public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
From: Dominik 'Rathann' Mierzejewski <dominik@greysector.net>
To: git-commits@fedoraproject.org
Subject: [rpms/minidlna] epel9-next: use systemctl try-restart in postrotate script (resolves rhbz#2372859)
Date: Mon, 20 Jul 2026 18:20:46 GMT	[thread overview]
Message-ID: <178457164668.1.12190641953801116706.rpms-minidlna-b5c6ed96a922@fedoraproject.org> (raw)

            A new commit has been pushed.

            Repo   : rpms/minidlna
            Branch : epel9-next
            Commit : b5c6ed96a9228102bdc5942bd16dadd6ac643c84
            Author : Dominik 'Rathann' Mierzejewski <dominik@greysector.net>
            Date   : 2025-07-07T18:26:08+02:00
            Stats  : +209/-2 in 3 file(s)
            URL    : https://src.fedoraproject.org/rpms/minidlna/c/b5c6ed96a9228102bdc5942bd16dadd6ac643c84?branch=epel9-next

            Log:
            use systemctl try-restart in postrotate script (resolves rhbz#2372859)

- attempt to fix CVE-2023-47430 (resolves rhbz#2271621)

---
diff --git a/minidlna-CVE-2023-47430.patch b/minidlna-CVE-2023-47430.patch
new file mode 100644
index 0000000..5b7bdf9
--- /dev/null
+++ b/minidlna-CVE-2023-47430.patch
@@ -0,0 +1,200 @@
+diff -up minidlna-1.3.3/tivo_commands.c.orig minidlna-1.3.3/tivo_commands.c
+--- minidlna-1.3.3/tivo_commands.c.orig	2023-05-31 10:25:59.000000000 +0200
++++ minidlna-1.3.3/tivo_commands.c	2025-07-07 18:13:00.594971958 +0200
+@@ -435,8 +435,16 @@ SendContainer(struct upnphttp *h, const
+ 				}
+ 				if( strcasecmp(item, "Type") == 0 )
+ 				{
++					if (strlen(order)+5 < 96 && strlen(order2)+5 < 96)
++					{
+ 					strcat(order, "CLASS");
+ 					strcat(order2, "CLASS");
++					}
++					else
++					{
++						DPRINTF(E_INFO, L_TIVO, "Type order string too long [%s]\n", item);
++						goto unhandled_order;
++					}
+ 				}
+ 				else if( strcasecmp(item, "Title") == 0 )
+ 				{
+@@ -445,29 +453,61 @@ SendContainer(struct upnphttp *h, const
+ 					{
+ 						if( !title_state )
+ 						{
++							if (strlen(order)+4 < 96 && strlen(order2)+4 < 96)
++							{
+ 							strcat(order, "DISC");
+ 							strcat(order2, "DISC");
+ 							title_state = 1;
++							}
++							else
++							{
++								DPRINTF(E_INFO, L_TIVO, "Title order string too long [%s]\n", item);
++								goto unhandled_order;
++							}
+ 						}
+ 						else
+ 						{
++							if (strlen(order)+5 < 96 && strlen(order2)+5 < 96)
++							{
+ 							strcat(order, "TRACK");
+ 							strcat(order2, "TRACK");
+ 							title_state = 2;
++							}
++							else
++							{
++								DPRINTF(E_INFO, L_TIVO, "Title order string too long [%s]\n", item);
++								goto unhandled_order;
++							}
+ 						}
+ 					}
+ 					else
+ 					{
++						if (strlen(order)+5 < 96 && strlen(order2)+5 < 96)
++						{
+ 						strcat(order, "TITLE");
+ 						strcat(order2, "TITLE");
+ 						title_state = -1;
++						}
++						else
++						{
++							DPRINTF(E_INFO, L_TIVO, "Title order string too long [%s]\n", item);
++							goto unhandled_order;
++						}
+ 					}
+ 				}
+ 				else if( strcasecmp(item, "CreationDate") == 0 ||
+ 				         strcasecmp(item, "CaptureDate") == 0 )
+ 				{
++					if (strlen(order)+4 < 96 && strlen(order2)+4 < 96)
++					{
+ 					strcat(order, "DATE");
+ 					strcat(order2, "DATE");
++					}
++					else
++					{
++						DPRINTF(E_INFO, L_TIVO, "Date order string too long [%s]\n", item);
++						goto unhandled_order;
++					}
+ 				}
+ 				else
+ 				{
+@@ -477,39 +517,78 @@ SendContainer(struct upnphttp *h, const
+ 
+ 				if( reverse )
+ 				{
++					if (strlen(order)+5 < 96 && strlen(order2)+5 < 96)
++					{
+ 					strcat(order, " DESC");
+ 					if( itemCount >= 0 )
+ 						strcat(order2, " DESC");
+ 					else
+ 						strcat(order2, " ASC");
++					}
++					else
++					{
++						DPRINTF(E_INFO, L_TIVO, "Reverse order string too long [%s]\n", item);
++						goto unhandled_order;
++					}
+ 				}
+ 				else
+ 				{
++					if (strlen(order)+5 < 96 && strlen(order2)+5 < 96)
++					{
+ 					strcat(order, " ASC");
+ 					if( itemCount >= 0 )
+ 						strcat(order2, " ASC");
+ 					else
+ 						strcat(order2, " DESC");
++					}
++					else
++					{
++						DPRINTF(E_INFO, L_TIVO, "Reverse order string too long [%s]\n", item);
++						goto unhandled_order;
++					}
+ 				}
++				if (strlen(order)+2 < 96 && strlen(order2)+2 < 96)
++				{
+ 				strcat(order, ", ");
+ 				strcat(order2, ", ");
++				}
++				else
++				{
++					DPRINTF(E_INFO, L_TIVO, "Reverse order string too long [%s]\n", item);
++				}
+ 				unhandled_order:
+ 				if( title_state <= 0 )
+ 					item = strtok_r(NULL, ",", &saveptr);
+ 			}
+ 			if( title_state != -1 )
+ 			{
++				if (strlen(order)+11 < 96 && strlen(order2)+11 < 96)
++				{
+ 				strcat(order, "TITLE ASC, ");
+ 				if( itemCount >= 0 )
+ 					strcat(order2, "TITLE ASC, ");
+ 				else
+ 					strcat(order2, "TITLE DESC, ");
++				}
++				else
++				{
++					DPRINTF(E_INFO, L_TIVO, "order string too long [%s]\n", item);
++					goto unhandled_order2;
++				}
+ 			}
++			if (strlen(order)+11 < 96 && strlen(order2)+11 < 96)
++			{
+ 			strcat(order, "DETAIL_ID ASC");
+ 			if( itemCount >= 0 )
+ 				strcat(order2, "DETAIL_ID ASC");
+ 			else
+ 				strcat(order2, "DETAIL_ID DESC");
++			}
++			else
++			{
++				DPRINTF(E_INFO, L_TIVO, "order string too long [%s]\n", item);
++			}
++			unhandled_order2:
+ 		}
+ 	}
+ 	else
+@@ -528,27 +607,38 @@ SendContainer(struct upnphttp *h, const
+ 		{
+ 			if( i )
+ 			{
++				if (strlen(myfilter)+4 < 256)
+ 				strcat(myfilter, " or ");
++				else goto unhandled_filter;
+ 			}
+ 			if( (strcasecmp(item, "x-container/folder") == 0) ||
+ 			    (strncasecmp(item, "x-tivo-container/", 17) == 0) )
+ 			{
++				if (strlen(myfilter)+23 < 256)
+ 				strcat(myfilter, "CLASS glob 'container*'");
++				else goto unhandled_filter;
+ 			}
+ 			else if( strncasecmp(item, "image", 5) == 0 )
+ 			{
++				if (strlen(myfilter)+19 < 256)
+ 				strcat(myfilter, "MIME = 'image/jpeg'");
++				else goto unhandled_filter;
+ 			}
+ 			else if( strncasecmp(item, "audio", 5) == 0 )
+ 			{
++				if (strlen(myfilter)+19 < 256)
+ 				strcat(myfilter, "MIME = 'audio/mpeg'");
++				else goto unhandled_filter;
+ 			}
+ 			else if( strncasecmp(item, "video", 5) == 0 )
+ 			{
++				if (strlen(myfilter)+67 < 256)
+ 				strcat(myfilter, "MIME in ('video/mpeg', 'video/x-tivo-mpeg', 'video/x-tivo-mpeg-ts')");
++				else goto unhandled_filter;
+ 			}
+ 			else
+ 			{
++				unhandled_filter:
+ 				DPRINTF(E_INFO, L_TIVO, "Unhandled Filter [%s]\n", item);
+ 				if( i )
+ 				{

