Add cups-1.2.12-r5.ebuild to fix security issue CVE-2008-0882, see bug #211449.Remove...
authorTimo Gurr <tgurr@gentoo.org>
Thu, 28 Feb 2008 20:24:49 +0000 (20:24 +0000)
committerTimo Gurr <tgurr@gentoo.org>
Thu, 28 Feb 2008 20:24:49 +0000 (20:24 +0000)
Package-Manager: portage-2.1.4.4

12 files changed:
net-print/cups/ChangeLog
net-print/cups/Manifest
net-print/cups/cups-1.2.12-r4.ebuild
net-print/cups/cups-1.2.12-r5.ebuild [moved from net-print/cups/cups-1.2.10-r1.ebuild with 77% similarity]
net-print/cups/cups-1.3.5.ebuild [deleted file]
net-print/cups/cups-1.3.6-r1.ebuild [moved from net-print/cups/cups-1.3.6.ebuild with 96% similarity]
net-print/cups/files/cups-1.2.12-CVE-2007-4045.patch [moved from net-print/cups/files/cups-1.2.4-CVE-2007-4045.patch with 100% similarity]
net-print/cups/files/cups-1.2.12-CVE-2007-4351.patch [moved from net-print/cups/files/cups-1.2-str2561-v2.patch with 100% similarity]
net-print/cups/files/cups-1.2.12-CVE-2008-0882.patch [new file with mode: 0644]
net-print/cups/files/cups-1.3.0-bindnow.patch [deleted file]
net-print/cups/files/cups-1.3.4-CVE-2007-4045.patch [deleted file]
net-print/cups/files/pdftops.pl [deleted file]

index 0f1d73b7720c6acec3a5ebd09271a32f72dba15b..ca70056d52bf71a325b1c32a0d1eac8991f56011 100644 (file)
@@ -1,6 +1,21 @@
 # ChangeLog for net-print/cups
 # Copyright 1999-2008 Gentoo Foundation; Distributed under the GPL v2
-# $Header: /var/cvsroot/gentoo-x86/net-print/cups/ChangeLog,v 1.281 2008/02/22 18:13:58 tgurr Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-print/cups/ChangeLog,v 1.282 2008/02/28 20:24:49 tgurr Exp $
+
+*cups-1.3.6-r1 (28 Feb 2008)
+*cups-1.2.12-r5 (28 Feb 2008)
+
+  28 Feb 2008; Timo Gurr <tgurr@gentoo.org>
+  -files/cups-1.2.4-CVE-2007-4045.patch, -files/cups-1.2-str2561-v2.patch,
+  +files/cups-1.2.12-CVE-2007-4045.patch,
+  +files/cups-1.2.12-CVE-2007-4351.patch,
+  +files/cups-1.2.12-CVE-2008-0882.patch, -files/cups-1.3.0-bindnow.patch,
+  -files/cups-1.3.4-CVE-2007-4045.patch, -files/pdftops.pl,
+  -cups-1.2.10-r1.ebuild, cups-1.2.12-r4.ebuild, +cups-1.2.12-r5.ebuild,
+  -cups-1.3.5.ebuild, -cups-1.3.6.ebuild, +cups-1.3.6-r1.ebuild:
+  Add cups-1.2.12-r5.ebuild to fix security issue CVE-2008-0882, see bug
+  #211449.Remove older vulnerable versions. Rename patches for better
+  versioning. Minor ebuild cleanups.
 
 *cups-1.3.6 (22 Feb 2008)
 
index 6eed1e86955b6e623d8152048b3cd11de17b530d..605619858346d7787a8e42efe3d365df321467b3 100644 (file)
@@ -1,21 +1,16 @@
-AUX cups-1.2-str2561-v2.patch 3910 RMD160 461a232b2a0ebc52a83cb729112c0f7d3f3d0ffe SHA1 9b7706a34fd08c32b7911a9f09f02a02c790a77c SHA256 1da64de6358dea65971105530795ffb8d100ddfe5b42c03cdbd815432de219c8
 AUX cups-1.2.0-bindnow.patch 2178 RMD160 cdf51a6734c7a38fab33f270c7c374445a934321 SHA1 5406422e6b92c571f636d521baee354f84fafc2d SHA256 0fffd86557fdfbf85e32781d1b77f9696e5f0ed7eb30a78fb57ca82cfafdc190
+AUX cups-1.2.12-CVE-2007-4045.patch 1737 RMD160 6c239b26443af6cf841a457cc5611a2f78d809c3 SHA1 02c2bd1bf58204fd9e1b380f8899dae2f98c2fed SHA256 0e4898b7e42f74f894b416a1398d75bcf6062497a87e061984f09e904f68489e
+AUX cups-1.2.12-CVE-2007-4351.patch 3910 RMD160 461a232b2a0ebc52a83cb729112c0f7d3f3d0ffe SHA1 9b7706a34fd08c32b7911a9f09f02a02c790a77c SHA256 1da64de6358dea65971105530795ffb8d100ddfe5b42c03cdbd815432de219c8
 AUX cups-1.2.12-CVE-2007-5849.patch 1017 RMD160 0fd58946d8cfca13460ad07bfde670a3319fe1ff SHA1 4c4cb69d857427de43b5b91b5aceb7cb157be530 SHA256 9288292457f8c8de77b04eab651b547dd6506a03453ed93294577e2fb4f3c67b
-AUX cups-1.2.4-CVE-2007-4045.patch 1737 RMD160 6c239b26443af6cf841a457cc5611a2f78d809c3 SHA1 02c2bd1bf58204fd9e1b380f8899dae2f98c2fed SHA256 0e4898b7e42f74f894b416a1398d75bcf6062497a87e061984f09e904f68489e
-AUX cups-1.3.0-bindnow.patch 1919 RMD160 8ee1c27c0236b64df1cfc2a71f59370137768cc1 SHA1 16151a09d7b4a1fc431987191bdb09b92dd9631b SHA256 871d92fb8c6f658d1035a3ff058b5186131dfe295f54ecdcd4bc630b517eee4b
+AUX cups-1.2.12-CVE-2008-0882.patch 1090 RMD160 f6de4e0a4ebcb70f4969cbcb2cba38e5a98366c5 SHA1 3c834957b3fb625cdde4a0c21e5916c6a8c1667f SHA256 9168456e294e1ca30868580028ab79d68d31aaf208687f80699e3e30f3ad77e6
 AUX cups-1.3.0-configure.patch 651 RMD160 e4c7f45d7ddc28157433bf025c7f946c7e3b6d6a SHA1 101bf1893b56640d9fa82078e29319fbbd1449c7 SHA256 d6e5e60a982a3c093c0d0f89cf865e2b4c36290f5b1e188b7bf305d210070736
-AUX cups-1.3.4-CVE-2007-4045.patch 1276 RMD160 4aa328e6c0b30e58cfbf7b645380c147dc20dfd4 SHA1 4595ade2f84a2f868a4735a3ce2e1761e26b0ff4 SHA256 10023e221c1a59263b44d13649a26afbeb7d3e84a52b1c7ab25116eaae92811d
 AUX cupsd.init 288 RMD160 9bd676af5b43a97ba08ca51f70cefb445faeb8b8 SHA1 922868e1a6acb81b83e87a3c6905149789f16503 SHA256 008eeadc4979ad0e1f05e8ce5d22449eb798375e75ffc3176cbef138a53de4f9
 AUX cupsd.init.d 293 RMD160 19fbef21cee7e472e7028f3101b680baa0089c54 SHA1 e6b27b2638fec258fe2f55c926c2530e909ca3d2 SHA256 b4268a6bae95e96b6af21c3716ecc905073736ce7dc33be1489d574a447f3c48
 AUX pdftops-1.20.gentoo 10412 RMD160 16e229662c47e03af1d1f4cb5764a76d17a66642 SHA1 6afb8a655b6ff013a2c8c8cbfb615ba1e561503b SHA256 ac5fa01ca776d75bd7cef62eef9f6b0c3945ee87e8950b40ca9f9f3ff46a16c1
-AUX pdftops.pl 5552 RMD160 8c73e4a5bb5ae5a7eafb59b25ec483279dad90d4 SHA1 9c57044a5e1c716fb4b6cdb70d827c35bc0e82c1 SHA256 aeaca40973d4a4df2212e73820f96272923e23717a69b0bf738896a5fc04df25
-DIST cups-1.2.10-source.tar.bz2 3618084 RMD160 85b3bbd46a6fc097891c571ffad8e5e46693743f SHA1 241d7a3c52370fb08ed2ffc3fd8f59673d158299 SHA256 601b3b9256c55361477427c3e8db56c9ee4e141762814aea590bcf110a95bb36
 DIST cups-1.2.12-source.tar.bz2 3788301 RMD160 598270e37ff8a9b9ff1e667066d6f7e120493e32 SHA1 11a540f76a1d3164b6636bf8ba47928803ad9356 SHA256 b4ff8e934da7db32d5654360ea9068faa0ed5a00fde02161ae53c2052510d00f
-DIST cups-1.3.5-source.tar.bz2 4082098 RMD160 c6157e552e833447e623175a4e90146ceb9d9ba4 SHA1 f0f7674b46e00582f327765acd4133a6035d393e SHA256 3a8ef866ffe2d5aac6a601770d27cfefec3ba40e19b1550ca4c1eb1ab27f19d1
 DIST cups-1.3.6-source.tar.bz2 4079258 RMD160 1da6420f473562eba27e1e997e13d60e0ea101a8 SHA1 4f7ed1c2b16db46f945ab113beab8aeaecbca0b9 SHA256 b4003862daffd6887a52cf66a67a21854c1ecda15698bf44b2fe1fc12a833695
-EBUILD cups-1.2.10-r1.ebuild 6348 RMD160 5de50c4fc60398e9c5d15564e11da91b04eeb8dd SHA1 14fe4110363be2772b0088dc341aafae2a2d9568 SHA256 bb463b251d9a6131dfc2d926de59abccc18a1b04dcacef401ea616d1ea23ff61
-EBUILD cups-1.2.12-r4.ebuild 7107 RMD160 c3441cae5322936b013eec7d931babcdfe93a725 SHA1 94b6a1f27a566cb1213f6f69a8c08b3e2bfb5b11 SHA256 beac8389a1798ead8be7e2594842a95181961e641948cdc426ef544a5e691d8a
-EBUILD cups-1.3.5.ebuild 8180 RMD160 c29eccb692f4b9064ff275c310526c7574eea17f SHA1 b2e3481cc0a74c53ede976ed96c06f5cfa9d5dcb SHA256 7693bbafa966b8ad342be1201328f567836ed6a7222574ff2fba9c54978d6986
-EBUILD cups-1.3.6.ebuild 8048 RMD160 f38cba97edf437fc75106f1725e879b6594a047b SHA1 859fd6c5c941508a8266ce1e45c9180d6c6e0ee4 SHA256 6daf0906d04a497d1eb874b631c3d699907ebd92d8e2557d075745bf510cd7ce
-MISC ChangeLog 40401 RMD160 2479c4557068c0532d350bb163bc2ee3792cbb8e SHA1 b4575051e8e2847df8d6310c8e15bd6dc74981e8 SHA256 bb46b6dc3da4b2dbe026db5a9c6dcea8ed9fa392fc08780df574053d395da87e
+EBUILD cups-1.2.12-r4.ebuild 7113 RMD160 992518b586d5212e04fcff686cd537d858df1b71 SHA1 624a3559fb603c57aceb1805ef212a6807daf567 SHA256 ffb0514c243014229cfefdcee5102e4d987526b57fb134e4a55dc3ea84ca9ba8
+EBUILD cups-1.2.12-r5.ebuild 7064 RMD160 1fabc27c7fa0cf200c4d80b77c485dfe7604740b SHA1 e1e2451bb086aaff5a2700392928e729b7784bcb SHA256 a95f4514eb255ab531e5cc62e10fe17a16fbb9dbf8d58e84ac7af696199cd0b9
+EBUILD cups-1.3.6-r1.ebuild 8001 RMD160 1e197d8aa903dccd45842c2440bb8043e50fc467 SHA1 ea7c1c99842520426113e9e271b26cb85a25445e SHA256 e1e633dfd00a9664efd42d52ec7b0f05556968ea2d4a3fba809263ada1b27d34
+MISC ChangeLog 41118 RMD160 5625c11d749641a98e3d524d50133bdd31ea3b29 SHA1 9c76ed708e10fe4d713d19c16eef6d3649d6d246 SHA256 8182a9cf3ec401d74b50eefba233ea748d4c06356535b8349203a1ad076ee318
 MISC metadata.xml 161 RMD160 1e5b1e42553c8869b93c4a5448e9a2a2ed9fe525 SHA1 209c6a46e4cdd891980115e42ba419e3799f8088 SHA256 7c85e6739a71f5bb23e8de36c88677d772946e61f7285892f7554e37bd2bca76
index 6644a0c27195011c4aa420e2aa041f6ad541c4e5..d2fa314269235651518e6b44dfbeb765142fccbc 100644 (file)
@@ -1,6 +1,6 @@
 # Copyright 1999-2008 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.12-r4.ebuild,v 1.3 2008/01/10 09:04:24 vapier Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.12-r4.ebuild,v 1.4 2008/02/28 20:24:49 tgurr Exp $
 
