head 1.8; access; symbols pkgsrc-2026Q2:1.7.0.10 pkgsrc-2026Q2-base:1.7 pkgsrc-2026Q1:1.7.0.8 pkgsrc-2026Q1-base:1.7 pkgsrc-2025Q4:1.7.0.6 pkgsrc-2025Q4-base:1.7 pkgsrc-2025Q3:1.7.0.4 pkgsrc-2025Q3-base:1.7 pkgsrc-2025Q2:1.7.0.2 pkgsrc-2025Q2-base:1.7 pkgsrc-2025Q1:1.6.0.2 pkgsrc-2025Q1-base:1.6 pkgsrc-2024Q4:1.4.0.12 pkgsrc-2024Q4-base:1.4 pkgsrc-2024Q3:1.4.0.10 pkgsrc-2024Q3-base:1.4 pkgsrc-2024Q2:1.4.0.8 pkgsrc-2024Q2-base:1.4 pkgsrc-2024Q1:1.4.0.6 pkgsrc-2024Q1-base:1.4 pkgsrc-2023Q4:1.4.0.4 pkgsrc-2023Q4-base:1.4 pkgsrc-2023Q3:1.4.0.2 pkgsrc-2023Q3-base:1.4 pkgsrc-2023Q2:1.3.0.48 pkgsrc-2023Q2-base:1.3 pkgsrc-2023Q1:1.3.0.46 pkgsrc-2023Q1-base:1.3 pkgsrc-2022Q4:1.3.0.44 pkgsrc-2022Q4-base:1.3 pkgsrc-2022Q3:1.3.0.42 pkgsrc-2022Q3-base:1.3 pkgsrc-2022Q2:1.3.0.40 pkgsrc-2022Q2-base:1.3 pkgsrc-2022Q1:1.3.0.38 pkgsrc-2022Q1-base:1.3 pkgsrc-2021Q4:1.3.0.36 pkgsrc-2021Q4-base:1.3 pkgsrc-2021Q3:1.3.0.34 pkgsrc-2021Q3-base:1.3 pkgsrc-2021Q2:1.3.0.32 pkgsrc-2021Q2-base:1.3 pkgsrc-2021Q1:1.3.0.30 pkgsrc-2021Q1-base:1.3 pkgsrc-2020Q4:1.3.0.28 pkgsrc-2020Q4-base:1.3 pkgsrc-2020Q3:1.3.0.26 pkgsrc-2020Q3-base:1.3 pkgsrc-2020Q2:1.3.0.22 pkgsrc-2020Q2-base:1.3 pkgsrc-2020Q1:1.3.0.2 pkgsrc-2020Q1-base:1.3 pkgsrc-2019Q4:1.3.0.24 pkgsrc-2019Q4-base:1.3 pkgsrc-2019Q3:1.3.0.20 pkgsrc-2019Q3-base:1.3 pkgsrc-2019Q2:1.3.0.18 pkgsrc-2019Q2-base:1.3 pkgsrc-2019Q1:1.3.0.16 pkgsrc-2019Q1-base:1.3 pkgsrc-2018Q4:1.3.0.14 pkgsrc-2018Q4-base:1.3 pkgsrc-2018Q3:1.3.0.12 pkgsrc-2018Q3-base:1.3 pkgsrc-2018Q2:1.3.0.10 pkgsrc-2018Q2-base:1.3 pkgsrc-2018Q1:1.3.0.8 pkgsrc-2018Q1-base:1.3 pkgsrc-2017Q4:1.3.0.6 pkgsrc-2017Q4-base:1.3 pkgsrc-2017Q3:1.3.0.4 pkgsrc-2017Q3-base:1.3 pkgsrc-2017Q2:1.2.0.16 pkgsrc-2017Q2-base:1.2 pkgsrc-2017Q1:1.2.0.14 pkgsrc-2017Q1-base:1.2 pkgsrc-2016Q4:1.2.0.12 pkgsrc-2016Q4-base:1.2 pkgsrc-2016Q3:1.2.0.10 pkgsrc-2016Q3-base:1.2 pkgsrc-2016Q2:1.2.0.8 pkgsrc-2016Q2-base:1.2 pkgsrc-2016Q1:1.2.0.6 pkgsrc-2016Q1-base:1.2 pkgsrc-2015Q4:1.2.0.4 pkgsrc-2015Q4-base:1.2 pkgsrc-2015Q3:1.2.0.2 pkgsrc-2015Q3-base:1.2 pkgsrc-2015Q2:1.1.0.4 pkgsrc-2015Q2-base:1.1 pkgsrc-2015Q1:1.1.0.2 pkgsrc-2015Q1-base:1.1; locks; strict; comment @ * @; 1.8 date 2026.08.30.08.51.28; author ryoon; state dead; branches; next 1.7; commitid oPiP8T31qUKeJDTG; 1.7 date 2025.05.12.16.03.20; author wiz; state Exp; branches; next 1.6; commitid tq4oVgRhCy6VnDUF; 1.6 date 2025.02.13.19.43.02; author rillig; state Exp; branches 1.6.2.1; next 1.5; commitid Exvqnd3HgcqHqlJF; 1.5 date 2025.01.09.20.07.04; author ktnb; state Exp; branches; next 1.4; commitid 5NUIjIRACTuMGQEF; 1.4 date 2023.09.06.16.00.15; author vins; state Exp; branches; next 1.3; commitid e34oKDMk5MFd6JDE; 1.3 date 2017.07.18.23.02.18; author kim; state Exp; branches; next 1.2; commitid 78qXotVKMo9gtLZz; 1.2 date 2015.09.01.13.34.47; author kim; state Exp; branches; next 1.1; commitid xYtSZkEz6Ivdmyzy; 1.1 date 2015.02.13.04.44.40; author rodent; state Exp; branches; next ; commitid zVIVi2ODO8jkSN9y; 1.6.2.1 date 2025.05.16.14.14.45; author maya; state Exp; branches; next ; commitid jwAIyOFXRVTOE8VF; desc @@ 1.8 log @misc/screen: Update to 5.0.2 Changelog: Version 5.0.2 (12/07/26): * Add %* escape to output caret character literal ("^") * Add portable PAM conversation callback prototype (for Solaris) * Fixes: - type in screen on big-endian systems - UTF-8 combining sequences - typos - buffer overflow in SendCmdMessage() - detaching fail with empty terminfo and leave the session attached - eliminates the TOCTOU race - manpage fixes Version 5.0.1 (12/05/25): * Fixes: - CVE-2025-46805: do NOT send signals with root privileges - CVE-2025-46804: avoid file existence test information leaks - CVE-2025-46803: apply safe PTY default mode of 0620 - CVE-2025-46802: prevent temporary 0666 mode on PTYs in attacher - CVE-2025-23395: reintroduce lf_secreopen() for logfile - buffer overflow due bad strncpy() - uninitialized variables warnings - typos - combining char handling that could lead to a segfault @ text @$NetBSD: patch-socket.c,v 1.7 2025/05/12 16:03:20 wiz Exp $ Include for iovec. https://security.opensuse.org/2025/05/12/screen-security-issues.html --- socket.c.orig 2024-08-28 19:55:03.000000000 +0000 +++ socket.c @@@@ -35,9 +35,7 @@@@ #include #include #include -#ifdef _OpenBSD_ #include -#endif #include #include #include @@@@ -91,6 +89,11 @@@@ static void AskPassword(Message *); static bool CheckPassword(const char *password); static void PasswordProcessInput(char *, size_t); +static void KillUnpriv(pid_t pid, int sig) { + UserContext(); + UserReturn(kill(pid, sig)); +} + #define SOCKMODE (S_IWRITE | S_IREAD | (displays ? S_IEXEC : 0) | (multi ? 1 : 0)) /* @@@@ -148,8 +151,13 @@@@ int FindSocket(int *fdp, int *nfoundp, i xseteuid(real_uid); xsetegid(real_gid); - if ((dirp = opendir(SocketPath)) == NULL) - Panic(errno, "Cannot opendir %s", SocketPath); + if ((dirp = opendir(SocketPath)) == NULL) { + if (eff_uid == real_uid) { + Panic(errno, "Cannot opendir %s", SocketPath); + } else { + Panic(0, "Error accessing %s", SocketPath); + } + } slist = NULL; slisttail = &slist; @@@@ -606,7 +614,7 @@@@ static int CreateTempDisplay(Message *m, Msg(errno, "Could not perform necessary sanity " "checks on pts device."); close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } if (strcmp(ttyname_in_ns, m->m_tty)) { @@@@ -615,7 +623,7 @@@@ static int CreateTempDisplay(Message *m, ttyname_in_ns, m->m_tty[0] != '\0' ? m->m_tty : "(null)"); close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } /* m->m_tty so far contains the actual name of the pts @@@@ -633,24 +641,24 @@@@ static int CreateTempDisplay(Message *m, "Attach: passed fd does not match tty: %s - %s!", m->m_tty, myttyname ? myttyname : "NULL"); close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } } else if ((i = secopen(m->m_tty, O_RDWR | O_NONBLOCK, 0)) < 0) { Msg(errno, "Attach: Could not open %s!", m->m_tty); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } if (attach) - Kill(pid, SIGCONT); + KillUnpriv(pid, SIGCONT); if (attach) { if (display || win) { int unused_result = write(i, "Attaching from inside of screen?\n", 33); (void)unused_result; /* unused */ close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); Msg(0, "Attach msg ignored: coming from inside."); return -1; } @@@@ -673,7 +681,7 @@@@ static int CreateTempDisplay(Message *m, (void)unused_result; /* unused */ close(i); Msg(0, "Attach: could not make display for user %s", user); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } if (attach) { @@@@ -879,7 +887,7 @@@@ void ReceiveMsg(void) Msg(0, "Query attempt with bad pid(%d)!", m.m.command.apid); } else { - Kill(m.m.command.apid, (queryflag >= 0) ? SIGCONT : SIG_BYE); /* Send SIG_BYE if an error happened */ + KillUnpriv(m.m.command.apid, (queryflag >= 0) ? SIGCONT : SIG_BYE); /* Send SIG_BYE if an error happened */ queryflag = -1; } } @ 1.7 log @screen: add opensuse patches for security problems For https://security.opensuse.org/2025/05/12/screen-security-issues.html Bump PKGREVISION. @ text @d1 1 a1 1 $NetBSD: patch-socket.c,v 1.6 2025/02/13 19:43:02 rillig Exp $ @ 1.6 log @misc/screen: fix location to the system-wide screenrc @ text @d1 1 a1 1 $NetBSD: patch-socket.c,v 1.5 2025/01/09 20:07:04 ktnb Exp $ d5 3 a7 1 --- socket.c.orig 2025-01-09 02:58:51.269455114 +0000 d19 93 @ 1.6.2.1 log @Pullup ticket #6964 - requested by bsiegert misc/screen: Security fix (PR pkg/59417) Revisions pulled up: - misc/screen/MESSAGE deleted - misc/screen/Makefile 1.128-1.129 - misc/screen/distinfo 1.67 - misc/screen/patches/patch-attacher.c 1.1 - misc/screen/patches/patch-configure 1.1 - misc/screen/patches/patch-configure.ac 1.1 - misc/screen/patches/patch-logfile.c 1.1 - misc/screen/patches/patch-logfile.h 1.1 - misc/screen/patches/patch-process.c 1.1 - misc/screen/patches/patch-screen.c 1.7 - misc/screen/patches/patch-screen.h 1.1 - misc/screen/patches/patch-socket.c 1.7 --- Module Name: pkgsrc Committed By: wiz Date: Mon May 12 15:46:06 UTC 2025 Modified Files: pkgsrc/misc/screen: Makefile Removed Files: pkgsrc/misc/screen: MESSAGE Log Message: screen: remove setuid bit because of security problems Remove MESSAGE while here. Bump PKGREVISION. --- Module Name: pkgsrc Committed By: wiz Date: Mon May 12 16:03:20 UTC 2025 Modified Files: pkgsrc/misc/screen: Makefile distinfo pkgsrc/misc/screen/patches: patch-socket.c Added Files: pkgsrc/misc/screen/patches: patch-attacher.c patch-configure patch-configure.ac patch-logfile.c patch-logfile.h patch-process.c patch-screen.c patch-screen.h Log Message: screen: add opensuse patches for security problems For https://security.opensuse.org/2025/05/12/screen-security-issues.html Bump PKGREVISION. @ text @d1 1 a1 1 $NetBSD$ d5 1 a5 3 https://security.opensuse.org/2025/05/12/screen-security-issues.html --- socket.c.orig 2024-08-28 19:55:03.000000000 +0000 a16 93 @@@@ -91,6 +89,11 @@@@ static void AskPassword(Message *); static bool CheckPassword(const char *password); static void PasswordProcessInput(char *, size_t); +static void KillUnpriv(pid_t pid, int sig) { + UserContext(); + UserReturn(kill(pid, sig)); +} + #define SOCKMODE (S_IWRITE | S_IREAD | (displays ? S_IEXEC : 0) | (multi ? 