Project

General

Profile

Bug #14481 ยป rubygems-276-for-ruby22.patch

hsbt (Hiroshi SHIBATA), 02/16/2018 10:55 AM

View differences:

lib/rubygems.rb
9 9
require 'thread'
10 10

  
11 11
module Gem
12
  VERSION = '2.4.5.4'
12
  VERSION = '2.4.5.5'
13 13
end
14 14

  
15 15
# Must be first since it unloads the prelude from 1.9.2
lib/rubygems/package.rb
408 408
    destination = File.expand_path destination
409 409

  
410 410
    raise Gem::Package::PathError.new(destination, destination_dir) unless
411
      destination.start_with? destination_dir
411
      destination.start_with? destination_dir + '/'
412 412

  
413 413
    destination.untaint
414 414
    destination
......
587 587
      raise Gem::Package::FormatError.new \
588 588
              'package content (data.tar.gz) is missing', @gem
589 589
    end
590

  
591
    if duplicates = @files.group_by {|f| f }.select {|k,v| v.size > 1 }.map(&:first) and duplicates.any?
592
      raise Gem::Security::Exception, "duplicate files in the package: (#{duplicates.map(&:inspect).join(', ')})"
593
    end
590 594
  end
591 595

  
592 596
  ##
lib/rubygems/package/tar_header.rb
103 103
    fields = header.unpack UNPACK_FORMAT
104 104

  
105 105
    new :name     => fields.shift,
106
        :mode     => fields.shift.oct,
107
        :uid      => fields.shift.oct,
108
        :gid      => fields.shift.oct,
109
        :size     => fields.shift.oct,
110
        :mtime    => fields.shift.oct,
111
        :checksum => fields.shift.oct,
106
        :mode     => strict_oct(fields.shift),
107
        :uid      => strict_oct(fields.shift),
108
        :gid      => strict_oct(fields.shift),
109
        :size     => strict_oct(fields.shift),
110
        :mtime    => strict_oct(fields.shift),
111
        :checksum => strict_oct(fields.shift),
112 112
        :typeflag => fields.shift,
113 113
        :linkname => fields.shift,
114 114
        :magic    => fields.shift,
115
        :version  => fields.shift.oct,
115
        :version  => strict_oct(fields.shift),
116 116
        :uname    => fields.shift,
117 117
        :gname    => fields.shift,
118
        :devmajor => fields.shift.oct,
119
        :devminor => fields.shift.oct,
118
        :devmajor => strict_oct(fields.shift),
119
        :devminor => strict_oct(fields.shift),
120 120
        :prefix   => fields.shift,
121 121

  
122 122
        :empty => empty
123 123
  end
124 124

  
125
  def self.strict_oct(str)
126
    return str.oct if str =~ /\A[0-7]*\z/
127
    raise ArgumentError, "#{str.inspect} is not an octal string"
128
  end
129

  
125 130
  ##
126 131
  # Creates a new TarHeader using +vals+
127 132

  
lib/rubygems/package/tar_writer.rb
195 195
      digest_name == signer.digest_name
196 196
    end
197 197

  
198
    raise "no #{signer.digest_name} in #{digests.values.compact}" unless signature_digest
199

  
198 200
    if signer.key then
199 201
      signature = signer.sign signature_digest.digest
200 202

  
lib/rubygems/server.rb
625 625
      executables = nil if executables.empty?
626 626
      executables.last["is_last"] = true if executables
627 627

  
628
      # Pre-process spec homepage for safety reasons
629
      begin
630
        homepage_uri = URI.parse(spec.homepage)
631
        if [URI::HTTP, URI::HTTPS].member? homepage_uri.class
632
          homepage_uri = spec.homepage
633
        else
634
          homepage_uri = "."
635
        end
636
      rescue URI::InvalidURIError
637
        homepage_uri = "."
638
      end
639

  
628 640
      specs << {
629 641
        "authors"             => spec.authors.sort.join(", "),
630 642
        "date"                => spec.date.to_s,
......
634 646
        "only_one_executable" => (executables && executables.size == 1),
635 647
        "full_name"           => spec.full_name,
636 648
        "has_deps"            => !deps.empty?,
637
        "homepage"            => spec.homepage,
649
        "homepage"            => homepage_uri,
638 650
        "name"                => spec.name,
639 651
        "rdoc_installed"      => Gem::RDoc.new(spec).rdoc_installed?,
640 652
        "ri_installed"        => Gem::RDoc.new(spec).ri_installed?,
lib/rubygems/specification.rb
13 13
require 'rubygems/basic_specification'
14 14
require 'rubygems/stub_specification'
15 15
require 'rubygems/util/stringio'
16
require 'uri'
16 17

  
17 18
##
18 19
# The Specification class contains the information for a Gem.  Typically
......
2609 2610
      raise Gem::InvalidSpecificationException, "#{lazy} is not a summary"
2610 2611
    end
2611 2612

  
2612
    if homepage and not homepage.empty? and
2613
       homepage !~ /\A[a-z][a-z\d+.-]*:/i then
2614
      raise Gem::InvalidSpecificationException,
2615
            "\"#{homepage}\" is not a URI"
2613
    # Make sure a homepage is valid HTTP/HTTPS URI
2614
    if homepage and not homepage.empty?
2615
      begin
2616
        homepage_uri = URI.parse(homepage)
2617
        unless [URI::HTTP, URI::HTTPS].member? homepage_uri.class
2618
          raise Gem::InvalidSpecificationException, "\"#{homepage}\" is not a valid HTTP URI"
2619
        end
2620
      rescue URI::InvalidURIError
2621
        raise Gem::InvalidSpecificationException, "\"#{homepage}\" is not a valid HTTP URI"
2622
      end
2616 2623
    end
2617 2624

  
2618 2625
    # Warnings
test/rubygems/test_gem_package.rb
507 507
                 "#{@destination} is not allowed", e.message)
508 508
  end
509 509

  
510
  def test_install_location_suffix
511
    package = Gem::Package.new @gem
512

  
513
    filename = "../#{File.basename(@destination)}suffix.rb"
514

  
515
    e = assert_raises Gem::Package::PathError do
516
      package.install_location filename, @destination
517
    end
518

  
519
    parent = File.expand_path File.join @destination, filename
520

  
521
    assert_equal("installing into parent path #{parent} of " +
522
                 "#{@destination} is not allowed", e.message)
523
  end
524

  
510 525
  def test_load_spec
511 526
    entry = StringIO.new Gem.gzip @spec.to_yaml
512 527
    def entry.full_name() 'metadata.gz' end
......
664 679
    assert_match %r%nonexistent.gem$%,           e.message
665 680
  end
666 681

  
682
  def test_verify_duplicate_file
683
    FileUtils.mkdir_p 'lib'
684
    FileUtils.touch 'lib/code.rb'
685

  
686
    build = Gem::Package.new @gem
687
    build.spec = @spec
688
    build.setup_signer
689
    open @gem, 'wb' do |gem_io|
690
      Gem::Package::TarWriter.new gem_io do |gem|
691
        build.add_metadata gem
692
        build.add_contents gem
693

  
694
        gem.add_file_simple 'a.sig', 0444, 0
695
        gem.add_file_simple 'a.sig', 0444, 0
696
      end
697
    end
698

  
699
    package = Gem::Package.new @gem
700

  
701
    e = assert_raises Gem::Security::Exception do
702
      package.verify
703
    end
704

  
705
    assert_equal 'duplicate files in the package: ("a.sig")', e.message
706
  end
707

  
667 708
  def test_verify_security_policy
668 709
    skip 'openssl is missing' unless defined?(OpenSSL::SSL)
669 710

  
......
721 762

  
722 763
        # write bogus data.tar.gz to foil signature
723 764
        bogus_data = Gem.gzip 'hello'
724
        gem.add_file_simple 'data.tar.gz', 0444, bogus_data.length do |io|
765
        fake_signer = Class.new do
766
          def digest_name; 'SHA512'; end
767
          def digest_algorithm; Digest(:SHA512); end
768
          def key; 'key'; end
769
          def sign(*); 'fake_sig'; end
770
        end
771
        gem.add_file_signed 'data2.tar.gz', 0444, fake_signer.new do |io|
725 772
          io.write bogus_data
726 773
        end
727 774

  
test/rubygems/test_gem_package_tar_header.rb
142 142
    assert_equal '012467', @tar_header.checksum
143 143
  end
144 144

  
145
  def test_from_bad_octal
146
    test_cases = [
147
      "00000006,44\000", # bogus character
148
      "00000006789\000", # non-octal digit
149
      "+0000001234\000", # positive sign
150
      "-0000001000\000", # negative sign
151
      "0x000123abc\000", # radix prefix
152
    ]
153

  
154
    test_cases.each do |val|
155
      header_s = @tar_header.to_s
156
      # overwrite the size field
157
      header_s[124, 12] = val
158
      io = TempIO.new header_s
159
      assert_raises ArgumentError do
160
        new_header = Gem::Package::TarHeader.from io
161
      end
162
      io.close! if io.respond_to? :close!
163
    end
164
  end
165

  
145 166
end
146 167

  
test/rubygems/test_gem_server.rb
331 331
    assert_match 'z 9', @res.body
332 332
  end
333 333

  
334

  
335
  def test_xss_homepage_fix_289313
336
    data = StringIO.new "GET / HTTP/1.0\r\n\r\n"
337
    dir = "#{@gemhome}2"
338

  
339
    spec = util_spec 'xsshomepagegem', 1
340
    spec.homepage = "javascript:confirm(document.domain)"
341

  
342
    specs_dir = File.join dir, 'specifications'
343
    FileUtils.mkdir_p specs_dir
344

  
345
    open File.join(specs_dir, spec.spec_name), 'w' do |io|
346
      io.write spec.to_ruby
347
    end
348

  
349
    server = Gem::Server.new dir, process_based_port, false
350

  
351
    @req.parse data
352

  
353
    server.root @req, @res
354

  
355
    assert_equal 200, @res.status
356
    assert_match 'xsshomepagegem 1', @res.body
357

  
358
    # This verifies that the homepage for this spec is not displayed and is set to ".", because it's not a 
359
    # valid HTTP/HTTPS URL and could be unsafe in an HTML context.  We would prefer to throw an exception here,
360
    # but spec.homepage is currently free form and not currently required to be a URL, this behavior may be 
361
    # validated in future versions of Gem::Specification.
362
    #
363
    # There are two variant we're checking here, one where rdoc is not present, and one where rdoc is present in the same regex:
364
    #
365
    # Variant #1 - rdoc not installed
366
    #
367
    #   <b>xsshomepagegem 1</b>
368
    #
369
    #
370
    #  <span title="rdoc not installed">[rdoc]</span>
371
    #
372
    #
373
    #
374
    #  <a href="." title=".">[www]</a>
375
    #
376
    # Variant #2 - rdoc installed
377
    #
378
    #   <b>xsshomepagegem 1</b>
379
    #
380
    #
381
    #  <a href="\/doc_root\/xsshomepagegem-1\/">\[rdoc\]<\/a>
382
    #
383
    #
384
    #
385
    #  <a href="." title=".">[www]</a>
386
    regex_match = /xsshomepagegem 1<\/b>[\n\s]+(<span title="rdoc not installed">\[rdoc\]<\/span>|<a href="\/doc_root\/xsshomepagegem-1\/">\[rdoc\]<\/a>)[\n\s]+<a href="\." title="\.">\[www\]<\/a>/
387
    assert_match regex_match, @res.body
388
  end
389

  
390
  def test_invalid_homepage
391
    data = StringIO.new "GET / HTTP/1.0\r\n\r\n"
392
    dir = "#{@gemhome}2"
393

  
394
    spec = util_spec 'invalidhomepagegem', 1
395
    spec.homepage = "notavalidhomepageurl"
396

  
397
    specs_dir = File.join dir, 'specifications'
398
    FileUtils.mkdir_p specs_dir
399

  
400
    open File.join(specs_dir, spec.spec_name), 'w' do |io|
401
      io.write spec.to_ruby
402
    end
403

  
404
    server = Gem::Server.new dir, process_based_port, false
405

  
406
    @req.parse data
407

  
408
    server.root @req, @res
409

  
410
    assert_equal 200, @res.status
411
    assert_match 'invalidhomepagegem 1', @res.body
412

