From adc3f11305a887484321f015edeaf58ec284684a Mon Sep 17 00:00:00 2001 From: Michal Ruprich Date: Tue, 2 Apr 2024 13:30:36 +0200 Subject: [PATCH 01/15] Resolves: #2271362 - wget2 blacklists files intended for download --- 0002-normalize-path-in-url.patch | 48 ++++++++++++++++++++++++++++++++ wget2.spec | 7 ++++- 2 files changed, 54 insertions(+), 1 deletion(-) create mode 100644 0002-normalize-path-in-url.patch diff --git a/0002-normalize-path-in-url.patch b/0002-normalize-path-in-url.patch new file mode 100644 index 0000000..9fce4b7 --- /dev/null +++ b/0002-normalize-path-in-url.patch @@ -0,0 +1,48 @@ +From 9aeab55d09f9df833bca4467b0a209cea2901ede Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Thu, 28 Mar 2024 18:12:19 +0100 +Subject: [PATCH] Fix --no-parent for denormalized paths + +* libwget/iri.c (wget_iri_parse): Normalize path part of URL. +* unit-tests/test.c (test_iri_parse): Add test with denormalized path. +--- + libwget/iri.c | 3 +++ + unit-tests/test.c | 1 + + 2 files changed, 4 insertions(+) + +diff --git a/libwget/iri.c b/libwget/iri.c +index 8241ea971..13bd5259b 100644 +--- a/libwget/iri.c ++++ b/libwget/iri.c +@@ -82,6 +82,8 @@ static struct iri_scheme { + [WGET_IRI_SCHEME_HTTPS] = { 443, "https" }, + }; + ++static size_t WGET_GCC_NONNULL_ALL normalize_path(char *path); ++ + /** + * \param[in] scheme Scheme to get name for + * \return Name of \p scheme (e.g. "http" or "https") or NULL is not supported +@@ -561,6 +563,7 @@ wget_iri *wget_iri_parse(const char *url, const char *encoding) + c = *s; + if (c) *s++ = 0; + wget_iri_unescape_inline((char *)iri->path); ++ normalize_path((char *)iri->path); + } + + if (c == '?') { +diff --git a/unit-tests/test.c b/unit-tests/test.c +index da8cc728b..80ddeced5 100644 +--- a/unit-tests/test.c ++++ b/unit-tests/test.c +@@ -584,6 +584,7 @@ static void test_iri_parse(void) + { "http://example+.com/pa+th?qu+ery#fr+ag", NULL, WGET_IRI_SCHEME_HTTP, NULL, NULL, "example+.com", 80, "pa+th", "qu ery", "fr+ag"}, + { "http://example.com#frag?x", NULL, WGET_IRI_SCHEME_HTTP, NULL, NULL, "example.com", 80, NULL, NULL, "frag?x"}, + { "http://user:pw@example.com", NULL, WGET_IRI_SCHEME_HTTP, "user", "pw", "example.com", 80, NULL, NULL, NULL}, ++ { "http://example.com//path//file", NULL, WGET_IRI_SCHEME_HTTP, NULL, NULL, "example.com", 80, "path/file", NULL, NULL}, + }; + unsigned it; + +-- +GitLab + diff --git a/wget2.spec b/wget2.spec index 391318a..7d6fa58 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.1.0 -Release: 7%{?dist} +Release: 8%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -22,6 +22,8 @@ Source2: tim.ruehsen-keyring.asc # Backports from upstream ## Fix behavior for downloading to stdin (rhbz#2257700, gl#gnuwget/wget2#651) Patch0001: 0001-src-log.c-log_init-Redirect-INFO-logs-to-stderr-with.patch +## Fix normalization of path part of URL (rhbz#2271362) +Patch0002: 0002-normalize-path-in-url.patch # Buildsystem build requirements BuildRequires: autoconf @@ -184,6 +186,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Tue Apr 02 2024 Michal Ruprich - 2.1.0-8 +- Resolves: #2271362 - wget2 blacklists files intended for download + * Sat Jan 27 2024 Fedora Release Engineering - 2.1.0-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From b06801c556caae8aa38f3408751f51dc901f275c Mon Sep 17 00:00:00 2001 From: Romain Geissler Date: Fri, 10 May 2024 16:29:30 +0000 Subject: [PATCH 02/15] Allow option --no-tcp-fastopen to work on Linux kernels >= 4.11. --- ...tcp-fastopen-to-work-on-Linux-kernel.patch | 35 +++++++++++++++++++ wget2.spec | 8 ++++- 2 files changed, 42 insertions(+), 1 deletion(-) create mode 100644 0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch diff --git a/0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch b/0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch new file mode 100644 index 0000000..9dd1dc0 --- /dev/null +++ b/0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch @@ -0,0 +1,35 @@ +From 7929bf887c69ffdcbdfb525825bffba4c9e5d6e8 Mon Sep 17 00:00:00 2001 +From: Romain Geissler +Date: Fri, 10 May 2024 16:24:57 +0000 +Subject: [PATCH] Allow option --no-tcp-fastopen to work on Linux kernels >= + 4.11. + +* libwget/net.c (set_socket_options): Add check for tcp->tcp_fastopen. + +Copyright-paperwork-exempt: Yes +--- + libwget/net.c | 8 +++++--- + 1 file changed, 5 insertions(+), 3 deletions(-) + +diff --git a/libwget/net.c b/libwget/net.c +index 8fc6d143..836649c0 100644 +--- a/libwget/net.c ++++ b/libwget/net.c +@@ -640,9 +640,11 @@ static void set_socket_options(const wget_tcp *tcp, int fd) + #endif + + #ifdef TCP_FASTOPEN_LINUX_411 +- on = 1; +- if (setsockopt(fd, IPPROTO_TCP, TCP_FASTOPEN_CONNECT, (void *)&on, sizeof(on)) == -1) +- debug_printf("Failed to set socket option TCP_FASTOPEN_CONNECT\n"); ++ if (tcp->tcp_fastopen) { ++ on = 1; ++ if (setsockopt(fd, IPPROTO_TCP, TCP_FASTOPEN_CONNECT, (void *)&on, sizeof(on)) == -1) ++ debug_printf("Failed to set socket option TCP_FASTOPEN_CONNECT\n"); ++ } + #endif + } + +-- +2.43.0 + diff --git a/wget2.spec b/wget2.spec index 7d6fa58..dea4bd7 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.1.0 -Release: 8%{?dist} +Release: 9%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -24,6 +24,9 @@ Source2: tim.ruehsen-keyring.asc Patch0001: 0001-src-log.c-log_init-Redirect-INFO-logs-to-stderr-with.patch ## Fix normalization of path part of URL (rhbz#2271362) Patch0002: 0002-normalize-path-in-url.patch +# https://github.com/rockdaboot/wget2/pull/316 +# Allow option --no-tcp-fastopen to work on Linux kernels >= 4.11 +Patch0003: 0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch # Buildsystem build requirements BuildRequires: autoconf @@ -186,6 +189,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Sat May 11 2024 Romain Geissler - 2.1.0-9 +- Allow option --no-tcp-fastopen to work on Linux kernels >= 4.11. + * Tue Apr 02 2024 Michal Ruprich - 2.1.0-8 - Resolves: #2271362 - wget2 blacklists files intended for download From ff3ad5a501070454ea53915644b52dedb89dc40c Mon Sep 17 00:00:00 2001 From: Romain Geissler Date: Sat, 18 May 2024 23:01:04 +0000 Subject: [PATCH 03/15] Backport upstream --progress and OCSP fixes to be more like wget 1.x --- 0004-Disable-OCSP-by-default.patch | 627 ++++++++++++++++++ ...ss-dot-.-for-backwards-compatibility.patch | 57 ++ wget2.spec | 12 +- 3 files changed, 695 insertions(+), 1 deletion(-) create mode 100644 0004-Disable-OCSP-by-default.patch create mode 100644 0005-Accept-progress-dot-.-for-backwards-compatibility.patch diff --git a/0004-Disable-OCSP-by-default.patch b/0004-Disable-OCSP-by-default.patch new file mode 100644 index 0000000..edf1931 --- /dev/null +++ b/0004-Disable-OCSP-by-default.patch @@ -0,0 +1,627 @@ +Backport of all the OCSP-related commits related to issue https://gitlab.com/gnuwget/wget2/-/issues/664: + - 53a8a88e8479fca04fb17f923b0f40781ee6a253 + - a96f88a054a0dbb31eb23d7f39b0922447177ab3 + - 715e646642e169a0a4510bdf51a5b4fc512f94d6 + - 35986bd093676df0b2acd6110620534d41d0ec4d + - 0895f9230859207385393a148d6b0a6ec24521b9 + - c341fcd1dfd57b3cf5a1f5acb84784571fff3a20 + - c556a3226aca0e99191b52218117b7967889a9bf + - 543e1f270821cc7ea562444bfd79ae4d66d5b964 + - f4e7c46073850af7b5c3d58b9452bdd2124b593c + - de294c8ddf27b11e8abc7954856d590d7ce2d4f3 + + +commit 53a8a88e8479fca04fb17f923b0f40781ee6a253 +Author: Tim Rühsen +Date: Sun May 12 15:14:31 2024 +0200 + + Fix OCSP verification of first intermediate certificate. + + * libwget/ssl_gnutls.c (verify_certificate_callback): Fix off-by-one check. + + See https://gitlab.com/gnuwget/wget2/-/issues/664#note_1901610438 + +diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c +index 35f20279..5524c02c 100644 +--- a/libwget/ssl_gnutls.c ++++ b/libwget/ssl_gnutls.c +@@ -1153,7 +1153,7 @@ static int verify_certificate_callback(gnutls_session_t session) + cert_verify_hpkp(cert, hostname, session); + + #ifdef WITH_OCSP +- if (config.ocsp && it > nvalid) { ++ if (config.ocsp && it >= nvalid) { + char fingerprint[64 * 2 +1]; + int revoked; + +commit a96f88a054a0dbb31eb23d7f39b0922447177ab3 +Author: Tim Rühsen +Date: Sun May 12 19:51:03 2024 +0200 + + -* libwget/ssl_gnutls.c (cert_verify_ocsp): Fix segfault when OCSP response is missing + +diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c +index 5524c02c..1058e50f 100644 +--- a/libwget/ssl_gnutls.c ++++ b/libwget/ssl_gnutls.c +@@ -860,6 +860,11 @@ static int cert_verify_ocsp(gnutls_x509_crt_t cert, gnutls_x509_crt_t issuer) + return -1; + } + ++ if (!resp) { ++ debug_printf("Missing response from OCSP server\n"); ++ return -1; ++ } ++ + /* verify and check the response for revoked cert */ + ret = check_ocsp_response(cert, issuer, resp, &nonce); + wget_buffer_free(&resp); +commit 715e646642e169a0a4510bdf51a5b4fc512f94d6 +Author: Tim Rühsen +Date: Sun May 12 19:51:44 2024 +0200 + + Fix tests/test-ocsp-server + + * tests/libtest.c: Handle > 1 OCSP responses. + * tests/libtest.h: Rename WGET_TEST_OCSP_RESP_FILE to WGET_TEST_OCSP_RESP_FILES. + * tests/test-ocsp-server.c: Make use of WGET_TEST_OCSP_RESP_FILES. + +diff --git a/tests/libtest.c b/tests/libtest.c +index 533f5d47..e3850bc0 100644 +--- a/tests/libtest.c ++++ b/tests/libtest.c +@@ -90,9 +90,11 @@ static int + keep_tmpfiles, + clean_directory, + reject_http_connection, +- reject_https_connection; ++ reject_https_connection, ++ ocsp_response_pos; + static wget_vector +- *request_urls; ++ *request_urls, ++ *ocsp_responses; + static wget_test_url_t + *urls; + static size_t +@@ -121,12 +123,12 @@ static struct MHD_Daemon + static gnutls_pcert_st *pcrt; + static gnutls_privkey_t *privkey; + +-static struct ocsp_resp_t { ++typedef struct { + char + *data; + size_t + size; +-} *ocsp_resp; ++} ocsp_resp_t; + #endif + + #ifdef WITH_GNUTLS_OCSP +@@ -311,14 +313,14 @@ static enum MHD_Result _ocsp_ahc( + } else if (!first && upload_data == NULL) { + int ret = 0; + +- if (ocsp_resp->data) { ++ ocsp_resp_t *ocsp_resp = wget_vector_get(ocsp_responses, ocsp_response_pos++); ++ ++ if (ocsp_resp) { + struct MHD_Response *response = MHD_create_response_from_buffer (ocsp_resp->size, ocsp_resp->data, MHD_RESPMEM_MUST_COPY); + + ret = MHD_queue_response (connection, MHD_HTTP_OK, response); + + MHD_destroy_response (response); +- +- wget_xfree(ocsp_resp->data); + } + + return ret; +@@ -715,11 +717,6 @@ static void _http_server_stop(void) + + #ifdef WITH_GNUTLS_OCSP + gnutls_global_deinit(); +- +- if(ocsp_resp) +- wget_free(ocsp_resp->data); +- +- wget_xfree(ocsp_resp); + #endif + } + +@@ -892,8 +889,6 @@ static int _http_server_start(int SERVER_MODE) + #endif + MHD_OPTION_CONNECTION_MEMORY_LIMIT, (size_t) 1*1024*1024, + MHD_OPTION_END); +- +- ocsp_resp = wget_malloc(sizeof(struct ocsp_resp_t)); + #endif + + if (!ocspdaemon) +@@ -1121,6 +1116,7 @@ void wget_test_stop_server(void) + { + // wget_vector_free(&response_headers); + wget_vector_free(&request_urls); ++ wget_vector_free(&ocsp_responses); + + for (wget_test_url_t *url = urls; url < urls + nurls; url++) { + if (url->body_original) { +@@ -1535,9 +1531,6 @@ void wget_test(int first_key, ...) + const char + *request_url, + *options = "", +-#ifdef WITH_GNUTLS_OCSP +- *ocsp_resp_file = NULL, +-#endif + *executable = global_executable; + const wget_test_file_t + *expected_files = NULL, +@@ -1581,6 +1574,10 @@ void wget_test(int first_key, ...) + wget_vector_set_destructor(request_urls, NULL); + } + ++ if (!ocsp_responses) { ++ ocsp_responses = wget_vector_create(2, NULL); ++ } ++ + va_start (args, first_key); + for (key = first_key; key; key = va_arg(args, int)) { + switch (key) { +@@ -1633,9 +1630,24 @@ void wget_test(int first_key, ...) + #endif + } + break; +- case WGET_TEST_OCSP_RESP_FILE: ++ case WGET_TEST_OCSP_RESP_FILES: + #ifdef WITH_GNUTLS_OCSP +- ocsp_resp_file = va_arg(args, const char *); ++ { ++ const char *ocsp_resp_file = NULL; ++ while ((ocsp_resp_file = va_arg(args, const char *))) { ++ if (ocspdaemon) { ++ ocsp_resp_t ocsp_resp = { .data = wget_strdup(""), .size = 0 }; ++ if (*ocsp_resp_file) { ++ ocsp_resp.data = wget_read_file(ocsp_resp_file, &ocsp_resp.size); ++ if (ocsp_resp.data == NULL) { ++ wget_error_printf_exit("Couldn't read the response from '%s'.\n", ocsp_resp_file); ++ } ++ } ++ wget_vector_add_memdup(ocsp_responses, &ocsp_resp, sizeof(ocsp_resp)); ++ } ++ } ++ ocsp_response_pos = 0; ++ } + #endif + break; + default: +@@ -1650,19 +1662,6 @@ void wget_test(int first_key, ...) + _empty_directory(cmd->data); + } + +-#ifdef WITH_GNUTLS_OCSP +- if (ocspdaemon) { +- if (ocsp_resp_file) { +- ocsp_resp->data = wget_read_file(ocsp_resp_file, &(ocsp_resp->size)); +- if (ocsp_resp->data == NULL) { +- wget_error_printf_exit("Couldn't read the response.\n"); +- } +- } else { +- wget_error_printf_exit("Need value for option WGET_TEST_OCSP_RESP_FILE.\n"); +- } +- } +-#endif +- + // create files + if (existing_files) { + for (it = 0; existing_files[it].name; it++) { +@@ -1835,6 +1834,11 @@ void wget_test(int first_key, ...) + wget_free(post_handshake_auth); + #endif + ++ for (int i = 0; i < wget_vector_size(ocsp_responses); i++) { ++ ocsp_resp_t *r = wget_vector_get(ocsp_responses, it); ++ wget_xfree(r->data); ++ } ++ wget_vector_clear(ocsp_responses); + wget_vector_clear(request_urls); + wget_buffer_free(&cmd); + +diff --git a/tests/libtest.h b/tests/libtest.h +index 7aa72088..dfccbe0b 100644 +--- a/tests/libtest.h ++++ b/tests/libtest.h +@@ -76,7 +76,7 @@ extern "C" { + #define WGET_TEST_POST_HANDSHAKE_AUTH 3002 + + // for OCSP testing +-#define WGET_TEST_OCSP_RESP_FILE 3003 ++#define WGET_TEST_OCSP_RESP_FILES 3003 + + typedef enum { + INTERRUPT_RESPONSE_DISABLED = 0, +diff --git a/tests/test-ocsp-server.c b/tests/test-ocsp-server.c +index 8b844e18..ebe443a5 100644 +--- a/tests/test-ocsp-server.c ++++ b/tests/test-ocsp-server.c +@@ -46,7 +46,7 @@ int main(void) + WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp --ocsp-server http://localhost:{{ocspport}}", + WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", + WGET_TEST_EXPECTED_ERROR_CODE, 0, +- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_ok.der", ++ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_ok.der", NULL, + WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { + {urls[0].name + 1, urls[0].body}, + { NULL} }, +@@ -58,7 +58,7 @@ int main(void) + WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp --ocsp-server http://localhost:{{ocspport}}", + WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", + WGET_TEST_EXPECTED_ERROR_CODE, 5, +- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", ++ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", NULL, + 0); + #endif + +@@ -67,7 +67,7 @@ int main(void) + WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp --ocsp-server http://localhost:{{ocspport}} --no-check-certificate", + WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", + WGET_TEST_EXPECTED_ERROR_CODE, 0, +- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", ++ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", NULL, + WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { + {urls[0].name + 1, urls[0].body}, + { NULL} }, +@@ -79,7 +79,7 @@ int main(void) + WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp", + WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", + WGET_TEST_EXPECTED_ERROR_CODE, 0, +- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_ok.der", ++ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_ok.der", NULL, + WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { + {urls[0].name + 1, urls[0].body}, + { NULL} }, +commit 35986bd093676df0b2acd6110620534d41d0ec4d +Author: Tim Rühsen +Date: Sat May 18 14:35:45 2024 +0200 + + Disable explicit OCSP requests by default + + * docs/wget2.md: Document --ocsp default value as 'off'. + * src/options.c (struct config): Disable .ocsp by default. + + OCSP validation of the server certificate implies privacy issues: + - The OCSP request tells the CA which web service the client tries to reach. + - The OCSP requests are sent via unencrypted HTTP, so every "listener in the + middle" can see which web service the client tries to connect. + Additionally, the OCSP requests slow down operation and may cause unexpected + network traffic, which may trigger security alarms unnecessarily. + + Due to these issues we explicitly disable OCSP by default. + +diff --git a/docs/wget2.md b/docs/wget2.md +index 6e408592..61da3ccb 100644 +--- a/docs/wget2.md ++++ b/docs/wget2.md +@@ -1569,7 +1569,7 @@ Go to background immediately after startup. If no output file is specified via t + + ### `--ocsp` + +- Enable OCSP server access to check the possible revocation the HTTPS server certificate(s) (default: on). ++ Enable OCSP server access to check the possible revocation the HTTPS server certificate(s) (default: off). + + This procedure is pretty slow (connect to server, HTTP request, response) and thus we support + OSCP stapling (server sends OCSP response within TLS handshake) and persistent OCSP caching. +diff --git a/src/options.c b/src/options.c +index 54e8cabb..7684b795 100644 +--- a/src/options.c ++++ b/src/options.c +@@ -1302,7 +1302,16 @@ struct config config = { + .http2 = 1, + .http2_request_window = 30, + #endif +- .ocsp = 1, ++ // OCSP validation of the server certificate implies privacy issues: ++ // - The OCSP request tells the CA which web service the client tries to reach. ++ // - The OCSP requests are sent via unencrypted HTTP, so every "listener in the middle" can see which web service ++ // the client tries to connect. ++ // Additionally, the OCSP requests slow down operation and may cause unexpected network traffic, which may trigger ++ // security alarms unnecessarily. ++ // Due to these issues we explicitly disable OCSP by default. ++ // ++ // The upside of enabling OCSP mostly is a "real-time" recognition of certificate revocations. ++ .ocsp = 0, + .ocsp_date = 1, + .ocsp_stapling = 1, + .ocsp_nonce = 1, +commit 0895f9230859207385393a148d6b0a6ec24521b9 +Author: Tim Rühsen +Date: Sat May 18 14:46:07 2024 +0200 + + * libwget/ssl_gnutls.c: Improve messages for OCSP stapling + +diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c +index 1058e50f..f12b5e74 100644 +--- a/libwget/ssl_gnutls.c ++++ b/libwget/ssl_gnutls.c +@@ -1136,7 +1136,7 @@ static int verify_certificate_callback(gnutls_session_t session) + } + #endif + else if (!config.ocsp) +- error_printf_check(_("WARNING: The certificate's (stapled) OCSP status has not been sent\n")); ++ error_printf_check(_("WARNING: OCSP stapling is not supported by '%s'\n"), hostname); + #endif + } else if (ctx->valid) + debug_printf("OCSP: Host '%s' is valid (from cache)\n", hostname); +@@ -1728,13 +1728,14 @@ int wget_ssl_open(wget_tcp *tcp) + // If we know the cert chain for the hostname being valid at the moment, + // we don't ask for OCSP stapling to avoid unneeded IP traffic. + // In the unlikely case that the server's certificate chain changed right now, +- // we fallback to OCSP responder request later. ++ // we fallback to OCSP responder request later (if enabled). + if (hostname) { + if (!(ctx->valid = wget_ocsp_hostname_is_valid(config.ocsp_host_cache, hostname))) { + #if GNUTLS_VERSION_NUMBER >= 0x030103 +- if ((rc = gnutls_ocsp_status_request_enable_client(session, NULL, 0, NULL)) == GNUTLS_E_SUCCESS) ++ if ((rc = gnutls_ocsp_status_request_enable_client(session, NULL, 0, NULL)) == GNUTLS_E_SUCCESS) { ++ debug_printf("OCSP stapling requested for %s\n", hostname); + ctx->ocsp_stapling = 1; +- else ++ } else + error_printf("GnuTLS: %s\n", gnutls_strerror(rc)); // no translation + #endif + } +commit c341fcd1dfd57b3cf5a1f5acb84784571fff3a20 +Author: Tim Rühsen +Date: Sun May 19 12:41:55 2024 +0200 + + Disable explicit OCSP requests by default for TLS library functions + + * libwget/ssl_openssl: Disable explicit OCSP requests by default. + * libwget/ssl_gnutls: Likewise. + * libwget/ssl_wolfssl.c: Likewise. + +diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c +index f12b5e74..7dbbde39 100644 +--- a/libwget/ssl_gnutls.c ++++ b/libwget/ssl_gnutls.c +@@ -116,7 +116,7 @@ static struct config { + .report_invalid_cert = 1, + .check_hostname = 1, + #ifdef WITH_OCSP +- .ocsp = 1, ++ .ocsp = 0, + .ocsp_stapling = 1, + #endif + .ca_type = WGET_SSL_X509_FMT_PEM, +diff --git a/libwget/ssl_openssl.c b/libwget/ssl_openssl.c +index 94da0d3f..2332ec40 100644 +--- a/libwget/ssl_openssl.c ++++ b/libwget/ssl_openssl.c +@@ -102,7 +102,7 @@ static struct config + .check_certificate = 1, + .check_hostname = 1, + #ifdef WITH_OCSP +- .ocsp = 1, ++ .ocsp = 0, + .ocsp_stapling = 1, + #endif + .ca_type = WGET_SSL_X509_FMT_PEM, +diff --git a/libwget/ssl_wolfssl.c b/libwget/ssl_wolfssl.c +index 47ed9ba9..967e984d 100644 +--- a/libwget/ssl_wolfssl.c ++++ b/libwget/ssl_wolfssl.c +@@ -108,7 +108,7 @@ static struct config { + .check_certificate = 1, + .report_invalid_cert = 1, + .check_hostname = 1, +- .ocsp = 1, ++ .ocsp = 0, + .ocsp_stapling = 1, + .ca_type = WGET_SSL_X509_FMT_PEM, + .cert_type = WGET_SSL_X509_FMT_PEM, +commit c556a3226aca0e99191b52218117b7967889a9bf +Author: Tim Rühsen +Date: Sun May 19 13:05:11 2024 +0200 + + * libwget/ssl_openssl.c (verify_ocsp): Fix segfault when OCSP response is missing + +diff --git a/libwget/ssl_openssl.c b/libwget/ssl_openssl.c +index 2332ec40..6cac6ecb 100644 +--- a/libwget/ssl_openssl.c ++++ b/libwget/ssl_openssl.c +@@ -1024,9 +1024,7 @@ static int verify_ocsp(const char *ocsp_uri, + certid = OCSP_cert_to_id(EVP_sha1(), subject_cert, issuer_cert); + + /* Send OCSP request to server, via HTTP */ +- if (!(ocspreq = send_ocsp_request(ocsp_uri, +- certid, +- &resp))) ++ if (!(ocspreq = send_ocsp_request(ocsp_uri, certid, &resp)) || !resp || !resp->body) + return -1; + + /* Check server's OCSP response */ +commit 543e1f270821cc7ea562444bfd79ae4d66d5b964 +Author: Tim Rühsen +Date: Sun May 19 12:26:29 2024 +0200 + + * libwget/ssl_gnutls.c (verify_certificate_callback): Warn about OCSP privacy leak + +diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c +index 7dbbde39..08f95383 100644 +--- a/libwget/ssl_gnutls.c ++++ b/libwget/ssl_gnutls.c +@@ -1121,6 +1121,8 @@ static int verify_certificate_callback(gnutls_session_t session) + // At this point, the cert chain has been found valid regarding the locally available CA certificates and CRLs. + // Now, we are going to check the revocation status via OCSP + #ifdef WITH_OCSP ++ bool skip_server_cert_check = false; ++ + if (config.ocsp_stapling) { + if (!ctx->valid && ctx->ocsp_stapling) { + #if GNUTLS_VERSION_NUMBER >= 0x030103 +@@ -1129,14 +1131,20 @@ static int verify_certificate_callback(gnutls_session_t session) + // _get_cert_fingerprint(cert, fingerprint, sizeof(fingerprint)); // calc hexadecimal fingerprint string + add_cert_to_ocsp_cache(cert, true); + nvalid = 1; ++ skip_server_cert_check = true; + } + #if GNUTLS_VERSION_NUMBER >= 0x030400 + else if (gnutls_ocsp_status_request_is_checked(session, GNUTLS_OCSP_SR_IS_AVAIL)) { + error_printf_check(_("WARNING: The certificate's (stapled) OCSP status is invalid\n")); ++ skip_server_cert_check = true; + } + #endif +- else if (!config.ocsp) +- error_printf_check(_("WARNING: OCSP stapling is not supported by '%s'\n"), hostname); ++ else if (!config.ocsp) { ++ debug_printf(_("OCSP stapling is not supported by '%s'\n"), hostname); ++ } else { ++ error_printf_check(_("WARNING: OCSP stapling is not supported by '%s', but OCSP validation has been requested.\n"), hostname); ++ error_printf_check(_("WARNING: This implies a privacy leak: the client sends the certificate serial ID over HTTP to the CA.\n")); ++ } + #endif + } else if (ctx->valid) + debug_printf("OCSP: Host '%s' is valid (from cache)\n", hostname); +@@ -1158,55 +1166,55 @@ static int verify_certificate_callback(gnutls_session_t session) + cert_verify_hpkp(cert, hostname, session); + + #ifdef WITH_OCSP +- if (config.ocsp && it >= nvalid) { +- char fingerprint[64 * 2 +1]; +- int revoked; ++ if (!config.ocsp || (skip_server_cert_check && it == 0)) ++ continue; + +- _get_cert_fingerprint(cert, fingerprint, sizeof(fingerprint)); // calc hexadecimal fingerprint string ++ char fingerprint[64 * 2 +1]; ++ _get_cert_fingerprint(cert, fingerprint, sizeof(fingerprint)); // calc hexadecimal fingerprint string + +- if (wget_ocsp_fingerprint_in_cache(config.ocsp_cert_cache, fingerprint, &revoked)) { +- // found cert's fingerprint in cache +- if (revoked) { +- debug_printf("Certificate[%u] of '%s' has been revoked (cached)\n", it, hostname); +- nrevoked++; +- } else { +- debug_printf("Certificate[%u] of '%s' is valid (cached)\n", it, hostname); +- nvalid++; +- } +- continue; ++ int revoked; ++ if (wget_ocsp_fingerprint_in_cache(config.ocsp_cert_cache, fingerprint, &revoked)) { ++ // found cert's fingerprint in cache ++ if (revoked) { ++ debug_printf("Certificate[%u] of '%s' has been revoked (cached)\n", it, hostname); ++ nrevoked++; ++ } else { ++ debug_printf("Certificate[%u] of '%s' is valid (cached)\n", it, hostname); ++ nvalid++; + } ++ continue; ++ } + +- if (deinit_issuer) { +- gnutls_x509_crt_deinit(issuer); +- deinit_issuer = 0; +- } +- if ((err = gnutls_certificate_get_issuer(credentials, cert, &issuer, 0)) != GNUTLS_E_SUCCESS && it < cert_list_size - 1) { +- gnutls_x509_crt_init(&issuer); +- deinit_issuer = 1; +- if ((err = gnutls_x509_crt_import(issuer, &cert_list[it + 1], GNUTLS_X509_FMT_DER)) != GNUTLS_E_SUCCESS) { +- debug_printf("Decoding error: %s\n", gnutls_strerror(err)); +- continue; +- } +- } else if (err != GNUTLS_E_SUCCESS) { +- debug_printf("Cannot find issuer: %s\n", gnutls_strerror(err)); ++ if (deinit_issuer) { ++ gnutls_x509_crt_deinit(issuer); ++ deinit_issuer = 0; ++ } ++ if ((err = gnutls_certificate_get_issuer(credentials, cert, &issuer, 0)) != GNUTLS_E_SUCCESS && it < cert_list_size - 1) { ++ gnutls_x509_crt_init(&issuer); ++ deinit_issuer = 1; ++ if ((err = gnutls_x509_crt_import(issuer, &cert_list[it + 1], GNUTLS_X509_FMT_DER)) != GNUTLS_E_SUCCESS) { ++ debug_printf("Decoding error: %s\n", gnutls_strerror(err)); + continue; + } ++ } else if (err != GNUTLS_E_SUCCESS) { ++ debug_printf("Cannot find issuer: %s\n", gnutls_strerror(err)); ++ continue; ++ } + +- ocsp_ok = cert_verify_ocsp(cert, issuer); +- debug_printf("check_ocsp_response() returned %d\n", ocsp_ok); +- +- if (ocsp_ok == 1) { +- debug_printf("Certificate[%u] of '%s' is valid (via OCSP)\n", it, hostname); +- wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, true); // 1h valid +- nvalid++; +- } else if (ocsp_ok == 0) { +- debug_printf("%s: Certificate[%u] of '%s' has been revoked (via OCSP)\n", tag, it, hostname); +- wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, false); // cert has been revoked +- nrevoked++; +- } else { +- debug_printf("WARNING: OCSP response not available or ignored\n"); +- nignored++; +- } ++ ocsp_ok = cert_verify_ocsp(cert, issuer); ++ debug_printf("check_ocsp_response() returned %d\n", ocsp_ok); ++ ++ if (ocsp_ok == 1) { ++ debug_printf("Certificate[%u] of '%s' is valid (via OCSP)\n", it, hostname); ++ wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, true); // 1h valid ++ nvalid++; ++ } else if (ocsp_ok == 0) { ++ debug_printf("%s: Certificate[%u] of '%s' has been revoked (via OCSP)\n", tag, it, hostname); ++ wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, false); // cert has been revoked ++ nrevoked++; ++ } else { ++ debug_printf("WARNING: OCSP response not available or ignored\n"); ++ nignored++; + } + #endif + } +commit f4e7c46073850af7b5c3d58b9452bdd2124b593c +Author: Tim Rühsen +Date: Sun May 19 19:36:59 2024 +0200 + + * libwget/ssl_gnutls.c (verify_certificate_callback): Fix 'do not translate debug strings' + +diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c +index 08f95383..a3cf6f5d 100644 +--- a/libwget/ssl_gnutls.c ++++ b/libwget/ssl_gnutls.c +@@ -1140,7 +1140,7 @@ static int verify_certificate_callback(gnutls_session_t session) + } + #endif + else if (!config.ocsp) { +- debug_printf(_("OCSP stapling is not supported by '%s'\n"), hostname); ++ debug_printf("OCSP stapling is not supported by '%s'\n", hostname); + } else { + error_printf_check(_("WARNING: OCSP stapling is not supported by '%s', but OCSP validation has been requested.\n"), hostname); + error_printf_check(_("WARNING: This implies a privacy leak: the client sends the certificate serial ID over HTTP to the CA.\n")); +commit de294c8ddf27b11e8abc7954856d590d7ce2d4f3 +Author: Tim Rühsen +Date: Sun May 19 20:02:31 2024 +0200 + + * libwget/ssl_gnutls.c (verify_certificate_callback): Fix gcc warning -Wjump-misses-init + +diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c +index a3cf6f5d..6edbcea1 100644 +--- a/libwget/ssl_gnutls.c ++++ b/libwget/ssl_gnutls.c +@@ -965,6 +965,7 @@ static int verify_certificate_callback(gnutls_session_t session) + gnutls_x509_crt_t cert = NULL, issuer = NULL; + const char *tag = config.check_certificate ? _("ERROR") : _("WARNING"); + #ifdef WITH_OCSP ++ bool skip_server_cert_check = false; + unsigned nvalid = 0, nrevoked = 0, nignored = 0; + #endif + +@@ -1121,8 +1122,6 @@ static int verify_certificate_callback(gnutls_session_t session) + // At this point, the cert chain has been found valid regarding the locally available CA certificates and CRLs. + // Now, we are going to check the revocation status via OCSP + #ifdef WITH_OCSP +- bool skip_server_cert_check = false; +- + if (config.ocsp_stapling) { + if (!ctx->valid && ctx->ocsp_stapling) { + #if GNUTLS_VERSION_NUMBER >= 0x030103 diff --git a/0005-Accept-progress-dot-.-for-backwards-compatibility.patch b/0005-Accept-progress-dot-.-for-backwards-compatibility.patch new file mode 100644 index 0000000..2d93ebd --- /dev/null +++ b/0005-Accept-progress-dot-.-for-backwards-compatibility.patch @@ -0,0 +1,57 @@ +From e8f1e99c96a8303421e66b0feda1651a11c8b250 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Mon, 20 May 2024 13:19:06 +0200 +Subject: [PATCH] Accept --progress=dot:... for backwards compatibility + +* src/options.c (parse_progress_type): Fix checking dot options. +* tests/test-wget-1.c: Add check for --progress variants. +--- + src/options.c | 6 +++--- + tests/test-wget-1.c | 10 ++++++++++ + 2 files changed, 13 insertions(+), 3 deletions(-) + +diff --git a/src/options.c b/src/options.c +index 7684b795..0f7b3f35 100644 +--- a/src/options.c ++++ b/src/options.c +@@ -798,13 +798,13 @@ static int WGET_GCC_PURE WGET_GCC_NONNULL((1)) parse_progress_type(option_t opt, + + if (!wget_strcasecmp_ascii(val, "none")) + *((char *)opt->var) = PROGRESS_TYPE_NONE; +- else if (!wget_strncasecmp_ascii(val, "bar", 3)) { ++ else if (!wget_strncasecmp_ascii(val, "bar", 3) && (val[3] == ':' || val[3] == 0)) { + *((char *)opt->var) = PROGRESS_TYPE_BAR; + // Silent Wget compatibility +- if (!wget_strncasecmp_ascii(val+3, ":force", 6) || !wget_strncasecmp_ascii(val+3, ":noscroll:force", 15)) { ++ if (!wget_strncasecmp_ascii(val+4, "force", 5) || !wget_strncasecmp_ascii(val+4, "noscroll:force", 14)) { + config.force_progress = true; + } +- } else if (!wget_strcasecmp_ascii(val, "dot")) { ++ } else if (!wget_strncasecmp_ascii(val, "dot", 3) && (val[3] == ':' || val[3] == 0)) { + // Wget compatibility, whether want to support 'dot' depends on user feedback. + info_printf(_("Progress type '%s' ignored. It is not implemented yet\n"), val); + } else { +diff --git a/tests/test-wget-1.c b/tests/test-wget-1.c +index fdd4f54e..8a08d74d 100644 +--- a/tests/test-wget-1.c ++++ b/tests/test-wget-1.c +@@ -626,6 +626,16 @@ int main(void) + { NULL } }, + 0); + ++ // test different --progress options to be accepted ++ wget_test( ++ WGET_TEST_OPTIONS, "--progress=none --progress=bar --progress=bar:force --progress=bar:noscroll:force --progress=dot --progress=dot:giga", ++ WGET_TEST_REQUEST_URL, "dummy.txt", ++ WGET_TEST_EXPECTED_ERROR_CODE, 0, ++ WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { ++ { "dummy.txt", urls[3].body }, ++ { NULL } }, ++ 0); ++ + // test--https-only + wget_test( + WGET_TEST_OPTIONS, "--https-only -r -nH", +-- +2.43.0 + diff --git a/wget2.spec b/wget2.spec index dea4bd7..c3476dc 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.1.0 -Release: 9%{?dist} +Release: 10%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -27,6 +27,12 @@ Patch0002: 0002-normalize-path-in-url.patch # https://github.com/rockdaboot/wget2/pull/316 # Allow option --no-tcp-fastopen to work on Linux kernels >= 4.11 Patch0003: 0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch +# https://gitlab.com/gnuwget/wget2/-/issues/664 +# Disable explicit OCSP requests by default for privacy reasons. +Patch0004: 0004-Disable-OCSP-by-default.patch +# https://gitlab.com/gnuwget/wget2/-/issues/661 +# Accept --progress=dot:... for backwards compatibility +Patch0005: 0005-Accept-progress-dot-.-for-backwards-compatibility.patch # Buildsystem build requirements BuildRequires: autoconf @@ -189,6 +195,10 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Mon May 20 2024 Romain Geissler - 2.1.0-10 +- Disable explicit OCSP requests by default for privacy reasons. +- Accept --progress=dot:... for backwards compatibility. + * Sat May 11 2024 Romain Geissler - 2.1.0-9 - Allow option --no-tcp-fastopen to work on Linux kernels >= 4.11. From 2685e7829399c0914b03a79c774762d77c044c9b Mon Sep 17 00:00:00 2001 From: Romain Geissler Date: Mon, 1 Jul 2024 22:03:26 +0000 Subject: [PATCH 04/15] Disable tcp fastopen as it is not well supported everywhere. Reported use case are users of the Palo Alto firewall and also the own Fedora infrastructure itself. Resovles: rhbz#2291017 --- 0006-Disable-TCP-Fast-Open-by-default.patch | 51 +++++++++++++++++++++ wget2.spec | 9 +++- 2 files changed, 59 insertions(+), 1 deletion(-) create mode 100644 0006-Disable-TCP-Fast-Open-by-default.patch diff --git a/0006-Disable-TCP-Fast-Open-by-default.patch b/0006-Disable-TCP-Fast-Open-by-default.patch new file mode 100644 index 0000000..a1ad51a --- /dev/null +++ b/0006-Disable-TCP-Fast-Open-by-default.patch @@ -0,0 +1,51 @@ +From 7a945d31aeb34fc73cf86a494673ae97e069d84d Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Sun, 30 Jun 2024 19:33:01 +0200 +Subject: [PATCH] Disable TCP Fast Open by default + +* docs/wget2.md: Amended description of --tcp-fastopen. +* src/options.c (struct config config): Disabled TFO. +--- + docs/wget2.md | 8 +++++++- + src/options.c | 1 - + 2 files changed, 7 insertions(+), 2 deletions(-) + +diff --git a/docs/wget2.md b/docs/wget2.md +index 61da3ccb..06828bf8 100644 +--- a/docs/wget2.md ++++ b/docs/wget2.md +@@ -730,12 +730,18 @@ Go to background immediately after startup. If no output file is specified via t + + ### `--tcp-fastopen` + +- Enable support for TCP Fast Open (TFO) (default: on). ++ Enable support for TCP Fast Open (TFO) (default: off). + + TFO reduces connection latency by 1 RT on "hot" connections (2nd+ connection to the same host in a certain amount of time). + + Currently this works on recent Linux and OSX kernels, on HTTP and HTTPS. + ++ The main reasons why TFO is disabled by default are ++ - possible user tracking issues ++ - possible issues with middle boxes that do not support TFO ++ ++ This article gives has more details about TFO than fits here: https://candrews.integralblue.com/2019/03/the-sad-story-of-tcp-fast-open/ ++ + ### `--dns-cache-preload=file` + + Load a list of IP / Name tuples into the DNS cache. +diff --git a/src/options.c b/src/options.c +index 026aa415..f4b5d1a1 100644 +--- a/src/options.c ++++ b/src/options.c +@@ -1235,7 +1235,6 @@ struct config config = { + .max_redirect = 20, + .max_threads = 5, + .dns_caching = 1, +- .tcp_fastopen = 1, + .user_agent = PACKAGE_NAME"/"PACKAGE_VERSION, + .verbose = 1, + .check_certificate= CHECK_CERTIFICATE_ENABLED, +-- +2.43.0 + diff --git a/wget2.spec b/wget2.spec index c3476dc..39a7645 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.1.0 -Release: 10%{?dist} +Release: 11%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -33,6 +33,10 @@ Patch0004: 0004-Disable-OCSP-by-default.patch # https://gitlab.com/gnuwget/wget2/-/issues/661 # Accept --progress=dot:... for backwards compatibility Patch0005: 0005-Accept-progress-dot-.-for-backwards-compatibility.patch +# https://gitlab.com/gnuwget/wget2/-/commit/7a945d31aeb34fc73cf86a494673ae97e069d84d +# Disable TCP Fast Open by default +# rhbz#2291017 +Patch0006: 0006-Disable-TCP-Fast-Open-by-default.patch # Buildsystem build requirements BuildRequires: autoconf @@ -195,6 +199,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Tue Jul 02 2024 Romain Geissler - 2.1.0-11 +- Disable TCP Fast Open by default + * Mon May 20 2024 Romain Geissler - 2.1.0-10 - Disable explicit OCSP requests by default for privacy reasons. - Accept --progress=dot:... for backwards compatibility. From 76c2c5ed886fa4c50d6a42400621920e081c717e Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 20 Jul 2024 09:17:18 +0000 Subject: [PATCH 05/15] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- wget2.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/wget2.spec b/wget2.spec index 39a7645..0ea03c4 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.1.0 -Release: 11%{?dist} +Release: 12%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -199,6 +199,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Sat Jul 20 2024 Fedora Release Engineering - 2.1.0-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Tue Jul 02 2024 Romain Geissler - 2.1.0-11 - Disable TCP Fast Open by default From a05eb637c21e1fa06926ef7e963518572f8cdbad Mon Sep 17 00:00:00 2001 From: Jonathan Wright Date: Fri, 9 Aug 2024 10:03:56 -0500 Subject: [PATCH 06/15] do not replace wget on el10 --- wget2.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/wget2.spec b/wget2.spec index 0ea03c4..73055b2 100644 --- a/wget2.spec +++ b/wget2.spec @@ -1,4 +1,4 @@ -%if (0%{?fedora} && 0%{?fedora} < 40) || (0%{?rhel} && 0%{?rhel} < 10) +%if (0%{?fedora} && 0%{?fedora} < 40) || (0%{?rhel} && 0%{?rhel} < 11) %bcond as_wget 0 %else %bcond as_wget 1 @@ -8,7 +8,7 @@ Name: wget2 Version: 2.1.0 -Release: 12%{?dist} +Release: 13%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -199,6 +199,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Fri Aug 09 2024 Jonathan Wright - 2.1.0-13 +- do not replace wget on el10 + * Sat Jul 20 2024 Fedora Release Engineering - 2.1.0-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From d8b2ba96fa6421621c476e573643f89a61161009 Mon Sep 17 00:00:00 2001 From: Michal Ruprich Date: Mon, 2 Dec 2024 10:02:47 +0100 Subject: [PATCH 07/15] New version 2.2.0 --- .gitignore | 2 + ...it-Redirect-INFO-logs-to-stderr-with.patch | 25 - 0001-use-signed-char-ascii.patch | 24 + 0002-dont-truncate-no-clobber.patch | 23 + 0002-normalize-path-in-url.patch | 48 -- ...tcp-fastopen-to-work-on-Linux-kernel.patch | 35 - 0004-Disable-OCSP-by-default.patch | 627 ------------------ ...ss-dot-.-for-backwards-compatibility.patch | 57 -- 0006-Disable-TCP-Fast-Open-by-default.patch | 51 -- sources | 4 +- wget2.spec | 37 +- 11 files changed, 67 insertions(+), 866 deletions(-) delete mode 100644 0001-src-log.c-log_init-Redirect-INFO-logs-to-stderr-with.patch create mode 100644 0001-use-signed-char-ascii.patch create mode 100644 0002-dont-truncate-no-clobber.patch delete mode 100644 0002-normalize-path-in-url.patch delete mode 100644 0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch delete mode 100644 0004-Disable-OCSP-by-default.patch delete mode 100644 0005-Accept-progress-dot-.-for-backwards-compatibility.patch delete mode 100644 0006-Disable-TCP-Fast-Open-by-default.patch diff --git a/.gitignore b/.gitignore index 447fe5f..70ccca6 100644 --- a/.gitignore +++ b/.gitignore @@ -1,3 +1,5 @@ /wget2-2.0.0.tar.gz /wget2-2.1.0.tar.gz /wget2-2.1.0.tar.gz.sig +/wget2-2.2.0.tar.gz +/wget2-2.2.0.tar.gz.sig diff --git a/0001-src-log.c-log_init-Redirect-INFO-logs-to-stderr-with.patch b/0001-src-log.c-log_init-Redirect-INFO-logs-to-stderr-with.patch deleted file mode 100644 index c34f426..0000000 --- a/0001-src-log.c-log_init-Redirect-INFO-logs-to-stderr-with.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 7da90c7ea755fffbfbe9006d29524c7c8a86a925 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Tim=20R=C3=BChsen?= -Date: Sun, 14 Jan 2024 16:43:15 +0100 -Subject: [PATCH] * src/log.c (log_init): Redirect INFO logs to stderr with -O- - ---- - src/log.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/log.c b/src/log.c -index 8b6796e9..61adde4b 100644 ---- a/src/log.c -+++ b/src/log.c -@@ -226,7 +226,7 @@ void log_init(void) - - // set info logging - wget_logger_set_func(wget_get_logger(WGET_LOGGER_INFO), -- config.verbose && !config.quiet ? (fileno(stdout) == fileno(stderr) ? write_info_stderr : write_info_stdout) : NULL); -+ config.verbose && !config.quiet ? ((fileno(stdout) == fileno(stderr) || !wget_strcmp(config.output_document, "-")) ? write_info_stderr : write_info_stdout) : NULL); - // wget_logger_set_stream(wget_get_logger(WGET_LOGGER_INFO), config.verbose && !config.quiet ? stdout : NULL); - #endif - } --- -2.43.0 - diff --git a/0001-use-signed-char-ascii.patch b/0001-use-signed-char-ascii.patch new file mode 100644 index 0000000..5f49f3e --- /dev/null +++ b/0001-use-signed-char-ascii.patch @@ -0,0 +1,24 @@ +From e4a04807d77d4eb1dfe63442ef1ad2ba749e86cc Mon Sep 17 00:00:00 2001 +From: Michal Ruprich +Date: Sat, 30 Nov 2024 19:52:23 +0100 +Subject: [PATCH] * src/utils.c (wget_restrict_file_name): Explicitly use + signed char + +Fix test--restrict-ascii failures on aarch64, s390x and ppc64le. +--- + src/utils.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/utils.c b/src/utils.c +index fa2104f60..54a03f76c 100644 +--- a/src/utils.c ++++ b/src/utils.c +@@ -151,7 +151,7 @@ char *wget_restrict_file_name(const char *fname, char *esc, int mode) + bool ascii = mode & WGET_RESTRICT_NAMES_ASCII; + + for (dst = esc, s = fname; *s; s++) { +- char c = *s; ++ signed char c = *s; + + if (lowercase && c >= 'A' && c <= 'Z') { // isupper() also returns true for chars > 0x7f, the test is not EBCDIC compatible ;-) + c |= 0x20; diff --git a/0002-dont-truncate-no-clobber.patch b/0002-dont-truncate-no-clobber.patch new file mode 100644 index 0000000..ee13135 --- /dev/null +++ b/0002-dont-truncate-no-clobber.patch @@ -0,0 +1,23 @@ +From ad80bf39ce6b2bc39a9b286d3f3fc6b67142e7e7 Mon Sep 17 00:00:00 2001 +From: Michal Ruprich +Date: Tue, 26 Nov 2024 13:26:06 +0100 +Subject: [PATCH] Prevent file truncation with --no-clobber + +* src/options.c (init): Check config.clobber. +--- + src/options.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/options.c b/src/options.c +index 36cd3bb4..2132bfd1 100644 +--- a/src/options.c ++++ b/src/options.c +@@ -3492,7 +3492,7 @@ int init(int argc, const char **argv) + if (config.output_document && strcmp(config.output_document, "-") && !config.dont_write) { + if (config.unlink) { + unlink(config.output_document); +- } else if (!config.continue_download) { ++ } else if (!config.continue_download && config.clobber) { + int fd = open(config.output_document, O_WRONLY | O_TRUNC | O_BINARY); + + if (fd != -1) diff --git a/0002-normalize-path-in-url.patch b/0002-normalize-path-in-url.patch deleted file mode 100644 index 9fce4b7..0000000 --- a/0002-normalize-path-in-url.patch +++ /dev/null @@ -1,48 +0,0 @@ -From 9aeab55d09f9df833bca4467b0a209cea2901ede Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Tim=20R=C3=BChsen?= -Date: Thu, 28 Mar 2024 18:12:19 +0100 -Subject: [PATCH] Fix --no-parent for denormalized paths - -* libwget/iri.c (wget_iri_parse): Normalize path part of URL. -* unit-tests/test.c (test_iri_parse): Add test with denormalized path. ---- - libwget/iri.c | 3 +++ - unit-tests/test.c | 1 + - 2 files changed, 4 insertions(+) - -diff --git a/libwget/iri.c b/libwget/iri.c -index 8241ea971..13bd5259b 100644 ---- a/libwget/iri.c -+++ b/libwget/iri.c -@@ -82,6 +82,8 @@ static struct iri_scheme { - [WGET_IRI_SCHEME_HTTPS] = { 443, "https" }, - }; - -+static size_t WGET_GCC_NONNULL_ALL normalize_path(char *path); -+ - /** - * \param[in] scheme Scheme to get name for - * \return Name of \p scheme (e.g. "http" or "https") or NULL is not supported -@@ -561,6 +563,7 @@ wget_iri *wget_iri_parse(const char *url, const char *encoding) - c = *s; - if (c) *s++ = 0; - wget_iri_unescape_inline((char *)iri->path); -+ normalize_path((char *)iri->path); - } - - if (c == '?') { -diff --git a/unit-tests/test.c b/unit-tests/test.c -index da8cc728b..80ddeced5 100644 ---- a/unit-tests/test.c -+++ b/unit-tests/test.c -@@ -584,6 +584,7 @@ static void test_iri_parse(void) - { "http://example+.com/pa+th?qu+ery#fr+ag", NULL, WGET_IRI_SCHEME_HTTP, NULL, NULL, "example+.com", 80, "pa+th", "qu ery", "fr+ag"}, - { "http://example.com#frag?x", NULL, WGET_IRI_SCHEME_HTTP, NULL, NULL, "example.com", 80, NULL, NULL, "frag?x"}, - { "http://user:pw@example.com", NULL, WGET_IRI_SCHEME_HTTP, "user", "pw", "example.com", 80, NULL, NULL, NULL}, -+ { "http://example.com//path//file", NULL, WGET_IRI_SCHEME_HTTP, NULL, NULL, "example.com", 80, "path/file", NULL, NULL}, - }; - unsigned it; - --- -GitLab - diff --git a/0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch b/0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch deleted file mode 100644 index 9dd1dc0..0000000 --- a/0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 7929bf887c69ffdcbdfb525825bffba4c9e5d6e8 Mon Sep 17 00:00:00 2001 -From: Romain Geissler -Date: Fri, 10 May 2024 16:24:57 +0000 -Subject: [PATCH] Allow option --no-tcp-fastopen to work on Linux kernels >= - 4.11. - -* libwget/net.c (set_socket_options): Add check for tcp->tcp_fastopen. - -Copyright-paperwork-exempt: Yes ---- - libwget/net.c | 8 +++++--- - 1 file changed, 5 insertions(+), 3 deletions(-) - -diff --git a/libwget/net.c b/libwget/net.c -index 8fc6d143..836649c0 100644 ---- a/libwget/net.c -+++ b/libwget/net.c -@@ -640,9 +640,11 @@ static void set_socket_options(const wget_tcp *tcp, int fd) - #endif - - #ifdef TCP_FASTOPEN_LINUX_411 -- on = 1; -- if (setsockopt(fd, IPPROTO_TCP, TCP_FASTOPEN_CONNECT, (void *)&on, sizeof(on)) == -1) -- debug_printf("Failed to set socket option TCP_FASTOPEN_CONNECT\n"); -+ if (tcp->tcp_fastopen) { -+ on = 1; -+ if (setsockopt(fd, IPPROTO_TCP, TCP_FASTOPEN_CONNECT, (void *)&on, sizeof(on)) == -1) -+ debug_printf("Failed to set socket option TCP_FASTOPEN_CONNECT\n"); -+ } - #endif - } - --- -2.43.0 - diff --git a/0004-Disable-OCSP-by-default.patch b/0004-Disable-OCSP-by-default.patch deleted file mode 100644 index edf1931..0000000 --- a/0004-Disable-OCSP-by-default.patch +++ /dev/null @@ -1,627 +0,0 @@ -Backport of all the OCSP-related commits related to issue https://gitlab.com/gnuwget/wget2/-/issues/664: - - 53a8a88e8479fca04fb17f923b0f40781ee6a253 - - a96f88a054a0dbb31eb23d7f39b0922447177ab3 - - 715e646642e169a0a4510bdf51a5b4fc512f94d6 - - 35986bd093676df0b2acd6110620534d41d0ec4d - - 0895f9230859207385393a148d6b0a6ec24521b9 - - c341fcd1dfd57b3cf5a1f5acb84784571fff3a20 - - c556a3226aca0e99191b52218117b7967889a9bf - - 543e1f270821cc7ea562444bfd79ae4d66d5b964 - - f4e7c46073850af7b5c3d58b9452bdd2124b593c - - de294c8ddf27b11e8abc7954856d590d7ce2d4f3 - - -commit 53a8a88e8479fca04fb17f923b0f40781ee6a253 -Author: Tim Rühsen -Date: Sun May 12 15:14:31 2024 +0200 - - Fix OCSP verification of first intermediate certificate. - - * libwget/ssl_gnutls.c (verify_certificate_callback): Fix off-by-one check. - - See https://gitlab.com/gnuwget/wget2/-/issues/664#note_1901610438 - -diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c -index 35f20279..5524c02c 100644 ---- a/libwget/ssl_gnutls.c -+++ b/libwget/ssl_gnutls.c -@@ -1153,7 +1153,7 @@ static int verify_certificate_callback(gnutls_session_t session) - cert_verify_hpkp(cert, hostname, session); - - #ifdef WITH_OCSP -- if (config.ocsp && it > nvalid) { -+ if (config.ocsp && it >= nvalid) { - char fingerprint[64 * 2 +1]; - int revoked; - -commit a96f88a054a0dbb31eb23d7f39b0922447177ab3 -Author: Tim Rühsen -Date: Sun May 12 19:51:03 2024 +0200 - - -* libwget/ssl_gnutls.c (cert_verify_ocsp): Fix segfault when OCSP response is missing - -diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c -index 5524c02c..1058e50f 100644 ---- a/libwget/ssl_gnutls.c -+++ b/libwget/ssl_gnutls.c -@@ -860,6 +860,11 @@ static int cert_verify_ocsp(gnutls_x509_crt_t cert, gnutls_x509_crt_t issuer) - return -1; - } - -+ if (!resp) { -+ debug_printf("Missing response from OCSP server\n"); -+ return -1; -+ } -+ - /* verify and check the response for revoked cert */ - ret = check_ocsp_response(cert, issuer, resp, &nonce); - wget_buffer_free(&resp); -commit 715e646642e169a0a4510bdf51a5b4fc512f94d6 -Author: Tim Rühsen -Date: Sun May 12 19:51:44 2024 +0200 - - Fix tests/test-ocsp-server - - * tests/libtest.c: Handle > 1 OCSP responses. - * tests/libtest.h: Rename WGET_TEST_OCSP_RESP_FILE to WGET_TEST_OCSP_RESP_FILES. - * tests/test-ocsp-server.c: Make use of WGET_TEST_OCSP_RESP_FILES. - -diff --git a/tests/libtest.c b/tests/libtest.c -index 533f5d47..e3850bc0 100644 ---- a/tests/libtest.c -+++ b/tests/libtest.c -@@ -90,9 +90,11 @@ static int - keep_tmpfiles, - clean_directory, - reject_http_connection, -- reject_https_connection; -+ reject_https_connection, -+ ocsp_response_pos; - static wget_vector -- *request_urls; -+ *request_urls, -+ *ocsp_responses; - static wget_test_url_t - *urls; - static size_t -@@ -121,12 +123,12 @@ static struct MHD_Daemon - static gnutls_pcert_st *pcrt; - static gnutls_privkey_t *privkey; - --static struct ocsp_resp_t { -+typedef struct { - char - *data; - size_t - size; --} *ocsp_resp; -+} ocsp_resp_t; - #endif - - #ifdef WITH_GNUTLS_OCSP -@@ -311,14 +313,14 @@ static enum MHD_Result _ocsp_ahc( - } else if (!first && upload_data == NULL) { - int ret = 0; - -- if (ocsp_resp->data) { -+ ocsp_resp_t *ocsp_resp = wget_vector_get(ocsp_responses, ocsp_response_pos++); -+ -+ if (ocsp_resp) { - struct MHD_Response *response = MHD_create_response_from_buffer (ocsp_resp->size, ocsp_resp->data, MHD_RESPMEM_MUST_COPY); - - ret = MHD_queue_response (connection, MHD_HTTP_OK, response); - - MHD_destroy_response (response); -- -- wget_xfree(ocsp_resp->data); - } - - return ret; -@@ -715,11 +717,6 @@ static void _http_server_stop(void) - - #ifdef WITH_GNUTLS_OCSP - gnutls_global_deinit(); -- -- if(ocsp_resp) -- wget_free(ocsp_resp->data); -- -- wget_xfree(ocsp_resp); - #endif - } - -@@ -892,8 +889,6 @@ static int _http_server_start(int SERVER_MODE) - #endif - MHD_OPTION_CONNECTION_MEMORY_LIMIT, (size_t) 1*1024*1024, - MHD_OPTION_END); -- -- ocsp_resp = wget_malloc(sizeof(struct ocsp_resp_t)); - #endif - - if (!ocspdaemon) -@@ -1121,6 +1116,7 @@ void wget_test_stop_server(void) - { - // wget_vector_free(&response_headers); - wget_vector_free(&request_urls); -+ wget_vector_free(&ocsp_responses); - - for (wget_test_url_t *url = urls; url < urls + nurls; url++) { - if (url->body_original) { -@@ -1535,9 +1531,6 @@ void wget_test(int first_key, ...) - const char - *request_url, - *options = "", --#ifdef WITH_GNUTLS_OCSP -- *ocsp_resp_file = NULL, --#endif - *executable = global_executable; - const wget_test_file_t - *expected_files = NULL, -@@ -1581,6 +1574,10 @@ void wget_test(int first_key, ...) - wget_vector_set_destructor(request_urls, NULL); - } - -+ if (!ocsp_responses) { -+ ocsp_responses = wget_vector_create(2, NULL); -+ } -+ - va_start (args, first_key); - for (key = first_key; key; key = va_arg(args, int)) { - switch (key) { -@@ -1633,9 +1630,24 @@ void wget_test(int first_key, ...) - #endif - } - break; -- case WGET_TEST_OCSP_RESP_FILE: -+ case WGET_TEST_OCSP_RESP_FILES: - #ifdef WITH_GNUTLS_OCSP -- ocsp_resp_file = va_arg(args, const char *); -+ { -+ const char *ocsp_resp_file = NULL; -+ while ((ocsp_resp_file = va_arg(args, const char *))) { -+ if (ocspdaemon) { -+ ocsp_resp_t ocsp_resp = { .data = wget_strdup(""), .size = 0 }; -+ if (*ocsp_resp_file) { -+ ocsp_resp.data = wget_read_file(ocsp_resp_file, &ocsp_resp.size); -+ if (ocsp_resp.data == NULL) { -+ wget_error_printf_exit("Couldn't read the response from '%s'.\n", ocsp_resp_file); -+ } -+ } -+ wget_vector_add_memdup(ocsp_responses, &ocsp_resp, sizeof(ocsp_resp)); -+ } -+ } -+ ocsp_response_pos = 0; -+ } - #endif - break; - default: -@@ -1650,19 +1662,6 @@ void wget_test(int first_key, ...) - _empty_directory(cmd->data); - } - --#ifdef WITH_GNUTLS_OCSP -- if (ocspdaemon) { -- if (ocsp_resp_file) { -- ocsp_resp->data = wget_read_file(ocsp_resp_file, &(ocsp_resp->size)); -- if (ocsp_resp->data == NULL) { -- wget_error_printf_exit("Couldn't read the response.\n"); -- } -- } else { -- wget_error_printf_exit("Need value for option WGET_TEST_OCSP_RESP_FILE.\n"); -- } -- } --#endif -- - // create files - if (existing_files) { - for (it = 0; existing_files[it].name; it++) { -@@ -1835,6 +1834,11 @@ void wget_test(int first_key, ...) - wget_free(post_handshake_auth); - #endif - -+ for (int i = 0; i < wget_vector_size(ocsp_responses); i++) { -+ ocsp_resp_t *r = wget_vector_get(ocsp_responses, it); -+ wget_xfree(r->data); -+ } -+ wget_vector_clear(ocsp_responses); - wget_vector_clear(request_urls); - wget_buffer_free(&cmd); - -diff --git a/tests/libtest.h b/tests/libtest.h -index 7aa72088..dfccbe0b 100644 ---- a/tests/libtest.h -+++ b/tests/libtest.h -@@ -76,7 +76,7 @@ extern "C" { - #define WGET_TEST_POST_HANDSHAKE_AUTH 3002 - - // for OCSP testing --#define WGET_TEST_OCSP_RESP_FILE 3003 -+#define WGET_TEST_OCSP_RESP_FILES 3003 - - typedef enum { - INTERRUPT_RESPONSE_DISABLED = 0, -diff --git a/tests/test-ocsp-server.c b/tests/test-ocsp-server.c -index 8b844e18..ebe443a5 100644 ---- a/tests/test-ocsp-server.c -+++ b/tests/test-ocsp-server.c -@@ -46,7 +46,7 @@ int main(void) - WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp --ocsp-server http://localhost:{{ocspport}}", - WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", - WGET_TEST_EXPECTED_ERROR_CODE, 0, -- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_ok.der", -+ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_ok.der", NULL, - WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { - {urls[0].name + 1, urls[0].body}, - { NULL} }, -@@ -58,7 +58,7 @@ int main(void) - WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp --ocsp-server http://localhost:{{ocspport}}", - WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", - WGET_TEST_EXPECTED_ERROR_CODE, 5, -- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", -+ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", NULL, - 0); - #endif - -@@ -67,7 +67,7 @@ int main(void) - WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp --ocsp-server http://localhost:{{ocspport}} --no-check-certificate", - WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", - WGET_TEST_EXPECTED_ERROR_CODE, 0, -- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", -+ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_revoked.der", NULL, - WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { - {urls[0].name + 1, urls[0].body}, - { NULL} }, -@@ -79,7 +79,7 @@ int main(void) - WGET_TEST_OPTIONS, "--ca-certificate=" SRCDIR "/certs/ocsp/x509-root-cert.pem --no-ocsp-file --no-ocsp-date --no-ocsp-nonce --ocsp", - WGET_TEST_REQUEST_URL, "https://localhost:{{sslport}}/index.html", - WGET_TEST_EXPECTED_ERROR_CODE, 0, -- WGET_TEST_OCSP_RESP_FILE, SRCDIR "/certs/ocsp/ocsp_resp_ok.der", -+ WGET_TEST_OCSP_RESP_FILES, "", SRCDIR "/certs/ocsp/ocsp_resp_ok.der", NULL, - WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { - {urls[0].name + 1, urls[0].body}, - { NULL} }, -commit 35986bd093676df0b2acd6110620534d41d0ec4d -Author: Tim Rühsen -Date: Sat May 18 14:35:45 2024 +0200 - - Disable explicit OCSP requests by default - - * docs/wget2.md: Document --ocsp default value as 'off'. - * src/options.c (struct config): Disable .ocsp by default. - - OCSP validation of the server certificate implies privacy issues: - - The OCSP request tells the CA which web service the client tries to reach. - - The OCSP requests are sent via unencrypted HTTP, so every "listener in the - middle" can see which web service the client tries to connect. - Additionally, the OCSP requests slow down operation and may cause unexpected - network traffic, which may trigger security alarms unnecessarily. - - Due to these issues we explicitly disable OCSP by default. - -diff --git a/docs/wget2.md b/docs/wget2.md -index 6e408592..61da3ccb 100644 ---- a/docs/wget2.md -+++ b/docs/wget2.md -@@ -1569,7 +1569,7 @@ Go to background immediately after startup. If no output file is specified via t - - ### `--ocsp` - -- Enable OCSP server access to check the possible revocation the HTTPS server certificate(s) (default: on). -+ Enable OCSP server access to check the possible revocation the HTTPS server certificate(s) (default: off). - - This procedure is pretty slow (connect to server, HTTP request, response) and thus we support - OSCP stapling (server sends OCSP response within TLS handshake) and persistent OCSP caching. -diff --git a/src/options.c b/src/options.c -index 54e8cabb..7684b795 100644 ---- a/src/options.c -+++ b/src/options.c -@@ -1302,7 +1302,16 @@ struct config config = { - .http2 = 1, - .http2_request_window = 30, - #endif -- .ocsp = 1, -+ // OCSP validation of the server certificate implies privacy issues: -+ // - The OCSP request tells the CA which web service the client tries to reach. -+ // - The OCSP requests are sent via unencrypted HTTP, so every "listener in the middle" can see which web service -+ // the client tries to connect. -+ // Additionally, the OCSP requests slow down operation and may cause unexpected network traffic, which may trigger -+ // security alarms unnecessarily. -+ // Due to these issues we explicitly disable OCSP by default. -+ // -+ // The upside of enabling OCSP mostly is a "real-time" recognition of certificate revocations. -+ .ocsp = 0, - .ocsp_date = 1, - .ocsp_stapling = 1, - .ocsp_nonce = 1, -commit 0895f9230859207385393a148d6b0a6ec24521b9 -Author: Tim Rühsen -Date: Sat May 18 14:46:07 2024 +0200 - - * libwget/ssl_gnutls.c: Improve messages for OCSP stapling - -diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c -index 1058e50f..f12b5e74 100644 ---- a/libwget/ssl_gnutls.c -+++ b/libwget/ssl_gnutls.c -@@ -1136,7 +1136,7 @@ static int verify_certificate_callback(gnutls_session_t session) - } - #endif - else if (!config.ocsp) -- error_printf_check(_("WARNING: The certificate's (stapled) OCSP status has not been sent\n")); -+ error_printf_check(_("WARNING: OCSP stapling is not supported by '%s'\n"), hostname); - #endif - } else if (ctx->valid) - debug_printf("OCSP: Host '%s' is valid (from cache)\n", hostname); -@@ -1728,13 +1728,14 @@ int wget_ssl_open(wget_tcp *tcp) - // If we know the cert chain for the hostname being valid at the moment, - // we don't ask for OCSP stapling to avoid unneeded IP traffic. - // In the unlikely case that the server's certificate chain changed right now, -- // we fallback to OCSP responder request later. -+ // we fallback to OCSP responder request later (if enabled). - if (hostname) { - if (!(ctx->valid = wget_ocsp_hostname_is_valid(config.ocsp_host_cache, hostname))) { - #if GNUTLS_VERSION_NUMBER >= 0x030103 -- if ((rc = gnutls_ocsp_status_request_enable_client(session, NULL, 0, NULL)) == GNUTLS_E_SUCCESS) -+ if ((rc = gnutls_ocsp_status_request_enable_client(session, NULL, 0, NULL)) == GNUTLS_E_SUCCESS) { -+ debug_printf("OCSP stapling requested for %s\n", hostname); - ctx->ocsp_stapling = 1; -- else -+ } else - error_printf("GnuTLS: %s\n", gnutls_strerror(rc)); // no translation - #endif - } -commit c341fcd1dfd57b3cf5a1f5acb84784571fff3a20 -Author: Tim Rühsen -Date: Sun May 19 12:41:55 2024 +0200 - - Disable explicit OCSP requests by default for TLS library functions - - * libwget/ssl_openssl: Disable explicit OCSP requests by default. - * libwget/ssl_gnutls: Likewise. - * libwget/ssl_wolfssl.c: Likewise. - -diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c -index f12b5e74..7dbbde39 100644 ---- a/libwget/ssl_gnutls.c -+++ b/libwget/ssl_gnutls.c -@@ -116,7 +116,7 @@ static struct config { - .report_invalid_cert = 1, - .check_hostname = 1, - #ifdef WITH_OCSP -- .ocsp = 1, -+ .ocsp = 0, - .ocsp_stapling = 1, - #endif - .ca_type = WGET_SSL_X509_FMT_PEM, -diff --git a/libwget/ssl_openssl.c b/libwget/ssl_openssl.c -index 94da0d3f..2332ec40 100644 ---- a/libwget/ssl_openssl.c -+++ b/libwget/ssl_openssl.c -@@ -102,7 +102,7 @@ static struct config - .check_certificate = 1, - .check_hostname = 1, - #ifdef WITH_OCSP -- .ocsp = 1, -+ .ocsp = 0, - .ocsp_stapling = 1, - #endif - .ca_type = WGET_SSL_X509_FMT_PEM, -diff --git a/libwget/ssl_wolfssl.c b/libwget/ssl_wolfssl.c -index 47ed9ba9..967e984d 100644 ---- a/libwget/ssl_wolfssl.c -+++ b/libwget/ssl_wolfssl.c -@@ -108,7 +108,7 @@ static struct config { - .check_certificate = 1, - .report_invalid_cert = 1, - .check_hostname = 1, -- .ocsp = 1, -+ .ocsp = 0, - .ocsp_stapling = 1, - .ca_type = WGET_SSL_X509_FMT_PEM, - .cert_type = WGET_SSL_X509_FMT_PEM, -commit c556a3226aca0e99191b52218117b7967889a9bf -Author: Tim Rühsen -Date: Sun May 19 13:05:11 2024 +0200 - - * libwget/ssl_openssl.c (verify_ocsp): Fix segfault when OCSP response is missing - -diff --git a/libwget/ssl_openssl.c b/libwget/ssl_openssl.c -index 2332ec40..6cac6ecb 100644 ---- a/libwget/ssl_openssl.c -+++ b/libwget/ssl_openssl.c -@@ -1024,9 +1024,7 @@ static int verify_ocsp(const char *ocsp_uri, - certid = OCSP_cert_to_id(EVP_sha1(), subject_cert, issuer_cert); - - /* Send OCSP request to server, via HTTP */ -- if (!(ocspreq = send_ocsp_request(ocsp_uri, -- certid, -- &resp))) -+ if (!(ocspreq = send_ocsp_request(ocsp_uri, certid, &resp)) || !resp || !resp->body) - return -1; - - /* Check server's OCSP response */ -commit 543e1f270821cc7ea562444bfd79ae4d66d5b964 -Author: Tim Rühsen -Date: Sun May 19 12:26:29 2024 +0200 - - * libwget/ssl_gnutls.c (verify_certificate_callback): Warn about OCSP privacy leak - -diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c -index 7dbbde39..08f95383 100644 ---- a/libwget/ssl_gnutls.c -+++ b/libwget/ssl_gnutls.c -@@ -1121,6 +1121,8 @@ static int verify_certificate_callback(gnutls_session_t session) - // At this point, the cert chain has been found valid regarding the locally available CA certificates and CRLs. - // Now, we are going to check the revocation status via OCSP - #ifdef WITH_OCSP -+ bool skip_server_cert_check = false; -+ - if (config.ocsp_stapling) { - if (!ctx->valid && ctx->ocsp_stapling) { - #if GNUTLS_VERSION_NUMBER >= 0x030103 -@@ -1129,14 +1131,20 @@ static int verify_certificate_callback(gnutls_session_t session) - // _get_cert_fingerprint(cert, fingerprint, sizeof(fingerprint)); // calc hexadecimal fingerprint string - add_cert_to_ocsp_cache(cert, true); - nvalid = 1; -+ skip_server_cert_check = true; - } - #if GNUTLS_VERSION_NUMBER >= 0x030400 - else if (gnutls_ocsp_status_request_is_checked(session, GNUTLS_OCSP_SR_IS_AVAIL)) { - error_printf_check(_("WARNING: The certificate's (stapled) OCSP status is invalid\n")); -+ skip_server_cert_check = true; - } - #endif -- else if (!config.ocsp) -- error_printf_check(_("WARNING: OCSP stapling is not supported by '%s'\n"), hostname); -+ else if (!config.ocsp) { -+ debug_printf(_("OCSP stapling is not supported by '%s'\n"), hostname); -+ } else { -+ error_printf_check(_("WARNING: OCSP stapling is not supported by '%s', but OCSP validation has been requested.\n"), hostname); -+ error_printf_check(_("WARNING: This implies a privacy leak: the client sends the certificate serial ID over HTTP to the CA.\n")); -+ } - #endif - } else if (ctx->valid) - debug_printf("OCSP: Host '%s' is valid (from cache)\n", hostname); -@@ -1158,55 +1166,55 @@ static int verify_certificate_callback(gnutls_session_t session) - cert_verify_hpkp(cert, hostname, session); - - #ifdef WITH_OCSP -- if (config.ocsp && it >= nvalid) { -- char fingerprint[64 * 2 +1]; -- int revoked; -+ if (!config.ocsp || (skip_server_cert_check && it == 0)) -+ continue; - -- _get_cert_fingerprint(cert, fingerprint, sizeof(fingerprint)); // calc hexadecimal fingerprint string -+ char fingerprint[64 * 2 +1]; -+ _get_cert_fingerprint(cert, fingerprint, sizeof(fingerprint)); // calc hexadecimal fingerprint string - -- if (wget_ocsp_fingerprint_in_cache(config.ocsp_cert_cache, fingerprint, &revoked)) { -- // found cert's fingerprint in cache -- if (revoked) { -- debug_printf("Certificate[%u] of '%s' has been revoked (cached)\n", it, hostname); -- nrevoked++; -- } else { -- debug_printf("Certificate[%u] of '%s' is valid (cached)\n", it, hostname); -- nvalid++; -- } -- continue; -+ int revoked; -+ if (wget_ocsp_fingerprint_in_cache(config.ocsp_cert_cache, fingerprint, &revoked)) { -+ // found cert's fingerprint in cache -+ if (revoked) { -+ debug_printf("Certificate[%u] of '%s' has been revoked (cached)\n", it, hostname); -+ nrevoked++; -+ } else { -+ debug_printf("Certificate[%u] of '%s' is valid (cached)\n", it, hostname); -+ nvalid++; - } -+ continue; -+ } - -- if (deinit_issuer) { -- gnutls_x509_crt_deinit(issuer); -- deinit_issuer = 0; -- } -- if ((err = gnutls_certificate_get_issuer(credentials, cert, &issuer, 0)) != GNUTLS_E_SUCCESS && it < cert_list_size - 1) { -- gnutls_x509_crt_init(&issuer); -- deinit_issuer = 1; -- if ((err = gnutls_x509_crt_import(issuer, &cert_list[it + 1], GNUTLS_X509_FMT_DER)) != GNUTLS_E_SUCCESS) { -- debug_printf("Decoding error: %s\n", gnutls_strerror(err)); -- continue; -- } -- } else if (err != GNUTLS_E_SUCCESS) { -- debug_printf("Cannot find issuer: %s\n", gnutls_strerror(err)); -+ if (deinit_issuer) { -+ gnutls_x509_crt_deinit(issuer); -+ deinit_issuer = 0; -+ } -+ if ((err = gnutls_certificate_get_issuer(credentials, cert, &issuer, 0)) != GNUTLS_E_SUCCESS && it < cert_list_size - 1) { -+ gnutls_x509_crt_init(&issuer); -+ deinit_issuer = 1; -+ if ((err = gnutls_x509_crt_import(issuer, &cert_list[it + 1], GNUTLS_X509_FMT_DER)) != GNUTLS_E_SUCCESS) { -+ debug_printf("Decoding error: %s\n", gnutls_strerror(err)); - continue; - } -+ } else if (err != GNUTLS_E_SUCCESS) { -+ debug_printf("Cannot find issuer: %s\n", gnutls_strerror(err)); -+ continue; -+ } - -- ocsp_ok = cert_verify_ocsp(cert, issuer); -- debug_printf("check_ocsp_response() returned %d\n", ocsp_ok); -- -- if (ocsp_ok == 1) { -- debug_printf("Certificate[%u] of '%s' is valid (via OCSP)\n", it, hostname); -- wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, true); // 1h valid -- nvalid++; -- } else if (ocsp_ok == 0) { -- debug_printf("%s: Certificate[%u] of '%s' has been revoked (via OCSP)\n", tag, it, hostname); -- wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, false); // cert has been revoked -- nrevoked++; -- } else { -- debug_printf("WARNING: OCSP response not available or ignored\n"); -- nignored++; -- } -+ ocsp_ok = cert_verify_ocsp(cert, issuer); -+ debug_printf("check_ocsp_response() returned %d\n", ocsp_ok); -+ -+ if (ocsp_ok == 1) { -+ debug_printf("Certificate[%u] of '%s' is valid (via OCSP)\n", it, hostname); -+ wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, true); // 1h valid -+ nvalid++; -+ } else if (ocsp_ok == 0) { -+ debug_printf("%s: Certificate[%u] of '%s' has been revoked (via OCSP)\n", tag, it, hostname); -+ wget_ocsp_db_add_fingerprint(config.ocsp_cert_cache, fingerprint, time(NULL) + 3600, false); // cert has been revoked -+ nrevoked++; -+ } else { -+ debug_printf("WARNING: OCSP response not available or ignored\n"); -+ nignored++; - } - #endif - } -commit f4e7c46073850af7b5c3d58b9452bdd2124b593c -Author: Tim Rühsen -Date: Sun May 19 19:36:59 2024 +0200 - - * libwget/ssl_gnutls.c (verify_certificate_callback): Fix 'do not translate debug strings' - -diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c -index 08f95383..a3cf6f5d 100644 ---- a/libwget/ssl_gnutls.c -+++ b/libwget/ssl_gnutls.c -@@ -1140,7 +1140,7 @@ static int verify_certificate_callback(gnutls_session_t session) - } - #endif - else if (!config.ocsp) { -- debug_printf(_("OCSP stapling is not supported by '%s'\n"), hostname); -+ debug_printf("OCSP stapling is not supported by '%s'\n", hostname); - } else { - error_printf_check(_("WARNING: OCSP stapling is not supported by '%s', but OCSP validation has been requested.\n"), hostname); - error_printf_check(_("WARNING: This implies a privacy leak: the client sends the certificate serial ID over HTTP to the CA.\n")); -commit de294c8ddf27b11e8abc7954856d590d7ce2d4f3 -Author: Tim Rühsen -Date: Sun May 19 20:02:31 2024 +0200 - - * libwget/ssl_gnutls.c (verify_certificate_callback): Fix gcc warning -Wjump-misses-init - -diff --git a/libwget/ssl_gnutls.c b/libwget/ssl_gnutls.c -index a3cf6f5d..6edbcea1 100644 ---- a/libwget/ssl_gnutls.c -+++ b/libwget/ssl_gnutls.c -@@ -965,6 +965,7 @@ static int verify_certificate_callback(gnutls_session_t session) - gnutls_x509_crt_t cert = NULL, issuer = NULL; - const char *tag = config.check_certificate ? _("ERROR") : _("WARNING"); - #ifdef WITH_OCSP -+ bool skip_server_cert_check = false; - unsigned nvalid = 0, nrevoked = 0, nignored = 0; - #endif - -@@ -1121,8 +1122,6 @@ static int verify_certificate_callback(gnutls_session_t session) - // At this point, the cert chain has been found valid regarding the locally available CA certificates and CRLs. - // Now, we are going to check the revocation status via OCSP - #ifdef WITH_OCSP -- bool skip_server_cert_check = false; -- - if (config.ocsp_stapling) { - if (!ctx->valid && ctx->ocsp_stapling) { - #if GNUTLS_VERSION_NUMBER >= 0x030103 diff --git a/0005-Accept-progress-dot-.-for-backwards-compatibility.patch b/0005-Accept-progress-dot-.-for-backwards-compatibility.patch deleted file mode 100644 index 2d93ebd..0000000 --- a/0005-Accept-progress-dot-.-for-backwards-compatibility.patch +++ /dev/null @@ -1,57 +0,0 @@ -From e8f1e99c96a8303421e66b0feda1651a11c8b250 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Tim=20R=C3=BChsen?= -Date: Mon, 20 May 2024 13:19:06 +0200 -Subject: [PATCH] Accept --progress=dot:... for backwards compatibility - -* src/options.c (parse_progress_type): Fix checking dot options. -* tests/test-wget-1.c: Add check for --progress variants. ---- - src/options.c | 6 +++--- - tests/test-wget-1.c | 10 ++++++++++ - 2 files changed, 13 insertions(+), 3 deletions(-) - -diff --git a/src/options.c b/src/options.c -index 7684b795..0f7b3f35 100644 ---- a/src/options.c -+++ b/src/options.c -@@ -798,13 +798,13 @@ static int WGET_GCC_PURE WGET_GCC_NONNULL((1)) parse_progress_type(option_t opt, - - if (!wget_strcasecmp_ascii(val, "none")) - *((char *)opt->var) = PROGRESS_TYPE_NONE; -- else if (!wget_strncasecmp_ascii(val, "bar", 3)) { -+ else if (!wget_strncasecmp_ascii(val, "bar", 3) && (val[3] == ':' || val[3] == 0)) { - *((char *)opt->var) = PROGRESS_TYPE_BAR; - // Silent Wget compatibility -- if (!wget_strncasecmp_ascii(val+3, ":force", 6) || !wget_strncasecmp_ascii(val+3, ":noscroll:force", 15)) { -+ if (!wget_strncasecmp_ascii(val+4, "force", 5) || !wget_strncasecmp_ascii(val+4, "noscroll:force", 14)) { - config.force_progress = true; - } -- } else if (!wget_strcasecmp_ascii(val, "dot")) { -+ } else if (!wget_strncasecmp_ascii(val, "dot", 3) && (val[3] == ':' || val[3] == 0)) { - // Wget compatibility, whether want to support 'dot' depends on user feedback. - info_printf(_("Progress type '%s' ignored. It is not implemented yet\n"), val); - } else { -diff --git a/tests/test-wget-1.c b/tests/test-wget-1.c -index fdd4f54e..8a08d74d 100644 ---- a/tests/test-wget-1.c -+++ b/tests/test-wget-1.c -@@ -626,6 +626,16 @@ int main(void) - { NULL } }, - 0); - -+ // test different --progress options to be accepted -+ wget_test( -+ WGET_TEST_OPTIONS, "--progress=none --progress=bar --progress=bar:force --progress=bar:noscroll:force --progress=dot --progress=dot:giga", -+ WGET_TEST_REQUEST_URL, "dummy.txt", -+ WGET_TEST_EXPECTED_ERROR_CODE, 0, -+ WGET_TEST_EXPECTED_FILES, &(wget_test_file_t []) { -+ { "dummy.txt", urls[3].body }, -+ { NULL } }, -+ 0); -+ - // test--https-only - wget_test( - WGET_TEST_OPTIONS, "--https-only -r -nH", --- -2.43.0 - diff --git a/0006-Disable-TCP-Fast-Open-by-default.patch b/0006-Disable-TCP-Fast-Open-by-default.patch deleted file mode 100644 index a1ad51a..0000000 --- a/0006-Disable-TCP-Fast-Open-by-default.patch +++ /dev/null @@ -1,51 +0,0 @@ -From 7a945d31aeb34fc73cf86a494673ae97e069d84d Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Tim=20R=C3=BChsen?= -Date: Sun, 30 Jun 2024 19:33:01 +0200 -Subject: [PATCH] Disable TCP Fast Open by default - -* docs/wget2.md: Amended description of --tcp-fastopen. -* src/options.c (struct config config): Disabled TFO. ---- - docs/wget2.md | 8 +++++++- - src/options.c | 1 - - 2 files changed, 7 insertions(+), 2 deletions(-) - -diff --git a/docs/wget2.md b/docs/wget2.md -index 61da3ccb..06828bf8 100644 ---- a/docs/wget2.md -+++ b/docs/wget2.md -@@ -730,12 +730,18 @@ Go to background immediately after startup. If no output file is specified via t - - ### `--tcp-fastopen` - -- Enable support for TCP Fast Open (TFO) (default: on). -+ Enable support for TCP Fast Open (TFO) (default: off). - - TFO reduces connection latency by 1 RT on "hot" connections (2nd+ connection to the same host in a certain amount of time). - - Currently this works on recent Linux and OSX kernels, on HTTP and HTTPS. - -+ The main reasons why TFO is disabled by default are -+ - possible user tracking issues -+ - possible issues with middle boxes that do not support TFO -+ -+ This article gives has more details about TFO than fits here: https://candrews.integralblue.com/2019/03/the-sad-story-of-tcp-fast-open/ -+ - ### `--dns-cache-preload=file` - - Load a list of IP / Name tuples into the DNS cache. -diff --git a/src/options.c b/src/options.c -index 026aa415..f4b5d1a1 100644 ---- a/src/options.c -+++ b/src/options.c -@@ -1235,7 +1235,6 @@ struct config config = { - .max_redirect = 20, - .max_threads = 5, - .dns_caching = 1, -- .tcp_fastopen = 1, - .user_agent = PACKAGE_NAME"/"PACKAGE_VERSION, - .verbose = 1, - .check_certificate= CHECK_CERTIFICATE_ENABLED, --- -2.43.0 - diff --git a/sources b/sources index 8cfaa7c..ce583cb 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (wget2-2.1.0.tar.gz) = ae1fc267b1c2ee182ee59f0fc34fef238326a20f1ea1c15be6db2c16b70d49e89f61ca937d3e64d214f73ef9646ba4318782ac4210db51bd3d89c55ce4406872 -SHA512 (wget2-2.1.0.tar.gz.sig) = 22139c2a5314ab5689ac18d4daa4d39efb18bbd444bcba22eec79ccfe4401d0e01f41f293cc7f0a09ff66d25b365574a823302b0c41deb97ddc3d98e0d1500cf +SHA512 (wget2-2.2.0.tar.gz) = b39fb6f65b3be39c0f8f33a337c0417c8b31bf993cddbab1ef5e3dba66c6651ff8ec25d3a01ab5aa632072b14adab06adc4941bdb8e9cbf3b60bdd6f3f059cf1 +SHA512 (wget2-2.2.0.tar.gz.sig) = 217060bd7b6064c020f7d18ee1cf15b8e644de7da6d86c973c215f2a49bc0fbba16cab98db9f9f7058fb20bfa6561fba84f3c4ec230be07614f65de9a8e905e1 diff --git a/wget2.spec b/wget2.spec index 73055b2..1716fbd 100644 --- a/wget2.spec +++ b/wget2.spec @@ -4,11 +4,11 @@ %bcond as_wget 1 %endif -%global somajor 2 +%global somajor 3 Name: wget2 -Version: 2.1.0 -Release: 13%{?dist} +Version: 2.2.0 +Release: 1%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -20,23 +20,11 @@ Source1: https://ftp.gnu.org/gnu/wget/%{name}-%{version}.tar.gz.sig Source2: tim.ruehsen-keyring.asc # Backports from upstream -## Fix behavior for downloading to stdin (rhbz#2257700, gl#gnuwget/wget2#651) -Patch0001: 0001-src-log.c-log_init-Redirect-INFO-logs-to-stderr-with.patch -## Fix normalization of path part of URL (rhbz#2271362) -Patch0002: 0002-normalize-path-in-url.patch -# https://github.com/rockdaboot/wget2/pull/316 -# Allow option --no-tcp-fastopen to work on Linux kernels >= 4.11 -Patch0003: 0003-Allow-option-no-tcp-fastopen-to-work-on-Linux-kernel.patch -# https://gitlab.com/gnuwget/wget2/-/issues/664 -# Disable explicit OCSP requests by default for privacy reasons. -Patch0004: 0004-Disable-OCSP-by-default.patch -# https://gitlab.com/gnuwget/wget2/-/issues/661 -# Accept --progress=dot:... for backwards compatibility -Patch0005: 0005-Accept-progress-dot-.-for-backwards-compatibility.patch -# https://gitlab.com/gnuwget/wget2/-/commit/7a945d31aeb34fc73cf86a494673ae97e069d84d -# Disable TCP Fast Open by default -# rhbz#2291017 -Patch0006: 0006-Disable-TCP-Fast-Open-by-default.patch +# Patch0001 needed for proper build on other than x86 arches +Patch0001: 0001-use-signed-char-ascii.patch +# -O and -nc together truncate existing file and cause data loss +# rhbz#2298879 +Patch0002: 0002-dont-truncate-no-clobber.patch # Buildsystem build requirements BuildRequires: autoconf @@ -136,7 +124,7 @@ the system provider of wget. %prep %{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}' -%autosetup -p1 +%autosetup -p1 -S git %build @@ -199,6 +187,13 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Mon Dec 02 2024 Michal Ruprich - 2.2.0-1 +- New version 2.2.0 +- Resolves: rhbz#2298879 - Using options -nc and -O simultaneously causes existing files to be clobbered/truncated +- Resolves: rhbz#2327788 - wget starts using non-working IPv6 addresses on dual stack +- Resolves: rhbz#2327728 - Crash: "free(): double free detected in tcache 2" when using --load-cookies +- Resolves: rhbz#2280151 - wget2 always re-downdloads when using custom output filename + * Fri Aug 09 2024 Jonathan Wright - 2.1.0-13 - do not replace wget on el10 From 7398cec27f4f3dff8dd0bd44a7069bc1b70495cf Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 19 Jan 2025 14:57:19 +0000 Subject: [PATCH 08/15] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- wget2.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/wget2.spec b/wget2.spec index 1716fbd..8b3d015 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.2.0 -Release: 1%{?dist} +Release: 2%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -187,6 +187,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Sun Jan 19 2025 Fedora Release Engineering - 2.2.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Mon Dec 02 2024 Michal Ruprich - 2.2.0-1 - New version 2.2.0 - Resolves: rhbz#2298879 - Using options -nc and -O simultaneously causes existing files to be clobbered/truncated From abcac6a2d752dc20c5757bde890bc7083183cbb5 Mon Sep 17 00:00:00 2001 From: Neal Gompa Date: Fri, 28 Feb 2025 09:49:22 -0500 Subject: [PATCH 09/15] Backport support for --show-progress flag Resolves: rhbz#2348997 --- 0003-Add-show-progress.patch | 32 ++++++++++++++++++++++++++++++++ wget2.spec | 11 +++++++++-- 2 files changed, 41 insertions(+), 2 deletions(-) create mode 100644 0003-Add-show-progress.patch diff --git a/0003-Add-show-progress.patch b/0003-Add-show-progress.patch new file mode 100644 index 0000000..25701a7 --- /dev/null +++ b/0003-Add-show-progress.patch @@ -0,0 +1,32 @@ +From bc77fe1c8a3ebefa07eff7ec1088fb58876a03d3 Mon Sep 17 00:00:00 2001 +From: CaitCatDev +Date: Mon, 27 Jan 2025 23:38:32 +0000 +Subject: [PATCH] Add --show-progress + +* src/options.c (struct optionw options): Add show-progress item. + +Copyright-paperwork-exempt: Yes +--- + src/options.c | 6 ++++++ + 1 file changed, 6 insertions(+) + +diff --git a/src/options.c b/src/options.c +index 2132bfd1..83fab8f7 100644 +--- a/src/options.c ++++ b/src/options.c +@@ -2265,6 +2265,12 @@ static const struct optionw options[] = { + { "Print the server response headers. (default: off)\n" + } + }, ++ { "show-progress", &config.force_progress, parse_bool, -1, 0, ++ SECTION_DOWNLOAD, ++ { "Show Progress Bar (Deprecated alias for --force-progress)\n", ++ "(default: off)\n" ++ } ++ }, + #ifdef WITH_GPGME + { "signature-extensions", &config.sig_ext, parse_stringlist, 1, 0, + SECTION_GPG, +-- +2.48.1 + diff --git a/wget2.spec b/wget2.spec index 8b3d015..b75c69a 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.2.0 -Release: 2%{?dist} +Release: 3%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -25,6 +25,9 @@ Patch0001: 0001-use-signed-char-ascii.patch # -O and -nc together truncate existing file and cause data loss # rhbz#2298879 Patch0002: 0002-dont-truncate-no-clobber.patch +# Add --show-progress as alias for --force-progress for wget1 compat +# rhbz#2348997 +Patch0003: 0003-Add-show-progress.patch # Buildsystem build requirements BuildRequires: autoconf @@ -124,7 +127,7 @@ the system provider of wget. %prep %{gpgverify} --keyring='%{SOURCE2}' --signature='%{SOURCE1}' --data='%{SOURCE0}' -%autosetup -p1 -S git +%autosetup -S git_am %build @@ -187,6 +190,10 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Fri Feb 28 2025 Neal Gompa - 2.2.0-3 +- Backport support for --show-progress flag + Resolves: rhbz#2348997 + * Sun Jan 19 2025 Fedora Release Engineering - 2.2.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From ed66a50ca2d6407c7b82e4bd3369938ce3a96a24 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ondrej=20Mosn=C3=A1=C4=8Dek?= Date: Thu, 24 Apr 2025 09:47:20 +0200 Subject: [PATCH 10/15] Backport "Fix redirect regression" from upstream MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This fixes a bug that I hit frequently: https://gitlab.com/gnuwget/wget2/-/issues/689 Signed-off-by: Ondrej Mosnáček --- 0004-Fix-redirect-regression.patch | 37 ++++++++++++++++++++++++++++++ wget2.spec | 5 +++- 2 files changed, 41 insertions(+), 1 deletion(-) create mode 100644 0004-Fix-redirect-regression.patch diff --git a/0004-Fix-redirect-regression.patch b/0004-Fix-redirect-regression.patch new file mode 100644 index 0000000..96a8fc3 --- /dev/null +++ b/0004-Fix-redirect-regression.patch @@ -0,0 +1,37 @@ +From 400713caebb51e17046c7d884e08729a27cfa505 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Tim=20R=C3=BChsen?= +Date: Sun, 2 Feb 2025 19:42:40 +0100 +Subject: [PATCH] Fix redirect regression + +* src/wget.c (process_response_header): Follow location header. + +Fixes https://gitlab.com/gnuwget/wget2/-/issues/689 +Reported-by: https://gitlab.com/omos +--- + src/wget.c | 10 ++++++++++ + 1 file changed, 10 insertions(+) + +diff --git a/src/wget.c b/src/wget.c +index a2358fed6..3713db6eb 100644 +--- a/src/wget.c ++++ b/src/wget.c +@@ -1907,6 +1907,16 @@ static int process_response_header(wget_http_response *resp) + + wget_cookie_normalize_cookies(job->iri, resp->cookies); + wget_cookie_store_cookies(config.cookie_db, resp->cookies); ++ ++ wget_buffer uri_buf; ++ char uri_sbuf[1024]; ++ wget_buffer_init(&uri_buf, uri_sbuf, sizeof(uri_sbuf)); ++ ++ wget_iri_relative_to_abs(iri, resp->location, (size_t) -1, &uri_buf); ++ if (uri_buf.length) ++ queue_url_from_remote(job, "utf-8", uri_buf.data, URL_FLG_REDIRECTION, NULL); ++ ++ wget_buffer_deinit(&uri_buf); + } + + return 0; +-- +GitLab + diff --git a/wget2.spec b/wget2.spec index b75c69a..4866444 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.2.0 -Release: 3%{?dist} +Release: 4%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -28,6 +28,9 @@ Patch0002: 0002-dont-truncate-no-clobber.patch # Add --show-progress as alias for --force-progress for wget1 compat # rhbz#2348997 Patch0003: 0003-Add-show-progress.patch +# Fix redirect regression +# https://gitlab.com/gnuwget/wget2/-/issues/689 +Patch0004: %{url}/-/commit/400713caebb51e17046c7d884e08729a27cfa505.patch#/0004-Fix-redirect-regression.patch # Buildsystem build requirements BuildRequires: autoconf From ee6ffdc19099596c08cc14517e46038b753060e9 Mon Sep 17 00:00:00 2001 From: Michal Ruprich Date: Wed, 14 May 2025 15:46:22 +0200 Subject: [PATCH 11/15] Removing Obsoletes so that wget2 can be replaced by wget1 --- wget2.spec | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/wget2.spec b/wget2.spec index 4866444..34b1820 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.2.0 -Release: 4%{?dist} +Release: 5%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -114,9 +114,8 @@ use functionality from GNU Wget2. %package wget Summary: %{name} shim to provide wget Requires: wget2%{?_isa} = %{version}-%{release} -# Replace wget +# Replace wget1 Conflicts: wget < 2 -Obsoletes: wget < 2 Provides: wget = %{version}-%{release} Provides: wget%{?_isa} = %{version}-%{release} # From original wget package @@ -193,6 +192,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Wed May 14 2025 Michal Ruprich - 2.2.0-5 +- Removing Obsoletes so that wget2 can be replaced by wget1 + * Fri Feb 28 2025 Neal Gompa - 2.2.0-3 - Backport support for --show-progress flag Resolves: rhbz#2348997 From 197a68b3f65e0ff7c0a778d22811b64e2adb30ef Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 25 Jul 2025 20:23:26 +0000 Subject: [PATCH 12/15] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- wget2.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/wget2.spec b/wget2.spec index 34b1820..77a09de 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.2.0 -Release: 5%{?dist} +Release: 6%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -192,6 +192,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Fri Jul 25 2025 Fedora Release Engineering - 2.2.0-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Wed May 14 2025 Michal Ruprich - 2.2.0-5 - Removing Obsoletes so that wget2 can be replaced by wget1 From bea1c56115378036e0fecfce66c8e19e8dfd15e9 Mon Sep 17 00:00:00 2001 From: LuK1337 Date: Thu, 1 Jan 2026 17:33:55 +0100 Subject: [PATCH 13/15] New version 2.2.1 --- .gitignore | 2 ++ 0001-use-signed-char-ascii.patch | 24 ------------------- 0002-dont-truncate-no-clobber.patch | 23 ------------------ 0003-Add-show-progress.patch | 32 ------------------------- 0004-Fix-redirect-regression.patch | 37 ----------------------------- sources | 4 ++-- wget2.spec | 22 +++++------------ 7 files changed, 10 insertions(+), 134 deletions(-) delete mode 100644 0001-use-signed-char-ascii.patch delete mode 100644 0002-dont-truncate-no-clobber.patch delete mode 100644 0003-Add-show-progress.patch delete mode 100644 0004-Fix-redirect-regression.patch diff --git a/.gitignore b/.gitignore index 70ccca6..e3bb629 100644 --- a/.gitignore +++ b/.gitignore @@ -3,3 +3,5 @@ /wget2-2.1.0.tar.gz.sig /wget2-2.2.0.tar.gz /wget2-2.2.0.tar.gz.sig +/wget2-2.2.1.tar.gz +/wget2-2.2.1.tar.gz.sig diff --git a/0001-use-signed-char-ascii.patch b/0001-use-signed-char-ascii.patch deleted file mode 100644 index 5f49f3e..0000000 --- a/0001-use-signed-char-ascii.patch +++ /dev/null @@ -1,24 +0,0 @@ -From e4a04807d77d4eb1dfe63442ef1ad2ba749e86cc Mon Sep 17 00:00:00 2001 -From: Michal Ruprich -Date: Sat, 30 Nov 2024 19:52:23 +0100 -Subject: [PATCH] * src/utils.c (wget_restrict_file_name): Explicitly use - signed char - -Fix test--restrict-ascii failures on aarch64, s390x and ppc64le. ---- - src/utils.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/utils.c b/src/utils.c -index fa2104f60..54a03f76c 100644 ---- a/src/utils.c -+++ b/src/utils.c -@@ -151,7 +151,7 @@ char *wget_restrict_file_name(const char *fname, char *esc, int mode) - bool ascii = mode & WGET_RESTRICT_NAMES_ASCII; - - for (dst = esc, s = fname; *s; s++) { -- char c = *s; -+ signed char c = *s; - - if (lowercase && c >= 'A' && c <= 'Z') { // isupper() also returns true for chars > 0x7f, the test is not EBCDIC compatible ;-) - c |= 0x20; diff --git a/0002-dont-truncate-no-clobber.patch b/0002-dont-truncate-no-clobber.patch deleted file mode 100644 index ee13135..0000000 --- a/0002-dont-truncate-no-clobber.patch +++ /dev/null @@ -1,23 +0,0 @@ -From ad80bf39ce6b2bc39a9b286d3f3fc6b67142e7e7 Mon Sep 17 00:00:00 2001 -From: Michal Ruprich -Date: Tue, 26 Nov 2024 13:26:06 +0100 -Subject: [PATCH] Prevent file truncation with --no-clobber - -* src/options.c (init): Check config.clobber. ---- - src/options.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/options.c b/src/options.c -index 36cd3bb4..2132bfd1 100644 ---- a/src/options.c -+++ b/src/options.c -@@ -3492,7 +3492,7 @@ int init(int argc, const char **argv) - if (config.output_document && strcmp(config.output_document, "-") && !config.dont_write) { - if (config.unlink) { - unlink(config.output_document); -- } else if (!config.continue_download) { -+ } else if (!config.continue_download && config.clobber) { - int fd = open(config.output_document, O_WRONLY | O_TRUNC | O_BINARY); - - if (fd != -1) diff --git a/0003-Add-show-progress.patch b/0003-Add-show-progress.patch deleted file mode 100644 index 25701a7..0000000 --- a/0003-Add-show-progress.patch +++ /dev/null @@ -1,32 +0,0 @@ -From bc77fe1c8a3ebefa07eff7ec1088fb58876a03d3 Mon Sep 17 00:00:00 2001 -From: CaitCatDev -Date: Mon, 27 Jan 2025 23:38:32 +0000 -Subject: [PATCH] Add --show-progress - -* src/options.c (struct optionw options): Add show-progress item. - -Copyright-paperwork-exempt: Yes ---- - src/options.c | 6 ++++++ - 1 file changed, 6 insertions(+) - -diff --git a/src/options.c b/src/options.c -index 2132bfd1..83fab8f7 100644 ---- a/src/options.c -+++ b/src/options.c -@@ -2265,6 +2265,12 @@ static const struct optionw options[] = { - { "Print the server response headers. (default: off)\n" - } - }, -+ { "show-progress", &config.force_progress, parse_bool, -1, 0, -+ SECTION_DOWNLOAD, -+ { "Show Progress Bar (Deprecated alias for --force-progress)\n", -+ "(default: off)\n" -+ } -+ }, - #ifdef WITH_GPGME - { "signature-extensions", &config.sig_ext, parse_stringlist, 1, 0, - SECTION_GPG, --- -2.48.1 - diff --git a/0004-Fix-redirect-regression.patch b/0004-Fix-redirect-regression.patch deleted file mode 100644 index 96a8fc3..0000000 --- a/0004-Fix-redirect-regression.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 400713caebb51e17046c7d884e08729a27cfa505 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Tim=20R=C3=BChsen?= -Date: Sun, 2 Feb 2025 19:42:40 +0100 -Subject: [PATCH] Fix redirect regression - -* src/wget.c (process_response_header): Follow location header. - -Fixes https://gitlab.com/gnuwget/wget2/-/issues/689 -Reported-by: https://gitlab.com/omos ---- - src/wget.c | 10 ++++++++++ - 1 file changed, 10 insertions(+) - -diff --git a/src/wget.c b/src/wget.c -index a2358fed6..3713db6eb 100644 ---- a/src/wget.c -+++ b/src/wget.c -@@ -1907,6 +1907,16 @@ static int process_response_header(wget_http_response *resp) - - wget_cookie_normalize_cookies(job->iri, resp->cookies); - wget_cookie_store_cookies(config.cookie_db, resp->cookies); -+ -+ wget_buffer uri_buf; -+ char uri_sbuf[1024]; -+ wget_buffer_init(&uri_buf, uri_sbuf, sizeof(uri_sbuf)); -+ -+ wget_iri_relative_to_abs(iri, resp->location, (size_t) -1, &uri_buf); -+ if (uri_buf.length) -+ queue_url_from_remote(job, "utf-8", uri_buf.data, URL_FLG_REDIRECTION, NULL); -+ -+ wget_buffer_deinit(&uri_buf); - } - - return 0; --- -GitLab - diff --git a/sources b/sources index ce583cb..6b0b36d 100644 --- a/sources +++ b/sources @@ -1,2 +1,2 @@ -SHA512 (wget2-2.2.0.tar.gz) = b39fb6f65b3be39c0f8f33a337c0417c8b31bf993cddbab1ef5e3dba66c6651ff8ec25d3a01ab5aa632072b14adab06adc4941bdb8e9cbf3b60bdd6f3f059cf1 -SHA512 (wget2-2.2.0.tar.gz.sig) = 217060bd7b6064c020f7d18ee1cf15b8e644de7da6d86c973c215f2a49bc0fbba16cab98db9f9f7058fb20bfa6561fba84f3c4ec230be07614f65de9a8e905e1 +SHA512 (wget2-2.2.1.tar.gz) = ce458c31eda12b12120dd39d43751d7ac3c9b46ea994ae383cc5a68be2ee776840126e5251a9479b8e3b350f093c6b3dc1dc8fca48a159e4117a73b328a91021 +SHA512 (wget2-2.2.1.tar.gz.sig) = ae79112fad4eaf7d12d8d6da86a735851b63433ed2c48300937f2e70ed52fe552a49e64e9c597580c91009cda7e2c5e129d6f9978e8312f8430438c723cbc16b diff --git a/wget2.spec b/wget2.spec index 77a09de..7612d00 100644 --- a/wget2.spec +++ b/wget2.spec @@ -4,11 +4,11 @@ %bcond as_wget 1 %endif -%global somajor 3 +%global somajor 4 Name: wget2 -Version: 2.2.0 -Release: 6%{?dist} +Version: 2.2.1 +Release: 1%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -19,19 +19,6 @@ Source1: https://ftp.gnu.org/gnu/wget/%{name}-%{version}.tar.gz.sig # key 08302DB6A2670428 Source2: tim.ruehsen-keyring.asc -# Backports from upstream -# Patch0001 needed for proper build on other than x86 arches -Patch0001: 0001-use-signed-char-ascii.patch -# -O and -nc together truncate existing file and cause data loss -# rhbz#2298879 -Patch0002: 0002-dont-truncate-no-clobber.patch -# Add --show-progress as alias for --force-progress for wget1 compat -# rhbz#2348997 -Patch0003: 0003-Add-show-progress.patch -# Fix redirect regression -# https://gitlab.com/gnuwget/wget2/-/issues/689 -Patch0004: %{url}/-/commit/400713caebb51e17046c7d884e08729a27cfa505.patch#/0004-Fix-redirect-regression.patch - # Buildsystem build requirements BuildRequires: autoconf BuildRequires: automake @@ -192,6 +179,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Thu Jan 01 2026 LuK1337 - 2.2.1-1 +- New version 2.2.1 + * Fri Jul 25 2025 Fedora Release Engineering - 2.2.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild From f0fa5dc35268ddeeaf4597dc75b4809a2ff4ca73 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 17 Jan 2026 20:12:30 +0000 Subject: [PATCH 14/15] Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild --- wget2.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/wget2.spec b/wget2.spec index 7612d00..79279c1 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.2.1 -Release: 1%{?dist} +Release: 2%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -179,6 +179,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Sat Jan 17 2026 Fedora Release Engineering - 2.2.1-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild + * Thu Jan 01 2026 LuK1337 - 2.2.1-1 - New version 2.2.1 From 1d74f6b4548be71ae14ec993dd367856b571332b Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 17 Jul 2026 08:46:52 +0000 Subject: [PATCH 15/15] Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild --- wget2.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/wget2.spec b/wget2.spec index 79279c1..a1f6380 100644 --- a/wget2.spec +++ b/wget2.spec @@ -8,7 +8,7 @@ Name: wget2 Version: 2.2.1 -Release: 2%{?dist} +Release: 3%{?dist} Summary: An advanced file and recursive website downloader # Documentation is GFDL @@ -179,6 +179,9 @@ echo ".so man1/%{name}.1" > %{buildroot}%{_mandir}/man1/wget.1 %changelog +* Fri Jul 17 2026 Fedora Release Engineering - 2.2.1-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild + * Sat Jan 17 2026 Fedora Release Engineering - 2.2.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild