ruby-changes:47690
From: usa <ko1@a...>
Date: Sun, 10 Sep 2017 10:10:31 +0900 (JST)
Subject: [ruby-changes:47690] usa:r59805 (ruby_2_2): * lib/rubygems: fix several vulnerabilities in RubyGems; bump to version
usa 2017-09-10 10:10:24 +0900 (Sun, 10 Sep 2017) New Revision: 59805 https://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=59805 Log: * lib/rubygems: fix several vulnerabilities in RubyGems; bump to version 2.4.5.3. [Backport #13842] Modified files: branches/ruby_2_2/ChangeLog branches/ruby_2_2/lib/rubygems/commands/query_command.rb branches/ruby_2_2/lib/rubygems/installer.rb branches/ruby_2_2/lib/rubygems/remote_fetcher.rb branches/ruby_2_2/lib/rubygems/specification.rb branches/ruby_2_2/lib/rubygems/text.rb branches/ruby_2_2/lib/rubygems.rb branches/ruby_2_2/test/rubygems/test_gem_commands_query_command.rb branches/ruby_2_2/test/rubygems/test_gem_installer.rb branches/ruby_2_2/test/rubygems/test_gem_remote_fetcher.rb branches/ruby_2_2/test/rubygems/test_gem_specification.rb branches/ruby_2_2/test/rubygems/test_gem_text.rb branches/ruby_2_2/version.h Index: ruby_2_2/version.h =================================================================== --- ruby_2_2/version.h (revision 59804) +++ ruby_2_2/version.h (revision 59805) @@ -1,6 +1,6 @@ https://github.com/ruby/ruby/blob/trunk/ruby_2_2/version.h#L1 #define RUBY_VERSION "2.2.8" #define RUBY_RELEASE_DATE "2017-09-09" -#define RUBY_PATCHLEVEL 472 +#define RUBY_PATCHLEVEL 473 #define RUBY_RELEASE_YEAR 2017 #define RUBY_RELEASE_MONTH 9 Index: ruby_2_2/lib/rubygems/text.rb =================================================================== --- ruby_2_2/lib/rubygems/text.rb (revision 59804) +++ ruby_2_2/lib/rubygems/text.rb (revision 59805) @@ -6,12 +6,25 @@ require 'rubygems' https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/text.rb#L6 module Gem::Text ## + # Remove any non-printable characters and make the text suitable for + # printing. + def clean_text(text) + text.gsub(/[\000-\b\v-\f\016-\037\177]/, ".".freeze) + end + + def truncate_text(text, description, max_length = 100_000) + raise ArgumentError, "max_length must be positive" unless max_length > 0 + return text if text.size <= max_length + "Truncating #{description} to #{max_length.to_s.reverse.gsub(/...(?=.)/,'\&,').reverse} characters:\n" + text[0, max_length] + end + + ## # Wraps +text+ to +wrap+ characters and optionally indents by +indent+ # characters def format_text(text, wrap, indent=0) result = [] - work = text.dup + work = clean_text(text) while work.length > wrap do if work =~ /^(.{0,#{wrap}})[ \n]/ then Index: ruby_2_2/lib/rubygems/installer.rb =================================================================== --- ruby_2_2/lib/rubygems/installer.rb (revision 59804) +++ ruby_2_2/lib/rubygems/installer.rb (revision 59805) @@ -646,6 +646,11 @@ class Gem::Installer https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/installer.rb#L646 unpack or File.writable?(gem_home) end + def verify_spec_name + return if spec.name =~ Gem::Specification::VALID_NAME_PATTERN + raise Gem::InstallError, "#{spec} has an invalid name" + end + ## # Return the text for an application file. @@ -771,6 +776,8 @@ TEXT https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/installer.rb#L776 ensure_loadable_spec + verify_spec_name + if options[:install_as_default] Gem.ensure_default_gem_subdirectories gem_home else Index: ruby_2_2/lib/rubygems/specification.rb =================================================================== --- ruby_2_2/lib/rubygems/specification.rb (revision 59804) +++ ruby_2_2/lib/rubygems/specification.rb (revision 59805) @@ -106,6 +106,8 @@ class Gem::Specification < Gem::BasicSpe https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/specification.rb#L106 private_constant :LOAD_CACHE if defined? private_constant + VALID_NAME_PATTERN = /\A[a-zA-Z0-9\.\-\_]+\z/ # :nodoc: + # :startdoc: ## @@ -2477,9 +2479,15 @@ class Gem::Specification < Gem::BasicSpe https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/specification.rb#L2479 end end - unless String === name then + if !name.is_a?(String) then + raise Gem::InvalidSpecificationException, + "invalid value for attribute name: \"#{name.inspect}\" must be a string" + elsif name !~ /[a-zA-Z]/ then + raise Gem::InvalidSpecificationException, + "invalid value for attribute name: #{name.dump} must include at least one letter" + elsif name !~ VALID_NAME_PATTERN then raise Gem::InvalidSpecificationException, - "invalid value for attribute name: \"#{name.inspect}\"" + "invalid value for attribute name: #{name.dump} can only include letters, numbers, dashes, and underscores" end if raw_require_paths.empty? then Index: ruby_2_2/lib/rubygems/remote_fetcher.rb =================================================================== --- ruby_2_2/lib/rubygems/remote_fetcher.rb (revision 59804) +++ ruby_2_2/lib/rubygems/remote_fetcher.rb (revision 59805) @@ -96,7 +96,7 @@ class Gem::RemoteFetcher https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/remote_fetcher.rb#L96 else target = res.target.to_s.strip - if /\.#{Regexp.quote(host)}\z/ =~ target + if URI("http://" + target).host.end_with?(".#{host}") return URI.parse "#{uri.scheme}://#{target}#{uri.path}" end Index: ruby_2_2/lib/rubygems/commands/query_command.rb =================================================================== --- ruby_2_2/lib/rubygems/commands/query_command.rb (revision 59804) +++ ruby_2_2/lib/rubygems/commands/query_command.rb (revision 59805) @@ -218,7 +218,7 @@ is too hard to use. https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/commands/query_command.rb#L218 end end - output << make_entry(matching_tuples, platforms) + output << clean_text(make_entry(matching_tuples, platforms)) end end @@ -336,7 +336,8 @@ is too hard to use. https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems/commands/query_command.rb#L336 end def spec_summary entry, spec - entry << "\n\n" << format_text(spec.summary, 68, 4) + summary = truncate_text(spec.summary, "the summary for #{spec.full_name}") + entry << "\n\n" << format_text(summary, 68, 4) end end Index: ruby_2_2/lib/rubygems.rb =================================================================== --- ruby_2_2/lib/rubygems.rb (revision 59804) +++ ruby_2_2/lib/rubygems.rb (revision 59805) @@ -9,7 +9,7 @@ require 'rbconfig' https://github.com/ruby/ruby/blob/trunk/ruby_2_2/lib/rubygems.rb#L9 require 'thread' module Gem - VERSION = '2.4.5.2' + VERSION = '2.4.5.3' end # Must be first since it unloads the prelude from 1.9.2 Index: ruby_2_2/test/rubygems/test_gem_specification.rb =================================================================== --- ruby_2_2/test/rubygems/test_gem_specification.rb (revision 59804) +++ ruby_2_2/test/rubygems/test_gem_specification.rb (revision 59805) @@ -2610,7 +2610,37 @@ http://opensource.org/licenses/alphabeti https://github.com/ruby/ruby/blob/trunk/ruby_2_2/test/rubygems/test_gem_specification.rb#L2610 @a1.validate end - assert_equal 'invalid value for attribute name: ":json"', e.message + assert_equal 'invalid value for attribute name: ":json" must be a string', e.message + + @a1.name = [] + e = assert_raises Gem::InvalidSpecificationException do + @a1.validate + end + assert_equal "invalid value for attribute name: \"[]\" must be a string", e.message + + @a1.name = "" + e = assert_raises Gem::InvalidSpecificationException do + @a1.validate + end + assert_equal "invalid value for attribute name: \"\" must include at least one letter", e.message + + @a1.name = "12345" + e = assert_raises Gem::InvalidSpecificationException do + @a1.validate + end + assert_equal "invalid value for attribute name: \"12345\" must include at least one letter", e.message + + @a1.name = "../malicious" + e = assert_raises Gem::InvalidSpecificationException do + @a1.validate + end + assert_equal "invalid value for attribute name: \"../malicious\" can only include letters, numbers, dashes, and underscores", e.message + + @a1.name = "\ba\t" + e = assert_raises Gem::InvalidSpecificationException do + @a1.validate + end + assert_equal "invalid value for attribute name: \"\\ba\\t\" can only include letters, numbers, dashes, and underscores", e.message end def test_validate_non_nil Index: ruby_2_2/test/rubygems/test_gem_installer.rb =================================================================== --- ruby_2_2/test/rubygems/test_gem_installer.rb (revision 59804) +++ ruby_2_2/test/rubygems/test_gem_installer.rb (revision 59805) @@ -1214,6 +1214,38 @@ gem 'other', version https://github.com/ruby/ruby/blob/trunk/ruby_2_2/test/rubygems/test_gem_installer.rb#L1214 end end + def test_pre_install_checks_malicious_name + spec = Gem::Specification.new do |s| + s.platform = Gem::Platform::RUBY + s.name = '../malicious' + s.version = '1' + s.author = 'A User' + s.email = 'example@e...' + s.homepage = 'http://example.com' + s.summary = "this is a summary" + s.description = "This is a test description" + end + + Gem::Specification.reset + + def spec.full_name # so the spec is buildable + "malicious-1" + end + def spec.validate; end + + util_build_gem spec + + gem = File.join(@gemhome, 'cache', spec.file_name) + + use_ui @ui do + @installer = Gem::Installer.new gem + e = assert_raises Gem::InstallError do + @installer.pre_install_checks + end + assert_equal '#<Gem::Specification name=../malicious version=1> has an invalid name', e.message + end + end + def test_shebang util_make_exec @spec, "#!/usr/bin/ruby" Index: ruby_2_2/test/rubygems/test_gem_remote_fetcher.rb =================================================================== --- ruby_2_2/test/rubygems/test_gem_remote_fetcher.rb (revision 59804) +++ ruby_2_2/test/rubygems/test_gem_remote_fetcher.rb (revision 59805) @@ -181,6 +181,21 @@ gems: https://github.com/ruby/ruby/blob/trunk/ruby_2_2/test/rubygems/test_gem_remote_fetcher.rb#L181 dns.verify end + def test_api_endpoint_ignores_trans_domain_values_that_end_with_original_in_path + uri = URI.parse "http://example.com/foo" + target = MiniTest::Mock.new + target.expect :target, "evil.com/a.example.com" + + dns = MiniTest::Mock.new + dns.expect :getresource, target, [String, Object] + + fetch = Gem::RemoteFetcher.new nil, dns + assert_equal URI.parse("http://example.com/foo"), fetch.api_endpoint(uri) + + target.verify + dns.verify + end + def test_api_endpoint_ignores_trans_domain_values uri = URI.parse "http://gems.example.com/foo" target = MiniTest::Mock.new Index: ruby_2_2/test/rubygems/test_gem_commands_query_command.rb =================================================================== --- ruby_2_2/test/rubygems/test_gem_commands_query_command.rb (revision 59804) +++ ruby_2_2/test/rubygems/test_gem_commands_query_command.rb (revision 59805) @@ -159,6 +159,86 @@ pl (1) https://github.com/ruby/ruby/blob/trunk/ruby_2_2/test/rubygems/test_gem_commands_query_command.rb#L159 assert_equal '', @ui.error end + def test_execute_details_cleans_text + spec_fetcher do |fetcher| + fetcher.spec 'a', 2 do |s| + s.summary = 'This is a lot of text. ' * 4 + s.authors = ["Abraham Lincoln \x01", "\x02 Hirohito"] + s.homepage = "http://a.example.com/\x03" + end + + fetcher.legacy_platform + end + + @cmd.handle_options %w[-r -d] + + use_ui @ui do + @cmd.execute + end + + expected = <<-EOF + +*** REMOTE GEMS *** + +a (2) + Authors: Abraham Lincoln ., . Hirohito + Homepage: http://a.example.com/. + + This is a lot of text. This is a lot of text. This is a lot of text. + This is a lot of text. + +pl (1) + Platform: i386-linux + Author: A User + Homepage: http://example.com + + this is a summary + EOF + + assert_equal expected, @ui.output + assert_equal '', @ui.error + end + + def test_execute_details_truncates_summary + spec_fetcher do |fetcher| + fetcher.spec 'a', 2 do |s| + s.summary = 'This is a lot of text. ' * 10_000 + s.authors = ["Abraham Lincoln \x01", "\x02 Hirohito"] + s.homepage = "http://a.example.com/\x03" + end + + fetcher.legacy_platform + end + + @cmd.handle_options %w[-r -d] + + use_ui @ui do + @cmd.execute + end + + expected = <<-EOF + +*** REMOTE GEMS *** + +a (2) + Authors: Abraham Lincoln ., . Hirohito + Homepage: http://a.example.com/. + + Truncating the summary for a-2 to 100,000 characters: +#{" This is a lot of text. This is a lot of text. This is a lot of text.\n" * 1449} This is a lot of te + +pl (1) + Platform: i386-linux + Author: A User + Homepage: http://example.com + + this is a summary + EOF + + assert_equal expected, @ui.output + assert_equal '', @ui.error + end + def test_execute_details_platform spec_fetcher do |fetcher| fetcher.clear Index: ruby_2_2/test/rubygems/test_gem_text.rb =================================================================== --- ruby_2_2/test/rubygems/test_gem_text.rb (revision 59804) +++ ruby_2_2/test/rubygems/test_gem_text.rb (revision 59805) @@ -35,6 +35,10 @@ Without the wrapping, the text might not https://github.com/ruby/ruby/blob/trunk/ruby_2_2/test/rubygems/test_gem_text.rb#L35 assert_equal expected, format_text(text, 78) end + def test_format_removes_nonprintable_characters + assert_equal "text with weird .. stuff .", format_text("text with weird \x1b\x02 stuff \x7f", 40) + end + def test_min3 assert_equal 1, min3(1, 1, 1) assert_equal 1, min3(1, 1, 2) @@ -71,4 +75,11 @@ Without the wrapping, the text might not https://github.com/ruby/ruby/blob/trunk/ruby_2_2/test/rubygems/test_gem_text.rb#L75 assert_equal 7, levenshtein_distance("xxxxxxx", "ZenTest") assert_equal 7, levenshtein_distance("zentest", "xxxxxxx") end + + def test_truncate_text + assert_equal "abc", truncate_text("abc", "desc") + assert_equal "Truncating desc to 2 characters:\nab", truncate_text("abc", "desc", 2) + s = "ab" * 500_001 + assert_equal "Truncating desc to 1,000,000 characters:\n#{s[0, 1_000_000]}", truncate_text(s, "desc", 1_000_000) + end end Index: ruby_2_2/ChangeLog =================================================================== --- ruby_2_2/ChangeLog (revision 59804) +++ ruby_2_2/ChangeLog (revision 59805) @@ -1,3 +1,8 @@ https://github.com/ruby/ruby/blob/trunk/ruby_2_2/ChangeLog#L1 +Sun Sep 10 10:10:05 2017 SHIBATA Hiroshi <hsbt@r...> + + * lib/rubygems: fix several vulnerabilities in RubyGems; bump to version + 2.4.5.3. [Backport #13842] + Sat Sep 9 21:08:24 2017 SHIBATA Hiroshi <hsbt@r...> * ext/psych/yaml: update libyaml to 0.1.7. -- ML: ruby-changes@q... Info: http://www.atdot.net/~ko1/quickml/