Compare commits
44 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fb2e5574bb | ||
|
|
836ff705c2 | ||
|
|
49f9652f5c | ||
|
|
078d69522d | ||
|
|
1383964453 | ||
|
|
dd68028f6b | ||
|
|
5b4377121c | ||
|
|
b5a87ca22e | ||
|
|
ad34885095 | ||
|
|
373f52944a | ||
|
|
a9a83044fa | ||
|
|
a9e00acea1 | ||
|
|
f582b55fbe | ||
|
|
ac4b6e4993 | ||
|
|
95a84ad1b7 | ||
|
|
a54966db57 | ||
|
|
abdf4532b5 | ||
|
|
7db1a4ef1c | ||
|
|
8123ab8015 | ||
|
|
92f13228cc | ||
|
|
0efe85f61a | ||
|
|
6fda885dc5 | ||
|
|
8da97ca0c6 | ||
|
|
81a80ac8b6 | ||
|
|
50f05f9d37 | ||
|
|
cd291b33f4 | ||
|
|
95c725f04b | ||
|
|
073a53cbdc | ||
|
|
4bcb67e99b | ||
|
|
331a4dfc44 | ||
|
|
c78eda7ed2 | ||
|
|
7780321823 |
||
|
|
29ebf510eb |
||
|
|
58b4be26c9 |
||
|
|
92418f5a6f | ||
|
|
949d0657af |
||
|
|
3fb52d3cd9 |
||
|
|
2f04a72955 | ||
|
|
8bfd07bb63 | ||
|
|
9ccd7ef8fa | ||
|
|
adf21f58c0 | ||
|
|
9bee76b0d6 | ||
|
|
80e5369b36 | ||
|
|
598f3d5692 |
4 changed files with 310 additions and 293 deletions
8
.gitignore
vendored
8
.gitignore
vendored
|
|
@ -6,3 +6,11 @@ xstream-distribution-1.3.1-src.zip
|
|||
/xstream-distribution-1.4.7-src.zip
|
||||
/xstream-distribution-1.4.8-src.zip
|
||||
/xstream-distribution-1.4.9-src.zip
|
||||
/xstream-distribution-1.4.11.1-src.zip
|
||||
/xstream-distribution-1.4.12-src.zip
|
||||
/xstream-distribution-1.4.13-src.zip
|
||||
/xstream-distribution-1.4.14-src.zip
|
||||
/xstream-distribution-1.4.18-src.zip
|
||||
/xstream-distribution-1.4.19-src.zip
|
||||
/xstream-distribution-1.4.20-src.zip
|
||||
/xstream-distribution-1.4.21-src.zip
|
||||
|
|
|
|||
|
|
@ -1,123 +0,0 @@
|
|||
From 376175c482a4914c8d288cf663f978dfb5e55849 Mon Sep 17 00:00:00 2001
|
||||
From: Michael Simacek <msimacek@redhat.com>
|
||||
Date: Wed, 12 Apr 2017 12:19:21 +0200
|
||||
Subject: [PATCH] Prevent deserialization of void
|
||||
|
||||
---
|
||||
.../SunLimitedUnsafeReflectionProvider.java | 22 ++++++++++++--------
|
||||
.../xstream/security/PrimitiveTypePermission.java | 5 +++--
|
||||
.../acceptance/SecurityVulnerabilityTest.java | 24 +++++++++++++++++++++-
|
||||
3 files changed, 39 insertions(+), 12 deletions(-)
|
||||
|
||||
diff --git a/xstream/src/java/com/thoughtworks/xstream/converters/reflection/SunLimitedUnsafeReflectionProvider.java b/xstream/src/java/com/thoughtworks/xstream/converters/reflection/SunLimitedUnsafeReflectionProvider.java
|
||||
index 2c569ae..491f0d6 100644
|
||||
--- a/xstream/src/java/com/thoughtworks/xstream/converters/reflection/SunLimitedUnsafeReflectionProvider.java
|
||||
+++ b/xstream/src/java/com/thoughtworks/xstream/converters/reflection/SunLimitedUnsafeReflectionProvider.java
|
||||
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* Copyright (C) 2004, 2005 Joe Walnes.
|
||||
- * Copyright (C) 2006, 2007, 2008, 2011, 2013, 2014, 2016 XStream Committers.
|
||||
+ * Copyright (C) 2006, 2007, 2008, 2011, 2013, 2014, 2016, 2017 XStream Committers.
|
||||
* All rights reserved.
