed GH-18976 pack() overflow with h/H format and INT_MAX repeater value. (David Carlier) - Streams: . Fixed GH-13264 (fgets() and stream_get_line() do not return false on filter fatal error). (Jakub Zelenka) - Zip: . Fix leak when path is too long in ZipArchive::extractTo(). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.26 2025/07/04 01:25:48 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.24.tar.xz) = 60547bf7453aecd0c2cb0603147b54b6ddbc9879f6b2a5eb721e024f6d441a80 SHA512 (php-8.3.24.tar.xz) = c4a59e04bcbca45e7727ccac33d968a5e4270b90ba5614d63447059d738c1e1ba3715d991b23fea9dd2905d70e0a367fa1fd06a277ccf6f4824b1552bc5fb1b4 Size (php-8.3.24.tar.xz) = 12579100 bytes @ 1.26 log @lang/php83: update to 8.3.23 PHP 8.3.23 (2025-07-03) - Core: . Fixed GH-18695 (zend_ast_export() - float number is not preserved). (Oleg Efimov) . Do not delete main chunk in zend_gc. (danog, Arnaud) . Fix compile issues with zend_alloc and some non-default options. (nielsdos) - Curl: . Fix memory leak when setting a list via curl_setopt fails. (nielsdos) . Fix incorrect OpenSSL version detection. (Peter Kokot) - Date: . Fix leaks with multiple calls to DatePeriod iterator current(). (nielsdos) - FPM: . Fixed GH-18662 (fpm_get_status segfault). (txuna) - Hash: . Fixed bug GH-14551 (PGO build fails with xxhash). (nielsdos) - Intl: . Fix memory leak in intl_datetime_decompose() on failure. (nielsdos) . Fix memory leak in locale lookup on failure. (nielsdos) - ODBC: . Fix memory leak on php_odbc_fetch_hash() failure. (nielsdos) - Opcache: . Fixed bug GH-18743 (Incompatibility in Inline TLS Assembly on Alpine 3.22). (nielsdos, Arnaud) - OpenSSL: . Fix memory leak of X509_STORE in php_openssl_setup_verify() on failure. (nielsdos) . Fixed bug #74796 (Requests through http proxy set peer name). (Jakub Zelenka) - PGSQL: . Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) (Jakub Zelenka) - Phar: . Add missing filter cleanups on phar failure. (nielsdos) . Fixed bug GH-18642 (Signed integer overflow in ext/phar fseek). (nielsdos) - PHPDBG: . Fix 'phpdbg --help' segfault on shutdown with USE_ZEND_ALLOC=0. (nielsdos) - PDO ODBC: . Fix memory leak if WideCharToMultiByte() fails. (nielsdos) - PGSQL: . Fix warning not being emitted when failure to cancel a query with pg_cancel_query(). (Girgias) - Random: . Fix reference type confusion and leak in user random engine. (nielsdos, timwolla) - Readline: . Fix memory leak when calloc() fails in php_readline_completion_cb(). (nielsdos) - SOAP: . Fix memory leaks in php_http.c when call_user_function() fails. (nielsdos) . Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix). (CVE-2025-6491) (Lekssays, nielsdos) - Standard: . Fixed GHSA-3cr5-j632-f35r (Null byte termination in hostnames). (CVE-2025-1220) (Jakub Zelenka) - Tidy: . Fix memory leak in tidy output handler on error. (nielsdos) . Fix tidyOptIsReadonly deprecation, using tidyOptGetCategory. (David Carlier) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.25 2025/06/11 14:58:27 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.23.tar.xz) = dd18090efa68c7130d0ca99a8e2c31644e30fa1e23c363f7fc9ed23518e43ce1 SHA512 (php-8.3.23.tar.xz) = c3dd534d5597ff9c1b64bfd1662984ef768030cd418e11e594f80e3e851e15e0d2da9ed1639c3e367a8e849b22bcd97e0117b4e19265fa2c86edd747a7c39191 Size (php-8.3.23.tar.xz) = 12577624 bytes @ 1.25 log @lang/php{74,81,82,83,84}: correct include_path Correct default include_path in configuration files. Bump PKGREVISION. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.24 2025/06/08 16:27:30 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.22.tar.xz) = 90934219c8efa794845cd474bc518eb9e6c3d131f85505cf2a153c5693e9dbf1 SHA512 (php-8.3.22.tar.xz) = 58a107531bb6a28c058fd45a6fd2cab049ebd1ca541729dea2e9c08bd1cbe25279fdb30a10da138efd2ccad424c4fe0b06b5a40c34aad249ceed1cfae3110b67 Size (php-8.3.22.tar.xz) = 12555076 bytes @ 1.25.2.1 log @Pullup ticket #6978 - requested by taca lang/php83: Security fix Revisions pulled up: - lang/php/phpversion.mk 1.470 - lang/php83/Makefile 1.17 - lang/php83/distinfo 1.26 --- Module Name: pkgsrc Committed By: taca Date: Fri Jul 4 01:25:48 UTC 2025 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php83: Makefile distinfo Log Message: lang/php83: update to 8.3.23 PHP 8.3.23 (2025-07-03) - Core: . Fixed GH-18695 (zend_ast_export() - float number is not preserved). (Oleg Efimov) . Do not delete main chunk in zend_gc. (danog, Arnaud) . Fix compile issues with zend_alloc and some non-default options. (nielsdos) - Curl: . Fix memory leak when setting a list via curl_setopt fails. (nielsdos) . Fix incorrect OpenSSL version detection. (Peter Kokot) - Date: . Fix leaks with multiple calls to DatePeriod iterator current(). (nielsdos) - FPM: . Fixed GH-18662 (fpm_get_status segfault). (txuna) - Hash: . Fixed bug GH-14551 (PGO build fails with xxhash). (nielsdos) - Intl: . Fix memory leak in intl_datetime_decompose() on failure. (nielsdos) . Fix memory leak in locale lookup on failure. (nielsdos) - ODBC: . Fix memory leak on php_odbc_fetch_hash() failure. (nielsdos) - Opcache: . Fixed bug GH-18743 (Incompatibility in Inline TLS Assembly on Alpine 3.22). (nielsdos, Arnaud) - OpenSSL: . Fix memory leak of X509_STORE in php_openssl_setup_verify() on failure. (nielsdos) . Fixed bug #74796 (Requests through http proxy set peer name). (Jakub Zelenka) - PGSQL: . Fixed GHSA-hrwm-9436-5mv3 (pgsql extension does not check for errors during escaping). (CVE-2025-1735) (Jakub Zelenka) - Phar: . Add missing filter cleanups on phar failure. (nielsdos) . Fixed bug GH-18642 (Signed integer overflow in ext/phar fseek). (nielsdos) - PHPDBG: . Fix 'phpdbg --help' segfault on shutdown with USE_ZEND_ALLOC=0. (nielsdos) - PDO ODBC: . Fix memory leak if WideCharToMultiByte() fails. (nielsdos) - PGSQL: . Fix warning not being emitted when failure to cancel a query with pg_cancel_query(). (Girgias) - Random: . Fix reference type confusion and leak in user random engine. (nielsdos, timwolla) - Readline: . Fix memory leak when calloc() fails in php_readline_completion_cb(). (nielsdos) - SOAP: . Fix memory leaks in php_http.c when call_user_function() fails. (nielsdos) . Fixed GHSA-453j-q27h-5p8x (NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix). (CVE-2025-6491) (Lekssays, nielsdos) - Standard: . Fixed GHSA-3cr5-j632-f35r (Null byte termination in hostnames). (CVE-2025-1220) (Jakub Zelenka) - Tidy: . Fix memory leak in tidy output handler on error. (nielsdos) . Fix tidyOptIsReadonly deprecation, using tidyOptGetCategory. (David Carlier) @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (php-8.3.23.tar.xz) = dd18090efa68c7130d0ca99a8e2c31644e30fa1e23c363f7fc9ed23518e43ce1 SHA512 (php-8.3.23.tar.xz) = c3dd534d5597ff9c1b64bfd1662984ef768030cd418e11e594f80e3e851e15e0d2da9ed1639c3e367a8e849b22bcd97e0117b4e19265fa2c86edd747a7c39191 Size (php-8.3.23.tar.xz) = 12577624 bytes @ 1.24 log @lang/php83: update to 8.3.22 PHP 8.3.22 (2025-06-05) - Core: . Fixed GH-18480 (array_splice with large values for offset/length arguments). (nielsdos/David Carlier) . Partially fixed GH-18572 (nested object comparisons leading to stack overflow). (David Carlier) . Fixed OSS-Fuzz #417078295. (nielsdos) . Fixed OSS-Fuzz #418106144. (nielsdos) - Curl: . Fixed GH-18460 (curl_easy_setopt with CURLOPT_USERPWD/CURLOPT_USERNAME/ CURLOPT_PASSWORD set the Authorization header when set to NULL). (David Carlier) - Date: . Fixed bug GH-18076 (Since PHP 8, the date_sun_info() function returns inaccurate sunrise and sunset times, but other calculated times are correct) (JiriJozif). . Fixed bug GH-18481 (date_sunrise with unexpected nan value for the offset). (nielsdos/David Carlier) - Intl: . Fix various reference issues. (nielsdos) - LDAP: . Fixed bug GH-18529 (ldap no longer respects TLS_CACERT from ldaprc in ldap_start_tls()). (Remi) - Opcache: . Fixed bug GH-18417 (Windows SHM reattachment fails when increasing memory_consumption or jit_buffer_size). (nielsdos) . Fixed bug GH-18567 (Preloading with internal class alias triggers assertion failure). (nielsdos) . Fix leak of accel_globals->key. (nielsdos) - OpenSSL: . Fix missing checks against php_set_blocking() in xp_ssl.c. (nielsdos) - PDO_OCI: . Fixed bug GH-18494 (PDO OCI segfault in statement GC). (nielsdos) - SPL: . Fixed bug GH-18421 (Integer overflow with large numbers in LimitIterator). (nielsdos) - Standard: . Fixed bug GH-17403 (Potential deadlock when putenv fails). (nielsdos) . Fixed bug GH-18509 (Dynamic calls to assert() ignore zend.assertions). (timwolla) - Windows: . Fix leak+crash with sapi_windows_set_ctrl_handler(). (nielsdos) - Zip: . Fixed bug GH-18431 (Registering ZIP progress callback twice doesn't work). (nielsdos) . Fixed bug GH-18438 (Handling of empty data and errors in ZipArchive::addPattern). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.23 2025/05/19 15:00:56 taca Exp $ d18 2 a19 2 SHA1 (patch-php.ini-development) = 73ff10ef292404e2788897ce893a99758cf4962c SHA1 (patch-php.ini-production) = dbffa0ccc84b604f9efb58d9fee0b9dd0295801f @ 1.23 log @lang/php83: update to 8.3.21 PHP 8.3.21 (2025-05-08) Core: * Fixed bug GH-18304 (Changing the properties of a DateInterval through dynamic properties triggers a SegFault). * Fix some leaks in php_scandir. Filter: * Fixed bug GH-18309 (ipv6 filter integer overflow). GD: * Fixed imagecrop() overflow with rect argument with x/width y/heigh usage in gdImageCrop(). * Fixed GH-18243 imagettftext() overflow/underflow on font size value. Intl: * Fix reference support for intltz_get_offset(). LDAP: * Fixed bug GH-17776 (LDAP_OPT_X_TLS_* options can't be overridden). * Fix NULL deref on high modification key. libxml: * Fixed custom external entity loader returning an invalid resource leading to a confusing TypeError message. OpenSSL: * Fix memory leak in openssl_sign() when passing invalid algorithm. * Fix potential leaks when writing to BIO fails. PDO Firebird: * Fixed GH-18276 - persistent connection - "zend_mm_heap corrupted" with setAttribute() (SakiTakamachi). SPL: * Fixed bug GH-18322 (SplObjectStorage debug handler mismanages memory). Standard: * Fixed bug GH-18145 (php8ts crashes in php_clear_stat_cache()). * Fixed bug GH-18209 (Use-after-free in extract() with EXTR_REFS). * Fixed bug GH-18212 (fseek with SEEK_CUR whence value and negative offset leads to negative stream position). * Fix resource leak in iptcembed() on error. Zip: * Fix uouv when handling empty options in ZipArchive::addGlob(). * Fix memory leak when handling a too long path in ZipArchive::addGlob(). @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.22 2025/04/13 15:56:18 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.21.tar.xz) = 624d55f08aead806d0f30d01e68e0bff6093c4e95425fe3df2a080af40469dda SHA512 (php-8.3.21.tar.xz) = 63ab270ef6fde033245e134ba7c1824b7e449a667ab7a6ffe001e18b7fc26218eefe55959b8be9093c35fd6437175244c40f3e4efe72478fe7819573bb4973b2 Size (php-8.3.21.tar.xz) = 12565664 bytes @ 1.22 log @lang/php83: update to 8.3.20 This is a bug fix release. PHP 8.3.20 (2025-04-10) Core: * Fixed bug GH-17961 (use-after-free during dl()'ed module class destruction). * Fixed bug GH-15367 (dl() of module with aliased class crashes in shutdown). * Fixed bug GH-13193 again (Significant performance degradation in 'foreach'). DOM: * Fix weird unpack behaviour in DOM. * Fix xinclude destruction of live attributes. Embed: * Fixed bug GH-8533 (Unable to link dynamic libphp on Mac). Fuzzer: * Fixed bug GH-18081 (Memory leaks in error paths of fuzzer SAPI). GD: * Fixed bug GH-17984 (calls with arguments as array with references). Intl: * Fix locale_compose and locale_lookup to work with their array argument with values as references. * Fix dateformat_format when the time is an array of references. * Fix UConverter::transcode with substitutes as references. Mbstring: * Fixed bug GH-17989 (mb_output_handler crash with unset http_output_conv_mimetypes). Opcache: * Fixed bug GH-18112 (NULL access with preloading and INI option). * Fixed bug GH-18107 (Opcache CFG jmp optimization with try-finally breaks the exception table). PDO: * Fix memory leak when destroying PDORow. SOAP: * Fixed bug #66049 (Typemap can break parsing in parse_packet_soap leading to a segfault) . SPL: * Fixed bug GH-18018 (RC1 data returned from offsetGet causes UAF in ArrayObject). Treewide: * Fixed bug GH-17736 (Assertion failure zend_reference_destroy()). Windows: * Fixed bug GH-17836 (zend_vm_gen.php shouldn't break on Windows line endings). @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.21 2025/04/07 17:33:36 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.20.tar.xz) = 87a88cc7b033c94aac11f1a29718ea8fef7ca0d879e8c351c592c76bc264ce1d SHA512 (php-8.3.20.tar.xz) = 2641a721ca0cbcb05200217ba38c7d0707b6294c355e109486180beccf0f5fa4822f92caab479a473bfccf93558a5bc34d42ef271355022701d62e2d11afeff9 Size (php-8.3.20.tar.xz) = 12549020 bytes @ 1.21 log @Correct pear path in configure.ac for consistency. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.20 2025/03/13 15:16:17 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.19.tar.xz) = c5119f2fa7692da110db99b803c46d67c004a29cc67a1b0b4ad3a7ae46c7b932 SHA512 (php-8.3.19.tar.xz) = 2872639f6a6de1680540da5a2df43db7ceeb7e25690b6f66d73373779ee3f9b0c2fe74aeeb7181749c9738b64f8d41b8a6f496751778c1df10b7f9aab43f21f7 Size (php-8.3.19.tar.xz) = 12560852 bytes d8 1 a8 1 SHA1 (patch-build_Makefile.global) = 87c533087a536649b5f51108ef4f4b72c8efc5b2 @ 1.20 log @lang/php83: update to 8.3.19 This is security release. (PHP 8.3.18 seems to be skipped.) PHP 8.3.19 (2025-03-13) - BCMath: . Fixed bug GH-17398 (bcmul memory leak). (SakiTakamachi) - Core: . Fixed bug GH-17623 (Broken stack overflow detection for variable compilation). (ilutov) . Fixed bug GH-17618 (UnhandledMatchError does not take zend.exception_ignore_args=1 into account). (timwolla) . Fix fallback paths in fast_long_{add,sub}_function. (nielsdos) . Fixed bug GH-17718 (Calling static methods on an interface that has `__callStatic` is allowed). (timwolla) . Fixed bug GH-17797 (zend_test_compile_string crash on invalid script path). (David Carlier) . Fixed GHSA-rwp7-7vc6-8477 (Reference counting in php_request_shutdown causes Use-After-Free). (CVE-2024-11235) (ilutov) - DOM: . Fixed bug GH-17847 (xinclude destroys live node). (nielsdos) - FFI: . Fix FFI Parsing of Pointer Declaration Lists. (davnotdev) - FPM: . Fixed bug GH-17643 (FPM with httpd ProxyPass encoded PATH_INFO env). (Jakub Zelenka) - GD: . Fixed bug GH-17772 (imagepalettetotruecolor crash with memory_limit=2M). (David Carlier) - LDAP: . Fixed bug GH-17704 (ldap_search fails when $attributes contains a non-packed array with numerical keys). (nielsdos, 7u83) - LibXML: . Fixed GHSA-wg4p-4hqh-c3g9 (Reocurrence of #72714). (nielsdos) . Fixed GHSA-p3x9-6h7p-cgfc (libxml streams use wrong `content-type` header when requesting a redirected resource). (CVE-2025-1219) (timwolla) - MBString: . Fixed bug GH-17503 (Undefined float conversion in mb_convert_variables). (cmb) - Opcache: . Fixed bug GH-17654 (Multiple classes using same trait causes function JIT crash). (nielsdos) . Fixed bug GH-17577 (JIT packed type guard crash). (nielsdos, Dmitry) . Fixed bug GH-17899 (zend_test_compile_string with invalid path when opcache is enabled). (David Carlier) . Fixed bug GH-17868 (Cannot allocate memory with tracing JIT). (nielsdos) - PDO_SQLite: . Fixed GH-17837 ()::getColumnMeta() on unexecuted statement segfaults). (cmb) . Fix cycle leak in sqlite3 setAuthorizer(). (nielsdos) - Phar: . Fixed bug GH-17808: PharFileInfo refcount bug. (nielsdos) - PHPDBG: . Partially fixed bug GH-17387 (Trivial crash in phpdbg lexer). (nielsdos) . Fix memory leak in phpdbg calling registered function. (nielsdos) - Reflection: . Fixed bug GH-15902 (Core dumped in ext/reflection/php_reflection.c). (DanielEScherzer) - Standard: . Fixed bug #72666 (stat cache clearing inconsistent between file:// paths and plain paths). (Jakub Zelenka) - Streams: . Fixed bug GH-17650 (realloc with size 0 in user_filters.c). (nielsdos) . Fix memory leak on overflow in _php_stream_scandir(). (nielsdos) . Fixed GHSA-hgf54-96fm-v528 (Stream HTTP wrapper header check might omit basic auth header). (CVE-2025-1736) (Jakub Zelenka) . Fixed GHSA-52jp-hrpf-2jff (Stream HTTP wrapper truncate redirect location to 1024 bytes). (CVE-2025-1861) (Jakub Zelenka) . Fixed GHSA-pcmh-g36c-qc44 (Streams HTTP wrapper does not fail for headers without colon). (CVE-2025-1734) (Jakub Zelenka) . Fixed GHSA-v8xr-gpvj-cx9g (Header parser of `http` stream wrapper does not handle folded headers). (CVE-2025-1217) (Jakub Zelenka) - Windows: . Fixed phpize for Windows 11 (24H2). (bwoebi) . Fixed GH-17855 (CURL_STATICLIB flag set even if linked with shared lib). (cmb) - Zlib: . Fixed bug GH-17745 (zlib extension incorrectly handles object arguments). (nielsdos) . Fix memory leak when encoding check fails. (nielsdos) . Fix zlib support for large files. (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.19 2025/02/17 15:28:31 taca Exp $ d10 1 a10 1 SHA1 (patch-configure.ac) = d3bb35c423250d1124e2ada0974fc93448634abb @ 1.19 log @lang/php83: update to 8.3.17 PHP 8.3.17 (2025-02-13) - Core: . Fixed bug GH-16892 (ini_parse_quantity() fails to parse inputs starting with 0x0b). (nielsdos) . Fixed bug GH-16886 (ini_parse_quantity() fails to emit warning for 0x+0). (nielsdos) . Fixed bug GH-17214 (Relax final+private warning for trait methods with inherited final). (ilutov) . Fixed NULL arithmetic during system program execution on Windows. (cmb, nielsdos) . Fixed potential OOB when checking for trailing spaces on Windows. (cmb) . Fixed bug GH-17408 (Assertion failure Zend/zend_exceptions.c). (nielsdos, ilutov) . Fix may_have_extra_named_args flag for ZEND_AST_UNPACK. (nielsdos) . Fix NULL arithmetic in System V shared memory emulation for Windows. (cmb) - DOM: . Fixed bug GH-17500 (Segfault with requesting nodeName on nameless doctype). (nielsdos) - Enchant: . Fix crashes in enchant when passing null bytes. (nielsdos) - FTP: . Fixed bug GH-16800 (ftp functions can abort with EINTR). (nielsdos) - GD: . Fixed bug GH-17349 (Tiled truecolor filling looses single color transparency). (cmb) . Fixed bug GH-17373 (imagefttext() ignores clipping rect for palette images). (cmb) . Ported fix for libgd 223 (gdImageRotateGeneric() does not properly interpolate). (cmb) - Intl: . Fixed bug GH-11874 (intl causing segfault in docker images). (nielsdos) . Fixed bug GH-17469 (UConverter::transcode always emit E_WARNING on invalid encoding). (David Carlier) - Opcache: . Fixed bug GH-17307 (Internal closure causes JIT failure). (nielsdos) . Fixed bug GH-17564 (Potential UB when reading from / writing to struct padding). (ilutov) - PDO: . Fixed a memory leak when the GC is used to free a PDOStatment. (Girgias) . Fixed a crash in the PDO Firebird Statement destructor. (nielsdos) . Fixed UAFs when changing default fetch class ctor args. (Girgias, nielsdos) - Phar: . Fixed bug GH-17518 (offset overflow phar extractTo()). (nielsdos) - PHPDBG: . Fix crashes in function registration + test. (nielsdos, Girgias) - Session: . Fix type confusion with session SID constant. (nielsdos) . Fixed bug GH-17541 (ext/session NULL pointer dereferencement during ID reset). (Girgias) - SimpleXML: . Fixed bug GH-17409 (Assertion failure Zend/zend_hash.c:1730). (nielsdos) - SNMP: . Fixed bug GH-17330 (SNMP::setSecurity segfault on closed session). (David Carlier) - SPL: . Fixed bug GH-17463 (crash on SplTempFileObject::ftruncate with negative value). (David Carlier) - Zip: . Fixed bug GH-17139 (Fix zip_entry_name() crash on invalid entry). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.18 2025/02/08 02:59:57 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.17.tar.xz) = 474ba0cc03fe6142637634018c68aa3cbc5b4801996fafb7aa68f42a6260f995 SHA512 (php-8.3.17.tar.xz) = 78ec7896ecaaab7e968914055e11c840f64492d55c68ae6ee693a5c96b633b8b75093fc334836832422a24d4156d86e8e0c4af2f87cbd861df8b67842f1bcf88 Size (php-8.3.17.tar.xz) = 12541560 bytes @ 1.18 log @lang/php83: multiple PHP support @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.17 2025/01/19 13:57:17 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.16.tar.xz) = 1b4d6aa1a00a604850aee654576fbede8b5800256f1172a16de9d74b1a377f78 SHA512 (php-8.3.16.tar.xz) = 2caa5c4e1b1b719a67dfefc976d47d289ba6f9b6a527181f2961fff481b258c2e038d6993df7507f4977c5fce59df38d9738cd4186a4602e39bbcbd5c1e2dbf4 Size (php-8.3.16.tar.xz) = 12544360 bytes @ 1.17 log @lang/php83: update to 8.3.16 PHP 8.3.16 (2025-01-16) - Core: . Fixed bug GH-17106 (ZEND_MATCH_ERROR misoptimization). (ilutov) . Fixed bug GH-17162 (zend_array_try_init() with dtor can cause engine UAF). (nielsdos) . Fixed bug GH-17101 (AST->string does not reproduce constructor property promotion correctly). (nielsdos) . Fixed bug GH-17211 (observer segfault on function loaded with dl()). (Arnaud) . Fixed bug GH-17216 (Trampoline crash on error). (nielsdos) - Date: . Fixed bug GH-14709 DatePeriod::__construct() overflow on recurrences. (David Carlier) - DBA: . Skip test if inifile is disabled. (orlitzky) - DOM: . Fixed bug GH-17224 (UAF in importNode). (nielsdos) - Embed: . Make build command for program using embed portable. (dunglas) - FFI: . Fixed bug #79075 (FFI header parser chokes on comments). (nielsdos) . Fix memory leak on ZEND_FFI_TYPE_CHAR conversion failure. (nielsdos) . Fixed bug GH-16013 and bug #80857 (Big endian issues). (Dmitry, nielsdos) - Filter: . Fixed bug GH-16944 (Fix filtering special IPv4 and IPv6 ranges, by using information from RFC 6890). (Derick) - FPM: . Fixed bug GH-13437 (FPM: ERROR: scoreboard: failed to lock (already locked)). (Jakub Zelenka) . Fixed bug GH-17112 (Macro redefinitions). (cmb, nielsdos) . Fixed bug GH-17208 (bug64539-status-json-encoding.phpt fail on 32-bits). (nielsdos) - GD: . Fixed bug GH-16255 (Unexpected nan value in ext/gd/libgd/gd_filter.c). (nielsdos, cmb) . Ported fix for libgd bug 276 (Sometimes pixels are missing when storing images as BMPs). (cmb) - Gettext: . Fixed bug GH-17202 (Segmentation fault ext/gettext/gettext.c bindtextdomain()). (Michael Orlitzky) - Iconv: . Fixed bug GH-17047 (UAF on iconv filter failure). (nielsdos) - LDAP: . Fixed bug GH-17280 (ldap_search() fails when $attributes array has holes). (nielsdos) - LibXML: . Fixed bug GH-17223 (Memory leak in libxml encoding handling). (nielsdos) - MBString: . Fixed bug GH-17112 (Macro redefinitions). (nielsdos, cmb) - Opcache: . opcache_get_configuration() properly reports jit_prof_threshold. (cmb) . Fixed bug GH-17246 (GC during SCCP causes segfault). (Dmitry) - PCNTL: . Fix memory leak in cleanup code of pcntl_exec() when a non stringable value is encountered past the first entry. (Girgias) - PgSql: . Fixed bug GH-17158 (pg_fetch_result Shows Incorrect ArgumentCountError Message when Called With 1 Argument). (nielsdos) . Fixed further ArgumentCountError for calls with flexible number of arguments. (David Carlier) - Phar: . Fixed bug GH-17137 (Segmentation fault ext/phar/phar.c). (nielsdos) - SimpleXML: . Fixed bug GH-17040 (SimpleXML's unset can break DOM objects). (nielsdos) . Fixed bug GH-17153 (SimpleXML crash when using autovivification on document). (nielsdos) - Sockets: . Fixed bug GH-16276 (socket_strerror overflow handling with INT_MIN). (David Carlier / cmb) . Fixed overflow on SO_LINGER values setting, strengthening values check on SO_SNDTIMEO/SO_RCVTIMEO for socket_set_option(). (David Carlier) - SPL: . Fixed bug GH-17225 (NULL deref in spl_directory.c). (nielsdos) - Streams: . Fixed bug GH-17037 (UAF in user filter when adding existing filter name due to incorrect error handling). (nielsdos) . Fixed bug GH-16810 (overflow on fopen HTTP wrapper timeout value). (David Carlier) . Fixed bug GH-17067 (glob:// wrapper doesn't cater to CWD for ZTS builds). (cmb) - Windows: . Hardened proc_open() against cmd.exe hijacking. (cmb) - XML: . Fixed bug GH-1718 (unreachable program point in zend_hash). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.16 2024/12/24 14:35:10 taca Exp $ d8 3 a10 1 SHA1 (patch-build_php.m4) = c85864ae22556c0a5f14b323d2cf031523625e9b d18 3 a20 3 SHA1 (patch-php.ini-development) = 373d76cc7a022b578f1d5e296d1f0ac88bc26b72 SHA1 (patch-php.ini-production) = 5ab7fa6bf8403907160b0a62b56c1ee527f8eda6 SHA1 (patch-sapi_apache2handler_config.m4) = c5650a7d07a8213038fe2e2a6a1ce345d325df82 d22 1 d24 6 a29 1 SHA1 (patch-sapi_fpm_php-fpm.conf.in) = acf9b4e70d4c5ea2b96e37e7bbf9005379ecc4d0 @ 1.16 log @lang/php83: update to 8.3.15 8.3.15 (2024-12-19) Calendar: * Fixed jdtogregorian overflow. * Fixed cal_to_jd julian_days argument overflow. COM: * Fixed bug GH-16991 (Getting typeinfo of non DISPATCH variant segfaults). Core: * Fail early in *nix configuration build script. * Fixed bug GH-16727 (Opcache bad signal 139 crash in ZTS bookworm (frankenphp)). * Fixed bug GH-16799 (Assertion failure at Zend/zend_vm_execute.h:7469). * Fixed bug GH-16630 (UAF in lexer with encoding translation and heredocs). * Fix is_zend_ptr() huge block comparison. * Fixed potential OOB read in zend_dirname() on Windows. Curl: * Fixed bug GH-16802 (open_basedir bypass using curl extension). * Fix various memory leaks in curl mime handling. DOM: * Fixed bug GH-16777 (Calling the constructor again on a DOM object after it is in a document causes UAF). * Fixed bug GH-16906 (Reloading document can cause UAF in iterator). FPM: * Fixed GH-16432 (PHP-FPM 8.2 SIGSEGV in fpm_get_status). GD: * Fixed GH-16776 (imagecreatefromstring overflow). GMP: * Fixed bug GH-16890 (array_sum() with GMP can loose precision (LLP64)). Hash: * Fixed GH-16711: Segfault in mhash(). Opcache: * Fixed bug GH-16770 (Tracing JIT type mismatch when returning UNDEF). * Fixed bug GH-16851 (JIT_G(enabled) not set correctly on other threads). * Fixed bug GH-16902 (Set of opcache tests fail zts+aarch64). OpenSSL: * Prevent unexpected array entry conversion when reading key. * Fix various memory leaks related to openssl exports. * Fix memory leak in php_openssl_pkey_from_zval(). PDO: * Fixed memory leak of `setFetchMode()`. Phar: * Fixed bug GH-16695 (phar:// tar parser and zero-length file header blocks). PHPDBG: * Fixed bug GH-15208 (Segfault with breakpoint map and phpdbg_clear()). SAPI: * Fixed bug GH-16998 (UBSAN warning in rfc1867). SimpleXML: * Fixed bug GH-16808 (Segmentation fault in RecursiveIteratorIterator ->current() with a xml element input). SOAP: * Fix make check being invoked in ext/soap. Standard: * Fixed bug GH-16905 (Internal iterator functions can't handle UNDEF properties). * Fixed bug GH-16957 (Assertion failure in array_shift with self-referencing array). Streams: * Fixed network connect poll interuption handling. Windows: * Fixed bug GH-16849 (Error dialog causes process to hang). @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.15 2024/11/25 14:36:20 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.15.tar.xz) = a94ce86342e2a59006d8c3cfb38520c84febabc3d9d36521f167fda7d28c4d62 SHA512 (php-8.3.15.tar.xz) = 43057cca0a6c2187f7991dfbf9743495784f0fa4d0336f08392036ecc2b6f83c7155737ebef3af6144a79eca557bf84cba4aedd34e0d19c701249ca4e8fa86d0 Size (php-8.3.15.tar.xz) = 12525028 bytes @ 1.15 log @lang/php82: update to 8.2.26 PHP 8.3.14 (2024-11-21) - CLI: . Fixed bug GH-16373 (Shebang is not skipped for router script in cli-server started through shebang). (ilutov) . Fixed bug GHSA-4w77-75f9-2c8w (Heap-Use-After-Free in sapi_read_post_data Processing in CLI SAPI Interface). (nielsdos) - COM: . Fixed out of bound writes to SafeArray data. (cmb) - Core: . Fixed bug GH-16168 (php 8.1 and earlier crash immediately when compiled with Xcode 16 clang on macOS 15). (nielsdos) . Fixed bug GH-16371 (Assertion failure in Zend/zend_weakrefs.c:646). (Arnaud) . Fixed bug GH-16515 (Incorrect propagation of ZEND_ACC_RETURN_REFERENCE for call trampoline). (ilutov) . Fixed bug GH-16509 (Incorrect line number in function redeclaration error). (ilutov) . Fixed bug GH-16508 (Incorrect line number in inheritance errors of delayed early bound classes). (ilutov) . Fixed bug GH-16648 (Use-after-free during array sorting). (ilutov) - Curl: . Fixed bug GH-16302 (CurlMultiHandle holds a reference to CurlHandle if curl_multi_add_handle fails). (timwolla) - Date: . Fixed bug GH-16454 (Unhandled INF in date_sunset() with tiny $utcOffset). (cmb) . Fixed bug GH-14732 (date_sun_info() fails for non-finite values). (cmb) - DBA: . Fixed bug GH-16390 (dba_open() can segfault for "pathless" streams). (cmb) - DOM: . Fixed bug GH-16316 (DOMXPath breaks when not initialized properly). (nielsdos) . Add missing hierarchy checks to replaceChild. (nielsdos) . Fixed bug GH-16336 (Attribute intern document mismanagement). (nielsdos) . Fixed bug GH-16338 (Null-dereference in ext/dom/node.c). (nielsdos) . Fixed bug GH-16473 (dom_import_simplexml stub is wrong). (nielsdos) . Fixed bug GH-16533 (Segfault when adding attribute to parent that is not an element). (nielsdos) . Fixed bug GH-16535 (UAF when using document as a child). (nielsdos) . Fixed bug GH-16593 (Assertion failure in DOM->replaceChild). (nielsdos) . Fixed bug GH-16595 (Another UAF in DOM -> cloneNode). (nielsdos) - EXIF: . Fixed bug GH-16409 (Segfault in exif_thumbnail when not dealing with a real file). (nielsdos, cmb) - FFI: . Fixed bug GH-16397 (Segmentation fault when comparing FFI object). (nielsdos) - Filter: . Fixed bug GH-16523 (FILTER_FLAG_HOSTNAME accepts ending hyphen). (cmb) - FPM: . Fixed bug GH-16628 (FPM logs are getting corrupted with this log statement). (nielsdos) - GD: . Fixed bug GH-16334 (imageaffine overflow on matrix elements). (David Carlier) . Fixed bug GH-16427 (Unchecked libavif return values). (cmb) . Fixed bug GH-16559 (UBSan abort in ext/gd/libgd/gd_interpolation.c:1007). (nielsdos) - GMP: . Fixed floating point exception bug with gmp_pow when using large exposant values. (David Carlier). . Fixed bug GH-16411 (gmp_export() can cause overflow). (cmb) . Fixed bug GH-16501 (gmp_random_bits() can cause overflow). (David Carlier) . Fixed gmp_pow() overflow bug with large base/exponents. (David Carlier) . Fixed segfaults and other issues related to operator overloading with GMP objects. (Girgias) - LDAP: . Fixed bug GHSA-g665-fm4p-vhff (OOB access in ldap_escape). (CVE-2024-8932) (nielsdos) - MBstring: . Fixed bug GH-16361 (mb_substr overflow on start/length arguments). (David Carlier) - MySQLnd: . Fixed bug GHSA-h35g-vwh6-m678 (Leak partial content of the heap through heap buffer over-read). (CVE-2024-8929) (Jakub Zelenka) - Opcache: . Fixed bug GH-16408 (Array to string conversion warning emitted in optimizer). (ilutov) - OpenSSL: . Fixed bug GH-16357 (openssl may modify member types of certificate arrays). (cmb) . Fixed bug GH-16433 (Large values for openssl_csr_sign() $days overflow). (cmb) . Fix various memory leaks on error conditions in openssl_x509_parse(). (nielsdos) - PDO DBLIB: . Fixed bug GHSA-5hqh-c84r-qjcv (Integer overflow in the dblib quoter causing OOB writes). (CVE-2024-11236) (nielsdos) - PDO Firebird: . Fixed bug GHSA-5hqh-c84r-qjcv (Integer overflow in the firebird quoter causing OOB writes). (CVE-2024-11236) (nielsdos) - PDO ODBC: . Fixed bug GH-16450 (PDO_ODBC can inject garbage into field values). (cmb) - Phar: . Fixed bug GH-16406 (Assertion failure in ext/phar/phar.c:2808). (nielsdos) - PHPDBG: . Fixed bug GH-16174 (Empty string is an invalid expression for ev). (cmb) - Reflection: . Fixed bug GH-16601 (Memory leak in Reflection constructors). (nielsdos) - Session: . Fixed bug GH-16385 (Unexpected null returned by session_set_cookie_params). (nielsdos) . Fixed bug GH-16290 (overflow on cookie_lifetime ini value). (David Carlier) - SOAP: . Fixed bug GH-16318 (Recursive array segfaults soap encoding). (nielsdos) . Fixed bug GH-16429 (Segmentation fault access null pointer in SoapClient). (nielsdos) - Sockets: . Fixed bug with overflow socket_recvfrom $length argument. (David Carlier) - SPL: . Fixed bug GH-16337 (Use-after-free in SplHeap). (nielsdos) . Fixed bug GH-16464 (Use-after-free in SplDoublyLinkedList::offsetSet()). (ilutov) . Fixed bug GH-16479 (Use-after-free in SplObjectStorage::setInfo()). (ilutov) . Fixed bug GH-16478 (Use-after-free in SplFixedArray::unset()). (ilutov) . Fixed bug GH-16588 (UAF in Observer->serialize). (nielsdos) . Fix GH-16477 (Segmentation fault when calling __debugInfo() after failed SplFileObject::__constructor). (Girgias) . Fixed bug GH-16589 (UAF in SplDoublyLinked->serialize()). (nielsdos) . Fixed bug GH-14687 (segfault on SplObjectIterator instance). (David Carlier) . Fixed bug GH-16604 (Memory leaks in SPL constructors). (nielsdos) . Fixed bug GH-16646 (UAF in ArrayObject::unset() and ArrayObject::exchangeArray()). (ilutov) - Standard: . Fixed bug GH-16293 (Failed assertion when throwing in assert() callback with bail enabled). (ilutov) - Streams: . Fixed bug GHSA-c5f2-jwm7-mmq2 (Configuring a proxy in a stream context might allow for CRLF injection in URIs). (CVE-2024-11234) (Jakub Zelenka) . Fixed bug GHSA-r977-prxv-hc43 (Single byte overread with convert.quoted-printable-decode filter). (CVE-2024-11233) (nielsdos) - SysVMsg: . Fixed bug GH-16592 (msg_send() crashes when a type does not properly serialized). (David Carlier / cmb) - SysVShm: . Fixed bug GH-16591 (Assertion error in shm_put_var). (nielsdos, cmb) - XMLReader: . Fixed bug GH-16292 (Segmentation fault in ext/xmlreader/php_xmlreader.c). (nielsdos) - Zlib: . Fixed bug GH-16326 (Memory management is broken for bad dictionaries.) (cmb) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.14 2024/11/10 22:09:50 prlw1 Exp $ d3 3 a5 3 BLAKE2s (php-8.3.14.tar.xz) = 1ff4d97ae5d0fa3a1019cb986df86a92833c2fe4a46307b1759fb4695cb33c4a SHA512 (php-8.3.14.tar.xz) = 48a995a5095626dc1b8bb40641e86f01e6806ce10a8c159a402f3b081f8464429ef2d33c3a288cb0f7c643c9236601220dfc604d36b3c2a572cd9f30e5359752 Size (php-8.3.14.tar.xz) = 12519488 bytes @ 1.14 log @php83 Backport of https://github.com/php/php-src/commit/2d6bd1644d104fe934a5117d232d3f50ffe9ff28 to fix Cannot load lib/httpd/mod_php8.so into server: /usr/pkg/lib/httpd/mod_php8.so: No space available for static Thread Local Storage PR pkg/56717 @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.13 2024/10/24 13:52:06 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.13.tar.xz) = bd76f27687418dc834d2c31f92b2592c190689e78896ec556cfaec76cfa3a934 SHA512 (php-8.3.13.tar.xz) = e910671375e18dcd90822b4d16bda9b878271b78dc83ef4b7834c0ddf042c82d72cd501c12aaa4550ee530ff3a315d0f468dcf3858db0814d5366048dfdbca65 Size (php-8.3.13.tar.xz) = 12484032 bytes @ 1.13 log @lang/php83: update to 8.3.13 24 Oct 2024, PHP 8.3.13 - Calendar: . Fixed GH-16240: jdtounix overflow on argument value. (David Carlier) . Fixed GH-16241: easter_days/easter_date overflow on year argument. (David Carlier) . Fixed GH-16263: jddayofweek overflow. (cmb) . Fixed GH-16234: jewishtojd overflow. (nielsdos) - CLI: . Fixed bug GH-16137: duplicate http headers when set several times by the client. (David Carlier) - Core: . Fixed bug GH-16054 (Segmentation fault when resizing hash table iterator list while adding). (nielsdos) . Fixed bug GH-15905 (Assertion failure for TRACK_VARS_SERVER). (cmb) . Fixed bug GH-15907 (Failed assertion when promoting Serialize deprecation to exception). (ilutov) . Fixed bug GH-15851 (Segfault when printing backtrace during cleanup of nested generator frame). (ilutov) . Fixed bug GH-15866 (Core dumped in Zend/zend_generators.c). (Arnaud) . Fixed bug GH-16188 (Assertion failure in Zend/zend_exceptions.c). (Arnaud) . Fixed bug GH-16233 (Observer segfault when calling user function in internal function via trampoline). (nielsdos) - DOM: . Fixed bug GH-16039 (Segmentation fault (access null pointer) in ext/dom/parentnode/tree.c). (nielsdos) . Fixed bug GH-16149 (Null pointer dereference in DOMElement->getAttributeNames()). (nielsdos) . Fixed bug GH-16151 (Assertion failure in ext/dom/parentnode/tree.c). (nielsdos) . Fixed bug GH-16150 (Use after free in php_dom.c). (nielsdos) . Fixed bug GH-16152 (Memory leak in DOMProcessingInstruction/DOMDocument). (nielsdos) - JSON: . Fixed bug GH-15168 (stack overflow in json_encode()). (nielsdos) - GD: . Fixed bug GH-16232 (bitshift overflow on wbmp file content reading / fix backport from upstream). (David Carlier) . Fixed bug GH-12264 (overflow/underflow on imagerotate degrees value) (David Carlier) . Fixed bug GH-16274 (imagescale underflow on RBG channels / fix backport from upstream). (David Carlier) - LDAP: . Fixed bug GH-16032 (Various NULL pointer dereferencements in ldap_modify_batch()). (Girgias) . Fixed bug GH-16101 (Segfault in ldap_list(), ldap_read(), and ldap_search() when LDAPs array is not a list). (Girgias) . Fix GH-16132 (php_ldap_do_modify() attempts to free pointer not allocated by ZMM.). (Girgias) . Fix GH-16136 (Memory leak in php_ldap_do_modify() when entry is not a proper dictionary). (Girgias) - MBString: . Fixed bug GH-16261 (Reference invariant broken in mb_convert_variables()). (nielsdos) - OpenSSL: . Fixed stub for openssl_csr_new. (Jakub Zelenka) - PCRE: . Fixed bug GH-16189 (underflow on offset argument). (David Carlier) . Fixed bug GH-16184 (UBSan address overflowed in ext/pcre/php_pcre.c). (nielsdos) - PHPDBG: . Fixed bug GH-15901 (phpdbg: Assertion failure on i funcs). (cmb) . Fixed bug GH-16181 (phpdbg: exit in exception handler reports fatal error). (cmb) - Reflection: . Fixed bug GH-16187 (Assertion failure in ext/reflection/php_reflection.c). (DanielEScherzer) - SAPI: . Fixed bug GH-15395 (php-fpm: zend_mm_heap corrupted with cgi-fcgi request). (Jakub Zelenka, David Carlier) - SimpleXML: . Fixed bug GH-15837 (Segmentation fault in ext/simplexml/simplexml.c). (nielsdos) - Sockets: . Fixed bug GH-16267 (socket_strerror overflow on errno argument). (David Carlier) - SOAP: . Fixed bug #73182 (PHP SOAPClient does not support stream context HTTP headers in array form). (nielsdos) . Fixed bug #62900 (Wrong namespace on xsd import error message). (nielsdos) . Fixed bug GH-15711 (SoapClient can't convert BackedEnum to scalar value). (nielsdos) . Fixed bug GH-16237 (Segmentation fault when cloning SoapServer). (nielsdos) . Fix Soap leaking http_msg on error. (nielsdos) . Fixed bug GH-16256 (Assertion failure in ext/soap/php_encoding.c:460). (nielsdos) . Fixed bug GH-16259 (Soap segfault when classmap instantiation fails). (nielsdos) - SPL: . Fixed bug GH-15918 (Assertion failure in ext/spl/spl_fixedarray.c). (nielsdos) - Standard: . Fixed bug GH-16053 (Assertion failure in Zend/zend_hash.c). (Arnaud) . Fixed bug GH-15169 (stack overflow when var serialization in ext/standard/var). (nielsdos) - Streams: . Fixed bugs GH-15908 and GH-15026 (leak / assertion failure in streams.c). (nielsdos) . Fixed bug GH-15980 (Signed integer overflow in main/streams/streams.c). (cmb) - TSRM: . Prevent closing of unrelated handles. (cmb) - Windows: . Fixed minimal Windows version. (cmb) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.12 2024/09/28 15:03:38 taca Exp $ d6 2 d10 1 @ 1.12 log @lang/php83: update to 8.3.12 PHP 8.3.12 (2024-09-26) - CGI: . Fixed bug GHSA-p99j-rfp4-xqvq (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926) (nielsdos) . Fixed bug GHSA-94p6-54jq-9mwp (cgi.force_redirect configuration is bypassable due to the environment variable collision). (CVE-2024-8927) (nielsdos) - Core: . Fixed bug GH-15408 (MSan false-positve on zend_max_execution_timer). (zeriyoshi) . Fixed bug GH-15515 (Configure error grep illegal option q). (Peter Kokot) . Fixed bug GH-15514 (Configure error: genif.sh: syntax error). (Peter Kokot) . Fixed bug GH-15565 (--disable-ipv6 during compilation produces error EAI_SYSTEM not found). (nielsdos) . Fixed bug GH-15587 (CRC32 API build error on arm 32-bit). (Bernd Kuhls, Thomas Petazzoni) . Fixed bug GH-15330 (Do not scan generator frames more than once). (Arnaud) . Fixed uninitialized lineno in constant AST of internal enums. (ilutov) - Curl: . FIxed bug GH-15547 (curl_multi_select overflow on timeout argument). (David Carlier) - DOM: . Fixed bug GH-15551 (Segmentation fault (access null pointer) in ext/dom/xml_common.h). (nielsdos) . Fixed bug GH-15654 (Signed integer overflow in ext/dom/nodelist.c). (nielsdos) - Fileinfo: . Fixed bug GH-15752 (Incorrect error message for finfo_file with an empty filename argument). (DanielEScherzer) - FPM: . Fixed bug GHSA-865w-9rf3-2wh5 (Logs from childrens may be altered). (CVE-2024-9026) (Jakub Zelenka) - MySQLnd: . Fixed bug GH-15432 (Heap corruption when querying a vector). (cmb, Kamil Tekiela) - Opcache: . Fixed bug GH-15661 (Access null pointer in Zend/Optimizer/zend_inference.c). (nielsdos) . Fixed bug GH-15658 (Segmentation fault in Zend/zend_vm_execute.h). (nielsdos) - SAPI: . Fixed bug GHSA-9pqp-7h25-4f32 (Erroneous parsing of multipart form data). (CVE-2024-8925) (Arnaud) - Standard: . Fixed bug GH-15552 (Signed integer overflow in ext/standard/scanf.c). (cmb) - Streams: . Fixed bug GH-15628 (php_stream_memory_get_buffer() not zero-terminated). (cmb) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.11 2024/08/31 04:36:24 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.12.tar.xz) = 00136a68d893cfe2f69d86b9d86cfe443a8d287417d7abb74969f88d9626c509 SHA512 (php-8.3.12.tar.xz) = 2c4b440fa52950c75934559e977f39a179d1ad9edf8a17fe1b9ff89b58fbcafffb1bc1d59b6df46a9631554f0255c9271d906238c59287c799d195459be3e6a3 Size (php-8.3.12.tar.xz) = 12493432 bytes @ 1.11 log @lang/php83: update to 8.3.11 PHP 8.3.11 (2024-08-29) - Core: . Fixed bug GH-15020 (Memory leak in Zend/Optimizer/escape_analysis.c). (nielsdos) . Fixed bug GH-15023 (Memory leak in Zend/zend_ini.c). (nielsdos) . Fixed bug GH-13330 (Append -Wno-implicit-fallthrough flag conditionally). (Peter Kokot) . Fix uninitialized memory in network.c. (nielsdos) . Fixed bug GH-15108 (Segfault when destroying generator during shutdown). (Arnaud) . Fixed bug GH-15275 (Crash during GC of suspended generator delegate). (Arnaud) - Curl: . Fixed case when curl_error returns an empty string. (David Carlier) - DOM: . Fix UAF when removing doctype and using foreach iteration. (nielsdos) - FFI: . Fixed bug GH-14286 (ffi enum type (when enum has no name) make memory leak). (nielsdos, dstogov) - Hash: . Fix crash when converting array data for array in shm in xxh3. (nielsdos) - Intl: . Fixed bug GH-15087 (IntlChar::foldCase()'s $option is not optional). (cmb) - Opcache: . Fixed bug GH-13817 (Segmentation fault for enabled observers after pass 4). (Bob) . Fixed bug GH-13775 (Memory leak possibly related to opcache SHM placement). (Arnaud, nielsdos) - Output: . Fixed bug GH-15179 (Segmentation fault (null pointer dereference) in ext/standard/url_scanner_ex.re). (nielsdos) - PDO_Firebird: . Fix bogus fallthrough path in firebird_handle_get_attribute(). (nielsdos) - PHPDBG: . Fixed bug GH-13199 (EOF emits redundant prompt in phpdbg local console mode with libedit/readline). (Peter Kokot) . Fixed bug GH-15268 (heap buffer overflow in phpdbg (zend_hash_num_elements() Zend/zend_hash.h)). (nielsdos) . Fixed bug GH-15210 use-after-free on watchpoint allocations. (nielsdos) - Soap: . Fixed bug #55639 (Digest autentication dont work). (nielsdos) . Fix SoapFault property destruction. (nielsdos) . Fixed bug GH-15252 (SOAP XML broken since PHP 8.3.9 when using classmap constructor option). (nielsdos) - Standard: . Fix passing non-finite timeout values in stream functions. (nielsdos) . Fixed GH-14780 p(f)sockopen timeout overflow. (David Carlier) - Streams: . Fixed bug GH-15028 (Memory leak in ext/phar/stream.c). (nielsdos) . Fixed bug GH-15034 (Integer overflow on stream_notification_callback byte_max parameter with files bigger than 2GB). (nielsdos) . Reverted fix for GH-14930 (Custom stream wrapper dir_readdir output truncated to 255 characters). (Jakub Zelenka) - Tidy: . Fix memory leaks in ext/tidy basedir restriction code. (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.10 2024/08/02 15:29:30 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.11.tar.xz) = 9e5f311bd225857c647625bf1c6f7790d07ea54e2766a692a2304e0cfa67de7a SHA512 (php-8.3.11.tar.xz) = 69df9347643c33a41be4f98aebf13f29f8a22eb7120ae5192a1b2d7a9f487889efe98f273e18f7219b4c7ddff72eb42df05c76baeb36b2f63f32a9276c872a58 Size (php-8.3.11.tar.xz) = 12481420 bytes @ 1.10 log @lang/php83: update to 8.3.10 8.3.10 (2024-08-01) - Core: . Fixed bug GH-13922 (Fixed support for systems with sysconf(_SC_GETPW_R_SIZE_MAX) == -1). (Arnaud) . Fixed bug GH-14626 (Fix is_zend_ptr() for huge blocks). (Arnaud) . Fixed bug GH-14590 (Memory leak in FPM test gh13563-conf-bool-env.phpt. (nielsdos) . Fixed OSS-Fuzz #69765. (nielsdos) . Fixed bug GH-14741 (Segmentation fault in Zend/zend_types.h). (nielsdos) . Fixed bug GH-14969 (Use-after-free in property coercion with __toString()). (ilutov) - Dom: . Fixed bug GH-14702 (DOMDocument::xinclude() crash). (nielsdos) - Fileinfo: . Fixed bug GH-14888 (README.REDIST.BINS refers to non-existing LICENSE). (cmb) - Gd: . ext/gd/tests/gh10614.phpt: skip if no PNG support. (orlitzky) . restored warning instead of fata error. (dryabov) - LibXML: . Fixed bug GH-14563 (Build failure with libxml2 v2.13.0). (nielsdos) - Opcache: . Fixed bug GH-14550 (No warning message when Zend DTrace is enabled that opcache.jit is implictly disabled). (nielsdos) - Output: . Fixed bug GH-14808 (Unexpected null pointer in Zend/zend_string.h with empty output buffer). (nielsdos) - PDO: . Fixed bug GH-14712 (Crash with PDORow access to null property). (David Carlier) - Phar: . Fixed bug GH-14603 (null string from zip entry). (David Carlier) - PHPDBG: . Fixed bug GH-14596 (crashes with ASAN and ZEND_RC_DEBUG=1). (David Carlier) . Fixed bug GH-14553 (echo output trimmed at NULL byte). (nielsdos) - Shmop: . Fixed bug GH-14537 (shmop Windows 11 crashes the process). (nielsdos) - SPL: . Fixed bug GH-14639 (Member access within null pointer in ext/spl/spl_observer.c). (nielsdos) - Standard: . Fixed bug GH-14775 (range function overflow with negative step argument). (David Carlier) . Fix 32-bit wordwrap test failures. (orlitzky) . Fixed bug GH-14774 (time_sleep_until overflow). (David Carlier) - Streams: . Fixed bug GH-14930 (Custom stream wrapper dir_readdir output truncated to 255 characters in PHP 8.3). (Joe Cai) - Tidy: . Fix memory leak in tidy_repair_file(). (nielsdos) - Treewide: . Fix compatibility with libxml2 2.13.2. (nielsdos) - XML: . Move away from to-be-deprecated libxml fields. (nielsdos) . Fixed bug GH-14834 (Error installing PHP when --with-pear is used). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.9 2024/07/05 03:32:40 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.10.tar.xz) = 11c7a4ec5e695a935c6b8480ffef7d77ffa59b5cd37cff1ea9a92de4b8e2ea78 SHA512 (php-8.3.10.tar.xz) = 99dc53cef802304dba455b7e1e54183e780fa21a58ec044ee5eac34d24fc9e5a1390447c18a3ef0035ef3dc531fc817016b47edab5b2e90af1233a73b59517be Size (php-8.3.10.tar.xz) = 12484660 bytes @ 1.9 log @lang/php83: update to 8.3.9 PHP 8.3.9 (2024-07-04) - Core: . Fixed bug GH-14315 (Incompatible pointer type warnings). (Peter Kokot) . Fixed bug GH-12814 (max_execution_time reached too early on MacOS 14 when running on Apple Silicon). (Manuel Kress) . Fixed bug GH-14387 (Crash when stack walking in destructor of yielded from values during Generator->throw()). (Bob) . Fixed bug GH-14456 (Attempting to initialize class with private constructor calls destructor). (Girgias) . Fixed bug GH-14510 (memleak due to missing pthread_attr_destroy()-call). (Florian Engelhardt) . Fixed bug GH-14549 (Incompatible function pointer type for fclose). (Ryan Carsten Schmidt) - BCMatch: . Fixed bug (bcpowmod() with mod = -1 returns 1 when it must be 0). (Girgias) - Curl: . Fixed bug GH-14307 (Test curl_basic_024 fails with curl 8.8.0). (nielsdos) - DOM: . Fixed bug GH-14343 (Memory leak in xml and dom). (nielsdos) - FPM: . Fixed bug GH-14037 (PHP-FPM ping.path and ping.response config vars are ignored in status pool). (Wilhansen Li, Pierrick Charron) - GD: . Fix parameter numbers for imagecolorset(). (Giovanni Giacobbi) - Intl: . Fix reference handling in SpoofChecker. (nielsdos) - MySQLnd: . Partially fix bug GH-10599 (Apache crash on Windows when using a self-referencing anonymous function inside a class with an active mysqli connection). (nielsdos) - Opcache: . Fixed bug GH-14267 (opcache.jit=off does not allow enabling JIT at runtime). (ilutov) . Fixed TLS access in JIT on FreeBSD/amd64. (Arnaud) . Fixed bug GH-11188 (Error when building TSRM in ARM64). (nielsdos) - PDO ODBC: . Fixed bug GH-14367 (incompatible SDWORD type with iODBC). (Calvin Buckley) - PHPDBG: . Fixed bug GH-13681 (segfault on watchpoint addition failure). (David Carlier) - Soap: . Fixed bug #47925 (PHPClient can't decompress response). (nielsdos) . Fix missing error restore code. (nielsdos) . Fix memory leak if calling SoapServer::setObject() twice. (nielsdos) . Fix memory leak if calling SoapServer::setClass() twice. (nielsdos) . Fix reading zlib ini settings in ext-soap. (nielsdos) . Fix memory leaks with string function name lookups. (nielsdos) . Fixed bug #69280 (SoapClient classmap doesn't support fully qualified class name). (nielsdos) . Fixed bug #76232 (SoapClient Cookie Header Semicolon). (nielsdos) . Fixed memory leaks when calling SoapFault::__construct() twice. (Girgias) - Sodium: . Fix memory leaks in ext/sodium on failure of some functions. (nielsdos) - SPL: . Fixed bug GH-14290 (Member access within null pointer in extension spl). (nielsdos) - Standard: . Fixed bug GH-14483 (Fixed off-by-one error in checking length of abstract namespace Unix sockets). (Derick) - Streams: . Fixed bug GH-11078 (PHP Fatal error triggers pointer being freed was not allocated and malloc: double free for ptr errors). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.8 2024/06/07 13:57:24 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.9.tar.xz) = f76fd653e05d83d5eca507cf6fce78a7e892ddc5768a2fb4418d6d7d61d22763 SHA512 (php-8.3.9.tar.xz) = f6291b71cf2c66f9effc2a8a7b0365364481cd5532551161194376893074f1f20dc7e9dbd628727e3b07460ac63b6d38bf4871bf4976e2b3b290f230b0111360 Size (php-8.3.9.tar.xz) = 12470616 bytes @ 1.8 log @lang/php83: update to 8.3.8 pkgsrc change: Instead of patch configure, patch m4 files and use autoconf to generate configure. PHP 8.3.8 (2024-06-06) - CGI: . Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) . Fixed bug GHSA-3qgc-jrrr-25jv (Bypass of CVE-2012-1823, Argument Injection in PHP-CGI). (CVE-2024-4577) (nielsdos) - CLI: . Fixed bug GH-14189 (PHP Interactive shell input state incorrectly handles quoted heredoc literals.). (nielsdos) - Core: . Fixed bug GH-13970 (Incorrect validation of #[Attribute] flags type for non-compile-time expressions). (ilutov) - DOM: . Fix crashes when entity declaration is removed while still having entity references. (nielsdos) . Fix references not handled correctly in C14N. (nielsdos) . Fix crash when calling childNodes next() when iterator is exhausted. (nielsdos) . Fix crash in ParentNode::append() when dealing with a fragment containing text nodes. (nielsdos) - Filter: . Fixed bug GHSA-w8qr-v226-r27w (Filter bypass in filter_var FILTER_VALIDATE_URL). (CVE-2024-5458) (nielsdos) - FPM: . Fix bug GH-14175 (Show decimal number instead of scientific notation in systemd status). (Benjamin Cremer) - Hash: . ext/hash: Swap the checking order of `__has_builtin` and `__GNUC__` (Saki Takamachi) - Intl: . Fixed build regression on systems without C++17 compilers. (Calvin Buckley, Peter Kokot) - MySQLnd: . Fix bug GH-14255 (mysqli_fetch_assoc reports error from nested query). (Kamil Tekiela) - Opcache: . Fixed bug GH-14109 (Fix accidental persisting of internal class constant in shm). (ilutov) - OpenSSL: . The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. (CVE-2024-2408) - Standard: . Fixed bug GHSA-9fcc-425m-g385 (Bypass of CVE-2024-1874). (CVE-2024-5585) (nielsdos) - XML: . Fixed bug GH-14124 (Segmentation fault with XML extension under certain memory limit). (nielsdos) - XMLReader: . Fixed bug GH-14183 (XMLReader::open() can't be overridden). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.7 2024/05/10 15:50:34 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.8.tar.xz) = ba672f712e3d735c0320f301bf5f3a09bbf3440e09abd44813a57ed001a0db57 SHA512 (php-8.3.8.tar.xz) = 1a2840f0b5dcbea6dfcc3894cb9e38d103bf4110c1b956438199deee0b60e5ae63cce34be25ca6f03ac8d26581a852657f8800f92fefe38345e20443b646bb3e Size (php-8.3.8.tar.xz) = 12480896 bytes @ 1.7 log @lang/php83: update to 8.3.7 I missed update of 8.3.6. PHP 8.3.7 (2024-05-09) - Core: . Fixed zend_call_stack build with Linux/uclibc-ng without thread support. (Fabrice Fontaine) . Fixed bug GH-13772 (Invalid execute_data->opline pointers in observer fcall handlers when JIT is enabled). (Bob) . Fixed bug GH-13931 (Applying zero offset to null pointer in Zend/zend_opcode.c). (nielsdos) . Fixed bug GH-13942 (Align the behavior of zend-max-execution-timers with other timeout implementations). (Kévin Dunglas) . Fixed bug GH-14003 (Broken cleanup of unfinished calls with callable convert parameters). (ilutov) . Fixed bug GH-14013 (Erroneous dnl appended in configure). (Peter Kokot) . Fixed bug GH-10232 (If autoloading occurs during constant resolution filename and lineno are identified incorrectly). (ranvis) . Fixed bug GH-13727 (Missing void keyword). (Peter Kokot) - Fibers: . Fixed bug GH-13903 (ASAN false positive underflow when executing copy()). (nielsdos) - Fileinfo: . Fixed bug GH-13795 (Test failing in ext/fileinfo/tests/bug78987.phpt on big-endian PPC). (orlitzky) - FPM: . Fixed bug GH-13563 (Setting bool values via env in FPM config fails). (Jakub Zelenka) - Intl: . Fixed build for icu 74 and onwards. (dunglas) - MySQLnd: . Fix shift out of bounds on 32-bit non-fast-path platforms. (nielsdos) - Opcache: . Fixed bug GH-13433 (Segmentation Fault in zend_class_init_statics when using opcache.preload). (nielsdos) . Fixed incorrect assumptions across compilation units for static calls. (ilutov) - OpenSSL: . Fixed bug GH-10495 (feof on OpenSSL stream hangs indefinitely). (Jakub Zelenka) - PDO SQLite: . Fix GH-13984 (Buffer size is now checked before memcmp). (Saki Takamachi) . Fix GH-13998 (Manage refcount of agg_context->val correctly). (Saki Takamachi) - Phar: . Fixed bug GH-13836 (Renaming a file in a Phar to an already existing filename causes a NULL pointer dereference). (nielsdos) . Fixed bug GH-13833 (Applying zero offset to null pointer in zend_hash.c). (nielsdos) . Fix potential NULL pointer dereference before calling EVP_SignInit. (icy17) - PHPDBG: . Fixed bug GH-13827 (Null pointer access of type 'zval' in phpdbg_frame). (nielsdos) - Posix: . Fix usage of reentrant functions in ext/posix. (Arnaud) - Session: . Fixed bug GH-13856 (Member access within null pointer of type 'ps_files' in ext/session/mod_files.c). (nielsdos) . Fixed bug GH-13891 (memleak and segfault when using ini_set with session.trans_sid_hosts). (nielsdos, kamil-tekiela) . Fixed buffer _read/_write size limit on windows for the file mode. (David Carlier) - Streams: . Fixed file_get_contents() on Windows fails with "errno=22 Invalid argument". (Damian Wójcik) . Fixed bug GH-13264 (Part 1 - Memory leak on stream filter failure). (Jakub Zelenka) . Fixed bug GH-13860 (Incorrect PHP_STREAM_OPTION_CHECK_LIVENESS case in ext/openssl/xp_ssl.c - causing use of dead socket). (nielsdos) . Fixed bug GH-11678 (Build fails on musl 1.2.4 - lfs64). (Arnaud) - Treewide: . Fix gcc-14 Wcalloc-transposed-args warnings. (Cristian Rodríguez) PHP 8.3.6 (2024-04-10) - Standard: . Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some inputs). (CVE-2024-2757) (Alex Dowad) . Fix bug GH-13932 (Attempt to fix mbstring on windows build) (msvc). (David Carlier) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.6 2024/04/13 02:51:54 taca Exp $ d3 4 a6 4 BLAKE2s (php-8.3.7.tar.xz) = 009b796292f0f05c1a21a6f0f40886e1ec5c6a01f4cbae0c7de34a4fc5c9db96 SHA512 (php-8.3.7.tar.xz) = ff2c16a5cc08b1a59a61eee9df75c4c9a6dda7054d48198b75d104c194e934109fed3665005ba798eeca3d7294d7dc81df3a14e63a527baf9f196e229068d9a3 Size (php-8.3.7.tar.xz) = 12456020 bytes SHA1 (patch-configure) = 3d7106a039a3bffaf9f439c8fed77048f1072749 d15 1 @ 1.6 log @lang/php83: update to 8.3.5 This release includes security fixes. 11 Apr 2024, PHP 8.3.5 - Core: . Fixed GH-13569 (GC buffer unnecessarily grows up to GC_MAX_BUF_SIZE when scanning WeakMaps). (Arnaud) . Fixed bug GH-13612 (Corrupted memory in destructor with weak references). (nielsdos) . Fixed bug GH-13446 (Restore exception handler after it finishes). (ilutov) . Fixed bug GH-13784 (AX_GCC_FUNC_ATTRIBUTE failure). (Remi) . Fixed bug GH-13670 (GC does not scale well with a lot of objects created in destructor). (Arnaud) - DOM: . Add some missing ZPP checks. (nielsdos) . Fix potential memory leak in XPath evaluation results. (nielsdos) - FPM: . Fixed GH-11086 (FPM: config test runs twice in daemonised mode). (Jakub Zelenka) . Fix incorrect check in fpm_shm_free(). (nielsdos) - GD: . Fixed bug GH-12019 (add GDLIB_CFLAGS in feature tests). (Michael Orlitzky) - Gettext: . Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5 with category set to LC_ALL. (David Carlier) - MySQLnd: . Fix GH-13452 (Fixed handshake response [mysqlnd]). (Saki Takamachi) . Fix incorrect charset length in check_mb_eucjpms(). (nielsdos) - Opcache: . Fixed GH-13508 (JITed QM_ASSIGN may be optimized out when op1 is null). (Arnaud, Dmitry) . Fixed GH-13712 (Segmentation fault for enabled observers when calling trait method of internal trait when opcache is loaded). (Bob) - Random: . Fixed bug GH-13544 (Pre-PHP 8.2 compatibility for mt_srand with unknown modes). (timwolla) . Fixed bug GH-13690 (Global Mt19937 is not properly reset in-between requests when MT_RAND_PHP is used). (timwolla) - Session: . Fixed bug GH-13680 (Segfault with session_decode and compilation error). (nielsdos) - SPL: . Fixed bug GH-13685 (Unexpected null pointer in zend_string.h). (nielsdos) - Standard: . Fixed bug GH-11808 (Live filesystem modified by tests). (nielsdos) . Fixed GH-13402 (Added validation of `\n` in $additional_headers of mail()). (SakiTakamachi) . Fixed bug GH-13203 (file_put_contents fail on strings over 4GB on Windows). (divinity76) . Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command parameter of proc_open). (CVE-2024-1874) (Jakub Zelenka) . Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix). (CVE-2024-2756) (nielsdos) . Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true, opening ATO risk). (CVE-2024-3096) (Jakub Zelenka) Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some inputs). (CVE-2024-2757) (Alex Dowad) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.5 2024/03/17 16:48:19 taca Exp $ d3 4 a6 4 BLAKE2s (php-8.3.5.tar.xz) = cf85b04006f4ac04268c3cf86f57e0be5800813accf93e10ae36842b642bb49f SHA512 (php-8.3.5.tar.xz) = 6ae60efe2e4df60bf217808cbd710fb3b71a4494de8ded8e0ae7ed9ad5f737fcb49acd004abcb2f7dfcc216108b39143e8094dc40096aefcce72a59b55d4c4bd Size (php-8.3.5.tar.xz) = 12461308 bytes SHA1 (patch-configure) = fdeb39ffcd2abd085c4cda6ced05de748b1a0a68 @ 1.5 log @lang/php83: update to 8.3.4 PHP 8.3.4 (2024-03-14) - Core: . Fix ZTS persistent resource crashes on shutdown. (nielsdos) - Curl: . Fix failing tests due to string changes in libcurl 8.6.0. (Ayesh) - DOM: . Fix unlikely memory leak in case of namespace removal with extremely deep trees. (nielsdos) . Fix reference access in dimensions for DOMNodeList and DOMNodeMap. (nielsdos) - Fileinfo: . Fixed bug GH-13344 (finfo::buffer(): Failed identify data 0:(null), backport). (nielsdos) - FPM: . Fixed bug #75712 (getenv in php-fpm should not read $_ENV, $_SERVER). (Jakub Zelenka) - GD: . Fixed bug GH-12019 (detection of image formats in system gd library). (Michael Orlitzky) - MySQLnd: . Fixed bug GH-11950 ([mysqlnd] Fixed not to set CR_MALFORMED_PACKET to error if CR_SERVER_GONE_ERROR is already set). (Saki Takamachi) - PDO: . Fix various PDORow bugs. (Girgias) - PGSQL: . Fixed bug GH-13354 (pg_execute/pg_send_query_params/pg_send_execute with null value passed by reference). (George Barbarosie) - SPL: . Fixed bug GH-13531 (Unable to resize SplfixedArray after being unserialized in PHP 8.2.15). (nielsdos) - Standard: . Fixed bug GH-13279 (Instable array during in-place modification in uksort). (ilutov) . Fixed array key as hash to string (case insensitive) comparison typo for the second operand buffer size (albeit unused for now). (A. Slepykh) - XML: . Fixed bug GH-13517 (Multiple test failures when building with --with-expat). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.4 2024/02/16 13:15:19 taca Exp $ d3 4 a6 4 BLAKE2s (php-8.3.4.tar.xz) = 4502a9122864f77bc8f05f46717796f637fee78b002c5c10b179a01a332bc9ea SHA512 (php-8.3.4.tar.xz) = 7254421c57de6c8f9f84079212ead38b397e053ad2dc202bd4e0c9d63aa5d9884a6a856fb93fcdbc9e671051436814188439bc5de480979e53fdcb5488cdc321 Size (php-8.3.4.tar.xz) = 12443980 bytes SHA1 (patch-configure) = c6c1657a10caeca4f9c2abf5e66f8fa16e5feca1 @ 1.5.2.1 log @Pullup ticket #6848 - requested by taca lang/php83: security fix Revisions pulled up: - lang/php/phpversion.mk 1.428 - lang/php83/distinfo 1.6 - lang/php83/patches/patch-configure 1.4 --- Module Name: pkgsrc Committed By: taca Date: Sat Apr 13 02:51:54 UTC 2024 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php83: distinfo pkgsrc/lang/php83/patches: patch-configure Log Message: lang/php83: update to 8.3.5 This release includes security fixes. 11 Apr 2024, PHP 8.3.5 - Core: . Fixed GH-13569 (GC buffer unnecessarily grows up to GC_MAX_BUF_SIZE when scanning WeakMaps). (Arnaud) . Fixed bug GH-13612 (Corrupted memory in destructor with weak references). (nielsdos) . Fixed bug GH-13446 (Restore exception handler after it finishes). (ilutov) . Fixed bug GH-13784 (AX_GCC_FUNC_ATTRIBUTE failure). (Remi) . Fixed bug GH-13670 (GC does not scale well with a lot of objects created in destructor). (Arnaud) - DOM: . Add some missing ZPP checks. (nielsdos) . Fix potential memory leak in XPath evaluation results. (nielsdos) - FPM: . Fixed GH-11086 (FPM: config test runs twice in daemonised mode). (Jakub Zelenka) . Fix incorrect check in fpm_shm_free(). (nielsdos) - GD: . Fixed bug GH-12019 (add GDLIB_CFLAGS in feature tests). (Michael Orlitzky) - Gettext: . Fixed sigabrt raised with dcgettext/dcngettext calls with gettext 0.22.5 with category set to LC_ALL. (David Carlier) - MySQLnd: . Fix GH-13452 (Fixed handshake response [mysqlnd]). (Saki Takamachi) . Fix incorrect charset length in check_mb_eucjpms(). (nielsdos) - Opcache: . Fixed GH-13508 (JITed QM_ASSIGN may be optimized out when op1 is null). (Arnaud, Dmitry) . Fixed GH-13712 (Segmentation fault for enabled observers when calling trait method of internal trait when opcache is loaded). (Bob) - Random: . Fixed bug GH-13544 (Pre-PHP 8.2 compatibility for mt_srand with unknown modes). (timwolla) . Fixed bug GH-13690 (Global Mt19937 is not properly reset in-between requests when MT_RAND_PHP is used). (timwolla) - Session: . Fixed bug GH-13680 (Segfault with session_decode and compilation error). (nielsdos) - SPL: . Fixed bug GH-13685 (Unexpected null pointer in zend_string.h). (nielsdos) - Standard: . Fixed bug GH-11808 (Live filesystem modified by tests). (nielsdos) . Fixed GH-13402 (Added validation of `\n` in $additional_headers of mail()). (SakiTakamachi) . Fixed bug GH-13203 (file_put_contents fail on strings over 4GB on Windows). (divinity76) . Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command parameter of proc_open). (CVE-2024-1874) (Jakub Zelenka) . Fixed bug GHSA-wpj3-hf5j-x4v4 (__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix). (CVE-2024-2756) (nielsdos) . Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true, opening ATO risk). (CVE-2024-3096) (Jakub Zelenka) Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some inputs). (CVE-2024-2757) (Alex Dowad) @ text @d1 1 a1 1 $NetBSD$ d3 4 a6 4 BLAKE2s (php-8.3.5.tar.xz) = cf85b04006f4ac04268c3cf86f57e0be5800813accf93e10ae36842b642bb49f SHA512 (php-8.3.5.tar.xz) = 6ae60efe2e4df60bf217808cbd710fb3b71a4494de8ded8e0ae7ed9ad5f737fcb49acd004abcb2f7dfcc216108b39143e8094dc40096aefcce72a59b55d4c4bd Size (php-8.3.5.tar.xz) = 12461308 bytes SHA1 (patch-configure) = fdeb39ffcd2abd085c4cda6ced05de748b1a0a68 @ 1.5.2.2 log @Pullup ticket #6858 - requested by taca lang/php83: security fix Revisions pulled up: - lang/php/phpversion.mk 1.431 - lang/php83/distinfo 1.7 - lang/php83/patches/patch-configure 1.5 --- Module Name: pkgsrc Committed By: taca Date: Fri May 10 15:50:34 UTC 2024 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php83: distinfo pkgsrc/lang/php83/patches: patch-configure Log Message: lang/php83: update to 8.3.7 I missed update of 8.3.6. PHP 8.3.7 (2024-05-09) - Core: . Fixed zend_call_stack build with Linux/uclibc-ng without thread support. (Fabrice Fontaine) . Fixed bug GH-13772 (Invalid execute_data->opline pointers in observer fcall handlers when JIT is enabled). (Bob) . Fixed bug GH-13931 (Applying zero offset to null pointer in Zend/zend_opcode.c). (nielsdos) . Fixed bug GH-13942 (Align the behavior of zend-max-execution-timers with other timeout implementations). (Kévin Dunglas) . Fixed bug GH-14003 (Broken cleanup of unfinished calls with callable convert parameters). (ilutov) . Fixed bug GH-14013 (Erroneous dnl appended in configure). (Peter Kokot) . Fixed bug GH-10232 (If autoloading occurs during constant resolution filename and lineno are identified incorrectly). (ranvis) . Fixed bug GH-13727 (Missing void keyword). (Peter Kokot) - Fibers: . Fixed bug GH-13903 (ASAN false positive underflow when executing copy()). (nielsdos) - Fileinfo: . Fixed bug GH-13795 (Test failing in ext/fileinfo/tests/bug78987.phpt on big-endian PPC). (orlitzky) - FPM: . Fixed bug GH-13563 (Setting bool values via env in FPM config fails). (Jakub Zelenka) - Intl: . Fixed build for icu 74 and onwards. (dunglas) - MySQLnd: . Fix shift out of bounds on 32-bit non-fast-path platforms. (nielsdos) - Opcache: . Fixed bug GH-13433 (Segmentation Fault in zend_class_init_statics when using opcache.preload). (nielsdos) . Fixed incorrect assumptions across compilation units for static calls. (ilutov) - OpenSSL: . Fixed bug GH-10495 (feof on OpenSSL stream hangs indefinitely). (Jakub Zelenka) - PDO SQLite: . Fix GH-13984 (Buffer size is now checked before memcmp). (Saki Takamachi) . Fix GH-13998 (Manage refcount of agg_context->val correctly). (Saki Takamachi) - Phar: . Fixed bug GH-13836 (Renaming a file in a Phar to an already existing filename causes a NULL pointer dereference). (nielsdos) . Fixed bug GH-13833 (Applying zero offset to null pointer in zend_hash.c). (nielsdos) . Fix potential NULL pointer dereference before calling EVP_SignInit. (icy17) - PHPDBG: . Fixed bug GH-13827 (Null pointer access of type 'zval' in phpdbg_frame). (nielsdos) - Posix: . Fix usage of reentrant functions in ext/posix. (Arnaud) - Session: . Fixed bug GH-13856 (Member access within null pointer of type 'ps_files' in ext/session/mod_files.c). (nielsdos) . Fixed bug GH-13891 (memleak and segfault when using ini_set with session.trans_sid_hosts). (nielsdos, kamil-tekiela) . Fixed buffer _read/_write size limit on windows for the file mode. (David Carlier) - Streams: . Fixed file_get_contents() on Windows fails with "errno=22 Invalid argument". (Damian Wójcik) . Fixed bug GH-13264 (Part 1 - Memory leak on stream filter failure). (Jakub Zelenka) . Fixed bug GH-13860 (Incorrect PHP_STREAM_OPTION_CHECK_LIVENESS case in ext/openssl/xp_ssl.c - causing use of dead socket). (nielsdos) . Fixed bug GH-11678 (Build fails on musl 1.2.4 - lfs64). (Arnaud) - Treewide: . Fix gcc-14 Wcalloc-transposed-args warnings. (Cristian Rodríguez) PHP 8.3.6 (2024-04-10) - Standard: . Fixed bug GHSA-fjp9-9hwx-59fq (mb_encode_mimeheader runs endlessly for some inputs). (CVE-2024-2757) (Alex Dowad) . Fix bug GH-13932 (Attempt to fix mbstring on windows build) (msvc). (David Carlier) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.5.2.1 2024/04/22 12:49:08 bsiegert Exp $ d3 4 a6 4 BLAKE2s (php-8.3.7.tar.xz) = 009b796292f0f05c1a21a6f0f40886e1ec5c6a01f4cbae0c7de34a4fc5c9db96 SHA512 (php-8.3.7.tar.xz) = ff2c16a5cc08b1a59a61eee9df75c4c9a6dda7054d48198b75d104c194e934109fed3665005ba798eeca3d7294d7dc81df3a14e63a527baf9f196e229068d9a3 Size (php-8.3.7.tar.xz) = 12456020 bytes SHA1 (patch-configure) = 3d7106a039a3bffaf9f439c8fed77048f1072749 @ 1.5.2.3 log @Pullup ticket #6866 - requested by taca lang/php83: security fix Revisions pulled up: - lang/php/phpversion.mk 1.434 - lang/php83/Makefile 1.3 - lang/php83/distinfo 1.8 - lang/php83/patches/patch-build_php.m4 1.1 - lang/php83/patches/patch-configure deleted - lang/php83/patches/patch-sapi_apache2handler_config.m4 1.1 --- Module Name: pkgsrc Committed By: taca Date: Fri Jun 7 13:57:24 UTC 2024 Modified Files: pkgsrc/lang/php: phpversion.mk pkgsrc/lang/php83: Makefile distinfo Added Files: pkgsrc/lang/php83/patches: patch-build_php.m4 patch-sapi_apache2handler_config.m4 Removed Files: pkgsrc/lang/php83/patches: patch-configure Log Message: lang/php83: update to 8.3.8 pkgsrc change: Instead of patch configure, patch m4 files and use autoconf to generate configure. PHP 8.3.8 (2024-06-06) - CGI: . Fixed buffer limit on Windows, replacing read call usage by _read. (David Carlier) . Fixed bug GHSA-3qgc-jrrr-25jv (Bypass of CVE-2012-1823, Argument Injection in PHP-CGI). (CVE-2024-4577) (nielsdos) - CLI: . Fixed bug GH-14189 (PHP Interactive shell input state incorrectly handles quoted heredoc literals.). (nielsdos) - Core: . Fixed bug GH-13970 (Incorrect validation of #[Attribute] flags type for non-compile-time expressions). (ilutov) - DOM: . Fix crashes when entity declaration is removed while still having entity references. (nielsdos) . Fix references not handled correctly in C14N. (nielsdos) . Fix crash when calling childNodes next() when iterator is exhausted. (nielsdos) . Fix crash in ParentNode::append() when dealing with a fragment containing text nodes. (nielsdos) - Filter: . Fixed bug GHSA-w8qr-v226-r27w (Filter bypass in filter_var FILTER_VALIDATE_URL). (CVE-2024-5458) (nielsdos) - FPM: . Fix bug GH-14175 (Show decimal number instead of scientific notation in systemd status). (Benjamin Cremer) - Hash: . ext/hash: Swap the checking order of `__has_builtin` and `__GNUC__` (Saki Takamachi) - Intl: . Fixed build