  
413
    # This verifies that the homepage for this spec is not displayed and is set to ".", because it's not a 
414
    # valid HTTP/HTTPS URL and could be unsafe in an HTML context.  We would prefer to throw an exception here,
415
    # but spec.homepage is currently free form and not currently required to be a URL, this behavior may be 
416
    # validated in future versions of Gem::Specification.
417
    #
418
    # There are two variant we're checking here, one where rdoc is not present, and one where rdoc is present in the same regex:
419
    #
420
    # Variant #1 - rdoc not installed
421
    #
422
    #   <b>invalidhomepagegem 1</b>
423
    #
424
    #
425
    #  <span title="rdoc not installed">[rdoc]</span>
426
    #
427
    #
428
    #
429
    #  <a href="." title=".">[www]</a>
430
    #
431
    # Variant #2 - rdoc installed
432
    #
433
    #   <b>invalidhomepagegem 1</b>
434
    #
435
    #
436
    #  <a href="\/doc_root\/invalidhomepagegem-1\/">\[rdoc\]<\/a>
437
    #
438
    #
439
    #
440
    #  <a href="." title=".">[www]</a>
441
    regex_match = /invalidhomepagegem 1<\/b>[\n\s]+(<span title="rdoc not installed">\[rdoc\]<\/span>|<a href="\/doc_root\/invalidhomepagegem-1\/">\[rdoc\]<\/a>)[\n\s]+<a href="\." title="\.">\[www\]<\/a>/
442
    assert_match regex_match, @res.body
443
  end
444

  
445
  def test_valid_homepage_http
446
    data = StringIO.new "GET / HTTP/1.0\r\n\r\n"
447
    dir = "#{@gemhome}2"
448

  
449
    spec = util_spec 'validhomepagegemhttp', 1
450
    spec.homepage = "http://rubygems.org"
451

  
452
    specs_dir = File.join dir, 'specifications'
453
    FileUtils.mkdir_p specs_dir
454

  
455
    open File.join(specs_dir, spec.spec_name), 'w' do |io|
456
      io.write spec.to_ruby
457
    end
458

  
459
    server = Gem::Server.new dir, process_based_port, false
460

  
461
    @req.parse data
462

  
463
    server.root @req, @res
464

  
465
    assert_equal 200, @res.status
466
    assert_match 'validhomepagegemhttp 1', @res.body
467

  
468
    regex_match = /validhomepagegemhttp 1<\/b>[\n\s]+(<span title="rdoc not installed">\[rdoc\]<\/span>|<a href="\/doc_root\/validhomepagegemhttp-1\/">\[rdoc\]<\/a>)[\n\s]+<a href="http:\/\/rubygems\.org" title="http:\/\/rubygems\.org">\[www\]<\/a>/
469
    assert_match regex_match, @res.body
470
  end
471

  
472
  def test_valid_homepage_https
473
    data = StringIO.new "GET / HTTP/1.0\r\n\r\n"
474
    dir = "#{@gemhome}2"
475

  
476
    spec = util_spec 'validhomepagegemhttps', 1
477
    spec.homepage = "https://rubygems.org"
478

  
479
    specs_dir = File.join dir, 'specifications'
480
    FileUtils.mkdir_p specs_dir
481

  
482
    open File.join(specs_dir, spec.spec_name), 'w' do |io|
483
      io.write spec.to_ruby
484
    end
485

  
486
    server = Gem::Server.new dir, process_based_port, false
487

  
488
    @req.parse data
489

  
490
    server.root @req, @res
491

  
492
    assert_equal 200, @res.status
493
    assert_match 'validhomepagegemhttps 1', @res.body
494

  
495
    regex_match = /validhomepagegemhttps 1<\/b>[\n\s]+(<span title="rdoc not installed">\[rdoc\]<\/span>|<a href="\/doc_root\/validhomepagegemhttps-1\/">\[rdoc\]<\/a>)[\n\s]+<a href="https:\/\/rubygems\.org" title="https:\/\/rubygems\.org">\[www\]<\/a>/
496
    assert_match regex_match, @res.body
497
  end
498

  
334 499
  def test_specs
335 500
    data = StringIO.new "GET /specs.#{Gem.marshal_version} HTTP/1.0\r\n\r\n"
336 501
    @req.parse data
test/rubygems/test_gem_specification.rb
2584 2584
        @a1.validate
2585 2585
      end
2586 2586

  
2587
      assert_equal '"over at my cool site" is not a URI', e.message
2587
      assert_equal '"over at my cool site" is not a valid HTTP URI', e.message
2588

  
2589
      @a1.homepage = 'ftp://rubygems.org'
2590

  
2591
      e = assert_raises Gem::InvalidSpecificationException do
2592
        @a1.validate
2593
      end
2594

  
2595
      assert_equal '"ftp://rubygems.org" is not a valid HTTP URI', e.message
2596

  
2597
      @a1.homepage = 'http://rubygems.org'
2598
      assert_equal true, @a1.validate
2599

  
2600
      @a1.homepage = 'https://rubygems.org'
2601
      assert_equal true, @a1.validate
2602

  
2588 2603
    end
2589 2604
  end
2590 2605