Version bump. Drop --oknodo in init.d #377771 by Michael Mair-Keimberger. Add GSSAP...
authorMike Frysinger <vapier@gentoo.org>
Wed, 7 Sep 2011 01:38:46 +0000 (01:38 +0000)
committerMike Frysinger <vapier@gentoo.org>
Wed, 7 Sep 2011 01:38:46 +0000 (01:38 +0000)
Package-Manager: portage-2.2.0_alpha51/cvs/Linux x86_64

net-misc/openssh/ChangeLog
net-misc/openssh/Manifest
net-misc/openssh/files/openssh-5.9_p1-sshd-gssapi-multihomed.patch [new file with mode: 0644]
net-misc/openssh/files/sshd.rc6.3 [new file with mode: 0755]
net-misc/openssh/openssh-5.9_p1.ebuild [new file with mode: 0644]

index ef747aa767dce4feef1f981eb54d4d5f84c3f849..62d76440e06fa5f618cdca5981b1519060b1f95f 100644 (file)
@@ -1,6 +1,13 @@
 # ChangeLog for net-misc/openssh
 # Copyright 1999-2011 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/net-misc/openssh/ChangeLog,v 1.420 2011/05/28 16:57:48 vapier Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openssh/ChangeLog,v 1.421 2011/09/07 01:38:46 vapier Exp $
+
+*openssh-5.9_p1 (07 Sep 2011)
+
+  07 Sep 2011; Mike Frysinger <vapier@gentoo.org> +openssh-5.9_p1.ebuild,
+  +files/openssh-5.9_p1-sshd-gssapi-multihomed.patch, +files/sshd.rc6.3:
+  Version bump. Drop --oknodo in init.d #377771 by Michael Mair-Keimberger. Add
+  GSSAPI/Kerberos fix #378361 by Kevan Carstensen.
 
   28 May 2011; Mike Frysinger <vapier@gentoo.org> files/sshd.rc6.2:
   Move custom opts to checkconfig and include those when verifying config
index 03057a69a02ea18d114e2b0bb8df246d42846d40..19932e293be3a5c5ea10f2b1d4e9917e43a0624b 100644 (file)
@@ -12,12 +12,14 @@ AUX openssh-5.6_p1-x509-hpn-glue.patch 1974 RMD160 bccefdc9ee8e923968c6dac5d4704
 AUX openssh-5.7_p1-x509-hpn-glue.patch 1888 RMD160 d0af977ecc3b89fc6efbd554f8bb3680acd88c32 SHA1 185e0f56db550cdc0f76d359296681bef55920f3 SHA256 30f63dea0e810d92790ddaf9813f0b8dec1e827a39e1752faff6bb41382f3c1b
 AUX openssh-5.8_p1-selinux.patch 433 RMD160 ec21b74785b475264d8dece2f10102d730684f21 SHA1 db97948d0e54194ad5a00b7d08982b05c2b502b2 SHA256 0de250c75f4dae78406e5151f563bd104b8e7792a825515510e095fb47462cfd
 AUX openssh-5.8_p1-x509-hpn-glue.patch 1907 RMD160 954bfc141bf780e0c36712ee2f0f211bb7147e59 SHA1 a332690d47c18b2ae88a7381a177cc28a098d984 SHA256 7ab452c02b141645b764d404aa3de0754ab240a64601a6bb587919673f957682
+AUX openssh-5.9_p1-sshd-gssapi-multihomed.patch 6622 RMD160 abde3019aab3c94995ffe5574dc27d250b22af82 SHA1 0c825c0ea5f37836bd6206f59953dab751f3371b SHA256 f5ae8419023d9e5f64c4273e43d60664d0079b5888ed999496038f295852e0ae
 AUX sshd.confd 396 RMD160 029680b2281961130a815ef599750c4fc4e84987 SHA1 23c283d0967944b6125be26ed4628f49abf586b2 SHA256 29c6d57ac3ec6018cadc6ba6cd9b90c9ed46e20049b970fdcc68ee2481a2ee41
 AUX sshd.pam 294 RMD160 1d4499a7de54188e51e87a240ec7a1b3b1af583d SHA1 4cd17fb40793fa9ca77ac93698129f2c8cafd7b8 SHA256 f01cc51c624b21a815fb6c0be35edc590e2e6f8a5ffbdcabc220a9630517972f
 AUX sshd.pam_include.2 156 RMD160 c4f6ba6e3a705eef63e571189e28de71e7d61178 SHA1 1223f7a43a5e124521d48852b2d23bb8ba0a788f SHA256 166136e27d653e0bf481a6ca79fecb7d9fa2fc3d597d041f97df595f65a8193c
 AUX sshd.rc6 2159 RMD160 961c7222fe809d81dc04c1f62e14c8292c0e3452 SHA1 d9853a50ff89d4359cc813a0f5ec936659941646 SHA256 83b94fed859ab3a00861969f97c166bd3b2fdd217f26468153e17005dfd55828
 AUX sshd.rc6.1 2244 RMD160 112f62244a4654d706fa3892da514df8130dabf3 SHA1 4a561034f7376bf10dc4601f2b847f247b83bf53 SHA256 09b7f29890fd0c28e364637236518c7ee4fea018af94dd72b8682a548678cd73
 AUX sshd.rc6.2 2040 RMD160 e9091c05a3b6393f3614746404a0e922ffef3b29 SHA1 e130639256fe8ff59f70f94cce495add0fba100f SHA256 d29519fee9cf634b676f214df663304c172374bf10fa94d6fce4220a3456a053
+AUX sshd.rc6.3 2031 RMD160 bb93eabfe7c1b48189536a6674ffef78a07d7cd6 SHA1 9b5551b2a1ff599f2d4c096c2b15767b942449d9 SHA256 35916fa3b3a492baf7dd1ae6244a4dc6c6bc1869c47f3da22b924500280c89b3
 DIST openssh-5.4p1-hpn13v7-x509variant.diff.gz 22941 RMD160 383b3883984ee0e6068363fdd645d2dd24c7964c SHA1 d3f04c938ab6e5e10587d0ffb717af37360a8dd6 SHA256 c2b1a81c6952ae73cc4dfd1528d560588c45cf1242ea8b0e6eadb0cc83b50377
 DIST openssh-5.5p1+x509-6.2.3.diff.gz 156737 RMD160 cf6d9e5f51512b3e22a3561ff7e1c6daad80d016 SHA1 5f163b03b3086605d9759b76565e6f3a5fa8cb85 SHA256 a2fdf904c21036fe6ee89da7572a37f4763ef414348f9a953c7c7e0fb3562a7f
 DIST openssh-5.5p1-hpn13v9.diff.gz 22657 RMD160 bb9d44589018030fa3102898f85f4dfd7032d2f0 SHA1 8601fabf0067ff9c59501dc0006ad3853dbb3de0 SHA256 0556ad75cbd29cba71263a5b7ddc44c03d17c09297a6c41a16d39d3549e5079c
@@ -33,6 +35,8 @@ DIST openssh-5.8p1-hpn13v10.diff.bz2 20120 RMD160 6f7bb5bb06bfd019795679d741c007
 DIST openssh-5.8p1-hpn13v11.diff.gz 22993 RMD160 45fbb8e2db2f829f2749cd745ed6a0542adb1c45 SHA1 ea61ab71605ee867eebc1a92875a3ea5369e2d28 SHA256 62b500d29d8889ce76c8b596eb65731d8ac3469d89d9c6eb29fec2a845159df7
 DIST openssh-5.8p1.tar.gz 1113798 RMD160 c3903b1cf99553a8fc8d762d52c0f28db830edd0 SHA1 adebb2faa9aba2a3a3c8b401b2b19677ab53f0de SHA256 e1c77a8f3562a5e779c59d64ab14a336c160a56db924eaf82b124ac0b6b1323b
 DIST openssh-5.8p2.tar.gz 1115475 RMD160 f70cdb10983c389b1d6e52da522b9ff8256f1aff SHA1 64798328d310e4f06c9f01228107520adbc8b3e5 SHA256 5c35ec7c966ce05cc4497ac59c0b54a556e55ae7368165cc8c4129694654f314
+DIST openssh-5.9p1-hpn13v11.diff.bz2 20666 RMD160 f597b0a99297648d94f0f8723564b465af435459 SHA1 989a1f97bfae83bc850a42a3b45e0f8870a48e9d SHA256 7577dba8e44bfe8e672aabe1019646ef06717080fb2c0aca76390393e5d15574
+DIST openssh-5.9p1.tar.gz 1110014 RMD160 12d92321a2b9f404641a9cdada738784eb30e1cd SHA1 ac4e0055421e9543f0af5da607a72cf5922dcc56 SHA256 8d3e8b6b6ff04b525a6dfa6fdeb6a99043ccf6c3310cc32eba84c939b07777d5
 DIST openssh-lpk-5.4p1-0.3.13.patch.gz 18105 RMD160 734b2c3ea740b6de610e3bfa91c93a2540b79acc SHA1 4c73f21b16db41c16e096db834380ec53f15c723 SHA256 4e5dbe769e487c914ecc5b104866f6d4412cbe35c3f2bed897d06f7d824878be
 DIST openssh-lpk-5.6p1-0.3.13.patch.gz 18376 RMD160 c928a22d890de17c43ac8a71ac0a551fbe38a831 SHA1 477ef82043278ba9e314e14e7a487f1541fbc48b SHA256 42a76b67c390c3ed28efd6e1734ca5a7edfefc635c35086dbd610999130678e9
 DIST openssh-lpk-5.7p1-0.3.13.patch.gz 18392 RMD160 9ca299e2c05c97528ecbea5cc30fe604904daa2c SHA1 5581a12eee5d5e739b77927ce7ddb00625ab03c4 SHA256 739fa32e267f2c30362bb953d597bcbb55b58d76e13f644004fa63ded81522f7
@@ -42,12 +46,13 @@ EBUILD openssh-5.6_p1-r2.ebuild 8382 RMD160 f211edf9dca59ceeb04a4b8ed6e65a6fa35a
 EBUILD openssh-5.7_p1-r1.ebuild 8231 RMD160 62b3bb8b59ad675f8e15ee6f3045806eda352258 SHA1 0fc459848cb5bde826647e095666a43598717b57 SHA256 9c5e767344eb2ae35e567dbf870b6adb1e44cc112fe9b89c8f1c5dccf565658f
 EBUILD openssh-5.8_p1-r1.ebuild 8446 RMD160 e674ea00d8be3d9297c2aa5f98f0d4d8e37a360c SHA1 3bafcd521dfc16fc9d6c39e74b4bccf1bef7088d SHA256 4b385808bcf59c3be6ab92c9cea1638c61db7b4c9089f7804f606b08c0fa3aa3
 EBUILD openssh-5.8_p2.ebuild 8480 RMD160 8d931edee1e597fdeb2f3dedc2e13fd81c96b3a2 SHA1 c50d89503ea7b2b6e8c07150f67895950ce39d43 SHA256 244927dfba721ef5f0cf036619e62744a7895879e607834bb601bc5488c2c12e
-MISC ChangeLog 66025 RMD160 52b89e03f8e19e8fb4ae547adb1bdbb728ff8118 SHA1 70450863ae5992631be81f725537421086669cc2 SHA256 1f18bb64d7f13bf2fd0251cd433875e092bef23ea9e9b983101e911072085f16
+EBUILD openssh-5.9_p1.ebuild 8477 RMD160 96ff61cf738672466590773b42d9e1083191431a SHA1 6f8909001d310f24ee446e007df2c99806f18ad8 SHA256 f09c44454dacf3795b18e0f9920b6a4107e5d5da88f0bb2e26b3fe1b0abc446e
+MISC ChangeLog 66335 RMD160 90f30976ff0386c5affb11f9d902dff350dedca8 SHA1 d738e2fcaf231435849d5185c51c84f2cd8673b1 SHA256 1d1b613170b8d365231460446bc697d5c6211abdfdf0df6fb08da0b2d14cf821
 MISC metadata.xml 1599 RMD160 31fdd1531a4111aa437882680029451b29ddf4aa SHA1 af53a6887ebf563150184ab40b4cc018ab4e4d3f SHA256 fddc51b98b6831f5bc0f1f5fdeb78c064f9c40fc5c9a9f31ec816890e6aade86
 -----BEGIN PGP SIGNATURE-----
 Version: GnuPG v2.0.17 (GNU/Linux)
 
-iF4EAREIAAYFAk3hKZYACgkQaC/OocHi7JZ+6gD/Q3EeyfUtEHUf3wSt8W8/5UOH
-7+3llbEhhTxl4bMSmwkA/jC8LmQU+o7Xhvwexg//9Sq0Cr/xyeMFMbmqK8fXcbpe
-=RGxg
+iF4EAREIAAYFAk5myzEACgkQaC/OocHi7JZdSwD+Kg+5K7csPV48dBSucq7EYZYg
+t8+KvfjDbzoNn+TDpREA/iayIvzh6P5MH5GM7Mpyp7mA2uPESKkz9DU8i4kQa7VB
+=MynI
 -----END PGP SIGNATURE-----
diff --git a/net-misc/openssh/files/openssh-5.9_p1-sshd-gssapi-multihomed.patch b/net-misc/openssh/files/openssh-5.9_p1-sshd-gssapi-multihomed.patch
new file mode 100644 (file)
index 0000000..6377d03
--- /dev/null
@@ -0,0 +1,184 @@
+Index: gss-serv.c
+===================================================================
+RCS file: /cvs/src/usr.bin/ssh/gss-serv.c,v
+retrieving revision 1.22
+diff -u -p -r1.22 gss-serv.c
+--- gss-serv.c 8 May 2008 12:02:23 -0000       1.22
++++ gss-serv.c 11 Jan 2010 05:38:29 -0000
+@@ -41,9 +41,12 @@
+ #include "channels.h"
+ #include "session.h"
+ #include "misc.h"
++#include "servconf.h"
+ #include "ssh-gss.h"
++extern ServerOptions options;
++
+ static ssh_gssapi_client gssapi_client =
+     { GSS_C_EMPTY_BUFFER, GSS_C_EMPTY_BUFFER,
+     GSS_C_NO_CREDENTIAL, NULL, {NULL, NULL, NULL}};
+@@ -77,25 +80,32 @@ ssh_gssapi_acquire_cred(Gssctxt *ctx)
+       char lname[MAXHOSTNAMELEN];
+       gss_OID_set oidset;
+-      gss_create_empty_oid_set(&status, &oidset);
+-      gss_add_oid_set_member(&status, ctx->oid, &oidset);
+-
+-      if (gethostname(lname, MAXHOSTNAMELEN)) {
+-              gss_release_oid_set(&status, &oidset);
+-              return (-1);
+-      }
++      if (options.gss_strict_acceptor) {
++              gss_create_empty_oid_set(&status, &oidset);
++              gss_add_oid_set_member(&status, ctx->oid, &oidset);
++
++              if (gethostname(lname, MAXHOSTNAMELEN)) {
++                      gss_release_oid_set(&status, &oidset);
++                      return (-1);
++              }
++
++              if (GSS_ERROR(ssh_gssapi_import_name(ctx, lname))) {
++                      gss_release_oid_set(&status, &oidset);
++                      return (ctx->major);
++              }
++
++              if ((ctx->major = gss_acquire_cred(&ctx->minor,
++                  ctx->name, 0, oidset, GSS_C_ACCEPT, &ctx->creds,
++                  NULL, NULL)))
++                      ssh_gssapi_error(ctx);
+-      if (GSS_ERROR(ssh_gssapi_import_name(ctx, lname))) {
+               gss_release_oid_set(&status, &oidset);
+               return (ctx->major);
++      } else {
++              ctx->name = GSS_C_NO_NAME;
++              ctx->creds = GSS_C_NO_CREDENTIAL;
+       }
+-
+-      if ((ctx->major = gss_acquire_cred(&ctx->minor,
+-          ctx->name, 0, oidset, GSS_C_ACCEPT, &ctx->creds, NULL, NULL)))
+-              ssh_gssapi_error(ctx);
+-
+-      gss_release_oid_set(&status, &oidset);
+-      return (ctx->major);
++      return GSS_S_COMPLETE;
+ }
+ /* Privileged */
+Index: servconf.c
+===================================================================
+RCS file: /cvs/src/usr.bin/ssh/servconf.c,v
+retrieving revision 1.201
+diff -u -p -r1.201 servconf.c
+--- servconf.c 10 Jan 2010 03:51:17 -0000      1.201
++++ servconf.c 11 Jan 2010 05:34:56 -0000
+@@ -86,6 +86,7 @@ initialize_server_options(ServerOptions 
+       options->kerberos_get_afs_token = -1;
+       options->gss_authentication=-1;
+       options->gss_cleanup_creds = -1;
++      options->gss_strict_acceptor = -1;
+       options->password_authentication = -1;
+       options->kbd_interactive_authentication = -1;
+       options->challenge_response_authentication = -1;
+@@ -200,6 +201,8 @@ fill_default_server_options(ServerOption
+               options->gss_authentication = 0;
+       if (options->gss_cleanup_creds == -1)
+               options->gss_cleanup_creds = 1;
++      if (options->gss_strict_acceptor == -1)
++              options->gss_strict_acceptor = 0;
+       if (options->password_authentication == -1)
+               options->password_authentication = 1;
+       if (options->kbd_interactive_authentication == -1)
+@@ -277,7 +280,8 @@ typedef enum {
+       sBanner, sUseDNS, sHostbasedAuthentication,
+       sHostbasedUsesNameFromPacketOnly, sClientAliveInterval,
+       sClientAliveCountMax, sAuthorizedKeysFile,
+-      sGssAuthentication, sGssCleanupCreds, sAcceptEnv, sPermitTunnel,
++      sGssAuthentication, sGssCleanupCreds, sGssStrictAcceptor,
++      sAcceptEnv, sPermitTunnel,
+       sMatch, sPermitOpen, sForceCommand, sChrootDirectory,
+       sUsePrivilegeSeparation, sAllowAgentForwarding,
+       sZeroKnowledgePasswordAuthentication, sHostCertificate,
+@@ -327,9 +331,11 @@ static struct {
+ #ifdef GSSAPI
+       { "gssapiauthentication", sGssAuthentication, SSHCFG_ALL },
+       { "gssapicleanupcredentials", sGssCleanupCreds, SSHCFG_GLOBAL },
++      { "gssapistrictacceptorcheck", sGssStrictAcceptor, SSHCFG_GLOBAL },
+ #else
+       { "gssapiauthentication", sUnsupported, SSHCFG_ALL },
+       { "gssapicleanupcredentials", sUnsupported, SSHCFG_GLOBAL },
++      { "gssapistrictacceptorcheck", sUnsupported, SSHCFG_GLOBAL },
+ #endif
+       { "passwordauthentication", sPasswordAuthentication, SSHCFG_ALL },
+       { "kbdinteractiveauthentication", sKbdInteractiveAuthentication, SSHCFG_ALL },
+@@ -850,6 +856,10 @@ process_server_config_line(ServerOptions
+       case sGssCleanupCreds:
+               intptr = &options->gss_cleanup_creds;
++              goto parse_flag;
++
++      case sGssStrictAcceptor:
++              intptr = &options->gss_strict_acceptor;
+               goto parse_flag;
+       case sPasswordAuthentication:
+Index: servconf.h
+===================================================================
+RCS file: /cvs/src/usr.bin/ssh/servconf.h,v
+retrieving revision 1.89
+diff -u -p -r1.89 servconf.h
+--- servconf.h 9 Jan 2010 23:04:13 -0000       1.89
++++ servconf.h 11 Jan 2010 05:32:28 -0000
+@@ -92,6 +92,7 @@ typedef struct {
+                                                * authenticated with Kerberos. */
+       int     gss_authentication;     /* If true, permit GSSAPI authentication */
+       int     gss_cleanup_creds;      /* If true, destroy cred cache on logout */
++      int     gss_strict_acceptor;    /* If true, restrict the GSSAPI acceptor name */
+       int     password_authentication;        /* If true, permit password
+                                                * authentication. */
+       int     kbd_interactive_authentication; /* If true, permit */
+Index: sshd_config
+===================================================================
+RCS file: /cvs/src/usr.bin/ssh/sshd_config,v
+retrieving revision 1.81
+diff -u -p -r1.81 sshd_config
+--- sshd_config        8 Oct 2009 14:03:41 -0000       1.81
++++ sshd_config        11 Jan 2010 05:32:28 -0000
+@@ -69,6 +69,7 @@
+ # GSSAPI options
+ #GSSAPIAuthentication no
+ #GSSAPICleanupCredentials yes
++#GSSAPIStrictAcceptorCheck yes
+ # Set this to 'yes' to enable PAM authentication, account processing, 
+ # and session processing. If this is enabled, PAM authentication will 
+Index: sshd_config.5
+===================================================================
+RCS file: /cvs/src/usr.bin/ssh/sshd_config.5,v
+retrieving revision 1.116
+diff -u -p -r1.116 sshd_config.5
+--- sshd_config.5      9 Jan 2010 23:04:13 -0000       1.116
++++ sshd_config.5      11 Jan 2010 05:37:20 -0000
+@@ -386,6 +386,21 @@ on logout.
+ The default is
+ .Dq yes .
+ Note that this option applies to protocol version 2 only.
++.It Cm GSSAPIStrictAcceptorCheck
++Determines whether to be strict about the identity of the GSSAPI acceptor
++a client authenticates against.
++If set to
++.Dq yes
++then the client must authenticate against the
++.Pa host
++service on the current hostname.
++If set to
++.Dq no
++then the client may authenticate against any service key stored in the
++machine's default store.
++This facility is provided to assist with operation on multi homed machines.
++The default is
++.Dq yes .
+ .It Cm HostbasedAuthentication
+ Specifies whether rhosts or /etc/hosts.equiv authentication together
+ with successful public key client host authentication is allowed
diff --git a/net-misc/openssh/files/sshd.rc6.3 b/net-misc/openssh/files/sshd.rc6.3
new file mode 100755 (executable)
index 0000000..8c12dea
--- /dev/null
@@ -0,0 +1,84 @@
+#!/sbin/runscript
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openssh/files/sshd.rc6.3,v 1.1 2011/09/07 01:38:46 vapier Exp $
+
+opts="${opts} reload checkconfig gen_keys"
+
+depend() {
+       use logger dns
+       need net
+}
+
+SSHD_CONFDIR=${SSHD_CONFDIR:-/etc/ssh}
+SSHD_PIDFILE=${SSHD_PIDFILE:-/var/run/${SVCNAME}.pid}
+SSHD_BINARY=${SSHD_BINARY:-/usr/sbin/sshd}
+
+checkconfig() {
+       if [ ! -d /var/empty ] ; then
+               mkdir -p /var/empty || return 1
+       fi
+
+       if [ ! -e "${SSHD_CONFDIR}"/sshd_config ] ; then
+               eerror "You need an ${SSHD_CONFDIR}/sshd_config file to run sshd"
+               eerror "There is a sample file in /usr/share/doc/openssh"
+               return 1
+       fi
+
+       gen_keys || return 1
+
+       [ "${SSHD_PIDFILE}" != "/var/run/sshd.pid" ] \
+               && SSHD_OPTS="${SSHD_OPTS} -o PidFile=${SSHD_PIDFILE}"
+       [ "${SSHD_CONFDIR}" != "/etc/ssh" ] \
+               && SSHD_OPTS="${SSHD_OPTS} -f ${SSHD_CONFDIR}/sshd_config"
+
+       "${SSHD_BINARY}" -t ${SSHD_OPTS} || return 1
+}
+
+gen_key() {
+       local type=$1 key ks
+       [ $# -eq 1 ] && ks="${type}_"
+       key="${SSHD_CONFDIR}/ssh_host_${ks}key"
+       if [ ! -e "${key}" ] ; then
+               ebegin "Generating ${type} host key"
+               ssh-keygen -t ${type} -f "${key}" -N ''
+               eend $? || return $?
+       fi
+}
+
+gen_keys() {
+       if egrep -q '^[[:space:]]*Protocol[[:space:]]+.*1' "${SSHD_CONFDIR}"/sshd_config ; then
+               gen_key rsa1 "" || return 1
+       fi
+       gen_key dsa && gen_key rsa && gen_key ecdsa
+       return $?
+}
+
+start() {
+       checkconfig || return 1
+
+       ebegin "Starting ${SVCNAME}"
+       start-stop-daemon --start --exec "${SSHD_BINARY}" \
+           --pidfile "${SSHD_PIDFILE}" \
+           -- ${SSHD_OPTS}
+       eend $?
+}
+
+stop() {
+       if [ "${RC_CMD}" = "restart" ] ; then
+               checkconfig || return 1
+       fi
+
+       ebegin "Stopping ${SVCNAME}"
+       start-stop-daemon --stop --exec "${SSHD_BINARY}" \
+           --pidfile "${SSHD_PIDFILE}" --quiet
+       eend $?
+}
+
+reload() {
+       checkconfig || return 1
+       ebegin "Reloading ${SVCNAME}"
+       start-stop-daemon --stop --signal HUP \
+           --exec "${SSHD_BINARY}" --pidfile "${SSHD_PIDFILE}"
+       eend $?
+}
diff --git a/net-misc/openssh/openssh-5.9_p1.ebuild b/net-misc/openssh/openssh-5.9_p1.ebuild
new file mode 100644 (file)
index 0000000..92ebf54
--- /dev/null
@@ -0,0 +1,257 @@
+# Copyright 1999-2011 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+# $Header: /var/cvsroot/gentoo-x86/net-misc/openssh/openssh-5.9_p1.ebuild,v 1.1 2011/09/07 01:38:46 vapier Exp $
+
+EAPI="2"
+inherit eutils flag-o-matic multilib autotools pam
+
+# Make it more portable between straight releases
+# and _p? releases.
+PARCH=${P/_}
+
+HPN_PATCH="${PARCH}-hpn13v11.diff.bz2"
+#LDAP_PATCH="${PARCH/-/-lpk-}-0.3.14.patch.gz"
+#X509_VER="7.0" X509_PATCH="${PARCH}+x509-${X509_VER}.diff.gz"
+
+DESCRIPTION="Port of OpenBSD's free SSH release"
+HOMEPAGE="http://www.openssh.org/"
+SRC_URI="mirror://openbsd/OpenSSH/portable/${PARCH}.tar.gz
+       ${HPN_PATCH:+hpn? ( http://www.psc.edu/networking/projects/hpn-ssh/${HPN_PATCH} mirror://gentoo/${HPN_PATCH} )}
+       ${LDAP_PATCH:+ldap? ( mirror://gentoo/${LDAP_PATCH} )}
+       ${X509_PATCH:+X509? ( http://roumenpetrov.info/openssh/x509-${X509_VER}/${X509_PATCH} )}
+       "
+
+LICENSE="as-is"
+SLOT="0"
+#KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~x86 ~sparc-fbsd ~x86-fbsd"
+IUSE="${HPN_PATCH:++}hpn kerberos ldap libedit pam selinux skey static tcpd X X509"
+
+RDEPEND="pam? ( virtual/pam )
+       kerberos? ( virtual/krb5 )
+       selinux? ( >=sys-libs/libselinux-1.28 )
+       skey? ( >=sys-auth/skey-1.1.5-r1 )
+       ldap? ( net-nds/openldap )
+       libedit? ( dev-libs/libedit )
+       >=dev-libs/openssl-0.9.6d
+       >=sys-libs/zlib-1.2.3
+       tcpd? ( >=sys-apps/tcp-wrappers-7.6 )
+       X? ( x11-apps/xauth )
+       userland_GNU? ( sys-apps/shadow )"
+DEPEND="${RDEPEND}
+       dev-util/pkgconfig
+       virtual/os-headers
+       sys-devel/autoconf"
+RDEPEND="${RDEPEND}
+       pam? ( >=sys-auth/pambase-20081028 )"
+
+S=${WORKDIR}/${PARCH}
+
+pkg_setup() {
+       # this sucks, but i'd rather have people unable to `emerge -u openssh`
+       # than not be able to log in to their server any more
+       maybe_fail() { [[ -z ${!2} ]] && echo ${1} ; }
+       local fail="
+               $(use X509 && maybe_fail X509 X509_PATCH)
+               $(use ldap && maybe_fail ldap LDAP_PATCH)
+               $(use hpn && maybe_fail hpn HPN_PATCH)
+       "
+       fail=$(echo ${fail})
+       if [[ -n ${fail} ]] ; then
+               eerror "Sorry, but this version does not yet support features"
+               eerror "that you requested:      ${fail}"
+               eerror "Please mask ${PF} for now and check back later:"
+               eerror " # echo '=${CATEGORY}/${PF}' >> /etc/portage/package.mask"
+               die "booooo"
+       fi
+}
+
+src_prepare() {
+       sed -i \
+               -e '/_PATH_XAUTH/s:/usr/X11R6/bin/xauth:/usr/bin/xauth:' \
+               pathnames.h || die
+       # keep this as we need it to avoid the conflict between LPK and HPN changing
+       # this file.
+       cp version.h version.h.pristine
+
+       if use X509 ; then
+               epatch "${WORKDIR}"/${X509_PATCH%.*}
+               epatch "${FILESDIR}"/${PN}-5.8_p1-x509-hpn-glue.patch
+       fi
+       if ! use X509 ; then
+               if [[ -n ${LDAP_PATCH} ]] && use ldap ; then
+                       epatch "${WORKDIR}"/${LDAP_PATCH%.*}
+                       #epatch "${FILESDIR}"/${PN}-5.2p1-ldap-stdargs.diff #266654 - merged
+                       # version.h patch conflict avoidence
+                       mv version.h version.h.lpk
+                       cp -f version.h.pristine version.h
+               fi
+       else
+               use ldap && ewarn "Sorry, X509 and LDAP conflict internally, disabling LDAP"
+       fi
+       epatch "${FILESDIR}"/${PN}-5.9_p1-sshd-gssapi-multihomed.patch #378361
+       epatch "${FILESDIR}"/${PN}-4.7_p1-GSSAPI-dns.patch #165444 integrated into gsskex
+       if [[ -n ${HPN_PATCH} ]] && use hpn; then
+               epatch "${WORKDIR}"/${HPN_PATCH%.*}
+               epatch "${FILESDIR}"/${PN}-5.6_p1-hpn-progressmeter.patch
+               # version.h patch conflict avoidence
+               mv version.h version.h.hpn
+               cp -f version.h.pristine version.h
+               # The AES-CTR multithreaded variant is broken, and causes random hangs
+               # when combined background threading and control sockets. To avoid
+               # this, we change the internal table to use the non-multithread version
+               # for the meantime. Do NOT remove this in new versions. See bug #354113
+               # comment #6 for testcase.
+               # Upstream reference: http://www.psc.edu/networking/projects/hpn-ssh/
+               ## Additionally, the MT-AES-CTR mode cipher replaces the default ST-AES-CTR mode
+               ## cipher. Be aware that if the client process is forked using the -f command line
+               ## option the process will hang as the parent thread gets 'divorced' from the key
+               ## generation threads. This issue will be resolved as soon as possible
+               sed -i \
+                       -e '/aes...-ctr.*SSH_CIPHER_SSH2/s,evp_aes_ctr_mt,evp_aes_128_ctr,' \
+                       cipher.c || die
+       fi
+
+       sed -i "s:-lcrypto:$(pkg-config --libs openssl):" configure{,.ac} || die
+
+       # Disable PATH reset, trust what portage gives us. bug 254615
+       sed -i -e 's:^PATH=/:#PATH=/:' configure || die
+
+       # Now we can build a sane merged version.h
+       (
+               sed '/^#define SSH_RELEASE/d' version.h.* | sort -u
+               printf '#define SSH_RELEASE SSH_VERSION SSH_PORTABLE %s %s\n' \
+                       "$([ -e version.h.hpn ] && echo SSH_HPN)" \
+                       "$([ -e version.h.lpk ] && echo SSH_LPK)"
+       ) > version.h
+
+       eautoreconf
+}
+
+static_use_with() {
+       local flag=$1
+       if use static && use ${flag} ; then
+               ewarn "Disabling '${flag}' support because of USE='static'"
+               # rebuild args so that we invert the first one (USE flag)
+               # but otherwise leave everything else working so we can
+               # just leverage use_with
+               shift
+               [[ -z $1 ]] && flag="${flag} ${flag}"
+               set -- !${flag} "$@"
+       fi
+       use_with "$@"
+}
+
+src_configure() {
+       addwrite /dev/ptmx
+       addpredict /etc/skey/skeykeys #skey configure code triggers this
+
+       use static && append-ldflags -static
+
+       econf \
+               --with-ldflags="${LDFLAGS}" \
+               --disable-strip \
+               --sysconfdir=/etc/ssh \
+               --libexecdir=/usr/$(get_libdir)/misc \
+               --datadir=/usr/share/openssh \
+               --with-privsep-path=/var/empty \
+               --with-privsep-user=sshd \
+               --with-md5-passwords \
+               --with-ssl-engine \
+               $(static_use_with pam) \
+               $(static_use_with kerberos kerberos5 /usr) \
+               ${LDAP_PATCH:+$(use X509 || ( use ldap && use_with ldap ))} \
+               $(use_with libedit) \
+               $(use_with selinux) \
+               $(use_with skey) \
+               $(use_with tcpd tcp-wrappers)
+}
+
+src_install() {
+       emake install-nokeys DESTDIR="${D}" || die
+       fperms 600 /etc/ssh/sshd_config
+       dobin contrib/ssh-copy-id || die
+       newinitd "${FILESDIR}"/sshd.rc6.3 sshd
+       newconfd "${FILESDIR}"/sshd.confd sshd
+       keepdir /var/empty
+
+       # not all openssl installs support ecc, or are functional #352645
+       if ! grep -q '#define OPENSSL_HAS_ECC 1' config.h ; then
+               dosed 's:&& gen_key ecdsa::' /etc/init.d/sshd || die
+       fi
+
+       newpamd "${FILESDIR}"/sshd.pam_include.2 sshd
+       if use pam ; then
+               sed -i \
+                       -e "/^#UsePAM /s:.*:UsePAM yes:" \
+                       -e "/^#PasswordAuthentication /s:.*:PasswordAuthentication no:" \
+                       -e "/^#PrintMotd /s:.*:PrintMotd no:" \
+                       -e "/^#PrintLastLog /s:.*:PrintLastLog no:" \
+                       "${D}"/etc/ssh/sshd_config || die "sed of configuration file failed"
+       fi
+
+       # This instruction is from the HPN webpage,
+       # Used for the server logging functionality
+       if [[ -n ${HPN_PATCH} ]] && use hpn ; then
+               keepdir /var/empty/dev
+       fi
+
+       doman contrib/ssh-copy-id.1
+       dodoc ChangeLog CREDITS OVERVIEW README* TODO sshd_config
+
+       diropts -m 0700
+       dodir /etc/skel/.ssh
+}
+
+src_test() {
+       local t tests skipped failed passed shell
+       tests="interop-tests compat-tests"
+       skipped=""
+       shell=$(getent passwd ${UID} | cut -d: -f7)
+       if [[ ${shell} == */nologin ]] || [[ ${shell} == */false ]] ; then
+               elog "Running the full OpenSSH testsuite"
+               elog "requires a usable shell for the 'portage'"
+               elog "user, so we will run a subset only."
+               skipped="${skipped} tests"
+       else
+               tests="${tests} tests"
+       fi
+       for t in ${tests} ; do
+               # Some tests read from stdin ...
+               emake -k -j1 ${t} </dev/null \
+                       && passed="${passed}${t} " \
+                       || failed="${failed}${t} "
+       done
+       einfo "Passed tests: ${passed}"
+       ewarn "Skipped tests: ${skipped}"
+       if [[ -n ${failed} ]] ; then
+               ewarn "Failed tests: ${failed}"
+               die "Some tests failed: ${failed}"
+       else
+               einfo "Failed tests: ${failed}"
+               return 0
+       fi
+}
+
+pkg_postinst() {
+       enewgroup sshd 22
+       enewuser sshd 22 -1 /var/empty sshd
+
+       elog "Starting with openssh-5.8p1, the server will default to a newer key"
+       elog "algorithm (ECDSA).  You are encouraged to manually update your stored"
+       elog "keys list as servers update theirs.  See ssh-keyscan(1) for more info."
+       echo
+       ewarn "Remember to merge your config files in /etc/ssh/ and then"
+       ewarn "reload sshd: '/etc/init.d/sshd reload'."
+       if use pam ; then
+               echo
+               ewarn "Please be aware users need a valid shell in /etc/passwd"
+               ewarn "in order to be allowed to login."
+       fi
+       # This instruction is from the HPN webpage,
+       # Used for the server logging functionality
+       if [[ -n ${HPN_PATCH} ]] && use hpn ; then
+               echo
+               einfo "For the HPN server logging patch, you must ensure that"
+               einfo "your syslog application also listens at /var/empty/dev/log."
+       fi
+}