|
||||
*
|
||||
* Created on 08. January 2014 by Joerg Schaible, factored out from SunUnsafeReflectionProvider
|
||||
@@ -78,14 +78,18 @@ public class SunLimitedUnsafeReflectionProvider extends PureJavaReflectionProvid
|
||||
throw ex;
|
||||
}
|
||||
ErrorWritingException ex = null;
|
||||
- try {
|
||||
- return unsafe.allocateInstance(type);
|
||||
- } catch (SecurityException e) {
|
||||
- ex = new ObjectAccessException("Cannot construct type", e);
|
||||
- } catch (InstantiationException e) {
|
||||
- ex = new ConversionException("Cannot construct type", e);
|
||||
- } catch (IllegalArgumentException e) {
|
||||
- ex = new ObjectAccessException("Cannot construct type", e);
|
||||
+ if (type == void.class || type == Void.class) {
|
||||
+ ex = new ConversionException("Type void cannot have an instance");
|
||||
+ } else {
|
||||
+ try {
|
||||
+ return unsafe.allocateInstance(type);
|
||||
+ } catch (SecurityException e) {
|
||||
+ ex = new ObjectAccessException("Cannot construct type", e);
|
||||
+ } catch (InstantiationException e) {
|
||||
+ ex = new ConversionException("Cannot construct type", e);
|
||||
+ } catch (IllegalArgumentException e) {
|
||||
+ ex = new ObjectAccessException("Cannot construct type", e);
|
||||
+ }
|
||||
}
|
||||
ex.add("construction-type", type.getName());
|
||||
throw ex;
|
||||
diff --git a/xstream/src/java/com/thoughtworks/xstream/security/PrimitiveTypePermission.java b/xstream/src/java/com/thoughtworks/xstream/security/PrimitiveTypePermission.java
|
||||
index fb69b95..c3cbad9 100644
|
||||
--- a/xstream/src/java/com/thoughtworks/xstream/security/PrimitiveTypePermission.java
|
||||
+++ b/xstream/src/java/com/thoughtworks/xstream/security/PrimitiveTypePermission.java
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
- * Copyright (C) 2014 XStream Committers.
|
||||
+ * Copyright (C) 2014, 2017 XStream Committers.
|
||||
* All rights reserved.
|
||||
*
|
||||
* Created on 09. January 2014 by Joerg Schaible
|
||||
@@ -8,8 +8,9 @@ package com.thoughtworks.xstream.security;
|
||||
|
||||
import com.thoughtworks.xstream.core.util.Primitives;
|
||||
|
||||
+
|
||||
/**
|
||||
- * Permission for any primitive type and its boxed counterpart (incl. void).
|
||||
+ * Permission for any primitive type and its boxed counterpart (excl. void).
|
||||
*
|
||||
* @author Jörg Schaible
|
||||
* @since 1.4.7
|
||||
diff --git a/xstream/src/test/com/thoughtworks/acceptance/SecurityVulnerabilityTest.java b/xstream/src/test/com/thoughtworks/acceptance/SecurityVulnerabilityTest.java
|
||||
index c77b3ce..0180fd7 100644
|
||||
--- a/xstream/src/test/com/thoughtworks/acceptance/SecurityVulnerabilityTest.java
|
||||
+++ b/xstream/src/test/com/thoughtworks/acceptance/SecurityVulnerabilityTest.java
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
- * Copyright (C) 2013, 2014 XStream Committers.
|
||||
+ * Copyright (C) 2013, 2014, 2017 XStream Committers.
|
||||
* All rights reserved.
|
||||
*
|
||||
* The software in this package is published under the terms of the BSD
|
||||
@@ -13,9 +13,12 @@ package com.thoughtworks.acceptance;
|
||||
import java.beans.EventHandler;
|
||||
|
||||
import com.thoughtworks.xstream.XStreamException;
|
||||
+import com.thoughtworks.xstream.converters.ConversionException;
|
||||
import com.thoughtworks.xstream.converters.reflection.ReflectionConverter;
|
||||
+import com.thoughtworks.xstream.security.ForbiddenClassException;
|
||||
import com.thoughtworks.xstream.security.ProxyTypePermission;
|
||||
|
||||
+
|
||||
/**
|
||||
* @author Jörg Schaible
|
||||
*/
|
||||
@@ -80,4 +83,23 @@ public class SecurityVulnerabilityTest extends AbstractAcceptanceTest {
|
||||
BUFFER.append("Executed!");
|
||||
}
|
||||
}
|
||||
+
|
||||
+ public void testDeniedInstanceOfVoid() {
|
||||
+ try {
|
||||
+ xstream.fromXML("<void/>");
|
||||
+ fail("Thrown " + ForbiddenClassException.class.getName() + " expected");
|
||||
+ } catch (final ForbiddenClassException e) {
|
||||
+ // OK
|
||||
+ }
|
||||
+ }
|
||||
+
|
||||
+ public void testAllowedInstanceOfVoid() {
|
||||
+ xstream.allowTypes(void.class, Void.class);
|
||||
+ try {
|
||||
+ xstream.fromXML("<void/>");
|
||||
+ fail("Thrown " + ConversionException.class.getName() + " expected");
|
||||
+ } catch (final ConversionException e) {
|
||||
+ assertEquals("void", e.get("construction-type"));
|
||||
+ }
|
||||
+ }
|
||||
}
|
||||
--
|
||||
2.9.3
|
||||
|
||||
3
sources
3
sources
|
|
@ -1,2 +1 @@
|
|||
94b452e5b45812b9994d304b532e2dc9 xstream-distribution-1.4.8-src.zip
|
||||
834424a0bbe68791ec5b71489011081e xstream-distribution-1.4.9-src.zip
|
||||
SHA512 (xstream-distribution-1.4.21-src.zip) = 495a415bad652bd3ad3ea91f8e8e12a4cfa34c3ba87e8822e3686f545b8e5a38aceb93e854da4d52ab5a5388f50a586f44b03e4c6f884ead30304672afb08a55
