Re: nasty patches in pkgsrc regarding CVE-2010-4651: relative paths with ../

Alistair Crooks <[email protected]> Fri, 3 Jul 2026 09:50:41 -0700
Newsgroups gmane.os.netbsd.devel.packages
Message-ID <CAN5gJXprSHh9fxFcZTddQSDwXNocmXpmuO972KbMO5w8iUuuNw@mail.gmail.com>
--00000000000044a8090655b7ba46
Content-Type: text/plain; charset="UTF-8"

On Fri, Jul 3, 2026 at 04:19 Greg Troxel <[email protected]> wrote:

> Tobias Nygren <[email protected]> writes:
>
> > If you have a cleaner method to apply patches from $WRKDIR
> > instead of $WRKSRC, please make a proposal. Bonus points awarded if
> > it works with mkpatches.
>
> Three proposals
>
> 0) Ask the rust world to mend their ways.


Would be good, yes

>
>
> 1) Change our rules for patches to be baed in WRKDIR instead.


This would be problematic - we have enough games to play with getting the
directory name correct in WRKSRC, and to have todo that for all patches
too?

Beyond that, and taking a more objective stance, we should be patching the
source code. WRKDIR includes stuff that is not source code, but can
influence the build. I'm reluctant to go down that route, despite all the
eyeballs, as tnn notes

>
>
> 2) Add patches-wrkdir *additionally* for patches based on wrkdir.  Teach
> mkpatches to put patches within WRKSRC in patches, and other patches in
> patches-wrkdir
>

I'm still not sure this is a good idea :(

But I do agree that relative paths in patch files, all 180+ of them, should
not exist. Good catch

>
>

--00000000000044a8090655b7ba46
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div><br></div><div><br><div class=3D"gmail_quote gmail_quote_container"><d=
iv dir=3D"ltr" class=3D"gmail_attr">On Fri, Jul 3, 2026 at 04:19 Greg Troxe=
l &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br></=
div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;bor=
der-left:1px solid rgb(204,204,204);padding-left:1ex">Tobias Nygren &lt;tnn=
@NetBSD.org&gt; writes:<br>
<br>
&gt; If you have a cleaner method to apply patches from $WRKDIR<br>
&gt; instead of $WRKSRC, please make a proposal. Bonus points awarded if<br=
>
&gt; it works with mkpatches.<br>
<br>
Three proposals<br>
<br>
0) Ask the rust world to mend their ways.</blockquote><div dir=3D"auto"><br=
></div><div dir=3D"auto">Would be good, yes</div><blockquote class=3D"gmail=
_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204=
,204);padding-left:1ex" dir=3D"auto"><br>
<br>
1) Change our rules for patches to be baed in WRKDIR instead.</blockquote><=
div dir=3D"auto"><br></div><div dir=3D"auto">This would be problematic - we=
 have enough games to play with getting the directory name correct in WRKSR=
C, and to have todo that for all patches too?=C2=A0</div><div dir=3D"auto">=
<br></div><div dir=3D"auto">Beyond that, and taking a more objective stance=
, we should be patching the source code. WRKDIR includes stuff that is not =
source code, but can influence the build. I&#39;m reluctant to go down that=
 route, despite all the eyeballs, as tnn notes</div><blockquote class=3D"gm=
ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,=
204,204);padding-left:1ex" dir=3D"auto"><br>
<br>
2) Add patches-wrkdir *additionally* for patches based on wrkdir.=C2=A0 Tea=
ch<br>
mkpatches to put patches within WRKSRC in patches, and other patches in<br>
patches-wrkdir<br>
</blockquote><div dir=3D"auto"><br>I&#39;m still not sure this is a good id=
ea :(</div><div dir=3D"auto"><br></div><div dir=3D"auto">But I do agree tha=
t relative paths in patch files, all 180+ of them, should not exist. Good c=
atch<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px=
 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" dir=3D"auto=
"><br>
</blockquote></div></div>

--00000000000044a8090655b7ba46--