diff --git a/.gitignore b/.gitignore index 8721528..99c1bde 100644 --- a/.gitignore +++ b/.gitignore @@ -8,5 +8,3 @@ yaml-cpp-0.2.5.tar.gz /yaml-cpp-0.6.1.tar.gz /yaml-cpp-0.6.2.tar.gz /yaml-cpp-0.6.3.tar.gz -/yaml-cpp-0.7.0.tar.gz -/yaml-cpp-0.8.0.tar.gz diff --git a/1211.patch b/1211.patch deleted file mode 100644 index 29085ab..0000000 --- a/1211.patch +++ /dev/null @@ -1,29 +0,0 @@ -From 8153a1add19018f65527faad3c4d3941705baf39 Mon Sep 17 00:00:00 2001 -From: Craig Scott -Date: Wed, 16 Aug 2023 15:55:44 +1000 -Subject: [PATCH] Specify CMake policy range to avoid deprecation warning - -CMake 3.27 started issuing a deprecation warning for any -cmake_minimum_required() call that specified a minimum -version older than 3.5. Specifying a version range instead of -a simple minimum version avoids that warning without -raising the minimum supported CMake version. The NEW -policy behavior will be used for all policies introduced up to -CMake 3.14 with this change. ---- - CMakeLists.txt | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - -diff --git a/CMakeLists.txt b/CMakeLists.txt -index 46dc18059..1ae92e2b7 100644 ---- a/CMakeLists.txt -+++ b/CMakeLists.txt -@@ -1,5 +1,6 @@ --# 3.5 is actually available almost everywhere, but this a good minimum --cmake_minimum_required(VERSION 3.4) -+# 3.5 is actually available almost everywhere, but this a good minimum. -+# 3.14 as the upper policy limit avoids CMake deprecation warnings. -+cmake_minimum_required(VERSION 3.4...3.14) - - # enable MSVC_RUNTIME_LIBRARY target property - # see https://cmake.org/cmake/help/latest/policy/CMP0091.html diff --git a/CVE-2017-5950.patch b/CVE-2017-5950.patch new file mode 100644 index 0000000..3a96432 --- /dev/null +++ b/CVE-2017-5950.patch @@ -0,0 +1,383 @@ +From d540476e31b080aa1f903ad20ec0426dd3838be7 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Antoine=20Beaupr=C3=A9?= +Date: Tue, 25 Apr 2017 20:10:20 -0400 +Subject: [PATCH 1/4] fix stack overflow in HandleNode() (CVE-2017-5950) + +simply set a hardcoded recursion limit to 2000 (inspired by Python's) +to avoid infinitely recursing into arbitrary data structures + +assert() the depth. unsure if this is the right approach, but given +that HandleNode() is "void", I am not sure how else to return an +error. the problem with this approach of course is that it will still +crash the caller, unless they have proper exception handling in place. + +Closes: #459 +--- + src/singledocparser.cpp | 2 ++ + src/singledocparser.h | 2 ++ + 2 files changed, 4 insertions(+) + +diff --git a/src/singledocparser.cpp b/src/singledocparser.cpp +index a27c1c3b..1b4262ee 100644 +--- a/src/singledocparser.cpp ++++ b/src/singledocparser.cpp +@@ -46,6 +46,8 @@ void SingleDocParser::HandleDocument(EventHandler& eventHandler) { + } + + void SingleDocParser::HandleNode(EventHandler& eventHandler) { ++ assert(depth < depth_limit); ++ depth++; + // an empty node *is* a possibility + if (m_scanner.empty()) { + eventHandler.OnNull(m_scanner.mark(), NullAnchor); +diff --git a/src/singledocparser.h b/src/singledocparser.h +index 2b92067c..7046f1e2 100644 +--- a/src/singledocparser.h ++++ b/src/singledocparser.h +@@ -51,6 +51,8 @@ class SingleDocParser : private noncopyable { + anchor_t LookupAnchor(const Mark& mark, const std::string& name) const; + + private: ++ int depth = 0; ++ int depth_limit = 2000; + Scanner& m_scanner; + const Directives& m_directives; + std::unique_ptr m_pCollectionStack; + +From ac00ef937702598aa27739c8c46be37ac5699039 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Antoine=20Beaupr=C3=A9?= +Date: Wed, 26 Apr 2017 10:25:43 -0400 +Subject: [PATCH 2/4] throw an exception instead of using assert() + +assert() may be compiled out in production and is clunkier to catch. + +some ParserException are already thrown elsewhere in the code and it +seems to make sense to reuse the primitive, although it may still +crash improperly configured library consumers, those who do not handle +exceptions explicitly. + +we use the BAD_FILE error message because at this point we do not +exactly know which specific data structure led to the recursion. +--- + src/singledocparser.cpp | 4 +++- + 1 file changed, 3 insertions(+), 1 deletion(-) + +diff --git a/src/singledocparser.cpp b/src/singledocparser.cpp +index 1b4262ee..1af13f49 100644 +--- a/src/singledocparser.cpp ++++ b/src/singledocparser.cpp +@@ -46,7 +46,9 @@ void SingleDocParser::HandleDocument(EventHandler& eventHandler) { + } + + void SingleDocParser::HandleNode(EventHandler& eventHandler) { +- assert(depth < depth_limit); ++ if (depth > depth_limit) { ++ throw ParserException(m_scanner.mark(), ErrorMsg::BAD_FILE); ++ } + depth++; + // an empty node *is* a possibility + if (m_scanner.empty()) { + +From e78e3bf6a6d61ca321af90d213dc4435ed5cf602 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Antoine=20Beaupr=C3=A9?= +Date: Wed, 26 Apr 2017 10:39:45 -0400 +Subject: [PATCH 3/4] increase and decrease depth properly on subhandlers + +the original implementation couldn't parse a document with more than +depth_limit entries. now we explicitly increase *and* decrease the +depth on specific handlers like maps, sequences and so on - any +handler that may in turn callback into HandleNode(). + +this is a little clunky - I would have prefered to increment and +decrement the counter in only one place, but there are many different +return points and this is not Golang so I can't think of a better way +to to this. +--- + src/singledocparser.cpp | 13 ++++++++++++- + 1 file changed, 12 insertions(+), 1 deletion(-) + +diff --git a/src/singledocparser.cpp b/src/singledocparser.cpp +index 1af13f49..89234867 100644 +--- a/src/singledocparser.cpp ++++ b/src/singledocparser.cpp +@@ -49,7 +49,6 @@ void SingleDocParser::HandleNode(EventHandler& eventHandler) { + if (depth > depth_limit) { + throw ParserException(m_scanner.mark(), ErrorMsg::BAD_FILE); + } +- depth++; + // an empty node *is* a possibility + if (m_scanner.empty()) { + eventHandler.OnNull(m_scanner.mark(), NullAnchor); +@@ -61,9 +60,11 @@ void SingleDocParser::HandleNode(EventHandler& eventHandler) { + + // special case: a value node by itself must be a map, with no header + if (m_scanner.peek().type == Token::VALUE) { ++ depth++; + eventHandler.OnMapStart(mark, "?", NullAnchor, EmitterStyle::Default); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); ++ depth--; + return; + } + +@@ -98,32 +99,42 @@ void SingleDocParser::HandleNode(EventHandler& eventHandler) { + m_scanner.pop(); + return; + case Token::FLOW_SEQ_START: ++ depth++; + eventHandler.OnSequenceStart(mark, tag, anchor, EmitterStyle::Flow); + HandleSequence(eventHandler); + eventHandler.OnSequenceEnd(); ++ depth--; + return; + case Token::BLOCK_SEQ_START: ++ depth++; + eventHandler.OnSequenceStart(mark, tag, anchor, EmitterStyle::Block); + HandleSequence(eventHandler); + eventHandler.OnSequenceEnd(); ++ depth--; + return; + case Token::FLOW_MAP_START: ++ depth++; + eventHandler.OnMapStart(mark, tag, anchor, EmitterStyle::Flow); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); ++ depth--; + return; + case Token::BLOCK_MAP_START: ++ depth++; + eventHandler.OnMapStart(mark, tag, anchor, EmitterStyle::Block); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); ++ depth--; + return; + case Token::KEY: + // compact maps can only go in a flow sequence + if (m_pCollectionStack->GetCurCollectionType() == + CollectionType::FlowSeq) { ++ depth++; + eventHandler.OnMapStart(mark, tag, anchor, EmitterStyle::Flow); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); ++ depth--; + return; + } + break; + +From 1690cacb3ff6d927286ded92b8fedd37b4045c7c Mon Sep 17 00:00:00 2001 +From: Keith Bennett +Date: Thu, 29 Mar 2018 16:45:11 -0500 +Subject: [PATCH 4/4] use RAII type class to guard against stack depth + recursion instead of error-prone manual increment/check/decrement + +--- + include/yaml-cpp/depthguard.h | 74 +++++++++++++++++++++++++++++++++++ + src/depthguard.cpp | 14 +++++++ + src/singledocparser.cpp | 18 ++------- + src/singledocparser.h | 4 +- + 4 files changed, 94 insertions(+), 16 deletions(-) + create mode 100644 include/yaml-cpp/depthguard.h + create mode 100644 src/depthguard.cpp + +diff --git a/include/yaml-cpp/depthguard.h b/include/yaml-cpp/depthguard.h +new file mode 100644 +index 00000000..6aac81aa +--- /dev/null ++++ b/include/yaml-cpp/depthguard.h +@@ -0,0 +1,74 @@ ++#ifndef DEPTH_GUARD_H_00000000000000000000000000000000000000000000000000000000 ++#define DEPTH_GUARD_H_00000000000000000000000000000000000000000000000000000000 ++ ++#if defined(_MSC_VER) || \ ++ (defined(__GNUC__) && (__GNUC__ == 3 && __GNUC_MINOR__ >= 4) || \ ++ (__GNUC__ >= 4)) // GCC supports "pragma once" correctly since 3.4 ++#pragma once ++#endif ++ ++#include "exceptions.h" ++ ++namespace YAML { ++ ++/** ++ * @brief The DeepRecursion class ++ * An exception class which is thrown by DepthGuard. Ideally it should be ++ * a member of DepthGuard. However, DepthGuard is a templated class which means ++ * that any catch points would then need to know the template parameters. It is ++ * simpler for clients to not have to know at the catch point what was the ++ * maximum depth. ++ */ ++class DeepRecursion : public ParserException { ++ int m_atDepth = 0; ++public: ++ // no custom dtor needed, but virtual dtor necessary to prevent slicing ++ virtual ~DeepRecursion() = default; ++ ++ // construct an exception explaining how deep you were ++ DeepRecursion(int at_depth, const Mark& mark_, const std::string& msg_); ++ ++ // query how deep you were when the exception was thrown ++ int AtDepth() const; ++}; ++ ++/** ++ * @brief The DepthGuard class ++ * DepthGuard takes a reference to an integer. It increments the integer upon ++ * construction of DepthGuard and decrements the integer upon destruction. ++ * ++ * If the integer would be incremented past max_depth, then an exception is ++ * thrown. This is ideally geared toward guarding against deep recursion. ++ * ++ * @param max_depth ++ * compile-time configurable maximum depth. ++ */ ++template ++class DepthGuard final /* final because non-virtual dtor */ { ++ int & m_depth; ++public: ++ DepthGuard(int & depth_, const Mark& mark_, const std::string& msg_) : m_depth(depth_) { ++ ++m_depth; ++ if ( max_depth <= m_depth ) { ++ throw DeepRecursion{m_depth, mark_, msg_}; ++ } ++ } ++ ++ // DepthGuard is neither copyable nor moveable. ++ DepthGuard(const DepthGuard & copy_ctor) = delete; ++ DepthGuard(DepthGuard && move_ctor) = delete; ++ DepthGuard & operator=(const DepthGuard & copy_assign) = delete; ++ DepthGuard & operator=(DepthGuard && move_assign) = delete; ++ ++ ~DepthGuard() { ++ --m_depth; ++ } ++ ++ int current_depth() const { ++ return m_depth; ++ } ++}; ++ ++} // namespace YAML ++ ++#endif // DEPTH_GUARD_H_00000000000000000000000000000000000000000000000000000000 +diff --git a/src/depthguard.cpp b/src/depthguard.cpp +new file mode 100644 +index 00000000..6d47eba3 +--- /dev/null ++++ b/src/depthguard.cpp +@@ -0,0 +1,14 @@ ++#include "yaml-cpp/depthguard.h" ++ ++namespace YAML { ++ ++DeepRecursion::DeepRecursion(int at_depth, const Mark& mark_, const std::string& msg_) ++ : ParserException(mark_, msg_), ++ m_atDepth(at_depth) { ++} ++ ++int DeepRecursion::AtDepth() const { ++ return m_atDepth; ++} ++ ++} // namespace YAML +diff --git a/src/singledocparser.cpp b/src/singledocparser.cpp +index 89234867..37cc1f51 100644 +--- a/src/singledocparser.cpp ++++ b/src/singledocparser.cpp +@@ -7,6 +7,7 @@ + #include "singledocparser.h" + #include "tag.h" + #include "token.h" ++#include "yaml-cpp/depthguard.h" + #include "yaml-cpp/emitterstyle.h" + #include "yaml-cpp/eventhandler.h" + #include "yaml-cpp/exceptions.h" // IWYU pragma: keep +@@ -46,9 +47,8 @@ void SingleDocParser::HandleDocument(EventHandler& eventHandler) { + } + + void SingleDocParser::HandleNode(EventHandler& eventHandler) { +- if (depth > depth_limit) { +- throw ParserException(m_scanner.mark(), ErrorMsg::BAD_FILE); +- } ++ DepthGuard depthguard(depth, m_scanner.mark(), ErrorMsg::BAD_FILE); ++ + // an empty node *is* a possibility + if (m_scanner.empty()) { + eventHandler.OnNull(m_scanner.mark(), NullAnchor); +@@ -60,11 +60,9 @@ void SingleDocParser::HandleNode(EventHandler& eventHandler) { + + // special case: a value node by itself must be a map, with no header + if (m_scanner.peek().type == Token::VALUE) { +- depth++; + eventHandler.OnMapStart(mark, "?", NullAnchor, EmitterStyle::Default); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); +- depth--; + return; + } + +@@ -99,42 +97,32 @@ void SingleDocParser::HandleNode(EventHandler& eventHandler) { + m_scanner.pop(); + return; + case Token::FLOW_SEQ_START: +- depth++; + eventHandler.OnSequenceStart(mark, tag, anchor, EmitterStyle::Flow); + HandleSequence(eventHandler); + eventHandler.OnSequenceEnd(); +- depth--; + return; + case Token::BLOCK_SEQ_START: +- depth++; + eventHandler.OnSequenceStart(mark, tag, anchor, EmitterStyle::Block); + HandleSequence(eventHandler); + eventHandler.OnSequenceEnd(); +- depth--; + return; + case Token::FLOW_MAP_START: +- depth++; + eventHandler.OnMapStart(mark, tag, anchor, EmitterStyle::Flow); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); +- depth--; + return; + case Token::BLOCK_MAP_START: +- depth++; + eventHandler.OnMapStart(mark, tag, anchor, EmitterStyle::Block); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); +- depth--; + return; + case Token::KEY: + // compact maps can only go in a flow sequence + if (m_pCollectionStack->GetCurCollectionType() == + CollectionType::FlowSeq) { +- depth++; + eventHandler.OnMapStart(mark, tag, anchor, EmitterStyle::Flow); + HandleMap(eventHandler); + eventHandler.OnMapEnd(); +- depth--; + return; + } + break; +diff --git a/src/singledocparser.h b/src/singledocparser.h +index 7046f1e2..f1676c43 100644 +--- a/src/singledocparser.h ++++ b/src/singledocparser.h +@@ -16,6 +16,8 @@ + + namespace YAML { + class CollectionStack; ++template class DepthGuard; // depthguard.h ++class DeepRecursion; // an exception which may be thrown from excessive call stack recursion, see depthguard.h + class EventHandler; + class Node; + class Scanner; +@@ -51,8 +53,8 @@ class SingleDocParser : private noncopyable { + anchor_t LookupAnchor(const Mark& mark, const std::string& name) const; + + private: ++ using DepthGuard = YAML::DepthGuard<2000>; + int depth = 0; +- int depth_limit = 2000; + Scanner& m_scanner; + const Directives& m_directives; + std::unique_ptr m_pCollectionStack; diff --git a/sources b/sources index 8cdbf36..051b970 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (yaml-cpp-0.8.0.tar.gz) = aae9d618f906117d620d63173e95572c738db518f4ff1901a06de2117d8deeb8045f554102ca0ba4735ac0c4d060153a938ef78da3e0da3406d27b8298e5f38e +SHA512 (yaml-cpp-0.6.3.tar.gz) = 68b9ce987cabc1dec79382f922de20cc2c222cb9c090ecb93dc686b048da5c917facf4fce6d8f72feea44b61e5a6770ed3b0c199c4cd4e6bde5b6245c09f8e49 diff --git a/yaml-cpp-include.patch b/yaml-cpp-include.patch deleted file mode 100644 index b248543..0000000 --- a/yaml-cpp-include.patch +++ /dev/null @@ -1,9 +0,0 @@ -Index: yaml-cpp-0.8.0/src/emitterutils.cpp -=================================================================== ---- yaml-cpp-0.8.0.orig/src/emitterutils.cpp -+++ yaml-cpp-0.8.0/src/emitterutils.cpp -@@ -1,3 +1,4 @@ -+#include - #include - #include - #include diff --git a/yaml-cpp-include_dir.patch b/yaml-cpp-include_dir.patch new file mode 100644 index 0000000..4de7320 --- /dev/null +++ b/yaml-cpp-include_dir.patch @@ -0,0 +1,12 @@ +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -335,8 +335,7 @@ else() + endif() + endif() + +-file(RELATIVE_PATH REL_INCLUDE_DIR "${CMAKE_INSTALL_PREFIX}/${INSTALL_CMAKE_DIR}" "${CMAKE_INSTALL_PREFIX}/${INCLUDE_INSTALL_ROOT_DIR}") +-set(CONFIG_INCLUDE_DIRS "\${YAML_CPP_CMAKE_DIR}/${REL_INCLUDE_DIR}") ++set(CONFIG_INCLUDE_DIRS "${CMAKE_INSTALL_PREFIX}/${INCLUDE_INSTALL_DIR}") + + configure_file(${CMAKE_CURRENT_SOURCE_DIR}/yaml-cpp-config.cmake.in + "${PROJECT_BINARY_DIR}${CMAKE_FILES_DIRECTORY}/${YAML_TARGET}-config.cmake" @ONLY) diff --git a/yaml-cpp-static.patch b/yaml-cpp-static.patch new file mode 100644 index 0000000..5ae46f4 --- /dev/null +++ b/yaml-cpp-static.patch @@ -0,0 +1,116 @@ +--- a/CMakeLists.txt ++++ b/CMakeLists.txt +@@ -274,16 +274,20 @@ set(_INSTALL_DESTINATIONS + ### + ### Library + ### +-add_library(yaml-cpp ${library_sources}) +-set_target_properties(yaml-cpp PROPERTIES +- COMPILE_FLAGS "${yaml_c_flags} ${yaml_cxx_flags}" +-) +- +-set_target_properties(yaml-cpp PROPERTIES ++if(BUILD_SHARED_LIBS) ++ add_library(yaml-cpp SHARED ${library_sources}) ++ set_target_properties(yaml-cpp PROPERTIES + VERSION "${YAML_CPP_VERSION}" + SOVERSION "${YAML_CPP_VERSION_MAJOR}.