diff --git a/.fmf/version b/.fmf/version new file mode 100644 index 0000000..d00491f --- /dev/null +++ b/.fmf/version @@ -0,0 +1 @@ +1 diff --git a/.gitignore b/.gitignore index 634ee42..ad68e32 100644 --- a/.gitignore +++ b/.gitignore @@ -5,3 +5,7 @@ gzip-1.4.tar.xz /gzip-1.8.tar.xz /gzip-1.9.tar.xz /gzip-1.10.tar.xz +/gzip-1.11.tar.xz +/gzip-1.12.tar.xz +/gzip-1.13.tar.xz +/gzip-1.14.tar.xz diff --git a/cve-2022-1271-part1.patch b/cve-2022-1271-part1.patch deleted file mode 100644 index 2544012..0000000 --- a/cve-2022-1271-part1.patch +++ /dev/null @@ -1,43 +0,0 @@ -From dc9740df61e575e8c3148b7bd3c147a81ea00c7c Mon Sep 17 00:00:00 2001 -From: Lasse Collin -Date: Mon, 4 Apr 2022 23:52:49 -0700 -Subject: zgrep: avoid exploit via multi-newline file names - -* zgrep.in: The issue with the old code is that with multiple -newlines, the N-command will read the second line of input, -then the s-commands will be skipped because it's not the end -of the file yet, then a new sed cycle starts and the pattern -space is printed and emptied. So only the last line or two get -escaped. This patch makes sed read all lines into the pattern -space and then do the escaping. - -This vulnerability was discovered by: -cleemy desu wayo working with Trend Micro Zero Day Initiative ---- - zgrep.in | 10 +++++++--- - 1 file changed, 7 insertions(+), 3 deletions(-) - -diff --git a/zgrep.in b/zgrep.in -index 345dae3..bdf7da2 100644 ---- a/zgrep.in -+++ b/zgrep.in -@@ -222,9 +222,13 @@ do - '* | *'&'* | *'\'* | *'|'*) - i=$(printf '%s\n' "$i" | - sed ' -- $!N -- $s/[&\|]/\\&/g -- $s/\n/\\n/g -+ :start -+ $!{ -+ N -+ b start -+ } -+ s/[&\|]/\\&/g -+ s/\n/\\n/g - ');; - esac - sed_script="s|^|$i:|" --- -cgit v1.1 - diff --git a/cve-2022-1271-part2.patch b/cve-2022-1271-part2.patch deleted file mode 100644 index fa7dc9b..0000000 --- a/cve-2022-1271-part2.patch +++ /dev/null @@ -1,77 +0,0 @@ -From d74a30d45c6834c8e9f87115197370fe86656d81 Mon Sep 17 00:00:00 2001 -From: Jim Meyering -Date: Mon, 4 Apr 2022 23:52:49 -0700 -Subject: zgrep: add NEWS and tests for this exploitable bug - -* tests/zgrep-abuse: New file, based on PoC by cleemy desu wayo. -* tests/Makefile.am (TESTS): Add it. -* NEWS: Mention the exploit. -The bug appears to have been present since the beginning. ---- - tests/Makefile.am | 1 + - tests/zgrep-abuse | 41 +++++++++++++++++++++++++++++++++++++++++ - 3 files changed, 45 insertions(+) - create mode 100755 tests/zgrep-abuse - -diff --git a/tests/Makefile.am b/tests/Makefile.am -index d09672e..5f148d6 100644 ---- a/tests/Makefile.am -+++ b/tests/Makefile.am -@@ -36,6 +36,7 @@ TESTS = \ - z-suffix \ - zdiff \ - zgrep-f \ -+ zgrep-abuse \ - zgrep-context \ - zgrep-signal \ - znew-k -diff --git a/tests/zgrep-abuse b/tests/zgrep-abuse -new file mode 100755 -index 0000000..3e8a8f9 ---- /dev/null -+++ b/tests/zgrep-abuse -@@ -0,0 +1,41 @@ -+#!/bin/sh -+# Show how zgrep applied to a crafted file name may overwrite -+# a selected file with chosen content. Fixed in gzip-1.12. -+ -+# Copyright (C) 2022 Free Software Foundation, Inc. -+ -+# This program is free software: you can redistribute it and/or modify -+# it under the terms of the GNU General Public License as published by -+# the Free Software Foundation, either version 3 of the License, or -+# (at your option) any later version. -+ -+# This program is distributed in the hope that it will be useful, -+# but WITHOUT ANY WARRANTY; without even the implied warranty of -+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the -+# GNU General Public License for more details. -+ -+# You should have received a copy of the GNU General Public License -+# along with this program. If not, see . -+# limit so don't run it by default. -+ -+. "${srcdir=.}/init.sh"; path_prepend_ .. -+ -+: > z || framework_failure_ -+echo test |gzip > 'z| -+p -+1s|.*|chosen-content| -+1w hacked -+etouch .\x2fhacked2 -+d -+# -+#' || framework_failure_ -+ -+fail=0 -+ -+zgrep test z* > /dev/null -+ -+# Before the fix, each of these would be created. -+test -f hacked && fail=1 -+test -f hacked2 && fail=1 -+ -+Exit $fail --- -cgit v1.1 - diff --git a/cve-2022-1271-part3.patch b/cve-2022-1271-part3.patch deleted file mode 100644 index 3509464..0000000 --- a/cve-2022-1271-part3.patch +++ /dev/null @@ -1,46 +0,0 @@ -From c99f320d5c0fd98fe88d9cea5407eb7ad9d50e8a Mon Sep 17 00:00:00 2001 -From: Paul Eggert -Date: Mon, 4 Apr 2022 23:52:49 -0700 -Subject: zgrep: port to POSIX sed -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -* zgrep.in (res): When escaping the file name do not rely on GNU -sed’s extension to POSIX with respect to s/.../\n/. Instead, use -features that should also work with AIX and/or Solaris sed. This is -simpler anyway, and would have prevented the recently-fixed bug. ---- - zgrep.in | 15 ++++----------- - 1 file changed, 4 insertions(+), 11 deletions(-) - -diff --git a/zgrep.in b/zgrep.in -index bdf7da2..6a16dd1 100644 ---- a/zgrep.in -+++ b/zgrep.in -@@ -220,18 +220,11 @@ do - case $i in - (*' - '* | *'&'* | *'\'* | *'|'*) -- i=$(printf '%s\n' "$i" | -- sed ' -- :start -- $!{ -- N -- b start -- } -- s/[&\|]/\\&/g -- s/\n/\\n/g -- ');; -+ icolon=$(printf '%s\n' "$i:" | -+ sed -e 's/[&\|]/\\&/g' -e '$!s/$/\\/');; -+ (*) icolon="$i:";; - esac -- sed_script="s|^|$i:|" -+ sed_script="s|^|$icolon|" - - # Fail if grep or sed fails. - r=$( --- -cgit v1.1 - diff --git a/gzexe.patch b/gzexe.patch deleted file mode 100644 index e48fa2d..0000000 --- a/gzexe.patch +++ /dev/null @@ -1,75 +0,0 @@ -From 21cd963565a43dabd59516bd4cca5c76a614f255 Mon Sep 17 00:00:00 2001 -From: Jakub Martisko -Date: Tue, 26 Mar 2019 12:29:30 +0100 -Subject: [PATCH] Fix: the value of the skip variable in the gzexe - ---- - gzexe.in | 4 ++-- - tests/Makefile.am | 1 + - tests/gzexe | 20 ++++++++++++++++++++ - 3 files changed, 23 insertions(+), 2 deletions(-) - create mode 100755 tests/gzexe - -diff --git a/gzexe.in b/gzexe.in -index 6c61183..cffa84e 100644 ---- a/gzexe.in -+++ b/gzexe.in -@@ -145,7 +145,7 @@ for i do - if test $decomp -eq 0; then - (cat <<'EOF' && - #!/bin/sh --skip=44 -+skip=49 - - tab=' ' - nl=' -@@ -201,7 +201,7 @@ EOF - - else - # decompression -- skip=44 -+ skip=49 - skip_line=`sed -e 1d -e 2q "$file"` - case $skip_line in - skip=[0-9] | skip=[0-9][0-9] | skip=[0-9][0-9][0-9]) -diff --git a/tests/Makefile.am b/tests/Makefile.am -index ebdce5b..4dfbccf 100644 ---- a/tests/Makefile.am -+++ b/tests/Makefile.am -@@ -15,6 +15,7 @@ - # along with this program. If not, see . - - TESTS = \ -+ gzexe \ - gzip-env \ - helin-segv \ - help-version \ -diff --git a/tests/gzexe b/tests/gzexe -new file mode 100755 -index 0000000..45f71c7 ---- /dev/null -+++ b/tests/gzexe -@@ -0,0 +1,20 @@ -+#!/bin/sh -+#Try running simple shell script compressed by gzexe -+ -+. "${srcdir=.}/init.sh"; path_prepend_ .. -+ -+cat < foo || framework_failure_ -+#!/bin/sh -+echo "Hello World!" -+EOF -+ -+echo "Hello World!" > exp || framework_failure_ -+ -+fail=0 -+gzexe foo || fail=1 -+/bin/sh foo > out 2> err || fail=1 -+ -+compare exp out || fail=1 -+test -s err && fail=1 -+ -+Exit $fail --- -2.21.0 - diff --git a/gzip.spec b/gzip.spec index ff78a92..3247385 100644 --- a/gzip.spec +++ b/gzip.spec @@ -1,25 +1,21 @@ -Summary: The GNU data compression program +Summary: GNU data compression program Name: gzip -Version: 1.10 -Release: 5%{?dist} +Version: 1.14 +Release: 1%{?dist} # info pages are under GFDL license -License: GPLv3+ and GFDL -Source0: http://ftp.gnu.org/gnu/gzip/gzip-%{version}.tar.xz +License: GPL-3.0-or-later AND GFDL-1.3-only +Source0: https://ftp.gnu.org/gnu/gzip/gzip-%{version}.tar.xz Source1: https://www.gnu.org/licenses/fdl-1.3.txt # downstream solution for coloured z*grep (#1034839) Source100: colorzgrep.csh Source101: colorzgrep.sh -Patch1: gnulib.patch -Patch2: gzexe.patch -Patch3: cve-2022-1271-part1.patch -Patch4: cve-2022-1271-part2.patch -Patch5: cve-2022-1271-part3.patch +Patch1: s390_errno.patch # Fixed in upstream code. # http://thread.gmane.org/gmane.comp.gnu.gzip.bugs/378 -URL: http://www.gzip.org/ +URL: https://www.gzip.org/ # Requires should not be added for gzip wrappers (eg. zdiff, zgrep, # zless) of another tools, because gzip "extends" the tools by its # wrappers much more than it "requires" them. @@ -43,11 +39,8 @@ very commonly used data compression program. %prep %setup -q -#%patch1 -p1 -b .gnulib -%patch2 -p1 -b .gzexe -%patch3 -p1 -%patch4 -p1 -%patch5 -p1 +%patch 1 -p1 + cp %{SOURCE1} . autoreconf @@ -57,13 +50,23 @@ export CPPFLAGS="-DHAVE_LSTAT" export CC="%{__cc}" export CPP="%{__cpp}" export CXX="%{__cxx}" +%ifarch s390x + +#When the otpimizations are enabled, the huft test fails as of F44/gzip1.14 +#export CFLAGS="$RPM_OPT_FLAGS -Dalignas=_Alignas -DDFLTCC_LEVEL_MASK=0x7e" +#use this in the next realease after gzip 1.13 export CFLAGS="$RPM_OPT_FLAGS -DDFLTCC_LEVEL_MASK=0x7e" +#%configure --enable-dfltcc + %configure +%else +%configure +%endif make +%check make check #make gzip.info %install -rm -rf ${RPM_BUILD_ROOT} %makeinstall gzip -9nf ${RPM_BUILD_ROOT}%{_infodir}/gzip.info* @@ -71,7 +74,7 @@ gzip -9nf ${RPM_BUILD_ROOT}%{_infodir}/gzip.info* # we don't ship it, so let's remove it from ${RPM_BUILD_ROOT} rm -f ${RPM_BUILD_ROOT}%{_infodir}/dir # uncompress is a part of ncompress package -rm -f ${RPM_BUILD_ROOT}/%{_bindir}/uncompress +rm -f ${RPM_BUILD_ROOT}%{_bindir}/uncompress # coloured z*grep (#1034839) %global profiledir %{_sysconfdir}/profile.d @@ -81,7 +84,6 @@ install -p -m 644 %{SOURCE101} %{buildroot}%{profiledir} %files %doc NEWS README AUTHORS ChangeLog THANKS TODO -%{!?_licensedir:%global license %%doc} %license COPYING fdl-1.3.txt %{_bindir}/* %{_mandir}/*/* @@ -89,10 +91,64 @@ install -p -m 644 %{SOURCE101} %{buildroot}%{profiledir} %{profiledir}/* %changelog -* Wed Apr 13 2022 Jakub Martisko - 1.10-5 -- fix an arbitrary-file-write vulnerability in zgrep +* Thu Aug 14 2025 Jakub Martisko - 1.14-1 +- Rebase to gzip 1.14 +- There are some issues when the s390x optimizations are turned on - the hufts test fails +- This will need some further investigation, for the time, I've disabled the optimizations + +* Thu Jul 24 2025 Fedora Release Engineering - 1.13-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Fri Jan 17 2025 Fedora Release Engineering - 1.13-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Thu Jul 18 2024 Fedora Release Engineering - 1.13-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Thu Feb 01 2024 Jakub Martisko - 1.13-1 +- Rebase to gzip 1.13 +- There's a bug on s390x: https://lists.gnu.org/archive/html/bug-gzip/2023-10/msg00000.html +- Revert the s390x build options in the next release +Resolves: rhbz#2232890 + +* Wed Jan 24 2024 Fedora Release Engineering - 1.12-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sat Jan 20 2024 Fedora Release Engineering - 1.12-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Wed Aug 02 2023 Jakub Martisko - 1.12-6 +- Enbale the s390x optimizations +Resolves: rhbz#2175699 + +* Thu Jul 20 2023 Fedora Release Engineering - 1.12-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu Apr 13 2023 Lukáš Zaoral - 1.12-4 +- migrate to SPDX license format + +* Thu Jan 19 2023 Fedora Release Engineering - 1.12-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Thu Jul 21 2022 Fedora Release Engineering - 1.12-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Mon Apr 11 2022 Jakub Martisko - 1.12-1 +- Rebase to gzip 1.12 +Resolves: rhbz#2073133 Resolves: CVE-2022-1271 +* Thu Jan 20 2022 Fedora Release Engineering - 1.11-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Thu Oct 21 2021 Jakub Martisko - 1.11-1 +- Rebase to gzip 1.11 +- Run the tests in the check section instead of the build section +Resolve: rhbz#2001025 + +* Thu Jul 22 2021 Fedora Release Engineering - 1.10-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + * Tue Jan 26 2021 Fedora Release Engineering - 1.10-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild diff --git a/plans/all.fmf b/plans/all.fmf new file mode 100644 index 0000000..d5b1643 --- /dev/null +++ b/plans/all.fmf @@ -0,0 +1,6 @@ +summary: Basic smoke test +discover: + how: fmf + url: https://src.fedoraproject.org/tests/gzip.git +execute: + how: tmt diff --git a/s390_errno.patch b/s390_errno.patch new file mode 100644 index 0000000..73ba47f --- /dev/null +++ b/s390_errno.patch @@ -0,0 +1,26 @@ +From c76affb4551630ff661ac1c1ee99353a17eb16e1 Mon Sep 17 00:00:00 2001 +From: Paul Eggert +Date: Fri, 30 May 2025 12:31:04 -0700 +Subject: gzip: fix s390x build failure + +Problem reported by Jakub Martisko . +* dfltcc.c: Include errno.h. +--- + dfltcc.c | 1 + + 1 file changed, 1 insertion(+) + +diff --git a/dfltcc.c b/dfltcc.c +index 9f86581..8307a97 100644 +--- a/dfltcc.c ++++ b/dfltcc.c +@@ -17,6 +17,7 @@ + + #include + ++#include + #include + + #ifdef HAVE_SYS_SDT_H +-- +cgit v1.2.3 + diff --git a/sources b/sources index 3b27769..6561239 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (gzip-1.10.tar.xz) = e6ba9e3906cdb6a6235b213515093d02afa1722686f73eddacbacae628542b586b449829783b6a1701e9b9e0c4d4dfa6845904d3b6b010f5cf21aec4997c9299 +SHA512 (gzip-1.14.tar.xz) = 82aef53188b3e69b51b7ddab5b8c44a11a5b73c0039b22a315a0c7d244694feab0146748add4265901eb1b4c0cee8a9eb69594995f098830d964091af97079c5 diff --git a/tests/.gitignore b/tests/.gitignore deleted file mode 100644 index 8793994..0000000 --- a/tests/.gitignore +++ /dev/null @@ -1,2 +0,0 @@ -*.swp -*.retry diff --git a/tests/test-simple b/tests/test-simple deleted file mode 100644 index 278d622..0000000 --- a/tests/test-simple +++ /dev/null @@ -1,11 +0,0 @@ -#!/bin/sh -set -ex - -# exercise installed gzip/gunzip programs -echo "Bla" > bla.file -cp bla.file bla.file.orig -gzip bla.file -gunzip bla.file.gz -cmp bla.file bla.file.orig -echo "hi" -rm bla.file bla.file.orig diff --git a/tests/test_simple.yml b/tests/test_simple.yml deleted file mode 100644 index 37fdd70..0000000 --- a/tests/test_simple.yml +++ /dev/null @@ -1,32 +0,0 @@ ---- -- hosts: localhost - vars: - - artifacts: ./artifacts - tags: - - atomic - - classic - - container - remote_user: root - tasks: - - name: Create the folder where we will store the tests - action: file state=directory path={{ item }} - owner=root group=root - with_items: - - /usr/local/bin - - - name: Install the test files - copy: src={{ item.file }} dest=/usr/local/bin/{{ item.dest }} - mode=0755 - with_items: - - {file: test-simple, dest: test-simple } - - - block: - - name: Execute the tests - shell: exec > /tmp/test.log && /usr/local/bin/test-simple 2>&1 - - - always: - - name: Pull out the logs - fetch: - dest: "{{ artifacts }}/" - src: "/tmp/test.log" - flat: yes diff --git a/tests/tests.yml b/tests/tests.yml deleted file mode 100644 index 8a6aab3..0000000 --- a/tests/tests.yml +++ /dev/null @@ -1 +0,0 @@ -- include: test_simple.yml