From debbugs-submit-bounces@debbugs.gnu.org Wed Apr 01 14:44:34 2020 Received: (at submit) by debbugs.gnu.org; 1 Apr 2020 18:44:34 +0000 Received: from localhost ([127.0.0.1]:38654 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiLq-0003Qn-8a for submit@debbugs.gnu.org; Wed, 01 Apr 2020 14:44:34 -0400 Received: from lists.gnu.org ([209.51.188.17]:46739) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiLm-0003Qb-Jz for submit@debbugs.gnu.org; Wed, 01 Apr 2020 14:44:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:55681) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jJiLl-00018D-LC for guix-patches@gnu.org; Wed, 01 Apr 2020 14:44:30 -0400 X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on eggs.gnu.org X-Spam-Level: X-Spam-Status: No, score=0.0 required=5.0 tests=BAYES_20,UNPARSEABLE_RELAY, URIBL_BLOCKED autolearn=disabled version=3.3.2 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1jJiLh-0005HZ-Rn for guix-patches@gnu.org; Wed, 01 Apr 2020 14:44:29 -0400 Received: from mira.cbaines.net ([212.71.252.8]:33060) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1jJiLh-0005GC-Le for guix-patches@gnu.org; Wed, 01 Apr 2020 14:44:25 -0400 Received: from localhost (unknown [46.237.163.68]) by mira.cbaines.net (Postfix) with ESMTPSA id E81DF27BBE1 for ; Wed, 1 Apr 2020 19:44:22 +0100 (BST) Received: from localhost (localhost [local]) by localhost (OpenSMTPD) with ESMTPA id 78ec23b7 for ; Wed, 1 Apr 2020 18:44:20 +0000 (UTC) User-agent: mu4e 1.2.0; emacs 26.3 From: Christopher Baines To: guix-patches@gnu.org Subject: [PATCH 0/3] Update existing Ruby versions. Date: Wed, 01 Apr 2020 19:44:20 +0100 Message-ID: <877dyz9hbv.fsf@cbaines.net> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 212.71.252.8 X-Spam-Score: 0.3 (/) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -0.7 (/) --=-=-= Content-Type: text/plain Christopher Baines (3): gnu: ruby: Remove ruby-2.3. gnu: ruby-2.4: Update to 2.4.10. gnu: ruby: Replace 2.5.3 with 2.5.8. gnu/local.mk | 1 - .../ruby-rubygems-276-for-ruby24.patch | 605 ------------------ gnu/packages/ruby.scm | 14 +- 3 files changed, 7 insertions(+), 613 deletions(-) delete mode 100644 gnu/packages/patches/ruby-rubygems-276-for-ruby24.patch --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEPonu50WOcg2XVOCyXiijOwuE9XcFAl6E4QRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDNF ODlFRUU3NDU4RTcyMEQ5NzU0RTBCMjVFMjhBMzNCMEI4NEY1NzcACgkQXiijOwuE 9Xcqpg//f0E4uxyyrdyrP3zFCJ4VgPmkGxcX84dw/wbk6PaIhb/1qXVC8nFqjlQw ABR9Tt+YJNsVAkoMIz6TKaBF4PZTA7e8pHvvfsbJ7zIFnO0wUYQdF4OHVMDRjTO+ p+YLXSEVRdbn0eQAWFdzkJ2CfSRJOM0X9my59Gs/PcsO8p2RSXQd3bTcio8yh+ed Y0Tgxq2BYtCBIF4ZPBOuM6GBOoWNx0Qgw995bogZUjtGviKnQs98OlL691uutPvc wK4P7iWoBsF41K9THkbchUefPCi6sotS91/MWyN0C5pMORIQVO+EeHdMZbCNgcUE 3iCoF7aBNTP/FRmCdpqbQ8STNWxZJTo14SevxLeDZOR8y5QP0rDGmOnOsutCu0QT 0+e9J4aqA3zFIlcq9lWB+CajOtDaIoNORc81pghG8wWquQ2mCO6lbfsRPEx2oyuM ydAAlSogS+J4rY6fm5X6VcAN3ZsNhpkjbiHEjuyUEPBkPv/a39/dTz4/UlJTS1y7 ZJLJNV0iFmNtFvVp+dEB7P0l2GPe4l6xKGSosN3xQVlnb9zWnEyJ4dpi25D+VON+ imSBSx8v6XTfvV2vBpoqJCpfqYGsmMgqmaR2LJkcjjqU3NHuQeCgsrB10VzY/pqv +I3n2wbyEvDj3yTioSlz4ZRXO9W9VZtuNZoeWv7DrQ/eksy0fDo= =1DLU -----END PGP SIGNATURE----- --=-=-=-- From debbugs-submit-bounces@debbugs.gnu.org Wed Apr 01 14:56:50 2020 Received: (at 40378) by debbugs.gnu.org; 1 Apr 2020 18:56:50 +0000 Received: from localhost ([127.0.0.1]:38665 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiXh-00044i-Nd for submit@debbugs.gnu.org; Wed, 01 Apr 2020 14:56:50 -0400 Received: from mira.cbaines.net ([212.71.252.8]:34650) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiXf-00044O-S7 for 40378@debbugs.gnu.org; Wed, 01 Apr 2020 14:56:48 -0400 Received: from localhost (unknown [46.237.163.68]) by mira.cbaines.net (Postfix) with ESMTPSA id E46E427BBE1 for <40378@debbugs.gnu.org>; Wed, 1 Apr 2020 19:56:46 +0100 (BST) Received: from localhost (localhost [local]) by localhost (OpenSMTPD) with ESMTPA id 57938596 for <40378@debbugs.gnu.org>; Wed, 1 Apr 2020 18:56:44 +0000 (UTC) From: Christopher Baines To: 40378@debbugs.gnu.org Subject: [PATCH 1/3] gnu: ruby: Remove ruby-2.3. Date: Wed, 1 Apr 2020 19:56:42 +0100 Message-Id: <20200401185644.6506-1-mail@cbaines.net> X-Mailer: git-send-email 2.26.0 In-Reply-To: <877dyz9hbv.fsf@cbaines.net> References: <877dyz9hbv.fsf@cbaines.net> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 40378 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) No packages in Guix depend on Ruby 2.3, and it was declared as end-of-life on 2019-03-31 by the upstream project. * gnu/packages/ruby.scm (ruby-2.3): Remove variable. --- gnu/packages/ruby.scm | 19 ------------------- 1 file changed, 19 deletions(-) diff --git a/gnu/packages/ruby.scm b/gnu/packages/ruby.scm index a31f177349..4964db0042 100644 --- a/gnu/packages/ruby.scm +++ b/gnu/packages/ruby.scm @@ -148,25 +148,6 @@ a focus on simplicity and productivity.") (delete-file-recursively "ext/fiddle/libffi-3.2.1") #t)))))) -(define-public ruby-2.3 - (package - (inherit ruby) - (version "2.3.8") - (source - (origin - (method url-fetch) - (uri (string-append "http://cache.ruby-lang.org/pub/ruby/" - (version-major+minor version) - "/ruby-" version ".tar.xz")) - (sha256 - (base32 - "1zhxbjff08pvbnxvn58krns6q0p6g4977q6ykfn823gxhifn63wi")) - (modules '((guix build utils))) - (snippet `(begin - ;; Remove bundled libffi - (delete-file-recursively "ext/fiddle/libffi-3.2.1") - #t)))))) - (define-public mruby (package (name "mruby") -- 2.26.0 From debbugs-submit-bounces@debbugs.gnu.org Wed Apr 01 14:56:50 2020 Received: (at 40378) by debbugs.gnu.org; 1 Apr 2020 18:56:50 +0000 Received: from localhost ([127.0.0.1]:38667 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiXi-00044l-2s for submit@debbugs.gnu.org; Wed, 01 Apr 2020 14:56:50 -0400 Received: from mira.cbaines.net ([212.71.252.8]:34654) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiXf-00044Q-TL for 40378@debbugs.gnu.org; Wed, 01 Apr 2020 14:56:48 -0400 Received: from localhost (unknown [46.237.163.68]) by mira.cbaines.net (Postfix) with ESMTPSA id 24ACD27BBEA for <40378@debbugs.gnu.org>; Wed, 1 Apr 2020 19:56:47 +0100 (BST) Received: from localhost (localhost [local]) by localhost (OpenSMTPD) with ESMTPA id 29cb9512 for <40378@debbugs.gnu.org>; Wed, 1 Apr 2020 18:56:44 +0000 (UTC) From: Christopher Baines To: 40378@debbugs.gnu.org Subject: [PATCH 3/3] gnu: ruby: Replace 2.5.3 with 2.5.8. Date: Wed, 1 Apr 2020 19:56:44 +0100 Message-Id: <20200401185644.6506-3-mail@cbaines.net> X-Mailer: git-send-email 2.26.0 In-Reply-To: <20200401185644.6506-1-mail@cbaines.net> References: <877dyz9hbv.fsf@cbaines.net> <20200401185644.6506-1-mail@cbaines.net> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 40378 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) * gnu/packages/ruby.scm (ruby/fixed): New variable. (ruby)[replacement]: Set to ruby/fixed. --- gnu/packages/ruby.scm | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/gnu/packages/ruby.scm b/gnu/packages/ruby.scm index 0383c898d7..2468d0a8f2 100644 --- a/gnu/packages/ruby.scm +++ b/gnu/packages/ruby.scm @@ -78,6 +78,7 @@ (package (name "ruby") (version "2.5.3") + (replacement ruby/fixed) (source (origin (method url-fetch) @@ -128,6 +129,25 @@ a focus on simplicity and productivity.") (home-page "https://www.ruby-lang.org") (license license:ruby))) +(define ruby/fixed + (package + (inherit ruby) + (version "2.5.8") + (source + (origin + (method url-fetch) + (uri (string-append "http://cache.ruby-lang.org/pub/ruby/" + (version-major+minor version) + "/ruby-" version ".tar.xz")) + (sha256 + (base32 + "0vad5ah1lrdhxsyqr5iqc8c7r7qczpmm76cz8rsf4crimpzv5483")) + (modules '((guix build utils))) + (snippet `(begin + ;; Remove bundled libffi + (delete-file-recursively "ext/fiddle/libffi-3.2.1") + #t)))))) + (define-public ruby-2.4 (package (inherit ruby) -- 2.26.0 From debbugs-submit-bounces@debbugs.gnu.org Wed Apr 01 14:57:04 2020 Received: (at 40378) by debbugs.gnu.org; 1 Apr 2020 18:57:04 +0000 Received: from localhost ([127.0.0.1]:38669 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiXm-00045B-AY for submit@debbugs.gnu.org; Wed, 01 Apr 2020 14:57:03 -0400 Received: from mira.cbaines.net ([212.71.252.8]:34652) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jJiXf-00044P-RR for 40378@debbugs.gnu.org; Wed, 01 Apr 2020 14:56:51 -0400 Received: from localhost (unknown [46.237.163.68]) by mira.cbaines.net (Postfix) with ESMTPSA id 087D527BBE4 for <40378@debbugs.gnu.org>; Wed, 1 Apr 2020 19:56:47 +0100 (BST) Received: from localhost (localhost [local]) by localhost (OpenSMTPD) with ESMTPA id 5676f68f for <40378@debbugs.gnu.org>; Wed, 1 Apr 2020 18:56:44 +0000 (UTC) From: Christopher Baines To: 40378@debbugs.gnu.org Subject: [PATCH 2/3] gnu: ruby-2.4: Update to 2.4.10. Date: Wed, 1 Apr 2020 19:56:43 +0100 Message-Id: <20200401185644.6506-2-mail@cbaines.net> X-Mailer: git-send-email 2.26.0 In-Reply-To: <20200401185644.6506-1-mail@cbaines.net> References: <877dyz9hbv.fsf@cbaines.net> <20200401185644.6506-1-mail@cbaines.net> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 40378 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) * gnu/packages/ruby.scm (ruby-2.4): Update to 2.4.10. [source]: Remove a now redundant patch * gnu/packages/patches/ruby-rubygems-276-for-ruby24.patch: Delete file. * gnu/local.mk: Remove deleted patch. --- gnu/local.mk | 1 - .../ruby-rubygems-276-for-ruby24.patch | 605 ------------------ gnu/packages/ruby.scm | 5 +- 3 files changed, 2 insertions(+), 609 deletions(-) delete mode 100644 gnu/packages/patches/ruby-rubygems-276-for-ruby24.patch diff --git a/gnu/local.mk b/gnu/local.mk index 19ab32c0f5..9a03966aea 100644 --- a/gnu/local.mk +++ b/gnu/local.mk @@ -1396,7 +1396,6 @@ dist_patch_DATA = \ %D%/packages/patches/rtags-separate-rct.patch \ %D%/packages/patches/racket-store-checksum-override.patch \ %D%/packages/patches/retroarch-disable-online-updater.patch \ - %D%/packages/patches/ruby-rubygems-276-for-ruby24.patch \ %D%/packages/patches/ruby-rack-ignore-failing-test.patch \ %D%/packages/patches/ruby-tzinfo-data-ignore-broken-test.patch\ %D%/packages/patches/runc-CVE-2019-5736.patch \ diff --git a/gnu/packages/patches/ruby-rubygems-276-for-ruby24.patch b/gnu/packages/patches/ruby-rubygems-276-for-ruby24.patch deleted file mode 100644 index 0d0ed6b204..0000000000 --- a/gnu/packages/patches/ruby-rubygems-276-for-ruby24.patch +++ /dev/null @@ -1,605 +0,0 @@ -diff --git lib/rubygems.rb lib/rubygems.rb -index 0685bcb3c6..a5a9202e56 100644 ---- ruby-2.4.3/lib/rubygems.rb -+++ ruby-2.4.3/lib/rubygems.rb -@@ -10,7 +10,7 @@ - require 'thread' - - module Gem -- VERSION = "2.6.14" -+ VERSION = "2.6.14.1" - end - - # Must be first since it unloads the prelude from 1.9.2 -diff --git lib/rubygems/commands/owner_command.rb lib/rubygems/commands/owner_command.rb -index 4b99434e87..2ee7f84462 100644 ---- ruby-2.4.3/lib/rubygems/commands/owner_command.rb -+++ ruby-2.4.3/lib/rubygems/commands/owner_command.rb -@@ -62,7 +62,7 @@ def show_owners name - end - - with_response response do |resp| -- owners = YAML.load resp.body -+ owners = Gem::SafeYAML.load resp.body - - say "Owners for gem: #{name}" - owners.each do |owner| -diff --git lib/rubygems/package.rb lib/rubygems/package.rb -index 77811ed5ec..b5a5fe2a26 100644 ---- ruby-2.4.3/lib/rubygems/package.rb -+++ ruby-2.4.3/lib/rubygems/package.rb -@@ -378,7 +378,7 @@ def extract_tar_gz io, destination_dir, pattern = "*" # :nodoc: - File.dirname destination - end - -- FileUtils.mkdir_p mkdir, mkdir_options -+ mkdir_p_safe mkdir, mkdir_options, destination_dir, entry.full_name - - open destination, 'wb' do |out| - out.write entry.read -@@ -416,20 +416,35 @@ def install_location filename, destination_dir # :nodoc: - raise Gem::Package::PathError.new(filename, destination_dir) if - filename.start_with? '/' - -- destination_dir = File.realpath destination_dir if -- File.respond_to? :realpath -+ destination_dir = realpath destination_dir - destination_dir = File.expand_path destination_dir - - destination = File.join destination_dir, filename - destination = File.expand_path destination - - raise Gem::Package::PathError.new(destination, destination_dir) unless -- destination.start_with? destination_dir -+ destination.start_with? destination_dir + '/' - - destination.untaint - destination - end - -+ def mkdir_p_safe mkdir, mkdir_options, destination_dir, file_name -+ destination_dir = realpath File.expand_path(destination_dir) -+ parts = mkdir.split(File::SEPARATOR) -+ parts.reduce do |path, basename| -+ path = realpath path unless path == "" -+ path = File.expand_path(path + File::SEPARATOR + basename) -+ lstat = File.lstat path rescue nil -+ if !lstat || !lstat.directory? -+ unless path.start_with? destination_dir and (FileUtils.mkdir path, mkdir_options rescue false) -+ raise Gem::Package::PathError.new(file_name, destination_dir) -+ end -+ end -+ path -+ end -+ end -+ - ## - # Loads a Gem::Specification from the TarEntry +entry+ - -@@ -603,6 +618,10 @@ def verify_files gem - raise Gem::Package::FormatError.new \ - 'package content (data.tar.gz) is missing', @gem - end -+ -+ if duplicates = @files.group_by {|f| f }.select {|k,v| v.size > 1 }.map(&:first) and duplicates.any? -+ raise Gem::Security::Exception, "duplicate files in the package: (#{duplicates.map(&:inspect).join(', ')})" -+ end - end - - ## -@@ -616,6 +635,16 @@ def verify_gz entry # :nodoc: - raise Gem::Package::FormatError.new(e.message, entry.full_name) - end - -+ if File.respond_to? :realpath -+ def realpath file -+ File.realpath file -+ end -+ else -+ def realpath file -+ file -+ end -+ end -+ - end - - require 'rubygems/package/digest_io' -diff --git lib/rubygems/package/tar_header.rb lib/rubygems/package/tar_header.rb -index c54bd14d57..d557357114 100644 ---- ruby-2.4.3/lib/rubygems/package/tar_header.rb -+++ ruby-2.4.3/lib/rubygems/package/tar_header.rb -@@ -104,25 +104,30 @@ def self.from(stream) - fields = header.unpack UNPACK_FORMAT - - new :name => fields.shift, -- :mode => fields.shift.oct, -- :uid => fields.shift.oct, -- :gid => fields.shift.oct, -- :size => fields.shift.oct, -- :mtime => fields.shift.oct, -- :checksum => fields.shift.oct, -+ :mode => strict_oct(fields.shift), -+ :uid => strict_oct(fields.shift), -+ :gid => strict_oct(fields.shift), -+ :size => strict_oct(fields.shift), -+ :mtime => strict_oct(fields.shift), -+ :checksum => strict_oct(fields.shift), - :typeflag => fields.shift, - :linkname => fields.shift, - :magic => fields.shift, -- :version => fields.shift.oct, -+ :version => strict_oct(fields.shift), - :uname => fields.shift, - :gname => fields.shift, -- :devmajor => fields.shift.oct, -- :devminor => fields.shift.oct, -+ :devmajor => strict_oct(fields.shift), -+ :devminor => strict_oct(fields.shift), - :prefix => fields.shift, - - :empty => empty - end - -+ def self.strict_oct(str) -+ return str.oct if str =~ /\A[0-7]*\z/ -+ raise ArgumentError, "#{str.inspect} is not an octal string" -+ end -+ - ## - # Creates a new TarHeader using +vals+ - -diff --git lib/rubygems/package/tar_writer.rb lib/rubygems/package/tar_writer.rb -index f68b8d4c5e..390f7851a3 100644 ---- ruby-2.4.3/lib/rubygems/package/tar_writer.rb -+++ ruby-2.4.3/lib/rubygems/package/tar_writer.rb -@@ -196,6 +196,8 @@ def add_file_signed name, mode, signer - digest_name == signer.digest_name - end - -+ raise "no #{signer.digest_name} in #{digests.values.compact}" unless signature_digest -+ - if signer.key then - signature = signer.sign signature_digest.digest - -diff --git lib/rubygems/server.rb lib/rubygems/server.rb -index df4eb566d3..a7b5243ba0 100644 ---- ruby-2.4.3/lib/rubygems/server.rb -+++ ruby-2.4.3/lib/rubygems/server.rb -@@ -631,6 +631,18 @@ def root(req, res) - executables = nil if executables.empty? - executables.last["is_last"] = true if executables - -+ # Pre-process spec homepage for safety reasons -+ begin -+ homepage_uri = URI.parse(spec.homepage) -+ if [URI::HTTP, URI::HTTPS].member? homepage_uri.class -+ homepage_uri = spec.homepage -+ else -+ homepage_uri = "." -+ end -+ rescue URI::InvalidURIError -+ homepage_uri = "." -+ end -+ - specs << { - "authors" => spec.authors.sort.join(", "), - "date" => spec.date.to_s, -@@ -640,7 +652,7 @@ def root(req, res) - "only_one_executable" => (executables && executables.size == 1), - "full_name" => spec.full_name, - "has_deps" => !deps.empty?, -- "homepage" => spec.homepage, -+ "homepage" => homepage_uri, - "name" => spec.name, - "rdoc_installed" => Gem::RDoc.new(spec).rdoc_installed?, - "ri_installed" => Gem::RDoc.new(spec).ri_installed?, -diff --git lib/rubygems/specification.rb lib/rubygems/specification.rb -index 40e3a70d47..0a154b9001 100644 ---- ruby-2.4.3/lib/rubygems/specification.rb -+++ ruby-2.4.3/lib/rubygems/specification.rb -@@ -15,6 +15,7 @@ - require 'rubygems/stub_specification' - require 'rubygems/util/list' - require 'stringio' -+require 'uri' - - ## - # The Specification class contains the information for a Gem. Typically -@@ -2813,10 +2814,16 @@ def validate packaging = true - raise Gem::InvalidSpecificationException, "#{lazy} is not a summary" - end - -- if homepage and not homepage.empty? and -- homepage !~ /\A[a-z][a-z\d+.-]*:/i then -- raise Gem::InvalidSpecificationException, -- "\"#{homepage}\" is not a URI" -+ # Make sure a homepage is valid HTTP/HTTPS URI -+ if homepage and not homepage.empty? -+ begin -+ homepage_uri = URI.parse(homepage) -+ unless [URI::HTTP, URI::HTTPS].member? homepage_uri.class -+ raise Gem::InvalidSpecificationException, "\"#{homepage}\" is not a valid HTTP URI" -+ end -+ rescue URI::InvalidURIError -+ raise Gem::InvalidSpecificationException, "\"#{homepage}\" is not a valid HTTP URI" -+ end - end - - # Warnings -diff --git test/rubygems/test_gem_commands_owner_command.rb test/rubygems/test_gem_commands_owner_command.rb -index 44652c1093..53cac4ce87 100644 ---- ruby-2.4.3/test/rubygems/test_gem_commands_owner_command.rb -+++ ruby-2.4.3/test/rubygems/test_gem_commands_owner_command.rb -@@ -43,6 +43,31 @@ def test_show_owners - assert_match %r{- 4}, @ui.output - end - -+ def test_show_owners_dont_load_objects -+ skip "testing a psych-only API" unless defined?(::Psych::DisallowedClass) -+ -+ response = <xsshomepagegem 1 -+ # -+ # -+ # [rdoc] -+ # -+ # -+ # -+ # [www] -+ # -+ # Variant #2 - rdoc installed -+ # -+ # xsshomepagegem 1 -+ # -+ # -+ # \[rdoc\]<\/a> -+ # -+ # -+ # -+ # [www] -+ regex_match = /xsshomepagegem 1<\/b>[\n\s]+(\[rdoc\]<\/span>|\[rdoc\]<\/a>)[\n\s]+\[www\]<\/a>/ -+ assert_match regex_match, @res.body -+ end -+ -+ def test_invalid_homepage -+ data = StringIO.new "GET / HTTP/1.0\r\n\r\n" -+ dir = "#{@gemhome}2" -+ -+ spec = util_spec 'invalidhomepagegem', 1 -+ spec.homepage = "notavalidhomepageurl" -+ -+ specs_dir = File.join dir, 'specifications' -+ FileUtils.mkdir_p specs_dir -+ -+ open File.join(specs_dir, spec.spec_name), 'w' do |io| -+ io.write spec.to_ruby -+ end -+ -+ server = Gem::Server.new dir, process_based_port, false -+ -+ @req.parse data -+ -+ server.root @req, @res -+ -+ assert_equal 200, @res.status -+ assert_match 'invalidhomepagegem 1', @res.body -+ -+ # This verifies that the homepage for this spec is not displayed and is set to ".", because it's not a -+ # valid HTTP/HTTPS URL and could be unsafe in an HTML context. We would prefer to throw an exception here, -+ # but spec.homepage is currently free form and not currently required to be a URL, this behavior may be -+ # validated in future versions of Gem::Specification. -+ # -+ # There are two variant we're checking here, one where rdoc is not present, and one where rdoc is present in the same regex: -+ # -+ # Variant #1 - rdoc not installed -+ # -+ # invalidhomepagegem 1 -+ # -+ # -+ # [rdoc] -+ # -+ # -+ # -+ # [www] -+ # -+ # Variant #2 - rdoc installed -+ # -+ # invalidhomepagegem 1 -+ # -+ # -+ # \[rdoc\]<\/a> -+ # -+ # -+ # -+ # [www] -+ regex_match = /invalidhomepagegem 1<\/b>[\n\s]+(\[rdoc\]<\/span>|\[rdoc\]<\/a>)[\n\s]+\[www\]<\/a>/ -+ assert_match regex_match, @res.body -+ end -+ -+ def test_valid_homepage_http -+ data = StringIO.new "GET / HTTP/1.0\r\n\r\n" -+ dir = "#{@gemhome}2" -+ -+ spec = util_spec 'validhomepagegemhttp', 1 -+ spec.homepage = "http://rubygems.org" -+ -+ specs_dir = File.join dir, 'specifications' -+ FileUtils.mkdir_p specs_dir -+ -+ open File.join(specs_dir, spec.spec_name), 'w' do |io| -+ io.write spec.to_ruby -+ end -+ -+ server = Gem::Server.new dir, process_based_port, false -+ -+ @req.parse data -+ -+ server.root @req, @res -+ -+ assert_equal 200, @res.status -+ assert_match 'validhomepagegemhttp 1', @res.body -+ -+ regex_match = /validhomepagegemhttp 1<\/b>[\n\s]+(\[rdoc\]<\/span>|\[rdoc\]<\/a>)[\n\s]+\[www\]<\/a>/ -+ assert_match regex_match, @res.body -+ end -+ -+ def test_valid_homepage_https -+ data = StringIO.new "GET / HTTP/1.0\r\n\r\n" -+ dir = "#{@gemhome}2" -+ -+ spec = util_spec 'validhomepagegemhttps', 1 -+ spec.homepage = "https://rubygems.org" -+ -+ specs_dir = File.join dir, 'specifications' -+ FileUtils.mkdir_p specs_dir -+ -+ open File.join(specs_dir, spec.spec_name), 'w' do |io| -+ io.write spec.to_ruby -+ end -+ -+ server = Gem::Server.new dir, process_based_port, false -+ -+ @req.parse data -+ -+ server.root @req, @res -+ -+ assert_equal 200, @res.status -+ assert_match 'validhomepagegemhttps 1', @res.body -+ -+ regex_match = /validhomepagegemhttps 1<\/b>[\n\s]+(\[rdoc\]<\/span>|\[rdoc\]<\/a>)[\n\s]+\[www\]<\/a>/ -+ assert_match regex_match, @res.body -+ end -+ - def test_specs - data = StringIO.new "GET /specs.#{Gem.marshal_version} HTTP/1.0\r\n\r\n" - @req.parse data -diff --git test/rubygems/test_gem_specification.rb test/rubygems/test_gem_specification.rb -index 0fcc11e78f..1c68826fb3 100644 ---- ruby-2.4.3/test/rubygems/test_gem_specification.rb -+++ ruby-2.4.3/test/rubygems/test_gem_specification.rb -@@ -2890,7 +2890,22 @@ def test_validate_homepage - @a1.validate - end - -- assert_equal '"over at my cool site" is not a URI', e.message -+ assert_equal '"over at my cool site" is not a valid HTTP URI', e.message -+ -+ @a1.homepage = 'ftp://rubygems.org' -+ -+ e = assert_raises Gem::InvalidSpecificationException do -+ @a1.validate -+ end -+ -+ assert_equal '"ftp://rubygems.org" is not a valid HTTP URI', e.message -+ -+ @a1.homepage = 'http://rubygems.org' -+ assert_equal true, @a1.validate -+ -+ @a1.homepage = 'https://rubygems.org' -+ assert_equal true, @a1.validate -+ - end - end - diff --git a/gnu/packages/ruby.scm b/gnu/packages/ruby.scm index 4964db0042..0383c898d7 100644 --- a/gnu/packages/ruby.scm +++ b/gnu/packages/ruby.scm @@ -131,7 +131,7 @@ a focus on simplicity and productivity.") (define-public ruby-2.4 (package (inherit ruby) - (version "2.4.3") + (version "2.4.10") (source (origin (method url-fetch) @@ -140,8 +140,7 @@ a focus on simplicity and productivity.") "/ruby-" version ".tar.xz")) (sha256 (base32 - "0l9bv67dgsphk42lmiskhrnh47hbyj6rfg2rcjx22xivpx07srr3")) - (patches (search-patches "ruby-rubygems-276-for-ruby24.patch")) + "1prhqlgik1zmw9lakl6hkriqslspw48pvhxff17h7ns42p8qwrnm")) (modules '((guix build utils))) (snippet `(begin ;; Remove bundled libffi -- 2.26.0 From debbugs-submit-bounces@debbugs.gnu.org Wed May 13 12:44:34 2020 Received: (at 40378-done) by debbugs.gnu.org; 13 May 2020 16:44:34 +0000 Received: from localhost ([127.0.0.1]:59219 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jYuUg-0007qH-Mc for submit@debbugs.gnu.org; Wed, 13 May 2020 12:44:34 -0400 Received: from mira.cbaines.net ([212.71.252.8]:57556) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jYuUb-0007q6-M1 for 40378-done@debbugs.gnu.org; Wed, 13 May 2020 12:44:28 -0400 Received: from localhost (unknown [46.237.173.210]) by mira.cbaines.net (Postfix) with ESMTPSA id B262527BBE1 for <40378-done@debbugs.gnu.org>; Wed, 13 May 2020 17:44:24 +0100 (BST) Received: from localhost (localhost [local]) by localhost (OpenSMTPD) with ESMTPA id 101fc67b for <40378-done@debbugs.gnu.org>; Wed, 13 May 2020 16:44:22 +0000 (UTC) References: <877dyz9hbv.fsf@cbaines.net> User-agent: mu4e 1.2.0; emacs 26.3 From: Christopher Baines To: 40378-done@debbugs.gnu.org Subject: Re: [bug#40378] [PATCH 0/3] Update existing Ruby versions. In-reply-to: <877dyz9hbv.fsf@cbaines.net> Date: Wed, 13 May 2020 17:44:19 +0100 Message-ID: <87r1vnokd8.fsf@cbaines.net> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: 40378-done X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --=-=-= Content-Type: text/plain Christopher Baines writes: > Christopher Baines (3): > gnu: ruby: Remove ruby-2.3. > gnu: ruby-2.4: Update to 2.4.10. > gnu: ruby: Replace 2.5.3 with 2.5.8. > > gnu/local.mk | 1 - > .../ruby-rubygems-276-for-ruby24.patch | 605 ------------------ > gnu/packages/ruby.scm | 14 +- > 3 files changed, 7 insertions(+), 613 deletions(-) > delete mode 100644 gnu/packages/patches/ruby-rubygems-276-for-ruby24.patch I've gone ahead an pushed a changed version of these patches as a09ff632cc02a2e1fee75b175d58636c6fed50a0. Since the core-updates merge meant grafting ruby@2.5 was unnecessary, so I just updated the package. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEPonu50WOcg2XVOCyXiijOwuE9XcFAl68I+RfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDNF ODlFRUU3NDU4RTcyMEQ5NzU0RTBCMjVFMjhBMzNCMEI4NEY1NzcACgkQXiijOwuE 9Xe42hAAi7YXALQxmQTEY3oCxQx8wHCqcdSnZ1u/RMsVeOB2GpOmxE1B7ssDZRU0 7IowK2jv+pk7wc+8v2BbpX+gmQDaGAooxAyk3caiGoHivovs1e280RHcQ59mEER3 NXkaIo8ACy5SgtRYAL6O34W0YaBomGBhe+rAWkzijB+H3dg7r+EK3/vLv0/hCMVb nzE5vw3dLfzfTdhWDFLZRMbsdyo8pw6pqp1CwMlCI+Jc5rDUM5j6qkrFJk/4lsZp v0YZmAg60brSdIc7u8E2VR9zWh+N4oSP4pKGIjIkvqzov5wvviu04wGDEt1gdYxV juk5sfIs19SQqSyt+0j14Mv5pFnLUN/Vxc619qXGNxcli/2rwoayW9p31M1UFjF7 QzgqDN/ZE+WpZEaCK/g7ORCMfcmehk0+kuSRnuwuHaDkuUhQG0X49jaid4MXpRcp vDrQG0jqPLY5yRZxM/tbNrqPpBaBkNZEyEptoN9FG9Oji9/1jUV4w+m+kinGKjRf xFLzQsK/IdQlhF9ZBtVvL8bss/S5U9t5NkBE6FEH43LIrNPbMZlLx40ooctdw15k vccrtU3REOip+t88No4NQYYZ17S1w5gspTKjQQPTvRIJ/GliS7StRCHWKvDmiZbE HYmSjoGwcVKzpqW/e5/YiXcMAekKtfWHL2hodHAqUxHoVL88LPY= =TdkZ -----END PGP SIGNATURE----- --=-=-=-- From unknown Sat Jun 21 10:44:02 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Thu, 11 Jun 2020 11:24:08 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator