Compare commits
19 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b7316319ef | ||
|
|
16463a79f5 | ||
|
|
0383ea27d4 | ||
|
|
702cc3f7da | ||
|
|
8446d35cde | ||
|
|
9c1bab774b | ||
|
|
c039bec76a | ||
|
|
c163152846 | ||
|
|
56f9bc9eca | ||
|
|
24be5bac48 | ||
|
|
8f8ee6bc68 | ||
|
|
f75a09275e | ||
|
|
dda78ba4a3 | ||
|
|
ef9bc5fd03 | ||
|
|
49f4e68b6b | ||
|
|
04783ad24f | ||
|
|
eb2c84eb26 | ||
|
|
a703e397c1 | ||
|
|
ae4d8de2fd |
8 changed files with 1148 additions and 1238 deletions
1
.gitignore
vendored
1
.gitignore
vendored
|
|
@ -1,2 +1,3 @@
|
|||
/yelp-*.tar.bz2
|
||||
/yelp-*.tar.xz
|
||||
/yelp-*-build
|
||||
|
|
|
|||
40
.packit.yaml
Normal file
40
.packit.yaml
Normal file
|
|
@ -0,0 +1,40 @@
|
|||
# Minimal Packit Configuration for GNOME Packages
|
||||
# Copy this to your dist-git repository as .packit.yaml
|
||||
#
|
||||
# Prerequisites:
|
||||
# - Package is monitored by release-monitoring.org
|
||||
# - Monitoring status set to "Monitoring" in dist-git
|
||||
|
||||
jobs:
|
||||
# Automated updates for stable branches
|
||||
- job: pull_from_upstream
|
||||
trigger: release
|
||||
dist_git_branches:
|
||||
- fedora-stable
|
||||
|
||||
# ========================================================================
|
||||
# VERSIONING: Choose ONE option based on your package's versioning scheme
|
||||
# ========================================================================
|
||||
|
||||
# OPTION A: Major version only - allows minor and patch updates
|
||||
# For 2-digit: 50.0 -> 50.1 ✅, 50.x -> 51.0 ❌
|
||||
# For 3-digit: 1.2.3 -> 1.3.0 ✅, 1.x.x -> 2.0.0 ❌
|
||||
# Use for: GNOME apps/libs with 2-digit versions, or libraries following semver
|
||||
version_update_mask: '^\d+\.'
|
||||
|
||||
# OPTION B: Major.minor version - patch updates only
|
||||
# Examples: 1.2.3 -> 1.2.4 ✅, 1.2.x -> 1.3.0 ❌
|
||||
# Use for: Libraries with ABI concerns, even/odd development scheme
|
||||
# version_update_mask: '^\d+\.\d+\.'
|
||||
|
||||
# Build in Koji after merge
|
||||
- job: koji_build
|
||||
trigger: commit
|
||||
dist_git_branches:
|
||||
- fedora-stable
|
||||
|
||||
# Submit Bodhi update
|
||||
- job: bodhi_update
|
||||
trigger: commit
|
||||
dist_git_branches:
|
||||
- fedora-stable
|
||||
|
|
@ -1,26 +0,0 @@
|
|||
From c323dd5087a15cb2b820fedf311ca288ec347878 Mon Sep 17 00:00:00 2001
|
||||
From: Matthias Clasen <mclasen@redhat.com>
|
||||
Date: Thu, 8 Nov 2012 22:57:12 -0500
|
||||
Subject: [PATCH] Center new windows
|
||||
|
||||
This makes more sense than letting mutter put them in the top
|
||||
left corner.
|
||||
---
|
||||
src/yelp-application.c | 1 +
|
||||
1 file changed, 1 insertion(+)
|
||||
|
||||
diff --git a/src/yelp-application.c b/src/yelp-application.c
|
||||
index 2d004c2..e669661 100644
|
||||
--- a/src/yelp-application.c
|
||||
+++ b/src/yelp-application.c
|
||||
@@ -444,6 +444,7 @@ application_uri_resolved (YelpUri *uri,
|
||||
|
||||
g_settings_get (settings, "geometry", "(ii)", &width, &height);
|
||||
window = yelp_window_new (data->app);
|
||||
+ gtk_window_set_position (GTK_WINDOW (window), GTK_WIN_POS_CENTER);
|
||||
gtk_window_set_default_size (GTK_WINDOW (window), width, height);
|
||||
g_signal_connect (window, "resized", G_CALLBACK (window_resized), data->app);
|
||||
priv->windows = g_slist_prepend (priv->windows, window);
|
||||
--
|
||||
1.7.12.1
|
||||
|
||||
13
monitoring.toml
Normal file
13
monitoring.toml
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
# Enable/disable monitoring
|
||||
monitoring = true
|
||||
# Enable/disable filling bugzilla ticket for new release
|
||||
# When disabled it will also disable scratch builds
|
||||
bugzilla = false
|
||||
# Enable/disable reporting only stable versions
|
||||
# Stable versions are recognized based on release-monitoring.org project settings
|
||||
stable_only = true
|
||||
# Enable/disable reporting all new versions instead of the latest one
|
||||
# Enabling this will disable scratch builds
|
||||
all_versions = true
|
||||
# Enable/disable scratch build for newly opened version
|
||||
scratch_build = false
|
||||
2
sources
2
sources
|
|
@ -1 +1 @@
|
|||
SHA512 (yelp-42.2.tar.xz) = 7fd8da347b3cdb9b24a31eebe14c4964c5e41956caa2b79e70d6ea0c829d94f8428bbd96a2472c02d56673ca0ed1c75f7c6f874a59c4eea0b1440918a99969f4
|
||||
SHA512 (yelp-49.2.tar.xz) = 8cca0fbc0b8bdf8d1881c408ef1b4d4f008fc05631b7a50b97288fdb11d1e06fe8ffc268354a23e6f59b76dd3d390759e25e5aa93cac6a487d09c2eb7665564c
|
||||
|
|
|
|||
|
|
@ -1,118 +0,0 @@
|
|||
From 7ecd58dc0ca7bf9d0acb00bf04194a0cb6e8b724 Mon Sep 17 00:00:00 2001
|
||||
From: Shaun McCance <shaunm@gnome.org>
|
||||
Date: Fri, 18 Apr 2025 11:33:01 -0400
|
||||
Subject: [PATCH] Initial fix for CVE-2025-3155 from parrot409
|
||||
|
||||
https://gitlab.gnome.org/GNOME/yelp/-/issues/221
|
||||
---
|
||||
data/xslt/mal2html.xsl.in | 5 +++++
|
||||
data/xslt/man2html.xsl.in | 2 +-
|
||||
data/xslt/yelp-common.xsl.in | 7 +++++++
|
||||
libyelp/yelp-transform.c | 19 +++++++++++++++++++
|
||||
libyelp/yelp-view.c | 2 +-
|
||||
5 files changed, 33 insertions(+), 2 deletions(-)
|
||||
|
||||
diff --git a/data/xslt/mal2html.xsl.in b/data/xslt/mal2html.xsl.in
|
||||
index 9e44b734..0a74da55 100644
|
||||
--- a/data/xslt/mal2html.xsl.in
|
||||
+++ b/data/xslt/mal2html.xsl.in
|
||||
@@ -19,6 +19,11 @@
|
||||
<xsl:param name="mal.link.prefix" select="'xref:'"/>
|
||||
<xsl:param name="mal.link.extension" select="''"/>
|
||||
|
||||
+<xsl:template name="html.head.top.custom">
|
||||
+ <xsl:param name="node" select="."/>
|
||||
+ <meta http-equiv="Content-Security-Policy" content="default-src bogus-ghelp: bogus-gnome-help: bogus-help: bogus-help-list: bogus-info: bogus-man: ; script-src 'nonce-{$html.csp.nonce}'; style-src 'nonce-{$html.csp.nonce}'; "/>
|
||||
+</xsl:template>
|
||||
+
|
||||
<xsl:template name="mal.link.target.custom">
|
||||
<xsl:param name="node" select="."/>
|
||||
<xsl:param name="action" select="$node/@action"/>
|
||||
diff --git a/data/xslt/man2html.xsl.in b/data/xslt/man2html.xsl.in
|
||||
index 676ce3eb..56bc1f5c 100644
|
||||
--- a/data/xslt/man2html.xsl.in
|
||||
+++ b/data/xslt/man2html.xsl.in
|
||||
@@ -131,7 +131,7 @@
|
||||
the correct styling and a single character which we measure the
|
||||
width of and update each sheet as required.
|
||||
-->
|
||||
-<script type="text/javascript" language="javascript">
|
||||
+<script type="text/javascript" language="javascript" nonce="{$html.csp.nonce}">
|
||||
<xsl:text>
|
||||
$(document).ready (function () {
|
||||
var div = document.getElementById("invisible-char");
|
||||
diff --git a/data/xslt/yelp-common.xsl.in b/data/xslt/yelp-common.xsl.in
|
||||
index 0c1ec9bb..421fc02d 100644
|
||||
--- a/data/xslt/yelp-common.xsl.in
|
||||
+++ b/data/xslt/yelp-common.xsl.in
|
||||
@@ -15,6 +15,13 @@
|
||||
<xsl:param name="html.syntax.highlight" select="true()"/>
|
||||
<xsl:param name="html.js.root" select="'file://@XSL_JSDIR@/'"/>
|
||||
|
||||
+<xsl:param name="html.csp.nonce" select="yelp:generate_nonce()"/>
|
||||
+
|
||||
+<xsl:template name="html.head.top.custom">
|
||||
+ <xsl:param name="node" select="."/>
|
||||
+ <meta http-equiv="Content-Security-Policy" content="default-src bogus-ghelp: bogus-gnome-help: bogus-help: bogus-help-list: bogus-info: bogus-man: ; script-src 'nonce-{$html.csp.nonce}'; style-src 'unsafe-inline'; "/>
|
||||
+</xsl:template>
|
||||
+
|
||||
<xsl:template name="html.js.mathjax">
|
||||
<xsl:param name="node" select="."/>
|
||||
<xsl:if test="$node//mml:*[1]">
|
||||
diff --git a/libyelp/yelp-transform.c b/libyelp/yelp-transform.c
|
||||
index e74eb463..2ce1d05b 100644
|
||||
--- a/libyelp/yelp-transform.c
|
||||
+++ b/libyelp/yelp-transform.c
|
||||
@@ -71,6 +71,8 @@ static void xslt_yelp_cache (xsltTransformContextPtr ctxt,
|
||||
xsltStylePreCompPtr comp);
|
||||
static void xslt_yelp_aux (xmlXPathParserContextPtr ctxt,
|
||||
int nargs);
|
||||
+static void xslt_yelp_generate_nonce (xmlXPathParserContextPtr ctxt,
|
||||
+ int nargs);
|
||||
|
||||
enum {
|
||||
PROP_0,
|
||||
@@ -412,6 +414,10 @@ transform_run (YelpTransform *transform)
|
||||
BAD_CAST "input",
|
||||
BAD_CAST YELP_NAMESPACE,
|
||||
(xmlXPathFunction) xslt_yelp_aux);
|
||||
+ xsltRegisterExtFunction (priv->context,
|
||||
+ BAD_CAST "generate_nonce",
|
||||
+ BAD_CAST YELP_NAMESPACE,
|
||||
+ (xmlXPathFunction) xslt_yelp_generate_nonce);
|
||||
|
||||
priv->output = xsltApplyStylesheetUser (priv->stylesheet,
|
||||
priv->input,
|
||||
@@ -607,3 +613,16 @@ xslt_yelp_aux (xmlXPathParserContextPtr ctxt, int nargs)
|
||||
xsltExtensionInstructionResultRegister (tctxt, ret);
|
||||
valuePush (ctxt, ret);
|
||||
}
|
||||
+
|
||||
+static void
|
||||
+xslt_yelp_generate_nonce (xmlXPathParserContextPtr ctxt, int nargs)
|
||||
+{
|
||||
+ GRand* rand;
|
||||
+ gchar* nonce_str;
|
||||
+
|
||||
+ rand = g_rand_new ();
|
||||
+ nonce_str = g_strdup_printf("%08x%08x", g_rand_int (rand), g_rand_int (rand));
|
||||
+ xmlXPathReturnString (ctxt, xmlStrdup ((xmlChar *) nonce_str));
|
||||
+ g_free(nonce_str);
|
||||
+ g_rand_free(rand);
|
||||
+}
|
||||
diff --git a/libyelp/yelp-view.c b/libyelp/yelp-view.c
|
||||
index 32ae131e..d544c5df 100644
|
||||
--- a/libyelp/yelp-view.c
|
||||
+++ b/libyelp/yelp-view.c
|
||||
@@ -971,7 +971,7 @@ view_external_uri (YelpView *view,
|
||||
|
||||
if (app_info)
|
||||
{
|
||||
- if (!strstr (g_app_info_get_executable (app_info), "yelp"))
|
||||
+ if (!strstr (g_app_info_get_executable (app_info), "yelp") && !strstr (struri, "%3C") && !strstr (struri, "%3E"))
|
||||
{
|
||||
GList l;
|
||||
|
||||
--
|
||||
GitLab
|
||||
|
||||
Loading…
Add table
Add a link
Reference in a new issue