Compare commits

..

1 commit

Author SHA1 Message Date
Charalampos Stratakis
56bb8c450c Remove unsafe dead code (CVE-2025-56005) from the bundled ply 2026-03-26 00:23:30 +01:00
6 changed files with 163 additions and 35 deletions

7
.gitignore vendored
View file

@ -1 +1,6 @@
/pycparser-*.tar.gz /release_v2.09.1.tar.gz
/release_v2.10.tar.gz
/release_v2.14.tar.gz
/release_v2.19.tar.gz
/release_v2.20.tar.gz
/release_v2.22.tar.gz

View file

@ -1,23 +0,0 @@
From 8c219ec62ea3bf835c473954f30ea9b1202069eb Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Miro=20Hron=C4=8Dok?= <miro@hroncok.cz>
Date: Mon, 23 Mar 2026 14:18:23 +0100
Subject: [PATCH] Drop an unneeded direct build depndency on wheel (#597)
- wheel is not needed to build sdists
- with setuptools 71+, wheel is not needed to build wheels either
- older setuptools would communicate the dependency on wheel themselves
---
pyproject.toml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pyproject.toml b/pyproject.toml
index 5b9d7d38..9bc8da7f 100644
--- a/pyproject.toml
+++ b/pyproject.toml
@@ -1,5 +1,5 @@
[build-system]
-requires = ["setuptools>=69", "wheel"]
+requires = ["setuptools>=69"]
build-backend = "setuptools.build_meta"
[project]

View file

@ -13,7 +13,7 @@ sys.path.extend(['.', '..'])
import sys import sys
import os import os
boiler_plate = 'sys.path.extend([".", ".."])\n' boiler_plate = "sys.path.extend(['.', '..'])\n"
d = sys.argv[1] d = sys.argv[1]
for (root, dirs, files) in os.walk(d): for (root, dirs, files) in os.walk(d):
for i in files: for i in files:

View file

@ -2,17 +2,19 @@
Name: python-pycparser Name: python-pycparser
Summary: C parser and AST generator written in Python Summary: C parser and AST generator written in Python
Version: 3.00 Version: 2.22
Release: %autorelease Release: %autorelease
# pycparser: BSD-3-Clause
# bundled ply: BSD-3-Clause
License: BSD-3-Clause License: BSD-3-Clause
URL: https://github.com/eliben/pycparser URL: http://github.com/eliben/pycparser
Source0: %{url}/archive/release_v%{version}/pycparser-release_v%{version}.tar.gz Source0: %{url}/archive/release_v%{version}.tar.gz
Source1: pycparser-3.00-remove-relative-sys-path.py Source1: pycparser-0.91.1-remove-relative-sys-path.py
# Drop redundant BuildRequires for python3-wheel # Remove unsafe dead code (CVE-2025-56005) from the bundled ply
# https://github.com/fedora-eln/eln/issues/284 Patch: remove-ply-unsafe-pickle-code.patch
Patch: https://github.com/eliben/pycparser/commit/8c219ec6.patch
BuildArch: noarch BuildArch: noarch
@ -31,6 +33,12 @@ need to parse C source code.
%package -n python3-pycparser %package -n python3-pycparser
Summary: %{summary} Summary: %{summary}
# pycaparser bundles ply,
# which is the preferred upstream for both upstreams.
# See https://github.com/eliben/pycparser/pull/589
%global ply_version 3.9
Provides: bundled(python3dist(ply)) = %{ply_version}
%description -n python3-pycparser %description -n python3-pycparser
pycparser is a complete parser for the C language, written in pure Python. pycparser is a complete parser for the C language, written in pure Python.
It is a module designed to be easily integrated into applications that It is a module designed to be easily integrated into applications that
@ -47,7 +55,7 @@ need to parse C source code.
%build %build
pushd pycparser pushd pycparser
%{python3} _ast_gen.py %{python3} _build_tables.py
popd popd
%pyproject_wheel %pyproject_wheel
@ -61,9 +69,9 @@ export %{py3_test_envvars}
%if %{with tests} %if %{with tests}
%{python3} -m unittest discover %{python3} -m unittest discover
%endif %endif
%{python3} -c 'import pycparser; assert pycparser.ply.__version__ == "%{ply_version}"'
%files -n python3-pycparser -f %{pyproject_files} %files -n python3-pycparser -f %{pyproject_files}
%doc README.rst
%doc examples %doc examples
%changelog %changelog

View file

@ -0,0 +1,138 @@
From a8e7cb61ccd5773c390b69112c24cbb6a20ec63c Mon Sep 17 00:00:00 2001
From: Charalampos Stratakis <cstratak@redhat.com>
Date: Thu, 26 Mar 2026 00:19:40 +0100
Subject: [PATCH] Remove unsafe pickle code from bundled ply (CVE-2025-56005)
---
pycparser/ply/yacc.py | 73 ++-----------------------------------------
1 file changed, 2 insertions(+), 71 deletions(-)
diff --git a/pycparser/ply/yacc.py b/pycparser/ply/yacc.py
index 20b4f28..6b38a30 100644
--- a/pycparser/ply/yacc.py
+++ b/pycparser/ply/yacc.py
@@ -90,8 +90,6 @@ yaccdevel = False # Set to True if developing yacc. This turns off
resultlimit = 40 # Size limit of results when running in debug mode.
-pickle_protocol = 0 # Protocol to use when writing pickle files
-
# String type-checking compatibility
if sys.version_info[0] < 3:
string_types = basestring
@@ -1995,33 +1993,6 @@ class LRTable(object):
self.lr_method = parsetab._lr_method
return parsetab._lr_signature
- def read_pickle(self, filename):
- try:
- import cPickle as pickle
- except ImportError:
- import pickle
-
- if not os.path.exists(filename):
- raise ImportError
-
- in_f = open(filename, 'rb')
-
- tabversion = pickle.load(in_f)
- if tabversion != __tabversion__:
- raise VersionError('yacc table file version is out of date')
- self.lr_method = pickle.load(in_f)
- signature = pickle.load(in_f)
- self.lr_action = pickle.load(in_f)
- self.lr_goto = pickle.load(in_f)
- productions = pickle.load(in_f)
-
- self.lr_productions = []
- for p in productions:
- self.lr_productions.append(MiniProduction(*p))
-
- in_f.close()
- return signature
-
# Bind all production function names to callable objects in pdict
def bind_callables(self, pdict):
for p in self.lr_productions:
@@ -2839,32 +2810,6 @@ del _lr_goto_items
raise
- # -----------------------------------------------------------------------------
- # pickle_table()
- #
- # This function pickles the LR parsing tables to a supplied file object
- # -----------------------------------------------------------------------------
-
- def pickle_table(self, filename, signature=''):
- try:
- import cPickle as pickle
- except ImportError:
- import pickle
- with open(filename, 'wb') as outf:
- pickle.dump(__tabversion__, outf, pickle_protocol)
- pickle.dump(self.lr_method, outf, pickle_protocol)
- pickle.dump(signature, outf, pickle_protocol)
- pickle.dump(self.lr_action, outf, pickle_protocol)
- pickle.dump(self.lr_goto, outf, pickle_protocol)
-
- outp = []
- for p in self.lr_productions:
- if p.func:
- outp.append((p.str, p.name, p.len, p.func, os.path.basename(p.file), p.line))
- else:
- outp.append((str(p), p.name, p.len, None, None, None))
- pickle.dump(outp, outf, pickle_protocol)
-
# -----------------------------------------------------------------------------
# === INTROSPECTION ===
#
@@ -3213,7 +3158,7 @@ class ParserReflect(object):
def yacc(method='LALR', debug=yaccdebug, module=None, tabmodule=tab_module, start=None,
check_recursion=True, optimize=False, write_tables=True, debugfile=debug_file,
- outputdir=None, debuglog=None, errorlog=None, picklefile=None):
+ outputdir=None, debuglog=None, errorlog=None):
if tabmodule is None:
tabmodule = tab_module
@@ -3221,10 +3166,6 @@ def yacc(method='LALR', debug=yaccdebug, module=None, tabmodule=tab_module, star
# Reference to the parsing method of the last built parser
global parse
- # If pickling is enabled, table files are not created
- if picklefile:
- write_tables = 0
-
if errorlog is None:
errorlog = PlyLogger(sys.stderr)
@@ -3281,10 +3222,7 @@ def yacc(method='LALR', debug=yaccdebug, module=None, tabmodule=tab_module, star
# Read the tables
try:
lr = LRTable()
- if picklefile:
- read_signature = lr.read_pickle(picklefile)
- else:
- read_signature = lr.read_table(tabmodule)
+ read_signature = lr.read_table(tabmodule)
if optimize or (read_signature == signature):
try:
lr.bind_callables(pinfo.pdict)
@@ -3479,13 +3417,6 @@ def yacc(method='LALR', debug=yaccdebug, module=None, tabmodule=tab_module, star
except IOError as e:
errorlog.warning("Couldn't create %r. %s" % (tabmodule, e))
- # Write a pickled version of the tables
- if picklefile:
- try:
- lr.pickle_table(picklefile, signature)
- except IOError as e:
- errorlog.warning("Couldn't create %r. %s" % (picklefile, e))
-
# Build the parser
lr.bind_callables(pinfo.pdict)
parser = LRParser(lr, pinfo.error_func)
--
2.53.0

View file

@ -1 +1 @@
SHA512 (pycparser-release_v3.00.tar.gz) = e3b877aebedd49616f2144812e385de973add7bf358cf908fecd210149e9c2da563ffd27b09e915ebbf0f159fec83de76c7f7c27d0baa1282f75c50beb666590 SHA512 (release_v2.22.tar.gz) = 1c5be2b83c0a892cafa55a2595942d7048994772dc0fc71d2943004b4198d939c0bf2a164d763d94fe11d532e49371c59c1cf4037c32dab8d3cf0c553a8de64a