52cd1a
# ./pullrev.sh 1692801 1694012
52cd1a
52cd1a
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-3187
52cd1a
52cd1a
http://svn.apache.org/viewvc?view=revision&revision=1692801
52cd1a
52cd1a
- excluding changes from CVE-2015-3184
52cd1a
52cd1a
diff -uap subversion-1.7.14/subversion/libsvn_repos/rev_hunt.c.cve3187 subversion-1.7.14/subversion/libsvn_repos/rev_hunt.c
52cd1a
--- subversion-1.7.14/subversion/libsvn_repos/rev_hunt.c.cve3187
52cd1a
+++ subversion-1.7.14/subversion/libsvn_repos/rev_hunt.c
52cd1a
@@ -721,23 +721,6 @@ svn_repos_trace_node_locations(svn_fs_t
52cd1a
       if (! prev_path)
52cd1a
         break;
52cd1a
 
52cd1a
-      if (authz_read_func)
52cd1a
-        {
52cd1a
-          svn_boolean_t readable;
52cd1a
-          svn_fs_root_t *tmp_root;
52cd1a
-
52cd1a
-          SVN_ERR(svn_fs_revision_root(&tmp_root, fs, revision, currpool));
52cd1a
-          SVN_ERR(authz_read_func(&readable, tmp_root, path,
52cd1a
-                                  authz_read_baton, currpool));
52cd1a
-          if (! readable)
52cd1a
-            {
52cd1a
-              svn_pool_destroy(lastpool);
52cd1a
-              svn_pool_destroy(currpool);
52cd1a
-
52cd1a
-              return SVN_NO_ERROR;
52cd1a
-            }
52cd1a
-        }
52cd1a
-
52cd1a
       /* Assign the current path to all younger revisions until we reach
52cd1a
          the copy target rev. */
52cd1a
       while ((revision_ptr < revision_ptr_end)
52cd1a
@@ -760,6 +743,20 @@ svn_repos_trace_node_locations(svn_fs_t
52cd1a
       path = prev_path;
52cd1a
       revision = prev_rev;
52cd1a
 
52cd1a
+      if (authz_read_func)
52cd1a
+        {
52cd1a
+          svn_boolean_t readable;
52cd1a
+          SVN_ERR(svn_fs_revision_root(&root, fs, revision, currpool));
52cd1a
+          SVN_ERR(authz_read_func(&readable, root, path,
52cd1a
+                                  authz_read_baton, currpool));
52cd1a
+          if (!readable)
52cd1a
+            {
52cd1a
+              svn_pool_destroy(lastpool);
52cd1a
+              svn_pool_destroy(currpool);
52cd1a
+              return SVN_NO_ERROR;
52cd1a
+            }
52cd1a
+        }
52cd1a
+
52cd1a
       /* Clear last pool and switch. */
52cd1a
       svn_pool_clear(lastpool);
52cd1a
       tmppool = lastpool;
52cd1a
diff -uap subversion-1.7.14/subversion/tests/cmdline/authz_tests.py.cve3187 subversion-1.7.14/subversion/tests/cmdline/authz_tests.py
52cd1a
--- subversion-1.7.14/subversion/tests/cmdline/authz_tests.py.cve3187
52cd1a
+++ subversion-1.7.14/subversion/tests/cmdline/authz_tests.py
52cd1a
@@ -608,8 +608,10 @@ def authz_log_and_tracing_test(sbox):
52cd1a
 
52cd1a
   ## cat
52cd1a
 
52cd1a
+  expected_err2 = ".*svn: E195012: Unable to find repository location.*"
52cd1a
+
52cd1a
   # now see if we can look at the older version of rho
52cd1a
-  svntest.actions.run_and_verify_svn(None, None, expected_err,
52cd1a
+  svntest.actions.run_and_verify_svn(None, None, expected_err2,
52cd1a
                                      'cat', '-r', '2', D_url+'/rho')
52cd1a
 
52cd1a
   if sbox.repo_url.startswith('http'):
52cd1a
@@ -626,10 +628,11 @@ def authz_log_and_tracing_test(sbox):
52cd1a
   svntest.actions.run_and_verify_svn(None, None, expected_err,
52cd1a
                                      'diff', '-r', 'HEAD', G_url+'/rho')
52cd1a
 
52cd1a
-  svntest.actions.run_and_verify_svn(None, None, expected_err,
52cd1a
+  # diff treats the unreadable path as indicating an add so no error
52cd1a
+  svntest.actions.run_and_verify_svn(None, None, [],
52cd1a
                                      'diff', '-r', '2', D_url+'/rho')
52cd1a
 
52cd1a
-  svntest.actions.run_and_verify_svn(None, None, expected_err,
52cd1a
+  svntest.actions.run_and_verify_svn(None, None, [],
52cd1a
                                      'diff', '-r', '2:4', D_url+'/rho')
52cd1a
 
52cd1a
 # test whether read access is correctly granted and denied
52cd1a
diff -uap subversion-1.7.14/subversion/tests/libsvn_repos/repos-test.c.cve3187 subversion-1.7.14/subversion/tests/libsvn_repos/repos-test.c
52cd1a
--- subversion-1.7.14/subversion/tests/libsvn_repos/repos-test.c.cve3187
52cd1a
+++ subversion-1.7.14/subversion/tests/libsvn_repos/repos-test.c
52cd1a
@@ -2526,6 +2526,246 @@ issue_4060(const svn_test_opts_t *opts,
52cd1a
   return SVN_NO_ERROR;
52cd1a
 }
52cd1a
 
52cd1a
+static svn_error_t *
52cd1a
+mkdir_delete_copy(svn_repos_t *repos,
52cd1a
+                  const char *src,
52cd1a
+                  const char *dst,
52cd1a
+                  apr_pool_t *pool)
52cd1a
+{
52cd1a
+  svn_fs_t *fs = svn_repos_fs(repos);
52cd1a
+  svn_revnum_t youngest_rev;
52cd1a
+  svn_fs_txn_t *txn;
52cd1a
+  svn_fs_root_t *txn_root, *rev_root;
52cd1a
+
52cd1a
+  SVN_ERR(svn_fs_youngest_rev(&youngest_rev, fs, pool));
52cd1a
+  
52cd1a
+  SVN_ERR(svn_fs_begin_txn(&txn, fs, youngest_rev, pool));
52cd1a
+  SVN_ERR(svn_fs_txn_root(&txn_root, txn, pool));
52cd1a
+  SVN_ERR(svn_fs_make_dir(txn_root, "A/T", pool));
52cd1a
+  SVN_ERR(svn_repos_fs_commit_txn(NULL, repos, &youngest_rev, txn, pool));
52cd1a
+
52cd1a
+  SVN_ERR(svn_fs_begin_txn(&txn, fs, youngest_rev, pool));
52cd1a
+  SVN_ERR(svn_fs_txn_root(&txn_root, txn, pool));
52cd1a
+  SVN_ERR(svn_fs_delete(txn_root, "A/T", pool));
52cd1a
+  SVN_ERR(svn_repos_fs_commit_txn(NULL, repos, &youngest_rev, txn, pool));
52cd1a
+
52cd1a
+  SVN_ERR(svn_fs_begin_txn(&txn, fs, youngest_rev, pool));
52cd1a
+  SVN_ERR(svn_fs_txn_root(&txn_root, txn, pool));
52cd1a
+  SVN_ERR(svn_fs_revision_root(&rev_root, fs, youngest_rev - 1, pool));
52cd1a
+  SVN_ERR(svn_fs_copy(rev_root, src, txn_root, dst, pool));
52cd1a
+  SVN_ERR(svn_repos_fs_commit_txn(NULL, repos, &youngest_rev, txn, pool));
52cd1a
+
52cd1a
+  return SVN_NO_ERROR;
52cd1a
+}
52cd1a
+
52cd1a
+struct authz_read_baton_t {
52cd1a
+  apr_hash_t *paths;
52cd1a
+  apr_pool_t *pool;
52cd1a
+  const char *deny;
52cd1a
+};
52cd1a
+
52cd1a
+static svn_error_t *
52cd1a
+authz_read_func(svn_boolean_t *allowed,
52cd1a
+                svn_fs_root_t *root,
52cd1a
+                const char *path,
52cd1a
+                void *baton,
52cd1a
+                apr_pool_t *pool)
52cd1a
+{
52cd1a
+  struct authz_read_baton_t *b = baton;
52cd1a
+
52cd1a
+  if (b->deny && !strcmp(b->deny, path))
52cd1a
+    *allowed = FALSE;
52cd1a
+  else
52cd1a
+    *allowed = TRUE;
52cd1a
+
52cd1a
+  apr_hash_set(b->paths, apr_pstrdup(b->pool, path), APR_HASH_KEY_STRING,
52cd1a
+               (void*)1);
52cd1a
+
52cd1a
+  return SVN_NO_ERROR;
52cd1a
+}
52cd1a
+
52cd1a
+static svn_error_t *
52cd1a
+verify_locations(apr_hash_t *actual,
52cd1a
+                 apr_hash_t *expected,
52cd1a
+                 apr_hash_t *checked,
52cd1a
+                 apr_pool_t *pool)
52cd1a
+{
52cd1a
+  apr_hash_index_t *hi;
52cd1a
+
52cd1a
+  for (hi = apr_hash_first(pool, expected); hi; hi = apr_hash_next(hi))
52cd1a
+    {
52cd1a
+      const svn_revnum_t *rev = svn__apr_hash_index_key(hi);
52cd1a
+      const char *path = apr_hash_get(actual, rev, sizeof(svn_revnum_t));
52cd1a
+
52cd1a
+      if (!path)
52cd1a
+        return svn_error_createf(SVN_ERR_TEST_FAILED, NULL,
52cd1a
+                                 "expected %s for %d found (null)",
52cd1a
+                                 (char*)svn__apr_hash_index_val(hi),
52cd1a
+                                 (int)*rev);
52cd1a
+      else if (strcmp(path, svn__apr_hash_index_val(hi)))
52cd1a
+        return svn_error_createf(SVN_ERR_TEST_FAILED, NULL,
52cd1a
+                                 "expected %s for %d found %s",
52cd1a
+                                 (char*)svn__apr_hash_index_val(hi),
52cd1a
+                                 (int)*rev, path);
52cd1a
+
52cd1a
+    }
52cd1a
+
52cd1a
+  for (hi = apr_hash_first(pool, actual); hi; hi = apr_hash_next(hi))
52cd1a
+    {
52cd1a
+      const svn_revnum_t *rev = svn__apr_hash_index_key(hi);
52cd1a
+      const char *path = apr_hash_get(expected, rev, sizeof(svn_revnum_t));
52cd1a
+
52cd1a
+      if (!path)
52cd1a
+        return svn_error_createf(SVN_ERR_TEST_FAILED, NULL,
52cd1a
+                                 "found %s for %d expected (null)",
52cd1a
+                                 (char*)svn__apr_hash_index_val(hi),
52cd1a
+                                 (int)*rev);
52cd1a
+      else if (strcmp(path, svn__apr_hash_index_val(hi)))
52cd1a
+        return svn_error_createf(SVN_ERR_TEST_FAILED, NULL,
52cd1a
+                                 "found %s for %d expected %s",
52cd1a
+                                 (char*)svn__apr_hash_index_val(hi),
52cd1a
+                                 (int)*rev, path);
52cd1a
+
52cd1a
+      if (!apr_hash_get(checked, path, APR_HASH_KEY_STRING))
52cd1a
+        return svn_error_createf(SVN_ERR_TEST_FAILED, NULL,
52cd1a
+                                 "did not check %s", path);
52cd1a
+    }
52cd1a
+
52cd1a
+  return SVN_NO_ERROR;
52cd1a
+}
52cd1a
+
52cd1a
+static void
52cd1a
+set_expected(apr_hash_t *expected,
52cd1a
+             svn_revnum_t rev,
52cd1a
+             const char *path,
52cd1a
+             apr_pool_t *pool)
52cd1a
+{
52cd1a
+  svn_revnum_t *rp = apr_palloc(pool, sizeof(svn_revnum_t));
52cd1a
+  *rp = rev;
52cd1a
+  apr_hash_set(expected, rp, sizeof(svn_revnum_t), path);
52cd1a
+}
52cd1a
+
52cd1a
+static svn_error_t *
52cd1a
+trace_node_locations_authz(const svn_test_opts_t *opts,
52cd1a
+                           apr_pool_t *pool)
52cd1a
+{
52cd1a
+  svn_repos_t *repos;
52cd1a
+  svn_fs_t *fs;
52cd1a
+  svn_revnum_t youngest_rev = 0;
52cd1a
+  svn_fs_txn_t *txn;
52cd1a
+  svn_fs_root_t *txn_root;
52cd1a
+  struct authz_read_baton_t arb;
52cd1a
+  apr_array_header_t *revs = apr_array_make(pool, 10, sizeof(svn_revnum_t));
52cd1a
+  apr_hash_t *locations;
52cd1a
+  apr_hash_t *expected = apr_hash_make(pool);
52cd1a
+  int i;
52cd1a
+
52cd1a
+  /* Create test repository. */
52cd1a
+  SVN_ERR(svn_test__create_repos(&repos, "test-repo-trace-node-locations-authz",
52cd1a
+                                 opts, pool));
52cd1a
+  fs = svn_repos_fs(repos);
52cd1a
+
52cd1a
+  /* r1 create A */
52cd1a
+  SVN_ERR(svn_fs_begin_txn(&txn, fs, youngest_rev, pool));
52cd1a
+  SVN_ERR(svn_fs_txn_root(&txn_root, txn, pool));
52cd1a
+  SVN_ERR(svn_fs_make_dir(txn_root, "A", pool));
52cd1a
+  SVN_ERR(svn_fs_make_file(txn_root, "A/f", pool));
52cd1a
+  SVN_ERR(svn_test__set_file_contents(txn_root, "A/f", "foobar", pool));
52cd1a
+  SVN_ERR(svn_repos_fs_commit_txn(NULL, repos, &youngest_rev, txn, pool));
52cd1a
+
52cd1a
+  /* r4 copy A to B */
52cd1a
+  SVN_ERR(mkdir_delete_copy(repos, "A", "B", pool));
52cd1a
+
52cd1a
+  /* r7 copy B to C */
52cd1a
+  SVN_ERR(mkdir_delete_copy(repos, "B", "C", pool));
52cd1a
+
52cd1a
+  /* r10 copy C to D */
52cd1a
+  SVN_ERR(mkdir_delete_copy(repos, "C", "D", pool));
52cd1a
+
52cd1a
+  SVN_ERR(svn_fs_youngest_rev(&youngest_rev, fs, pool));
52cd1a
+  SVN_ERR_ASSERT(youngest_rev == 10);
52cd1a
+
52cd1a
+  arb.paths = apr_hash_make(pool);
52cd1a
+  arb.pool = pool;
52cd1a
+  arb.deny = NULL;
52cd1a
+
52cd1a
+  apr_array_clear(revs);
52cd1a
+  for (i = 0; i <= youngest_rev; ++i)
52cd1a
+    APR_ARRAY_PUSH(revs, svn_revnum_t) = i;
52cd1a
+  set_expected(expected, 10, "/D/f", pool);
52cd1a
+  set_expected(expected, 8, "/C/f", pool);
52cd1a
+  set_expected(expected, 7, "/C/f", pool);
52cd1a
+  set_expected(expected, 5, "/B/f", pool);
52cd1a
+  set_expected(expected, 4, "/B/f", pool);
52cd1a
+  set_expected(expected, 2, "/A/f", pool);
52cd1a
+  set_expected(expected, 1, "/A/f", pool);
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  apr_array_clear(revs);
52cd1a
+  for (i = 1; i <= youngest_rev; ++i)
52cd1a
+    APR_ARRAY_PUSH(revs, svn_revnum_t) = i;
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  apr_array_clear(revs);
52cd1a
+  for (i = 2; i <= youngest_rev; ++i)
52cd1a
+    APR_ARRAY_PUSH(revs, svn_revnum_t) = i;
52cd1a
+  set_expected(expected, 1, NULL, pool);
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  apr_array_clear(revs);
52cd1a
+  for (i = 3; i <= youngest_rev; ++i)
52cd1a
+    APR_ARRAY_PUSH(revs, svn_revnum_t) = i;
52cd1a
+  set_expected(expected, 2, NULL, pool);
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  apr_array_clear(revs);
52cd1a
+  for (i = 6; i <= youngest_rev; ++i)
52cd1a
+    APR_ARRAY_PUSH(revs, svn_revnum_t) = i;
52cd1a
+  set_expected(expected, 5, NULL, pool);
52cd1a
+  set_expected(expected, 4, NULL, pool);
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  arb.deny = "/B/f";
52cd1a
+  apr_array_clear(revs);
52cd1a
+  for (i = 0; i <= youngest_rev; ++i)
52cd1a
+    APR_ARRAY_PUSH(revs, svn_revnum_t) = i;
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  apr_array_clear(revs);
52cd1a
+  for (i = 6; i <= youngest_rev; ++i)
52cd1a
+    APR_ARRAY_PUSH(revs, svn_revnum_t) = i;
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  APR_ARRAY_PUSH(revs, svn_revnum_t) = 0;
52cd1a
+  apr_hash_clear(arb.paths);
52cd1a
+  SVN_ERR(svn_repos_trace_node_locations(fs, &locations, "D/f", 10, revs,
52cd1a
+                                         authz_read_func, &arb, pool));
52cd1a
+  SVN_ERR(verify_locations(locations, expected, arb.paths, pool));
52cd1a
+
52cd1a
+  return SVN_NO_ERROR;
52cd1a
+}
52cd1a
+
52cd1a
 
52cd1a
 /* The test table.  */
52cd1a
 
52cd1a
@@ -2562,5 +2802,7 @@ struct svn_test_descriptor_t test_funcs[
52cd1a
                        "test svn_repos_get_file_revsN"),
52cd1a
     SVN_TEST_OPTS_PASS(issue_4060,
52cd1a
                        "test issue 4060"),
52cd1a
+    SVN_TEST_OPTS_PASS(trace_node_locations_authz,
52cd1a
+                       "authz for svn_repos_trace_node_locations"),
52cd1a
     SVN_TEST_NULL
52cd1a
   };