summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAlin Năstac <mrness@gentoo.org>2008-10-12 16:39:14 +0000
committerAlin Năstac <mrness@gentoo.org>2008-10-12 16:39:14 +0000
commit82cf03a42dfb4d81b26cdb9f991ae2b2aff4d302 (patch)
tree20b757ea594646b668176b9371116fda6fc948ca /net-misc/openswan
parentbump to 2.22.3-r1, backport upstream bug fixes announced on distributor list. (diff)
downloadgentoo-2-82cf03a42dfb4d81b26cdb9f991ae2b2aff4d302.tar.gz
gentoo-2-82cf03a42dfb4d81b26cdb9f991ae2b2aff4d302.tar.bz2
gentoo-2-82cf03a42dfb4d81b26cdb9f991ae2b2aff4d302.zip
Remove livetest script wrt security bug #238574.
Skip xml validation (#237132). (Portage version: 2.1.4.4, RepoMan options: --force)
Diffstat (limited to 'net-misc/openswan')
-rw-r--r--net-misc/openswan/ChangeLog11
-rw-r--r--net-misc/openswan/files/openswan-2.4.13-gentoo-fixed.patch12
-rw-r--r--net-misc/openswan/files/openswan-2.6.18-gentoo.patch104
-rw-r--r--net-misc/openswan/openswan-2.4.13-r1.ebuild (renamed from net-misc/openswan/openswan-2.4.13.ebuild)2
-rw-r--r--net-misc/openswan/openswan-2.6.18.ebuild161
5 files changed, 288 insertions, 2 deletions
diff --git a/net-misc/openswan/ChangeLog b/net-misc/openswan/ChangeLog
index c8648f3afde2..def8d44653e8 100644
--- a/net-misc/openswan/ChangeLog
+++ b/net-misc/openswan/ChangeLog
@@ -1,6 +1,15 @@
# ChangeLog for net-misc/openswan
# Copyright 2002-2008 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/net-misc/openswan/ChangeLog,v 1.53 2008/09/21 12:42:31 mrness Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openswan/ChangeLog,v 1.54 2008/10/12 16:39:13 mrness Exp $
+
+*openswan-2.6.18 (12 Oct 2008)
+*openswan-2.4.13-r1 (12 Oct 2008)
+
+ 12 Oct 2008; Alin Năstac <mrness@gentoo.org>
+ files/openswan-2.4.13-gentoo-fixed.patch,
+ +files/openswan-2.6.18-gentoo.patch, -openswan-2.4.13.ebuild,
+ +openswan-2.4.13-r1.ebuild, +openswan-2.6.18.ebuild:
+ Remove livetest script wrt security bug #238574. Skip xml validation (#237132).
*openswan-2.6.16 (21 Sep 2008)
diff --git a/net-misc/openswan/files/openswan-2.4.13-gentoo-fixed.patch b/net-misc/openswan/files/openswan-2.4.13-gentoo-fixed.patch
index 1a4f9575ae4f..0be5a8d38ef6 100644
--- a/net-misc/openswan/files/openswan-2.4.13-gentoo-fixed.patch
+++ b/net-misc/openswan/files/openswan-2.4.13-gentoo-fixed.patch
@@ -19,6 +19,18 @@ diff -ur openswan-2.4.13.orig/Makefile.inc openswan-2.4.13/Makefile.inc
EXAMPLECONFDIR=${DESTDIR}${FINALEXAMPLECONFDIR}
FINALDOCDIR?=${INC_USRLOCAL}/${INC_DOCDIR}/openswan
+diff -Nru openswan-2.4.13.orig/programs/Makefile openswan-2.4.13/programs/Makefile
+--- openswan-2.4.13.orig/programs/Makefile 2006-10-27 14:47:07.000000000 +0000
++++ openswan-2.4.13/programs/Makefile 2008-10-12 16:12:31.000000000 +0000
+@@ -24,7 +24,7 @@
+ SUBDIRS+=_realsetup _secretcensor _startklips _updown _updown_x509
+ SUBDIRS+=auto barf verify ipsec look manual newhostkey ranbits secrets
+ SUBDIRS+=rsasigkey setup showdefaults showhostkey calcgoo mailkey
+-SUBDIRS+=ikeping examples livetest
++SUBDIRS+=ikeping examples
+
+ ifeq ($(USE_LWRES),true)
+ SUBDIRS+=lwdnsq
diff -ur openswan-2.4.13.orig/programs/_confread/_confread.in openswan-2.4.13/programs/_confread/_confread.in
--- openswan-2.4.13.orig/programs/_confread/_confread.in 2006-04-12 19:55:42.000000000 +0000
+++ openswan-2.4.13/programs/_confread/_confread.in 2008-08-16 09:56:57.000000000 +0000
diff --git a/net-misc/openswan/files/openswan-2.6.18-gentoo.patch b/net-misc/openswan/files/openswan-2.6.18-gentoo.patch
new file mode 100644
index 000000000000..fe493b3dc38a
--- /dev/null
+++ b/net-misc/openswan/files/openswan-2.6.18-gentoo.patch
@@ -0,0 +1,104 @@
+diff -Nru openswan-2.6.18.orig/Makefile.inc openswan-2.6.18/Makefile.inc
+--- openswan-2.6.18.orig/Makefile.inc 2008-10-12 16:30:24.000000000 +0000
++++ openswan-2.6.18/Makefile.inc 2008-10-12 16:27:49.000000000 +0000
+@@ -49,7 +49,7 @@
+ DESTDIR?=
+
+ # "local" part of tree, used in building other pathnames
+-INC_USRLOCAL=/usr/local
++INC_USRLOCAL?=/usr
+
+ # PUBDIR is where the "ipsec" command goes; beware, many things define PATH
+ # settings which are assumed to include it (or at least, to include *some*
+@@ -94,7 +94,7 @@
+
+ # sample configuration files go into
+ INC_DOCDIR?=share/doc
+-FINALEXAMPLECONFDIR=${INC_USRLOCAL}/${INC_DOCDIR}/openswan
++FINALEXAMPLECONFDIR?=${INC_USRLOCAL}/${INC_DOCDIR}/openswan
+ EXAMPLECONFDIR=${DESTDIR}${FINALEXAMPLECONFDIR}
+
+ FINALDOCDIR?=${INC_USRLOCAL}/${INC_DOCDIR}/openswan
+diff -Nru openswan-2.6.18.orig/programs/Makefile openswan-2.6.18/programs/Makefile
+--- openswan-2.6.18.orig/programs/Makefile 2008-10-12 16:30:24.000000000 +0000
++++ openswan-2.6.18/programs/Makefile 2008-10-12 16:27:49.000000000 +0000
+@@ -42,7 +42,7 @@
+ SUBDIRS+=_realsetup _secretcensor _startklips _updown _updown.klips _updown.mast
+ SUBDIRS+=auto barf verify ipsec look newhostkey ranbits secrets
+ SUBDIRS+=rsasigkey setup showdefaults showhostkey
+-SUBDIRS+=ikeping examples livetest
++SUBDIRS+=ikeping examples
+ ifeq ($(USE_KLIPS),true)
+ SUBDIRS+= _startklips _updown.klips
+ endif
+diff -Nru openswan-2.6.18.orig/programs/Makefile.manpages openswan-2.6.18/programs/Makefile.manpages
+--- openswan-2.6.18.orig/programs/Makefile.manpages 2008-10-06 16:52:49.000000000 +0000
++++ openswan-2.6.18/programs/Makefile.manpages 2008-10-12 16:30:42.000000000 +0000
+@@ -1,15 +1,15 @@
+ # xmlto is from http://cyberelk.net/tim/xmlto/
+ ifneq ($(strip $(XMLTO)),)
+ %.8: %.8.xml
+- ${XMLTO} man $<
++ ${XMLTO} --skip-validation man $<
+ @for m in ipsec_*.8; do if [ -f $$m ]; then mv $$m $@; fi; done
+
+ %.5: %.5.xml
+- ${XMLTO} man $<
++ ${XMLTO} --skip-validation man $<
+ @for m in ipsec_*.5; do if [ -f $$m ]; then mv $$m $@; fi; done
+
+ %.1: %.1.xml
+- ${XMLTO} man $<
++ ${XMLTO} --skip-validation man $<
+ @for m in ipsec_*.1; do if [ -f $$m ]; then mv $$m $@; fi; done
+ endif
+
+diff -Nru openswan-2.6.18.orig/programs/setup/Makefile openswan-2.6.18/programs/setup/Makefile
+--- openswan-2.6.18.orig/programs/setup/Makefile 2008-10-12 16:30:24.000000000 +0000
++++ openswan-2.6.18/programs/setup/Makefile 2008-10-12 16:27:49.000000000 +0000
+@@ -18,7 +18,6 @@
+
+ # this dance is because setup has to get installed as /etc/rc.d/init.d/ipsec
+ # not as /etc/rc.d/init.d/setup.
+-PROGRAMDIR=$(RCDIR)
+ PROGRAM=setup
+ EXTRA8MAN=setup.8
+
+@@ -29,32 +28,6 @@
+ # into the $BINDIR.
+ #
+ # the priorities match those in setup's chkconfig line
+-doinstall:: setup
+- @rm -f $(BINDIR)/setup
+- @$(INSTALL) $(INSTBINFLAGS) setup $(RCDIR)/ipsec
+- @ln -s $(FINALRCDIR)/ipsec $(BINDIR)/setup
+- -@for i in 0 1 2 3 4 5 6; do mkdir -p $(RCDIR)/../rc$$i.d; done
+- -@cd $(RCDIR)/../rc0.d && ln -f -s ../init.d/ipsec K76ipsec
+- -@cd $(RCDIR)/../rc1.d && ln -f -s ../init.d/ipsec K76ipsec
+- -@cd $(RCDIR)/../rc2.d && ln -f -s ../init.d/ipsec S47ipsec
+- -@cd $(RCDIR)/../rc3.d && ln -f -s ../init.d/ipsec S47ipsec
+- -@cd $(RCDIR)/../rc4.d && ln -f -s ../init.d/ipsec S47ipsec
+- -@cd $(RCDIR)/../rc5.d && ln -f -s ../init.d/ipsec S47ipsec
+- -@cd $(RCDIR)/../rc6.d && ln -f -s ../init.d/ipsec K76ipsec
+-
+-install_file_list::
+- @echo $(RCDIR)/ipsec
+- @echo $(BINDIR)/setup
+- @echo $(RCDIR)/../rc0.d/K76ipsec
+- @echo $(RCDIR)/../rc1.d/K76ipsec
+- @echo $(RCDIR)/../rc2.d/S47ipsec
+- @echo $(RCDIR)/../rc3.d/S47ipsec
+- @echo $(RCDIR)/../rc4.d/S47ipsec
+- @echo $(RCDIR)/../rc5.d/S47ipsec
+- @echo $(RCDIR)/../rc6.d/K76ipsec
+-
+-cleanall::
+- @rm -f setup
+
+ #
+ # $Log: openswan-2.6.18-gentoo.patch,v $
+ # Revision 1.1 2008/10/12 16:39:14 mrness
+ # Remove livetest script wrt security bug #238574.
+ # Skip xml validation (#237132).
+ # (Portage version: 2.1.4.4, RepoMan options: --force)
+ #
diff --git a/net-misc/openswan/openswan-2.4.13.ebuild b/net-misc/openswan/openswan-2.4.13-r1.ebuild
index c080a0af16a0..41a87dab1619 100644
--- a/net-misc/openswan/openswan-2.4.13.ebuild
+++ b/net-misc/openswan/openswan-2.4.13-r1.ebuild
@@ -1,6 +1,6 @@
# Copyright 1999-2008 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-misc/openswan/openswan-2.4.13.ebuild,v 1.3 2008/09/17 20:57:16 maekke Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openswan/openswan-2.4.13-r1.ebuild,v 1.1 2008/10/12 16:39:13 mrness Exp $
inherit eutils linux-info
diff --git a/net-misc/openswan/openswan-2.6.18.ebuild b/net-misc/openswan/openswan-2.6.18.ebuild
new file mode 100644
index 000000000000..df5933851be2
--- /dev/null
+++ b/net-misc/openswan/openswan-2.6.18.ebuild
@@ -0,0 +1,161 @@
+# Copyright 1999-2008 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openswan/openswan-2.6.18.ebuild,v 1.1 2008/10/12 16:39:13 mrness Exp $
+
+inherit eutils linux-info
+
+DESCRIPTION="Open Source implementation of IPsec for the Linux operating system (was SuperFreeS/WAN)."
+HOMEPAGE="http://www.openswan.org/"
+SRC_URI="http://www.openswan.org/download/${P}.tar.gz"
+
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="~amd64 ~ppc ~sparc ~x86"
+IUSE="curl ldap smartcard extra-algorithms weak-algorithms nocrypto-algorithms"
+
+COMMON_DEPEND="!net-misc/strongswan
+ dev-libs/gmp
+ dev-lang/perl
+ smartcard? ( dev-libs/opensc )
+ curl? ( net-misc/curl )
+ ldap? ( net-nds/openldap )"
+DEPEND="${COMMON_DEPEND}
+ virtual/linux-sources
+ app-text/xmlto"
+RDEPEND="${COMMON_DEPEND}
+ virtual/logger
+ sys-apps/iproute2"
+
+pkg_setup() {
+ if use nocrypto-algorithms && ! use weak-algorithms; then
+ ewarn "Enabling nocrypto-algorithms USE flag has no effect when"
+ ewarn "weak-algorithms USE flag is disabled"
+ fi
+
+ linux-info_pkg_setup
+
+ if kernel_is 2 6; then
+ einfo "This ebuild will set ${P} to use 2.6 native IPsec (KAME)."
+ einfo "KLIPS will not be compiled/installed."
+ MYMAKE="programs"
+
+ elif kernel_is 2 4; then
+ if ! [[ -d "${KERNEL_DIR}/net/ipsec" ]]; then
+ eerror "You need to have an IPsec enabled 2.4.x kernel."
+ eerror "Ensure you have one running and make a symlink to it in /usr/src/linux"
+ die
+ fi
+
+ einfo "Using patched-in IPsec code for kernel 2.4"
+ einfo "Your kernel only supports KLIPS for kernel level IPsec."
+ MYMAKE="confcheck programs"
+
+ else
+ die "Unsupported kernel version"
+ fi
+}
+
+src_unpack() {
+ unpack ${A}
+
+ cd "${S}"
+ epatch "${FILESDIR}"/${P}-gentoo.patch
+
+ find . -regex '.*[.][1-8]' -exec sed -i \
+ -e s:/usr/local:/usr:g '{}' \; ||
+ die "failed to replace text in xml docs"
+}
+
+get_make_options() {
+ echo KERNELSRC=\"${KERNEL_DIR}\" \
+ FINALEXAMPLECONFDIR=/usr/share/doc/${P} \
+ INC_RCDEFAULT=/etc/init.d \
+ INC_USRLOCAL=/usr \
+ INC_MANDIR=share/man \
+ FINALDOCDIR=/usr/share/doc/${P} \
+ DESTDIR=\"${D}\" \
+ USERCOMPILE=\"${CFLAGS}\"
+ if use smartcard ; then
+ echo USE_SMARTCARD=true
+ fi
+ if use extra-algorithms ; then
+ echo USE_EXTRACRYPTO=true
+ else
+ echo USE_EXTRACRYPTO=false
+ fi
+ if use weak-algorithms ; then
+ echo USE_WEAKSTUFF=true
+ if use nocrypto-algorithms; then
+ echo USE_NOCRYPTO=true
+ fi
+ fi
+ echo USE_LWRES=false # needs bind9 with lwres support
+ local USETHREADS=false
+ if use curl; then
+ echo USE_LIBCURL=true
+ USETHREADS=true
+ fi
+ if use ldap; then
+ echo USE_LDAP=true
+ USETHREADS=true
+ fi
+ echo HAVE_THREADS=${USETHREADS}
+}
+
+src_compile() {
+ eval set -- $(get_make_options)
+ emake "$@" \
+ ${MYMAKE} || die "emake failed"
+}
+
+src_install() {
+ eval set -- $(get_make_options)
+ emake "$@" \
+ install || die "emake install failed"
+
+ newinitd "${FILESDIR}"/ipsec-initd ipsec || die "failed to install init script"
+
+ dodir /var/run/pluto || die "failed to create /var/run/pluto"
+}
+
+pkg_preinst() {
+ if has_version "<net-misc/openswan-2.6.14" && pushd "${ROOT}etc/ipsec"; then
+ ewarn "Following files and directories were moved from '${ROOT}etc/ipsec' to '${ROOT}etc':"
+ local i err=0
+ if [ -h "../ipsec.d" ]; then
+ rm "../ipsec.d" || die "failed to remove ../ipsec.d symlink"
+ fi
+ for i in *; do
+ if [ -e "../$i" ]; then
+ eerror " $i NOT MOVED, ../$i already exists!"
+ err=1
+ elif [ -d "$i" ]; then
+ mv "$i" .. || die "failed to move $i directory"
+ ewarn " directory $i"
+ elif [ -f "$i" ]; then
+ sed -i -e 's:/etc/ipsec/:/etc/:g' "$i" && \
+ mv "$i" .. && ewarn " file $i" || \
+ die "failed to move $i file"
+ else
+ eerror " $i NOT MOVED, it is not a file nor a directory!"
+ err=1
+ fi
+ done
+ popd
+ if [ $err -eq 0 ]; then
+ rmdir "${ROOT}etc/ipsec" || eerror "Failed to remove ${ROOT}etc/ipsec"
+ else
+ ewarn "${ROOT}etc/ipsec is not empty, you will have to remove it yourself"
+ fi
+ fi
+}
+
+pkg_postinst() {
+ if kernel_is 2 6; then
+ CONFIG_CHECK="~NET_KEY ~INET_XFRM_MODE_TRANSPORT ~INET_XFRM_MODE_TUNNEL ~INET_AH ~INET_ESP ~INET_IPCOMP"
+ WARNING_INET_AH="CONFIG_INET_AH:\tmissing IPsec AH support (needed if you want only authentication)"
+ WARNING_INET_ESP="CONFIG_INET_ESP:\tmissing IPsec ESP support (needed if you want authentication and encryption)"
+ WARNING_INET_IPCOMP="CONFIG_INET_IPCOMP:\tmissing IPsec Payload Compression (required for compress=yes)"
+ check_extra_config
+ fi
+}