From 59890c154b24a1b5135d7f3ef1115ddc52784ecf Mon Sep 17 00:00:00 2001 From: Kamil Dudka Date: Fri, 31 Mar 2017 12:09:39 +0200 Subject: [PATCH 1/6] new upstream release - 2.8.0 --- ...timens-if-available-instead-of-utime.patch | 50 ++++--------------- nano-2.7.5.tar.gz.asc | 11 ---- nano-2.8.0.tar.gz.asc | 11 ++++ nano.spec | 15 +++--- sources | 2 +- 5 files changed, 30 insertions(+), 59 deletions(-) delete mode 100644 nano-2.7.5.tar.gz.asc create mode 100644 nano-2.8.0.tar.gz.asc diff --git a/0002-use-futimens-if-available-instead-of-utime.patch b/0002-use-futimens-if-available-instead-of-utime.patch index 91df017..c528c07 100644 --- a/0002-use-futimens-if-available-instead-of-utime.patch +++ b/0002-use-futimens-if-available-instead-of-utime.patch @@ -4,57 +4,27 @@ Date: Thu, 19 Aug 2010 15:23:06 +0200 Subject: [PATCH 2/2] use futimens() if available, instead of utime() --- - config.h.in | 3 +++ - configure | 2 +- - configure.ac | 2 +- - src/files.c | 46 +++++++++++++++++++++++++++++++++++----------- - 4 files changed, 40 insertions(+), 13 deletions(-) + configure.ac | 1 + + src/files.c | 46 +++++++++++++++++++++++++++++++++++----------- + 2 files changed, 36 insertions(+), 11 deletions(-) -diff --git a/config.h.in b/config.h.in -index 52e13f1..cb17b29 100644 ---- a/config.h.in -+++ b/config.h.in -@@ -72,6 +72,9 @@ - /* Define to 1 if you don't have `vprintf' but do have `_doprnt.' */ - #undef HAVE_DOPRNT - -+/* Define to 1 if you have the `futimens' function. */ -+#undef HAVE_FUTIMENS -+ - /* Define to 1 if you have the `getdelim' function. */ - #undef HAVE_GETDELIM - -diff --git a/configure b/configure -index 02733c7..1805e53 100755 ---- a/configure -+++ b/configure -@@ -7776,7 +7776,7 @@ fi - - - --for ac_func in getdelim getline isblank strcasecmp strcasestr strncasecmp strnlen snprintf vsnprintf -+for ac_func in futimens getdelim getline isblank strcasecmp strcasestr strncasecmp strnlen snprintf vsnprintf - do : - as_ac_var=`$as_echo "ac_cv_func_$ac_func" | $as_tr_sh` - ac_fn_c_check_func "$LINENO" "$ac_func" "$as_ac_var" diff --git a/configure.ac b/configure.ac index 66f8ee3..f4975d3 100644 --- a/configure.ac +++ b/configure.ac -@@ -442,7 +442,7 @@ int main(void) +@@ -468,6 +468,7 @@ int main(void) + dnl Checks for functions. - --AC_CHECK_FUNCS(getdelim getline isblank strcasecmp strcasestr strncasecmp strnlen snprintf vsnprintf) -+AC_CHECK_FUNCS(futimens getdelim getline isblank strcasecmp strcasestr strncasecmp strnlen snprintf vsnprintf) ++AC_CHECK_FUNCS(futimens) if test "x$enable_utf8" != xno; then - AC_CHECK_FUNCS(iswalnum iswblank iswpunct iswspace nl_langinfo mblen mbstowcs mbtowc wctomb wcwidth) + AC_CHECK_FUNCS(iswalnum iswpunct mblen mbstowcs mbtowc wctomb) diff --git a/src/files.c b/src/files.c index 99cc1b8..9a1bdcc 100644 --- a/src/files.c +++ b/src/files.c -@@ -1696,6 +1696,29 @@ int copy_file(FILE *inn, FILE *out) +@@ -1570,6 +1570,29 @@ int copy_file(FILE *inn, FILE *out) return retval; } @@ -84,7 +54,7 @@ index 99cc1b8..9a1bdcc 100644 /* Write a file out to disk. If f_open isn't NULL, we assume that it is * a stream associated with the file, and we don't try to open it * ourselves. If tmp is TRUE, we set the umask to disallow anyone else -@@ -1917,17 +1940,9 @@ bool write_file(const char *name, FILE *f_open, bool tmp, +@@ -1789,17 +1812,9 @@ bool write_file(const char *name, FILE *f_open, bool tmp, fprintf(stderr, "Backing up %s to %s\n", realname, backupname); #endif @@ -105,7 +75,7 @@ index 99cc1b8..9a1bdcc 100644 if (prompt_failed_backupwrite(backupname)) goto skip_backup; statusline(HUSH, _("Error writing backup file %s: %s"), -@@ -1939,6 +1954,15 @@ bool write_file(const char *name, FILE *f_open, bool tmp, +@@ -1811,6 +1826,15 @@ bool write_file(const char *name, FILE *f_open, bool tmp, goto cleanup_and_exit; } diff --git a/nano-2.7.5.tar.gz.asc b/nano-2.7.5.tar.gz.asc deleted file mode 100644 index 8107640..0000000 --- a/nano-2.7.5.tar.gz.asc +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAliuvfwACgkQnfSGKvEX -XFsMkwgAl4JYw3aVvqClkV50hM9S3hTgYXFisnlBcOPax963k7zUjEip5zFmOIcD -ctm9CMDXp35kYmwhS5yYkNcgtoRcOwGpWNltrUhJgXU+k1W1aErA4odmuBqdoufS -r0b2knVRpPaaSjF+aPNqJRPMZrXdelN0QsVJS5WNkz9WgV6WIRcw0M5U+vjSypov -zG/FujMFukiCtCcEuQ+5V+ZNyjHH9BshcCRZCpYVRoKIx6zPTYUSPCZGfiMigoIh -gROCll8A+/s6V3E950LFxMtCgQbwZvHTL8eZ6TaYiKgYHNmgzYqys5uPDByD2zY2 -xo+X27r5HVX+Z8lr3V8fvOCMXjVq+w== -=NMSG ------END PGP SIGNATURE----- diff --git a/nano-2.8.0.tar.gz.asc b/nano-2.8.0.tar.gz.asc new file mode 100644 index 0000000..c62abaa --- /dev/null +++ b/nano-2.8.0.tar.gz.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAljeHL8ACgkQnfSGKvEX +XFvzkwf/YbAe+RfETWd7nZlw+c9CqntPLqcc1mVnCOO9ng3a7wAyCfzuHtgg0m63 +vYufpYxi/AyFwTjv8GyPnqcVGdwqXiY06kKsPSh+3vP8ChIujYoAfrTXZoX4qGhP +68xX0ZxioR6NOUZ+Nwxa2n4VJO6q+P0fJKe2NoiX+tLRgErpZl/NPVdL+ekKWaau +iJ3snxkMNrm0cC6KnZn6eYr+mSaLY85StoCFX5l9dhkm+RtZfYx8RuFF69oSItW5 +Q7PcSxtDj0/e+0ZhkM6gdbTEY7SAqdmAgs6vIt2CQZ16l8FAfRFd+r7rWsnKJFyU +OW8RlvHHNkbxeSrlLEmM4bspZ3zj5A== +=ZCcd +-----END PGP SIGNATURE----- diff --git a/nano.spec b/nano.spec index 36ae8d5..f25ef94 100644 --- a/nano.spec +++ b/nano.spec @@ -1,15 +1,16 @@ Summary: A small text editor Name: nano -Version: 2.7.5 +Version: 2.8.0 Release: 1%{?dist} License: GPLv3+ URL: https://www.nano-editor.org -Source: https://www.nano-editor.org/dist/v2.7/%{name}-%{version}.tar.gz +Source: https://www.nano-editor.org/dist/v2.8/%{name}-%{version}.tar.gz Source2: nanorc # http://lists.gnu.org/archive/html/nano-devel/2010-08/msg00005.html Patch2: 0002-use-futimens-if-available-instead-of-utime.patch +BuildRequires: automake BuildRequires: file-devel BuildRequires: gettext-devel BuildRequires: git @@ -26,15 +27,12 @@ GNU nano is a small and friendly text editor. %prep %autosetup -S git - -# do not run autotools, we have already reflected the configure.ac -# changes in configure and config.h.in -touch -c aclocal.m4 config.h.in configure Makefile.in +autoreconf -v %build mkdir build cd build -ln -s ../configure +%global _configure ../configure %configure make %{?_smp_mflags} @@ -85,6 +83,9 @@ exit 0 %{_datadir}/nano %changelog +* Tue Apr 04 2017 Kamil Dudka - 2.8.0-1 +- new upstream release + * Thu Feb 23 2017 Kamil Dudka - 2.7.5-1 - new upstream release diff --git a/sources b/sources index 31c7ad4..7cefc42 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (nano-2.7.5.tar.gz) = a5332a361c4d0d9d0a77ebb11cdcffa976bee4981d5665b2732a9e6d7a2997566d9345332f2e6e5cb74f0a81be4413f54ca8f719962ab10b32d7ec1c9271973c +SHA512 (nano-2.8.0.tar.gz) = 75631ddddf960aadfffb3d5df235e7b47118ee3050118927677a94036a87f9d7dfee9f0a75bd5dc6813c12e4edd51d7836c9173057d5caebf55ba9cfaafc6159 From 6f88c58042dbd43fa1a6e3f753e2ed91799e035b Mon Sep 17 00:00:00 2001 From: Kamil Dudka Date: Tue, 4 Apr 2017 12:33:06 +0200 Subject: [PATCH 2/6] use upstream patch to prevent symlink attack ... while creating a backup --- 0001-nano-2.8.0-backup-futimens.patch | 126 ++++++++++++++++++ ...timens-if-available-instead-of-utime.patch | 96 ------------- nano.spec | 7 +- 3 files changed, 129 insertions(+), 100 deletions(-) create mode 100644 0001-nano-2.8.0-backup-futimens.patch delete mode 100644 0002-use-futimens-if-available-instead-of-utime.patch diff --git a/0001-nano-2.8.0-backup-futimens.patch b/0001-nano-2.8.0-backup-futimens.patch new file mode 100644 index 0000000..1716850 --- /dev/null +++ b/0001-nano-2.8.0-backup-futimens.patch @@ -0,0 +1,126 @@ +From 48bc217a9e0cc5c6ad494cff925185912740dbb4 Mon Sep 17 00:00:00 2001 +From: Kamil Dudka +Date: Tue, 4 Apr 2017 09:29:31 +0200 +Subject: [PATCH] backup: prevent a symlink attack by operating on the file + descriptor + +Use futimens() instead of utime() to change the timestamps on a backup +file. Otherwise, a non-privileged user could create an arbitrary symlink +with the name of the backup file and in this way fool a privileged user +to call utime() on the attacker-chosen file. + +Upstream-commit: 70bcf752dcc82d1eed04ba4f900ed69ce2b97500 +Signed-off-by: Kamil Dudka +--- + src/files.c | 24 ++++++++++++++---------- + src/proto.h | 2 +- + 2 files changed, 15 insertions(+), 11 deletions(-) + +diff --git a/src/files.c b/src/files.c +index 033b963..df2627c 100644 +--- a/src/files.c ++++ b/src/files.c +@@ -1541,12 +1541,14 @@ void init_backup_dir(void) + + /* Read from inn, write to out. We assume inn is opened for reading, + * and out for writing. We return 0 on success, -1 on read error, or -2 +- * on write error. */ +-int copy_file(FILE *inn, FILE *out) ++ * on write error. inn is always closed by this function, out is closed ++ * only if close_out is true. */ ++int copy_file(FILE *inn, FILE *out, bool close_out) + { + int retval = 0; + char buf[BUFSIZ]; + size_t charsread; ++ int (*flush_out_fnc)(FILE *) = (close_out) ? fclose : fflush; + + assert(inn != NULL && out != NULL && inn != out); + +@@ -1564,7 +1566,7 @@ int copy_file(FILE *inn, FILE *out) + + if (fclose(inn) == EOF) + retval = -1; +- if (fclose(out) == EOF) ++ if (flush_out_fnc(out) == EOF) + retval = -2; + + return retval; +@@ -1655,13 +1657,13 @@ bool write_file(const char *name, FILE *f_open, bool tmp, + int backup_fd; + FILE *backup_file; + char *backupname; +- struct utimbuf filetime; ++ static struct timespec filetime[2]; + int copy_status; + int backup_cflags; + + /* Save the original file's access and modification times. */ +- filetime.actime = openfile->current_stat->st_atime; +- filetime.modtime = openfile->current_stat->st_mtime; ++ filetime[0].tv_sec = openfile->current_stat->st_atime; ++ filetime[1].tv_sec = openfile->current_stat->st_mtime; + + if (f_open == NULL) { + /* Open the original file to copy to the backup. */ +@@ -1790,7 +1792,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, + #endif + + /* Copy the file. */ +- copy_status = copy_file(f, backup_file); ++ copy_status = copy_file(f, backup_file, FALSE); + + if (copy_status != 0) { + statusline(ALERT, _("Error reading %s: %s"), realname, +@@ -1799,7 +1801,8 @@ bool write_file(const char *name, FILE *f_open, bool tmp, + } + + /* And set its metadata. */ +- if (utime(backupname, &filetime) == -1 && !ISSET(INSECURE_BACKUP)) { ++ if (futimens(backup_fd, filetime) == -1 && !ISSET(INSECURE_BACKUP)) { ++ fclose(backup_file); + if (prompt_failed_backupwrite(backupname)) + goto skip_backup; + statusline(HUSH, _("Error writing backup file %s: %s"), +@@ -1811,6 +1814,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, + goto cleanup_and_exit; + } + ++ fclose(backup_file); + free(backupname); + } + +@@ -1867,7 +1871,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, + } + } + +- if (f_source == NULL || copy_file(f_source, f) != 0) { ++ if (f_source == NULL || copy_file(f_source, f, TRUE) != 0) { + statusline(ALERT, _("Error writing temp file: %s"), + strerror(errno)); + unlink(tempname); +@@ -1975,7 +1979,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, + goto cleanup_and_exit; + } + +- if (copy_file(f_source, f) == -1) { ++ if (copy_file(f_source, f, TRUE) == -1) { + statusline(ALERT, _("Error writing %s: %s"), realname, + strerror(errno)); + goto cleanup_and_exit; +diff --git a/src/proto.h b/src/proto.h +index 0250ad6..d8255a9 100644 +--- a/src/proto.h ++++ b/src/proto.h +@@ -298,7 +298,7 @@ void init_backup_dir(void); + int delete_lockfile(const char *lockfilename); + int write_lockfile(const char *lockfilename, const char *origfilename, bool modified); + #endif +-int copy_file(FILE *inn, FILE *out); ++int copy_file(FILE *inn, FILE *out, bool close_out); + bool write_file(const char *name, FILE *f_open, bool tmp, + kind_of_writing_type method, bool nonamechange); + #ifndef NANO_TINY +-- +2.9.3 + diff --git a/0002-use-futimens-if-available-instead-of-utime.patch b/0002-use-futimens-if-available-instead-of-utime.patch deleted file mode 100644 index c528c07..0000000 --- a/0002-use-futimens-if-available-instead-of-utime.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 23510b930ea31f7de8005e2f0ff6cab7062b4e26 Mon Sep 17 00:00:00 2001 -From: Kamil Dudka -Date: Thu, 19 Aug 2010 15:23:06 +0200 -Subject: [PATCH 2/2] use futimens() if available, instead of utime() - ---- - configure.ac | 1 + - src/files.c | 46 +++++++++++++++++++++++++++++++++++----------- - 2 files changed, 36 insertions(+), 11 deletions(-) - -diff --git a/configure.ac b/configure.ac -index 66f8ee3..f4975d3 100644 ---- a/configure.ac -+++ b/configure.ac -@@ -468,6 +468,7 @@ int main(void) - - - dnl Checks for functions. -+AC_CHECK_FUNCS(futimens) - - if test "x$enable_utf8" != xno; then - AC_CHECK_FUNCS(iswalnum iswpunct mblen mbstowcs mbtowc wctomb) -diff --git a/src/files.c b/src/files.c -index 99cc1b8..9a1bdcc 100644 ---- a/src/files.c -+++ b/src/files.c -@@ -1570,6 +1570,29 @@ int copy_file(FILE *inn, FILE *out) - return retval; - } - -+#ifdef HAVE_FUTIMENS -+/* set atime/mtime by file descriptor */ -+int utime_wrap(int fd, const char *filename, struct utimbuf *ut) -+{ -+ struct timespec times[2]; -+ (void) filename; -+ -+ times[0].tv_sec = ut->actime; -+ times[1].tv_sec = ut->modtime; -+ times[0].tv_nsec = 0L; -+ times[1].tv_nsec = 0L; -+ -+ return futimens(fd, times); -+} -+#else -+/* set atime/mtime by file name */ -+int utime_wrap(int fd, const char *filename, struct utimbuf *ut) -+{ -+ (void) fd; -+ return utime(filename, ut); -+} -+#endif -+ - /* Write a file out to disk. If f_open isn't NULL, we assume that it is - * a stream associated with the file, and we don't try to open it - * ourselves. If tmp is TRUE, we set the umask to disallow anyone else -@@ -1789,17 +1812,9 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - fprintf(stderr, "Backing up %s to %s\n", realname, backupname); - #endif - -- /* Copy the file. */ -- copy_status = copy_file(f, backup_file); -- -- if (copy_status != 0) { -- statusline(ALERT, _("Error reading %s: %s"), realname, -- strerror(errno)); -- goto cleanup_and_exit; -- } -- -- /* And set its metadata. */ -- if (utime(backupname, &filetime) == -1 && !ISSET(INSECURE_BACKUP)) { -+ /* Set backup's file metadata. */ -+ if (utime_wrap(backup_fd, backupname, &filetime) == -1 -+ && !ISSET(INSECURE_BACKUP)) { - if (prompt_failed_backupwrite(backupname)) - goto skip_backup; - statusline(HUSH, _("Error writing backup file %s: %s"), -@@ -1811,6 +1826,15 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - goto cleanup_and_exit; - } - -+ /* Copy the file. */ -+ copy_status = copy_file(f, backup_file); -+ -+ if (copy_status != 0) { -+ statusline(ALERT, _("Error reading %s: %s"), realname, -+ strerror(errno)); -+ goto cleanup_and_exit; -+ } -+ - free(backupname); - } - --- -1.7.4 - diff --git a/nano.spec b/nano.spec index f25ef94..b4970ee 100644 --- a/nano.spec +++ b/nano.spec @@ -7,10 +7,9 @@ URL: https://www.nano-editor.org Source: https://www.nano-editor.org/dist/v2.8/%{name}-%{version}.tar.gz Source2: nanorc -# http://lists.gnu.org/archive/html/nano-devel/2010-08/msg00005.html -Patch2: 0002-use-futimens-if-available-instead-of-utime.patch +# backup: prevent a symlink attack by operating on the file descriptor +Patch1: 0001-nano-2.8.0-backup-futimens.patch -BuildRequires: automake BuildRequires: file-devel BuildRequires: gettext-devel BuildRequires: git @@ -27,7 +26,6 @@ GNU nano is a small and friendly text editor. %prep %autosetup -S git -autoreconf -v %build mkdir build @@ -84,6 +82,7 @@ exit 0 %changelog * Tue Apr 04 2017 Kamil Dudka - 2.8.0-1 +- use upstream patch to prevent symlink attack while creating a backup - new upstream release * Thu Feb 23 2017 Kamil Dudka - 2.7.5-1 From 64f7a852d5428f11eb1335dd583df957967d2a90 Mon Sep 17 00:00:00 2001 From: Kamil Dudka Date: Wed, 12 Apr 2017 22:32:16 +0200 Subject: [PATCH 3/6] new upstream release - 2.8.1 --- 0001-nano-2.8.0-backup-futimens.patch | 126 -------------------------- nano-2.8.0.tar.gz.asc | 11 --- nano-2.8.1.tar.gz.asc | 11 +++ nano.spec | 8 +- sources | 2 +- 5 files changed, 16 insertions(+), 142 deletions(-) delete mode 100644 0001-nano-2.8.0-backup-futimens.patch delete mode 100644 nano-2.8.0.tar.gz.asc create mode 100644 nano-2.8.1.tar.gz.asc diff --git a/0001-nano-2.8.0-backup-futimens.patch b/0001-nano-2.8.0-backup-futimens.patch deleted file mode 100644 index 1716850..0000000 --- a/0001-nano-2.8.0-backup-futimens.patch +++ /dev/null @@ -1,126 +0,0 @@ -From 48bc217a9e0cc5c6ad494cff925185912740dbb4 Mon Sep 17 00:00:00 2001 -From: Kamil Dudka -Date: Tue, 4 Apr 2017 09:29:31 +0200 -Subject: [PATCH] backup: prevent a symlink attack by operating on the file - descriptor - -Use futimens() instead of utime() to change the timestamps on a backup -file. Otherwise, a non-privileged user could create an arbitrary symlink -with the name of the backup file and in this way fool a privileged user -to call utime() on the attacker-chosen file. - -Upstream-commit: 70bcf752dcc82d1eed04ba4f900ed69ce2b97500 -Signed-off-by: Kamil Dudka ---- - src/files.c | 24 ++++++++++++++---------- - src/proto.h | 2 +- - 2 files changed, 15 insertions(+), 11 deletions(-) - -diff --git a/src/files.c b/src/files.c -index 033b963..df2627c 100644 ---- a/src/files.c -+++ b/src/files.c -@@ -1541,12 +1541,14 @@ void init_backup_dir(void) - - /* Read from inn, write to out. We assume inn is opened for reading, - * and out for writing. We return 0 on success, -1 on read error, or -2 -- * on write error. */ --int copy_file(FILE *inn, FILE *out) -+ * on write error. inn is always closed by this function, out is closed -+ * only if close_out is true. */ -+int copy_file(FILE *inn, FILE *out, bool close_out) - { - int retval = 0; - char buf[BUFSIZ]; - size_t charsread; -+ int (*flush_out_fnc)(FILE *) = (close_out) ? fclose : fflush; - - assert(inn != NULL && out != NULL && inn != out); - -@@ -1564,7 +1566,7 @@ int copy_file(FILE *inn, FILE *out) - - if (fclose(inn) == EOF) - retval = -1; -- if (fclose(out) == EOF) -+ if (flush_out_fnc(out) == EOF) - retval = -2; - - return retval; -@@ -1655,13 +1657,13 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - int backup_fd; - FILE *backup_file; - char *backupname; -- struct utimbuf filetime; -+ static struct timespec filetime[2]; - int copy_status; - int backup_cflags; - - /* Save the original file's access and modification times. */ -- filetime.actime = openfile->current_stat->st_atime; -- filetime.modtime = openfile->current_stat->st_mtime; -+ filetime[0].tv_sec = openfile->current_stat->st_atime; -+ filetime[1].tv_sec = openfile->current_stat->st_mtime; - - if (f_open == NULL) { - /* Open the original file to copy to the backup. */ -@@ -1790,7 +1792,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - #endif - - /* Copy the file. */ -- copy_status = copy_file(f, backup_file); -+ copy_status = copy_file(f, backup_file, FALSE); - - if (copy_status != 0) { - statusline(ALERT, _("Error reading %s: %s"), realname, -@@ -1799,7 +1801,8 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - } - - /* And set its metadata. */ -- if (utime(backupname, &filetime) == -1 && !ISSET(INSECURE_BACKUP)) { -+ if (futimens(backup_fd, filetime) == -1 && !ISSET(INSECURE_BACKUP)) { -+ fclose(backup_file); - if (prompt_failed_backupwrite(backupname)) - goto skip_backup; - statusline(HUSH, _("Error writing backup file %s: %s"), -@@ -1811,6 +1814,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - goto cleanup_and_exit; - } - -+ fclose(backup_file); - free(backupname); - } - -@@ -1867,7 +1871,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - } - } - -- if (f_source == NULL || copy_file(f_source, f) != 0) { -+ if (f_source == NULL || copy_file(f_source, f, TRUE) != 0) { - statusline(ALERT, _("Error writing temp file: %s"), - strerror(errno)); - unlink(tempname); -@@ -1975,7 +1979,7 @@ bool write_file(const char *name, FILE *f_open, bool tmp, - goto cleanup_and_exit; - } - -- if (copy_file(f_source, f) == -1) { -+ if (copy_file(f_source, f, TRUE) == -1) { - statusline(ALERT, _("Error writing %s: %s"), realname, - strerror(errno)); - goto cleanup_and_exit; -diff --git a/src/proto.h b/src/proto.h -index 0250ad6..d8255a9 100644 ---- a/src/proto.h -+++ b/src/proto.h -@@ -298,7 +298,7 @@ void init_backup_dir(void); - int delete_lockfile(const char *lockfilename); - int write_lockfile(const char *lockfilename, const char *origfilename, bool modified); - #endif --int copy_file(FILE *inn, FILE *out); -+int copy_file(FILE *inn, FILE *out, bool close_out); - bool write_file(const char *name, FILE *f_open, bool tmp, - kind_of_writing_type method, bool nonamechange); - #ifndef NANO_TINY --- -2.9.3 - diff --git a/nano-2.8.0.tar.gz.asc b/nano-2.8.0.tar.gz.asc deleted file mode 100644 index c62abaa..0000000 --- a/nano-2.8.0.tar.gz.asc +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAljeHL8ACgkQnfSGKvEX -XFvzkwf/YbAe+RfETWd7nZlw+c9CqntPLqcc1mVnCOO9ng3a7wAyCfzuHtgg0m63 -vYufpYxi/AyFwTjv8GyPnqcVGdwqXiY06kKsPSh+3vP8ChIujYoAfrTXZoX4qGhP -68xX0ZxioR6NOUZ+Nwxa2n4VJO6q+P0fJKe2NoiX+tLRgErpZl/NPVdL+ekKWaau -iJ3snxkMNrm0cC6KnZn6eYr+mSaLY85StoCFX5l9dhkm+RtZfYx8RuFF69oSItW5 -Q7PcSxtDj0/e+0ZhkM6gdbTEY7SAqdmAgs6vIt2CQZ16l8FAfRFd+r7rWsnKJFyU -OW8RlvHHNkbxeSrlLEmM4bspZ3zj5A== -=ZCcd ------END PGP SIGNATURE----- diff --git a/nano-2.8.1.tar.gz.asc b/nano-2.8.1.tar.gz.asc new file mode 100644 index 0000000..d1c8eb8 --- /dev/null +++ b/nano-2.8.1.tar.gz.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAljt49YACgkQnfSGKvEX +XFtKQggAgERS3BJ5achC9Q7oj9TGbTwparikEjUQ55A6lZBJKeaTciyj6kqJLHgT +j004eE0r6NFnQe5S5TB8UsjRRMg2ruoLoYOjotMOChEwAi3MQioqVeKI0+opqMm6 +XikBNe2tqZCc9Rsy/DHpr/dBSk8vxuKSxsFhoUNdceWaqhxVm1FjzuRfGU721wc5 +vxIWqD6gsJaJBsNm2tB7zYKftOWz02DVvrDejYU5l4/EELoQkd1jdrZIQlGj+NNn +qLiRdSYNQBuPJrEg+RMK97d2VXh+avrCXIlq5phni3uQwaAm4XpBqO3BcwH/1wM6 +3fWpoGCYaGhP8ci8tuT5gPGE7OgddA== +=kG90 +-----END PGP SIGNATURE----- diff --git a/nano.spec b/nano.spec index b4970ee..71c50df 100644 --- a/nano.spec +++ b/nano.spec @@ -1,15 +1,12 @@ Summary: A small text editor Name: nano -Version: 2.8.0 +Version: 2.8.1 Release: 1%{?dist} License: GPLv3+ URL: https://www.nano-editor.org Source: https://www.nano-editor.org/dist/v2.8/%{name}-%{version}.tar.gz Source2: nanorc -# backup: prevent a symlink attack by operating on the file descriptor -Patch1: 0001-nano-2.8.0-backup-futimens.patch - BuildRequires: file-devel BuildRequires: gettext-devel BuildRequires: git @@ -81,6 +78,9 @@ exit 0 %{_datadir}/nano %changelog +* Wed Apr 12 2017 Kamil Dudka - 2.8.1-1 +- new upstream release + * Tue Apr 04 2017 Kamil Dudka - 2.8.0-1 - use upstream patch to prevent symlink attack while creating a backup - new upstream release diff --git a/sources b/sources index 7cefc42..0989026 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (nano-2.8.0.tar.gz) = 75631ddddf960aadfffb3d5df235e7b47118ee3050118927677a94036a87f9d7dfee9f0a75bd5dc6813c12e4edd51d7836c9173057d5caebf55ba9cfaafc6159 +SHA512 (nano-2.8.1.tar.gz) = 00184c311973f99364daa1102cc3e8d8c95ef5e77532f7514dba977685beb86a40b5f81cd6e931b7f9b2af868dc0c4677b23f3f11f6a1b78cedabeb249667dae From f4e34be9ae9b7dfca32bedfe732fee5c685b6611 Mon Sep 17 00:00:00 2001 From: Kamil Dudka Date: Thu, 4 May 2017 12:29:50 +0200 Subject: [PATCH 4/6] new upstream release - 2.8.2 --- nano-2.8.1.tar.gz.asc | 11 ----------- nano-2.8.2.tar.gz.asc | 11 +++++++++++ nano.spec | 5 ++++- sources | 2 +- 4 files changed, 16 insertions(+), 13 deletions(-) delete mode 100644 nano-2.8.1.tar.gz.asc create mode 100644 nano-2.8.2.tar.gz.asc diff --git a/nano-2.8.1.tar.gz.asc b/nano-2.8.1.tar.gz.asc deleted file mode 100644 index d1c8eb8..0000000 --- a/nano-2.8.1.tar.gz.asc +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAljt49YACgkQnfSGKvEX -XFtKQggAgERS3BJ5achC9Q7oj9TGbTwparikEjUQ55A6lZBJKeaTciyj6kqJLHgT -j004eE0r6NFnQe5S5TB8UsjRRMg2ruoLoYOjotMOChEwAi3MQioqVeKI0+opqMm6 -XikBNe2tqZCc9Rsy/DHpr/dBSk8vxuKSxsFhoUNdceWaqhxVm1FjzuRfGU721wc5 -vxIWqD6gsJaJBsNm2tB7zYKftOWz02DVvrDejYU5l4/EELoQkd1jdrZIQlGj+NNn -qLiRdSYNQBuPJrEg+RMK97d2VXh+avrCXIlq5phni3uQwaAm4XpBqO3BcwH/1wM6 -3fWpoGCYaGhP8ci8tuT5gPGE7OgddA== -=kG90 ------END PGP SIGNATURE----- diff --git a/nano-2.8.2.tar.gz.asc b/nano-2.8.2.tar.gz.asc new file mode 100644 index 0000000..79d1547 --- /dev/null +++ b/nano-2.8.2.tar.gz.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAlkK8y4ACgkQnfSGKvEX +XFvpJQf+PinlEztIOa/TuHdX92Qwu78FfsVmFeXfKq1LIT+7lY/OeSrWypCqwBOH +uJkzowV3SiYIqGmha4/ZzAnmrnf12myoGICp2gXUnwO3dUy1XnhRpnaS7py00frC +gYATv1qVBGAdZul5m3dHCjNxCmZA051z3Ie/SZzDlj8CAqVfwXNHVcGght++07TN +Xu4vavDX7IyUz3qfPgEcTqXKyAqjwhlYwUw5I3FTrDXkHkfbYLvPpim/ubQcyJGd +CgGNCy2pt1JFIBb4GZ/BRro2AXoIqFmadqLqjKC/MlsiAKS0S7kIxZbCAAJ3UPE/ +Ig9rStPSTSHZWy37U2NRFFgwMToy9w== +=Bq5v +-----END PGP SIGNATURE----- diff --git a/nano.spec b/nano.spec index 71c50df..766ae74 100644 --- a/nano.spec +++ b/nano.spec @@ -1,6 +1,6 @@ Summary: A small text editor Name: nano -Version: 2.8.1 +Version: 2.8.2 Release: 1%{?dist} License: GPLv3+ URL: https://www.nano-editor.org @@ -78,6 +78,9 @@ exit 0 %{_datadir}/nano %changelog +* Thu May 04 2017 Kamil Dudka - 2.8.2-1 +- new upstream release + * Wed Apr 12 2017 Kamil Dudka - 2.8.1-1 - new upstream release diff --git a/sources b/sources index 0989026..7be546f 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (nano-2.8.1.tar.gz) = 00184c311973f99364daa1102cc3e8d8c95ef5e77532f7514dba977685beb86a40b5f81cd6e931b7f9b2af868dc0c4677b23f3f11f6a1b78cedabeb249667dae +SHA512 (nano-2.8.2.tar.gz) = 7f4626de4bf8c2250e494c6682743ad599632023a839acff66685ac045a88789061c0a6fc70eba7c3c57f960e633acf425b033d1cc5fbfa644b422515b810f75 From 235537f9b734c83cf8e0df6454aa4caeb39550f9 Mon Sep 17 00:00:00 2001 From: Kamil Dudka Date: Thu, 18 May 2017 17:06:16 +0200 Subject: [PATCH 5/6] new upstream release - 2.8.3 --- nano-2.8.2.tar.gz.asc | 11 ----------- nano-2.8.3.tar.gz.asc | 11 +++++++++++ nano.spec | 5 ++++- sources | 2 +- 4 files changed, 16 insertions(+), 13 deletions(-) delete mode 100644 nano-2.8.2.tar.gz.asc create mode 100644 nano-2.8.3.tar.gz.asc diff --git a/nano-2.8.2.tar.gz.asc b/nano-2.8.2.tar.gz.asc deleted file mode 100644 index 79d1547..0000000 --- a/nano-2.8.2.tar.gz.asc +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAlkK8y4ACgkQnfSGKvEX -XFvpJQf+PinlEztIOa/TuHdX92Qwu78FfsVmFeXfKq1LIT+7lY/OeSrWypCqwBOH -uJkzowV3SiYIqGmha4/ZzAnmrnf12myoGICp2gXUnwO3dUy1XnhRpnaS7py00frC -gYATv1qVBGAdZul5m3dHCjNxCmZA051z3Ie/SZzDlj8CAqVfwXNHVcGght++07TN -Xu4vavDX7IyUz3qfPgEcTqXKyAqjwhlYwUw5I3FTrDXkHkfbYLvPpim/ubQcyJGd -CgGNCy2pt1JFIBb4GZ/BRro2AXoIqFmadqLqjKC/MlsiAKS0S7kIxZbCAAJ3UPE/ -Ig9rStPSTSHZWy37U2NRFFgwMToy9w== -=Bq5v ------END PGP SIGNATURE----- diff --git a/nano-2.8.3.tar.gz.asc b/nano-2.8.3.tar.gz.asc new file mode 100644 index 0000000..b3ea2ae --- /dev/null +++ b/nano-2.8.3.tar.gz.