regression on systems without C++17 compilers. (Calvin Buckley, Peter Kokot) - MySQLnd: . Fix bug GH-14255 (mysqli_fetch_assoc reports error from nested query). (Kamil Tekiela) - Opcache: . Fixed bug GH-14109 (Fix accidental persisting of internal class constant in shm). (ilutov) - OpenSSL: . The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. (CVE-2024-2408) - Standard: . Fixed bug GHSA-9fcc-425m-g385 (Bypass of CVE-2024-1874). (CVE-2024-5585) (nielsdos) - XML: . Fixed bug GH-14124 (Segmentation fault with XML extension under certain memory limit). (nielsdos) - XMLReader: . Fixed bug GH-14183 (XMLReader::open() can't be overridden). (nielsdos) --- Module Name: pkgsrc Committed By: taca Date: Fri Jun 7 23:11:41 UTC 2024 Modified Files: pkgsrc/lang/php81: Makefile Makefile.php pkgsrc/lang/php82: Makefile Makefile.php pkgsrc/lang/php83: Makefile Makefile.php pkgsrc/www/ap-php: Makefile pkgsrc/www/php-fpm: Makefile Log Message: Fix build problem of www/ap-php and www/php-fpm. Switch these packages to use autoconf, too. @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.5.2.2 2024/06/13 13:47:10 bsiegert Exp $ d3 4 a6 4 BLAKE2s (php-8.3.8.tar.xz) = ba672f712e3d735c0320f301bf5f3a09bbf3440e09abd44813a57ed001a0db57 SHA512 (php-8.3.8.tar.xz) = 1a2840f0b5dcbea6dfcc3894cb9e38d103bf4110c1b956438199deee0b60e5ae63cce34be25ca6f03ac8d26581a852657f8800f92fefe38345e20443b646bb3e Size (php-8.3.8.tar.xz) = 12480896 bytes SHA1 (patch-build_php.m4) = c85864ae22556c0a5f14b323d2cf031523625e9b a14 1 SHA1 (patch-sapi_apache2handler_config.m4) = c5650a7d07a8213038fe2e2a6a1ce345d325df82 @ 1.4 log @lang/php83: update to 8.3.3 15 Feb 2024, PHP 8.3.3 - Core: . Fixed timer leak in zend-max-execution-timers builds. (withinboredom) . Fixed bug GH-12349 (linking failure on ARM with mold). (Jan Palus) . Fixed bug GH-13097 (Anonymous class reference in trigger_error / thrown Exception). (nielsdos) . Fixed bug GH-13177 (PHP 8.3.2: final private constructor not allowed when used in trait). (nielsdos) . Fixed bug GH-13215 (GCC 14 build failure). (Remi) - Curl: . Fix missing error check in curl_multi_init(). (divinity76) - FPM: . Fixed bug GH-12996 (Incorrect SCRIPT_NAME with Apache ProxyPassMatch when plus in path). (Jakub Zelenka) - GD: . Fixed bug GH-10344 (imagettfbbox(): Could not find/open font UNC path). (nielsdos) . Fixed bug GH-10614 (imagerotate will turn the picture all black, when rotated 90). (nielsdos) - LibXML: . Fix crashes with entity references and predefined entities. (nielsdos) - MySQLnd: . Fixed bug GH-12107 (When running a stored procedure (that returns a result set) twice, PHP crashes). (nielsdos) - Opcache: . Fixed bug GH-13145 (strtok() is not comptime). (ilutov) . Fixed type inference of range(). (ilutov) . Fixed bug GH-13232 (Segmentation fault will be reported when JIT is off but JIT_debug is still on). (nielsdos) - OpenSSL: . Fixed LibreSSL undefined reference when OPENSSL_NO_ENGINE not set. (David Carlier). - PDO_Firebird: . Fix GH-13119 (Changed to convert float and double values ​​into strings using `H` format). (SakiTakamachi) - Phar: . Fixed bug #71465 (PHAR doesn't know about litespeed). (nielsdos) . Fixed bug GH-13037 (PharData incorrectly extracts zip file). (nielsdos) - Random: . Fixed bug GH-13138 (Randomizer::pickArrayKeys() does not detect broken engines). (timwolla) - Session: . Fixed bug GH-12504 (Corrupted session written when there's a fatal error in autoloader). (nielsdos) - Standard: . Fixed bug GH-13094 (range(9.9, '0') causes segmentation fault). (nielsdos) - Streams: . Fixed bug GH-13071 (Copying large files using mmap-able source streams may exhaust available memory and fail). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.3 2024/01/21 07:53:53 taca Exp $ d3 4 a6 4 BLAKE2s (php-8.3.3.tar.xz) = cfa8082530bbfda9b5cf8f780bbfe6bd0c75064c5bee1270f6b1f109d1604cfc SHA512 (php-8.3.3.tar.xz) = 42141cc46b6abb11fa51cc96c34424cbf9990150b973d84488fa39a07935b22552a1316978f5a4e48762bf3c94eee3d7dfe741c4ee1a12bf752ce1c2660cc8b0 Size (php-8.3.3.tar.xz) = 12463880 bytes SHA1 (patch-configure) = 7f8b996d6f16671c28607da64dca737fe5f49406 @ 1.3 log @lang/php83: update to 8.3.2 8.3.2 (2024-01-18) - Core: . Fixed bug GH-12953 (false positive SSA integrity verification failed when loading composer classmaps with more than 11k elements). (nielsdos) . Fixed bug GH-12999 (zend_strnlen build when strnlen is unsupported). (rainerjung) . Fixed bug GH-12966 (missing cross-compiling 3rd argument so Autoconf doesn't emit warnings). (Peter Kokot) . Fixed bug GH-12854 (8.3 - as final trait-used method does not correctly report visibility in Reflection). (nielsdos) - Cli: . Fix incorrect timeout in built-in web server when using router script and max_input_time. (ilutov) - DOM: . Fixed bug GH-12870 (Creating an xmlns attribute results in a DOMException). (nielsdos) . Fix crash when toggleAttribute() is used without a document. (nielsdos) . Fix crash in adoptNode with attribute references. (nielsdos) . Fixed bug GH-13012 (DOMNode::isEqualNode() is incorrect when attribute order is different). (nielsdos) - FFI: . Fixed bug GH-9698 (stream_wrapper_register crashes with FFI\CData). (Jakub Zelenka) . Fixed bug GH-12905 (FFI::new interacts badly with observers). (nielsdos) - Intl: . Fixed GH-12943 (IntlDateFormatter::__construct accepts 'C' as valid locale). (David Carlier) - Hash: . Fixed bug GH-12936 (hash() function hangs endlessly if using sha512 on strings >= 4GiB). (nielsdos) - ODBC: . Fix crash on Apache shutdown with persistent connections. (nielsdos) - Opcache: . Fixed oss-fuzz #64727 (JIT undefined array key warning may overwrite DIM with NULL when DIM is the same var as result). (ilutov) . Added workaround for SELinux mprotect execheap issue. See https://bugzilla.kernel.org/show_bug.cgi?id=218258. (ilutov) - OpenSSL: . Fixed bug GH-12987 (openssl_csr_sign might leak new cert on error). (Jakub Zelenka) - PDO: . Fix GH-12969 (Fixed PDO::getAttribute() to get PDO::ATTR_STRINGIFY_FETCHES). (SakiTakamachi) - PDO_ODBC: . Fixed bug GH-12767 (Unable to turn on autocommit mode with setAttribute()). (SakiTakamachi) - PGSQL: . Fixed auto_reset_persistent handling and allow_persistent type. (David Carlier) . Fixed bug GH-12974 (Apache crashes on shutdown when using pg_pconnect()). (nielsdos) - Phar: . Fixed bug #77432 (Segmentation fault on including phar file). (nielsdos) - PHPDBG: . Fixed bug GH-12962 (Double free of init_file in phpdbg_prompt.c). (nielsdos) - SimpleXML: . Fix getting the address of an uninitialized property of a SimpleXMLElement resulting in a crash. (nielsdos) . Fixed bug GH-12929 (SimpleXMLElement with stream_wrapper_register can segfault). (nielsdos) - Tidy: . Fixed bug GH-12980 (tidynode.props.attribute is missing "Boolean Attributes" and empty attributes). (nielsdos) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.2 2024/01/05 02:08:41 taca Exp $ d3 4 a6 4 BLAKE2s (php-8.3.2.tar.xz) = aab521c58a524555372f2f5ecbf527aa178030d0932869dd91a1e650e499f16a SHA512 (php-8.3.2.tar.xz) = acf9013d35ae639558fd4816d12dcae03f8af7944c2639f33cd33517503c6170d30101da6c72ebdaf5542bcaf858a54a22ecc8f86822a128f52938bd6ea9606c Size (php-8.3.2.tar.xz) = 12440200 bytes SHA1 (patch-configure) = c8578bf4893665cb8dee242bbdc866d100912436 @ 1.2 log @lang/php83: update to 8.3.1 PHP 8.3.1 (2023-12-21) - Core: . Fixed bug GH-12758 / GH-12768 (Invalid opline in OOM handlers within ZEND_FUNC_GET_ARGS and ZEND_BIND_STATIC). (Florian Engelhardt) . Fix various missing NULL checks. (nielsdos, dstogov) . Fixed bug GH-12835 (Leak of call->extra_named_params on internal __call). (ilutov) . Fixed bug GH-12826 (Weird pointers issue in nested loops). (nielsdos) - FPM: . Fixed bug GH-12705 (Segmentation fault in fpm_status_export_to_zval). (Patrick Prasse) - FTP: . Fixed bug GH-9348 (FTP & SSL session reuse). (nielsdos) - LibXML: . Fixed test failures for libxml2 2.12.0. (nielsdos) - MySQLnd: . Avoid using uninitialised struct. (mikhainin) . Fixed bug GH-12791 (Possible dereference of NULL in MySQLnd debug code). (nielsdos) - Opcache: . Fixed JIT bug (Function JIT emits "Uninitialized string offset" warning at the same time as invalid offset Error). (Girgias) . Fixed JIT bug (JIT emits "Attempt to assign property of non-object" warning at the same time as Error is being thrown). (Girgias) - PDO PGSQL: . Fixed the default value of $fetchMode in PDO::pgsqlGetNotify() (kocsismate) - SOAP: . Fixed bug GH-12838 ([SOAP] Temporary WSDL cache files not being deleted). (nielsdos) - Standard . Fixed GH-12745 (http_build_query() default null argument for $arg_separator is implicitly coerced to string). (Girgias) @ text @d1 1 a1 1 $NetBSD: distinfo,v 1.1 2023/11/30 16:14:50 taca Exp $ d3 3 a5 3 BLAKE2s (php-8.3.1.tar.xz) = eab944ff3b663d58484eed4910e78a7e23877ff38b01cd0d77ea9faf1dde82de SHA512 (php-8.3.1.tar.xz) = 9806f7bdaf9c071a6402152af02eaf5f00285ec7a8c8ee319fd8a7ef4f8e6e33d0e362326969bae59b2c9e6f02fd7b92c93736acb807dfa797cc204226b69fe6 Size (php-8.3.1.tar.xz) = 12444232 bytes @ 1.1 log @lang/php83: add version 8.3.0 PHP is a widely-used open source general-purpose scripting language that is especially suited for web development and can be embedded into HTML. It is modular, and object-oriented. Much of its syntax is borrowed from C, Java and Perl with a couple of unique PHP-specific features thrown in. The language is designed to allow web developers to write dynamically generated pages quickly. PHP 8.3 comes with numerous improvements and new features such as * Typed Class Constants * Fetch class constant dynamically syntax * Readonly Amendments * Override Attribute * New Randomizer method Random\Randomizer::getBytesFromString * New function json_validate * And much much more... @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 BLAKE2s (php-8.3.0.tar.xz) = a0dd4af2670fa1df1f70dfe524c3be08f589582d61834e75d7d33fd1d1be1393 SHA512 (php-8.3.0.tar.xz) = 8758bb0789787dda04f3d4a175f4d4a0bffadc8c3d272fefa000d6fd7b0c0a7096347c829c1ddfb3b60cf6300803d68ba6d8379f2a343e02d935ba77d01c5cf1 Size (php-8.3.0.tar.xz) = 12431612 bytes @