diff options
author | Hans de Graaff <graaff@gentoo.org> | 2018-09-19 08:43:25 +0200 |
---|---|---|
committer | Hans de Graaff <graaff@gentoo.org> | 2018-09-19 08:44:49 +0200 |
commit | 5eb5ac90d68ae10603c84ece0b83967c519f9ae9 (patch) | |
tree | 17128d32b2a721293cf823aa43472d7090db9c97 /net-vpn/libreswan | |
parent | net-vpn/libreswan: cleanup (diff) | |
download | gentoo-5eb5ac90d68ae10603c84ece0b83967c519f9ae9.tar.gz gentoo-5eb5ac90d68ae10603c84ece0b83967c519f9ae9.tar.bz2 gentoo-5eb5ac90d68ae10603c84ece0b83967c519f9ae9.zip |
net-vpn/libreswan: add 3.26
Package-Manager: Portage-2.3.49, Repoman-2.3.10
Diffstat (limited to 'net-vpn/libreswan')
-rw-r--r-- | net-vpn/libreswan/Manifest | 1 | ||||
-rw-r--r-- | net-vpn/libreswan/files/libreswan-3.26-nss-link.patch | 22 | ||||
-rw-r--r-- | net-vpn/libreswan/files/libreswan-3.26-nss.patch | 27 | ||||
-rw-r--r-- | net-vpn/libreswan/libreswan-3.26.ebuild | 115 |
4 files changed, 165 insertions, 0 deletions
diff --git a/net-vpn/libreswan/Manifest b/net-vpn/libreswan/Manifest index a8dd92def944..281c1a96924f 100644 --- a/net-vpn/libreswan/Manifest +++ b/net-vpn/libreswan/Manifest @@ -1,2 +1,3 @@ DIST libreswan-3.22.tar.gz 6910418 BLAKE2B c06134fa2d1096231797f1ea93de8ed61121472b10ae30ee9a843250dce4ef9f21e7d3bf63f38daf53fbfd8d1e435cfdc704743d0fdcbde8ecac137d9becac48 SHA512 93868327394527750590e1297443d3eb1c9a528d680348098fd2913123dac52c9fecd73b855ee00586c2516b8aa00f7f0d158d8e9b19d7487b5fb26432b86aff DIST libreswan-3.25.tar.gz 3988630 BLAKE2B 8479b5b0d7d49055b7dcefa6c3b2f469b0aa60005e05446d5c1c6f73a32c904835422248c6ead2a1c2dc83b63794fd50f7461fd22c4206414b5890c01b99b722 SHA512 246649cb5bef1d0690217d1080f3f6f175a0d7a5f27e5a7affdf291b2f418a11937e96b64716a33e6312530409a2c1b10b90e2fa5ec339a27c94c990d86ed517 +DIST libreswan-3.26.tar.gz 3706205 BLAKE2B e54e6d3a0163f0b6812c53400e7f57e01319d7cf64a5d9e84d5002bbab24d5de1b6461c6bba02d60630017a50c23ecb1a095f3da1a36a4e6fc64e90cf08fd798 SHA512 10965a23197ef5d21a66dc0838066ceb620b2653f64471553284e0043fbc993584e497742b498e0be410427aeed3d8ce5bfdc6dfab59b8a1a1ba9a363473c4a4 diff --git a/net-vpn/libreswan/files/libreswan-3.26-nss-link.patch b/net-vpn/libreswan/files/libreswan-3.26-nss-link.patch new file mode 100644 index 000000000000..267aa2120dbd --- /dev/null +++ b/net-vpn/libreswan/files/libreswan-3.26-nss-link.patch @@ -0,0 +1,22 @@ +From b3199806cc66de4888917ddc85b511b433e43d63 Mon Sep 17 00:00:00 2001 +From: Paul Wouters <pwouters@redhat.com> +Date: Mon, 17 Sep 2018 11:23:11 -0400 +Subject: [PATCH] building: -lfreebl is no longer needed + +--- + mk/config.mk | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/mk/config.mk b/mk/config.mk +index 3bd2527497..d8497c2104 100644 +--- a/mk/config.mk ++++ b/mk/config.mk +@@ -234,7 +234,7 @@ BISONOSFLAGS?= + NSSFLAGS?=$(shell pkg-config --cflags nss) + # We don't want to link against every library pkg-config --libs nss + # returns +-NSS_LDFLAGS ?= -lnss3 -lfreebl -lnssutil3 ++NSS_LDFLAGS ?= -lnss3 -lnssutil3 + NSS_SMIME_LDFLAGS ?= -lsmime3 + NSS_UTIL_LDFLAGS ?= -lnssutil3 + NSPR_LDFLAGS ?= -lnspr4 diff --git a/net-vpn/libreswan/files/libreswan-3.26-nss.patch b/net-vpn/libreswan/files/libreswan-3.26-nss.patch new file mode 100644 index 000000000000..89a6436a2a26 --- /dev/null +++ b/net-vpn/libreswan/files/libreswan-3.26-nss.patch @@ -0,0 +1,27 @@ +From 910f69119b491c6d7abcc85cf8911d2fa012a135 Mon Sep 17 00:00:00 2001 +From: Andrew Cagney <cagney@gnu.org> +Date: Mon, 17 Sep 2018 11:56:56 -0400 +Subject: [PATCH] ecdsa: don't include NSS's "blapi.h", no longer needed and + not on debian + +(not to be confused with "lbapit.h", which also looks suspect) + +Follow-up b3199806cc66de4888917ddc85b511b433e43d63 and +2d093c9fb83c8104604e4b40defa4e41129577ea. The latter +relaced the call to ECDSA_VerifyDigest() with PK11_Verify(). +--- + programs/pluto/keys.c | 1 - + 1 file changed, 1 deletion(-) + +diff --git a/programs/pluto/keys.c b/programs/pluto/keys.c +index b3df5802cf..bd9d8d8c6c 100644 +--- a/programs/pluto/keys.c ++++ b/programs/pluto/keys.c +@@ -72,7 +72,6 @@ + #include <secerr.h> + #include <secport.h> + #include <time.h> +-#include <blapi.h> + #include "lswconf.h" + #include "lswnss.h" + #include "secrets.h" diff --git a/net-vpn/libreswan/libreswan-3.26.ebuild b/net-vpn/libreswan/libreswan-3.26.ebuild new file mode 100644 index 000000000000..7c3de3ac0b86 --- /dev/null +++ b/net-vpn/libreswan/libreswan-3.26.ebuild @@ -0,0 +1,115 @@ +# Copyright 1999-2018 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 + +EAPI=6 + +inherit systemd toolchain-funcs + +SRC_URI="https://download.libreswan.org/${P}.tar.gz" +KEYWORDS="~amd64 ~ppc ~x86" + +DESCRIPTION="IPsec implementation for Linux, fork of Openswan" +HOMEPAGE="https://libreswan.org/" + +LICENSE="GPL-2 BSD-4 RSA DES" +SLOT="0" +IUSE="caps curl dnssec ldap pam seccomp selinux systemd test" + +COMMON_DEPEND=" + dev-libs/gmp:0= + dev-libs/libevent:0= + dev-libs/nspr + caps? ( sys-libs/libcap-ng ) + curl? ( net-misc/curl ) + dnssec? ( net-dns/unbound:= net-libs/ldns ) + ldap? ( net-nds/openldap ) + pam? ( sys-libs/pam ) + seccomp? ( sys-libs/libseccomp ) + selinux? ( sys-libs/libselinux ) + systemd? ( sys-apps/systemd:0= ) +" +DEPEND="${COMMON_DEPEND} + app-text/docbook-xml-dtd:4.1.2 + app-text/xmlto + dev-libs/nss + sys-devel/bison + sys-devel/flex + virtual/pkgconfig + test? ( dev-python/setproctitle ) +" +RDEPEND="${COMMON_DEPEND} + dev-libs/nss[utils(+)] + sys-apps/iproute2 + !net-misc/openswan + !net-vpn/strongswan + selinux? ( sec-policy/selinux-ipsec ) +" + +usetf() { + usex "$1" true false +} + +src_prepare() { + eapply "${FILESDIR}/${P}-nss.patch" + eapply "${FILESDIR}/${P}-nss-link.patch" + + sed -i -e 's:/sbin/runscript:/sbin/openrc-run:' initsystems/openrc/ipsec.init.in || die + sed -i -e '/^install/ s/postcheck//' -e '/^doinstall/ s/oldinitdcheck//' initsystems/systemd/Makefile || die + default +} + +src_configure() { + tc-export AR CC + export INC_USRLOCAL=/usr + export INC_MANDIR=share/man + export FINALEXAMPLECONFDIR=/usr/share/doc/${PF} + export FINALDOCDIR=/usr/share/doc/${PF}/html + export INITSYSTEM=openrc + export INC_RCDIRS= + export INC_RCDEFAULT=/etc/init.d + export USERCOMPILE= + export USERLINK= + export USE_DNSSEC=$(usetf dnssec) + export USE_LABELED_IPSEC=$(usetf selinux) + export USE_LIBCAP_NG=$(usetf caps) + export USE_LIBCURL=$(usetf curl) + export USE_LINUX_AUDIT=$(usetf selinux) + export USE_LDAP=$(usetf ldap) + export USE_SECCOMP=$(usetf seccomp) + export USE_SYSTEMD_WATCHDOG=$(usetf systemd) + export SD_WATCHDOGSEC=$(usex systemd 200 0) + export USE_XAUTHPAM=$(usetf pam) + export DEBUG_CFLAGS= + export OPTIMIZE_CFLAGS= + export WERROR_CFLAGS= +} + +src_compile() { + emake all + emake -C initsystems INITSYSTEM=systemd UNITDIR="$(systemd_get_systemunitdir)" all +} + +src_test() { + : # integration tests only that require set of kvms to be set up +} + +src_install() { + default + emake -C initsystems INITSYSTEM=systemd UNITDIR="$(systemd_get_systemunitdir)" DESTDIR="${D}" install + + echo "include /etc/ipsec.d/*.secrets" > "${D}"/etc/ipsec.secrets + fperms 0600 /etc/ipsec.secrets + + dodoc -r docs + + find "${D}" -type d -empty -delete || die +} + +pkg_postinst() { + local IPSEC_CONFDIR=${ROOT%/}/etc/ipsec.d + if [[ ! -f ${IPSEC_CONFDIR}/cert8.db ]]; then + ebegin "Setting up NSS database in ${IPSEC_CONFDIR}" + certutil -N -d "${IPSEC_CONFDIR}" -f <(echo) + eend $? + fi +} |