 WANT_AUTOMAKE=latest
 
@@ -84,10 +84,10 @@ src_unpack() {
        # upstream does not acknowledge bindnow as a solution
        epatch "${FILESDIR}"/cups-1.2.0-bindnow.patch
 
-       # CVE-2007-4351 security patch, bug #196736
-       epatch "${FILESDIR}"/${PN}-1.2-str2561-v2.patch
        # CVE-2007-4045 security patch, bug #199195
-       epatch "${FILESDIR}"/${PN}-1.2.4-CVE-2007-4045.patch
+       epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4045.patch
+       # CVE-2007-4351 security patch, bug #196736
+       epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4351.patch
        # CVE-2007-5849 security patch, bug #201570
        epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-5849.patch
 
similarity index 77%
rename from net-print/cups/cups-1.2.10-r1.ebuild
rename to net-print/cups/cups-1.2.12-r5.ebuild
index 1a26e80e402f3db78714b6a79d2b1cf5e5cf5e43..4f3d54165b21cff12ab1a223a00be928e7b53189 100644 (file)
@@ -1,8 +1,6 @@
 # Copyright 1999-2008 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.10-r1.ebuild,v 1.13 2008/02/22 18:13:58 tgurr Exp $
-
-WANT_AUTOMAKE=latest
+# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.2.12-r5.ebuild,v 1.1 2008/02/28 20:24:49 tgurr Exp $
 
 inherit autotools eutils flag-o-matic multilib pam
 
@@ -10,12 +8,11 @@ MY_P=${P/_}
 
 DESCRIPTION="The Common Unix Printing System"
 HOMEPAGE="http://www.cups.org/"
-SRC_URI="http://ftp.funet.fi/pub/mirrors/ftp.easysw.com/pub/cups/${PV}/${MY_P}-source.tar.bz2"
-#ESVN_REPO_URI="http://svn.easysw.com/public/cups/trunk"
+SRC_URI="mirror://sourceforge/cups/${MY_P}-source.tar.bz2"
 
 LICENSE="GPL-2"
 SLOT="0"
-KEYWORDS="alpha amd64 arm hppa ia64 m68k ~mips ppc ppc64 s390 sh sparc x86 ~x86-fbsd"
+KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~sparc-fbsd ~x86 ~x86-fbsd"
 IUSE="ldap ssl slp pam php samba nls dbus tiff png ppds jpeg X"
 
 DEP="pam? ( virtual/pam )
@@ -60,9 +57,18 @@ PROVIDE="virtual/lpr"
 # we just leave it out, even if FEATURES=test
 RESTRICT="test"
 
-S="${WORKDIR}/${MY_P}"
+S=${WORKDIR}/${MY_P}
 
 pkg_setup() {
+       if use x86 && [ -d "/usr/lib64" ]
+       then
+               eerror "You are running an x86 system, but /usr/lib64 exists, cups will install all library objects into this directory!"
+               eerror "You should remove /usr/lib64, but before you do, you should check for existing objects, and re-compile all affected packages."
+               eerror "You can use qfile (emerge portage-utils to install qfile) to get a list of the affected ebuilds:"
+               eerror "# qfile -qC /usr/lib64"
+               die "lib64 on x86 detected"
+       fi
+
        enewgroup lp
        enewuser lp -1 -1 -1 lp
 
@@ -73,8 +79,14 @@ src_unpack() {
        unpack ${A}
        cd "${S}"
 
-       # upstream does not acknowledge bindnow as a solution
-       epatch "${FILESDIR}"/cups-1.2.0-bindnow.patch
+       # CVE-2007-4045 security patch, bug #199195
+       epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4045.patch
+       # CVE-2007-4351 security patch, bug #196736
+       epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-4351.patch
+       # CVE-2007-5849 security patch, bug #201570
+       epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2007-5849.patch
+       # CVE-2008-0882 security patch, bug #211449
+       epatch "${FILESDIR}"/${PN}-1.2.12-CVE-2008-0882.patch
 
        # cups does not use autotools "the usual way" and ship a static config.h.in
        eaclocal
@@ -83,13 +95,17 @@ src_unpack() {
 
 src_compile() {
        export DSOFLAGS="${LDFLAGS}"
+
+       if use ldap; then
+               append-flags -DLDAP_DEPRECATED
+       fi
+
        econf \
                --with-cups-user=lp \
                --with-cups-group=lp \
                --with-system-groups=lpadmin \
                --localstatedir=/var \
                --with-docdir=/usr/share/cups/html \
-               --with-bindnow=$(bindnow-flags) \
                $(use_enable pam) \
                $(use_enable ssl) \
                --enable-gnutls \
@@ -135,7 +151,7 @@ src_install() {
 
        # install pdftops filter
        exeinto /usr/libexec/cups/filter/
-       newexe "${FILESDIR}"/pdftops.pl pdftops
+       newexe "${FILESDIR}"/pdftops-1.20.gentoo pdftops
 
        # only for gs-esp this is correct, see bug 163897
        if has_version app-text/ghostscript-gpl || has_version app-text/ghostscript-gnu; then
@@ -159,18 +175,20 @@ src_install() {
 
 pkg_preinst() {
        # cleanups
-       [ -n "${PN}" ] && rm -fR "${ROOT}"/usr/share/doc/"${PN}"-*
+       [ -n "${PN}" ] && rm -fR "${ROOT}"/usr/share/doc/${PN}-*
 }
 
 pkg_postinst() {
-       einfo "Remote printing: change "
-       einfo "Listen localhost:631"
-       einfo "to"
-       einfo "Listen *:631"
-       einfo "in /etc/cups/cupsd.conf"
-       einfo
-       einfo "For more information about installing a printer take a look at:"
-       einfo "http://www.gentoo.org/doc/en/printing-howto.xml."
+       echo
+       elog "Remote printing: change "
+       elog "Listen localhost:631"
+       elog "to"
+       elog "Listen *:631"
+       elog "in /etc/cups/cupsd.conf"
+       echo
+       elog "For more information about installing a printer take a look at:"
+       elog "http://www.gentoo.org/doc/en/printing-howto.xml."
+       echo
 
        local good_gs=false
        for x in app-text/ghostscript-gpl app-text/ghostscript-gnu app-text/ghostscript-esp; do
diff --git a/net-print/cups/cups-1.3.5.ebuild b/net-print/cups/cups-1.3.5.ebuild
deleted file mode 100644 (file)
index de35e52..0000000
+++ /dev/null
@@ -1,280 +0,0 @@
-# Copyright 1999-2007 Gentoo Foundation
-# Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.3.5.ebuild,v 1.2 2007/12/26 16:55:59 cardoe Exp $
-
-inherit autotools eutils flag-o-matic multilib pam
-
-MY_P=${P/_}
-
-DESCRIPTION="The Common Unix Printing System"
-HOMEPAGE="http://www.cups.org/"
-SRC_URI="mirror://sourceforge/cups/${MY_P}-source.tar.bz2"
-
-LICENSE="GPL-2"
-SLOT="0"
-KEYWORDS="~alpha ~amd64 ~arm ~hppa ~ia64 ~m68k ~mips ~ppc ~ppc64 ~s390 ~sh ~sparc ~sparc-fbsd ~x86 ~x86-fbsd"
-IUSE="acl avahi dbus java jpeg kerberos ldap nls pam perl php png ppds python samba slp ssl static tiff X zeroconf"
-
-COMMON_DEPEND="acl? ( kernel_linux? ( sys-apps/acl sys-apps/attr ) )
-       avahi? ( net-dns/avahi )
-       dbus? ( sys-apps/dbus )
-       java? ( >=virtual/jre-1.4 )
-       jpeg? ( >=media-libs/jpeg-6b )
-       kerberos? ( virtual/krb5 )
-       ldap? ( net-nds/openldap )
-       pam? ( virtual/pam )
-       perl? ( dev-lang/perl )
-       php? ( dev-lang/php )
-       png? ( >=media-libs/libpng-1.2.1 )
-       python? ( dev-lang/python )
-       slp? ( >=net-libs/openslp-1.0.4 )
-       ssl? ( net-libs/gnutls )
-       tiff? ( >=media-libs/tiff-3.5.5 )
-       zeroconf? ( !avahi? ( net-misc/mDNSResponder ) )
-       app-text/libpaper
-       dev-libs/libgcrypt"
-
-DEPEND="${COMMON_DEPEND}
-       !<net-print/foomatic-filters-ppds-20070501
-       !<net-print/hplip-1.7.4a-r1
-       nls? ( sys-devel/gettext )"
-
-RDEPEND="${COMMON_DEPEND}
-       !virtual/lpr
-       nls? ( virtual/libintl )
-       X? ( x11-misc/xdg-utils )
-       >=app-text/poppler-0.4.3-r1"
-
-PDEPEND="
-       ppds? ( || (
-               (
-                       net-print/foomatic-filters-ppds
-                       net-print/foomatic-db-ppds
-               )
-               net-print/foomatic-filters-ppds
-               net-print/foomatic-db-ppds
-               net-print/hplip
-               media-gfx/gimp-print
-               net-print/foo2zjs
-               net-print/cups-pdf
-       ) )
-       samba? ( >=net-fs/samba-3.0.8 )
-       virtual/ghostscript"
-
-PROVIDE="virtual/lpr"
-
-# upstream includes an interactive test which is a nono for gentoo.
-# therefore, since the printing herd has bigger fish to fry, for now,
-# we just leave it out, even if FEATURES=test
-RESTRICT="test"
-
-S="${WORKDIR}/${MY_P}"
-
-LANGS="de en es et fr he it ja pl sv zh_TW"
-for X in ${LANGS} ; do
-       IUSE="${IUSE} linguas_${X}"
-done
-
-pkg_setup() {
-       if use avahi && ! built_with_use net-dns/avahi mdnsresponder-compat ; then
-               echo
-               eerror "In order to have cups working with avahi zeroconf support, you need"
-               eerror "to have net-dns/avahi emerged with 'mdnsresponder-compat' in your USE"
-               eerror "flag. Please add that flag, re-emerge avahi, and then emerge cups again."
-               die "net-dns/avahi is missing the mdnsresponder-compat feature."
-       fi
-
-       enewgroup lp
-       enewuser lp -1 -1 -1 lp
-
-       enewgroup lpadmin 106
-}
-
-src_unpack() {
-       unpack ${A}
-       cd "${S}"
-
-       # upstream does not acknowledge bindnow as a solution
-       epatch "${FILESDIR}/${PN}-1.3.0-bindnow.patch"
-
-       # disable configure automagic for acl/attr
-       epatch "${FILESDIR}/${PN}-1.3.0-configure.patch"
-
-       # CVE-2007-4045 security patch, bug #199195
-       epatch "${FILESDIR}/${PN}-1.3.4-CVE-2007-4045.patch"
-
-       # cups does not use autotools "the usual way" and ship a static config.h.in
-       eaclocal
-       eautoconf
-}
-
-src_compile() {
-
-       # locale support
-       strip-linguas ${LANGS}
-
-       if [ -z "${LINGUAS}" ] ; then
-               export LINGUAS=all
-       fi
-
-       export DSOFLAGS="${LDFLAGS}"
-
-       if use ldap; then
-               append-flags -DLDAP_DEPRECATED
-       fi
-
-       local myconf
-
-       if use avahi || use zeroconf ; then
-               myconf="${myconf} --enable-dnssd"
-       else
-               myconf="${myconf} --disable-dnssd"
-       fi
-
-       econf \
-               --libdir=/usr/$(get_libdir) \
-               --localstatedir=/var \
-               --with-bindnow=$(bindnow-flags) \
-               --with-cups-user=lp \
-               --with-cups-group=lp \
-               --with-docdir=/usr/share/cups/html \
-               --with-languages=${LINGUAS} \
-               --with-system-groups=lpadmin \
-               $(use_enable acl) \
-               $(use_enable dbus) \
-               $(use_enable jpeg) \
-               $(use_enable kerberos gssapi) \
-               $(use_enable ldap) \
-               $(use_enable nls) \
-               $(use_enable pam) \
-               $(use_enable png) \
-               $(use_enable slp) \
-               $(use_enable ssl) \
-               $(use_enable static) \
-               $(use_enable tiff) \
-               $(use_with java) \
-               $(use_with perl) \
-               $(use_with php) \
-               $(use_with python) \
-               --enable-gnutls \
-               --enable-libpaper \
-               --enable-threads \
-               --disable-pdftops \
-               ${myconf} \
-               || die "econf failed"
-
-       # install in /usr/libexec always, instead of using /usr/lib/cups, as that
-       # makes more sense when facing multilib support.
-       sed -i -e 's:SERVERBIN.*:SERVERBIN = "$(BUILDROOT)"/usr/libexec/cups:' Makedefs
-       sed -i -e 's:#define CUPS_SERVERBIN.*:#define CUPS_SERVERBIN "/usr/libexec/cups":' config.h
-       sed -i -e 's:cups_serverbin=.*:cups_serverbin=/usr/libexec/cups:' cups-config
-
-       emake || die "emake failed"
-}
-
-src_install() {
-       emake BUILDROOT="${D}" install || die "emake install failed"
-       dodoc {CHANGES{,-1.{0,1}},CREDITS,README}.txt || die "dodoc install failed"
-
-       # clean out cups init scripts
-       rm -rf "${D}"/etc/{init.d/cups,rc*,pam.d/cups}
-
-       # install our init script
-       local neededservices
-       use avahi && neededservices="$neededservices avahi-daemon"
-       use dbus && neededservices="$neededservices dbus"
-       use zeroconf && ! use avahi && neededservices="$neededservices mDNSResponderPosix"
-       [[ -n ${neededservices} ]] && neededservices="need${neededservices}"
-       sed -e "s/@neededservices@/$neededservices/" "${FILESDIR}"/cupsd.init.d > "${T}"/cupsd
-       doinitd "${T}"/cupsd
-
-       # install our pam script
-       pamd_mimic_system cups auth account
-
-       # correct path
-       sed -i -e "s:server = .*:server = /usr/libexec/cups/daemon/cups-lpd:" "${D}"/etc/xinetd.d/cups-lpd
-       # it is safer to disable this by default, bug 137130
-       grep -w 'disable' "${D}"/etc/xinetd.d/cups-lpd || \
-               sed -i -e "s:}:\tdisable = yes\n}:" "${D}"/etc/xinetd.d/cups-lpd
-
-       # install pdftops filter
-       exeinto /usr/libexec/cups/filter/
-       newexe "${FILESDIR}"/pdftops-1.20.gentoo pdftops
-
-       # only for gs-esp this is correct, see bug 163897
-       if has_version app-text/ghostscript-gpl || has_version app-text/ghostscript-gnu; then
-               sed -i -e "s:#application/vnd.cups-postscript:application/vnd.cups-postscript:" "${D}"/etc/cups/mime.convs
-       fi
-
-       keepdir /usr/share/cups/profiles /usr/libexec/cups/driver /var/log/cups \
-               /var/run/cups/certs /var/cache/cups /var/spool/cups/tmp /etc/cups/ssl
-
-       # .desktop handling. X useflag. xdg-open from freedesktop is preferred
-       if use X; then
-               sed -i -e "s:htmlview:xdg-open:" "${D}"/usr/share/applications/cups.desktop
-       else
-               rm -r "${D}"/usr/share/applications
-       fi
-
-       # fix a symlink collision, see bug #172341
-       dodir /usr/share/ppd
-       dosym /usr/share/ppd /usr/share/cups/model/foomatic-ppds
-
-       # create RSS feed directory
-       diropts -m 0740 -o lp -g lp
-       dodir /var/cache/cups/rss
-}
-
-pkg_preinst() {
-       # cleanups
-       [ -n "${PN}" ] && rm -fR "${ROOT}"/usr/share/doc/"${PN}"-*
-}
-
-pkg_postinst() {
-       echo
-       elog "For information about installing a printer and general cups setup"
-       elog "take a look at: http://www.gentoo.org/doc/en/printing-howto.xml"
-       echo
-
-       local good_gs=false
-       for x in app-text/ghostscript-gpl app-text/ghostscript-gnu app-text/ghostscript-esp; do
-               if has_version ${x} && built_with_use ${x} cups; then
-                       good_gs=true
-                       break
-               fi
-       done;
-       if ! ${good_gs}; then
-               echo
-               ewarn "You need to emerge ghostscript with the \"cups\" USE flag turned on"
-               echo
-       fi
-
-       if has_version =net-print/cups-1.1*; then
-               echo
-               ewarn "The configuration changed with cups-1.3, you may want to save the old"
-               ewarn "one and start from scratch:"
-               ewarn "# mv /etc/cups /etc/cups.orig; emerge -va1 cups"
-               echo
-               ewarn "You need to rebuild kdelibs for kdeprinter to work with cups-1.3"
-               echo
-       fi
-
-       if [ -e "${ROOT}"/usr/lib/cups ]; then
-               echo
-               ewarn "/usr/lib/cups exists - You need to remerge every ebuild that"
-               ewarn "installed into /usr/lib/cups and /etc/cups, qfile is in portage-utils:"
-               ewarn "# FEATURES=-collision-protect emerge -va1 \$(qfile -qC /usr/lib/cups /etc/cups | sed \"s:net-print/cups$::\")"
-               echo
-               ewarn "FEATURES=-collision-protect is needed to overwrite the compatibility"
-               ewarn "symlinks installed by this package, it won't be needed on later merges."
-               ewarn "You should also run revdep-rebuild"
-               echo
-
-               # place symlinks to make the update smoothless
-               for i in "${ROOT}"/usr/lib/cups/{backend,filter}/*; do
-                       if [ "${i/\*}" == "${i}" ] && ! [ -e ${i/lib/libexec} ]; then
-                               ln -s ${i} ${i/lib/libexec}
-                       fi
-               done
-       fi
-}
similarity index 96%
rename from net-print/cups/cups-1.3.6.ebuild
rename to net-print/cups/cups-1.3.6-r1.ebuild
index ce8da7d51c5deaf1ae02f73886d44900514764ad..39d6d10322422f52e2aab4271cfcc4dfee3ce61d 100644 (file)
@@ -1,6 +1,6 @@
 # Copyright 1999-2008 Gentoo Foundation
 # Distributed under the terms of the GNU General Public License v2
-# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.3.6.ebuild,v 1.1 2008/02/22 18:13:58 tgurr Exp $
+# $Header: /var/cvsroot/gentoo-x86/net-print/cups/cups-1.3.6-r1.ebuild,v 1.1 2008/02/28 20:24:49 tgurr Exp $
 
 inherit autotools eutils flag-o-matic multilib pam
 
@@ -94,12 +94,9 @@ src_unpack() {
        unpack ${A}
        cd "${S}"
 
-       # disable configure automagic for acl/attr
+       # disable configure automagic for acl/attr, upstream bug STR #2723.
        epatch "${FILESDIR}/${PN}-1.3.0-configure.patch"
 
-       # CVE-2007-4045 security patch, bug #199195
-       epatch "${FILESDIR}/${PN}-1.3.4-CVE-2007-4045.patch"
-
        # cups does not use autotools "the usual way" and ship a static config.h.in
        eaclocal
        eautoconf
@@ -205,7 +202,7 @@ src_install() {
        keepdir /usr/share/cups/profiles /usr/libexec/cups/driver /var/log/cups \
                /var/run/cups/certs /var/cache/cups /var/spool/cups/tmp /etc/cups/ssl
 
-       # .desktop handling. X useflag. xdg-open from freedesktop is preferred
+       # .desktop handling. X useflag. xdg-open from freedesktop is preferred, upstream bug STR #2724.
        if use X ; then
                sed -i -e "s:htmlview:xdg-open:" "${D}"/usr/share/applications/cups.desktop
        else
diff --git a/net-print/cups/files/cups-1.2.12-CVE-2008-0882.patch b/net-print/cups/files/cups-1.2.12-CVE-2008-0882.patch
new file mode 100644 (file)
index 0000000..655e70e
--- /dev/null
@@ -0,0 +1,28 @@
+diff -up cups-1.2.4/scheduler/dirsvc.c.str2656 cups-1.2.4/scheduler/dirsvc.c
+--- cups-1.2.4/scheduler/dirsvc.c.str2656      2008-02-21 13:33:06.000000000 +0000
++++ cups-1.2.4/scheduler/dirsvc.c      2008-02-21 13:33:49.000000000 +0000
+@@ -1943,9 +1943,9 @@ process_browse_data(
+     if (hptr && !*hptr)
+       *hptr = '.';                    /* Resource FQDN */
+ 
+-    if ((p = cupsdFindClass(name)) == NULL && BrowseShortNames)
++    if ((p = cupsdFindDest(name)) == NULL && BrowseShortNames)
+     {
+-      if ((p = cupsdFindClass(resource + 9)) != NULL)
++      if ((p = cupsdFindDest(resource + 9)) != NULL)
+       {
+         if (p->hostname && strcasecmp(p->hostname, host))
+       {
+@@ -2049,9 +2049,9 @@ process_browse_data(
+     if (hptr && !*hptr)
+       *hptr = '.';                    /* Resource FQDN */
+ 
+-    if ((p = cupsdFindPrinter(name)) == NULL && BrowseShortNames)
++    if ((p = cupsdFindDest(name)) == NULL && BrowseShortNames)
+     {
+-      if ((p = cupsdFindPrinter(resource + 10)) != NULL)
++      if ((p = cupsdFindDest(resource + 10)) != NULL)
+       {
+         if (p->hostname && strcasecmp(p->hostname, host))
+       {
+
diff --git a/net-print/cups/files/cups-1.3.0-bindnow.patch b/net-print/cups/files/cups-1.3.0-bindnow.patch
deleted file mode 100644 (file)
index aa97cd4..0000000
+++ /dev/null
@@ -1,47 +0,0 @@
-diff -Naur cups-1.3.0/config-scripts/cups-setXid.m4 cups-1.3.0/config-scripts/cups-setXid.m4.new
---- cups-1.3.0/config-scripts/cups-setXid.m4   1970-01-01 01:00:00.000000000 +0100
-+++ cups-1.3.0/config-scripts/cups-setXid.m4.new       2006-05-08 23:50:22.000000000 +0200
-@@ -0,0 +1,9 @@
-+dnl
-+dnl   Copyright 1999-2007 Gentoo Foundation
-+dnl   Distributed under the terms of the GNU General Public License v2
-+dnl
-+
-+AC_ARG_WITH(bindnow, [  --with-bindnow          Set linker flags for force-binding setuid binaries],
-+      BINDNOW_FLAGS="$withval",
-+      BINDNOW_FLAGS="")
-+AC_SUBST(BINDNOW_FLAGS)
-diff -Naur cups-1.3.0/configure.in cups-1.3.0/configure.in.new
---- cups-1.3.0/configure.in        2007-07-25 01:47:12.000000000 +0200
-+++ cups-1.3.0/configure.in.new    2007-08-15 10:31:58.896923749 +0200
-@@ -41,6 +41,7 @@
- sinclude(config-scripts/cups-pap.m4)
- sinclude(config-scripts/cups-pdf.m4)
- sinclude(config-scripts/cups-scripting.m4)
-+sinclude(config-scripts/cups-setXid.m4)
-
- INSTALL_LANGUAGES=""
- UNINSTALL_LANGUAGES=""
-diff -Naur cups-1.3.0/Makedefs.in cups-1.3.0/Makedefs.in.new
---- cups-1.3.0/Makedefs.in 2007-07-18 21:49:45.000000000 +0200
-+++ cups-1.3.0/Makedefs.in.new     2007-08-15 10:24:56.634342552 +0200
-@@ -132,6 +132,7 @@
- LEGACY_BACKENDS       =       @LEGACY_BACKENDS@
- LIBCUPSORDER  =       @LIBCUPSORDER@
- LIBCUPSIMAGEORDER =   @LIBCUPSIMAGEORDER@
-+BINDNOW_FLAGS =       @BINDNOW_FLAGS@
- LINKCUPS      =       @LINKCUPS@ $(SSLLIBS)
- LINKCUPSIMAGE =       @LINKCUPSIMAGE@
- LIBS          =       $(LINKCUPS) $(COMMONLIBS)
-diff -Naur cups-1.3.0/systemv/Makefile cups-1.3.0/systemv/Makefile.new
---- cups-1.3.0/systemv/Makefile    2007-07-11 23:46:42.000000000 +0200
-+++ cups-1.3.0/systemv/Makefile.new        2007-08-15 10:34:29.771906823 +0200
-@@ -212,7 +212,7 @@
-
- lppasswd:      lppasswd.o ../cups/$(LIBCUPS)
-       echo Linking $@...
--      $(CC) $(LDFLAGS) -o lppasswd lppasswd.o $(LIBZ) $(LIBS)
-+      $(CC) $(LDFLAGS) $(BINDNOW_FLAGS) -o lppasswd lppasswd.o $(LIBZ) $(LIBS)
-
-
- #
diff --git a/net-print/cups/files/cups-1.3.4-CVE-2007-4045.patch b/net-print/cups/files/cups-1.3.4-CVE-2007-4045.patch
deleted file mode 100644 (file)
index aab1b21..0000000
+++ /dev/null
@@ -1,47 +0,0 @@
-diff -up cups-1.3.4/scheduler/client.c.CVE-2007-4045 cups-1.3.4/scheduler/client.c
---- cups-1.3.4/scheduler/client.c.CVE-2007-4045        2007-11-07 21:11:58.000000000 +0000
-+++ cups-1.3.4/scheduler/client.c      2007-11-07 21:13:26.000000000 +0000
-@@ -114,6 +114,25 @@ static int                write_file(cupsd_client_t *c
- static void           write_pipe(cupsd_client_t *con);
- 
- 
-+void
-+_cupsdFixClientsBIO(void)
-+{
-+#ifdef HAVE_LIBSSL
-+  cupsd_client_t *c;
-+  BIO *bio;
-+  cupsArraySave (Clients);
-+  for (c = (cupsd_client_t *)cupsArrayFirst(Clients);
-+       c;
-+       c = (cupsd_client_t *)cupsArrayNext(Clients))
-+  {
-+    bio = SSL_get_wbio(c->http.tls);
-+    BIO_ctrl(bio, BIO_C_SET_FILE_PTR, 0, (char *)HTTP(c));
-+  }
-+  cupsArrayRestore (Clients);
-+#endif
-+}
-+
-+
- /*
-  * 'cupsdAcceptClient()' - Accept a new client.
-  */
-@@ -451,6 +470,7 @@ cupsdAcceptClient(cupsd_listener_t *lis)
-   }
- 
-   cupsArrayAdd(Clients, con);
-+  _cupsdFixClientsBIO();
- 
-   cupsdLogMessage(CUPSD_LOG_DEBUG2,
-                   "cupsdAcceptClient: %d connected to server on %s:%d",
-@@ -735,6 +755,7 @@ cupsdCloseClient(cupsd_client_t *con)      /*
-     */
- 
-     cupsArrayRemove(Clients, con);
-+    _cupsdFixClientsBIO();
- 
-     free(con);
-   }
-diff -up cups-1.3.4/scheduler/main.c.CVE-2007-4045 cups-1.3.4/scheduler/main.c
-
diff --git a/net-print/cups/files/pdftops.pl b/net-print/cups/files/pdftops.pl
deleted file mode 100644 (file)
index 3693223..0000000
+++ /dev/null
@@ -1,162 +0,0 @@
-#!/usr/bin/perl -w
-# pdftops.pl - wrapper script for xpdf's pdftops utility to act as a CUPS filter
-# ==============================================================================
-# 1.00 - 2004-10-05/Bl
-#      Initial implementation
-#
-# Copyright: Helge Blischke / SRZ Berlin 2004
-# This program is free seoftware and governed by the GNU Public License Version 2.
-#
-# Description:
-# ------------
-#      This program wraps the pdftops utility from the xpdf 3.00 (and higher) suite
-#      to behave as a CUPS filter as a replacement for the original pdftops filter.
-#
-#      The main purpose of this approach is to keep the properties of a PDF to be
-#      printed as undesturbed as possible, especially with respect to page size,
-#      scaling, and positioning.
-#
-#      The pdftops utility reads a configuration file 'pdftops.conf' in the 
-#      CUPS_SERVERROOT directory, which must exist but may be empty. The sample
-#      configuration file accompanying this program sets the defaults which
-#      seem plausible to me with respect to high end production printers.
-#
-#      To give the user highest possible flexibility, this program accepts and
-#      evaluates a set of job attributes special to this filter, which are 
-#      described below:
-#      
-#              pdf-pages=<f>,<l>
-#                              expands to the -f and -l options of pdftops
-#                              to select a page range to process. This is independent
-#                              of the page-ranges attribute and may significantly
-#                              increase throughput when printing page ranges.
-#                              Either of these numbers may be omitted.
-#
-#              pdf-paper=<name>
-#              pdf-paper=<width>x<height>
-#                              <name> may be one of letter, legal , A4, A3, or match;
-#                              <width> and <height> are the paper width and height
-#                              in printers points (1/72 inch). This expands to
-#                              either the -paper or the -paperh and -paperw options
-#                              of pdftops
-#
-#              pdf-opw=<password>
-#              pdf-upw=<password>
-#                              expand to the -opw and -upw options of pdftops,
-#                              respectively and permit printing of password
-#                              protected PDFs.
-#
-#              pdf-<option>    where <option> is one of
-#                              level1, level1sep, level2, level2sep, level3, level3sep,
-#                              opi, nocrop, expand, noshrink, nocenter.
-#                              See the pdftops manpage for a detailed description of
-#                              the respective options.
-#
-#      All other pdftops commandline options are refused.
-#
-#      When printing from STDIN, the program copies the input to a temporary file
-#      in TMPDIR, which is deleted on exit.
-#
-#      The return code of the pdftops utility, if nonzero, is used as the exit code
-#      of this program; error messages of the pdftops utility are only visible
-#      if 'debug' is specified as LogLevel in cupsd.conf.
-
-#
-# Site specific parameters - modify as needed
-# ------------------------------------------------------------------------------
-$pdftops_path = "/usr/bin/pdftops";    # path to the xpdf utility
-# ------------------------------------------------------------------------------
-
-use File::Copy;
-
-#
-# Check the arguments
-#
-die ("ERROR: wrong number of arguments\n") if (scalar @ARGV < 5);
-
-$jobid = $username = $title = $copies = undef;
-$jobid = shift;                                        # Job ID
-$username = shift;                             # Job requesting user name
-$title = shift;                                        # Job title
-$copies = shift;                               # Number of requested copies
-$options = shift;                              # Textual representation of job attributes
-$pdffile = shift;                              # Pathname of PDF file to process
-
-# If we are reading from STDIN, we must copy the input to a temporary file
-# as the PDF consumer needs a seekable input.
-
-if (! defined $pdffile)
-{
-       my $tmpfile = $ENV{TMPDIR} . "pdfin.$$.tmp";
-       open (TEMP, ">$tmpfile") || die ("ERROR: pdftops wrapper: $tmpfile: $!\n");
-       if (! copy (STDIN, TEMP))
-       {
-               close (TEMP);
-               unlink $tmpfile;
-               die ("ERROR: pdftops wrapper: $tmpfile: $!\n");
-       }
-       close (TEMP);
-       $pdffile = $tmpfile;
-       $delete_input = 1;                      # for deleting the temp file after converting
-}
-
-# 
-# Check the options string for options to modify the bahaviour of the pdftops utility:
-#
-@optarr = split (/\s+/, $options);
-$cmdopt = "";
-# The following are the (parameterless) command line options that may be used to change the 
-# defaults defiend by pdftops.conf
-$simple = 'level1|level1sep|level2|level2sep|level3|level3sep|opi|nocrop|expand|noshrink|nocenter';
-foreach my $option (@optarr)
-{
-       if ($option =~ /^pdf-(.+)$/)
-       {       # We assume this is an option to evaluate
-               my $optkey = $1;                # possible pdftops option
-               if ($optkey =~ /^pages=(\d*),(\d*)$/)
-               {
-                       # We do this hack here to avoid clashes with the page-ranges atrribute
-                       # which is handled by the pstops filter. And we allow one of the numbers
-                       # to be omitted.
-                       my $first = $1;
-                       my $lastp = $2;
-                       $cmdopt .= " -f $1" if ($1);            # first page
-                       $cmdopt .= " -l $2" if ($2);            # last page
-               }
-               elsif ($optkey =~ /^paper=(letter|legal|A4|A3|match)$/)
-               {
-                       $cmdopt .= " -paper $1";                        # paper name
-               }
-               elsif ($optkey =~ /^paper=(\d+)x(\d+)$/)
-               {
-                       $cmdopt .= " -paperw $1 -paperh $2";            # paper dimensions
-               }
-               elsif ($optkey =~ /^(o|u)pw=(\S+)$/)
-               {
-                       $cmdopt .= " $1" . 'pw ' . $2;                  # owner/user password
-               }
-               elsif ($optkey =~ /^($simple)$/)
-               {
-                       $cmdopt .= ' -' . $1;                           # allowed simple options
-               }
-               else
-               {
-                       warn ("ERROR: pdftops wrapper: illegal attribute \"pdf-$optkey\"\n");
-               }
-       }
-       # All other attributes are processed elsewhere
-}
-#
-# Complete the command
-#
-warn ("ERROR: pdftops-options: $cmdopt\n");
-$rc = system ("$pdftops_path $cmdopt $pdffile -");
-if ($rc)
-{
-       $ir = $rc & 127;
-       $rc >>= 8;
-       warn ("ERROR: pdftops_path exited with ", ($ir) ? "signal $ir, " : " exit code $rc", "\n");
-       exit $rc;
-}
-unlink ($pdffile) if (defined $delete_input);          # Delete the temp file if any
-exit 0;