libxml2: Apply ABI breaking patch from Chromium needed for libxslt CVE fixes

This commit is contained in:
Jan Tojnar
2025-06-18 09:47:59 +02:00
parent 9e83b64f72
commit 77b52c3520
2 changed files with 29 additions and 0 deletions
@@ -51,6 +51,15 @@ stdenv.mkDerivation (finalAttrs: {
hash = "sha256-J3KUyzMRmrcbK8gfL0Rem8lDW4k60VuyzSsOhZoO6Eo=";
};
patches = [
# Unmerged ABI-breaking patch required to fix the following security issues:
# - https://gitlab.gnome.org/GNOME/libxslt/-/issues/139
# - https://gitlab.gnome.org/GNOME/libxslt/-/issues/140
# See also https://gitlab.gnome.org/GNOME/libxml2/-/issues/906
# Source: https://github.com/chromium/chromium/blob/4fb4ae8ce3daa399c3d8ca67f2dfb9deffcc7007/third_party/libxml/chromium/xml-attr-extra.patch
./xml-attr-extra.patch
];
strictDeps = true;
nativeBuildInputs = [
@@ -0,0 +1,20 @@
diff --git a/include/libxml/tree.h b/include/libxml/tree.h
index e5a8fb709471f..7819d5819b427 100644
--- a/include/libxml/tree.h
+++ b/include/libxml/tree.h
@@ -454,6 +454,7 @@ struct _xmlAttr {
xmlAttributeType atype; /* the attribute type if validating */
void *psvi; /* for type/PSVI information */
struct _xmlID *id; /* the ID struct */
+ unsigned int extra; /* extra data for XPath/XSLT */
};
/**
@@ -592,6 +593,7 @@ struct _xmlDoc {
document */
int properties; /* set of xmlDocProperties for this document
set at the end of parsing */
+ unsigned int extra; /* extra data for XPath/XSLT */
};