Compare commits

...
Sign in to create a new pull request.

6 commits

Author SHA1 Message Date
ea9fc3e984 WordPress 4.6.1 Security and Maintenance Release
(cherry picked from commit b2e1003fec)
2016-09-08 08:49:13 +02:00
0b1de33368 WordPress 4.6 “Pepper”
(cherry picked from commit cc7bdefab7)
2016-09-03 08:51:56 +02:00
9abc1b7ba9 WordPress 4.5.3 Maintenance and Security Release 2016-06-22 11:06:11 +02:00
27ee516617 WordPress 4.5.2 Security Release
(cherry picked from commit 22f8927f3a)
2016-05-11 07:33:16 +02:00
efc2c3609c WordPress 4.5.1 Maintenance Release
(cherry picked from commit f295541234)
2016-04-27 07:05:43 +02:00
a93d4e6b59 WordPress 4.5 “Coleman” 2016-04-13 08:42:50 +02:00
7 changed files with 222 additions and 109 deletions

8
.gitignore vendored
View file

@ -24,3 +24,11 @@ clog
/wordpress-4.4.tar.gz
/wordpress-4.4.1.tar.gz
/wordpress-4.4.2.tar.gz
/wordpress-4.5-RC1.tar.gz
/wordpress-4.5.tar.gz
/wordpress-4.5.1.tar.gz
/wordpress-4.5.2.tar.gz
/wordpress-4.5.3.tar.gz
/wordpress-debian_patches_hello.patch
/wordpress-4.6.tar.gz
/wordpress-4.6.1.tar.gz

View file

@ -1 +1 @@
65d89263dad6154fdc8b747e9ef4e357 wordpress-4.4.2.tar.gz
ca0b978fd702eac033830ca2d0784b79 wordpress-4.6.1.tar.gz

View file

@ -1,88 +0,0 @@
diff -up wordpress/wp-admin/includes/admin-filters.php.orig wordpress/wp-admin/includes/admin-filters.php
--- wordpress/wp-admin/includes/admin-filters.php.orig 2015-10-15 00:35:24.000000000 +0200
+++ wordpress/wp-admin/includes/admin-filters.php 2015-12-09 17:08:00.945112230 +0100
@@ -100,7 +100,6 @@ add_action( 'profile_update', 'default_p
add_action( 'admin_init', 'wp_plugin_update_rows' );
add_action( 'admin_init', 'wp_theme_update_rows' );
-add_action( 'admin_notices', 'update_nag', 3 );
add_action( 'admin_notices', 'maintenance_nag', 10 );
add_filter( 'update_footer', 'core_update_footer' );
diff -up wordpress/wp-admin/includes/class-wp-upgrader.php.orig wordpress/wp-admin/includes/class-wp-upgrader.php
--- wordpress/wp-admin/includes/class-wp-upgrader.php.orig 2015-11-16 03:47:25.000000000 +0100
+++ wordpress/wp-admin/includes/class-wp-upgrader.php 2015-12-09 17:09:34.735571806 +0100
@@ -2386,6 +2386,9 @@ class Core_Upgrader extends WP_Upgrader
}
}
+ // RPM: nether allow core update
+ return false;
+
// 1: If we're already on that version, not much point in updating?
if ( $offered_ver == $wp_version )
return false;
@@ -2627,7 +2630,7 @@ class WP_Automatic_Updater {
*/
public function is_disabled() {
// Background updates are disabled if you don't want file changes.
- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
return true;
if ( wp_installing() )
diff -up wordpress/wp-admin/includes/update.php.orig wordpress/wp-admin/includes/update.php
--- wordpress/wp-admin/includes/update.php.orig 2015-12-09 17:08:00.946112235 +0100
+++ wordpress/wp-admin/includes/update.php 2015-12-09 17:10:27.642831054 +0100
@@ -251,7 +251,7 @@ function update_right_now_message() {
$cur = get_preferred_from_update_core();
if ( isset( $cur->response ) && $cur->response == 'upgrade' )
- $msg .= '<a href="' . network_admin_url( 'update-core.php' ) . '" class="button" aria-describedby="wp-version">' . sprintf( __( 'Update to %s' ), $cur->current ? $cur->current : __( 'Latest' ) ) . '</a> ';
+ $msg .= '';
}
/* translators: 1: version number, 2: theme name */
diff -up wordpress/wp-includes/capabilities.php.orig wordpress/wp-includes/capabilities.php
--- wordpress/wp-includes/capabilities.php.orig 2015-11-29 03:27:18.000000000 +0100
+++ wordpress/wp-includes/capabilities.php 2015-12-09 17:08:00.946112235 +0100
@@ -308,7 +308,7 @@ function map_meta_cap( $cap, $user_id )
// Disallow the file editors.
if ( defined( 'DISALLOW_FILE_EDIT' ) && DISALLOW_FILE_EDIT )
$caps[] = 'do_not_allow';
- elseif ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
+ elseif ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
$caps[] = 'do_not_allow';
elseif ( is_multisite() && ! is_super_admin( $user_id ) )
$caps[] = 'do_not_allow';
@@ -326,7 +326,7 @@ function map_meta_cap( $cap, $user_id )
case 'update_core':
// Disallow anything that creates, deletes, or updates core, plugin, or theme files.
// Files in uploads are excepted.
- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
$caps[] = 'do_not_allow';
} elseif ( is_multisite() && ! is_super_admin( $user_id ) ) {
$caps[] = 'do_not_allow';
diff -up wordpress/wp-includes/update.php.orig wordpress/wp-includes/update.php
--- wordpress/wp-includes/update.php.orig 2015-12-06 16:44:27.000000000 +0100
+++ wordpress/wp-includes/update.php 2015-12-09 17:12:09.038327895 +0100
@@ -637,9 +637,6 @@ function _maybe_update_themes() {
* @since 3.1.0
*/
function wp_schedule_update_checks() {
- if ( ! wp_next_scheduled( 'wp_version_check' ) && ! wp_installing() )
- wp_schedule_event(time(), 'twicedaily', 'wp_version_check');
-
if ( ! wp_next_scheduled( 'wp_update_plugins' ) && ! wp_installing() )
wp_schedule_event(time(), 'twicedaily', 'wp_update_plugins');
@@ -681,8 +678,6 @@ if ( ( ! is_main_site() && ! is_network_
}
add_action( 'admin_init', '_maybe_update_core' );
-add_action( 'wp_version_check', 'wp_version_check' );
-add_action( 'upgrader_process_complete', 'wp_version_check', 10, 0 );
add_action( 'load-plugins.php', 'wp_update_plugins' );
add_action( 'load-update.php', 'wp_update_plugins' );

View file

@ -0,0 +1,103 @@
diff -up wordpress/wp-admin/includes/admin-filters.php.rpm wordpress/wp-admin/includes/admin-filters.php
--- wordpress/wp-admin/includes/admin-filters.php.rpm 2016-09-03 07:50:51.812312381 +0200
+++ wordpress/wp-admin/includes/admin-filters.php 2016-09-03 07:51:39.070577518 +0200
@@ -106,7 +106,6 @@ add_action( 'profile_update', 'default_p
add_action( 'load-plugins.php', 'wp_plugin_update_rows', 20 ); // After wp_update_plugins() is called.
add_action( 'load-themes.php', 'wp_theme_update_rows', 20 ); // After wp_update_themes() is called.
-add_action( 'admin_notices', 'update_nag', 3 );
add_action( 'admin_notices', 'maintenance_nag', 10 );
add_filter( 'update_footer', 'core_update_footer' );
diff -up wordpress/wp-admin/includes/class-core-upgrader.php.rpm wordpress/wp-admin/includes/class-core-upgrader.php
--- wordpress/wp-admin/includes/class-core-upgrader.php.rpm 2016-09-03 07:59:45.832367671 +0200
+++ wordpress/wp-admin/includes/class-core-upgrader.php 2016-09-03 07:59:50.160392833 +0200
@@ -236,6 +236,9 @@ class Core_Upgrader extends WP_Upgrader
* @return bool True if we should update to the offered version, otherwise false.
*/
public static function should_update_to_version( $offered_ver ) {
+ // RPM: nether allow core update
+ return false;
+
include( ABSPATH . WPINC . '/version.php' ); // $wp_version; // x.y.z
$current_branch = implode( '.', array_slice( preg_split( '/[.-]/', $wp_version ), 0, 2 ) ); // x.y
diff -up wordpress/wp-admin/includes/class-wp-automatic-updater.php.rpm wordpress/wp-admin/includes/class-wp-automatic-updater.php
--- wordpress/wp-admin/includes/class-wp-automatic-updater.php.rpm 2016-09-03 08:00:15.810540773 +0200
+++ wordpress/wp-admin/includes/class-wp-automatic-updater.php 2016-09-03 08:00:28.915616106 +0200
@@ -31,7 +31,7 @@ class WP_Automatic_Updater {
*/
public function is_disabled() {
// Background updates are disabled if you don't want file changes.
- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
return true;
if ( wp_installing() )
diff -up wordpress/wp-admin/includes/translation-install.php.rpm wordpress/wp-admin/includes/translation-install.php
--- wordpress/wp-admin/includes/translation-install.php.rpm 2016-05-22 20:01:30.000000000 +0200
+++ wordpress/wp-admin/includes/translation-install.php 2016-09-03 07:50:51.813312387 +0200
@@ -181,7 +181,7 @@ function wp_download_language_pack( $dow
return $download;
}
- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
return false;
}
@@ -224,7 +224,7 @@ function wp_download_language_pack( $dow
* @return bool Returns true on success, false on failure.
*/
function wp_can_install_language_pack() {
- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
return false;
}
diff -up wordpress/wp-admin/includes/update.php.rpm wordpress/wp-admin/includes/update.php
--- wordpress/wp-admin/includes/update.php.rpm 2016-08-10 21:06:31.000000000 +0200
+++ wordpress/wp-admin/includes/update.php 2016-09-03 07:50:51.812312381 +0200
@@ -271,7 +271,7 @@ function update_right_now_message() {
$cur = get_preferred_from_update_core();
if ( isset( $cur->response ) && $cur->response == 'upgrade' )
- $msg .= '<a href="' . network_admin_url( 'update-core.php' ) . '" class="button" aria-describedby="wp-version">' . sprintf( __( 'Update to %s' ), $cur->current ? $cur->current : __( 'Latest' ) ) . '</a> ';
+ $msg .= '';
}
/* translators: 1: version number, 2: theme name */
diff -up wordpress/wp-includes/capabilities.php.rpm wordpress/wp-includes/capabilities.php
--- wordpress/wp-includes/capabilities.php.rpm 2016-06-30 03:02:29.000000000 +0200
+++ wordpress/wp-includes/capabilities.php 2016-09-03 07:50:51.812312381 +0200
@@ -330,7 +330,7 @@ function map_meta_cap( $cap, $user_id )
// Disallow the file editors.
if ( defined( 'DISALLOW_FILE_EDIT' ) && DISALLOW_FILE_EDIT )
$caps[] = 'do_not_allow';
- elseif ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS )
+ elseif ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS )
$caps[] = 'do_not_allow';
elseif ( is_multisite() && ! is_super_admin( $user_id ) )
$caps[] = 'do_not_allow';
@@ -348,7 +348,7 @@ function map_meta_cap( $cap, $user_id )
case 'update_core':
// Disallow anything that creates, deletes, or updates core, plugin, or theme files.
// Files in uploads are excepted.
- if ( defined( 'DISALLOW_FILE_MODS' ) && DISALLOW_FILE_MODS ) {
+ if ( !defined( 'DISALLOW_FILE_MODS' ) || DISALLOW_FILE_MODS ) {
$caps[] = 'do_not_allow';
} elseif ( is_multisite() && ! is_super_admin( $user_id ) ) {
$caps[] = 'do_not_allow';
diff -up wordpress/wp-includes/update.php.rpm wordpress/wp-includes/update.php
--- wordpress/wp-includes/update.php.rpm 2016-05-25 21:36:28.000000000 +0200
+++ wordpress/wp-includes/update.php 2016-09-03 07:50:51.813312387 +0200
@@ -653,9 +653,6 @@ function _maybe_update_themes() {
* @since 3.1.0
*/
function wp_schedule_update_checks() {
- if ( ! wp_next_scheduled( 'wp_version_check' ) && ! wp_installing() )
- wp_schedule_event(time(), 'twicedaily', 'wp_version_check');
-
if ( ! wp_next_scheduled( 'wp_update_plugins' ) && ! wp_installing() )
wp_schedule_event(time(), 'twicedaily', 'wp_update_plugins');

View file

@ -1,5 +1,8 @@
Alias /wordpress /usr/share/wordpress
# Access is only allowed via local access
# Change this once configured
<Directory /usr/share/wordpress>
AllowOverride Options
<IfModule mod_authz_core.c>
@ -15,7 +18,16 @@ Alias /wordpress /usr/share/wordpress
</IfModule>
</Directory>
<Directory /usr/share/wordpress/wp-content/uploads>
# Deny access to any php file in the uploads directory
<FilesMatch "\.(php)$">
Order Deny,Allow
Deny from all
</FilesMatch>
</Directory>
<Directory /usr/share/wordpress/wp-content/plugins/akismet>
# Deny access to any php file in the akismet directory
<FilesMatch "\.(php|txt)$">
Order Deny,Allow
Deny from all

35
wordpress-nginx-conf Normal file
View file

@ -0,0 +1,35 @@
# Wordpress
location = /wordpress {
alias /usr/share/wordpress/;
}
location /wordpress/ {
root /usr/share;
index index.php;
location ~ ^/wordpress/wp-content/uploads/(.+)\.php$ {
# Deny access to any php file in the uploads directory
deny all;
}
location ~ ^/wordpress/wp-content/plugins/akismet/(.+)\.php$ {
# Deny access to any php file in the akismet directory
deny all;
}
# Access is only allowed via local access
# Change this once configured
location ~ ^/wordpress/(.+\.php)$ {
allow 127.0.0.1;
allow ::1;
deny all;
try_files $uri =404;
fastcgi_intercept_errors on;
include fastcgi_params;
fastcgi_param SERVER_NAME $host;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_pass php-fpm;
}
}

View file

@ -8,30 +8,33 @@
%{!?_pkgdocdir: %global _pkgdocdir %{_docdir}/%{name}-%{version}}
%global wp_content %{_datadir}/wordpress/wp-content
%if 0%{?rhel} == 5
%global with_cacert 0
%if 0%{?fedora} >= 21
%global with_nginx 1
%else
%global with_cacert 1
%global with_nginx 0
%endif
# https://bugzilla.redhat.com/1147817 php53-getid3 review
%if 0%{?fedora} >= 17 || 0%{?rhel} >= 6
%global with_getid3 1
%else
%global with_getid3 0
%endif
#global prever RC1
Summary: Blog tool and publishing platform
URL: http://www.wordpress.org
Name: wordpress
Version: 4.4.2
Version: 4.6.1
Group: Applications/Publishing
Release: 1%{?dist}
License: GPLv2
Source0: http://wordpress.org/%{name}-%{version}.tar.gz
Source0: http://wordpress.org/%{name}-%{version}%{?prever:-%{prever}}.tar.gz
Source1: wordpress-httpd-conf
Source2: README.fedora.wordpress
Source3: README.fedora.wordpress-mu
Source4: wordpress-nginx-conf
# Patch out copyrighted text of Hello, Dolly
# (and replace it with Free Software Song)
@ -53,7 +56,7 @@ Patch5: wordpress-4.0-config.patch
# disable version check and updated
# change DISALLOW_FILE_MODS default value to true
# ignore WP_AUTO_UPDATE_CORE (always false)
Patch6: wordpress-4.4-noupdate.patch
Patch6: wordpress-4.6-noupdate.patch
# Use system libraries
Patch7: wordpress-4.4-systemlibs.patch
@ -66,19 +69,33 @@ Requires: php53-simplepie >= 1.3.1
%if %{with_getid3}
Requires: php53-getid3
%endif
Requires: php53-mysql
%else
%if %{with_nginx}
Requires: webserver
Requires: php(httpd)
Suggests: httpd
# For directory ownership
Requires: httpd-filesystem
Requires: nginx-filesystem
%else
Requires: php >= 5.2.4
%endif
Requires: php-simplepie >= 1.3.1
%if %{with_getid3}
Requires: php-getid3
%endif
Requires: php-ctype
Requires: php-filter
Requires: php-mysqli
%endif
# From phpcompatinfo report for version 3.8
# From phpcompatinfo report for version 4.5.3
Requires: php-curl
Requires: php-date
Requires: php-dom
Requires: php-enchant
Requires: php-ereg
Requires: php-exif
Requires: php-fileinfo
Requires: php-ftp
@ -89,7 +106,6 @@ Requires: php-iconv
Requires: php-json
Requires: php-libxml
Requires: php-mbstring
Requires: php-mysql
Requires: php-openssl
Requires: php-pcre
Requires: php-posix
@ -103,9 +119,8 @@ Requires: php-zlib
# Unbundled libraries
Requires: php-PHPMailer
Requires: httpd
%if %{with_cacert}
Requires: ca-certificates
%endif
# ca-certificates (excepted on EL-5)
Requires: %{_sysconfdir}/pki/tls/certs/ca-bundle.crt
Provides: wordpress-mu = %{version}-%{release}
Obsoletes: wordpress-mu < 2.9.3
@ -190,6 +205,10 @@ sed -i -e 's/\r//' license.txt
# Apache configuration
install -m 0644 -D -p %{SOURCE1} ${RPM_BUILD_ROOT}%{_sysconfdir}/httpd/conf.d/wordpress.conf
%if %{with_nginx}
install -m 0644 -D -p %{SOURCE4} ${RPM_BUILD_ROOT}%{_sysconfdir}/nginx/default.d/wordpress.conf
%endif
# Application
mkdir -p ${RPM_BUILD_ROOT}%{_datadir}/wordpress
cp -pr * ${RPM_BUILD_ROOT}%{_datadir}/wordpress
@ -233,11 +252,9 @@ rm -r ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/ID3
%endif
# Remove bundled ca-bundle.crt
%if %{with_cacert}
rm ${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/certificates/ca-bundle.crt
ln -s /etc/pki/tls/certs/ca-bundle.crt \
ln -s %{_sysconfdir}/pki/tls/certs/ca-bundle.crt \
${RPM_BUILD_ROOT}%{_datadir}/wordpress/wp-includes/certificates/ca-bundle.crt
%endif
# Remove backup copies of patches
find ${RPM_BUILD_ROOT} \( -name \*.dolly -o -name \*.rhbz522897 -o -name \*.orig \) \
@ -263,16 +280,19 @@ rm -rf ${RPM_BUILD_ROOT}
%files
%defattr(-,root,root,-)
%config(noreplace) %{_sysconfdir}/httpd/conf.d/wordpress.conf
%if %{with_nginx}
%config(noreplace) %{_sysconfdir}/nginx/default.d/wordpress.conf
%endif
%dir %{_datadir}/wordpress
%{_datadir}/wordpress/wp-admin
%{_datadir}/wordpress/wp-includes
%{_datadir}/wordpress/index.php
%dir %{wp_content}/
%{wp_content}/index.php
%dir %attr(0775,apache,ftp) %{wp_content}/plugins
%dir %attr(0775,apache,ftp) %{wp_content}/themes
%dir %attr(0775,apache,ftp) %{wp_content}/upgrade
%dir %attr(0775,apache,ftp) %{wp_content}/uploads
%dir %attr(2775,apache,ftp) %{wp_content}/plugins
%dir %attr(2775,apache,ftp) %{wp_content}/themes
%dir %attr(2775,apache,ftp) %{wp_content}/upgrade
%dir %attr(2775,apache,ftp) %{wp_content}/uploads
%{wp_content}/plugins/*
%{wp_content}/themes/*
%{!?_licensedir:%global license %%doc}
@ -287,6 +307,29 @@ rm -rf ${RPM_BUILD_ROOT}
%changelog
* Thu Sep 8 2016 Remi Collet <remi@fedoraproject.org> - 4.6.1-1
- WordPress 4.6.1 Security and Maintenance Release
* Sat Sep 3 2016 Remi Collet <remi@fedoraproject.org> - 4.6-2
- WordPress 4.6 “Pepper”
- fix directory permissions #1305687
* Wed Jun 22 2016 Remi Collet <remi@fedoraproject.org> - 4.5.3-1
- WordPress 4.5.3 Maintenance and Security Release
- never bundle ca-bundle.crt (EL-5)
- provide nginx configuration (fedora)
- drop mandatory dependency on httpd (suggested) #1336091
- protect php files in uploads directory
* Tue May 10 2016 Remi Collet <remi@fedoraproject.org> - 4.5.2-1
- WordPress 4.5.2 Security Release
* Wed Apr 27 2016 Remi Collet <remi@fedoraproject.org> - 4.5.1-1
- WordPress 4.5.1 Maintenance Release
* Wed Apr 13 2016 Remi Collet <remi@fedoraproject.org> - 4.5-1
- WordPress 4.5 “Coleman”
* Wed Feb 3 2016 Remi Collet <remi@fedoraproject.org> - 4.4.2-1
- WordPress 4.4.2 Security and Maintenance Release