Jan Macku
3c4947ef97
new upstream release - 8.18.0
2026-01-07 11:16:40 +01:00
Jan Macku
da5bf8f889
new upstream release - 8.18.0~rc3
2026-01-05 09:35:50 +01:00
Jan Macku
9e1a11614b
new upstream release - 8.18.0~rc2
2025-12-16 14:49:18 +01:00
Jan Macku
9d9fd36c2e
new upstream release - 8.18.0~rc1
2025-12-09 08:53:40 +01:00
Aleksei Bavshin
fe73859ecd
Enable HTTP/3 support with ngtcp2
2025-12-07 11:36:05 -08:00
Jan Macku
7d91f53d81
http3: apply upstream patches for valgrind issues
...
Related: #2408809
2025-12-04 10:44:25 +01:00
Jan Macku
6803c01e8d
recommend wcurl package instead of bundled wcurl utility
2025-11-13 16:01:43 +01:00
Jan Macku
b15bd53eb8
remove bundled wcurl utility that was added in 8.14.0~rc1, use wcurl
...
package instead
2025-11-13 09:24:32 +01:00
Jan Macku
d2da397853
new upstream release - 8.17.0
2025-11-06 15:10:09 +01:00
Jan Macku
9bd80279ea
new upstream release - 8.17.0~rc3
2025-10-30 09:37:38 +01:00
Jan Macku
6bf2cb17bf
new upstream release - 8.17.0~rc2
2025-10-21 13:12:51 +02:00
Jan Macku
9776a6bb74
new upstream release - 8.17.0~rc1
2025-10-13 10:25:01 +02:00
Adam Williamson
804c73ca4b
Update test URLs to Fedora 42 to fix tests
...
Tests currently fail because Fedora 38 is archived. This bumps
the version to 42 and updates the expected content.
This will need updating again annually or so. It'd be safer to
use something that doesn't age out frequently instead.
Signed-off-by: Adam Williamson <awilliam@redhat.com>
2025-09-12 10:43:27 -07:00
Jan Macku
4335a7a3cb
new upstream release - 8.16.0
2025-09-10 08:56:14 +02:00
Jan Macku
581c1b9ace
new upstream release - 8.16.0~rc3
2025-09-03 10:39:46 +02:00
Jan Macku
e4069769c8
new upstream release - 8.16.0~rc2
2025-08-26 10:01:14 +02:00
Fedora Release Engineering
cc5717f9ec
Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
2025-07-23 18:56:38 +00:00
Jan Macku
e6d7e2ed2d
new upstream release - 8.15.0
2025-07-16 10:14:01 +02:00
Jan Macku
c602d3aa56
new upstream release - 8.15.0~rc3
2025-07-10 09:21:53 +02:00
Jan Macku
1984beb537
new upstream release - 8.15.0~rc2
2025-06-30 13:44:33 +02:00
Jan Macku
1b9d79c6fd
new upstream release - 8.15.0~rc1
2025-06-23 10:29:25 +02:00
Jan Macku
8077eb733b
new upstream release - 8.14.1
2025-06-04 12:59:43 +02:00
Jan Macku
b8ae67753a
new upstream release - 8.14.0
2025-05-28 14:59:28 +02:00
Jan Macku
ece940a649
new upstream release - 8.14.0~rc1
2025-05-02 09:36:02 +02:00
Jan Macku
4d98bbf51e
new upstream release - 8.13.0
2025-04-03 10:38:50 +02:00
Jan Macku
95664fdd30
new upstream release - 8.13.0~rc3
2025-03-26 10:11:44 +01:00
Jan Macku
4fcaa6c404
new upstream release - 8.13.0~rc2
2025-03-18 09:23:12 +01:00
Jan Macku
5e5bbeb413
fix --cert parameter
...
Resolves : #2351531
2025-03-13 09:30:38 +01:00
Jan Macku
3ce21a370c
new upstream release - 8.13.0~rc1
2025-03-10 14:57:45 +01:00
Jan Macku
9c7fc53ab2
new upstream release - 8.12.1
2025-02-13 08:28:44 +01:00
Jan Macku
057c9e09f0
new upstream release - 8.12.0
2025-02-05 09:44:27 +01:00
Jan Macku
dbdb66e32e
TLS: check connection for SSL use, not handler
...
Resolves : #2324130
2025-01-31 15:01:32 +01:00
Fedora Release Engineering
84d98cb3c3
Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
2025-01-16 15:05:19 +00:00
Paul Howarth
348d650b12
Fix crash with Unexpected error 9 on netlink descriptor 10 (rhbz#2332350)
...
- https://github.com/curl/curl/issues/15725
- https://github.com/curl/curl/pull/15727
2024-12-15 12:06:23 +00:00
Paul Howarth
60dca4fc32
Add rpmlintrc
2024-12-15 12:05:17 +00:00
Jan Macku
f200f97c28
new upstream release - 8.11.1
2024-12-11 15:04:00 +01:00
Yaakov Selkowitz
0e038361dd
Disable engine support on RHEL 10+
...
RHEL 10 does not provide the engine header at all. Also, restore
compatibility with earlier versions which do not have a separate subpackage
for the engine header.
2024-11-06 13:13:17 -05:00
Jan Macku
44fdfebea1
new upstream release - 8.11.0
2024-11-06 15:42:48 +01:00
Zbigniew Jędrzejewski-Szmek
e685607ffd
Make curl-config arch-independent
...
The final /usr/bin/curl-config file had a comment like
"prefix=/usr # used in /usr/lib64" or "prefix=/usr # used in /usr/lib",
depending on the arch. This causes the following error on upgrades from f40
for people who have both libcurl-devel.i686 and libcurl-devel.x86_64
installed:
Transaction failed: Rpm transaction failed.
- file /usr/bin/curl-config conflicts between attempted installs of
libcurl-devel-8.9.1-2.fc41.i686 and libcurl-devel-8.9.1-2.fc41.x86_64
The comment is actually not useful at all after the variable is expanded,
since it's not clear what is meant by "used in /usr/lib64". Just drop it.
With this change, the packages are constinstallable again.
2024-10-01 10:16:16 +02:00
Zbigniew Jędrzejewski-Szmek
d92476d332
Move the autoreconf invocation to %build section
...
The %prep section is supposed to extract and possibly patch the sources. In
particular, the code provided by the package should not be called here, but
only in %build section. This keeps %prep quick and allows the code provided by
upstream to be inspected before running it.
Also drop space after the redirection operator to match the style elsewhere in
the spec file. Having symmetrical whitespace around the operator makes it look
like a binary operator, which it very much is not.
2024-09-29 16:07:10 +02:00
Jan Macku
1268eeab81
spec: use tls-ca-bundle.pem instead of ca-bundle.crt
...
Resolves : #2313564
2024-09-24 13:37:40 +02:00
Jan Macku
67e25e1742
new upstream release - 8.10.1
2024-09-18 09:45:38 +02:00
Jan Macku
8669cc0727
new upstream release - 8.10.0
2024-09-11 10:38:41 +02:00
Jacek Migacz
25bb999ab6
Retire depricated ntlm-wb configure option
2024-08-21 18:07:32 +02:00
voidanix
cc42129b02
Add patch due to upstream curl-8.9.1 regression
2024-08-05 16:22:44 +02:00
Jan Macku
40967e47b5
new upstream release - 8.9.1
2024-07-31 09:47:16 +02:00
Jan Macku
27557f0746
new upstream release - 8.9.0
2024-07-24 15:17:24 +02:00
Fedora Release Engineering
ed1f78db34
Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
2024-07-17 20:23:31 +00:00
Paul Howarth
781fa86ead
adapt for https://fedoraproject.org/wiki/Changes/OpensslDeprecateEngine
...
Added build condition for openssl_engine_support, true by default so as to
not change the resulting built package (yet)
- With openssl_engine_support true, BR: openssl-devel-engine
- With openssl_engine_support false, build with -DOPENSSL_NO_ENGINE
2024-07-12 08:06:48 +01:00
Jan Macku
24a6093c53
new upstream release - 8.8.0
2024-05-22 13:07:32 +02:00
Jan Macku
f9311ae69d
new upstream release - 8.7.1
...
Resolves: CVE-2024-2004 - Usage of disabled protocol
Resolves: CVE-2024-2379 - QUIC certificate check bypass with wolfSSL
Resolves: CVE-2024-2398 - HTTP/2 push headers memory-leak
Resolves: CVE-2024-2466 - TLS certificate check bypass with mbedTLS
2024-04-02 14:00:38 +02:00
Jan Macku
9a38bdf948
fix: Leftovers after chunking should not be part of the curl buffer output
...
Resolves : #2264220
2024-02-19 13:23:34 +01:00
Jan Macku
e58b8f772b
spec: use printf to populate tests/data/DISABLED with a newline
2024-02-12 17:34:59 +01:00
Jan Macku
cbc7f6603c
spec: use echo -e to populate tests/data/DISABLED with a newline
2024-02-12 17:13:40 +01:00
Jan Macku
cbd939da23
spec: don't suggests libcurl-minimal
...
it might break existing setups, tests, etc.
Also fedora documentation about suggests is not right about meaning of Suggests macro.
2024-02-12 16:24:35 +01:00
Jan Macku
685f0d3645
temporarily disable test 0313
...
```
test 0313...[CRL test]
../libtool --mode=execute /usr/bin/valgrind --tool=memcheck --quiet
--leak-check=yes --suppressions=../../tests/valgrind.supp --num-callers=16
--log-file=log/valgrind313 ../src/curl --output log/curl313.out --include
--trace-ascii log/trace313 --trace-time --cacert
../../tests/certs/EdelCurlRoot-ca.crt --crlfile
../../tests/certs/Server-localhost-sv.crl https://localhost:37247/313 >
log/stdout313 2> log/stderr313
CMD (15360): ../libtool --mode=execute /usr/bin/valgrind --tool=memcheck
--quiet --leak-check=yes --suppressions=../../tests/valgrind.supp
--num-callers=16 --log-file=log/valgrind313 ../src/curl --output
log/curl313.out --include --trace-ascii log/trace313 --trace-time --cacert
../../tests/certs/EdelCurlRoot-ca.crt --crlfile
../../tests/certs/Server-localhost-sv.crl https://localhost:37247/313 >
log/stdout313 2> log/stderr313
valgrind ERROR ==89628== 1,795 (248 direct, 1,547 indirect) bytes in 1 blocks
are definitely lost in loss record 32 of 32
==89628== at 0x484280F: malloc (vg_replace_malloc.c:442)
==89628== by 0x4D71B20: CRYPTO_malloc (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4D71BD4: CRYPTO_zalloc (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4C67FD3: ??? (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4C69B00: ??? (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4C69E3F: ASN1_item_d2i_ex (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4D944C0: PEM_ASN1_read_bio (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4DD3C31: X509_load_crl_file (in
/usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x48B6D48: UnknownInlinedFun (openssl.c:3284)
==89628== by 0x48B6D48: Curl_ssl_setup_x509_store (openssl.c:3437)
==89628== by 0x48B7445: ossl_bio_cf_in_read (openssl.c:776)
==89628== by 0x4C6DB32: ??? (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4C71C16: ??? (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4C71DAA: BIO_read (in /usr/lib64/libcrypto.so.3.2.1)
==89628== by 0x4B9BE92: ??? (in /usr/lib64/libssl.so.3.2.1)
==89628== by 0x4BA0B4A: ??? (in /usr/lib64/libssl.so.3.2.1)
==89628== by 0x4B9B099: ??? (in /usr/lib64/libssl.so.3.2.1)
==89628==
== Contents of files in the log/ dir after test 313
=== Start of file commands.log
../libtool --mode=execute /usr/bin/valgrind --tool=memcheck --quiet
--leak-check=yes --suppressions=../../tests/valgrind.supp --num-callers=16
--log-file=log/valgrind313 ../src/curl --output log/curl313.out --include
--trace-ascii log/trace313 --trace-time --cacert
../../tests/certs/EdelCurlRoot-ca.crt --crlfile
../../tests/certs/Server-localhost-sv.crl https://localhost:37247/313 >
log/stdout313 2> log/stderr313
=== End of file commands.log
```
Related: openssl #2263877
a
2024-02-12 16:24:31 +01:00
Jan Macku
9c77cd7c46
vtls: revert "receive max buffer" + add test case
...
It breaks the test suite of pycurl
2024-02-12 14:06:34 +01:00
Jan Macku
31bc86593e
curl-full: add Provides to curl-minimal
2024-02-12 13:50:03 +01:00
Jan Macku
8cec2e9cc7
drop curl-minimal subpackage in favor of curl-full
...
The reason for maintaining two separate packages for curl is no longer valid.
The curl-minimal is currently almost identical to curl-full, so let's drop curl-minimal.
Resolves : #2262096
2024-02-07 13:05:39 +01:00
Jan Macku
ec3f7ae8ee
fix: ignore response body to HEAD requests
...
Discovered/Reported by: @lis in FEDORA-2024-634a6662aa
2024-02-05 10:49:10 +01:00
Kamil Dudka
be5d7739cf
deduplicate the --disable-manual configure option
...
No change in behavior intended.
Related: #2262373
Closes: https://src.fedoraproject.org/rpms/curl/pull-request/22
2024-02-02 12:04:20 +01:00
Jan Macku
6730b754a9
don't build curl manual feature use man 1 curl instead
...
Resolves : #2262373
2024-02-02 10:22:12 +01:00
Jan Macku
98780da3f8
new upstream release - 8.6.0
...
Resolves: CVE-2024-0853 - OCSP verification bypass with TLS session reuse
2024-02-01 15:11:39 +01:00
Fedora Release Engineering
3c4671bd88
Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
2024-01-19 16:32:26 +00:00
Jan Macku
7d149f66f5
new upstream release - 8.5.0
...
Resolves: CVE-2023-46218 - cookie mixed case PSL bypass
Resolves: CVE-2023-46219 - HSTS long file name clears contents
2023-12-06 12:29:18 +01:00
Jan Macku
cb17cbc66a
new upstream release - 8.4.0
...
Resolves: CVE-2023-38545 - SOCKS5 heap buffer overflow
Resolves: CVE-2023-38546 - cookie injection with none file
2023-10-11 15:36:19 +02:00
Lukáš Zaoral
554e13f798
tests: use newer Fedora URLs for testing
...
... because F36 URLs are no longer available.
2023-10-09 10:48:08 +02:00
Jan Macku
dd8c36f3ea
new upstream release - 8.3.0
...
Resolves: CVE-2023-38039 - HTTP headers eat all memory
2023-09-13 10:33:22 +02:00
Jan Macku
76f5788cab
enable websockets
...
Resolves : #2224651
2023-08-10 12:44:06 +02:00
Lukáš Zaoral
b64627ff52
new upstream release - 8.2.1
...
Resolves: rhbz#2226659
2023-07-26 12:40:15 +02:00
Jan Macku
de1364bf2c
new upstream release - 8.2.0
...
