Search Criteria
Package Details: h2o-2.2 2.2.6-5
Package Actions
Git Clone URL: | https://aur.archlinux.org/h2o-2.2.git (read-only, click to copy) |
---|---|
Package Base: | h2o-2.2 |
Description: | Optimized HTTP server with support for HTTP/1.x and HTTP/2 |
Upstream URL: | https://github.com/h2o/h2o |
Licenses: | MIT |
Conflicts: | h2o, h2o-git, libh2o |
Provides: | h2o, libh2o |
Submitter: | HLFH |
Maintainer: | HLFH (rgacogne) |
Last Packager: | rgacogne |
Votes: | 3 |
Popularity: | 0.000005 |
First Submitted: | 2021-12-08 14:39 (UTC) |
Last Updated: | 2023-12-19 14:12 (UTC) |
Dependencies (12)
- libuv (libuv-gitAUR)
- libyaml (libyaml-gitAUR)
- openssl (openssl-gitAUR, openssl-staticAUR)
- wslay (libwslay)
- zlib (zlib-ng-compat-gitAUR, zlib-gitAUR, zlib-ng-compatAUR, zlib-ng-compat)
- bison (byacc-bisonAUR, bison-gitAUR) (make)
- cmake (cmake-gitAUR) (make)
- gcc (gcc-gitAUR, gccrs-gitAUR, gcc11AUR, gcc-snapshotAUR) (make)
- libtool (libtool-gitAUR) (make)
- make (make-gitAUR) (make)
- pkg-config (pkgconf-gitAUR, pkg-config-gitAUR, pkgconf) (make)
- ruby (make)
Latest Comments
1 2 Next › Last »
rgacogne commented on 2023-12-19 14:15 (UTC)
Thanks a lot! I pushed an update adding the security fix patch for CVE-2023-44487. I did not apply @phoepsilonix patches: I'm not exactly sure of what some of the patches fix so I cannot test it, and some changes to the PKGBUILD seem to be disabling static and shared libraries which would make this package useless for me.
HLFH commented on 2023-12-16 06:25 (UTC) (edited on 2023-12-16 06:25 (UTC) by HLFH)
@rgacogne
I have added you as co-maintainer.
Feel free to:
- apply your security fix patch: https://github.com/h2o/h2o/pull/3293 ;
- apply the @phoepsilonix patches (mruby-Rakefile.patch, deps.patch, h2o-libressl-3.6.2.patch, PKGBUILD patch).
HLFH commented on 2023-12-16 06:09 (UTC)
Hello, looking at it today.
rgacogne commented on 2023-12-15 13:03 (UTC)
I'm afraid this package is still vulnerable to CVE-2023-44487, would you accept a patch backporting the fix?
rgacogne commented on 2023-10-16 07:40 (UTC)
Note that the commit has now been merged into the 2.2.x branch upstream so it's no longer needed to switch to a different repository. Unfortunately there will be no new h2o releases so we would still to either apply the patch in top of 2.2.6 or build from the 2.2.x branch directly. Let me know if you are interested in a co-maintainer, by the way :-)
rgacogne commented on 2023-10-11 12:08 (UTC)
Hi! Would you be willing to add the commit from https://github.com/h2o/h2o/pull/3293 that is backporting a security fix to the 2.2.x branch? The maintainer of h2o has made it clear a new 2.2.x release will not happen. Thanks!
phoepsilonix commented on 2023-03-07 15:43 (UTC) (edited on 2023-03-08 20:18 (UTC) by phoepsilonix)
It can be built with lto enabled. Also fixed a mistake in the mruby Rakefile. Postscript, just in case.
My patch is in the public domain.
mruby-Rakefile.patch
deps.patch
h2o-libressl-3.6.2.patch
PKGBUILD
rgacogne commented on 2022-12-08 16:55 (UTC)
Thanks, much appreciated!
HLFH commented on 2022-12-08 14:17 (UTC)
Please use h2o-2.2 2.2.6-4.
HLFH commented on 2022-12-08 14:09 (UTC)
I have added the options=(!lto). I guess we're good now.
1 2 Next › Last »