1 : 0)) /* @@@@ -148,8 +151,13 @@@@ int FindSocket(int *fdp, int *nfoundp, i xseteuid(real_uid); xsetegid(real_gid); - if ((dirp = opendir(SocketPath)) == NULL) - Panic(errno, "Cannot opendir %s", SocketPath); + if ((dirp = opendir(SocketPath)) == NULL) { + if (eff_uid == real_uid) { + Panic(errno, "Cannot opendir %s", SocketPath); + } else { + Panic(0, "Error accessing %s", SocketPath); + } + } slist = NULL; slisttail = &slist; @@@@ -606,7 +614,7 @@@@ static int CreateTempDisplay(Message *m, Msg(errno, "Could not perform necessary sanity " "checks on pts device."); close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } if (strcmp(ttyname_in_ns, m->m_tty)) { @@@@ -615,7 +623,7 @@@@ static int CreateTempDisplay(Message *m, ttyname_in_ns, m->m_tty[0] != '\0' ? m->m_tty : "(null)"); close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } /* m->m_tty so far contains the actual name of the pts @@@@ -633,24 +641,24 @@@@ static int CreateTempDisplay(Message *m, "Attach: passed fd does not match tty: %s - %s!", m->m_tty, myttyname ? myttyname : "NULL"); close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } } else if ((i = secopen(m->m_tty, O_RDWR | O_NONBLOCK, 0)) < 0) { Msg(errno, "Attach: Could not open %s!", m->m_tty); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } if (attach) - Kill(pid, SIGCONT); + KillUnpriv(pid, SIGCONT); if (attach) { if (display || win) { int unused_result = write(i, "Attaching from inside of screen?\n", 33); (void)unused_result; /* unused */ close(i); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); Msg(0, "Attach msg ignored: coming from inside."); return -1; } @@@@ -673,7 +681,7 @@@@ static int CreateTempDisplay(Message *m, (void)unused_result; /* unused */ close(i); Msg(0, "Attach: could not make display for user %s", user); - Kill(pid, SIG_BYE); + KillUnpriv(pid, SIG_BYE); return -1; } if (attach) { @@@@ -879,7 +887,7 @@@@ void ReceiveMsg(void) Msg(0, "Query attempt with bad pid(%d)!", m.m.command.apid); } else { - Kill(m.m.command.apid, (queryflag >= 0) ? SIGCONT : SIG_BYE); /* Send SIG_BYE if an error happened */ + KillUnpriv(m.m.command.apid, (queryflag >= 0) ? SIGCONT : SIG_BYE); /* Send SIG_BYE if an error happened */ queryflag = -1; } } @ 1.5 log @screen: update to 5.0.0 - Rewriten autentication mechanism - Add escape %T to show current tty for window - Add escape %O to show number of currently open windows - Use wcwdith() instead of UTF-8 hard-coded tables - New commands: - auth [on|off] Provides password protection - status [top|up|down|bottom] [left|right] The status window by default is in bottom-left corner This command can move status messages to any corner of the screen. - truecolor [on|off] - multiinput Input to multiple windows at the same time - Removed commands: - time - debug - password - maxwin - nethack - Fixes: - Screen buffers ESC keypresses indefinitely - Crashes after passing through a zmodem transfer - Fix double -U issue @ text @d1 1 a1 1 $NetBSD: patch-socket.c,v 1.4 2023/09/06 16:00:15 vins Exp $ d3 1 a3 1 Include for iovec. @ 1.4 log @misc/screen: update to 4.9.1. # Changes Version 4.9.1 (20/08/2023): * Support stop/parity bits on serial port (#23952) * Add needed system headers in checks and return values for implicit function declarations * Fixes: - Avoid zombies after shell exit (#25089) - Missed signal sending permission check on failed query messages (CVE-2023-24626) - manpage fixes - source code fixes during cleanup - UTF-8 encoding can emit invalid UTF-8 sequences for out of range unicode values (#62097) @ text @d1 1 a1 1 $NetBSD: patch-socket.c,v 1.3 2017/07/18 23:02:18 kim Exp $ d5 3 a7 3 --- socket.c.orig 2017-07-10 19:26:25.000000000 +0000 +++ socket.c 2017-07-18 22:35:40.000000000 +0000 @@@@ -34,9 +34,7 @@@@ d10 7 a16 8 # include -# ifdef _OpenBSD_ -# include -# endif +# include # include #ifndef SIGINT @ 1.3 log @Upgrade misc/screen to version 4.6.1 Version 4.6.1 (10/07/2017): * Fixes: - problems with starting session in some cases - parallel make install - segfault when querying info on nonUTF locale Version 4.6.0 (28/06/2017): * Update Unicode wide tables to 9.0 * Support more serial speeds * Improved namespaces support * Migrate from fifos to sockets * Start viewing scrollback at first line of output @ text @d1 3 a3 1 $NetBSD$ @ 1.2 log @Upgrade misc/screen to version 4.3.1 and address stack overflog bug 45713. Ref: https://savannah.gnu.org/bugs/?45713 Changes since version 4.2.1 --------------------------- Version 4.3.1 (28/06/2015): * Fix resize bug Version 4.3.0 (13/06/2015): * Introduce Xx string escape showing the executed command of a window * Implement dead/zombie window polling, allowing for auto reconnecting * Allow setting hardstatus on first line New Commands: * 'sort' command sorting windows by title * 'bumpleft', 'bumpright' - manually move windows on window list * 'collapse' removing numbering 'gaps' between windows, by renumbering * 'windows' command now accepts arguments for use with querying @ text @d1 1 a1 1 $NetBSD: patch-socket.c,v 1.1 2015/02/13 04:44:40 rodent Exp $ d3 4 a6 3 --- socket.c.orig 2015-06-28 21:22:56.000000000 +0000 +++ socket.c 2015-09-01 12:42:34.000000000 +0000 @@@@ -32,9 +32,7 @@@@ a7 1 #if !defined(NAMEDPIPE) a13 1 #endif d15 1 @ 1.1 log @Add patch which includes to fix build on OpenBSD. Defuzz patchset. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 5 --- socket.c.orig 2014-04-26 16:22:43.000000000 +0000 +++ socket.c @@@@ -30,6 +30,7 @@@@ #include #include a6 1 +#include d8 8 a15 2 #include #include @