public inbox for gentoo-commits@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Joonas Niilola" <juippis@gentoo.org>
To: gentoo-commits@lists.gentoo.org
Subject: [gentoo-commits] repo/gentoo:master commit in: net-firewall/fwknop/
Date: Mon,  4 Mar 2024 07:53:53 +0000 (UTC)	[thread overview]
Message-ID: <1709538827.1d29ef3e3ee3cfed5cc90e993c21d7abd7fe6d15.juippis@gentoo> (raw)

commit:     1d29ef3e3ee3cfed5cc90e993c21d7abd7fe6d15
Author:     Hank Leininger <hlein <AT> korelogic <DOT> com>
AuthorDate: Thu Feb  8 22:41:09 2024 +0000
Commit:     Joonas Niilola <juippis <AT> gentoo <DOT> org>
CommitDate: Mon Mar  4 07:53:47 2024 +0000
URL:        https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1d29ef3e

net-firewall/fwknop: add 2.6.11

Signed-off-by: Hank Leininger <hlein <AT> korelogic.com>
Closes: https://bugs.gentoo.org/822741
Closes: https://bugs.gentoo.org/920793
Closes: https://github.com/gentoo/gentoo/pull/35236
Signed-off-by: Joonas Niilola <juippis <AT> gentoo.org>

 net-firewall/fwknop/Manifest             |   2 +
 net-firewall/fwknop/fwknop-2.6.11.ebuild | 133 +++++++++++++++++++++++++++++++
 2 files changed, 135 insertions(+)

diff --git a/net-firewall/fwknop/Manifest b/net-firewall/fwknop/Manifest
index 53b2c9de54bf..9dca4d3387dd 100644
--- a/net-firewall/fwknop/Manifest
+++ b/net-firewall/fwknop/Manifest
@@ -1 +1,3 @@
 DIST fwknop-2.6.10.tar.gz 1988197 BLAKE2B d4c2010c64ab160f0edc02e2b1530749ee47ff6ed16d6b556d366daef7ce5e22ef38fbbbf6e8cfaa14e0d9706ba2b65937b03c70b54b3429ff1732ae33c1852c SHA512 3b3e35eda574abd1759431c88677eea7078c54cb3252c0ee0e1019b5b8224ed8844d30760da70a952e1cd92b04715a547f6effabda54678f791fff9afa32cd80
+DIST fwknop-2.6.11.tar.bz2 1812061 BLAKE2B 7cfb8abc95fd8aa8a8d6774507fe4dea8deacc5aa4c9f5874c39dc2a3ab0c413cf479632a34027c76180cecd0a4fbf11d8cac5fe77f48993932fab13ea740a0b SHA512 79ce0585d075dffe77143b4d6ec3f8653ddad5f46cfb596e9f373be0065bdace7efdfe9cd341ebfaa7232d39f905affa81325b569635c8a44095fd551debadd7
+DIST fwknop-2.6.11.tar.bz2.asc 195 BLAKE2B 56ea868bd31fc4d06e3e976042bd3969f2c8df5bcb1e6a12d87c5740eb39b2eaf1118620be260e94b07758f4bc875e58f6b63a7989cdc08a32f049aa208b57a3 SHA512 2902a9ccb1c82baa4a96af5841d21ac873b606876fe01e8fbcf2b1e2a89c75965477f574c62a6f261f2af4420038ea6d41ef66af57b79742527054593e3cd3d7

diff --git a/net-firewall/fwknop/fwknop-2.6.11.ebuild b/net-firewall/fwknop/fwknop-2.6.11.ebuild
new file mode 100644
index 000000000000..2ae43d31f5f7
--- /dev/null
+++ b/net-firewall/fwknop/fwknop-2.6.11.ebuild
@@ -0,0 +1,133 @@
+# Copyright 1999-2024 Gentoo Authors
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=8
+
+VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/fwknop.gpg
+inherit autotools linux-info readme.gentoo-r1 systemd tmpfiles verify-sig
+
+DESCRIPTION="Single Packet Authorization and Port Knocking application"
+HOMEPAGE="https://www.cipherdyne.org/fwknop/"
+SRC_URI="
+	https://www.cipherdyne.org/fwknop/download/${P}.tar.bz2
+	verify-sig? ( https://www.cipherdyne.org/fwknop/download/${P}.tar.bz2.asc )
+	"
+
+LICENSE="GPL-2+"
+SLOT="0"
+KEYWORDS="~amd64 ~x86"
+IUSE="+client extras firewalld gdbm gpg +iptables nfqueue +server static-libs udp-server"
+
+DEPEND="
+	client? ( net-misc/wget[ssl] )
+	firewalld? ( net-firewall/firewalld )
+	gdbm? ( sys-libs/gdbm )
+	gpg? (
+		app-crypt/gpgme:=
+		dev-libs/libassuan
+		dev-libs/libgpg-error
+	)
+	iptables? ( net-firewall/iptables )
+	nfqueue? ( net-libs/libnetfilter_queue )
+	server? ( !nfqueue? ( !udp-server? ( net-libs/libpcap ) ) )
+	verify-sig? ( sec-keys/openpgp-keys-fwknop )
+"
+RDEPEND="${DEPEND}"
+
+REQUIRED_USE="
+	nfqueue? ( server )
+	server? ( ^^ ( firewalld iptables ) )
+	udp-server? ( server )
+"
+
+##PATCHES=( "${FILESDIR}/${PN}-2.6.10_fno-common_fix.patch" )
+
+DOCS=( AUTHORS ChangeLog README )
+
+DISABLE_AUTOFORMATTING=1
+DOC_CONTENTS="
+Example configuration files were installed to '${EPREFIX}/etc/fwknopd/'.
+Please edit them to suit your needs and then remove the .example suffix.
+
+fwknopd supports several backends: firewalld, iptables, ipfw, pf, ipf.
+You can set the desired backend via FIREWALL_EXE option in fwknopd.conf
+instead of the default one chosen at compile time.
+"
+
+pkg_setup() {
+	linux-info_pkg_setup
+}
+
+src_prepare() {
+	default_src_prepare
+
+	# Install example configs with .example suffix.
+	if use server; then
+		sed -i -e 's|conf;|conf.example;|g' Makefile.am || die
+	fi
+
+	eautoreconf
+}
+
+src_configure() {
+	local myeconfargs=(
+		--localstatedir="${EPREFIX}/run"
+		$(use_enable client)
+		$(use_enable !gdbm file-cache)
+		$(use_enable nfqueue nfq-capture)
+		$(use_enable server)
+		$(use_enable udp-server)
+		$(use_with gpg gpgme)
+	)
+	use firewalld && myeconfargs+=(--with-firewalld="${EPREFIX}/usr/sbin/firewalld")
+	use iptables && myeconfargs+=(--with-iptables="${EPREFIX}/sbin/iptables")
+
+	econf "${myeconfargs[@]}"
+}
+
+src_install() {
+	default_src_install
+
+	if use extras; then
+		dodoc extras/apparmor/usr.sbin.fwknopd
+		dodoc extras/console-qr/console-qr.sh
+		dodoc extras/fwknop-launcher/*
+	fi
+
+	if use server; then
+		newinitd "${FILESDIR}/fwknopd.init" fwknopd
+		newconfd "${FILESDIR}/fwknopd.confd" fwknopd
+		systemd_dounit extras/systemd/fwknopd.service
+		newtmpfiles "${FILESDIR}/fwknopd.tmpfiles.conf" fwknopd.conf
+		readme.gentoo_create_doc
+	fi
+
+	find "${ED}" -type f -name "*.la" -delete || die
+
+	if ! use static-libs ; then
+		find "${ED}" -type f -name libfko.a -delete || die
+	fi
+}
+
+pkg_postinst() {
+	if use server; then
+		readme.gentoo_print_elog
+
+		tmpfiles_process fwknopd.conf
+
+		if ! linux_config_exists || ! linux_chkconfig_present NETFILTER_XT_MATCH_COMMENT; then
+			echo
+			ewarn "fwknopd daemon relies on the 'comment' match in order to expire"
+			ewarn "created firewall rules, which is an important security feature."
+			ewarn "Please enable NETFILTER_XT_MATCH_COMMENT support in your kernel."
+			echo
+		fi
+		if use nfqueue && \
+			! linux_config_exists || ! linux_chkconfig_present NETFILTER_XT_TARGET_NFQUEUE; then
+			echo
+			ewarn "fwknopd daemon relies on the 'NFQUEUE' target for NFQUEUE mode."
+			ewarn "Please enable NETFILTER_XT_TARGET_NFQUEUE support in your kernel."
+			echo
+		fi
+	fi
+}


             reply	other threads:[~2024-03-04  7:53 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-03-04  7:53 Joonas Niilola [this message]
  -- strict thread matches above, loose matches on Subject: below --
2024-06-23  1:49 [gentoo-commits] repo/gentoo:master commit in: net-firewall/fwknop/ Sam James
2022-02-16 21:53 David Seifert
2021-07-30 23:31 Sam James
2021-03-07 11:58 David Seifert
2020-08-01 23:20 Andreas Sturmlechner
2020-07-01 23:55 Aaron Bauman
2020-02-09 15:54 Michał Górny
2019-11-04  6:23 Joonas Niilola
2019-11-04  6:23 Joonas Niilola
2017-09-06 12:06 Michał Górny
2016-09-21  0:29 Patrice Clement
2016-06-21  1:25 Göktürk Yüksek
2016-06-12  4:37 Göktürk Yüksek
2016-06-12  4:37 Göktürk Yüksek
2016-06-12  4:37 Göktürk Yüksek
2016-01-23 17:55 Patrice Clement
2016-01-23 17:55 Patrice Clement
2015-12-24  8:31 Ian Delaney
2015-12-21 23:55 Patrice Clement
2015-12-21 23:55 Patrice Clement
2015-12-21  3:01 Ian Delaney
2015-11-26 10:07 Patrice Clement
2015-11-24 23:28 Ian Delaney
2015-11-24 23:28 Ian Delaney
2015-10-31  9:36 Ian Delaney
2015-09-05 14:45 Ian Delaney

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1709538827.1d29ef3e3ee3cfed5cc90e993c21d7abd7fe6d15.juippis@gentoo \
    --to=juippis@gentoo.org \
    --cc=gentoo-commits@lists.gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox