Compare commits

...

No commits in common. 'c9' and 'i8c-beta-stream-2.7' have entirely different histories.

@ -1 +1 @@
1ce15f82eba5184cabe6ac1491cb58262e27adfd SOURCES/Babel-2.9.1.tar.gz
9adbd49864392713c6a3080aeb0a9e6432577277 SOURCES/Babel-2.5.1.tar.gz

2
.gitignore vendored

@ -1 +1 @@
SOURCES/Babel-2.9.1.tar.gz
SOURCES/Babel-2.5.1.tar.gz

@ -0,0 +1,128 @@
diff --git a/babel/localedata.py b/babel/localedata.py
index 4b6d3b6..080b723 100644
--- a/babel/localedata.py
+++ b/babel/localedata.py
@@ -13,6 +13,8 @@
"""
import os
+import re
+import sys
import threading
from collections import MutableMapping
from itertools import chain
@@ -33,6 +35,7 @@ def get_base_dir():
_cache = {}
_cache_lock = threading.RLock()
_dirname = os.path.join(get_base_dir(), 'locale-data')
+_windows_reserved_name_re = re.compile("^(con|prn|aux|nul|com[0-9]|lpt[0-9])$", re.I)
def normalize_locale(name):
@@ -49,6 +52,22 @@ def normalize_locale(name):
return locale_id
+def resolve_locale_filename(name):
+ """
+ Resolve a locale identifier to a `.dat` path on disk.
+ """
+
+ # Clean up any possible relative paths.
+ name = os.path.basename(name)
+
+ # Ensure we're not left with one of the Windows reserved names.
+ if sys.platform == "win32" and _windows_reserved_name_re.match(os.path.splitext(name)[0]):
+ raise ValueError("Name %s is invalid on Windows" % name)
+
+ # Build the path.
+ return os.path.join(_dirname, '%s.dat' % name)
+
+
def exists(name):
"""Check whether locale data is available for the given locale.
@@ -60,7 +79,7 @@ def exists(name):
return False
if name in _cache:
return True
- file_found = os.path.exists(os.path.join(_dirname, '%s.dat' % name))
+ file_found = os.path.exists(resolve_locale_filename(name))
return True if file_found else bool(normalize_locale(name))
@@ -102,6 +121,7 @@ def load(name, merge_inherited=True):
:raise `IOError`: if no locale data file is found for the given locale
identifer, or one of the locales it inherits from
"""
+ name = os.path.basename(name)
_cache_lock.acquire()
try:
data = _cache.get(name)
@@ -119,7 +139,7 @@ def load(name, merge_inherited=True):
else:
parent = '_'.join(parts[:-1])
data = load(parent).copy()
- filename = os.path.join(_dirname, '%s.dat' % name)
+ filename = resolve_locale_filename(name)
with open(filename, 'rb') as fileobj:
if name != 'root' and merge_inherited:
merge(data, pickle.load(fileobj))
diff --git a/tests/test_localedata.py b/tests/test_localedata.py
index 3599b21..173e7a3 100644
--- a/tests/test_localedata.py
+++ b/tests/test_localedata.py
@@ -11,12 +11,18 @@
# individuals. For the exact contribution history, see the revision
# history and logs, available at http://babel.edgewall.org/log/.
+import os
+import pickle
+import sys
+import tempfile
import unittest
import random
from operator import methodcaller
import sys
-from babel import localedata, numbers
+import pytest
+
+from babel import localedata, Locale, UnknownLocaleError, numbers
class MergeResolveTestCase(unittest.TestCase):
@@ -117,3 +123,33 @@ def test_locale_argument_acceptance():
assert normalized_locale == None
locale_exist = localedata.exists(['en_us', None])
assert locale_exist == False
+
+def test_locale_name_cleanup():
+ """
+ Test that locale identifiers are cleaned up to avoid directory traversal.
+ """
+ no_exist_name = os.path.join(tempfile.gettempdir(), "babel%d.dat" % random.randint(1, 99999))
+ with open(no_exist_name, "wb") as f:
+ pickle.dump({}, f)
+
+ try:
+ name = os.path.splitext(os.path.relpath(no_exist_name, localedata._dirname))[0]
+ except ValueError:
+ if sys.platform == "win32":
+ pytest.skip("unable to form relpath")
+ raise
+
+ assert not localedata.exists(name)
+ with pytest.raises(IOError):
+ localedata.load(name)
+ with pytest.raises(UnknownLocaleError):
+ Locale(name)
+
+
+@pytest.mark.skipif(sys.platform != "win32", reason="windows-only test")
+def test_reserved_locale_names():
+ for name in ("con", "aux", "nul", "prn", "com8", "lpt5"):
+ with pytest.raises(ValueError):
+ localedata.load(name)
+ with pytest.raises(ValueError):
+ Locale(name)

@ -0,0 +1,160 @@
From 5dfa1057b809f9bf848916a1001c742cf5229f46 Mon Sep 17 00:00:00 2001
From: Tomas Orsava <torsava@redhat.com>
Date: Mon, 18 Jun 2018 15:14:52 +0200
Subject: [PATCH] Skip tests involving freezegun module which we're not
shipping
---
tests/messages/test_frontend.py | 31 +++++++++++++++----------------
1 file changed, 15 insertions(+), 16 deletions(-)
diff --git a/tests/messages/test_frontend.py b/tests/messages/test_frontend.py
index 20904a3..236dd5c 100644
--- a/tests/messages/test_frontend.py
+++ b/tests/messages/test_frontend.py
@@ -11,7 +11,6 @@
# individuals. For the exact contribution history, see the revision
# history and logs, available at http://babel.edgewall.org/log/.
import shlex
-from freezegun import freeze_time
from datetime import datetime
from distutils.dist import Distribution
from distutils.errors import DistutilsOptionError
@@ -150,7 +149,7 @@ class ExtractMessagesTestCase(unittest.TestCase):
self.cmd.output_file = self._pot_file()
self.assertRaises(DistutilsOptionError, self.cmd.finalize_options)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_extraction_with_default_mapping(self):
self.cmd.copyright_holder = 'FooBar, Inc.'
self.cmd.msgid_bugs_address = 'bugs.address@email.tld'
@@ -208,7 +207,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_extraction_with_mapping_file(self):
self.cmd.copyright_holder = 'FooBar, Inc.'
self.cmd.msgid_bugs_address = 'bugs.address@email.tld'
@@ -261,7 +260,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_extraction_with_mapping_dict(self):
self.dist.message_extractors = {
'project': [
@@ -392,7 +391,7 @@ class InitCatalogTestCase(unittest.TestCase):
self.cmd.output_file = 'dummy'
self.assertRaises(DistutilsOptionError, self.cmd.finalize_options)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_with_output_dir(self):
self.cmd.input_file = 'project/i18n/messages.pot'
self.cmd.locale = 'en_US'
@@ -444,7 +443,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_keeps_catalog_non_fuzzy(self):
self.cmd.input_file = 'project/i18n/messages_non_fuzzy.pot'
self.cmd.locale = 'en_US'
@@ -496,7 +495,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_correct_init_more_than_2_plurals(self):
self.cmd.input_file = 'project/i18n/messages.pot'
self.cmd.locale = 'lv_LV'
@@ -550,7 +549,7 @@ msgstr[2] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_correct_init_singular_plural_forms(self):
self.cmd.input_file = 'project/i18n/messages.pot'
self.cmd.locale = 'ja_JP'
@@ -601,7 +600,7 @@ msgstr[0] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_supports_no_wrap(self):
self.cmd.input_file = 'project/i18n/long_messages.pot'
self.cmd.locale = 'en_US'
@@ -662,7 +661,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_supports_width(self):
self.cmd.input_file = 'project/i18n/long_messages.pot'
self.cmd.locale = 'en_US'
@@ -827,7 +826,7 @@ commands:
def assert_pot_file_exists(self):
assert os.path.isfile(self._pot_file())
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_extract_with_default_mapping(self):
pot_file = self._pot_file()
self.cli.run(sys.argv + ['extract',
@@ -883,7 +882,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_extract_with_mapping_file(self):
pot_file = self._pot_file()
self.cli.run(sys.argv + ['extract',
@@ -934,7 +933,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_extract_with_exact_file(self):
"""Tests that we can call extract with a particular file and only
strings from that file get extracted. (Note the absence of strings from file1.py)
@@ -983,7 +982,7 @@ msgstr[1] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_init_with_output_dir(self):
po_file = self._po_file('en_US')
self.cli.run(sys.argv + ['init',
@@ -1034,7 +1033,7 @@ msgstr[1] ""
def _i18n_dir(self):
return os.path.join(self.datadir, 'project', 'i18n')
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_init_singular_plural_forms(self):
po_file = self._po_file('ja_JP')
self.cli.run(sys.argv + ['init',
@@ -1081,7 +1080,7 @@ msgstr[0] ""
actual_content = f.read()
self.assertEqual(expected_content, actual_content)
- @freeze_time("1994-11-11")
+ @pytest.mark.skip(reason="Not shipping the freezegun module")
def test_init_more_than_2_plural_forms(self):
po_file = self._po_file('lv_LV')
self.cli.run(sys.argv + ['init',
--
2.14.4

@ -0,0 +1,15 @@
diff -up Babel-2.3.4/setup.py.orig Babel-2.3.4/setup.py
--- Babel-2.3.4/setup.py.orig 2016-04-11 11:58:25.000000000 +0200
+++ Babel-2.3.4/setup.py 2016-04-25 13:35:54.458765892 +0200
@@ -59,7 +59,10 @@ setup(
# This version identifier is currently necessary as
# pytz otherwise does not install on pip 1.4 or
# higher.
- 'pytz>=0a',
+ ### But the version confuses setuptools 8 and higher so remove it in the
+ ### system package
+ #'pytz>=0a',
+ 'pytz',
],
cmdclass={'import_cldr': import_cldr},

@ -1,37 +1,63 @@
%global srcname Babel
%global sum Library for internationalizing Python applications
%bcond_without python3
%bcond_with python36_module
# There is some bootstrapping involved when upgrading Python 3
# First of all we need babel (this package) to use sphinx
# And pytest is at this point not yet ready
%bcond_with bootstrap
%global bootstrap 0
Name: babel
Version: 2.9.1
Release: 2%{?dist}
Version: 2.5.1
Release: 10%{?dist}
Summary: Tools for internationalizing Python applications
License: BSD
URL: https://babel.pocoo.org/
Source0: %{pypi_source}
URL: http://babel.pocoo.org/
Source0: https://files.pythonhosted.org/packages/source/B/%{srcname}/%{srcname}-%{version}.tar.gz
Patch0: babel-2.3.4-remove-pytz-version.patch
# Remove dependency on an exotic testing package python-freezegun which we
# don't have capacity to ship in RHEL8
Patch1: Skip-tests-involving-freezegun-module-which-we-re-no.patch
# Fix CVE-2021-20095: relative path traversal allows an attacker to load
# arbitrary locale files on disk and execute arbitrary code
# Resolved upstream: https://github.com/python-babel/babel/pull/782/
# CVE bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1955615
Patch2: CVE-2021-20095.patch
BuildArch: noarch
BuildRequires: python2-devel
BuildRequires: python2-setuptools
BuildRequires: python2-pytz
BuildRequires: python2-pytest
%if %{with python3}
%if %{with python36_module}
BuildRequires: python36-devel
%else
BuildRequires: python3-devel
%endif
BuildRequires: python3-setuptools
%if !%{with bootstrap}
%if !%{bootstrap}
BuildRequires: python3-pytz
BuildRequires: python3-pytest
%endif
# build the documentation
BuildRequires: make
%if !%{with bootstrap}
%if !%{bootstrap}
BuildRequires: python3-sphinx
%endif
Requires: python3-babel
Requires: python3-setuptools
%endif # bootstrap
%endif # python3
Requires: python2-babel
Requires: python2-setuptools
%description
@ -43,7 +69,24 @@ Babel is composed of two major parts:
providing access to various locale display names, localized number
and date formatting, etc.
%package -n python2-babel
Summary: %sum
Requires: python2-setuptools
Requires: python2-pytz
%{?python_provide:%python_provide python2-babel}
%description -n python2-babel
Babel is composed of two major parts:
* tools to build and work with gettext message catalogs
* a Python interface to the CLDR (Common Locale Data Repository),
providing access to various locale display names, localized number
and date formatting, etc.
%if %{with python3}
%package -n python3-babel
Summary: %sum
@ -61,26 +104,30 @@ Babel is composed of two major parts:
providing access to various locale display names, localized number
and date formatting, etc.
%if !%{with bootstrap}
%package doc
Summary: Documentation for Babel
Provides: python-babel-doc = %{version}-%{release}
Provides: python2-babel-doc = %{version}-%{release}
Provides: python3-babel-doc = %{version}-%{release}
%description doc
Documentation for Babel
%endif
%prep
%autosetup -p1 -n %{srcname}-%{version}
%autosetup -n %{srcname}-%{version} -p1
%build
%py2_build
%if %{with python3}
%py3_build
%endif
%if %{with python3}
%if !%{bootstrap}
BUILDDIR="$PWD/built-docs"
rm -rf "$BUILDDIR"
%if !%{with bootstrap}
pushd docs
make \
SPHINXBUILD=sphinx-build-3 \
@ -89,129 +136,80 @@ make \
popd
rm -f "$BUILDDIR/html/.buildinfo"
%endif
%endif
%install
%if %{with python3}
%py3_install
%endif
%py2_install
mv %{buildroot}%{_bindir}/pybabel{,-%{python2_version}}
ln -s pybabel-%{python2_version} %{buildroot}%{_bindir}/pybabel-2
%check
export TZ=UTC
%if !%{with bootstrap}
# tests/messages/test_frontend.py and tests/test_dates require freezegun
%{__python3} -m pytest --ignore tests/messages/test_frontend.py --ignore tests/test_dates.py
export TZ=America/New_York
%{__python2} -m pytest
%if %{with python3}
%if !%{bootstrap}
%{__python3} -m pytest
%endif
%endif
%files
%doc CHANGES AUTHORS
%license LICENSE
%{_bindir}/pybabel
%{_bindir}/pybabel-2
%{_bindir}/pybabel-%{python2_version}
%files -n python2-babel
%{python2_sitelib}/Babel-%{version}-py*.egg-info
%{python2_sitelib}/babel
%if %{with python3}
%files -n python3-babel
%{python3_sitelib}/Babel-%{version}-py*.egg-info/
%{python3_sitelib}/babel/
%{python3_sitelib}/Babel-%{version}-py*.egg-info
%{python3_sitelib}/babel
%if !%{with bootstrap}
%if !%{bootstrap}
%files doc
%doc built-docs/html/*
%endif
%endif # bootstrap
%endif # python3
%changelog
* Mon Aug 09 2021 Mohan Boddu <mboddu@redhat.com> - 2.9.1-2
- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688
* Wed Apr 03 2024 MSVSphere Packaging Team <packager@msvsphere-os.ru> - 2.5.1-10
- Rebuilt for MSVSphere 8.10 beta
* Fri May 21 2021 Charalampos Stratakis <cstratak@redhat.com> - 2.9.1-1
- Update to 2.9.1.
- Fixes CVE-2021-20095
* Wed May 12 2021 Charalampos Stratakis <cstratak@redhat.com> - 2.5.1-10
- Fix CVE-2021-20095
Resolves: rhbz#1955615
* Thu Apr 15 2021 Mohan Boddu <mboddu@redhat.com> - 2.9.0-6
- Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937
* Tue Apr 13 2021 Miro Hrončok <mhroncok@redhat.com> - 2.9.0-5
- Drop build dependency on python-freezegun
- Resolves: rhbz#1947517
* Tue Jan 26 2021 Fedora Release Engineering <releng@fedoraproject.org> - 2.9.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Mon Dec 21 2020 Miro Hrončok <mhroncok@redhat.com> - 2.9.0-3
- Disable Python 2 build entirely
* Tue Nov 24 2020 Miro Hrončok <mhroncok@redhat.com>
- Disable Python 2 build on RHEL 9+
* Mon Nov 16 22:22:25 CET 2020 Felix Schwarz <fschwarz@fedoraproject.org> - 2.9.0-1
- update to 2.9.0
* Mon Jul 27 2020 Fedora Release Engineering <releng@fedoraproject.org> - 2.8.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Sat May 23 2020 Miro Hrončok <mhroncok@redhat.com> - 2.8.0-6
- Rebuilt for Python 3.9
* Fri May 22 2020 Miro Hrončok <mhroncok@redhat.com> - 2.8.0-5
- Bootstrap for Python 3.9
* Fri May 08 2020 Felix Schwarz <fschwarz@fedoraproject.org> - 2.8.0-4
- reenable Python 2 subpackage for Fedora 33+ (rhbz #1737930)
* Tue May 05 2020 Felix Schwarz <fschwarz@fedoraproject.org> - 2.8.0-3
- add patch for compatibility with Python 3.9a6
* Tue Jan 28 2020 Fedora Release Engineering <releng@fedoraproject.org> - 2.8.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Thu Jan 02 2020 Felix Schwarz <fschwarz@fedoraproject.org> - 2.8.0-1
- update to upstream version 2.8.0
* Thu Oct 31 2019 Nils Philippsen <nils@tiptoe.de> - 2.7.0-7
- drop python2-babel only from F33 on as it is needed for trac (for the time
being, #1737930)
* Thu Oct 31 2019 Nils Philippsen <nils@tiptoe.de> - 2.7.0-6
- drop python2-babel from F32 on
* Fri Sep 13 2019 Miro Hrončok <mhroncok@redhat.com> - 2.7.0-5
- Reduce Python 2 build dependencies on Fedora 32
* Fri Aug 16 2019 Miro Hrončok <mhroncok@redhat.com> - 2.7.0-4
- Rebuilt for Python 3.8
* Thu Aug 15 2019 Miro Hrončok <mhroncok@redhat.com> - 2.7.0-3
- Bootstrap for Python 3.8
* Wed Jul 24 2019 Fedora Release Engineering <releng@fedoraproject.org> - 2.7.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Mon May 27 2019 Felix Schwarz <fschwarz@fedoraproject.org> - 2.7.0-1
- update to upstream version 2.7.0
* Thu Jan 31 2019 Fedora Release Engineering <releng@fedoraproject.org> - 2.6.0-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Thu Jul 12 2018 Fedora Release Engineering <releng@fedoraproject.org> - 2.6.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Mon Jul 02 2018 Miro Hrončok <mhroncok@redhat.com> - 2.6.0-4
- Rebuilt for Python 3.7
* Thu Apr 25 2019 Tomas Orsava <torsava@redhat.com> - 2.5.1-9
- Bumping due to problems with modular RPM upgrade path
- Resolves: rhbz#1695587
* Mon Jul 02 2018 Miro Hrončok <mhroncok@redhat.com> - 2.6.0-3
- Rebuilt for Python 3.7
* Tue Oct 02 2018 Lumír Balhar <lbalhar@redhat.com> - 2.5.1-8
- Fix unversioned requires/buildrequires
- Resolves: rhbz#1628242
* Fri Jun 29 2018 Felix Schwarz <fschwarz@fedoraproject.org> - 2.6.0-2
- add setting to build without Python 2 support
* Wed Aug 08 2018 Lumír Balhar <lbalhar@redhat.com> - 2.5.1-7
- Remove unversioned binaries
- Resolves: rhbz#1613343
* Fri Jun 29 2018 Felix Schwarz <fschwarz@fedoraproject.org> - 2.6.0-1
- update to upstream version 2.6.0
* Tue Jul 31 2018 Lumír Balhar <lbalhar@redhat.com> - 2.5.1-6
- Make possible to disable python3 subpackage
* Mon Jun 18 2018 Tomas Orsava <torsava@redhat.com> - 2.5.1-5
- Run tests in pytest (as declared in BuildRequires)
- Remove dependency on an exotic testing package python-freezegun which we
don't have capacity to ship in RHEL8
- Run tests in pytest (as declared in BuildRequires) instead of unittest
* Sat Jun 16 2018 Miro Hrončok <mhroncok@redhat.com> - 2.5.1-4
- Rebuilt for Python 3.7
* Mon Jun 18 2018 Tomas Orsava <torsava@redhat.com> - 2.5.1-4
- Build the documentation always using the Python 3 version Sphinx
* Thu Jun 14 2018 Miro Hrončok <mhroncok@redhat.com> - 2.5.1-3
- Bootstrap for Python 3.7
* Tue May 01 2018 Tomas Orsava <torsava@redhat.com> - 2.5.1-3
- Require the python36-devel package when building for the python36 module
* Wed Feb 07 2018 Fedora Release Engineering <releng@fedoraproject.org> - 2.5.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild

Loading…
Cancel
Save