2
0
mirror of https://github.com/xcat2/xcat-dep.git synced 2026-09-30 14:55:17 +00:00
Files
xcat-dep/perl-Net-DNS/Net-DNS.spec
T
Daniel Hilst e125f6f79f fix(xcat-dep): the riscv64 Net::DNS carries CVE-2026-64193 and CVE-2026-64194
perl-Net-DNS built Net::DNS 1.47 without patches. That release decodes
the EDNS EXTENDED-ERROR text with a string eval (CVE-2026-64193) and
follows compression pointer chains of any depth (CVE-2026-64194).
Net::DNS 1.56 fixes both, and 1.57 also stops an unbounded recursion on
a misplaced TSIG.

Build Net::DNS 1.57. The tarball, the spec, the Buildnote and the
riscv64 manifest pin move together. The build requirements of 1.57 are
the same as those of 1.47.

t/net_dns_rr_types.t decodes a reply with a 200-pointer chain and fails
on 1.47.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
2026-09-29 08:46:22 -03:00

168 lines
5.6 KiB
RPMSpec

#
# - Net::DNS -
# This spec file was automatically generated by cpan2rpm [ver: 2.028]
# The following arguments were used:
# ./Net-DNS-1.57.tar.gz
# For more information on cpan2rpm please visit: http://perl.arix.com/
#
%define pkgname Net-DNS
%define filelist %{pkgname}-%{version}-filelist
%define NVR %{pkgname}-%{version}-%{release}
%define maketest 1
name: perl-Net-DNS
summary: Net-DNS - Perl DNS resolver module
version: 1.57
release: 1
vendor: Olaf Kolkman <olaf@net-dns.org>
packager: Arix International <cpan2rpm@arix.com>
license: Artistic
group: Applications/CPAN
url: http://www.cpan.org
buildroot: %{_tmppath}/%{name}-%{version}-%(id -u -n)
buildarch: noarch
prefix: %(echo %{_prefix})
source: Net-DNS-1.57.tar.gz
# cpan2rpm specs carry no BuildRequires; an EL10 buildroot has neither perl nor make, and
# perl-generators is what makes rpm compute the perl(...) Requires.
BuildRequires: make
BuildRequires: perl-interpreter
BuildRequires: perl-generators
BuildRequires: perl(ExtUtils::MakeMaker)
BuildRequires: perl(Digest::HMAC)
BuildRequires: perl(Digest::MD5)
BuildRequires: perl(Digest::SHA)
BuildRequires: perl(IO::Socket::IP)
BuildRequires: perl(MIME::Base64)
BuildRequires: perl(Test::More)
# The perl dependency generator reads "use base OS_CONF" in Net::DNS::Resolver::Base as a module
# name. OS_CONF is a constant that names the platform resolver class at run time, so no package
# provides perl(OS_CONF) and the generated dependency stops dnf from installing the rpm.
%global __requires_exclude ^perl\\(OS_CONF\\)$
%description
Net::DNS is a collection of Perl modules that act as a Domain Name System
(DNS) resolver. It allows the programmer to perform DNS queries that are
beyond the capabilities of "gethostbyname" and "gethostbyaddr".
The programmer should be somewhat familiar with the format of a DNS packet
and its various sections. See RFC 1035 or DNS and BIND (Albitz & Liu) for
details.
#
# This package was generated automatically with the cpan2rpm
# utility. To get this software or for more information
# please visit: http://perl.arix.com/
#
%prep
%setup -q -n %{pkgname}-%{version}
chmod -R u+w %{_builddir}/%{pkgname}-%{version}
%build
grep -rsl '^#!.*perl' . |
grep -v '.bak$' |xargs --no-run-if-empty \
%__perl -MExtUtils::MakeMaker -e 'MY->fixin(@ARGV)'
CFLAGS="$RPM_OPT_FLAGS"
# Net::DNS is pure perl from 1.01 on, so one noarch rpm serves every arch. The mock chroot has
# no network: --noonline-tests keeps the resolver tests from waiting for one.
%{__perl} Makefile.PL --noonline-tests `%{__perl} -MExtUtils::MakeMaker -e ' print qq|PREFIX=%{buildroot}%{_prefix}| if \$ExtUtils::MakeMaker::VERSION =~ /5\.9[1-6]|6\.0[0-5]/ '`
%{__make}
%if %maketest
%{__make} test
%endif
%install
[ "%{buildroot}" != "/" ] && rm -rf %{buildroot}
%{makeinstall} `%{__perl} -MExtUtils::MakeMaker -e ' print \$ExtUtils::MakeMaker::VERSION <= 6.05 ? qq|PREFIX=%{buildroot}%{_prefix}| : qq|DESTDIR=%{buildroot}| '`
cmd=/usr/share/spec-helper/compress_files
[ -x $cmd ] || cmd=/usr/lib/rpm/brp-compress
[ -x $cmd ] && $cmd
# SuSE Linux
if [ -e /etc/SuSE-release -o -e /etc/UnitedLinux-release ]
then
%{__mkdir_p} %{buildroot}/var/adm/perl-modules
%{__cat} `find %{buildroot} -name "perllocal.pod"` \
| %{__sed} -e s+%{buildroot}++g \
> %{buildroot}/var/adm/perl-modules/%{name}
fi
# remove special files
find %{buildroot} -name "perllocal.pod" \
-o -name ".packlist" \
-o -name "*.bs" \
|xargs -i rm -f {}
# no empty directories
find %{buildroot}%{_prefix} \
-type d -depth \
-exec rmdir {} \; 2>/dev/null
%{__perl} -MFile::Find -le '
find({ wanted => \&wanted, no_chdir => 1}, "%{buildroot}");
print "%doc Changes LICENSE README contrib demo";
for my $x (sort @dirs, @files) {
push @ret, $x unless indirs($x);
}
print join "\n", sort @ret;
sub wanted {
return if /auto$/;
local $_ = $File::Find::name;
my $f = $_; s|^\Q%{buildroot}\E||;
return unless length;
return $files[@files] = $_ if -f $f;
$d = $_;
/\Q$d\E/ && return for reverse sort @INC;
$d =~ /\Q$_\E/ && return
for qw|/etc %_prefix/man %_prefix/bin %_prefix/share|;
$dirs[@dirs] = $_;
}
sub indirs {
my $x = shift;
$x =~ /^\Q$_\E\// && $x ne $_ && return 1 for @dirs;
}
' > %filelist
[ -z %filelist ] && {
echo "ERROR: empty %files listing"
exit -1
}
%clean
[ "%{buildroot}" != "/" ] && rm -rf %{buildroot}
%files -f %filelist
%defattr(-,root,root)
%changelog
* Tue Sep 29 2026 xCAT build - 1.57-1
- Net::DNS 1.57. 1.47 carries CVE-2026-64193 (code injection via EDNS
EXTENDED-ERROR) and CVE-2026-64194 (deep compression pointer chains),
fixed in 1.56, and unbounded recursion on a misplaced TSIG, fixed in 1.57.
* Sat Sep 05 2026 xCAT build - 1.47-1
- Net::DNS 1.47. Release 0.80 leaves the DNSSEC records to Net::DNS::SEC, so
Net::DNS::RR->new("<key>. IN KEY ...") dies and xCAT makedns fails. 1.47 is
also the release EPEL 10 ships, so every architecture now gets the same one.
- Makefile.PL of 1.47 rejects --noxs (the module carries no XS); pass
--noonline-tests instead, because the mock chroot has no network.
- BuildRequires perl(IO::Socket::IP), which Makefile.PL needs to configure.
* Thu Aug 20 2026 xCAT build - 0.80-2
- Build the pure-perl module (--noxs) as noarch instead of an XS x86_64 rpm.
- BuildRequires for an EL10 buildroot (make, perl-interpreter, perl-generators,
MakeMaker, Digest::HMAC/MD5/SHA, MIME::Base64, Test::More).
* Tue Oct 28 2014 root@slesmn
- Initial build.