Bug 40757 - by cvsupfile defaults
Summary: by cvsupfile defaults
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: jkh
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2002-07-19 07:20 UTC by aeonflux
Modified: 2002-08-12 21:40 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description aeonflux 2002-07-19 07:20:02 UTC
The cvsupit port has a special user friendly application that builds a cvsupfile for you.  This file is flawed by default and does NOT include src-crypto or src-secure, meaning that openssl and openssh do NOT get updated when you run make world, and thus remain the older (READ: Vulnerable) versions of the software.

Fix: 

Change the defaults to read src-all, instead of individually listing every category except the REALLY important ones like security and crypto :)

the port should also create an empty /usr/sup/refuse and tell the user of it's existence.  So the users know they can add "russian", or whatever other ports from the collection they dont want to it.  By default this isn't explained.
How-To-Repeat: install cvsupit and look at the file created in /etc/cvsupfile
notice how src-secure and src-crypto are NOT included.
Comment 1 Ying-Chieh Liao freebsd_committer freebsd_triage 2002-07-19 10:33:13 UTC
Responsible Changed
From-To: freebsd-ports->jkh

over to maintainer
Comment 2 jkh freebsd_committer freebsd_triage 2002-08-12 21:40:47 UTC
State Changed
From-To: open->closed

Port was updated.