Resolves: CVE-2023-32001 - fopen race condition
2023-07-19 13:44:49 +02:00
Jan Macku
f91221e9d7
new upstream release - 8.1.2
...
Resolves : #2210976
2023-05-30 10:05:35 +02:00
Jan Macku
d31965bf5b
new upstream release - 8.1.1
...
Resolves : #2209217
2023-05-23 10:07:28 +02:00
Paul Howarth
dc1838de58
Additional test suite dependencies
2023-05-17 13:14:43 +01:00
Paul Howarth
6beac07229
Ignore lzma-compressed tarballs from old releases
2023-05-17 13:13:21 +01:00
Kamil Dudka
fa58a15ce6
add BR for perl(base) needed by the test-suite
2023-05-17 12:11:00 +02:00
Kamil Dudka
4da3349c05
drop 0103-curl-7.87.0-test3012.patch
...
The related valgrind bug has been fixed
https://bugzilla.redhat.com/2143040
2023-05-17 09:55:40 +02:00
Kamil Dudka
c0b70e927f
new upstream release - 8.1.0
...
Resolves: CVE-2023-28321 - IDN wildcard match
Resolves: CVE-2023-28322 - more POST-after-PUT confusion
2023-05-17 09:42:41 +02:00
Kamil Dudka
65d0dfbac5
changelog: trim entries that predate curl-7.29.0
...
... which RHEL-7 builds of curl are based on
Closes: https://src.fedoraproject.org/rpms/curl/pull-request/16
2023-04-21 18:30:49 +02:00
Kamil Dudka
d8bddc669c
tests: re-enable temporarily disabled test-cases
2023-04-21 18:11:12 +02:00
Kamil Dudka
2d313d8a46
tests: attempt to fix a conflict on port numbers
...
... where stunnel listens for legacy HTTPS and HTTP/2, which manifests
as a hard-to-explain failure of the following tests: 1630 1631 1632 1904
1941 1945 2050 2055 3028
```
[...]
startnew: perl -I../../tests ../../tests/secureserver.pl --pidfile ".https_server.pid" --logfile "log/https_stunnel.log" --ipv4 --proto https --stunnel "/usr/bin/stunnel" --srcdir "../../tests" --connect 42917 --accept 24642
RUN: HTTPS server is PID 114398 port 24642
* pid https => 114398 114402
[...]
startnew: perl -I../../tests ../../tests/secureserver.pl --pidfile ".https2_server.pid" --logfile "log/https2_stunnel.log" --id 2 --ipv4 --proto https --stunnel "/usr/bin/stunnel" --srcdir "../../tests" --connect 36763 --accept 24642
startnew: child process has died, server might start up
Warning: http2 server unexpectedly alive
RUN: Process with pid 73992 signalled to die
RUN: Process with pid 73992 forced to die with SIGKILL
== Contents of files in the log/ dir after test 1630
=== Start of file http2_server.log
14:01:21.881018 exit_signal_handler: 15
14:01:21.881372 signalled to die
14:01:21.881511 ========> IPv4 sws (port 36763 pid: 73992) exits with signal (15)
=== End of file http2_server.log
=== Start of file https2_stunnel.log
[ ] Initializing inetd mode configuration
[ ] Clients allowed=500
[.] stunnel 5.69 on x86_64-redhat-linux-gnu platform
[.] Compiled/running with OpenSSL 3.0.8 7 Feb 2023
[.] Threading:PTHREAD Sockets:POLL,IPv6 TLS:ENGINE,FIPS,OCSP,PSK,SNI
[ ] errno: (*__errno_location ())
[ ] Initializing inetd mode configuration
[.] Reading configuration from file /builddir/build/BUILD/curl-8.0.1/build-minimal/tests/https_stunnel.conf
[.] UTF-8 byte order mark not detected
[.] FIPS mode disabled
[ ] Compression disabled
[ ] No PRNG seeding was required
[ ] Initializing service [curltest]
[ ] Using the default TLS minimum version as specified in crypto policies. Not setting explicitly.
[ ] Using the default TLS maximum version as specified in crypto policies. Not setting explicitly
[ ] stunnel default security level set: 2
[ ] Ciphers: PROFILE=SYSTEM
[ ] TLSv1.3 ciphersuites: TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256
[ ] TLS options: 0x2100000 (+0x0, -0x0)
[ ] Session resumption enabled
[ ] Loading certificate from file: /builddir/build/BUILD/curl-8.0.1/tests/stunnel.pem
[ ] Certificate loaded from file: /builddir/build/BUILD/curl-8.0.1/tests/stunnel.pem
[ ] Loading private key from file: /builddir/build/BUILD/curl-8.0.1/tests/stunnel.pem
[ ] Private key loaded from file: /builddir/build/BUILD/curl-8.0.1/tests/stunnel.pem
[ ] Private key check succeeded
[!] No trusted certificates found
[ ] DH initialization needed for DHE-RSA-AES256-GCM-SHA384
[ ] DH initialization
[ ] Could not load DH parameters from /builddir/build/BUILD/curl-8.0.1/tests/stunnel.pem
[ ] Using dynamic DH parameters
[ ] ECDH initialization
[ ] ECDH initialized with curves X25519:P-256:X448:P-521:P-384
[.] Configuration successful
[ ] Deallocating deployed section defaults
[ ] Binding service [curltest]
[ ] Listening file descriptor created (FD=8)
[ ] Setting accept socket options (FD=8)
[ ] Option SO_REUSEADDR set on accept socket
[.] Binding service [curltest] to 0.0.0.0:24642: Address already in use (98)
[ ] Listening file descriptor created (FD=8)
[ ] Setting accept socket options (FD=8)
[ ] Option SO_REUSEADDR set on accept socket
[.] Binding service [curltest] to :::24642: Address already in use (98)
[!] Binding service [curltest] failed
[ ] Unbinding service [curltest]
[ ] Service [curltest] closed
[ ] Deallocating deployed section defaults
[ ] Deallocating section [curltest]
[ ] Initializing inetd mode configuration
=== End of file https2_stunnel.log
```
2023-04-21 18:05:52 +02:00
Kamil Dudka
fb877acc4b
curl.spec: forgot to bump release
2023-04-21 14:41:58 +02:00
Kamil Dudka
449e5165fd
curl.spec: apply patches automatically
...
... to ease maintenance and to avoid the following warning on Fedora
Rawhide:
```
warning: %patchN is deprecated (4 usages found), use %patch N (or %patch -P N)
```
2023-04-21 14:35:22 +02:00
Lukáš Zaoral
54363444c5
migrate to SPDX license
2023-03-21 15:46:58 +01:00
Kamil Dudka
c96705f9dc
new upstream release - 8.0.1
2023-03-20 15:56:09 +01:00
Kamil Dudka
7b0a4d3dfc
new upstream release - 8.0.0
...
Resolves: CVE-2023-27538 - SSH connection too eager reuse still
Resolves: CVE-2023-27537 - HSTS double-free
Resolves: CVE-2023-27536 - GSS delegation too eager connection re-use
Resolves: CVE-2023-27535 - FTP too eager connection reuse
Resolves: CVE-2023-27534 - SFTP path ~ resolving discrepancy
Resolves: CVE-2023-27533 - TELNET option IAC injection
2023-03-20 13:46:30 +01:00
Kamil Dudka
d5c1163ef3
new upstream release - 7.88.1
2023-02-20 14:42:32 +01:00
Kamil Dudka
13a96c9b8f
http2: set drain on stream end
...
This is an attempt to fix the following issue in COPR:
https://pagure.io/fedora-infrastructure/issue/11133
2023-02-17 14:38:21 +01:00
Kamil Dudka
bdbf01f50c
add glibc-langpack-en BR needed for test1560 to succeed
...
Suggested-by: Paul Howarth
2023-02-15 12:54:31 +01:00
Kamil Dudka
f3c2fe3549
do not fail on warnings in the upstream test driver
2023-02-15 10:46:00 +01:00
Kamil Dudka
98c91c9f34
new upstream release - 7.88.0
...
Resolves: CVE-2023-23916 - HTTP multi-header compression denial of service
Resolves: CVE-2023-23915 - HSTS amnesia with --parallel
Resolves: CVE-2023-23914 - HSTS ignored on multiple requests
2023-02-15 10:06:24 +01:00
Kamil Dudka
8ff989f4fd
Resolves : #2162716 - fix regression in a public header file
2023-01-20 17:48:02 +01:00
Fedora Release Engineering
c3e870d57a
Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-19 00:50:41 +00:00
Kamil Dudka
04ebed546a
Related: #2143040 - test3012: temporarily disable valgrind
2023-01-11 09:00:16 +01:00
Kamil Dudka
0d0fa259a7
do not use stunnnel for testing on aarch64
...
The test 1561 intermittently fails when upstream test-suite runs
for the second time during the build:
```
[ ] Initializing inetd mode configuration
[ ] Clients allowed=500
[.] stunnel 5.66 on aarch64-redhat-linux-gnu platform
[.] Compiled/running with OpenSSL 3.0.5 5 Jul 2022
[.] Threading:PTHREAD Sockets:POLL,IPv6 TLS:ENGINE,FIPS,OCSP,PSK,SNI
[ ] errno: (*__errno_location ())
[ ] Initializing inetd mode configuration
[.] Reading configuration from file /builddir/build/BUILD/curl-7.87.0/build-full/tests/https_stunnel.conf
[.] UTF-8 byte order mark not detected
[.] FIPS mode disabled
[ ] Compression disabled
[ ] No PRNG seeding was required
[ ] Initializing service [curltest]
[ ] Using the default TLS version as specified in OpenSSL crypto policies. Not setting explicitly.
[ ] Using the default TLS version as specified in OpenSSL crypto policies. Not setting explicitly
[ ] stunnel default security level set: 2
[ ] Ciphers: PROFILE=SYSTEM
[ ] TLSv1.3 ciphersuites: TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_CHACHA20_POLY1305_SHA256
[ ] TLS options: 0x2100000 (+0x0, -0x0)
[ ] Session resumption enabled
[ ] Loading certificate from file: /builddir/build/BUILD/curl-7.87.0/tests/stunnel.pem
[ ] Certificate loaded from file: /builddir/build/BUILD/curl-7.87.0/tests/stunnel.pem
[ ] Loading private key from file: /builddir/build/BUILD/curl-7.87.0/tests/stunnel.pem
[ ] Private key loaded from file: /builddir/build/BUILD/curl-7.87.0/tests/stunnel.pem
[ ] Private key check succeeded
[ ] DH initialization needed for DHE-RSA-AES256-GCM-SHA384
[ ] DH initialization
[ ] Could not load DH parameters from /builddir/build/BUILD/curl-7.87.0/tests/stunnel.pem
[ ] Using dynamic DH parameters
[ ] ECDH initialization
[ ] ECDH initialized with curves X25519:P-256:X448:P-521:P-384
[.] Configuration successful
[ ] Deallocating deployed section defaults
[ ] Binding service [curltest]
[ ] Listening file descriptor created (FD=8)
[ ] Setting accept socket options (FD=8)
[ ] Option SO_REUSEADDR set on accept socket
[.] Binding service [curltest] to 0.0.0.0:24847: Address already in use (98)
[ ] Listening file descriptor created (FD=8)
[ ] Setting accept socket options (FD=8)
[ ] Option SO_REUSEADDR set on accept socket
[.] Binding service [curltest] to :::24847: Address already in use (98)
[!] Binding service [curltest] failed
[ ] Unbinding service [curltest]
[ ] Service [curltest] closed
[ ] Deallocating deployed section defaults
[ ] Deallocating section [curltest]
[ ] Initializing inetd mode configuration
```
2022-12-21 16:45:28 +01:00
Kamil Dudka
60cc0c5574
new upstream release - 7.87.0
...
Resolves: CVE-2022-43552 - HTTP Proxy deny use-after-free
Resolves: CVE-2022-43551 - Another HSTS bypass via IDN
2022-12-21 13:51:32 +01:00
Kamil Dudka
aa9b0f2a8f
Resolves : #2149224 - noproxy: tailmatch like in 7.85.0 and earlier
2022-11-29 12:07:37 +01:00
Kamil Dudka
7b44e0b7aa
Related: #2144277 - enforce versioned libnghttp2 dependency for libcurl
2022-11-24 16:26:48 +01:00
Kamil Dudka
394bdcb956
fix regression in noproxy matching
2022-10-31 09:34:58 +01:00
Kamil Dudka
3501daee0b
new upstream release - 7.86.0
...
Resolves: CVE-2022-42916 - HSTS bypass via IDN
Resolves: CVE-2022-42915 - HTTP proxy double-free
Resolves: CVE-2022-35260 - .netrc parser out-of-bounds access
Resolves: CVE-2022-32221 - POST following PUT confusion
2022-10-26 14:27:26 +02:00
Kamil Dudka
4bceeec6e1
curl.spec: fix the last change log entry
2022-10-26 14:16:26 +02:00
Kamil Dudka
1322e86ddb
new upstream release - 7.85.0
...
Resolves: CVE-2022-35252 - control code in cookie denial of service
2022-09-01 14:13:21 +02:00
Kamil Dudka
f58874c271
tests: fix http2 tests to use CRLF headers
...
... to make it work with nghttp2-1.49.0
2022-08-25 13:22:29 +02:00
Fedora Release Engineering
2fded2f1a8
Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-07-20 23:54:27 +00:00
Kamil Dudka
f052e58217
test3026: avoid pthread_create() failure due to resource exhaustion on i386
2022-06-28 09:04:19 +02:00
Kamil Dudka
9ba06cfc6e
easy_lock.h: include sched.h if available to fix build
2022-06-27 17:52:30 +02:00
Kamil Dudka
768ce3965d
test3026: disable valgrind
...
It fails on x86_64 with:
```
Use --max-threads=INT to specify a larger number of threads
and rerun valgrind
valgrind: the 'impossible' happened:
Max number of threads is too low
host stacktrace:
==174357== at 0x58042F5A: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x58043087: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x580432EF: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x58043310: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x58099E77: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x580E67E9: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x5809D59D: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x5809901A: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x5809B0B6: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
==174357== by 0x580E4050: ??? (in /usr/libexec/valgrind/memcheck-amd64-linux)
sched status:
running_tid=1
Thread 1: status = VgTs_Runnable syscall 56 (lwpid 174357)
==174357== at 0x4A07816: clone (in /usr/lib64/libc.so.6)
==174357== by 0x4A08720: __clone_internal (in /usr/lib64/libc.so.6)
==174357== by 0x4987ACF: create_thread (in /usr/lib64/libc.so.6)
==174357== by 0x49885F6: pthread_create@@GLIBC_2.34 (in /usr/lib64/libc.so.6)
==174357== by 0x1093B5: test.part.0 (lib3026.c:64)
==174357== by 0x492454F: (below main) (in /usr/lib64/libc.so.6)
client stack range: [0x1FFEFFC000 0x1FFF000FFF] client SP: 0x1FFEFFC998
valgrind stack range: [0x1002BAA000 0x1002CA9FFF] top usage: 11728 of 1048576
[...]
```
2022-06-27 17:00:18 +02:00
Kamil Dudka
a4ed273b19
new upstream release - 7.84.0
...
Resolves: CVE-2022-32207 - Unpreserved file permissions
Resolves: CVE-2022-32205 - Set-Cookie denial of service
Resolves: CVE-2022-32206 - HTTP compression denial of service
Resolves: CVE-2022-32208 - FTP-KRB bad message verification
2022-06-27 13:00:50 +02:00
Lukáš Zaoral
dd6ee45b2d
tests/non-root-user-download: fix test failures
2022-05-12 10:15:57 +02:00
Kamil Dudka
4ad1229e9d
new upstream release - 7.83.1
...
Resolves: CVE-2022-27782 - fix too eager reuse of TLS and SSH connections
Resolves: CVE-2022-27779 - do not accept cookies for TLD with trailing dot
Resolves: CVE-2022-27778 - do not remove wrong file on error
Resolves: CVE-2022-30115 - hsts: ignore trailing dots when comparing hosts names
Resolves: CVE-2022-27780 - reject percent-encoded path separator in URL host
2022-05-11 10:03:28 +02:00
Kamil Dudka
f17162c526
new upstream release - 7.83.0
...
Resolves: CVE-2022-27774 - curl credential leak on redirect
Resolves: CVE-2022-27776 - curl auth/cookie leak on redirect
Resolves: CVE-2022-27775 - curl bad local IPv6 connection reuse
Resolves: CVE-2022-22576 - curl OAUTH2 bearer bypass in connection re-use
2022-04-27 13:52:54 +02:00
Kamil Dudka
cd99025ff8
curl.spec: bump release for the previous commit
2022-03-15 12:57:49 +01:00
Kamil Dudka
cbc7b73e10
openssl: fix incorrect CURLE_OUT_OF_MEMORY error
...
... on CN check failure, which was breaking the test-suite of pycurl.
Reported-by: Lukas Zaoral
2022-03-15 12:53:45 +01:00
Kamil Dudka
4f4da0817d
new upstream release - 7.82.0
2022-03-05 11:17:52 +01:00
Kamil Dudka
cf3c14e497
enable IDN support also in libcurl-minimal
...
... as requested at fedora devel mailing-list:
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/SH5WAIBVF7GVSKL2VPMSQKY7BB4QYEB5/
2022-02-24 09:50:19 +01:00
Zbigniew Jędrzejewski-Szmek
d768f3c814
Pull in libcurl-minimal if installing curl-minimal
...
curl-minimal has an automatically generated dependency on libcurl.so.4(), so it'd
pull in either libcurl or libcurl-minimal. Let's make the second one preferred.
$ sudo dnf install --releasever=rawhide --installroot=/var/tmp/f36-test --setopt install_weak_deps=False curl-minimal
...
Total download size: 21 M
Installed size: 64 M
$ sudo dnf install --releasever=rawhide --installroot=/var/tmp/f36-test --setopt install_weak_deps=False curl-minimal libcurl-minimal
...
Total download size: 18 M
Installed size: 57 M
2022-02-10 20:52:05 +01:00
Fedora Release Engineering
c3286199cb
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-01-20 00:08:37 +00:00
Kamil Dudka
3e801a6f9f
new upstream release - 7.81.0
2022-01-05 09:35:58 +01:00
Paul Howarth
503307b687
sshserver.pl (used in test suite) now requires the Digest::SHA perl module
2021-11-14 17:06:12 +00:00
Kamil Dudka
ef0743b641
new upstream release - 7.80.0
2021-11-10 09:03:50 +01:00
Kamil Dudka
ac00a5bac0
temporarily disable tests 300{0,1} on x86_64
...
stunnel clashes with itself
2021-10-27 13:57:07 +02:00
Kamil Dudka
94a3e807dd
Related: #2005874 - re-enable HSTS in libcurl-minimal
...
... as a security feature
2021-10-26 17:15:50 +02:00
Miroslav Vadkerti
1b982b367e
Migrate tests to tmt
...
Signed-off-by: Miroslav Vadkerti <mvadkert@redhat.com>
2021-10-05 06:26:42 +00:00
Kamil Dudka
a0acb0cc77
Related: #2005874 - use correct bug ID in the change log
2021-10-04 12:29:42 +02:00
Kamil Dudka
d4c5b54bf3
run upstream tests for both curl-minimal and curl-full
...
As we made libcurl-minimal more minimal, it differs more from
libcurl-full and it should be tested separately. On the other
hand, the test-suite for libcurl-minimal runs faster now because
more tests are skipped.
2021-10-04 09:55:13 +02:00
Kamil Dudka
5ebead952b
Resolves : #1994521 - disable more protocols and features in libcurl-minimal
...
... to limit vulnerability exposure in case there is a CVE in curl
in some of the rarer protocols
2021-10-04 09:55:11 +02:00
Kamil Dudka
54117120e4
explicitly disable zstd while configuring curl
...
... in order to make local builds closer to what we get from Koji
2021-10-04 09:54:25 +02:00
Kamil Dudka
c2f61abc1c
curl.spec: align the lists of configure options
...
... to make it easier to extend the lists
2021-10-04 09:54:25 +02:00
Kamil Dudka
407e3960e4
new upstream release - 7.79.1
2021-09-22 09:16:36 +02:00
Kamil Dudka
e2155b2695
fix regression in http2 implementation
...
... introduced in the last release
2021-09-16 12:26:16 +02:00
Sahana Prasad
f97c73e9d7
Rebuilt with OpenSSL 3.0.0
2021-09-16 12:23:37 +02:00
Kamil Dudka
31329d9443
forgot to bump release in the previous commit
2021-09-16 08:51:26 +02:00
Kamil Dudka
25f443ae12
make SCP/SFTP tests work with openssh-8.7p1
2021-09-16 08:45:33 +02:00
Kamil Dudka
287da1ceec
temporarily disable test 1184
...
... which occasionally fails on aarch64/armv7hl Koji builders
for no apparent reason
2021-09-15 10:55:21 +02:00
Kamil Dudka
d02617d325
new upstream release - 7.79.0
...
Resolves: CVE-2021-22947 - STARTTLS protocol injection via MITM
Resolves: CVE-2021-22946 - protocol downgrade required TLS bypassed
Resolves: CVE-2021-22945 - use-after-free and double-free in MQTT sending
2021-09-15 09:09:11 +02:00
Sahana Prasad
62e2b8d564
Rebuilt with OpenSSL 3.0.0
2021-09-14 19:00:02 +02:00
Kamil Dudka
f964aefff3
make explicit dependency on openssl work with alpha/beta builds of openssl
...
Reported-by: Daniel Rusek
2021-07-23 17:15:57 +02:00
Fedora Release Engineering
adeb2cb476
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-07-21 20:15:37 +00:00
Kamil Dudka
85619bdba3
disable tests 320..322 on ppc64le where it started to hang/fail
...
... in Koji environment only. I was not able to reproduce the issues
with the fedora-rawhide-ppc64le buildroot in mock on a ppc64le machine.
2021-07-21 15:53:36 +02:00
Kamil Dudka
0ac0b6fbd1
prevent valgrind from being extremely slow
2021-07-21 12:39:45 +02:00
Kamil Dudka
c921b2c69d
remove a valgrind-related patch no longer needed
2021-07-21 12:38:15 +02:00
Kamil Dudka
ef5a5be78e
temporarily disable test 1452 on s390x
...
... where the client times out
2021-07-21 12:06:57 +02:00
Kamil Dudka
64bcb4bcc1
new upstream release - 7.78.0
...
Resolves: CVE-2021-22925 - TELNET stack contents disclosure again
Resolves: CVE-2021-22924 - bad connection reuse due to flawed path name checks
Resolves: CVE-2021-22923 - metalink download sends credentials
Resolves: CVE-2021-22922 - wrong content via metalink not discarded
2021-07-21 10:22:33 +02:00
Stewart Smith
ece67bdd2f
gpgverify source tarball
...
Signed-off-by: Stewart Smith <trawets@amazon.com>
2021-07-09 18:42:11 +00:00
Kamil Dudka
ddaf41062c
Resolves : #1967213 - build the curl tool without metalink support
...
Today curl upstream announced that they are going to completely remove
support for metalink from curl already in the next release of curl due
to a number of difficult to fix security issues:
https://curl.se/mail/archive-2021-06/0006.html
https://github.com/curl/curl/pull/7176
2021-06-02 19:55:01 +02:00
Kamil Dudka
4c89d92ee7
new upstream release - 7.77.0
...
Resolves: CVE-2021-22901 - TLS session caching disaster
Resolves: CVE-2021-22898 - TELNET stack contents disclosure
2021-05-26 09:20:35 +02:00
Kamil Dudka
4b7b124d75
Resolves : #1938699 - http2: fix resource leaks detected by Coverity
2021-05-03 17:54:40 +02:00
Kamil Dudka
bf8bb4b5b4
new upstream release - 7.76.1
2021-04-14 09:54:33 +02:00
Kamil Dudka
a0d250c162
new upstream release - 7.76.0
...
Resolves: CVE-2021-22890 - TLS 1.3 session ticket proxy host mixup
Resolves: CVE-2021-22876 - Automatic referer leaks credentials
2021-03-31 10:47:25 +02:00
Kamil Dudka
25676e54ef
replace 0104-curl-7.73.0-localhost6.patch by sed invocation
...
... to avoid conflict resolution on new upstream releases
2021-03-31 10:47:24 +02:00
Kamil Dudka
b57f5589af
fix misplaced comment in %prep from the previous commit
2021-03-24 11:17:40 +01:00
Kamil Dudka
742526c048
Resolves : #1941925 - fix SIGSEGV upon disconnect of a ldaps:// transfer
2021-03-24 11:04:10 +01:00
Kamil Dudka
bd924f90f2
build-require python3-impacket only on Fedora
...
It might not be available in RHEL or CentOS Stream build repos.
2021-02-23 22:03:03 +01:00
Kamil Dudka
d781733304
%check: use unstripped library from the build dir
...
It results in more detailed backtraces in valgrind's output.
2021-02-11 11:51:32 +01:00
Kamil Dudka
7dada590f2
new upstream release - 7.75.0
2021-02-03 09:07:33 +01:00
Kamil Dudka
1cfc0aeb3b
do not use stunnel for tests on s390x builds
...
... to avoid spurious failures
2021-01-26 15:13:50 +01:00
Fedora Release Engineering
3613691251
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-01-26 02:51:37 +00:00
Kamil Dudka
182c2a8bbb
do not rewrite shebangs in test-suite to use python3 explicitly
2020-12-09 18:51:40 +01:00
Kamil Dudka
c829072f9f
new upstream release - 7.74.0
...
Resolves: CVE-2020-8286 - curl: Inferior OCSP verification
Resolves: CVE-2020-8285 - libcurl: FTP wildcard stack overflow
Resolves: CVE-2020-8284 - curl: trusting FTP PASV responses
2020-12-09 11:13:15 +01:00
Paul Howarth
9ef73a22d0
Upstream moved from curl.haxx.se to curl.se
2020-11-09 12:31:52 +00:00
Kamil Dudka
3c950d5541
prevent upstream test 1451 from being skipped
2020-10-14 11:54:54 +02:00
Kamil Dudka
a15dd89aaa
new upstream release - 7.73.0
2020-10-14 10:31:57 +02:00
Paul Howarth
89714e3b24
Fix bug reference in changelog
2020-09-20 11:49:49 +01:00
Jinoh Kang
4226c316c7
Resolves: #1877671O - fix multiarch conflicts in libcurl-minimal
2020-09-10 09:45:17 +02:00
Kamil Dudka
e7a12a6b7b
new upstream release - 7.72.0
...
Resolves: CVE-2020-8231 - libcurl: wrong connect-only connection
2020-08-19 12:29:51 +02:00
Kamil Dudka
840be82e6f
pick an upstream fix to make test 1140 pass again
2020-08-06 11:48:24 +02:00
Kamil Dudka
b740a1ecc6
setopt: unset NOBODY switches to GET if still HEAD
...
Reported-by: Vít Ondruch
2020-08-06 11:04:30 +02:00
Fedora Release Engineering
407d32e00a
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-27 14:52:54 +00:00
Tom Stellard
df63713984
Use make macros
...
https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro
2020-07-13 19:00:01 +00:00
Kamil Dudka
87d774717a
Resolves : #1833193 - curl: make the --krb option work again
2020-07-03 12:47:48 +02:00
Kamil Dudka
6071e0dd16
new upstream release - 7.71.1
2020-07-01 09:26:44 +02:00
Kamil Dudka
8c661bb9d7
new upstream release - 7.71.0
...
Resolves: CVE-2020-8169 - curl: Partial password leak over DNS on HTTP redirect
Resolves: CVE-2020-8177 - curl: overwrite local file with -J
2020-06-24 10:03:56 +02:00
Kamil Dudka
c74a58b095
Related: #1829180 - add BuildRequires for hostname
...
It is used by the test-suite but it is missing in armv7hl buildroot.
2020-05-02 10:08:32 +02:00
Kamil Dudka
ce4949188b
Related: #1829180 - temporarily disable tests 702 703 716 on armv7hl
2020-05-02 09:52:39 +02:00
Kamil Dudka
c88a6aff30
new upstream release - 7.70.0
2020-04-29 14:59:25 +02:00
Kamil Dudka
6a752013d0
Resolves : #1824926 - SSH: use new ECDSA key types to check known hosts
2020-04-20 11:34:56 +02:00
Tom Stellard
53c8c93125
Prevent discarding of -g when compiling with clang
2020-04-17 16:06:52 +00:00
Kamil Dudka
ac5c236f18
new upstream release - 7.69.1
2020-03-11 10:23:53 +01:00
Kamil Dudka
fbcad9a3a0
Resolves : #1810989 - make Flatpak work again
2020-03-09 09:54:27 +01:00
Kamil Dudka
249d0aea51
new upstream release - 7.69.0
2020-03-04 11:41:43 +01:00
Fedora Release Engineering
83181bd6d3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-28 15:11:40 +00:00
Kamil Dudka
dfb411a0a2
new upstream release - 7.68.0
2020-01-08 09:52:29 +01:00
Kamil Dudka
13f70ceee2
fix upstream release number in last two change log items
2020-01-08 09:47:26 +01:00
Kamil Dudka
d1233ad4cd
do not run test-suite through valgrind on i686 brew builds
...
The architecture is being decommissioned in Fedora, which makes it
difficult to debug valgrind failures (usually not related to curl
anyway).
2019-11-15 10:37:39 +01:00
Kamil Dudka
eeb37e29bd
Related: #1771025 - fix date in the last change log entry
2019-11-14 16:25:25 +01:00
Kamil Dudka
2298078d54
Resolves : #1771025 - fix infinite loop on upload using a glob
2019-11-14 13:57:39 +01:00
Kamil Dudka
c667b141d6
new upstream release - 7.67.0
2019-11-06 09:26:57 +01:00
Kamil Dudka
e0bf66ef6c
fix memory leaked by parse_metalink()
2019-09-13 10:18:24 +02:00
Kamil Dudka
da9af16256
new upstream release - 7.66.0
...
Resolves: CVE-2019-5481 - double free due to subsequent call of realloc()
Resolves: CVE-2019-5482 - heap buffer overflow in function tftp_receive_packet()
2019-09-12 15:20:21 +02:00
Kamil Dudka
91c50ee6d4
Resolves : #1690971 - avoid reporting spurious error in the HTTP2 framing layer
2019-08-27 18:11:29 +02:00
Kamil Dudka
8559ecc1d9
changelog: fix copy/paste error in the last entry
2019-08-01 16:41:42 +02:00
Kamil Dudka
863394fd95
improve handling of gss_init_sec_context() failures
2019-08-01 16:37:57 +02:00
Fedora Release Engineering
22186831fb
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-07-24 21:21:56 +00:00
Paul Howarth
a5c984a590
new upstream release - 7.65.3
2019-07-20 12:02:57 +01:00
Kamil Dudka
6e794d5beb
new upstream release - 7.65.2
2019-07-17 10:34:24 +02:00
Kamil Dudka
901da63160
new upstream release - 7.65.1
2019-06-05 09:33:30 +02:00
Kamil Dudka
b6ccff47ac
Resolves : #1714893 - fix spurious timeout events with speed-limit
2019-05-30 15:27:58 +02:00
Kamil Dudka
3c7950da77
new upstream release - 7.65.0
...
Resolves: CVE-2019-5436 - TFTP receive buffer overflow
Resolves: CVE-2019-5435 - integer overflows in curl_url_set()
2019-05-22 10:42:26 +02:00
Kamil Dudka
9dd5d73f3b
do not treat failure of gss_init_sec_context() with --negotiate as fatal
...
This commit fixes a major incompatibility introduced in curl-7.64.1.
Bug: https://github.com/curl/curl/issues/3726
2019-05-09 10:08:03 +02:00
Paul Howarth
8fd906c559
generation of shell completions now needs more perl stuff
2019-04-05 13:38:27 +01:00
Kamil Dudka
bbad3e0a62
new upstream release - 7.64.1
2019-03-27 12:45:46 +01:00
Kamil Dudka
0ed971f14f
fix last but one change log entry
2019-03-25 12:39:00 +01:00
Kamil Dudka
7594f15bce
Related: #1690971 - remove verbose "Expire in" ... messages
2019-03-25 12:35:52 +01:00
Kamil Dudka
902ddefeb5
avoid spurious "Could not resolve host: [host name]" error messages
2019-03-21 09:39:30 +01:00
Kamil Dudka
95008127cf
Resolves : #1683676 - fix NULL dereference if flushing cookies with no CookieInfo set
2019-02-27 18:02:05 +01:00
Kamil Dudka
e97fdf9b7f
Resolves : #1680198 - prevent NetworkManager from leaking file descriptors
2019-02-25 14:24:32 +01:00
Kamil Dudka
9ace613273
make zsh completion work again
2019-02-11 13:22:07 +01:00
Kamil Dudka
2bdb624139
new upstream release - 7.64.0
...
Resolves: CVE-2019-3823 - SMTP end-of-response out-of-bounds read
Resolves: CVE-2019-3822 - NTLMv2 type-3 header stack buffer overflow
Resolves: CVE-2018-16890 - NTLM type-2 out-of-bounds buffer read
2019-02-06 09:56:05 +01:00
Kamil Dudka
3c5dec6602
prevent valgrind from reporting false positives on x86_64
2019-02-04 17:45:12 +01:00
Fedora Release Engineering
9221f774a1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-01-31 16:37:02 +00:00
Kamil Dudka
1a6a3b20a6
Resolves: CVE-2018-20483 - xattr: strip credentials from any URL that is stored
2019-01-21 10:13:55 +01:00
Kamil Dudka
da8449decd
replace 0001-curl-7.62.0-http-post-negotiate.patch by upstream patch
2019-01-07 12:42:06 +01:00
Kamil Dudka
32b0144f20
replace 0105-curl-7.63.0-libstubgss-ldadd.patch by upstream patch
2019-01-04 14:18:53 +01:00
Kamil Dudka
49f5a42f96
Resolves : #1658574 - curl -J: do not append to the destination file
2018-12-19 13:43:28 +01:00
Kamil Dudka
c30a9c7fdb
Resolves : #1659329 - revert an upstream commit that broke fedpkg new-sources
2018-12-14 11:21:54 +01:00
Kamil Dudka
c91c27bce9
libtest: avoid symbol lookup error in libstubgss.so
2018-12-12 14:39:00 +01:00
Kamil Dudka
a94ce82de0
new upstream release - 7.63.0
2018-12-12 09:51:10 +01:00
Kamil Dudka
34a4d8f848
new upstream release - 7.62.0
...
Resolves: CVE-2018-16839 - SASL password overflow via integer overflow
Resolves: CVE-2018-16840 - use-after-free in handle close
Resolves: CVE-2018-16842 - warning message out-of-buffer read
2018-10-31 12:47:56 +01:00
Kamil Dudka
9be316eea1
enable TLS 1.3 post-handshake auth in OpenSSL
...
Bug: https://github.com/curl/curl/pull/3027
2018-10-11 16:16:32 +02:00
Kamil Dudka
2346b66a23
update the documentation of --tlsv1.0 in curl(1) man page
2018-10-11 16:16:18 +02:00
Kamil Dudka
800bb58ef3
Resolves : #1631804 - enforce versioned libpsl dependency for libcurl
2018-10-05 13:59:35 +02:00
Kamil Dudka
84125cbefe
test320: update expected output for gnutls-3.6.4
2018-10-05 13:41:48 +02:00
Kamil Dudka
ece57c4aa4
Related: #1622594 - drop 0105-curl-7.61.0-tests-ssh-keygen.patch no longer needed
2018-10-04 15:37:53 +02:00
Kamil Dudka
20b63790e4
new upstream release - 7.61.1
...
Resolves: CVE-2018-14618 - NTLM password overflow via integer overflow
2018-09-05 10:03:29 +02:00
Kamil Dudka
e7b6b91818
make the --tls13-ciphers option work
2018-09-04 15:48:11 +02:00
Kamil Dudka
8bff7e0d6b
Related: #1622594 - tests: make ssh-keygen always produce PEM format
...
The default format produced by openssh-7.8p1 cannot be consumed
by currently available versions of libssh and libssh2.
2018-08-27 16:55:32 +02:00
Kamil Dudka
023b327acc
Resolves : #1595135 - scp/sftp: fix infinite connect loop on invalid private key
2018-08-15 13:57:06 +02:00
Kamil Dudka
178b0fc823
Resolves : #1219544 - ssl: set engine implicitly when a PKCS#11 URI is provided
2018-08-09 15:35:59 +02:00
Kamil Dudka
35134a4aee
Related: #1610888 - relax crypto policy for the test-suite to make it pass again
2018-08-07 16:56:26 +02:00
Kamil Dudka
3fb6e23557
disable flaky test 1900, which covers deprecated HTTP pipelining
...
See https://github.com/curl/curl/pull/2705 for details.
2018-07-31 10:42:03 +02:00
Kamil Dudka
85286dc2b3
adapt test 323 for updated OpenSSL
2018-07-31 10:33:53 +02:00
Kamil Dudka
bcdea58703
temporarily disable test 582 on s390x (client times out)
2018-07-13 13:47:08 +02:00
Fedora Release Engineering
072eac2fb6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-07-12 22:28:24 +00:00
Kamil Dudka
a89a46eca8
new upstream release - 7.61.0
...
Resolves: CVE-2018-0500 - SMTP send heap buffer overflow
2018-07-11 14:19:28 +02:00
Kamil Dudka
d41d215108
disable test 1455, which occasionally fails in Koji
...
... with 'bind failed with errno 98: Address already in use'
2018-07-10 15:16:40 +02:00
Kamil Dudka
9f5f0d1189
enable support for brotli compression in libcurl-full
2018-07-10 13:51:08 +02:00
Kamil Dudka
befa5428f0
do not hard-wire path of the Python 3 interpreter
2018-07-04 15:20:51 +02:00
Kamil Dudka
4f55f71cfe
Related: #1570246 - enable vlagrind again
...
This reverts commit e51a34d6cc .
2018-07-04 15:15:24 +02:00
Kamil Dudka
e51a34d6cc
Related: #1570246 - temporarily disable valgrind completely
...
... and revert the previous workaround, which does not work on Koji
2018-05-16 15:58:58 +02:00
Kamil Dudka
09c874db53
require glibc-debuginfo for valgrind-enabled build
...
... as suggested by valgrind itself:
valgrind: Fatal error at startup: a function redirection
valgrind: which is mandatory for this platform-tool combination
valgrind: cannot be set up. Details of the redirection are:
valgrind:
valgrind: A must-be-redirected function
valgrind: whose name matches the pattern: strlen
valgrind: in an object with soname matching: ld-linux-x86-64.so.2
valgrind: was not found whilst processing
valgrind: symbols from the object with soname: ld-linux-x86-64.so.2
valgrind:
valgrind: Possible fixes: (1, short term): install glibc's debuginfo
valgrind: package on this machine. (2, longer term): ask the packagers
valgrind: for your Linux distribution to please in future ship a non-
valgrind: stripped ld.so (or whatever the dynamic linker .so is called)
valgrind: that exports the above-named function using the standard
valgrind: calling conventions for this platform. The package you need
valgrind: to install for fix (1) is called
valgrind:
valgrind: On Debian, Ubuntu: libc6-dbg
valgrind: On SuSE, openSuSE, Fedora, RHEL: glibc-debuginfo
valgrind:
valgrind: Note that if you are debugging a 32 bit process on a
valgrind: 64 bit system, you will need a corresponding 32 bit debuginfo
valgrind: package (e.g. libc6-dbg:i386).
valgrind:
valgrind: Cannot continue -- exiting now. Sorry.
2018-05-16 15:23:55 +02:00
Kamil Dudka
5a0fa9250b
new upstream release, which fixes the following vulnerabilities
...
Resolves: CVE-2018-1000300 - FTP shutdown response buffer overflow
Resolves: CVE-2018-1000301 - RTSP bad headers buffer over-read
2018-05-16 15:02:28 +02:00
Kamil Dudka
a1b38730ce
make the test-suite use Python 3
...
Unfortunately, smbserver.py does not work with Python 3 because
there is no 'impacket' module available for Python 3:
https://github.com/CoreSecurity/impacket/issues/61
2018-03-15 15:43:07 +01:00
Kamil Dudka
6402b496fc
ftp: fix typo in recursive callback detection for seeking
2018-03-14 14:43:54 +01:00
Kamil Dudka
bdef0a1bf6
new upstream release - 7.59.0
...
Resolves: CVE-2018-1000120 - FTP path trickery leads to NIL byte out of bounds write
Resolves: CVE-2018-1000121 - LDAP NULL pointer dereference
Resolves: CVE-2018-1000122 - RTSP RTP buffer over-read
2018-03-14 10:28:05 +01:00
Kamil Dudka
43b81665b0
http2: mark the connection for close on GOAWAY
2018-03-12 10:28:21 +01:00
Paul Howarth
bdc6ab544b
Robustness improvements to spec file
...
- Add explicity-used build requirements
- Fix libcurl soname version number in %files list to avoid accidental soname
bumps
2018-02-19 10:10:12 +00:00
Paul Howarth
a16f4de7a2
Update scriptlets, enforce versioned libssh dependency
...
- switch to %ldconfig_scriptlets
- drop legacy BuildRoot: and Group: tags
- enforce versioned libssh dependency for libcurl
2018-02-15 09:57:54 +00:00
Igor Gnatenko
5012445aca
Remove BuildRoot definition
...
None of currently supported distributions need that.
It was needed last for EL5 which is EOL now
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2018-02-13 23:11:49 +01:00
Kamil Dudka
960515d8a1
Related: #1540549 - drop temporary workaround for the GCC bug
2018-02-13 10:33:16 +01:00
Fedora Release Engineering
1bbb30f4f6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-02-07 06:08:47 +00:00
Kamil Dudka
b76e2f2c65
Related: #1540549 - use the workaround for f28 only
...
... so that it does not break the build with old versions of GCC
2018-02-01 14:05:00 +01:00
Kamil Dudka
bf966a954e
Related: #1540549 - temporarily work around internal compiler error on x86_64
2018-02-01 12:55:07 +01:00
Kamil Dudka
3ad2894efb
disable brp-ldconfig to make RemovePathPostfixes work
...
... with shared libraries again
Suggested at:
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/message/54Y4DZXHYSDXJDHJTBTBYLXC7OJ73JDU/
2018-01-31 14:44:06 +01:00
Andreas Schneider
cbbefe6fb9
Resolves : #1531483 - use libssh (instead of libssh2)
...
... to implement SCP/SFTP in libcurl
2018-01-24 18:06:50 +01:00
Kamil Dudka
93c55561d3
new upstream release - 7.58.0
...
Resolves: CVE-2018-1000005 - curl: HTTP/2 trailer out-of-bounds read
Resolves: CVE-2018-1000007 - curl: HTTP authentication leak in redirects
2018-01-24 11:55:14 +01:00
Kamil Dudka
ed352e927e
new upstream release - 7.57.0
...
Resolves: CVE-2017-8816 - curl: NTLM buffer overflow via integer overflow
Resolves: CVE-2017-8817 - curl: FTP wildcard out of bounds read
Resolves: CVE-2017-8818 - curl: SSL out of buffer access
2017-11-29 14:03:21 +01:00
Kamil Dudka
5d4a9257c3
new upstream release - 7.56.1 (fixes CVE-2017-1000257)
2017-10-23 10:13:16 +02:00
Kamil Dudka
c4a2596b22
re-enable temporarily disabled IDN2 test-cases
...
test2033 is now marked flaky by upstream, so it does not need
to explicitly disabled any more
2017-10-04 10:00:50 +02:00
Kamil Dudka
46c8abb050
new upstream release - 7.56.0 (fixes CVE-2017-1000254)
2017-10-04 09:36:05 +02:00
Andrei Stepanov
c7e4ac606d
Add CI tests using the standard test interface
...
Adds tests according to the CI wiki [0] specifically the standard test interface in the spec [1].
[0] https://fedoraproject.org/wiki/CI
[1] https://fedoraproject.org/wiki/Changes/InvokingTests
Signed-off-by: Andrei Stepanov <astepano@redhat.com>
2017-09-26 15:46:24 +00:00