Compare commits

..

1 commit

Author SHA1 Message Date
Vít Ondruch
a1f325a3e9 Fix to directory traversal attacks (CVE-2017-17042). 2017-12-01 20:09:47 +01:00
8 changed files with 240 additions and 243 deletions

13
.gitignore vendored
View file

@ -1,3 +1,10 @@
/yard-*.gem
/yard-*-spec.txz
/yard-*-test-missing-files.tar.gz
yard-0.5.3.gem
/yard-0.7.2.gem
/yard-0.7.4.gem
/yard-0.8.1.gem
/yard-0.8.2.1.gem
/yard-0.8.5.2.gem
/yard-0.8.7.gem
/yard-0.8.7.4.gem
/yard-0.8.7.6.gem
/yard-0.9.8.gem

View file

@ -0,0 +1,46 @@
From 2d1e9f3b7696a45ed8e48a624a33d662cb99e5cb Mon Sep 17 00:00:00 2001
From: Tim Bellefleur <nomoon@phoebus.ca>
Date: Thu, 12 Jan 2017 17:14:47 -0800
Subject: [PATCH] Replace deprecated TRUE and FALSE constants with their
equivalents.
---
lib/yard/parser/ruby/legacy/ruby_lex.rb | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/lib/yard/parser/ruby/legacy/ruby_lex.rb b/lib/yard/parser/ruby/legacy/ruby_lex.rb
index 0ddda80..412b2d0 100644
--- a/lib/yard/parser/ruby/legacy/ruby_lex.rb
+++ b/lib/yard/parser/ruby/legacy/ruby_lex.rb
@@ -599,7 +599,7 @@ def lex_init()
end
@OP.def_rules(" ", "\t", "\f", "\r", "\13") do |chars, _io|
- @space_seen = TRUE
+ @space_seen = true
while (ch = getc) =~ /[ \t\f\r\13]/
chars << ch
end
@@ -642,9 +642,9 @@ def lex_init()
@colonblock_seen = false
case @lex_state
when EXPR_BEG, EXPR_FNAME, EXPR_DOT
- @continue = TRUE
+ @continue = true
else
- @continue = FALSE
+ @continue = false
@lex_state = EXPR_BEG
end
Token(TkNL).set_text("\n")
@@ -1166,8 +1166,8 @@ def identify_number(start)
end
type = TkINTEGER
- allow_point = TRUE
- allow_e = TRUE
+ allow_point = true
+ allow_e = true
while ch = getc
case ch
when /[0-9_]/

View file

@ -0,0 +1,48 @@
From b0217b3e30dc53d057b1682506333335975e62b4 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 23 Nov 2017 13:34:33 -0800
Subject: [PATCH] Disallow relative paths that start with ../
Fixes a potential arbitrary file read vulnerability in yard server.
Thanks to ztz <ztz@ztz.me> for discovery of this security issue.
---
lib/yard/core_ext/file.rb | 2 ++
spec/core_ext/file_spec.rb | 6 +++---
2 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/lib/yard/core_ext/file.rb b/lib/yard/core_ext/file.rb
index 3902f2bd..a0b983e9 100644
--- a/lib/yard/core_ext/file.rb
+++ b/lib/yard/core_ext/file.rb
@@ -40,6 +40,8 @@ class File
if comp == RELATIVE_PARENTDIR && !acc.empty? && acc.last != RELATIVE_PARENTDIR
acc.pop
next acc
+ elsif comp == RELATIVE_PARENTDIR && acc.empty?
+ next acc
end
acc << comp
end
diff --git a/spec/core_ext/file_spec.rb b/spec/core_ext/file_spec.rb
index f61081f6..15806360 100644
--- a/spec/core_ext/file_spec.rb
+++ b/spec/core_ext/file_spec.rb
@@ -41,12 +41,12 @@ RSpec.describe File do
expect(File.cleanpath('A/B/C/D/..')).to eq "A/B/C"
end
- it "passes the initial directory" do
- expect(File.cleanpath('C/../../D')).to eq "../D"
+ it "does not allow relative path above root" do
+ expect(File.cleanpath('A/../../../../../D')).to eq "D"
end
it "does not remove multiple '../' at the beginning" do
- expect(File.cleanpath('../../A/B')).to eq '../../A/B'
+ expect(File.cleanpath('../../A/B')).to eq 'A/B'
end
end
--
2.15.1

View file

@ -0,0 +1,65 @@
From 3bcccf678040e827f706b8305456424aa83f6471 Mon Sep 17 00:00:00 2001
From: Loren Segal <lsegal@soen.ca>
Date: Thu, 23 Nov 2017 13:47:35 -0800
Subject: [PATCH] Fix broken tests
---
lib/yard/cli/yardoc.rb | 2 +-
lib/yard/core_ext/file.rb | 5 +++--
spec/core_ext/file_spec.rb | 4 ++++
3 files changed, 8 insertions(+), 3 deletions(-)
diff --git a/lib/yard/cli/yardoc.rb b/lib/yard/cli/yardoc.rb
index a2918a36..f40e4dd1 100644
--- a/lib/yard/cli/yardoc.rb
+++ b/lib/yard/cli/yardoc.rb
@@ -649,7 +649,7 @@ module YARD
opts.on('--asset FROM[:TO]', 'A file or directory to copy over to output ',
' directory after generating') do |asset|
re = %r{^(?:\.\./|/)}
- from, to = *asset.split(':').map {|f| File.cleanpath(f) }
+ from, to = *asset.split(':').map {|f| File.cleanpath(f, true) }
to ||= from
if from =~ re || to =~ re
log.warn "Invalid file '#{asset}'"
diff --git a/lib/yard/core_ext/file.rb b/lib/yard/core_ext/file.rb
index a0b983e9..c918b5af 100644
--- a/lib/yard/core_ext/file.rb
+++ b/lib/yard/core_ext/file.rb
@@ -32,15 +32,16 @@ class File
# @example Clean a path
# File.cleanpath('a/b//./c/../e') # => "a/b/e"
# @param [String] path the path to clean
+ # @param [Boolean] rel_root allows relative path above root value
# @return [String] the sanitized path
- def self.cleanpath(path)
+ def self.cleanpath(path, rel_root = false)
path = path.split(SEPARATOR)
path = path.inject([]) do |acc, comp|
next acc if comp == RELATIVE_SAMEDIR
if comp == RELATIVE_PARENTDIR && !acc.empty? && acc.last != RELATIVE_PARENTDIR
acc.pop
next acc
- elsif comp == RELATIVE_PARENTDIR && acc.empty?
+ elsif !rel_root && comp == RELATIVE_PARENTDIR && acc.empty?
next acc
end
acc << comp
diff --git a/spec/core_ext/file_spec.rb b/spec/core_ext/file_spec.rb
index 15806360..e3d3930c 100644
--- a/spec/core_ext/file_spec.rb
+++ b/spec/core_ext/file_spec.rb
@@ -41,6 +41,10 @@ RSpec.describe File do
expect(File.cleanpath('A/B/C/D/..')).to eq "A/B/C"
end
+ it "allows '../' at the beginning if rel_root=true" do
+ expect(File.cleanpath('A/../../B', true)).to eq '../B'
+ end
+
it "does not allow relative path above root" do
expect(File.cleanpath('A/../../../../../D')).to eq "D"
end
--
2.15.1

View file

@ -1,48 +1,30 @@
%global gem_name yard
%global gem_name yard
Name: rubygem-%{gem_name}
Version: 0.9.38
Release: 2%{?dist}
Summary: Documentation tool for consistent and usable documentation in Ruby
# lib/yard/parser/ruby/legacy/ruby_lex.rb: under GPL-2.0-only OR Ruby
# lib/yard/rubygems/backports/: MIT OR Ruby
# lib/yard/server/http_utils.rb: BSD 2-Clause
# lib/yard/server/templates/default/fulldoc/html/js/autocomplete.js:
# MIT OR GPL(version 2??), as this is OR, use MIT for now
# Others are MIT
# SPDX confirmed
License: MIT AND (MIT OR Ruby) AND BSD-2-Clause AND (GPL-2.0-only OR Ruby)
URL: http://yardoc.org
Source0: https://rubygems.org/gems/%{gem_name}-%{version}.gem
Source1: %{gem_name}-%{version}-test-missing-files.tar.gz
# Source1 is created by $ bash %%SOURCE2 %%version
Source2: yard-create-missing-test-files.sh
# https://github.com/lsegal/yard/issues/1637
# Fix spec testsuite with namespace collision
Patch0: yard-0.9.38-issue1637-spec-namespace-collision.patch
# The 'irb/notifier' might be required for parsing of some old Ruby code.
# https://github.com/lsegal/yard/blob/v0.9.24/lib/yard/parser/ruby/legacy/irb/slex.rb#L13
Recommends: rubygem(irb)
BuildRequires: ruby(release)
BuildRequires: rubygems-devel
BuildRequires: ruby
BuildRequires: rubygem(RedCloth)
BuildRequires: rubygem(asciidoctor)
BuildRequires: rubygem(bundler)
BuildRequires: rubygem(irb)
BuildRequires: rubygem(rack)
BuildRequires: /usr/bin/rackup
BuildRequires: rubygem(rake)
BuildRequires: rubygem(redcarpet)
BuildRequires: rubygem(rspec)
BuildRequires: rubygem(webrick)
BuildArch: noarch
Name: rubygem-%{gem_name}
Version: 0.9.8
Release: 4%{?dist}
Summary: Documentation tool for consistent and usable documentation in Ruby
Group: Development/Languages
License: MIT and (BSD or Ruby)
URL: http://yardoc.org
Source0: https://rubygems.org/gems/%{gem_name}-%{version}.gem
# Fix depracation warnings.
# https://github.com/lsegal/yard/pull/1057
# https://github.com/lsegal/yard/commit/2d1e9f3b7696a45ed8e48a624a33d662cb99e5cb
Patch0: pry-0.9.8-Replace-deprecated-TRUE-and-FALSE-constants-with-their-equivalents.patch
# Fix to directory traversal attacks (CVE-2017-17042)
# https://github.com/lsegal/yard/commit/b0217b3e30dc53d057b1682506333335975e62b4
Patch1: rubygem-yard-0.9.11-Disallow-relative-paths-that-start-with.patch
# https://github.com/lsegal/yard/commit/3bcccf678040e827f706b8305456424aa83f6471
Patch2: rubygem-yard-0.9.11-Fix-broken-tests.patch
BuildRequires: ruby(release)
BuildRequires: rubygems-devel
BuildRequires: ruby
BuildRequires: rubygem(RedCloth)
BuildRequires: rubygem(rspec)
BuildRequires: rubygem(redcarpet)
BuildRequires: rubygem(rack)
BuildArch: noarch
%description
YARD is a documentation generation tool for the Ruby programming language.
@ -51,178 +33,79 @@ exported to a number of formats very easily, and also supports extending for
custom Ruby constructs such as custom class level definitions.
%package doc
Summary: Documentation for %{name}
Requires: %{name} = %{version}-%{release}
BuildArch: noarch
%package doc
Summary: Documentation for %{name}
Group: Documentation
Requires: %{name} = %{version}-%{release}
BuildArch: noarch
%description doc
Documentation for %{name}.
%prep
%setup -q -n %{gem_name}-%{version} -b1
%patch -P0 -p1
mv ../%{gem_name}-%{version}.gemspec .
%setup -q -T -c
%gem_install -n %{SOURCE0}
pushd .%{gem_instdir}
%patch0 -p1
%patch1 -p1
%patch2 -p1
popd
%build
gem build ./%{gem_name}-%{version}.gemspec
%gem_install
%install
mkdir -p %{buildroot}%{gem_dir}
cp -a .%{gem_dir}/* \
%{buildroot}%{gem_dir}/
%{buildroot}%{gem_dir}/
pushd %{buildroot}%{gem_instdir}
rm -rf .yardopts* \
%{nil}
popd
mkdir -p %{buildroot}%{_bindir}
cp -a .%{_bindir}/* \
%{buildroot}%{_bindir}/
cp -pa .%{_bindir}/* \
%{buildroot}%{_bindir}/
find %{buildroot}%{gem_instdir}/bin -type f | xargs chmod 0755
rm -f %{buildroot}%{gem_cache}
find %{buildroot}%{gem_instdir}/bin -type f | xargs chmod a+x
%check
# FIXME
# investigate this: was okay with yard 0.9.28
sed -i spec/cli/diff_spec.rb \
-e '\@"searches for .gem file"@s|\([ \t]it \)|\txit |'
rspec -r spec_helper spec
pushd .%{gem_instdir}
# Not sure if this is needed, since bundler is not user or because Fedora
# provides more recent RSpec :/
sed -i '/allow(File)\.to receive(:exist?).with(\/\\\.yardopts$\/)/ i\ allow(File).to receive(:exist?).and_return(true)' spec/cli/server_spec.rb
rspec -rspec_helper spec
popd
%files
%dir %{gem_instdir}
%license %{gem_instdir}/LEGAL
%license %{gem_instdir}/LICENSE
%doc %{gem_instdir}/CHANGELOG.md
%doc %{gem_instdir}/README.md
%dir %{gem_instdir}
%{_bindir}/yard
%{_bindir}/yardoc
%{_bindir}/yri
%{gem_libdir}/
%exclude %{gem_instdir}/.yardopts
%license %{gem_instdir}/LEGAL
%license %{gem_instdir}/LICENSE
%{gem_instdir}/bin
%{gem_instdir}/po/
%{gem_instdir}/templates/
%{gem_libdir}
%{gem_instdir}/templates
%exclude %{gem_cache}
%{gem_spec}
%{?gem_plugin}
%files doc
%doc %{gem_docdir}
%doc %{gem_instdir}/docs/
%doc %{gem_docdir}
%doc %{gem_instdir}/CHANGELOG.md
%doc %{gem_instdir}/README.md
%{gem_instdir}/Rakefile
%{gem_instdir}/benchmarks
%doc %{gem_instdir}/docs
%{gem_instdir}/spec
%{gem_instdir}/%{gem_name}.gemspec
%changelog
* Fri Jan 02 2026 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.38-2
- Fix spec testsuite failure with namespace collision
* Mon Dec 08 2025 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.38-1
- 0.9.38
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.37-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jun 10 2025 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.37-3
- BR: /usr/bin/rackup for rack / rackup gem split (bug 2371181)
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.37-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Sep 05 2024 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.37-1
- 0.9.37
* Fri Jul 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.36-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Fri Mar 01 2024 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.36-1
- 0.9.36 (Fixes CVE-2024-27285)
* Fri Jan 26 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.34-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Nov 10 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-4
- Testsuite: remove invalid yield usage from spec (for ruby3.3)
* Mon Sep 25 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-3
- Backport upstream patch for BOM detection change in ruby33
* Fri Jul 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.34-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Apr 13 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.34-1
- 0.9.34
* Wed Apr 12 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.33-1
- 0.9.33
* Mon Apr 10 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.32-1
- 0.9.32
* Sun Apr 9 2023 Mamoru TASAKA <mtasaka@fedoraproject.org> - 0.9.29-1
- 0.9.29
- Whitespace cleanup
- SPDX migration
* Fri Jan 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.28-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Mon Aug 08 2022 Vít Ondruch <vondruch@redhat.com> - 0.9.28-1
- Update to YARD 0.9.28.
Resolves: rhbz#2027537
Resolves: rhbz#2113713
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Fri Jan 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Apr 06 2021 Vít Ondruch <vondruch@redhat.com> - 0.9.26-3
- Add `BR: rubygem(irb)`, which was previosly pulled in indirectly.
* Wed Jan 27 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.26-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Fri Dec 18 02:42:33 CET 2020 Pavel Valena <pvalena@redhat.com> - 0.9.26-1
- Update to yard 0.9.26.
Resolves: rhbz#1830795
- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_3.0
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.24-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Tue Feb 04 2020 Vít Ondruch <vondruch@redhat.com> - 0.9.24-1
- Update to YARD 0.9.24.
* Thu Jan 30 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Fri Jul 26 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Sat Feb 02 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Thu Mar 29 2018 Vít Ondruch <vondruch@redhat.com> - 0.9.12-3
- Fix FTBFS due to failing test suite (rhbz#1556422).
* Fri Feb 09 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.12-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Fri Dec 01 2017 Vít Ondruch <vondruch@redhat.com> - 0.9.12-1
- Update to YARD 0.9.12.
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.8-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Dec 01 2017 Vít Ondruch <vondruch@redhat.com> - 0.9.8-4
- Fix to directory traversal attacks (CVE-2017-17042).
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.9.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild

View file

@ -1,2 +1 @@
SHA512 (yard-0.9.38.gem) = af69f50fb7ce065adc8b387c93327ee9001fd2526ddce9381d883c4aa9f1518e895a2128623956210509c2c0528700cab91c4fcb30c0c88802e9007d5c5b43f2
SHA512 (yard-0.9.38-test-missing-files.tar.gz) = 08084b435ebbccf7fb85707c243d7a6e5be21f09188b05ebe50e41b897e34cb32d2310423567a89aef205ef2db5bfdfa7e334a1f2f61013132112331bce6df08
SHA512 (yard-0.9.8.gem) = e27aaae008b92cc40a4be327c03b721884443ac6ecdeba7066ad1377c5a0037f56e0495eda4c1a83948308af124d6d2029d829a97e09b8629c7af5710c06c94c

View file

@ -1,16 +0,0 @@
diff --git a/spec/tags/types_explainer_spec.rb b/spec/tags/types_explainer_spec.rb
index de7454d3..5eb72d47 100644
--- a/spec/tags/types_explainer_spec.rb
+++ b/spec/tags/types_explainer_spec.rb
@@ -5,10 +5,9 @@ RSpec.describe YARD::Tags::TypesExplainer do
CollectionType = YARD::Tags::TypesExplainer::CollectionType
FixedCollectionType = YARD::Tags::TypesExplainer::FixedCollectionType
HashCollectionType = YARD::Tags::TypesExplainer::HashCollectionType
- Parser = YARD::Tags::TypesExplainer::Parser
def parse(types)
- Parser.new(types).parse
+ YARD::Tags::TypesExplainer::Parser.new(types).parse
end
def parse_fail(types)

View file

@ -1,35 +0,0 @@
#!/bin/bash
usage() {
echo "$0 <VERSION>"
}
set -e
set -x
if [ $# -lt 1 ] ; then
usage
exit 1
fi
VERSION=$1
GEMNAME=yard
TMPDIR=$(mktemp -d /tmp/${GEMNAME}-XXXXXX)
CURDIR=$(pwd)
GITTOPDIR=${GEMNAME}-${VERSION}
pushd $TMPDIR
git clone http://github.com/lsegal/${GEMNAME} ${GITTOPDIR}
cd ${GEMNAME}-$VERSION
git checkout -b fedora-$VERSION v$VERSION
cd ..
tar czf $CURDIR/${GEMNAME}-${VERSION}-test-missing-files.tar.gz \
${GITTOPDIR}/spec/ \
popd
rm -rf $TMPDIR