Gentoo Archives: gentoo-commits

From: Eray Aslan <eras@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] repo/gentoo:master commit in: app-crypt/mit-krb5/files/, app-crypt/mit-krb5/
Date: Mon, 07 Nov 2022 10:43:41
Message-Id: 1667817782.3fb4979bc5980af0060e50e80ee5bea3ae72a713.eras@gentoo
1 commit: 3fb4979bc5980af0060e50e80ee5bea3ae72a713
2 Author: Eray Aslan <eras <AT> gentoo <DOT> org>
3 AuthorDate: Mon Nov 7 10:43:02 2022 +0000
4 Commit: Eray Aslan <eras <AT> gentoo <DOT> org>
5 CommitDate: Mon Nov 7 10:43:02 2022 +0000
6 URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=3fb4979b
7
8 app-crypt/mit-krb5: drop 1.19.2-r4, 1.19.3-r2
9
10 Signed-off-by: Eray Aslan <eras <AT> gentoo.org>
11
12 app-crypt/mit-krb5/Manifest | 2 -
13 .../mit-krb5/files/mit-krb5-CVE-2021-37750.patch | 43 ------
14 app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild | 162 ---------------------
15 app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild | 161 --------------------
16 4 files changed, 368 deletions(-)
17
18 diff --git a/app-crypt/mit-krb5/Manifest b/app-crypt/mit-krb5/Manifest
19 index 04c701bf322e..ed2f9ab88d2c 100644
20 --- a/app-crypt/mit-krb5/Manifest
21 +++ b/app-crypt/mit-krb5/Manifest
22 @@ -1,3 +1 @@
23 -DIST krb5-1.19.2.tar.gz 8741053 BLAKE2B 963722721201e75381c91a2af6e982f569a5b1602beb2d1ded83d35f6f914235a6ed91e5d54f56c97e94921a32ed27c49aded258327966ee13d39485208c38d8 SHA512 b90d6ed0e1e8a87eb5cb2c36d88b823a6a6caabf85e5d419adb8a930f7eea09a5f8491464e7e454cca7ba88be09d19415962fe0036ad2e31fc584f9fc0bbd470
24 -DIST krb5-1.19.3.tar.gz 8741343 BLAKE2B 79e68237ee82affa85299060c509e303453c0fab965adc6b9ed305ab64a1f73bd51e65df1b3faadc60815cd506ffefaeed535765ca060d393a9141812f85b48a SHA512 18235440d6f7d8a72c5d7ca5cd8c6465e8adf091d85c483225c7b00d64b4688c1c7924cb800c2fc17e590b2709f1a9de48e6ec79f6debd11dcb7d6fa16c6f351
25 DIST krb5-1.20.tar.gz 8660756 BLAKE2B fdaaab6c16dbe073c4308f312e321536b582b75fad10e5450be66b6b828825c8c775e56f5287d4a7df819d20889e5c0d9cc1d179d861c9caba185332c0db7387 SHA512 9aed84a971a4d74188468870260087ec7c3a614cceb5fe32ad7da1cb8db3d66e00df801c9f900f0131ac56eb828674b8be93df474c2d13b892b70c7977388604
26
27 diff --git a/app-crypt/mit-krb5/files/mit-krb5-CVE-2021-37750.patch b/app-crypt/mit-krb5/files/mit-krb5-CVE-2021-37750.patch
28 deleted file mode 100644
29 index 2f4c949e9f31..000000000000
30 --- a/app-crypt/mit-krb5/files/mit-krb5-CVE-2021-37750.patch
31 +++ /dev/null
32 @@ -1,43 +0,0 @@
33 -From d775c95af7606a51bf79547a94fa52ddd1cb7f49 Mon Sep 17 00:00:00 2001
34 -From: Greg Hudson <ghudson@×××.edu>
35 -Date: Tue, 3 Aug 2021 01:15:27 -0400
36 -Subject: [PATCH] Fix KDC null deref on TGS inner body null server
37 -
38 -After the KDC decodes a FAST inner body, it does not check for a null
39 -server. Prior to commit 39548a5b17bbda9eeb63625a201cfd19b9de1c5b this
40 -would typically result in an error from krb5_unparse_name(), but with
41 -the addition of get_local_tgt() it results in a null dereference. Add
42 -a null check.
43 -
44 -Reported by Joseph Sutton of Catalyst.
45 -
46 -CVE-2021-37750:
47 -
48 -In MIT krb5 releases 1.14 and later, an authenticated attacker can
49 -cause a null dereference in the KDC by sending a FAST TGS request with
50 -no server field.
51 -
52 -ticket: 9008 (new)
53 -tags: pullup
54 -target_version: 1.19-next
55 -target_version: 1.18-next
56 ----
57 - src/kdc/do_tgs_req.c | 5 +++++
58 - 1 file changed, 5 insertions(+)
59 -
60 -diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c
61 -index 582e497cc9..32dc65fa8e 100644
62 ---- a/kdc/do_tgs_req.c
63 -+++ b/kdc/do_tgs_req.c
64 -@@ -204,6 +204,11 @@ process_tgs_req(krb5_kdc_req *request, krb5_data *pkt,
65 - status = "FIND_FAST";
66 - goto cleanup;
67 - }
68 -+ if (sprinc == NULL) {
69 -+ status = "NULL_SERVER";
70 -+ errcode = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN;
71 -+ goto cleanup;
72 -+ }
73 -
74 - errcode = get_local_tgt(kdc_context, &sprinc->realm, header_server,
75 - &local_tgt, &local_tgt_storage, &local_tgt_key);
76
77 diff --git a/app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild b/app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild
78 deleted file mode 100644
79 index a88217f5154c..000000000000
80 --- a/app-crypt/mit-krb5/mit-krb5-1.19.2-r4.ebuild
81 +++ /dev/null
82 @@ -1,162 +0,0 @@
83 -# Copyright 1999-2022 Gentoo Authors
84 -# Distributed under the terms of the GNU General Public License v2
85 -
86 -EAPI=8
87 -
88 -PYTHON_COMPAT=( python3_{8..10} )
89 -inherit autotools flag-o-matic multilib-minimal python-any-r1 systemd toolchain-funcs
90 -
91 -MY_P="${P/mit-}"
92 -P_DIR=$(ver_cut 1-2)
93 -DESCRIPTION="MIT Kerberos V"
94 -HOMEPAGE="https://web.mit.edu/kerberos/www/"
95 -SRC_URI="https://web.mit.edu/kerberos/dist/krb5/${P_DIR}/${MY_P}.tar.gz"
96 -
97 -LICENSE="openafs-krb5-a BSD MIT OPENLDAP BSD-2 HPND BSD-4 ISC RSA CC-BY-SA-3.0 || ( BSD-2 GPL-2+ )"
98 -SLOT="0"
99 -KEYWORDS="~alpha amd64 arm arm64 hppa ~ia64 ~mips ~ppc ppc64 ~riscv ~s390 sparc x86"
100 -IUSE="cpu_flags_x86_aes doc +keyutils lmdb nls openldap +pkinit selinux +threads test xinetd"
101 -
102 -# some tests requires network access
103 -RESTRICT="test"
104 -
105 -DEPEND="
106 - !!app-crypt/heimdal
107 - >=sys-fs/e2fsprogs-1.46.4-r51[${MULTILIB_USEDEP}]
108 - || (
109 - >=dev-libs/libverto-0.2.5[libev,${MULTILIB_USEDEP}]
110 - >=dev-libs/libverto-0.2.5[libevent,${MULTILIB_USEDEP}]
111 - )
112 - keyutils? ( >=sys-apps/keyutils-1.5.8:=[${MULTILIB_USEDEP}] )
113 - lmdb? ( dev-db/lmdb:= )
114 - nls? ( sys-devel/gettext[${MULTILIB_USEDEP}] )
115 - openldap? ( >=net-nds/openldap-2.4.38-r1:=[${MULTILIB_USEDEP}] )
116 - pkinit? ( >=dev-libs/openssl-1.0.1h-r2:0=[${MULTILIB_USEDEP}] )
117 - xinetd? ( sys-apps/xinetd )
118 - "
119 -BDEPEND="
120 - ${PYTHON_DEPS}
121 - virtual/yacc
122 - cpu_flags_x86_aes? (
123 - amd64? ( dev-lang/yasm )
124 - x86? ( dev-lang/yasm )
125 - )
126 - doc? ( virtual/latex-base )
127 - test? (
128 - ${PYTHON_DEPS}
129 - dev-lang/tcl:0
130 - dev-util/dejagnu
131 - dev-util/cmocka
132 - )"
133 -RDEPEND="${DEPEND}
134 - selinux? ( sec-policy/selinux-kerberos )"
135 -
136 -S=${WORKDIR}/${MY_P}/src
137 -
138 -PATCHES=(
139 - "${FILESDIR}/${PN}-1.12_warn_cflags.patch"
140 - "${FILESDIR}/${PN}-config_LDFLAGS-r1.patch"
141 - "${FILESDIR}/${PN}_dont_create_rundir.patch"
142 - "${FILESDIR}/${PN}-1.18.2-krb5-config.patch"
143 - "${FILESDIR}/${PN}-CVE-2021-37750.patch"
144 -)
145 -
146 -MULTILIB_CHOST_TOOLS=(
147 - /usr/bin/krb5-config
148 -)
149 -
150 -src_prepare() {
151 - default
152 - # Make sure we always use the system copies.
153 - rm -rf util/{et,ss,verto}
154 - sed -i 's:^[[:space:]]*util/verto$::' configure.ac || die
155 -
156 - eautoreconf
157 -}
158 -
159 -src_configure() {
160 - # QA
161 - append-flags -fno-strict-aliasing
162 - append-flags -fno-strict-overflow
163 -
164 - multilib-minimal_src_configure
165 -}
166 -
167 -multilib_src_configure() {
168 - ECONF_SOURCE=${S} \
169 - AR="$(tc-getAR)" \
170 - WARN_CFLAGS="set" \
171 - econf \
172 - $(use_with openldap ldap) \
173 - "$(multilib_native_use_with test tcl "${EPREFIX}/usr")" \
174 - $(use_enable nls) \
175 - $(use_enable pkinit) \
176 - $(use_enable threads thread-support) \
177 - $(use_with lmdb) \
178 - $(use_with keyutils) \
179 - --without-hesiod \
180 - --enable-shared \
181 - --with-system-et \
182 - --with-system-ss \
183 - --enable-dns-for-realm \
184 - --enable-kdc-lookaside-cache \
185 - --with-system-verto \
186 - --disable-rpath
187 -}
188 -
189 -multilib_src_compile() {
190 - emake -j1
191 -}
192 -
193 -multilib_src_test() {
194 - multilib_is_native_abi && emake -j1 check
195 -}
196 -
197 -multilib_src_install() {
198 - emake \
199 - DESTDIR="${D}" \
200 - EXAMPLEDIR="${EPREFIX}/usr/share/doc/${PF}/examples" \
201 - install
202 -}
203 -
204 -multilib_src_install_all() {
205 - # default database dir
206 - keepdir /var/lib/krb5kdc
207 -
208 - cd ..
209 - dodoc README
210 -
211 - if use doc; then
212 - dodoc -r doc/html
213 - docinto pdf
214 - dodoc doc/pdf/*.pdf
215 - fi
216 -
217 - newinitd "${FILESDIR}"/mit-krb5kadmind.initd-r2 mit-krb5kadmind
218 - newinitd "${FILESDIR}"/mit-krb5kdc.initd-r2 mit-krb5kdc
219 - newinitd "${FILESDIR}"/mit-krb5kpropd.initd-r2 mit-krb5kpropd
220 - newconfd "${FILESDIR}"/mit-krb5kadmind.confd mit-krb5kadmind
221 - newconfd "${FILESDIR}"/mit-krb5kdc.confd mit-krb5kdc
222 - newconfd "${FILESDIR}"/mit-krb5kpropd.confd mit-krb5kpropd
223 -
224 - systemd_newunit "${FILESDIR}"/mit-krb5kadmind.service mit-krb5kadmind.service
225 - systemd_newunit "${FILESDIR}"/mit-krb5kdc.service mit-krb5kdc.service
226 - systemd_newunit "${FILESDIR}"/mit-krb5kpropd.service mit-krb5kpropd.service
227 - systemd_newunit "${FILESDIR}"/mit-krb5kpropd_at.service "mit-krb5kpropd@.service"
228 - systemd_newunit "${FILESDIR}"/mit-krb5kpropd.socket mit-krb5kpropd.socket
229 -
230 - insinto /etc
231 - newins "${ED}/usr/share/doc/${PF}/examples/krb5.conf" krb5.conf.example
232 - insinto /var/lib/krb5kdc
233 - newins "${ED}/usr/share/doc/${PF}/examples/kdc.conf" kdc.conf.example
234 -
235 - if use openldap ; then
236 - insinto /etc/openldap/schema
237 - doins "${S}/plugins/kdb/ldap/libkdb_ldap/kerberos.schema"
238 - fi
239 -
240 - if use xinetd ; then
241 - insinto /etc/xinetd.d
242 - newins "${FILESDIR}/kpropd.xinetd" kpropd
243 - fi
244 -}
245
246 diff --git a/app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild b/app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild
247 deleted file mode 100644
248 index e90b52a26ebe..000000000000
249 --- a/app-crypt/mit-krb5/mit-krb5-1.19.3-r2.ebuild
250 +++ /dev/null
251 @@ -1,161 +0,0 @@
252 -# Copyright 1999-2022 Gentoo Authors
253 -# Distributed under the terms of the GNU General Public License v2
254 -
255 -EAPI=8
256 -
257 -PYTHON_COMPAT=( python3_{8..10} )
258 -inherit autotools flag-o-matic multilib-minimal python-any-r1 systemd toolchain-funcs
259 -
260 -MY_P="${P/mit-}"
261 -P_DIR=$(ver_cut 1-2)
262 -DESCRIPTION="MIT Kerberos V"
263 -HOMEPAGE="https://web.mit.edu/kerberos/www/"
264 -SRC_URI="https://web.mit.edu/kerberos/dist/krb5/${P_DIR}/${MY_P}.tar.gz"
265 -
266 -LICENSE="openafs-krb5-a BSD MIT OPENLDAP BSD-2 HPND BSD-4 ISC RSA CC-BY-SA-3.0 || ( BSD-2 GPL-2+ )"
267 -SLOT="0"
268 -KEYWORDS="~alpha ~amd64 ~arm ~arm64 ~hppa ~ia64 ~loong ~mips ~ppc ~ppc64 ~riscv ~s390 ~sparc ~x86"
269 -IUSE="cpu_flags_x86_aes doc +keyutils lmdb nls openldap +pkinit selinux +threads test xinetd"
270 -
271 -# some tests requires network access
272 -RESTRICT="test"
273 -
274 -DEPEND="
275 - !!app-crypt/heimdal
276 - >=sys-fs/e2fsprogs-1.46.4-r51[${MULTILIB_USEDEP}]
277 - || (
278 - >=dev-libs/libverto-0.2.5[libev,${MULTILIB_USEDEP}]
279 - >=dev-libs/libverto-0.2.5[libevent,${MULTILIB_USEDEP}]
280 - )
281 - keyutils? ( >=sys-apps/keyutils-1.5.8:=[${MULTILIB_USEDEP}] )
282 - lmdb? ( dev-db/lmdb:= )
283 - nls? ( sys-devel/gettext[${MULTILIB_USEDEP}] )
284 - openldap? ( >=net-nds/openldap-2.4.38-r1:=[${MULTILIB_USEDEP}] )
285 - pkinit? ( >=dev-libs/openssl-1.0.1h-r2:0=[${MULTILIB_USEDEP}] )
286 - xinetd? ( sys-apps/xinetd )
287 - "
288 -BDEPEND="
289 - ${PYTHON_DEPS}
290 - virtual/yacc
291 - cpu_flags_x86_aes? (
292 - amd64? ( dev-lang/yasm )
293 - x86? ( dev-lang/yasm )
294 - )
295 - doc? ( virtual/latex-base )
296 - test? (
297 - ${PYTHON_DEPS}
298 - dev-lang/tcl:0
299 - dev-util/dejagnu
300 - dev-util/cmocka
301 - )"
302 -RDEPEND="${DEPEND}
303 - selinux? ( sec-policy/selinux-kerberos )"
304 -
305 -S=${WORKDIR}/${MY_P}/src
306 -
307 -PATCHES=(
308 - "${FILESDIR}/${PN}-1.12_warn_cflags.patch"
309 - "${FILESDIR}/${PN}-config_LDFLAGS-r1.patch"
310 - "${FILESDIR}/${PN}_dont_create_rundir.patch"
311 - "${FILESDIR}/${PN}-1.18.2-krb5-config.patch"
312 -)
313 -
314 -MULTILIB_CHOST_TOOLS=(
315 - /usr/bin/krb5-config
316 -)
317 -
318 -src_prepare() {
319 - default
320 - # Make sure we always use the system copies.
321 - rm -rf util/{et,ss,verto}
322 - sed -i 's:^[[:space:]]*util/verto$::' configure.ac || die
323 -
324 - eautoreconf
325 -}
326 -
327 -src_configure() {
328 - # QA
329 - append-flags -fno-strict-aliasing
330 - append-flags -fno-strict-overflow
331 -
332 - multilib-minimal_src_configure
333 -}
334 -
335 -multilib_src_configure() {
336 - ECONF_SOURCE=${S} \
337 - AR="$(tc-getAR)" \
338 - WARN_CFLAGS="set" \
339 - econf \
340 - $(use_with openldap ldap) \
341 - "$(multilib_native_use_with test tcl "${EPREFIX}/usr")" \
342 - $(use_enable nls) \
343 - $(use_enable pkinit) \
344 - $(use_enable threads thread-support) \
345 - $(use_with lmdb) \
346 - $(use_with keyutils) \
347 - --without-hesiod \
348 - --enable-shared \
349 - --with-system-et \
350 - --with-system-ss \
351 - --enable-dns-for-realm \
352 - --enable-kdc-lookaside-cache \
353 - --with-system-verto \
354 - --disable-rpath
355 -}
356 -
357 -multilib_src_compile() {
358 - emake -j1
359 -}
360 -
361 -multilib_src_test() {
362 - multilib_is_native_abi && emake -j1 check
363 -}
364 -
365 -multilib_src_install() {
366 - emake \
367 - DESTDIR="${D}" \
368 - EXAMPLEDIR="${EPREFIX}/usr/share/doc/${PF}/examples" \
369 - install
370 -}
371 -
372 -multilib_src_install_all() {
373 - # default database dir
374 - keepdir /var/lib/krb5kdc
375 -
376 - cd ..
377 - dodoc README
378 -
379 - if use doc; then
380 - dodoc -r doc/html
381 - docinto pdf
382 - dodoc doc/pdf/*.pdf
383 - fi
384 -
385 - newinitd "${FILESDIR}"/mit-krb5kadmind.initd-r2 mit-krb5kadmind
386 - newinitd "${FILESDIR}"/mit-krb5kdc.initd-r2 mit-krb5kdc
387 - newinitd "${FILESDIR}"/mit-krb5kpropd.initd-r2 mit-krb5kpropd
388 - newconfd "${FILESDIR}"/mit-krb5kadmind.confd mit-krb5kadmind
389 - newconfd "${FILESDIR}"/mit-krb5kdc.confd mit-krb5kdc
390 - newconfd "${FILESDIR}"/mit-krb5kpropd.confd mit-krb5kpropd
391 -
392 - systemd_newunit "${FILESDIR}"/mit-krb5kadmind.service mit-krb5kadmind.service
393 - systemd_newunit "${FILESDIR}"/mit-krb5kdc.service mit-krb5kdc.service
394 - systemd_newunit "${FILESDIR}"/mit-krb5kpropd.service mit-krb5kpropd.service
395 - systemd_newunit "${FILESDIR}"/mit-krb5kpropd_at.service "mit-krb5kpropd@.service"
396 - systemd_newunit "${FILESDIR}"/mit-krb5kpropd.socket mit-krb5kpropd.socket
397 -
398 - insinto /etc
399 - newins "${ED}/usr/share/doc/${PF}/examples/krb5.conf" krb5.conf.example
400 - insinto /var/lib/krb5kdc
401 - newins "${ED}/usr/share/doc/${PF}/examples/kdc.conf" kdc.conf.example
402 -
403 - if use openldap ; then
404 - insinto /etc/openldap/schema
405 - doins "${S}/plugins/kdb/ldap/libkdb_ldap/kerberos.schema"
406 - fi
407 -
408 - if use xinetd ; then
409 - insinto /etc/xinetd.d
410 - newins "${FILESDIR}/kpropd.xinetd" kpropd
411 - fi
412 -}