Hello community,

here is the log from the commit of package libXxf86dga for openSUSE:Factory 
checked in at 2013-06-05 12:00:50
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libXxf86dga (Old)
 and      /work/SRC/openSUSE:Factory/.libXxf86dga.new (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libXxf86dga"

Changes:
--------
--- /work/SRC/openSUSE:Factory/libXxf86dga/libXxf86dga.changes  2013-03-22 
12:00:21.000000000 +0100
+++ /work/SRC/openSUSE:Factory/.libXxf86dga.new/libXxf86dga.changes     
2013-06-05 12:00:52.000000000 +0200
@@ -1,0 +2,7 @@
+Sat Jun  1 20:04:11 UTC 2013 - [email protected]
+
+- Update to version 1.1.4:
+  This release provides the fixes for the recently announced security issues
+  CVE-2013-1991 & CVE-2013-2000, along with a couple build fixes.
+
+-------------------------------------------------------------------

Old:
----
  libXxf86dga-1.1.3.tar.bz2

New:
----
  libXxf86dga-1.1.4.tar.bz2

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libXxf86dga.spec ++++++
--- /var/tmp/diff_new_pack.0xsYRo/_old  2013-06-05 12:00:53.000000000 +0200
+++ /var/tmp/diff_new_pack.0xsYRo/_new  2013-06-05 12:00:53.000000000 +0200
@@ -18,7 +18,7 @@
 
 Name:           libXxf86dga
 %define lname  libXxf86dga1
-Version:        1.1.3
+Version:        1.1.4
 Release:        0
 Summary:        XFree86-DGA extension client library
 License:        MIT

++++++ libXxf86dga-1.1.3.tar.bz2 -> libXxf86dga-1.1.4.tar.bz2 ++++++
++++ 13152 lines of diff (skipped)
++++    retrying with extended exclude list
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' --exclude Makefile.in --exclude configure --exclude 
config.guess --exclude '*.pot' --exclude mkinstalldirs --exclude aclocal.m4 
--exclude config.sub --exclude depcomp --exclude install-sh --exclude ltmain.sh 
old/libXxf86dga-1.1.3/ChangeLog new/libXxf86dga-1.1.4/ChangeLog
--- old/libXxf86dga-1.1.3/ChangeLog     2012-03-08 06:38:04.000000000 +0100
+++ new/libXxf86dga-1.1.4/ChangeLog     2013-05-31 03:36:52.000000000 +0200
@@ -1,3 +1,128 @@
+commit 0f2e21d7e8310cf7bc02bba56884be0e52c061ae
+Author: Alan Coopersmith <[email protected]>
+Date:   Thu May 30 18:36:19 2013 -0700
+
+    libXxf86dga 1.1.4
+    
+    Signed-off-by: Alan Coopersmith <[email protected]>
+
+commit a8dc6be3213bc91dec5e25535ef4bad5a9456af0
+Author: Alan Coopersmith <[email protected]>
+Date:   Sat Apr 13 12:53:49 2013 -0700
+
+    integer overflow in XDGAOpenFramebuffer()
+    
+    rep.length is a CARD32 and should be bounds checked before left shifting
+    to come up with the size to allocate and read from the network, though
+    since both functions take the same size, there should be no way for the
+    buffer to be overflowed in this case.
+    
+    Signed-off-by: Alan Coopersmith <[email protected]>
+
+commit b69d6d51a82b1d1e8c68a233360acb742c879375
+Author: Alan Coopersmith <[email protected]>
+Date:   Sat Apr 13 12:45:41 2013 -0700
+
+    buffer overflow in XDGASetMode() [CVE-2013-2000 2/2]
+    
+    When reading the name strings for the mode off the network, we never
+    checked to make sure the length of the name strings didn't overflow
+    the size of the buffer we'd allocated based on the reported rep.length
+    for the total reply size.
+    
+    Reported-by: Ilja Van Sprundel <[email protected]>
+    Signed-off-by: Alan Coopersmith <[email protected]>
+
+commit f89cf306a60facdf102696840bc05acebd7d1772
+Author: Alan Coopersmith <[email protected]>
+Date:   Sat Apr 13 12:38:25 2013 -0700
+
+    integer overflow & underflow in XDGASetMode() [CVE-2013-1991 2/2]
+    
+    rep.length is a CARD32 and needs to be bounds checked before bit shifting
+    and subtracting sz_xXDGAModeInfo to come up with the total size to 
allocate,
+    to avoid integer overflow or underflow leading to underallocation and
+    writing data from the network past the end of the allocated buffer.
+    
+    Reported-by: Ilja Van Sprundel <[email protected]>
+    Signed-off-by: Alan Coopersmith <[email protected]>
+
+commit 5dcfa6a8cf2df39828da733e5945e730518c27b3
+Author: Alan Coopersmith <[email protected]>
+Date:   Sat Apr 13 12:27:10 2013 -0700
+
+    buffer overflow in XDGAQueryModes() [CVE-2013-2000 1/2]
+    
+    When reading the name strings for the modes off the network, we never
+    checked to make sure the length of the individual name strings didn't
+    overflow the size of the buffer we'd allocated based on the reported
+    rep.length for the total reply size.
+    
+    Reported-by: Ilja Van Sprundel <[email protected]>
+    Signed-off-by: Alan Coopersmith <[email protected]>
+
+commit f4a8dd63af518640468d82948f450aad4b2b1e6a
+Author: Alan Coopersmith <[email protected]>
+Date:   Sat Apr 13 12:18:57 2013 -0700
+
+    integer overflow in XDGAQueryModes() [CVE-2013-1991 1/2]
+    
+    number is a CARD32 and needs to be bounds checked before multiplying by
+    sizeof(XDGAmode) to come up with the total size to allocate, to avoid
+    integer overflow leading to underallocation and writing data from the
+    network past the end of the allocated buffer.
+    
+    Reported-by: Ilja Van Sprundel <[email protected]>
+    Signed-off-by: Alan Coopersmith <[email protected]>
+
+commit 6fa471be7a005bde97bcb5ca5a17662ea8d32587
+Author: Alan Coopersmith <[email protected]>
+Date:   Sat Apr 13 12:05:25 2013 -0700
+
+    Use _XEatDataWords to avoid overflow of rep.length shifting
+    
+    rep.length is a CARD32, so rep.length << 2 could overflow in 32-bit builds
+    
+    Signed-off-by: Alan Coopersmith <[email protected]>
+
+commit 1e454b8da70e3f125dd512baa5e66f948878f9f5
+Author: Colin Walters <[email protected]>
+Date:   Wed Jan 4 17:37:06 2012 -0500
+
+    autogen.sh: Implement GNOME Build API
+    
+    http://people.gnome.org/~walters/docs/build-api.txt
+    
+    Signed-off-by: Adam Jackson <[email protected]>
+
+commit 968295ede4d96fd40483d97bc4d25ae32d86a9fa
+Author: Adam Jackson <[email protected]>
+Date:   Tue Jan 15 14:28:48 2013 -0500
+
+    configure: Remove AM_MAINTAINER_MODE
+    
+    Signed-off-by: Adam Jackson <[email protected]>
+
+commit d4f89f7f42484963575b4c7d2fa694051e111e76
+Author: Jeremy Huddleston <[email protected]>
+Date:   Fri Mar 9 02:48:14 2012 -0800
+
+    Include <stdint.h> for uintptr_t
+    
+    Found-by: Tinderbox
+    
+    Signed-off-by: Jeremy Huddleston <[email protected]>
+
+commit 56b5a5887349e9d0e1d28da157fe6441ca691f56
+Author: Jeremy Huddleston <[email protected]>
+Date:   Thu Mar 8 11:49:36 2012 -0800
+
+    Build fix when sizeof(off_t) > sizeof(void *)
+    
+    https://trac.macports.org/ticket/33532
+    
+    Signed-off-by: Jeremy Huddleston <[email protected]>
+
 commit 3dad5d7c34c5787f0466b9ff50d7c26cd18e37bd
 Author: Alan Coopersmith <[email protected]>
 Date:   Wed Mar 7 21:34:06 2012 -0800
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' --exclude Makefile.in --exclude configure --exclude 
config.guess --exclude '*.pot' --exclude mkinstalldirs --exclude aclocal.m4 
--exclude config.sub --exclude depcomp --exclude install-sh --exclude ltmain.sh 
old/libXxf86dga-1.1.3/configure.ac new/libXxf86dga-1.1.4/configure.ac
--- old/libXxf86dga-1.1.3/configure.ac  2012-03-08 06:35:46.000000000 +0100
+++ new/libXxf86dga-1.1.4/configure.ac  2013-05-31 03:36:29.000000000 +0200
@@ -1,14 +1,13 @@
 
 # Initialize Autoconf
 AC_PREREQ([2.60])
-AC_INIT([libXxf86dga], [1.1.3],
+AC_INIT([libXxf86dga], [1.1.4],
         [https://bugs.freedesktop.org/enter_bug.cgi?product=xorg], 
[libXxf86dga])
 AC_CONFIG_SRCDIR([Makefile.am])
 AC_CONFIG_HEADERS(src/config.h)
 
 # Initialize Automake
 AM_INIT_AUTOMAKE([foreign dist-bzip2])
-AM_MAINTAINER_MODE
 
 # Initialize libtool
 AC_PROG_LIBTOOL
@@ -23,6 +22,12 @@
 # Obtain compiler/linker options for depedencies
 PKG_CHECK_MODULES(XXF86DGA, xproto x11 xextproto xext [xf86dgaproto >= 
2.0.99.2])
 
+# Check for _XEatDataWords function that may be patched into older Xlib release
+SAVE_LIBS="$LIBS"
+LIBS="$XXF86DGA_LIBS"
+AC_CHECK_FUNCS([_XEatDataWords])
+LIBS="$SAVE_LIBS"
+
 AC_CONFIG_FILES([Makefile
                src/Makefile
                man/Makefile
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' --exclude Makefile.in --exclude configure --exclude 
config.guess --exclude '*.pot' --exclude mkinstalldirs --exclude aclocal.m4 
--exclude config.sub --exclude depcomp --exclude install-sh --exclude ltmain.sh 
old/libXxf86dga-1.1.3/missing new/libXxf86dga-1.1.4/missing
--- old/libXxf86dga-1.1.3/missing       2012-03-08 06:35:56.000000000 +0100
+++ new/libXxf86dga-1.1.4/missing       2013-05-31 03:36:38.000000000 +0200
@@ -1,11 +1,10 @@
 #! /bin/sh
-# Common stub for a few missing GNU programs while installing.
+# Common wrapper for a few potentially missing GNU programs.
 
-scriptversion=2009-04-28.21; # UTC
+scriptversion=2012-06-26.16; # UTC
 
-# Copyright (C) 1996, 1997, 1999, 2000, 2002, 2003, 2004, 2005, 2006,
-# 2008, 2009 Free Software Foundation, Inc.
-# Originally by Fran,cois Pinard <[email protected]>, 1996.
+# Copyright (C) 1996-2013 Free Software Foundation, Inc.
+# Originally written by Fran,cois Pinard <[email protected]>, 1996.
 
 # This program is free software; you can redistribute it and/or modify
 # it under the terms of the GNU General Public License as published by
@@ -26,69 +25,40 @@
 # the same distribution terms that you use for the rest of that program.
 
 if test $# -eq 0; then
-  echo 1>&2 "Try \`$0 --help' for more information"
+  echo 1>&2 "Try '$0 --help' for more information"
   exit 1
 fi
 
-run=:
-sed_output='s/.* --output[ =]\([^ ]*\).*/\1/p'
-sed_minuso='s/.* -o \([^ ]*\).*/\1/p'
-
-# In the cases where this matters, `missing' is being run in the
-# srcdir already.
-if test -f configure.ac; then
-  configure_ac=configure.ac
-else
-  configure_ac=configure.in
-fi
+case $1 in
 
-msg="missing on your system"
+  --is-lightweight)
+    # Used by our autoconf macros to check whether the available missing
+    # script is modern enough.
+    exit 0
+    ;;
 
-case $1 in
---run)
-  # Try to run requested program, and just exit if it succeeds.
-  run=
-  shift
-  "$@" && exit 0
-  # Exit code 63 means version mismatch.  This often happens
-  # when the user try to use an ancient version of a tool on
-  # a file that requires a minimum version.  In this case we
-  # we should proceed has if the program had been absent, or
-  # if --run hadn't been passed.
-  if test $? = 63; then
-    run=:
-    msg="probably too old"
-  fi
-  ;;
+  --run)
+    # Back-compat with the calling convention used by older automake.
+    shift
+    ;;
 
   -h|--h|--he|--hel|--help)
     echo "\
 $0 [OPTION]... PROGRAM [ARGUMENT]...
 
-Handle \`PROGRAM [ARGUMENT]...' for when PROGRAM is missing, or return an
-error status if there is no known handling for PROGRAM.
+Run 'PROGRAM [ARGUMENT]...', returning a proper advice when this fails due
+to PROGRAM being missing or too old.
 
 Options:
   -h, --help      display this help and exit
   -v, --version   output version information and exit
-  --run           try to run the given command, and emulate it if it fails
 
 Supported PROGRAM values:
-  aclocal      touch file \`aclocal.m4'
-  autoconf     touch file \`configure'
-  autoheader   touch file \`config.h.in'
-  autom4te     touch the output file, or create a stub one
-  automake     touch all \`Makefile.in' files
-  bison        create \`y.tab.[ch]', if possible, from existing .[ch]
-  flex         create \`lex.yy.c', if possible, from existing .c
-  help2man     touch the output file
-  lex          create \`lex.yy.c', if possible, from existing .c
-  makeinfo     touch the output file
-  tar          try tar, gnutar, gtar, then tar without non-portable flags
-  yacc         create \`y.tab.[ch]', if possible, from existing .[ch]
+  aclocal   autoconf  autoheader   autom4te  automake  makeinfo
+  bison     yacc      flex         lex       help2man
 
-Version suffixes to PROGRAM as well as the prefixes \`gnu-', \`gnu', and
-\`g' are ignored when checking the name.
+Version suffixes to PROGRAM as well as the prefixes 'gnu-', 'gnu', and
+'g' are ignored when checking the name.
 
 Send bug reports to <[email protected]>."
     exit $?
@@ -100,272 +70,141 @@
     ;;
 
   -*)
-    echo 1>&2 "$0: Unknown \`$1' option"
-    echo 1>&2 "Try \`$0 --help' for more information"
+    echo 1>&2 "$0: unknown '$1' option"
+    echo 1>&2 "Try '$0 --help' for more information"
     exit 1
     ;;
 
 esac
 
-# normalize program name to check for.
-program=`echo "$1" | sed '
-  s/^gnu-//; t
-  s/^gnu//; t
-  s/^g//; t'`
-
-# Now exit if we have it, but it failed.  Also exit now if we
-# don't have it and --version was passed (most likely to detect
-# the program).  This is about non-GNU programs, so use $1 not
-# $program.
-case $1 in
-  lex*|yacc*)
-    # Not GNU programs, they don't have --version.
-    ;;
-
-  tar*)
-    if test -n "$run"; then
-       echo 1>&2 "ERROR: \`tar' requires --run"
-       exit 1
-    elif test "x$2" = "x--version" || test "x$2" = "x--help"; then
-       exit 1
-    fi
-    ;;
+# Run the given program, remember its exit status.
+"$@"; st=$?
 
-  *)
-    if test -z "$run" && ($1 --version) > /dev/null 2>&1; then
-       # We have it, but it failed.
-       exit 1
-    elif test "x$2" = "x--version" || test "x$2" = "x--help"; then
-       # Could not run --version or --help.  This is probably someone
-       # running `$TOOL --version' or `$TOOL --help' to check whether
-       # $TOOL exists and not knowing $TOOL uses missing.
-       exit 1
-    fi
-    ;;
-esac
-
-# If it does not exist, or fails to run (possibly an outdated version),
-# try to emulate it.
-case $program in
-  aclocal*)
-    echo 1>&2 "\
-WARNING: \`$1' is $msg.  You should only need it if
-         you modified \`acinclude.m4' or \`${configure_ac}'.  You might want
-         to install the \`Automake' and \`Perl' packages.  Grab them from
-         any GNU archive site."
-    touch aclocal.m4
-    ;;
-
-  autoconf*)
-    echo 1>&2 "\
-WARNING: \`$1' is $msg.  You should only need it if
-         you modified \`${configure_ac}'.  You might want to install the
-         \`Autoconf' and \`GNU m4' packages.  Grab them from any GNU
-         archive site."
-    touch configure
-    ;;
-
-  autoheader*)
-    echo 1>&2 "\
-WARNING: \`$1' is $msg.  You should only need it if
-         you modified \`acconfig.h' or \`${configure_ac}'.  You might want
-         to install the \`Autoconf' and \`GNU m4' packages.  Grab them
-         from any GNU archive site."
-    files=`sed -n 's/^[ ]*A[CM]_CONFIG_HEADER(\([^)]*\)).*/\1/p' 
${configure_ac}`
-    test -z "$files" && files="config.h"
-    touch_files=
-    for f in $files; do
-      case $f in
-      *:*) touch_files="$touch_files "`echo "$f" |
-                                      sed -e 's/^[^:]*://' -e 's/:.*//'`;;
-      *) touch_files="$touch_files $f.in";;
-      esac
-    done
-    touch $touch_files
-    ;;
-
-  automake*)
-    echo 1>&2 "\
-WARNING: \`$1' is $msg.  You should only need it if
-         you modified \`Makefile.am', \`acinclude.m4' or \`${configure_ac}'.
-         You might want to install the \`Automake' and \`Perl' packages.
-         Grab them from any GNU archive site."
-    find . -type f -name Makefile.am -print |
-          sed 's/\.am$/.in/' |
-          while read f; do touch "$f"; done
-    ;;
+# If it succeeded, we are done.
+test $st -eq 0 && exit 0
 
-  autom4te*)
-    echo 1>&2 "\
-WARNING: \`$1' is needed, but is $msg.
-         You might have modified some files without having the
-         proper tools for further handling them.
-         You can get \`$1' as part of \`Autoconf' from any GNU
-         archive site."
-
-    file=`echo "$*" | sed -n "$sed_output"`
-    test -z "$file" && file=`echo "$*" | sed -n "$sed_minuso"`
-    if test -f "$file"; then
-       touch $file
-    else
-       test -z "$file" || exec >$file
-       echo "#! /bin/sh"
-       echo "# Created by GNU Automake missing as a replacement of"
-       echo "#  $ $@"
-       echo "exit 0"
-       chmod +x $file
-       exit 1
-    fi
-    ;;
-
-  bison*|yacc*)
-    echo 1>&2 "\
-WARNING: \`$1' $msg.  You should only need it if
-         you modified a \`.y' file.  You may need the \`Bison' package
-         in order for those modifications to take effect.  You can get
-         \`Bison' from any GNU archive site."
-    rm -f y.tab.c y.tab.h
-    if test $# -ne 1; then
-        eval LASTARG="\${$#}"
-       case $LASTARG in
-       *.y)
-           SRCFILE=`echo "$LASTARG" | sed 's/y$/c/'`
-           if test -f "$SRCFILE"; then
-                cp "$SRCFILE" y.tab.c
-           fi
-           SRCFILE=`echo "$LASTARG" | sed 's/y$/h/'`
-           if test -f "$SRCFILE"; then
-                cp "$SRCFILE" y.tab.h
-           fi
-         ;;
-       esac
-    fi
-    if test ! -f y.tab.h; then
-       echo >y.tab.h
-    fi
-    if test ! -f y.tab.c; then
-       echo 'main() { return 0; }' >y.tab.c
-    fi
-    ;;
-
-  lex*|flex*)
-    echo 1>&2 "\
-WARNING: \`$1' is $msg.  You should only need it if
-         you modified a \`.l' file.  You may need the \`Flex' package
-         in order for those modifications to take effect.  You can get
-         \`Flex' from any GNU archive site."
-    rm -f lex.yy.c
-    if test $# -ne 1; then
-        eval LASTARG="\${$#}"
-       case $LASTARG in
-       *.l)
-           SRCFILE=`echo "$LASTARG" | sed 's/l$/c/'`
-           if test -f "$SRCFILE"; then
-                cp "$SRCFILE" lex.yy.c
-           fi
-         ;;
-       esac
-    fi
-    if test ! -f lex.yy.c; then
-       echo 'main() { return 0; }' >lex.yy.c
-    fi
-    ;;
-
-  help2man*)
-    echo 1>&2 "\
-WARNING: \`$1' is $msg.  You should only need it if
-        you modified a dependency of a manual page.  You may need the
-        \`Help2man' package in order for those modifications to take
-        effect.  You can get \`Help2man' from any GNU archive site."
-
-    file=`echo "$*" | sed -n "$sed_output"`
-    test -z "$file" && file=`echo "$*" | sed -n "$sed_minuso"`
-    if test -f "$file"; then
-       touch $file
-    else
-       test -z "$file" || exec >$file
-       echo ".ab help2man is required to generate this page"
-       exit $?
-    fi
-    ;;
-
-  makeinfo*)
-    echo 1>&2 "\
-WARNING: \`$1' is $msg.  You should only need it if
-         you modified a \`.texi' or \`.texinfo' file, or any other file
-         indirectly affecting the aspect of the manual.  The spurious
-         call might also be the consequence of using a buggy \`make' (AIX,
-         DU, IRIX).  You might want to install the \`Texinfo' package or
-         the \`GNU make' package.  Grab either from any GNU archive site."
-    # The file to touch is that specified with -o ...
-    file=`echo "$*" | sed -n "$sed_output"`
-    test -z "$file" && file=`echo "$*" | sed -n "$sed_minuso"`
-    if test -z "$file"; then
-      # ... or it is the one specified with @setfilename ...
-      infile=`echo "$*" | sed 's/.* \([^ ]*\) *$/\1/'`
-      file=`sed -n '
-       /^@setfilename/{
-         s/.* \([^ ]*\) *$/\1/
-         p
-         q
-       }' $infile`
-      # ... or it is derived from the source name (dir/f.texi becomes f.info)
-      test -z "$file" && file=`echo "$infile" | sed 's,.*/,,;s,.[^.]*$,,'`.info
-    fi
-    # If the file does not exist, the user really needs makeinfo;
-    # let's fail without touching anything.
-    test -f $file || exit 1
-    touch $file
-    ;;
-
-  tar*)
-    shift
-
-    # We have already tried tar in the generic part.
-    # Look for gnutar/gtar before invocation to avoid ugly error
-    # messages.
-    if (gnutar --version > /dev/null 2>&1); then
-       gnutar "$@" && exit 0
-    fi
-    if (gtar --version > /dev/null 2>&1); then
-       gtar "$@" && exit 0
-    fi
-    firstarg="$1"
-    if shift; then
-       case $firstarg in
-       *o*)
-           firstarg=`echo "$firstarg" | sed s/o//`
-           tar "$firstarg" "$@" && exit 0
-           ;;
-       esac
-       case $firstarg in
-       *h*)
-           firstarg=`echo "$firstarg" | sed s/h//`
-           tar "$firstarg" "$@" && exit 0
-           ;;
-       esac
-    fi
-
-    echo 1>&2 "\
-WARNING: I can't seem to be able to run \`tar' with the given arguments.
-         You may want to install GNU tar or Free paxutils, or check the
-         command line arguments."
-    exit 1
-    ;;
-
-  *)
-    echo 1>&2 "\
-WARNING: \`$1' is needed, and is $msg.
-         You might have modified some files without having the
-         proper tools for further handling them.  Check the \`README' file,
-         it often tells you about the needed prerequisites for installing
-         this package.  You may also peek at any GNU archive site, in case
-         some other package would contain this missing \`$1' program."
-    exit 1
-    ;;
-esac
+# Also exit now if we it failed (or wasn't found), and '--version' was
+# passed; such an option is passed most likely to detect whether the
+# program is present and works.
+case $2 in --version|--help) exit $st;; esac
+
+# Exit code 63 means version mismatch.  This often happens when the user
+# tries to use an ancient version of a tool on a file that requires a
+# minimum version.
+if test $st -eq 63; then
+  msg="probably too old"
+elif test $st -eq 127; then
+  # Program was missing.
+  msg="missing on your system"
+else
+  # Program was found and executed, but failed.  Give up.
+  exit $st
+fi
 
-exit 0
+perl_URL=http://www.perl.org/
+flex_URL=http://flex.sourceforge.net/
+gnu_software_URL=http://www.gnu.org/software
+
+program_details ()
+{
+  case $1 in
+    aclocal|automake)
+      echo "The '$1' program is part of the GNU Automake package:"
+      echo "<$gnu_software_URL/automake>"
+      echo "It also requires GNU Autoconf, GNU m4 and Perl in order to run:"
+      echo "<$gnu_software_URL/autoconf>"
+      echo "<$gnu_software_URL/m4/>"
+      echo "<$perl_URL>"
+      ;;
+    autoconf|autom4te|autoheader)
+      echo "The '$1' program is part of the GNU Autoconf package:"
+      echo "<$gnu_software_URL/autoconf/>"
+      echo "It also requires GNU m4 and Perl in order to run:"
+      echo "<$gnu_software_URL/m4/>"
+      echo "<$perl_URL>"
+      ;;
+  esac
+}
+
+give_advice ()
+{
+  # Normalize program name to check for.
+  normalized_program=`echo "$1" | sed '
+    s/^gnu-//; t
+    s/^gnu//; t
+    s/^g//; t'`
+
+  printf '%s\n' "'$1' is $msg."
+
+  configure_deps="'configure.ac' or m4 files included by 'configure.ac'"
+  case $normalized_program in
+    autoconf*)
+      echo "You should only need it if you modified 'configure.ac',"
+      echo "or m4 files included by it."
+      program_details 'autoconf'
+      ;;
+    autoheader*)
+      echo "You should only need it if you modified 'acconfig.h' or"
+      echo "$configure_deps."
+      program_details 'autoheader'
+      ;;
+    automake*)
+      echo "You should only need it if you modified 'Makefile.am' or"
+      echo "$configure_deps."
+      program_details 'automake'
+      ;;
+    aclocal*)
+      echo "You should only need it if you modified 'acinclude.m4' or"
+      echo "$configure_deps."
+      program_details 'aclocal'
+      ;;
+   autom4te*)
+      echo "You might have modified some maintainer files that require"
+      echo "the 'automa4te' program to be rebuilt."
+      program_details 'autom4te'
+      ;;
+    bison*|yacc*)
+      echo "You should only need it if you modified a '.y' file."
+      echo "You may want to install the GNU Bison package:"
+      echo "<$gnu_software_URL/bison/>"
+      ;;
+    lex*|flex*)
+      echo "You should only need it if you modified a '.l' file."
+      echo "You may want to install the Fast Lexical Analyzer package:"
+      echo "<$flex_URL>"
+      ;;
+    help2man*)
+      echo "You should only need it if you modified a dependency" \
+           "of a man page."
+      echo "You may want to install the GNU Help2man package:"
+      echo "<$gnu_software_URL/help2man/>"
+    ;;
+    makeinfo*)
+      echo "You should only need it if you modified a '.texi' file, or"
+      echo "any other file indirectly affecting the aspect of the manual."
+      echo "You might want to install the Texinfo package:"
+      echo "<$gnu_software_URL/texinfo/>"
+      echo "The spurious makeinfo call might also be the consequence of"
+      echo "using a buggy 'make' (AIX, DU, IRIX), in which case you might"
+      echo "want to install GNU make:"
+      echo "<$gnu_software_URL/make/>"
+      ;;
+    *)
+      echo "You might have modified some files without having the proper"
+      echo "tools for further handling them.  Check the 'README' file, it"
+      echo "often tells you about the needed prerequisites for installing"
+      echo "this package.  You may also peek at any GNU archive site, in"
+      echo "case some other package contains this missing '$1' program."
+      ;;
+  esac
+}
+
+give_advice "$1" | sed -e '1s/^/WARNING: /' \
+                       -e '2,$s/^/         /' >&2
+
+# Propagate the correct exit status (expected to be 127 for a program
+# not found, 63 for a program that failed due to version mismatch).
+exit $st
 
 # Local variables:
 # eval: (add-hook 'write-file-hooks 'time-stamp)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' --exclude Makefile.in --exclude configure --exclude 
config.guess --exclude '*.pot' --exclude mkinstalldirs --exclude aclocal.m4 
--exclude config.sub --exclude depcomp --exclude install-sh --exclude ltmain.sh 
old/libXxf86dga-1.1.3/src/XF86DGA2.c new/libXxf86dga-1.1.4/src/XF86DGA2.c
--- old/libXxf86dga-1.1.3/src/XF86DGA2.c        2012-03-08 06:35:46.000000000 
+0100
+++ new/libXxf86dga-1.1.4/src/XF86DGA2.c        2013-05-31 03:36:29.000000000 
+0200
@@ -6,6 +6,9 @@
 */
 
 /* THIS IS NOT AN X CONSORTIUM STANDARD */
+#ifdef HAVE_CONFIG_H
+#include <config.h>
+#endif
 
 #ifdef __UNIXOS2__ /* needed here to override certain constants in X headers */
 #define INCL_DOS
@@ -21,6 +24,19 @@
 #include <X11/extensions/extutil.h>
 #include <stdio.h>
 
+#include <stdint.h>
+#include <limits.h>
+
+#ifndef HAVE__XEATDATAWORDS
+static inline void _XEatDataWords(Display *dpy, unsigned long n)
+{
+# ifndef LONG64
+    if (n >= (ULONG_MAX >> 2))
+        _XIOError(dpy);
+# endif
+    _XEatData (dpy, n << 2);
+}
+#endif
 
 /* If you change this, change the Bases[] array below as well */
 #define MAX_HEADS 16
@@ -234,9 +250,14 @@
        return False;
     }
 
-    if(rep.length) {
-       deviceName = Xmalloc(rep.length << 2);
-       _XRead(dpy, deviceName, rep.length << 2);
+    if (rep.length) {
+       if (rep.length < (INT_MAX >> 2)) {
+           unsigned long size = rep.length << 2;
+           deviceName = Xmalloc(size);
+           _XRead(dpy, deviceName, size);
+           deviceName[size - 1] = '\0';
+       } else
+           _XEatDataWords(dpy, rep.length);
     }
 
     ret = XDGAMapFramebuffer(screen, deviceName,
@@ -296,16 +317,21 @@
     if (_XReply(dpy, (xReply *)&rep, 0, xFalse)) {
        if(rep.length) {
           xXDGAModeInfo info;
-          int i, size;
+          unsigned long size = 0;
           char *offset;
 
-          size = rep.length << 2;
-          size -= rep.number * sz_xXDGAModeInfo; /* find text size */
-          modes = (XDGAMode*)Xmalloc((rep.number * sizeof(XDGAMode)) + size);
-          offset = (char*)(&modes[rep.number]); /* start of text */
-
+          if ((rep.length < (INT_MAX >> 2)) &&
+              (rep.number < (INT_MAX / sizeof(XDGAMode)))) {
+              size = rep.length << 2;
+              if (size > (rep.number * sz_xXDGAModeInfo)) {
+                  size -= rep.number * sz_xXDGAModeInfo; /* find text size */
+                  modes = Xmalloc((rep.number * sizeof(XDGAMode)) + size);
+                  offset = (char*)(&modes[rep.number]);  /* start of text */
+              }
+          }
 
-          if(modes) {
+          if (modes != NULL) {
+             unsigned int i;
              for(i = 0; i < rep.number; i++) {
                _XRead(dpy, (char*)(&info), sz_xXDGAModeInfo);
 
@@ -335,13 +361,20 @@
                modes[i].reserved1 = info.reserved1;
                modes[i].reserved2 = info.reserved2;
 
-               _XRead(dpy, offset, info.name_size);
-               modes[i].name = offset;
-               offset += info.name_size;
+               if (info.name_size > 0 && info.name_size <= size) {
+                   _XRead(dpy, offset, info.name_size);
+                   modes[i].name = offset;
+                   modes[i].name[info.name_size - 1] = '\0';
+                   offset += info.name_size;
+                   size -= info.name_size;
+               } else {
+                   _XEatData(dpy, info.name_size);
+                   modes[i].name = NULL;
+               }
              }
              *num = rep.number;
           } else
-               _XEatData(dpy, rep.length << 2);
+               _XEatDataWords(dpy, rep.length);
        }
     }
 
@@ -377,12 +410,15 @@
     if (_XReply(dpy, (xReply *)&rep, 0, xFalse)) {
        if(rep.length) {
           xXDGAModeInfo info;
-          int size;
+          unsigned long size;
 
-          size = rep.length << 2;
-          size -= sz_xXDGAModeInfo; /* get text size */
+          if ((rep.length < (INT_MAX >> 2)) &&
+              (rep.length > (sz_xXDGAModeInfo >> 2))) {
+              size = rep.length << 2;
+              size -= sz_xXDGAModeInfo; /* get text size */
 
-          dev = (XDGADevice*)Xmalloc(sizeof(XDGADevice) + size);
+              dev = Xmalloc(sizeof(XDGADevice) + size);
+          }
 
           if(dev) {
                _XRead(dpy, (char*)(&info), sz_xXDGAModeInfo);
@@ -413,8 +449,14 @@
                dev->mode.reserved1 = info.reserved1;
                dev->mode.reserved2 = info.reserved2;
 
-               dev->mode.name = (char*)(&dev[1]);
-               _XRead(dpy, dev->mode.name, info.name_size);
+               if (info.name_size > 0 && info.name_size <= size) {
+                   dev->mode.name = (char*)(&dev[1]);
+                   _XRead(dpy, dev->mode.name, info.name_size);
+                   dev->mode.name[info.name_size - 1] = '\0';
+               } else {
+                   dev->mode.name = NULL;
+                   _XEatDataWords(dpy, rep.length);
+               }
 
                dev->pixmap = (rep.flags & XDGAPixmap) ? pid : 0;
                dev->data = XDGAGetMappedMemory(screen);
@@ -423,6 +465,8 @@
                    dev->data += rep.offset;
           }
           /* not sure what to do if the allocation fails */
+          else
+              _XEatDataWords(dpy, rep.length);
        }
     }
 
@@ -928,7 +972,7 @@
     if ((pMap->fd = open(name, O_RDWR)) < 0)
        return False;
     pMap->virtual = mmap(NULL, size, PROT_READ | PROT_WRITE,
-                       MAP_FILE | MAP_SHARED, pMap->fd, (off_t)base);
+                       MAP_FILE | MAP_SHARED, pMap->fd, 
(off_t)(uintptr_t)base);
     if (pMap->virtual == (void *)-1)
        return False;
     mprotect(pMap->virtual, size, PROT_READ | PROT_WRITE);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' --exclude Makefile.in --exclude configure --exclude 
config.guess --exclude '*.pot' --exclude mkinstalldirs --exclude aclocal.m4 
--exclude config.sub --exclude depcomp --exclude install-sh --exclude ltmain.sh 
old/libXxf86dga-1.1.3/src/config.h.in new/libXxf86dga-1.1.4/src/config.h.in
--- old/libXxf86dga-1.1.3/src/config.h.in       2012-03-08 06:35:55.000000000 
+0100
+++ new/libXxf86dga-1.1.4/src/config.h.in       2013-05-31 03:36:37.000000000 
+0200
@@ -30,6 +30,9 @@
 /* Define to 1 if you have the <unistd.h> header file. */
 #undef HAVE_UNISTD_H
 
+/* Define to 1 if you have the `_XEatDataWords' function. */
+#undef HAVE__XEATDATAWORDS
+
 /* Define to the sub-directory in which libtool stores uninstalled libraries.
    */
 #undef LT_OBJDIR

-- 
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to