mirror of
git://slackware.nl/current.git
synced 2025-01-15 15:41:54 +01:00
79e6c8efb8
extra/php81/php81-8.1.22-x86_64-1_slack15.0.txz: Upgraded. This update fixes a security issue: Libxml: Fixed bug GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). For more information, see: https://www.cve.org/CVERecord?id=CVE-2023-3823 (* Security fix *) extra/rust-for-mozilla/rust-1.70.0-x86_64-1_slack15.0.txz: Upgraded. Upgraded the Rust compiler for Firefox 115.1.0 ESR and Thunderbird 115.1.0. pasture/samba-4.15.13-x86_64-1_slack15.0.txz: Added. We'll hang onto this just in case. patches/packages/mozilla-firefox-115.1.0esr-x86_64-1_slack15.0.txz: Upgraded. This update contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/firefox/115.1.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2023-31/ https://www.cve.org/CVERecord?id=CVE-2023-4045 https://www.cve.org/CVERecord?id=CVE-2023-4046 https://www.cve.org/CVERecord?id=CVE-2023-4047 https://www.cve.org/CVERecord?id=CVE-2023-4048 https://www.cve.org/CVERecord?id=CVE-2023-4049 https://www.cve.org/CVERecord?id=CVE-2023-4050 https://www.cve.org/CVERecord?id=CVE-2023-4052 https://www.cve.org/CVERecord?id=CVE-2023-4054 https://www.cve.org/CVERecord?id=CVE-2023-4055 https://www.cve.org/CVERecord?id=CVE-2023-4056 https://www.cve.org/CVERecord?id=CVE-2023-4057 (* Security fix *) patches/packages/mozilla-thunderbird-115.1.0-x86_64-1_slack15.0.txz: Upgraded. This is a bugfix release. For more information, see: https://www.mozilla.org/en-US/thunderbird/115.1.0/releasenotes/ patches/packages/samba-4.18.5-x86_64-1_slack15.0.txz: Upgraded. PLEASE NOTE: We are taking the unusual step of moving to the latest Samba branch because Windows has made changes that break Samba 4.15.x. The last 4.15.x will be retained in /pasture as a fallback. There may be some required configuration changes with this, but we've kept using MIT Kerberos to try to have the behavior change as little as possible. Upgrade carefully. This update fixes security issues: When winbind is used for NTLM authentication, a maliciously crafted request can trigger an out-of-bounds read in winbind and possibly crash it. SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. An infinite loop bug in Samba's mdssvc RPC service for Spotlight can be triggered by an unauthenticated attacker by issuing a malformed RPC request. Missing type validation in Samba's mdssvc RPC service for Spotlight can be used by an unauthenticated attacker to trigger a process crash in a shared RPC mdssvc worker process. As part of the Spotlight protocol Samba discloses the server-side absolute path of shares and files and directories in search results. For more information, see: https://www.samba.org/samba/security/CVE-2022-2127.html https://www.samba.org/samba/security/CVE-2023-3347.html https://www.samba.org/samba/security/CVE-2023-34966.html https://www.samba.org/samba/security/CVE-2023-34967.html https://www.samba.org/samba/security/CVE-2023-34968.html https://www.cve.org/CVERecord?id=CVE-2022-2127 https://www.cve.org/CVERecord?id=CVE-2023-3347 https://www.cve.org/CVERecord?id=CVE-2023-34966 https://www.cve.org/CVERecord?id=CVE-2023-34967 https://www.cve.org/CVERecord?id=CVE-2023-34968 (* Security fix *)
367 lines
12 KiB
Bash
Executable file
367 lines
12 KiB
Bash
Executable file
#!/bin/bash
|
|
|
|
# Copyright 2008, 2009, 2010, 2011, 2012, 2014, 2016, 2017, 2018, 2019, 2020, 2021, 2022, 2023 Patrick J. Volkerding, Sebeka, Minnesota, USA
|
|
# All rights reserved.
|
|
#
|
|
# Redistribution and use of this script, with or without modification, is
|
|
# permitted provided that the following conditions are met:
|
|
#
|
|
# 1. Redistributions of this script must retain the above copyright
|
|
# notice, this list of conditions and the following disclaimer.
|
|
#
|
|
# THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR IMPLIED
|
|
# WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
|
|
# MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO
|
|
# EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
|
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
|
|
# PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS;
|
|
# OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
|
|
# WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
|
|
# OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
|
|
# ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
# Modified 2012 by Eric Hameleers <alien at slackware.com> for ARM port.
|
|
|
|
# Thanks to the folks at the Mozilla Foundation for permission to
|
|
# distribute this, and for all the great work! :-)
|
|
|
|
cd $(dirname $0) ; CWD=$(pwd)
|
|
|
|
PKGNAM=mozilla-thunderbird
|
|
VERSION=$(basename $(ls thunderbird-*.tar.?z | cut -d - -f 2 | rev | cut -f 3- -d . | rev) .source)
|
|
RELEASEVER=$(echo $VERSION | cut -f 1 -d e | cut -f 1 -d b)
|
|
BUILD=${BUILD:-1_slack15.0}
|
|
|
|
# Specify this variable for a localized build.
|
|
# For example, to build a version of Thunderbird with Italian support, run
|
|
# the build script like this:
|
|
#
|
|
# MOZLOCALIZE=it ./mozilla-thunderbird.SlackBuild
|
|
#
|
|
MOZLOCALIZE=${MOZLOCALIZE:-}
|
|
|
|
# Without LANG=C, building the Python environment may fail with:
|
|
# "UnicodeDecodeError: 'ascii' codec can't decode byte 0xe2 in position 36: ordinal not in range(128)"
|
|
LANG=C
|
|
|
|
# Add a shell script to start the thunderbird binary with MOZ_ALLOW_DOWNGRADE=1
|
|
# to avoid backing up (and disabling) the user profile if a browser downgrade
|
|
# is detected. If you want to build with the stock default behavior, set
|
|
# this to something other than "YES":
|
|
MOZ_ALLOW_DOWNGRADE=${MOZ_ALLOW_DOWNGRADE:-YES}
|
|
|
|
# Automatically determine the architecture we're building on:
|
|
if [ -z "$ARCH" ]; then
|
|
case "$( uname -m )" in
|
|
i?86) export ARCH=i686 ;;
|
|
armv7hl) export ARCH=armv7hl ;;
|
|
arm*) export ARCH=arm ;;
|
|
# Unless $ARCH is already set, use uname -m for all other archs:
|
|
*) export ARCH=$( uname -m ) ;;
|
|
esac
|
|
fi
|
|
|
|
# If the variable PRINT_PACKAGE_NAME is set, then this script will report what
|
|
# the name of the created package would be, and then exit. This information
|
|
# could be useful to other scripts.
|
|
if [ ! -z "${PRINT_PACKAGE_NAME}" ]; then
|
|
if [ -z $MOZLOCALIZE ]; then
|
|
echo "$PKGNAM-$VERSION-$ARCH-$BUILD.txz"
|
|
else
|
|
echo "$PKGNAM-$VERSION-$ARCH-${BUILD}_$MOZLOCALIZE.txz"
|
|
fi
|
|
exit 0
|
|
fi
|
|
|
|
# Thunderbird has been requiring more and more memory, especially while linking
|
|
# libxul. If it fails to build natively on x86 32-bit, it can be useful to
|
|
# attempt the build using an x86_64 kernel and a 32-bit userspace. Detect this
|
|
# situation and set the ARCH to i686. Later in the script we'll add some
|
|
# options to the .mozconfig so that the compile will do the right thing.
|
|
if [ "$(uname -m)" = "x86_64" -a "$(file -L /usr/bin/gcc | grep 80386 | grep 32-bit)" != "" ]; then
|
|
COMPILE_X86_UNDER_X86_64=true
|
|
ARCH=i686
|
|
fi
|
|
|
|
if [ "$ARCH" = "i586" ]; then
|
|
SLKCFLAGS="-g0"
|
|
LIBDIRSUFFIX=""
|
|
elif [ "$ARCH" = "i686" ]; then
|
|
SLKCFLAGS="-g0"
|
|
LIBDIRSUFFIX=""
|
|
elif [ "$ARCH" = "s390" ]; then
|
|
SLKCFLAGS="-g0"
|
|
LIBDIRSUFFIX=""
|
|
elif [ "$ARCH" = "x86_64" ]; then
|
|
SLKCFLAGS="-g0 -fPIC"
|
|
LIBDIRSUFFIX="64"
|
|
elif [ "$ARCH" = "arm" ]; then
|
|
SLKCFLAGS="-g0 -march=armv4 -mtune=xscale"
|
|
LIBDIRSUFFIX=""
|
|
elif [ "$ARCH" = "armel" ]; then
|
|
SLKCFLAGS="-g0 -march=armv4t"
|
|
LIBDIRSUFFIX=""
|
|
else
|
|
SLKCFLAGS="-g0"
|
|
LIBDIRSUFFIX=""
|
|
fi
|
|
|
|
# Choose a compiler (gcc/g++ or clang/clang++):
|
|
export CC=${CC:-clang}
|
|
export CXX=${CXX:-clang++}
|
|
|
|
# Set linker to use:
|
|
if [ "$CC" = "clang" -a "$(which lld 2> /dev/null)" = "/usr/bin/lld" ]; then
|
|
# Upstream default:
|
|
LINKER=lld
|
|
else
|
|
LINKER=bfd
|
|
fi
|
|
|
|
# Keep memory usage as low as possible when linking:
|
|
if [ ! "$LINKER" = "lld" ]; then
|
|
SLKLDFLAGS=" -Wl,--as-needed -Wl,--no-keep-memory -Wl,--stats -Wl,--reduce-memory-overheads"
|
|
export LDFLAGS="$SLKLDFLAGS"
|
|
export MOZ_LINK_FLAGS="$SLKLDFLAGS"
|
|
fi
|
|
|
|
# Put Rust objects on a diet to keep the linker from running into memory
|
|
# issues (especially on 32-bit):
|
|
export RUSTFLAGS="-Cdebuginfo=0"
|
|
|
|
TMP=${TMP:-/tmp}
|
|
PKG=$TMP/package-mozilla-thunderbird
|
|
|
|
# If there is a private Google API key available at compile time, use
|
|
# it to enable support for Google Safe Browsing. For Slackware builds,
|
|
# we use a private key issued for the Slackware project. If you are
|
|
# rebuilding and need this support, or you are producing your own
|
|
# distribution, you may obtain your own Google API key at no charge by
|
|
# following these instructions:
|
|
# https://bugzilla.mozilla.org/show_bug.cgi?id=1377987#c0
|
|
if [ -r /root/google-api-key ]; then
|
|
GOOGLE_API_KEY="--with-google-safebrowsing-api-keyfile=/root/google-api-key"
|
|
fi
|
|
|
|
NUMJOBS=${NUMJOBS:-" -j$(expr $(nproc) + 1) "}
|
|
|
|
rm -rf $PKG
|
|
mkdir -p $TMP $PKG/usr/lib${LIBDIRSUFFIX}
|
|
|
|
# Build or unpack build-time dependencies:
|
|
. ./build-deps.sh
|
|
|
|
cd $TMP
|
|
rm -rf thunderbird-$RELEASEVER
|
|
# Unpack this in a subdirectory to prevent changing permissions on /tmp:
|
|
rm -rf thunderbird-unpack
|
|
mkdir thunderbird-unpack
|
|
cd thunderbird-unpack
|
|
echo "Extracting $CWD/thunderbird-$VERSION.source.tar.?z..."
|
|
tar xf $CWD/thunderbird-$VERSION.source.tar.?z || exit 1
|
|
mv * ..
|
|
cd ..
|
|
rm -rf thunderbird-unpack
|
|
cd thunderbird-$RELEASEVER || exit 1
|
|
|
|
# Delete object directory if it was mistakenly included in the tarball:
|
|
rm -rf obj-x86_64-pc-linux-gnu
|
|
|
|
# Retain GTK+ v2 scrolling behavior:
|
|
zcat $CWD/tb.ui.scrollToClick.diff.gz | patch -p1 --verbose || exit 1
|
|
|
|
# Bypass a test that fails the build:
|
|
zcat $CWD/gkrust.a.no.networking.check.diff.gz | patch -p1 --verbose || exit 1
|
|
|
|
# Fix header mismatch on x86 with GCC:
|
|
if [ "$ARCH" = "i686" -a "$CC" = "gcc" ]; then
|
|
zcat $CWD/double_t.x86.diff.gz | patch -p1 --verbose || exit 1
|
|
fi
|
|
|
|
# Fetch localization, if requested:
|
|
if [ ! -z $MOZLOCALIZE ]; then
|
|
LOC_TAG="THUNDERBIRD_$( echo $VERSION | tr \. _ )_RELEASE"
|
|
rm -f $LOC_TAG.tar.bz2
|
|
wget https://hg.mozilla.org/releases/l10n/mozilla-release/$MOZLOCALIZE/archive/$LOC_TAG.tar.bz2
|
|
tar xvf $LOC_TAG.tar.bz2
|
|
mv $MOZLOCALIZE-$LOC_TAG $MOZLOCALIZE
|
|
fi
|
|
|
|
# Arch-dependent patches:
|
|
case "$ARCH" in
|
|
armv7hl) ARCH_CONFIG="--with-arch=armv7-a --with-float-abi=hard --with-fpu=vfpv3-d16 --disable-elf-hack"
|
|
;;
|
|
*) ARCH_CONFIG=" "
|
|
;;
|
|
esac
|
|
|
|
chown -R root:root .
|
|
find . \
|
|
\( -perm 777 -o -perm 775 -o -perm 711 -o -perm 555 -o -perm 511 \) \
|
|
-exec chmod 755 {} \+ -o \
|
|
\( -perm 666 -o -perm 664 -o -perm 600 -o -perm 444 -o -perm 440 -o -perm 400 \) \
|
|
-exec chmod 644 {} \+
|
|
|
|
# Our building options, in a configure-like display ;)
|
|
OPTIONS="\
|
|
--enable-official-branding \
|
|
--prefix=/usr \
|
|
--libdir=/usr/lib${LIBDIRSUFFIX} \
|
|
--with-system-zlib \
|
|
--enable-alsa \
|
|
--with-unsigned-addon-scopes=app,system \
|
|
--without-wasm-sandboxed-libraries \
|
|
--allow-addon-sideload \
|
|
--enable-application=comm/mail \
|
|
--enable-default-toolkit=cairo-gtk3-wayland \
|
|
--enable-linker=$LINKER \
|
|
--disable-strip \
|
|
--disable-install-strip \
|
|
--enable-cpp-rtti \
|
|
--enable-accessibility \
|
|
--enable-optimize \
|
|
$GOOGLE_API_KEY \
|
|
--disable-crashreporter \
|
|
--disable-debug-symbols \
|
|
--disable-debug \
|
|
--disable-elf-hack \
|
|
--disable-tests \
|
|
--disable-updater \
|
|
--host=$ARCH-slackware-linux \
|
|
--target=$ARCH-slackware-linux"
|
|
# Complains about missing APNG support in Slackware's libpng:
|
|
#--with-system-png \
|
|
# Broken with 12.0:
|
|
#--enable-system-cairo \
|
|
if [ ! -z $MOZLOCALIZE ]; then
|
|
OPTIONS=$OPTIONS" \
|
|
--enable-ui-locale=$MOZLOCALIZE
|
|
--with-l10n-base=.."
|
|
# There are no dictionaries in localized builds
|
|
sed -i \
|
|
-e "/@BINPATH@\/dictionaries\/\*/d" \
|
|
-e "/@RESPATH@\/dictionaries\/\*/d" \
|
|
mail/installer/package-manifest.in || exit 1
|
|
fi
|
|
|
|
export MACH_USE_SYSTEM_PYTHON="1"
|
|
export BUILD_OFFICIAL=1
|
|
export MOZILLA_OFFICIAL=1
|
|
export MOZ_PHOENIX=1
|
|
export CFLAGS="$SLKCFLAGS"
|
|
export CXXFLAGS="$SLKCFLAGS"
|
|
export MOZ_MAKE_FLAGS="$NUMJOBS"
|
|
# Set the following variable to empty. =0 does not work.
|
|
export MOZ_REQUIRE_SIGNING=
|
|
export MOZBUILD_STATE_PATH="$TMP/thunderbird-$RELEASEVER/.mozbuild"
|
|
|
|
# Clear some variables that could break the build
|
|
unset DBUS_SESSION_BUS_ADDRESS ORBIT_SOCKETDIR SESSION_MANAGER \
|
|
XDG_SESSION_COOKIE XAUTHORITY MAKEFLAGS
|
|
|
|
# Assemble our .mozconfig:
|
|
echo > .mozconfig
|
|
|
|
# Tell .mozconfig about the selected compiler:
|
|
echo "export CC=\"${CC}\"" >> .mozconfig
|
|
echo "export CXX=\"${CXX}\"" >> .mozconfig
|
|
|
|
# Mozilla devs enforce using an objdir for building
|
|
# https://developer.mozilla.org/en/Configuring_Build_Options#Building_with_an_objdir
|
|
mkdir obj
|
|
echo "mk_add_options MOZ_OBJDIR=$(pwd)/obj" >> .mozconfig
|
|
# This directory is also needed or the build will fail:
|
|
mkdir -p mozilla/obj
|
|
|
|
if [ "$COMPILE_X86_UNDER_X86_64" = "true" ]; then
|
|
# Compile for i686 under an x86_64 kernel:
|
|
echo "ac_add_options --host=i686-pc-linux-gnu" >> .mozconfig
|
|
echo "ac_add_options --target=i686-pc-linux-gnu" >> .mozconfig
|
|
fi
|
|
|
|
# Add the $OPTIONS above to .mozconfig:
|
|
for option in $OPTIONS; do echo "ac_add_options $option" >> .mozconfig; done
|
|
|
|
# Do a standard build:
|
|
./mach build || exit 1
|
|
./mach buildsymbols || exit 1
|
|
DESTDIR=$PKG ./mach install || exit 1
|
|
|
|
# Strip binaries:
|
|
find $PKG | xargs file | grep -e "executable" -e "shared object" | grep ELF | cut -f 1 -d : | xargs strip --strip-unneeded 2> /dev/null
|
|
|
|
## Clean up the build time dependencies:
|
|
#rm -rf $TMP/mozilla-thunderbird-build-deps
|
|
|
|
# We don't need these (just symlinks anyway):
|
|
rm -rf $PKG/usr/lib${LIBDIRSUFFIX}/thunderbird-devel-$RELEASEVER
|
|
|
|
# Nor these:
|
|
rm -rf $PKG/usr/include
|
|
|
|
# Thunderbird 3.x cruft?
|
|
# If we still need something like this (and you know what we need :), let me know.
|
|
#( cd $PKG/usr/lib${LIBDIRSUFFIX}/thunderbird-$VERSION
|
|
# cp -a defaults/profile/mimeTypes.rdf defaults/profile/mimeTypes.rdf.orig
|
|
# zcat $CWD/mimeTypes.rdf > defaults/profile/mimeTypes.rdf || exit 1
|
|
#) || exit 1
|
|
|
|
mkdir -p $PKG/usr/lib${LIBDIRSUFFIX}/mozilla/plugins
|
|
mkdir -p $PKG/usr/share/applications
|
|
cat $CWD/mozilla-thunderbird.desktop > $PKG/usr/share/applications/mozilla-thunderbird.desktop
|
|
mkdir -p $PKG/usr/share/pixmaps
|
|
# Symlinked below.
|
|
#cat $CWD/thunderbird.png > $PKG/usr/share/pixmaps/thunderbird.png
|
|
|
|
# Need some default icons in the right place:
|
|
for i in 16 22 24 32 48 256; do
|
|
install -m 0644 -D comm/mail/branding/thunderbird/default${i}.png \
|
|
$PKG/usr/share/icons/hicolor/${i}x${i}/apps/thunderbird.png
|
|
done
|
|
mkdir -p $PKG/usr/share/pixmaps
|
|
( cd $PKG/usr/share/pixmaps ; ln -sf /usr/share/icons/hicolor/256x256/apps/thunderbird.png . )
|
|
mkdir -p $PKG/usr/lib$LIBDIRSUFFIX/thunderbird-$RELEASEVER/chrome/icons/default
|
|
install -m 644 other-licenses/branding/thunderbird/mailicon16.png \
|
|
$PKG/usr/lib$LIBDIRSUFFIX/thunderbird-$RELEASEVER/icons/
|
|
install -m 644 other-licenses/branding/thunderbird/mailicon16.png \
|
|
$PKG/usr/lib$LIBDIRSUFFIX/thunderbird-$RELEASEVER/chrome/icons/default/
|
|
|
|
# Copy over the LICENSE
|
|
install -p -c -m 644 LICENSE $PKG/usr/lib${LIBDIRSUFFIX}/thunderbird-$RELEASEVER/
|
|
|
|
# If MOZ_ALLOW_DOWNGRADE=YES, replace the /usr/bin/thunderbird symlink with a
|
|
# shell script that sets the MOZ_ALLOW_DOWNGRADE=1 environment variable so
|
|
# that a detected downgrade does not reset the user profile:
|
|
if [ "$MOZ_ALLOW_DOWNGRADE" = "YES" ]; then
|
|
rm -f $PKG/usr/bin/thunderbird
|
|
cat << EOF > $PKG/usr/bin/thunderbird
|
|
#!/bin/sh
|
|
#
|
|
# Shell script to start Mozilla Thunderbird.
|
|
#
|
|
# Don't reset the user profile on a detected downgrade:
|
|
export MOZ_ALLOW_DOWNGRADE=1
|
|
|
|
# Start Thunderbird:
|
|
exec /usr/lib${LIBDIRSUFFIX}/thunderbird/thunderbird "\$@"
|
|
EOF
|
|
chown root:root $PKG/usr/bin/thunderbird
|
|
chmod 755 $PKG/usr/bin/thunderbird
|
|
fi
|
|
|
|
# Fix duplicate binary, https://bugzilla.mozilla.org/show_bug.cgi?id=658850
|
|
( cd $PKG/usr/lib$LIBDIRSUFFIX/thunderbird
|
|
if cmp thunderbird thunderbird-bin ; then
|
|
ln -sf thunderbird-bin thunderbird
|
|
fi
|
|
)
|
|
|
|
mkdir $PKG/install
|
|
cat $CWD/slack-desc > $PKG/install/slack-desc
|
|
|
|
cd $PKG
|
|
if [ -z $MOZLOCALIZE ]; then
|
|
/sbin/makepkg -l y -c n $TMP/mozilla-thunderbird-$VERSION-$ARCH-$BUILD.txz
|
|
else
|
|
/sbin/makepkg -l y -c n $TMP/mozilla-thunderbird-$VERSION-$ARCH-${BUILD}_$MOZLOCALIZE.txz
|
|
fi
|