mirror of
https://github.com/gentoo-mirror/gentoo.git
synced 2026-08-23 18:38:08 -07:00
dev-cpp/yaml-cpp: version bump to 0.6.2
Bug: https://bugs.gentoo.org/614850 Closes: https://bugs.gentoo.org/638326 Closes: https://github.com/gentoo/gentoo/pull/7294 Package-Manager: Portage-2.3.26, Repoman-2.3.7 Signed-off-by: Johannes Huber <johu@gentoo.org>
This commit is contained in:
committed by
Johannes Huber
parent
d67e1191e0
commit
40eeb5defc
@@ -1 +1,2 @@
|
||||
DIST yaml-cpp-0.5.3.tar.gz 2016737 BLAKE2B 6c10d44fe04fdd81cd61c909acdb576834f5358dd44353723b04d8a42bf8a1312cfa752e445c84f93c6ce76358b2d42dee5263f6fbd47a1f928d1cd28aedef07 SHA512 5ed15fee3c6455c08e6bd8f74256b230f274ef18f8e144491e940640e41626517c7eaaf4a1f380c4179066a2a757c8a0f61878df9dc3caa15e37c4954be47fe0
|
||||
DIST yaml-cpp-0.6.2.tar.gz 1396250 BLAKE2B be342c212c980cdb03349dbafbe1db0bb581123b4dd6909393d3cdc86145b997a9d2f9b57a5e9d7c8cc60cdfd03f1c37e9db610d8784f2d29fdeada5ab322894 SHA512 fea8ce0a20a00cbc75023d1db442edfcd32d0ac57a3c41b32ec8d56f87cc1d85d7dd7a923ce662f5d3a315f91a736d6be0d649997acd190915c1d68cc93795e4
|
||||
|
||||
45
dev-cpp/yaml-cpp/files/yaml-cpp-0.6.2-CVE-2017-5950.patch
Normal file
45
dev-cpp/yaml-cpp/files/yaml-cpp-0.6.2-CVE-2017-5950.patch
Normal file
@@ -0,0 +1,45 @@
|
||||
From d540476e31b080aa1f903ad20ec0426dd3838be7 Mon Sep 17 00:00:00 2001
|
||||
From: =?UTF-8?q?Antoine=20Beaupr=C3=A9?= <anarcat@debian.org>
|
||||
Date: Tue, 25 Apr 2017 20:10:20 -0400
|
||||
Subject: [PATCH] fix stack overflow in HandleNode() (CVE-2017-5950)
|
||||
|
||||
simply set a hardcoded recursion limit to 2000 (inspired by Python's)
|
||||
to avoid infinitely recursing into arbitrary data structures
|
||||
|
||||
assert() the depth. unsure if this is the right approach, but given
|
||||
that HandleNode() is "void", I am not sure how else to return an
|
||||
error. the problem with this approach of course is that it will still
|
||||
crash the caller, unless they have proper exception handling in place.
|
||||
|
||||
Closes: #459
|
||||
---
|
||||
src/singledocparser.cpp | 2 ++
|
||||
src/singledocparser.h | 2 ++
|
||||
2 files changed, 4 insertions(+)
|
||||
|
||||
diff --git a/src/singledocparser.cpp b/src/singledocparser.cpp
|
||||
index a27c1c3b..1b4262ee 100644
|
||||
--- a/src/singledocparser.cpp
|
||||
+++ b/src/singledocparser.cpp
|
||||
@@ -46,6 +46,8 @@ void SingleDocParser::HandleDocument(EventHandler& eventHandler) {
|
||||
}
|
||||
|
||||
void SingleDocParser::HandleNode(EventHandler& eventHandler) {
|
||||
+ assert(depth < depth_limit);
|
||||
+ depth++;
|
||||
// an empty node *is* a possibility
|
||||
if (m_scanner.empty()) {
|
||||
eventHandler.OnNull(m_scanner.mark(), NullAnchor);
|
||||
diff --git a/src/singledocparser.h b/src/singledocparser.h
|
||||
index 2b92067c..7046f1e2 100644
|
||||
--- a/src/singledocparser.h
|
||||
+++ b/src/singledocparser.h
|
||||
@@ -51,6 +51,8 @@ class SingleDocParser : private noncopyable {
|
||||
anchor_t LookupAnchor(const Mark& mark, const std::string& name) const;
|
||||
|
||||
private:
|
||||
+ int depth = 0;
|
||||
+ int depth_limit = 2000;
|
||||
Scanner& m_scanner;
|
||||
const Directives& m_directives;
|
||||
std::unique_ptr<CollectionStack> m_pCollectionStack;
|
||||
70
dev-cpp/yaml-cpp/files/yaml-cpp-0.6.2-unbundle-gtest.patch
Normal file
70
dev-cpp/yaml-cpp/files/yaml-cpp-0.6.2-unbundle-gtest.patch
Normal file
@@ -0,0 +1,70 @@
|
||||
From 259f944bc3e45420f5891737101260f07ab3030a Mon Sep 17 00:00:00 2001
|
||||
From: "Azamat H. Hackimov" <azamat.hackimov@gmail.com>
|
||||
Date: Tue, 27 Feb 2018 14:17:49 +0500
|
||||
Subject: [PATCH] Externalize googletest project
|
||||
|
||||
Externalize gtest to avoid installation, fixes #539.
|
||||
---
|
||||
test/CMakeLists.txt | 35 ++++++++++++++++++++++++++---------
|
||||
1 file changed, 26 insertions(+), 9 deletions(-)
|
||||
|
||||
diff --git a/test/CMakeLists.txt b/test/CMakeLists.txt
|
||||
index 3633da5..7b39dd4 100644
|
||||
--- a/test/CMakeLists.txt
|
||||
+++ b/test/CMakeLists.txt
|
||||
@@ -1,16 +1,27 @@
|
||||
+include(ExternalProject)
|
||||
+
|
||||
+ExternalProject_Add(
|
||||
+ googletest_project
|
||||
+ SOURCE_DIR "${CMAKE_SOURCE_DIR}/test/gtest-1.8.0"
|
||||
+ INSTALL_DIR "${CMAKE_BINARY_DIR}/prefix"
|
||||
+ CMAKE_ARGS -DCMAKE_INSTALL_PREFIX:PATH=<INSTALL_DIR> -DBUILD_GMOCK=ON
|
||||
+)
|
||||
+
|
||||
+add_library(gmock UNKNOWN IMPORTED)
|
||||
+set_target_properties(gmock PROPERTIES
|
||||
+ IMPORTED_LOCATION ${PROJECT_BINARY_DIR}/prefix/lib/libgmock.a
|
||||
+)
|
||||
+
|
||||
+find_package(Threads)
|
||||
+
|
||||
+include_directories(SYSTEM "${PROJECT_BINARY_DIR}/prefix/include")
|
||||
+
|
||||
set(gtest_force_shared_crt ${MSVC_SHARED_RT} CACHE BOOL
|
||||
"Use shared (DLL) run-time lib even when Google Test built as a static lib.")
|
||||
-add_subdirectory(gtest-1.8.0)
|
||||
-include_directories(SYSTEM gtest-1.8.0/googlemock/include)
|
||||
-include_directories(SYSTEM gtest-1.8.0/googletest/include)
|
||||
-
|
||||
-if(WIN32 AND BUILD_SHARED_LIBS)
|
||||
- add_definitions("-DGTEST_LINKED_AS_SHARED_LIBRARY")
|
||||
-endif()
|
||||
|
||||
if(CMAKE_CXX_COMPILER_ID MATCHES "GNU" OR
|
||||
CMAKE_CXX_COMPILER_ID MATCHES "Clang")
|
||||
- set(yaml_test_flags "-Wno-variadic-macros -Wno-sign-compare")
|
||||
+ set(yaml_test_flags "-Wno-variadic-macros -Wno-sign-compare")
|
||||
|
||||
if(CMAKE_CXX_COMPILER_ID MATCHES "Clang")
|
||||
set(yaml_test_flags "${yaml_test_flags} -Wno-c99-extensions")
|
||||
@@ -36,9 +47,15 @@ add_executable(run-tests
|
||||
${test_sources}
|
||||
${test_headers}
|
||||
)
|
||||
+
|
||||
+add_dependencies(run-tests googletest_project)
|
||||
+
|
||||
set_target_properties(run-tests PROPERTIES
|
||||
COMPILE_FLAGS "${yaml_c_flags} ${yaml_cxx_flags} ${yaml_test_flags}"
|
||||
)
|
||||
-target_link_libraries(run-tests yaml-cpp gmock)
|
||||
+target_link_libraries(run-tests
|
||||
+ yaml-cpp
|
||||
+ gmock
|
||||
+ ${CMAKE_THREAD_LIBS_INIT})
|
||||
|
||||
add_test(yaml-test ${CMAKE_RUNTIME_OUTPUT_DIRECTORY}/run-tests)
|
||||
--
|
||||
2.16.1
|
||||
|
||||
41
dev-cpp/yaml-cpp/yaml-cpp-0.6.2.ebuild
Normal file
41
dev-cpp/yaml-cpp/yaml-cpp-0.6.2.ebuild
Normal file
@@ -0,0 +1,41 @@
|
||||
# Copyright 1999-2018 Gentoo Foundation
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
EAPI=6
|
||||
|
||||
inherit cmake-multilib
|
||||
|
||||
DESCRIPTION="YAML parser and emitter in C++"
|
||||
HOMEPAGE="https://github.com/jbeder/yaml-cpp"
|
||||
SRC_URI="https://github.com/jbeder/${PN}/archive/${P}.tar.gz"
|
||||
|
||||
LICENSE="MIT"
|
||||
SLOT="0/0.6"
|
||||
KEYWORDS="~amd64 ~arm ~arm64 ~hppa ~ppc ~ppc64 ~sparc ~x86 ~amd64-linux ~x86-linux"
|
||||
IUSE="test"
|
||||
|
||||
DEPEND="test? ( dev-cpp/gtest )"
|
||||
|
||||
S="${WORKDIR}/${PN}-${P}"
|
||||
|
||||
PATCHES=(
|
||||
"${FILESDIR}/${P}-CVE-2017-5950.patch"
|
||||
"${FILESDIR}/${P}-unbundle-gtest.patch"
|
||||
)
|
||||
|
||||
src_prepare() {
|
||||
sed -i \
|
||||
-e 's:INCLUDE_INSTALL_ROOT_DIR:INCLUDE_INSTALL_DIR:g' \
|
||||
yaml-cpp.pc.cmake || die
|
||||
|
||||
cmake-utils_src_prepare
|
||||
}
|
||||
|
||||
src_configure() {
|
||||
local mycmakeargs=(
|
||||
-DBUILD_SHARED_LIBS=ON
|
||||
-DYAML_CPP_BUILD_TOOLS=OFF # Don't have install rule
|
||||
-DYAML_CPP_BUILD_TESTS=$(usex test)
|
||||
)
|
||||
cmake-multilib_src_configure
|
||||
}
|
||||
Reference in New Issue
Block a user