Compare commits

..

1 commit

Author SHA1 Message Date
Vít Ondruch
cb20b20f7c Fix to directory traversal attacks (CVE-2017-17042). 2017-12-01 20:52:33 +01:00
8 changed files with 215 additions and 249 deletions

12
.gitignore vendored
View file

@ -1,3 +1,9 @@
/yard-*.gem
/yard-*-spec.txz
/yard-*-test-missing-files.tar.gz
yard-0.5.3.gem
/yard-0.7.2.gem
/yard-0.7.4.gem
/yard-0.8.1.gem
/yard-0.8.2.1.gem
/yard-0.8.5.2.gem
/yard-0.8.7.gem
/yard-0.8.7.4.gem
/yard-0.8.7.6.gem

View file

@ -0,0 +1,23 @@
From afbcbc18efbf56ae81842094c78ac6ad218e9922 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 14 Apr 2016 23:52:09 -0700
Subject: [PATCH] Fix brittle test on Ruby 2.3
Fixes #927
---
spec/parser/ruby/ruby_parser_spec.rb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/spec/parser/ruby/ruby_parser_spec.rb b/spec/parser/ruby/ruby_parser_spec.rb
index 6e5bd89..07d7212 100644
--- a/spec/parser/ruby/ruby_parser_spec.rb
+++ b/spec/parser/ruby/ruby_parser_spec.rb
@@ -351,7 +351,7 @@ eof
# end comment
end
eof
- comment = ast.first.last.first
+ comment = ast.first.last.jump(:comment)
comment.type.should == :comment
comment.docstring_hash_flag.should be_true
comment.docstring.strip.should == "comment here"

View file

@ -0,0 +1,48 @@
From b0217b3e30dc53d057b1682506333335975e62b4 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 23 Nov 2017 13:34:33 -0800
Subject: [PATCH] Disallow relative paths that start with ../
Fixes a potential arbitrary file read vulnerability in yard server.
Thanks to ztz <ztz@ztz.me> for discovery of this security issue.
---
lib/yard/core_ext/file.rb | 2 ++
spec/core_ext/file_spec.rb | 6 +++---
2 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/lib/yard/core_ext/file.rb b/lib/yard/core_ext/file.rb
index 3902f2bd..a0b983e9 100644
--- a/lib/yard/core_ext/file.rb
+++ b/lib/yard/core_ext/file.rb
@@ -39,6 +39,8 @@ class File
if comp == RELATIVE_PARENTDIR && acc.size > 0 && acc.last != RELATIVE_PARENTDIR
acc.pop
next acc
+ elsif comp == RELATIVE_PARENTDIR && acc.empty?
+ next acc
end
acc << comp
end
diff --git a/spec/core_ext/file_spec.rb b/spec/core_ext/file_spec.rb
index f61081f6..15806360 100644
--- a/spec/core_ext/file_spec.rb
+++ b/spec/core_ext/file_spec.rb
@@ -41,12 +41,12 @@ RSpec.describe File do
File.cleanpath('A/B/C/D/..').should == "A/B/C"
end
- it "should pass the initial directory" do
- File.cleanpath('C/../../D').should == "../D"
+ it "does not allow relative path above root" do
+ File.cleanpath('A/../../../../../D').should == "D"
end
it "should not remove multiple '../' at the beginning" do
- File.cleanpath('../../A/B').should == '../../A/B'
+ File.cleanpath('../../A/B').should == 'A/B'
end
end
--
2.15.1

View file

@ -0,0 +1,65 @@
From 3bcccf678040e827f706b8305456424aa83f6471 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 23 Nov 2017 13:47:35 -0800
Subject: [PATCH] Fix broken tests
---
lib/yard/cli/yardoc.rb | 2 +-
lib/yard/core_ext/file.rb | 5 +++--
spec/core_ext/file_spec.rb | 4 ++++
3 files changed, 8 insertions(+), 3 deletions(-)
diff --git a/lib/yard/cli/yardoc.rb b/lib/yard/cli/yardoc.rb
index a2918a36..f40e4dd1 100644
--- a/lib/yard/cli/yardoc.rb
+++ b/lib/yard/cli/yardoc.rb
@@ -640,7 +640,7 @@ module YARD
opts.on('--asset FROM[:TO]', 'A file or directory to copy over to output ',
' directory after generating') do |asset|
re = /^(?:\.\.\/|\/)/
- from, to = *asset.split(':').map {|f| File.cleanpath(f) }
+ from, to = *asset.split(':').map {|f| File.cleanpath(f, true) }
to ||= from
if from =~ re || to =~ re
log.warn "Invalid file '#{asset}'"
diff --git a/lib/yard/core_ext/file.rb b/lib/yard/core_ext/file.rb
index a0b983e9..c918b5af 100644
--- a/lib/yard/core_ext/file.rb
+++ b/lib/yard/core_ext/file.rb
@@ -31,15 +31,16 @@ class File
# @example Clean a path
# File.cleanpath('a/b//./c/../e') # => "a/b/e"
# @param [String] path the path to clean
+ # @param [Boolean] rel_root allows relative path above root value
# @return [String] the sanitized path
- def self.cleanpath(path)
+ def self.cleanpath(path, rel_root = false)
path = path.split(SEPARATOR)
path = path.inject([]) do |acc, comp|
next acc if comp == RELATIVE_SAMEDIR
if comp == RELATIVE_PARENTDIR && acc.size > 0 && acc.last != RELATIVE_PARENTDIR
acc.pop
next acc
- elsif comp == RELATIVE_PARENTDIR && acc.empty?
+ elsif !rel_root && comp == RELATIVE_PARENTDIR && acc.empty?
next acc
end
acc << comp
diff --git a/spec/core_ext/file_spec.rb b/spec/core_ext/file_spec.rb
index 15806360..e3d3930c 100644
--- a/spec/core_ext/file_spec.rb
+++ b/spec/core_ext/file_spec.rb
@@ -41,6 +41,10 @@ RSpec.describe File do
File.cleanpath('A/B/C/D/..').should == "A/B/C"
end
+ it "allows '../' at the beginning if rel_root=true" do
+ expect(File.cleanpath('A/../../B', true)).to eq '../B'
+ end
+
it "does not allow relative path above root" do
File.cleanpath('A/../../../../../D').should == "D"
end
--
2.15.1

View file

@ -1,48 +1,30 @@
%global gem_name yard
%global gem_name yard
Name: rubygem-%{gem_name}
Version: 0.9.38
Release: 2%{?dist}
Name: rubygem-%{gem_name}
Version: 0.8.7.6
Release: 4%{?dist}
Summary: Documentation tool for consistent and usable documentation in Ruby
Group: Development/Languages
License: MIT and (BSD or Ruby)
URL: http://yardoc.org
Source0: https://rubygems.org/gems/%{gem_name}-%{version}.gem
# Fix to directory traversal attacks (CVE-2017-17042)
# https://github.com/lsegal/yard/commit/b0217b3e30dc53d057b1682506333335975e62b4
Patch1: rubygem-yard-0.9.11-Disallow-relative-paths-that-start-with.patch
# https://github.com/lsegal/yard/commit/3bcccf678040e827f706b8305456424aa83f6471
Patch2: rubygem-yard-0.9.11-Fix-broken-tests.patch
BuildRequires: ruby(release)
BuildRequires: rubygems-devel
BuildRequires: ruby
BuildRequires: rubygem(RedCloth)
BuildRequires: rubygem(rspec) < 3
BuildRequires: rubygem(redcarpet)
BuildRequires: rubygem(rack)
BuildArch: noarch
Summary: Documentation tool for consistent and usable documentation in Ruby
# lib/yard/parser/ruby/legacy/ruby_lex.rb: under GPL-2.0-only OR Ruby
# lib/yard/rubygems/backports/: MIT OR Ruby
# lib/yard/server/http_utils.rb: BSD 2-Clause
# lib/yard/server/templates/default/fulldoc/html/js/autocomplete.js:
# MIT OR GPL(version 2??), as this is OR, use MIT for now
# Others are MIT
# SPDX confirmed
License: MIT AND (MIT OR Ruby) AND BSD-2-Clause AND (GPL-2.0-only OR Ruby)
URL: http://yardoc.org
Source0: https://rubygems.org/gems/%{gem_name}-%{version}.gem
Source1: %{gem_name}-%{version}-test-missing-files.tar.gz
# Source1 is created by $ bash %%SOURCE2 %%version
Source2: yard-create-missing-test-files.sh
# https://github.com/lsegal/yard/issues/1637
# Fix spec testsuite with namespace collision
Patch0: yard-0.9.38-issue1637-spec-namespace-collision.patch
# The 'irb/notifier' might be required for parsing of some old Ruby code.
# https://github.com/lsegal/yard/blob/v0.9.24/lib/yard/parser/ruby/legacy/irb/slex.rb#L13
Recommends: rubygem(irb)
BuildRequires: ruby(release)
BuildRequires: rubygems-devel
BuildRequires: ruby
BuildRequires: rubygem(RedCloth)
BuildRequires: rubygem(asciidoctor)
BuildRequires: rubygem(bundler)
BuildRequires: rubygem(irb)
BuildRequires: rubygem(rack)
BuildRequires: /usr/bin/rackup
BuildRequires: rubygem(rake)
BuildRequires: rubygem(redcarpet)
BuildRequires: rubygem(rspec)
BuildRequires: rubygem(webrick)
BuildArch: noarch
# Fix test suite in Ruby 2.3.
# https://github.com/lsegal/yard/commit/afbcbc1.patch
Patch0: rubygem-yard-0.8.7.6-fix-test-for-ruby-2.3.patch
%description
YARD is a documentation generation tool for the Ruby programming language.
@ -51,184 +33,78 @@ exported to a number of formats very easily, and also supports extending for
custom Ruby constructs such as custom class level definitions.
%package doc
Summary: Documentation for %{name}
Requires: %{name} = %{version}-%{release}
BuildArch: noarch
%package doc
Summary: Documentation for %{name}
Group: Documentation
Requires: %{name} = %{version}-%{release}
BuildArch: noarch
%description doc
Documentation for %{name}.
%prep
%setup -q -n %{gem_name}-%{version} -b1
%patch -P0 -p1
mv ../%{gem_name}-%{version}.gemspec .
%setup -q -T -c
%gem_install -n %{SOURCE0}
pushd .%{gem_instdir}
%patch1 -p1
%patch2 -p1
popd
%build
gem build ./%{gem_name}-%{version}.gemspec
%gem_install
%install
mkdir -p %{buildroot}%{gem_dir}
cp -a .%{gem_dir}/* \
%{buildroot}%{gem_dir}/
pushd %{buildroot}%{gem_instdir}
rm -rf .yardopts* \
%{nil}
popd
%{buildroot}%{gem_dir}/
mkdir -p %{buildroot}%{_bindir}
cp -a .%{_bindir}/* \
%{buildroot}%{_bindir}/
%{buildroot}%{_bindir}/
find %{buildroot}%{gem_instdir}/bin -type f | xargs chmod 0755
rm -f %{buildroot}%{gem_cache}
find %{buildroot}%{gem_instdir}/bin -type f | xargs chmod a+x
%check
# FIXME
# investigate this: was okay with yard 0.9.28
sed -i spec/cli/diff_spec.rb \
-e '\@"searches for .gem file"@s|\([ \t]it \)|\txit |'
rspec -r spec_helper spec
pushd .%{gem_instdir}
# Not sure if this is needed, since bundler is not user or because Fedora
# provides more recent RSpec :/
sed -i '/File\.stub(:exist?).with(\/\\\.yardopts$\/)/ i\ File.stub(:exist?).and_return(true)' spec/cli/server_spec.rb
patch -p1 < %{PATCH0}
rspec2 spec
popd
%files
%dir %{gem_instdir}
%license %{gem_instdir}/LEGAL
%license %{gem_instdir}/LICENSE
%doc %{gem_instdir}/CHANGELOG.md
%doc %{gem_instdir}/README.md
%{_bindir}/yard
%{_bindir}/yardoc
%{_bindir}/yri
%{gem_libdir}/
%{_bindir}/yard
%dir %{gem_instdir}
%{gem_instdir}/bin
%{gem_instdir}/po/
%{gem_instdir}/templates/
%{gem_libdir}
%{gem_instdir}/templates
%exclude %{gem_instdir}/.yardopts
%doc %{gem_instdir}/LEGAL
%exclude %{gem_cache}
%{gem_spec}
%{?gem_plugin}
%license %{gem_instdir}/LICENSE
%files doc
%doc %{gem_docdir}
%doc %{gem_instdir}/docs/
%doc %{gem_docdir}
%doc %{gem_instdir}/CHANGELOG.md
%doc %{gem_instdir}/README.md
%{gem_instdir}/Rakefile
%{gem_instdir}/%{gem_name}.gemspec
%{gem_instdir}/benchmarks
%{gem_instdir}/spec
%doc %{gem_instdir}/docs
%changelog
* Fri Jan 02 2026 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.38-2
- Fix spec testsuite failure with namespace collision
* Mon Dec 08 2025 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.38-1
- 0.9.38
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.37-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jun 10 2025 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.37-3
- BR: /usr/bin/rackup for rack / rackup gem split (bug 2371181)
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.37-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Sep 05 2024 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.37-1
- 0.9.37
* Fri Jul 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.36-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Fri Mar 01 2024 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.36-1
- 0.9.36 (Fixes CVE-2024-27285)
* Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.34-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Nov 10 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-4
- Testsuite: remove invalid yield usage from spec (for ruby3.3)
* Mon Sep 25 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-3
- Backport upstream patch for BOM detection change in ruby33
* Fri Jul 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.34-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Apr 13 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-1
- 0.9.34
* Wed Apr 12 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.33-1
- 0.9.33
* Mon Apr 10 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.32-1
- 0.9.32
* Sun Apr 9 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.29-1
- 0.9.29
- Whitespace cleanup
- SPDX migration
* Fri Jan 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.28-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Mon Aug 08 2022 Vít Ondruch <vondruch@redhat.com> - 0.9.28-1
- Update to YARD 0.9.28.
Resolves: rhbz#2027537
Resolves: rhbz#2113713
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Fri Jan 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Apr 06 2021 Vít Ondruch <vondruch@redhat.com> - 0.9.26-3
- Add `BR: rubygem(irb)`, which was previosly pulled in indirectly.
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Fri Dec 18 02:42:33 CET 2020 Pavel Valena <pvalena@redhat.com> - 0.9.26-1
- Update to yard 0.9.26.
Resolves: rhbz#1830795
- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_3.0
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.24-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Tue Feb 04 2020 Vít Ondruch <vondruch@redhat.com> - 0.9.24-1
- Update to YARD 0.9.24.
* Thu Jan 30 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Fri Jul 26 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Sat Feb 02 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Thu Mar 29 2018 Vít Ondruch <vondruch@redhat.com> - 0.9.12-3
- Fix FTBFS due to failing test suite (rhbz#1556422).
* Fri Feb 09 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Fri Dec 01 2017 Vít Ondruch <vondruch@redhat.com> - 0.9.12-1
- Update to YARD 0.9.12.
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.8-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Mon Jan 30 2017 Vít Ondruch <vondruch@redhat.com> - 0.9.8-1
- Update to YARD 0.9.8.
* Fri Dec 01 2017 Vít Ondruch <vondruch@redhat.com> - 0.8.7.6-4
- Fix to directory traversal attacks (CVE-2017-17042).
* Wed May 25 2016 Jun Aruga <jaruga@redhat.com> - 0.8.7.6-3
- Fix test suite for Ruby 2.3 compatibility. (rhbz#1308100)

View file

@ -1,2 +1 @@
SHA512 (yard-0.9.38.gem) = af69f50fb7ce065adc8b387c93327ee9001fd2526ddce9381d883c4aa9f1518e895a2128623956210509c2c0528700cab91c4fcb30c0c88802e9007d5c5b43f2
SHA512 (yard-0.9.38-test-missing-files.tar.gz) = 08084b435ebbccf7fb85707c243d7a6e5be21f09188b05ebe50e41b897e34cb32d2310423567a89aef205ef2db5bfdfa7e334a1f2f61013132112331bce6df08
55559a424c6bc58cba9a8affdbc86dc9 yard-0.8.7.6.gem

View file

@ -1,16 +0,0 @@
diff --git a/spec/tags/types_explainer_spec.rb b/spec/tags/types_explainer_spec.rb
index de7454d3..5eb72d47 100644
--- a/spec/tags/types_explainer_spec.rb
+++ b/spec/tags/types_explainer_spec.rb
@@ -5,10 +5,9 @@ RSpec.describe YARD::Tags::TypesExplainer do
CollectionType = YARD::Tags::TypesExplainer::CollectionType
FixedCollectionType = YARD::Tags::TypesExplainer::FixedCollectionType
HashCollectionType = YARD::Tags::TypesExplainer::HashCollectionType
- Parser = YARD::Tags::TypesExplainer::Parser
def parse(types)
- Parser.new(types).parse
+ YARD::Tags::TypesExplainer::Parser.new(types).parse
end
def parse_fail(types)

View file

@ -1,35 +0,0 @@
#!/bin/bash
usage() {
echo "$0 <VERSION>"
}
set -e
set -x
if [ $# -lt 1 ] ; then
usage
exit 1
fi
VERSION=$1
GEMNAME=yard
TMPDIR=$(mktemp -d /tmp/${GEMNAME}-XXXXXX)
CURDIR=$(pwd)
GITTOPDIR=${GEMNAME}-${VERSION}
pushd $TMPDIR
git clone http://github.com/lsegal/${GEMNAME} ${GITTOPDIR}
cd ${GEMNAME}-$VERSION
git checkout -b fedora-$VERSION v$VERSION
cd ..
tar czf $CURDIR/${GEMNAME}-${VERSION}-test-missing-files.tar.gz \
${GITTOPDIR}/spec/ \
popd
rm -rf $TMPDIR