mirror of
git://slackware.nl/current.git
synced 2024-12-28 09:59:53 +01:00
1269f45932
It may look like we're currently experiencing more stuckness, but this will lead us to Quality. We'll have this release in the can before you know it. a/aaa_glibc-solibs-2.33-x86_64-5.txz: Rebuilt. a/aaa_libraries-15.0-x86_64-16.txz: Rebuilt. Rebuilt to pick up the patched libexpat.so.1.8.3. a/kernel-firmware-20220124_eb8ea1b-noarch-1.txz: Upgraded. a/kernel-generic-5.15.16-x86_64-2.txz: Upgraded. a/kernel-huge-5.15.16-x86_64-2.txz: Upgraded. -9P_FSCACHE n 9P_FS m -> y Thanks to peake. a/kernel-modules-5.15.16-x86_64-2.txz: Upgraded. a/mkinitrd-1.4.11-x86_64-27.txz: Rebuilt. mkinitrd_command_generator.sh: properly detect partitions of a RAID device. Thanks to perrin4869. a/util-linux-2.37.3-x86_64-1.txz: Upgraded. This release fixes two security mount(8) and umount(8) issues: An issue related to parsing the /proc/self/mountinfo file allows an unprivileged user to unmount other user's filesystems that are either world-writable themselves or mounted in a world-writable directory. Improper UID check in libmount allows an unprivileged user to unmount FUSE filesystems of users with similar UID. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3995 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3996 (* Security fix *) ap/vim-8.2.4212-x86_64-1.txz: Upgraded. d/git-2.35.0-x86_64-1.txz: Upgraded. d/kernel-headers-5.15.16-x86-2.txz: Upgraded. k/kernel-source-5.15.16-noarch-2.txz: Upgraded. l/expat-2.4.3-x86_64-2.txz: Rebuilt. Fix signed integer overflow in function XML_GetBuffer for when XML_CONTEXT_BYTES is defined to >0 (which is both common and default). Impact is denial of service or other undefined behavior. While we're here, also patch a memory leak on output file opening error. Thanks to marav. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23852 (* Security fix *) l/fluidsynth-2.2.5-x86_64-1.txz: Upgraded. l/glibc-2.33-x86_64-5.txz: Rebuilt. This update patches two security issues: Unexpected return value from glibc's realpath(). Off-by-one buffer overflow/underflow in glibc's getcwd(). Thanks to Qualys Research Labs for reporting these issues. For more information, see: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3998 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3999 (* Security fix *) l/glibc-i18n-2.33-x86_64-5.txz: Rebuilt. l/glibc-profile-2.33-x86_64-5.txz: Rebuilt. l/tdb-1.4.6-x86_64-1.txz: Upgraded. x/xf86-input-libinput-1.2.1-x86_64-1.txz: Upgraded. xap/mozilla-thunderbird-91.5.1-x86_64-1.txz: Upgraded. This is a bugfix release. For more information, see: https://www.mozilla.org/en-US/thunderbird/91.5.1/releasenotes/ xap/vim-gvim-8.2.4212-x86_64-1.txz: Upgraded. isolinux/initrd.img: Rebuilt. kernels/*: Upgraded. usb-and-pxe-installers/usbboot.img: Rebuilt.
149 lines
4.5 KiB
Bash
Executable file
149 lines
4.5 KiB
Bash
Executable file
#!/bin/bash
|
|
# Copyright 2006, 2007, 2008, 2009, 2010, 2011, 2012, 2013, 2015, 2018, 2020, 2021 Patrick J. Volkerding, Sebeka, MN, USA
|
|
# All rights reserved.
|
|
#
|
|
# Redistribution and use of this script, with or without modification, is
|
|
# permitted provided that the following conditions are met:
|
|
#
|
|
# 1. Redistributions of this script must retain the above copyright
|
|
# notice, this list of conditions and the following disclaimer.
|
|
#
|
|
# THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR IMPLIED
|
|
# WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
|
|
# MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO
|
|
# EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
|
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
|
|
# PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS;
|
|
# OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
|
|
# WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR
|
|
# OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
|
|
# ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
cd $(dirname $0) ; CWD=$(pwd)
|
|
|
|
PKGNAM=aaa_libraries
|
|
VERSION=${VERSION:-15.0}
|
|
BUILD=${BUILD:-16}
|
|
|
|
# Automatically determine the architecture we're building on:
|
|
if [ -z "$ARCH" ]; then
|
|
case "$( uname -m )" in
|
|
i?86) export ARCH=i586 ;;
|
|
arm*) export ARCH=arm ;;
|
|
# Unless $ARCH is already set, use uname -m for all other archs:
|
|
*) export ARCH=$( uname -m ) ;;
|
|
esac
|
|
fi
|
|
|
|
# If the variable PRINT_PACKAGE_NAME is set, then this script will report what
|
|
# the name of the created package would be, and then exit. This information
|
|
# could be useful to other scripts.
|
|
if [ ! -z "${PRINT_PACKAGE_NAME}" ]; then
|
|
echo "$PKGNAM-$VERSION-$ARCH-$BUILD.txz"
|
|
exit 0
|
|
fi
|
|
|
|
if [ "$ARCH" = "x86_64" ]; then
|
|
LIBDIRSUFFIX="64"
|
|
else
|
|
LIBDIRSUFFIX=""
|
|
fi
|
|
|
|
TMP=${TMP:-/tmp}
|
|
PKG=$TMP/package-${PKGNAM}
|
|
rm -rf $PKG
|
|
mkdir -p $TMP $PKG
|
|
|
|
if [ -x /sbin/ldconfig ]; then
|
|
/sbin/ldconfig
|
|
fi
|
|
|
|
cd $PKG
|
|
cat $CWD/symlinks-to-tracked-libs \
|
|
| grep -v "^#" | grep -v "^$" \
|
|
| sed -e "s#^/lib/#/lib${LIBDIRSUFFIX}/#" \
|
|
-e "s#^/usr/lib/#/usr/lib${LIBDIRSUFFIX}/#" \
|
|
| while read library ; do
|
|
( if [ ! -e $library ]; then
|
|
echo "WARNING: $library not found"
|
|
sleep 10
|
|
exit 0
|
|
fi
|
|
echo "Adding $library"
|
|
mkdir -p $(dirname $library | cut -b2- )
|
|
cd $(dirname $library | cut -b2- )
|
|
rm -f $(basename $library)
|
|
cp -a $library .
|
|
rm -f $(readlink $library)
|
|
cp -a $(dirname $library)/$(readlink $library) .
|
|
)
|
|
done
|
|
|
|
cat $CWD/tracked-files \
|
|
| grep -v "^#" | grep -v "^$" \
|
|
| sed -e "s#^/lib/#/lib${LIBDIRSUFFIX}/#" \
|
|
-e "s#^/usr/lib/#/usr/lib${LIBDIRSUFFIX}/#" \
|
|
| while read library ; do
|
|
( if [ ! -e $library ]; then
|
|
echo "WARNING: $library not found"
|
|
sleep 10
|
|
exit 0
|
|
fi
|
|
echo "Adding $library"
|
|
mkdir -p $(dirname $library | cut -b2- )
|
|
cd $(dirname $library | cut -b2- )
|
|
rm -f $(basename $library)
|
|
cp -a $library .
|
|
)
|
|
done
|
|
|
|
cat $CWD/symlinks-to-tracked-libs-tmp.d/* \
|
|
| grep -v "^#" | grep -v "^$" \
|
|
| sed -e "s#^/lib/#/lib${LIBDIRSUFFIX}/#" \
|
|
-e "s#^/usr/lib/#/usr/lib${LIBDIRSUFFIX}/#" \
|
|
| while read library ; do
|
|
( if [ ! -e $library ]; then
|
|
echo "WARNING: $library not found"
|
|
sleep 10
|
|
exit 0
|
|
fi
|
|
echo "Adding $library"
|
|
mkdir -p $(dirname $library | cut -b2- )
|
|
cd $(dirname $library | cut -b2- )
|
|
rm -f $(basename $library)
|
|
cp -a $library .
|
|
rm -f $(readlink $library)
|
|
cp -a $(dirname $library)/$(readlink $library) .
|
|
)
|
|
done
|
|
|
|
cat $CWD/tracked-files-tmp.d/* \
|
|
| grep -v "^#" | grep -v "^$" \
|
|
| sed -e "s#^/lib/#/lib${LIBDIRSUFFIX}/#" \
|
|
-e "s#^/usr/lib/#/usr/lib${LIBDIRSUFFIX}/#" \
|
|
| while read library ; do
|
|
( if [ ! -e $library ]; then
|
|
echo "WARNING: $library not found"
|
|
sleep 10
|
|
exit 0
|
|
fi
|
|
echo "Adding $library"
|
|
mkdir -p $(dirname $library | cut -b2- )
|
|
cd $(dirname $library | cut -b2- )
|
|
rm -f $(basename $library)
|
|
cp -a $library .
|
|
)
|
|
done
|
|
|
|
# Make sure shared libraries are executable:
|
|
chmod 755 $PKG/lib${LIBDIRSUFFIX}/lib*.so.* $PKG/usr/lib${LIBDIRSUFFIX}/lib*.so.*
|
|
|
|
# Don't ship symlinks in aaa_libraries... it's just asking for trouble.
|
|
# installpkg will create them if needed by running ldconfig.
|
|
find $PKG -type l -exec rm --verbose "{}" \+
|
|
|
|
mkdir -p $PKG/install
|
|
cat $CWD/slack-desc > $PKG/install/slack-desc
|
|
|
|
cd $PKG
|
|
/sbin/makepkg -l y -c n $TMP/${PKGNAM}-$VERSION-$ARCH-$BUILD.txz
|