[oe-commits] [meta-openembedded] 05/37: xarchiver: Fix build with security flags turned on

git at git.openembedded.org git at git.openembedded.org
Thu Apr 6 11:01:21 UTC 2017


This is an automated email from the git hooks/post-receive script.

martin_jansa pushed a commit to branch master-next
in repository meta-openembedded.

commit 2ae91ddd68e1b621873baa319eaa05080719dfd1
Author: Khem Raj <raj.khem at gmail.com>
AuthorDate: Thu Mar 30 11:26:23 2017 -0700

    xarchiver: Fix build with security flags turned on
    
    Signed-off-by: Khem Raj <raj.khem at gmail.com>
---
 ...formatting-string-to-printf-like-function.patch | 40 ++++++++++++++++++++++
 meta-xfce/recipes-apps/xarchiver/xarchiver_git.bb  |  4 ++-
 2 files changed, 43 insertions(+), 1 deletion(-)

diff --git a/meta-xfce/recipes-apps/xarchiver/xarchiver/0001-Add-proper-formatting-string-to-printf-like-function.patch b/meta-xfce/recipes-apps/xarchiver/xarchiver/0001-Add-proper-formatting-string-to-printf-like-function.patch
new file mode 100644
index 0000000..a115883
--- /dev/null
+++ b/meta-xfce/recipes-apps/xarchiver/xarchiver/0001-Add-proper-formatting-string-to-printf-like-function.patch
@@ -0,0 +1,40 @@
+From baf93ea9acf845c5455d577ac19a6f680dac3d2d Mon Sep 17 00:00:00 2001
+From: Khem Raj <raj.khem at gmail.com>
+Date: Thu, 30 Mar 2017 11:22:42 -0700
+Subject: [PATCH] Add proper formatting string to printf-like functions
+
+Avoids potential security holes and makes compiler happy
+
+| ../../../../../../../workspace/sources/xarchiver/src/window.c:236:72: error: format string is not a string literal (potentially insecure) [-Werror,-Wformat-security]
+|         gtk_message_dialog_format_secondary_text (GTK_MESSAGE_DIALOG (dialog),message2);
+
+Signed-off-by: Khem Raj <raj.khem at gmail.com>
+---
+ src/window.c | 6 +++---
+ 1 file changed, 3 insertions(+), 3 deletions(-)
+
+Index: git/src/window.c
+===================================================================
+--- git.orig/src/window.c
++++ git/src/window.c
+@@ -231,9 +231,9 @@ int xa_show_message_dialog (GtkWindow *w
+ {
+ 	int response;
+ 
+-	dialog = gtk_message_dialog_new (window,mode,type,button,message1);
++	dialog = gtk_message_dialog_new (window,mode,type,button,"%s",message1);
+ 	gtk_dialog_set_default_response (GTK_DIALOG (dialog),GTK_RESPONSE_NO);
+-	gtk_message_dialog_format_secondary_text (GTK_MESSAGE_DIALOG (dialog),message2);
++	gtk_message_dialog_format_secondary_text (GTK_MESSAGE_DIALOG (dialog),"%s",message2);
+ 	response = gtk_dialog_run (GTK_DIALOG (dialog));
+ 	gtk_widget_destroy (GTK_WIDGET (dialog));
+ 	return response;
+@@ -511,7 +511,7 @@ void xa_list_archive (GtkMenuItem *menui
+ 			g_fprintf (stream,_("Comment:\n"));
+ 			if (bp)
+ 				g_fprintf(stream,"</b><pre>");
+-			g_fprintf (stream,archive[idx]->comment->str);
++			g_fprintf (stream,"%s",archive[idx]->comment->str);
+ 			if (bp)
+ 				g_fprintf(stream,"</pre>");
+ 			g_fprintf (stream,"\n");
diff --git a/meta-xfce/recipes-apps/xarchiver/xarchiver_git.bb b/meta-xfce/recipes-apps/xarchiver/xarchiver_git.bb
index ca29922..ea34a52 100644
--- a/meta-xfce/recipes-apps/xarchiver/xarchiver_git.bb
+++ b/meta-xfce/recipes-apps/xarchiver/xarchiver_git.bb
@@ -7,7 +7,9 @@ LIC_FILES_CHKSUM = "file://COPYING;md5=94d55d512a9ba36caa9b7df079bae19f"
 
 DEPENDS = "gtk+ glib-2.0 xfce4-dev-tools-native intltool-native"
 
-SRC_URI = "git://github.com/schnitzeltony/xarchiver.git;branch=master"
+SRC_URI = "git://github.com/schnitzeltony/xarchiver.git;branch=master \
+           file://0001-Add-proper-formatting-string-to-printf-like-function.patch \
+           "
 SRCREV = "e80e90528c9aab2fe36d9078b945b44c05cc20d3"
 PV = "0.5.3"
 S = "${WORKDIR}/git"

-- 
To stop receiving notification emails like this one, please contact
the administrator of this repository.


More information about the Openembedded-commits mailing list