Re: pledge ffmpegthumbnailer

2016-06-14 Thread Carlin Bingham
On Tue, Jun 14, 2016 at 06:47:25AM +0200, Sebastien Marie wrote: > Hi, > > First, a bump of library version would be required as you added new > exported functions. > > But I think your changes are too invasive for been patches for OpenBSD > port tree. > > You should first deal with upstream for

Re: pledge ffmpegthumbnailer

2016-06-13 Thread Sebastien Marie
Hi, First, a bump of library version would be required as you added new exported functions. But I think your changes are too invasive for been patches for OpenBSD port tree. You should first deal with upstream for these changes, else it will be a shame for us to deal with future upgrade. Thanks

pledge ffmpegthumbnailer

2016-06-13 Thread Carlin Bingham
This thing has been used in the past as a vector to exploit ffmpeg library vulneraiblities, and it's also unpledgeable without some changes. It opens the only file it's going to write early on, so if we could pledge immediately after that it wouldn't need wpath or cpath, but the public methods to