net-analyzer/nagios-core: new version 4.3.4 for testing.
authorMichael Orlitzky <mjo@gentoo.org>
Wed, 30 Aug 2017 13:55:01 +0000 (09:55 -0400)
committerMichael Orlitzky <mjo@gentoo.org>
Wed, 30 Aug 2017 14:09:30 +0000 (10:09 -0400)
This new version comes with few upstream changes, but I took a flaming
sword to the ebuild. Upstream defaults to installing everything as
nagios:nagios, and this creates a few easy-to-exploit scenarios. The
ebuild will now install everything as root:root where I think we can
get away with it, but this is all an experiment. I'll mask this
version and ask for help testing.

Package-Manager: Portage-2.3.6, Repoman-2.3.1

net-analyzer/nagios-core/Manifest
net-analyzer/nagios-core/nagios-core-4.3.4.ebuild [new file with mode: 0644]

index f1029f0cbd783acfcf27652549d82f216c447099..ffabb32a4f4185d1fbeac64350741971df9c1cc3 100644 (file)
@@ -1,4 +1,5 @@
 DIST nagios-3.5.1.tar.gz 1763584 SHA256 ca9dd68234fa090b3c35ecc8767b2c9eb743977eaf32612fa9b8341cc00a0f99 SHA512 48e2ecb91002b08203937b12a438c87c62cd3c5c401a0ed9e861cd6d79074c7017ed373e9379f013d87dea1fd7cb8e3d85112d55c87ac91aed96b256868c112d WHIRLPOOL 2c02584702c64dbb0e353e34b758fab079eee0dc7a401e7b5947a21733758d3596401e5519e2dd7f05c89ee4835c21965d2718157fd9d6d3d20af9c853d688ca
 DIST nagios-4.3.1.tar.gz 11095797 SHA256 dfc2f5f146eb508b2a28d28af7c338ef9eb604327efdc50142642026f7e79f82 SHA512 d5f1919e2b32b0b2f4c5766367f0992fcf9b1f6766f4d3386e15e318cc1f57cdae6bc07f09464fd8212bef1713948fcb25d233eab588438036f996b6c479c97e WHIRLPOOL 72032e93802fd28db71bb5a10bba703a9508c587de69ff24ce302ad4fbbd93996b4800ceb7dd4f5648e2717377409cd7a66591f177e775da1c69444d528be1a2
 DIST nagios-4.3.3.tar.gz 11101531 SHA256 1fc4c72f76c720884dd3b538dc423b44f3bdde24e014f4212e58046a1fc114b6 SHA512 588292a95342cb2d95d7b58f70442b82b99a23dd9fdc1390e9ae0743626a047e5127d77b1d7e6a1d8edd6f34a425e581bcd42459b673a0ddea14125bde4b7d9e WHIRLPOOL 1452256a79190eae90076a9b50fdac3876557a6382d15d38a0c7930ec6d286c58e44220fee3243c9bcb1ae0ef337ddadd19e3552f02049959e69eaffd9fcd4a8
+DIST nagios-4.3.4.tar.gz 11101966 SHA256 c90b7812d9e343db12be19a572e15c415c5d6353a91c5e226e432c2d4aaa44f1 SHA512 f4e92aa98151739442a225a245871d93b5560d89510bdacb1a615959b9687f7a92675f10fcba71078b104ca8f237b0155a9261d67ec66f80aec7f033b4b3e316 WHIRLPOOL dae991fe44f2d8c5457cffec6647d2b8a7ace60450e0ec2409838aaf1a6f35af1f6c56d260a36cceeede21cfd4521e695146a8c18b38d4e6689d0801d3471157
 DIST nagios-core-gentoo-icons-20141125.tar 40960 SHA256 68b715f636eb291343cab3259862bbed8b6b898520b58df522438524de3d8761 SHA512 bf109879cddd6136b76baba55d0b60b2596e37431dcf5ce0905d34a9fa292ebf7e4bde82d9a084362c486e8fac344c76d88f9298b1b85541ed70ffd608493766 WHIRLPOOL 7ec3a944b2a659b456d3168818ca5b1af3a427436e6af2f3e5d6cba6fc7b1c7bad6f552301f064df31988865b3b32fd117d9e6f61c630d6d817a51cbbbcb331d
diff --git a/net-analyzer/nagios-core/nagios-core-4.3.4.ebuild b/net-analyzer/nagios-core/nagios-core-4.3.4.ebuild
new file mode 100644 (file)
index 0000000..6de6b18
--- /dev/null
@@ -0,0 +1,214 @@
+# Copyright 1999-2017 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=6
+
+inherit toolchain-funcs user
+
+MY_P=${PN/-core}-${PV}
+DESCRIPTION="Nagios core - monitoring daemon, web GUI, and documentation"
+HOMEPAGE="http://www.nagios.org/"
+
+# The name of the directory into which our Gentoo icons will be
+# extracted, and also the basename of the archive containing it.
+GENTOO_ICONS="${PN}-gentoo-icons-20141125"
+SRC_URI="mirror://sourceforge/nagios/${MY_P}.tar.gz
+       web? ( https://dev.gentoo.org/~mjo/distfiles/${GENTOO_ICONS}.tar )"
+
+LICENSE="GPL-2"
+SLOT="0"
+KEYWORDS="~alpha ~amd64 ~arm ~arm64 ~hppa ~ppc ~ppc64 ~sparc ~x86"
+IUSE="apache2 classicui lighttpd perl +web vim-syntax"
+
+# In pkg_postinst(), we change the group of the Nagios configuration
+# directory to that of the web server user. It can't belong to both
+# apache/lighttpd groups at the same time, so we block this combination
+# for our own sanity.
+#
+# This could be made to work, but we would need a better way to allow
+# the web user read-only access to Nagios's configuration directory.
+#
+REQUIRED_USE="apache2? ( !lighttpd )"
+
+# sys-devel/libtool dependency is bug #401237.
+#
+# Note, we require one of the apache2 CGI modules:
+#
+#   * mod_cgi
+#   * mod_cgid
+#   * mod_fcgid
+#
+# We just don't care /which/ one. And of course PHP supports both CGI
+# (USE=cgi) and FastCGI (USE=fpm). We're pretty lenient with the
+# dependencies, and expect the user not to do anything /too/
+# stupid. (For example, installing Apache with only FastCGI support, and
+# PHP with only CGI support.)
+#
+# Another annoyance is that the upstream Makefile uses app-arch/unzip to
+# extract a snapshot of AngularJS, but that's only needed when USE=web.
+#
+MOD_ALIAS=apache2_modules_alias
+DEPEND="sys-devel/libtool
+       virtual/mailx
+       perl? ( dev-lang/perl:= )
+       web? (
+               app-arch/unzip
+               media-libs/gd[jpeg,png]
+               lighttpd? ( www-servers/lighttpd[php] )
+               apache2? (
+                       || (
+                               >=www-servers/apache-2.4[${MOD_ALIAS},apache2_modules_cgi]
+                               >=www-servers/apache-2.4[${MOD_ALIAS},apache2_modules_cgid]
+                               >=www-servers/apache-2.4[${MOD_ALIAS},apache2_modules_fcgid] )
+                       || (
+                               dev-lang/php:*[apache2]
+                               dev-lang/php:*[cgi]
+                               dev-lang/php:*[fpm] )
+               )
+       )"
+RDEPEND="${DEPEND}
+       vim-syntax? ( app-vim/nagios-syntax )"
+
+S="${WORKDIR}/${MY_P}"
+
+pkg_setup() {
+       enewgroup nagios
+       enewuser nagios -1 /bin/bash /var/nagios/home nagios
+}
+
+src_configure() {
+       local myconf
+
+       if use perl; then
+               myconf="${myconf} --enable-embedded-perl --with-perlcache"
+       fi
+
+       if use !apache2 && use !lighttpd ; then
+               myconf="${myconf} --with-command-group=nagios"
+       else
+               if use apache2 ; then
+                       myconf="${myconf} --with-command-group=apache"
+                       myconf="${myconf} --with-httpd-conf=/etc/apache2/conf.d"
+               elif use lighttpd ; then
+                       myconf="${myconf} --with-command-group=lighttpd"
+               fi
+       fi
+
+       econf ${myconf} \
+               --prefix=/usr \
+               --bindir=/usr/sbin \
+               --sbindir=/usr/$(get_libdir)/nagios/cgi-bin \
+               --datadir=/usr/share/nagios/htdocs \
+               --localstatedir=/var/nagios \
+               --sysconfdir=/etc/nagios \
+               --libexecdir=/usr/$(get_libdir)/nagios/plugins
+}
+
+src_compile() {
+       emake CC=$(tc-getCC) nagios
+
+       if use web; then
+               # Only compile the CGIs/HTML when USE=web is set.
+               emake CC=$(tc-getCC) DESTDIR="${D}" cgis html
+       fi
+}
+
+src_install() {
+       dodoc Changelog CONTRIBUTING.md README.asciidoc THANKS UPGRADING
+
+       # There is no way to install the CGIs unstripped from the top-level
+       # makefile, so descend into base/ here. The empty INSTALL_OPTS
+       # ensures that root:root: owns the nagios executables.
+       cd "${S}/base" || die
+       emake INSTALL_OPTS="" DESTDIR="${D}" install-unstripped
+       cd "${S}" || die
+
+       # Otherwise this gets installed as 770 and you get "access denied"
+       # for some reason or other when starting nagios. The permissions
+       # on nagiostats are just for consistency (these should both get
+       # fixed upstream).
+       fperms 775 /usr/sbin/nagios /usr/sbin/nagiostats
+
+       # INSTALL_OPTS are needed for most of install-basic, but we don't
+       # want them on the LIBEXECDIR, argh.
+       emake DESTDIR="${D}" install-basic
+       fowners root:root /usr/$(get_libdir)/nagios/plugins
+
+       # Don't make the configuration owned by the nagios user, because
+       # then he can edit nagios.cfg and trick nagios into running as root
+       # and doing his bidding.
+       emake INSTALL_OPTS="" DESTDIR="${D}" install-config
+
+       # No INSTALL_OPTS used in install-commandmode, thankfully.
+       emake DESTDIR="${D}" install-commandmode
+
+       if use web; then
+               # There is no way to install the CGIs unstripped from the
+               # top-level makefile, so descend into cgi/ here. The empty
+               # INSTALL_OPTS ensures that root:root: owns the CGI executables.
+               cd "${S}/cgi" || die
+               emake INSTALL_OPTS="" DESTDIR="${D}" install-unstripped
+               cd "${S}" || die
+
+               # install-html installs the new exfoliation theme
+               emake INSTALL_OPTS="" DESTDIR="${D}" install-html
+
+               if use classicui; then
+                       # This overwrites the already-installed exfoliation theme
+                       emake INSTALL_OPTS="" DESTDIR="${D}" install-classicui
+               fi
+
+               # Install cute Gentoo icons (bug #388323), setting their
+               # owner, group, and mode to match those of the rest of Nagios's
+               # images.
+               insinto /usr/share/nagios/htdocs/images/logos
+               doins "${WORKDIR}/${GENTOO_ICONS}"/*.*
+       fi
+
+       newinitd openrc-init nagios
+
+       if use web ; then
+               if use apache2 ; then
+                       # Install the Nagios configuration file for Apache.
+                       insinto "/etc/apache2/modules.d"
+                       doins "${FILESDIR}"/99_nagios4.conf
+               elif use lighttpd ; then
+                       # Install the Nagios configuration file for Lighttpd.
+                       insinto /etc/lighttpd
+                       newins "${FILESDIR}/lighttpd_nagios4.conf" nagios.conf
+               else
+                       ewarn "${CATEGORY}/${PF} only supports apache or lighttpd"
+                       ewarn "out of the box. Since you are not using one of them, you"
+                       ewarn "will have to configure your webserver yourself."
+               fi
+       fi
+}
+
+pkg_postinst() {
+
+       if use web; then
+               if use apache2 || use lighttpd ; then
+                       if use apache2; then
+                               elog "To enable the Nagios web front-end, please edit"
+                               elog "${ROOT}etc/conf.d/apache2 and add \"-D NAGIOS -D PHP\""
+                               elog "to APACHE2_OPTS. Then Nagios will be available at,"
+                               elog
+                       elif use lighttpd; then
+                               elog "To enable the Nagios web front-end, please add"
+                               elog "'include \"nagios.conf\"' to the lighttpd configuration"
+                               elog "file at ${ROOT}etc/lighttpd/lighttpd.conf. Then Nagios"
+                               elog "will be available at,"
+                               elog
+                       fi
+
+                       elog "  http://localhost/nagios/"
+               fi
+       fi
+
+       elog
+       elog "If your kernel has /proc protection, nagios"
+       elog "will not be happy as it relies on accessing the proc"
+       elog "filesystem. You can fix this by adding nagios into"
+       elog "the group wheel, but this is not recomended."
+       elog
+}