diff --git a/.gitignore b/.gitignore index bad46b5..feafd3e 100644 --- a/.gitignore +++ b/.gitignore @@ -8,5 +8,6 @@ nokogiri-1.4.3.1.gem /nokogiri-1.5.5.gem /nokogiri-1.5.6.gem /nokogiri-1.5.9.gem +/nokogiri-1.5.11.gem /nokogiri-1.6.0.gem /nokogiri-1.6.1.gem diff --git a/nokogiri-1.6.1.gem b/nokogiri-1.6.1.gem new file mode 100644 index 0000000..8de96b6 Binary files /dev/null and b/nokogiri-1.6.1.gem differ diff --git a/rubygem-nokogiri-1.5.0-allow-non-crosscompile.patch b/rubygem-nokogiri-1.5.0-allow-non-crosscompile.patch deleted file mode 100644 index f45734b..0000000 --- a/rubygem-nokogiri-1.5.0-allow-non-crosscompile.patch +++ /dev/null @@ -1,26 +0,0 @@ ---- nokogiri-1.5.0/Rakefile.debug 2012-01-18 16:23:02.472224272 +0900 -+++ nokogiri-1.5.0/Rakefile 2012-01-18 16:23:29.935430496 +0900 -@@ -83,14 +83,21 @@ - HOE.spec.files += ['lib/nokogiri/nokogiri.jar'] - end - else -- require 'tasks/cross_compile' -+ do_cross_compile = true -+ begin -+ require 'tasks/cross_compile' -+ rescue RuntimeError => e -+ warn "WARNING: Could not perform some cross-compiling: #{e}" -+ do_cross_compile = false -+ end - require "rake/extensiontask" - -- HOE.spec.files.reject! { |f| f =~ %r{^ext/java|\.jar$} } -+ HOE.spec.files.reject! { |f| f =~ %r{^ext/java|\.jar$} } if do_cross_compile - - Rake::ExtensionTask.new("nokogiri", HOE.spec) do |ext| - ext.lib_dir = File.join(*['lib', 'nokogiri', ENV['FAT_DIR']].compact) - ext.config_options << ENV['EXTOPTS'] -+ next unless do_cross_compile - ext.cross_compile = true - ext.cross_platform = ["x86-mswin32-60", "x86-mingw32"] - ext.cross_config_options << "--with-xml2-include=#{File.join($recipes[:libxml2].path, 'include', 'libxml2')}" diff --git a/rubygem-nokogiri-1.6.1-CVE-2022-24836-backport.patch b/rubygem-nokogiri-1.6.1-CVE-2022-24836-backport.patch new file mode 100644 index 0000000..3ed8fe6 --- /dev/null +++ b/rubygem-nokogiri-1.6.1-CVE-2022-24836-backport.patch @@ -0,0 +1,58 @@ +From edb70d07af416aae9a51ce0d44e414b64ddefad0 Mon Sep 17 00:00:00 2001 +From: Troy Dawson +Date: Wed, 25 May 2022 09:47:36 -0700 +Subject: [PATCH] CVE-2022-24836-backport + +--- + lib/nokogiri/html/document.rb | 4 ++-- + test/html/test_document_encoding.rb | 12 ++++++++++++ + 2 files changed, 14 insertions(+), 2 deletions(-) + +diff --git a/lib/nokogiri/html/document.rb b/lib/nokogiri/html/document.rb +index ba10b7a..297c940 100644 +--- a/lib/nokogiri/html/document.rb ++++ b/lib/nokogiri/html/document.rb +@@ -173,7 +173,7 @@ module Nokogiri + if Nokogiri.jruby? && EncodingReader.is_jruby_without_fix? + return EncodingReader.detect_encoding_for_jruby_without_fix(chunk) + end +- m = chunk.match(/\A(<\?xml[ \t\r\n]+[^>]*>)/) and ++ m = chunk.match(/\A(<\?xml[ \t\r\n][^>]*>)/) and + return Nokogiri.XML(m[1]).encoding + + if Nokogiri.jruby? +@@ -196,7 +196,7 @@ module Nokogiri + end + + def self.detect_encoding_for_jruby_without_fix(chunk) +- m = chunk.match(/\A(<\?xml[ \t\r\n]+[^>]*>)/) and ++ m = chunk.match(/\A(<\?xml[ \t\r\n][^>]*>)/) and + return Nokogiri.XML(m[1]).encoding + + m = chunk.match(/( +Date: Wed, 25 May 2022 10:20:25 -0700 +Subject: [PATCH] CVE-2022-29181-backport + +--- + ext/nokogiri/html_sax_parser_context.c | 4 ++-- + ext/nokogiri/xml_sax_parser_context.c | 12 ++++++++++-- + lib/nokogiri/html/sax/parser.rb | 2 +- + test/html/sax/test_parser.rb | 8 +++++++- + test/html/sax/test_parser_context.rb | 9 +++++++++ + test/xml/sax/test_parser.rb | 8 +++++++- + test/xml/sax/test_parser_context.rb | 7 +++++++ + 7 files changed, 43 insertions(+), 7 deletions(-) + +diff --git a/ext/nokogiri/html_sax_parser_context.c b/ext/nokogiri/html_sax_parser_context.c +index 02172ad..8967cb0 100644 +--- a/ext/nokogiri/html_sax_parser_context.c ++++ b/ext/nokogiri/html_sax_parser_context.c +@@ -18,8 +18,8 @@ parse_memory(VALUE klass, VALUE data, VALUE encoding) + { + htmlParserCtxtPtr ctxt; + +- if (NIL_P(data)) +- rb_raise(rb_eArgError, "data cannot be nil"); ++ Check_Type(data, T_STRING); ++ + if (!(int)RSTRING_LEN(data)) + rb_raise(rb_eRuntimeError, "data cannot be empty"); + +diff --git a/ext/nokogiri/xml_sax_parser_context.c b/ext/nokogiri/xml_sax_parser_context.c +index d042e4f..d2e5f63 100644 +--- a/ext/nokogiri/xml_sax_parser_context.c ++++ b/ext/nokogiri/xml_sax_parser_context.c +@@ -2,6 +2,8 @@ + + VALUE cNokogiriXmlSaxParserContext ; + ++static ID id_read; ++ + static void deallocate(xmlParserCtxtPtr ctxt) + { + NOKOGIRI_DEBUG_START(handler); +@@ -25,6 +27,10 @@ parse_io(VALUE klass, VALUE io, VALUE encoding) + xmlParserCtxtPtr ctxt; + xmlCharEncoding enc = (xmlCharEncoding)NUM2INT(encoding); + ++ if (!rb_respond_to(io, id_read)) { ++ rb_raise(rb_eTypeError, "argument expected to respond to :read"); ++ } ++ + ctxt = xmlCreateIOParserCtxt(NULL, NULL, + (xmlInputReadCallback)io_read_callback, + (xmlInputCloseCallback)io_close_callback, +@@ -60,8 +66,8 @@ parse_memory(VALUE klass, VALUE data) + { + xmlParserCtxtPtr ctxt; + +- if (NIL_P(data)) +- rb_raise(rb_eArgError, "data cannot be nil"); ++ Check_Type(data, T_STRING); ++ + if (!(int)RSTRING_LEN(data)) + rb_raise(rb_eRuntimeError, "data cannot be empty"); + +@@ -219,4 +225,6 @@ void init_xml_sax_parser_context() + rb_define_method(klass, "replace_entities", get_replace_entities, 0); + rb_define_method(klass, "line", line, 0); + rb_define_method(klass, "column", column, 0); ++ ++ id_read = rb_intern("read"); + } +diff --git a/lib/nokogiri/html/sax/parser.rb b/lib/nokogiri/html/sax/parser.rb +index a1ee0cc..3b64ce3 100644 +--- a/lib/nokogiri/html/sax/parser.rb ++++ b/lib/nokogiri/html/sax/parser.rb +@@ -29,7 +29,7 @@ module Nokogiri + ### + # Parse html stored in +data+ using +encoding+ + def parse_memory data, encoding = 'UTF-8' +- raise ArgumentError unless data ++ raise TypeError unless String === data + return unless data.length > 0 + ctx = ParserContext.memory(data, encoding) + yield ctx if block_given? +diff --git a/test/html/sax/test_parser.rb b/test/html/sax/test_parser.rb +index 06099aa..bed52dd 100644 +--- a/test/html/sax/test_parser.rb ++++ b/test/html/sax/test_parser.rb +@@ -54,7 +54,7 @@ module Nokogiri + end + + def test_parse_memory_nil +- assert_raise ArgumentError do ++ assert_raise TypeError do + @parser.parse_memory(nil) + end + end +@@ -135,6 +135,12 @@ module Nokogiri + def test_empty_processing_instruction + @parser.parse_memory("this will segfault") + end ++ ++ it "handles invalid types gracefully" do ++ assert_raises(TypeError) { Nokogiri::HTML::SAX::Parser.new.parse(0xcafecafe) } ++ assert_raises(TypeError) { Nokogiri::HTML::SAX::Parser.new.parse_memory(0xcafecafe) } ++ assert_raises(TypeError) { Nokogiri::HTML::SAX::Parser.new.parse_io(0xcafecafe) } ++ end + end + end + end +diff --git a/test/html/sax/test_parser_context.rb b/test/html/sax/test_parser_context.rb +index 5d1f5aa..0b681f9 100644 +--- a/test/html/sax/test_parser_context.rb ++++ b/test/html/sax/test_parser_context.rb +@@ -39,6 +39,15 @@ module Nokogiri + ctx.parse_with parser + # end + end ++ ++ def test_graceful_handling_of_invalid_types ++ assert_raises(TypeError) { ParserContext.new(0xcafecafe) } ++ assert_raises(TypeError) { ParserContext.memory(0xcafecafe, "UTF-8") } ++ assert_raises(TypeError) { ParserContext.io(0xcafecafe, 1) } ++ assert_raises(TypeError) { ParserContext.io(StringIO.new("asdf"), "should be an index into ENCODINGS") } ++ assert_raises(TypeError) { ParserContext.file(0xcafecafe, "UTF-8") } ++ assert_raises(TypeError) { ParserContext.file("path/to/file", 0xcafecafe) } ++ end + end + end + end +diff --git a/test/xml/sax/test_parser.rb b/test/xml/sax/test_parser.rb +index 04c8cac..b993a35 100644 +--- a/test/xml/sax/test_parser.rb ++++ b/test/xml/sax/test_parser.rb +@@ -66,6 +66,12 @@ module Nokogiri + end + end + ++ def test_graceful_handling_of_invalid_types ++ assert_raises(TypeError) { Nokogiri::XML::SAX::Parser.new.parse(0xcafecafe) } ++ assert_raises(TypeError) { Nokogiri::XML::SAX::Parser.new.parse_memory(0xcafecafe) } ++ assert_raises(TypeError) { Nokogiri::XML::SAX::Parser.new.parse_io(0xcafecafe) } ++ end ++ + def test_namespace_declaration_order_is_saved + @parser.parse <<-eoxml + +@@ -261,7 +267,7 @@ module Nokogiri + end + + def test_render_parse_nil_param +- assert_raises(ArgumentError) { @parser.parse_memory(nil) } ++ assert_raises(TypeError) { @parser.parse_memory(nil) } + end + + def test_bad_encoding_args +diff --git a/test/xml/sax/test_parser_context.rb b/test/xml/sax/test_parser_context.rb +index ad6d994..33b484e 100644 +--- a/test/xml/sax/test_parser_context.rb ++++ b/test/xml/sax/test_parser_context.rb +@@ -65,6 +65,13 @@ world + assert_equal true, pc.replace_entities + end + ++ def test_graceful_handling_of_invalid_types ++ assert_raises(TypeError) { ParserContext.new(0xcafecafe) } ++ assert_raises(TypeError) { ParserContext.memory(0xcafecafe) } ++ assert_raises(TypeError) { ParserContext.io(0xcafecafe, 1) } ++ assert_raises(TypeError) { ParserContext.io(StringIO.new("asdf"), "should be an index into ENCODINGS") } ++ end ++ + def test_from_io + ctx = ParserContext.new StringIO.new('fo'), 'UTF-8' + assert ctx +-- +2.31.1 + diff --git a/rubygem-nokogiri.spec b/rubygem-nokogiri.spec index 0c78161..55c7752 100644 --- a/rubygem-nokogiri.spec +++ b/rubygem-nokogiri.spec @@ -35,7 +35,7 @@ Summary: An HTML, XML, SAX, and Reader parser Name: rubygem-%{gemname} Version: %{mainver} -Release: %{?prever:0.}%{mainrel}%{?prever:.%{prerpmver}}%{?dist}.1 +Release: %{?prever:0.}%{mainrel}%{?prever:.%{prerpmver}}%{?dist}.2 Group: Development/Languages License: MIT URL: http://nokogiri.rubyforge.org/nokogiri/ @@ -43,7 +43,13 @@ Source0: http://gems.rubyforge.org/gems/%{gemname}-%{mainver}%{?prever}.gem # ./test/html/test_element_description.rb:62 fails, as usual...... # Patch0: rubygem-nokogiri-1.5.0.beta3-test-failure.patch #Patch0: rubygem-nokogiri-1.5.0-allow-non-crosscompile.patch -%if 0%{?fedora} >= 19 +# Fix for CVE-2022-24836, backported +Patch1: %{name}-1.6.1-CVE-2022-24836-backport.patch +# https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267 +# Fix for CVE-2022-24836, backported +Patch2: %{name}-1.6.1-CVE-2022-29181-backport.patch + +%if 0%{?fedora} >= 19 || 0%{?rhel} >= 7 Requires: ruby(release) BuildRequires: ruby(release) %else @@ -116,6 +122,8 @@ cd %{gem_name}-%{version} # patches #%%patch0 -p1 +%patch1 -p1 +%patch2 -p1 gem specification -l --ruby %{SOURCE0} > %{gem_name}.gemspec @@ -233,6 +241,10 @@ popd %{gemdir}/doc/%{gemname}-%{mainver}%{?prever}/ %changelog +* Wed May 25 2022 Troy Dawson - 1.6.1-1.2 +- Backport CVE-2022-24836 (#2074347) +- Backport CVE-2022-29181 (#2088685) + * Wed Dec 25 2013 Mamoru TASAKA - 1.6.1-1 - 1.6.1 @@ -280,7 +292,7 @@ popd - F-17: rebuild for ruby19 - For now aviod build failure by touching some files -* Thu Jan 18 2012 Mamoru Tasaka - 1.5.0-1 +* Wed Jan 18 2012 Mamoru Tasaka - 1.5.0-1 - 1.5.0 * Sat Jan 14 2012 Fedora Release Engineering - 1.5.0-0.5.beta4.1 @@ -289,7 +301,7 @@ popd * Sun Jun 26 2011 Mamoru Tasaka - 1.5.0-0.5.beta4 - Remove unneeded patch -* Thu Mar 18 2011 Mamoru Tasaka - 1.5.0-0.4.beta4 +* Fri Mar 18 2011 Mamoru Tasaka - 1.5.0-0.4.beta4 - Patch for newer rake to make testsuite run * Wed Feb 09 2011 Fedora Release Engineering - 1.5.0-0.3.beta4.1