mirror of
https://github.com/gentoo-mirror/gentoo.git
synced 2026-09-24 04:59:14 -07:00
net-firewall/iptables: bump to v1.8.6
Package-Manager: Portage-3.0.8, Repoman-3.0.2 Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>
This commit is contained in:
@@ -2,3 +2,4 @@ DIST iptables-1.6.1.tar.bz2 620890 BLAKE2B b45ac26e1fb7e8b17a6df0afab3b6c0e2f0a5
|
||||
DIST iptables-1.6.2.tar.bz2 639785 BLAKE2B 3d129756fd33c8c73d56d57e3c5595896db86ded14834a45db21b964d82840b62216ce3cea4ae4960e8c5f0671df3cc6bfb222f68d29cf3a8c99e0eee14bf017 SHA512 04f22e969c794246b9aa28055b202638081cfb0bb4a5625c049a30c48ac84cdd41db12a53c5831398cfe47c8f5691aa02b30b0ae3b5afe0f20ec48cf86a799c0
|
||||
DIST iptables-1.8.4.tar.bz2 704312 BLAKE2B f677bb9ed2c86e6a39953c0565766991e9647224effdc7db2b563f3f491f6ace2f9073ecc8e865d489101a9f80cf964d9775ab81536412dbd4ca85937432de94 SHA512 a7faaab58608ffaa51e26e8056551c0e91a49187439d30fcf5cce2800274cc3c0515db6cfba0f4c85613fb80779cf96089b8915db0e89161e9980a6384faebdb
|
||||
DIST iptables-1.8.5.tar.bz2 713769 BLAKE2B 49659fc2f1f284f31637048fa1e6edb4853e9bf6ac0b6ada5599a7af34a4449205b5eb6b85b630ce4757b49cf3f8ac9ad6220e07c2c22abb688a3aeb5cf99cd2 SHA512 6a6baa541bb7aa331b176e0a91894e0766859814b59e77c71351ac34d6ebd337487981db48c70e476a48c67bcf891cfc663221a7582feb1496ad1df56eb28da8
|
||||
DIST iptables-1.8.6.tar.bz2 715744 BLAKE2B 72167610b396054fe18c495d7a9e23051d217116074ee39198af989a3e50b9908cb75f42b9172d3cfd76343835386a78a2c51d1153ed5d219a6d68209e11dc9c SHA512 d06e4cddb69822c4618664a35877fc5811992936cade2040bb0e4eb25a4d879eadc7c84401c40fb39ffac7888568505adcb1cfe995cd166a15c702237daf6acf
|
||||
|
||||
179
net-firewall/iptables/iptables-1.8.6.ebuild
Normal file
179
net-firewall/iptables/iptables-1.8.6.ebuild
Normal file
@@ -0,0 +1,179 @@
|
||||
# Copyright 1999-2020 Gentoo Authors
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
EAPI=7
|
||||
|
||||
inherit multilib systemd toolchain-funcs autotools flag-o-matic usr-ldscript
|
||||
|
||||
DESCRIPTION="Linux kernel (2.4+) firewall, NAT and packet mangling tools"
|
||||
HOMEPAGE="https://www.netfilter.org/projects/iptables/"
|
||||
SRC_URI="https://www.netfilter.org/projects/iptables/files/${P}.tar.bz2"
|
||||
|
||||
LICENSE="GPL-2"
|
||||
# Subslot reflects PV when libxtables and/or libip*tc was changed
|
||||
# the last time.
|
||||
SLOT="0/1.8.3"
|
||||
KEYWORDS="~alpha ~amd64 ~arm ~arm64 ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~riscv ~s390 ~sparc ~x86"
|
||||
IUSE="conntrack ipv6 netlink nftables pcap static-libs"
|
||||
|
||||
BUILD_DEPEND="
|
||||
>=app-eselect/eselect-iptables-20200508
|
||||
"
|
||||
COMMON_DEPEND="
|
||||
conntrack? ( >=net-libs/libnetfilter_conntrack-1.0.6 )
|
||||
netlink? ( net-libs/libnfnetlink )
|
||||
nftables? (
|
||||
>=net-libs/libmnl-1.0:0=
|
||||
>=net-libs/libnftnl-1.1.6:0=
|
||||
)
|
||||
pcap? ( net-libs/libpcap )
|
||||
"
|
||||
DEPEND="${COMMON_DEPEND}
|
||||
virtual/os-headers
|
||||
>=sys-kernel/linux-headers-4.4:0
|
||||
"
|
||||
BDEPEND="${BUILD_DEPEND}
|
||||
app-eselect/eselect-iptables
|
||||
virtual/pkgconfig
|
||||
nftables? (
|
||||
sys-devel/flex
|
||||
virtual/yacc
|
||||
)
|
||||
"
|
||||
RDEPEND="${COMMON_DEPEND}
|
||||
${BUILD_DEPEND}
|
||||
nftables? ( net-misc/ethertypes )
|
||||
!<net-firewall/ebtables-2.0.11-r1
|
||||
!<net-firewall/arptables-0.0.5-r1
|
||||
"
|
||||
|
||||
PATCHES=(
|
||||
"${FILESDIR}/iptables-1.8.4-no-symlinks.patch"
|
||||
"${FILESDIR}/iptables-1.8.2-link.patch"
|
||||
)
|
||||
|
||||
src_prepare() {
|
||||
# use the saner headers from the kernel
|
||||
rm include/linux/{kernel,types}.h || die
|
||||
|
||||
default
|
||||
eautoreconf
|
||||
}
|
||||
|
||||
src_configure() {
|
||||
# Some libs use $(AR) rather than libtool to build #444282
|
||||
tc-export AR
|
||||
|
||||
# Hack around struct mismatches between userland & kernel for some ABIs. #472388
|
||||
use amd64 && [[ ${ABI} == "x32" ]] && append-flags -fpack-struct
|
||||
|
||||
sed -i \
|
||||
-e "/nfnetlink=[01]/s:=[01]:=$(usex netlink 1 0):" \
|
||||
-e "/nfconntrack=[01]/s:=[01]:=$(usex conntrack 1 0):" \
|
||||
configure || die
|
||||
|
||||
local myeconfargs=(
|
||||
--sbindir="${EPREFIX}/sbin"
|
||||
--libexecdir="${EPREFIX}/$(get_libdir)"
|
||||
--enable-devel
|
||||
--enable-shared
|
||||
$(use_enable nftables)
|
||||
$(use_enable pcap bpf-compiler)
|
||||
$(use_enable pcap nfsynproxy)
|
||||
$(use_enable static-libs static)
|
||||
$(use_enable ipv6)
|
||||
)
|
||||
econf "${myeconfargs[@]}"
|
||||
}
|
||||
|
||||
src_compile() {
|
||||
emake V=1
|
||||
}
|
||||
|
||||
src_install() {
|
||||
default
|
||||
dodoc INCOMPATIBILITIES iptables/iptables.xslt
|
||||
|
||||
# all the iptables binaries are in /sbin, so might as well
|
||||
# put these small files in with them
|
||||
into /
|
||||
dosbin iptables/iptables-apply
|
||||
dosym iptables-apply /sbin/ip6tables-apply
|
||||
doman iptables/iptables-apply.8
|
||||
|
||||
insinto /usr/include
|
||||
doins include/iptables.h $(use ipv6 && echo include/ip6tables.h)
|
||||
insinto /usr/include/iptables
|
||||
doins include/iptables/internal.h
|
||||
|
||||
keepdir /var/lib/iptables
|
||||
newinitd "${FILESDIR}"/${PN}-r2.init iptables
|
||||
newconfd "${FILESDIR}"/${PN}-r1.confd iptables
|
||||
if use ipv6 ; then
|
||||
keepdir /var/lib/ip6tables
|
||||
dosym iptables /etc/init.d/ip6tables
|
||||
newconfd "${FILESDIR}"/ip6tables-r1.confd ip6tables
|
||||
fi
|
||||
|
||||
if use nftables; then
|
||||
# Bug 647458
|
||||
rm "${ED}"/etc/ethertypes || die
|
||||
|
||||
# Bugs 660886 and 669894
|
||||
rm "${ED}"/sbin/{arptables,ebtables}{,-{save,restore}} || die
|
||||
fi
|
||||
|
||||
systemd_dounit "${FILESDIR}"/systemd/iptables-{re,}store.service
|
||||
if use ipv6 ; then
|
||||
systemd_dounit "${FILESDIR}"/systemd/ip6tables-{re,}store.service
|
||||
fi
|
||||
|
||||
# Move important libs to /lib #332175
|
||||
gen_usr_ldscript -a ip{4,6}tc xtables
|
||||
|
||||
find "${ED}" -type f -name "*.la" -delete || die
|
||||
}
|
||||
|
||||
pkg_postinst() {
|
||||
local default_iptables="xtables-legacy-multi"
|
||||
if ! eselect iptables show &>/dev/null; then
|
||||
elog "Current iptables implementation is unset, setting to ${default_iptables}"
|
||||
eselect iptables set "${default_iptables}"
|
||||
fi
|
||||
|
||||
if use nftables; then
|
||||
local tables
|
||||
for tables in {arp,eb}tables; do
|
||||
if ! eselect ${tables} show &>/dev/null; then
|
||||
elog "Current ${tables} implementation is unset, setting to ${default_iptables}"
|
||||
eselect ${tables} set xtables-nft-multi
|
||||
fi
|
||||
done
|
||||
fi
|
||||
|
||||
eselect iptables show
|
||||
}
|
||||
|
||||
pkg_prerm() {
|
||||
elog "Unsetting iptables symlinks before removal"
|
||||
eselect iptables unset
|
||||
|
||||
if ! has_version 'net-firewall/ebtables'; then
|
||||
elog "Unsetting ebtables symlinks before removal"
|
||||
eselect ebtables unset
|
||||
elif [[ -z ${REPLACED_BY_VERSION} ]]; then
|
||||
elog "Resetting ebtables symlinks to ebtables-legacy"
|
||||
eselect ebtables set ebtables-legacy
|
||||
fi
|
||||
|
||||
if ! has_version 'net-firewall/arptables'; then
|
||||
elog "Unsetting arptables symlinks before removal"
|
||||
eselect arptables unset
|
||||
elif [[ -z ${REPLACED_BY_VERSION} ]]; then
|
||||
elog "Resetting arptables symlinks to arptables-legacy"
|
||||
eselect arptables set arptables-legacy
|
||||
fi
|
||||
|
||||
# the eselect module failing should not be fatal
|
||||
return 0
|
||||
}
|
||||
Reference in New Issue
Block a user