Compare commits
5 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
80d325ee45 | ||
|
|
be9b6cae7c | ||
|
|
149f8182b2 | ||
|
|
ea1016d18a | ||
|
|
b023e49a91 |
8 changed files with 425 additions and 1 deletions
5
.gitignore
vendored
Normal file
5
.gitignore
vendored
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
uzbl-afc0f873e.tar.gz
|
||||
/uzbl-afc0f873e.tar.gz
|
||||
/uzbl-518004933.tar.gz
|
||||
/uzbl-8bbc39b83.tar.gz
|
||||
/uzbl-e7578e27c.tar.gz
|
||||
37
0001-Fedora-specific-error-messages-on-no-configs.patch
Normal file
37
0001-Fedora-specific-error-messages-on-no-configs.patch
Normal file
|
|
@ -0,0 +1,37 @@
|
|||
From fe8a23f0875e4daa8c506ebfeb6e65ae6775410b Mon Sep 17 00:00:00 2001
|
||||
From: Ben Boeckel <MathStuf@gmail.com>
|
||||
Date: Sat, 2 Oct 2010 16:57:33 -0400
|
||||
Subject: [PATCH] Fedora-specific error messages on no configs
|
||||
|
||||
---
|
||||
src/uzbl-browser | 14 +++++++++++++-
|
||||
1 files changed, 13 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/src/uzbl-browser b/src/uzbl-browser
|
||||
index 88d3742..61a2f56 100755
|
||||
--- a/src/uzbl-browser
|
||||
+++ b/src/uzbl-browser
|
||||
@@ -37,7 +37,19 @@ if [ ! -f "$XDG_CONFIG_HOME"/uzbl/config ]
|
||||
then
|
||||
if [ ! -r "$EXAMPLES"/config/config ]
|
||||
then
|
||||
- echo "Error: Global config not found; please check if your distribution ships them separately"
|
||||
+ text="Global config not found; please install the uzbl-defaults package"
|
||||
+ if [ -x zenity ]
|
||||
+ then
|
||||
+ zenity --error --text="$text"
|
||||
+ elif [ -x kdialog ]
|
||||
+ then
|
||||
+ kdialog --error "$text"
|
||||
+ elif [ -x Xdialog ]
|
||||
+ then
|
||||
+ Xdialog --msgbox "Error: $text"
|
||||
+ else
|
||||
+ echo "Error: $text"
|
||||
+ fi
|
||||
exit 3
|
||||
fi
|
||||
if ! cp "$EXAMPLES"/config/config "$XDG_CONFIG_HOME"/uzbl/config
|
||||
--
|
||||
1.7.3.2
|
||||
|
||||
|
|
@ -0,0 +1,79 @@
|
|||
From 0d747f8715f2b9d2acddda8748e0c3f838f197de Mon Sep 17 00:00:00 2001
|
||||
From: Luca Bruno <lucab@debian.org>
|
||||
Date: Sat, 11 Feb 2012 15:23:14 +0100
|
||||
Subject: [PATCH] Restrict third-party access to cookie jar (CVE-2012-0843)
|
||||
|
||||
Make sure new cookie jar is created with no permission for "others",
|
||||
and remove excessive rights on existing jar if any.
|
||||
This fixes CVE-2012-0843 and uzbl bug #291.
|
||||
|
||||
Signed-off-by: Luca Bruno <lucab@debian.org>
|
||||
---
|
||||
examples/data/plugins/cookies.py | 20 +++++++++++++++++++-
|
||||
1 files changed, 19 insertions(+), 1 deletions(-)
|
||||
|
||||
diff --git a/examples/data/plugins/cookies.py b/examples/data/plugins/cookies.py
|
||||
index e29ee36..721feef 100644
|
||||
--- a/examples/data/plugins/cookies.py
|
||||
+++ b/examples/data/plugins/cookies.py
|
||||
@@ -2,7 +2,7 @@
|
||||
forwards cookies to all other instances connected to the event manager"""
|
||||
|
||||
from collections import defaultdict
|
||||
-import os, re
|
||||
+import os, re, stat
|
||||
|
||||
# these are symbolic names for the components of the cookie tuple
|
||||
symbolic = {'domain': 0, 'path':1, 'name':2, 'value':3, 'scheme':4, 'expires':5}
|
||||
@@ -32,6 +32,14 @@ class ListStore(list):
|
||||
class TextStore(object):
|
||||
def __init__(self, filename):
|
||||
self.filename = filename
|
||||
+ try:
|
||||
+ # make sure existing cookie jar is not world-open
|
||||
+ perm_mode = os.stat(self.filename).st_mode
|
||||
+ if (perm_mode & (stat.S_IRWXO | stat.S_IRWXG)) > 0:
|
||||
+ safe_perm = stat.S_IMODE(perm_mode) & ~(stat.S_IRWXO | stat.S_IRWXG)
|
||||
+ os.chmod(self.filename, safe_perm)
|
||||
+ except OSError:
|
||||
+ pass
|
||||
|
||||
def as_event(self, cookie):
|
||||
"""Convert cookie.txt row to uzbls cookie event format"""
|
||||
@@ -76,16 +84,25 @@ class TextStore(object):
|
||||
# delete equal cookies (ignoring expire time, value and secure flag)
|
||||
self.delete_cookie(None, cookie[:-3])
|
||||
|
||||
+ # restrict umask before creating the cookie jar
|
||||
+ curmask=os.umask(0)
|
||||
+ os.umask(curmask| stat.S_IRWXO | stat.S_IRWXG)
|
||||
+
|
||||
first = not os.path.exists(self.filename)
|
||||
with open(self.filename, 'a') as f:
|
||||
if first:
|
||||
print >> f, "# HTTP Cookie File"
|
||||
print >> f, '\t'.join(self.as_file(cookie))
|
||||
+ os.umask(curmask)
|
||||
|
||||
def delete_cookie(self, rkey, key):
|
||||
if not os.path.exists(self.filename):
|
||||
return
|
||||
|
||||
+ # restrict umask before creating the cookie jar
|
||||
+ curmask=os.umask(0)
|
||||
+ os.umask(curmask | stat.S_IRWXO | stat.S_IRWXG)
|
||||
+
|
||||
# read all cookies
|
||||
with open(self.filename, 'r') as f:
|
||||
cookies = f.readlines()
|
||||
@@ -96,6 +113,7 @@ class TextStore(object):
|
||||
c = self.as_event(l.split('\t'))
|
||||
if c is None or not match(key, c):
|
||||
print >> f, l,
|
||||
+ os.umask(curmask)
|
||||
|
||||
xdg_data_home = os.environ.get('XDG_DATA_HOME', os.path.join(os.environ['HOME'], '.local/share'))
|
||||
DefaultStore = TextStore(os.path.join(xdg_data_home, 'uzbl/cookies.txt'))
|
||||
--
|
||||
1.7.9.1
|
||||
|
||||
|
|
@ -1 +0,0 @@
|
|||
requires webkit1 which has been retired
|
||||
1
sources
Normal file
1
sources
Normal file
|
|
@ -0,0 +1 @@
|
|||
5b09de34e57e7afde1b3ec66872d6144 uzbl-e7578e27c.tar.gz
|
||||
20
uzbl-makefile.patch
Normal file
20
uzbl-makefile.patch
Normal file
|
|
@ -0,0 +1,20 @@
|
|||
diff --git a/Makefile b/Makefile
|
||||
index 91b66b6..44e06a7 100644
|
||||
--- a/Makefile
|
||||
+++ b/Makefile
|
||||
@@ -124,14 +124,10 @@ install-dirs:
|
||||
|
||||
install-uzbl-core: all install-dirs
|
||||
install -d $(INSTALLDIR)/share/uzbl/
|
||||
- install -d $(DOCDIR)
|
||||
- install -m644 docs/* $(DOCDIR)/
|
||||
- install -m644 src/config.h $(DOCDIR)/
|
||||
- install -m644 README $(DOCDIR)/
|
||||
- install -m644 AUTHORS $(DOCDIR)/
|
||||
cp -r examples $(INSTALLDIR)/share/uzbl/
|
||||
chmod 755 $(INSTALLDIR)/share/uzbl/examples/data/scripts/*
|
||||
install -m755 uzbl-core $(INSTALLDIR)/bin/uzbl-core
|
||||
+ chmod 644 $(INSTALLDIR)/share/uzbl/examples/data/scripts/*.js
|
||||
|
||||
install-uzbl-browser: install-dirs
|
||||
install -m755 src/uzbl-browser $(INSTALLDIR)/bin/uzbl-browser
|
||||
9
uzbl.desktop
Normal file
9
uzbl.desktop
Normal file
|
|
@ -0,0 +1,9 @@
|
|||
[Desktop Entry]
|
||||
Name=Uzbl
|
||||
GenericName=Uzbl Web Browser
|
||||
Comment=Browse the Web
|
||||
Exec=uzbl-browser
|
||||
Icon=uzbl
|
||||
Terminal=false
|
||||
Type=Application
|
||||
Categories=Network;WebBrowser;
|
||||
274
uzbl.spec
Normal file
274
uzbl.spec
Normal file
|
|
@ -0,0 +1,274 @@
|
|||
%global uzblcommit e7578e27c
|
||||
|
||||
Name: uzbl
|
||||
Summary: Lightweight WebKit browser following the UNIX philosophy
|
||||
Group: Applications/Internet
|
||||
Version: 0
|
||||
Release: 0.26.20110402git%{uzblcommit}%{?dist}
|
||||
License: GPLv3
|
||||
URL: http://www.uzbl.org
|
||||
# The source for this package was pulled from upstream's vcs. Use the
|
||||
# following commands to generate the tarball:
|
||||
# git clone git://github.com/Dieterbe/uzbl.git
|
||||
# cd uzbl
|
||||
# export uzblcommit=e7578e27c
|
||||
# git archive --format tar --prefix uzbl-${uzblcommit}/ ${uzblcommit} |\
|
||||
# gzip -c > ../uzbl-${uzblcommit}.tar.gz
|
||||
Source0: %{name}-%{uzblcommit}.tar.gz
|
||||
Source1: %{name}.desktop
|
||||
# RPM handles docs for us, won't be upstreamed
|
||||
Patch0: %{name}-makefile.patch
|
||||
# Fedora-specific, won't be upstreamed
|
||||
Patch1: 0001-Fedora-specific-error-messages-on-no-configs.patch
|
||||
# From upstream
|
||||
Patch5: 0001-Restrict-third-party-access-to-cookie-jar-CVE-2012-0.patch
|
||||
|
||||
BuildRequires: webkitgtk-devel
|
||||
BuildRequires: desktop-file-utils
|
||||
BuildRequires: pkgconfig
|
||||
|
||||
# New users probably want a tabbed browser
|
||||
Requires: uzbl-tabbed = %{version}-%{release}
|
||||
Requires: uzbl-defaults = %{version}-%{release}
|
||||
|
||||
%description
|
||||
Uzbl is a lightweight web browser based on WebKit/Gtk+. Uzbl follows
|
||||
the UNIX philosophy - "Write programs that do one thing and do it
|
||||
well. Write programs to work together. Write programs to handle text
|
||||
streams, because that is a universal interface."
|
||||
|
||||
%package core
|
||||
Summary: Core component of Uzbl
|
||||
Group: Applications/Internet
|
||||
|
||||
%description core
|
||||
The core component to Uzbl. This part does little on its own. For a more
|
||||
complete browsing experience, see the uzbl package.
|
||||
|
||||
%package browser
|
||||
Summary: A complete browser using Uzbl
|
||||
Group: Applications/Internet
|
||||
Requires: %{name}-core = %{version}-%{release}
|
||||
|
||||
%description browser
|
||||
A complete browsing experience based on Uzbl's core component.
|
||||
|
||||
%package tabbed
|
||||
Summary: Tabbed interface to Uzbl
|
||||
Group: Applications/Internet
|
||||
Requires: %{name}-browser = %{version}-%{release}
|
||||
Requires: pygtk2
|
||||
|
||||
%description tabbed
|
||||
Uzbl-tabbed wraps around uzbl-browser and multiplexes it. It spawns
|
||||
one window containing multiple tabs, each tab containing a full
|
||||
embedded uzbl-browser Ideal as a quick and simple solution to manage
|
||||
multiple uzbl-browser instances without getting lost.
|
||||
|
||||
%package defaults
|
||||
Summary: Default configuration for uzbl
|
||||
Group: Applications/Internet
|
||||
Requires: %{name}-browser = %{version}-%{release}
|
||||
|
||||
# XXX: Be aware that script dependencies need enumerated here
|
||||
# Dialog for bookmarks and authentication
|
||||
Requires: zenity
|
||||
# Communication
|
||||
Requires: socat
|
||||
# scripts/formfiller.sh (dmenu also used by loading history/bookmarks)
|
||||
Requires: dmenu
|
||||
Requires: xterm
|
||||
# scripts/auth.py
|
||||
Requires: pygtk2
|
||||
# scripts/download.sh
|
||||
Requires: wget
|
||||
# Default config
|
||||
Requires: xclip
|
||||
|
||||
%description defaults
|
||||
Default configuration for uzbl.
|
||||
|
||||
%package vim
|
||||
Summary: Vim highlighting for uzbl's config
|
||||
Group: Applications/Text
|
||||
Requires: vim-filesystem
|
||||
|
||||
%description vim
|
||||
Highlighting files for uzbl's configuration.
|
||||
|
||||
|
||||
%prep
|
||||
%setup -q -n %{name}-%{uzblcommit}
|
||||
%patch0 -p1 -b .makefile
|
||||
%patch1 -p1 -b .fedora
|
||||
%patch5 -p1 -b .cookie-perms
|
||||
|
||||
mkdir -p icons/hicolor/32x32/apps
|
||||
mv examples/data/uzbl.png icons/hicolor/32x32/apps
|
||||
|
||||
|
||||
%build
|
||||
CFLAGS="%{optflags}"
|
||||
export CFLAGS
|
||||
make %{?_smp_mflags}
|
||||
|
||||
|
||||
%install
|
||||
make DESTDIR=%{buildroot} PREFIX=%{_prefix} install
|
||||
|
||||
cp -pr icons %{buildroot}%{_datadir}
|
||||
desktop-file-install --dir=%{buildroot}%{_datadir}/applications \
|
||||
%{SOURCE1}
|
||||
|
||||
mkdir -p %{buildroot}%{_datadir}/vim/vimfiles/ftdetect/
|
||||
install -p extras/vim/ftdetect/uzbl.vim %{buildroot}%{_datadir}/vim/vimfiles/ftdetect/uzbl.vim
|
||||
mkdir -p %{buildroot}%{_datadir}/vim/vimfiles/ftplugin/
|
||||
install -p extras/vim/ftplugin/uzbl.vim %{buildroot}%{_datadir}/vim/vimfiles/ftplugin/uzbl.vim
|
||||
mkdir -p %{buildroot}%{_datadir}/vim/vimfiles/syntax/
|
||||
install -p extras/vim/syntax/uzbl.vim %{buildroot}%{_datadir}/vim/vimfiles/syntax/uzbl.vim
|
||||
|
||||
|
||||
%post
|
||||
touch --no-create %{_datadir}/icons/hicolor &> /dev/null || :
|
||||
|
||||
|
||||
%postun
|
||||
if [ $1 -eq 0 ]; then
|
||||
touch --no-create %{_datadir}/icons/hicolor &> /dev/null || :
|
||||
gtk-update-icon-cache %{_datadir}/icons/hicolor &> /dev/null || :
|
||||
fi
|
||||
|
||||
|
||||
%posttrans
|
||||
gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || :
|
||||
|
||||
|
||||
%files
|
||||
%defattr(-, root, root, -)
|
||||
|
||||
%files core
|
||||
%defattr(-, root, root, -)
|
||||
%doc AUTHORS LICENSE README docs/* src/config.h
|
||||
%{_bindir}/uzbl-core
|
||||
|
||||
%files browser
|
||||
%defattr(-, root, root, -)
|
||||
%{_bindir}/uzbl-browser
|
||||
%{_bindir}/uzbl-event-manager
|
||||
|
||||
%files tabbed
|
||||
%defattr(-, root, root, -)
|
||||
%{_bindir}/uzbl-tabbed
|
||||
|
||||
%files defaults
|
||||
%defattr(-, root, root, -)
|
||||
%{_datadir}/icons/*/*/apps/%{name}.*
|
||||
%{_datadir}/applications/%{name}.desktop
|
||||
%{_datadir}/%{name}/examples/config/
|
||||
%{_datadir}/%{name}/examples/data/
|
||||
|
||||
%files vim
|
||||
%defattr(-, root, root, -)
|
||||
%{_datadir}/vim/vimfiles/ftdetect/uzbl.vim
|
||||
%{_datadir}/vim/vimfiles/ftplugin/uzbl.vim
|
||||
%{_datadir}/vim/vimfiles/syntax/uzbl.vim
|
||||
|
||||
|
||||
%changelog
|
||||
* Thu Feb 23 2012 Ben Boeckel <mathstuf@gmail.com> - 0-0.26.20110402gite7578e27c
|
||||
- Lock down permissions on cookie files (CVE-2012-0843)
|
||||
- Clean up vim subpackage
|
||||
|
||||
* Mon Apr 4 2011 Daiki Ueno <dueno@redhat.com> - 0-0.25.20110402gite7578e27c
|
||||
- New upstream snapshot
|
||||
- Don't install removed uzbl-cookie-manager and related files.
|
||||
|
||||
* Wed Mar 2 2011 Daiki Ueno <dueno@redhat.com> - 0-0.24.20110215git8bbc39b83
|
||||
- New upstream snapshot
|
||||
|
||||
* Mon Feb 07 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0-0.23.20101125git518004933
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
|
||||
|
||||
* Tue Jan 25 2011 Ben Boeckel <mathstuf@gmail.com> - 0-0.22.20101125git518004933
|
||||
- Update the vim subpackage to install for 7.3
|
||||
|
||||
* Mon Nov 29 2010 Daiki Ueno <dueno@redhat.com> - 0-0.21.20101125git518004933
|
||||
- omit unnecessary buildroot stuff
|
||||
|
||||
* Mon Nov 29 2010 Daiki Ueno <dueno@redhat.com> - 0-0.20.20101125git518004933
|
||||
- new upstream snapshot.
|
||||
- remove patches incorporated into the upstream git master.
|
||||
|
||||
* Sun Oct 10 2010 Ben Boeckel <mathstuf@gmail.com> - 0-0.19.20100626gitafc0f873e
|
||||
- Split out -defaults package
|
||||
- Install vim files
|
||||
- Remove -O0 compile flag
|
||||
- Use %%{optflags}
|
||||
|
||||
* Mon Sep 6 2010 Daiki Ueno <dueno@redhat.com> - 0-0.18.20100626gitafc0f873e
|
||||
- add patch to avoid crash on "Open Image in New Window" (#584733)
|
||||
|
||||
* Fri Aug 20 2010 Ben Boeckel <mathstuf@gmail.com> - 0-0.17.20100626gitafc0f873e
|
||||
- Add Requires: on xclip
|
||||
|
||||
* Fri Aug 06 2010 Ben Boeckel <mathstuf@gmail.com> - 0-0.16.20100626gitafc0f873e
|
||||
- Add patch for shell escaping bug (BZ#621965)
|
||||
|
||||
* Sat Jul 03 2010 Ben Boeckel <mathstuf@gmail.com> - 0-0.15.20100626gitafc0f873e
|
||||
- Rebuild against webkitgtk
|
||||
|
||||
* Wed Jun 30 2010 Daiki Ueno <dueno@redhat.com> - 0-0.14.20100626gitafc0f873e
|
||||
- new upstream snapshot.
|
||||
|
||||
* Mon May 31 2010 Daiki Ueno <dueno@redhat.com> - 0-0.13.20100410gitec473e124
|
||||
- new upstream snapshot.
|
||||
|
||||
* Wed Apr 14 2010 Ben Boeckel <MathStuf@gmail.com> - 0-0.12.20100405gitae15d257a
|
||||
- Split out core and browser subpackages
|
||||
- Enumerate dependencies of the default scripts
|
||||
- Minor reorganization
|
||||
|
||||
* Thu Apr 8 2010 Daiki Ueno <dueno@redhat.com> - 0-0.11.20100405gitae15d257a
|
||||
- don't strip uzbl-core with the install command (closes #580250).
|
||||
|
||||
* Mon Apr 5 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.10.20100405gitae15d257a
|
||||
- split out uzbl-tabbed as a seperate package to avoid dependency on
|
||||
pygtk2 (partially merged a patch from Ben Boeckel <mathstuf@gmail.com>).
|
||||
- new upstream snapshot.
|
||||
|
||||
* Fri Mar 26 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.9.20100221gitabbffe5c3
|
||||
- add dist number to Release.
|
||||
|
||||
* Fri Mar 19 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.8.20100221gitabbffe5c3
|
||||
- use the macro "global" instead of "define".
|
||||
|
||||
* Thu Mar 18 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.7.20100221gitabbffe5c3
|
||||
- copy files under /usr/share/uzbl/ only once.
|
||||
|
||||
* Tue Mar 16 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.6.20100221gitabbffe5c3
|
||||
- preserve timestamp of installed files.
|
||||
- include scriptlets for icon cache.
|
||||
- claim ownership of the directory "uzbl" under datadir.
|
||||
|
||||
* Sat Mar 13 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.5.20100221gitabbffe5c3
|
||||
- install 32x32 icon under the standard icon path.
|
||||
- fix the executable name in uzbl.desktop.
|
||||
- prevent re-compilation on "make install".
|
||||
- install examples/* under /usr/share/uzbl/examples, since the path is
|
||||
hard-coded in bundled scripts.
|
||||
|
||||
* Mon Mar 8 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.4.20100221gitabbffe5c3
|
||||
- make sure support scripts are not executable.
|
||||
|
||||
* Sun Mar 7 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.3.20100221gitabbffe5c3
|
||||
- use LDFLAGS from x11.pc to follow the F-13 DSO linking change.
|
||||
|
||||
* Sun Mar 7 2010 Daiki Ueno <ueno@unixuser.org> - 0-0.2.20100221gitabbffe5c3
|
||||
- don't use Epoch.
|
||||
- make the build log more verbose.
|
||||
- don't use the makeinstall macro and use _prefix macro.
|
||||
- include uzbl.desktop.
|
||||
- install all document files under /usr/share/doc/uzbl-0.
|
||||
|
||||
* Sun Feb 21 2010 Daiki Ueno <ueno@unixuser.org> - 1:0-0.1.20100221gitabbffe5c3
|
||||
- initial packaging for fedora.
|
||||
Loading…
Add table
Add a link
Reference in a new issue