~ruther/guix-local

ref: 76fed2b3c4e3703d1ad81c4330edd94d551b6334 guix-local/gnu/packages/patches/ghostscript-no-header-uuid.patch -rw-r--r-- 2.5 KiB
76fed2b3 — Alex Vong gnu: libxml2: Fix CVE-2017-{0663,7375,7376,9047,9048,9049,9050}. 8 years ago
                                                                                
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
This patch makes the UUIDs in the XMP header optional, depending on the
setting of the environment variable GS_GENERATE_UUIDS.

If the environment variable GS_GENERATE_UUIDS is set to "0" or "no", it will
not write out the Document UUID field and also will write the Instance ID
field value as "".

Upstream does not want to do this.

See: https://bugs.ghostscript.com/show_bug.cgi?id=698208
diff -ur orig/gnu-ghostscript-9.14.0/devices/vector/gdevpdfe.c aa/gnu-ghostscript-9.14.0/devices/vector/gdevpdfe.c
--- orig/gnu-ghostscript-9.14.0/devices/vector/gdevpdfe.c	2017-07-09 23:30:28.960479189 +0200
+++ gnu-ghostscript-9.14.0/devices/vector/gdevpdfe.c	2017-07-10 01:04:12.252478276 +0200
@@ -617,7 +617,7 @@
         return code;
 
     /* PDF/A XMP reference recommends setting UUID to empty. If not empty must be a URI */
-    if (pdev->PDFA != 0)
+    if (pdev->PDFA != 0 || (getenv("GS_GENERATE_UUIDS") && (strcasecmp(getenv("GS_GENERATE_UUIDS"), "0") == 0 || strcasecmp(getenv("GS_GENERATE_UUIDS"), "no") == 0)))
         instance_uuid[0] = 0x00;
 
     cre_date_time_len = pdf_get_docinfo_item(pdev, "/CreationDate", cre_date_time, sizeof(cre_date_time));
@@ -719,15 +719,18 @@
             pdf_xml_tag_close(s, "rdf:Description");
             pdf_xml_newline(s);
 
-            pdf_xml_tag_open_beg(s, "rdf:Description");
-            pdf_xml_attribute_name(s, "rdf:about");
-            pdf_xml_attribute_value(s, instance_uuid);
-            pdf_xml_attribute_name(s, "xmlns:xapMM");
-            pdf_xml_attribute_value(s, "http://ns.adobe.com/xap/1.0/mm/");
-            pdf_xml_attribute_name(s, "xapMM:DocumentID");
-            pdf_xml_attribute_value(s, document_uuid);
-            pdf_xml_tag_end_empty(s);
-            pdf_xml_newline(s);
+            if (!getenv("GS_GENERATE_UUIDS") || (strcasecmp(getenv("GS_GENERATE_UUIDS"), "0") != 0 && strcasecmp(getenv("GS_GENERATE_UUIDS"), "no") != 0))
+            {
+                pdf_xml_tag_open_beg(s, "rdf:Description");
+                pdf_xml_attribute_name(s, "rdf:about");
+                pdf_xml_attribute_value(s, instance_uuid);
+                pdf_xml_attribute_name(s, "xmlns:xapMM");
+                pdf_xml_attribute_value(s, "http://ns.adobe.com/xap/1.0/mm/");
+                pdf_xml_attribute_name(s, "xapMM:DocumentID");
+                pdf_xml_attribute_value(s, document_uuid);
+                pdf_xml_tag_end_empty(s);
+                pdf_xml_newline(s);
+            }
 
             pdf_xml_tag_open_beg(s, "rdf:Description");
             pdf_xml_attribute_name(s, "rdf:about");