diff --git a/pisi-index.xml b/pisi-index.xml
index 912421c2b8..e337f4351c 100644
--- a/pisi-index.xml
+++ b/pisi-index.xml
@@ -16726,6 +16726,156 @@
+
+
+ ntp
+ http://www.ntp.org
+
+ PisiLinux Community
+ admins@pisilinux.org
+
+ MIT
+ BSD
+ GPLv2+
+ service
+ server
+ NTP daemon and client
+ NTP hizmeti ve istemcisi
+ Network Time Protocol utilities and daemons that will synchronize your computer's time to Coordinated Universal Time (UTC) via the NTP protocol and NTP servers.
+ ntp, NTP protokolü üzerinden uzak sunucuları kullanarak sisteminizin zamanını eşitlemek için gerekli araçları ve hizmetleri içerir.
+ https://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-4.2/ntp-4.2.8p4.tar.gz
+ http://sourceforge.net/projects/ictom/files/ntpstat-0.2.tar.gz
+
+ fix-man-pages.sh
+
+
+ avahi-compat-libdns_sd-devel
+ libedit-devel
+ net-snmp-devel
+ perl-HTML-Parser
+ libcap-devel
+ openssl-devel
+ libevent-devel
+
+ server/ntp/pspec.xml
+
+
+ ntp-server
+ NTP server
+ NTP hizmeti
+
+ avahi-compat-libdns_sd
+ libedit
+ net-snmp
+ libcap
+ openssl
+ libevent
+ ntp-client
+
+
+ /etc/ntp.conf
+ /etc/conf.d
+ /etc/ntp/crypto
+ /usr/bin/ntpstat
+ /usr/bin/update-leap
+ /usr/bin/calc_tickadj
+ /usr/share/ntp/lib/NTP/Util.pm
+ /usr/libexec
+ /usr/sbin
+ /usr/share/doc
+ /usr/share/man
+ /var/lib/ntp
+
+
+ System.Package
+ System.Service
+
+
+ fedora/ntp.conf
+ fedora/ntpd.sysconfig
+ fedora/ntp.cryptopw
+
+
+
+ ntp-client
+ NTP client
+ NTP istemcisi
+ app:console
+ util.admin
+
+ /etc/conf.d/ntpdate
+ /etc/ntp/step-tickers
+ /etc/ntp/keys
+ /usr/sbin/ntpdate
+ /usr/share/man/man8/ntpdate.8*
+
+
+ System.Service
+ System.Package
+
+
+ fedora/ntpdate.sysconfig
+ fedora/ntp.step-tickers
+ fedora/ntp.keys
+
+
+
+ ntp-docs
+ NTP documentation
+ NTP belgeleri
+ data:doc
+
+ ntp-client
+
+
+ /usr/share/doc/ntp/html
+
+
+
+
+ 2016-01-01
+ 4.2.8_p4
+ Version Bump.
+ Stefan Gronewold
+ groni@pisilinux.org
+
+
+ 2014-07-08
+ 4.2.6_p5
+ Version Bump.
+ Vedat Demir
+ vedat@pisilinux.org
+
+
+ 2014-05-30
+ 4.2.6_p2
+ Rebuild.
+ Stefan Gronewold (groni)
+ groni@pisilinux.org
+
+
+ 2014-03-09
+ 4.2.6_p2
+ Rebuild.
+ Alihan Öztürk
+ alihan@pisilinux.org
+
+
+ 2013-03-06
+ 4.2.6_p2
+ URL Fixed
+ Osman Erkan
+ osman.erkan@pisilinux.org
+
+
+ 2011-02-16
+ 4.2.6_p2
+ First release
+ Pisi Linux Admins
+ admins@pisilinux.org
+
+
+ cdparanoia
diff --git a/pisi-index.xml.sha1sum b/pisi-index.xml.sha1sum
index e478d4f816..be2f1c9f6d 100644
--- a/pisi-index.xml.sha1sum
+++ b/pisi-index.xml.sha1sum
@@ -1 +1 @@
-6550d3f1ae47cb5d3a46074c48af935a1c48077c
\ No newline at end of file
+2963887f076b8a144c03f1a6583cddbd7115941c
\ No newline at end of file
diff --git a/pisi-index.xml.xz b/pisi-index.xml.xz
index d8e630b2b1..c1dc8a8bf8 100644
Binary files a/pisi-index.xml.xz and b/pisi-index.xml.xz differ
diff --git a/pisi-index.xml.xz.sha1sum b/pisi-index.xml.xz.sha1sum
index 4952ea8d95..48153a2d0e 100644
--- a/pisi-index.xml.xz.sha1sum
+++ b/pisi-index.xml.xz.sha1sum
@@ -1 +1 @@
-cfed27980a6f8afd0c1d0633030b4b6dc772cab7
\ No newline at end of file
+53b8e9cd923af96c4540670e941b9f7a94c0646a
\ No newline at end of file
diff --git a/server/ntp/actions.py b/server/ntp/actions.py
new file mode 100644
index 0000000000..b0bee8e9e9
--- /dev/null
+++ b/server/ntp/actions.py
@@ -0,0 +1,59 @@
+#!/usr/bin/python
+# -*- coding: utf-8 -*-
+#
+# Licensed under the GNU General Public License, version 3.
+# See the file http://www.gnu.org/licenses/gpl.txt
+
+from pisi.actionsapi import shelltools
+from pisi.actionsapi import autotools
+from pisi.actionsapi import pisitools
+from pisi.actionsapi import get
+
+WorkDir="%s" % get.srcDIR().replace("_", "")
+
+def setup():
+ shelltools.export("CFLAGS", "%s -pie -fPIE -fno-strict-aliasing" % get.CFLAGS())
+
+ # needed to link with avahi
+ shelltools.export("ac_cv_header_dns_sd_h", "yes")
+ shelltools.export("ac_cv_lib_dns_sd_DNSServiceRegister", "yes")
+
+ pisitools.dosed("ntpstat-0.2/Makefile", "^CC=.*gcc", "CC=%s" % get.CC())
+ pisitools.dosed("ntpstat-0.2/Makefile", "^CFLAGS=.*", "CFLAGS=%s" % get.CFLAGS())
+
+ autotools.configure("--enable-all-clocks \
+ --enable-parse-clocks \
+ --enable-linuxcaps \
+ --enable-ipv6 \
+ --with-crypto")
+
+def build():
+ autotools.make()
+ autotools.make("-C ntpstat-0.2")
+
+ #shelltools.cd("html")
+ #shelltools.system("../scripts/html2man")
+ #shelltools.system("../fix-man-pages")
+
+def install():
+ autotools.rawInstall("DESTDIR=%s" % get.installDIR())
+
+ # Remove autotools installed man pages
+ pisitools.removeDir("/usr/share/man")
+
+ # pisitools.doman("html/man/man5/*.5", "html/man/man8/*.8")
+
+ for sbin in ["sntp", "ntpdc", "ntpd", "ntp-keygen", "ntp-wait",
+ "ntpq", "ntptime", "ntptrace", "tickadj", "ntpsnmpd", "ntpdate"]:
+ pisitools.domove("/usr/bin/%s" % sbin, "/usr/sbin")
+
+ # Additional ntpstat binary and man page
+ pisitools.dobin("ntpstat-0.2/ntpstat")
+ pisitools.doman("ntpstat-0.2/ntpstat.1")
+
+ pisitools.dodir("/var/lib/ntp")
+
+ #pisitools.removeDir("/usr/lib")
+
+ pisitools.dohtml("html/*")
+ pisitools.dodoc("ChangeLog", "NEWS", "README", "TODO", "WHERE-TO-START")
diff --git a/server/ntp/comar/ntp-server-package.py b/server/ntp/comar/ntp-server-package.py
new file mode 100644
index 0000000000..6035f682ab
--- /dev/null
+++ b/server/ntp/comar/ntp-server-package.py
@@ -0,0 +1,8 @@
+#!/usr/bin/python
+
+import os
+
+def postInstall(fromVersion, fromRelease, toVersion, toRelease):
+ os.system("chown -R ntp:ntp /var/lib/ntp")
+ os.system("chown -R root:ntp /etc/ntp/crypto")
+ os.chmod("/etc/ntp/crypto", 0750)
diff --git a/server/ntp/comar/ntpd-service.py b/server/ntp/comar/ntpd-service.py
new file mode 100644
index 0000000000..8150b8cd6f
--- /dev/null
+++ b/server/ntp/comar/ntpd-service.py
@@ -0,0 +1,28 @@
+# -*- coding: utf-8 -*-
+from comar.service import *
+
+import os
+
+serviceType = "server"
+serviceDesc = _({"en": "NTP Daemon",
+ "tr": "NTP Hizmeti"})
+serviceConf = "ntpd"
+
+PIDFILE = "/run/ntpd.pid"
+
+@synchronized
+def start():
+ startService(command="/usr/sbin/ntpd",
+ args=config.get("OPTIONS", "-u ntp:ntp -p %s -g" % PIDFILE),
+ donotify=True)
+
+@synchronized
+def stop():
+ stopService(pidfile=PIDFILE,
+ donotify=True)
+
+ if os.path.exists(PIDFILE):
+ os.unlink(PIDFILE)
+
+def status():
+ return isServiceRunning(pidfile=PIDFILE)
diff --git a/server/ntp/comar/ntpdate-package.py b/server/ntp/comar/ntpdate-package.py
new file mode 100644
index 0000000000..455f7a50b6
--- /dev/null
+++ b/server/ntp/comar/ntpdate-package.py
@@ -0,0 +1,7 @@
+#!/usr/bin/python
+
+import os
+
+def postInstall(fromVersion, fromRelease, toVersion, toRelease):
+ os.system("/bin/chown root:wheel /usr/sbin/ntpdate")
+ os.system("/bin/chmod 04710 /usr/sbin/ntpdate")
diff --git a/server/ntp/comar/ntpdate-service.py b/server/ntp/comar/ntpdate-service.py
new file mode 100644
index 0000000000..4d34920ca6
--- /dev/null
+++ b/server/ntp/comar/ntpdate-service.py
@@ -0,0 +1,80 @@
+# -*- coding: utf-8 -*-
+from comar.service import *
+
+import re
+
+serviceType = "local"
+serviceDesc = _({"en": "Set the date & time via NTP",
+ "tr": "Tarih & zamanı NTP ile ayarlayın"})
+serviceConf = "ntpdate"
+serviceDefault = "conditional"
+
+# ntpdate will run if it finds a ticker in any of the configuration files
+
+NTPCONF = "/etc/ntp.conf"
+NTPSTEP = "/etc/ntp/step-tickers"
+PIDFILE = "/run/ntpdate.pid"
+
+MSG_NOSERVER = _({"en" : "NTP server not specified in %s or %s." % (NTPSTEP, NTPCONF),
+ "tr" : "%s veya %s dosyasında hiç NTP sunucu belirtilmemiş." % (NTPSTEP, NTPCONF)})
+
+def parse_tickers():
+ tickers = []
+ if os.path.exists(NTPSTEP):
+ for line in open(NTPSTEP, "r").read().strip().split("\n"):
+ if line and not line.startswith("#"):
+ tickers.append(line)
+
+ if tickers:
+ return tickers
+
+ if os.path.exists(NTPCONF):
+ for line in open(NTPCONF, "r").read().strip().split("\n"):
+ if line.startswith(("server", "peer")):
+ try:
+ peer = line.split()[1]
+ if not re.match("127\.127\.[0-9]+\.[0-9]+", peer):
+ tickers.append(peer)
+ except IndexError:
+ pass
+
+ return tickers
+
+@synchronized
+def start():
+ tickers = parse_tickers()
+
+ if len(tickers) == 0:
+ fail(MSG_NOSERVER)
+
+ tickers = " ".join(tickers)
+
+ # Eventhough the ntpdate is a oneshot process, the pidfile hack is used to
+ # work around COMAR's silly status() check in startService()
+ startService(command="/usr/sbin/ntpdate",
+ args="%s %s" % (config.get("OPTIONS", "-U ntp -s -b"), tickers),
+ makepid=True,
+ pidfile=PIDFILE,
+ donotify=True)
+
+ if os.path.exists(PIDFILE):
+ os.unlink(PIDFILE)
+
+ if config.get("SYNC_HWCLOCK", "no") == "yes":
+ run("/sbin/hwclock --systohc")
+
+def ready():
+ status = is_on()
+ tickers = parse_tickers()
+ if status == "on" or (status == "conditional" and tickers):
+ start()
+
+
+@synchronized
+def stop():
+ # There's nothing to do
+ pass
+
+def status():
+ # No need to supply a status as the service is oneshot
+ return
diff --git a/server/ntp/files/fedora/ntp-4.2.4p7-getprecision.patch b/server/ntp/files/fedora/ntp-4.2.4p7-getprecision.patch
new file mode 100644
index 0000000000..ecf6defafa
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.4p7-getprecision.patch
@@ -0,0 +1,12 @@
+diff -up ntp-4.2.4p7/ntpd/ntp_proto.c.getprecision ntp-4.2.4p7/ntpd/ntp_proto.c
+--- ntp-4.2.4p7/ntpd/ntp_proto.c.getprecision 2009-09-29 14:16:22.000000000 +0200
++++ ntp-4.2.4p7/ntpd/ntp_proto.c 2009-09-29 14:18:13.000000000 +0200
+@@ -3099,7 +3099,7 @@ peer_unfit(
+ /*
+ * Find the precision of this particular machine
+ */
+-#define MINSTEP 100e-9 /* minimum clock increment (s) */
++#define MINSTEP 10e-9 /* minimum clock increment (s) */
+ #define MAXSTEP 20e-3 /* maximum clock increment (s) */
+ #define MINLOOPS 5 /* minimum number of step samples */
+
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-bcast.patch b/server/ntp/files/fedora/ntp-4.2.6p1-bcast.patch
new file mode 100644
index 0000000000..8c30cf3231
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-bcast.patch
@@ -0,0 +1,93 @@
+diff -up ntp-4.2.6p1/ntpd/ntp_io.c.bcast ntp-4.2.6p1/ntpd/ntp_io.c
+--- ntp-4.2.6p1/ntpd/ntp_io.c.bcast 2009-12-09 08:36:37.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_io.c 2010-03-05 14:49:25.000000000 +0100
+@@ -151,6 +151,8 @@ int ninterfaces; /* Total number of in
+
+ int disable_dynamic_updates; /* scan interfaces once only */
+
++static int pktinfo_status = 0; /* is IP_PKTINFO on wildipv4 iface enabled? */
++
+ #ifdef REFCLOCK
+ /*
+ * Refclock stuff. We keep a chain of structures with data concerning
+@@ -1937,6 +1939,17 @@ set_reuseaddr(
+ #endif /* ! SO_EXCLUSIVEADDRUSE */
+ }
+
++static void
++set_pktinfo(int flag)
++{
++ if (wildipv4 == NULL)
++ return;
++ if (setsockopt(wildipv4->fd, SOL_IP, IP_PKTINFO, &flag, sizeof (flag))) {
++ msyslog(LOG_ERR, "set_pktinfo: setsockopt(IP_PKTINFO, %s) failed: %m", flag ? "on" : "off");
++ } else
++ pktinfo_status = flag;
++}
++
+ /*
+ * This is just a wrapper around an internal function so we can
+ * make other changes as necessary later on
+@@ -2374,6 +2387,7 @@ io_setbclient(void)
+ }
+ }
+ set_reuseaddr(0);
++ set_pktinfo(1);
+ if (nif > 0)
+ DPRINTF(1, ("io_setbclient: Opened broadcast clients\n"));
+ else if (!nif)
+@@ -2405,6 +2419,7 @@ io_unsetbclient(void)
+
+ socket_broadcast_disable(interf, &interf->sin);
+ }
++ set_pktinfo(0);
+ }
+
+ /*
+@@ -3130,7 +3145,8 @@ read_network_packet(
+ #ifdef HAVE_TIMESTAMP
+ struct msghdr msghdr;
+ struct iovec iovec;
+- char control[TIMESTAMP_CTLMSGBUF_SIZE];
++ char control[sizeof (struct cmsghdr) * 2 + sizeof (struct timeval) +
++ sizeof (struct in_pktinfo) + 32];
+ #endif
+
+ /*
+@@ -3141,7 +3157,7 @@ read_network_packet(
+ */
+
+ rb = get_free_recv_buffer();
+- if (NULL == rb || itf->ignore_packets) {
++ if (NULL == rb || (itf->ignore_packets && !(pktinfo_status && itf == wildipv4))) {
+ char buf[RX_BUFF_SIZE];
+ sockaddr_u from;
+
+@@ -3201,6 +3217,27 @@ read_network_packet(
+ return (buflen);
+ }
+
++ if (pktinfo_status && itf->ignore_packets && itf == wildipv4) {
++ /* check for broadcast on 255.255.255.255, exception allowed on wildipv4 */
++ struct cmsghdr *cmsg;
++ struct in_pktinfo *pktinfo = NULL;
++
++ if ((cmsg = CMSG_FIRSTHDR(&msghdr)))
++ do {
++ if (cmsg->cmsg_level == SOL_IP && cmsg->cmsg_type == IP_PKTINFO)
++ pktinfo = (struct in_pktinfo *) CMSG_DATA(cmsg);
++ } while ((cmsg = CMSG_NXTHDR(&msghdr, cmsg)));
++ if (pktinfo && pktinfo->ipi_addr.s_addr == INADDR_BROADCAST) {
++ DPRINTF(4, ("INADDR_BROADCAST\n"));
++ } else {
++ DPRINTF(4, ("%s on (%lu) fd=%d from %s\n", "ignore",
++ free_recvbuffs(), fd, stoa(&rb->recv_srcadr)));
++ packets_ignored++;
++ freerecvbuf(rb);
++ return (buflen);
++ }
++ }
++
+ DPRINTF(3, ("read_network_packet: fd=%d length %d from %s\n",
+ fd, buflen, stoa(&rb->recv_srcadr)));
+
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-cmsgalign.patch b/server/ntp/files/fedora/ntp-4.2.6p1-cmsgalign.patch
new file mode 100644
index 0000000000..0e4b8ccc7a
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-cmsgalign.patch
@@ -0,0 +1,14 @@
+diff -up ntp-4.2.6p1/ntpd/ntp_io.c.cmsgalign ntp-4.2.6p1/ntpd/ntp_io.c
+--- ntp-4.2.6p1/ntpd/ntp_io.c.cmsgalign 2010-03-04 18:28:53.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_io.c 2010-03-04 18:30:34.000000000 +0100
+@@ -3194,8 +3194,8 @@ read_network_packet(
+ msghdr.msg_namelen = fromlen;
+ msghdr.msg_iov = &iovec;
+ msghdr.msg_iovlen = 1;
+- msghdr.msg_control = (void *)&control;
+- msghdr.msg_controllen = sizeof(control);
++ msghdr.msg_control = (void *)((long)(control + 7) & -8); /* align to 8 bytes */
++ msghdr.msg_controllen = sizeof(control) - 8;
+ msghdr.msg_flags = 0;
+ rb->recv_length = recvmsg(fd, &msghdr, 0);
+ #endif
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-droproot.patch b/server/ntp/files/fedora/ntp-4.2.6p1-droproot.patch
new file mode 100644
index 0000000000..4d946b2a30
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-droproot.patch
@@ -0,0 +1,208 @@
+diff -up ntp-4.2.6p1/html/ntpdate.html.droproot ntp-4.2.6p1/html/ntpdate.html
+--- ntp-4.2.6p1/html/ntpdate.html.droproot 2006-12-28 13:02:58.000000000 +0100
++++ ntp-4.2.6p1/html/ntpdate.html 2010-03-03 15:32:08.000000000 +0100
+@@ -18,7 +18,7 @@
+
+
Disclaimer: The functionality of this program is now available in the ntpd program. See the -q command line option in the ntpd - Network Time Protocol (NTP) daemon page. After a suitable period of mourning, the ntpdate program is to be retired from this distribution
+ ntpdate sets the local date and time by polling the Network Time Protocol (NTP) server(s) given as the server arguments to determine the correct time. It must be run as root on the local host. A number of samples are obtained from each of the servers specified and a subset of the NTP clock filter and selection algorithms are applied to select the best of these. Note that the accuracy and reliability of ntpdate depends on the number of servers, the number of polls each time it is run and the interval between runs.
+
ntpdate can be run manually as necessary to set the host clock, or it can be run from the host startup script to set the clock at boot time. This is useful in some cases to set the clock initially before starting the NTP daemon ntpd. It is also possible to run ntpdate from a cron script. However, it is important to note that ntpdate with contrived cron scripts is no substitute for the NTP daemon, which uses sophisticated algorithms to maximize accuracy and reliability while minimizing resource use. Finally, since ntpdate does not discipline the host clock frequency as does ntpd, the accuracy using ntpdate is limited.
+@@ -58,6 +58,11 @@
+
Direct ntpdate to use an unprivileged port or outgoing packets. This is most useful when behind a firewall that blocks incoming traffic to privileged ports, and you want to synchronise with hosts beyond the firewall. Note that the -d option always uses unprivileged ports.
+
-v
+
Be verbose. This option will cause ntpdate's version identification string to be logged.
++
++
-U user_name
++
ntpdate process drops root privileges and changes user ID to
++ user_name and group ID to the primary group of
++ server_user.
+
+
Diagnostics
+ ntpdate's exit status is zero if it finds a server and updates the clock, and nonzero otherwise.
+diff -up ntp-4.2.6p1/ntpdate/ntpdate.c.droproot ntp-4.2.6p1/ntpdate/ntpdate.c
+--- ntp-4.2.6p1/ntpdate/ntpdate.c.droproot 2009-12-09 08:36:35.000000000 +0100
++++ ntp-4.2.6p1/ntpdate/ntpdate.c 2010-03-03 15:33:06.000000000 +0100
+@@ -48,6 +48,12 @@
+
+ #include
+
++/* Linux capabilities */
++#include
++#include
++#include
++#include
++
+ #ifdef SYS_VXWORKS
+ # include "ioLib.h"
+ # include "sockLib.h"
+@@ -152,6 +158,11 @@ int simple_query = 0;
+ int unpriv_port = 0;
+
+ /*
++ * Use capabilities to drop privileges and switch uids
++ */
++char *server_user;
++
++/*
+ * Program name.
+ */
+ char *progname;
+@@ -293,6 +304,88 @@ void clear_globals()
+ static ni_namelist *getnetinfoservers (void);
+ #endif
+
++/* This patch is adapted (copied) from Chris Wings drop root patch
++ * for xntpd.
++ */
++void drop_root(uid_t server_uid, gid_t server_gid)
++{
++ cap_t caps;
++
++ if (prctl(PR_SET_KEEPCAPS, 1)) {
++ if (syslogit) {
++ msyslog(LOG_ERR, "prctl(PR_SET_KEEPCAPS, 1) failed");
++ }
++ else {
++ fprintf(stderr, "prctl(PR_SET_KEEPCAPS, 1) failed.\n");
++ }
++ exit(1);
++ }
++
++ if ( setgroups(0, NULL) == -1 ) {
++ if (syslogit) {
++ msyslog(LOG_ERR, "setgroups failed.");
++ }
++ else {
++ fprintf(stderr, "setgroups failed.\n");
++ }
++ exit(1);
++ }
++
++ if ( setegid(server_gid) == -1 || seteuid(server_uid) == -1 ) {
++ if (syslogit) {
++ msyslog(LOG_ERR, "setegid/seteuid to uid=%d/gid=%d failed.", server_uid,
++ server_gid);
++ }
++ else {
++ fprintf(stderr, "setegid/seteuid to uid=%d/gid=%d failed.\n", server_uid,
++ server_gid);
++ }
++ exit(1);
++ }
++
++ caps = cap_from_text("cap_sys_time=epi");
++ if (caps == NULL) {
++ if (syslogit) {
++ msyslog(LOG_ERR, "cap_from_text failed.");
++ }
++ else {
++ fprintf(stderr, "cap_from_text failed.\n");
++ }
++ exit(1);
++ }
++
++ if (cap_set_proc(caps) == -1) {
++ if (syslogit) {
++ msyslog(LOG_ERR, "cap_set_proc failed.");
++ }
++ else {
++ fprintf(stderr, "cap_set_proc failed.\n");
++ }
++ exit(1);
++ }
++
++ /* Try to free the memory from cap_from_text */
++ cap_free( caps );
++
++ if ( setregid(server_gid, server_gid) == -1 ||
++ setreuid(server_uid, server_uid) == -1 ) {
++ if (syslogit) {
++ msyslog(LOG_ERR, "setregid/setreuid to uid=%d/gid=%d failed.",
++ server_uid, server_gid);
++ }
++ else {
++ fprintf(stderr, "setregid/setreuid to uid=%d/gid=%d failed.\n",
++ server_uid, server_gid);
++ }
++ exit(1);
++ }
++
++ if (syslogit) {
++ msyslog(LOG_DEBUG, "running as uid(%d)/gid(%d) euid(%d)/egid(%d).",
++ getuid(), getgid(), geteuid(), getegid());
++ }
++}
++
+ /*
+ * Main program. Initialize us and loop waiting for I/O and/or
+ * timer expiries.
+@@ -340,6 +433,8 @@ ntpdatemain (
+
+ init_lib(); /* sets up ipv4_works, ipv6_works */
+
++ server_user = NULL;
++
+ /* Check to see if we have IPv6. Otherwise default to IPv4 */
+ if (!ipv6_works)
+ ai_fam_templ = AF_INET;
+@@ -351,7 +446,7 @@ ntpdatemain (
+ /*
+ * Decode argument list
+ */
+- while ((c = ntp_getopt(argc, argv, "46a:bBde:k:o:p:qst:uv")) != EOF)
++ while ((c = ntp_getopt(argc, argv, "46a:bBde:k:o:p:qst:uvU:")) != EOF)
+ switch (c)
+ {
+ case '4':
+@@ -429,6 +524,14 @@ ntpdatemain (
+ case 'u':
+ unpriv_port = 1;
+ break;
++ case 'U':
++ if (ntp_optarg) {
++ server_user = strdup(ntp_optarg);
++ }
++ else {
++ ++errflg;
++ }
++ break;
+ case '?':
+ ++errflg;
+ break;
+@@ -438,7 +541,7 @@ ntpdatemain (
+
+ if (errflg) {
+ (void) fprintf(stderr,
+- "usage: %s [-46bBdqsuv] [-a key#] [-e delay] [-k file] [-p samples] [-o version#] [-t timeo] server ...\n",
++ "usage: %s [-46bBdqsuv] [-a key#] [-e delay] [-k file] [-p samples] [-o version#] [-t timeo] [-U username] server ...\n",
+ progname);
+ exit(2);
+ }
+@@ -544,6 +647,24 @@ ntpdatemain (
+ initializing = 0;
+ was_alarmed = 0;
+
++ if (server_user) {
++ struct passwd *pwd = NULL;
++
++ /* Lookup server_user uid/gid before chroot/chdir */
++ pwd = getpwnam( server_user );
++ if ( pwd == NULL ) {
++ if (syslogit) {
++ msyslog(LOG_ERR, "Failed to lookup user '%s'.", server_user);
++ }
++ else {
++ fprintf(stderr, "Failed to lookup user '%s'.\n", server_user);
++ }
++ exit(1);
++ }
++ drop_root(pwd->pw_uid, pwd->pw_gid);
++ }
++
++
+ while (complete_servers < sys_numservers) {
+ #ifdef HAVE_POLL_H
+ struct pollfd* rdfdes;
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-logdefault.patch b/server/ntp/files/fedora/ntp-4.2.6p1-logdefault.patch
new file mode 100644
index 0000000000..ae816b7419
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-logdefault.patch
@@ -0,0 +1,12 @@
+diff -up ntp-4.2.6p1/ntpd/ntp_config.c.logdefault ntp-4.2.6p1/ntpd/ntp_config.c
+--- ntp-4.2.6p1/ntpd/ntp_config.c.logdefault 2010-01-24 11:01:45.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_config.c 2010-03-09 17:44:09.000000000 +0100
+@@ -3794,7 +3794,7 @@ getconfig(
+
+ #endif /* SYS_WINNT */
+ res_fp = NULL;
+- ntp_syslogmask = NLOG_SYNCMASK; /* set more via logconfig */
++ ntp_syslogmask = NLOG_SYNCMASK | NLOG_EVENT | NLOG_STATUS; /* set more via logconfig */
+
+ /*
+ * install a non default variable with this daemon version
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-nano.patch b/server/ntp/files/fedora/ntp-4.2.6p1-nano.patch
new file mode 100644
index 0000000000..aa1cf15985
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-nano.patch
@@ -0,0 +1,18 @@
+diff -up ntp-4.2.6p1/include/ntp_syscall.h.nano ntp-4.2.6p1/include/ntp_syscall.h
+--- ntp-4.2.6p1/include/ntp_syscall.h.nano 2009-12-09 08:36:37.000000000 +0100
++++ ntp-4.2.6p1/include/ntp_syscall.h 2010-03-03 15:42:18.000000000 +0100
+@@ -14,6 +14,14 @@
+ # include
+ #endif
+
++#if defined(ADJ_NANO) && !defined(MOD_NANO)
++#define MOD_NANO ADJ_NANO
++#endif
++
++#if defined(ADJ_TAI) && !defined(MOD_TAI)
++#define MOD_TAI ADJ_TAI
++#endif
++
+ #ifndef NTP_SYSCALLS_LIBC
+ #ifdef NTP_SYSCALLS_STD
+ # define ntp_adjtime(t) syscall(SYS_ntp_adjtime, (t))
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-retcode.patch b/server/ntp/files/fedora/ntp-4.2.6p1-retcode.patch
new file mode 100644
index 0000000000..6d676d274e
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-retcode.patch
@@ -0,0 +1,12 @@
+diff -up ntp-4.2.6p1/ntpd/ntp_proto.c.retcode ntp-4.2.6p1/ntpd/ntp_proto.c
+--- ntp-4.2.6p1/ntpd/ntp_proto.c.retcode 2009-12-09 08:36:36.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_proto.c 2010-03-03 16:06:00.000000000 +0100
+@@ -269,7 +269,7 @@ transmit(
+ "ntpd: no servers found");
+ printf(
+ "ntpd: no servers found\n");
+- exit (0);
++ exit (1);
+ }
+ }
+ }
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-rtnetlink.patch b/server/ntp/files/fedora/ntp-4.2.6p1-rtnetlink.patch
new file mode 100644
index 0000000000..2f3aa418d7
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-rtnetlink.patch
@@ -0,0 +1,26 @@
+diff -up ntp-4.2.6p1/configure.rtnetlink ntp-4.2.6p1/configure
+--- ntp-4.2.6p1/configure.rtnetlink 2010-02-09 11:19:49.000000000 +0100
++++ ntp-4.2.6p1/configure 2010-03-04 17:11:50.000000000 +0100
+@@ -20579,6 +20579,7 @@ else
+ /* end confdefs.h. */
+
+ #include
++#include
+ #include
+ int
+ main ()
+diff -up ntp-4.2.6p1/ntpd/ntp_io.c.rtnetlink ntp-4.2.6p1/ntpd/ntp_io.c
+--- ntp-4.2.6p1/ntpd/ntp_io.c.rtnetlink 2009-12-09 08:36:37.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_io.c 2010-03-04 17:11:32.000000000 +0100
+@@ -4304,10 +4304,7 @@ init_async_notifications()
+ #ifdef HAVE_RTNETLINK
+ memset(&sa, 0, sizeof(sa));
+ sa.nl_family = PF_NETLINK;
+- sa.nl_groups = RTMGRP_LINK | RTMGRP_IPV4_IFADDR
+- | RTMGRP_IPV6_IFADDR | RTMGRP_IPV4_ROUTE
+- | RTMGRP_IPV4_MROUTE | RTMGRP_IPV6_ROUTE
+- | RTMGRP_IPV6_MROUTE;
++ sa.nl_groups = RTMGRP_IPV4_IFADDR | RTMGRP_IPV6_IFADDR;
+ if (bind(fd, (struct sockaddr *)&sa, sizeof(sa)) < 0) {
+ msyslog(LOG_ERR,
+ "bind failed on routing socket (%m) - using polled interface update");
diff --git a/server/ntp/files/fedora/ntp-4.2.6p1-sleep.patch b/server/ntp/files/fedora/ntp-4.2.6p1-sleep.patch
new file mode 100644
index 0000000000..577ef26eed
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p1-sleep.patch
@@ -0,0 +1,495 @@
+diff -up ntp-4.2.6p1/include/ntp_refclock.h.sleep ntp-4.2.6p1/include/ntp_refclock.h
+--- ntp-4.2.6p1/include/ntp_refclock.h.sleep 2009-12-09 08:36:35.000000000 +0100
++++ ntp-4.2.6p1/include/ntp_refclock.h 2010-03-10 19:27:46.000000000 +0100
+@@ -260,6 +260,7 @@ extern void refclock_control (sockaddr_u
+ struct refclockstat *);
+ extern int refclock_open (char *, u_int, u_int);
+ extern int refclock_setup (int, u_int, u_int);
++extern int refclock_timer_needed (struct peer *);
+ extern void refclock_timer (struct peer *);
+ extern void refclock_transmit (struct peer *);
+ extern int refclock_ioctl (int, u_int);
+diff -up ntp-4.2.6p1/include/ntp_stdlib.h.sleep ntp-4.2.6p1/include/ntp_stdlib.h
+--- ntp-4.2.6p1/include/ntp_stdlib.h.sleep 2009-12-09 08:36:35.000000000 +0100
++++ ntp-4.2.6p1/include/ntp_stdlib.h 2010-03-10 19:27:46.000000000 +0100
+@@ -116,6 +116,7 @@ extern const char * FindConfig (const ch
+ extern void signal_no_reset (int, RETSIGTYPE (*func)(int));
+
+ extern void getauthkeys (const char *);
++extern int auth_agekeys_needed (void);
+ extern void auth_agekeys (void);
+ extern void rereadkeys (void);
+
+diff -up ntp-4.2.6p1/include/ntpd.h.sleep ntp-4.2.6p1/include/ntpd.h
+--- ntp-4.2.6p1/include/ntpd.h.sleep 2009-12-09 08:36:35.000000000 +0100
++++ ntp-4.2.6p1/include/ntpd.h 2010-03-10 19:27:46.000000000 +0100
+@@ -112,8 +112,10 @@ extern void block_io_and_alarm (void);
+ /* ntp_loopfilter.c */
+ extern void init_loopfilter(void);
+ extern int local_clock(struct peer *, double);
+-extern void adj_host_clock(void);
++extern int adj_host_clock_needed(void);
++extern void adj_host_clock(int);
+ extern void loop_config(int, double);
++extern int huffpuff_enabled(void);
+ extern void huffpuff(void);
+ extern u_long sys_clocktime;
+ extern u_int sys_tai;
+@@ -219,6 +221,8 @@ extern void hack_restrict (int, sockaddr
+ /* ntp_timer.c */
+ extern void init_timer (void);
+ extern void reinit_timer (void);
++extern double get_timeout (l_fp *);
++extern int timer_elapsed (l_fp, int);
+ extern void timer (void);
+ extern void timer_clr_stats (void);
+ extern void timer_interfacetimeout (u_long);
+diff -up ntp-4.2.6p1/libntp/authkeys.c.sleep ntp-4.2.6p1/libntp/authkeys.c
+--- ntp-4.2.6p1/libntp/authkeys.c.sleep 2009-12-09 08:36:35.000000000 +0100
++++ ntp-4.2.6p1/libntp/authkeys.c 2010-03-10 19:27:46.000000000 +0100
+@@ -445,6 +445,25 @@ auth_delkeys(void)
+ }
+ }
+
++int
++auth_agekeys_needed(void) {
++ struct savekey *sk;
++ int i;
++
++ if (authnumkeys > 20)
++ return 1;
++
++ for (i = 0; i < HASHSIZE; i++) {
++ sk = key_hash[i];
++ while (sk != 0) {
++ if (sk->lifetime > 0)
++ return 1;
++ sk = sk->next;
++ }
++ }
++ return 0;
++}
++
+ /*
+ * auth_agekeys - delete keys whose lifetimes have expired
+ */
+diff -up ntp-4.2.6p1/ntpd/ntp_loopfilter.c.sleep ntp-4.2.6p1/ntpd/ntp_loopfilter.c
+--- ntp-4.2.6p1/ntpd/ntp_loopfilter.c.sleep 2009-12-09 08:36:36.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_loopfilter.c 2010-03-10 19:27:46.000000000 +0100
+@@ -677,6 +677,13 @@ local_clock(
+ #endif /* LOCKCLOCK */
+ }
+
++int
++adj_host_clock_needed(void)
++{
++ return !(!ntp_enable || mode_ntpdate || (pll_control &&
++ kern_enable));
++}
++
+
+ /*
+ * adj_host_clock - Called once every second to update the local clock.
+@@ -686,7 +693,7 @@ local_clock(
+ */
+ void
+ adj_host_clock(
+- void
++ int time_elapsed
+ )
+ {
+ double adjustment;
+@@ -698,7 +705,7 @@ adj_host_clock(
+ * since the poll interval can exceed one day, the old test
+ * would be counterproductive.
+ */
+- sys_rootdisp += clock_phi;
++ sys_rootdisp += clock_phi * time_elapsed;
+
+ #ifndef LOCKCLOCK
+ /*
+@@ -819,6 +826,12 @@ set_freq(
+ #endif /* KERNEL_PLL */
+ }
+
++int
++huffpuff_enabled(void)
++{
++ return sys_huffpuff != NULL;
++}
++
+ /*
+ * huff-n'-puff filter
+ */
+diff -up ntp-4.2.6p1/ntpd/ntp_refclock.c.sleep ntp-4.2.6p1/ntpd/ntp_refclock.c
+--- ntp-4.2.6p1/ntpd/ntp_refclock.c.sleep 2009-12-09 08:36:36.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_refclock.c 2010-03-10 19:27:46.000000000 +0100
+@@ -268,6 +268,21 @@ refclock_unpeer(
+ }
+
+
++int
++refclock_timer_needed(
++ struct peer *peer /* peer structure pointer */
++ )
++{
++ u_char clktype;
++ int unit;
++
++ clktype = peer->refclktype;
++ unit = peer->refclkunit;
++ if (refclock_conf[clktype]->clock_timer != noentry)
++ return 1;
++ return 0;
++}
++
+ /*
+ * refclock_timer - called once per second for housekeeping.
+ */
+diff -up ntp-4.2.6p1/ntpd/ntp_timer.c.sleep ntp-4.2.6p1/ntpd/ntp_timer.c
+--- ntp-4.2.6p1/ntpd/ntp_timer.c.sleep 2009-12-09 08:36:35.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntp_timer.c 2010-03-11 15:23:59.000000000 +0100
+@@ -56,7 +56,6 @@ static u_long adjust_timer; /* second ti
+ static u_long stats_timer; /* stats timer */
+ static u_long huffpuff_timer; /* huff-n'-puff timer */
+ u_long leapsec; /* leapseconds countdown */
+-l_fp sys_time; /* current system time */
+ #ifdef OPENSSL
+ static u_long revoke_timer; /* keys revoke timer */
+ static u_long keys_timer; /* session key timer */
+@@ -74,6 +73,12 @@ volatile u_long alarm_overflow;
+ #define DAY (24 * HOUR)
+
+ u_long current_time; /* seconds since startup */
++l_fp timer_base;
++int time_elapsed;
++
++#define TIMEOUT_TS_SIZE 2
++l_fp timeout_ts[TIMEOUT_TS_SIZE];
++unsigned int timeout_ts_index;
+
+ /*
+ * Stats. Number of overflows and number of calls to transmit().
+@@ -110,6 +115,8 @@ static RETSIGTYPE alarming (int);
+ void
+ reinit_timer(void)
+ {
++ get_systime(&timer_base);
++#if 0
+ #if !defined(SYS_WINNT) && !defined(VMS)
+ # if defined(HAVE_TIMER_CREATE) && defined(HAVE_TIMER_SETTIME)
+ timer_gettime(ntpd_timerid, &itimer);
+@@ -143,6 +150,7 @@ reinit_timer(void)
+ setitimer(ITIMER_REAL, &itimer, (struct itimerval *)0);
+ # endif
+ # endif /* VMS */
++#endif
+ }
+
+ /*
+@@ -165,6 +173,12 @@ init_timer(void)
+ timer_xmtcalls = 0;
+ timer_timereset = 0;
+
++ get_systime(&timer_base);
++
++ for (timeout_ts_index = 0; timeout_ts_index < TIMEOUT_TS_SIZE; timeout_ts_index++)
++ L_CLR(&timeout_ts[timeout_ts_index]);
++ timeout_ts_index = 0;
++#if 0
+ #if !defined(SYS_WINNT)
+ /*
+ * Set up the alarm interrupt. The first comes 2**EVENT_TIMEOUT
+@@ -226,6 +240,7 @@ init_timer(void)
+ }
+
+ #endif /* SYS_WINNT */
++#endif
+ }
+
+ #if defined(SYS_WINNT)
+@@ -236,6 +251,104 @@ get_timer_handle(void)
+ }
+ #endif
+
++double
++get_timeout(l_fp *now)
++{
++ register struct peer *peer, *next_peer;
++ u_int n;
++ double r;
++ int next;
++ l_fp ts;
++
++ ts = *now;
++ L_SUB(&ts, &timeout_ts[timeout_ts_index]);
++ timeout_ts[timeout_ts_index] = *now;
++ timeout_ts_index = (timeout_ts_index + 1) % TIMEOUT_TS_SIZE;
++
++ /* don't waste CPU time if called too frequently */
++ if (ts.l_ui == 0) {
++ next = 1;
++ goto finish;
++ }
++
++ next = current_time + HOUR;
++
++ if (adj_host_clock_needed()) {
++ next = 1;
++ goto finish;
++ }
++ for (n = 0; n < NTP_HASH_SIZE; n++) {
++ for (peer = peer_hash[n]; peer != 0; peer = next_peer) {
++ next_peer = peer->next;
++#ifdef REFCLOCK
++ if (peer->flags & FLAG_REFCLOCK && refclock_timer_needed(peer)) {
++ next = 1;
++ goto finish;
++ }
++#endif /* REFCLOCK */
++ if (peer->action)
++ next = min(next, peer->nextaction);
++ next = min(next, peer->nextdate);
++ }
++ }
++
++ if (leapsec > 0)
++ next = min(next, leapsec);
++
++ if (huffpuff_enabled())
++ next = min(next, huffpuff_timer);
++
++#ifdef OPENSSL
++ if (auth_agekeys_needed())
++ next = min(next, keys_timer);
++ if (sys_leap != LEAP_NOTINSYNC)
++ next = min(next, revoke_timer);
++#endif /* OPENSSL */
++
++ if (interface_interval)
++ next = min(next, interface_timer);
++
++ next = min(next, stats_timer);
++
++ next -= current_time;
++ if (next <= 0)
++ next = 1;
++finish:
++ ts = timer_base;
++ ts.l_ui += next;
++ L_SUB(&ts, now);
++ LFPTOD(&ts, r);
++#ifdef DEBUG
++ DPRINTF(2, ("timer: timeout %f\n", r));
++#endif
++
++ return r;
++}
++
++int
++timer_elapsed(l_fp now, int timeout)
++{
++ int elapsed;
++
++ L_SUB(&now, &timer_base);
++ elapsed = now.l_i;
++ if (elapsed < 0 || elapsed > timeout + 10) {
++#ifdef DEBUG
++ DPRINTF(2, ("timer: unexpected time jump\n"));
++#endif
++ elapsed = 0;
++ reinit_timer();
++
++ }
++ timer_base.l_ui += elapsed;
++ time_elapsed += elapsed;
++ current_time += elapsed;
++#ifdef DEBUG
++ DPRINTF(2, ("timer: time elapsed %d\n", time_elapsed));
++#endif
++ return time_elapsed;
++}
++
+ /*
+ * timer - event timer
+ */
+@@ -251,11 +364,9 @@ timer(void)
+ * kiss-o'-deatch function and implement the association
+ * polling function..
+ */
+- current_time++;
+- get_systime(&sys_time);
+ if (adjust_timer <= current_time) {
+- adjust_timer += 1;
+- adj_host_clock();
++ adjust_timer += time_elapsed;
++ adj_host_clock(time_elapsed);
+ #ifdef REFCLOCK
+ for (n = 0; n < NTP_HASH_SIZE; n++) {
+ for (peer = peer_hash[n]; peer != 0; peer = next_peer) {
+@@ -286,7 +397,7 @@ timer(void)
+ * 128 s or less.
+ */
+ if (peer->throttle > 0)
+- peer->throttle--;
++ peer->throttle -= min(peer->throttle, time_elapsed);
+ if (peer->nextdate <= current_time) {
+ #ifdef REFCLOCK
+ if (peer->flags & FLAG_REFCLOCK)
+@@ -333,7 +444,7 @@ timer(void)
+ * set.
+ */
+ if (leapsec > 0) {
+- leapsec--;
++ leapsec -= min(leapsec, time_elapsed);
+ if (leapsec == 0) {
+ sys_leap = LEAP_NOWARNING;
+ sys_tai = leap_tai;
+@@ -398,11 +509,15 @@ timer(void)
+ * Finally, write hourly stats.
+ */
+ if (stats_timer <= current_time) {
++ l_fp sys_time;
++ get_systime(&sys_time);
+ stats_timer += HOUR;
+ write_stats();
+ if (sys_tai != 0 && sys_time.l_ui > leap_expire)
+ report_event(EVNT_LEAPVAL, NULL, NULL);
+ }
++
++ time_elapsed = 0;
+ }
+
+
+diff -up ntp-4.2.6p1/ntpd/ntpd.c.sleep ntp-4.2.6p1/ntpd/ntpd.c
+--- ntp-4.2.6p1/ntpd/ntpd.c.sleep 2010-03-10 19:27:46.000000000 +0100
++++ ntp-4.2.6p1/ntpd/ntpd.c 2010-03-10 19:27:46.000000000 +0100
+@@ -195,8 +195,6 @@ extern const char *Version;
+
+ char const *progname;
+
+-int was_alarmed;
+-
+ #ifdef DECL_SYSCALL
+ /*
+ * We put this here, since the argument profile is syscall-specific
+@@ -1033,7 +1031,7 @@ getgroup:
+ #else /* normal I/O */
+
+ BLOCK_IO_AND_ALARM();
+- was_alarmed = 0;
++
+ for (;;)
+ {
+ # if !defined(HAVE_SIGNALED_IO)
+@@ -1041,42 +1039,39 @@ getgroup:
+ extern int maxactivefd;
+
+ fd_set rdfdes;
+- int nfound;
+-# endif
++ int nfound, time_elapsed;
+
+- if (alarm_flag) /* alarmed? */
+- {
+- was_alarmed = 1;
+- alarm_flag = 0;
+- }
++ time_elapsed = 0;
++# endif
+
+- if (!was_alarmed && has_full_recv_buffer() == ISC_FALSE)
++ if (has_full_recv_buffer() == ISC_FALSE)
+ {
+ /*
+ * Nothing to do. Wait for something.
+ */
+ # ifndef HAVE_SIGNALED_IO
++ double timeout;
++
+ rdfdes = activefds;
+-# if defined(VMS) || defined(SYS_VXWORKS)
+- /* make select() wake up after one second */
+- {
+- struct timeval t1;
++ get_systime(&now);
++ timeout = get_timeout(&now);
+
+- t1.tv_sec = 1; t1.tv_usec = 0;
++ if (timeout > 0.0) {
++ struct timeval t1;
++
++ t1.tv_sec = timeout;
++ t1.tv_usec = (timeout - t1.tv_sec) * 1000000;
+ nfound = select(maxactivefd+1, &rdfdes, (fd_set *)0,
+ (fd_set *)0, &t1);
+- }
+-# else
+- nfound = select(maxactivefd+1, &rdfdes, (fd_set *)0,
+- (fd_set *)0, (struct timeval *)0);
+-# endif /* VMS */
+- if (nfound > 0)
+- {
+- l_fp ts;
++ get_systime(&now);
++ } else
++ nfound = 0;
+
+- get_systime(&ts);
++ time_elapsed = timer_elapsed(now, timeout);
+
+- (void)input_handler(&ts);
++ if (nfound > 0)
++ {
++ (void)input_handler(&now);
+ }
+ else if (nfound == -1 && errno != EINTR)
+ msyslog(LOG_ERR, "select() error: %m");
+@@ -1085,17 +1080,13 @@ getgroup:
+ msyslog(LOG_DEBUG, "select(): nfound=%d, error: %m", nfound);
+ # endif /* DEBUG */
+ # else /* HAVE_SIGNALED_IO */
++# error not supported by sleep patch
+
+ wait_for_signal();
+ # endif /* HAVE_SIGNALED_IO */
+- if (alarm_flag) /* alarmed? */
+- {
+- was_alarmed = 1;
+- alarm_flag = 0;
+- }
+ }
+
+- if (was_alarmed)
++ if (time_elapsed > 0)
+ {
+ UNBLOCK_IO_AND_ALARM();
+ /*
+@@ -1103,7 +1094,6 @@ getgroup:
+ * to process expiry.
+ */
+ timer();
+- was_alarmed = 0;
+ BLOCK_IO_AND_ALARM();
+ }
+
+@@ -1121,19 +1111,8 @@ getgroup:
+ rbuf = get_full_recv_buffer();
+ while (rbuf != NULL)
+ {
+- if (alarm_flag)
+- {
+- was_alarmed = 1;
+- alarm_flag = 0;
+- }
+ UNBLOCK_IO_AND_ALARM();
+
+- if (was_alarmed)
+- { /* avoid timer starvation during lengthy I/O handling */
+- timer();
+- was_alarmed = 0;
+- }
+-
+ /*
+ * Call the data procedure to handle each received
+ * packet.
diff --git a/server/ntp/files/fedora/ntp-4.2.6p2-html2man.patch b/server/ntp/files/fedora/ntp-4.2.6p2-html2man.patch
new file mode 100644
index 0000000000..a82bc98745
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p2-html2man.patch
@@ -0,0 +1,220 @@
+diff -up ntp-4.2.6p2/scripts/html2man.in.html2man ntp-4.2.6p2/scripts/html2man.in
+--- ntp-4.2.6p2/scripts/html2man.in.html2man 2006-06-06 22:17:10.000000000 +0200
++++ ntp-4.2.6p2/scripts/html2man.in 2010-09-15 16:56:55.000000000 +0200
+@@ -20,31 +20,33 @@ $MANDIR = "./man";
+ # name of man page, man section, 'see also' section
+ %manfiles = (
+ 'ntpd' => ['ntpd', 8, 'ntp.conf(5), ntpq(8), ntpdc(8)'],
+- 'ntpq' => ['ntpq', 8, 'ntpd(8), ntpdc(8)'],
++ 'ntpq' => ['ntpq', 8, 'ntp_decode(5), ntpd(8), ntpdc(8)'],
+ 'ntpdate' => ['ntpdate', 8, 'ntpd(8)'],
+ 'ntpdc' => ['ntpdc', 8, 'ntpd(8)'],
+- 'ntptime' => ['ntpdtime', 8, 'ntpd(8), ntpdate(8)'],
++ 'ntptime' => ['ntptime', 8, 'ntpd(8), ntpdate(8)'],
+ 'ntptrace' => ['ntptrace', 8, 'ntpd(8)'],
++ 'ntp-wait' => ['ntp-wait', 8, 'ntpd(8)'],
+ 'keygen' => ['ntp-keygen', 8, 'ntpd(8), ntp_auth(5)'],
+- 'confopt' => ['ntp.conf', 5, 'ntpd(8)'],
++ 'tickadj' => ['tickadj', 8, 'ntpd(8)'],
++ 'confopt' => ['ntp.conf', 5, 'ntpd(8), ntp_auth(5), ntp_mon(5), ntp_acc(5), ntp_clock(5), ntp_misc(5)'],
+ 'authopt' => ['ntp_auth', 5, 'ntp.conf(5), ntpd(8)'],
+- 'monopt' => ['ntp_mon', 5, 'ntp.conf(5)'],
++ 'monopt' => ['ntp_mon', 5, 'ntp.conf(5), ntp_decode(5)'],
+ 'accopt' => ['ntp_acc', 5, 'ntp.conf(5)'],
+ 'clockopt' => ['ntp_clock', 5, 'ntp.conf(5)'],
++ 'decode' => ['ntp_decode', 5, 'ntpq(8), ntp_mon(5)'],
+ 'miscopt' => ['ntp_misc', 5, 'ntp.conf(5)']);
+
++%table_headers = (
++ 'ntpd' => 'l l l l.',
++ 'ntpq' => 'l l.',
++ 'monopt' => 'l l l.',
++ 'decode' => 'l l l l.',
++ 'authopt' => 'c c c c c c.'
++);
++
+ # Disclaimer to go in SEE ALSO section of the man page
+-$seealso_disclaimer = 'These man pages are automatically hacked from the main NTP ' .
+- 'documentation pages, which are maintained in HTML format. These files are ' .
+- 'included in the NTP source distribution. If you installed NTP from a binary ' .
+- 'package, or it came pre-installed on your system, chances are the documentation ' .
+- 'was also included in the usual place for your system. The HTML files are more ' .
+- 'correct and complete than these man pages, which are provided for your reference ' .
+- 'only.';
+-
+-# Disclaimer to go right at the top
+-$top_disclaimer = 'This file was automatically generated from HTML source, and may be ' .
+- 'incorrect. See the SEE ALSO section at the end of this file for more info';
++$seealso_disclaimer = "HTML documentation in ntp-doc package.\n\n" .
++ "This file was automatically generated from HTML source.\n";
+
+ mkdir $MANDIR, 0777;
+ mkdir "$MANDIR/man8", 0777;
+@@ -64,7 +66,8 @@ sub process {
+ $fileinfo = $manfiles{$filename};
+
+ $p = HTML::TokeParser->new("$filename.html") || die "Can't open $filename.html: $!";
+- open(MANOUT, ">$MANDIR/man$fileinfo->[1]/$fileinfo->[0].$fileinfo->[1]")
++ $fileout = "$MANDIR/man$fileinfo->[1]/$fileinfo->[0].$fileinfo->[1]";
++ open(MANOUT, ">$fileout")
+ || die "Can't open: $!";
+
+ $p->get_tag("title");
+@@ -73,7 +76,6 @@ sub process {
+
+ # Setup man header
+ print MANOUT ".TH " . $fileinfo->[0] . " " . $fileinfo->[1] . "\n";
+- print MANOUT ".UC 4\n";
+ print MANOUT ".SH NAME\n";
+ $pat = $fileinfo->[0];
+ if ($name =~ /$pat/) {
+@@ -81,10 +83,13 @@ sub process {
+ # Add the manpage name, if not in the HTML title already
+ print MANOUT "$fileinfo->[0] - ";
+ }
+- print MANOUT "$name\n\n";
+-
+- print MANOUT "$top_disclaimer\n";
++ print MANOUT "$name\n.SH \\ \n\n";
+
++ @fontstack = ();
++ $deflevel = 0;
++ $pre = 0;
++ $ignore = 0;
++ $first_td = 1;
+ # Now start scanning. We basically print everything after translating some tags.
+ # $token->[0] has "T", "S", "E" for Text, Start, End
+ # $token->[1] has the tag name, or text (for "T" case)
+@@ -92,19 +97,37 @@ sub process {
+ while (my $token = $p->get_token) {
+ if($token->[0] eq "T") {
+ my $text = $token->[1];
+- if($tag) {
+- $text =~ s/^[\n ]*//;
+- $text =~ s/[\n ]*$/ /;
++ if (!$pre) {
++ if($tag) {
++ $text =~ s/^[\n\t ]*//;
++ }
++ $text =~ s/^[\n\t ][\n\t ]+$//;
++ $text =~ s/[\n\t ]+/ /g;
++ $text =~ s/ \;/ /g;
++ $text =~ s/>\;/>/g;
++ $text =~ s/<\;/[0] eq "S") {
+ if($token->[1] eq "h4") {
+ my $text = uc($p->get_trimmed_text("/h4"));
+- print MANOUT ".SH $text\n";
++ # ignore these sections in ntpd.html
++ if ($filename eq "ntpd" &&
++ ($text eq "CONFIGURATION OPTIONS")) {
++ $ignore = 1;
++ close(MANOUT);
++ open(MANOUT, ">/dev/null");
++ } elsif ($ignore) {
++ $ignore = 0;
++ close(MANOUT);
++ open(MANOUT, ">>$fileout");
++ }
++ print MANOUT "\n\n.SH $text\n";
+ }
+ if($token->[1] eq "tt") {
+ push @fontstack, "tt";
+@@ -118,22 +141,42 @@ sub process {
+ my $text = $p->get_trimmed_text("/address");
+ print MANOUT "\n.SH AUTHOR\n$text\n";
+ }
+- if($token->[1] eq "dt") {
+- $tmp = $deflevel-4;
+- print MANOUT "\n.RS $tmp\n";
++ if($token->[1] eq "dt" || $token->[1] eq "br" && $deflevel > 0) {
++ print MANOUT "\n.TP 8\n";
+ $tag = 1;
+ }
+ if($token->[1] eq "dd") {
+- print MANOUT "\n.RS $deflevel\n";
++ print MANOUT "\n";
+ $tag = 1;
+ }
+ if($token->[1] eq "dl") {
+- $deflevel+=4;
++ $deflevel+=1;
++ if ($deflevel > 0) {
++ print MANOUT "\n.RS ", $deflevel > 1 ? 8 : 0;
++ }
++ }
++ if($token->[1] eq "p") {
++ print MANOUT "\n";
++ }
++ if($token->[1] eq "pre") {
++ print MANOUT "\n.nf";
++ $pre = 1;
++ }
++ if($token->[1] eq "table") {
++ print MANOUT "\n.TS\n";
++ print MANOUT "expand allbox tab(%);\n";
++ print MANOUT $table_headers{$filename};
++ print MANOUT "\n";
++ }
++ if($token->[1] eq "td") {
++ if ($first_td == 0) {
++ print MANOUT " % ";
++ }
++ $first_td = 0;
+ }
+ }
+ elsif($token->[0] eq "E") {
+- if($token->[1] eq "dd") {
+- print MANOUT "\n.RE\n";
++ if($token->[1] eq "h4") {
+ $tag = 1;
+ }
+ if($token->[1] eq "tt") {
+@@ -157,15 +200,34 @@ sub process {
+ print MANOUT "$fontswitch";
+ }
+ if($token->[1] eq "dl") {
+- $deflevel-=4;
++ if ($deflevel > 0) {
++ print MANOUT "\n.RE";
++ }
++ print MANOUT "\n";
++ $deflevel-=1;
+ }
+- if($token->[1] eq "dt") {
+- print MANOUT "\n.RE";
++ if($token->[1] eq "p") {
++ print MANOUT "\n";
+ $tag = 1;
+ }
++ if($token->[1] eq "pre") {
++ print MANOUT "\n.fi";
++ $pre = 0;
++ }
++ if($token->[1] eq "table") {
++ print MANOUT ".TE\n";
++ }
++ if($token->[1] eq "tr") {
++ print MANOUT "\n";
++ $first_td = 1;
++ }
+ }
+ }
+- print MANOUT ".SH SEE ALSO\n\n";
++ if ($ignore) {
++ close(MANOUT);
++ open(MANOUT, ">>$fileout");
++ }
++ print MANOUT "\n.SH SEE ALSO\n\n";
+ print MANOUT "$fileinfo->[2]\n\n";
+ print MANOUT "$seealso_disclaimer\n";
+ close(MANOUT);
diff --git a/server/ntp/files/fedora/ntp-4.2.6p2-htmldoc.patch b/server/ntp/files/fedora/ntp-4.2.6p2-htmldoc.patch
new file mode 100644
index 0000000000..5ec30707f1
--- /dev/null
+++ b/server/ntp/files/fedora/ntp-4.2.6p2-htmldoc.patch
@@ -0,0 +1,394 @@
+diff -up ntp-4.2.6p2/html/authopt.html.htmldoc ntp-4.2.6p2/html/authopt.html
+--- ntp-4.2.6p2/html/authopt.html.htmldoc 2010-04-18 10:05:39.000000000 +0200
++++ ntp-4.2.6p2/html/authopt.html 2010-07-12 16:31:43.000000000 +0200
+@@ -208,11 +208,7 @@ UTC
+
+
+
+-
Client
+-
Server
+-
+-
+-
++
Client/Server
+
NONE
+
AUTH
+
PC
+@@ -368,7 +364,7 @@ UTC
+ are left unspecified, the default names are used as described below. Unless
+ the complete path and name of the file are specified, the location of a file
+ is relative to the keys directory specified in the keysdir configuration
+- command or default /usr/local/etc. Following are the options.
++ command or default /etc/ntp/crypto. Following are the options.
+
+
+
+@@ -400,7 +396,7 @@ UTC
+
Specifies the complete path to the MD5 key file containing the keys and key IDs used by ntpd, ntpq and ntpdc when operating with symmetric key cryptography. This is the same operation as the -k command line option. Note that the directory path for Autokey media is specified by the keysdir command.
+
+
keysdir pathK
+-
This command specifies the default directory path for Autokey cryptographic keys, parameters and certificates. The default is /usr/local/etc/. Note that the path for the symmetric keys file is specified by the keys command.
++
This command specifies the default directory path for Autokey cryptographic keys, parameters and certificates. The default is /etc/ntp/crypto. Note that the path for the symmetric keys file is specified by the keys command.
+
+
requestkey keyid
+
Specifies the key ID to use with the
+@@ -494,4 +490,4 @@ UTC
+
+