blob: b29b82a1480d61fbf74e0ea9649fde6125fa2b94 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
|
# Copyright 1999-2006 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
# $Header: /var/cvsroot/gentoo-x86/net-misc/scponly/scponly-4.6-r1.ebuild,v 1.1 2006/05/20 05:37:28 matsuu Exp $
inherit eutils
DESCRIPTION="A tiny pseudoshell which only permits scp and sftp"
HOMEPAGE="http://www.sublimation.org/scponly/"
SRC_URI="http://www.sublimation.org/scponly/${P}.tgz"
LICENSE="as-is"
SLOT="0"
KEYWORDS="~amd64 ~ppc ~sparc ~x86"
IUSE="subversion"
DEPEND="virtual/libc
net-misc/openssh
subversion? ( dev-util/subversion )"
myuser="scponly"
myhome="/home/${myuser}"
src_unpack() {
unpack ${A}
cd "${S}"
# Bug 125796
epatch "${FILESDIR}"/${P}-helper.patch
}
src_compile() {
PATH="${PATH}:/usr/$(get_libdir)/misc" \
econf \
--enable-scp-compat \
--enable-winscp-compat \
--enable-rsync-compat \
--enable-chrooted-binary \
$(use_enable subversion svn-compat) \
$(use_enable subversion svnserv-compat) \
|| die "./configure failed"
emake || die
}
src_install() {
make DESTDIR="${D}" install || die
dodoc AUTHOR BUILDING-JAILS.TXT CHANGELOG CONTRIB README TODO
dodoc setup_chroot.sh
}
pkg_postinst() {
einfo "You might want to run:"
einfo "\"emerge --config =${CATEGORY}/${PF}\""
einfo "to setup the chroot."
einfo "Otherwise you will have to setup chroot manually."
# two slashes ('//') are used by scponlyc to determine the chroot point.
enewgroup ${myuser}
enewuser ${myuser} -1 /usr/sbin/scponlyc ${myhome}// ${myuser}
}
pkg_config() {
# pkg_postinst is based on ${S}/setup_chroot.sh.
einfo "Updating /etc/shells"
{ grep -v "^/usr/bin/scponly$" /etc/shells;
echo "/usr/bin/scponly"
} > ${T}/shells
mv -f ${T}/shells /etc/shells
{ grep -v "^/usr/sbin/scponlyc$" /etc/shells;
echo "/usr/sbin/scponlyc"
} > ${T}/shells
mv -f ${T}/shells /etc/shells
BINARIES="/usr/$(get_libdir)/misc/sftp-server /bin/ls /usr/bin/scp /bin/rm /bin/ln /bin/mv /bin/chmod /bin/chown /bin/chgrp /bin/mkdir /bin/rmdir /bin/pwd /bin/groups /usr/bin/ld /bin/echo /usr/bin/rsync"
if built_with_use ${PN} subversion; then
BINARIES="$BINARIES /usr/bin/svn /usr/bin/svnserve"
fi
LIB_LIST=`/usr/bin/ldd $BINARIES 2> /dev/null | /bin/cut -f2 -d\> | /bin/cut -f1 -d\( | /bin/grep "^ " | /bin/sort -u`
LDSO_LIST="/$(get_libdir)/ld.so /libexec/ld-elf.so /libexec/ld-elf.so.1 /usr/libexec/ld.so /$(get_libdir)/ld-linux.so.2 /usr/libexec/ld-elf.so.1"
for lib in $LDSO_LIST; do
if [ -f $lib ]; then
LIB_LIST="$LIB_LIST $lib"
fi
done
/bin/ls /$(get_libdir)/libnss_compat* > /dev/null 2>&1
if [ $? -eq 0 ]; then
LIB_LIST="$LIB_LIST /$(get_libdir)/libnss_compat*"
fi
ldconfig
LIB_LIST="$LIB_LIST /etc/ld.so.cache /etc/ld.so.conf"
if [ ! -d ${myhome} ]; then
/bin/install -c -d ${myhome}
/bin/chmod 755 ${myhome}
fi
if [ ! -d ${myhome} ]; then
/bin/install -c -d ${myhome}/etc
/bin/chown 0:0 ${myhome}/etc
/bin/chmod 755 ${myhome}/etc
fi
if [ ! -d ${myhome}/$(get_libdir) ]; then
/bin/install -c -d ${myhome}/$(get_libdir)
/bin/chmod 755 ${myhome}/$(get_libdir)
fi
if [ ! -d ${myhome}/lib ]; then
/usr/bin/ln -s $(get_libdir) ${myhome}/lib
fi
if [ ! -d ${myhome}/usr/$(get_libdir) ]; then
/bin/install -c -d ${myhome}/usr/$(get_libdir)
/bin/chmod 755 ${myhome}/usr/$(get_libdir)
fi
if [ ! -d ${myhome}/usr/lib ]; then
/usr/bin/ln -s $(get_libdir) ${myhome}/usr/lib
fi
for bin in $BINARIES; do
/bin/install -c -d ${myhome}/`/bin/dirname $bin`
/bin/install -c $bin ${myhome}/$bin
done
for lib in $LIB_LIST; do
/bin/install -c -d ${myhome}/`/bin/dirname $lib`
/bin/install -c $lib ${myhome}/$lib
done
/bin/chown 0:0 ${myhome}
if [ -d ${myhome}/.ssh ]; then
/bin/chown 0:0 ${myhome}/.ssh
fi
if [ ! -d ${myhome}/incoming ]; then
einfo "creating ${myhome}/incoming directory for uploading files"
/bin/install -c -o ${myuser} -d ${myhome}/incoming
fi
/bin/chown $myuser:$myuser ${myhome}/incoming
grep "^${myuser}" /etc/passwd > ${myhome}/etc/passwd
einfo "if you experience a warning with winscp regarding groups, please install"
einfo "the provided hacked out fake groups program into your chroot, like so:"
einfo "cp groups ${myhome}/bin/groups"
}
|