1 |
commit: 9ba34aa34c25d07f495ae56fc56a2bbaab5d4dd6 |
2 |
Author: Lars Wendler <polynomial-c <AT> gentoo <DOT> org> |
3 |
AuthorDate: Tue Apr 2 08:50:44 2019 +0000 |
4 |
Commit: Lars Wendler <polynomial-c <AT> gentoo <DOT> org> |
5 |
CommitDate: Tue Apr 2 08:54:13 2019 +0000 |
6 |
URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9ba34aa3 |
7 |
|
8 |
www-servers/apache: Security bump to version 2.4.39 |
9 |
|
10 |
Attempt to make apache2ctl systemd compatible |
11 |
|
12 |
Bug: https://bugs.gentoo.org/673530 |
13 |
Bug: https://bugs.gentoo.org/682306 |
14 |
Package-Manager: Portage-2.3.62, Repoman-2.3.12 |
15 |
Signed-off-by: Lars Wendler <polynomial-c <AT> gentoo.org> |
16 |
|
17 |
www-servers/apache/Manifest | 2 + |
18 |
www-servers/apache/apache-2.4.39.ebuild | 257 ++++++++++++++++++++++++++++++++ |
19 |
2 files changed, 259 insertions(+) |
20 |
|
21 |
diff --git a/www-servers/apache/Manifest b/www-servers/apache/Manifest |
22 |
index 0284c46168f..dbbbf43fdc8 100644 |
23 |
--- a/www-servers/apache/Manifest |
24 |
+++ b/www-servers/apache/Manifest |
25 |
@@ -2,7 +2,9 @@ DIST gentoo-apache-2.2.34-20170918.tar.bz2 64390 BLAKE2B d3f6d85192706d7c49a38cc |
26 |
DIST gentoo-apache-2.4.27-20170918.tar.bz2 24850 BLAKE2B a832c2c7a575e167b72214f325cb85922c49969ea8cc4b5821ce97b1d4028ab56852bf416cb32c99f2b2b356545b6fea0af0fa4f6e13bf001393b468357cbcfb SHA512 c58a9a0b171188ff163f6b45c47f243797d4050cf461ba1a642115350285879005be6496cee2031bffaccc0d8beda4c27de87afa2ded17cbe559f792eb7c00e8 |
27 |
DIST gentoo-apache-2.4.34-20180716.tar.bz2 24773 BLAKE2B 6ff3b711e16a0156f8c5da4c5ee830a6e3d55b1f29c44a81be26decf6611e2680c84ec7779372bc0de775f3aff90fdaec48f5bc7253c8c9317c1308b60bf10e3 SHA512 4b96c2c7cad0aeef070584b64396360acb2ec24139a5af4755fc36b1f3cd2b82b213ebbfc45035f61c49b59ba40870930227b42e0b60042fd1147f34ba5df574 |
28 |
DIST gentoo-apache-2.4.38-20190226.tar.bz2 24810 BLAKE2B 31dc4363c7bdb3dd49287da405541b73e31f251b1b31ecfdffd066a3cd6b838938acf7326a7963a05693e20d6dc34e71223efd1ecd5062a25829d6f6f4721595 SHA512 3dbddedab74e4326b53a9ec3daeb53d727c2789736ae3234d127ccffe873541bd7baa26d5cf9ed064b6e4125fd5a2baee97bccb81e67fdc5674cffe81ca93c40 |
29 |
+DIST gentoo-apache-2.4.39-20190402.tar.bz2 25491 BLAKE2B ce230b07ec156048c7d7c1eb4b0e732fa6140f55d136e317714591327bde3f85bab7780424e6eef04b7a4518cbdcfdddcbc094409f4ca19ffea1ce967bdf7cf1 SHA512 bc0ffa20cffd9a89c2ea64420fa2243d77e97d7922bcd0b387a7fcfcc3c6908a056972b499a81344f7c3e3e19b55ffc300fd034c54b287f4f32d8931bd50cde4 |
30 |
DIST httpd-2.2.34.tar.bz2 5779739 BLAKE2B 8cdd41fb5d1880da4a1cfef252b4682f613b938594057ea4c9665d3881a50b298fb7339c1ceb3dafc215aa927048f99d500f2d29c125016d5766954be9b632b4 SHA512 e6dac5865a48533c025fe17523ee74d68c3a23f9512c9441b78a140e33cfb6835573eb049b0ad424eb5c5ca78a1915778c54e8a409da95fbdd3890cb99e08240 |
31 |
DIST httpd-2.4.27.tar.bz2 6527394 BLAKE2B 50a650eb2edd121dac860ff555273290010d7e85bf4d5fbe3683f82e1928dde99ebfabc42186436f5052a66555a73d8b797b114c76c123faa31b9f51575d0bbb SHA512 7e7e8070715b74cb6890096a74e194f4c6a49c14bda685b1ad832e84312f1ac4316ea03a430e679502bfd8e1853aefa544ee002a20d0f7e994b9a590c74bc42c |
32 |
DIST httpd-2.4.34.tar.bz2 6942969 BLAKE2B 02ecb9980f48bef7ac915077598560353e0682001bdaa99410b7faad459c4581f8d0878b4840e38e570b1872d549d58743260cb3030c145ae93bef97fc692cc4 SHA512 2bc09213f08a4722e305929fbac5f5060c7a8444704494894bb9b61f17e4d20bb6e3d663bb93fc5b2030b04a43fb12373d260cc291422b210b299725aaf3b5c8 |
33 |
DIST httpd-2.4.38.tar.bz2 7035030 BLAKE2B 52d965b0eae3402c268f1c5f5fb669ad84408699871d0518ba254c6e7c00f2198cba8cb6106114a62f0f6de67e0a8b921b5783af9530d165ed4d435312ce5164 SHA512 8bdc36fa2bd13fd83feee17fdce4a5316ed8f96c1ac32b636ba106572ba257815438c72068d2d0e900783a3fa25c90a5da34c3f83fc2c04a1dbdbf234f7ad448 |
34 |
+DIST httpd-2.4.39.tar.bz2 7030539 BLAKE2B 1e378833efb9bbdd6fdc277a779620a08752d064524489f9ad747cf85350fbb6ad65f57b30c81d57273cd6693d8a2c4e988f5a2c42bd5c9c538b305b9b7719e8 SHA512 9742202040b3dc6344b301540f54b2d3f8e36898410d24206a7f8dcecb1bea7d7230fabc7256752724558af249facf64bffe2cf678b8f7cccb64076737abfda7 |
35 |
|
36 |
diff --git a/www-servers/apache/apache-2.4.39.ebuild b/www-servers/apache/apache-2.4.39.ebuild |
37 |
new file mode 100644 |
38 |
index 00000000000..a32861d5b7c |
39 |
--- /dev/null |
40 |
+++ b/www-servers/apache/apache-2.4.39.ebuild |
41 |
@@ -0,0 +1,257 @@ |
42 |
+# Copyright 1999-2019 Gentoo Authors |
43 |
+# Distributed under the terms of the GNU General Public License v2 |
44 |
+ |
45 |
+EAPI=6 |
46 |
+ |
47 |
+# latest gentoo apache files |
48 |
+GENTOO_PATCHSTAMP="20190402" |
49 |
+GENTOO_DEVELOPER="polynomial-c" |
50 |
+GENTOO_PATCHNAME="gentoo-apache-2.4.39" |
51 |
+ |
52 |
+# IUSE/USE_EXPAND magic |
53 |
+IUSE_MPMS_FORK="prefork" |
54 |
+IUSE_MPMS_THREAD="event worker" |
55 |
+ |
56 |
+# << obsolete modules: |
57 |
+# authn_default authz_default mem_cache |
58 |
+# mem_cache is replaced by cache_disk |
59 |
+# ?? buggy modules |
60 |
+# proxy_scgi: startup error: undefined symbol "ap_proxy_release_connection", no fix found |
61 |
+# >> added modules for reason: |
62 |
+# compat: compatibility with 2.2 access control |
63 |
+# authz_host: new module for access control |
64 |
+# authn_core: functionality provided by authn_alias in previous versions |
65 |
+# authz_core: new module, provides core authorization capabilities |
66 |
+# cache_disk: replacement for mem_cache |
67 |
+# lbmethod_byrequests: Split off from mod_proxy_balancer in 2.3 |
68 |
+# lbmethod_bytraffic: Split off from mod_proxy_balancer in 2.3 |
69 |
+# lbmethod_bybusyness: Split off from mod_proxy_balancer in 2.3 |
70 |
+# lbmethod_heartbeat: Split off from mod_proxy_balancer in 2.3 |
71 |
+# slotmem_shm: Slot-based shared memory provider (for lbmethod_byrequests). |
72 |
+# socache_shmcb: shared object cache provider. Default config with ssl needs it |
73 |
+# unixd: fixes startup error: Invalid command 'User' |
74 |
+IUSE_MODULES="access_compat actions alias asis auth_basic auth_digest |
75 |
+authn_alias authn_anon authn_core authn_dbd authn_dbm authn_file authz_core |
76 |
+authz_dbd authz_dbm authz_groupfile authz_host authz_owner authz_user autoindex |
77 |
+brotli cache cache_disk cache_socache cern_meta charset_lite cgi cgid dav dav_fs dav_lock |
78 |
+dbd deflate dir dumpio env expires ext_filter file_cache filter headers http2 |
79 |
+ident imagemap include info lbmethod_byrequests lbmethod_bytraffic lbmethod_bybusyness |
80 |
+lbmethod_heartbeat log_config log_forensic logio macro md mime mime_magic negotiation |
81 |
+proxy proxy_ajp proxy_balancer proxy_connect proxy_ftp proxy_html proxy_http proxy_scgi |
82 |
+proxy_http2 proxy_fcgi proxy_wstunnel rewrite ratelimit remoteip reqtimeout setenvif |
83 |
+slotmem_shm speling socache_shmcb status substitute unique_id userdir usertrack |
84 |
+unixd version vhost_alias watchdog xml2enc" |
85 |
+# The following are also in the source as of this version, but are not available |
86 |
+# for user selection: |
87 |
+# bucketeer case_filter case_filter_in echo http isapi optional_fn_export |
88 |
+# optional_fn_import optional_hook_export optional_hook_import |
89 |
+ |
90 |
+# inter-module dependencies |
91 |
+# TODO: this may still be incomplete |
92 |
+MODULE_DEPENDS=" |
93 |
+ brotli:filter |
94 |
+ dav_fs:dav |
95 |
+ dav_lock:dav |
96 |
+ deflate:filter |
97 |
+ cache_disk:cache |
98 |
+ ext_filter:filter |
99 |
+ file_cache:cache |
100 |
+ lbmethod_byrequests:proxy_balancer |
101 |
+ lbmethod_byrequests:slotmem_shm |
102 |
+ lbmethod_bytraffic:proxy_balancer |
103 |
+ lbmethod_bybusyness:proxy_balancer |
104 |
+ lbmethod_heartbeat:proxy_balancer |
105 |
+ log_forensic:log_config |
106 |
+ logio:log_config |
107 |
+ cache_disk:cache |
108 |
+ cache_socache:cache |
109 |
+ md:watchdog |
110 |
+ mime_magic:mime |
111 |
+ proxy_ajp:proxy |
112 |
+ proxy_balancer:proxy |
113 |
+ proxy_balancer:slotmem_shm |
114 |
+ proxy_connect:proxy |
115 |
+ proxy_ftp:proxy |
116 |
+ proxy_html:proxy |
117 |
+ proxy_html:xml2enc |
118 |
+ proxy_http:proxy |
119 |
+ proxy_scgi:proxy |
120 |
+ proxy_fcgi:proxy |
121 |
+ proxy_wstunnel:proxy |
122 |
+ substitute:filter |
123 |
+" |
124 |
+ |
125 |
+# module<->define mappings |
126 |
+MODULE_DEFINES=" |
127 |
+ auth_digest:AUTH_DIGEST |
128 |
+ authnz_ldap:AUTHNZ_LDAP |
129 |
+ cache:CACHE |
130 |
+ cache_disk:CACHE |
131 |
+ cache_socache:CACHE |
132 |
+ dav:DAV |
133 |
+ dav_fs:DAV |
134 |
+ dav_lock:DAV |
135 |
+ file_cache:CACHE |
136 |
+ http2:HTTP2 |
137 |
+ info:INFO |
138 |
+ ldap:LDAP |
139 |
+ md:SSL |
140 |
+ proxy:PROXY |
141 |
+ proxy_ajp:PROXY |
142 |
+ proxy_balancer:PROXY |
143 |
+ proxy_connect:PROXY |
144 |
+ proxy_ftp:PROXY |
145 |
+ proxy_html:PROXY |
146 |
+ proxy_http:PROXY |
147 |
+ proxy_fcgi:PROXY |
148 |
+ proxy_scgi:PROXY |
149 |
+ proxy_wstunnel:PROXY |
150 |
+ socache_shmcb:SSL |
151 |
+ ssl:SSL |
152 |
+ status:STATUS |
153 |
+ suexec:SUEXEC |
154 |
+ userdir:USERDIR |
155 |
+" |
156 |
+ |
157 |
+# critical modules for the default config |
158 |
+MODULE_CRITICAL=" |
159 |
+ authn_core |
160 |
+ authz_core |
161 |
+ authz_host |
162 |
+ dir |
163 |
+ mime |
164 |
+ unixd |
165 |
+" |
166 |
+inherit apache-2 systemd tmpfiles toolchain-funcs |
167 |
+ |
168 |
+DESCRIPTION="The Apache Web Server" |
169 |
+HOMEPAGE="https://httpd.apache.org/" |
170 |
+ |
171 |
+# some helper scripts are Apache-1.1, thus both are here |
172 |
+LICENSE="Apache-2.0 Apache-1.1" |
173 |
+SLOT="2" |
174 |
+KEYWORDS="~alpha ~amd64 ~arm ~arm64 ~hppa ~ia64 ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~x86 ~amd64-linux ~x64-macos ~x86-macos ~m68k-mint ~sparc64-solaris ~x64-solaris" |
175 |
+ |
176 |
+# Enable http2 by default (bug #563452) |
177 |
+# FIXME: Move to apache-2.eclass once this has reached stable. |
178 |
+IUSE="${IUSE/apache2_modules_http2/+apache2_modules_http2}" |
179 |
+# New suexec options (since 2.4.34) |
180 |
+IUSE="${IUSE} +suexec-caps suexec-syslog" |
181 |
+ |
182 |
+CDEPEND="apache2_modules_brotli? ( >=app-arch/brotli-0.6.0:= ) |
183 |
+ apache2_modules_http2? ( >=net-libs/nghttp2-1.2.1 ) |
184 |
+ apache2_modules_md? ( >=dev-libs/jansson-2.10 )" |
185 |
+ |
186 |
+DEPEND+="${CDEPEND} |
187 |
+ suexec? ( suexec-caps? ( sys-libs/libcap ) )" |
188 |
+RDEPEND+="${CDEPEND}" |
189 |
+ |
190 |
+REQUIRED_USE="apache2_modules_http2? ( ssl ) |
191 |
+ apache2_modules_md? ( ssl )" |
192 |
+ |
193 |
+pkg_setup() { |
194 |
+ # dependend critical modules which are not allowed in global scope due |
195 |
+ # to USE flag conditionals (bug #499260) |
196 |
+ use ssl && MODULE_CRITICAL+=" socache_shmcb" |
197 |
+ use doc && MODULE_CRITICAL+=" alias negotiation setenvif" |
198 |
+ apache-2_pkg_setup |
199 |
+} |
200 |
+ |
201 |
+src_configure() { |
202 |
+ # Brain dead check. |
203 |
+ tc-is-cross-compiler && export ap_cv_void_ptr_lt_long="no" |
204 |
+ |
205 |
+ apache-2_src_configure |
206 |
+} |
207 |
+ |
208 |
+src_compile() { |
209 |
+ if tc-is-cross-compiler; then |
210 |
+ # This header is the same across targets, so use the build compiler. |
211 |
+ pushd server >/dev/null |
212 |
+ emake gen_test_char |
213 |
+ tc-export_build_env BUILD_CC |
214 |
+ ${BUILD_CC} ${BUILD_CFLAGS} ${BUILD_CPPFLAGS} ${BUILD_LDFLAGS} \ |
215 |
+ gen_test_char.c -o gen_test_char $(apr-1-config --includes) || die |
216 |
+ popd >/dev/null |
217 |
+ fi |
218 |
+ |
219 |
+ default |
220 |
+} |
221 |
+ |
222 |
+src_install() { |
223 |
+ apache-2_src_install |
224 |
+ local i |
225 |
+ local apache_tools_prune_list=( |
226 |
+ /usr/bin/{htdigest,logresolve,htpasswd,htdbm,ab,httxt2dbm} |
227 |
+ /usr/sbin/{checkgid,fcgistarter,htcacheclean,rotatelogs} |
228 |
+ /usr/share/man/man1/{logresolve.1,htdbm.1,htdigest.1,htpasswd.1,dbmmanage.1,ab.1} |
229 |
+ /usr/share/man/man8/{rotatelogs.8,htcacheclean.8} |
230 |
+ ) |
231 |
+ for i in ${apache_tools_prune_list[@]} ; do |
232 |
+ rm "${ED%/}"/${i} || die "Failed to prune apache-tools bits" |
233 |
+ done |
234 |
+ |
235 |
+ # install apxs in /usr/bin (bug #502384) and put a symlink into the |
236 |
+ # old location until all ebuilds and eclasses have been modified to |
237 |
+ # use the new location. |
238 |
+ dobin support/apxs |
239 |
+ dosym ../bin/apxs /usr/sbin/apxs |
240 |
+ |
241 |
+ # Note: wait for mod_systemd to be included in some forthcoming release, |
242 |
+ # Then apache2.4.service can be used and systemd support controlled |
243 |
+ # through --enable-systemd |
244 |
+ systemd_newunit "${FILESDIR}/apache2.2-hardened.service" "apache2.service" |
245 |
+ systemd_dotmpfilesd "${FILESDIR}/apache.conf" |
246 |
+ #insinto /etc/apache2/modules.d |
247 |
+ #doins "${FILESDIR}/00_systemd.conf" |
248 |
+ |
249 |
+ # Install http2 module config |
250 |
+ insinto /etc/apache2/modules.d |
251 |
+ doins "${FILESDIR}"/41_mod_http2.conf |
252 |
+ |
253 |
+ # Fix path to apache libdir |
254 |
+ sed "s|@LIBDIR@|$(get_libdir)|" -i "${ED%/}"/usr/sbin/apache2ctl || die |
255 |
+} |
256 |
+ |
257 |
+pkg_postinst() { |
258 |
+ apache-2_pkg_postinst || die "apache-2_pkg_postinst failed" |
259 |
+ |
260 |
+ tmpfiles_process apache.conf #662544 |
261 |
+ |
262 |
+ # warnings that default config might not work out of the box |
263 |
+ local mod cmod |
264 |
+ for mod in ${MODULE_CRITICAL} ; do |
265 |
+ if ! use "apache2_modules_${mod}"; then |
266 |
+ echo |
267 |
+ ewarn "Warning: Critical module not installed!" |
268 |
+ ewarn "Modules 'authn_core', 'authz_core' and 'unixd'" |
269 |
+ ewarn "are highly recomended but might not be in the base profile yet." |
270 |
+ ewarn "Default config for ssl needs module 'socache_shmcb'." |
271 |
+ ewarn "Enabling the following flags is highly recommended:" |
272 |
+ for cmod in ${MODULE_CRITICAL} ; do |
273 |
+ use "apache2_modules_${cmod}" || \ |
274 |
+ ewarn "+ apache2_modules_${cmod}" |
275 |
+ done |
276 |
+ echo |
277 |
+ break |
278 |
+ fi |
279 |
+ done |
280 |
+ # warning for proxy_balancer and missing load balancing scheduler |
281 |
+ if use apache2_modules_proxy_balancer; then |
282 |
+ local lbset= |
283 |
+ for mod in lbmethod_byrequests lbmethod_bytraffic lbmethod_bybusyness lbmethod_heartbeat; do |
284 |
+ if use "apache2_modules_${mod}"; then |
285 |
+ lbset=1 && break |
286 |
+ fi |
287 |
+ done |
288 |
+ if [ ! ${lbset} ] ; then |
289 |
+ echo |
290 |
+ ewarn "Info: Missing load balancing scheduler algorithm module" |
291 |
+ ewarn "(They were split off from proxy_balancer in 2.3)" |
292 |
+ ewarn "In order to get the ability of load balancing, at least" |
293 |
+ ewarn "one of these modules has to be present:" |
294 |
+ ewarn "lbmethod_byrequests lbmethod_bytraffic lbmethod_bybusyness lbmethod_heartbeat" |
295 |
+ echo |
296 |
+ fi |
297 |
+ fi |
298 |
+} |