import CS git emacs-29.4-13.el10_2
This commit is contained in:
parent
c9cdc046ee
commit
0b8d9f03da
165
emacs-CVE-2024-53920.patch
Normal file
165
emacs-CVE-2024-53920.patch
Normal file
@ -0,0 +1,165 @@
|
||||
From b5158bd191422e46273c4d9412f2bf097e2da2e0 Mon Sep 17 00:00:00 2001
|
||||
From: Stefan Monnier <monnier@iro.umontreal.ca>
|
||||
Date: Tue, 10 Dec 2024 16:26:31 -0500
|
||||
Subject: elisp-mode.el: Disable Flymake byte-compile backend in untrusted
|
||||
files
|
||||
|
||||
To address serious security issues (CVE-2024-53920), disable
|
||||
`elisp-flymake-byte-compile` except in those files explicitly
|
||||
specified as "trusted".
|
||||
|
||||
For that introduce a new custom var `trusted-files` and new
|
||||
function `trusted-content-p`.
|
||||
|
||||
While at it, similarly skip the implicit macroexpansion done during
|
||||
completion if the current file is not trusted.
|
||||
|
||||
* lisp/files.el (trusted-files): New variable.
|
||||
(trusted-content-p): New function.
|
||||
|
||||
* lisp/progmodes/elisp-mode.el (elisp--safe-macroexpand-all):
|
||||
New function, extracted from `elisp--local-variables`.
|
||||
Use `trusted-content-p`.
|
||||
(elisp--local-variables): Use it.
|
||||
(elisp-flymake-byte-compile): Disable according to `trusted-content-p`.
|
||||
|
||||
Backported to emacs-29.4 for CentOS Stream 10
|
||||
---
|
||||
lisp/files.el | 49 ++++++++++++++++++++++++++++++++++++
|
||||
lisp/progmodes/elisp-mode.el | 45 +++++++++++++++++++++++----------
|
||||
2 files changed, 81 insertions(+), 13 deletions(-)
|
||||
|
||||
--- emacs-29.4.orig/lisp/files.el 2026-03-06 11:21:46.972502007 +0000
|
||||
+++ emacs-29.4/lisp/files.el 2026-03-06 11:22:16.648320007 +0000
|
||||
@@ -703,6 +703,55 @@
|
||||
This variable might be subject to change without notice.")
|
||||
(put 'untrusted-content 'permanent-local t)
|
||||
|
||||
+(defcustom trusted-files nil
|
||||
+ "List of files and directories whose content we trust.
|
||||
+Be extra careful here since trusting means that Emacs might execute the
|
||||
+code contained within those files and directories without an explicit
|
||||
+request by the user.
|
||||
+One important case when this might happen is when `flymake-mode' is
|
||||
+enabled (for example, when it is added to a mode hook).
|
||||
+Each element of the list should be a string:
|
||||
+- If it ends in \"/\", it is considered as a directory name and means that
|
||||
+ Emacs should trust all the files whose name has this directory as a prefix.
|
||||
+- else it is considered as a file name.
|
||||
+Use abbreviated file names. For example, an entry \"~/mycode\" means
|
||||
+that Emacs will trust all the files in your directory \"mycode\".
|
||||
+This variable can also be set to `:all', in which case Emacs will trust
|
||||
+all files, which opens a gaping security hole."
|
||||
+ :type '(choice (repeat :tag "List" file)
|
||||
+ (const :tag "Trust everything (DANGEROUS!)" :all))
|
||||
+ :version "30.1")
|
||||
+(put 'trusted-files 'risky-local-variable t)
|
||||
+
|
||||
+(defun trusted-content-p ()
|
||||
+ "Return non-nil if we trust the contents of the current buffer.
|
||||
+Here, \"trust\" means that we are willing to run code found inside of it.
|
||||
+See also `trusted-files'."
|
||||
+ ;; We compare with `buffer-file-truename' i.s.o `buffer-file-name'
|
||||
+ ;; to try and avoid marking as trusted a file that's merely accessed
|
||||
+ ;; via a symlink that happens to be inside a trusted dir.
|
||||
+ (and (not untrusted-content)
|
||||
+ buffer-file-truename
|
||||
+ (with-demoted-errors "trusted-content-p: %S"
|
||||
+ (let ((exists (file-exists-p buffer-file-truename)))
|
||||
+ (or
|
||||
+ (eq trusted-files :all)
|
||||
+ ;; We can't avoid trusting the user's init file.
|
||||
+ (if (and exists user-init-file)
|
||||
+ (file-equal-p buffer-file-truename user-init-file)
|
||||
+ (equal buffer-file-truename user-init-file))
|
||||
+ (let ((file (abbreviate-file-name buffer-file-truename))
|
||||
+ (trusted nil))
|
||||
+ (dolist (tf trusted-files)
|
||||
+ (when (or (if exists (file-equal-p tf file) (equal tf file))
|
||||
+ ;; We don't use `file-in-directory-p' here, because
|
||||
+ ;; we want to err on the conservative side: "guilty
|
||||
+ ;; until proven innocent".
|
||||
+ (and (string-suffix-p "/" tf)
|
||||
+ (string-prefix-p tf file)))
|
||||
+ (setq trusted t)))
|
||||
+ trusted))))))
|
||||
+
|
||||
;; This is an odd variable IMO.
|
||||
;; You might wonder why it is needed, when we could just do:
|
||||
;; (setq-local enable-local-variables nil)
|
||||
--- emacs-29.4.orig/lisp/progmodes/elisp-mode.el 2026-03-06 11:21:47.009502007 +0000
|
||||
+++ emacs-29.4/lisp/progmodes/elisp-mode.el 2026-03-06 11:23:00.404547013 +0000
|
||||
@@ -430,6 +430,33 @@
|
||||
|
||||
(defvar warning-minimum-log-level)
|
||||
|
||||
+
|
||||
+(defvar elisp--macroexpand-untrusted-warning t)
|
||||
+
|
||||
+(defun elisp--safe-macroexpand-all (sexp)
|
||||
+ (if (not (trusted-content-p))
|
||||
+ ;; FIXME: We should try and do better here, either using a notion
|
||||
+ ;; of "safe" macros, or with `bwrap', or ...
|
||||
+ (progn
|
||||
+ (when elisp--macroexpand-untrusted-warning
|
||||
+ (setq-local elisp--macroexpand-untrusted-warning nil) ;Don't spam!
|
||||
+ (message "Completion of local vars is disabled in %s (untrusted content)"
|
||||
+ (buffer-name)))
|
||||
+ sexp)
|
||||
+ (let ((macroexpand-advice
|
||||
+ (lambda (expander form &rest args)
|
||||
+ (condition-case err
|
||||
+ (apply expander form args)
|
||||
+ (error
|
||||
+ (message "Ignoring macroexpansion error: %S" err) form)))))
|
||||
+ (unwind-protect
|
||||
+ ;; Silence any macro expansion errors when
|
||||
+ ;; attempting completion at point (bug#58148).
|
||||
+ (let ((inhibit-message t)
|
||||
+ (warning-minimum-log-level :emergency))
|
||||
+ (advice-add 'macroexpand-1 :around macroexpand-advice)
|
||||
+ (macroexpand-all sexp))
|
||||
+ (advice-remove 'macroexpand-1 macroexpand-advice)))))
|
||||
(defun elisp--local-variables ()
|
||||
"Return a list of locally let-bound variables at point."
|
||||
(save-excursion
|
||||
@@ -445,22 +472,8 @@
|
||||
(car (read-from-string
|
||||
(concat txt "elisp--witness--lisp" closer)))
|
||||
((invalid-read-syntax end-of-file) nil)))
|
||||
- (macroexpand-advice (lambda (expander form &rest args)
|
||||
- (condition-case nil
|
||||
- (apply expander form args)
|
||||
- (error form))))
|
||||
- (sexp
|
||||
- (unwind-protect
|
||||
- ;; Silence any macro expansion errors when
|
||||
- ;; attempting completion at point (bug#58148).
|
||||
- (let ((inhibit-message t)
|
||||
- (warning-minimum-log-level :emergency))
|
||||
- (advice-add 'macroexpand :around macroexpand-advice)
|
||||
- (condition-case nil
|
||||
- (macroexpand-all sexp)
|
||||
- (error sexp)))
|
||||
- (advice-remove 'macroexpand macroexpand-advice)))
|
||||
- (vars (elisp--local-variables-1 nil sexp)))
|
||||
+ (vars (elisp--local-variables-1
|
||||
+ nil (elisp--safe-macroexpand-all sexp))))
|
||||
(delq nil
|
||||
(mapcar (lambda (var)
|
||||
(and (symbolp var)
|
||||
@@ -2164,6 +2177,14 @@
|
||||
"A Flymake backend for elisp byte compilation.
|
||||
Spawn an Emacs process that byte-compiles a file representing the
|
||||
current buffer state and calls REPORT-FN when done."
|
||||
+ (unless (trusted-content-p)
|
||||
+ ;; FIXME: Use `bwrap' and friends to compile untrusted content.
|
||||
+ ;; FIXME: We emit a message *and* signal an error, because by default
|
||||
+ ;; Flymake doesn't display the warning it puts into "*flmake log*".
|
||||
+ (message "Disabling elisp-flymake-byte-compile in %s (untrusted content)"
|
||||
+ (buffer-name))
|
||||
+ (error "Disabling elisp-flymake-byte-compile in %s (untrusted content)"
|
||||
+ (buffer-name)))
|
||||
(when elisp-flymake--byte-compile-process
|
||||
(when (process-live-p elisp-flymake--byte-compile-process)
|
||||
(kill-process elisp-flymake--byte-compile-process)))
|
||||
@ -1,8 +1,8 @@
|
||||
## START: Set by rpmautospec
|
||||
## (rpmautospec version 0.6.5)
|
||||
## (rpmautospec version 0.8.1)
|
||||
## RPMAUTOSPEC: autorelease, autochangelog
|
||||
%define autorelease(e:s:pb:n) %{?-p:0.}%{lua:
|
||||
release_number = 12;
|
||||
release_number = 13;
|
||||
base_release_number = tonumber(rpm.expand("%{?-b*}%{!?-b:1}"));
|
||||
print(release_number + base_release_number - 1);
|
||||
}%{?-e:.%{-e*}}%{?-s:.%{-s*}}%{!?-n:%{?dist}}
|
||||
@ -46,6 +46,7 @@ Patch7: emacs-man-el-shell-injection-vulnerability.patch
|
||||
# Avoid trademark issues
|
||||
Patch8: pong-and-tetris-are-excluded.patch
|
||||
Patch9: fix-flymake-tests-with-gcc-14.patch
|
||||
Patch10: emacs-CVE-2024-53920.patch
|
||||
|
||||
BuildRequires: gcc
|
||||
BuildRequires: atk-devel
|
||||
@ -622,6 +623,9 @@ desktop-file-validate %{buildroot}/%{_datadir}/applications/*.desktop
|
||||
|
||||
%changelog
|
||||
## START: Generated by rpmautospec
|
||||
* Fri Mar 06 2026 Jacek Migacz <jmigacz@redhat.com> - 1:29.4-13
|
||||
- Fix CVE-2024-53920 arbitrary code execution vulnerability
|
||||
|
||||
* Tue Jun 17 2025 Jacek Migacz <jmigacz@redhat.com> - 1:29.4-12
|
||||
- Fix flymake tests with GCC 14
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user