From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) by finch.gentoo.org (Postfix) with ESMTP id 8EF20138D29 for ; Fri, 14 Feb 2014 19:02:46 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 77E69E09F3; Fri, 14 Feb 2014 19:02:45 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id E4FFBE09F3 for ; Fri, 14 Feb 2014 19:02:44 +0000 (UTC) Received: from spoonbill.gentoo.org (spoonbill.gentoo.org [81.93.255.5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id A527333F945 for ; Fri, 14 Feb 2014 19:02:43 +0000 (UTC) Received: from localhost.localdomain (localhost [127.0.0.1]) by spoonbill.gentoo.org (Postfix) with ESMTP id 3AF6F18873 for ; Fri, 14 Feb 2014 19:02:42 +0000 (UTC) From: "Anthony G. Basile" To: gentoo-commits@lists.gentoo.org Content-Transfer-Encoding: 8bit Content-type: text/plain; charset=UTF-8 Reply-To: gentoo-dev@lists.gentoo.org, "Anthony G. Basile" Message-ID: <1392404610.5c6f7a6259fca349aafd04522a862f7d47df6db5.blueness@gentoo> Subject: [gentoo-commits] proj/hardened-dev:musl commit in: dev-libs/icu/, dev-libs/icu/files/ X-VCS-Repository: proj/hardened-dev X-VCS-Files: dev-libs/icu/files/icu-51.1-CVE-2013-2924.patch dev-libs/icu/files/icu-51.2-timezone.patch dev-libs/icu/icu-51.2-r99.ebuild dev-libs/icu/metadata.xml X-VCS-Directories: dev-libs/icu/ dev-libs/icu/files/ X-VCS-Committer: blueness X-VCS-Committer-Name: Anthony G. Basile X-VCS-Revision: 5c6f7a6259fca349aafd04522a862f7d47df6db5 X-VCS-Branch: musl Date: Fri, 14 Feb 2014 19:02:42 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org X-Archives-Salt: bf071a51-03d9-427f-af66-fcc37cc505da X-Archives-Hash: 7fc58d6c6766d715b797830406e62c6d commit: 5c6f7a6259fca349aafd04522a862f7d47df6db5 Author: Felix Janda posteo de> AuthorDate: Fri Feb 14 09:26:24 2014 +0000 Commit: Anthony G. Basile gentoo org> CommitDate: Fri Feb 14 19:03:30 2014 +0000 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-dev.git;a=commit;h=5c6f7a62 dev-libs/icu: moved to tree Package-Manager: portage-2.2.7 Manifest-Sign-Key: 0xF52D4BBA --- dev-libs/icu/files/icu-51.1-CVE-2013-2924.patch | 36 +++++++ dev-libs/icu/files/icu-51.2-timezone.patch | 11 +++ dev-libs/icu/icu-51.2-r99.ebuild | 124 ++++++++++++++++++++++++ dev-libs/icu/metadata.xml | 5 + 4 files changed, 176 insertions(+) diff --git a/dev-libs/icu/files/icu-51.1-CVE-2013-2924.patch b/dev-libs/icu/files/icu-51.1-CVE-2013-2924.patch new file mode 100644 index 0000000..65e734c --- /dev/null +++ b/dev-libs/icu/files/icu-51.1-CVE-2013-2924.patch @@ -0,0 +1,36 @@ +Index: /icu/trunk/source/i18n/csrucode.cpp +=================================================================== +--- /icu/trunk/source/i18n/csrucode.cpp (revision 34075) ++++ /icu/trunk/source/i18n/csrucode.cpp (revision 34076) +@@ -1,5 +1,5 @@ + /* + ********************************************************************** +- * Copyright (C) 2005-2012, International Business Machines ++ * Copyright (C) 2005-2013, International Business Machines + * Corporation and others. All Rights Reserved. + ********************************************************************** +@@ -34,6 +34,7 @@ + const uint8_t *input = textIn->fRawInput; + int32_t confidence = 0; ++ int32_t length = textIn->fRawLength; + +- if (input[0] == 0xFE && input[1] == 0xFF) { ++ if (length >=2 && input[0] == 0xFE && input[1] == 0xFF) { + confidence = 100; + } +@@ -58,6 +59,7 @@ + const uint8_t *input = textIn->fRawInput; + int32_t confidence = 0; ++ int32_t length = textIn->fRawLength; + +- if (input[0] == 0xFF && input[1] == 0xFE && (input[2] != 0x00 || input[3] != 0x00)) { ++ if (length >= 4 && input[0] == 0xFF && input[1] == 0xFE && (input[2] != 0x00 || input[3] != 0x00)) { + confidence = 100; + } +@@ -82,5 +84,5 @@ + int32_t confidence = 0; + +- if (getChar(input, 0) == 0x0000FEFFUL) { ++ if (limit > 0 && getChar(input, 0) == 0x0000FEFFUL) { + hasBOM = TRUE; + } diff --git a/dev-libs/icu/files/icu-51.2-timezone.patch b/dev-libs/icu/files/icu-51.2-timezone.patch new file mode 100644 index 0000000..889045e --- /dev/null +++ b/dev-libs/icu/files/icu-51.2-timezone.patch @@ -0,0 +1,11 @@ +--- a/icu/source/common/putilimp.h ++++ b/icu/source/common/putilimp.h +@@ -116,7 +116,7 @@ + #elif U_PLATFORM == U_PF_ANDROID + # define U_TIMEZONE timezone + #elif U_PLATFORM_IS_LINUX_BASED +-# if !defined(__UCLIBC__) ++# if defined(__GLIBC__) + /* __timezone is only available in glibc */ + # define U_TIMEZONE __timezone + # endif diff --git a/dev-libs/icu/icu-51.2-r99.ebuild b/dev-libs/icu/icu-51.2-r99.ebuild new file mode 100644 index 0000000..e0e308c --- /dev/null +++ b/dev-libs/icu/icu-51.2-r99.ebuild @@ -0,0 +1,124 @@ +# Copyright 1999-2013 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/dev-libs/icu/icu-51.2-r1.ebuild,v 1.11 2013/11/12 20:12:53 ago Exp $ + +EAPI=5 + +inherit eutils toolchain-funcs base autotools + +DESCRIPTION="International Components for Unicode" +HOMEPAGE="http://www.icu-project.org/" +SRC_URI="http://download.icu-project.org/files/icu4c/${PV/_/}/icu4c-${PV//./_}-src.tgz" + +LICENSE="BSD" + +SLOT="0/51.2" +# As far as I can remember, icu consumers reacted rather sensitive to icu upgrades in the past. +# Even if revdep-rebuild did not rebuild (i.e. soname did not change), random crashes and +# other irregularities occured until the consumers were rebuilt. So let's rather err on the side +# of caution and more rebuilds here. See also bug 464876. dilfridge + +KEYWORDS="alpha amd64 arm hppa ia64 ~mips ppc ppc64 ~s390 ~sh sparc x86 ~amd64-fbsd ~x86-fbsd" +IUSE="debug doc examples static-libs" + +DEPEND=" + doc? ( + app-doc/doxygen[dot] + ) +" + +S="${WORKDIR}/${PN}/source" + +PATCHES=( + "${FILESDIR}/${PN}-51.1-CVE-2013-2924.patch" + "${FILESDIR}/${PN}-51.2-timezone.patch" +) + +src_prepare() { + local variable + + base_src_prepare + + # Do not hardcode flags in icu-config and icu-*.pc files. + # https://ssl.icu-project.org/trac/ticket/6102 + for variable in CFLAGS CPPFLAGS CXXFLAGS FFLAGS LDFLAGS; do + sed \ + -e "/^${variable} =.*/s: *@${variable}@\( *$\)\?::" \ + -i config/icu.pc.in \ + -i config/Makefile.inc.in \ + || die + done + + # Disable renaming as it is stupind thing to do + sed -i \ + -e "s/#define U_DISABLE_RENAMING 0/#define U_DISABLE_RENAMING 1/" \ + common/unicode/uconfig.h || die + + # Fix linking of icudata + sed -i \ + -e "s:LDFLAGSICUDT=-nodefaultlibs -nostdlib:LDFLAGSICUDT=:" \ + config/mh-linux || die + + # Append doxygen configuration to configure + sed -i \ + -e 's:icudefs.mk:icudefs.mk Doxyfile:' \ + configure.in || die + eautoreconf +} + +src_configure() { + local cross_opts + + # bootstrap for cross compilation + if tc-is-cross-compiler; then + CFLAGS="" CXXFLAGS="" ASFLAGS="" LDFLAGS="" \ + CC="$(tc-getBUILD_CC)" CXX="$(tc-getBUILD_CXX)" AR="$(tc-getBUILD_AR)" \ + RANLIB="$(tc-getBUILD_RANLIB)" LD="$(tc-getBUILD_LD)" \ + ./configure --disable-renaming --disable-debug \ + --disable-samples --enable-static || die + emake + mkdir -p "${WORKDIR}/host/" + cp -a {bin,lib,config,tools} "${WORKDIR}/host/" + emake clean + + cross_opts="--with-cross-build=${WORKDIR}/host" + fi + + econf \ + --disable-renaming \ + $(use_enable debug) \ + $(use_enable examples samples) \ + $(use_enable static-libs static) \ + ${cross_opts} +} + +src_compile() { + default + + if use doc; then + doxygen -u Doxyfile || die + doxygen Doxyfile || die + fi +} + +src_test() { + # INTLTEST_OPTS: intltest options + # -e: Exhaustive testing + # -l: Reporting of memory leaks + # -v: Increased verbosity + # IOTEST_OPTS: iotest options + # -e: Exhaustive testing + # -v: Increased verbosity + # CINTLTST_OPTS: cintltst options + # -e: Exhaustive testing + # -v: Increased verbosity + emake -j1 VERBOSE="1" check +} + +src_install() { + default + + dohtml ../readme.html + + use doc && dohtml -p api -r doc/html/ +} diff --git a/dev-libs/icu/metadata.xml b/dev-libs/icu/metadata.xml new file mode 100644 index 0000000..5d46203 --- /dev/null +++ b/dev-libs/icu/metadata.xml @@ -0,0 +1,5 @@ + + + + openoffice +