games-simulation/pmars-sdl: compile with format-security. Bug #544358
authorTupone Alfredo <tupone@gentoo.org>
Wed, 28 Oct 2015 12:29:54 +0000 (13:29 +0100)
committerTupone Alfredo <tupone@gentoo.org>
Wed, 28 Oct 2015 12:30:10 +0000 (13:30 +0100)
Package-Manager: portage-2.2.20.1

games-simulation/pmars-sdl/files/pmars-sdl-0.9.2e-format.patch [new file with mode: 0644]
games-simulation/pmars-sdl/pmars-sdl-0.9.2e.ebuild

diff --git a/games-simulation/pmars-sdl/files/pmars-sdl-0.9.2e-format.patch b/games-simulation/pmars-sdl/files/pmars-sdl-0.9.2e-format.patch
new file mode 100644 (file)
index 0000000..d8c588a
--- /dev/null
@@ -0,0 +1,65 @@
+--- src/asm.c.old      2015-10-28 13:23:53.465014342 +0100
++++ src/asm.c  2015-10-28 13:23:10.502813377 +0100
+@@ -652,7 +652,7 @@
+   macputs(str);
+ #else
+   if (!inCdb)
+-    fprintf(stderr, str);
++    fprintf(stderr, "%s", str);
+ #if defined DOSALLGRAPHX
+   else {
+     if (displayMode == TEXT)
+@@ -833,7 +833,7 @@
+ #ifdef __MAC__
+     textout(notEnoughMemErr);
+ #else
+-    fprintf(stderr, notEnoughMemErr);
++    fprintf(stderr, "%s", notEnoughMemErr);
+ #endif
+     Exit(MEMERR);
+     break;
+@@ -916,7 +916,7 @@
+   }
+ 
+   if (ierr >= ERRMAX) {
+-    sprintf(outs, tooManyMsgErr);
++    sprintf(outs, "%s", tooManyMsgErr);
+ #ifndef VMS
+     textout(outs);
+ #else
+--- src/cdb.c.old      2015-10-28 13:24:04.669805966 +0100
++++ src/cdb.c  2015-10-28 13:23:10.502813377 +0100
+@@ -2760,7 +2760,7 @@
+       fprintf(outp, nameByAuthorScores, warrior[idxV[i]].name, warrior[idxV[i]].authorName,
+               scrV[idxV[i]]);
+       if (warriors > 2) {
+-        fprintf(outp, resultsAre);
++        fprintf(outp, "%s", resultsAre);
+         for (j = 0; j < warriors; ++j) {
+           fprintf(outp, " %d", warrior[idxV[i]].score[j]);
+         }
+--- src/clparse.c.old  2015-10-28 13:24:10.648694768 +0100
++++ src/clparse.c      2015-10-28 13:23:10.502813377 +0100
+@@ -289,7 +289,7 @@
+               if (next_input(filep, inputs)) {
+                 if (!strcmp(inputs, "-")) {
+                   newFile = stdin;
+-                  fprintf(stderr, readingStdin);
++                  fprintf(stderr, "%s", readingStdin);
+                 } else {
+                   if ((newFile = fopen(inputs, "r")) == NULL) {
+                     code = FILENAME;        /* command file not found */
+@@ -430,11 +430,11 @@
+     errout(outs);
+     break;
+   case MEMORY:
+-    sprintf(outs, outOfMemory);
++    sprintf(outs, "%s", outOfMemory);
+     errout(outs);
+     break;
+   case FILENAME:
+-    sprintf(outs, cannotOpenParameterFile);
++    sprintf(outs, "%s", cannotOpenParameterFile);
+     errout(outs);
+     break;
+   }
index 3efe83a1c9d54f1c4207530410a98366d4845e81..3429dd0f2a9db3e7d0a25e4854d3a146b1a6753d 100644 (file)
@@ -3,7 +3,7 @@
 # $Id$
 
 EAPI=5
-inherit toolchain-funcs games
+inherit toolchain-funcs games eutils
 
 MY_PN="${PN/-sdl/}"
 MY_PV="${PV/e/-5}"
@@ -24,6 +24,10 @@ DEPEND="sdl? ( x11-libs/libX11 media-libs/libsdl[video] )
 
 S=${WORKDIR}/${MY_P}
 
+src_prepare() {
+       epatch "${FILESDIR}"/${P}-format.patch
+}
+
 src_compile() {
        CFLAGS="${CFLAGS} -DEXT94 -DPERMUTATE"
        LFLAGS="-x"