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAlkdk5kACgkQnfSGKvEX +XFuKPAgAh/X9LVLJV3aWgYDFusJINm1YOz3kz7wuEFV4AnzwmQULfzgCV4CiBLNd +RLuRSez64gaYMhD/ZSDDrrjhc5SBqNIcJUpdQKoxzwb7WGR3wLr8+Rh8bzZHzDz0 +pTIEoOdzuMRausPG0NxxeRuFxEzeHAw0Wvbfz1uP1Ltg6P+djUxLZH2BjwFvgzh9 +BTOvuctPuKj1oDo5vuFyuf5n+4kxgeJk9TA/C9EADEdb6VBOs7EVXOpj8hcyBvH7 +/ln3uCqFw9wvEJG/PW94nii9CCPgSk4B+vEMzt1vabRxh3V4/nCO2cd9B2FsQq0/ +FiYU4ZvNMHGLesAGZ2QhWlgVynCS1w== +=eYqL +-----END PGP SIGNATURE----- diff --git a/nano.spec b/nano.spec index 766ae74..72b6caf 100644 --- a/nano.spec +++ b/nano.spec @@ -1,6 +1,6 @@ Summary: A small text editor Name: nano -Version: 2.8.2 +Version: 2.8.3 Release: 1%{?dist} License: GPLv3+ URL: https://www.nano-editor.org @@ -78,6 +78,9 @@ exit 0 %{_datadir}/nano %changelog +* Thu May 18 2017 Kamil Dudka - 2.8.3-1 +- new upstream release + * Thu May 04 2017 Kamil Dudka - 2.8.2-1 - new upstream release diff --git a/sources b/sources index 7be546f..bb98e9e 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (nano-2.8.2.tar.gz) = 7f4626de4bf8c2250e494c6682743ad599632023a839acff66685ac045a88789061c0a6fc70eba7c3c57f960e633acf425b033d1cc5fbfa644b422515b810f75 +SHA512 (nano-2.8.3.tar.gz) = ffedd36252bf13d57c9970840bc05b68c2b9211bf222a47a9aa559c078fdd993929c004d9aae3648e3190cbb32eef7ffb7a57de1c02e6e56b230366b9b55d9a1 From acd97ad12bfe9757056a6fb06ffca69476db03a8 Mon Sep 17 00:00:00 2001 From: Kamil Dudka Date: Mon, 22 May 2017 14:05:19 +0200 Subject: [PATCH 6/6] new upstream release - 2.8.4 --- nano-2.8.3.tar.gz.asc | 11 ----------- nano-2.8.4.tar.gz.asc | 11 +++++++++++ nano.spec | 5 ++++- sources | 2 +- 4 files changed, 16 insertions(+), 13 deletions(-) delete mode 100644 nano-2.8.3.tar.gz.asc create mode 100644 nano-2.8.4.tar.gz.asc diff --git a/nano-2.8.3.tar.gz.asc b/nano-2.8.3.tar.gz.asc deleted file mode 100644 index b3ea2ae..0000000 --- a/nano-2.8.3.tar.gz.asc +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAlkdk5kACgkQnfSGKvEX -XFuKPAgAh/X9LVLJV3aWgYDFusJINm1YOz3kz7wuEFV4AnzwmQULfzgCV4CiBLNd -RLuRSez64gaYMhD/ZSDDrrjhc5SBqNIcJUpdQKoxzwb7WGR3wLr8+Rh8bzZHzDz0 -pTIEoOdzuMRausPG0NxxeRuFxEzeHAw0Wvbfz1uP1Ltg6P+djUxLZH2BjwFvgzh9 -BTOvuctPuKj1oDo5vuFyuf5n+4kxgeJk9TA/C9EADEdb6VBOs7EVXOpj8hcyBvH7 -/ln3uCqFw9wvEJG/PW94nii9CCPgSk4B+vEMzt1vabRxh3V4/nCO2cd9B2FsQq0/ -FiYU4ZvNMHGLesAGZ2QhWlgVynCS1w== -=eYqL ------END PGP SIGNATURE----- diff --git a/nano-2.8.4.tar.gz.asc b/nano-2.8.4.tar.gz.asc new file mode 100644 index 0000000..03efa3d --- /dev/null +++ b/nano-2.8.4.tar.gz.asc @@ -0,0 +1,11 @@ +-----BEGIN PGP SIGNATURE----- + +iQEzBAABCAAdFiEEp/amSmfaCe+SeC3XnfSGKvEXXFsFAlkhVs0ACgkQnfSGKvEX +XFsgzggAunFKAJXX/ppHkgVdol9Z2XV9jpI8hb5z+kuRzo1N32eNfepxAnWVq4yo +jUyjmDRMJ4ALkuSutLC3GVfspSFxxwLvOC1IEUPq3RBqniSrJJ2/RxMBDKuFA0QY +3mzzwIi7jQojUTUCOo0m5bJXWwdzdQdgjvxySVnNvXLo/LJBlIO8bKriRNENKCLw +/oa5GxBbxnGrD7uTWBMCG5lvz+NYD4tZrDUayyz8+PD56H947/eXo7kHuZOjA4zY +X7UMtl8ULL8jzn0OGBNChfo2oUpOIcGqX7Jn0QQMC35Y78ZEYqaeOA4CnZaeoYI9 +diiuHyW5szDfuQ99AJ30KcEL23Wq5g== +=OcXk +-----END PGP SIGNATURE----- diff --git a/nano.spec b/nano.spec index 72b6caf..08989ff 100644 --- a/nano.spec +++ b/nano.spec @@ -1,6 +1,6 @@ Summary: A small text editor Name: nano -Version: 2.8.3 +Version: 2.8.4 Release: 1%{?dist} License: GPLv3+ URL: https://www.nano-editor.org @@ -78,6 +78,9 @@ exit 0 %{_datadir}/nano %changelog +* Mon May 22 2017 Kamil Dudka - 2.8.4-1 +- new upstream release + * Thu May 18 2017 Kamil Dudka - 2.8.3-1 - new upstream release diff --git a/sources b/sources index bb98e9e..657bd4b 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (nano-2.8.3.tar.gz) = ffedd36252bf13d57c9970840bc05b68c2b9211bf222a47a9aa559c078fdd993929c004d9aae3648e3190cbb32eef7ffb7a57de1c02e6e56b230366b9b55d9a1 +SHA512 (nano-2.8.4.tar.gz) = bbcaf710fdb5f403812b584a182ee472421d65c076f5fa2d538603c4cda8292485010157a2670e9890fcffc29d7db5c7334334d54d14f4e154b9bc3fe1ee919c