source: networking/netlibs/curl.xml@ ebf4942

10.0 10.1 11.0 11.1 11.2 11.3 12.0 12.1 kea ken/TL2024 ken/inkscape-core-mods ken/tuningfonts lazarus lxqt plabs/newcss plabs/python-mods python3.11 qt5new rahul/power-profiles-daemon renodr/vulkan-addition trunk upgradedb xry111/intltool xry111/llvm18 xry111/soup3 xry111/test-20220226 xry111/xf86-video-removal
Last change on this file since ebf4942 was ebf4942, checked in by Xi Ruoyao <xry111@…>, 4 years ago

curl: add security hotfix for 7.71.1 (blfs-10.0)

git-svn-id: svn://svn.linuxfromscratch.org/BLFS/trunk/BOOK@23584 af4574ff-66df-0310-9fd7-8a98e5e911e0

  • Property mode set to 100644
File size: 15.7 KB
Line 
1<?xml version="1.0" encoding="ISO-8859-1"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../../general.ent">
5 %general-entities;
6
7 <!ENTITY curl-download-http "https://curl.haxx.se/download/curl-&curl-version;.tar.xz">
8 <!ENTITY curl-download-ftp " ">
9 <!ENTITY curl-md5sum "b54b386057846ce3edd3584b19741569">
10 <!ENTITY curl-size "2.3 MB">
11 <!ENTITY curl-buildsize "94 MB (add 16 MB for tests)">
12 <!ENTITY curl-time "0.3 SBU (add 13 SBU for tests)">
13]>
14
15<sect1 id="curl" xreflabel="cURL-&curl-version;">
16 <?dbhtml filename="curl.html"?>
17
18 <sect1info>
19 <othername>$LastChangedBy$</othername>
20 <date>$Date$</date>
21 </sect1info>
22
23 <title>cURL-&curl-version;</title>
24
25 <indexterm zone="curl">
26 <primary sortas="a-cURL">cURL</primary>
27 </indexterm>
28
29 <sect2 role="package">
30 <title>Introduction to cURL</title>
31
32 <para>
33 The <application>cURL</application> package contains an utility
34 and a library used for transferring files with URL syntax to any of
35 the following protocols: FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP,
36 TELNET, DICT, LDAP, LDAPS and FILE. Its ability to both download
37 and upload files can be incorporated into other programs to support
38 functions like streaming media.
39 </para>
40
41 &lfs10_checked;
42
43 <bridgehead renderas="sect3">Package Information</bridgehead>
44 <itemizedlist spacing="compact">
45 <listitem>
46 <para>
47 Download (HTTP): <ulink url="&curl-download-http;"/>
48 </para>
49 </listitem>
50 <listitem>
51 <para>
52 Download (FTP): <ulink url="&curl-download-ftp;"/>
53 </para>
54 </listitem>
55 <listitem>
56 <para>
57 Download MD5 sum: &curl-md5sum;
58 </para>
59 </listitem>
60 <listitem>
61 <para>
62 Download size: &curl-size;
63 </para>
64 </listitem>
65 <listitem>
66 <para>
67 Estimated disk space required: &curl-buildsize;
68 </para>
69 </listitem>
70 <listitem>
71 <para>
72 Estimated build time: &curl-time;
73 </para>
74 </listitem>
75 </itemizedlist>
76
77 <bridgehead renderas="sect3">Additional Downloads</bridgehead>
78 <itemizedlist spacing="compact">
79 <listitem>
80 <para>
81 <!-- A hotfix for LFS-10.0, to fix the CVE w/o change the API
82 and ABI. So we won't need to rebuild massively. Will be
83 dropped in LFS-10.1 once we update to curl-7.72.0. -->
84 Patch to fix CVE-2020-8231: <ulink
85 url="&patch-root;/curl-7.71.1-security_fixes-1.patch"/>
86 </para>
87 </listitem>
88 </itemizedlist>
89
90 <bridgehead renderas="sect3">cURL Dependencies</bridgehead>
91
92 <bridgehead renderas="sect4">Recommended</bridgehead>
93 <para role="recommended">
94 <xref role="runtime" linkend="make-ca"/> (runtime)
95 </para>
96
97 <bridgehead renderas="sect4">Optional</bridgehead>
98 <para role="optional">
99 <xref linkend="brotli"/>,
100 <xref linkend="c-ares"/>,
101 <xref linkend="gnutls"/>,
102 <xref linkend="libidn2"/>,
103 <xref linkend="libpsl"/>,
104 <xref linkend="libssh2"/>,
105 <xref linkend="mitkrb"/>,
106 <xref linkend="nghttp2"/>,
107 <xref linkend="openldap"/>,
108 <xref linkend="samba"/>,
109 <ulink url="https://www.secureauth.com/labs/open-source-tools/impacket/">impacket</ulink>,
110 <ulink url="https://launchpad.net/libmetalink/">libmetalink</ulink>,
111 <ulink url="http://rtmpdump.mplayerhq.hu/">librtmp</ulink>,
112 <ulink url="https://github.com/ngtcp2/ngtcp2/">ngtcp2</ulink>,
113 <!--<ulink url="https://tls.mbed.org/">mbed TLS</ulink> (formerly known as
114 PolarSSL), and -->
115 <!-- mbedTLS/PolarSSL support was removed in 7.65.1 -->
116 <ulink url="https://github.com/cloudflare/quiche">quiche</ulink>, and
117 <ulink url="http://spnego.sourceforge.net/">SPNEGO</ulink>
118 </para>
119
120 <bridgehead renderas="sect4">Optional if Running the Test Suite</bridgehead>
121 <para role="optional">
122 <!-- stunnel is still listed in the docs as required, but 7.58.0
123 tests completed happily without it, although the test for unit1323
124 reported that the tool set in the test case does not exist - ken -->
125 <xref linkend="stunnel"/> (for the HTTPS and FTPS tests) and
126 <xref linkend="valgrind"/> (this will slow the tests down and may cause failures.)
127 </para>
128
129 <para condition="html" role="usernotes">User Notes:
130 <ulink url="&blfs-wiki;/curl"/>
131 </para>
132 </sect2>
133
134 <sect2 role="installation">
135 <title>Installation of cURL</title>
136
137 <para>
138 First, apply a patch to fix a security issue:
139 </para>
140
141<screen><userinput>patch -Np1 -i ../curl-7.71.1-security_fixes-1.patch</userinput></screen>
142
143 <para>
144 Install <application>cURL</application> by running the following
145 commands:
146 </para>
147
148<screen><userinput>./configure --prefix=/usr \
149 --disable-static \
150 --enable-threaded-resolver \
151 --with-ca-path=/etc/ssl/certs &amp;&amp;
152make</userinput></screen>
153
154<!--
155 For version 7.54.1 I got:
156 TESTDONE: 869 tests out of 869 reported OK: 100%
157 TESTDONE: 1092 tests were considered during 1080 seconds
158
159 <para>
160 Running the test suite is optional. About 2% of the tests fail. Increase
161 in test time by each failed test is about 10%. Tests SBU above was
162 obtained disabling failing tests, with:
163 </para>
164
165 2017-10-29 - bdubbs
166 For version 7.56.1 I had a lot of test failures which included long
167 timeouts. Could not determine the cause of the timeouts or failures,
168 but I was missing c-ares, MIT Kerberos, ldap, samba, and the six
169 external packages.
170
171 2017-12-01 - bdubbs
172 Still a lot of test failures. I did have c-ares, Kerberos, and ldap
173 installed this time. Best guess is that servers are not available.
174
175 2018-08-01 - renodr
176 No test failures, but I didn't have any of the optional dependencies except
177 for c-ares and libidn2. I might re-run this test suite before release with
178 all of the optional deps, but right now, it isn't a priority - rather
179 the security fix is.
180-->
181
182 <para>
183 To run the test suite, issue: <command>make test</command>.
184 <!--Tests 323, 1139, 1140, and 1173 are known to fail.
185 A few other tests may fail randomly for unknown reasons.-->
186 </para>
187<!-- Two (of 857) tests
188fail for unknown reasons, and all tests fail is valgrind is installed. Moving
189valgrind out of $PATH is recommended if you wish to run the test suite while
190it is installed.
191
192Added by Pierre for curl-7.59.0:
193no stunnel, no valgrind, no options
194Warning: smb server unexpectedly alive
195Warning: dict server unexpectedly alive
196TESTDONE: 950 tests out of 951 reported OK: 99%
197TESTFAIL: These test cases failed: 1148
198TESTDONE: 1189 tests were considered during 362 seconds.
199__________
200
201 if stunnel and valgrind are not installed, and also most options
202 (I had rtmpdump), the tests complete without problems.
203Warning: smb server unexpectedly alive
204Warning: dict server unexpectedly alive
205TESTDONE: 938 tests out of 938 reported OK: 100%
206TESTDONE: 1175 tests were considered during 355 seconds.
207 and no. I don't have smb - so commenting the rest of this:
208 To run the test suite, issue: <command>make test</command>. Many tests
209 may fail that depend on optional dependencies that may not be installed
210 or upstream servers that may not be available, especially for tests
211 numbered 700 and above.
212 Test time may be significantly increase due to hanging tests that fail.
213__________
214Added by Bruce for curl-7.60.0:
215TESTDONE: 957 tests out of 959 reported OK: 99%
216TESTFAIL: These test cases failed: 1139 1140
217TESTDONE: 1196 tests were considered during 1184 seconds.
218From the logs, both appear to be ipv6 releated.
219
220==========
221Added by Douglas for curl-7.61.0:
222TESTDONE: 961 tests out of 961 reported OK: 100%
223TESTDONE: 1202 tests were considered during 338 seconds.
224I only have c-ares and libidn2 installed, I will likely try before release
225with all optional dependencies in the book installed.
226
227=========
2287.61.1 NOTE: The test suite is extremely noisy, complaining about verification errors.
229It's possible this is due to openssl-1.1.1, BUT 79/79 tests report as 100% OK. I had
230c-ares, libpsl, and libidn1/2 installed. - Doug
231
232========
2337.62.0: All tests passed. libpsl, c-ares, libssh2, libidn2 installed.
234All 1098 tests report OK.
235
236=======
237Added by Douglas for curl-7.64.0:
238TESTDONE: 1022 tests out of 1023 reported OK: 99%
239TESTFAIL: These tests cases failed: 323
240TESTDONE: 1235 tests were considered during 1279 seconds.
241For dependencies, I had c-ares, gnutls, libidn2, libpsl, krb5, libssh2, nghttp2,
242OpenLDAP, Samba, stunnel, and Valgrind installed.
243=======
244Added by bdubbs for curl-7.64.1:
245TESTDONE: 1022 tests out of 1025 reported OK: 99%
246TESTFAIL: These test cases failed: 323 1139 1140
247TESTDONE: 1242 tests were considered during 1483 seconds
248
249=======
250Added by renodr for curl-7.65.1:
251TESTDONE: 996 tests out of 997 reported OK: 99%
252TESTFAIL: These test cases failed: 1560
253TESTDONE: 1249 tests were considered during 1091 seconds.
254All dependencies except for externals installed.
255=======
256Added by bdubbs for curl-7.65.2:
257TESTDONE: 1034 tests out of 1036 reported OK: 99%
258TESTFAIL: These test cases failed: 323 1560
259TESTDONE: 1254 tests were considered during 1362 seconds.
260Time above does not include test build time.
261All dependencies except for externals installed.
262=======
263Added by bdubbs for curl-7.65.3:
264TESTDONE: 1031 tests out of 1036 reported OK: 99%
265TESTFAIL: These test cases failed: 323 1139 1140 1173 1560
266TESTDONE: 1254 tests were considered during 1364 seconds.
267
268The tests that fail seem to be somewhat random. What happened between
269yesterday and today that that tests 1139 1140 1173 now fail?
270
271=======
272Added by bdubbs for curl-7.68.0:
273TESTDONE: 1066 tests out of 1071 reported OK: 99%
274TESTFAIL: These test cases failed: 323 1139 1140 1173 1560
275TESTDONE: 1290 tests were considered during 1515 seconds.
276
277=======
278Added by bdubbs for curl-7.69.0:
279TESTDONE: 074 tests out of 1079 reported OK: 99%
280TESTFAIL: These test cases failed: 323 1139 1140 1173 1560
281TESTDONE: 1320 tests were considered during 1514 seconds.
282
283For curl-7.69.1, 1082 tests out of 1086 reported OK. 1560 now passes.
2841330 tests were considered during 1528 seconds.
285
286======
287Added by renodr for curl-7.70.0:
288TESTDONE: 1062 tests out of 1062 reported OK: 100%
289TESTDONE: 1352 tests were considered during 1218 seconds.
290Tests were ran with all dependencies present except for stunnel.
291impacket only seems to add one extra test to the mix as well.
292
293======
294Added by renodr for curl-7.71.0:
295TESTDONE: 1072 tests out of 1072 reported OK: 100%
296TESTDONE: 1364 tests were considered during 1202 seconds.
297Tests were run similarly to 7.70.0 - all deps except for stunnel.
298
299======
300Added by renodr for curl-7.71.1:
301TESTDONE: 1076 tests out of 1076 reported OK: 100%
302TESTDONE: 1368 tests were considered during 1207 seconds.
303Tests were run similarly to 7.71.0, including impacket, but no stunnel.
304-->
305
306 <para>
307 Now, as the <systemitem class="username">root</systemitem>
308 user:
309 </para>
310
311<screen role="root"><userinput>make install &amp;&amp;
312
313rm -rf docs/examples/.deps &amp;&amp;
314
315find docs \( -name Makefile\* -o -name \*.1 -o -name \*.3 \) -exec rm {} \; &amp;&amp;
316
317install -v -d -m755 /usr/share/doc/curl-&curl-version; &amp;&amp;
318cp -v -R docs/* /usr/share/doc/curl-&curl-version;</userinput></screen>
319
320 <para>
321 Simple tests to the new installed <command>curl</command>:
322 <command>curl --trace-ascii debugdump.txt http://www.example.com/</command>
323 and
324 <command>curl --trace-ascii d.txt --trace-time http://example.com/</command>.
325 Inspect the locally created trace files <filename>debugdump.txt</filename>
326 and <filename>d.txt</filename>, which contain version downloaded
327 files information, etc. One file has the time for each action logged.
328 </para>
329 </sect2>
330
331 <sect2 role="commands">
332 <title>Command Explanations</title>
333
334 <xi:include xmlns:xi="http://www.w3.org/2001/XInclude"
335 href="../../xincludes/static-libraries.xml"/>
336
337 <para>
338 <parameter>--enable-threaded-resolver</parameter>: This switch enables
339 <application>cURL</application>'s builtin threaded DNS resolver.
340 </para>
341
342 <para>
343 <parameter>--with-ca-path=/etc/ssl/certs</parameter>: This
344 switch sets the location of the BLFS Certificate Authority store.
345 </para>
346
347 <para>
348 <option>--with-gssapi</option>: This parameter adds
349 <application>Kerberos 5</application> support to
350 <filename class="libraryfile">libcurl</filename>.
351 </para>
352
353 <para>
354 <option>--without-ssl --with-gnutls</option>: Use to
355 build with <application>GnuTLS</application> support
356 instead of <application>OpenSSL</application> for SSL/TLS.
357 </para>
358
359 <para>
360 <option>--with-ca-bundle=/etc/pki/tls/certs/ca-bundle.crt</option>: Use
361 this switch instead of <parameter>--with-ca-path</parameter> if
362 building with <application>GnuTLS</application> support
363 instead of <application>OpenSSL</application> for SSL/TLS.
364 </para>
365
366 <para>
367 <option>--with-libssh2</option>: This paramater adds
368 <application>SSH</application> support to cURL. This is disabled
369 by default.
370 </para>
371
372 <para>
373 <option>--enable-ares</option>: This paramater adds
374 support for DNS resolution through the c-ares library. It is disabled
375 by default, but does speed up DNS resolution queries.
376 </para>
377
378 <para>
379 <command>find docs ... -exec rm {} \;</command>: This command removes
380 <filename>Makefiles</filename> and man files from the documentation
381 directory that would otherwise be installed by the commands that follow.
382 </para>
383
384 </sect2>
385
386 <sect2 role="content">
387 <title>Contents</title>
388
389 <segmentedlist>
390 <segtitle>Installed Programs</segtitle>
391 <segtitle>Installed Library</segtitle>
392 <segtitle>Installed Directories</segtitle>
393
394 <seglistitem>
395 <seg>
396 curl and curl-config
397 </seg>
398 <seg>
399 libcurl.so
400 </seg>
401 <seg>
402 /usr/include/curl and
403 /usr/share/doc/curl-&curl-version;
404 </seg>
405 </seglistitem>
406 </segmentedlist>
407
408 <variablelist>
409 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
410 <?dbfo list-presentation="list"?>
411 <?dbhtml list-presentation="table"?>
412
413 <varlistentry id="curl-prog">
414 <term><command>curl</command></term>
415 <listitem>
416 <para>
417 is a command line tool for transferring files with URL syntax.
418 </para>
419 <indexterm zone="curl curl-prog">
420 <primary sortas="b-curl">curl</primary>
421 </indexterm>
422 </listitem>
423 </varlistentry>
424
425 <varlistentry id="curl-config">
426 <term><command>curl-config</command></term>
427 <listitem>
428 <para>
429 prints information about the last compile, like libraries
430 linked to and prefix setting.
431 </para>
432 <indexterm zone="curl curl-config">
433 <primary sortas="b-curl-config">curl-config</primary>
434 </indexterm>
435 </listitem>
436 </varlistentry>
437
438 <varlistentry id="libcurl">
439 <term><filename class="libraryfile">libcurl.so</filename></term>
440 <listitem>
441 <para>
442 provides the API functions required by
443 <command>curl</command> and other programs.
444 </para>
445 <indexterm zone="curl libcurl">
446 <primary sortas="c-libcurl">libcurl.so</primary>
447 </indexterm>
448 </listitem>
449 </varlistentry>
450
451 </variablelist>
452
453 </sect2>
454
455</sect1>
Note: See TracBrowser for help on using the repository browser.