From 49b82ebcd6543088d00ba0cc7b8808b4958e6511 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 22 Jul 2023 19:29:56 +0000 Subject: [PATCH 01/26] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- yelp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yelp.spec b/yelp.spec index 75529c6..83e779e 100644 --- a/yelp.spec +++ b/yelp.spec @@ -6,7 +6,7 @@ Name: yelp Epoch: 2 Version: 42.2 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Help browser for the GNOME desktop License: LGPLv2+ and ASL 2.0 and GPLv2+ @@ -98,6 +98,9 @@ desktop-file-validate $RPM_BUILD_ROOT%{_datadir}/applications/yelp.desktop %changelog +* Sat Jul 22 2023 Fedora Release Engineering - 2:42.2-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Sat Jan 21 2023 Fedora Release Engineering - 2:42.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild From 03f93173647515c82584ebb570245e0176d8d12f Mon Sep 17 00:00:00 2001 From: Yaakov Selkowitz Date: Fri, 11 Aug 2023 12:42:42 -0400 Subject: [PATCH 02/26] Drop unused libunwind dependencies These were added 08 April 2022 to fix issues with rawhide composes at the time, but yelp has no such dependency at either build nor runtime. Parts of GStreamer and Mesa do use libunwind, so it was possibly transitive. --- yelp.spec | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/yelp.spec b/yelp.spec index 83e779e..25df8b2 100644 --- a/yelp.spec +++ b/yelp.spec @@ -1,12 +1,11 @@ %global libhandy_version 1.5.0 -%global libunwind_version 1.6.2 %global tarball_version %%(echo %{version} | tr '~' '.') Name: yelp Epoch: 2 Version: 42.2 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Help browser for the GNOME desktop License: LGPLv2+ and ASL 2.0 and GPLv2+ @@ -25,7 +24,6 @@ BuildRequires: pkgconfig(libxslt) BuildRequires: pkgconfig(sqlite3) BuildRequires: pkgconfig(webkit2gtk-4.1) BuildRequires: pkgconfig(yelp-xsl) -BuildRequires: libunwind BuildRequires: desktop-file-utils BuildRequires: bzip2-devel BuildRequires: gcc @@ -34,7 +32,6 @@ BuildRequires: intltool BuildRequires: itstool BuildRequires: make Requires: libhandy%{?_isa} >= %{libhandy_version} -Requires: libunwind%{?_isa} >= %{libunwind_version} Requires: yelp-libs%{?_isa} = %{epoch}:%{version}-%{release} Requires: yelp-xsl @@ -98,6 +95,9 @@ desktop-file-validate $RPM_BUILD_ROOT%{_datadir}/applications/yelp.desktop %changelog +* Fri Aug 11 2023 Yaakov Selkowitz - 2:42.2-4 +- Drop unused libunwind dependencies + * Sat Jul 22 2023 Fedora Release Engineering - 2:42.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild From 4f435be116c06435c51681ed7d86c3bdfbfc269c Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 27 Jan 2024 10:45:40 +0000 Subject: [PATCH 03/26] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- yelp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yelp.spec b/yelp.spec index 25df8b2..0b70fb5 100644 --- a/yelp.spec +++ b/yelp.spec @@ -5,7 +5,7 @@ Name: yelp Epoch: 2 Version: 42.2 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Help browser for the GNOME desktop License: LGPLv2+ and ASL 2.0 and GPLv2+ @@ -95,6 +95,9 @@ desktop-file-validate $RPM_BUILD_ROOT%{_datadir}/applications/yelp.desktop %changelog +* Sat Jan 27 2024 Fedora Release Engineering - 2:42.2-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Fri Aug 11 2023 Yaakov Selkowitz - 2:42.2-4 - Drop unused libunwind dependencies From 479e2ba578898daff7d8f2e2bee151260a8ef799 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 20 Jul 2024 10:41:08 +0000 Subject: [PATCH 04/26] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- yelp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yelp.spec b/yelp.spec index 0b70fb5..427989b 100644 --- a/yelp.spec +++ b/yelp.spec @@ -5,7 +5,7 @@ Name: yelp Epoch: 2 Version: 42.2 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Help browser for the GNOME desktop License: LGPLv2+ and ASL 2.0 and GPLv2+ @@ -95,6 +95,9 @@ desktop-file-validate $RPM_BUILD_ROOT%{_datadir}/applications/yelp.desktop %changelog +* Sat Jul 20 2024 Fedora Release Engineering - 2:42.2-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Sat Jan 27 2024 Fedora Release Engineering - 2:42.2-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From 89bca12d4cfd6e77435131079ee1f6d2bdba6883 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miroslav=20Such=C3=BD?= Date: Wed, 4 Sep 2024 23:00:26 +0200 Subject: [PATCH 05/26] convert license to SPDX This is part of https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_4 --- yelp.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/yelp.spec b/yelp.spec index 427989b..ca2ea92 100644 --- a/yelp.spec +++ b/yelp.spec @@ -5,10 +5,11 @@ Name: yelp Epoch: 2 Version: 42.2 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Help browser for the GNOME desktop -License: LGPLv2+ and ASL 2.0 and GPLv2+ +# Automatically converted from old format: LGPLv2+ and ASL 2.0 and GPLv2+ - review is highly recommended. +License: LicenseRef-Callaway-LGPLv2+ AND Apache-2.0 AND GPL-2.0-or-later URL: https://wiki.gnome.org/Apps/Yelp Source: https://download.gnome.org/sources/%{name}/42/%{name}-%{tarball_version}.tar.xz @@ -95,6 +96,9 @@ desktop-file-validate $RPM_BUILD_ROOT%{_datadir}/applications/yelp.desktop %changelog +* Wed Sep 04 2024 Miroslav Suchý - 2:42.2-7 +- convert license to SPDX + * Sat Jul 20 2024 Fedora Release Engineering - 2:42.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From 1fc4efa67e9fc9141c302e1e35931199de14a33f Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 19 Jan 2025 16:32:59 +0000 Subject: [PATCH 06/26] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- yelp.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/yelp.spec b/yelp.spec index ca2ea92..ad22988 100644 --- a/yelp.spec +++ b/yelp.spec @@ -5,7 +5,7 @@ Name: yelp Epoch: 2 Version: 42.2 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Help browser for the GNOME desktop # Automatically converted from old format: LGPLv2+ and ASL 2.0 and GPLv2+ - review is highly recommended. @@ -96,6 +96,9 @@ desktop-file-validate $RPM_BUILD_ROOT%{_datadir}/applications/yelp.desktop %changelog +* Sun Jan 19 2025 Fedora Release Engineering - 2:42.2-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Wed Sep 04 2024 Miroslav Suchý - 2:42.2-7 - convert license to SPDX From 8ab3826b971f5fef2d8da095d2191995a688bc15 Mon Sep 17 00:00:00 2001 From: Jan Grulich Date: Fri, 9 May 2025 09:03:26 +0200 Subject: [PATCH 07/26] Fix CVE-2025-3155 - arbitrary file-read --- yelp-CVE-2025-3155.patch | 118 +++++++++++++++++++++++++++++++++++++++ yelp.spec | 7 ++- 2 files changed, 124 insertions(+), 1 deletion(-) create mode 100644 yelp-CVE-2025-3155.patch diff --git a/yelp-CVE-2025-3155.patch b/yelp-CVE-2025-3155.patch new file mode 100644 index 0000000..1c10b61 --- /dev/null +++ b/yelp-CVE-2025-3155.patch @@ -0,0 +1,118 @@ +From 7ecd58dc0ca7bf9d0acb00bf04194a0cb6e8b724 Mon Sep 17 00:00:00 2001 +From: Shaun McCance +Date: Fri, 18 Apr 2025 11:33:01 -0400 +Subject: [PATCH] Initial fix for CVE-2025-3155 from parrot409 + +https://gitlab.gnome.org/GNOME/yelp/-/issues/221 +--- + data/xslt/mal2html.xsl.in | 5 +++++ + data/xslt/man2html.xsl.in | 2 +- + data/xslt/yelp-common.xsl.in | 7 +++++++ + libyelp/yelp-transform.c | 19 +++++++++++++++++++ + libyelp/yelp-view.c | 2 +- + 5 files changed, 33 insertions(+), 2 deletions(-) + +diff --git a/data/xslt/mal2html.xsl.in b/data/xslt/mal2html.xsl.in +index 9e44b734..0a74da55 100644 +--- a/data/xslt/mal2html.xsl.in ++++ b/data/xslt/mal2html.xsl.in +@@ -19,6 +19,11 @@ + + + ++ ++ ++ ++ ++ + + + +diff --git a/data/xslt/man2html.xsl.in b/data/xslt/man2html.xsl.in +index 676ce3eb..56bc1f5c 100644 +--- a/data/xslt/man2html.xsl.in ++++ b/data/xslt/man2html.xsl.in +@@ -131,7 +131,7 @@ + the correct styling and a single character which we measure the + width of and update each sheet as required. + --> +-