net-ftp/pure-ftpd: temporarily disable TLSv1.3 support
authorThomas Deutschmann <whissi@gentoo.org>
Sat, 23 Feb 2019 16:18:59 +0000 (17:18 +0100)
committerThomas Deutschmann <whissi@gentoo.org>
Sat, 23 Feb 2019 16:22:10 +0000 (17:22 +0100)
Bug: https://github.com/jedisct1/pure-ftpd/issues/102
Package-Manager: Portage-2.3.62, Repoman-2.3.12
Signed-off-by: Thomas Deutschmann <whissi@gentoo.org>
net-ftp/pure-ftpd/files/pure-ftpd-1.0.47-disable-TLSv1.3.patch [new file with mode: 0644]
net-ftp/pure-ftpd/pure-ftpd-1.0.47-r4.ebuild [moved from net-ftp/pure-ftpd/pure-ftpd-1.0.47-r3.ebuild with 98% similarity]

diff --git a/net-ftp/pure-ftpd/files/pure-ftpd-1.0.47-disable-TLSv1.3.patch b/net-ftp/pure-ftpd/files/pure-ftpd-1.0.47-disable-TLSv1.3.patch
new file mode 100644 (file)
index 0000000..cbe9c8b
--- /dev/null
@@ -0,0 +1,21 @@
+Temporarily disable TLSv1.3 support
+
+Disable TLSv1.3 until support for it is fixed in pure-ftpd. This is a
+workaround for the following issue:
+https://github.com/jedisct1/pure-ftpd/issues/102
+
+--- a/src/tls.c
++++ b/src/tls.c
+@@ -301,6 +301,10 @@ int tls_init_library(void)
+ # endif
+ # ifdef SSL_OP_NO_TLSv1_2
+     SSL_CTX_clear_options(tls_ctx, SSL_OP_NO_TLSv1_2);
++# endif
++    /* Disable TLSv1.3 support until it works properly in pure-ftpd */
++# ifdef SSL_OP_NO_TLSv1_3
++    SSL_CTX_set_options(tls_ctx, SSL_OP_NO_TLSv1_3);
+ # endif
+     if (tlsciphersuite != NULL) {
+         if (SSL_CTX_set_cipher_list(tls_ctx, tlsciphersuite) != 1) {
+-- 
+2.20.1
similarity index 98%
rename from net-ftp/pure-ftpd/pure-ftpd-1.0.47-r3.ebuild
rename to net-ftp/pure-ftpd/pure-ftpd-1.0.47-r4.ebuild
index 58e90f89ddc0d6a7170d83a1c0bfe005d86b8366..48506572446775352e15edcbd55d83e30cbf41f1 100644 (file)
@@ -44,6 +44,7 @@ PATCHES=(
        "${FILESDIR}/${PN}-1.0.28-pam.patch"
        "${FILESDIR}/${PN}-1.0.47-MAX_DATA_SIZE.patch"
        "${FILESDIR}/${PN}-1.0.47-TLSv1.3.patch"
+       "${FILESDIR}/${PN}-1.0.47-disable-TLSv1.3.patch"
 )
 
 src_configure() {