Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 297760 - media-libs/devil-1.7.8: version bump request
Summary: media-libs/devil-1.7.8: version bump request
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: Gentoo Games
URL:
Whiteboard:
Keywords:
: 313757 (view as bug list)
Depends on:
Blocks:
 
Reported: 2009-12-21 11:42 UTC by Karl-Robert Ernst
Modified: 2010-05-10 20:49 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Modified ebuild (devil-1.7.8.ebuild,1.50 KB, text/plain)
2009-12-21 11:43 UTC, Karl-Robert Ernst
Details
version bump and security hole fix, and tons of new use flags. (devil-1.7.8-CVE-2009-3994.patch,587 bytes, patch)
2010-04-08 01:33 UTC, Christopher Harvey
Details | Diff
more use flags, apply security fix. version bump (devil-1.7.8.ebuild,2.68 KB, text/plain)
2010-04-08 01:38 UTC, Christopher Harvey
Details
new ebuild (devil-1.7.8.ebuild,1.60 KB, text/plain)
2010-04-09 00:26 UTC, Christopher Harvey
Details
Patch to work with libpng 1.4 (devil_libpng14.patch,1.10 KB, patch)
2010-05-07 16:59 UTC, marbacz
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Karl-Robert Ernst 2009-12-21 11:42:28 UTC
Its out since March 2009, adding support for new formats, fixing bugs etc.

Modifications to ebuild:
* updated SRC_URI to make download from sourceforge working
* removed the NVIDIA TEXTOOLS workaround as it broke configure

Reproducible: Always

Steps to Reproduce:
Comment 1 Karl-Robert Ernst 2009-12-21 11:43:09 UTC
Created attachment 213669 [details]
Modified ebuild
Comment 2 Alex Legler (RETIRED) archtester gentoo-dev Security 2009-12-21 11:44:21 UTC
DO NOT bump to this version unless you add a patch for bug 297373.
Comment 3 Mr. Bones. (RETIRED) gentoo-dev 2009-12-31 22:06:07 UTC
We'll pick up the next version.
Comment 4 Andreas K. Hüttel archtester gentoo-dev 2010-04-07 23:34:08 UTC
*** Bug 313757 has been marked as a duplicate of this bug. ***
Comment 5 Christopher Harvey 2010-04-08 01:33:17 UTC
Created attachment 226943 [details, diff]
version bump and security hole fix, and tons of new use flags.
Comment 6 Christopher Harvey 2010-04-08 01:36:30 UTC
(In reply to comment #3)
> We'll pick up the next version.
> 

This is off the homepage:
----------------------------
October 19, 2009

DevIL is not dead, but I have had no time to work on it. I am currently working on my PhD in physics at the University of North Texas, so my primary focus is of course on that. If I get a break at some point, I will work on DevIL some, but that is really unlikely for awhile. If someone wants to work on DevIL, just let me know. I have definitely enjoyed developing DevIL, and I hope to have a chance to work on it again sometime.

- Denton
--------------------------------

I've created an ebuild that applies a patch to fix that security hole. (and just noticed the other ebuild attachment by karl on 2009-12-21) My ebuild is a bit different, it has many more use flags. Not sure if this is he right behavior, but I thought I'd bring it to the attention of the developers. After all, the options are in the ./configure script.

Either way, the patch has to be applied for this version to go in.

Also, should this go into a new slot? I'm pretty sure there is API breakage, but I can't find any official documentation. I've had problems between those two versions.
Comment 7 Christopher Harvey 2010-04-08 01:38:20 UTC
Created attachment 226945 [details]
more use flags, apply security fix. version bump

Ugh, I got the comment for the last patch wrong, it's the patch this ebuild uses, not the ebuild itself.
Comment 8 Samuli Suominen (RETIRED) gentoo-dev 2010-04-08 15:44:11 UTC
(In reply to comment #7)
> Created an attachment (id=226945) [details]
> more use flags ...

Please don't do that, only add USE flags for features that bring in new dependencies, if the support is internal, it doesn't need a USE flag.

But reopening per mail from user, this might be the last release there will be
Comment 9 Christopher Harvey 2010-04-09 00:26:47 UTC
Created attachment 227065 [details]
new ebuild

Wrote an ebuild with fewer use flags (the ones that create extra deps are included only). This ebuild uses the attached patch from a previous post. I also withdraw what I said about API changes, I was not able to reproduce. I tested this ebuild, should be ready for portage, afaik.
Comment 10 marbacz 2010-05-07 16:59:00 UTC
Created attachment 230715 [details, diff]
Patch to work with libpng 1.4

Without this patch, devil won't compile against libpng-1.4.
Comment 11 Samuli Suominen (RETIRED) gentoo-dev 2010-05-10 20:49:00 UTC
in portage