mirror of
https://github.com/gentoo-mirror/gentoo.git
synced 2026-09-23 16:49:10 -07:00
www-servers/nginx: Security cleanup (bug #624552)
Package-Manager: Portage-2.3.5, Repoman-2.3.2
This commit is contained in:
@@ -1,12 +1,5 @@
|
||||
DIST modsecurity-2.9.1.tar.gz 4261212 SHA256 958cc5a7a7430f93fac0fd6f8b9aa92fc1801efce0cda797d6029d44080a9b24 SHA512 374733cbfc26e53d95b78c8f268a4e465d838163e9893fc24e33a9d272b114f1b287147bab6d0289575074cbbd94f48983e23fa59832cbcb32950046cea59269 WHIRLPOOL 5f41bebf032f8a269412d104b7632a06af4d4c495658c9cd1ebf69b82c10ce1bbcb34b9dd159a7b00e57348714a5e93ad3db19701dda51479accd3a9dc79a9cb
|
||||
DIST nginx-1.10.3.tar.gz 911509 SHA256 75020f1364cac459cb733c4e1caed2d00376e40ea05588fb8793076a4c69dd90 SHA512 25cddbe5c419700aeca41bff3be5b7c3accfb38ad846ec8d91d81ab7c15f10db719f02d9263edf1fa12f59805ff7001b62864dc2885370b24afeea1d7d2afbbf WHIRLPOOL 1ebf540d49d28a853a9221a558b53d28e2e7dfddf345e433baa4c2b819f6e1fe34528b4680387147c73271d3837529a4452e53b863dff5d29772c2b0a75e0ba6
|
||||
DIST nginx-1.11.10.tar.gz 967773 SHA256 778b3cabb07633f754cd9dee32fc8e22582bce22bfa407be76a806abd935533d SHA512 b6437d8305547a834a0f3ad076ac591b90189eb922f48759094efaa9618e39fc249600ab13650113fe841fc9af0b736acc61a9b9baba7bacd35224c34df1bbc9 WHIRLPOOL f9535d4fabad7603cc384dda13aca51be77c7901d099190f9d5a187e517128a56a28cb851408b93091f8d99ce118678857ec08fba16bec4c2e2ed2d75ab543bd
|
||||
DIST nginx-1.11.13.tar.gz 980784 SHA256 360b601ef8ed2998c80fa56a27bf3cd745c3ce18c5fb10892e6595467b1415d3 SHA512 6546a1d96e5234c9512217559c22bc4be0e5f793d6082a9a3acaa1724c91c656b36a976cb452195b256915dc0d21fd433f539cd6c06d73c8dbb0233220d54fa8 WHIRLPOOL 53b3e0b8767ea93d4a3daaf5cfcd489dd83d9f60f53f985c677dfb328b7e6aee13114290bed22b268bca12d2e63fbb142b2357ef7dd8166e8da9eac4c931289a
|
||||
DIST nginx-1.12.0.tar.gz 980831 SHA256 b4222e26fdb620a8d3c3a3a8b955e08b713672e1bc5198d1e4f462308a795b30 SHA512 e2e930b61491d91090090d4716740895fc7812e8e266c427ac2b40c5a70493150e5c81e769c6b7563baf5f0e15b32fae8f2b11fd5699e468e1cc40706defb8ee WHIRLPOOL 0f4819cccd965837f1dcc5217de6c98cfd2d83e406fedb4840096d8ccacaac77767ae02551f2f927f2dc4a9413944206d8a26cf8eff8e425a53ba0ce425c5657
|
||||
DIST nginx-1.12.1.tar.gz 981093 SHA256 8793bf426485a30f91021b6b945a9fd8a84d87d17b566562c3797aba8fac76fb SHA512 3a2ad2a559b366dda92dd58c0fe40ee84dd60a3eaf72071454110e032c3e9a03f2a63b28fe3a615b527950521eeb533c687a2cc4c87524e1d8f3a0a5f043fdb6 WHIRLPOOL 17e91044636839f0c8c476879227f2de1633679199787157e5ed47c306dcb9597646c5be96957d51e38d96ddbb0346ec9f72b87c37023e19e572fa404ef0fd1f
|
||||
DIST nginx-1.13.0.tar.gz 982592 SHA256 79f52ab6550f854e14439369808105b5780079769d7b8db3856be03c683605d7 SHA512 54745876db546cc4d42ef048159bf6f9584278989f03e7e3451597eacbaad7713f9bf9bf93fc540a1be13380281d499f4aa4f27dcdfd3e860bc1203c9cde314b WHIRLPOOL 535f646b1da1193d1d40ae6e2fda12ab6480f863d98f7e35cccc8f561e96acb28255a1f44996ac3865236a664622e8dba2afd1d6219806d1c0765ee1a53e5df9
|
||||
DIST nginx-1.13.1.tar.gz 984142 SHA256 a5856c72a6609a4dc68c88a7f3c33b79e6693343b62952e021e043fe347b6776 SHA512 09ed3aa700965061d70edef732fccb2e32b9ace9eedbd86c8ad8d152748caf2d779ba2b06c3108ca0ad32f16e1a2e3551dbd1dc123c7dc1b64d672357dbd97ea WHIRLPOOL a5684393746e44777a1b8aa69de607c9cc6ebf227fac122a70b12888931939d992ffbc2bbfa44f063b69e1e8c06cdb15289c2d9ac0a1301f57aca1b1d3686e87
|
||||
DIST nginx-1.13.2.tar.gz 985802 SHA256 d77f234d14989d273a363f570e1d892395c006fef2ec04789be90f41a1919b70 SHA512 b07a0a6e8201979dbcec5ecdec9dd1210f35d5e861ff149b3a59f7d1d36f15ec195ef41c6d82a3bf618e9f044dbae06bb45d7f0369574cde97bd74b750dea905 WHIRLPOOL 46de82a5554a78249079a200720ec6184ff2e52a5609c12e365bdbc7f052486c3991eee3fac8bab71d75068e132a2eb112b4a99211a6365d991273a44e5d8ec2
|
||||
DIST nginx-1.13.3.tar.gz 985931 SHA256 5b73f98004c302fb8e4a172abf046d9ce77739a82487e4873b39f9b0dcbb0d72 SHA512 4a8924b1edd0b8476437680ea548a0bc983d360e73f2d5797f60cebc3ef7d6fb64e56b6aaf5a4fc1707d24519dc70d466a7bf1d336c463651928d65c2f7b5380 WHIRLPOOL 9cb1f77a60945d9c1df6e2589116406f31939882131759d3aa95b25edfe86bc5fe712a517a3b0f77a5fca2b3706884984b90e293a4e791faa824bbf0e964518e
|
||||
DIST nginx-auth-ldap-49a8b4d28fc4a518563c82e0b52821e5f37db1fc.tar.gz 17159 SHA256 3c11c32f05da04f1a4647dc4e35dd8d8aeacd5a2e763ba349feba3dba8663132 SHA512 323abd0ca8e90f5afcaf81a8ff1a8abe3dfcbff3d69f0dd4a1c005fe6436acbf3076c4c57a4df877b3d8e388cbea085d46301bb2df9c0752e2567817ff7cca92 WHIRLPOOL ad65e8182b2634db5fa06055ef7d91c7d8aabd0fa986d8402a4845977354d6edb329621b6f9f96c90ce2d158cff20e42ae50fba06a088a84de3e3f414205dbc2
|
||||
DIST nginx_http_sticky_module_ng-1.2.6-10-g08a395c66e42.tar.bz2 124047 SHA256 6f9102321d8c68df6d67e9bde145a8de3f45f99f6cb47c08735a86f003234d31 SHA512 6c1bfdcf89884b2855d51ae7da0f6e53a4ca3629e1aaf58433b70c07dcb2af797ba6e87d9b3eb4fe2fb6d4d697e862f2b4c2f8d8b3fdaea201740c97ec936529 WHIRLPOOL 38abe56e177e22dad68ac7d6570425ecd763d2e891627a75156a6f39bd7edc54f664c3d2f638e1ea57c743dadc6a8c9889be087abbdb4c98b5641c299f7fbc07
|
||||
@@ -17,18 +10,13 @@ DIST ngx_http_dav_ext-0.0.3.tar.gz 6260 SHA256 d428a0236c933779cb40ac8c91afb19d5
|
||||
DIST ngx_http_echo-0.60.tar.gz 52771 SHA256 1077da2229ac7d0a0215e9e6817e297c10697e095010d88f1adbd1add1ce9f4e SHA512 c455bee73cebd0752449472452d15614b9587ddd199263d366484ede890c4d108eacbbeaef31adc9dc7732b56ef2bfc73c0fef3366366db03a8ec3fdc27a985c WHIRLPOOL 8938ac18aae74a5c4806ff3611c243c9bee108ef93fef7b0da284040c2ec2d9a57cb3cad9e3719cb795bbb063176d7afe81b7288ebacf5096d26b16e5ef34da6
|
||||
DIST ngx_http_fancyindex-0.4.1.tar.gz 21130 SHA256 2b00d8e0ad2a67152a9cee7b7ee67990c742d501412df912baaf1eee9bb6dc71 SHA512 ce0043ad4a2b638c5d99244d6caaa65ad142cea78884084a9aeca5a9593c68dbe508c9e4dd85dc5722eb63ef386612bffc48d4b6fc1487df244fbcb7a73bffe1 WHIRLPOOL 4a885afbadf64bbd25df6580a099472ae48836d9dddfe1dee6ac6a6f97bfb0cf7120ff10dd69fceca7085fab590bec3a4b4b5be5644f2352375316885ddc3cac
|
||||
DIST ngx_http_headers_more-0.32.tar.gz 28033 SHA256 c6d9dab8ea1fc997031007e2e8f47cced01417e203cd88d53a9fe9f6ae138720 SHA512 e42582b45c3111de3940bbeb67ce161aca2d55adcfb00c61c12256fa0e36221d38723013f36edbcf6d1b520f8dfb49d4657df8a956e66d36e68425afad382bd1 WHIRLPOOL 2b95ea8e2933e83082b9dfd7aaa8f57dd38b0ec12fb452a4aa38a215ca76b6572fe35b79c8afe8cf3097bf89ced0e81c33e07ee6913c99966b87b8e610df3121
|
||||
DIST ngx_http_lua-0.10.7.tar.gz 605171 SHA256 c21c8937dcdd6fc2b6a955f929e3f4d1388610f47180e60126e6dcab06786f77 SHA512 d060a13de4d01d77e6d6cd1635ecbb405330e4326b71b89341c1c128ee4182978a51d53355bc07c350e3c3a7df15325e3df380d9c3a98b2ff7d7efa18fa09b32 WHIRLPOOL 7b64f75aae2ab74f51b3b2d07a59262a2c8ab2b863698b93b1184c003049641b45eded8fa5cc6301887c80d5fc34e9f22365da7765b3d5594ad838dacfceddd7
|
||||
DIST ngx_http_lua-0.10.8.tar.gz 606643 SHA256 d67449c71051b3cc2d6dd60df0ae0d21fca08aa19c9b30c5b95ee21ff38ef8dd SHA512 ad621cec178eb37109f16ebc30dbab7b1ea344ac4b523ff1e6ad62364b8cf437488a89c593ca44b446b729a1c578e3a97685851847b4b16a147ac9eca8f23a2a WHIRLPOOL 07ba9d1c35c5f8cf627a485ee19b4a5bd0969efc70283f4617af542c5152879aba2b6f5e0a8fd1a6d1a69c2438a499f56156de6f3345a0f2f6527686e682baba
|
||||
DIST ngx_http_naxsi-0.55.1.tar.gz 185997 SHA256 45dd0df7a6b0b6aa9c64eb8c39a8e294d659d87fb18e192cf58f1402f3cdb0a8 SHA512 aebda20e5b78e9111b7bac1e15829258e6b85b80e4ce333e4dba8caead36287b3f0fcb453c51d7c59f07d637fa62f5c6b23aecd3bf6a3c3da4abebf1a6689f14 WHIRLPOOL 36830d10a35b724b7ea15e3884e96e2e4dd84f2b81fc1c7122d3e2e83a1942227321b1a7141d829423788bc52a3e199a95ca2637369e17f84ea16eb0cb2e5e37
|
||||
DIST ngx_http_naxsi-0.55.3.tar.gz 187416 SHA256 0b3c95d250772dc89ad8b49e47c1e024c5ae2c76c0cffa445e9fe05c4dd13495 SHA512 9e8f41a5cd1342cc9b8aa334a603842d14a256aab1f4a21205bb1278aecbb0c49e39c889d8113a5b41aad2efeaa2ed9f11cba6929173f50add91f54c4c59c8a0 WHIRLPOOL 0a1bbe06730730944a882d86ffa378c4a3c759366208913603ffd18fcd7b18e65b6b1a89e9a07dc82e360dfe7ef4a6430391f6e52de35023d33ca19e80a3b693
|
||||
DIST ngx_http_push_stream-0.5.2.tar.gz 182008 SHA256 1d07f38acdb8194bd49344b0ba21de101070de9b8731d27a8d22e928850bc199 SHA512 ee8bf9ece652da6aa5a39879298bba70d1842696545259f3f5e302cc61397b35f016364805805f9ab1914fc39ed2f07c015e042155789073e3d1fdc02a0783de WHIRLPOOL d309cecbb1bb5b6c4f64712d44889e3ecca59140d845a31a3f605dc3cc2aa01622b0deadb8f6852baea3c211bebbe6ed7d7868399447ac1249c1b1b740fa3c27
|
||||
DIST ngx_http_slowfs_cache-1.10.tar.gz 11809 SHA256 1e81453942e5b0877de1f1f06c56ae82918ea9818255cb935bcb673c95a758a1 SHA512 fbc9609a8d6913aeefe535f206b9e53477503f131934ead2ae5a6169e395af2f5fb54778704824d5eeb22a4ef40a11ebbcde580db62a631f70edcc2cfc06b15d WHIRLPOOL a02ed77422c47d9e476f8746186d19d632ddb953635d8d9dd51ff076225a78044286ee7e114478bc02e4b2a422e4fdc207154fc287629dd2cd7c3f9a634dad18
|
||||
DIST ngx_http_upload_progress-0.9.2-r1.tar.gz 17268 SHA256 b286689355442657650421d8e8398bd4abf9dbbaade65947bb0cb74a349cc497 SHA512 c31c46344d49704389722325a041b9cd170fa290acefe92cfc572c07f711cd3039de78f28df48ca7dcb79b2e4bbe442580aaaf4d92883fd3a14bf41d66dd9d8c WHIRLPOOL e847603f1445c7e1471a5570e2774a448be880eb71eeb21e27361586bcee9aae31cb0a8a80cd5abfc8d14e2c356fabfa7293e6a4d5f6782d41521a7bdc124066
|
||||
DIST ngx_http_upstream_check-0.3.0-10-gf3bdb7b.tar.gz 129060 SHA256 9e0835e8c1550033e74c7eaeebf94d41ab1617cff152dd076da976e0eba30bfc SHA512 5b2ae6d305d24d0c64dc118fd3b0c23f5bf0e9a282e70e8d2c4eb946ed510263b5e845f64ca352784e34708cf9d98804cacf64b6c9efd712a395076dd0ba7c29 WHIRLPOOL 8dab8aa1bf3f7c9adbf2952148d76cc627682876b5e64dc789582b573a4b6fa73910043325fc664784b68966bcb1e8ba9ae6bfa457133bde0d52e39b7d3c09e0
|
||||
DIST ngx_memc_module-0.17.tar.gz 36369 SHA256 25cbe3ff4931283a681260607bc91ae4a922075345d5770b293c6cd7f1e3bdcc SHA512 e6fdecb4bb629f0882868b78f4b3a2549fce4471efcc4f2c6fdc414435799be6ce41cf056a3170952f8a1f401ee1ca372c97f2d7f79fba79239599755ade8949 WHIRLPOOL 766d84e7a2dfb2a6f069fd846e19d635f4dbd36f78014e97bbd159312d0b38d671b4db989584ca2b5b449046483b5b90d09edbe1c4531b266d8592ad7bad3c3a
|
||||
DIST ngx_memc_module-0.18.tar.gz 37113 SHA256 4e280d1dcb8b312bc7875604c1e35b17879279126d3d5fbf482aa9cc7c11276d SHA512 8087bd361fb4e522493e66f93d59c9b13245d6eef0fe4a53f619d1826feb02af60769c0a04f87f2faf5308a44b794ef146a445bdbe7cbc7f21c0edaaba08c706 WHIRLPOOL 9570bf7fb4e925d1794f3af0914efca036fe65696e7e380969133b89878e5f46f71cd5ffb7b5ea94085aced26d289abca77d7ef805f03ff614bc12a47d7aab3f
|
||||
DIST ngx_metrics-0.1.1.tar.gz 2964 SHA256 1c62ebb31e3caafad91720962770b0e7a4287f195520cf12471c262ac19b154e SHA512 d36a8fb0104c83b6b564e03b351aa750cab08650264c74d6f786af357bfb7006b531a93270dd961896ea8dafe27e5db8548ede714c5f52c4742876bc73af4b5e WHIRLPOOL 2796f5a97e76dfcc91133240e8e90ba493f0356f781a173d8cacdd09eba64b75ef531db398c0566fda395124700de8c991b771433e376ca0d5898c2ea6f82868
|
||||
DIST ngx_mogilefs_module-1.0.4.tar.gz 11208 SHA256 7ac230d30907f013dff8d435a118619ea6168aa3714dba62c6962d350c6295ae SHA512 b8cb7eaf6274f4e2247dbcb39db05072d2b2d4361256a325fafab5533d7ce0c4ae9e2905b954dfcfa4789c9cab5cccf2ac1c3a1f02f6a327ed95b562d7773ed1 WHIRLPOOL 64c9b11ad938e6dbe5ba31298f1cd46f6e6bb4ba039c96b1e43bd85919d1606326f74b677f789ecabe0b0f4e0f08ac5aaf8148bf820de65aaa1e9966a28b9f61
|
||||
DIST ngx_rtmp-1.1.10.tar.gz 519877 SHA256 f9491dd24390b0d5d70dfe3553edf3d14efeb7c7a81b4d4a20c5cfeaefc1141c SHA512 bcc0aee3308af7c61bf01a5530fcf1dae938e6778306f6e3eb5995e6d0529f43d33b7ee2acb813d5a39acc92e4853d207a01e8e41b766a6e0dd07aade60cd98f WHIRLPOOL 655f4dcb02f928698ae14d29e5b7f60ad3fd71c757d67f1930c695a3501054d124a92f7ada7d4e605204f1e73e0779cad0b60102bc98d64764535581db0b1867
|
||||
DIST ngx_rtmp-1.1.11.tar.gz 519988 SHA256 71e8a0b42a41d1cb5ab1b9a8793f0e479e31fa9b59c4c6f5665df41cebf09e2b SHA512 e7c897265d1e93b06f7e46a653b113e24d2451e2112a7a6da415f130928437444a0346832fd9c10042397fea6120e4e44acc2bccf649ec30ca5bffbf985672e2 WHIRLPOOL a9799368dbfdc18d396b8b3abfe5582783c912fec1f3b0d8ce9444e1e0549c63eec9586a18adda1a323a86a4af09ae43051335545cd27e1b5dcb15bb25e1dac9
|
||||
DIST ngx_rtmp-1.2.0.tar.gz 519895 SHA256 a8026f5ade30b178a06f12c46dff053cfe12256016ad465a46646183086b16b0 SHA512 8965d9bee91a46375516ccd012d1c43cd23f15c0630d11ed01472b9a84504574b476f22c5584f43c972a8f923e9ae025b9b60c64aace0ed159c7279bcbd376c8 WHIRLPOOL ea18f30cac7310a9b9be92178266afab5403f9e2e52cf89142c3c8bd20c05b12390ae90bdb50ceabef7ba869ef95502fee2f046716daea95de10527acba826c8
|
||||
|
||||
@@ -1,40 +0,0 @@
|
||||
From 2fbc95b6ece36e01e6fea8c5691ef1611d948943 Mon Sep 17 00:00:00 2001
|
||||
From: Thomas Deutschmann <whissi@gentoo.org>
|
||||
Date: Tue, 15 Nov 2016 18:56:30 +0100
|
||||
Subject: [PATCH] Upstream: don't consider default_port when matching
|
||||
upstreams.
|
||||
|
||||
Upstream changed API [Link 1] and removed ngx_http_upstream_srv_conf_t.default_port.
|
||||
|
||||
Upstream's own changeset [Link 2] suggests that the check was not needed at
|
||||
all.
|
||||
|
||||
Link 1: http://hg.nginx.org/nginx/rev/4dea01cf49e8
|
||||
Link 2: http://hg.nginx.org/nginx/rev/3fa5983b6b44
|
||||
Bug: https://github.com/openresty/memc-nginx-module/issues/26
|
||||
---
|
||||
src/ngx_http_memc_util.c | 2 ++
|
||||
1 file changed, 2 insertions(+)
|
||||
|
||||
diff --git a/src/ngx_http_memc_util.c b/src/ngx_http_memc_util.c
|
||||
index 090bf43..20cb877 100644
|
||||
--- a/src/ngx_http_memc_util.c
|
||||
+++ b/src/ngx_http_memc_util.c
|
||||
@@ -141,12 +141,14 @@ ngx_http_memc_upstream_add(ngx_http_request_t *r, ngx_url_t *url)
|
||||
continue;
|
||||
}
|
||||
|
||||
+#if defined(nginx_version) && nginx_version < 1011006
|
||||
if (uscfp[i]->default_port && url->default_port
|
||||
&& uscfp[i]->default_port != url->default_port)
|
||||
{
|
||||
dd("upstream_add: default_port not match");
|
||||
continue;
|
||||
}
|
||||
+#endif
|
||||
|
||||
return uscfp[i];
|
||||
}
|
||||
--
|
||||
2.10.2
|
||||
|
||||
@@ -1,988 +0,0 @@
|
||||
# Copyright 1999-2017 Gentoo Foundation
|
||||
# Distributed under the terms of the GNU General Public License v2
|
||||
|
||||
EAPI=6
|
||||
|
||||
# Maintainer notes:
|
||||
# - http_rewrite-independent pcre-support makes sense for matching locations without an actual rewrite
|
||||
# - any http-module activates the main http-functionality and overrides USE=-http
|
||||
# - keep the following requirements in mind before adding external modules:
|
||||
# * alive upstream
|
||||
# * sane packaging
|
||||
# * builds cleanly
|
||||
# * does not need a patch for nginx core
|
||||
# - TODO: test the google-perftools module (included in vanilla tarball)
|
||||
|
||||
# prevent perl-module from adding automagic perl DEPENDs
|
||||
GENTOO_DEPEND_ON_PERL="no"
|
||||
|
||||
# devel_kit (https://github.com/simpl/ngx_devel_kit, BSD license)
|
||||
DEVEL_KIT_MODULE_PV="0.3.0"
|
||||
DEVEL_KIT_MODULE_P="ngx_devel_kit-${DEVEL_KIT_MODULE_PV}-r1"
|
||||
DEVEL_KIT_MODULE_URI="https://github.com/simpl/ngx_devel_kit/archive/v${DEVEL_KIT_MODULE_PV}.tar.gz"
|
||||
DEVEL_KIT_MODULE_WD="${WORKDIR}/ngx_devel_kit-${DEVEL_KIT_MODULE_PV}"
|
||||
|
||||
# http_uploadprogress (https://github.com/masterzen/nginx-upload-progress-module, BSD-2 license)
|
||||
HTTP_UPLOAD_PROGRESS_MODULE_PV="0.9.2"
|
||||
HTTP_UPLOAD_PROGRESS_MODULE_P="ngx_http_upload_progress-${HTTP_UPLOAD_PROGRESS_MODULE_PV}-r1"
|
||||
HTTP_UPLOAD_PROGRESS_MODULE_URI="https://github.com/masterzen/nginx-upload-progress-module/archive/v${HTTP_UPLOAD_PROGRESS_MODULE_PV}.tar.gz"
|
||||
HTTP_UPLOAD_PROGRESS_MODULE_WD="${WORKDIR}/nginx-upload-progress-module-${HTTP_UPLOAD_PROGRESS_MODULE_PV}"
|
||||
|
||||
# http_headers_more (https://github.com/agentzh/headers-more-nginx-module, BSD license)
|
||||
HTTP_HEADERS_MORE_MODULE_PV="0.32"
|
||||
HTTP_HEADERS_MORE_MODULE_P="ngx_http_headers_more-${HTTP_HEADERS_MORE_MODULE_PV}"
|
||||
HTTP_HEADERS_MORE_MODULE_URI="https://github.com/agentzh/headers-more-nginx-module/archive/v${HTTP_HEADERS_MORE_MODULE_PV}.tar.gz"
|
||||
HTTP_HEADERS_MORE_MODULE_WD="${WORKDIR}/headers-more-nginx-module-${HTTP_HEADERS_MORE_MODULE_PV}"
|
||||
|
||||
# http_cache_purge (http://labs.frickle.com/nginx_ngx_cache_purge/, https://github.com/FRiCKLE/ngx_cache_purge, BSD-2 license)
|
||||
HTTP_CACHE_PURGE_MODULE_PV="2.3"
|
||||
HTTP_CACHE_PURGE_MODULE_P="ngx_http_cache_purge-${HTTP_CACHE_PURGE_MODULE_PV}"
|
||||
HTTP_CACHE_PURGE_MODULE_URI="http://labs.frickle.com/files/ngx_cache_purge-${HTTP_CACHE_PURGE_MODULE_PV}.tar.gz"
|
||||
HTTP_CACHE_PURGE_MODULE_WD="${WORKDIR}/ngx_cache_purge-${HTTP_CACHE_PURGE_MODULE_PV}"
|
||||
|
||||
# http_slowfs_cache (http://labs.frickle.com/nginx_ngx_slowfs_cache/, BSD-2 license)
|
||||
HTTP_SLOWFS_CACHE_MODULE_PV="1.10"
|
||||
HTTP_SLOWFS_CACHE_MODULE_P="ngx_http_slowfs_cache-${HTTP_SLOWFS_CACHE_MODULE_PV}"
|
||||
HTTP_SLOWFS_CACHE_MODULE_URI="http://labs.frickle.com/files/ngx_slowfs_cache-${HTTP_SLOWFS_CACHE_MODULE_PV}.tar.gz"
|
||||
HTTP_SLOWFS_CACHE_MODULE_WD="${WORKDIR}/ngx_slowfs_cache-${HTTP_SLOWFS_CACHE_MODULE_PV}"
|
||||
|
||||
# http_fancyindex (https://github.com/aperezdc/ngx-fancyindex, BSD license)
|
||||
HTTP_FANCYINDEX_MODULE_PV="0.4.1"
|
||||
HTTP_FANCYINDEX_MODULE_P="ngx_http_fancyindex-${HTTP_FANCYINDEX_MODULE_PV}"
|
||||
HTTP_FANCYINDEX_MODULE_URI="https://github.com/aperezdc/ngx-fancyindex/archive/v${HTTP_FANCYINDEX_MODULE_PV}.tar.gz"
|
||||
HTTP_FANCYINDEX_MODULE_WD="${WORKDIR}/ngx-fancyindex-${HTTP_FANCYINDEX_MODULE_PV}"
|
||||
|
||||
# http_lua (https://github.com/openresty/lua-nginx-module, BSD license)
|
||||
HTTP_LUA_MODULE_PV="0.10.7"
|
||||
HTTP_LUA_MODULE_P="ngx_http_lua-${HTTP_LUA_MODULE_PV}"
|
||||
HTTP_LUA_MODULE_URI="https://github.com/openresty/lua-nginx-module/archive/v${HTTP_LUA_MODULE_PV}.tar.gz"
|
||||
HTTP_LUA_MODULE_WD="${WORKDIR}/lua-nginx-module-${HTTP_LUA_MODULE_PV}"
|
||||
|
||||
# http_auth_pam (https://github.com/stogh/ngx_http_auth_pam_module/, http://web.iti.upv.es/~sto/nginx/, BSD-2 license)
|
||||
HTTP_AUTH_PAM_MODULE_PV="1.5.1"
|
||||
HTTP_AUTH_PAM_MODULE_P="ngx_http_auth_pam-${HTTP_AUTH_PAM_MODULE_PV}"
|
||||
HTTP_AUTH_PAM_MODULE_URI="https://github.com/stogh/ngx_http_auth_pam_module/archive/v${HTTP_AUTH_PAM_MODULE_PV}.tar.gz"
|
||||
HTTP_AUTH_PAM_MODULE_WD="${WORKDIR}/ngx_http_auth_pam_module-${HTTP_AUTH_PAM_MODULE_PV}"
|
||||
|
||||
# http_upstream_check (https://github.com/yaoweibin/nginx_upstream_check_module, BSD license)
|
||||
HTTP_UPSTREAM_CHECK_MODULE_PV="0.3.0-10-gf3bdb7b"
|
||||
HTTP_UPSTREAM_CHECK_MODULE_P="ngx_http_upstream_check-${HTTP_UPSTREAM_CHECK_MODULE_PV}"
|
||||
HTTP_UPSTREAM_CHECK_MODULE_URI="https://github.com/yaoweibin/nginx_upstream_check_module/archive/v${HTTP_UPSTREAM_CHECK_MODULE_PV}.tar.gz"
|
||||
HTTP_UPSTREAM_CHECK_MODULE_WD="${WORKDIR}/nginx_upstream_check_module-f3bdb7b85a194e2ad58e3c306c1d021ee76da2f5"
|
||||
|
||||
# http_metrics (https://github.com/zenops/ngx_metrics, BSD license)
|
||||
HTTP_METRICS_MODULE_PV="0.1.1"
|
||||
HTTP_METRICS_MODULE_P="ngx_metrics-${HTTP_METRICS_MODULE_PV}"
|
||||
HTTP_METRICS_MODULE_URI="https://github.com/madvertise/ngx_metrics/archive/v${HTTP_METRICS_MODULE_PV}.tar.gz"
|
||||
HTTP_METRICS_MODULE_WD="${WORKDIR}/ngx_metrics-${HTTP_METRICS_MODULE_PV}"
|
||||
|
||||
# naxsi-core (https://github.com/nbs-system/naxsi, GPLv2+)
|
||||
HTTP_NAXSI_MODULE_PV="0.55.1"
|
||||
HTTP_NAXSI_MODULE_P="ngx_http_naxsi-${HTTP_NAXSI_MODULE_PV}"
|
||||
HTTP_NAXSI_MODULE_URI="https://github.com/nbs-system/naxsi/archive/${HTTP_NAXSI_MODULE_PV}.tar.gz"
|
||||
HTTP_NAXSI_MODULE_WD="${WORKDIR}/naxsi-${HTTP_NAXSI_MODULE_PV}/naxsi_src"
|
||||
|
||||
# nginx-rtmp-module (https://github.com/arut/nginx-rtmp-module, BSD license)
|
||||
RTMP_MODULE_PV="1.1.10"
|
||||
RTMP_MODULE_P="ngx_rtmp-${RTMP_MODULE_PV}"
|
||||
RTMP_MODULE_URI="https://github.com/arut/nginx-rtmp-module/archive/v${RTMP_MODULE_PV}.tar.gz"
|
||||
RTMP_MODULE_WD="${WORKDIR}/nginx-rtmp-module-${RTMP_MODULE_PV}"
|
||||
|
||||
# nginx-dav-ext-module (https://github.com/arut/nginx-dav-ext-module, BSD license)
|
||||
HTTP_DAV_EXT_MODULE_PV="0.0.3"
|
||||
HTTP_DAV_EXT_MODULE_P="ngx_http_dav_ext-${HTTP_DAV_EXT_MODULE_PV}"
|
||||
HTTP_DAV_EXT_MODULE_URI="https://github.com/arut/nginx-dav-ext-module/archive/v${HTTP_DAV_EXT_MODULE_PV}.tar.gz"
|
||||
HTTP_DAV_EXT_MODULE_WD="${WORKDIR}/nginx-dav-ext-module-${HTTP_DAV_EXT_MODULE_PV}"
|
||||
|
||||
# echo-nginx-module (https://github.com/openresty/echo-nginx-module, BSD license)
|
||||
HTTP_ECHO_MODULE_PV="0.60"
|
||||
HTTP_ECHO_MODULE_P="ngx_http_echo-${HTTP_ECHO_MODULE_PV}"
|
||||
HTTP_ECHO_MODULE_URI="https://github.com/openresty/echo-nginx-module/archive/v${HTTP_ECHO_MODULE_PV}.tar.gz"
|
||||
HTTP_ECHO_MODULE_WD="${WORKDIR}/echo-nginx-module-${HTTP_ECHO_MODULE_PV}"
|
||||
|
||||
# mod_security for nginx (https://modsecurity.org/, Apache-2.0)
|
||||
# keep the MODULE_P here consistent with upstream to avoid tarball duplication
|
||||
HTTP_SECURITY_MODULE_PV="2.9.1"
|
||||
HTTP_SECURITY_MODULE_P="modsecurity-${HTTP_SECURITY_MODULE_PV}"
|
||||
HTTP_SECURITY_MODULE_URI="https://www.modsecurity.org/tarball/${HTTP_SECURITY_MODULE_PV}/${HTTP_SECURITY_MODULE_P}.tar.gz"
|
||||
HTTP_SECURITY_MODULE_WD="${WORKDIR}/${HTTP_SECURITY_MODULE_P}"
|
||||
|
||||
# push-stream-module (http://www.nginxpushstream.com, https://github.com/wandenberg/nginx-push-stream-module, GPL-3)
|
||||
HTTP_PUSH_STREAM_MODULE_PV="0.5.2"
|
||||
HTTP_PUSH_STREAM_MODULE_P="ngx_http_push_stream-${HTTP_PUSH_STREAM_MODULE_PV}"
|
||||
HTTP_PUSH_STREAM_MODULE_URI="https://github.com/wandenberg/nginx-push-stream-module/archive/${HTTP_PUSH_STREAM_MODULE_PV}.tar.gz"
|
||||
HTTP_PUSH_STREAM_MODULE_WD="${WORKDIR}/nginx-push-stream-module-${HTTP_PUSH_STREAM_MODULE_PV}"
|
||||
|
||||
# sticky-module (https://bitbucket.org/nginx-goodies/nginx-sticky-module-ng, BSD-2)
|
||||
HTTP_STICKY_MODULE_PV="1.2.6-10-g08a395c66e42"
|
||||
HTTP_STICKY_MODULE_P="nginx_http_sticky_module_ng-${HTTP_STICKY_MODULE_PV}"
|
||||
HTTP_STICKY_MODULE_URI="https://bitbucket.org/nginx-goodies/nginx-sticky-module-ng/get/${HTTP_STICKY_MODULE_PV}.tar.bz2"
|
||||
HTTP_STICKY_MODULE_WD="${WORKDIR}/nginx-goodies-nginx-sticky-module-ng-08a395c66e42"
|
||||
|
||||
# mogilefs-module (https://github.com/vkholodkov/nginx-mogilefs-module, BSD-2)
|
||||
HTTP_MOGILEFS_MODULE_PV="1.0.4"
|
||||
HTTP_MOGILEFS_MODULE_P="ngx_mogilefs_module-${HTTP_MOGILEFS_MODULE_PV}"
|
||||
HTTP_MOGILEFS_MODULE_URI="https://github.com/vkholodkov/nginx-mogilefs-module/archive/${HTTP_MOGILEFS_MODULE_PV}.tar.gz"
|
||||
HTTP_MOGILEFS_MODULE_WD="${WORKDIR}/nginx_mogilefs_module-${HTTP_MOGILEFS_MODULE_PV}"
|
||||
|
||||
# memc-module (https://github.com/openresty/memc-nginx-module, BSD-2)
|
||||
HTTP_MEMC_MODULE_PV="0.17"
|
||||
HTTP_MEMC_MODULE_P="ngx_memc_module-${HTTP_MEMC_MODULE_PV}"
|
||||
HTTP_MEMC_MODULE_URI="https://github.com/openresty/memc-nginx-module/archive/v${HTTP_MEMC_MODULE_PV}.tar.gz"
|
||||
HTTP_MEMC_MODULE_WD="${WORKDIR}/memc-nginx-module-${HTTP_MEMC_MODULE_PV}"
|
||||
|
||||
# nginx-ldap-auth-module (https://github.com/kvspb/nginx-auth-ldap, BSD-2)
|
||||
HTTP_LDAP_MODULE_PV="49a8b4d28fc4a518563c82e0b52821e5f37db1fc"
|
||||
HTTP_LDAP_MODULE_P="nginx-auth-ldap-${HTTP_LDAP_MODULE_PV}"
|
||||
HTTP_LDAP_MODULE_URI="https://github.com/kvspb/nginx-auth-ldap/archive/${HTTP_LDAP_MODULE_PV}.tar.gz"
|
||||
HTTP_LDAP_MODULE_WD="${WORKDIR}/nginx-auth-ldap-${HTTP_LDAP_MODULE_PV}"
|
||||
|
||||
# We handle deps below ourselves
|
||||
SSL_DEPS_SKIP=1
|
||||
AUTOTOOLS_AUTO_DEPEND="no"
|
||||
|
||||
inherit autotools ssl-cert toolchain-funcs perl-module flag-o-matic user systemd versionator multilib
|
||||
|
||||
DESCRIPTION="Robust, small and high performance http and reverse proxy server"
|
||||
HOMEPAGE="https://nginx.org"
|
||||
SRC_URI="https://nginx.org/download/${P}.tar.gz
|
||||
${DEVEL_KIT_MODULE_URI} -> ${DEVEL_KIT_MODULE_P}.tar.gz
|
||||
nginx_modules_http_upload_progress? ( ${HTTP_UPLOAD_PROGRESS_MODULE_URI} -> ${HTTP_UPLOAD_PROGRESS_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_headers_more? ( ${HTTP_HEADERS_MORE_MODULE_URI} -> ${HTTP_HEADERS_MORE_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_cache_purge? ( ${HTTP_CACHE_PURGE_MODULE_URI} -> ${HTTP_CACHE_PURGE_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_slowfs_cache? ( ${HTTP_SLOWFS_CACHE_MODULE_URI} -> ${HTTP_SLOWFS_CACHE_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_fancyindex? ( ${HTTP_FANCYINDEX_MODULE_URI} -> ${HTTP_FANCYINDEX_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_lua? ( ${HTTP_LUA_MODULE_URI} -> ${HTTP_LUA_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_auth_pam? ( ${HTTP_AUTH_PAM_MODULE_URI} -> ${HTTP_AUTH_PAM_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_upstream_check? ( ${HTTP_UPSTREAM_CHECK_MODULE_URI} -> ${HTTP_UPSTREAM_CHECK_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_metrics? ( ${HTTP_METRICS_MODULE_URI} -> ${HTTP_METRICS_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_naxsi? ( ${HTTP_NAXSI_MODULE_URI} -> ${HTTP_NAXSI_MODULE_P}.tar.gz )
|
||||
rtmp? ( ${RTMP_MODULE_URI} -> ${RTMP_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_dav_ext? ( ${HTTP_DAV_EXT_MODULE_URI} -> ${HTTP_DAV_EXT_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_echo? ( ${HTTP_ECHO_MODULE_URI} -> ${HTTP_ECHO_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_security? ( ${HTTP_SECURITY_MODULE_URI} -> ${HTTP_SECURITY_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_push_stream? ( ${HTTP_PUSH_STREAM_MODULE_URI} -> ${HTTP_PUSH_STREAM_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_sticky? ( ${HTTP_STICKY_MODULE_URI} -> ${HTTP_STICKY_MODULE_P}.tar.bz2 )
|
||||
nginx_modules_http_mogilefs? ( ${HTTP_MOGILEFS_MODULE_URI} -> ${HTTP_MOGILEFS_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_memc? ( ${HTTP_MEMC_MODULE_URI} -> ${HTTP_MEMC_MODULE_P}.tar.gz )
|
||||
nginx_modules_http_auth_ldap? ( ${HTTP_LDAP_MODULE_URI} -> ${HTTP_LDAP_MODULE_P}.tar.gz )"
|
||||
|
||||
LICENSE="BSD-2 BSD SSLeay MIT GPL-2 GPL-2+
|
||||
nginx_modules_http_security? ( Apache-2.0 )
|
||||
nginx_modules_http_push_stream? ( GPL-3 )"
|
||||
|
||||
SLOT="0"
|
||||
KEYWORDS="amd64 ~arm ~arm64 ~ppc x86 ~x86-fbsd ~amd64-linux ~x86-linux"
|
||||
|
||||
# Package doesn't provide a real test suite
|
||||
RESTRICT="test"
|
||||
|
||||
NGINX_MODULES_STD="access auth_basic autoindex browser charset empty_gif
|
||||
fastcgi geo gzip limit_req limit_conn map memcached proxy referer
|
||||
rewrite scgi ssi split_clients upstream_ip_hash userid uwsgi"
|
||||
NGINX_MODULES_OPT="addition auth_request dav degradation flv geoip gunzip
|
||||
gzip_static image_filter mp4 perl random_index realip secure_link
|
||||
slice stub_status sub xslt"
|
||||
NGINX_MODULES_STREAM="access limit_conn upstream"
|
||||
NGINX_MODULES_MAIL="imap pop3 smtp"
|
||||
NGINX_MODULES_3RD="
|
||||
http_upload_progress
|
||||
http_headers_more
|
||||
http_cache_purge
|
||||
http_slowfs_cache
|
||||
http_fancyindex
|
||||
http_lua
|
||||
http_auth_pam
|
||||
http_upstream_check
|
||||
http_metrics
|
||||
http_naxsi
|
||||
http_dav_ext
|
||||
http_echo
|
||||
http_security
|
||||
http_push_stream
|
||||
http_sticky
|
||||
http_mogilefs
|
||||
http_memc
|
||||
http_auth_ldap"
|
||||
|
||||
IUSE="aio debug +http +http2 +http-cache ipv6 libatomic libressl luajit +pcre
|
||||
pcre-jit rtmp selinux ssl threads userland_GNU vim-syntax"
|
||||
|
||||
for mod in $NGINX_MODULES_STD; do
|
||||
IUSE="${IUSE} +nginx_modules_http_${mod}"
|
||||
done
|
||||
|
||||
for mod in $NGINX_MODULES_OPT; do
|
||||
IUSE="${IUSE} nginx_modules_http_${mod}"
|
||||
done
|
||||
|
||||
for mod in $NGINX_MODULES_STREAM; do
|
||||
IUSE="${IUSE} nginx_modules_stream_${mod}"
|
||||
done
|
||||
|
||||
for mod in $NGINX_MODULES_MAIL; do
|
||||
IUSE="${IUSE} nginx_modules_mail_${mod}"
|
||||
done
|
||||
|
||||
for mod in $NGINX_MODULES_3RD; do
|
||||
IUSE="${IUSE} nginx_modules_${mod}"
|
||||
done
|
||||
|
||||
# Add so we can warn users updating about config changes
|
||||
# @TODO: jbergstroem: remove on next release series
|
||||
IUSE="${IUSE} nginx_modules_http_spdy"
|
||||
|
||||
CDEPEND="
|
||||
pcre? ( dev-libs/libpcre:= )
|
||||
pcre-jit? ( dev-libs/libpcre:=[jit] )
|
||||
ssl? (
|
||||
!libressl? ( dev-libs/openssl:0= )
|
||||
libressl? ( dev-libs/libressl:= )
|
||||
)
|
||||
http2? (
|
||||
!libressl? ( >=dev-libs/openssl-1.0.1c:0= )
|
||||
libressl? ( dev-libs/libressl:= )
|
||||
)
|
||||
http-cache? (
|
||||
userland_GNU? (
|
||||
!libressl? ( dev-libs/openssl:0= )
|
||||
libressl? ( dev-libs/libressl:= )
|
||||
)
|
||||
)
|
||||
nginx_modules_http_geoip? ( dev-libs/geoip )
|
||||
nginx_modules_http_gunzip? ( sys-libs/zlib )
|
||||
nginx_modules_http_gzip? ( sys-libs/zlib )
|
||||
nginx_modules_http_gzip_static? ( sys-libs/zlib )
|
||||
nginx_modules_http_image_filter? ( media-libs/gd:=[jpeg,png] )
|
||||
nginx_modules_http_perl? ( >=dev-lang/perl-5.8:= )
|
||||
nginx_modules_http_rewrite? ( dev-libs/libpcre:= )
|
||||
nginx_modules_http_secure_link? (
|
||||
userland_GNU? (
|
||||
!libressl? ( dev-libs/openssl:0= )
|
||||
libressl? ( dev-libs/libressl:= )
|
||||
)
|
||||
)
|
||||
nginx_modules_http_xslt? ( dev-libs/libxml2:= dev-libs/libxslt )
|
||||
nginx_modules_http_lua? ( !luajit? ( dev-lang/lua:0= ) luajit? ( dev-lang/luajit:2= ) )
|
||||
nginx_modules_http_auth_pam? ( virtual/pam )
|
||||
nginx_modules_http_metrics? ( dev-libs/yajl:= )
|
||||
nginx_modules_http_dav_ext? ( dev-libs/expat )
|
||||
nginx_modules_http_security? (
|
||||
dev-libs/apr:=
|
||||
dev-libs/apr-util:=
|
||||
dev-libs/libxml2:=
|
||||
net-misc/curl
|
||||
www-servers/apache
|
||||
)
|
||||
nginx_modules_http_auth_ldap? ( net-nds/openldap[ssl?] )"
|
||||
RDEPEND="${CDEPEND}
|
||||
selinux? ( sec-policy/selinux-nginx )
|
||||
!www-servers/nginx:mainline"
|
||||
DEPEND="${CDEPEND}
|
||||
nginx_modules_http_security? ( ${AUTOTOOLS_DEPEND} )
|
||||
arm? ( dev-libs/libatomic_ops )
|
||||
libatomic? ( dev-libs/libatomic_ops )"
|
||||
PDEPEND="vim-syntax? ( app-vim/nginx-syntax )"
|
||||
|
||||
REQUIRED_USE="pcre-jit? ( pcre )
|
||||
nginx_modules_http_lua? ( nginx_modules_http_rewrite )
|
||||
nginx_modules_http_naxsi? ( pcre )
|
||||
nginx_modules_http_dav_ext? ( nginx_modules_http_dav )
|
||||
nginx_modules_http_metrics? ( nginx_modules_http_stub_status )
|
||||
nginx_modules_http_security? ( pcre )
|
||||
nginx_modules_http_push_stream? ( ssl )"
|
||||
|
||||
pkg_setup() {
|
||||
NGINX_HOME="/var/lib/nginx"
|
||||
NGINX_HOME_TMP="${NGINX_HOME}/tmp"
|
||||
|
||||
ebegin "Creating nginx user and group"
|
||||
enewgroup ${PN}
|
||||
enewuser ${PN} -1 -1 "${NGINX_HOME}" ${PN}
|
||||
eend $?
|
||||
|
||||
if use libatomic; then
|
||||
ewarn "GCC 4.1+ features built-in atomic operations."
|
||||
ewarn "Using libatomic_ops is only needed if using"
|
||||
ewarn "a different compiler or a GCC prior to 4.1"
|
||||
fi
|
||||
|
||||
if [[ -n $NGINX_ADD_MODULES ]]; then
|
||||
ewarn "You are building custom modules via \$NGINX_ADD_MODULES!"
|
||||
ewarn "This nginx installation is not supported!"
|
||||
ewarn "Make sure you can reproduce the bug without those modules"
|
||||
ewarn "_before_ reporting bugs."
|
||||
fi
|
||||
|
||||
if use !http; then
|
||||
ewarn "To actually disable all http-functionality you also have to disable"
|
||||
ewarn "all nginx http modules."