${YAML_CPP_VERSION_MINOR}" + PROJECT_LABEL "yaml-cpp ${LABEL_SUFFIX}" ++ COMPILE_FLAGS "${yaml_c_flags} ${yaml_cxx_flags}" + ) ++else() ++ add_library(yaml-cpp STATIC ${library_sources}) ++ set_target_properties(yaml-cpp PROPERTIES ++ COMPILE_FLAGS "${yaml_c_flags} ${yaml_cxx_flags}" ++ ) ++endif() + + if(IPHONE) + set_target_properties(yaml-cpp PROPERTIES +@@ -303,48 +307,56 @@ if(MSVC) + endif() + endif() + +-install(TARGETS yaml-cpp EXPORT yaml-cpp-targets ${_INSTALL_DESTINATIONS}) + install( + DIRECTORY ${header_directory} + DESTINATION ${INCLUDE_INSTALL_DIR} + FILES_MATCHING PATTERN "*.h" + ) + +-export( +- TARGETS yaml-cpp +- FILE "${PROJECT_BINARY_DIR}/yaml-cpp-targets.cmake") +-export(PACKAGE yaml-cpp) +-set(EXPORT_TARGETS yaml-cpp CACHE INTERNAL "export targets") ++if(BUILD_SHARED_LIBS) ++ set(YAML_TARGET "yaml-cpp") ++else() ++ set(YAML_TARGET "yaml-cpp-static") ++endif() + ++install(TARGETS yaml-cpp EXPORT ${YAML_TARGET}-targets ${_INSTALL_DESTINATIONS}) ++export(TARGETS yaml-cpp ++ FILE "${PROJECT_BINARY_DIR}/${YAML_TARGET}-targets.cmake") ++set(EXPORT_TARGETS yaml-cpp CACHE INTERNAL "export targets") + set(CONFIG_INCLUDE_DIRS "${YAML_CPP_SOURCE_DIR}/include") + configure_file(${CMAKE_CURRENT_SOURCE_DIR}/yaml-cpp-config.cmake.in +- "${PROJECT_BINARY_DIR}/yaml-cpp-config.cmake" @ONLY) ++ "${PROJECT_BINARY_DIR}/${YAML_TARGET}-config.cmake" @ONLY) + ++if(NOT INSTALL_CMAKE_DIR) + if(WIN32 AND NOT CYGWIN) + set(INSTALL_CMAKE_DIR CMake) + else() +- set(INSTALL_CMAKE_DIR ${LIB_INSTALL_DIR}/cmake/yaml-cpp) ++ set(INSTALL_CMAKE_DIR ${LIB_INSTALL_DIR}/cmake/) ++endif() + endif() + + file(RELATIVE_PATH REL_INCLUDE_DIR "${CMAKE_INSTALL_PREFIX}/${INSTALL_CMAKE_DIR}" "${CMAKE_INSTALL_PREFIX}/${INCLUDE_INSTALL_ROOT_DIR}") + set(CONFIG_INCLUDE_DIRS "\${YAML_CPP_CMAKE_DIR}/${REL_INCLUDE_DIR}") +-configure_file(${CMAKE_CURRENT_SOURCE_DIR}/yaml-cpp-config.cmake.in +- "${PROJECT_BINARY_DIR}${CMAKE_FILES_DIRECTORY}/yaml-cpp-config.cmake" @ONLY) + ++configure_file(${CMAKE_CURRENT_SOURCE_DIR}/yaml-cpp-config.cmake.in ++ "${PROJECT_BINARY_DIR}${CMAKE_FILES_DIRECTORY}/${YAML_TARGET}-config.cmake" @ONLY) + configure_file(${CMAKE_CURRENT_SOURCE_DIR}/yaml-cpp-config-version.cmake.in +- "${PROJECT_BINARY_DIR}/yaml-cpp-config-version.cmake" @ONLY) +- ++ "${PROJECT_BINARY_DIR}/${YAML_TARGET}-config-version.cmake" @ONLY) + install(FILES +- "${PROJECT_BINARY_DIR}${CMAKE_FILES_DIRECTORY}/yaml-cpp-config.cmake" +- "${PROJECT_BINARY_DIR}/yaml-cpp-config-version.cmake" +- DESTINATION "${INSTALL_CMAKE_DIR}" COMPONENT dev) +-install(EXPORT yaml-cpp-targets DESTINATION ${INSTALL_CMAKE_DIR}) ++ "${PROJECT_BINARY_DIR}${CMAKE_FILES_DIRECTORY}/${YAML_TARGET}-config.cmake" ++ "${PROJECT_BINARY_DIR}/${YAML_TARGET}-config-version.cmake" ++ DESTINATION "${INSTALL_CMAKE_DIR}${YAML_TARGET}" COMPONENT dev) ++install(EXPORT ${YAML_TARGET}-targets DESTINATION ${INSTALL_CMAKE_DIR}${YAML_TARGET}) + + if(UNIX) +- set(PC_FILE ${CMAKE_BINARY_DIR}/yaml-cpp.pc) +- configure_file("yaml-cpp.pc.cmake" ${PC_FILE} @ONLY) +- install(FILES ${PC_FILE} DESTINATION ${LIB_INSTALL_DIR}/pkgconfig) ++if(BUILD_SHARED_LIBS) ++ set(PC_FILE ${CMAKE_BINARY_DIR}/yaml-cpp.pc) ++else() ++ set(PC_FILE ${CMAKE_BINARY_DIR}/yaml-cpp-static.pc) + endif() ++configure_file("yaml-cpp.pc.cmake" ${PC_FILE} @ONLY) ++install(FILES ${PC_FILE} DESTINATION ${LIB_INSTALL_DIR}/pkgconfig) ++endif(UNIX) + + + ### +--- a/yaml-cpp-config.cmake.in ++++ b/yaml-cpp-config.cmake.in +@@ -8,7 +8,7 @@ get_filename_component(YAML_CPP_CMAKE_DI + set(YAML_CPP_INCLUDE_DIR "@CONFIG_INCLUDE_DIRS@") + + # Our library dependencies (contains definitions for IMPORTED targets) +-include("${YAML_CPP_CMAKE_DIR}/yaml-cpp-targets.cmake") ++include("${YAML_CPP_CMAKE_DIR}/@YAML_TARGET@-targets.cmake") + + # These are IMPORTED targets created by yaml-cpp-targets.cmake + set(YAML_CPP_LIBRARIES "@EXPORT_TARGETS@") diff --git a/yaml-cpp.spec b/yaml-cpp.spec index 6234375..278b06e 100644 --- a/yaml-cpp.spec +++ b/yaml-cpp.spec @@ -1,156 +1,95 @@ -%global sover 0.8 +%global sover 0.6 Name: yaml-cpp -Version: 0.8.0 -Release: 6%{?dist} - -License: MIT +Version: 0.6.3 +Release: 3%{?dist} Summary: A YAML parser and emitter for C++ +License: MIT URL: https://github.com/jbeder/yaml-cpp -Source0: https://github.com/jbeder/yaml-cpp/archive/%{version}/%{name}-%{version}.tar.gz +Source0: https://github.com/jbeder/yaml-cpp/archive/%{name}-%{version}.tar.gz -Patch0: yaml-cpp-include.patch +Patch0: CVE-2017-5950.patch -# Allow CMake 4.0 build -Patch1: https://github.com/jbeder/yaml-cpp/pull/1211.patch - -BuildRequires: cmake -BuildRequires: gcc -BuildRequires: gcc-c++ +BuildRequires: cmake gcc gcc-c++ %description yaml-cpp is a YAML parser and emitter in C++ written around the YAML 1.2 spec. + %package devel Summary: Development files for %{name} -Requires: %{name}%{?_isa} = %{?epoch:%{epoch}:}%{version}-%{release} -Requires: libstdc++-devel%{?_isa} +License: MIT +Requires: %{name}%{?_isa} = %{version}-%{release} +Requires: pkgconfig %description devel The %{name}-devel package contains libraries and header files for developing applications that use %{name}. + %package static Summary: Static library for %{name} -Requires: %{name}-devel%{?_isa} = %{?epoch:%{epoch}:}%{version}-%{release} +License: MIT +Requires: %{name}-devel%{?_isa} = %{version}-%{release} %description static The %{name}-static package contains the static library for %{name}. + %prep -%autosetup -p1 +%autosetup -p1 -n %{name}-%{name}-%{version} + %build -# Define separate build directories for static and shared -%global _vpath_builddir %{_target_platform}-${variant} +%cmake -B build_shared \ + -DYAML_CPP_BUILD_TOOLS=OFF \ + -DYAML_BUILD_SHARED_LIBS=ON \ + -DYAML_CPP_BUILD_TESTS=OFF \ + %{nil} +%make_build -C build_shared -variant=static -%cmake \ - -DCMAKE_BUILD_TYPE=Release \ - -DYAML_CPP_BUILD_TOOLS:BOOL=OFF \ - -DYAML_CPP_FORMAT_SOURCE:BOOL=OFF \ - -DYAML_CPP_INSTALL:BOOL=ON \ - -DYAML_BUILD_SHARED_LIBS:BOOL=OFF \ - -DYAML_CPP_BUILD_TESTS:BOOL=OFF +%cmake -B build_static \ + -DYAML_CPP_BUILD_TOOLS=OFF \ + -DYAML_BUILD_SHARED_LIBS=OFF \ + -DYAML_CPP_BUILD_TESTS=OFF \ + %{nil} +%make_build -C build_static -variant=shared -%cmake \ - -DCMAKE_BUILD_TYPE=Release \ - -DYAML_CPP_BUILD_TOOLS:BOOL=OFF \ - -DYAML_CPP_FORMAT_SOURCE:BOOL=OFF \ - -DYAML_CPP_INSTALL:BOOL=ON \ - -DYAML_BUILD_SHARED_LIBS:BOOL=ON \ - -DYAML_CPP_BUILD_TESTS:BOOL=OFF - -for variant in static shared; do - %cmake_build -done %install -variant=static -%cmake_install +%make_install -C build_static yaml-cpp # Move files so they don't get trampled mv %{buildroot}%{_libdir}/cmake/%{name} \ - %{buildroot}%{_libdir}/cmake/%{name}-static + %{buildroot}%{_libdir}/cmake/%{name}-static mv %{buildroot}%{_libdir}/pkgconfig/%{name}.pc \ - %{buildroot}%{_libdir}/pkgconfig/%{name}-static.pc + %{buildroot}%{_libdir}/pkgconfig/%{name}-static.pc + + +%make_install -C build_shared + +%ldconfig_scriptlets -variant=shared -%cmake_install %files %doc CONTRIBUTING.md README.md %license LICENSE -%{_libdir}/lib%{name}.so.%{sover}* +%{_libdir}/*.so.%{sover}* %files devel %{_includedir}/yaml-cpp/ -%{_libdir}/lib%{name}.so +%{_libdir}/*.so %{_libdir}/cmake/%{name} %{_libdir}/pkgconfig/%{name}.pc %files static %license LICENSE -%{_libdir}/lib%{name}.a +%{_libdir}/*.a %{_libdir}/cmake/%{name}-static %{_libdir}/pkgconfig/%{name}-static.pc + %changelog -* Fri Jul 17 2026 Fedora Release Engineering - 0.8.0-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild - -* Sat Jan 17 2026 Fedora Release Engineering - 0.8.0-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild - -* Fri Jul 25 2025 Fedora Release Engineering - 0.8.0-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild - -* Thu May 15 2025 Cristian Le - 0.8.0-3 -- Allow to build with CMake 4.0 and Ninja generator - -* Sun Jan 26 2025 Richard Shaw - 0.8.0-2 -- Added patch for FTBFS, BZ#2341591. - -* Sun Jan 19 2025 Fedora Release Engineering - 0.8.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild - -* Mon Oct 21 2024 Orion Poplawski - 0.8.0-1 -- Update to 0.8.0 - -* Sat Jul 20 2024 Fedora Release Engineering - 0.7.0-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild - -* Sat Jan 27 2024 Fedora Release Engineering - 0.7.0-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild - -* Sat Jul 22 2023 Fedora Release Engineering - 0.7.0-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild - -* Wed Apr 19 2023 Vitaly Zaitsev - 0.7.0-3 -- Fixed broken CMake configs (rhbz#2188009). -- Backported CMake fixes from upstream. -- Converted license tag to SPDX. -- Performed minor SPEC cleanup. - -* Sat Jan 21 2023 Fedora Release Engineering - 0.7.0-2 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild - -* Tue Sep 06 2022 Richard Shaw - 0.7.0-1 -- Update to 0.7.0. - -* Sat Jul 23 2022 Fedora Release Engineering - 0.6.3-7 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild - -* Sat Jan 22 2022 Fedora Release Engineering - 0.6.3-6 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild - -* Fri Jul 23 2021 Fedora Release Engineering - 0.6.3-5 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild - -* Thu Jan 28 2021 Fedora Release Engineering - 0.6.3-4 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild - * Wed Jul 29 2020 Fedora Release Engineering - 0.6.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild