HomeFreeBSD

Revert "MFV: xz 5.6.0"

Description

Revert "MFV: xz 5.6.0"

This commit reverts 8db56defa766eacdbaf89a37f25b11a57fd9787a,
rolling back the vendor import of xz 5.6.0 and restoring the
package to version 5.4.5.

The revert was not directly due to the attack (CVE-2024-3094):
our import process have removed the test cases and build scripts
that would have enabled the attack. However, reverting would
help to reduce potential confusion and false positives from
security scanners that assess risk based solely on version
numbers.

Another commit will follow to restore binary compatibility with
the liblzma 5.6.0 library by making the previously private
symbol (lzma_mt_block_size) public.

PR: 278127

(cherry picked from commit 2f9cd13d6c1824633251fb4267c9752d3b044a45)

Details

Provenance
delphijAuthored on Apr 5 2024, 6:39 AM
Parents
rG6ac10e8a72a7: rights.4: add note about rights not being simple bitmasks
Branches
Unknown
Tags
Unknown
Reverts
rG8db56defa766: MFV: xz 5.6.0.