Compare commits
1 commit
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
9be9f6d5d4 |
5 changed files with 109 additions and 192 deletions
4
.gitignore
vendored
4
.gitignore
vendored
|
|
@ -1,2 +1,2 @@
|
|||
/nano-[3-8].*.tar.xz
|
||||
/nano-[3-8].*.tar.xz.asc
|
||||
/nano-[3-7].*.tar.xz
|
||||
/nano-[3-7].*.tar.xz.asc
|
||||
|
|
|
|||
96
nano-7.2-emergency-file-replace-vuln.patch
Normal file
96
nano-7.2-emergency-file-replace-vuln.patch
Normal file
|
|
@ -0,0 +1,96 @@
|
|||
From 5e7a3c2e7e118c7f12d5dfda9f9140f638976aa2 Mon Sep 17 00:00:00 2001
|
||||
From: Benno Schulenberg <bensberg@telfort.nl>
|
||||
Date: Sun, 28 Apr 2024 10:51:52 +0200
|
||||
Subject: files: run `chmod` and `chown` on the descriptor, not on the filename
|
||||
|
||||
This closes a window of opportunity where the emergency file could be
|
||||
replaced by a malicious symlink.
|
||||
|
||||
The issue was reported by `MartinJM` and `InvisibleMeerkat`.
|
||||
|
||||
Problem existed since version 2.2.0, commit 123110c5, when chmodding
|
||||
and chowning of the emergency .save file was added.
|
||||
---
|
||||
src/definitions.h | 2 +-
|
||||
src/files.c | 13 ++++++++++++-
|
||||
src/nano.c | 12 +-----------
|
||||
3 files changed, 14 insertions(+), 13 deletions(-)
|
||||
|
||||
diff --git a/src/definitions.h b/src/definitions.h
|
||||
index af3a793..55d8235 100644
|
||||
--- a/src/definitions.h
|
||||
+++ b/src/definitions.h
|
||||
@@ -288,7 +288,7 @@ typedef enum {
|
||||
} message_type;
|
||||
|
||||
typedef enum {
|
||||
- OVERWRITE, APPEND, PREPEND
|
||||
+ OVERWRITE, APPEND, PREPEND, EMERGENCY
|
||||
} kind_of_writing_type;
|
||||
|
||||
typedef enum {
|
||||
diff --git a/src/files.c b/src/files.c
|
||||
index 57c2001..584b579 100644
|
||||
--- a/src/files.c
|
||||
+++ b/src/files.c
|
||||
@@ -1763,6 +1763,8 @@ bool write_file(const char *name, FILE *thefile, bool normal,
|
||||
#endif
|
||||
char *realname = real_dir_from_tilde(name);
|
||||
/* The filename after tilde expansion. */
|
||||
+ int fd = 0;
|
||||
+ /* The descriptor that is assigned when opening the file. */
|
||||
char *tempname = NULL;
|
||||
/* The name of the temporary file we use when prepending. */
|
||||
linestruct *line = openfile->filetop;
|
||||
@@ -1846,7 +1848,6 @@ bool write_file(const char *name, FILE *thefile, bool normal,
|
||||
* For an emergency file, access is restricted to just the owner. */
|
||||
if (thefile == NULL) {
|
||||
mode_t permissions = (normal ? RW_FOR_ALL : S_IRUSR|S_IWUSR);
|
||||
- int fd;
|
||||
|
||||
#ifndef NANO_TINY
|
||||
block_sigwinch(TRUE);
|
||||
@@ -1972,6 +1973,16 @@ bool write_file(const char *name, FILE *thefile, bool normal,
|
||||
}
|
||||
#endif
|
||||
|
||||
+#if !defined(NANO_TINY) && defined(HAVE_CHMOD) && defined(HAVE_CHOWN)
|
||||
+ /* Change permissions and owner of an emergency save file to the values
|
||||
+ * of the original file, but ignore any failure as we are in a hurry. */
|
||||
+ if (method == EMERGENCY && fd && openfile->statinfo) {
|
||||
+ IGNORE_CALL_RESULT(fchmod(fd, openfile->statinfo->st_mode));
|
||||
+ IGNORE_CALL_RESULT(fchown(fd, openfile->statinfo->st_uid,
|
||||
+ openfile->statinfo->st_gid));
|
||||
+ }
|
||||
+#endif
|
||||
+
|
||||
if (fclose(thefile) != 0) {
|
||||
statusline(ALERT, _("Error writing %s: %s"), realname, strerror(errno));
|
||||
|
||||
diff --git a/src/nano.c b/src/nano.c
|
||||
index 90b4a0b..973054f 100644
|
||||
--- a/src/nano.c
|
||||
+++ b/src/nano.c
|
||||
@@ -337,18 +337,8 @@ void emergency_save(const char *filename)
|
||||
|
||||
if (*targetname == '\0')
|
||||
fprintf(stderr, _("\nToo many .save files\n"));
|
||||
- else if (write_file(targetname, NULL, SPECIAL, OVERWRITE, NONOTES)) {
|
||||
+ else if (write_file(targetname, NULL, SPECIAL, EMERGENCY, NONOTES))
|
||||
fprintf(stderr, _("\nBuffer written to %s\n"), targetname);
|
||||
-#if !defined(NANO_TINY) && defined(HAVE_CHMOD) && defined(HAVE_CHOWN)
|
||||
- /* Try to chmod/chown the saved file to the values of the original file,
|
||||
- * but ignore any failure as we are in a hurry to get out. */
|
||||
- if (openfile->statinfo) {
|
||||
- IGNORE_CALL_RESULT(chmod(targetname, openfile->statinfo->st_mode));
|
||||
- IGNORE_CALL_RESULT(chown(targetname, openfile->statinfo->st_uid,
|
||||
- openfile->statinfo->st_gid));
|
||||
- }
|
||||
-#endif
|
||||
- }
|
||||
|
||||
free(targetname);
|
||||
free(plainname);
|
||||
--
|
||||
cgit v1.1
|
||||
|
||||
|
|
@ -1,140 +0,0 @@
|
|||
From c028b6f1804a8fef398d7642d8ccb7d8f73150fb Mon Sep 17 00:00:00 2001
|
||||
From: Paul Eggert <eggert@cs.ucla.edu>
|
||||
Date: Sun, 23 Nov 2025 00:50:40 -0800
|
||||
Subject: [PATCH] Port to C23 qualifier-generic fns like strchr
|
||||
MIME-Version: 1.0
|
||||
Content-Type: text/plain; charset=UTF-8
|
||||
Content-Transfer-Encoding: 8bit
|
||||
|
||||
This ports Gnulib to strict C23 platforms that reject code
|
||||
like ‘char *q = strchr (P, 'x');’ when P is a pointer to const,
|
||||
because in C23 strchr is a qualifier-generic function so
|
||||
strchr (P, 'x') returns char const *.
|
||||
This patch does not attempt to do the following two things,
|
||||
which might be useful in the future:
|
||||
1. When compiling on non-C23 platforms, check user code for
|
||||
portability to platforms that define qualifier-generic functions.
|
||||
2. Port Gnulib to platforms that have qualifier-generic functions
|
||||
not listed in the C23 standard, e.g., strchrnul. I don’t know
|
||||
of any such platforms.
|
||||
* lib/c++defs.h (_GL_FUNCDECL_SYS_NAME): New macro.
|
||||
* lib/c++defs.h (_GL_FUNCDECL_SYS):
|
||||
* lib/stdlib.in.h (bsearch):
|
||||
Use it, to prevent C23 names like strchr from acting like macros.
|
||||
* lib/string.in.h (memchr, strchr, strpbrk, strrchr):
|
||||
Do not #undef when GNULIB_POSIXCHECK is defined, as this could
|
||||
cause conforming C23 code to fail to conform. It’s not clear why
|
||||
_GL_WARN_ON_USE_CXX; perhaps it was needed but isn’t any more?
|
||||
But for now, limit the removal of #undef to these four functions
|
||||
where #undeffing is clearly undesirable in C23.
|
||||
* lib/wchar.in.h (wmemchr): Parenthesize function name in decl,
|
||||
to prevent it from acting like a macro.
|
||||
|
||||
Cherry-picked-by: Lukáš Zaoral <lzaoral@redhat.com>
|
||||
Upstream-commit: df17f4f37ed3ca373d23ad42eae51122bdb96626
|
||||
---
|
||||
lib/c++defs.h | 12 +++++++++++-
|
||||
lib/stdlib.in.h | 6 +++---
|
||||
lib/string.in.h | 4 ----
|
||||
lib/wchar.in.h | 2 +-
|
||||
4 files changed, 15 insertions(+), 9 deletions(-)
|
||||
|
||||
diff --git a/lib/c++defs.h b/lib/c++defs.h
|
||||
index b77979a..7384457 100644
|
||||
--- a/lib/c++defs.h
|
||||
+++ b/lib/c++defs.h
|
||||
@@ -127,6 +127,16 @@
|
||||
#define _GL_FUNCDECL_RPL_1(rpl_func,rettype,parameters,...) \
|
||||
_GL_EXTERN_C_FUNC __VA_ARGS__ rettype rpl_func parameters
|
||||
|
||||
+/* _GL_FUNCDECL_SYS_NAME (func) expands to plain func if C++, and to
|
||||
+ parenthsized func otherwise. Parenthesization is needed in C23 if
|
||||
+ the function is like strchr and so is a qualifier-generic macro
|
||||
+ that expands to something more complicated. */
|
||||
+#ifdef __cplusplus
|
||||
+# define _GL_FUNCDECL_SYS_NAME(func) func
|
||||
+#else
|
||||
+# define _GL_FUNCDECL_SYS_NAME(func) (func)
|
||||
+#endif
|
||||
+
|
||||
/* _GL_FUNCDECL_SYS (func, rettype, parameters, [attributes]);
|
||||
declares the system function, named func, with the given prototype,
|
||||
consisting of return type, parameters, and attributes.
|
||||
@@ -139,7 +149,7 @@
|
||||
_GL_FUNCDECL_SYS (posix_openpt, int, (int flags), _GL_ATTRIBUTE_NODISCARD);
|
||||
*/
|
||||
#define _GL_FUNCDECL_SYS(func,rettype,parameters,...) \
|
||||
- _GL_EXTERN_C_FUNC __VA_ARGS__ rettype func parameters
|
||||
+ _GL_EXTERN_C_FUNC __VA_ARGS__ rettype _GL_FUNCDECL_SYS_NAME (func) parameters
|
||||
|
||||
/* _GL_CXXALIAS_RPL (func, rettype, parameters);
|
||||
declares a C++ alias called GNULIB_NAMESPACE::func
|
||||
diff --git a/lib/stdlib.in.h b/lib/stdlib.in.h
|
||||
index bef0aaa..fd0e1e0 100644
|
||||
--- a/lib/stdlib.in.h
|
||||
+++ b/lib/stdlib.in.h
|
||||
@@ -224,9 +224,9 @@ _GL_INLINE_HEADER_BEGIN
|
||||
|
||||
/* Declarations for ISO C N3322. */
|
||||
#if defined __GNUC__ && __GNUC__ >= 15 && !defined __clang__
|
||||
-_GL_EXTERN_C void *bsearch (const void *__key,
|
||||
- const void *__base, size_t __nmemb, size_t __size,
|
||||
- int (*__compare) (const void *, const void *))
|
||||
+_GL_EXTERN_C void *_GL_FUNCDECL_SYS_NAME (bsearch)
|
||||
+ (const void *__key, const void *__base, size_t __nmemb, size_t __size,
|
||||
+ int (*__compare) (const void *, const void *))
|
||||
_GL_ATTRIBUTE_NONNULL_IF_NONZERO (2, 3) _GL_ARG_NONNULL ((5));
|
||||
_GL_EXTERN_C void qsort (void *__base, size_t __nmemb, size_t __size,
|
||||
int (*__compare) (const void *, const void *))
|
||||
diff --git a/lib/string.in.h b/lib/string.in.h
|
||||
index fdcdd21..8b56acf 100644
|
||||
--- a/lib/string.in.h
|
||||
+++ b/lib/string.in.h
|
||||
@@ -409,7 +409,6 @@ _GL_CXXALIASWARN1 (memchr, void const *,
|
||||
_GL_CXXALIASWARN (memchr);
|
||||
# endif
|
||||
#elif defined GNULIB_POSIXCHECK
|
||||
-# undef memchr
|
||||
/* Assume memchr is always declared. */
|
||||
_GL_WARN_ON_USE (memchr, "memchr has platform-specific bugs - "
|
||||
"use gnulib module memchr for portability" );
|
||||
@@ -674,7 +673,6 @@ _GL_WARN_ON_USE (stpncpy, "stpncpy is unportable - "
|
||||
#if defined GNULIB_POSIXCHECK
|
||||
/* strchr() does not work with multibyte strings if the locale encoding is
|
||||
GB18030 and the character to be searched is a digit. */
|
||||
-# undef strchr
|
||||
/* Assume strchr is always declared. */
|
||||
_GL_WARN_ON_USE_CXX (strchr,
|
||||
const char *, char *, (const char *, int),
|
||||
@@ -981,7 +979,6 @@ _GL_CXXALIASWARN (strpbrk);
|
||||
Even in this simple case, it does not work with multibyte strings if the
|
||||
locale encoding is GB18030 and one of the characters to be searched is a
|
||||
digit. */
|
||||
-# undef strpbrk
|
||||
_GL_WARN_ON_USE_CXX (strpbrk,
|
||||
const char *, char *, (const char *, const char *),
|
||||
"strpbrk cannot work correctly on character strings "
|
||||
@@ -1011,7 +1008,6 @@ _GL_WARN_ON_USE (strspn, "strspn cannot work correctly on character strings "
|
||||
#if defined GNULIB_POSIXCHECK
|
||||
/* strrchr() does not work with multibyte strings if the locale encoding is
|
||||
GB18030 and the character to be searched is a digit. */
|
||||
-# undef strrchr
|
||||
/* Assume strrchr is always declared. */
|
||||
_GL_WARN_ON_USE_CXX (strrchr,
|
||||
const char *, char *, (const char *, int),
|
||||
diff --git a/lib/wchar.in.h b/lib/wchar.in.h
|
||||
index ab602a2..6be4515 100644
|
||||
--- a/lib/wchar.in.h
|
||||
+++ b/lib/wchar.in.h
|
||||
@@ -301,7 +301,7 @@ _GL_EXTERN_C int wcsncmp (const wchar_t *__s1, const wchar_t *__s2, size_t __n)
|
||||
_GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3)
|
||||
_GL_ATTRIBUTE_NONNULL_IF_NONZERO (2, 3);
|
||||
# ifndef __cplusplus
|
||||
-_GL_EXTERN_C wchar_t *wmemchr (const wchar_t *__s, wchar_t __wc, size_t __n)
|
||||
+_GL_EXTERN_C wchar_t *(wmemchr) (const wchar_t *__s, wchar_t __wc, size_t __n)
|
||||
_GL_ATTRIBUTE_NONNULL_IF_NONZERO (1, 3);
|
||||
# endif
|
||||
_GL_EXTERN_C wchar_t *wmemset (wchar_t *__s, wchar_t __wc, size_t __n)
|
||||
--
|
||||
2.52.0
|
||||
|
||||
57
nano.spec
57
nano.spec
|
|
@ -7,8 +7,8 @@
|
|||
|
||||
Summary: A small text editor
|
||||
Name: nano
|
||||
Version: 8.7
|
||||
Release: 1%{?dist}
|
||||
Version: 7.2
|
||||
Release: 5%{?dist}
|
||||
License: GPL-3.0-or-later
|
||||
URL: https://www.nano-editor.org
|
||||
|
||||
|
|
@ -26,14 +26,12 @@ Source11: nano-default-editor.sh
|
|||
Source12: nano-default-editor.csh
|
||||
Source13: nano-default-editor.fish
|
||||
|
||||
# gnulib C23 support
|
||||
# https://github.com/coreutils/gnulib/commit/df17f4f37ed3ca373d23ad42eae51122bdb96626
|
||||
Patch: nano-8.7-gnulib-c23.patch
|
||||
Patch0: nano-7.2-emergency-file-replace-vuln.patch
|
||||
|
||||
BuildRequires: file-devel
|
||||
BuildRequires: gettext-devel
|
||||
BuildRequires: gcc
|
||||
BuildRequires: git-core
|
||||
BuildRequires: git
|
||||
BuildRequires: gnupg2
|
||||
BuildRequires: groff
|
||||
BuildRequires: make
|
||||
|
|
@ -72,7 +70,7 @@ who don't have nano as a default editor during upgrade.
|
|||
|
||||
%prep
|
||||
%{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}'
|
||||
%autosetup -S git_am
|
||||
%autosetup -S git
|
||||
|
||||
%build
|
||||
mkdir build
|
||||
|
|
@ -84,8 +82,8 @@ cd build
|
|||
# generate default /etc/nanorc
|
||||
# - set hunspell as the default spell-checker
|
||||
# - enable syntax highlighting by default (#1270712)
|
||||
sed -E -e 's/^#.*set speller.*$/set speller "hunspell"/' \
|
||||
-e 's|^# (include "?/usr/share/nano/\*.nanorc"?)|\1|' \
|
||||
sed -e 's/^#.*set speller.*$/set speller "hunspell"/' \
|
||||
-e 's|^# \(include "/usr/share/nano/\*.nanorc"\)|\1|' \
|
||||
%{SOURCE3} doc/sample.nanorc > ./nanorc
|
||||
|
||||
%install
|
||||
|
|
@ -137,45 +135,8 @@ install -Dpm 0644 %{SOURCE13} %{buildroot}%{_datadir}/fish/vendor_conf.d/%{basen
|
|||
|
||||
|
||||
%changelog
|
||||
* Wed Nov 26 2025 Lukáš Zaoral <lzaoral@redhat.com> - 8.7-1
|
||||
- require only git-core which is already sufficient for %%autosetup -S git_am
|
||||
- rebase to latest upstream release (rhbz#2414527)
|
||||
|
||||
* Thu Aug 21 2025 Lukáš Zaoral <lzaoral@redhat.com> - 8.6-1
|
||||
- rebase to the latest upstream release (rhbz#2390027)
|
||||
|
||||
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 8.5-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
|
||||
|
||||
* Thu Jun 12 2025 Lukáš Zaoral <lzaoral@redhat.com> - 8.5-1
|
||||
- rebase to latest upstream release (rhbz#2372436)
|
||||
|
||||
* Mon Apr 07 2025 Lukáš Zaoral <lzaoral@redhat.com> - 8.4-1
|
||||
- rebase to latest upstream release (rhbz#2357699)
|
||||
|
||||
* Thu Mar 20 2025 Lukáš Zaoral <lzaoral@redhat.com> - 8.3-3
|
||||
- fix nano syntax highlighting in default nanorc (rhbz#2353508)
|
||||
|
||||
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 8.3-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
|
||||
|
||||
* Thu Jan 02 2025 Lukáš Zaoral <lzaoral@redhat.com> - 8.3-1
|
||||
- rebase to latest upstream version (rhbz#2333643)
|
||||
|
||||
* Thu Sep 05 2024 Lukáš Zaoral <lzaoral@redhat.com> - 8.2-1
|
||||
- rebase to latest upstream release (rhbz#2310179)
|
||||
|
||||
* Thu Jul 18 2024 Lukáš Zaoral <lzaoral@redhat.com> - 8.1-1
|
||||
- rebase to latest upstream release (rhbz#2297610)
|
||||
|
||||
* Thu May 02 2024 Lukáš Zaoral <lzaoral@redhat.com> - 8.0-1
|
||||
- rebase to latest upstream version (rhbz#2278126)
|
||||
|
||||
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 7.2-6
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 7.2-5
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
* Mon May 06 2024 Lukáš Zaoral <lzaoral@redhat.com> - 7.2-5
|
||||
- fix emergency file replacement vulnerability (rhbz#2277586)
|
||||
|
||||
* Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 7.2-4
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
|
||||
|
|
|
|||
4
sources
4
sources
|
|
@ -1,2 +1,2 @@
|
|||
SHA512 (nano-8.7.tar.xz.asc) = b525ae9bdd69eae326c364ffd76a03592f4012132fdbff061ec804741857f6cb7428ffa4ebb65ab584a3eb1ce310bf9865d4ad2f73b11d2b156b55bd2ade23c1
|
||||
SHA512 (nano-8.7.tar.xz) = 0aac5b1708b05a882cba57f718154e42a6cd8a57f1e1c13c76598fe85645c49703f0c17d2e650da90348eb60c2bdbe349925415b6511c27e5b1bea77d107ab37
|
||||
SHA512 (nano-7.2.tar.xz.asc) = 3ba3921c892ab3121cfe86ff37ab709c592d49524624c132fa32e22129b988ce5c6cac28f6b2fa7f1967ab3799dbc1652695c92ea91c576c378c2a2302b0f7b8
|
||||
SHA512 (nano-7.2.tar.xz) = a6dfa70edab62e439a9a998ca214f2415d57dbdc01766ad2e4b14048836557a32755f8b09de13c6a89023f215b61d2854017b389eae8d097ca6f3ba73ce2f583
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue