public inbox for gentoo-commits@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-commits] repo/gentoo:master commit in: profiles/, www-apache/mod_security/, www-apache/mod_security/files/
@ 2020-11-09 18:36 Marek Szuba
  0 siblings, 0 replies; only message in thread
From: Marek Szuba @ 2020-11-09 18:36 UTC (permalink / raw
  To: gentoo-commits

commit:     03e5af320cedd6609c4f3ff10db83c7cc2dd898a
Author:     Marek Szuba <marecki <AT> gentoo <DOT> org>
AuthorDate: Mon Nov  9 18:32:16 2020 +0000
Commit:     Marek Szuba <marecki <AT> gentoo <DOT> org>
CommitDate: Mon Nov  9 18:35:55 2020 +0000
URL:        https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=03e5af32

www-apache/mod_security: migrate to lua-single.eclass

Closes: https://bugs.gentoo.org/752513
Signed-off-by: Marek Szuba <marecki <AT> gentoo.org>

 profiles/package.mask                              |   1 +
 ..._security-2.9.3-autoconf_lua_package_name.patch |  11 ++
 .../mod_security/mod_security-2.9.3-r100.ebuild    | 124 +++++++++++++++++++++
 3 files changed, 136 insertions(+)

diff --git a/profiles/package.mask b/profiles/package.mask
index b20689779c5..20ae83f4b20 100644
--- a/profiles/package.mask
+++ b/profiles/package.mask
@@ -297,6 +297,7 @@ dev-lua/luacrypto
 >=net-analyzer/suricata-6.0.0-r100
 >=net-p2p/eiskaltdcpp-2.2.10-r100
 >=sci-visualization/gnuplot-5.4.0-r100
+>=www-apache/mod_security-2.9.3-r100
 >=www-servers/lighttpd-1.4.55-r100
 >=app-admin/conky-1.11.4
 >=media-sound/aqualung-1.1-r100

diff --git a/www-apache/mod_security/files/mod_security-2.9.3-autoconf_lua_package_name.patch b/www-apache/mod_security/files/mod_security-2.9.3-autoconf_lua_package_name.patch
new file mode 100644
index 00000000000..733524ebbc9
--- /dev/null
+++ b/www-apache/mod_security/files/mod_security-2.9.3-autoconf_lua_package_name.patch
@@ -0,0 +1,11 @@
+--- a/build/find_lua.m4
++++ b/build/find_lua.m4
+@@ -16,7 +16,7 @@
+ LUA_LDADD=""
+ LUA_LDFLAGS=""
+ LUA_CONFIG=${PKG_CONFIG}
+-LUA_PKGNAMES="lua5.1 lua-5.1 lua_5.1 lua-51 lua_51 lua51 lua5 lua lua5.2 lua-5.2 lua_5.2 lua-52 lua_52 lua52 lua5.3 lua-5.3 lua_5.3 lua-53 lua_53 lua53 "
++LUA_PKGNAMES="lua "
+ LUA_SONAMES="so la sl dll dylib a"
+ 
+ AC_ARG_WITH(

diff --git a/www-apache/mod_security/mod_security-2.9.3-r100.ebuild b/www-apache/mod_security/mod_security-2.9.3-r100.ebuild
new file mode 100644
index 00000000000..270824b6cb6
--- /dev/null
+++ b/www-apache/mod_security/mod_security-2.9.3-r100.ebuild
@@ -0,0 +1,124 @@
+# Copyright 1999-2020 Gentoo Authors
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=7
+
+LUA_COMPAT=( lua5-{1..3} )
+
+inherit autotools apache-module lua-single
+
+MY_PN=modsecurity
+MY_P=${MY_PN}-${PV}
+
+DESCRIPTION="Application firewall and intrusion detection for Apache"
+HOMEPAGE="https://www.modsecurity.org/"
+SRC_URI="https://www.modsecurity.org/tarball/${PV}/${MY_P}.tar.gz"
+
+LICENSE="Apache-2.0"
+SLOT="0"
+KEYWORDS="~amd64 ~x86"
+IUSE="doc fuzzyhash geoip jit json lua mlogc"
+
+REQUIRED_USE="lua? ( ${LUA_REQUIRED_USE} )"
+
+COMMON_DEPEND="dev-libs/apr
+	dev-libs/apr-util[openssl]
+	dev-libs/libxml2
+	dev-libs/libpcre[jit?]
+	fuzzyhash? ( app-crypt/ssdeep )
+	json? ( dev-libs/yajl )
+	lua? ( ${LUA_DEPS} )
+	mlogc? ( net-misc/curl )
+	www-servers/apache[apache2_modules_unique_id]"
+BDEPEND="doc? ( app-doc/doxygen )"
+DEPEND="${COMMON_DEPEND}"
+RDEPEND="${COMMON_DEPEND}
+	geoip? ( dev-libs/geoip )
+	mlogc? ( dev-lang/perl )"
+PDEPEND=">=www-apache/modsecurity-crs-2.2.6-r1"
+
+S="${WORKDIR}/${MY_P}"
+
+APACHE2_MOD_FILE="apache2/.libs/${PN}2.so"
+APACHE2_MOD_CONF="79_${PN}"
+APACHE2_MOD_DEFINE="SECURITY"
+
+# Tests require symbols only defined within the Apache binary.
+RESTRICT=test
+
+PATCHES=(
+	"${FILESDIR}"/${PN}-2.9.3-autoconf_lua_package_name.patch
+)
+
+need_apache2
+
+pkg_setup() {
+	_init_apache2
+	_init_apache2_late
+	lua-single_pkg_setup
+}
+
+src_prepare() {
+	default
+	eautoreconf
+}
+
+src_configure() {
+	local myconf=(
+		--disable-static
+		--enable-request-early
+		--with-apxs="${APXS}"
+		--with-pic
+		$(use_with fuzzyhash ssdeep)
+		$(use_with json yajl)
+		$(use_enable mlogc)
+		$(use_with lua)
+		$(use_enable lua lua-cache)
+		$(use_enable jit pcre-jit)
+		$(use_enable doc docs) )
+
+	econf ${myconf[@]}
+}
+
+src_compile() {
+	default
+}
+
+src_install() {
+	apache-module_src_install
+
+	dodoc CHANGES README.md modsecurity.conf-recommended
+
+	if use doc; then
+		dodoc -r doc/apache/html
+	fi
+
+	if use mlogc; then
+		insinto /etc/
+		newins mlogc/mlogc-default.conf mlogc.conf
+		dobin mlogc/mlogc
+		dobin mlogc/mlogc-batch-load.pl
+		newdoc mlogc/INSTALL INSTALL-mlogc
+	fi
+
+	# Use /var/lib instead of /var/cache. This stuff is "persistent,"
+	# and isn't a cached copy of something that we can recreate.
+	# Bug 605496.
+	keepdir /var/lib/modsecurity
+	fowners apache:apache /var/lib/modsecurity
+	fperms 0750 /var/lib/modsecurity
+	for dir in data tmp upload; do
+		keepdir "/var/lib/modsecurity/${dir}"
+		fowners apache:apache "/var/lib/modsecurity/${dir}"
+		fperms 0750 "/var/lib/modsecurity/${dir}"
+	done
+}
+
+pkg_postinst() {
+	elog "The base configuration file has been renamed ${APACHE2_MOD_CONF}"
+	elog "so that you can put your own configuration in (for example)"
+	elog "90_modsecurity_local.conf."
+	elog ""
+	elog "That would be the correct place for site-global security rules."
+	elog "Note: 80_modsecurity_crs.conf is used by www-apache/modsecurity-crs"
+}


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2020-11-09 18:36 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-11-09 18:36 [gentoo-commits] repo/gentoo:master commit in: profiles/, www-apache/mod_security/, www-apache/mod_security/files/ Marek Szuba

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox