已合并
update to version 1.6.55 #90
Funda Wang创建于 2月14日
update to version 1.6.55 #90
已合并
从已删除 :master合入到src-openeuler/libpngmaster
共 5 个文件变更+23-123
| @@ -1,56 +0,0 @@ | |||
| 1 | -From 01d03b8453eb30ade759cd45c707e5a1c7277d88 Mon Sep 17 00:00:00 2001 | ||
| 2 | -From: Cosmin Truta <ctruta@gmail.com> | ||
| 3 | -Date: Fri, 6 Feb 2026 19:11:54 +0200 | ||
| 4 | -Subject: [PATCH] Fix a heap buffer overflow in `png_set_quantize` | ||
| 5 | - | ||
| 6 | -The color distance hash table stored the current palette indices, but | ||
| 7 | -the color-pruning loop assumed the original indices. When colors were | ||
| 8 | -eliminated and indices changed, the stored indices became stale. This | ||
| 9 | -caused the loop bound `max_d` to grow past the 769-element hash array. | ||
| 10 | - | ||
| 11 | -The fix consists in storing the original indices via `palette_to_index` | ||
| 12 | -to match the pruning loop's expectations. | ||
| 13 | - | ||
| 14 | -Reported-by: Joshua Inscoe <pwnalone@users.noreply.github.com> | ||
| 15 | -Co-authored-by: Joshua Inscoe <pwnalone@users.noreply.github.com> | ||
| 16 | -Signed-off-by: Cosmin Truta <ctruta@gmail.com> | ||
| 17 | ---- | ||
| 18 | - AUTHORS | 1 + | ||
| 19 | - pngrtran.c | 6 +++--- | ||
| 20 | - 2 files changed, 4 insertions(+), 3 deletions(-) | ||
| 21 | - | ||
| 22 | -diff --git a/AUTHORS b/AUTHORS | ||
| 23 | -index b9c0fffcfd..4094f4a57d 100644 | ||
| 24 | ---- a/AUTHORS | ||
| 25 | -+++ b/AUTHORS | ||
| 26 | - Authors, for copyright and licensing purposes. | ||
| 27 | - * Guy Eric Schalnat | ||
| 28 | - * James Yu | ||
| 29 | - * John Bowler | ||
| 30 | -+ * Joshua Inscoe | ||
| 31 | - * Kevin Bracey | ||
| 32 | - * Lucas Chollet | ||
| 33 | - * Magnus Holmgren | ||
| 34 | -diff --git a/pngrtran.c b/pngrtran.c | ||
| 35 | -index fe8f9d32c9..1fce9af121 100644 | ||
| 36 | ---- a/pngrtran.c | ||
| 37 | -+++ b/pngrtran.c | ||
| 38 | - | ||
| 39 | - /* pngrtran.c - transforms the data in a row for PNG readers | ||
| 40 | - * | ||
| 41 | -- * Copyright (c) 2018-2025 Cosmin Truta | ||
| 42 | -+ * Copyright (c) 2018-2026 Cosmin Truta | ||
| 43 | - * Copyright (c) 1998-2002,2004,2006-2018 Glenn Randers-Pehrson | ||
| 44 | - * Copyright (c) 1996-1997 Andreas Dilger | ||
| 45 | - * Copyright (c) 1995-1996 Guy Eric Schalnat, Group 42, Inc. | ||
| 46 | - png_set_quantize(png_structrp png_ptr, png_colorp palette, | ||
| 47 | - break; | ||
| 48 | - | ||
| 49 | - t->next = hash[d]; | ||
| 50 | -- t->left = (png_byte)i; | ||
| 51 | -- t->right = (png_byte)j; | ||
| 52 | -+ t->left = png_ptr->palette_to_index[i]; | ||
| 53 | -+ t->right = png_ptr->palette_to_index[j]; | ||
| 54 | - hash[d] = t; | ||
| 55 | - } | ||
| 56 | - } | ||
| @@ -1,3 +1,3 @@ | |||
| 1 | version https://git-lfs.github.com/spec/v1 | 1 | version https://git-lfs.github.com/spec/v1 |
| 2 | -oid sha256:5638fc4500eaf48457b4d7c9e553fd82ab01d77304a70077d83368429d44f1b4 | 2 | +oid sha256:017c06f75ffed25f6cda9b5369ec6da0ac35a6616adf7abe4222516a0237f37a |
| 3 | -size 10604 | 3 | +size 10489 |
| @@ -1,3 +1,3 @@ | |||
| 1 | version https://git-lfs.github.com/spec/v1 | 1 | version https://git-lfs.github.com/spec/v1 |
| 2 | -oid sha256:01c9d8a303c941ec2c511c14312a3b1d36cedb41e2f5168ccdaa85d53b887805 | 2 | +oid sha256:d925722864837ad5ae2a82070d4b2e0603dc72af44bd457c3962298258b8e82d |
| 3 | -size 1064472 | 3 | +size 1064676 |
| @@ -1,52 +0,0 @@ | |||
| 1 | -From 70001f178343e82b3b4ae0872a1accd4a06d474d Mon Sep 17 00:00:00 2001 | ||
| 2 | -From: zhangxingrong <zhangxingrong@uniontech.com> | ||
| 3 | -Date: Tue, 21 May 2024 17:33:27 +0800 | ||
| 4 | -Subject: [PATCH] libpng fix arm neon | ||
| 5 | - | ||
| 6 | ---- | ||
| 7 | - configure.ac | 4 ++++ | ||
| 8 | - pngpriv.h | 2 +- | ||
| 9 | - 2 files changed, 5 insertions(+), 1 deletion(-) | ||
| 10 | - | ||
| 11 | -diff --git a/configure.ac b/configure.ac | ||
| 12 | -index 505d72f..4466b1c 100644 | ||
| 13 | ---- a/configure.ac | ||
| 14 | -+++ b/configure.ac | ||
| 15 | - AC_ARG_ENABLE([arm-neon], | ||
| 16 | - [case "$enableval" in | ||
| 17 | - no|off) | ||
| 18 | - # disable the default enabling on __ARM_NEON__ systems: | ||
| 19 | -+ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) | ||
| 20 | - AC_DEFINE([PNG_ARM_NEON_OPT], [0], | ||
| 21 | - [Disable ARM Neon optimizations]) | ||
| 22 | - # Prevent inclusion of the assembler files below: | ||
| 23 | - enable_arm_neon=no ;; | ||
| 24 | - check) | ||
| 25 | -+ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) | ||
| 26 | - AC_DEFINE([PNG_ARM_NEON_CHECK_SUPPORTED], [], | ||
| 27 | - [Check for ARM Neon support at run-time]);; | ||
| 28 | - api) | ||
| 29 | -+ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) | ||
| 30 | - AC_DEFINE([PNG_ARM_NEON_API_SUPPORTED], [], | ||
| 31 | - [Turn on ARM Neon optimizations at run-time]);; | ||
| 32 | - yes|on) | ||
| 33 | -+ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) | ||
| 34 | - AC_DEFINE([PNG_ARM_NEON_OPT], [2], | ||
| 35 | - [Enable ARM Neon optimizations]) | ||
| 36 | - AC_MSG_WARN([--enable-arm-neon: please specify 'check' or 'api';] | ||
| 37 | -diff --git a/pngpriv.h b/pngpriv.h | ||
| 38 | -index 9bfdb71..60aae9b 100644 | ||
| 39 | ---- a/pngpriv.h | ||
| 40 | -+++ b/pngpriv.h | ||
| 41 | - | ||
| 42 | - * associated assembler code, pass --enable-arm-neon=no to configure | ||
| 43 | - * or put -DPNG_ARM_NEON_OPT=0 in CPPFLAGS. | ||
| 44 | - */ | ||
| 45 | --# if (defined(__ARM_NEON__) || defined(__ARM_NEON)) && \ | ||
| 46 | -+# if defined(PNG_ARM_NEON) && (defined(__ARM_NEON__) || defined(__ARM_NEON)) && \ | ||
| 47 | - defined(PNG_ALIGNED_MEMORY_SUPPORTED) | ||
| 48 | - # define PNG_ARM_NEON_OPT 2 | ||
| 49 | - # else | ||
| 50 | --- | ||
| 51 | -2.43.0 | ||
| 52 | - | ||
| @@ -1,7 +1,7 @@ | |||
| 1 | Name: libpng | 1 | Name: libpng |
| 2 | Epoch: 2 | 2 | Epoch: 2 |
| 3 | -Version: 1.6.54 | 3 | +Version: 1.6.55 |
| 4 | -Release: 2 | 4 | +Release: 1 |
| 5 | Summary: A library of functions for manipulating PNG image format files | 5 | Summary: A library of functions for manipulating PNG image format files |
| 6 | License: zlib | 6 | License: zlib |
| 7 | URL: https://www.libpng.org/pub/png/libpng.html | 7 | URL: https://www.libpng.org/pub/png/libpng.html |
| @@ -10,10 +10,9 @@ Source1: pngusr.dfa | |||
| 10 | Source2: https://downloads.sourceforge.net/libpng-apng/libpng-%{version}-apng.patch.gz | 10 | Source2: https://downloads.sourceforge.net/libpng-apng/libpng-%{version}-apng.patch.gz |
| 11 | 11 | ||
| 12 | Patch0: libpng-multilib.patch | 12 | Patch0: libpng-multilib.patch |
| 13 | -Patch1: libpng-fix-arm-neon.patch | ||
| 14 | -Patch2: backport-CVE-2026-25646.patch | ||
| 15 | 13 | ||
| 16 | -BuildRequires: zlib-devel autoconf automake libtool | 14 | +BuildRequires: cmake >= 3.14 |
| 15 | +BuildRequires: zlib-devel | ||
| 17 | Provides: libpng-apng = %{epoch}:%{version}-%{release} | 16 | Provides: libpng-apng = %{epoch}:%{version}-%{release} |
| 18 | 17 | ||
| 19 | %description | 18 | %description |
| @@ -54,16 +53,17 @@ gunzip -dc %{S:2} | patch -p1 | |||
| 54 | cp -p %{S:1} . | 53 | cp -p %{S:1} . |
| 55 | 54 | ||
| 56 | %build | 55 | %build |
| 57 | -autoreconf -vif | 56 | +%cmake \ |
| 58 | -%configure | 57 | + -DPNG_SHARED:BOOL=ON \ |
| 59 | -%make_build DFA_XTRA=pngusr.dfa | 58 | + -DPNG_STATIC:BOOL=ON \ |
| 59 | + -DDFA_XTRA=%{S:1} | ||
| 60 | +%cmake_build | ||
| 60 | 61 | ||
| 61 | %install | 62 | %install |
| 62 | -%make_install | 63 | +%cmake_install |
| 63 | -%delete_la | ||
| 64 | 64 | ||
| 65 | %check | 65 | %check |
| 66 | -%make_build check | 66 | +%ctest |
| 67 | 67 | ||
| 68 | %files | 68 | %files |
| 69 | %license LICENSE | 69 | %license LICENSE |
| @@ -73,6 +73,9 @@ autoreconf -vif | |||
| 73 | %{_includedir}/* | 73 | %{_includedir}/* |
| 74 | %{_libdir}/libpng*.so | 74 | %{_libdir}/libpng*.so |
| 75 | %{_libdir}/pkgconfig/libpng*.pc | 75 | %{_libdir}/pkgconfig/libpng*.pc |
| 76 | +%{_libdir}/cmake/* | ||
| 77 | +%dir %{_libdir}/libpng | ||
| 78 | +%{_libdir}/libpng/*.cmake | ||
| 76 | 79 | ||
| 77 | %files static | 80 | %files static |
| 78 | %{_libdir}/libpng*.a | 81 | %{_libdir}/libpng*.a |
| @@ -85,6 +88,11 @@ autoreconf -vif | |||
| 85 | %{_mandir}/man*/* | 88 | %{_mandir}/man*/* |
| 86 | 89 | ||
| 87 | %changelog | 90 | %changelog |
| 91 | +* Sat Feb 14 2026 Funda Wang <fundawang@yeah.net> - 2:1.6.55-1 | ||
| 92 | +- update to 1.6.55 | ||
| 93 | +- build with cmake | ||
| 94 | +- drop neon work around as configure is not used any more | ||
| 95 | + | ||
| 88 | * Tue Feb 10 2026 Funda Wang <fundawang@yeah.net> - 2:1.6.54-2 | 96 | * Tue Feb 10 2026 Funda Wang <fundawang@yeah.net> - 2:1.6.54-2 |
| 89 | - fix CVE-2026-25646 | 97 | - fix CVE-2026-25646 |
| 90 | 98 | ||