head 1.1; access; symbols pkgsrc-2026Q3:1.1.0.2; locks; strict; comment @// @; 1.1 date 2026.09.22.14.38.43; author nia; state Exp; branches 1.1.2.1; next ; commitid cFFalJfNlkauUCWG; 1.1.2.1 date 2026.09.22.14.38.43; author bsiegert; state dead; branches; next 1.1.2.2; commitid gRMSr2dVcDFXYTXG; 1.1.2.2 date 2026.10.02.12.48.56; author bsiegert; state Exp; branches; next ; commitid gRMSr2dVcDFXYTXG; desc @@ 1.1 log @palemoon: Update to 35.0.1 35.x is a new major release series with a reworked higher-performance JavaScript garbage collector, enhancements to CSS support, and the introduction of new polyfills/compatibility shims for JavaScript APIs that can be easily substituted. Various CVEs have also been fixed. On i386, this package now supports running on 586-class CPUs without SSE, such as the AMD Geode and Vortex86 series. This package was verified to build on NetBSD/sparc64, NetBSD/i386, and CentOS 7. @ text @$NetBSD$ Revert commit 4c346cc711118689b9b6d05495c2fbcf495e5ab0 to work around bug in NetBSD/amd64 libc. https://repo.palemoon.org/MoonchildProductions/UXP/issues/3188 https://gnats.netbsd.org/60744 --- platform/js/src/jsprf.cpp.orig 2026-09-12 13:38:01.000000000 +0000 +++ platform/js/src/jsprf.cpp @@@@ -312,13 +312,17 @@@@ cvt_s(SprintfState* ss, const char* s, int width, int s = generic_null_str(s); // Limit string length by precision value +#ifndef __NetBSD__ // We'd want to use strnlen() here, but it is not supported by all targets // (Most notably old OS X), so use memchr instead. // Replace with `size_t slen = strnlen(s, size_t(prec));` once we no longer // need to cater to this. const char* sptr = (const char*)memchr(s, 0, size_t(prec)); size_t slen = sptr ? sptr - s : size_t(prec); - +#else + size_t slen = strnlen(s, size_t(prec)); +#endif + if (slen > INT_MAX) { return false; } @ 1.1.2.1 log @file patch-platform_js_src_jsprf.cpp was added on branch pkgsrc-2026Q3 on 2026-10-02 12:48:56 +0000 @ text @d1 29 @ 1.1.2.2 log @Pullup ticket #7255 - requested by nia www/palemoon: security fix Revisions pulled up: - www/palemoon-gtk3/Makefile 1.7 - www/palemoon-gtk3/PLIST 1.3 - www/palemoon/Makefile 1.53 - www/palemoon/Makefile.common 1.11 - www/palemoon/PLIST 1.11 - www/palemoon/distinfo 1.48 - www/palemoon/patches/patch-platform_build_autoconf_compiler-opts.m4 1.1 - www/palemoon/patches/patch-platform_build_moz.build 1.2 - www/palemoon/patches/patch-platform_js_src_jsprf.cpp 1.1 - www/palemoon/patches/patch-platform_media_libvpx_moz.build 1.3 --- Module Name: pkgsrc Committed By: nia Date: Tue Sep 22 14:38:43 UTC 2026 Modified Files: pkgsrc/www/palemoon: Makefile Makefile.common PLIST distinfo pkgsrc/www/palemoon-gtk3: Makefile PLIST pkgsrc/www/palemoon/patches: patch-platform_build_moz.build Added Files: pkgsrc/www/palemoon/patches: patch-platform_build_autoconf_compiler-opts.m4 patch-platform_js_src_jsprf.cpp patch-platform_media_libvpx_moz.build Log Message: palemoon: Update to 35.0.1 35.x is a new major release series with a reworked higher-performance JavaScript garbage collector, enhancements to CSS support, and the introduction of new polyfills/compatibility shims for JavaScript APIs that can be easily substituted. Various CVEs have also been fixed. On i386, this package now supports running on 586-class CPUs without SSE, such as the AMD Geode and Vortex86 series. This package was verified to build on NetBSD/sparc64, NetBSD/i386, and CentOS 7. @ text @a0 29 $NetBSD: patch-platform_js_src_jsprf.cpp,v 1.1 2026/09/22 14:38:43 nia Exp $ Revert commit 4c346cc711118689b9b6d05495c2fbcf495e5ab0 to work around bug in NetBSD/amd64 libc. https://repo.palemoon.org/MoonchildProductions/UXP/issues/3188 https://gnats.netbsd.org/60744 --- platform/js/src/jsprf.cpp.orig 2026-09-12 13:38:01.000000000 +0000 +++ platform/js/src/jsprf.cpp @@@@ -312,13 +312,17 @@@@ cvt_s(SprintfState* ss, const char* s, int width, int s = generic_null_str(s); // Limit string length by precision value +#ifndef __NetBSD__ // We'd want to use strnlen() here, but it is not supported by all targets // (Most notably old OS X), so use memchr instead. // Replace with `size_t slen = strnlen(s, size_t(prec));` once we no longer // need to cater to this. const char* sptr = (const char*)memchr(s, 0, size_t(prec)); size_t slen = sptr ? sptr - s : size_t(prec); - +#else + size_t slen = strnlen(s, size_t(prec)); +#endif + if (slen > INT_MAX) { return false; } @