[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-23 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #22 from commit-h...@freebsd.org --- A commit references this bug: Author: dbaio Date: Wed Sep 23 21:17:31 UTC 2020 New revision: 549855 URL: https://svnweb.freebsd.org/changeset/ports/549855 Log: MFH: r542025 r544404 Fix

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-22 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #21 from Danilo G. Baio --- (In reply to linus.sundqvist from comment #20) Thanks for reporting it. Update devel/py-canonicaljson to 1.2.0 (alone), will break bulk -a. This is what I tracked, I've sent an email to ports-secte

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-22 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #20 from linus.sundqv...@loopia.se --- I am unable to build this package in 2020Q3 because it depends on py37-canonicaljson>=1.2.0, but only 1.1.4 is available in 2020Q3 at the moment using these options: DOCS=on: Build and

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Danilo G. Baio changed: What|Removed |Added Status|Open|Closed Flags|merge-q

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #18 from commit-h...@freebsd.org --- A commit references this bug: Author: dbaio Date: Mon Sep 21 22:36:35 UTC 2020 New revision: 549534 URL: https://svnweb.freebsd.org/changeset/ports/549534 Log: MFH: r542468 r544604 r545291

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Danilo G. Baio changed: What|Removed |Added Flags|merge-quarterly-|merge-quarterly? --- Comment #17

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #16 from commit-h...@freebsd.org --- A commit references this bug: Author: dbaio Date: Mon Sep 21 21:07:57 UTC 2020 New revision: 549530 URL: https://svnweb.freebsd.org/changeset/ports/549530 Log: security/vuxml: Document net

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #15 from Sascha Biberhofer --- Comment on attachment 218143 --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=218143 Updated vuxml entry for py-matrix-synapse 1.19.1 and below Hi, sorry for the slight delay here and tha

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Denis Kasak changed: What|Removed |Added Attachment #218143||maintainer-approval+ Fl

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Denis Kasak changed: What|Removed |Added Attachment #218143|maintainer-approval+| Flags|

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-21 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #14 from Denis Kasak --- Created attachment 218143 --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=218143&action=edit Updated vuxml entry for py-matrix-synapse 1.19.1 and below Here's an updated vuxml entry with a mor

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Danilo G. Baio changed: What|Removed |Added Status|Closed |Open Resolution|FIXED

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #12 from Denis Kasak --- (In reply to Danilo G. Baio from comment #11) The security implication is that this is a classic DoS attack. An attacker sends a malformed event and breaks the application for other users, preventing th

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #11 from Danilo G. Baio --- (In reply to Denis Kasak from comment #10) Usually the project (matrix-org/synapse) documents its security issues, they didn't with this. "malformed events may prevent users from joining federated r

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #10 from Denis Kasak --- (In reply to Danilo G. Baio from comment #7) Out of curiosity, why not a vuxml entry? -- You are receiving this mail because: You are on the CC list for the bug. __

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Danilo G. Baio changed: What|Removed |Added Status|In Progress |Closed Resolution|---

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 --- Comment #8 from commit-h...@freebsd.org --- A commit references this bug: Author: dbaio Date: Sat Sep 19 18:13:56 UTC 2020 New revision: 549046 URL: https://svnweb.freebsd.org/changeset/ports/549046 Log: net-im/py-matrix-synapse: Upd

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Danilo G. Baio changed: What|Removed |Added Keywords|security| Flags|merge-quarter

[Bug 249375] net-im/py-matrix-synapse: Update to 1.19.3

2020-09-19 Thread bugzilla-noreply
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=249375 Danilo G. Baio changed: What|Removed |Added Summary|net-im/py-matrix-synapse: |net-im/py-matrix-synapse: