Compare commits

..

1 commit

Author SHA1 Message Date
Vít Ondruch
cb20b20f7c Fix to directory traversal attacks (CVE-2017-17042). 2017-12-01 20:52:33 +01:00
8 changed files with 215 additions and 249 deletions

12
.gitignore vendored
View file

@ -1,3 +1,9 @@
/yard-*.gem yard-0.5.3.gem
/yard-*-spec.txz /yard-0.7.2.gem
/yard-*-test-missing-files.tar.gz /yard-0.7.4.gem
/yard-0.8.1.gem
/yard-0.8.2.1.gem
/yard-0.8.5.2.gem
/yard-0.8.7.gem
/yard-0.8.7.4.gem
/yard-0.8.7.6.gem

View file

@ -0,0 +1,23 @@
From afbcbc18efbf56ae81842094c78ac6ad218e9922 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 14 Apr 2016 23:52:09 -0700
Subject: [PATCH] Fix brittle test on Ruby 2.3
Fixes #927
---
spec/parser/ruby/ruby_parser_spec.rb | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/spec/parser/ruby/ruby_parser_spec.rb b/spec/parser/ruby/ruby_parser_spec.rb
index 6e5bd89..07d7212 100644
--- a/spec/parser/ruby/ruby_parser_spec.rb
+++ b/spec/parser/ruby/ruby_parser_spec.rb
@@ -351,7 +351,7 @@ eof
# end comment
end
eof
- comment = ast.first.last.first
+ comment = ast.first.last.jump(:comment)
comment.type.should == :comment
comment.docstring_hash_flag.should be_true
comment.docstring.strip.should == "comment here"

View file

@ -0,0 +1,48 @@
From b0217b3e30dc53d057b1682506333335975e62b4 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 23 Nov 2017 13:34:33 -0800
Subject: [PATCH] Disallow relative paths that start with ../
Fixes a potential arbitrary file read vulnerability in yard server.
Thanks to ztz <ztz@ztz.me> for discovery of this security issue.
---
lib/yard/core_ext/file.rb | 2 ++
spec/core_ext/file_spec.rb | 6 +++---
2 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/lib/yard/core_ext/file.rb b/lib/yard/core_ext/file.rb
index 3902f2bd..a0b983e9 100644
--- a/lib/yard/core_ext/file.rb
+++ b/lib/yard/core_ext/file.rb
@@ -39,6 +39,8 @@ class File
if comp == RELATIVE_PARENTDIR && acc.size > 0 && acc.last != RELATIVE_PARENTDIR
acc.pop
next acc
+ elsif comp == RELATIVE_PARENTDIR && acc.empty?
+ next acc
end
acc << comp
end
diff --git a/spec/core_ext/file_spec.rb b/spec/core_ext/file_spec.rb
index f61081f6..15806360 100644
--- a/spec/core_ext/file_spec.rb
+++ b/spec/core_ext/file_spec.rb
@@ -41,12 +41,12 @@ RSpec.describe File do
File.cleanpath('A/B/C/D/..').should == "A/B/C"
end
- it "should pass the initial directory" do
- File.cleanpath('C/../../D').should == "../D"
+ it "does not allow relative path above root" do
+ File.cleanpath('A/../../../../../D').should == "D"
end
it "should not remove multiple '../' at the beginning" do
- File.cleanpath('../../A/B').should == '../../A/B'
+ File.cleanpath('../../A/B').should == 'A/B'
end
end
--
2.15.1

View file

@ -0,0 +1,65 @@
From 3bcccf678040e827f706b8305456424aa83f6471 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 23 Nov 2017 13:47:35 -0800
Subject: [PATCH] Fix broken tests
---
lib/yard/cli/yardoc.rb | 2 +-
lib/yard/core_ext/file.rb | 5 +++--
spec/core_ext/file_spec.rb | 4 ++++
3 files changed, 8 insertions(+), 3 deletions(-)
diff --git a/lib/yard/cli/yardoc.rb b/lib/yard/cli/yardoc.rb
index a2918a36..f40e4dd1 100644
--- a/lib/yard/cli/yardoc.rb
+++ b/lib/yard/cli/yardoc.rb
@@ -640,7 +640,7 @@ module YARD
opts.on('--asset FROM[:TO]', 'A file or directory to copy over to output ',
' directory after generating') do |asset|
re = /^(?:\.\.\/|\/)/
- from, to = *asset.split(':').map {|f| File.cleanpath(f) }
+ from, to = *asset.split(':').map {|f| File.cleanpath(f, true) }
to ||= from
if from =~ re || to =~ re
log.warn "Invalid file '#{asset}'"
diff --git a/lib/yard/core_ext/file.rb b/lib/yard/core_ext/file.rb
index a0b983e9..c918b5af 100644
--- a/lib/yard/core_ext/file.rb
+++ b/lib/yard/core_ext/file.rb
@@ -31,15 +31,16 @@ class File
# @example Clean a path
# File.cleanpath('a/b//./c/../e') # => "a/b/e"
# @param [String] path the path to clean
+ # @param [Boolean] rel_root allows relative path above root value
# @return [String] the sanitized path
- def self.cleanpath(path)
+ def self.cleanpath(path, rel_root = false)
path = path.split(SEPARATOR)
path = path.inject([]) do |acc, comp|
next acc if comp == RELATIVE_SAMEDIR
if comp == RELATIVE_PARENTDIR && acc.size > 0 && acc.last != RELATIVE_PARENTDIR
acc.pop
next acc
- elsif comp == RELATIVE_PARENTDIR && acc.empty?
+ elsif !rel_root && comp == RELATIVE_PARENTDIR && acc.empty?
next acc
end
acc << comp
diff --git a/spec/core_ext/file_spec.rb b/spec/core_ext/file_spec.rb
index 15806360..e3d3930c 100644
--- a/spec/core_ext/file_spec.rb
+++ b/spec/core_ext/file_spec.rb
@@ -41,6 +41,10 @@ RSpec.describe File do
File.cleanpath('A/B/C/D/..').should == "A/B/C"
end
+ it "allows '../' at the beginning if rel_root=true" do
+ expect(File.cleanpath('A/../../B', true)).to eq '../B'
+ end
+
it "does not allow relative path above root" do
File.cleanpath('A/../../../../../D').should == "D"
end
--
2.15.1

View file

@ -1,49 +1,31 @@
%global gem_name yard %global gem_name yard
Name: rubygem-%{gem_name} Name: rubygem-%{gem_name}
Version: 0.9.38 Version: 0.8.7.6
Release: 2%{?dist} Release: 4%{?dist}
Summary: Documentation tool for consistent and usable documentation in Ruby Summary: Documentation tool for consistent and usable documentation in Ruby
Group: Development/Languages
# lib/yard/parser/ruby/legacy/ruby_lex.rb: under GPL-2.0-only OR Ruby License: MIT and (BSD or Ruby)
# lib/yard/rubygems/backports/: MIT OR Ruby
# lib/yard/server/http_utils.rb: BSD 2-Clause
# lib/yard/server/templates/default/fulldoc/html/js/autocomplete.js:
# MIT OR GPL(version 2??), as this is OR, use MIT for now
# Others are MIT
# SPDX confirmed
License: MIT AND (MIT OR Ruby) AND BSD-2-Clause AND (GPL-2.0-only OR Ruby)
URL: http://yardoc.org URL: http://yardoc.org
Source0: https://rubygems.org/gems/%{gem_name}-%{version}.gem Source0: https://rubygems.org/gems/%{gem_name}-%{version}.gem
Source1: %{gem_name}-%{version}-test-missing-files.tar.gz # Fix to directory traversal attacks (CVE-2017-17042)
# Source1 is created by $ bash %%SOURCE2 %%version # https://github.com/lsegal/yard/commit/b0217b3e30dc53d057b1682506333335975e62b4
Source2: yard-create-missing-test-files.sh Patch1: rubygem-yard-0.9.11-Disallow-relative-paths-that-start-with.patch
# https://github.com/lsegal/yard/issues/1637 # https://github.com/lsegal/yard/commit/3bcccf678040e827f706b8305456424aa83f6471
# Fix spec testsuite with namespace collision Patch2: rubygem-yard-0.9.11-Fix-broken-tests.patch
Patch0: yard-0.9.38-issue1637-spec-namespace-collision.patch
# The 'irb/notifier' might be required for parsing of some old Ruby code.
# https://github.com/lsegal/yard/blob/v0.9.24/lib/yard/parser/ruby/legacy/irb/slex.rb#L13
Recommends: rubygem(irb)
BuildRequires: ruby(release) BuildRequires: ruby(release)
BuildRequires: rubygems-devel BuildRequires: rubygems-devel
BuildRequires: ruby BuildRequires: ruby
BuildRequires: rubygem(RedCloth) BuildRequires: rubygem(RedCloth)
BuildRequires: rubygem(asciidoctor) BuildRequires: rubygem(rspec) < 3
BuildRequires: rubygem(bundler)
BuildRequires: rubygem(irb)
BuildRequires: rubygem(rack)
BuildRequires: /usr/bin/rackup
BuildRequires: rubygem(rake)
BuildRequires: rubygem(redcarpet) BuildRequires: rubygem(redcarpet)
BuildRequires: rubygem(rspec) BuildRequires: rubygem(rack)
BuildRequires: rubygem(webrick)
BuildArch: noarch BuildArch: noarch
# Fix test suite in Ruby 2.3.
# https://github.com/lsegal/yard/commit/afbcbc1.patch
Patch0: rubygem-yard-0.8.7.6-fix-test-for-ruby-2.3.patch
%description %description
YARD is a documentation generation tool for the Ruby programming language. YARD is a documentation generation tool for the Ruby programming language.
It enables the user to generate consistent, usable documentation that can be It enables the user to generate consistent, usable documentation that can be
@ -53,6 +35,7 @@ custom Ruby constructs such as custom class level definitions.
%package doc %package doc
Summary: Documentation for %{name} Summary: Documentation for %{name}
Group: Documentation
Requires: %{name} = %{version}-%{release} Requires: %{name} = %{version}-%{release}
BuildArch: noarch BuildArch: noarch
@ -60,175 +43,68 @@ BuildArch: noarch
Documentation for %{name}. Documentation for %{name}.
%prep %prep
%setup -q -n %{gem_name}-%{version} -b1 %setup -q -T -c
%patch -P0 -p1 %gem_install -n %{SOURCE0}
mv ../%{gem_name}-%{version}.gemspec .
pushd .%{gem_instdir}
%patch1 -p1
%patch2 -p1
popd
%build %build
gem build ./%{gem_name}-%{version}.gemspec
%gem_install
%install %install
mkdir -p %{buildroot}%{gem_dir} mkdir -p %{buildroot}%{gem_dir}
cp -a .%{gem_dir}/* \ cp -a .%{gem_dir}/* \
%{buildroot}%{gem_dir}/ %{buildroot}%{gem_dir}/
pushd %{buildroot}%{gem_instdir}
rm -rf .yardopts* \
%{nil}
popd
mkdir -p %{buildroot}%{_bindir} mkdir -p %{buildroot}%{_bindir}
cp -a .%{_bindir}/* \ cp -a .%{_bindir}/* \
%{buildroot}%{_bindir}/ %{buildroot}%{_bindir}/
find %{buildroot}%{gem_instdir}/bin -type f | xargs chmod 0755 find %{buildroot}%{gem_instdir}/bin -type f | xargs chmod a+x
rm -f %{buildroot}%{gem_cache}
%check %check
# FIXME pushd .%{gem_instdir}
# investigate this: was okay with yard 0.9.28 # Not sure if this is needed, since bundler is not user or because Fedora
sed -i spec/cli/diff_spec.rb \ # provides more recent RSpec :/
-e '\@"searches for .gem file"@s|\([ \t]it \)|\txit |' sed -i '/File\.stub(:exist?).with(\/\\\.yardopts$\/)/ i\ File.stub(:exist?).and_return(true)' spec/cli/server_spec.rb
rspec -r spec_helper spec
patch -p1 < %{PATCH0}
rspec2 spec
popd
%files %files
%dir %{gem_instdir}
%license %{gem_instdir}/LEGAL
%license %{gem_instdir}/LICENSE
%doc %{gem_instdir}/CHANGELOG.md
%doc %{gem_instdir}/README.md
%{_bindir}/yard
%{_bindir}/yardoc %{_bindir}/yardoc
%{_bindir}/yri %{_bindir}/yri
%{_bindir}/yard
%{gem_libdir}/ %dir %{gem_instdir}
%{gem_instdir}/bin %{gem_instdir}/bin
%{gem_instdir}/po/ %{gem_libdir}
%{gem_instdir}/templates/ %{gem_instdir}/templates
%exclude %{gem_instdir}/.yardopts
%doc %{gem_instdir}/LEGAL
%exclude %{gem_cache}
%{gem_spec} %{gem_spec}
%{?gem_plugin}
%license %{gem_instdir}/LICENSE
%files doc %files doc
%doc %{gem_docdir} %doc %{gem_docdir}
%doc %{gem_instdir}/docs/ %doc %{gem_instdir}/CHANGELOG.md
%doc %{gem_instdir}/README.md
%{gem_instdir}/Rakefile
%{gem_instdir}/%{gem_name}.gemspec
%{gem_instdir}/benchmarks
%{gem_instdir}/spec
%doc %{gem_instdir}/docs
%changelog %changelog
* Fri Jan 02 2026 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.38-2 * Fri Dec 01 2017 Vít Ondruch <vondruch@redhat.com> - 0.8.7.6-4
- Fix spec testsuite failure with namespace collision - Fix to directory traversal attacks (CVE-2017-17042).
* Mon Dec 08 2025 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.38-1
- 0.9.38
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.37-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jun 10 2025 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.37-3
- BR: /usr/bin/rackup for rack / rackup gem split (bug 2371181)
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.37-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Sep 05 2024 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.37-1
- 0.9.37
* Fri Jul 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.36-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Fri Mar 01 2024 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.36-1
- 0.9.36 (Fixes CVE-2024-27285)
* Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.34-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Nov 10 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-4
- Testsuite: remove invalid yield usage from spec (for ruby3.3)
* Mon Sep 25 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-3
- Backport upstream patch for BOM detection change in ruby33
* Fri Jul 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.34-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Apr 13 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-1
- 0.9.34
* Wed Apr 12 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.33-1
- 0.9.33
* Mon Apr 10 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.32-1
- 0.9.32
* Sun Apr 9 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.29-1
- 0.9.29
- Whitespace cleanup
- SPDX migration
* Fri Jan 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.28-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Mon Aug 08 2022 Vít Ondruch <vondruch@redhat.com> - 0.9.28-1
- Update to YARD 0.9.28.
Resolves: rhbz#2027537
Resolves: rhbz#2113713
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Fri Jan 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Apr 06 2021 Vít Ondruch <vondruch@redhat.com> - 0.9.26-3
- Add `BR: rubygem(irb)`, which was previosly pulled in indirectly.
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Fri Dec 18 02:42:33 CET 2020 Pavel Valena <pvalena@redhat.com> - 0.9.26-1
- Update to yard 0.9.26.
Resolves: rhbz#1830795
- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_3.0
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.24-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Tue Feb 04 2020 Vít Ondruch <vondruch@redhat.com> - 0.9.24-1
- Update to YARD 0.9.24.
* Thu Jan 30 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Fri Jul 26 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Sat Feb 02 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Thu Mar 29 2018 Vít Ondruch <vondruch@redhat.com> - 0.9.12-3
- Fix FTBFS due to failing test suite (rhbz#1556422).
* Fri Feb 09 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Fri Dec 01 2017 Vít Ondruch <vondruch@redhat.com> - 0.9.12-1
- Update to YARD 0.9.12.
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.8-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Mon Jan 30 2017 Vít Ondruch <vondruch@redhat.com> - 0.9.8-1
- Update to YARD 0.9.8.
* Wed May 25 2016 Jun Aruga <jaruga@redhat.com> - 0.8.7.6-3 * Wed May 25 2016 Jun Aruga <jaruga@redhat.com> - 0.8.7.6-3
- Fix test suite for Ruby 2.3 compatibility. (rhbz#1308100) - Fix test suite for Ruby 2.3 compatibility. (rhbz#1308100)

View file

@ -1,2 +1 @@
SHA512 (yard-0.9.38.gem) = af69f50fb7ce065adc8b387c93327ee9001fd2526ddce9381d883c4aa9f1518e895a2128623956210509c2c0528700cab91c4fcb30c0c88802e9007d5c5b43f2 55559a424c6bc58cba9a8affdbc86dc9 yard-0.8.7.6.gem
SHA512 (yard-0.9.38-test-missing-files.tar.gz) = 08084b435ebbccf7fb85707c243d7a6e5be21f09188b05ebe50e41b897e34cb32d2310423567a89aef205ef2db5bfdfa7e334a1f2f61013132112331bce6df08

View file

@ -1,16 +0,0 @@
diff --git a/spec/tags/types_explainer_spec.rb b/spec/tags/types_explainer_spec.rb
index de7454d3..5eb72d47 100644
--- a/spec/tags/types_explainer_spec.rb
+++ b/spec/tags/types_explainer_spec.rb
@@ -5,10 +5,9 @@ RSpec.describe YARD::Tags::TypesExplainer do
CollectionType = YARD::Tags::TypesExplainer::CollectionType
FixedCollectionType = YARD::Tags::TypesExplainer::FixedCollectionType
HashCollectionType = YARD::Tags::TypesExplainer::HashCollectionType
- Parser = YARD::Tags::TypesExplainer::Parser
def parse(types)
- Parser.new(types).parse
+ YARD::Tags::TypesExplainer::Parser.new(types).parse
end
def parse_fail(types)

View file

@ -1,35 +0,0 @@
#!/bin/bash
usage() {
echo "$0 <VERSION>"
}
set -e
set -x
if [ $# -lt 1 ] ; then
usage
exit 1
fi
VERSION=$1
GEMNAME=yard
TMPDIR=$(mktemp -d /tmp/${GEMNAME}-XXXXXX)
CURDIR=$(pwd)
GITTOPDIR=${GEMNAME}-${VERSION}
pushd $TMPDIR
git clone http://github.com/lsegal/${GEMNAME} ${GITTOPDIR}
cd ${GEMNAME}-$VERSION
git checkout -b fedora-$VERSION v$VERSION
cd ..
tar czf $CURDIR/${GEMNAME}-${VERSION}-test-missing-files.tar.gz \
${GITTOPDIR}/spec/ \
popd
rm -rf $TMPDIR