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_mogilefs && use threads; then
|
||||
eerror "mogilefs won't compile with threads support."
|
||||
eerror "Please disable either flag and try again."
|
||||
die "Can't compile mogilefs with threads support"
|
||||
fi
|
||||
}
|
||||
|
||||
src_prepare() {
|
||||
eapply "${FILESDIR}/${PN}-1.4.1-fix-perl-install-path.patch"
|
||||
eapply "${FILESDIR}/${PN}-httpoxy-mitigation-r1.patch"
|
||||
|
||||
if use nginx_modules_http_upstream_check; then
|
||||
eapply -p0 "${HTTP_UPSTREAM_CHECK_MODULE_WD}/check_1.9.2+".patch
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_lua; then
|
||||
sed -i -e 's/-llua5.1/-llua/' "${HTTP_LUA_MODULE_WD}/config" || die
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_security; then
|
||||
cd "${HTTP_SECURITY_MODULE_WD}" || die
|
||||
|
||||
eapply "${FILESDIR}"/http_security-pr_1158.patch
|
||||
|
||||
eautoreconf
|
||||
|
||||
if use luajit ; then
|
||||
sed -i \
|
||||
-e 's|^\(LUA_PKGNAMES\)=.*|\1="luajit"|' \
|
||||
configure || die
|
||||
fi
|
||||
|
||||
cd "${S}" || die
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_upload_progress; then
|
||||
cd "${HTTP_UPLOAD_PROGRESS_MODULE_WD}" || die
|
||||
eapply "${FILESDIR}"/http_uploadprogress-issue_50-r1.patch
|
||||
cd "${S}" || die
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_memc; then
|
||||
cd "${HTTP_MEMC_MODULE_WD}" || die
|
||||
eapply "${FILESDIR}"/http_memc-0.17-issue_26.patch
|
||||
cd "${S}" || die
|
||||
fi
|
||||
|
||||
find auto/ -type f -print0 | xargs -0 sed -i 's:\&\& make:\&\& \\$(MAKE):' || die
|
||||
# We have config protection, don't rename etc files
|
||||
sed -i 's:.default::' auto/install || die
|
||||
# remove useless files
|
||||
sed -i -e '/koi-/d' -e '/win-/d' auto/install || die
|
||||
|
||||
# don't install to /etc/nginx/ if not in use
|
||||
local module
|
||||
for module in fastcgi scgi uwsgi ; do
|
||||
if ! use nginx_modules_http_${module}; then
|
||||
sed -i -e "/${module}/d" auto/install || die
|
||||
fi
|
||||
done
|
||||
|
||||
eapply_user
|
||||
}
|
||||
|
||||
src_configure() {
|
||||
# mod_security needs to generate nginx/modsecurity/config before including it
|
||||
if use nginx_modules_http_security; then
|
||||
cd "${HTTP_SECURITY_MODULE_WD}" || die
|
||||
|
||||
./configure \
|
||||
--enable-standalone-module \
|
||||
--disable-mlogc \
|
||||
--with-ssdeep=no \
|
||||
$(use_enable pcre-jit) \
|
||||
$(use_with nginx_modules_http_lua lua) || die "configure failed for mod_security"
|
||||
|
||||
cd "${S}" || die
|
||||
fi
|
||||
|
||||
local myconf=() http_enabled= mail_enabled= stream_enabled=
|
||||
|
||||
use aio && myconf+=( --with-file-aio )
|
||||
use debug && myconf+=( --with-debug )
|
||||
use http2 && myconf+=( --with-http_v2_module )
|
||||
use ipv6 && myconf+=( --with-ipv6 )
|
||||
use libatomic && myconf+=( --with-libatomic )
|
||||
use pcre && myconf+=( --with-pcre )
|
||||
use pcre-jit && myconf+=( --with-pcre-jit )
|
||||
use threads && myconf+=( --with-threads )
|
||||
|
||||
# HTTP modules
|
||||
for mod in $NGINX_MODULES_STD; do
|
||||
if use nginx_modules_http_${mod}; then
|
||||
http_enabled=1
|
||||
else
|
||||
myconf+=( --without-http_${mod}_module )
|
||||
fi
|
||||
done
|
||||
|
||||
for mod in $NGINX_MODULES_OPT; do
|
||||
if use nginx_modules_http_${mod}; then
|
||||
http_enabled=1
|
||||
myconf+=( --with-http_${mod}_module )
|
||||
fi
|
||||
done
|
||||
|
||||
if use nginx_modules_http_fastcgi; then
|
||||
myconf+=( --with-http_realip_module )
|
||||
fi
|
||||
|
||||
# third-party modules
|
||||
if use nginx_modules_http_upload_progress; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_UPLOAD_PROGRESS_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_headers_more; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_HEADERS_MORE_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_cache_purge; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_CACHE_PURGE_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_slowfs_cache; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_SLOWFS_CACHE_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_fancyindex; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_FANCYINDEX_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_lua; then
|
||||
http_enabled=1
|
||||
if use luajit; then
|
||||
export LUAJIT_LIB=$(pkg-config --variable libdir luajit)
|
||||
export LUAJIT_INC=$(pkg-config --variable includedir luajit)
|
||||
else
|
||||
export LUA_LIB=$(pkg-config --variable libdir lua)
|
||||
export LUA_INC=$(pkg-config --variable includedir lua)
|
||||
fi
|
||||
myconf+=( --add-module=${DEVEL_KIT_MODULE_WD} )
|
||||
myconf+=( --add-module=${HTTP_LUA_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_auth_pam; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_AUTH_PAM_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_upstream_check; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_UPSTREAM_CHECK_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_metrics; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_METRICS_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_naxsi ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_NAXSI_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use rtmp ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${RTMP_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_dav_ext ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_DAV_EXT_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_echo ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_ECHO_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_security ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_SECURITY_MODULE_WD}/nginx/modsecurity )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_push_stream ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_PUSH_STREAM_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_sticky ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_STICKY_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_mogilefs ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_MOGILEFS_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_memc ; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_MEMC_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_auth_ldap; then
|
||||
http_enabled=1
|
||||
myconf+=( --add-module=${HTTP_LDAP_MODULE_WD} )
|
||||
fi
|
||||
|
||||
if use http || use http-cache || use http2; then
|
||||
http_enabled=1
|
||||
fi
|
||||
|
||||
if [ $http_enabled ]; then
|
||||
use http-cache || myconf+=( --without-http-cache )
|
||||
use ssl && myconf+=( --with-http_ssl_module )
|
||||
else
|
||||
myconf+=( --without-http --without-http-cache )
|
||||
fi
|
||||
|
||||
# Stream modules
|
||||
for mod in $NGINX_MODULES_STREAM; do
|
||||
if use nginx_modules_stream_${mod}; then
|
||||
stream_enabled=1
|
||||
else
|
||||
# Treat stream upstream slightly differently
|
||||
if ! use nginx_modules_stream_upstream; then
|
||||
myconf+=( --without-stream_upstream_hash_module )
|
||||
myconf+=( --without-stream_upstream_least_conn_module )
|
||||
myconf+=( --without-stream_upstream_zone_module )
|
||||
else
|
||||
myconf+=( --without-stream_${mod}_module )
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
if [ $stream_enabled ]; then
|
||||
myconf+=( --with-stream )
|
||||
use ssl && myconf+=( --with-stream_ssl_module )
|
||||
fi
|
||||
|
||||
# MAIL modules
|
||||
for mod in $NGINX_MODULES_MAIL; do
|
||||
if use nginx_modules_mail_${mod}; then
|
||||
mail_enabled=1
|
||||
else
|
||||
myconf+=( --without-mail_${mod}_module )
|
||||
fi
|
||||
done
|
||||
|
||||
if [ $mail_enabled ]; then
|
||||
myconf+=( --with-mail )
|
||||
use ssl && myconf+=( --with-mail_ssl_module )
|
||||
fi
|
||||
|
||||
# custom modules
|
||||
for mod in $NGINX_ADD_MODULES; do
|
||||
myconf+=( --add-module=${mod} )
|
||||
done
|
||||
|
||||
# https://bugs.gentoo.org/286772
|
||||
export LANG=C LC_ALL=C
|
||||
tc-export CC
|
||||
|
||||
if ! use prefix; then
|
||||
myconf+=( --user=${PN} )
|
||||
myconf+=( --group=${PN} )
|
||||
fi
|
||||
|
||||
./configure \
|
||||
--prefix="${EPREFIX}"/usr \
|
||||
--conf-path="${EPREFIX}"/etc/${PN}/${PN}.conf \
|
||||
--error-log-path="${EPREFIX}"/var/log/${PN}/error_log \
|
||||
--pid-path="${EPREFIX}"/run/${PN}.pid \
|
||||
--lock-path="${EPREFIX}"/run/lock/${PN}.lock \
|
||||
--with-cc-opt="-I${EROOT}usr/include" \
|
||||
--with-ld-opt="-L${EROOT}usr/$(get_libdir)" \
|
||||
--http-log-path="${EPREFIX}"/var/log/${PN}/access_log \
|
||||
--http-client-body-temp-path="${EPREFIX}${NGINX_HOME_TMP}"/client \
|
||||
--http-proxy-temp-path="${EPREFIX}${NGINX_HOME_TMP}"/proxy \
|
||||
--http-fastcgi-temp-path="${EPREFIX}${NGINX_HOME_TMP}"/fastcgi \
|
||||
--http-scgi-temp-path="${EPREFIX}${NGINX_HOME_TMP}"/scgi \
|
||||
--http-uwsgi-temp-path="${EPREFIX}${NGINX_HOME_TMP}"/uwsgi \
|
||||
"${myconf[@]}" || die "configure failed"
|
||||
|
||||
# A purely cosmetic change that makes nginx -V more readable. This can be
|
||||
# good if people outside the gentoo community would troubleshoot and
|
||||
# question the users setup.
|
||||
sed -i -e "s|${WORKDIR}|external_module|g" objs/ngx_auto_config.h || die
|
||||
}
|
||||
|
||||
src_compile() {
|
||||
use nginx_modules_http_security && emake -C "${HTTP_SECURITY_MODULE_WD}"
|
||||
|
||||
# https://bugs.gentoo.org/286772
|
||||
export LANG=C LC_ALL=C
|
||||
emake LINK="${CC} ${LDFLAGS}" OTHERLDFLAGS="${LDFLAGS}"
|
||||
}
|
||||
|
||||
src_install() {
|
||||
emake DESTDIR="${D%/}" install
|
||||
|
||||
cp "${FILESDIR}"/nginx.conf-r2 "${ED}"etc/nginx/nginx.conf || die
|
||||
|
||||
newinitd "${FILESDIR}"/nginx.initd-r4 nginx
|
||||
newconfd "${FILESDIR}"/nginx.confd nginx
|
||||
|
||||
systemd_newunit "${FILESDIR}"/nginx.service-r1 nginx.service
|
||||
|
||||
doman man/nginx.8
|
||||
dodoc CHANGES* README
|
||||
|
||||
# just keepdir. do not copy the default htdocs files (bug #449136)
|
||||
keepdir /var/www/localhost
|
||||
rm -rf "${D}"usr/html || die
|
||||
|
||||
# set up a list of directories to keep
|
||||
local keepdir_list="${NGINX_HOME_TMP}"/client
|
||||
local module
|
||||
for module in proxy fastcgi scgi uwsgi; do
|
||||
use nginx_modules_http_${module} && keepdir_list+=" ${NGINX_HOME_TMP}/${module}"
|
||||
done
|
||||
|
||||
keepdir /var/log/nginx ${keepdir_list}
|
||||
|
||||
# this solves a problem with SELinux where nginx doesn't see the directories
|
||||
# as root and tries to create them as nginx
|
||||
fperms 0750 "${NGINX_HOME_TMP}"
|
||||
fowners ${PN}:0 "${NGINX_HOME_TMP}"
|
||||
|
||||
fperms 0700 ${keepdir_list}
|
||||
fowners ${PN}:${PN} ${keepdir_list}
|
||||
|
||||
fperms 0710 /var/log/nginx
|
||||
fowners 0:${PN} /var/log/nginx
|
||||
|
||||
# logrotate
|
||||
insinto /etc/logrotate.d
|
||||
newins "${FILESDIR}"/nginx.logrotate-r1 nginx
|
||||
|
||||
if use nginx_modules_http_perl; then
|
||||
cd "${S}"/objs/src/http/modules/perl/ || die
|
||||
emake DESTDIR="${D}" INSTALLDIRS=vendor
|
||||
perl_delete_localpod
|
||||
cd "${S}" || die
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_cache_purge; then
|
||||
docinto ${HTTP_CACHE_PURGE_MODULE_P}
|
||||
dodoc "${HTTP_CACHE_PURGE_MODULE_WD}"/{CHANGES,README.md,TODO.md}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_slowfs_cache; then
|
||||
docinto ${HTTP_SLOWFS_CACHE_MODULE_P}
|
||||
dodoc "${HTTP_SLOWFS_CACHE_MODULE_WD}"/{CHANGES,README.md}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_fancyindex; then
|
||||
docinto ${HTTP_FANCYINDEX_MODULE_P}
|
||||
dodoc "${HTTP_FANCYINDEX_MODULE_WD}"/README.rst
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_lua; then
|
||||
docinto ${HTTP_LUA_MODULE_P}
|
||||
dodoc "${HTTP_LUA_MODULE_WD}"/README.markdown
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_auth_pam; then
|
||||
docinto ${HTTP_AUTH_PAM_MODULE_P}
|
||||
dodoc "${HTTP_AUTH_PAM_MODULE_WD}"/{README.md,ChangeLog}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_upstream_check; then
|
||||
docinto ${HTTP_UPSTREAM_CHECK_MODULE_P}
|
||||
dodoc "${HTTP_UPSTREAM_CHECK_MODULE_WD}"/{README,CHANGES}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_naxsi; then
|
||||
insinto /etc/nginx
|
||||
doins "${HTTP_NAXSI_MODULE_WD}"/../naxsi_config/naxsi_core.rules
|
||||
fi
|
||||
|
||||
if use rtmp; then
|
||||
docinto ${RTMP_MODULE_P}
|
||||
dodoc "${RTMP_MODULE_WD}"/{AUTHORS,README.md,stat.xsl}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_dav_ext; then
|
||||
docinto ${HTTP_DAV_EXT_MODULE_P}
|
||||
dodoc "${HTTP_DAV_EXT_MODULE_WD}"/README
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_echo; then
|
||||
docinto ${HTTP_ECHO_MODULE_P}
|
||||
dodoc "${HTTP_ECHO_MODULE_WD}"/README.markdown
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_security; then
|
||||
docinto ${HTTP_SECURITY_MODULE_P}
|
||||
dodoc "${HTTP_SECURITY_MODULE_WD}"/{CHANGES,README.TXT,authors.txt}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_push_stream; then
|
||||
docinto ${HTTP_PUSH_STREAM_MODULE_P}
|
||||
dodoc "${HTTP_PUSH_STREAM_MODULE_WD}"/{AUTHORS,CHANGELOG.textile,README.textile}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_sticky; then
|
||||
docinto ${HTTP_STICKY_MODULE_P}
|
||||
dodoc "${HTTP_STICKY_MODULE_WD}"/{README.md,Changelog.txt,docs/sticky.pdf}
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_memc; then
|
||||
docinto ${HTTP_MEMC_MODULE_P}
|
||||
dodoc "${HTTP_MEMC_MODULE_WD}"/README.markdown
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_auth_ldap; then
|
||||
docinto ${HTTP_LDAP_MODULE_P}
|
||||
dodoc "${HTTP_LDAP_MODULE_WD}"/example.conf
|
||||
fi
|
||||
}
|
||||
|
||||
pkg_postinst() {
|
||||
if use ssl; then
|
||||
if [[ ! -f "${EROOT}"etc/ssl/${PN}/${PN}.key ]]; then
|
||||
install_cert /etc/ssl/${PN}/${PN}
|
||||
use prefix || chown ${PN}:${PN} "${EROOT}"etc/ssl/${PN}/${PN}.{crt,csr,key,pem}
|
||||
fi
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_spdy; then
|
||||
ewarn "In nginx 1.9.5 the spdy module was superseded by http2."
|
||||
ewarn "Update your configs and package.use accordingly."
|
||||
fi
|
||||
|
||||
if use nginx_modules_http_lua && use http2; then
|
||||
ewarn "Lua 3rd party module author warns against using ${P} with"
|
||||
ewarn "NGINX_MODULES_HTTP=\"lua http2\". For more info, see http://git.io/OldLsg"
|
||||
fi
|
||||
|
||||
local _n_permission_layout_checks=0
|
||||
local _has_to_adjust_permissions=0
|
||||
local _has_to_show_permission_warning=0
|
||||
|
||||
# Defaults to 1 to inform people doing a fresh installation
|
||||
# that we ship modified {scgi,uwsgi,fastcgi}_params files
|
||||
local _has_to_show_httpoxy_mitigation_notice=1
|
||||
|
||||
local _replacing_version=
|
||||
for _replacing_version in ${REPLACING_VERSIONS}; do
|
||||
_n_permission_layout_checks=$((${_n_permission_layout_checks}+1))
|
||||
|
||||
if [[ ${_n_permission_layout_checks} -gt 1 ]]; then
|
||||
# Should never happen:
|
||||
# Package is abusing slots but doesn't allow multiple parallel installations.
|
||||
# If we run into this situation it is unsafe to automatically adjust any
|
||||
# permission...
|
||||
_has_to_show_permission_warning=1
|
||||
|
||||
ewarn "Replacing multiple ${PN}' versions is unsupported! " \
|
||||
"You will have to adjust permissions on your own."
|
||||
|
||||
break
|
||||
fi
|
||||
|
||||
local _replacing_version_branch=$(get_version_component_range 1-2 "${_replacing_version}")
|
||||
debug-print "Updating an existing installation (v${_replacing_version}; branch '${_replacing_version_branch}') ..."
|
||||
|
||||
# Do we need to adjust permissions to fix CVE-2013-0337 (bug #458726, #469094)?
|
||||
# This was before we introduced multiple nginx versions so we
|
||||
# do not need to distinguish between stable and mainline
|
||||
local _need_to_fix_CVE2013_0337=1
|
||||
|
||||
if version_is_at_least "1.4.1-r2" "${_replacing_version}"; then
|
||||
# We are updating an installation which should already be fixed
|
||||
_need_to_fix_CVE2013_0337=0
|
||||
debug-print "Skipping CVE-2013-0337 ... existing installation should not be affected!"
|
||||
else
|
||||
_has_to_adjust_permissions=1
|
||||
debug-print "Need to adjust permissions to fix CVE-2013-0337!"
|
||||
fi
|
||||
|
||||
# Do we need to inform about HTTPoxy mitigation?
|
||||
# In repository since commit 8be44f76d4ac02cebcd1e0e6e6284bb72d054b0f
|
||||
if ! version_is_at_least "1.10" "${_replacing_version_branch}"; then
|
||||
# Updating from <1.10
|
||||
_has_to_show_httpoxy_mitigation_notice=1
|
||||
debug-print "Need to inform about HTTPoxy mitigation!"
|
||||
else
|
||||
# Updating from >=1.10
|
||||
local _fixed_in_pvr=
|
||||
case "${_replacing_version_branch}" in
|
||||
"1.10")
|
||||
_fixed_in_pvr="1.10.1-r2"
|
||||
;;
|
||||
"1.11")
|
||||
_fixed_in_pvr="1.11.3-r1"
|
||||
;;
|
||||
*)
|
||||
# This should be any future branch.
|
||||
# If we run this code it is safe to assume that the user has
|
||||
# already seen the HTTPoxy mitigation notice because he/she is doing
|
||||
# an update from previous version where we have already shown
|
||||
# the warning. Otherwise, we wouldn't hit this code path ...
|
||||
_fixed_in_pvr=
|
||||
esac
|
||||
|
||||
if [[ -z "${_fixed_in_pvr}" ]] || version_is_at_least "${_fixed_in_pvr}" "${_replacing_version}"; then
|
||||
# We are updating an installation where we already informed
|
||||
# that we are mitigating HTTPoxy per default
|
||||
_has_to_show_httpoxy_mitigation_notice=0
|
||||
debug-print "No need to inform about HTTPoxy mitigation ... information was already shown for existing installation!"
|
||||
else
|
||||
_has_to_show_httpoxy_mitigation_notice=1
|
||||
debug-print "Need to inform about HTTPoxy mitigation!"
|
||||
fi
|
||||
fi
|
||||
|
||||
# Do we need to adjust permissions to fix CVE-2016-1247 (bug #605008)?
|
||||
# All branches up to 1.11 are affected
|
||||
local _need_to_fix_CVE2016_1247=1
|
||||
|
||||
if ! version_is_at_least "1.10" "${_replacing_version_branch}"; then
|
||||
# Updating from <1.10
|
||||
_has_to_adjust_permissions=1
|
||||
debug-print "Need to adjust permissions to fix CVE-2016-1247!"
|
||||
else
|
||||
# Updating from >=1.10
|
||||
local _fixed_in_pvr=
|
||||
case "${_replacing_version_branch}" in
|
||||
"1.10")
|
||||
_fixed_in_pvr="1.10.2-r3"
|
||||
;;
|
||||
"1.11")
|
||||
_fixed_in_pvr="1.11.6-r1"
|
||||
;;
|
||||
*)
|
||||
# This should be any future branch.
|
||||
# If we run this code it is safe to assume that we have already
|
||||
# adjusted permissions or were never affected because user is
|
||||
# doing an update from previous version which was safe or did
|
||||
# the adjustments. Otherwise, we wouldn't hit this code path ...
|
||||
_fixed_in_pvr=
|
||||
esac
|
||||
|
||||
if [[ -z "${_fixed_in_pvr}" ]] || version_is_at_least "${_fixed_in_pvr}" "${_replacing_version}"; then
|
||||
# We are updating an installation which should already be adjusted
|
||||
# or which was never affected
|
||||
_need_to_fix_CVE2016_1247=0
|
||||
debug-print "Skipping CVE-2016-1247 ... existing installation should not be affected!"
|
||||
else
|
||||
_has_to_adjust_permissions=1
|
||||
debug-print "Need to adjust permissions to fix CVE-2016-1247!"
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
if [[ ${_has_to_adjust_permissions} -eq 1 ]]; then
|
||||
# We do not DIE when chmod/chown commands are failing because
|
||||
# package is already merged on user's system at this stage
|
||||
# and we cannot retry without losing the information that
|
||||
# the existing installation needs to adjust permissions.
|
||||
# Instead we are going to a show a big warning ...
|
||||
|
||||
if [[ ${_has_to_show_permission_warning} -eq 0 ]] && [[ ${_need_to_fix_CVE2013_0337} -eq 1 ]]; then
|
||||
ewarn ""
|
||||
ewarn "The world-readable bit (if set) has been removed from the"
|
||||
ewarn "following directories to mitigate a security bug"
|
||||
ewarn "(CVE-2013-0337, bug #458726):"
|
||||
ewarn ""
|
||||
ewarn " ${EPREFIX%/}/var/log/nginx"
|
||||
ewarn " ${EPREFIX%/}${NGINX_HOME_TMP}/{,client,proxy,fastcgi,scgi,uwsgi}"
|
||||
ewarn ""
|
||||
ewarn "Check if this is correct for your setup before restarting nginx!"
|
||||
ewarn "This is a one-time change and will not happen on subsequent updates."
|
||||
ewarn "Furthermore nginx' temp directories got moved to '${EPREFIX%/}${NGINX_HOME_TMP}'"
|
||||
chmod o-rwx \
|
||||
"${EPREFIX%/}"/var/log/nginx \
|
||||
"${EPREFIX%/}"${NGINX_HOME_TMP}/{,client,proxy,fastcgi,scgi,uwsgi} || \
|
||||
_has_to_show_permission_warning=1
|
||||
fi
|
||||
|
||||
if [[ ${_has_to_show_permission_warning} -eq 0 ]] && [[ ${_need_to_fix_CVE2016_1247} -eq 1 ]]; then
|
||||
ewarn ""
|
||||
ewarn "The permissions on the following directory have been reset in"
|
||||
ewarn "order to mitigate a security bug (CVE-2016-1247, bug #605008):"
|
||||
ewarn ""
|
||||
ewarn " ${EPREFIX%/}/var/log/nginx"
|
||||
ewarn ""
|
||||
ewarn "Check if this is correct for your setup before restarting nginx!"
|
||||
ewarn "Also ensure that no other log directory used by any of your"
|
||||
ewarn "vhost(s) is not writeable for nginx user. Any of your log files"
|
||||
ewarn "used by nginx can be abused to escalate privileges!"
|
||||
ewarn "This is a one-time change and will not happen on subsequent updates."
|
||||
chown 0:nginx "${EPREFIX%/}"/var/log/nginx || _has_to_show_permission_warning=1
|
||||
chmod 710 "${EPREFIX%/}"/var/log/nginx || _has_to_show_permission_warning=1
|
||||
fi
|
||||
|
||||
if [[ ${_has_to_show_permission_warning} -eq 1 ]]; then
|
||||
# Should never happen ...
|
||||
ewarn ""
|
||||
ewarn "*************************************************************"
|
||||
ewarn "*************** W A R N I N G ***************"
|
||||
ewarn "*************************************************************"
|
||||
ewarn "The one-time only attempt to adjust permissions of the"
|
||||
ewarn "existing nginx installation failed. Be aware that we will not"
|
||||
ewarn "try to adjust the same permissions again because now you are"
|
||||
ewarn "using a nginx version where we expect that the permissions"
|
||||
ewarn "are already adjusted or that you know what you are doing and"
|
||||
ewarn "want to keep custom permissions."
|
||||
ewarn ""
|
||||
fi
|
||||
fi
|
||||
|
||||
# Sanity check for CVE-2016-1247
|
||||
# Required to warn users who received the warning above and thought
|
||||
# they could fix it by unmerging and re-merging the package or have
|
||||
# unmerged a affected installation on purpose in the past leaving
|
||||
# /var/log/nginx on their system due to keepdir/non-empty folder
|
||||
# and are now installing the package again.
|
||||
local _sanity_check_testfile=$(mktemp --dry-run "${EPREFIX%/}"/var/log/nginx/.CVE-2016-1247.XXXXXXXXX)
|
||||
su -s /bin/sh -c "touch ${_sanity_check_testfile}" nginx >&/dev/null
|
||||
if [ $? -eq 0 ] ; then
|
||||
# Cleanup -- no reason to die here!
|
||||
rm -f "${_sanity_check_testfile}"
|
||||
|
||||
ewarn ""
|
||||
ewarn "*************************************************************"
|
||||
ewarn "*************** W A R N I N G ***************"
|
||||
ewarn "*************************************************************"
|
||||
ewarn "Looks like your installation is vulnerable to CVE-2016-1247"
|
||||
ewarn "(bug #605008) because nginx user is able to create files in"
|
||||
ewarn ""
|
||||
ewarn " ${EPREFIX%/}/var/log/nginx"
|
||||
ewarn ""
|
||||
ewarn "Also ensure that no other log directory used by any of your"
|
||||
ewarn "vhost(s) is not writeable for nginx user. Any of your log files"
|
||||
ewarn "used by nginx can be abused to escalate privileges!"
|
||||
fi
|
||||
|
||||
if [[ ${_has_to_show_httpoxy_mitigation_notice} -eq 1 ]]; then
|
||||
# HTTPoxy mitigation
|
||||
ewarn ""
|
||||
ewarn "This nginx installation comes with a mitigation for the HTTPoxy"
|
||||
ewarn "vulnerability for FastCGI, SCGI and uWSGI applications by setting"
|
||||
ewarn "the HTTP_PROXY parameter to an empty string per default when you"
|
||||
ewarn "are sourcing one of the default"
|
||||
ewarn ""
|
||||
ewarn " - 'fastcgi_params' or 'fastcgi.conf'"
|
||||
ewarn " - 'scgi_params'"
|
||||
ewarn " - 'uwsgi_params'"
|
||||
ewarn ""
|
||||
ewarn "files in your server block(s)."
|
||||
ewarn ""
|
||||
ewarn "If this is causing any problems for you make sure that you are sourcing the"
|
||||
ewarn "default parameters _before_ you set your own values."
|
||||
ewarn "If you are relying on user-supplied proxy values you have to remove the"
|
||||
ewarn "correlating lines from the file(s) mentioned above."
|
||||
ewarn ""
|
||||
fi
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user