Compare commits

...

10 Commits

Author SHA1 Message Date
openeuler-ci-bot
67410e9fb7
!20 Fix CVE-2023-6378,CVE-2023-6481
From: @wk333 
Reviewed-by: @cherry530 
Signed-off-by: @cherry530
2023-12-12 06:07:23 +00:00
wk333
db6c27149b Fix CVE-2023-6378,CVE-2023-6481 2023-12-12 11:01:35 +08:00
openeuler-ci-bot
93d95ac335
!17 [合规提升]spec文件的License声明有歧义
From: @YixiongChen 
Reviewed-by: @luo-haibo 
Signed-off-by: @luo-haibo
2022-08-08 20:25:47 +00:00
chenyx2012
3e1f76e29a
License compliance rectification 2022-08-08 08:16:48 +00:00
openeuler-ci-bot
7261a82362
!15 [sync] PR-4: Upgrade to 1.2.8 version for fix CVE-2021-42550
From: @openeuler-sync-bot 
Reviewed-by: @caodongxia 
Signed-off-by: @caodongxia
2022-07-30 06:28:44 +00:00
houyingchao
966a0b626e Upgrade to 1.2.8 version for fix CVE-2021-42550
(cherry picked from commit 9e2a51a34e3601a8ed135005900864d1223978a9)
2022-07-30 10:15:08 +08:00
openeuler-ci-bot
83e93cc9aa !2 fix CVE-2017-5929
From: @wangxiao65
Reviewed-by: @miao_kaibo
Signed-off-by: @miao_kaibo
2020-09-19 17:35:37 +08:00
wangxiao65
f6c93fa6da fix CVE-2017-5929 2020-09-19 16:22:54 +08:00
openeuler-ci-bot
0a9f96c329 !1 package init
Merge pull request !1 from daidai_is_here/dqw_test
2020-03-07 18:48:06 +08:00
daidai_is_here
fa8f8a7679 package init 2020-03-07 18:42:58 +08:00
5 changed files with 669 additions and 0 deletions

View File

@ -0,0 +1,456 @@
From bb095154be011267b64e37a1d401546e7cc2b7c3 Mon Sep 17 00:00:00 2001
From: Ceki Gulcu <ceki@qos.ch>
Date: Fri, 1 Dec 2023 15:12:22 +0100
Subject: [PATCH] fix CVE-2023-6378
Signed-off-by: Ceki Gulcu <ceki@qos.ch>
---
.../logback/classic/spi/LoggingEventVO.java | 7 ++
.../src/test/input/issue/logback-1754.xml | 30 +++++++
.../issue/logback_1754/LogbackTest.java | 78 +++++++++++++++++++
.../core/net/HardenedObjectInputStream.java | 55 ++++++++++++-
.../ch/qos/logback/core/util/EnvUtil.java | 39 ++++++----
.../net/HardenedObjectInputStreamTest.java | 49 +++++++++++-
.../rolling/ScaffoldingForRollingTests.java | 2 +-
.../ch/qos/logback/core/util/EnvUtilTest.java | 34 ++++++++
8 files changed, 275 insertions(+), 19 deletions(-)
create mode 100644 logback-classic/src/test/input/issue/logback-1754.xml
create mode 100644 logback-classic/src/test/java/ch/qos/logback/classic/issue/logback_1754/LogbackTest.java
create mode 100644 logback-core/src/test/java/ch/qos/logback/core/util/EnvUtilTest.java
diff --git a/logback-classic/src/main/java/ch/qos/logback/classic/spi/LoggingEventVO.java b/logback-classic/src/main/java/ch/qos/logback/classic/spi/LoggingEventVO.java
index e21350b2cc..ea2c6ac128 100644
--- a/logback-classic/src/main/java/ch/qos/logback/classic/spi/LoggingEventVO.java
+++ b/logback-classic/src/main/java/ch/qos/logback/classic/spi/LoggingEventVO.java
@@ -14,6 +14,7 @@
package ch.qos.logback.classic.spi;
import java.io.IOException;
+import java.io.InvalidObjectException;
import java.io.ObjectInputStream;
import java.io.ObjectOutputStream;
import java.io.Serializable;
@@ -38,6 +39,7 @@ public class LoggingEventVO implements ILoggingEvent, Serializable {
private static final int NULL_ARGUMENT_ARRAY = -1;
private static final String NULL_ARGUMENT_ARRAY_ELEMENT = "NULL_ARGUMENT_ARRAY_ELEMENT";
+ private static final int ARGUMENT_ARRAY_DESERIALIZATION_LIMIT = 128;
private String threadName;
private String loggerName;
@@ -181,6 +183,11 @@ private void readObject(ObjectInputStream in) throws IOException, ClassNotFoundE
level = Level.toLevel(levelInt);
int argArrayLen = in.readInt();
+ // Prevent DOS attacks via large or negative arrays
+ if (argArrayLen < NULL_ARGUMENT_ARRAY || argArrayLen > ARGUMENT_ARRAY_DESERIALIZATION_LIMIT) {
+ throw new InvalidObjectException("Argument array length is invalid: " + argArrayLen);
+ }
+
if (argArrayLen != NULL_ARGUMENT_ARRAY) {
argumentArray = new String[argArrayLen];
for (int i = 0; i < argArrayLen; i++) {
diff --git a/logback-classic/src/test/input/issue/logback-1754.xml b/logback-classic/src/test/input/issue/logback-1754.xml
new file mode 100644
index 0000000000..ab41185a34
--- /dev/null
+++ b/logback-classic/src/test/input/issue/logback-1754.xml
@@ -0,0 +1,30 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<!--
+ ~ Logback: the reliable, generic, fast and flexible logging framework.
+ ~ Copyright (C) 1999-2023, QOS.ch. All rights reserved.
+ ~
+ ~ This program and the accompanying materials are dual-licensed under
+ ~ either the terms of the Eclipse Public License v1.0 as published by
+ ~ the Eclipse Foundation
+ ~
+ ~ or (per the licensee's choosing)
+ ~
+ ~ under the terms of the GNU Lesser General Public License version 2.1
+ ~ as published by the Free Software Foundation.
+ -->
+
+<configuration debug="true">
+ <appender name="GENERAL" class="ch.qos.logback.core.rolling.RollingFileAppender">
+ <rollingPolicy class="ch.qos.logback.core.rolling.TimeBasedRollingPolicy">
+ <fileNamePattern>${logback_1754_targetDirectory}/test-%d{yyyy-MM-dd}.log</fileNamePattern>
+ <maxHistory>120</maxHistory>
+ </rollingPolicy>
+ <encoder>
+ <pattern>%date{HH:mm:ss.SSS} [%level] %logger{0} [%thread] [%class{3}:%line] : %msg%n</pattern>
+ </encoder>
+ <prudent>true</prudent>
+ </appender>
+ <root level="debug">
+ <appender-ref ref="GENERAL" />
+ </root>
+</configuration>
\ No newline at end of file
diff --git a/logback-classic/src/test/java/ch/qos/logback/classic/issue/logback_1754/LogbackTest.java b/logback-classic/src/test/java/ch/qos/logback/classic/issue/logback_1754/LogbackTest.java
new file mode 100644
index 0000000000..3001c00a66
--- /dev/null
+++ b/logback-classic/src/test/java/ch/qos/logback/classic/issue/logback_1754/LogbackTest.java
@@ -0,0 +1,78 @@
+/*
+ * Logback: the reliable, generic, fast and flexible logging framework.
+ * Copyright (C) 1999-2023, QOS.ch. All rights reserved.
+ *
+ * This program and the accompanying materials are dual-licensed under
+ * either the terms of the Eclipse Public License v1.0 as published by
+ * the Eclipse Foundation
+ *
+ * or (per the licensee's choosing)
+ *
+ * under the terms of the GNU Lesser General Public License version 2.1
+ * as published by the Free Software Foundation.
+ */
+
+package ch.qos.logback.classic.issue.logback_1754;
+
+import ch.qos.logback.classic.ClassicConstants;
+import ch.qos.logback.classic.ClassicTestConstants;
+import ch.qos.logback.core.testUtil.RandomUtil;
+import org.slf4j.Logger;
+import org.slf4j.LoggerFactory;
+
+import java.util.ArrayList;
+import java.util.List;
+import java.util.concurrent.CountDownLatch;
+
+import static ch.qos.logback.classic.util.ContextInitializer.CONFIG_FILE_PROPERTY;
+
+public class LogbackTest {
+
+ private static final int THREADS = 16;
+
+ private void runTest() {
+
+ int diff = RandomUtil.getPositiveInt();
+ //System.setProperty("logback.statusListenerClass", "sysout");
+ System.setProperty(CONFIG_FILE_PROPERTY, ClassicTestConstants.INPUT_PREFIX+"issue/logback-1754.xml");
+ System.setProperty("logback_1754_targetDirectory", ClassicTestConstants.OUTPUT_DIR_PREFIX+"safeWrite_"+diff);
+
+ CountDownLatch latch = new CountDownLatch(THREADS);
+ List<Thread> threads = new ArrayList<Thread>(THREADS);
+ for (int i = 0; i < THREADS; i++) {
+ LoggerThread thread = new LoggerThread(latch, "message from thread " + i);
+ thread.start();
+ threads.add(thread);
+ }
+ for (Thread thread : threads) {
+ try {
+ thread.join();
+ } catch (InterruptedException e) {
+ Thread.currentThread().interrupt();
+ throw new RuntimeException(e);
+ }
+ }
+ }
+
+ public static void main(String... args) {
+ new LogbackTest().runTest();
+ }
+
+ private static final class LoggerThread extends Thread {
+ private static final Logger LOG = LoggerFactory.getLogger(LoggerThread.class);
+ private final CountDownLatch latch;
+ private final String message;
+
+ LoggerThread(CountDownLatch latch, String message) {
+ setDaemon(false);
+ this.latch = latch;
+ this.message = message;
+ }
+
+ @Override
+ public void run() {
+ latch.countDown();
+ LOG.info(message);
+ }
+ }
+}
diff --git a/logback-core/src/main/java/ch/qos/logback/core/net/HardenedObjectInputStream.java b/logback-core/src/main/java/ch/qos/logback/core/net/HardenedObjectInputStream.java
index d1b7301ea4..0674aaf3ea 100755
--- a/logback-core/src/main/java/ch/qos/logback/core/net/HardenedObjectInputStream.java
+++ b/logback-core/src/main/java/ch/qos/logback/core/net/HardenedObjectInputStream.java
@@ -1,10 +1,27 @@
+/**
+ * Logback: the reliable, generic, fast and flexible logging framework.
+ * Copyright (C) 1999-2023, QOS.ch. All rights reserved.
+ *
+ * This program and the accompanying materials are dual-licensed under
+ * either the terms of the Eclipse Public License v1.0 as published by
+ * the Eclipse Foundation
+ *
+ * or (per the licensee's choosing)
+ *
+ * under the terms of the GNU Lesser General Public License version 2.1
+ * as published by the Free Software Foundation.
+ */
package ch.qos.logback.core.net;
+import ch.qos.logback.core.util.EnvUtil;
+
import java.io.IOException;
import java.io.InputStream;
import java.io.InvalidClassException;
import java.io.ObjectInputStream;
import java.io.ObjectStreamClass;
+import java.lang.reflect.InvocationTargetException;
+import java.lang.reflect.Method;
import java.util.ArrayList;
import java.util.List;
@@ -22,10 +39,12 @@ public class HardenedObjectInputStream extends ObjectInputStream {
final List<String> whitelistedClassNames;
final static String[] JAVA_PACKAGES = new String[] { "java.lang", "java.util" };
+ final private static int DEPTH_LIMIT = 16;
+ final private static int ARRAY_LIMIT = 10000;
public HardenedObjectInputStream(InputStream in, String[] whilelist) throws IOException {
super(in);
-
+ initObjectFilter();
this.whitelistedClassNames = new ArrayList<String>();
if (whilelist != null) {
for (int i = 0; i < whilelist.length; i++) {
@@ -36,11 +55,43 @@ public HardenedObjectInputStream(InputStream in, String[] whilelist) throws IOEx
public HardenedObjectInputStream(InputStream in, List<String> whitelist) throws IOException {
super(in);
-
+ initObjectFilter();
this.whitelistedClassNames = new ArrayList<String>();
this.whitelistedClassNames.addAll(whitelist);
}
+ private void initObjectFilter() {
+
+ // invoke the following code by reflection
+ // this.setObjectInputFilter(ObjectInputFilter.Config.createFilter(
+ // "maxarray=" + ARRAY_LIMIT + ";maxdepth=" + DEPTH_LIMIT + ";"
+ // ));
+ if(EnvUtil.isJDK9OrHigher()) {
+ try {
+ ClassLoader classLoader = this.getClass().getClassLoader();
+
+ Class oifClass = classLoader.loadClass("java.io.ObjectInputFilter");
+ Class oifConfigClass = classLoader.loadClass("java.io.ObjectInputFilter$Config");
+ Method setObjectInputFilterMethod = this.getClass().getMethod("setObjectInputFilter", oifClass);
+
+ Method createFilterMethod = oifConfigClass.getMethod("createFilter", String.class);
+ Object filter = createFilterMethod.invoke(null, "maxarray=" + ARRAY_LIMIT + ";maxdepth=" + DEPTH_LIMIT + ";");
+ setObjectInputFilterMethod.invoke(this, filter);
+ } catch (ClassNotFoundException e) {
+ // this code should be unreachable
+ throw new RuntimeException("Failed to initialize object filter", e);
+ } catch (InvocationTargetException e) {
+ // this code should be unreachable
+ throw new RuntimeException("Failed to initialize object filter", e);
+ } catch (NoSuchMethodException e) {
+ // this code should be unreachable
+ throw new RuntimeException("Failed to initialize object filter", e);
+ } catch (IllegalAccessException e) {
+ // this code should be unreachable
+ throw new RuntimeException("Failed to initialize object filter", e);
+ }
+ }
+ }
@Override
protected Class<?> resolveClass(ObjectStreamClass anObjectStreamClass) throws IOException, ClassNotFoundException {
diff --git a/logback-core/src/main/java/ch/qos/logback/core/util/EnvUtil.java b/logback-core/src/main/java/ch/qos/logback/core/util/EnvUtil.java
index c200a1c984..f3dcd0cfe3 100644
--- a/logback-core/src/main/java/ch/qos/logback/core/util/EnvUtil.java
+++ b/logback-core/src/main/java/ch/qos/logback/core/util/EnvUtil.java
@@ -1,6 +1,6 @@
/**
* Logback: the reliable, generic, fast and flexible logging framework.
- * Copyright (C) 1999-2015, QOS.ch. All rights reserved.
+ * Copyright (C) 1999-2023, QOS.ch. All rights reserved.
*
* This program and the accompanying materials are dual-licensed under
* either the terms of the Eclipse Public License v1.0 as published by
@@ -22,22 +22,27 @@
public class EnvUtil {
static private boolean isJDK_N_OrHigher(int n) {
- List<String> versionList = new ArrayList<String>();
- // this code should work at least until JDK 10 (assuming n parameter is
- // always 6 or more)
- for (int i = 0; i < 5; i++) {
- versionList.add("1." + (n + i));
- }
-
- String javaVersion = System.getProperty("java.version");
- if (javaVersion == null) {
+ String javaVersionStr = System.getProperty("java.version", "");
+ if (javaVersionStr.isEmpty())
return false;
+
+ int version = getJDKVersion(javaVersionStr);
+ return version > 0 && n <= version;
+ }
+
+ static public int getJDKVersion(String javaVersionStr) {
+ int version = 0;
+
+ for (char ch : javaVersionStr.toCharArray()) {
+ if (Character.isDigit(ch)) {
+ version = (version * 10) + (ch - 48);
+ } else if (version == 1) {
+ version = 0;
+ } else {
+ break;
+ }
}
- for (String v : versionList) {
- if (javaVersion.startsWith(v))
- return true;
- }
- return false;
+ return version;
}
static public boolean isJDK5() {
@@ -52,6 +57,10 @@ static public boolean isJDK7OrHigher() {
return isJDK_N_OrHigher(7);
}
+ static public boolean isJDK9OrHigher() {
+ return isJDK_N_OrHigher(9);
+ }
+
static public boolean isJaninoAvailable() {
ClassLoader classLoader = EnvUtil.class.getClassLoader();
try {
diff --git a/logback-core/src/test/java/ch/qos/logback/core/net/HardenedObjectInputStreamTest.java b/logback-core/src/test/java/ch/qos/logback/core/net/HardenedObjectInputStreamTest.java
index ff4ddc599f..36f7f11b59 100755
--- a/logback-core/src/test/java/ch/qos/logback/core/net/HardenedObjectInputStreamTest.java
+++ b/logback-core/src/test/java/ch/qos/logback/core/net/HardenedObjectInputStreamTest.java
@@ -1,12 +1,17 @@
package ch.qos.logback.core.net;
import static org.junit.Assert.assertEquals;
+import static org.junit.Assert.fail;
import java.io.ByteArrayInputStream;
import java.io.ByteArrayOutputStream;
import java.io.IOException;
+import java.io.InvalidClassException;
import java.io.ObjectOutputStream;
+import java.util.HashSet;
+import java.util.Set;
+import ch.qos.logback.core.util.EnvUtil;
import org.junit.After;
import org.junit.Before;
import org.junit.Test;
@@ -54,5 +59,47 @@ private void writeObject(ObjectOutputStream oos, Object o) throws IOException {
oos.flush();
oos.close();
}
-
+
+ @Test
+ public void denialOfService() throws ClassNotFoundException, IOException {
+
+ if(!EnvUtil.isJDK9OrHigher()) {
+ return;
+ }
+
+ ByteArrayInputStream bis = new ByteArrayInputStream(payload());
+ inputStream = new HardenedObjectInputStream(bis, whitelist);
+ try {
+ inputStream.readObject();
+ fail("InvalidClassException expected");
+ } catch(InvalidClassException e) {
+ }
+ finally {
+ inputStream.close();
+ }
+ }
+
+ private byte[] payload() throws IOException {
+ Set root = buildEvilHashset();
+ writeObject(oos, root);
+ return bos.toByteArray();
+ }
+
+ private Set buildEvilHashset() {
+ Set root = new HashSet();
+ Set s1 = root;
+ Set s2 = new HashSet();
+ for (int i = 0; i < 100; i++) {
+ Set t1 = new HashSet();
+ Set t2 = new HashSet();
+ t1.add("foo"); // make it not equal to t2
+ s1.add(t1);
+ s1.add(t2);
+ s2.add(t1);
+ s2.add(t2);
+ s1 = t1;
+ s2 = t2;
+ }
+ return root;
+ }
}
diff --git a/logback-core/src/test/java/ch/qos/logback/core/rolling/ScaffoldingForRollingTests.java b/logback-core/src/test/java/ch/qos/logback/core/rolling/ScaffoldingForRollingTests.java
index 57389be3f7..504b52adc2 100755
--- a/logback-core/src/test/java/ch/qos/logback/core/rolling/ScaffoldingForRollingTests.java
+++ b/logback-core/src/test/java/ch/qos/logback/core/rolling/ScaffoldingForRollingTests.java
@@ -24,10 +24,10 @@
import java.io.File;
import java.io.IOException;
-import java.sql.Date;
import java.text.SimpleDateFormat;
import java.util.ArrayList;
import java.util.Calendar;
+import java.util.Date;
import java.util.Enumeration;
import java.util.List;
import java.util.concurrent.Future;
diff --git a/logback-core/src/test/java/ch/qos/logback/core/util/EnvUtilTest.java b/logback-core/src/test/java/ch/qos/logback/core/util/EnvUtilTest.java
new file mode 100644
index 0000000000..2ee4abd42e
--- /dev/null
+++ b/logback-core/src/test/java/ch/qos/logback/core/util/EnvUtilTest.java
@@ -0,0 +1,34 @@
+/**
+ * Logback: the reliable, generic, fast and flexible logging framework.
+ * Copyright (C) 1999-2023, QOS.ch. All rights reserved.
+ *
+ * This program and the accompanying materials are dual-licensed under
+ * either the terms of the Eclipse Public License v1.0 as published by
+ * the Eclipse Foundation
+ *
+ * or (per the licensee's choosing)
+ *
+ * under the terms of the GNU Lesser General Public License version 2.1
+ * as published by the Free Software Foundation.
+ */
+package ch.qos.logback.core.util;
+
+import org.junit.Test;
+
+import static org.junit.Assert.assertEquals;
+
+public class EnvUtilTest {
+
+
+ @Test
+ public void jdkVersion() {
+ assertEquals(4, EnvUtil.getJDKVersion("1.4.xx"));
+ assertEquals(5, EnvUtil.getJDKVersion("1.5"));
+ assertEquals(5, EnvUtil.getJDKVersion("1.5.xx"));
+ assertEquals(5, EnvUtil.getJDKVersion("1.5AA"));
+ assertEquals(9, EnvUtil.getJDKVersion("9EA"));
+ assertEquals(9, EnvUtil.getJDKVersion("9.0.1"));
+ assertEquals(18, EnvUtil.getJDKVersion("18.3+xx"));
+ assertEquals(21, EnvUtil.getJDKVersion("21.0.1"));
+ }
+}

71
logback-1.2.8-jetty.patch Normal file
View File

@ -0,0 +1,71 @@
--- logback-1.2.8/logback-access/pom.xml 2021-12-14 12:55:51.000000000 +0100
+++ logback-1.2.8/logback-access/pom.xml 2021-12-16 15:35:11.255651389 +0100
@@ -47,6 +47,12 @@
<optional>true</optional>
</dependency>
<dependency>
+ <groupId>org.eclipse.jetty</groupId>
+ <artifactId>jetty-util</artifactId>
+ <scope>compile</scope>
+ <optional>true</optional>
+ </dependency>
+ <dependency>
<groupId>org.codehaus.janino</groupId>
<artifactId>janino</artifactId>
<scope>compile</scope>
--- logback-1.2.8/logback-access/src/main/java/ch/qos/logback/access/jetty/RequestLogImpl.java 2021-12-14 12:55:51.000000000 +0100
+++ logback-1.2.8/logback-access/src/main/java/ch/qos/logback/access/jetty/RequestLogImpl.java 2021-12-16 15:35:11.255651389 +0100
@@ -209,11 +209,6 @@
started = false;
}
- @Override
- public boolean isRunning() {
- return started;
- }
-
public void setFileName(String fileName) {
this.fileName = fileName;
}
@@ -227,26 +222,6 @@
return started;
}
- @Override
- public boolean isStarting() {
- return false;
- }
-
- @Override
- public boolean isStopping() {
- return false;
- }
-
- @Override
- public boolean isStopped() {
- return !started;
- }
-
- @Override
- public boolean isFailed() {
- return false;
- }
-
public boolean isQuiet() {
return quiet;
}
@@ -310,13 +285,7 @@
return fai.getFilterChainDecision(event);
}
- @Override
- public void addLifeCycleListener(Listener listener) {
- // we'll implement this when asked
- }
-
- @Override
- public void removeLifeCycleListener(Listener listener) {
+ public void log(Request request, int status, long written) {
// we'll implement this when asked
}

138
logback.spec Normal file
View File

@ -0,0 +1,138 @@
Name: logback
Version: 1.2.8
Release: 3
Summary: A Java logging library
License: LGPLv2 or EPL-1.0
URL: http://logback.qos.ch/
Source0: https://github.com/qos-ch/logback/archive/v_%{version}.tar.gz
Patch0001: logback-1.2.8-jetty.patch
Patch0002: CVE-2023-6378-and-CVE-2023-6481.patch
BuildRequires: java-devel >= 1:1.6.0 maven-local mvn(javax.mail:mail)
BuildRequires: mvn(javax.servlet:javax.servlet-api) mvn(junit:junit) mvn(log4j:log4j:1.2.17)
BuildRequires: mvn(org.apache.ant:ant-junit) mvn(org.apache.felix:maven-bundle-plugin)
BuildRequires: mvn(org.apache.felix:org.apache.felix.main)
BuildRequires: mvn(org.apache.geronimo.specs:geronimo-jms_1.1_spec)
BuildRequires: mvn(org.apache.maven.plugins:maven-antrun-plugin)
BuildRequires: mvn(org.apache.tomcat:tomcat-catalina) mvn(org.apache.tomcat:tomcat-coyote)
BuildRequires: mvn(org.codehaus.gmavenplus:gmavenplus-plugin) mvn(org.codehaus.groovy:groovy-all)
BuildRequires: mvn(org.codehaus.janino:janino) mvn(org.eclipse.jetty:jetty-server)
BuildRequires: mvn(org.eclipse.jetty:jetty-util) mvn(org.fusesource:fusesource-pom:pom:)
BuildRequires: mvn(org.fusesource.jansi:jansi) mvn(org.slf4j:slf4j-api) mvn(org.slf4j:slf4j-ext)
BuildRequires: mvn(antlr:antlr) mvn(commons-cli:commons-cli) mvn(org.ow2.asm:asm-all)
BuildRequires: mvn(org.slf4j:slf4j-nop)
BuildArch: noarch
%description
Logback is intended as a successor to the popular log4j project.
Logback's architecture is sufficiently generic so as to apply under
different circumstances. At present time, logback is divided into
three modules, logback-core, logback-classic and logback-access.
The logback-core module lays the groundwork for the other two modules. The
logback-classic module can be assimilated to a significantly improved
version of log4j. Moreover, logback-classic natively implements the SLF4J
API so that you can readily switch back and forth between logback and other
logging frameworks such as log4j or java.util.logging (JUL).
The logback-access module integrates with Servlet containers, such as
Tomcat and Jetty, to provide HTTP-access log functionality. Note that you
could easily build your own module on top of logback-core.
%package help
Summary: Javadoc for %{name}
Provides: %{name}-javadoc = %{version}-%{release}
Obsoletes: %{name}-javadoc < %{version}-%{release}
%description help
API documentation for the Logback library
%package access
Summary: Logback-access module for Servlet integration
%description access
The logback-access module is integrated with servlet containers
(such as Tomcat and Jetty) to provide HTTP-access logging capabilities.
Note that you can easily build your own modules on top of logback-core.
%package examples
Summary: Logback Examples Module
%description examples
logback-examples module.
%prep
%autosetup -p1 -n %{name}-v_%{version}
find . -name "*.class" -delete
find . -name "*.cmd" -delete
find . -name "*.jar" -delete
%pom_remove_plugin :maven-source-plugin
%pom_remove_plugin :findbugs-maven-plugin
%pom_remove_plugin -r :maven-dependency-plugin
%pom_remove_plugin -r :cobertura-maven-plugin
sed -i 's/\r//' LICENSE.txt
sed -i 's#javax.servlet.*;version="2.5"#javax.servlet.*;version="3.1"#' %{name}-access/pom.xml
rm -r %{name}-*/src/test/java/*
%pom_xpath_remove -r "pom:dependency[pom:type = 'test-jar']"
%pom_xpath_remove -r "pom:dependency[pom:scope = 'test']"
%pom_xpath_remove -r "pom:plugin[pom:artifactId = 'maven-jar-plugin']/pom:executions"
%pom_xpath_remove "pom:project/pom:profiles/pom:profile[pom:id = 'host-orion']" %{name}-access
%pom_xpath_remove "pom:project/pom:profiles" %{name}-classic
%pom_xpath_remove "pom:project/pom:profiles/pom:profile[pom:id = 'javadocjar']"
%pom_xpath_remove "pom:executions/pom:execution/pom:goals/pom:goal[text() = 'generateTestStubs']" logback-classic
%pom_xpath_remove "pom:executions/pom:execution/pom:goals/pom:goal[text() = 'compileTests']" logback-classic
%pom_disable_module logback-site
%pom_xpath_remove "pom:build/pom:extensions"
%mvn_package ":%{name}-access" access
%mvn_package ":%{name}-examples" examples
%build
%mvn_build -f -- -Dorg.slf4j:slf4j-api:jar=$(build-classpath slf4j/api) \
-Dorg.apache.felix:org.apache.felix.main:jar=$(build-classpath felix/org.apache.felix.main)
%install
%mvn_install
install -d -m 755 %{buildroot}%{_datadir}/%{name}/examples
cp -r %{name}-examples/pom.xml %{name}-examples/src %{buildroot}%{_datadir}/%{name}/examples
%files -f .mfiles
%license LICENSE.txt
%files access -f .mfiles-access
%license LICENSE.txt
%files examples -f .mfiles-examples
%license LICENSE.txt
%{_datadir}/%{name}
%files help -f .mfiles-javadoc
%changelog
* Tue Dec 12 2023 wangkai <13474090681@163.com> - 1.2.8-3
- Fix CVE-2023-6378,CVE-2023-6481
* Mon Aug 8 2022 Chenyx <chenyixiong3@huawei.com> - 1.2.8-2
- License compliance rectification
* Mon Dec 27 2021 houyingchao <houyingchao@huawei.com> - 1.2.8-1
- Upgrade to 1.2.8
- Fix CVE-2021-42550
* Sat Sep 19 2020 wangxiao <wangxiao65@huawei.com> - 1.1.7-7
- fix CVE-2017-5929
* Wed Mar 4 2020 dingyiming <dingyiming3@huawei.com> - 1.1.7-6
- Package init

4
logback.yaml Normal file
View File

@ -0,0 +1,4 @@
version_control: github
src_repo: qos-ch/logback/
tag_prefix: ^v_
separator: .

BIN
v_1.2.8.tar.gz Normal file

Binary file not shown.