From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:58944) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gLv7a-0007CW-9T for guix-patches@gnu.org; Sun, 11 Nov 2018 14:10:11 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gLv7W-0003Wg-3w for guix-patches@gnu.org; Sun, 11 Nov 2018 14:10:10 -0500 Received: from debbugs.gnu.org ([208.118.235.43]:42483) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gLv7U-0003Uj-4d for guix-patches@gnu.org; Sun, 11 Nov 2018 14:10:05 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1gLv7S-0003tq-7g for guix-patches@gnu.org; Sun, 11 Nov 2018 14:10:03 -0500 Subject: [bug#33347] [PATCH 4/4] gnu: teeworlds: Update to 0.7.0 [fixes CVE-2018-18541]. References: <871s7r3095.fsf@gmail.com> In-Reply-To: <871s7r3095.fsf@gmail.com> Resent-Message-ID: From: Alex Vong Date: Mon, 12 Nov 2018 03:09:39 +0800 Message-ID: <87k1lj1le4.fsf@gmail.com> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="==-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+kyle=kyleam.com@gnu.org Sender: "Guix-patches" To: 33347@debbugs.gnu.org Cc: alexvong1995@gmail.com --==-=-= Content-Type: multipart/mixed; boundary="=-=-=" --=-=-= Content-Type: text/x-diff; charset=utf-8 Content-Disposition: inline; filename=0004-gnu-teeworlds-Update-to-0.7.0-fixes-CVE-2018-18541.patch Content-Transfer-Encoding: quoted-printable From=20340a24167fe00a3ea62804bb97760b8ba3b2f6f8 Mon Sep 17 00:00:00 2001 From: Alex Vong Date: Mon, 12 Nov 2018 02:42:25 +0800 Subject: [PATCH 4/4] gnu: teeworlds: Update to 0.7.0 [fixes CVE-2018-18541]. * gnu/packages/games.scm (teeworlds): Update to 0.7.0. [source]: Remove all bundled libraries. [arguments]: Adjust accordingly. [inputs]: Use sdl2 instead of sdl and python-wrapper instead of python-2. Add json-parser, libmd and pnglite. * gnu/packages/patches/teeworlds-use-latest-wavpack.patch: Update it. =2D-- gnu/packages/games.scm | 107 ++++++++++++------ .../teeworlds-use-latest-wavpack.patch | 72 +++++++++--- 2 files changed, 129 insertions(+), 50 deletions(-) diff --git a/gnu/packages/games.scm b/gnu/packages/games.scm index 3679aa09c..8817e4db8 100644 =2D-- a/gnu/packages/games.scm +++ b/gnu/packages/games.scm @@ -35,6 +35,7 @@ ;;; Copyright =C2=A9 2018 Tim Gesthuizen ;;; Copyright =C2=A9 2018 Madalin Ionel-Patrascu ;;; Copyright =C2=A9 2018 Benjamin Slade +;;; Copyright =C2=A9 2018 Alex Vong ;;; ;;; This file is part of GNU Guix. ;;; @@ -4139,31 +4140,41 @@ small robot living in the nano world, repair its ma= ker.") (define-public teeworlds (package (name "teeworlds") =2D (version "0.6.4") + (version "0.7.0") (source (origin (method url-fetch) =2D (uri (string-append "https://github.com/teeworlds/teeworld= s/" =2D "archive/" version "-release.tar.gz")) + (uri (string-append "https://github.com/teeworlds/teeworlds" + "/archive/" version ".tar.gz")) (file-name (string-append name "-" version ".tar.gz")) (sha256 (base32 =2D "1mqhp6xjl75l49050cid36wxyjn1qr0vjx1c709dfg1lkvmgs6l3")) + "1ih79qcfc44biiwyhc51gwvkyab4cy5hya9yc2bq8phf899fpz2q")) (modules '((guix build utils))) =2D (snippet =2D '(begin =2D (for-each delete-file-recursively =2D '("src/engine/external/wavpack/" =2D "src/engine/external/zlib/")) =2D #t)) + (snippet ; remove bundled libraries + '(begin (delete-file-recursively "src/engine/external/") + #t)) (patches (search-patches "teeworlds-use-latest-wavpack.patch")))) (build-system gnu-build-system) (arguments `(#:tests? #f ; no tests included + #:modules ((guix build gnu-build-system) + (guix build utils) + (srfi srfi-26)) #:phases (modify-phases %standard-phases (replace 'configure (lambda* (#:key outputs #:allow-other-keys) + (define (use-latest-json-parser file) + (substitute* file + (("engine/external/json-parser/json\\.h") + "json-parser/json.h") + (("json_parse_ex\\(&JsonSettings, pFileData, aError\\);") + "json_parse_ex(&JsonSettings, + pFileData, + strlen(pFileData), + aError);"))) + ;; Embed path to assets. (substitute* "src/engine/shared/storage.cpp" (("#define DATA_DIR.*") @@ -4173,50 +4184,76 @@ small robot living in the nano world, repair its ma= ker.") "\""))) =20 ;; Bam expects all files to have a recent time stamp. =2D (for-each (lambda (file) =2D (utime file 1 1)) + (for-each (cut utime <> 1 1) (find-files ".")) =20 ;; Do not use bundled libraries. (substitute* "bam.lua" =2D (("if config.zlib.value =3D=3D 1 then") =2D "if true then") =2D (("wavpack =3D .*") =2D "wavpack =3D {} =2Dsettings.link.libs:Add(\"wavpack\")\n")) + (("local json =3D Compile.+$") + "local json =3D nil +settings.link.libs:Add(\"jsonparser\")") + (("local md5 =3D Compile.+$") + "local md5 =3D nil +settings.link.libs:Add(\"md\")") + (("local png =3D Compile.+$") + "local png =3D nil +settings.link.libs:Add(\"pnglite\")") + (("local wavpack =3D Compile.+$") + "local wavpack =3D nil +settings.link.libs:Add(\"wavpack\")") + (("if config\\.zlib\\.value =3D=3D 1") + "settings.cc.flags:Add(\"-DLIBMD_MD5_ALADDIN\") +if config.zlib.value")) + (substitute* "src/engine/shared/network_token.cpp" + (("engine/external/md5/md5\\.h") + "md5.h")) + (substitute* "src/engine/client/graphics_threaded.cpp" + (("engine/external/pnglite/pnglite\\.h") + "pnglite.h")) (substitute* "src/engine/client/sound.cpp" =2D (("#include ") =2D "#include ")) + (("engine/external/wavpack/wavpack\\.h") + "wavpack/wavpack.h")) + (for-each use-latest-json-parser + '("src/game/client/components/countryflags.cpp" + "src/game/client/components/menus_settings.cpp" + "src/game/client/components/skins.cpp" + "src/game/client/localization.cpp" + "src/game/editor/auto_map.h" + "src/game/editor/editor.cpp")) #t)) (replace 'build (lambda _ =2D (zero? (system* "bam" "-a" "-v" "release")))) + (invoke "bam" "-a" "-v" "conf=3Drelease"))) (replace 'install (lambda* (#:key outputs #:allow-other-keys) =2D (let* ((out (assoc-ref outputs "out")) =2D (bin (string-append out "/bin")) =2D (data (string-append out "/share/teeworlds/data"))) =2D (mkdir-p bin) =2D (mkdir-p data) =2D (for-each (lambda (file) =2D (install-file file bin)) =2D '("teeworlds" "teeworlds_srv")) =2D (copy-recursively "data" data) + (let* ((arch ,(system->linux-architecture + (or (%current-target-system) + (%current-system)))) + (build (string-append "build/" arch "/release/")) + (data-built (string-append build "data/")) + (out (assoc-ref outputs "out")) + (bin (string-append out "/bin/")) + (data (string-append out "/share/teeworlds/data/"))) + (for-each (cut install-file <> bin) + (map (cut string-append build <>) + '("teeworlds" "teeworlds_srv"))) + (copy-recursively data-built data) #t)))))) =2D ;; FIXME: teeworlds bundles the sources of "pnglite", a two-file PNG =2D ;; library without a build system. (inputs `(("freetype" ,freetype) ("glu" ,glu) + ("json-parser" ,json-parser) + ("libmd" ,libmd) ("mesa" ,mesa) =2D ("sdl-union" ,(sdl-union (list sdl =2D sdl-mixer =2D sdl-image))) + ("pnglite" ,pnglite) + ("sdl2" ,sdl2) + ("sdl2-image" ,sdl2-image) + ("sdl2-mixer" ,sdl2-mixer) ("wavpack" ,wavpack) ("zlib" ,zlib))) (native-inputs `(("bam" ,bam) =2D ("python" ,python-2) + ("python" ,python-wrapper) ("pkg-config" ,pkg-config))) (home-page "https://www.teeworlds.com") (synopsis "2D retro multiplayer shooter game") diff --git a/gnu/packages/patches/teeworlds-use-latest-wavpack.patch b/gnu/= packages/patches/teeworlds-use-latest-wavpack.patch index e9fd99108..3ad1340d2 100644 =2D-- a/gnu/packages/patches/teeworlds-use-latest-wavpack.patch +++ b/gnu/packages/patches/teeworlds-use-latest-wavpack.patch @@ -1,10 +1,20 @@ =2DDownloaded from https://anonscm.debian.org/cgit/pkg-games/teeworlds.git/= plain/debian/patches/new-wavpack.patch. +Downloaded from https://salsa.debian.org/games-team/teeworlds/raw/master/d= ebian/patches/new-wavpack.patch. =20 =2DThis patch lets us build teeworlds with wavpack 5.1.0. +From: Markus Koschany +Date: Thu, 25 Oct 2018 20:52:27 +0200 +Subject: new-wavpack =20 +Make wavpack compatible with Debian's version. +--- + src/engine/client/sound.cpp | 33 +++++++++++++++------------------ + src/engine/client/sound.h | 4 ---- + 2 files changed, 15 insertions(+), 22 deletions(-) + +diff --git a/src/engine/client/sound.cpp b/src/engine/client/sound.cpp +index 048ec24..80de3c5 100644 --- a/src/engine/client/sound.cpp +++ b/src/engine/client/sound.cpp =2D@@ -328,17 +328,14 @@ void CSound::RateConvert(int SampleID) +@@ -325,10 +325,6 @@ void CSound::RateConvert(int SampleID) pSample->m_NumFrames =3D NumFrames; } =20=20 @@ -12,10 +22,10 @@ This patch lets us build teeworlds with wavpack 5.1.0. -{ - return io_read(ms_File, pBuffer, Size); -} =2D- =2D int CSound::LoadWV(const char *pFilename) +=20 + ISound::CSampleHandle CSound::LoadWV(const char *pFilename) { =2D CSample *pSample; +@@ -336,6 +332,8 @@ ISound::CSampleHandle CSound::LoadWV(const char *pFile= name) int SampleID =3D -1; char aError[100]; WavpackContext *pContext; @@ -24,17 +34,18 @@ This patch lets us build teeworlds with wavpack 5.1.0. =20=20 // don't waste memory on sound when we are stress testing if(g_Config.m_DbgStress) =2D@@ -351,19 +348,23 @@ int CSound::LoadWV(const char *pFilename =2D if(!m_pStorage) =2D return -1; +@@ -349,25 +347,29 @@ ISound::CSampleHandle CSound::LoadWV(const char *pFi= lename) + return CSampleHandle(); =20=20 + lock_wait(m_SoundLock); - ms_File =3D m_pStorage->OpenFile(pFilename, IOFLAG_READ, IStorage::TYPE_= ALL); - if(!ms_File) + File =3D m_pStorage->OpenFile(pFilename, IOFLAG_READ, IStorage::TYPE_ALL= , aWholePath, sizeof(aWholePath)); + if(!File) { dbg_msg("sound/wv", "failed to open file. filename=3D'%s'", pFilename); =2D return -1; + lock_unlock(m_SoundLock); + return CSampleHandle(); } + else + { @@ -43,7 +54,14 @@ This patch lets us build teeworlds with wavpack 5.1.0. =20=20 SampleID =3D AllocID(); if(SampleID < 0) =2D return -1; + { +- io_close(ms_File); +- ms_File =3D 0; ++ io_close(File); ++ File =3D 0; + lock_unlock(m_SoundLock); + return CSampleHandle(); + } pSample =3D &m_aSamples[SampleID]; =20=20 - pContext =3D WavpackOpenFileInput(ReadData, aError); @@ -51,7 +69,29 @@ This patch lets us build teeworlds with wavpack 5.1.0. if (pContext) { int m_aSamples =3D WavpackGetNumSamples(pContext); =2D@@ -419,9 +420,6 @@ int CSound::LoadWV(const char *pFilename +@@ -385,8 +387,8 @@ ISound::CSampleHandle CSound::LoadWV(const char *pFile= name) + if(pSample->m_Channels > 2) + { + dbg_msg("sound/wv", "file is not mono or stereo. filename=3D'%s'", pFi= lename); +- io_close(ms_File); +- ms_File =3D 0; ++ io_close(File); ++ File =3D 0; + lock_unlock(m_SoundLock); + return CSampleHandle(); + } +@@ -401,8 +403,8 @@ ISound::CSampleHandle CSound::LoadWV(const char *pFile= name) + if(BitsPerSample !=3D 16) + { + dbg_msg("sound/wv", "bps is %d, not 16, filname=3D'%s'", BitsPerSample= , pFilename); +- io_close(ms_File); +- ms_File =3D 0; ++ io_close(File); ++ File =3D 0; + lock_unlock(m_SoundLock); + return CSampleHandle(); + } +@@ -429,9 +431,6 @@ ISound::CSampleHandle CSound::LoadWV(const char *pFile= name) dbg_msg("sound/wv", "failed to open %s: %s", pFilename, aError); } =20=20 @@ -61,14 +101,16 @@ This patch lets us build teeworlds with wavpack 5.1.0. if(g_Config.m_Debug) dbg_msg("sound/wv", "loaded %s", pFilename); =20=20 =2D@@ -527,7 +525,5 @@ void CSound::StopAll() =2D lock_unlock(m_SoundLock); +@@ -560,7 +559,5 @@ bool CSound::IsPlaying(CSampleHandle SampleID) + return Ret; } =20=20 -IOHANDLE CSound::ms_File =3D 0; - IEngineSound *CreateEngineSound() { return new CSound; } =20=20 +diff --git a/src/engine/client/sound.h b/src/engine/client/sound.h +index ff357c0..cec2cde 100644 --- a/src/engine/client/sound.h +++ b/src/engine/client/sound.h @@ -21,10 +21,6 @@ public: @@ -81,4 +123,4 @@ This patch lets us build teeworlds with wavpack 5.1.0. - virtual bool IsSoundEnabled() { return m_SoundEnabled !=3D 0; } =20=20 =2D virtual int LoadWV(const char *pFilename); + virtual CSampleHandle LoadWV(const char *pFilename); =2D-=20 2.19.1 --=-=-=-- --==-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHUEARYIAB0WIQQwb8uPLAHCXSnTBVZh71Au9gJS8gUCW+h+cwAKCRBh71Au9gJS 8vuPAQC61zDZU1DCN9gbznDK941IZGv9isiKv1Ik4mWGkE6+zwEAgwfkouzxHBix n7oIl/OXYqCZH9KpJVqPiw+UKrEhrQU= =Xatc -----END PGP SIGNATURE----- --==-=-=--