From 89e9db5587f858c60c612350f2b5bb0f0a2b8d6b Mon Sep 17 00:00:00 2001 From: Jan Rybar Date: Tue, 2 May 2023 16:02:09 +0200 Subject: [PATCH 1/2] migrate to autosetup; convert specfile script to a patch; FORTIFY_SOURCE_3 detected a buffer overflow Resolves: bz#2190057 --- psacct-6.6.4-specfile-tweaks-file-locs.patch | 43 ++++++++++++++++++++ psacct-6.6.4-sprintf-buffer-overflow.patch | 12 ++++++ psacct.spec | 24 ++++------- 3 files changed, 64 insertions(+), 15 deletions(-) create mode 100644 psacct-6.6.4-specfile-tweaks-file-locs.patch create mode 100644 psacct-6.6.4-sprintf-buffer-overflow.patch diff --git a/psacct-6.6.4-specfile-tweaks-file-locs.patch b/psacct-6.6.4-specfile-tweaks-file-locs.patch new file mode 100644 index 0000000..270c7da --- /dev/null +++ b/psacct-6.6.4-specfile-tweaks-file-locs.patch @@ -0,0 +1,43 @@ +From fcc034e5674dfedebcdace114d059a77d312c0de Mon Sep 17 00:00:00 2001 +From: rpm-build +Date: Tue, 2 May 2023 13:11:07 +0200 +Subject: [PATCH] files locates specfile tweak + +--- + files.h.in | 6 +++--- + lib/stdio.in.h | 2 +- + 2 files changed, 4 insertions(+), 4 deletions(-) + +diff --git a/files.h.in b/files.h.in +index 900ad29..9800222 100644 +--- a/files.h.in ++++ b/files.h.in +@@ -31,9 +31,9 @@ + #include + + #define WTMP_FILE_LOC "@WTMP_FILE_LOC@" +-#define ACCT_FILE_LOC "@ACCT_FILE_LOC@" +-#define SAVACCT_FILE_LOC "@SAVACCT_FILE_LOC@" +-#define USRACCT_FILE_LOC "@USRACCT_FILE_LOC@" ++#define ACCT_FILE_LOC "/var/account/pacct" ++#define SAVACCT_FILE_LOC "/var/account/savacct" ++#define USRACCT_FILE_LOC "/var/account/usracct" + + /* Workaround for a kernel includes problem */ + #if defined(__linux__) && defined(__alpha__) +diff --git a/lib/stdio.in.h b/lib/stdio.in.h +index d6af99c..e58d026 100644 +--- a/lib/stdio.in.h ++++ b/lib/stdio.in.h +@@ -700,7 +700,7 @@ _GL_WARN_ON_USE (getline, "getline is unportable - " + removed it. */ + #undef gets + #if HAVE_RAW_DECL_GETS +-_GL_WARN_ON_USE (gets, "gets is a security hole - use fgets instead"); ++ + #endif + + +-- +2.40.0 + diff --git a/psacct-6.6.4-sprintf-buffer-overflow.patch b/psacct-6.6.4-sprintf-buffer-overflow.patch new file mode 100644 index 0000000..d86d0eb --- /dev/null +++ b/psacct-6.6.4-sprintf-buffer-overflow.patch @@ -0,0 +1,12 @@ +diff -up ./dev_hash.c.ori ./dev_hash.c +--- ./dev_hash.c.ori 2023-05-02 10:40:45.509862165 +0200 ++++ ./dev_hash.c 2023-05-02 10:40:48.266876499 +0200 +@@ -147,7 +147,7 @@ static void setup_devices(char *dirname) + { + char *fullname = (char *) alloca ((strlen (dirname) + + NAMLEN (dp) +- + 1) * sizeof (char)); ++ + 2) * sizeof (char)); /* slash + null; Fedora BZ#2190057 */ + + (void)sprintf (fullname, "%s/%s", dirname, dp->d_name); + if (stat (fullname, &sp)) diff --git a/psacct.spec b/psacct.spec index 0ae0863..2be000a 100644 --- a/psacct.spec +++ b/psacct.spec @@ -4,7 +4,7 @@ Summary: Utilities for monitoring process activities Name: psacct Version: 6.6.4 -Release: 15%{?dist} +Release: 15%{?dist}.1 License: GPLv3+ URL: http://www.gnu.org/software/acct/ @@ -16,6 +16,8 @@ Source3: accton-create Patch1: psacct-6.6.2-unnumberedsubsubsec.patch Patch2: psacct-6.6.1-SEGV-when-record-incomplete.patch Patch3: psacct-6.6.4-lastcomm-manpage-pid-twice.patch +Patch4: psacct-6.6.4-sprintf-buffer-overflow.patch +Patch5: psacct-6.6.4-specfile-tweaks-file-locs.patch Conflicts: filesystem < 3 Requires: coreutils @@ -40,20 +42,7 @@ commands. %prep -%setup -q -n acct-%{version} - -%patch1 -p1 -b .subsubsec -%patch2 -p1 -%patch3 -p1 - -# fixing 'gets' undeclared -sed -i 's|.*(gets,.*||g' lib/stdio.in.h - -# workaround for broken autotools stuff -sed -i 's|@ACCT_FILE_LOC@|/var/account/pacct|g' files.h.in -sed -i 's|@SAVACCT_FILE_LOC@|/var/account/savacct|g' files.h.in -sed -i 's|@USRACCT_FILE_LOC@|/var/account/usracct|g' files.h.in - +%autosetup -S git -n acct-%{version} %build %configure --enable-linux-multiformat @@ -134,6 +123,11 @@ touch /var/account/pacct && chmod 0600 /var/account/pacct %changelog +* Tue May 02 2023 Jan Rybar - 6.6.4-15.1 +- migrate to autosetup; convert specfile script to a patch +- FORTIFY_SOURCE_3 detected a buffer overflow +- Resolves: bz#2190057 + * Fri Jan 20 2023 Fedora Release Engineering - 6.6.4-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild From b601bf12cd4acd3bd6678f457253792ccaf47064 Mon Sep 17 00:00:00 2001 From: Jan Rybar Date: Tue, 2 May 2023 16:10:22 +0200 Subject: [PATCH 2/2] git in buildrequires --- psacct.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/psacct.spec b/psacct.spec index 2be000a..2e776d5 100644 --- a/psacct.spec +++ b/psacct.spec @@ -4,7 +4,7 @@ Summary: Utilities for monitoring process activities Name: psacct Version: 6.6.4 -Release: 15%{?dist}.1 +Release: 15%{?dist}.2 License: GPLv3+ URL: http://www.gnu.org/software/acct/ @@ -29,6 +29,7 @@ BuildRequires: make BuildRequires: autoconf BuildRequires: systemd BuildRequires: gcc +BuildRequires: git %description @@ -123,6 +124,9 @@ touch /var/account/pacct && chmod 0600 /var/account/pacct %changelog +* Tue May 02 2023 Jan Rybar - 6.6.4-15.2 +- obviously, 'autosetup -S git' still explicitly needs git in buildrequires + * Tue May 02 2023 Jan Rybar - 6.6.4-15.1 - migrate to autosetup; convert specfile script to a patch - FORTIFY_SOURCE_3 detected a buffer overflow