public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/glib2] cve-2026-58016-f44: Unbreak setting special directories to $HOME
@ 2026-08-11 10:38 Michael Kuhn
  0 siblings, 0 replies; only message in thread
From: Michael Kuhn @ 2026-08-11 10:38 UTC (permalink / raw)
  To: git-commits

            A new commit has been pushed.

            Repo   : rpms/glib2
            Branch : cve-2026-58016-f44
            Commit : 82ac7aba87d3a07be2e9dd2ca8ca429c63220b2c
            Author : Michael Kuhn <suraia@fedoraproject.org>
            Date   : 2025-11-05T14:06:25+01:00
            Stats  : +73/-0 in 2 file(s)
            URL    : https://src.fedoraproject.org/rpms/glib2/c/82ac7aba87d3a07be2e9dd2ca8ca429c63220b2c?branch=cve-2026-58016-f44

            Log:
            Unbreak setting special directories to $HOME

This is a regression in GLib 2.86.1.

https://src.fedoraproject.org/rpms/glib2/pull-request/23

---
diff --git a/glib2.spec b/glib2.spec
index bd22528..33ca487 100644
--- a/glib2.spec
+++ b/glib2.spec
@@ -15,6 +15,10 @@ Patch:          gnutls-hmac.patch
 # https://bugzilla.redhat.com/show_bug.cgi?id=2192204
 Patch:          default-terminal.patch
 
+# https://gitlab.gnome.org/GNOME/glib/-/issues/3811
+# https://gitlab.gnome.org/GNOME/nautilus/-/issues/4014
+Patch:          strip-trailing-slashes.patch
+
 BuildRequires:  gcc
 BuildRequires:  gcc-c++
 BuildRequires:  gettext

diff --git a/strip-trailing-slashes.patch b/strip-trailing-slashes.patch
new file mode 100644
index 0000000..9f968c9
--- /dev/null
+++ b/strip-trailing-slashes.patch
@@ -0,0 +1,69 @@
+From bb23a0e8cb2426c1b52a0d3d89bd97cc17919961 Mon Sep 17 00:00:00 2001
+From: Tobias Stoeckmann <tobias@stoeckmann.org>
+Date: Fri, 24 Oct 2025 13:34:03 +0200
+Subject: [PATCH] gutils: Strip all trailing slashes
+
+The code stripped all but the first trailing slash in order to handle
+the absolute root path "/". This breaks the removal of trailing slashes
+for paths starting with $HOME, though.
+
+Fix the logic to remove all trailing slashes if $HOME is encountered.
+
+Closes #3811
+---
+ glib/gutilsprivate.c | 6 ++++--
+ glib/tests/utils.c   | 7 ++++++-
+ 2 files changed, 10 insertions(+), 3 deletions(-)
+
+diff --git a/glib/gutilsprivate.c b/glib/gutilsprivate.c
+index 083f88c2ccc2..3b9206c45ce9 100644
+--- a/glib/gutilsprivate.c
++++ b/glib/gutilsprivate.c
+@@ -27,6 +27,7 @@ load_user_special_dirs_from_string (const gchar *string, const gchar *home_dir,
+ {
+   gchar **lines;
+   gint n_lines, i;
++  size_t min_len;
+ 
+   lines = g_strsplit (string, "\n", -1);
+   n_lines = g_strv_length (lines);
+@@ -122,8 +123,9 @@ load_user_special_dirs_from_string (const gchar *string, const gchar *home_dir,
+ 
+       d = p;
+ 
+-      /* remove trailing slashes */
+-      for (len = strlen (d); len > 1 && d[len - 1] == '/'; len--)
++      /* remove trailing slashes, but keep first slash in absolute path */
++      min_len = is_relative ? 0 : 1;
++      for (len = strlen (d); len > min_len && d[len - 1] == '/'; len--)
+         d[len - 1] = 0;
+ 
+       /* Duplicates override the previous value. This is not explicit in the
+diff --git a/glib/tests/utils.c b/glib/tests/utils.c
+index 2d0b2ed70876..e886897ba095 100644
+--- a/glib/tests/utils.c
++++ b/glib/tests/utils.c
+@@ -883,7 +883,9 @@ test_user_special_dirs_load_unlocked (void)
+                                     "XDG_DOWNLOAD_DIR = \"$HOME/Downloads\"\n"
+                                     "XDG_MUSIC_DIR = \"///\"\n"
+                                     "XDG_PICTURES_DIR = \"$HOME/Pictures\"\n"
+-                                    "XDG_PICTURES_DIR = \"/\"\nXDG_DOWNLOAD_DIR = \"/dev/null\n");
++                                    "XDG_PICTURES_DIR = \"/\"\n"
++                                    "XDG_PUBLICSHARE_DIR = \"$HOME/\"\n"
++                                    "XDG_DOWNLOAD_DIR = \"/dev/null\n");
+ 
+       g_reload_user_special_dirs_cache ();
+ 
+@@ -903,6 +905,9 @@ test_user_special_dirs_load_unlocked (void)
+ 
+       dir = g_get_user_special_dir (G_USER_DIRECTORY_PICTURES);
+       g_assert_cmpstr (dir, ==, "/");
++
++      dir = g_get_user_special_dir (G_USER_DIRECTORY_PUBLIC_SHARE);
++      g_assert_cmpstr (dir, ==, g_get_home_dir ());
+     }
+   else
+     {
+-- 
+2.51.1
+

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-11 10:38 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-11 10:38 [rpms/glib2] cve-2026-58016-f44: Unbreak setting special directories to $HOME Michael Kuhn

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox