1 |
robbat2 08/08/23 22:14:17 |
2 |
|
3 |
Modified: ChangeLog metadata.xml |
4 |
Added: openssh-5.1_p1-r1.ebuild |
5 |
Log: |
6 |
Update the LDAP patches, also mailed to upstream. |
7 |
(Portage version: 2.2_rc8/cvs/Linux 2.6.27-rc1-10246-gca5de40 x86_64) |
8 |
|
9 |
Revision Changes Path |
10 |
1.314 net-misc/openssh/ChangeLog |
11 |
|
12 |
file : http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/ChangeLog?rev=1.314&view=markup |
13 |
plain: http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/ChangeLog?rev=1.314&content-type=text/plain |
14 |
diff : http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/ChangeLog?r1=1.313&r2=1.314 |
15 |
|
16 |
Index: ChangeLog |
17 |
=================================================================== |
18 |
RCS file: /var/cvsroot/gentoo-x86/net-misc/openssh/ChangeLog,v |
19 |
retrieving revision 1.313 |
20 |
retrieving revision 1.314 |
21 |
diff -p -w -b -B -u -u -r1.313 -r1.314 |
22 |
--- ChangeLog 23 Aug 2008 21:33:05 -0000 1.313 |
23 |
+++ ChangeLog 23 Aug 2008 22:14:16 -0000 1.314 |
24 |
@@ -1,6 +1,13 @@ |
25 |
# ChangeLog for net-misc/openssh |
26 |
# Copyright 1999-2008 Gentoo Foundation; Distributed under the GPL v2 |
27 |
-# $Header: /var/cvsroot/gentoo-x86/net-misc/openssh/ChangeLog,v 1.313 2008/08/23 21:33:05 robbat2 Exp $ |
28 |
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openssh/ChangeLog,v 1.314 2008/08/23 22:14:16 robbat2 Exp $ |
29 |
+ |
30 |
+*openssh-5.1_p1-r1 (23 Aug 2008) |
31 |
+ |
32 |
+ 23 Aug 2008; Robin H. Johnson <robbat2@g.o> |
33 |
+ +files/openssh-5.1_p1-ldap-hpn-glue.patch, metadata.xml, |
34 |
+ +openssh-5.1_p1-r1.ebuild: |
35 |
+ Update the LDAP patches, also mailed to upstream. |
36 |
|
37 |
23 Aug 2008; Robin H. Johnson <robbat2@g.o> |
38 |
+files/openssh-5.1_p1-x509-hpn-glue.patch, openssh-5.1_p1.ebuild: |
39 |
|
40 |
|
41 |
|
42 |
1.8 net-misc/openssh/metadata.xml |
43 |
|
44 |
file : http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/metadata.xml?rev=1.8&view=markup |
45 |
plain: http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/metadata.xml?rev=1.8&content-type=text/plain |
46 |
diff : http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/metadata.xml?r1=1.7&r2=1.8 |
47 |
|
48 |
Index: metadata.xml |
49 |
=================================================================== |
50 |
RCS file: /var/cvsroot/gentoo-x86/net-misc/openssh/metadata.xml,v |
51 |
retrieving revision 1.7 |
52 |
retrieving revision 1.8 |
53 |
diff -p -w -b -B -u -u -r1.7 -r1.8 |
54 |
--- metadata.xml 8 Aug 2008 05:02:07 -0000 1.7 |
55 |
+++ metadata.xml 23 Aug 2008 22:14:16 -0000 1.8 |
56 |
@@ -24,5 +24,6 @@ ssh-keygen and sftp-server. OpenSSH supp |
57 |
<flag name="chroot">Enable chrooting support</flag> |
58 |
<flag name="hpn">Enable high performance ssh</flag> |
59 |
<flag name="X509">Adds support for X.509 certificate authentication</flag> |
60 |
+ <flag name="ldap">Add support for storing SSH public keys in LDAP</flag> |
61 |
</use> |
62 |
</pkgmetadata> |
63 |
|
64 |
|
65 |
|
66 |
1.1 net-misc/openssh/openssh-5.1_p1-r1.ebuild |
67 |
|
68 |
file : http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/openssh-5.1_p1-r1.ebuild?rev=1.1&view=markup |
69 |
plain: http://sources.gentoo.org/viewcvs.py/gentoo-x86/net-misc/openssh/openssh-5.1_p1-r1.ebuild?rev=1.1&content-type=text/plain |
70 |
|
71 |
Index: openssh-5.1_p1-r1.ebuild |
72 |
=================================================================== |
73 |
# Copyright 1999-2008 Gentoo Foundation |
74 |
# Distributed under the terms of the GNU General Public License v2 |
75 |
# $Header: /var/cvsroot/gentoo-x86/net-misc/openssh/openssh-5.1_p1-r1.ebuild,v 1.1 2008/08/23 22:14:16 robbat2 Exp $ |
76 |
|
77 |
inherit eutils flag-o-matic ccc multilib autotools pam |
78 |
|
79 |
# Make it more portable between straight releases |
80 |
# and _p? releases. |
81 |
PARCH=${P/_/} |
82 |
|
83 |
X509_PATCH="${PARCH}+x509-6.1.1.diff.gz" |
84 |
LDAP_PATCH="${PARCH/openssh/openssh-lpk}-0.3.10.patch.gz" |
85 |
HPN_PATCH="${PARCH}-hpn13v5.diff.gz" |
86 |
|
87 |
DESCRIPTION="Port of OpenBSD's free SSH release" |
88 |
HOMEPAGE="http://www.openssh.org/" |
89 |
SRC_URI="mirror://openbsd/OpenSSH/portable/${PARCH}.tar.gz |
90 |
http://www.sxw.org.uk/computing/patches/openssh-5.0p1-gsskex-20080404.patch |
91 |
${LDAP_PATCH:+ldap? ( mirror://gentoo/${LDAP_PATCH} )} |
92 |
${X509_PATCH:+X509? ( http://roumenpetrov.info/openssh/x509-6.1.1/${X509_PATCH} )} |
93 |
${HPN_PATCH:+hpn? ( http://www.psc.edu/networking/projects/hpn-ssh/${HPN_PATCH} )}" |
94 |
#${LDAP_PATCH:+ldap? ( http://dev.inversepath.com/openssh-lpk/${LDAP_PATCH} )} |
95 |
|
96 |
LICENSE="as-is" |
97 |
SLOT="0" |
98 |
KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~sparc-fbsd ~x86 ~x86-fbsd" |
99 |
IUSE="static pam tcpd kerberos skey selinux X509 ldap smartcard hpn libedit X" |
100 |
|
101 |
RDEPEND="pam? ( virtual/pam ) |
102 |
kerberos? ( virtual/krb5 ) |
103 |
selinux? ( >=sys-libs/libselinux-1.28 ) |
104 |
skey? ( >=sys-auth/skey-1.1.5-r1 ) |
105 |
ldap? ( net-nds/openldap ) |
106 |
libedit? ( dev-libs/libedit ) |
107 |
>=dev-libs/openssl-0.9.6d |
108 |
>=sys-libs/zlib-1.2.3 |
109 |
smartcard? ( dev-libs/opensc ) |
110 |
tcpd? ( >=sys-apps/tcp-wrappers-7.6 ) |
111 |
X? ( x11-apps/xauth ) |
112 |
userland_GNU? ( sys-apps/shadow )" |
113 |
DEPEND="${RDEPEND} |
114 |
dev-util/pkgconfig |
115 |
virtual/os-headers |
116 |
sys-devel/autoconf" |
117 |
RDEPEND="${RDEPEND} |
118 |
pam? ( sys-auth/pambase )" |
119 |
PROVIDE="virtual/ssh" |
120 |
|
121 |
S=${WORKDIR}/${PARCH} |
122 |
|
123 |
pkg_setup() { |
124 |
# this sucks, but i'd rather have people unable to `emerge -u openssh` |
125 |
# than not be able to log in to their server any more |
126 |
maybe_fail() { [[ -z ${!2} ]] && use ${1} && echo ${1} ; } |
127 |
local fail=" |
128 |
$(maybe_fail X509 X509_PATCH) |
129 |
$(maybe_fail ldap LDAP_PATCH) |
130 |
" |
131 |
fail=$(echo ${fail}) |
132 |
if [[ -n ${fail} ]] ; then |
133 |
eerror "Sorry, but this version does not yet support features" |
134 |
eerror "that you requested: ${fail}" |
135 |
eerror "Please mask ${PF} for now and check back later:" |
136 |
eerror " # echo '=${CATEGORY}/${PF}' >> /etc/portage/package.mask" |
137 |
die "booooo" |
138 |
fi |
139 |
} |
140 |
|
141 |
src_unpack() { |
142 |
unpack ${PARCH}.tar.gz |
143 |
cd "${S}" |
144 |
|
145 |
sed -i \ |
146 |
-e '/_PATH_XAUTH/s:/usr/X11R6/bin/xauth:/usr/bin/xauth:' \ |
147 |
pathnames.h || die |
148 |
|
149 |
use X509 && epatch "${DISTDIR}"/${X509_PATCH} "${FILESDIR}"/${PN}-5.1_p1-x509-hpn-glue.patch |
150 |
use smartcard && epatch "${FILESDIR}"/openssh-3.9_p1-opensc.patch |
151 |
if ! use X509 ; then |
152 |
if [[ -n ${LDAP_PATCH} ]] && use ldap ; then |
153 |
# The patch for bug 210110 64-bit stuff is now included. |
154 |
epatch "${DISTDIR}"/${LDAP_PATCH} |
155 |
epatch "${FILESDIR}"/${PN}-5.1_p1-ldap-hpn-glue.patch |
156 |
fi |
157 |
#epatch "${DISTDIR}"/openssh-5.0p1-gsskex-20080404.patch #115553 #216932 |
158 |
else |
159 |
use ldap && ewarn "Sorry, X509 and ldap don't get along, disabling ldap" |
160 |
fi |
161 |
epatch "${FILESDIR}"/${PN}-4.7_p1-GSSAPI-dns.patch #165444 integrated into gsskex |
162 |
[[ -n ${HPN_PATCH} ]] && use hpn && epatch "${DISTDIR}"/${HPN_PATCH} |
163 |
epatch "${FILESDIR}"/${PN}-4.7p1-selinux.diff #191665 |
164 |
|
165 |
sed -i "s:-lcrypto:$(pkg-config --libs openssl):" configure{,.ac} || die |
166 |
|
167 |
eautoreconf |
168 |
} |
169 |
|
170 |
src_compile() { |
171 |
addwrite /dev/ptmx |
172 |
addpredict /etc/skey/skeykeys #skey configure code triggers this |
173 |
|
174 |
local myconf="" |
175 |
if use static ; then |
176 |
append-ldflags -static |
177 |
use pam && ewarn "Disabling pam support becuse of static flag" |
178 |
myconf="${myconf} --without-pam" |
179 |
else |
180 |
myconf="${myconf} $(use_with pam)" |
181 |
fi |
182 |
|
183 |
econf \ |
184 |
--with-ldflags="${LDFLAGS}" \ |
185 |
--disable-strip \ |
186 |
--sysconfdir=/etc/ssh \ |
187 |
--libexecdir=/usr/$(get_libdir)/misc \ |
188 |
--datadir=/usr/share/openssh \ |
189 |
--with-privsep-path=/var/empty \ |
190 |
--with-privsep-user=sshd \ |
191 |
--with-md5-passwords \ |
192 |
--with-ssl-engine \ |
193 |
${LDAP_PATCH:+$(use_with ldap)} \ |
194 |
$(use_with libedit) \ |
195 |
$(use_with kerberos kerberos5 /usr) \ |
196 |
$(use_with tcpd tcp-wrappers) \ |
197 |
$(use_with selinux) \ |
198 |
$(use_with skey) \ |
199 |
$(use_with smartcard opensc) \ |
200 |
${myconf} \ |
201 |
|| die "bad configure" |
202 |
emake || die "compile problem" |
203 |
} |
204 |
|
205 |
src_install() { |
206 |
emake install-nokeys DESTDIR="${D}" || die |
207 |
fperms 600 /etc/ssh/sshd_config |
208 |
dobin contrib/ssh-copy-id |
209 |
newinitd "${FILESDIR}"/sshd.rc6 sshd |
210 |
newconfd "${FILESDIR}"/sshd.confd sshd |
211 |
keepdir /var/empty |
212 |
|
213 |
newpamd "${FILESDIR}"/sshd.pam_include.2 sshd |
214 |
use pam \ |
215 |
&& dosed "/^#UsePAM /s:.*:UsePAM yes:" /etc/ssh/sshd_config \ |
216 |
&& dosed "/^#PasswordAuthentication /s:.*:PasswordAuthentication no:" /etc/ssh/sshd_config |
217 |
|
218 |
doman contrib/ssh-copy-id.1 |
219 |
dodoc ChangeLog CREDITS OVERVIEW README* TODO sshd_config |
220 |
|
221 |
diropts -m 0700 |
222 |
dodir /etc/skel/.ssh |
223 |
} |
224 |
|
225 |
pkg_postinst() { |
226 |
enewgroup sshd 22 |
227 |
enewuser sshd 22 -1 /var/empty sshd |
228 |
|
229 |
# help fix broken perms caused by older ebuilds. |
230 |
# can probably cut this after the next stage release. |
231 |
chmod u+x "${ROOT}"/etc/skel/.ssh >& /dev/null |
232 |
|
233 |
ewarn "Remember to merge your config files in /etc/ssh/ and then" |
234 |
ewarn "restart sshd: '/etc/init.d/sshd restart'." |
235 |
if use pam ; then |
236 |
echo |
237 |
ewarn "Please be aware users need a valid shell in /etc/passwd" |
238 |
ewarn "in order to be allowed to login." |
239 |
fi |
240 |
} |