Import of pkgsrc-2016Q3

This commit is contained in:
2016-10-14 07:49:11 +02:00
committed by Lionel Sambuc
parent 9d819b6d54
commit 1242aa1e36
35952 changed files with 949749 additions and 377083 deletions

View File

@@ -1,7 +1,7 @@
# $NetBSD: Makefile,v 1.50 2015/04/06 08:17:37 adam Exp $
# $NetBSD: Makefile,v 1.58 2016/07/16 19:49:07 he Exp $
#
DISTNAME= opendnssec-1.4.7
DISTNAME= opendnssec-1.4.10
PKGREVISION= 1
CATEGORIES= security net
MASTER_SITES= http://www.opendnssec.org/files/source/

View File

@@ -1,4 +1,4 @@
@comment $NetBSD: PLIST,v 1.6 2014/09/27 19:41:06 pettai Exp $
@comment $NetBSD: PLIST,v 1.7 2015/11/16 10:09:08 he Exp $
bin/ods-getconf
bin/ods-hsmspeed
bin/ods-hsmutil
@@ -41,6 +41,8 @@ share/opendnssec/enforcerstate.rng
share/opendnssec/kasp.rnc
share/opendnssec/kasp.rng
share/opendnssec/kasp2html.xsl
share/opendnssec/migrate_1_4_8.mysql
share/opendnssec/migrate_1_4_8.sqlite3
share/opendnssec/migrate_adapters_1.mysql
share/opendnssec/migrate_adapters_1.sqlite3
share/opendnssec/migrate_id_mysql.pl

View File

@@ -1,8 +1,12 @@
$NetBSD: distinfo,v 1.29 2014/12/04 15:58:21 he Exp $
$NetBSD: distinfo,v 1.34 2016/07/16 19:49:07 he Exp $
SHA1 (opendnssec-1.4.7.tar.gz) = c8a5808d68a50db8ed7edf806a58f54428ad7aa8
RMD160 (opendnssec-1.4.7.tar.gz) = f14f7a19b0072754ac7cb242ad2ee610d933364e
Size (opendnssec-1.4.7.tar.gz) = 1038884 bytes
SHA1 (opendnssec-1.4.10.tar.gz) = c83c452b9951df8dd784d7c39aae90363f1a1213
RMD160 (opendnssec-1.4.10.tar.gz) = 0ee7e1b282da6839be919b18faf9fbe567bfc130
SHA512 (opendnssec-1.4.10.tar.gz) = 00ba6ceba595f9d4d7736af982b78779f204eb52fcf92222256792368328647ca1a4c84b4db64dcdd9a0119292f132a4efd15e60436c2a125bf6a8fb3f33540e
Size (opendnssec-1.4.10.tar.gz) = 1036069 bytes
SHA1 (patch-aa) = 104e077af6c368cbb5fc3034d58b2f2249fcf991
SHA1 (patch-enforcer_utils_Makefile.am) = bee7cb4f3cfe5aae96c5726a115eb8b6587288dd
SHA1 (patch-enforcer_utils_Makefile.in) = 4d40385e4d6a70c2722ec43268832ca27ca89cbc
SHA1 (patch-enforcer_utils_Makefile.am) = 80915dee723535e5854e62bc18f00ba2d5d7496c
SHA1 (patch-enforcer_utils_Makefile.in) = 6c1b4ad25956bfcc8b410a8ca22f2581e64198d1
SHA1 (patch-signer_src_signer_ixfr.c) = 74c2c320080e585a6126e146c453998f44c164f7
SHA1 (patch-signer_src_signer_zone.c) = 0330236f11ccab7ed83b73bc83d851f932124318
SHA1 (patch-signer_src_wire_query.c) = ab60e229687be910be9acd0a43d47987498de070

View File

@@ -1,14 +1,13 @@
$NetBSD: patch-enforcer_utils_Makefile.am,v 1.1 2013/08/22 11:05:45 he Exp $
$NetBSD: patch-enforcer_utils_Makefile.am,v 1.2 2015/11/16 10:09:08 he Exp $
Install the conversion scripts.
--- enforcer/utils/Makefile.am.orig 2012-10-24 10:42:52.000000000 +0000
--- enforcer/utils/Makefile.am.orig 2015-10-05 14:19:26.000000000 +0000
+++ enforcer/utils/Makefile.am
@@ -43,3 +43,9 @@ EXTRA_DIST = $(srcdir)/migrate_*.pl
EXTRA_DIST += $(srcdir)/migrate_adapters_1.*
EXTRA_DIST += $(srcdir)/convert_database.pl
@@ -43,3 +43,8 @@ EXTRA_DIST += $(srcdir)/convert_database
EXTRA_DIST += $(srcdir)/migrate_zone_delete.mysql
+
EXTRA_DIST += $(srcdir)/migrate_1_4_8.*
+install-data-local: $(EXTRA_DIST)
+ for f in $(EXTRA_DIST); do \
+ $(INSTALL_DATA) "$$f" $(DESTDIR)$(opendnssecdatadir) \

View File

@@ -1,10 +1,10 @@
$NetBSD: patch-enforcer_utils_Makefile.in,v 1.2 2014/12/04 15:58:21 he Exp $
$NetBSD: patch-enforcer_utils_Makefile.in,v 1.4 2016/06/08 08:35:10 he Exp $
Regenerate after adding installation of migration scripts to Makefile.am.
--- enforcer/utils/Makefile.in.orig 2014-12-04 15:18:00.000000000 +0000
--- enforcer/utils/Makefile.in.orig 2015-10-05 14:20:51.000000000 +0000
+++ enforcer/utils/Makefile.in
@@ -788,7 +788,8 @@ info: info-am
@@ -797,7 +797,8 @@ info: info-am
info-am:
@@ -14,7 +14,7 @@ Regenerate after adding installation of migration scripts to Makefile.am.
install-dvi: install-dvi-am
@@ -846,17 +847,24 @@ uninstall-man: uninstall-man1
@@ -855,20 +856,27 @@ uninstall-man: uninstall-man1
ctags ctags-am distclean distclean-compile distclean-generic \
distclean-libtool distclean-tags distdir dvi dvi-am html \
html-am info info-am install install-am install-binPROGRAMS \
@@ -28,7 +28,6 @@ Regenerate after adding installation of migration scripts to Makefile.am.
- mostlyclean-libtool pdf pdf-am ps ps-am tags tags-am uninstall \
- uninstall-am uninstall-binPROGRAMS \
- uninstall-dist_opendnssecdataDATA uninstall-man uninstall-man1
-
+ install-data install-data-am install-data-local \
+ install-dist_opendnssecdataDATA install-dvi install-dvi-am \
+ install-exec install-exec-am install-html install-html-am \
@@ -40,13 +39,16 @@ Regenerate after adding installation of migration scripts to Makefile.am.
+ pdf pdf-am ps ps-am tags tags-am uninstall uninstall-am \
+ uninstall-binPROGRAMS uninstall-dist_opendnssecdataDATA \
+ uninstall-man uninstall-man1
+
+
.PRECIOUS: Makefile
+install-data-local: $(EXTRA_DIST)
+ for f in $(EXTRA_DIST); do \
+ $(INSTALL_DATA) "$$f" $(DESTDIR)$(opendnssecdatadir) \
+ || exit $$?; \
+ done
+
# Tell versions [3.59,3.63) of GNU make to not export all variables.
# Otherwise a system limit (for SysV at least) may be exceeded.
.NOEXPORT:

View File

@@ -0,0 +1,17 @@
$NetBSD: patch-signer_src_signer_ixfr.c,v 1.1 2016/07/16 19:49:07 he Exp $
The part->soamin assertion seems to trigger.
Be helpful and log the zone name before the assert.
--- signer/src/signer/ixfr.c.orig 2016-01-21 14:31:54.000000000 +0000
+++ signer/src/signer/ixfr.c
@@ -227,6 +227,9 @@ part_print(FILE* fd, ixfr_type* ixfr, si
}
ods_log_assert(part->min);
ods_log_assert(part->plus);
+ if (!part->soamin) {
+ ods_log_error("[%s] zone %s no part->soamin", ixfr_str, zone->name);
+ }
ods_log_assert(part->soamin);
ods_log_assert(part->soaplus);
if (util_rr_print(fd, part->soamin) != ODS_STATUS_OK) {

View File

@@ -0,0 +1,30 @@
$NetBSD: patch-signer_src_signer_zone.c,v 1.1 2016/07/16 19:49:07 he Exp $
For debugging, save any corrupted ixfr journal files as <zone>.ixfr-bad.
--- signer/src/signer/zone.c.orig 2016-05-02 10:40:02.000000000 +0000
+++ signer/src/signer/zone.c
@@ -1028,12 +1028,22 @@ zone_recover2(zone_type* zone)
fd = ods_fopen(filename, NULL, "r");
}
if (fd) {
+ char *badfn = NULL;
+
status = backup_read_ixfr(fd, zone);
if (status != ODS_STATUS_OK) {
ods_log_warning("[%s] corrupted journal file zone %s, "
"skipping (%s)", zone_str, zone->name,
ods_status2str(status));
- (void)unlink(filename);
+ badfn = ods_build_path(zone->name, ".ixfr-bad", 0, 1);
+ if (badfn) {
+ (void)rename(filename, badfn);
+ ods_log_warning("[%s] corrupted journal for zone %s "
+ "saved as %s", zone_str, zone->name, badfn);
+ free(badfn);
+ } else {
+ (void)unlink(filename);
+ }
ixfr_cleanup(zone->ixfr);
zone->ixfr = ixfr_create((void*)zone);
}

View File

@@ -0,0 +1,18 @@
$NetBSD: patch-signer_src_wire_query.c,v 1.1 2016/07/16 19:49:07 he Exp $
Add a check for whether we have an RRset in the query,
to side-step DoS via crafted packet.
--- signer/src/wire/query.c.orig 2016-05-02 10:40:02.000000000 +0000
+++ signer/src/wire/query.c
@@ -869,6 +869,10 @@ query_process(query_type* q, void* engin
return query_formerr(q);
}
rr = ldns_rr_list_rr(ldns_pkt_question(pkt), 0);
+ if (rr == NULL) {
+ ods_log_debug("[%s] no RRset in query, ignoring", query_str);
+ return QUERY_DISCARDED; /* no RRset in query */
+ }
lock_basic_lock(&e->zonelist->zl_lock);
/* we can just lookup the zone, because we will only handle SOA queries,
zone transfers, updates and notifies */