summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMike Frysinger <vapier@gentoo.org>2006-09-30 19:06:22 +0000
committerMike Frysinger <vapier@gentoo.org>2006-09-30 19:06:22 +0000
commitfe5d2fac7ce213c3ca46b2422b1eb9ee9a530c69 (patch)
treedfe165dcbca0d2a3575a0d77c211e116c044c827 /net-firewall
parentarm/s390/sh stable (diff)
downloadgentoo-2-fe5d2fac7ce213c3ca46b2422b1eb9ee9a530c69.tar.gz
gentoo-2-fe5d2fac7ce213c3ca46b2422b1eb9ee9a530c69.tar.bz2
gentoo-2-fe5d2fac7ce213c3ca46b2422b1eb9ee9a530c69.zip
old
(Portage version: 2.1.2_pre2)
Diffstat (limited to 'net-firewall')
-rw-r--r--net-firewall/iptables/Manifest26
-rw-r--r--net-firewall/iptables/files/digest-iptables-1.3.49
-rw-r--r--net-firewall/iptables/files/digest-iptables-1.3.59
-rw-r--r--net-firewall/iptables/iptables-1.3.4.ebuild161
-rw-r--r--net-firewall/iptables/iptables-1.3.5.ebuild161
5 files changed, 0 insertions, 366 deletions
diff --git a/net-firewall/iptables/Manifest b/net-firewall/iptables/Manifest
index 1fabcf596d96..79876b6507ab 100644
--- a/net-firewall/iptables/Manifest
+++ b/net-firewall/iptables/Manifest
@@ -1,6 +1,3 @@
------BEGIN PGP SIGNED MESSAGE-----
-Hash: SHA1
-
AUX 1.2.11-files/CAN-2004-0986.patch 1365 RMD160 a184a41e0b3ad611f271e22e35adf684213307a5 SHA1 a9b5e7ac2753dc55d776d16c9e2911d9c5574669 SHA256 15c98cb61c8a2787bb6e4f01f01fd29b0e6a2731e817349bd5fa4c4cd458bef3
MD5 756f721b4c0c0646a174993befa199c4 files/1.2.11-files/CAN-2004-0986.patch 1365
RMD160 a184a41e0b3ad611f271e22e35adf684213307a5 files/1.2.11-files/CAN-2004-0986.patch 1365
@@ -83,9 +80,7 @@ RMD160 fef1e2c096171e32eb3e62e79eb7043033153ef6 files/iptables-1.3.2.init 2548
SHA256 3ededc7a04ed94ac847d438e7980e1d4a53bfac830eb73c9d420b24b76358e44 files/iptables-1.3.2.init 2548
DIST iptables-1.2.11.tar.bz2 156988 RMD160 66e0fa391444a1e169feaf2fc67b5f8622ec1d89 SHA1 1a2236e2705b02834aaa506632c08cf8a647efa2 SHA256 be7bd67232fddbe3ce81f40f5b79123380a2e67cd166ec06e650842f8acb373d
DIST iptables-1.3.0-imq1.diff 5369 RMD160 8ca1fa3bfea02d27232d8d8cb0a12586dd4537b5 SHA1 bdf665cacc985fceaadf119ae7a756caca1589ad SHA256 0f9d36e48b3f1e83ef9e1d39c19e7271a889a31c65c396c416200eb143f1795b
-DIST iptables-1.3.4.tar.bz2 189847 RMD160 3e37965406ae8a39896dead16e5a3722fc9256b4 SHA1 47a779204306dd8499ca73df4c3a5233f23dfaae SHA256 2067ed2134adde5f50716dd1d3752dfb023a634ff274af88eb635e5a1bba1bda
DIST iptables-1.3.5.tar.bz2 191820 RMD160 3364e0f37f67ba4aa9ac9caa6f11adb67887e528 SHA1 6dbeeee13517fa02852960b6f6e51115c7548a09 SHA256 1d8ee8634d167b0f1a8872b6547910c11bae676699faf2b4bc2c84a128449c3c
-DIST netfilter-layer7-v2.0.tar.gz 88489 RMD160 8e2f76f44db06d5b1b098c2ea37a10befd28e8a8 SHA1 ea3b4276ec593f2aebc502fa3b1c4556c2d8af3c SHA256 1a454c77a07c6447a2c641cc9d5f255023f1c1d5363b463825da5f3d5942168f
DIST netfilter-layer7-v2.1.tar.gz 89247 RMD160 cd2d455a16761b4fe2318d6d8a5671a535176d62 SHA1 5dc0c9bd1e3df3110cf724f3437a4b68d62b4dd3 SHA256 5022e8a349135f67045f4add47405af0d626c90a5e8b86ee01745755946e1390
DIST netfilter-layer7-v2.2.tar.gz 88944 RMD160 cf421e6ef4acf5b9107feacaee6566d55ad21683 SHA1 55eaad3b4e46feff09910cd5e3c76c57ac12dc58 SHA256 e82cc356ece2bea3da2bb4b467063a96337ced4bde6127a44f0296245e74d57d
DIST netfilter-layer7-v2.3.tar.gz 105587 RMD160 4c5c5315cf1f193c9ceb605d8d9d9328b515c64d SHA1 cfbe80a6c5725732e4935692e4b0cf5b42abd4f0 SHA256 4a5e4475d05c8d0998e56d12e8e27eb9acf23ce80a53000783b2f609a6bb33aa
@@ -93,10 +88,6 @@ EBUILD iptables-1.2.11-r3.ebuild 5335 RMD160 be0e4f868b4f24b39b1a684a6b120d5120e
MD5 fc6e50abc57966f2b5655301809a6d15 iptables-1.2.11-r3.ebuild 5335
RMD160 be0e4f868b4f24b39b1a684a6b120d5120ec0763 iptables-1.2.11-r3.ebuild 5335
SHA256 8ffed50f6d6ebbf4159b72279adda848f5932f615901c4066cbbd466f089054f iptables-1.2.11-r3.ebuild 5335
-EBUILD iptables-1.3.4.ebuild 5052 RMD160 a1e1e61bfa18fa05f040a50f946ab64b16c1158b SHA1 9b348920c9e7d1bca1378b6d7d098e2a3819cf54 SHA256 8aeae4c464cd920047da6fe0893af49ec5f7b31d41396797e1c051350050f045
-MD5 98e049aff157bac29735f232b0513fde iptables-1.3.4.ebuild 5052
-RMD160 a1e1e61bfa18fa05f040a50f946ab64b16c1158b iptables-1.3.4.ebuild 5052
-SHA256 8aeae4c464cd920047da6fe0893af49ec5f7b31d41396797e1c051350050f045 iptables-1.3.4.ebuild 5052
EBUILD iptables-1.3.5-r1.ebuild 5059 RMD160 45c9b9729cd8f57a87541b04655953c5b24b4998 SHA1 a1b36b92660ed9169c630749a8af60891fd22093 SHA256 8829221162e3efc705bbf792695d45f2003e3691f9703a49cfed06722c10690c
MD5 a13225ca53456b22ba77129c78370765 iptables-1.3.5-r1.ebuild 5059
RMD160 45c9b9729cd8f57a87541b04655953c5b24b4998 iptables-1.3.5-r1.ebuild 5059
@@ -113,10 +104,6 @@ EBUILD iptables-1.3.5-r4.ebuild 5778 RMD160 765eac409e003caeafbf350082d4a1be02d8
MD5 947dbc3f8973ca65a0b82103d7998608 iptables-1.3.5-r4.ebuild 5778
RMD160 765eac409e003caeafbf350082d4a1be02d825cf iptables-1.3.5-r4.ebuild 5778
SHA256 0d360603e2e5aa4a5a2049074884fdd0bc92100841796d545c3671dc5b3a32a6 iptables-1.3.5-r4.ebuild 5778
-EBUILD iptables-1.3.5.ebuild 5064 RMD160 f8e01015e5804862da12168cca8da9bf451dfb14 SHA1 d1b64266e3cadc4932729d10219ba37962abbc54 SHA256 1a37910c39e95ed8efbf2aaf132fc8c6878b61e0cbeb635ca072d9a68193f94e
-MD5 925412ddd3ef1cda9a5c0016c2268c06 iptables-1.3.5.ebuild 5064
-RMD160 f8e01015e5804862da12168cca8da9bf451dfb14 iptables-1.3.5.ebuild 5064
-SHA256 1a37910c39e95ed8efbf2aaf132fc8c6878b61e0cbeb635ca072d9a68193f94e iptables-1.3.5.ebuild 5064
MISC ChangeLog 23419 RMD160 8545706bb185094cc8c56d9e2d815be570962cdb SHA1 cf78795c721f06dce0d0578333b34833374f6d57 SHA256 dff344ce690cd35610b2dfd89b5063b9eb5da68d599436d0acb214ee8f11cf19
MD5 5fdc5aa7d3d2a9825c6d064ea5c5cac4 ChangeLog 23419
RMD160 8545706bb185094cc8c56d9e2d815be570962cdb ChangeLog 23419
@@ -128,12 +115,6 @@ SHA256 f5f2891f2a4791cd31350bb2bb572131ad7235cd0eeb124c9912c187ac10ce92 metadata
MD5 13a88a9390927b902c50843734a3bae4 files/digest-iptables-1.2.11-r3 250
RMD160 3f1cbe40eb8c267d72842a5cec5681cb710449b7 files/digest-iptables-1.2.11-r3 250
SHA256 b8bb323081b1c2700c2ce6fb31ae2ea180d3bbb0edcc404e6be23d6a50d00215 files/digest-iptables-1.2.11-r3 250
-MD5 d8412205d0e5195df31005c102dc4ce6 files/digest-iptables-1.3.4 756
-RMD160 23b786e469dbf88bd7f76c38ec02aa9525269ed1 files/digest-iptables-1.3.4 756
-SHA256 47723c1ea73cc5f4621f5b1f51d82792458f4f2fbd7ee30dbe2e37ec1e6e340b files/digest-iptables-1.3.4 756
-MD5 487c5df3e591b37fbe905e466b2b9560 files/digest-iptables-1.3.5 756
-RMD160 e8d5c054fc04e02e88abd7ecb02a8ff006c09202 files/digest-iptables-1.3.5 756
-SHA256 32d999c1b29451f454b3a53a4786425c5de23643018053be490b581e622c2b84 files/digest-iptables-1.3.5 756
MD5 4a0d337b8990fcc5411564ea9d8bca67 files/digest-iptables-1.3.5-r1 756
RMD160 06ac6ffaeaf6cdad1b079eacfe04010503882906 files/digest-iptables-1.3.5-r1 756
SHA256 91af3410c7dc59b6e89e0ef49860324769521f291bc7299de62392b8232f71e5 files/digest-iptables-1.3.5-r1 756
@@ -146,10 +127,3 @@ SHA256 5526edeb288993a93689f0d39cacd94bc6dbd0f8f41ea3b4e30b1d4790acee72 files/di
MD5 aad33073eeb74d8f8b7b7c1d8a15feda files/digest-iptables-1.3.5-r4 759
RMD160 b1301d3acf934885365d3dc23a56a0254f97f266 files/digest-iptables-1.3.5-r4 759
SHA256 77bb5fb7a5d08a68d83c29526ac411e6e40c1a8ae103bf446895f7b355bc5e7c files/digest-iptables-1.3.5-r4 759
------BEGIN PGP SIGNATURE-----
-Version: GnuPG v1.4.5 (GNU/Linux)
-
-iD8DBQFFHsAlamhnQswr0vIRAm2HAJ4uAKYCRADyCWDNxfeQoaIy07YDkgCghrqc
-vO9XedlNf5QrnaLhNDKUQ0Y=
-=nOUP
------END PGP SIGNATURE-----
diff --git a/net-firewall/iptables/files/digest-iptables-1.3.4 b/net-firewall/iptables/files/digest-iptables-1.3.4
deleted file mode 100644
index 8f3db7774f73..000000000000
--- a/net-firewall/iptables/files/digest-iptables-1.3.4
+++ /dev/null
@@ -1,9 +0,0 @@
-MD5 9adae8be9562775a176fc1b275b3cb29 iptables-1.3.0-imq1.diff 5369
-RMD160 8ca1fa3bfea02d27232d8d8cb0a12586dd4537b5 iptables-1.3.0-imq1.diff 5369
-SHA256 0f9d36e48b3f1e83ef9e1d39c19e7271a889a31c65c396c416200eb143f1795b iptables-1.3.0-imq1.diff 5369
-MD5 fdff8abe890807968226b0c374335305 iptables-1.3.4.tar.bz2 189847
-RMD160 3e37965406ae8a39896dead16e5a3722fc9256b4 iptables-1.3.4.tar.bz2 189847
-SHA256 2067ed2134adde5f50716dd1d3752dfb023a634ff274af88eb635e5a1bba1bda iptables-1.3.4.tar.bz2 189847
-MD5 dda42e68897845546e1b9715131c729b netfilter-layer7-v2.0.tar.gz 88489
-RMD160 8e2f76f44db06d5b1b098c2ea37a10befd28e8a8 netfilter-layer7-v2.0.tar.gz 88489
-SHA256 1a454c77a07c6447a2c641cc9d5f255023f1c1d5363b463825da5f3d5942168f netfilter-layer7-v2.0.tar.gz 88489
diff --git a/net-firewall/iptables/files/digest-iptables-1.3.5 b/net-firewall/iptables/files/digest-iptables-1.3.5
deleted file mode 100644
index 530eca3e2524..000000000000
--- a/net-firewall/iptables/files/digest-iptables-1.3.5
+++ /dev/null
@@ -1,9 +0,0 @@
-MD5 9adae8be9562775a176fc1b275b3cb29 iptables-1.3.0-imq1.diff 5369
-RMD160 8ca1fa3bfea02d27232d8d8cb0a12586dd4537b5 iptables-1.3.0-imq1.diff 5369
-SHA256 0f9d36e48b3f1e83ef9e1d39c19e7271a889a31c65c396c416200eb143f1795b iptables-1.3.0-imq1.diff 5369
-MD5 00fb916fa8040ca992a5ace56d905ea5 iptables-1.3.5.tar.bz2 191820
-RMD160 3364e0f37f67ba4aa9ac9caa6f11adb67887e528 iptables-1.3.5.tar.bz2 191820
-SHA256 1d8ee8634d167b0f1a8872b6547910c11bae676699faf2b4bc2c84a128449c3c iptables-1.3.5.tar.bz2 191820
-MD5 dda42e68897845546e1b9715131c729b netfilter-layer7-v2.0.tar.gz 88489
-RMD160 8e2f76f44db06d5b1b098c2ea37a10befd28e8a8 netfilter-layer7-v2.0.tar.gz 88489
-SHA256 1a454c77a07c6447a2c641cc9d5f255023f1c1d5363b463825da5f3d5942168f netfilter-layer7-v2.0.tar.gz 88489
diff --git a/net-firewall/iptables/iptables-1.3.4.ebuild b/net-firewall/iptables/iptables-1.3.4.ebuild
deleted file mode 100644
index c97fb92a9b35..000000000000
--- a/net-firewall/iptables/iptables-1.3.4.ebuild
+++ /dev/null
@@ -1,161 +0,0 @@
-# Copyright 1999-2006 Gentoo Foundation
-# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-firewall/iptables/iptables-1.3.4.ebuild,v 1.11 2006/02/04 17:50:47 vapier Exp $
-
-inherit eutils flag-o-matic toolchain-funcs linux-info
-
-L7_PV="2.0"
-L7_P="netfilter-layer7-v${L7_PV}"
-L7_PATCH="iptables-layer7-2.0.patch"
-IMQ_PATCH="iptables-1.3.0-imq1.diff"
-
-DESCRIPTION="Linux kernel (2.4+) firewall, NAT and packet mangling tools"
-HOMEPAGE="http://www.iptables.org/ http://www.linuximq.net/ http://l7-filter.sf.net/"
-SRC_URI="http://iptables.org/projects/iptables/files/${P}.tar.bz2
- extensions? (
- http://www.linuximq.net/patchs/${IMQ_PATCH}
- mirror://sourceforge/l7-filter/${L7_P}.tar.gz
- )"
-
-LICENSE="GPL-2"
-SLOT="0"
-KEYWORDS="alpha amd64 arm hppa ia64 m68k mips ppc ppc64 s390 sh sparc x86"
-IUSE="ipv6 static extensions"
-
-DEPEND="virtual/os-headers
- extensions? ( virtual/linux-sources )"
-RDEPEND=""
-
-pkg_setup() {
- if use extensions ; then
- ewarn "WARNING: 3rd party extensions has been enabled."
- ewarn "This means that iptables will use your currently installed"
- ewarn "kernel in ${KERNEL_DIR} as headers for iptables."
- ewarn
- ewarn "You may have to patch your kernel to allow iptables to build."
- ewarn "Please check http://ftp.netfilter.org/pub/patch-o-matic-ng/snapshot/ for patches"
- ewarn "for your kernel."
- ewarn
- ewarn "For layer 7 support emerge net-misc/l7-filter-${L7_PV} before this"
- linux-info_pkg_setup
- fi
-}
-
-src_unpack() {
- unpack ${P}.tar.bz2
- use extensions && unpack ${L7_P}.tar.gz
- cd "${S}"
-
- EPATCH_OPTS="-p0" \
- epatch "${FILESDIR}"/1.3.1-files/install_ipv6_apps.patch
- EPATCH_OPTS="-p1" \
- epatch "${FILESDIR}"/1.3.1-files/install_all_dev_files.patch-1.3.1
-
- # this provide's grsec's stealth match
- EPATCH_OPTS="-p0" \
- epatch "${FILESDIR}"/1.3.1-files/grsecurity-1.2.8-iptables.patch-1.3.1
- sed -i \
- -e "s/PF_EXT_SLIB:=/PF_EXT_SLIB:=stealth /g" \
- extensions/Makefile || die "failed to enable stealth extension"
-
- EPATCH_OPTS="-p1" \
- epatch "${FILESDIR}"/1.3.1-files/${PN}-1.3.1-compilefix.patch
-
- if use extensions ; then
- EPATCH_OPTS="-p1" epatch "${DISTDIR}"/${IMQ_PATCH}
- EPATCH_OPTS="-p1" epatch "${WORKDIR}"/${L7_P}/${L7_PATCH}
- chmod +x extensions/{.IMQ-test*,.childlevel-test*,.layer7-test*}
- fi
-}
-
-
-src_defs() {
- # these are used in both of src_compile and src_install
- myconf="${myconf} PREFIX="
- myconf="${myconf} LIBDIR=/$(get_libdir)"
- myconf="${myconf} BINDIR=/sbin"
- myconf="${myconf} MANDIR=/usr/share/man"
- myconf="${myconf} INCDIR=/usr/include"
- # iptables and libraries are now installed to /sbin and /lib, so that
- # systems with remote network-mounted /usr filesystems can get their
- # network interfaces up and running correctly without /usr.
- use ipv6 || myconf="${myconf} DO_IPV6=0"
- use static && myconf="${myconf} NO_SHARED_LIBS=0"
- export myconf
- if ! use extensions ; then
- export KERNEL_DIR="/usr"
- diemsg=""
- else
- diemsg="Please check http://cvs.iptables.org/patch-o-matic-ng/updates/ if your kernel needs to be patched for iptables"
- fi
- export diemsg
-}
-
-
-src_compile() {
- src_defs
-
- # iptables will NOT work correctly unless -O[123] are present!
- replace-flags -O0 -O2
- get-flag -O || append-flags -O2
-
- # prevent it from causing ICMP errors.
- # http://bugs.gentoo.org/show_bug.cgi?id=23645
- filter-flags -fstack-protector
-
- emake -j1 \
- COPT_FLAGS="${CFLAGS}" ${myconf} \
- KERNEL_DIR="${KERNEL_DIR}" \
- CC="$(tc-getCC)" \
- || die "${diemsg}"
-}
-
-src_install() {
- src_defs
- make ${myconf} \
- DESTDIR="${D}" \
- KERNEL_DIR="${KERNEL_DIR}" \
- install install-devel || die "${diemsg}"
-
- dodir /usr/$(get_libdir)
- mv -f "${D}"/$(get_libdir)/*.a "${D}"/usr/$(get_libdir)
-
- keepdir /var/lib/iptables
- newinitd "${FILESDIR}"/${PN}-1.3.2.init iptables
- newconfd "${FILESDIR}"/${PN}-1.3.2.confd iptables
-
- if use ipv6 ; then
- keepdir /var/lib/ip6tables
- newinitd "${FILESDIR}"/iptables-1.3.2.init ip6tables
- newconfd "${FILESDIR}"/ip6tables-1.3.2.confd ip6tables
- fi
-}
-
-pkg_postinst() {
- einfo "This package now includes an initscript which loads and saves"
- einfo "rules stored in /var/lib/iptables/rules-save"
- use ipv6 && einfo "and /var/lib/ip6tables/rules-save"
- einfo "This location can be changed in /etc/conf.d/iptables"
- einfo
- einfo "If you are using the iptables initsscript you should save your"
- einfo "rules using the new iptables version before rebooting."
- einfo
- einfo "If you are upgrading to a >=2.4.21 kernel you may need to rebuild"
- einfo "iptables."
- einfo
- ewarn "!!! ipforwarding is now not a part of the iptables initscripts."
- einfo
- einfo "To enable ipforwarding at bootup:"
- einfo "/etc/sysctl.conf and set net.ipv4.ip_forward = 1"
- if use ipv6 ; then
- einfo "and/or"
- einfo " net.ipv6.ip_forward = 1"
- einfo "for ipv6."
- fi
- if has_version '=net-firewall/iptables-1.2*' ; then
- echo
- ewarn "When upgrading from iptables-1.2.x, you may be unable to remove"
- ewarn "rules added with iptables-1.2.x. This is a known issue, please see:"
- ewarn "http://bugs.gentoo.org/92535"
- fi
-}
diff --git a/net-firewall/iptables/iptables-1.3.5.ebuild b/net-firewall/iptables/iptables-1.3.5.ebuild
deleted file mode 100644
index 4d0aa70e4d58..000000000000
--- a/net-firewall/iptables/iptables-1.3.5.ebuild
+++ /dev/null
@@ -1,161 +0,0 @@
-# Copyright 1999-2006 Gentoo Foundation
-# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-firewall/iptables/iptables-1.3.5.ebuild,v 1.3 2006/02/04 22:16:37 vapier Exp $
-
-inherit eutils flag-o-matic toolchain-funcs linux-info
-
-L7_PV="2.0"
-L7_P="netfilter-layer7-v${L7_PV}"
-L7_PATCH="iptables-layer7-2.0.patch"
-IMQ_PATCH="iptables-1.3.0-imq1.diff"
-
-DESCRIPTION="Linux kernel (2.4+) firewall, NAT and packet mangling tools"
-HOMEPAGE="http://www.iptables.org/ http://www.linuximq.net/ http://l7-filter.sf.net/"
-SRC_URI="http://iptables.org/projects/iptables/files/${P}.tar.bz2
- extensions? (
- http://www.linuximq.net/patchs/${IMQ_PATCH}
- mirror://sourceforge/l7-filter/${L7_P}.tar.gz
- )"
-
-LICENSE="GPL-2"
-SLOT="0"
-KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~x86"
-IUSE="ipv6 static extensions"
-
-DEPEND="virtual/os-headers
- extensions? ( virtual/linux-sources )"
-RDEPEND=""
-
-pkg_setup() {
- if use extensions ; then
- ewarn "WARNING: 3rd party extensions has been enabled."
- ewarn "This means that iptables will use your currently installed"
- ewarn "kernel in ${KERNEL_DIR} as headers for iptables."
- ewarn
- ewarn "You may have to patch your kernel to allow iptables to build."
- ewarn "Please check http://ftp.netfilter.org/pub/patch-o-matic-ng/snapshot/ for patches"
- ewarn "for your kernel."
- ewarn
- ewarn "For layer 7 support emerge net-misc/l7-filter-${L7_PV} before this"
- linux-info_pkg_setup
- fi
-}
-
-src_unpack() {
- unpack ${P}.tar.bz2
- use extensions && unpack ${L7_P}.tar.gz
- cd "${S}"
-
- EPATCH_OPTS="-p0" \
- epatch "${FILESDIR}"/1.3.1-files/install_ipv6_apps.patch
- EPATCH_OPTS="-p1" \
- epatch "${FILESDIR}"/1.3.1-files/install_all_dev_files.patch-1.3.1
-
- # this provide's grsec's stealth match
- EPATCH_OPTS="-p0" \
- epatch "${FILESDIR}"/1.3.1-files/grsecurity-1.2.8-iptables.patch-1.3.1
- sed -i \
- -e "s/PF_EXT_SLIB:=/PF_EXT_SLIB:=stealth /g" \
- extensions/Makefile || die "failed to enable stealth extension"
-
- EPATCH_OPTS="-p1" \
- epatch "${FILESDIR}"/1.3.1-files/${PN}-1.3.1-compilefix.patch
-
- if use extensions ; then
- EPATCH_OPTS="-p1" epatch "${DISTDIR}"/${IMQ_PATCH}
- EPATCH_OPTS="-p1" epatch "${WORKDIR}"/${L7_P}/${L7_PATCH}
- chmod +x extensions/{.IMQ-test*,.childlevel-test*,.layer7-test*}
- fi
-}
-
-
-src_defs() {
- # these are used in both of src_compile and src_install
- myconf="${myconf} PREFIX="
- myconf="${myconf} LIBDIR=/$(get_libdir)"
- myconf="${myconf} BINDIR=/sbin"
- myconf="${myconf} MANDIR=/usr/share/man"
- myconf="${myconf} INCDIR=/usr/include"
- # iptables and libraries are now installed to /sbin and /lib, so that
- # systems with remote network-mounted /usr filesystems can get their
- # network interfaces up and running correctly without /usr.
- use ipv6 || myconf="${myconf} DO_IPV6=0"
- use static && myconf="${myconf} NO_SHARED_LIBS=0"
- export myconf
- if ! use extensions ; then
- export KERNEL_DIR="/usr"
- diemsg=""
- else
- diemsg="Please check http://cvs.iptables.org/patch-o-matic-ng/updates/ if your kernel needs to be patched for iptables"
- fi
- export diemsg
-}
-
-
-src_compile() {
- src_defs
-
- # iptables will NOT work correctly unless -O[123] are present!
- replace-flags -O0 -O2
- get-flag -O || append-flags -O2
-
- # prevent it from causing ICMP errors.
- # http://bugs.gentoo.org/show_bug.cgi?id=23645
- filter-flags -fstack-protector
-
- emake -j1 \
- COPT_FLAGS="${CFLAGS}" ${myconf} \
- KERNEL_DIR="${KERNEL_DIR}" \
- CC="$(tc-getCC)" \
- || die "${diemsg}"
-}
-
-src_install() {
- src_defs
- make ${myconf} \
- DESTDIR="${D}" \
- KERNEL_DIR="${KERNEL_DIR}" \
- install install-devel || die "${diemsg}"
-
- dodir /usr/$(get_libdir)
- mv -f "${D}"/$(get_libdir)/*.a "${D}"/usr/$(get_libdir)
-
- keepdir /var/lib/iptables
- newinitd "${FILESDIR}"/${PN}-1.3.2.init iptables
- newconfd "${FILESDIR}"/${PN}-1.3.2.confd iptables
-
- if use ipv6 ; then
- keepdir /var/lib/ip6tables
- newinitd "${FILESDIR}"/iptables-1.3.2.init ip6tables
- newconfd "${FILESDIR}"/ip6tables-1.3.2.confd ip6tables
- fi
-}
-
-pkg_postinst() {
- einfo "This package now includes an initscript which loads and saves"
- einfo "rules stored in /var/lib/iptables/rules-save"
- use ipv6 && einfo "and /var/lib/ip6tables/rules-save"
- einfo "This location can be changed in /etc/conf.d/iptables"
- einfo
- einfo "If you are using the iptables initsscript you should save your"
- einfo "rules using the new iptables version before rebooting."
- einfo
- einfo "If you are upgrading to a >=2.4.21 kernel you may need to rebuild"
- einfo "iptables."
- einfo
- ewarn "!!! ipforwarding is now not a part of the iptables initscripts."
- einfo
- einfo "To enable ipforwarding at bootup:"
- einfo "/etc/sysctl.conf and set net.ipv4.ip_forward = 1"
- if use ipv6 ; then
- einfo "and/or"
- einfo " net.ipv6.ip_forward = 1"
- einfo "for ipv6."
- fi
- if has_version '=net-firewall/iptables-1.2*' ; then
- echo
- ewarn "When upgrading from iptables-1.2.x, you may be unable to remove"
- ewarn "rules added with iptables-1.2.x. This is a known issue, please see:"
- ewarn "http://bugs.gentoo.org/92535"
- fi
-}