diff --git a/minidlna.logrotate b/minidlna.logrotate
index db21c40..070455f 100644
--- a/minidlna.logrotate
+++ b/minidlna.logrotate
@@ -8,6 +8,6 @@
     compress
     create 0644 minidlna minidlna
     postrotate
-        /usr/bin/systemctl restart minidlna.service >/dev/null 2>&1 || true
+        /usr/bin/systemctl try-restart minidlna.service >/dev/null 2>&1 || true
     endscript
 }

diff --git a/minidlna.spec b/minidlna.spec
index 6fadb5c..e8e3365 100644
--- a/minidlna.spec
+++ b/minidlna.spec
@@ -1,6 +1,6 @@
 Name:           minidlna
 Version:        1.3.3
-Release:        12%{?dist}
+Release:        13%{?dist}
 Summary:        Lightweight DLNA/UPnP-AV server targeted at embedded systems
 
 # see minidlna-licensing-breakdown.txt for complete breakdown
@@ -20,6 +20,9 @@ Patch0:         %{name}-1.3.0-select_use_after_free.patch
 # Add compatibility with FFMPEG 7.0
 # https://sourceforge.net/p/minidlna/git/merge-requests/58/
 Patch1:         0001-Add-compatibility-with-FFMPEG-7.0.patch
+# Fix CVE-2023-47430
+# https://sourceforge.net/p/minidlna/bugs/361/
+Patch2:         %{name}-CVE-2023-47430.patch
 
 BuildRequires:  avahi-devel
 BuildRequires:  flac-devel
@@ -138,6 +141,10 @@ install -d -m 755 %{buildroot}%{_localstatedir}/log/%{name}/
 
 
 %changelog
+* Mon Jul 07 2025 Dominik Mierzejewski <dominik@greysector.net> - 1.3.3-13
+- use systemctl try-restart in postrotate script (resolves rhbz#2372859)
+- attempt to fix CVE-2023-47430 (resolves rhbz#2271621)
+
 * Tue May 27 2025 Jitka Plesnikova <jplesnik@redhat.com> - 1.3.3-12
 - Rebuilt for flac 1.5.0
 

                 reply	other threads:[~2026-07-20 18:20 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178457164668.1.12190641953801116706.rpms-minidlna-b5c6ed96a922@fedoraproject.org \
    --to=dominik@greysector.net \
    --cc=git-commits@fedoraproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox