From nobody@FreeBSD.org  Thu Jul 18 23:17:06 2002
Return-Path: <nobody@FreeBSD.org>
Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125])
	by hub.freebsd.org (Postfix) with ESMTP id 2243937B400
	for <freebsd-gnats-submit@FreeBSD.org>; Thu, 18 Jul 2002 23:17:06 -0700 (PDT)
Received: from www.freebsd.org (www.FreeBSD.org [216.136.204.117])
	by mx1.FreeBSD.org (Postfix) with ESMTP id DD72543E31
	for <freebsd-gnats-submit@FreeBSD.org>; Thu, 18 Jul 2002 23:17:05 -0700 (PDT)
	(envelope-from nobody@FreeBSD.org)
Received: from www.freebsd.org (localhost [127.0.0.1])
	by www.freebsd.org (8.12.4/8.12.4) with ESMTP id g6J6H5OT085335
	for <freebsd-gnats-submit@FreeBSD.org>; Thu, 18 Jul 2002 23:17:05 -0700 (PDT)
	(envelope-from nobody@www.freebsd.org)
Received: (from nobody@localhost)
	by www.freebsd.org (8.12.4/8.12.4/Submit) id g6J6H5Ut085334;
	Thu, 18 Jul 2002 23:17:05 -0700 (PDT)
Message-Id: <200207190617.g6J6H5Ut085334@www.freebsd.org>
Date: Thu, 18 Jul 2002 23:17:05 -0700 (PDT)
From: Caitlen <aeonflux@trioptimum.com>
To: freebsd-gnats-submit@FreeBSD.org
Subject: by cvsupfile defaults
X-Send-Pr-Version: www-1.0

>Number:         40757
>Category:       ports
>Synopsis:       by cvsupfile defaults
>Confidential:   no
>Severity:       serious
>Priority:       high
>Responsible:    jkh
>State:          closed
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          sw-bug
>Submitter-Id:   current-users
>Arrival-Date:   Thu Jul 18 23:20:02 PDT 2002
>Closed-Date:    Mon Aug 12 13:40:55 PDT 2002
>Last-Modified:  Mon Aug 12 13:40:55 PDT 2002
>Originator:     Caitlen
>Release:        4.6
>Organization:
none
>Environment:
4.6p3 release
>Description:
The cvsupit port has a special user friendly application that builds a cvsupfile for you.  This file is flawed by default and does NOT include src-crypto or src-secure, meaning that openssl and openssh do NOT get updated when you run make world, and thus remain the older (READ: Vulnerable) versions of the software.
>How-To-Repeat:
install cvsupit and look at the file created in /etc/cvsupfile
notice how src-secure and src-crypto are NOT included.
>Fix:
Change the defaults to read src-all, instead of individually listing every category except the REALLY important ones like security and crypto :)

the port should also create an empty /usr/sup/refuse and tell the user of it's existence.  So the users know they can add "russian", or whatever other ports from the collection they dont want to it.  By default this isn't explained.
>Release-Note:
>Audit-Trail:
Responsible-Changed-From-To: freebsd-ports->jkh 
Responsible-Changed-By: ijliao 
Responsible-Changed-When: Fri Jul 19 02:33:13 PDT 2002 
Responsible-Changed-Why:  
over to maintainer 

http://www.freebsd.org/cgi/query-pr.cgi?pr=40757 
State-Changed-From-To: open->closed 
State-Changed-By: jkh 
State-Changed-When: Mon Aug 12 13:40:47 PDT 2002 
State-Changed-Why:  
Port was updated. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=40757 
>Unformatted:
