diff --git a/.fmf/version b/.fmf/version deleted file mode 100644 index d00491f..0000000 --- a/.fmf/version +++ /dev/null @@ -1 +0,0 @@ -1 diff --git a/.gitignore b/.gitignore index c15e946..03adcba 100644 --- a/.gitignore +++ b/.gitignore @@ -24,4 +24,3 @@ fontforge_full-20100501.tar.bz2 /fontforge-20200314.tar.gz /fontforge-20201107.tar.gz /fontforge-20230101.tar.gz -/fontforge-20251009.tar.gz diff --git a/fix_memleak_in_function_DlgCreate8-5491.patch b/fix_memleak_in_function_DlgCreate8-5491.patch new file mode 100644 index 0000000..9af06f8 --- /dev/null +++ b/fix_memleak_in_function_DlgCreate8-5491.patch @@ -0,0 +1,31 @@ +From 701e4d7569d6bd777704ab3364d7d1c519d89a91 Mon Sep 17 00:00:00 2001 +From: zhailiangliang +Date: Mon, 4 Nov 2024 08:56:07 +0000 +Subject: [PATCH] fix memleak in function DlgCreate8 + +--- + gdraw/gaskdlg.c | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +diff --git a/gdraw/gaskdlg.c b/gdraw/gaskdlg.c +index 3563361796..8178be14c8 100644 +--- a/gdraw/gaskdlg.c ++++ b/gdraw/gaskdlg.c +@@ -209,12 +209,13 @@ static GWindow DlgCreate8(const char *title,const char *question,va_list ap, + extern GBox _GGadget_defaultbutton_box; + + if ( d!=NULL ) +- memset(d,0,sizeof(*d)); ++ memset(d,0,sizeof(*d)); + buf = vsmprintf(question, ap); + if ( screen_display==NULL ) { +- fprintf(stderr, "%s\n", buf ); +- if ( d!=NULL ) d->done = true; +-return( NULL ); ++ fprintf(stderr, "%s\n", buf); ++ if ( d!=NULL ) d->done = true; ++ free(buf); ++ return( NULL ); + } + ubuf = utf82u_copy(buf); + free(buf); diff --git a/fontforge.spec b/fontforge.spec index 846dfdd..2696d40 100644 --- a/fontforge.spec +++ b/fontforge.spec @@ -1,13 +1,21 @@ %global gettext_package FontForge Name: fontforge -Version: 20251009 -Release: 1%{?dist} +Version: 20230101 +Release: 16%{?dist} Summary: Outline and bitmap font editor License: GPL-3.0-or-later URL: http://fontforge.github.io/ Source0: https://github.com/fontforge/%{name}/archive/%{version}.tar.gz#/%{name}-%{version}.tar.gz +# Fix translations with gettext-0.22, https://github.com/fontforge/fontforge/pull/5257 +Patch0: 0001-Fix-errors-in-French-and-Italian-translations.patch +# https://github.com/fontforge/fontforge/pull/5367 +# Fixes CVE-2024-25081 and CVE-2024-25082 +Patch1: https://patch-diff.githubusercontent.com/raw/fontforge/fontforge/pull/5367.patch#/Fix_Splinefont_shell_invocation.patch +Patch2: pyconfig.patch +# https://github.com/fontforge/fontforge/pull/5491 +Patch3: fix_memleak_in_function_DlgCreate8-5491.patch Requires: xdg-utils Requires: (autotrace or potrace) @@ -38,8 +46,6 @@ BuildRequires: shared-mime-info BuildRequires: gtk3-devel BuildRequires: python3-sphinx BuildRequires: make -# 20151009 version requires below -BuildRequires: gtkmm3.0-devel %py_provides python3-fontforge %py_provides python3-psMat @@ -68,7 +74,11 @@ This package contains documentation files for %{name}. %prep -%autosetup +%autosetup -p1 + +# Remove tests that requires Internet access +sed -i '45d;82d;101d;127d' tests/CMakeLists.txt + %build export CFLAGS="%{optflags} -fno-strict-aliasing" @@ -96,7 +106,9 @@ appstream-util validate-relax --nonet %{buildroot}%{_metainfodir}/*.appdata.xml %find_lang %{gettext_package} %check -%ctest +pushd %{__cmake_builddir} +make check +popd %files -f %{gettext_package}.lang %doc AUTHORS @@ -119,22 +131,11 @@ appstream-util validate-relax --nonet %{buildroot}%{_metainfodir}/*.appdata.xml %doc %{_pkgdocdir} %changelog -* Fri Oct 10 2025 Parag Nemade - 20251009-1 -- Update to 20251009 version (#2402960) -- Remove upstream released patches -- Add new BR: gtkmm3.0-devel +* Tue Oct 28 2025 Parag Nemade - 20230101-16 +- Move to use %%autosetup macro so that we will not forget to apply patches -* Wed Jul 23 2025 Fedora Release Engineering - 20230101-18 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Thu Jul 17 2025 Parag Nemade - 20230101-17 -- Update for https://fedoraproject.org/wiki/Changes/CMake_ninja_default (rh#2381004) - -* Tue Jun 03 2025 Python Maint - 20230101-16 -- Rebuilt for Python 3.14 - -* Thu Jan 16 2025 Fedora Release Engineering - 20230101-15 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild +* Mon Oct 27 2025 Parag Nemade - 20230101-15 +- Resolves: CVE-2025-50949 * Wed Jul 17 2024 Fedora Release Engineering - 20230101-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild diff --git a/plans/fontforge.fmf b/plans/fontforge.fmf deleted file mode 100644 index c1627f9..0000000 --- a/plans/fontforge.fmf +++ /dev/null @@ -1,5 +0,0 @@ -summary: Basic smoke test -discover: - how: fmf -execute: - how: tmt diff --git a/pyconfig.patch b/pyconfig.patch index cfd90f4..628902e 100644 --- a/pyconfig.patch +++ b/pyconfig.patch @@ -1,5 +1,5 @@ ---- pycontrib/FontCompare/setup.py~ 2022-12-31 23:25:21.000000000 -0600 -+++ pycontrib/FontCompare/setup.py 2024-06-14 15:14:14.119920623 -0500 +--- fontforge/pycontrib/FontCompare/setup.py~ 2022-12-31 23:25:21.000000000 -0600 ++++ fontforge/pycontrib/FontCompare/setup.py 2024-06-14 15:14:14.119920623 -0500 @@ -15,7 +15,6 @@ along with this program. If not, see . """ @@ -8,8 +8,8 @@ from setuptools import setup setup(name='Font Compare', version='1.0', ---- fontforge/python.c~ 2022-12-31 23:25:21.000000000 -0600 -+++ fontforge/python.c 2024-06-14 15:38:41.397897757 -0500 +--- fontforge/fontforge/python.c~ 2022-12-31 23:25:21.000000000 -0600 ++++ fontforge/fontforge/python.c 2024-06-14 15:38:41.397897757 -0500 @@ -19633,7 +19633,10 @@ if ( saved_progname ) free(saved_progname); diff --git a/sources b/sources index 3c609cb..b0ab3ee 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (fontforge-20251009.tar.gz) = 2923c54e10585551c93102d8b7a389c9de3c629c1676fc8c576c9b9c3f1f6fe28f7a1e39fd5a57ab7eeadf0b17d722bf439ca94f0a788ceab6993e1a93ea7d5f +SHA512 (fontforge-20230101.tar.gz) = 67c21f7e55a78097ef7d7d9abac3add2017400015a6a9dfd56674d933bdba963cb6c4e631ae066026fe1862298d60dd968dec61a9bbee7253dd2f7d105655178 diff --git a/tests/main.fmf b/tests/main.fmf deleted file mode 100644 index 542903b..0000000 --- a/tests/main.fmf +++ /dev/null @@ -1,5 +0,0 @@ -require: -- fontforge -test: bash ./run_tests.sh -framework: shell - diff --git a/tests/runtests.sh b/tests/runtests.sh deleted file mode 100755 index a94d8f5..0000000 --- a/tests/runtests.sh +++ /dev/null @@ -1,47 +0,0 @@ -#!/bin/bash -. /usr/share/beakerlib/beakerlib.sh || exit 1 - -NAME=fontforge - -rlJournalStart - rlPhaseStartSetup - rlAssertRpm ${NAME} - rlAssertRpm ${NAME}-devel - rlShowPackageVersion ${NAME} - rlRun -t -l "VERSION=$(rpm -q ${NAME} --queryformat='%{version}')" 0 "Get VERSION" - FEDORA_VERSION=$(rlGetDistroRelease) - rlLog "FEDORA_VERSION=${DISTRO_RELEASE}" - rlRun "tmp=\$(mktemp -d)" 0 "Create tmp directory" - rlRun "pushd $tmp" - rlFetchSrcForInstalled "${NAME}" - rlRun "rpm --define '_topdir $tmp' -i *src.rpm" - rlRun -t -l "mkdir BUILD" 0 "Creating BUILD directory" - rlRun -t -l "rpmbuild --noclean --nodeps --define '_topdir $tmp' -bp $tmp/SPECS/*spec" - if [ -d BUILD/${NAME}-${VERSION}-build ]; then - rlRun -t -l "pushd BUILD/${NAME}-${VERSION}-build/${NAME}-${VERSION}" - else - rlRun -t -l "pushd BUILD/${NAME}-${VERSION}" - fi - rlRun "set -o pipefail" - rlRun "NOCONFIGURE=1 ./autogen.sh" - rlRun "./configure --disable-static --with-graphite2 --with-gobject --enable-introspection" - rlRun "make check" - rlRun "retval=$?" - rlRun "echo $retval" - rlPhaseEnd - - rlPhaseStartTest - rlRun -t -l "INSTALLED_VERSION=$(hb-info --version|awk 'NR==1 {print $3}')" \ - 0 "Get installed version" - rlAssertEquals "versions should be equal" "${VERSION}" "${INSTALLED_VERSION}" - rlGetTestState - rlLog "Number of failed asserts so far: ${ECODE}" - rlRun "popd" 0 - rlPhaseEnd - - rlPhaseStartCleanup - rlRun "popd" - rlRun "rm -r $tmp" 0 "Remove tmp directory" - rlPhaseEnd -rlJournalEnd - diff --git a/tests/generate-font.py b/tests/scripts/generate-font.py similarity index 100% rename from tests/generate-font.py rename to tests/scripts/generate-font.py diff --git a/tests/generate-sfd.pe b/tests/scripts/generate-sfd.pe similarity index 100% rename from tests/generate-sfd.pe rename to tests/scripts/generate-sfd.pe diff --git a/tests/generate-ttf.pe b/tests/scripts/generate-ttf.pe similarity index 100% rename from tests/generate-ttf.pe rename to tests/scripts/generate-ttf.pe diff --git a/tests/get-font-metadata.py b/tests/scripts/get-font-metadata.py similarity index 100% rename from tests/get-font-metadata.py rename to tests/scripts/get-font-metadata.py diff --git a/tests/run_tests.sh b/tests/scripts/run_tests.sh old mode 100755 new mode 100644 similarity index 100% rename from tests/run_tests.sh rename to tests/scripts/run_tests.sh diff --git a/tests/tests.yml b/tests/tests.yml new file mode 100644 index 0000000..aaf3946 --- /dev/null +++ b/tests/tests.yml @@ -0,0 +1,9 @@ +- hosts: localhost + roles: + - role: standard-test-basic + tags: + - classic + tests: + - simple: + dir: scripts/ + run: ./run_tests.sh