From d84dd5c462352f8eb1ec328a06b3e2aa33ac38a5 Mon Sep 17 00:00:00 2001 From: "Konstantin V. Arkhipov" Date: Sun, 17 Dec 2006 17:56:30 +0000 Subject: [PATCH] * double bump Package-Manager: portage-2.1.2_rc3-r6 --- net-dns/bind-tools/ChangeLog | 9 +- net-dns/bind-tools/bind-tools-9.2.7.ebuild | 74 +++++ net-dns/bind-tools/bind-tools-9.3.3.ebuild | 74 +++++ .../bind-tools/files/digest-bind-tools-9.2.7 | 3 + .../bind-tools/files/digest-bind-tools-9.3.3 | 3 + net-dns/bind/ChangeLog | 10 +- net-dns/bind/bind-9.2.7.ebuild | 291 ++++++++++++++++++ net-dns/bind/bind-9.3.3.ebuild | 286 +++++++++++++++++ net-dns/bind/files/digest-bind-9.2.7 | 9 + net-dns/bind/files/digest-bind-9.3.3 | 9 + net-dns/bind/files/localhost.zone-r2 | 11 + 11 files changed, 777 insertions(+), 2 deletions(-) create mode 100644 net-dns/bind-tools/bind-tools-9.2.7.ebuild create mode 100644 net-dns/bind-tools/bind-tools-9.3.3.ebuild create mode 100644 net-dns/bind-tools/files/digest-bind-tools-9.2.7 create mode 100644 net-dns/bind-tools/files/digest-bind-tools-9.3.3 create mode 100644 net-dns/bind/bind-9.2.7.ebuild create mode 100644 net-dns/bind/bind-9.3.3.ebuild create mode 100644 net-dns/bind/files/digest-bind-9.2.7 create mode 100644 net-dns/bind/files/digest-bind-9.3.3 create mode 100644 net-dns/bind/files/localhost.zone-r2 diff --git a/net-dns/bind-tools/ChangeLog b/net-dns/bind-tools/ChangeLog index fb85cc449657..1d5c2b77e97a 100644 --- a/net-dns/bind-tools/ChangeLog +++ b/net-dns/bind-tools/ChangeLog @@ -1,6 +1,13 @@ # ChangeLog for net-dns/bind-tools # Copyright 2002-2006 Gentoo Foundation; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/net-dns/bind-tools/ChangeLog,v 1.56 2006/07/20 20:25:48 flameeyes Exp $ +# $Header: /var/cvsroot/gentoo-x86/net-dns/bind-tools/ChangeLog,v 1.57 2006/12/17 17:53:18 voxus Exp $ + +*bind-tools-9.3.3 (17 Dec 2006) +*bind-tools-9.2.7 (17 Dec 2006) + + 17 Dec 2006; Konstantin V. Arkhipov + +bind-tools-9.2.7.ebuild, +bind-tools-9.3.3.ebuild: + Version bumps. 20 Jul 2006; Diego Pettenò bind-tools-9.3.2-r3.ebuild: diff --git a/net-dns/bind-tools/bind-tools-9.2.7.ebuild b/net-dns/bind-tools/bind-tools-9.2.7.ebuild new file mode 100644 index 000000000000..c5a507e82327 --- /dev/null +++ b/net-dns/bind-tools/bind-tools-9.2.7.ebuild @@ -0,0 +1,74 @@ +# Copyright 1999-2006 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/net-dns/bind-tools/bind-tools-9.2.7.ebuild,v 1.1 2006/12/17 17:53:18 voxus Exp $ + +inherit flag-o-matic + +MY_P=${P//-tools} +MY_P=${MY_P/_} +S=${WORKDIR}/${MY_P} +DESCRIPTION="bind tools: dig, nslookup, and host" +HOMEPAGE="http://www.isc.org/products/BIND/bind9.html" +SRC_URI="ftp://ftp.isc.org/isc/bind9/${PV/_}/${MY_P}.tar.gz" + +LICENSE="as-is" +SLOT="0" +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~mips ~ppc ~ppc64 ~s390 ~sparc ~x86" +IUSE="idn ipv6" + +DEPEND="" + +src_unpack() { + unpack ${A} || die + cd ${S} || die + + use idn && { + epatch ${S}/contrib/idn/idnkit-1.0-src/patch/bind9/bind-${PV}-patch + + cd ${S}/contrib/idn/idnkit-1.0-src + epatch ${FILESDIR}/${PN}-configure.patch + cd - + } + + # bug #151839 + sed \ + -e 's:CDEFINES =:CDEFINES = -USO_BSDCOMPAT:' \ + -i lib/isc/unix/Makefile.in +} + +src_compile() { + use ipv6 && myconf="${myconf} --enable-ipv6" || myconf="${myconf} --enable-ipv6=no" + + econf ${myconf} || die "Configure failed" + + cd ${S}/lib + emake -j1 || die "make failed in /lib" + + cd ${S}/bin/dig + emake -j1 || die "make failed in /bin/dig" + + cd ${S}/lib/lwres/ + emake -j1 || die "make failed in /lib/lwres" + + cd ${S}/bin/nsupdate/ + emake -j1 || die "make failed in /bin/nsupdate" + + use idn && { + cd ${S}/contrib/idn/idnkit-1.0-src + econf || die "idn econf failed" + emake -j1 || die "idn emake failed" + } +} + +src_install() { + dodoc README CHANGES FAQ + + cd ${S}/bin/dig + dobin dig host nslookup || die + doman dig.1 host.1 nslookup.1 || die + + cd ${S}/bin/nsupdate + dobin nsupdate || die + doman nsupdate.8 || die + dohtml nsupdate.html || die +} diff --git a/net-dns/bind-tools/bind-tools-9.3.3.ebuild b/net-dns/bind-tools/bind-tools-9.3.3.ebuild new file mode 100644 index 000000000000..ca606d295f87 --- /dev/null +++ b/net-dns/bind-tools/bind-tools-9.3.3.ebuild @@ -0,0 +1,74 @@ +# Copyright 1999-2006 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/net-dns/bind-tools/bind-tools-9.3.3.ebuild,v 1.1 2006/12/17 17:53:18 voxus Exp $ + +inherit flag-o-matic + +MY_P=${P//-tools} +MY_P=${MY_P/_} +S=${WORKDIR}/${MY_P} +DESCRIPTION="bind tools: dig, nslookup, and host" +HOMEPAGE="http://www.isc.org/products/BIND/bind9.html" +SRC_URI="ftp://ftp.isc.org/isc/bind9/${PV/_}/${MY_P}.tar.gz" + +LICENSE="as-is" +SLOT="0" +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~mips ~ppc ~ppc64 ~s390 ~sparc ~x86 ~x86-fbsd" +IUSE="idn ipv6" + +DEPEND="" + +src_unpack() { + unpack ${A} || die + cd ${S} || die + + use idn && { + epatch ${S}/contrib/idn/idnkit-1.0-src/patch/bind9/bind-${PV}-patch + + cd ${S}/contrib/idn/idnkit-1.0-src + epatch ${FILESDIR}/${PN}-configure.patch + cd - + } + + # bug #151839 + sed \ + -e 's:CDEFINES =:CDEFINES = -USO_BSDCOMPAT:' \ + -i lib/isc/unix/Makefile.in +} + +src_compile() { + use ipv6 && myconf="${myconf} --enable-ipv6" || myconf="${myconf} --enable-ipv6=no" + + econf ${myconf} || die "Configure failed" + + cd ${S}/lib + emake -j1 || die "make failed in /lib" + + cd ${S}/bin/dig + emake -j1 || die "make failed in /bin/dig" + + cd ${S}/lib/lwres/ + emake -j1 || die "make failed in /lib/lwres" + + cd ${S}/bin/nsupdate/ + emake -j1 || die "make failed in /bin/nsupdate" + + use idn && { + cd ${S}/contrib/idn/idnkit-1.0-src + econf || die "idn econf failed" + emake -j1 || die "idn emake failed" + } +} + +src_install() { + dodoc README CHANGES FAQ + + cd ${S}/bin/dig + dobin dig host nslookup || die + doman dig.1 host.1 nslookup.1 || die + + cd ${S}/bin/nsupdate + dobin nsupdate || die + doman nsupdate.8 || die + dohtml nsupdate.html || die +} diff --git a/net-dns/bind-tools/files/digest-bind-tools-9.2.7 b/net-dns/bind-tools/files/digest-bind-tools-9.2.7 new file mode 100644 index 000000000000..55605b1b6598 --- /dev/null +++ b/net-dns/bind-tools/files/digest-bind-tools-9.2.7 @@ -0,0 +1,3 @@ +MD5 4f3c993923872750d9261d38f35e36bb bind-9.2.7.tar.gz 5206002 +RMD160 d849dd8361c87645ce8308af5d64f87ba8917b3c bind-9.2.7.tar.gz 5206002 +SHA256 959095db8c1c9e1c4498c3065acb54fa1a3a6f9bbf710f148fa1d70e59aff899 bind-9.2.7.tar.gz 5206002 diff --git a/net-dns/bind-tools/files/digest-bind-tools-9.3.3 b/net-dns/bind-tools/files/digest-bind-tools-9.3.3 new file mode 100644 index 000000000000..61b02a4ced55 --- /dev/null +++ b/net-dns/bind-tools/files/digest-bind-tools-9.3.3 @@ -0,0 +1,3 @@ +MD5 b5cad77aa7912bf7b4cb770cfc42fdad bind-9.3.3.tar.gz 5401230 +RMD160 cb779390cf23d042aca568604bde3f1252e7527b bind-9.3.3.tar.gz 5401230 +SHA256 d2d115578f9feff1871cbb9a78e99d510da38da5b0eeb31b749b0c084b06dec2 bind-9.3.3.tar.gz 5401230 diff --git a/net-dns/bind/ChangeLog b/net-dns/bind/ChangeLog index c072ebd06ea5..b45c0f2f8ef6 100644 --- a/net-dns/bind/ChangeLog +++ b/net-dns/bind/ChangeLog @@ -1,6 +1,14 @@ # ChangeLog for net-dns/bind # Copyright 2002-2006 Gentoo Foundation; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/net-dns/bind/ChangeLog,v 1.129 2006/11/23 17:17:55 vivo Exp $ +# $Header: /var/cvsroot/gentoo-x86/net-dns/bind/ChangeLog,v 1.130 2006/12/17 17:56:30 voxus Exp $ + +*bind-9.3.3 (17 Dec 2006) +*bind-9.2.7 (17 Dec 2006) + + 17 Dec 2006; Konstantin V. Arkhipov + +files/localhost.zone-r2, +bind-9.2.7.ebuild, +bind-9.3.3.ebuild: + Version bumps, wrt security bugs #158217 and #131337. Also closing #153601 and + #151839. Support for net-dns/resolvconf-gentoo added. 23 Nov 2006; Francesco Riosa bind-9.2.6.ebuild, bind-9.2.6-r3.ebuild, bind-9.2.6-r4.ebuild, bind-9.2.6-r5.ebuild, diff --git a/net-dns/bind/bind-9.2.7.ebuild b/net-dns/bind/bind-9.2.7.ebuild new file mode 100644 index 000000000000..289cf6612d7b --- /dev/null +++ b/net-dns/bind/bind-9.2.7.ebuild @@ -0,0 +1,291 @@ +# Copyright 1999-2006 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/net-dns/bind/bind-9.2.7.ebuild,v 1.1 2006/12/17 17:56:30 voxus Exp $ + +inherit eutils libtool autotools + +DLZ_VERSION="9.2.7" + +DESCRIPTION="BIND - Berkeley Internet Name Domain - Name Server" +HOMEPAGE="http://www.isc.org/products/BIND/bind9.html" +SRC_URI="ftp://ftp.isc.org/isc/bind9/${PV}/${P}.tar.gz + mirror://gentoo/dyndns-samples.tbz2 + dlz? ( http://dev.gentoo.org/~voxus/dlz/dlz-${DLZ_VERSION}.patch.bz2 )" + +LICENSE="as-is" +SLOT="0" +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~x86" +IUSE="ssl ipv6 doc dlz postgres berkdb bind-mysql mysql odbc ldap selinux idn threads" + +DEPEND="ssl? ( >=dev-libs/openssl-0.9.6g ) + mysql? ( >=virtual/mysql-4.0 ) + bind-mysql? ( >=virtual/mysql-4.0 ) + odbc? ( >=dev-db/unixODBC-2.2.6 ) + ldap? ( net-nds/openldap )" +RDEPEND="${DEPEND} + selinux? ( sec-policy/selinux-bind )" + +pkg_setup() { + ebegin "Creating named group and user" + enewgroup named 40 + enewuser named 40 -1 /etc/bind named + eend ${?} +} + +src_unpack() { + use threads && { + echo + ewarn "If you're in vserver enviroment, you're probably want to" + ewarn "disable threads support because of linux capabilities dependency" + echo + } + + unpack ${A} && cd ${S} + + # Adjusting PATHs in manpages + for i in `echo bin/{named/named.8,check/named-checkconf.8,rndc/rndc.8}`; do + sed -i -e 's:/etc/named.conf:/etc/bind/named.conf:g' \ + -e 's:/etc/rndc.conf:/etc/bind/rndc.conf:g' \ + -e 's:/etc/rndc.key:/etc/bind/rndc.key:g' \ + ${i} + done + + if use dlz; then + epatch ${DISTDIR}/dlz-${DLZ_VERSION}.patch.bz2 + epatch ${FILESDIR}/bind-9.2.5-berkdb_fix.patch + epatch ${FILESDIR}/${PN}-dlzbdb-includes.patch + fi + + if use bind-mysql; then + if use dlz; then + MP=${P}-dlz-mysql.patch + else + MP=${P}-mysql.patch + fi + + ebegin "Fixing mysql patch" + eindent + + cp ${FILESDIR}/${MP} ${T}/${MP} + + sed -e "s:-I/usr/local/include:`mysql_config --include`:" \ + -e "s:-L/usr/local/lib/mysql -lmysqlclient:`mysql_config --libs`:" \ + -i ${T}/${MP} + + epatch ${T}/${MP} + + eoutdent + eend $? + fi + + if use idn; then + epatch ${S}/contrib/idn/idnkit-1.0-src/patch/bind9/${P}-patch + fi + + # it should be installed by bind-tools + sed -e "s:nsupdate ::g" -i ${S}/bin/Makefile.in + + cd "${S}" + WANT_AUTOCONF=2.5 AT_NO_RECURSIVE=1 eautoreconf || die "eautoreconf failed" + + # bug #151839 + sed \ + -e 's:CDEFINES =:CDEFINES = -USO_BSDCOMPAT:' \ + -i lib/isc/unix/Makefile.in +} + +src_compile() { + local myconf="" + + use ssl && myconf="${myconf} --with-openssl" + use dlz && { + myconf="${myconf} --with-dlz-filesystem --with-dlz-stub" + use postgres && myconf="${myconf} --with-dlz-postgres" + use mysql && myconf="${myconf} --with-dlz-mysql" + use berkdb && myconf="${myconf} --with-dlz-bdb" + use ldap && myconf="${myconf} --with-dlz-ldap" + use odbc && myconf="${myconf} --with-dlz-odbc=/usr/include" + } + + if use threads; then + if use dlz && use mysql; then + echo + ewarn "" + einfo "MySQL uses thread local storage in its C api. Thus MySQL" + einfo "requires that each thread of an application execute a MySQL" + einfo "\"thread initialization\" to setup the thread local storage." + einfo "This is impossible to do safely while staying within the DLZ" + einfo "driver API. This is a limitation caused by MySQL, and not the" + einfo "DLZ API." + ewarn "Because of this BIND MUST only run with a single thread when" + ewarn "using the MySQL driver." + echo + myconf="${myconf} --disable-linux-caps --disable-threads" + einfo "Threading support disabled" + epause 10 + else + myconf="${myconf} --enable-linux-caps --enable-threads" + einfo "Threading support enabled" + fi + else + myconf="${myconf} --disable-linux-caps --disable-threads" + fi + + econf \ + --sysconfdir=/etc/bind \ + --localstatedir=/var \ + `use_enable ipv6` \ + --with-libtool \ + ${myconf} || die "econf failed" + + emake -j1 || die "failed to compile bind" + + if use idn; then + cd ${S}/contrib/idn/idnkit-1.0-src + econf || die "idn econf failed" + emake || die "idn emake failed" + fi +} + +src_install() { + einstall || die "failed to install bind" + + dodoc CHANGES COPYRIGHT FAQ README + + use doc && { + docinto misc ; dodoc doc/misc/* + docinto html ; dohtml doc/arm/* + docinto draft ; dodoc doc/draft/* + docinto rfc ; dodoc doc/rfc/* + docinto contrib ; dodoc contrib/named-bootconf/named-bootconf.sh \ + contrib/nanny/nanny.pl + } + + insinto /etc/env.d + newins ${FILESDIR}/10bind.env 10bind + + # some handy-dandy dynamic dns examples + cd ${D}/usr/share/doc/${PF} + tar pjxf ${DISTDIR}/dyndns-samples.tbz2 + + dodir /etc/bind /var/bind/{pri,sec} + keepdir /var/bind/sec + + insinto /etc/bind ; newins ${FILESDIR}/named.conf-r3 named.conf + # ftp://ftp.rs.internic.net/domain/named.ca: + insinto /var/bind ; doins ${FILESDIR}/named.ca + + insinto /var/bind/pri + doins ${FILESDIR}/127.zone + newins ${FILESDIR}/localhost.zone-r2 localhost.zone + + cp ${FILESDIR}/named.init-r4 ${T}/named && doinitd ${T}/named + cp ${FILESDIR}/named.confd-r1 ${T}/named && doconfd ${T}/named + + dosym ../../var/bind/named.ca /var/bind/root.cache + dosym ../../var/bind/pri /etc/bind/pri + dosym ../../var/bind/sec /etc/bind/sec + + if use idn; then + cd ${S}/contrib/idn/idnkit-1.0-src + einstall || die "failed to install idn kit" + docinto idn + dodoc ChangeLog INSTALL{,.ja} README{,.ja} NEWS + fi + + # Let's get rid of those tools and their manpages since they're provided by bind-tools + rm -f ${D}/usr/share/man/man1/{dig.1,host.1,nslookup.1} + rm -f ${D}/usr/bin/{dig,host,nslookup} +} + +pkg_postinst() { + if [ ! -f '/etc/bind/rndc.key' ]; then + if [ -c /dev/urandom ]; then + einfo "Using /dev/urandom for generating rndc.key" + /usr/sbin/rndc-confgen -r /dev/urandom -a -u named + echo + else + einfo "Using /dev/random for generating rndc.key" + /usr/sbin/rndc-confgen -a -u named + echo + fi + fi + + install -d -o named -g named ${ROOT}/var/run/named \ + ${ROOT}/var/bind/pri ${ROOT}/var/bind/sec + chown -R named:named ${ROOT}/var/bind + + einfo "The default zone files are now installed as *.zone," + einfo "be careful merging config files if you have modified" + einfo "/var/bind/pri/127 or /var/bind/pri/localhost" + einfo + einfo "You can edit /etc/conf.d/named to customize named settings" + einfo + einfo "The BIND ebuild now includes chroot support." + einfo "If you like to run bind in chroot AND this is a new install OR" + einfo "your bind doesn't already run in chroot, simply run:" + einfo "\`emerge --config =${CATEGORY}/${PF}\`" + einfo "Before running the above command you might want to change the chroot" + einfo "dir in /etc/conf.d/named. Otherwise /chroot/dns will be used." + echo + einfo "Recently verisign added a wildcard A record to the .COM and .NET TLD" + einfo "zones making all .com and .net domains appear to be registered" + einfo "This causes many problems such as breaking important anti-spam checks" + einfo "which verify source domains exist. ISC released a patch for BIND which" + einfo "adds 'delegation-only' zones to allow admins to return the .com and .net" + einfo "domain resolution to their normal function." + echo + einfo "There is no need to create a com or net data file. Just the" + einfo "entries to the named.conf file is enough." + echo + einfo " zone "com" IN { type delegation-only; };" + einfo " zone "net" IN { type delegation-only; };" + + echo + ewarn "BIND >=9.2.5 makes the priority argument to MX records mandatory" + ewarn "when it was previously optional. If the priority is missing, BIND" + ewarn "won't load the zone file at all." + echo +} + +pkg_config() { + CHROOT=`sed -n 's/^[[:blank:]]\?CHROOT="\([^"]\+\)"/\1/p' /etc/conf.d/named 2>/dev/null` + EXISTS="no" + + if [ -z "${CHROOT}" -a ! -d "/chroot/dns" ]; then + CHROOT="/chroot/dns" + elif [ -d ${CHROOT} ]; then + eerror; eerror "${CHROOT:-/chroot/dns} already exists. Quitting."; eerror; EXISTS="yes" + fi + + if [ ! "$EXISTS" = yes ]; then + einfo ; einfon "Setting up the chroot directory..." + mkdir -m 700 -p ${CHROOT} + mkdir -p ${CHROOT}/{dev,etc,var/run/named} + chown -R named:named ${CHROOT}/var/run/named + cp -R /etc/bind ${CHROOT}/etc/ + cp /etc/localtime ${CHROOT}/etc/localtime + chown named:named ${CHROOT}/etc/bind/rndc.key + cp -R /var/bind ${CHROOT}/var/ + chown -R named:named ${CHROOT}/var/ + mknod ${CHROOT}/dev/zero c 1 5 + mknod ${CHROOT}/dev/random c 1 8 + chmod 666 ${CHROOT}/dev/{random,zero} + chown root:named ${CHROOT} + chmod 0750 ${CHROOT} + + grep -q "^#[[:blank:]]\?CHROOT" /etc/conf.d/named ; RETVAL=$? + if [ $RETVAL = 0 ]; then + sed 's/^# \?\(CHROOT.*\)$/\1/' /etc/conf.d/named > /etc/conf.d/named.orig 2>/dev/null + mv --force /etc/conf.d/named.orig /etc/conf.d/named + fi + + sleep 1; echo " Done."; sleep 1 + einfo + einfo "Add the following to your root .bashrc or .bash_profile: " + einfo " alias rndc='rndc -k ${CHROOT}/etc/bind/rndc.key'" + einfo "Then do the following: " + einfo " source /root/.bashrc or .bash_profile" + einfo + fi +} diff --git a/net-dns/bind/bind-9.3.3.ebuild b/net-dns/bind/bind-9.3.3.ebuild new file mode 100644 index 000000000000..6f7ed1068242 --- /dev/null +++ b/net-dns/bind/bind-9.3.3.ebuild @@ -0,0 +1,286 @@ +# Copyright 1999-2006 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/net-dns/bind/bind-9.3.3.ebuild,v 1.1 2006/12/17 17:56:30 voxus Exp $ + +inherit eutils libtool autotools + +DLZ_VERSION="9.3.3" + +DESCRIPTION="BIND - Berkeley Internet Name Domain - Name Server" +HOMEPAGE="http://www.isc.org/products/BIND/bind9.html" +SRC_URI="ftp://ftp.isc.org/isc/bind9/${PV}/${P}.tar.gz + doc? ( mirror://gentoo/dyndns-samples.tbz2 ) + dlz? ( http://dev.gentoo.org/~voxus/bind/ctrix_dlz_${DLZ_VERSION}.patch.bz2 )" + +LICENSE="as-is" +SLOT="0" +KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~x86 ~x86-fbsd" +IUSE="ssl ipv6 doc dlz postgres berkdb mysql odbc ldap selinux idn threads resolvconf" + +DEPEND="ssl? ( >=dev-libs/openssl-0.9.6g ) + mysql? ( >=virtual/mysql-4.0 ) + odbc? ( >=dev-db/unixODBC-2.2.6 ) + ldap? ( net-nds/openldap ) + resolvconf? ( net-dns/resolvconf-gentoo )" + +RDEPEND="${DEPEND} + selinux? ( sec-policy/selinux-bind )" + +pkg_setup() { + use threads && { + echo + ewarn "If you're in vserver enviroment, you're probably want to" + ewarn "disable threads support because of linux capabilities dependency" + echo + } + + ebegin "Creating named group and user" + enewgroup named 40 + enewuser named 40 -1 /etc/bind named + eend ${?} +} + +src_unpack() { + unpack ${A} + cd "${S}" + + # Adjusting PATHs in manpages + for i in bin/{named/named.8,check/named-checkconf.8,rndc/rndc.8} ; do + sed -i \ + -e 's:/etc/named.conf:/etc/bind/named.conf:g' \ + -e 's:/etc/rndc.conf:/etc/bind/rndc.conf:g' \ + -e 's:/etc/rndc.key:/etc/bind/rndc.key:g' \ + "${i}" + done + + use dlz && { + epatch ${DISTDIR}/ctrix_dlz_${DLZ_VERSION}.patch.bz2 + epatch ${FILESDIR}/${PN}-dlzbdb-includes.patch + + use odbc && epatch ${FILESDIR}/${P}-missing_odbc_test.patch + } + + use idn && epatch ${S}/contrib/idn/idnkit-1.0-src/patch/bind9/${P}-patch + + # should be installed by bind-tools + sed -e "s:nsupdate ::g" -i ${S}/bin/Makefile.in + + WANT_AUTOCONF=2.5 AT_NO_RECURSIVE=1 eautoreconf || die "eautoreconf failed" + + # bug #151839 + sed \ + -e 's:CDEFINES =:CDEFINES = -USO_BSDCOMPAT:' \ + -i lib/isc/unix/Makefile.in +} + +src_compile() { + local myconf="" + + use ssl && myconf="${myconf} --with-openssl" + + use dlz && { + myconf="${myconf} --with-dlz-filesystem --with-dlz-stub" + use postgres && myconf="${myconf} --with-dlz-postgres" + use mysql && myconf="${myconf} --with-dlz-mysql" + use berkdb && myconf="${myconf} --with-dlz-bdb" + use ldap && myconf="${myconf} --with-dlz-ldap" + use odbc && myconf="${myconf} --with-dlz-odbc" + } + + if use threads; then + if use dlz && use mysql; then + echo + ewarn "" + einfo "MySQL uses thread local storage in its C api. Thus MySQL" + einfo "requires that each thread of an application execute a MySQL" + einfo "\"thread initialization\" to setup the thread local storage." + einfo "This is impossible to do safely while staying within the DLZ" + einfo "driver API. This is a limitation caused by MySQL, and not" + einfo "the DLZ API." + ewarn "Because of this BIND MUST only run with a single thread when" + ewarn "using the MySQL driver." + echo + myconf="${myconf} --disable-linux-caps --disable-threads" + einfo "Threading support disabled" + epause 10 + else + myconf="${myconf} --enable-linux-caps --enable-threads" + einfo "Threading support enabled" + fi + else + myconf="${myconf} --disable-linux-caps --disable-threads" + fi + + econf \ + --sysconfdir=/etc/bind \ + --localstatedir=/var \ + --with-libtool \ + `use_enable ipv6` \ + ${myconf} || die "econf failed" + + emake -j1 || die "failed to compile bind" + + use idn && { + cd ${S}/contrib/idn/idnkit-1.0-src + econf || die "idn econf failed" + emake || die "idn emake failed" + } +} + +src_install() { + einstall || die "failed to install bind" + + dodoc CHANGES COPYRIGHT FAQ README + + use doc && { + docinto misc + dodoc doc/misc/* + + docinto html + dohtml doc/arm/* + + docinto draft + dodoc doc/draft/* + + docinto rfc + dodoc doc/rfc/* + + docinto contrib + dodoc contrib/named-bootconf/named-bootconf.sh \ + contrib/nanny/nanny.pl + + # some handy-dandy dynamic dns examples + cd ${D}/usr/share/doc/${PF} + tar pjxf ${DISTFILES}/dyndns-samples.tbz2 + } + + insinto /etc/env.d + newins ${FILESDIR}/10bind.env 10bind + + dodir /etc/bind /var/bind/{pri,sec} + keepdir /var/bind/sec + + insinto /etc/bind ; newins ${FILESDIR}/named.conf-r3 named.conf + + # ftp://ftp.rs.internic.net/domain/named.ca: + insinto /var/bind ; doins ${FILESDIR}/named.ca + + insinto /var/bind/pri + doins ${FILESDIR}/127.zone + newins ${FILESDIR}/localhost.zone-r2 localhost.zone + + cp ${FILESDIR}/named.init-r4 ${T}/named && doinitd ${T}/named + cp ${FILESDIR}/named.confd-r1 ${T}/named && doconfd ${T}/named + + dosym ../../var/bind/named.ca /var/bind/root.cache + dosym ../../var/bind/pri /etc/bind/pri + dosym ../../var/bind/sec /etc/bind/sec + + if use idn; then + cd ${S}/contrib/idn/idnkit-1.0-src + einstall || die "failed to install idn kit" + docinto idn + dodoc ChangeLog INSTALL{,.ja} README{,.ja} NEWS + fi + + # Let's get rid of those tools and their manpages since they're provided by bind-tools + rm -f ${D}/usr/share/man/man1/{dig.1,host.1,nslookup.1} + rm -f ${D}/usr/bin/{dig,host,nslookup} + + use resolvconf && { + exeinto /etc/resolvconf/update.d + newexe ${FILESDIR}/resolvconf.bind bind + } +} + +pkg_postinst() { + if [ ! -f '/etc/bind/rndc.key' ]; then + if [ -c /dev/urandom ]; then + einfo "Using /dev/urandom for generating rndc.key" + /usr/sbin/rndc-confgen -r /dev/urandom -a -u named + echo + else + einfo "Using /dev/random for generating rndc.key" + /usr/sbin/rndc-confgen -a -u named + echo + fi + fi + + install -d -o named -g named ${ROOT}/var/run/named \ + ${ROOT}/var/bind/pri ${ROOT}/var/bind/sec + chown -R named:named ${ROOT}/var/bind + + einfo "The default zone files are now installed as *.zone," + einfo "be careful merging config files if you have modified" + einfo "/var/bind/pri/127 or /var/bind/pri/localhost" + einfo + einfo "You can edit /etc/conf.d/named to customize named settings" + einfo + einfo "The BIND ebuild now includes chroot support." + einfo "If you like to run bind in chroot AND this is a new install OR" + einfo "your bind doesn't already run in chroot, simply run:" + einfo "\`emerge --config '=${CATEGORY}/${PF}'\`" + einfo "Before running the above command you might want to change the chroot" + einfo "dir in /etc/conf.d/named. Otherwise /chroot/dns will be used." + echo + einfo "Recently verisign added a wildcard A record to the .COM and .NET TLD" + einfo "zones making all .com and .net domains appear to be registered" + einfo "This causes many problems such as breaking important anti-spam checks" + einfo "which verify source domains exist. ISC released a patch for BIND which" + einfo "adds 'delegation-only' zones to allow admins to return the .com and .net" + einfo "domain resolution to their normal function." + echo + einfo "There is no need to create a com or net data file. Just the" + einfo "entries to the named.conf file is enough." + echo + einfo " zone "com" IN { type delegation-only; };" + einfo " zone "net" IN { type delegation-only; };" + + echo + ewarn "BIND >=9.2.5 makes the priority argument to MX records mandatory" + ewarn "when it was previously optional. If the priority is missing, BIND" + ewarn "won't load the zone file at all." + echo +} + +pkg_config() { + CHROOT=`sed -n 's/^[[:blank:]]\?CHROOT="\([^"]\+\)"/\1/p' /etc/conf.d/named 2>/dev/null` + EXISTS="no" + + if [ -z "${CHROOT}" -a ! -d "/chroot/dns" ]; then + CHROOT="/chroot/dns" + elif [ -d ${CHROOT} ]; then + eerror; eerror "${CHROOT:-/chroot/dns} already exists. Quitting."; eerror; EXISTS="yes" + fi + + if [ ! "$EXISTS" = yes ]; then + einfo ; einfon "Setting up the chroot directory..." + mkdir -m 700 -p ${CHROOT} + mkdir -p ${CHROOT}/{dev,etc,var/run/named} + chown -R named:named ${CHROOT}/var/run/named + cp -R /etc/bind ${CHROOT}/etc/ + cp /etc/localtime ${CHROOT}/etc/localtime + chown named:named ${CHROOT}/etc/bind/rndc.key + cp -R /var/bind ${CHROOT}/var/ + chown -R named:named ${CHROOT}/var/ + mknod ${CHROOT}/dev/zero c 1 5 + mknod ${CHROOT}/dev/random c 1 8 + chmod 666 ${CHROOT}/dev/{random,zero} + chown root:named ${CHROOT} + chmod 0750 ${CHROOT} + + grep -q "^#[[:blank:]]\?CHROOT" /etc/conf.d/named ; RETVAL=$? + if [ $RETVAL = 0 ]; then + sed 's/^# \?\(CHROOT.*\)$/\1/' /etc/conf.d/named > /etc/conf.d/named.orig 2>/dev/null + mv --force /etc/conf.d/named.orig /etc/conf.d/named + fi + + sleep 1; echo " Done."; sleep 1 + einfo + einfo "Add the following to your root .bashrc or .bash_profile: " + einfo " alias rndc='rndc -k ${CHROOT}/etc/bind/rndc.key'" + einfo "Then do the following: " + einfo " source /root/.bashrc or .bash_profile" + einfo + fi +} diff --git a/net-dns/bind/files/digest-bind-9.2.7 b/net-dns/bind/files/digest-bind-9.2.7 new file mode 100644 index 000000000000..5df3d5469520 --- /dev/null +++ b/net-dns/bind/files/digest-bind-9.2.7 @@ -0,0 +1,9 @@ +MD5 4f3c993923872750d9261d38f35e36bb bind-9.2.7.tar.gz 5206002 +RMD160 d849dd8361c87645ce8308af5d64f87ba8917b3c bind-9.2.7.tar.gz 5206002 +SHA256 959095db8c1c9e1c4498c3065acb54fa1a3a6f9bbf710f148fa1d70e59aff899 bind-9.2.7.tar.gz 5206002 +MD5 10b9cf6eeb8f1a63ad49bef6d4739a66 dlz-9.2.7.patch.bz2 100068 +RMD160 d53b00b27e43b645e96d25c3a7bdbc8e0d2ebade dlz-9.2.7.patch.bz2 100068 +SHA256 db255c43cdee05c05ac8f240e1d75dcbee3f010e41e9f08b133c14b209363e8c dlz-9.2.7.patch.bz2 100068 +MD5 2bb12cfcd70284e72fbf9e70e5e2974d dyndns-samples.tbz2 22866 +RMD160 27d5b2d0edb8e1ff16b3f980c38d7af33ccf0c7d dyndns-samples.tbz2 22866 +SHA256 92fb06a92ca99cbbe96b90bcca229ef9c12397db57ae17e199dad9f1218fdbe8 dyndns-samples.tbz2 22866 diff --git a/net-dns/bind/files/digest-bind-9.3.3 b/net-dns/bind/files/digest-bind-9.3.3 new file mode 100644 index 000000000000..ec639a8973f7 --- /dev/null +++ b/net-dns/bind/files/digest-bind-9.3.3 @@ -0,0 +1,9 @@ +MD5 b5cad77aa7912bf7b4cb770cfc42fdad bind-9.3.3.tar.gz 5401230 +RMD160 cb779390cf23d042aca568604bde3f1252e7527b bind-9.3.3.tar.gz 5401230 +SHA256 d2d115578f9feff1871cbb9a78e99d510da38da5b0eeb31b749b0c084b06dec2 bind-9.3.3.tar.gz 5401230 +MD5 00419378bdf3691c7d2fe7737f25007d ctrix_dlz_9.3.3.patch.bz2 66143 +RMD160 ee3a7ef8e1b3167ff572ca8a7836a8d4d64a834d ctrix_dlz_9.3.3.patch.bz2 66143 +SHA256 6550455ba37f5f25f047078bedf825d05eab45bbc4a3d8b7bf23a716749423cf ctrix_dlz_9.3.3.patch.bz2 66143 +MD5 2bb12cfcd70284e72fbf9e70e5e2974d dyndns-samples.tbz2 22866 +RMD160 27d5b2d0edb8e1ff16b3f980c38d7af33ccf0c7d dyndns-samples.tbz2 22866 +SHA256 92fb06a92ca99cbbe96b90bcca229ef9c12397db57ae17e199dad9f1218fdbe8 dyndns-samples.tbz2 22866 diff --git a/net-dns/bind/files/localhost.zone-r2 b/net-dns/bind/files/localhost.zone-r2 new file mode 100644 index 000000000000..338d7050ca03 --- /dev/null +++ b/net-dns/bind/files/localhost.zone-r2 @@ -0,0 +1,11 @@ +$TTL 1W +@ IN SOA ns.localhost. root.localhost. ( + 2002081601 ; Serial + 28800 ; Refresh + 14400 ; Retry + 604800 ; Expire - 1 week + 86400 ) ; Minimum +@ IN NS ns +ns IN A 127.0.0.1 + +ns IN AAAA ::1 -- 2.26.2