|
||||
|
|
|
|||
479
xstream.spec
479
xstream.spec
|
|
@ -1,205 +1,339 @@
|
|||
# Copyright statement from JPackage this file is derived from:
|
||||
|
||||
# Copyright (c) 2000-2007, JPackage Project
|
||||
# All rights reserved.
|
||||
#
|
||||
# Redistribution and use in source and binary forms, with or without
|
||||
# modification, are permitted provided that the following conditions
|
||||
# are met:
|
||||
#
|
||||
# 1. Redistributions of source code must retain the above copyright
|
||||
# notice, this list of conditions and the following disclaimer.
|
||||
# 2. Redistributions in binary form must reproduce the above copyright
|
||||
# notice, this list of conditions and the following disclaimer in the
|
||||
# documentation and/or other materials provided with the
|
||||
# distribution.
|
||||
# 3. Neither the name of the JPackage Project nor the names of its
|
||||
# contributors may be used to endorse or promote products derived
|
||||
# from this software without specific prior written permission.
|
||||
#
|
||||
# THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
||||
# "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
||||
# LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
|
||||
# A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
||||
# OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
||||
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
||||
# LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
||||
# DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
||||
# THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
||||
# (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
||||
# OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
#
|
||||
|
||||
%bcond_without hibernate
|
||||
%bcond_without activation
|
||||
%bcond_without cglib
|
||||
%bcond_without dom4j
|
||||
%bcond_without jdom
|
||||
%bcond_without jdom2
|
||||
%bcond_with jettison
|
||||
%bcond_with joda-time
|
||||
%bcond_with kxml2
|
||||
%bcond_with stax
|
||||
%bcond_with woodstox
|
||||
%bcond_with xom
|
||||
%bcond_with xpp3
|
||||
|
||||
Name: xstream
|
||||
Version: 1.4.9
|
||||
Release: 5%{?dist}
|
||||
Version: 1.4.21
|
||||
Release: 2%{?dist}
|
||||
Summary: Java XML serialization library
|
||||
License: BSD
|
||||
URL: http://x-stream.github.io/
|
||||
# Automatically converted from old format: BSD - review is highly recommended.
|
||||
License: LicenseRef-Callaway-BSD
|
||||
URL: https://x-stream.github.io
|
||||
BuildArch: noarch
|
||||
|
||||
Source0: http://repo1.maven.org/maven2/com/thoughtworks/%{name}/%{name}-distribution/%{version}/%{name}-distribution-%{version}-src.zip
|
||||
|
||||
# Fixes deserialization of void
|
||||
# https://bugzilla.redhat.com/show_bug.cgi?id=1441542
|
||||
# backport of https://github.com/x-stream/xstream/commit/b3570be2f39234e61f99f9a20640756ea71b1b40
|
||||
Patch0: 0001-Prevent-deserialization-of-void.patch
|
||||
|
||||
BuildRequires: maven-local
|
||||
BuildRequires: mvn(cglib:cglib)
|
||||
BuildRequires: mvn(dom4j:dom4j)
|
||||
BuildRequires: mvn(javassist:javassist)
|
||||
BuildRequires: mvn(joda-time:joda-time)
|
||||
BuildRequires: mvn(net.sf.kxml:kxml2)
|
||||
BuildRequires: mvn(net.sf.kxml:kxml2-min)
|
||||
ExclusiveArch: %{java_arches} noarch
|
||||
Source0: https://repo1.maven.org/maven2/com/thoughtworks/%{name}/%{name}-distribution/%{version}/%{name}-distribution-%{version}-src.zip
|
||||
BuildRequires: maven-local-openjdk25
|
||||
BuildRequires: mvn(io.github.x-stream:mxparser)
|
||||
BuildRequires: mvn(jakarta.xml.bind:jakarta.xml.bind-api:2)
|
||||
BuildRequires: mvn(org.apache.felix:maven-bundle-plugin)
|
||||
BuildRequires: mvn(org.apache.maven.plugins:maven-antrun-plugin)
|
||||
BuildRequires: mvn(org.apache.maven.plugins:maven-enforcer-plugin)
|
||||
BuildRequires: mvn(org.codehaus.jettison:jettison)
|
||||
BuildRequires: mvn(org.apache.maven.plugins:maven-source-plugin)
|
||||
BuildRequires: mvn(org.codehaus.mojo:build-helper-maven-plugin)
|
||||
BuildRequires: mvn(org.codehaus.woodstox:woodstox-core-asl)
|
||||
%if %{with hibernate}
|
||||
BuildRequires: mvn(org.hibernate:hibernate-core)
|
||||
BuildRequires: mvn(org.hibernate:hibernate-envers)
|
||||
%if %{with activation}
|
||||
BuildRequires: mvn(jakarta.activation:jakarta.activation-api:1)
|
||||
%endif
|
||||
%if %{with cglib}
|
||||
BuildRequires: mvn(cglib:cglib-nodep)
|
||||
%endif
|
||||
%if %{with dom4j}
|
||||
BuildRequires: mvn(dom4j:dom4j)
|
||||
%endif
|
||||
%if %{with jdom}
|
||||
BuildRequires: mvn(org.jdom:jdom)
|
||||
%endif
|
||||
%if %{with jdom2}
|
||||
BuildRequires: mvn(org.jdom:jdom2)
|
||||
BuildRequires: mvn(org.slf4j:slf4j-simple)
|
||||
%endif
|
||||
%if %{with jettison}
|
||||
BuildRequires: mvn(org.codehaus.jettison:jettison)
|
||||
%endif
|
||||
%if %{with joda-time}
|
||||
BuildRequires: mvn(joda-time:joda-time)
|
||||
%endif
|
||||
%if %{with kxml2}
|
||||
BuildRequires: mvn(net.sf.kxml:kxml2-min)
|
||||
%endif
|
||||
%if %{with stax}
|
||||
BuildRequires: mvn(stax:stax)
|
||||
BuildRequires: mvn(stax:stax-api)
|
||||
%endif
|
||||
%if %{with woodstox}
|
||||
BuildRequires: mvn(org.codehaus.woodstox:wstx-asl)
|
||||
%endif
|
||||
%if %{with xom}
|
||||
BuildRequires: mvn(xom:xom)
|
||||
BuildRequires: mvn(xpp3:xpp3)
|
||||
%endif
|
||||
%if %{with xpp3}
|
||||
BuildRequires: mvn(xpp3:xpp3_min)
|
||||
|
||||
%endif
|
||||
|
||||
%description
|
||||
XStream is a simple library to serialize objects to XML
|
||||
and back again. A high level facade is supplied that
|
||||
simplifies common use cases. Custom objects can be serialized
|
||||
without need for specifying mappings. Speed and low memory
|
||||
footprint are a crucial part of the design, making it suitable
|
||||
for large object graphs or systems with high message throughput.
|
||||
No information is duplicated that can be obtained via reflection.
|
||||
This results in XML that is easier to read for humans and more
|
||||
compact than native Java serialization. XStream serializes internal
|
||||
fields, including private and final. Supports non-public and inner
|
||||
classes. Classes are not required to have default constructor.
|
||||
Duplicate references encountered in the object-model will be
|
||||
maintained. Supports circular references. By implementing an
|
||||
interface, XStream can serialize directly to/from any tree
|
||||
structure (not just XML). Strategies can be registered allowing
|
||||
customization of how particular types are represented as XML.
|
||||
When an exception occurs due to malformed XML, detailed diagnostics
|
||||
XStream is a simple library to serialize objects to XML
|
||||
and back again. A high level facade is supplied that
|
||||
simplifies common use cases. Custom objects can be serialized
|
||||
without need for specifying mappings. Speed and low memory
|
||||
footprint are a crucial part of the design, making it suitable
|
||||
for large object graphs or systems with high message throughput.
|
||||
No information is duplicated that can be obtained via reflection.
|
||||
This results in XML that is easier to read for humans and more
|
||||
compact than native Java serialization. XStream serializes internal
|
||||
fields, including private and final. Supports non-public and inner
|
||||
classes. Classes are not required to have default constructor.
|
||||
Duplicate references encountered in the object-model will be
|
||||
maintained. Supports circular references. By implementing an
|
||||
interface, XStream can serialize directly to/from any tree
|
||||
structure (not just XML). Strategies can be registered allowing
|
||||
customization of how particular types are represented as XML.
|
||||
When an exception occurs due to malformed XML, detailed diagnostics
|
||||
are provided to help isolate and fix the problem.
|
||||
|
||||
%package -n %{name}-benchmark
|
||||
Summary: Benchmark module for %{name}
|
||||
%description -n %{name}-benchmark
|
||||
Benchmark module for %{name}.
|
||||
|
||||
%package javadoc
|
||||
Summary: Javadoc for %{name}
|
||||
|
||||
%description javadoc
|
||||
%{name} API documentation.
|
||||
|
||||
%if %{with hibernate}
|
||||
%package hibernate
|
||||
Summary: hibernate module for %{name}
|
||||
Requires: %{name} = %{version}-%{release}
|
||||
|
||||
%description hibernate
|
||||
hibernate module for %{name}.
|
||||
%endif
|
||||
|
||||
%package benchmark
|
||||
Summary: benchmark module for %{name}
|
||||
Requires: %{name} = %{version}-%{release}
|
||||
|
||||
%description benchmark
|
||||
benchmark module for %{name}.
|
||||
|
||||
%package parent
|
||||
Summary: Parent POM for %{name}
|
||||
Requires: %{name} = %{version}-%{release}
|
||||
|
||||
%description parent
|
||||
Parent POM for %{name}.
|
||||
|
||||
%{?javadoc_package}
|
||||
|
||||
%prep
|
||||
%setup -qn %{name}-%{version}
|
||||
find . -name "*.class" -print -delete
|
||||
find . -name "*.jar" -print -delete
|
||||
|
||||
%patch0 -p1
|
||||
|
||||
# Remove org.apache.maven.wagon:wagon-webdav
|
||||
%pom_xpath_remove "pom:project/pom:build/pom:extensions"
|
||||
# Require org.codehaus.xsite:xsite-maven-plugin
|
||||
%pom_disable_module xstream-distribution
|
||||
|
||||
# missing artifacts:
|
||||
# org.openjdk.jmh:jmh-core:jar:1.11.1
|
||||
# org.openjdk.jmh:jmh-generator-annprocess:jar:1.11.1
|
||||
%pom_disable_module xstream-jmh
|
||||
|
||||
%pom_remove_plugin :xsite-maven-plugin
|
||||
%pom_remove_plugin :jxr-maven-plugin
|
||||
# Unwanted
|
||||
%pom_remove_plugin :maven-source-plugin
|
||||
%pom_remove_plugin :maven-dependency-plugin
|
||||
%pom_remove_plugin :maven-eclipse-plugin
|
||||
%pom_remove_plugin :maven-release-plugin
|
||||
|
||||
%pom_xpath_set "pom:dependency[pom:groupId = 'org.codehaus.woodstox' ]/pom:artifactId" woodstox-core-asl
|
||||
%pom_xpath_set "pom:dependency[pom:groupId = 'org.codehaus.woodstox' ]/pom:artifactId" woodstox-core-asl xstream
|
||||
%pom_xpath_set "pom:dependency[pom:groupId = 'cglib' ]/pom:artifactId" cglib
|
||||
%pom_xpath_set "pom:dependency[pom:groupId = 'cglib' ]/pom:artifactId" cglib xstream
|
||||
# Replace old xmlpull dependency with xpp3
|
||||
%pom_change_dep :xmlpull xpp3:xpp3:1.1.4c xstream
|
||||
# Require unavailable proxytoys:proxytoys
|
||||
%pom_remove_plugin :maven-dependency-plugin xstream
|
||||
|
||||
%pom_remove_plugin :maven-javadoc-plugin xstream
|
||||
|
||||
# provided by JDK
|
||||
%pom_remove_dep javax.activation:activation xstream
|
||||
|
||||
%pom_xpath_set "pom:project/pom:dependencies/pom:dependency[pom:groupId = 'cglib' ]/pom:artifactId" cglib xstream-hibernate
|
||||
%pom_xpath_inject "pom:project/pom:dependencies/pom:dependency[pom:groupId = 'junit' ]" "<scope>test</scope>" xstream-hibernate
|
||||
%pom_remove_plugin :maven-dependency-plugin xstream-hibernate
|
||||
%pom_remove_plugin :maven-javadoc-plugin xstream-hibernate
|
||||
|
||||
%pom_xpath_inject "pom:project/pom:dependencies/pom:dependency[pom:groupId = 'junit' ]" "<scope>test</scope>" xstream-benchmark
|
||||
%pom_remove_plugin :maven-javadoc-plugin xstream-benchmark
|
||||
|
||||
%if %{without hibernate}
|
||||
%pom_disable_module xstream-hibernate
|
||||
# -n: base directory name
|
||||
%autosetup -n %{name}-%{version}
|
||||
# delete precompiled jar and class files
|
||||
find -type f '(' -iname '*.jar' -o -iname '*.class' ')' -print -delete
|
||||
# change javax to jakarta
|
||||
# https://jakarta.ee/about/faq#What_happened_with_javax.*_namespace?
|
||||
%pom_change_dep -r javax.activation:activation jakarta.activation:jakarta.activation-api:1
|
||||
%pom_change_dep -r javax.xml.bind:jaxb-api jakarta.xml.bind:jakarta.xml.bind-api:2
|
||||
# remove dependency plugin
|
||||
%pom_remove_plugin -r :maven-dependency-plugin
|
||||
# optional dep: activation
|
||||
%if %{without activation}
|
||||
%pom_remove_dep -r jakarta.activation:jakarta.activation-api
|
||||
rm xstream/src/java/com/thoughtworks/xstream/converters/extended/ActivationDataFlavorConverter.java
|
||||
%endif
|
||||
|
||||
%mvn_file :%{name} %{name}/%{name} %{name}
|
||||
%mvn_file :%{name}-benchmark %{name}/%{name}-benchmark %{name}-benchmark
|
||||
|
||||
%mvn_package :%{name}
|
||||
# optional dep: cglib
|
||||
%if %{without cglib}
|
||||
%pom_remove_dep -r cglib:cglib-nodep
|
||||
rm xstream/src/java/com/thoughtworks/xstream/converters/reflection/CGLIBEnhancedConverter.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/mapper/CGLIBMapper.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/security/CGLIBProxyTypePermission.java
|
||||
%endif
|
||||
# optional dep: dom4j
|
||||
%if %{without dom4j}
|
||||
%pom_remove_dep -r dom4j:dom4j
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/Dom4JDriver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/Dom4JReader.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/Dom4JWriter.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/Dom4JXmlWriter.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamDom4J.java
|
||||
%endif
|
||||
# optional dep: jdom
|
||||
%if %{without jdom}
|
||||
%pom_remove_dep -r org.jdom:jdom
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/JDomDriver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/JDomReader.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/JDomWriter.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamJDom.java
|
||||
%endif
|
||||
# optional dep: jdom2
|
||||
%if %{without jdom2}
|
||||
%pom_remove_dep -r org.jdom:jdom2
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/JDom2Driver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/JDom2Reader.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/JDom2Writer.java
|
||||
%endif
|
||||
# optional dep: jettison
|
||||
%if %{without jettison}
|
||||
%pom_remove_dep -r org.codehaus.jettison:jettison
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/json/JettisonMappedXmlDriver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/json/JettisonStaxWriter.java
|
||||
%endif
|
||||
# optional dep: joda-time
|
||||
%if %{without joda-time}
|
||||
%pom_remove_dep -r joda-time:joda-time
|
||||
rm xstream/src/java/com/thoughtworks/xstream/core/util/ISO8601JodaTimeConverter.java
|
||||
%endif
|
||||
# optional dep: kxml2
|
||||
%if %{without kxml2}
|
||||
%pom_remove_dep -r net.sf.kxml:kxml2-min
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/KXml2DomDriver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/KXml2Driver.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamKXml2.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamKXml2DOM.java
|
||||
%endif
|
||||
# optional dep: stax
|
||||
%if %{without stax}
|
||||
%pom_remove_dep -r stax:stax
|
||||
%pom_remove_dep -r stax:stax-api
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/BEAStaxDriver.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamBEAStax.java
|
||||
%endif
|
||||
# optional dep: woodstox
|
||||
%if %{without woodstox}
|
||||
%pom_remove_dep -r org.codehaus.woodstox:wstx-asl
|
||||
%pom_remove_dep -r com.fasterxml.woodstox:woodstox-core
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/WstxDriver.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamWoodstox.java
|
||||
%endif
|
||||
# optional dep: xom
|
||||
%if %{without xom}
|
||||
%pom_remove_dep -r xom:xom
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/XomDriver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/XomReader.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/XomWriter.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamXom.java
|
||||
%endif
|
||||
# optional dep: xpp3
|
||||
%if %{without xpp3}
|
||||
%pom_remove_dep -r xpp3:xpp3_min
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/Xpp3DomDriver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/Xpp3Driver.java
|
||||
rm xstream/src/java/com/thoughtworks/xstream/io/xml/xppdom/Xpp3DomBuilder.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamXpp3.java
|
||||
rm xstream-benchmark/src/java/com/thoughtworks/xstream/tools/benchmark/products/XStreamXpp3DOM.java
|
||||
%endif
|
||||
# disable module distribution
|
||||
%pom_disable_module %{name}-distribution
|
||||
# disable module hibernate
|
||||
%pom_disable_module %{name}-hibernate
|
||||
# disable module jmh
|
||||
%pom_disable_module %{name}-jmh
|
||||
# don't install parent package
|
||||
%mvn_package :%{name}-parent __noinstall
|
||||
|
||||
%build
|
||||
# test skipped for unavailable test deps (com.megginson.sax:xml-writer)
|
||||
%mvn_build -f -s
|
||||
%mvn_build -s -f -- -Dversion.java.5=1.8 -Dversion.java.6=1.8 -Dversion.java.source=1.8 -Dversion.java.target=1.8
|
||||
|
||||
%install
|
||||
%mvn_install
|
||||
|
||||
%files -f .mfiles
|
||||
%doc LICENSE.txt README.txt
|
||||
%dir %{_javadir}/%{name}
|
||||
%files parent -f .mfiles-%{name}-parent
|
||||
%if %{with hibernate}
|
||||
%files hibernate -f .mfiles-%{name}-hibernate
|
||||
%endif
|
||||
%files benchmark -f .mfiles-%{name}-benchmark
|
||||
|
||||
%files javadoc -f .mfiles-javadoc
|
||||
%doc LICENSE.txt
|
||||
%files -n %{name} -f .mfiles-%{name}
|
||||
%license LICENSE.txt
|
||||
%doc README.txt
|
||||
%files -n %{name}-benchmark -f .mfiles-%{name}-benchmark
|
||||
%license LICENSE.txt
|
||||
%doc README.txt
|
||||
|
||||
%changelog
|
||||
* Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.21-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
|
||||
|
||||
* Mon Mar 09 2026 Ondřej Pohořelský <opohorel@redhat.com> - 1.4.21-1
|
||||
- New upstream release 1.4.21
|
||||
|
||||
* Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.20-11
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
|
||||
|
||||
* Tue Jul 29 2025 jiri vanek <jvanek@redhat.com> - 1.4.20-10
|
||||
- Rebuilt for java-25-openjdk as preffered jdk
|
||||
|
||||
* Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.20-9
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
|
||||
|
||||
* Sun Jan 19 2025 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.20-8
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
|
||||
|
||||
* Wed Sep 04 2024 Miroslav Suchý <msuchy@redhat.com> - 1.4.20-7
|
||||
- convert license to SPDX
|
||||
|
||||
* Sat Jul 20 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.20-6
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
|
||||
|
||||
* Tue Feb 27 2024 Jiri Vanek <jvanek@redhat.com> - 1.4.20-5
|
||||
- Rebuilt for java-21-openjdk as system jdk
|
||||
|
||||
* Mon Jan 29 2024 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.20-4
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
|
||||
|
||||
* Sat Jul 22 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.20-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
|
||||
|
||||
* Mon Feb 20 2023 Didik Supriadi <didiksupriadi41@fedoraproject.org> - 1.4.20-2
|
||||
- Depend on compat versions of activation and XML bind (by @mkoncek)
|
||||
- Re-enable activation
|
||||
|
||||
* Mon Feb 20 2023 Didik Supriadi <didiksupriadi41@fedoraproject.org> - 1.4.20-1
|
||||
- New upstream release 1.4.20
|
||||
- Disable activation
|
||||
|
||||
* Sat Jan 21 2023 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.19-5
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
|
||||
|
||||
* Sat Jul 23 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.19-4
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
|
||||
|
||||
* Fri Jul 08 2022 Jiri Vanek <jvanek@redhat.com> - 1.4.19-3
|
||||
- Rebuilt for Drop i686 JDKs
|
||||
|
||||
* Sat Feb 05 2022 Jiri Vanek <jvanek@redhat.com> - 1.4.19-2
|
||||
- Rebuilt for java-17-openjdk as system jdk
|
||||
|
||||
* Sat Jan 29 2022 Didik Supriadi <didiksupriadi41@fedoraproject.org> - 1.4.19-1
|
||||
- New upstream release 1.4.19
|
||||
|
||||
* Sat Jan 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.18-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
|
||||
|
||||
* Mon Oct 04 2021 Didik Supriadi <didiksupriadi41@fedoraproject.org> - 1.4.18-2
|
||||
- Enable activation, cglib, dom4j, jdom, and jdom2
|
||||
|
||||
* Fri Oct 01 2021 Didik Supriadi <didiksupriadi41@fedoraproject.org> - 1.4.18-1
|
||||
- Update to version 1.4.18
|
||||
|
||||
* Fri Jul 23 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.14-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
|
||||
|
||||
* Thu Jan 28 2021 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.14-2
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
|
||||
|
||||
* Tue Nov 17 2020 Ding-Yi Chen <dchen@redhat.com> - 1.4.14-1
|
||||
- Upstream update to 1.4.14
|
||||
|
||||
* Fri Aug 07 2020 Mat Booth <mat.booth@redhat.com> - 1.4.12-6
|
||||
- Allow building on JDK11
|
||||
|
||||
* Wed Jul 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.12-5
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
|
||||
|
||||
* Sat Jul 11 2020 Jiri Vanek <jvanek@redhat.com> - 1.4.12-4
|
||||
- Rebuilt for JDK-11, see https://fedoraproject.org/wiki/Changes/Java11
|
||||
|
||||
* Wed Jun 17 2020 Fabio Valentini <decathorpe@gmail.com> - 1.4.12-3
|
||||
- Disable unused optional dom4j, jdom, jdom2, kxml, and woodstox support.
|
||||
|
||||
* Mon Jun 08 2020 Fabio Valentini <decathorpe@gmail.com> - 1.4.12-2
|
||||
- Disable optional support for joda-time by default.
|
||||
|
||||
* Mon Apr 27 2020 Fabio Valentini <decathorpe@gmail.com> - 1.4.12-1
|
||||
- Update to version 1.4.12.
|
||||
- Disable optional support for BEA Stax by default.
|
||||
|
||||
* Fri Jan 31 2020 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.11.1-5
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
|
||||
|
||||
* Tue Nov 05 2019 Fabio Valentini <decathorpe@gmail.com> - 1.4.11.1-4
|
||||
- Use Java version override compatible with both xmvn 3.0.0 and 3.1.0.
|
||||
|
||||
* Fri Jul 26 2019 Fabio Valentini <decathorpe@gmail.com> - 1.4.11.1-3
|
||||
- Disable hibernate support by default.
|
||||
|
||||
* Tue Mar 05 2019 Mat Booth <mat.booth@redhat.com> - 1.4.11.1-2
|
||||
- Allow building with reduced dependency set
|
||||
|
||||
* Thu Feb 14 2019 Mat Booth <mat.booth@redhat.com> - 1.4.11.1-1
|
||||
- Update to latest upstream release
|
||||
|
||||
* Sun Feb 03 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.9-9
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
|
||||
|
||||
* Sat Jul 14 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.9-8
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
|
||||
|
||||
* Fri Feb 09 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.9-7
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
|
||||
|
||||
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.9-6
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
|
||||
|
||||
* Wed Apr 12 2017 Michael Simacek <msimacek@redhat.com> - 1.4.9-5
|
||||
- Backport fix for void deserialization
|
||||
- Resolves rhbz#1441542
|
||||
|
|
@ -264,7 +398,6 @@ find . -name "*.jar" -print -delete
|
|||
|
||||
* Thu Oct 24 2013 Mikolaj Izdebski <mizdebsk@redhat.com> - 1.4.5-3
|
||||
- Rebuild to move arch-independant JARs out of %%_jnidir
|
||||
|
||||
* Wed Oct 23 2013 Mikolaj Izdebski <mizdebsk@redhat.com> - 1.4.5-2
|
||||
- Rebuild to regenerate broken POM files
|
||||
- Related: rhbz#1021484
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue