diff --git a/.gitignore b/.gitignore index 64f18ef..69c3d86 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -/onig-*.tar.gz +onig-*.tar.gz diff --git a/create-tarball-from-git.sh b/create-tarball-from-git.sh deleted file mode 100644 index e23aadf..0000000 --- a/create-tarball-from-git.sh +++ /dev/null @@ -1,41 +0,0 @@ -#!/bin/sh - -set -e -set -x - -CURRENTDIR=$(pwd) -PKGNAME=oniguruma -TARNAME=onig - -TMPDIR=$(mktemp -d /var/tmp/$PKGNAME-XXXXXX) -pushd $TMPDIR - -GITSCM=https://github.com/kkos/$PKGNAME.git - -git clone $GITSCM -pushd $PKGNAME - -COMMIT=$(git log | head -n 1 | sed -e 's|^.*[ \t]||') -SHORTCOMMIT=$(echo $COMMIT | cut -c-7) -DATE=$(git show --format=%ci $COMMIT | head -n 1 | sed -e 's|[ \t].*$||') -SHORTDATE=$(echo $DATE | sed -e 's|-||g') -VERSION=$(cat configure.ac | grep AC_INIT | sed -n -e 's|^.*,[ \t]*\([0-9\.][0-9\.]*\).*$|\1|p') - -git log --format=fuller | head -n 12 - -echo "VERSION=$VERSION" -echo "COMMIT=$COMMIT" -echo "DATE=$DATE" - -echo -popd - -TARDIR=${TARNAME}-${VERSION}-${SHORTDATE}git${SHORTCOMMIT} -ln -sf $PKGNAME $TARDIR -tar czf ${TARDIR}.tar.gz ${TARDIR}/./ - -mv ${TARDIR}.tar.gz ${CURRENTDIR}/ -popd - -rm -rf $TMPDIR - diff --git a/oniguruma-6.8.2-CVE-2019-13225-fix.patch b/oniguruma-6.8.2-CVE-2019-13225-fix.patch new file mode 100644 index 0000000..ecddbd3 --- /dev/null +++ b/oniguruma-6.8.2-CVE-2019-13225-fix.patch @@ -0,0 +1,57 @@ +diff --git a/src/regcomp.c b/src/regcomp.c +index f953ed1..ae2caeb 100644 +--- a/src/regcomp.c ++++ b/src/regcomp.c +@@ -1131,8 +1131,9 @@ compile_length_enclosure_node(EnclosureNode* node, regex_t* reg) + len += tlen; + } + ++ len += SIZE_OP_JUMP + SIZE_OP_ATOMIC_END; ++ + if (IS_NOT_NULL(Else)) { +- len += SIZE_OP_JUMP; + tlen = compile_length_tree(Else, reg); + if (tlen < 0) return tlen; + len += tlen; +@@ -1274,7 +1275,7 @@ compile_enclosure_node(EnclosureNode* node, regex_t* reg, ScanEnv* env) + + case ENCLOSURE_IF_ELSE: + { +- int cond_len, then_len, jump_len; ++ int cond_len, then_len, else_len, jump_len; + Node* cond = NODE_ENCLOSURE_BODY(node); + Node* Then = node->te.Then; + Node* Else = node->te.Else; +@@ -1291,8 +1292,7 @@ compile_enclosure_node(EnclosureNode* node, regex_t* reg, ScanEnv* env) + else + then_len = 0; + +- jump_len = cond_len + then_len + SIZE_OP_ATOMIC_END; +- if (IS_NOT_NULL(Else)) jump_len += SIZE_OP_JUMP; ++ jump_len = cond_len + then_len + SIZE_OP_ATOMIC_END + SIZE_OP_JUMP; + + r = add_opcode_rel_addr(reg, OP_PUSH, jump_len); + if (r != 0) return r; +@@ -1307,9 +1307,19 @@ compile_enclosure_node(EnclosureNode* node, regex_t* reg, ScanEnv* env) + } + + if (IS_NOT_NULL(Else)) { +- int else_len = compile_length_tree(Else, reg); +- r = add_opcode_rel_addr(reg, OP_JUMP, else_len); +- if (r != 0) return r; ++ else_len = compile_length_tree(Else, reg); ++ if (else_len < 0) return else_len; ++ } ++ else ++ else_len = 0; ++ ++ r = add_opcode_rel_addr(reg, OP_JUMP, SIZE_OP_ATOMIC_END + else_len); ++ if (r != 0) return r; ++ ++ r = add_opcode(reg, OP_ATOMIC_END); ++ if (r != 0) return r; ++ ++ if (IS_NOT_NULL(Else)) { + r = compile_tree(Else, reg, env); + } + } diff --git a/oniguruma.spec b/oniguruma.spec index 3521ff4..4dabbe9 100644 --- a/oniguruma.spec +++ b/oniguruma.spec @@ -1,45 +1,15 @@ -%undefine _changelog_trimtime - -%global git_snapshot 0 - -%if 0%{?git_snapshot} -%define apply_git_patch git am -%else -%define apply_git_patch patch -p1 -%endif - -%if 0%{?git_snapshot} -%global gitdate 20230501 -%global gitcommit 41a3b802af2155eef6d648aa3608e39605110642 -%global shortcommit %(c=%{gitcommit}; echo ${c:0:7}) - -%global gitversion %{gitdate}git%{shortcommit} -%endif - -%global mainver 6.9.10 -#%%global postver 1 -#%%global betaver rc4 -#%%define prerelease 1 - -%global baserelease 3 - Name: oniguruma -Version: %{mainver}%{?postver:.%postver}%{?gitversion:^%{?gitversion}} -Release: %{?prerelease:0.}%{baserelease}%{?dist} +Version: 6.8.2 +Release: 2%{?dist} Summary: Regular expressions library -# SPDX confirmed -License: BSD-2-Clause +Group: System Environment/Libraries +License: BSD URL: https://github.com/kkos/oniguruma/ -Source0: https://github.com/kkos/oniguruma/releases/download/v%{mainver}%{?betaver:_%betaver}/onig-%{mainver}%{?postver:.%postver}%{?betaver:-%betaver}%{?gitversion:-%{?gitversion}}.tar.gz -Source1: create-tarball-from-git.sh - -BuildRequires: make -BuildRequires: gcc -%if 0%{?git_snapshot} -BuildRequires: automake -BuildRequires: libtool -%endif +Source0: https://github.com/kkos/oniguruma/releases/download/v%{version}/onig-%{version}.tar.gz +# Backport https://src.fedoraproject.org/rpms/oniguruma/blob/f29/f/0100-Apply-CVE-2019-13325-fix-to-6.9.1.patch +# (upstream: https://github.com/kkos/oniguruma/commit/c509265c5f6ae7264f7b8a8aae1cfa5fc59d108c) +Patch0: oniguruma-6.8.2-CVE-2019-13225-fix.patch %description Oniguruma is a regular expressions library. @@ -50,6 +20,7 @@ for every regular expression object can be specified. %package devel Summary: Development files for %{name} +Group: Development/Libraries Requires: %{name}%{?isa} = %{version}-%{release} %description devel @@ -58,35 +29,43 @@ developing applications that use %{name}. %prep -%setup -q -n onig-%{mainver}%{?gitversion:-%{?gitversion}} +%autosetup -p 1 -n onig-%{version} %{__sed} -i.multilib -e 's|-L@libdir@||' onig-config.in -%build -# This package fails its testsuite when compiled with LTO, but the real problem -# is that it ends up mixing and matching regexp bits between itself and glibc. -# Disable LTO -%define _lto_cflags %{nil} - -%if 0%{?git_snapshot} -autoreconf -fi +%if 0 +for f in \ + README.ja \ + doc/API.ja \ + doc/FAQ.ja \ + doc/RE.ja + do + iconv -f EUC-JP -t UTF-8 $f > $f.tmp && \ + ( touch -r $f $f.tmp ; %{__mv} -f $f.tmp $f ) || \ + %{__rm} -f $f.tmp +done %endif +%build %configure \ - --enable-posix-api \ - --enable-binary-compatible-posix-api \ - --disable-silent-rules \ + --disable-silent-rules \ --disable-static \ - --with-rubydir=%{_bindir} \ - %{nil} -%make_build + --with-rubydir=%{_bindir} +%{__make} %{?_smp_mflags} + %install -%make_install +%{__make} install \ + DESTDIR=$RPM_BUILD_ROOT \ + INSTALL="%{__install} -c -p" +find $RPM_BUILD_ROOT -name '*.la' \ + -exec %{__rm} -f {} ';' %check %{__make} check -%ldconfig_scriptlets +%post -p /sbin/ldconfig + +%postun -p /sbin/ldconfig %files @@ -108,8 +87,6 @@ autoreconf -fi %doc doc/CALLOUTS.BUILTIN %doc doc/FAQ %doc doc/RE -%doc doc/SYNTAX.md -%doc doc/UNICODE_PROPERTIES %lang(ja) %doc doc/API.ja %lang(ja) %doc doc/CALLOUTS.API.ja %lang(ja) %doc doc/CALLOUTS.BUILTIN.ja @@ -120,205 +97,14 @@ autoreconf -fi %{_libdir}/libonig.so %{_includedir}/onig*.h -%{_libdir}/pkgconfig/%{name}.pc +%{_libdir}/pkgconfig/%{name}.pc %changelog -* Thu Jul 24 2025 Fedora Release Engineering - 6.9.10-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild +* Tue Jun 14 2022 Carl George - 6.8.2-2 +- Backport fix for CVE-2019-13225 from RHEL8, resolves: rhbz#1728967 -* Fri Jan 17 2025 Fedora Release Engineering - 6.9.10-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Wed Jan 01 2025 Mamoru TASAKA - 6.9.10-1 -- 6.9.10 - -* Mon Nov 18 2024 Mamoru TASAKA - 6.9.9-5 -- Apply upstream patch for C23 compliance - -* Thu Jul 18 2024 Fedora Release Engineering - 6.9.9-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Thu Jan 25 2024 Fedora Release Engineering - 6.9.9-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Sun Jan 21 2024 Fedora Release Engineering - 6.9.9-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Tue Oct 17 2023 Mamoru TASAKA - 6.9.9-1 -- 6.9.9 - -* Thu Jul 20 2023 Fedora Release Engineering - 6.9.8^20230501git41a3b80-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Sat May 6 2023 Mamoru TASAKA - 6.9.8^20230501git41a3b80-1 -- Update to the latest git - -* Thu Jan 19 2023 Fedora Release Engineering - 6.9.8-2.D20220919gitb041f6d.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - -* Fri Sep 23 2022 Mamoru TASAKA - 6.9.8-2.D20220919gitb041f6d -- Update to the latest git, expecially: - - Update to Unicode 15.0 (upstream #272) - - [[:punct:]] behavoir change (upsteam #268) - -* Fri Jul 22 2022 Fedora Release Engineering - 6.9.8-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Sat Apr 30 2022 Mamoru TASAKA - 6.9.8-1 -- 6.9.8 - -* Thu Jan 20 2022 Fedora Release Engineering - 6.9.7.1-1.2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Thu Jul 22 2021 Fedora Release Engineering - 6.9.7.1-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Sat May 1 2021 Mamoru TASAKA - 6.9.7.1-1 -- 6.9.7.1 - -* Tue Jan 26 2021 Fedora Release Engineering - 6.9.6-1.2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - -* Thu Nov 5 2020 Mamoru TASAKA - 6.9.6-1 -- 6.9.6 - -* Wed Oct 21 2020 Mamoru TASAKA - 6.9.6-0.4.rc4 -- 6.9.6 rc4 - -* Tue Oct 20 2020 Mamoru TASAKA - 6.9.6-0.3.rc3 -- Apply upstream patch for upstream bug 221 - - Revert change for false CVE-2020-26159 issue - https://github.com/kkos/oniguruma/issues/221 - -* Sat Oct 17 2020 Mamoru TASAKA - 6.9.6-0.2.rc3 -- 6.9.6 rc3 - -* Mon Oct 12 2020 Mamoru TASAKA - 6.9.6-0.1.rc2 -- 6.9.6 rc2 -- Apply upstream patch to keep binary compatibility with 6.9.5 - -* Thu Oct 1 2020 Mamoru TASAKA - 6.9.5-3.rev1 -- Apply upstream fix for CVE-2020-26159 - -* Tue Jul 28 2020 Fedora Release Engineering - 6.9.5-2.rev1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild - -* Tue Jul 14 2020 Tom Stellard - 6.9.5-2.rev1.1 -- Use make macros -- https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro - -* Wed Jul 1 2020 Jeff Law - 6.9.5-2.rev1 -- Disable LTO - -* Thu May 7 2020 Mamoru TASAKA - 6.9.5-1.rev1 -- 6.9.5 revised 1 - -* Wed Jan 29 2020 Fedora Release Engineering - 6.9.4-1.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild - -* Fri Nov 29 2019 Mamoru TASAKA - 6.9.4-1 -- 6.9.4 final - -* Fri Nov 29 2019 Mamoru TASAKA - 6.9.4-0.2.rc3 -- 6.9.4 rc3 (CVE-2019-19204 CVE-2019-19203 CVE-2019-19012) - -* Sat Nov 9 2019 Mamoru TASAKA - 6.9.4-0.1.rc1 -- 6.9.4 rc1 (CVE-2019-19246) - -* Sun Aug 11 2019 Mamoru TASAKA - 6.9.3-1 -- 6.9.3 (CVE-2019-13224 CVE-2019-13225 CVE-2019-16163) - -* Thu Jul 25 2019 Fedora Release Engineering - 6.9.2-2.1 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild - -* Fri Jul 12 2019 Mamoru TASAKA - 6.9.2-2 -- Upstream patch for CVE-2019-13225 (#1728966) -- NON-upstream patch for CVE-2019-13224 (#1728971) - -* Tue May 7 2019 Mamoru TASAKA - 6.9.2-1 -- rc3 released as 6.9.2 final release - -* Wed Apr 24 2019 Mamoru TASAKA - 6.9.2-0.1.rc3 -- 6.9.2-rc3 - -* Fri Feb 01 2019 Fedora Release Engineering - 6.9.1-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild - -* Wed Dec 12 2018 Mamoru TASAKA - 6.9.1-1 -- 6.9.1 - -* Wed Sep 12 2018 Mamoru TASAKA - 6.9.0-2 -- 6.9.0 - -* Sat Sep 8 2018 Mamoru TASAKA - 6.8.2-3 -- Bump release - -* Fri Jul 13 2018 Fedora Release Engineering - 6.8.2-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild - -* Mon Apr 23 2018 Mamoru TASAKA - 6.8.2-1 -- 6.8.2 - -* Sun Apr 1 2018 Mamoru TASAKA - 6.8.1-1 -- 6.8.1 - -* Fri Feb 9 2018 Mamoru TASAKA - 6.7.1-1 -- 6.7.1 - -* Thu Feb 08 2018 Fedora Release Engineering - 6.7.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild - -* Sun Dec 31 2017 Mamoru TASAKA - 6.7.0-1 -- 6.7.0 - -* Tue Sep 5 2017 Mamoru TASAKA - 6.6.1-1 -- 6.6.1 - -* Sun Aug 13 2017 Mamoru TASAKA - 6.5.0-1 -- 6.5.0 - -* Thu Aug 03 2017 Fedora Release Engineering - 6.4.0-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild - -* Thu Jul 27 2017 Fedora Release Engineering - 6.4.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild - -* Wed Jul 5 2017 Mamoru TASAKA - 6.4.0-1 -- 6.4.0 - -* Tue May 30 2017 Mamoru TASAKA - 6.3.0-1 -- 6.3.0 - - CVEs 2017-9226 CVE-2017-9225 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228 - -* Wed Apr 26 2017 Nils Philippsen - 6.2.0-2 -- remove unnecessary BR: ruby - -* Fri Apr 21 2017 Mamoru TASAKA - 6.2.0-1 -- 6.2.0 - -* Sat Feb 11 2017 Fedora Release Engineering - 6.1.3-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild - -* Wed Dec 28 2016 Mamoru TASAKA - 6.1.3-1 -- 6.1.3 - -* Fri Nov 11 2016 Mamoru TASAKA - 6.1.2-1 -- 6.1.2 - -* Sun Oct 30 2016 Mamoru TASAKA - 6.1.1-1 -- 6.1.1 - -* Mon Jul 11 2016 Mamoru TASAKA - 6.0.0-1 -- 6.0.0 - -* Thu Feb 04 2016 Fedora Release Engineering - 5.9.6-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild - -* Wed Jun 17 2015 Fedora Release Engineering - 5.9.6-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild - -* Fri Jan 2 2015 - 5.9.6-1 -- 5.9.6 +* Tue May 26 2020 Carl George - 6.8.2-1 +- Rebase to 6.8.2 rhbz#1777660 * Sun Aug 17 2014 Fedora Release Engineering - 5.9.5-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild diff --git a/sources b/sources index 65274b0..daaa9c0 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (onig-6.9.10.tar.gz) = f7cf33008ca0181322fb8efc8e6bb67a1f81677095a33d88134781b804e6a9fbf675f05789d762fdd3d9f0171f8dc4c2e960c2b6a09ddd03bfd35a5ab0920317 +SHA512 (onig-6.8.2.tar.gz) = 1bfa6688c67b684afd558ce9f0654f484acbb733972382fccc0b3d1a05a2c2075e349d9d9c8f86371ee07221b45e5ef28ed238b5807be6fbc49d1f53b14e1596