From 59510d7b201c909ec4cef3508bf80ba461f4967e Mon Sep 17 00:00:00 2001 From: CoprDistGit Date: Sat, 10 Oct 2026 04:31:42 +0000 Subject: automatic import of poco --- 0004-Fix-SEGV-in-MultipartReader.patch | 37 ---------------------- backport-CVE-2025-6375.patch | 31 ++++++++++++++++++ poco-deal-with-libsuffix.patch | 12 +++++++ poco.spec | 58 ++++++++++++++++++---------------- 4 files changed, 73 insertions(+), 65 deletions(-) delete mode 100644 0004-Fix-SEGV-in-MultipartReader.patch create mode 100644 backport-CVE-2025-6375.patch create mode 100644 poco-deal-with-libsuffix.patch diff --git a/0004-Fix-SEGV-in-MultipartReader.patch b/0004-Fix-SEGV-in-MultipartReader.patch deleted file mode 100644 index b91549f..0000000 --- a/0004-Fix-SEGV-in-MultipartReader.patch +++ /dev/null @@ -1,37 +0,0 @@ -From 6f2f85913c191ab9ddfb8fae781f5d66afccf3bf Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?G=C3=BCnter=20Obiltschnig?= -Date: Wed, 16 Apr 2025 09:15:33 +0200 -Subject: [PATCH] fix(Net): A SEGV at Net/src/MultipartReader.cpp:164:1 #4915 - (move assertion out of ctor) - - -Backport of upstream commit 6f2f85913c191ab9ddfb8fae781f5d66afccf3bf -(included in pocoproject/poco release 1.14.2). -Fixes CVE-2025-6375: null pointer dereference in MultipartInputStream -(Net/src/MultipartReader.cpp). - ---- - Net/src/MultipartReader.cpp | 3 +-- - 1 file changed, 1 insertion(+), 2 deletions(-) - -diff --git a/Net/src/MultipartReader.cpp b/Net/src/MultipartReader.cpp -index f3a2f2bba2..f4aa27dd86 100644 ---- a/Net/src/MultipartReader.cpp -+++ b/Net/src/MultipartReader.cpp -@@ -36,7 +36,6 @@ MultipartStreamBuf::MultipartStreamBuf(std::istream& istr, const std::string& bo - _boundary(boundary), - _lastPart(false) - { -- poco_assert (!boundary.empty() && boundary.length() < STREAM_BUFFER_SIZE - 6); - } - - -@@ -47,7 +46,7 @@ MultipartStreamBuf::~MultipartStreamBuf() - - int MultipartStreamBuf::readFromDevice(char* buffer, std::streamsize length) - { -- poco_assert_dbg (length >= _boundary.length() + 6); -+ poco_assert (!_boundary.empty() && _boundary.length() < length - 6); - - static const int eof = std::char_traits::eof(); - std::streambuf& buf = *_istr.rdbuf(); diff --git a/backport-CVE-2025-6375.patch b/backport-CVE-2025-6375.patch new file mode 100644 index 0000000..412f2de --- /dev/null +++ b/backport-CVE-2025-6375.patch @@ -0,0 +1,31 @@ +From 6f2f85913c191ab9ddfb8fae781f5d66afccf3bf Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?G=C3=BCnter=20Obiltschnig?= +Date: Wed, 16 Apr 2025 09:15:33 +0200 +Subject: [PATCH] fix(Net): A SEGV at Net/src/MultipartReader.cpp:164:1 #4915 + (move assertion out of ctor) + +--- + Net/src/MultipartReader.cpp | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/Net/src/MultipartReader.cpp b/Net/src/MultipartReader.cpp +index f3a2f2bba2..f4aa27dd86 100644 +--- a/Net/src/MultipartReader.cpp ++++ b/Net/src/MultipartReader.cpp +@@ -36,7 +36,6 @@ MultipartStreamBuf::MultipartStreamBuf(std::istream& istr, const std::string& bo + _boundary(boundary), + _lastPart(false) + { +- poco_assert (!boundary.empty() && boundary.length() < STREAM_BUFFER_SIZE - 6); + } + + +@@ -47,7 +46,7 @@ MultipartStreamBuf::~MultipartStreamBuf() + + int MultipartStreamBuf::readFromDevice(char* buffer, std::streamsize length) + { +- poco_assert_dbg (length >= _boundary.length() + 6); ++ poco_assert (!_boundary.empty() && _boundary.length() < length - 6); + + static const int eof = std::char_traits::eof(); + std::streambuf& buf = *_istr.rdbuf(); diff --git a/poco-deal-with-libsuffix.patch b/poco-deal-with-libsuffix.patch new file mode 100644 index 0000000..9adeaa2 --- /dev/null +++ b/poco-deal-with-libsuffix.patch @@ -0,0 +1,12 @@ +--- poco-poco-1.12.5p2-release/CMakeLists.txt.orig 2025-08-23 10:35:09.617111500 +0800 ++++ poco-poco-1.12.5p2-release/CMakeLists.txt 2025-08-23 10:38:06.806080300 +0800 +@@ -52,6 +52,9 @@ + + # Enable standard installation directories + include(GNUInstallDirs) ++if("${LIB_SUFFIX}" STREQUAL "" AND NOT ${CMAKE_INSTALL_LIBDIR} STREQUAL "lib") ++ STRING(REPLACE "lib" "" LIB_SUFFIX ${CMAKE_INSTALL_LIBDIR}) ++endif("${LIB_SUFFIX}" STREQUAL "" AND NOT ${CMAKE_INSTALL_LIBDIR} STREQUAL "lib") + + # Include some common macros to simpilfy the Poco CMake files + include(PocoMacros) diff --git a/poco.spec b/poco.spec index f2eda98..9ca3021 100644 --- a/poco.spec +++ b/poco.spec @@ -17,13 +17,9 @@ %bcond_without mongodb %endif -%ifarch aarch64 ppc64le s390x x86_64 -%global poco_lib_suffix 64 -%endif - Name: poco Version: 1.12.5p2 -Release: 3 +Release: 4 Summary: C++ class libraries for network-centric applications License: BSL-1.0 @@ -37,10 +33,12 @@ Patch: 0001-Fix-XML-compilation-due-to-new-methods-being-guarded.patc Patch: 0002-Disable-tests-that-fail-in-koji.patch # Backport upstream b33e02d2: use 96-bit IV in testEncryptDecryptGCM so it passes under OpenSSL 3 Patch: 0003-Test-Use-12-byte-IV-for-aes-256-gcm.patch -# Backport upstream 6f2f859: move the assertion out of the MultipartStreamBuf ctor (CVE-2025-6375) -Patch: 0004-Fix-SEGV-in-MultipartReader.patch +# Deal with upcoming LIB_SUFFIX removal +Patch: poco-deal-with-libsuffix.patch #add by uos Patch100: 100-poco-uos-add-sw_64-support.patch +Patch101: backport-CVE-2025-6375.patch + #end BuildRequires: make @@ -141,28 +139,33 @@ rm -v XML/src/xmltok_ns.c %if %{without mongodb} %global poco_mongodb -DENABLE_MONGODB=OFF %endif -%cmake -DPOCO_UNBUNDLED=ON %{?poco_tests} %{?poco_mongodb} -DENABLE_REDIS=OFF -DODBC_INCLUDE_DIR=%{_includedir}/libiodbc -DLIB_SUFFIX=%{?poco_lib_suffix} -B %{cmake_build_dir} -cmake --build %{cmake_build_dir} --parallel %{_smp_build_ncpus} -%cmake -DPOCO_UNBUNDLED=ON %{?poco_tests} %{?poco_mongodb} -DENABLE_REDIS=OFF -DODBC_INCLUDE_DIR=%{_includedir}/libiodbc -DLIB_SUFFIX=%{?poco_lib_suffix} -DCMAKE_BUILD_TYPE=Debug -B %{cmake_debug_dir} -cmake --build %{cmake_debug_dir} --parallel %{_smp_build_ncpus} +%define _vpath_builddir %{cmake_build_dir} +%cmake -DCMAKE_INSTALL_LIBDIR=%{_lib} -DPOCO_UNBUNDLED=ON %{?poco_tests} %{?poco_mongodb} -DENABLE_REDIS=OFF -DODBC_INCLUDE_DIR=%{_includedir}/libiodbc +%cmake_build + +%define _vpath_builddir %{cmake_debug_dir} +%cmake -DCMAKE_INSTALL_LIBDIR=%{_lib} -DPOCO_UNBUNDLED=ON %{?poco_tests} %{?poco_mongodb} -DENABLE_REDIS=OFF -DODBC_INCLUDE_DIR=%{_includedir}/libiodbc -DCMAKE_BUILD_TYPE=Debug +%cmake_build %install -DESTDIR=%{buildroot} cmake --install %{cmake_debug_dir} -DESTDIR=%{buildroot} cmake --install %{cmake_build_dir} +%define _vpath_builddir %{cmake_build_dir} +%cmake_install + +%define _vpath_builddir %{cmake_debug_dir} +%cmake_install # conflict with arc rm -v %{buildroot}%{_bindir}/arc %check %if %{with tests} export POCO_BASE="$(pwd)" -pushd %{cmake_build_dir} +%define _vpath_builddir %{cmake_build_dir} %ifarch s390x # NetSSL test timed out on s390x -ctest -V %{?_smp_mflags} -E "MongoDB|Redis|DataMySQL|DataODBC|NetSSL" +%ctest -V %{?_smp_mflags} -E "MongoDB|Redis|DataMySQL|DataODBC|NetSSL" %else -ctest -V %{?_smp_mflags} -E "MongoDB|Redis|DataMySQL|DataODBC" +%ctest -V %{?_smp_mflags} -E "MongoDB|Redis|DataMySQL|DataODBC" %endif -popd %endif # ----------------------------------------------------------------------------- @@ -478,22 +481,21 @@ HTML format. %doc README NEWS LICENSE CONTRIBUTORS CHANGELOG doc/* %changelog -* Fri Oct 09 2026 kuyan_kubuds - 1.12.5p2-3 -- Fix CVE-2025-6375: backport upstream commit 6f2f85913c191ab9ddfb8fae781f5d66afccf3bf, - which moves an assertion out of the MultipartStreamBuf constructor to avoid - a null pointer dereference in Net/src/MultipartReader.cpp +* Fri Oct 09 2026 kuyan_kubuds - 1.12.5p2-4 +- Fix CVE-2025-6375 -* Fri Sep 11 2026 yanzhicong - 1.12.5p2-2 -- Fix CVE-2023-52389 by upgrading to 1.12.5p2 -- Use generator-independent CMake build and install commands -- Install libraries in the architecture-specific libdir +* Thu Aug 27 2026 kuyan_kubuds - 1.12.5p2-3 +- Upgrade to 1.12.5p2 to fix the version regression of openEuler-26.09 compared with openEuler-24.03-LTS-SP4 -* Mon Apr 27 2026 shiptux - 1.12.5p2-2 +* Thu Aug 13 2026 kuyan_kubuds - 1.12.4-5 - Backport upstream b33e02d2 (issue #4347): use 96-bit IV in testEncryptDecryptGCM so it passes under OpenSSL 3 -* Tue Feb 3 2026 wangkun - 1.12.5p2-1 -- upgrade to 1.12.5p2 +* Sun Oct 12 2025 Funda Wang - 1.12.4-4 +- fix build with ningja + +* Sat Aug 23 2025 Funda Wang - 1.12.4-3 +- deal with upcoming LIB_SUFFIX removal * Thu Feb 27 2025 zhangshaoning - 1.12.4-2 - Add sw_64 support -- cgit v1.2.3