mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
In Buildroot there are multiple way to apply patches on a package [1]
- Adding `.patch` file in the package directory.
- Define `<pkg>_PATCH` variable with the location of the patch tar.gz.
It used to download Debian patches tarball.
- Implement custom patching logic with `PRE`/`POST` patches hooks.
To make the CycloneDX SBOM generation not dependant on downloading the
packages, the two last options have the downside of not appearing on the
generated SBOM.
The heirloom-mailx package is downloading a tarball from the Debian
mirror with the `<pkg>_PATCH` method [2].
To improve the tracking of the patched vulnerabilities for the
heirloom-mailx package this commit import the patches previously
downloaded with the `_PATCH` variable in the Buildroot tree. This allows
to add the `CVE:` trailer [3] on the patches that fix vulnerabilities to
better track which patch is fixing the vulnerability.
[1] https://buildroot.org/downloads/manual/manual.html#patch-policy
[2] http://snapshot.debian.org/archive/debian/20150815T155609Z/pool/main/h/heirloom-mailx/heirloom-mailx_12.5-5.debian.tar.xz
[3] 1167d0ff3d docs/manual: mention CVE trailer
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
112 lines
2.6 KiB
Diff
112 lines
2.6 KiB
Diff
From 2bae8ecf04ec2ba6bb9f0af5b80485dd0edb427d Mon Sep 17 00:00:00 2001
|
|
From: Florian Weimer <fweimer@redhat.com>
|
|
Date: Mon, 17 Nov 2014 12:48:25 +0100
|
|
Subject: [PATCH] fio.c: Unconditionally require wordexp support
|
|
|
|
Upstream: https://sources.debian.org/patches/heirloom-mailx/12.5-4/0013-fio.c-Unconditionally-require-wordexp-support.patch/
|
|
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
|
|
---
|
|
fio.c | 67 +++++--------------------------------------------------------------
|
|
1 file changed, 5 insertions(+), 62 deletions(-)
|
|
|
|
diff --git a/fio.c b/fio.c
|
|
index 65e8f10..1529236 100644
|
|
--- a/fio.c
|
|
+++ b/fio.c
|
|
@@ -43,12 +43,15 @@ static char sccsid[] = "@(#)fio.c 2.76 (gritter) 9/16/09";
|
|
#endif /* not lint */
|
|
|
|
#include "rcv.h"
|
|
+
|
|
+#ifndef HAVE_WORDEXP
|
|
+#error wordexp support is required
|
|
+#endif
|
|
+
|
|
#include <sys/stat.h>
|
|
#include <sys/file.h>
|
|
#include <sys/wait.h>
|
|
-#ifdef HAVE_WORDEXP
|
|
#include <wordexp.h>
|
|
-#endif /* HAVE_WORDEXP */
|
|
#include <unistd.h>
|
|
|
|
#if defined (USE_NSS)
|
|
@@ -481,7 +484,6 @@ next:
|
|
static char *
|
|
globname(char *name)
|
|
{
|
|
-#ifdef HAVE_WORDEXP
|
|
wordexp_t we;
|
|
char *cp;
|
|
sigset_t nset;
|
|
@@ -527,65 +529,6 @@ globname(char *name)
|
|
}
|
|
wordfree(&we);
|
|
return cp;
|
|
-#else /* !HAVE_WORDEXP */
|
|
- char xname[PATHSIZE];
|
|
- char cmdbuf[PATHSIZE]; /* also used for file names */
|
|
- int pid, l;
|
|
- char *cp, *shell;
|
|
- int pivec[2];
|
|
- extern int wait_status;
|
|
- struct stat sbuf;
|
|
-
|
|
- if (pipe(pivec) < 0) {
|
|
- perror("pipe");
|
|
- return name;
|
|
- }
|
|
- snprintf(cmdbuf, sizeof cmdbuf, "echo %s", name);
|
|
- if ((shell = value("SHELL")) == NULL)
|
|
- shell = SHELL;
|
|
- pid = start_command(shell, 0, -1, pivec[1], "-c", cmdbuf, NULL);
|
|
- if (pid < 0) {
|
|
- close(pivec[0]);
|
|
- close(pivec[1]);
|
|
- return NULL;
|
|
- }
|
|
- close(pivec[1]);
|
|
-again:
|
|
- l = read(pivec[0], xname, sizeof xname);
|
|
- if (l < 0) {
|
|
- if (errno == EINTR)
|
|
- goto again;
|
|
- perror("read");
|
|
- close(pivec[0]);
|
|
- return NULL;
|
|
- }
|
|
- close(pivec[0]);
|
|
- if (wait_child(pid) < 0 && WTERMSIG(wait_status) != SIGPIPE) {
|
|
- fprintf(stderr, catgets(catd, CATSET, 81,
|
|
- "\"%s\": Expansion failed.\n"), name);
|
|
- return NULL;
|
|
- }
|
|
- if (l == 0) {
|
|
- fprintf(stderr, catgets(catd, CATSET, 82,
|
|
- "\"%s\": No match.\n"), name);
|
|
- return NULL;
|
|
- }
|
|
- if (l == sizeof xname) {
|
|
- fprintf(stderr, catgets(catd, CATSET, 83,
|
|
- "\"%s\": Expansion buffer overflow.\n"), name);
|
|
- return NULL;
|
|
- }
|
|
- xname[l] = 0;
|
|
- for (cp = &xname[l-1]; *cp == '\n' && cp > xname; cp--)
|
|
- ;
|
|
- cp[1] = '\0';
|
|
- if (strchr(xname, ' ') && stat(xname, &sbuf) < 0) {
|
|
- fprintf(stderr, catgets(catd, CATSET, 84,
|
|
- "\"%s\": Ambiguous.\n"), name);
|
|
- return NULL;
|
|
- }
|
|
- return savestr(xname);
|
|
-#endif /* !HAVE_WORDEXP */
|
|
}
|
|
|
|
/*
|
|
--
|
|
1.9.3
|
|
|
|
|