Merge pull request #44 from ayhanyalcinsoy/master

NM and deps moved into main repo for pisi 2.0
This commit is contained in:
Ertuğrul Erata
2015-07-04 22:22:32 +03:00
166 changed files with 16979 additions and 0 deletions
+33
View File
@@ -0,0 +1,33 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import shelltools
def setup():
# use python2.x
pisitools.dosed("configure", "(\/usr\/include\/)python\*", r"\1python2*")
# fix unused direct dependency
pisitools.dosed("Makefile.in", "(PLFLAGS=)`\$\$pyconfig --libs`", r"\1'-lpython2.7'")
pisitools.dosed("Makefile.in", "(PLDFLAGS=)`\$\$pyconfig --ldflags`", r"\1'-lpython2.7 -Xlinker -export-dynamic'")
shelltools.echo("config.h.in", "#define USE_INTERP_RESULT 1")
shelltools.export("PYTHON", "/usr/bin/python2.7")
autotools.configure("\
--with-gpm-support \
")
def build():
autotools.make()
def install():
autotools.install()
# remove static lib
pisitools.remove("/usr/lib/libnewt.a")
pisitools.dodoc("CHANGES", "COPYING")
+85
View File
@@ -0,0 +1,85 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>newt</Name>
<Homepage>https://fedorahosted.org/newt/</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>GPLv2</License>
<IsA>library</IsA>
<IsA>app:console</IsA>
<Summary>A windowing toolkit for text mode</Summary>
<Description>newt is a windowing toolkit for text mode, which provides many widgets and stackable windows.</Description>
<Archive sha1sum="9204940f8cd80910a1d0e80c9bc1b946eb6e730d" type="targz">https://fedorahosted.org/releases/n/e/newt/newt-0.52.17.tar.gz</Archive>
<BuildDependencies>
<Dependency versionFrom="8.6.0">tcl-devel</Dependency>
</BuildDependencies>
</Source>
<Package>
<Name>newt</Name>
<RuntimeDependencies>
<Dependency versionFrom="8.6.0">tcl</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="localedata">/usr/share/locale</Path>
<Path fileType="doc">/usr/share/doc</Path>
<Path fileType="man">/usr/share/man</Path>
</Files>
</Package>
<Package>
<Name>newt-devel</Name>
<Summary>Development files for newt</Summary>
<RuntimeDependencies>
<Dependency release="current">newt</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include</Path>
<Path fileType="data">/usr/lib/pkgconfig</Path>
</Files>
</Package>
<History>
<Update release="5">
<Date>2014-07-05</Date>
<Version>0.52.17</Version>
<Comment>Version bump.</Comment>
<Name>Serdar Soytetir</Name>
<Email>kaptan@pisilinux.org</Email>
</Update>
<Update release="4">
<Date>2013-11-05</Date>
<Version>0.52.16</Version>
<Comment>Version bump.</Comment>
<Name>Serdar Soytetir</Name>
<Email>kaptan@pisilinux.org</Email>
</Update>
<Update release="3">
<Date>2013-08-26</Date>
<Version>0.52.14</Version>
<Comment>Release bump.</Comment>
<Name>Serdar Soytetir</Name>
<Email>kaptan@pisilinux.org</Email>
</Update>
<Update release="2">
<Date>2013-01-30</Date>
<Version>0.52.14</Version>
<Comment>Build with new relaese Tcl</Comment>
<Name>Erdinç Gültekin</Name>
<Email>admins@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2012-09-17</Date>
<Version>0.52.14</Version>
<Comment>First release</Comment>
<Name>Serdar Soytetir</Name>
<Email>kaptan@pisilinux.org</Email>
</Update>
</History>
</PISI>
+13
View File
@@ -0,0 +1,13 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>newt</Name>
<Summary xml:lang="tr">Metin tabanlı bir pencere araç seti.</Summary>
<Description xml:lang="tr">Newt, metin tabanlı bir pencere araç setidir. Pek çok alet ve istiflenebilir pencere sağlar.</Description>
</Source>
<Package>
<Name>newt-devel</Name>
<Summary xml:lang="tr">newt için geliştirme dosyaları</Summary>
</Package>
</PISI>
+83
View File
@@ -0,0 +1,83 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import get
def setup():
#shelltools.system("sed -i -e '/SystemdService/d' obexd/src/org.bluez.obex.service.in")
pisitools.dosed("obexd/src/org.bluez.obex.service.in", "SystemdService", deleteLine=True)
autotools.autoreconf("-fi")
autotools.configure("--prefix=/usr \
--sysconfdir=/etc \
--localstatedir=/var \
--libexecdir=/usr/libexec/ \
--enable-sixaxis \
--enable-experimental \
--disable-android \
--enable-datafiles \
--enable-optimization \
--enable-pie \
--enable-threads \
--enable-library \
--enable-tools \
--enable-manpages \
--enable-monitor \
--enable-udev \
--enable-test \
--disable-systemd")
pisitools.dosed("libtool", " -shared ", " -Wl,-O1,--as-needed -shared ")
def build():
autotools.make()
def install():
autotools.rawInstall("DESTDIR=%s install-libexecPROGRAMS install-dbussessionbusDATA install-dbussystembusDATA install-dbusDATA install-man8" % get.installDIR())
# Install conf files
for i in ["profiles/input", "profiles/network" ,"src"]:
pisitools.insinto("/etc/bluetooth", "%s/*.conf" % (i))
# Simple test tools
for i in ["bluezutils.py",
"dbusdef.py",
"ftp-client",
"list-devices",
"map-client",
"monitor-bluetooth",
"opp-client",
"pbap-client",
"sap_client.py",
"simple-agent",
"simple-endpoint",
"simple-player",
"test-adapter",
"test-alert",
"test-cyclingspeed",
"test-device",
"test-discovery",
"test-health",
"test-health-sink",
"test-heartrate",
"test-hfp",
"test-manager",
"test-nap",
"test-network",
"test-profile",
"test-proximity",
"test-sap-server",
"test-thermometer"]:
pisitools.dobin("test/%s" % i)
# for i in
# pisitools.dodoc("doc/%s" % i)
# Install documents
pisitools.dodoc("AUTHORS", "ChangeLog", "README")
+33
View File
@@ -0,0 +1,33 @@
from comar.service import *
import os
serviceType = "local"
serviceDesc = _({"en": "Bluetooth Service",
"tr": "Bluetooth Hizmeti"})
serviceDefault = "on"
PIDFILE="/run/bluez.pid"
DAEMON ="/usr/libexec/bluetooth/bluetoothd"
@synchronized
def start():
startService(command=DAEMON,
pidfile=PIDFILE,
detach=True,
donotify=True)
os.system("pidof bluez + /usr/libexec/bluetooth/bluetoothd > /run/bluez.pid")
@synchronized
def stop():
stopService(pidfile=PIDFILE,
donotify=True)
try:
os.unlink(PIDFILE)
except:
pass
def status():
return isServiceRunning(pidfile=PIDFILE)
@@ -0,0 +1,61 @@
Submitted By: Armin K. <krejzi at email dot com>
Date: 2013-04-29
Initial Package Version: 5.17
Upstream Status: unknown
Origin: Arch Linux (Giovanni Campagna)
Description: Allow using obexd without systemd in the user session
Not all sessions run systemd --user (actually, the majority
doesn't), so the dbus daemon must be able to spawn obexd
directly, and to do so it needs the full path of the daemon.
---
Makefile.obexd | 4 ++--
obexd/src/org.bluez.obex.service | 4 ----
obexd/src/org.bluez.obex.service.in | 4 ++++
3 files changed, 6 insertions(+), 6 deletions(-)
delete mode 100644 obexd/src/org.bluez.obex.service
create mode 100644 obexd/src/org.bluez.obex.service.in
diff --git a/Makefile.obexd b/Makefile.obexd
index 3760867..142e7c3 100644
--- a/Makefile.obexd
+++ b/Makefile.obexd
@@ -2,12 +2,12 @@
if SYSTEMD
systemduserunitdir = @SYSTEMD_USERUNITDIR@
systemduserunit_DATA = obexd/src/obex.service
+endif
dbussessionbusdir = @DBUS_SESSIONBUSDIR@
dbussessionbus_DATA = obexd/src/org.bluez.obex.service
-endif
-EXTRA_DIST += obexd/src/obex.service.in obexd/src/org.bluez.obex.service
+EXTRA_DIST += obexd/src/obex.service.in obexd/src/org.bluez.obex.service.in
obex_plugindir = $(libdir)/obex/plugins
diff --git a/obexd/src/org.bluez.obex.service b/obexd/src/org.bluez.obex.service
deleted file mode 100644
index a538088..0000000
--- a/obexd/src/org.bluez.obex.service
+++ /dev/null
@@ -1,4 +0,0 @@
-[D-BUS Service]
-Name=org.bluez.obex
-Exec=/bin/false
-SystemdService=dbus-org.bluez.obex.service
diff --git a/obexd/src/org.bluez.obex.service.in b/obexd/src/org.bluez.obex.service.in
new file mode 100644
index 0000000..9c815f2
--- /dev/null
+++ b/obexd/src/org.bluez.obex.service.in
@@ -0,0 +1,4 @@
+[D-BUS Service]
+Name=org.bluez.obex
+Exec=@libexecdir@/obexd
+SystemdService=dbus-org.bluez.obex.service
--
1.8.3.1
@@ -0,0 +1,61 @@
Submitted By: Armin K. <krejzi at email dot com>
Date: 2013-04-29
Initial Package Version: 5.17
Upstream Status: unknown
Origin: Arch Linux (Giovanni Campagna)
Description: Allow using obexd without systemd in the user session
Not all sessions run systemd --user (actually, the majority
doesn't), so the dbus daemon must be able to spawn obexd
directly, and to do so it needs the full path of the daemon.
---
Makefile.obexd | 4 ++--
obexd/src/org.bluez.obex.service | 4 ----
obexd/src/org.bluez.obex.service.in | 4 ++++
3 files changed, 6 insertions(+), 6 deletions(-)
delete mode 100644 obexd/src/org.bluez.obex.service
create mode 100644 obexd/src/org.bluez.obex.service.in
diff --git a/Makefile.obexd b/Makefile.obexd
index 3760867..142e7c3 100644
--- a/Makefile.obexd
+++ b/Makefile.obexd
@@ -2,12 +2,12 @@
if SYSTEMD
systemduserunitdir = @SYSTEMD_USERUNITDIR@
systemduserunit_DATA = obexd/src/obex.service
+endif
dbussessionbusdir = @DBUS_SESSIONBUSDIR@
dbussessionbus_DATA = obexd/src/org.bluez.obex.service
-endif
-EXTRA_DIST += obexd/src/obex.service.in obexd/src/org.bluez.obex.service
+EXTRA_DIST += obexd/src/obex.service.in obexd/src/org.bluez.obex.service.in
obex_plugindir = $(libdir)/obex/plugins
diff --git a/obexd/src/org.bluez.obex.service b/obexd/src/org.bluez.obex.service
deleted file mode 100644
index a538088..0000000
--- a/obexd/src/org.bluez.obex.service
+++ /dev/null
@@ -1,4 +0,0 @@
-[D-BUS Service]
-Name=org.bluez.obex
-Exec=/bin/false
-SystemdService=dbus-org.bluez.obex.service
diff --git a/obexd/src/org.bluez.obex.service.in b/obexd/src/org.bluez.obex.service.in
new file mode 100644
index 0000000..9c815f2
--- /dev/null
+++ b/obexd/src/org.bluez.obex.service.in
@@ -0,0 +1,4 @@
+[D-BUS Service]
+Name=org.bluez.obex
+Exec=@libexecdir@/obexd
+SystemdService=dbus-org.bluez.obex.service
--
1.8.3.1
@@ -0,0 +1,61 @@
Submitted By: Armin K. <krejzi at email dot com>
Date: 2013-04-29
Initial Package Version: 5.17
Upstream Status: unknown
Origin: Arch Linux (Giovanni Campagna)
Description: Allow using obexd without systemd in the user session
Not all sessions run systemd --user (actually, the majority
doesn't), so the dbus daemon must be able to spawn obexd
directly, and to do so it needs the full path of the daemon.
---
Makefile.obexd | 4 ++--
obexd/src/org.bluez.obex.service | 4 ----
obexd/src/org.bluez.obex.service.in | 4 ++++
3 files changed, 6 insertions(+), 6 deletions(-)
delete mode 100644 obexd/src/org.bluez.obex.service
create mode 100644 obexd/src/org.bluez.obex.service.in
diff --git a/Makefile.obexd b/Makefile.obexd
index 3760867..142e7c3 100644
--- a/Makefile.obexd
+++ b/Makefile.obexd
@@ -2,12 +2,12 @@
if SYSTEMD
systemduserunitdir = @SYSTEMD_USERUNITDIR@
systemduserunit_DATA = obexd/src/obex.service
+endif
dbussessionbusdir = @DBUS_SESSIONBUSDIR@
dbussessionbus_DATA = obexd/src/org.bluez.obex.service
-endif
-EXTRA_DIST += obexd/src/obex.service.in obexd/src/org.bluez.obex.service
+EXTRA_DIST += obexd/src/obex.service.in obexd/src/org.bluez.obex.service.in
obex_plugindir = $(libdir)/obex/plugins
diff --git a/obexd/src/org.bluez.obex.service b/obexd/src/org.bluez.obex.service
deleted file mode 100644
index a538088..0000000
--- a/obexd/src/org.bluez.obex.service
+++ /dev/null
@@ -1,4 +0,0 @@
-[D-BUS Service]
-Name=org.bluez.obex
-Exec=/bin/false
-SystemdService=dbus-org.bluez.obex.service
diff --git a/obexd/src/org.bluez.obex.service.in b/obexd/src/org.bluez.obex.service.in
new file mode 100644
index 0000000..9c815f2
--- /dev/null
+++ b/obexd/src/org.bluez.obex.service.in
@@ -0,0 +1,4 @@
+[D-BUS Service]
+Name=org.bluez.obex
+Exec=@libexecdir@/obexd
+SystemdService=dbus-org.bluez.obex.service
--
1.8.3.1
+156
View File
@@ -0,0 +1,156 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>bluez</Name>
<Homepage>http://bluez.sourceforge.net</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>GPLv2+</License>
<IsA>service</IsA>
<IsA>library</IsA>
<IsA>app:console</IsA>
<Summary>Official Linux Bluetooth protocol stack</Summary>
<Description>bluez contains the tools and libraries that provides support for the core Bluetooth layers and protocols.</Description>
<Archive sha1sum="c1707e8ae38b299c07e6c18ff3c26a4b928d03bf" type="tarxz">https://www.kernel.org/pub/linux/bluetooth/bluez-5.27.tar.xz</Archive>
<BuildDependencies>
<Dependency>cups-devel</Dependency>
<Dependency>dbus-devel</Dependency>
<Dependency>libnl-devel</Dependency>
<Dependency>alsa-lib-devel</Dependency>
<Dependency>gstreamer-devel</Dependency>
<Dependency>libsndfile-devel</Dependency>
<Dependency>gst-plugins-base-devel</Dependency>
<Dependency>libical-devel</Dependency>
<Dependency>glib2-devel</Dependency>
<Dependency>libical-devel</Dependency>
</BuildDependencies>
<Patches>
<Patch level="1">bluez-5.27-obexd_without_systemd-1.patch</Patch>
</Patches>
</Source>
<Package>
<Name>bluez</Name>
<RuntimeDependencies>
<Dependency>cups</Dependency>
<Dependency>libnl</Dependency>
<Dependency>libusb</Dependency>
<Dependency>libical</Dependency>
<Dependency>alsa-lib</Dependency>
<Dependency>alsa-lib</Dependency>
<Dependency>setserial</Dependency>
<Dependency>gstreamer</Dependency>
<Dependency>libsndfile</Dependency>
<Dependency>gst-plugins-base</Dependency>
<Dependency release="current">bluez-libs</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="data">/lib/udev/rules.d</Path>
<Path fileType="data">/lib/systemd/system</Path>
<Path fileType="data">/usr/share/misc</Path>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="executable">/lib/udev</Path>
<Path fileType="executable">/lib/bluetooth/obexd</Path>
<Path fileType="executable">/lib/bluetooth/bluetoothd</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="executable">/usr/libexec</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="data">/var/lib/bluetooth</Path>
<Path fileType="data">/usr/share/alsa/bluetooth.conf</Path>
<Path fileType="data">/usr/share/dbus-1</Path>
<Path fileType="config">/etc</Path>
</Files>
<Provides>
<COMAR script="service.py">System.Service</COMAR>
</Provides>
</Package>
<Package>
<Name>bluez-libs</Name>
<Summary>Libraries for use in Bluetooth applications</Summary>
<RuntimeDependencies>
<Dependency>libical</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="library">/usr/lib/libbluetooth.so*</Path>
<Path fileType="doc">/usr/share/doc</Path>
</Files>
</Package>
<Package>
<Name>bluez-libs-devel</Name>
<Summary>Development files for bluez-libs</Summary>
<RuntimeDependencies>
<Dependency release="current">bluez-libs</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include/bluetooth</Path>
<Path fileType="data">/usr/lib/pkgconfig</Path>
</Files>
<Provides>
</Provides>
</Package>
<History>
<Update release="8">
<Date>2015-01-29</Date>
<Version>5.27</Version>
<Comment>rebuild.</Comment>
<Name>Vedat Demir</Name>
<Email>vedat@pisilinux.org</Email>
</Update>
<Update release="7">
<Date>2015-01-25</Date>
<Version>5.27</Version>
<Comment>Version bump.</Comment>
<Name>Stefan Gronewold(groni)</Name>
<Email>groni@pisilinux.org</Email>
</Update>
<Update release="6">
<Date>2014-07-05</Date>
<Version>5.21</Version>
<Comment>Version bump and bugs fix.</Comment>
<Name>Vedat Demir</Name>
<Email>vedat@pisilinux.org</Email>
</Update>
<Update release="5">
<Date>2014-05-23</Date>
<Version>5.18</Version>
<Comment>Version bump</Comment>
<Name>Burak Fazıl Ertürk</Name>
<Email>burakerturk@pisilinux.org</Email>
</Update>
<Update release="4">
<Date>2014-01-28</Date>
<Version>4.101</Version>
<Comment>Rebuild Unused</Comment>
<Name>Varol Maksutoğlu</Name>
<Email>waroi@pisilinux.org</Email>
</Update>
<Update release="3">
<Date>2013-08-27</Date>
<Version>4.101</Version>
<Comment>R.Bump</Comment>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
<Update release="2">
<Date>2013-06-28</Date>
<Version>4.101</Version>
<Comment>Add patches, --enable-hid2hci --enable-wiimote</Comment>
<Name>Marcin Bojara</Name>
<Email>marcin@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2013-01-09</Date>
<Version>4.101</Version>
<Comment>First release</Comment>
<Name>Erdinç Gültekin</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
+18
View File
@@ -0,0 +1,18 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>bluez</Name>
<Summary xml:lang="tr">Linux resmi Bluetooth protokol yığını</Summary>
<Description xml:lang="tr">Bu projenin genel amacı Linux'ta Bluetooth kablosuz standartların ayrıntılarını yerine getirmektir.</Description>
</Source>
<Package>
<Name>bluez-libs</Name>
<Summary xml:lang="tr">Uygulamalar için bluetooth erişim kitaplığı</Summary>
</Package>
<Package>
<Name>bluez-libs-devel</Name>
<Summary xml:lang="tr">bluez-libs için geliştirme dosyaları</Summary>
</Package>
</PISI>
@@ -0,0 +1,29 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import shelltools
from pisi.actionsapi import pisitools
from pisi.actionsapi import autotools
from pisi.actionsapi import get
def setup():
#shelltools.system("./autogen.sh")
autotools.configure("--disable-static \
--enable-more-warnings=yes \
--with-udev-base-dir=/lib/udev \
--with-tests=yes \
--with-polkit=no")
def build():
autotools.make()
def check():
autotools.make("check")
def install():
autotools.rawInstall("DESTDIR=%s" % get.installDIR())
pisitools.dodoc("README", "COPYING")
+107
View File
@@ -0,0 +1,107 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>ModemManager</Name>
<Homepage>http://projects.gnome.org/NetworkManager</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>LGPLv2.1</License>
<IsA>app:console</IsA>
<IsA>service</IsA>
<Summary>A manager framework for mobile broadband modems</Summary>
<Description>ModemManager provides a unified high level API for communicating with mobile broadband modems.</Description>
<Archive sha1sum="1e17965716a1b27a8b250e813dbeb135d88b0bb9" type="tarxz">http://www.freedesktop.org/software/ModemManager/ModemManager-1.2.0.tar.xz</Archive>
<BuildDependencies>
<Dependency>ppp-devel</Dependency>
<Dependency>libqmi-devel</Dependency>
<Dependency>libmbim-devel</Dependency>
</BuildDependencies>
</Source>
<Package>
<Name>ModemManager</Name>
<RuntimeDependencies>
<Dependency>ppp</Dependency>
<Dependency>libqmi</Dependency>
<Dependency>libmbim</Dependency>
<Dependency>libmm-glib</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="doc">/usr/share/doc</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="data">/usr/share/icons</Path>
<Path fileType="localedata">/usr/share/locale</Path>
<Path fileType="data">/usr/share/dbus-1</Path>
<Path fileType="data">/usr/share/gir-1.0/ModemManager-1.0.gir</Path>
<Path fileType="data">/lib/udev/rules.d/</Path>
<Path fileType="data">/etc/dbus-1/system.d/</Path>
<Path fileType="library">/usr/lib/ModemManager</Path>
<Path fileType="library">/usr/lib/girepository-1.0/ModemManager-1.0.typelib</Path>
<Path fileType="man">/usr/share/man/man8/ModemManager.8</Path>
</Files>
</Package>
<Package>
<Name>ModemManager-devel</Name>
<Summary>Development files for ModemManager</Summary>
<RuntimeDependencies>
<Dependency release="current">ModemManager</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include/ModemManager/</Path>
<Path fileType="data">/usr/lib/pkgconfig/ModemManager.pc</Path>
</Files>
</Package>
<Package>
<Name>libmm-glib</Name>
<Summary>D-Bus service for managing modems - shared libraries</Summary>
<Files>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="data">/usr/share/vala/vapi/libmm-glib.vapi </Path>
<Path fileType="data">/usr/share/vala/vapi/libmm-glib.deps </Path>
<Path fileType="data">/usr/lib/libmm-glib.so*</Path>
<Path fileType="man">/usr/share/man/man8/mmcli.8</Path>
</Files>
</Package>
<Package>
<Name>libmm-glib-devel</Name>
<Summary>Development files for libmm-glib</Summary>
<RuntimeDependencies>
<Dependency>ModemManager-devel</Dependency>
<Dependency release="current">libmm-glib</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include/libmm-glib/</Path>
<Path fileType="data">/usr/lib/pkgconfig/mm-glib.pc</Path>
</Files>
</Package>
<History>
<Update release="3">
<Date>2014-02-17</Date>
<Version>1.2.0</Version>
<Comment>Version bump.</Comment>
<Name>Yusuf Aydemir</Name>
<Email>yusuf.aydemir@pisilinux.org</Email>
</Update>
<Update release="2">
<Date>2014-01-20</Date>
<Version>1.0.0</Version>
<Comment>Version Bump</Comment>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2012-08-28</Date>
<Version>5.3.96</Version>
<Comment>First release</Comment>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
@@ -0,0 +1,24 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>ModemManager</Name>
<Summary xml:lang="tr">Mobil modemler için yönetim katmanı</Summary>
<Description xml:lang="tr">ModemManager, 3G ve GSM gibi mobil genişbant modemlerle D-Bus üzerinden iletişimi sağlayan bir sistem hizmetidir.</Description>
</Source>
<Package>
<Name>ModemManager-devel</Name>
<Summary xml:lang="tr">ModemManager için geliştirme dosyaları</Summary>
</Package>
<Package>
<Name>libmm-glib</Name>
<Summary xml:lang="en">D-Bus service for managing modems - shared libraries</Summary>
</Package>
<Package>
<Name>libmm-glib-devel</Name>
<Summary xml:lang="en">Development files for libmm-glib</Summary>
<Summary xml:lang="tr">libmm-glib için geliştirme dosyaları</Summary>
</Package>
</PISI>
+21
View File
@@ -0,0 +1,21 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import get
def setup():
autotools.configure("--disable-static")
def build():
autotools.make("-j1")
def install():
autotools.rawInstall("DESTDIR=%s man_prefix=/usr/share/man" % get.installDIR())
pisitools.insinto("/etc", "src/config/hosts.atm")
pisitools.dodoc("AUTHORS", "THANKS", "ChangeLog", "BUGS", "NEWS", "README")
@@ -0,0 +1,11 @@
diff -Nur linux-atm-2.5.0-old/src/led/main.c linux-atm-2.5.0/src/led/main.c
--- linux-atm-2.5.0-old/src/led/main.c 2008-04-25 03:39:28.000000000 +0300
+++ linux-atm-2.5.0/src/led/main.c 2008-04-25 03:39:43.000000000 +0300
@@ -46,6 +46,7 @@
#include <atmd.h>
#include <linux/atmlec.h>
+#include <limits.h>
/* Local incs */
#include "join.h"
@@ -0,0 +1,11 @@
--- linux-atm/src/ilmid/Makefile.am~ 2007-07-11 17:07:57.000000000 +0100
+++ linux-atm/src/ilmid/Makefile.am 2007-08-23 09:22:45.000000000 +0100
@@ -2,7 +2,7 @@ SUBDIRS = asn1
INCLUDES = -I$(srcdir)/../ilmid/asn1
-sbin_PROGRAMS = ilmid ilmidiag
+sbin_PROGRAMS = ilmid
ilmid_SOURCES = rfc1157_snmp.c rfc1157_snmp.h rfc1155_smi.c rfc1155_smi.h \
util.c util.h io.c io.h message.c message.h \
@@ -0,0 +1,11 @@
--- linux-atm/src/maint/atmtcp.c~ 2007-08-22 14:59:21.000000000 +0100
+++ linux-atm/src/maint/atmtcp.c 2007-08-22 18:27:24.000000000 +0100
@@ -109,7 +109,7 @@ static void control(int in_link,struct a
switch (msg->type) {
case ATMTCP_CTRL_OPEN:
if (out->ops->open)
- changed += out->ops->open(out,in_link,msg);
+ changed += (out->ops->open)(out,in_link,msg);
break;
case ATMTCP_CTRL_CLOSE:
if (out->ops->close)
@@ -0,0 +1,45 @@
diff -up linux-atm-2.5.1/src/led/zeppelin.8.fixman linux-atm-2.5.1/src/led/zeppelin.8
--- linux-atm-2.5.1/src/led/zeppelin.8.fixman 2003-05-02 19:35:04.000000000 +0200
+++ linux-atm-2.5.1/src/led/zeppelin.8 2010-10-13 12:58:18.000000000 +0200
@@ -99,7 +99,7 @@ Ring and ATM parts of the ELAN, so using
recommended. Token Ring support has received less testing than its
Ethernet counterpart.
.SH FILES
-.IP \fI/var/run/lec[interface number].pid\fP
+\fI/var/run/lec[interface number].pid\fP
The file containing the process id of zeppelin.
.SH BUGS
John Bonham died 1980 and Led Zeppelin broke.
diff -up linux-atm-2.5.1/src/mpoad/mpcd.8.fixman linux-atm-2.5.1/src/mpoad/mpcd.8
--- linux-atm-2.5.1/src/mpoad/mpcd.8.fixman 2001-10-10 00:33:07.000000000 +0200
+++ linux-atm-2.5.1/src/mpoad/mpcd.8 2010-10-13 12:59:14.000000000 +0200
@@ -28,7 +28,7 @@ mpcd \- ATM MPOA (Multi\-Protocol Over A
.B ]]
.SH DESCRIPTION
MPOA client
-.SM(MPC) is responsible for creating and receiving
+.SM (MPC) is responsible for creating and receiving
internetwork layer shortcuts. Using these shortcuts MPCs forward
unicast internetwork layer packets effectively over ATM without need
for routing protocols.
@@ -43,7 +43,7 @@ accepts shortcuts and packets arriving o
shortcuts is done with the help of
.SM MPOA
server
-.SM(MPS).
+.SM (MPS).
.PP
Just as the Linux
.SM LAN
diff -up linux-atm-2.5.1/src/sigd/atmsigd.conf.4.fixman linux-atm-2.5.1/src/sigd/atmsigd.conf.4
--- linux-atm-2.5.1/src/sigd/atmsigd.conf.4.fixman 2001-10-10 00:33:07.000000000 +0200
+++ linux-atm-2.5.1/src/sigd/atmsigd.conf.4 2010-10-13 12:58:49.000000000 +0200
@@ -125,7 +125,7 @@ a comment. The `#' character cannot be e
.P
If an option is specified in \fBatmsigd.conf\fP and on the command
line, the command line has priority.
-.COMPATIBILITY
+.SH COMPATIBILITY
Certain options used by past versions of \fBatmsigd\fP but no longer documented
on the man page are still recognized and supported, but they also yield a
warning message. Future versions of \fBatmsigd\fP will not recognize those
@@ -0,0 +1,33 @@
diff -Nur linux-atm-2.5.0-old/src/arpd/arp.c linux-atm-2.5.0/src/arpd/arp.c
--- linux-atm-2.5.0-old/src/arpd/arp.c 2008-04-25 03:34:35.000000000 +0300
+++ linux-atm-2.5.0/src/arpd/arp.c 2008-04-25 03:34:51.000000000 +0300
@@ -15,7 +15,6 @@
#include <sys/types.h>
#include <sys/socket.h> /* for linux/if_arp.h */
#include <netinet/in.h> /* for ntohs, etc. */
-#define _LINUX_NETDEVICE_H /* very crude hack for glibc2 */
#include <linux/types.h>
#include <linux/if_arp.h>
#include <linux/if_ether.h>
diff -Nur linux-atm-2.5.0-old/src/arpd/io.c linux-atm-2.5.0/src/arpd/io.c
--- linux-atm-2.5.0-old/src/arpd/io.c 2008-04-25 03:34:35.000000000 +0300
+++ linux-atm-2.5.0/src/arpd/io.c 2008-04-25 03:34:51.000000000 +0300
@@ -21,7 +21,6 @@
#include <atm.h>
#include <linux/atmclip.h> /* for CLIP_DEFAULT_IDLETIMER */
#include <linux/atmarp.h>
-#define _LINUX_NETDEVICE_H /* glibc2 */
#include <linux/types.h>
#include <linux/if_arp.h>
diff -Nur linux-atm-2.5.0-old/src/arpd/itf.c linux-atm-2.5.0/src/arpd/itf.c
--- linux-atm-2.5.0-old/src/arpd/itf.c 2008-04-25 03:34:35.000000000 +0300
+++ linux-atm-2.5.0/src/arpd/itf.c 2008-04-25 03:34:51.000000000 +0300
@@ -12,7 +12,6 @@
#include <sys/types.h>
#include <linux/atmclip.h>
#include <sys/socket.h>
-#define _LINUX_NETDEVICE_H /* glibc2 */
#include <linux/types.h>
#include <linux/if_arp.h>
@@ -0,0 +1,17 @@
Index: linux-atm-2.5.1/src/config/Makefile.in
===================================================================
--- linux-atm-2.5.1.orig/src/config/Makefile.in
+++ linux-atm-2.5.1/src/config/Makefile.in
@@ -413,10 +413,10 @@ uninstall-am: uninstall-local uninstall-
install-exec-local:
- -cp hosts.atm /etc
+ -cp hosts.atm $(DESTDIR)$(sysconfdir)
uninstall-local:
- -rm /etc/hosts.atm
+ -rm $(DESTDIR)$(sysconfdir)/hosts.atm
# Tell versions [3.59,3.63) of GNU make to not export all variables.
# Otherwise a system limit (for SysV at least) may be exceeded.
+72
View File
@@ -0,0 +1,72 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>linux-atm</Name>
<Homepage>http://linux-atm.sourceforge.net/</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>GPLv2</License>
<IsA>app:console</IsA>
<IsA>library</IsA>
<Summary>Tools to support ATM networking under Liunx</Summary>
<Description>linux-atm contains tools for Asynchronous Transfer Mode. Supports raw ATM connections (PVCs and SVCs), IP over ATM, LAN emulation, MPOA, Arequipa, and some others.</Description>
<Archive sha1sum="5a64964415bf19f855fb9a481b066ede3010aa2a" type="targz">mirrors://sourceforge/project/linux-atm/linux-atm/2.5.2/linux-atm-2.5.2.tar.gz</Archive>
<BuildDependencies>
<Dependency>flex</Dependency>
</BuildDependencies>
<Patches>
<Patch level="1">man-pages.patch</Patch>
<!--<Patch level="1">linux-atm-2.5.0-open-macro.patch</Patch>
<Patch level="1">linux-atm-2.5.0-disable-ilmidiag.patch</Patch>
<Patch level="1">gcc43.patch</Patch>
<Patch level="1">netdevice.patch</Patch>-->
</Patches>
</Source>
<Package>
<Name>linux-atm</Name>
<RuntimeDependencies>
<Dependency>flex</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="firmware">/lib/firmware</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="config">/etc</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="doc">/usr/share/doc</Path>
</Files>
</Package>
<Package>
<Name>linux-atm-devel</Name>
<Summary>Development files for linux-atm</Summary>
<RuntimeDependencies>
<Dependency release="current">linux-atm</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include</Path>
</Files>
</Package>
<History>
<Update release="2">
<Date>2015-04-13</Date>
<Version>2.5.2</Version>
<Comment>Version bump.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="1">
<Date>2010-10-13</Date>
<Version>2.5.1</Version>
<Comment>First release</Comment>
<Name>Gökcen Eraslan</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
@@ -0,0 +1,13 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>linux-atm</Name>
<Summary xml:lang="tr">ATM ağ bağlantısı desteği için araçlar</Summary>
<Description xml:lang="tr">linux-atm ATM (Asynchronous Transfer Mode) bağlantısı için gerekli çeşitli araçlar ve kitaplıklarını içerir.</Description>
</Source>
<Package>
<Name>linux-atm-devel</Name>
<Summary xml:lang="tr">linux-atm için geliştirme dosyaları</Summary>
</Package>
</PISI>
@@ -0,0 +1,20 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt.
from pisi.actionsapi import pisitools
from pisi.actionsapi import autotools
from pisi.actionsapi import get
def setup():
autotools.configure()
def build():
autotools.make()
def install():
autotools.rawInstall("DESTDIR=%s" % get.installDIR())
pisitools.dodoc("ChangeLog", "COPYING", "README*")
@@ -0,0 +1,34 @@
<?xml version="1.0" encoding="utf-8" standalone="no"?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>mobile-broadband-provider-info</Name>
<Homepage>http://live.gnome.org/NetworkManager/MobileBroadband/ServiceProviders</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>public-domain</License>
<IsA>data</IsA>
<Summary>Service provider specific settings of mobile broadband providers in different countries</Summary>
<Description>The mobile-broadband-provider-info package contains listings of mobile broadband (3G) providers and associated network and plan information.</Description>
<Archive sha1sum="cb09ed36024d08a7ed836d930e1cbc6a45eb4ba1" type="tarxz">ftp://ftp.gnome.org/pub/gnome/sources/mobile-broadband-provider-info/20120614/mobile-broadband-provider-info-20120614.tar.xz</Archive>
</Source>
<Package>
<Name>mobile-broadband-provider-info</Name>
<Files>
<Path fileType="data">/usr/share</Path>
</Files>
</Package>
<History>
<Update release="1">
<Date>2012-08-28</Date>
<Version>20120614</Version>
<Comment>First release</Comment>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
@@ -0,0 +1,8 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>mobile-broadband-provider-info</Name>
<Summary xml:lang="tr">Çeşitli ülkelerdeki mobil genişbant servis sağlayıcıları hakkında bilgileri içeren ayar veritabanı</Summary>
<Description xml:lang="tr">mobile-broadband-provider-info paketi, dünya üzerindeki mobil genişbant sağlayıcılarının ve ilgili tarifelerinin listesini tutan bir veritabanıdır.</Description>
</Source>
</PISI>
+47
View File
@@ -0,0 +1,47 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import get
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import shelltools
def setup():
pisitools.cflags.add("-fPIC", "-D_GNU_SOURCE")
shelltools.copytree("%s/dhcp" % get.workDIR(), "pppd/plugins")
pisitools.dosed("pppd/plugins/dhcp/Makefile.linux", "^(CFLAGS=.+)\s-O2", "\\1 %s" % get.CFLAGS())
# Enable atm
pisitools.dosed("pppd/Makefile.linux", "^#(HAVE_LIBATM=yes)", "\\1")
# Enable pam
pisitools.dosed("pppd/Makefile.linux", "^#(USE_PAM=y)", "\\1")
# Enable CBCP
pisitools.dosed("pppd/Makefile.linux", "^#(CBCP=y)", "\\1")
# Enable IPv6
pisitools.dosed("pppd/Makefile.linux", "^#(HAVE_INET6)", "\\1")
# Enable dhcp
pisitools.dosed("pppd/plugins/Makefile.linux", "^(SUBDIRS\s:=.+)", "\\1 dhcp")
autotools.configure()
def build():
autotools.make()
def install():
# The build mechanism is crap. Don't remove \/usr from DESTDIR or else the paths will fail
autotools.rawInstall("DESTDIR=%s/usr INSTROOT=%s install-etcppp" % ((get.installDIR(),)*2))
# No suid libraries
shelltools.chmod("%s/usr/lib/pppd/%s/*.so" % (get.installDIR(),get.srcVERSION()), 0755)
# Install Radius config files
pisitools.insinto("/etc/radiusclient", "pppd/plugins/radius/etc/*")
# Create peers directory
pisitools.dodir("/run/ppp")
pisitools.dodir("/etc/ppp/peers")
pisitools.dodoc("Changes*", "README*", "FAQ")
+14
View File
@@ -0,0 +1,14 @@
# /etc/ppp/chat-default:
'ABORT' 'BUSY'
'ABORT' 'ERROR'
'ABORT' 'NO ANSWER'
'ABORT' 'NO CARRIER'
'ABORT' 'NO DIALTONE'
'ABORT' 'Invalid Login'
'ABORT' 'Login incorrect'
'' 'ATZ'
'OK' 'ATDT$NUMBER'
'CONNECT' ''
'TIMEOUT' '5'
'~--' ''
+48
View File
@@ -0,0 +1,48 @@
# /etc/conf.d/net.ppp0:
# Config file for /etc/init.d/net.ppp0
PEER="MyPeer" # Define peer (aka ISP)
DEBUG="no" # Turn on debugging
PERSIST="no" # Redial after being dropped
ONDEMAND="no" # Only bring the interface up on demand?
MODEMPORT="/dev/ttyS1" # TTY device modem is connected to
LINESPEED="115200" # Speed pppd should try to connect at
INITSTRING="" # Extra init string for the modem
DEFROUTE="yes" # Must pppd set the default route?
HARDFLOWCTL="yes" # Use hardware flow control?
ESCAPECHARS="yes" # Use escape caracters ?
PPPOPTIONS="" # Extra options for pppd
USERNAME="user" # The PAP/CHAP username
PASSWORD="passwd" # Your password/secret. Ugly I know, but i
# will work on something more secure later
# on. 700 permission on /etc/init.d/net.ppp0
# should be enouth for now.
NUMBER="9180000" # The telephone number of your ISP
# leave blank for leased-line operation.
REMIP="" # The ip of the remote box if it should be set
NETMASK="" # Netmask
IPADDR="" # Our IP if we have a static one
MRU="768" # Sets the MRU
MTU="768" # Sets the MTU
RETRYTIMEOUT="60" # Retry timeout for when ONDEMAND="yes" or
# PERSIST="yes"
IDLETIMEOUT="600" # Idle timeout for when ONDEMAND="yes"
PEERDNS="no" # Should pppd set the peer dns?
AUTOCFGFILES="yes" # By default this scripts will generate
# /etc/ppp/chat-isp, /etc/ppp/chap-secrets,
# /etc/ppp/pap-secrets and /etc/ppp/peers/isp
# automatically. Set to "no" if you experience
# problems, or need specialized scripts. You
# will have to create these files by hand then.
AUTOCHATSCRIPT="yes" # By default this script iwll generate
# /etc/ppp/chat-${PEER} automatically. Set to "no"
# if you experience problems, or need specialized
# scripts. You will have to create these files by
# hand then.
# Directory where the templates is stored
TEMPLATEDIR=/etc/ppp
@@ -0,0 +1,194 @@
diff -ur ppp-2.4.5.orig/chat/Makefile.linux ppp-2.4.5/chat/Makefile.linux
--- ppp-2.4.5.orig/chat/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/chat/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -10,7 +10,6 @@
CDEF4= -DFNDELAY=O_NDELAY # Old name value
CDEFS= $(CDEF1) $(CDEF2) $(CDEF3) $(CDEF4)
-COPTS= -O2 -g -pipe
CFLAGS= $(COPTS) $(CDEFS)
INSTALL= install
@@ -18,7 +17,7 @@
all: chat
chat: chat.o
- $(CC) -o chat chat.o
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^
chat.o: chat.c
$(CC) -c $(CFLAGS) -o chat.o chat.c
diff -ur ppp-2.4.5.orig/pppd/Makefile.linux ppp-2.4.5/pppd/Makefile.linux
--- ppp-2.4.5.orig/pppd/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -32,7 +32,7 @@
# CC = gcc
#
-COPTS = -O2 -pipe -Wall -g
+COPTS+= -Wall
LIBS =
# Uncomment the next 2 lines to include support for Microsoft's
diff -ur ppp-2.4.5.orig/pppd/plugins/Makefile.linux ppp-2.4.5/pppd/plugins/Makefile.linux
--- ppp-2.4.5.orig/pppd/plugins/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/plugins/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -1,7 +1,11 @@
#CC = gcc
-COPTS = -O2 -g
CFLAGS = $(COPTS) -I.. -I../../include -fPIC
-LDFLAGS = -shared
+LDFLAGS_PROG := $(LDFLAGS)
+export LDFLAGS LDFLAGS_PROG
+LDFLAGS += -shared
+# need the following option, otherwise linking plugins might fail with undef errors (Gentoo bug 210837)
+LDFLAGS += -Wl,--allow-shlib-undefined
+LIBS =
INSTALL = install
DESTDIR = $(INSTROOT)@DESTDIR@
@@ -23,7 +27,7 @@
for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d all; done
%.so: %.c
- $(CC) -o $@ $(LDFLAGS) $(CFLAGS) $^
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^ $(LIBS)
VERSION = $(shell awk -F '"' '/VERSION/ { print $$2; }' ../patchlevel.h)
diff -ur ppp-2.4.5.orig/pppd/plugins/pppoatm/Makefile.linux ppp-2.4.5/pppd/plugins/pppoatm/Makefile.linux
--- ppp-2.4.5.orig/pppd/plugins/pppoatm/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/plugins/pppoatm/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -1,7 +1,5 @@
#CC = gcc
-COPTS = -O2 -g
CFLAGS = $(COPTS) -I../.. -I../../../include -fPIC
-LDFLAGS = -shared
INSTALL = install
#***********************************************************************
@@ -33,7 +31,7 @@
all: $(PLUGIN)
$(PLUGIN): $(PLUGIN_OBJS)
- $(CC) $(CFLAGS) -o $@ -shared $^ $(LIBS)
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^ $(LIBS)
install: all
$(INSTALL) -d -m 755 $(LIBDIR)
diff -ur ppp-2.4.5.orig/pppd/plugins/pppol2tp/Makefile.linux ppp-2.4.5/pppd/plugins/pppol2tp/Makefile.linux
--- ppp-2.4.5.orig/pppd/plugins/pppol2tp/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/plugins/pppol2tp/Makefile.linux 2010-08-08 09:20:02.000000000 +0200
@@ -1,7 +1,5 @@
#CC = gcc
-COPTS = -O2 -g
CFLAGS = $(COPTS) -I. -I../.. -I../../../include -fPIC
-LDFLAGS = -shared
INSTALL = install
#***********************************************************************
@@ -16,7 +14,7 @@
all: $(PLUGINS)
%.so: %.o
- $(CC) $(CFLAGS) -o $@ -shared $^ $(LIBS)
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^ $(LIBS)
install: all
$(INSTALL) -d -m 755 $(LIBDIR)
diff -ur ppp-2.4.5.orig/pppd/plugins/radius/Makefile.linux ppp-2.4.5/pppd/plugins/radius/Makefile.linux
--- ppp-2.4.5.orig/pppd/plugins/radius/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/plugins/radius/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -12,7 +12,7 @@
INSTALL = install
PLUGIN=radius.so radattr.so radrealms.so
-CFLAGS=-I. -I../.. -I../../../include -O2 -fPIC -DRC_LOG_FACILITY=LOG_DAEMON
+CFLAGS=$(COPTS) -I. -I../.. -I../../../include -fPIC -DRC_LOG_FACILITY=LOG_DAEMON
# Uncomment the next line to include support for Microsoft's
# MS-CHAP authentication protocol.
@@ -43,13 +43,13 @@
$(INSTALL) -c -m 444 pppd-radattr.8 $(MANDIR)
radius.so: radius.o libradiusclient.a
- $(CC) -o radius.so -shared radius.o libradiusclient.a
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^
radattr.so: radattr.o
- $(CC) -o radattr.so -shared radattr.o
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^
radrealms.so: radrealms.o
- $(CC) -o radrealms.so -shared radrealms.o
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^
CLIENTOBJS = avpair.o buildreq.o config.o dict.o ip_util.o \
clientid.o sendserver.o lock.o util.o md5.o
diff -ur ppp-2.4.5.orig/pppd/plugins/rp-pppoe/Makefile.linux ppp-2.4.5/pppd/plugins/rp-pppoe/Makefile.linux
--- ppp-2.4.5.orig/pppd/plugins/rp-pppoe/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/plugins/rp-pppoe/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -25,12 +25,11 @@
# Version is set ONLY IN THE MAKEFILE! Don't delete this!
RP_VERSION=3.8p
-COPTS=-O2 -g
CFLAGS=$(COPTS) -I../../../include '-DRP_VERSION="$(RP_VERSION)"'
all: rp-pppoe.so pppoe-discovery
pppoe-discovery: pppoe-discovery.o debug.o
- $(CC) -o pppoe-discovery pppoe-discovery.o debug.o
+ $(CC) $(LDFLAGS_PROG) $(CFLAGS) -o pppoe-discovery pppoe-discovery.o debug.o
pppoe-discovery.o: pppoe-discovery.c
$(CC) $(CFLAGS) -c -o pppoe-discovery.o pppoe-discovery.c
@@ -39,7 +38,7 @@
$(CC) $(CFLAGS) -c -o debug.o debug.c
rp-pppoe.so: plugin.o discovery.o if.o common.o
- $(CC) -o rp-pppoe.so -shared plugin.o discovery.o if.o common.o
+ $(CC) $(LDFLAGS) $(CFLAGS) -o rp-pppoe.so plugin.o discovery.o if.o common.o
install: all
$(INSTALL) -d -m 755 $(LIBDIR)
diff -ur ppp-2.4.5.orig/pppdump/Makefile.linux ppp-2.4.5/pppdump/Makefile.linux
--- ppp-2.4.5.orig/pppdump/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppdump/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -2,7 +2,7 @@
BINDIR = $(DESTDIR)/sbin
MANDIR = $(DESTDIR)/share/man/man8
-CFLAGS= -O -I../include/net
+CFLAGS=$(COPTS) -I../include/net
OBJS = pppdump.o bsd-comp.o deflate.o zlib.o
INSTALL= install
@@ -10,7 +10,7 @@
all: pppdump
pppdump: $(OBJS)
- $(CC) -o pppdump $(OBJS)
+ $(CC) $(LDFLAGS) -o pppdump $(OBJS)
clean:
rm -f pppdump $(OBJS) *~
diff -ur ppp-2.4.5.orig/pppstats/Makefile.linux ppp-2.4.5/pppstats/Makefile.linux
--- ppp-2.4.5.orig/pppstats/Makefile.linux 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppstats/Makefile.linux 2010-08-08 09:19:38.000000000 +0200
@@ -10,7 +10,6 @@
PPPSTATOBJS = pppstats.o
#CC = gcc
-COPTS = -O
COMPILE_FLAGS = -I../include
LIBS =
@@ -26,7 +25,7 @@
$(INSTALL) -c -m 444 pppstats.8 $(MANDIR)
pppstats: $(PPPSTATSRCS)
- $(CC) $(CFLAGS) -o pppstats pppstats.c $(LIBS)
+ $(CC) $(CFLAGS) $(LDFLAGS) -o pppstats pppstats.c $(LIBS)
clean:
rm -f pppstats *~ #* core
@@ -0,0 +1,431 @@
diff -Nur ppp-2.4.5.orig/pppd/main.c ppp-2.4.5/pppd/main.c
--- ppp-2.4.5.orig/pppd/main.c 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/main.c 2010-08-08 09:30:23.000000000 +0200
@@ -96,6 +96,9 @@
#include "fsm.h"
#include "lcp.h"
#include "ipcp.h"
+
+#include "mplscp.h"
+
#ifdef INET6
#include "ipv6cp.h"
#endif
@@ -283,6 +286,7 @@
&cbcp_protent,
#endif
&ipcp_protent,
+ &mplscp_protent,
#ifdef INET6
&ipv6cp_protent,
#endif
diff -Nur ppp-2.4.5.orig/pppd/Makefile.linux ppp-2.4.5/pppd/Makefile.linux
--- ppp-2.4.5.orig/pppd/Makefile.linux 2010-08-08 09:22:22.000000000 +0200
+++ ppp-2.4.5/pppd/Makefile.linux 2010-08-08 09:31:43.000000000 +0200
@@ -13,16 +13,16 @@
PPPDSRCS = main.c magic.c fsm.c lcp.c ipcp.c upap.c chap-new.c md5.c ccp.c \
ecp.c ipxcp.c auth.c options.c sys-linux.c md4.c chap_ms.c \
- demand.c utils.c tty.c eap.c chap-md5.c session.c
+ demand.c utils.c tty.c eap.c chap-md5.c session.c mplscp.c
HEADERS = ccp.h session.h chap-new.h ecp.h fsm.h ipcp.h \
ipxcp.h lcp.h magic.h md5.h patchlevel.h pathnames.h pppd.h \
- upap.h eap.h
+ upap.h eap.h mplscp.h
MANPAGES = pppd.8
PPPDOBJS = main.o magic.o fsm.o lcp.o ipcp.o upap.o chap-new.o md5.o ccp.o \
ecp.o auth.o options.o demand.o utils.o sys-linux.o ipxcp.o tty.o \
- eap.o chap-md5.o session.o
+ eap.o chap-md5.o session.o mplscp.o
#
# include dependencies if present
diff -Nur ppp-2.4.5.orig/pppd/mplscp.c ppp-2.4.5/pppd/mplscp.c
--- ppp-2.4.5.orig/pppd/mplscp.c 1970-01-01 01:00:00.000000000 +0100
+++ ppp-2.4.5/pppd/mplscp.c 2010-08-08 09:30:23.000000000 +0200
@@ -0,0 +1,371 @@
+
+/* MPLSCP - Serge.Krier@advalvas.be (C) 2001 */
+
+#include <stdio.h>
+#include <string.h>
+#include <netdb.h>
+#include <sys/param.h>
+#include <sys/types.h>
+#include <sys/socket.h>
+#include <netinet/in.h>
+#include <arpa/inet.h>
+
+#include "pppd.h"
+#include "fsm.h"
+#include "mplscp.h"
+
+
+/* local vars */
+/* static int mplscp_is_up; */ /* have called np_up() */
+
+/*
+ * Callbacks for fsm code. (CI = Configuration Information)
+ */
+static void mplscp_resetci __P((fsm *)); /* Reset our CI */
+static int mplscp_cilen __P((fsm *)); /* Return length of our CI */
+static void mplscp_addci __P((fsm *, u_char *, int *)); /* Add our CI */
+static int mplscp_ackci __P((fsm *, u_char *, int)); /* Peer ack'd our CI */
+static int mplscp_nakci __P((fsm *, u_char *, int)); /* Peer nak'd our CI */
+static int mplscp_rejci __P((fsm *, u_char *, int)); /* Peer rej'd our CI */
+static int mplscp_reqci __P((fsm *, u_char *, int *, int)); /* Rcv CI */
+static void mplscp_up __P((fsm *)); /* We're UP */
+static void mplscp_down __P((fsm *)); /* We're DOWN */
+static void mplscp_finished __P((fsm *)); /* Don't need lower layer */
+
+fsm mplscp_fsm[NUM_PPP]; /* MPLSCP fsm structure */
+
+static fsm_callbacks mplscp_callbacks = { /* MPLSCP callback routines */
+ mplscp_resetci, /* Reset our Configuration Information */
+ mplscp_cilen, /* Length of our Configuration Information */
+ mplscp_addci, /* Add our Configuration Information */
+ mplscp_ackci, /* ACK our Configuration Information */
+ mplscp_nakci, /* NAK our Configuration Information */
+ mplscp_rejci, /* Reject our Configuration Information */
+ mplscp_reqci, /* Request peer's Configuration Information */
+ mplscp_up, /* Called when fsm reaches OPENED state */
+ mplscp_down, /* Called when fsm leaves OPENED state */
+ NULL, /* Called when we want the lower layer up */
+ mplscp_finished, /* Called when we want the lower layer down */
+ NULL, /* Called when Protocol-Reject received */
+ NULL, /* Retransmission is necessary */
+ NULL, /* Called to handle protocol-specific codes */
+ "MPLSCP" /* String name of protocol */
+};
+
+static option_t mplscp_option_list[] = {
+ { "mpls", o_bool, &mplscp_protent.enabled_flag,
+ "Enable MPLSCP (and MPLS)", 1 },
+ { NULL } };
+
+/*
+ * Protocol entry points from main code.
+ */
+
+static void mplscp_init __P((int));
+static void mplscp_open __P((int));
+static void mplscp_close __P((int, char *));
+static void mplscp_lowerup __P((int));
+static void mplscp_lowerdown __P((int));
+static void mplscp_input __P((int, u_char *, int));
+static void mplscp_protrej __P((int));
+static int mplscp_printpkt __P((u_char *, int,
+ void (*) __P((void *, char *, ...)), void *));
+
+struct protent mplscp_protent = {
+ PPP_MPLSCP,
+ mplscp_init,
+ mplscp_input,
+ mplscp_protrej,
+ mplscp_lowerup,
+ mplscp_lowerdown,
+ mplscp_open,
+ mplscp_close,
+ mplscp_printpkt,
+ NULL,
+ 0, /* MPLS not enabled by default */
+ "MPLSCP",
+ "MPLS",
+ mplscp_option_list,
+ NULL,
+ NULL,
+ NULL
+};
+
+/*
+ * mplscp_init - Initialize MPLSCP.
+ */
+static void
+mplscp_init(int unit) {
+
+ fsm *f = &mplscp_fsm[unit];
+
+ f->unit = unit;
+ f->protocol = PPP_MPLSCP;
+ f->callbacks = &mplscp_callbacks;
+ fsm_init(&mplscp_fsm[unit]);
+
+}
+
+/*
+ * mplscp_open - MPLSCP is allowed to come up.
+ */
+static void
+mplscp_open(int unit) {
+
+ fsm_open(&mplscp_fsm[unit]);
+
+}
+
+/*
+ * mplscp_close - Take MPLSCP down.
+ */
+static void
+mplscp_close(int unit, char *reason) {
+
+ fsm_close(&mplscp_fsm[unit], reason);
+
+}
+
+/*
+ * mplscp_lowerup - The lower layer is up.
+ */
+static void
+mplscp_lowerup(int unit) {
+
+ fsm_lowerup(&mplscp_fsm[unit]);
+}
+
+/*
+ * mplscp_lowerdown - The lower layer is down.
+ */
+static void
+mplscp_lowerdown(int unit) {
+
+ fsm_lowerdown(&mplscp_fsm[unit]);
+}
+
+/*
+ * mplscp_input - Input MPLSCP packet.
+ */
+static void
+mplscp_input(int unit, u_char *p, int len) {
+
+ fsm_input(&mplscp_fsm[unit], p, len);
+}
+
+/*
+ * mplscp_protrej - A Protocol-Reject was received for MPLSCP.
+ * Pretend the lower layer went down, so we shut up.
+ */
+static void
+mplscp_protrej(int unit) {
+
+ fsm_lowerdown(&mplscp_fsm[unit]);
+}
+
+/*
+ * mplscp_resetci - Reset our CI.
+ * Called by fsm_sconfreq, Send Configure Request.
+ */
+static void
+mplscp_resetci(fsm *f) {
+
+ return;
+}
+
+/*
+ * mplscp_cilen - Return length of our CI.
+ * Called by fsm_sconfreq, Send Configure Request.
+ */
+static int
+mplscp_cilen(fsm *f) {
+
+ return 0;
+}
+
+/*
+ * mplscp_addci - Add our desired CIs to a packet.
+ * Called by fsm_sconfreq, Send Configure Request.
+ */
+static void
+mplscp_addci(fsm *f, u_char *ucp, int *lenp) {
+
+}
+
+/*
+ * ipcp_ackci - Ack our CIs.
+ * Called by fsm_rconfack, Receive Configure ACK.
+ *
+ * Returns:
+ * 0 - Ack was bad.
+ * 1 - Ack was good.
+ */
+static int
+mplscp_ackci(fsm *f, u_char *p, int len) {
+
+ return 1;
+
+}
+
+/*
+ * mplscp_nakci - Peer has sent a NAK for some of our CIs.
+ * This should not modify any state if the Nak is bad
+ * or if MPLSCP is in the OPENED state.
+ * Calback from fsm_rconfnakrej - Receive Configure-Nak or Configure-Reject.
+ *
+ * Returns:
+ * 0 - Nak was bad.
+ * 1 - Nak was good.
+ */
+static int
+mplscp_nakci(fsm *f, u_char *p, int len) {
+
+ return 1;
+}
+
+/*
+ * MPLSVP_rejci - Reject some of our CIs.
+ * Callback from fsm_rconfnakrej.
+ */
+static int
+mplscp_rejci(fsm *f, u_char *p, int len) {
+
+ return 1;
+
+}
+
+/*
+ * mplscp_reqci - Check the peer's requested CIs and send appropriate response.
+ * Callback from fsm_rconfreq, Receive Configure Request
+ *
+ * Returns: CONFACK, CONFNAK or CONFREJ and input packet modified
+ * appropriately. If reject_if_disagree is non-zero, doesn't return
+ * CONFNAK; returns CONFREJ if it can't return CONFACK.
+ */
+static int
+mplscp_reqci(fsm *f, u_char *inp, int *len, int reject_if_disagree) {
+
+
+ int rc = CONFACK; /* Final packet return code */
+
+ PUTCHAR(CONFACK,inp);
+
+ return rc;
+
+}
+
+static void
+mplscp_up(fsm *f) {
+
+ sifnpmode(f->unit, PPP_MPLS_UC, NPMODE_PASS);
+ /* sifnpmode(f->unit, PPP_MPLS_MC, NPMODE_PASS);*/
+
+ np_up(f->unit, PPP_MPLS_UC);
+ /* np_up(f->unit, PPP_MPLS_MC);*/
+ /* ipcp_is_up = 1;*/
+
+
+#if 1
+ printf("MPLSCP is OPENED\n");
+#endif
+
+}
+
+static void
+mplscp_down(fsm *f) {
+
+ sifnpmode(f->unit, PPP_MPLS_UC, NPMODE_DROP);
+ /* sifnpmode(f->unit, PPP_MPLS_MC, NPMODE_DROP);*/
+
+ sifdown(f->unit);
+
+#if 1
+ printf("MPLSCP is CLOSED\n");
+#endif
+
+
+}
+
+static void
+mplscp_finished(fsm *f) {
+
+ np_finished(f->unit, PPP_MPLS_UC);
+ /* np_finished(f->unit, PPP_MPLS_MC);*/
+
+}
+
+/*
+ * mpls_printpkt - print the contents of an MPLSCP packet.
+ */
+static char *mplscp_codenames[] = {
+ "ConfReq", "ConfAck", "ConfNak", "ConfRej",
+ "TermReq", "TermAck", "CodeRej"
+};
+
+static int
+mplscp_printpkt(u_char *p, int plen,
+ void (*printer) __P((void *, char *, ...)),
+ void *arg) {
+
+ int code, id, len, olen;
+ u_char *pstart, *optend;
+
+ if (plen < HEADERLEN)
+ return 0;
+ pstart = p;
+ GETCHAR(code, p);
+ GETCHAR(id, p);
+ GETSHORT(len, p);
+ if (len < HEADERLEN || len > plen)
+ return 0;
+
+ if (code >= 1 && code <= sizeof(mplscp_codenames) / sizeof(char *))
+ printer(arg, " %s", mplscp_codenames[code-1]);
+ else
+ printer(arg, " code=0x%x", code);
+ printer(arg, " id=0x%x", id);
+ len -= HEADERLEN;
+ switch (code) {
+ case CONFREQ:
+ case CONFACK:
+ case CONFNAK:
+ case CONFREJ:
+ /* print option list */
+ while (len >= 2) {
+ GETCHAR(code, p);
+ GETCHAR(olen, p);
+ p -= 2;
+ if (olen < 2 || olen > len) {
+ break;
+ }
+ printer(arg, " <");
+ len -= olen;
+ optend = p + olen;
+ while (p < optend) {
+ GETCHAR(code, p);
+ printer(arg, " %.2x", code);
+ }
+ printer(arg, ">");
+ }
+ break;
+
+ case TERMACK:
+ case TERMREQ:
+ if (len > 0 && *p >= ' ' && *p < 0x7f) {
+ printer(arg, " ");
+ print_string((char *)p, len, printer, arg);
+ p += len;
+ len = 0;
+ }
+ break;
+ }
+
+ /* print the rest of the bytes in the packet */
+ for (; len > 0; --len) {
+ GETCHAR(code, p);
+ printer(arg, " %.2x", code);
+ }
+
+ return p - pstart;
+
+}
diff -Nur ppp-2.4.5.orig/pppd/mplscp.h ppp-2.4.5/pppd/mplscp.h
--- ppp-2.4.5.orig/pppd/mplscp.h 1970-01-01 01:00:00.000000000 +0100
+++ ppp-2.4.5/pppd/mplscp.h 2010-08-08 09:30:23.000000000 +0200
@@ -0,0 +1,8 @@
+
+/* MPLSCP - Serge.Krier@advalvas.be (C) 2001 */
+
+#define PPP_MPLSCP 0x8281
+#define PPP_MPLS_UC 0x0281
+#define PPP_MPLS_MC 0x0283
+
+extern struct protent mplscp_protent;
@@ -0,0 +1,134 @@
diff -Nur ppp-2.4.5.orig/pppd/options.c ppp-2.4.5/pppd/options.c
--- ppp-2.4.5.orig/pppd/options.c 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/options.c 2010-08-08 09:43:47.000000000 +0200
@@ -100,6 +100,9 @@
char user[MAXNAMELEN]; /* Username for PAP */
char passwd[MAXSECRETLEN]; /* Password for PAP */
bool persist = 0; /* Reopen link after it goes down */
+bool killoldaddr = 0; /* If our IP is reassigned on
+ reconnect, kill active TCP
+ connections using the old IP. */
char our_name[MAXNAMELEN]; /* Our name for authentication purposes */
bool demand = 0; /* do dial-on-demand */
char *ipparam = NULL; /* Extra parameter for ip up/down scripts */
@@ -231,6 +234,11 @@
{ "demand", o_bool, &demand,
"Dial on demand", OPT_INITONLY | 1, &persist },
+ { "killoldaddr", o_bool, &killoldaddr,
+ "Kill connections from an old source address", 1},
+ { "nokilloldaddr", o_bool,&killoldaddr,
+ "Don't kill connections from an old source address" },
+
{ "--version", o_special_noarg, (void *)showversion,
"Show version number" },
{ "--help", o_special_noarg, (void *)showhelp,
diff -Nur ppp-2.4.5.orig/pppd/pppd.h ppp-2.4.5/pppd/pppd.h
--- ppp-2.4.5.orig/pppd/pppd.h 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/pppd.h 2010-08-08 09:43:47.000000000 +0200
@@ -298,6 +298,9 @@
extern char remote_name[MAXNAMELEN]; /* Peer's name for authentication */
extern bool explicit_remote;/* remote_name specified with remotename opt */
extern bool demand; /* Do dial-on-demand */
+extern bool killoldaddr; /* If our IP is reassigned on
+ reconnect, kill active TCP
+ connections using the old IP. */
extern char *ipparam; /* Extra parameter for ip up/down scripts */
extern bool cryptpap; /* Others' PAP passwords are encrypted */
extern int idle_time_limit;/* Shut down link if idle for this long */
diff -Nur ppp-2.4.5.orig/pppd/sys-linux.c ppp-2.4.5/pppd/sys-linux.c
--- ppp-2.4.5.orig/pppd/sys-linux.c 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/sys-linux.c 2010-08-08 09:43:47.000000000 +0200
@@ -165,6 +165,10 @@
#endif /* INET6 */
+#ifndef SIOCKILLADDR
+#define SIOCKILLADDR 0x8939
+#endif
+
/* We can get an EIO error on an ioctl if the modem has hung up */
#define ok_error(num) ((num)==EIO)
@@ -209,6 +213,7 @@
static u_int32_t proxy_arp_addr; /* Addr for proxy arp entry added */
static char proxy_arp_dev[16]; /* Device for proxy arp entry */
static u_int32_t our_old_addr; /* for detecting address changes */
+static u_int32_t our_current_addr;
static int dynaddr_set; /* 1 if ip_dynaddr set */
static int looped; /* 1 if using loop */
static int link_mtu; /* mtu for the link (not bundle) */
@@ -537,6 +542,27 @@
return -1;
}
+static void do_killaddr(u_int32_t oldaddr)
+{
+ struct ifreq ifr;
+
+ memset(&ifr,0,sizeof ifr);
+
+ SET_SA_FAMILY (ifr.ifr_addr, AF_INET);
+ SET_SA_FAMILY (ifr.ifr_dstaddr, AF_INET);
+ SET_SA_FAMILY (ifr.ifr_netmask, AF_INET);
+
+ SIN_ADDR(ifr.ifr_addr) = oldaddr;
+
+ strlcpy(ifr.ifr_name, ifname, sizeof (ifr.ifr_name));
+
+ if(ioctl(sock_fd,SIOCKILLADDR,&ifr) < 0) {
+ if (!ok_error (errno))
+ error("ioctl(SIOCKILLADDR): %m(%d)", errno);
+ return;
+ }
+}
+
/********************************************************************
*
* tty_disestablish_ppp - Restore the serial port to normal operation.
@@ -2385,21 +2411,29 @@
}
}
- /* set ip_dynaddr in demand mode if address changes */
- if (demand && tune_kernel && !dynaddr_set
- && our_old_addr && our_old_addr != our_adr) {
+ if(persist && our_old_addr && our_old_addr != our_adr) {
+
+ if(killoldaddr)
+ do_killaddr(our_old_addr);
+
+
+ /* set ip_dynaddr in persist mode if address changes */
+ if (tune_kernel && !dynaddr_set) {
/* set ip_dynaddr if possible */
char *path;
int fd;
path = path_to_procfs("/sys/net/ipv4/ip_dynaddr");
if (path != 0 && (fd = open(path, O_WRONLY)) >= 0) {
- if (write(fd, "1", 1) != 1)
- error("Couldn't enable dynamic IP addressing: %m");
- close(fd);
+ if (write(fd, "1", 1) != 1)
+ error("Couldn't enable dynamic IP addressing: %m");
+ close(fd);
}
dynaddr_set = 1; /* only 1 attempt */
+ }
}
+
+ our_current_addr = our_adr;
our_old_addr = 0;
return 1;
@@ -2455,7 +2489,8 @@
}
our_old_addr = our_adr;
-
+ our_current_addr = 0;
+
return 1;
}
@@ -0,0 +1,77 @@
diff -Nur ppp-2.4.5.orig/pppd/main.c ppp-2.4.5/pppd/main.c
--- ppp-2.4.5.orig/pppd/main.c 2010-08-08 09:34:32.000000000 +0200
+++ ppp-2.4.5/pppd/main.c 2010-08-08 09:46:00.000000000 +0200
@@ -249,6 +249,7 @@
static void forget_child __P((int pid, int status));
static int reap_kids __P((void));
static void childwait_end __P((void *));
+static void wait_children __P((void));
#ifdef USE_TDB
static void update_db_entry __P((void));
@@ -580,25 +581,11 @@
if (!persist)
break;
}
+
+ wait_children();
}
- /* Wait for scripts to finish */
- reap_kids();
- if (n_children > 0) {
- if (child_wait > 0)
- TIMEOUT(childwait_end, NULL, child_wait);
- if (debug) {
- struct subprocess *chp;
- dbglog("Waiting for %d child processes...", n_children);
- for (chp = children; chp != NULL; chp = chp->next)
- dbglog(" script %s, pid %d", chp->prog, chp->pid);
- }
- while (n_children > 0 && !childwait_done) {
- handle_events();
- if (kill_link && !childwait_done)
- childwait_end(NULL);
- }
- }
+ wait_children();
die(status);
return 0;
@@ -1794,6 +1781,36 @@
}
/*
+ * wait_children - wait for scripts to finish.
+ * if child_wait is 0, wait indefinitely.
+ * else, kill'em all at the end of timeout
+ */
+static void
+wait_children()
+{
+ /* Wait for scripts to finish */
+ reap_kids();
+ if (n_children > 0) {
+ childwait_done = 0;
+ if (child_wait > 0)
+ TIMEOUT(childwait_end, NULL, child_wait);
+ if (debug) {
+ struct subprocess *chp;
+ dbglog("Waiting for %d child processes...", n_children);
+ for (chp = children; chp != NULL; chp = chp->next)
+ dbglog(" script %s, pid %d", chp->prog, chp->pid);
+ }
+ while (n_children > 0 && !childwait_done) {
+ handle_events();
+ if (asked_to_quit && !childwait_done)
+ childwait_end(NULL);
+ }
+ if (child_wait > 0)
+ UNTIMEOUT(childwait_end, NULL);
+ }
+}
+
+/*
* childwait_end - we got fed up waiting for the child processes to
* exit, send them all a SIGTERM.
*/
@@ -0,0 +1,90 @@
This patch reverses revision 1.114 of the pppd/sys-linux.c file.
The default gateway is needed by the openswan's %defaultroute.
diff -Nur ppp-2.4.5.orig/pppd/sys-linux.c ppp-2.4.5/pppd/sys-linux.c
--- ppp-2.4.5.orig/pppd/sys-linux.c 2010-08-08 09:44:29.000000000 +0200
+++ ppp-2.4.5/pppd/sys-linux.c 2010-08-08 09:53:02.000000000 +0200
@@ -209,7 +209,7 @@
static unsigned char inbuf[512]; /* buffer for chars read from loopback */
static int if_is_up; /* Interface has been marked up */
-static int have_default_route; /* Gateway for default route added */
+static u_int32_t default_route_gateway; /* Gateway for default route added */
static u_int32_t proxy_arp_addr; /* Addr for proxy arp entry added */
static char proxy_arp_dev[16]; /* Device for proxy arp entry */
static u_int32_t our_old_addr; /* for detecting address changes */
@@ -346,8 +346,8 @@
/*
* Delete any routes through the device.
*/
- if (have_default_route)
- cifdefaultroute(0, 0, 0);
+ if (default_route_gateway != 0)
+ cifdefaultroute(0, 0, default_route_gateway);
if (has_proxy_arp)
cifproxyarp(0, proxy_arp_addr);
@@ -1639,17 +1639,17 @@
struct rtentry rt;
if (defaultroute_exists(&rt) && strcmp(rt.rt_dev, ifname) != 0) {
- if (rt.rt_flags & RTF_GATEWAY)
- error("not replacing existing default route via %I",
- SIN_ADDR(rt.rt_gateway));
- else
- error("not replacing existing default route through %s",
- rt.rt_dev);
+ u_int32_t old_gateway = SIN_ADDR(rt.rt_gateway);
+
+ if (old_gateway != gateway)
+ error("not replacing existing default route to %s [%I]",
+ rt.rt_dev, old_gateway);
return 0;
}
- memset (&rt, 0, sizeof (rt));
- SET_SA_FAMILY (rt.rt_dst, AF_INET);
+ memset (&rt, '\0', sizeof (rt));
+ SET_SA_FAMILY (rt.rt_dst, AF_INET);
+ SET_SA_FAMILY (rt.rt_gateway, AF_INET);
rt.rt_dev = ifname;
@@ -1658,14 +1658,16 @@
SIN_ADDR(rt.rt_genmask) = 0L;
}
- rt.rt_flags = RTF_UP;
+ SIN_ADDR(rt.rt_gateway) = gateway;
+
+ rt.rt_flags = RTF_UP | RTF_GATEWAY;
if (ioctl(sock_fd, SIOCADDRT, &rt) < 0) {
if ( ! ok_error ( errno ))
error("default route ioctl(SIOCADDRT): %m");
return 0;
}
- have_default_route = 1;
+ default_route_gateway = gateway;
return 1;
}
@@ -1678,7 +1680,7 @@
{
struct rtentry rt;
- have_default_route = 0;
+ default_route_gateway = 0;
memset (&rt, '\0', sizeof (rt));
SET_SA_FAMILY (rt.rt_dst, AF_INET);
@@ -1691,7 +1693,9 @@
SIN_ADDR(rt.rt_genmask) = 0L;
}
- rt.rt_flags = RTF_UP;
+ SIN_ADDR(rt.rt_gateway) = gateway;
+
+ rt.rt_flags = RTF_UP | RTF_GATEWAY;
if (ioctl(sock_fd, SIOCDELRT, &rt) < 0 && errno != ESRCH) {
if (still_ppp()) {
if ( ! ok_error ( errno ))
@@ -0,0 +1,97 @@
diff -Nru ppp-2.4.5.orig/pppd/auth.c ppp-2.4.5/pppd/auth.c
--- ppp-2.4.5.orig/pppd/auth.c 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/auth.c 2010-08-08 09:57:01.000000000 +0200
@@ -637,7 +637,7 @@
* we delete its pid file.
*/
if (!doing_multilink && !demand)
- remove_pidfiles();
+ remove_pidfile(pidfilename);
/*
* If we may want to bring the link up again, transfer
diff -Nru ppp-2.4.5.orig/pppd/main.c ppp-2.4.5/pppd/main.c
--- ppp-2.4.5.orig/pppd/main.c 2010-08-08 09:46:42.000000000 +0200
+++ ppp-2.4.5/pppd/main.c 2010-08-08 09:57:01.000000000 +0200
@@ -134,7 +134,7 @@
char *progname; /* Name of this program */
char hostname[MAXNAMELEN]; /* Our hostname */
-static char pidfilename[MAXPATHLEN]; /* name of pid file */
+char pidfilename[MAXPATHLEN]; /* name of pid file */
static char linkpidfile[MAXPATHLEN]; /* name of linkname pid file */
char ppp_devnam[MAXPATHLEN]; /* name of PPP tty (maybe ttypx) */
uid_t uid; /* Our real user-id */
@@ -245,6 +245,7 @@
static void toggle_debug __P((int));
static void open_ccp __P((int));
static void bad_signal __P((int));
+static void remove_pidfilenames __P((void));
static void holdoff_end __P((void *));
static void forget_child __P((int pid, int status));
static int reap_kids __P((void));
@@ -835,16 +836,24 @@
}
/*
- * remove_pidfile - remove our pid files
+ * remove_pidfile - remove one of the 2 pidfiles (pidfilename or linkpidfile)
*/
-void remove_pidfiles()
+void
+remove_pidfile(filename)
+ char* filename;
{
- if (pidfilename[0] != 0 && unlink(pidfilename) < 0 && errno != ENOENT)
- warn("unable to delete pid file %s: %m", pidfilename);
- pidfilename[0] = 0;
- if (linkpidfile[0] != 0 && unlink(linkpidfile) < 0 && errno != ENOENT)
- warn("unable to delete pid file %s: %m", linkpidfile);
- linkpidfile[0] = 0;
+ if (filename[0] != 0 && unlink(filename) < 0 && errno != ENOENT)
+ warn("unable to delete pid file %s: %m", filename);
+ filename[0] = 0;
+}
+
+/*
+ * remove_pidfiles - remove our pid files
+ */
+static void remove_pidfiles()
+{
+ remove_pidfile(pidfilename);
+ remove_pidfile(linkpidfile);
}
/*
diff -Nru ppp-2.4.5.orig/pppd/multilink.c ppp-2.4.5/pppd/multilink.c
--- ppp-2.4.5.orig/pppd/multilink.c 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/multilink.c 2010-08-08 09:57:01.000000000 +0200
@@ -267,7 +267,7 @@
notice("Connection terminated.");
print_link_stats();
if (!demand) {
- remove_pidfiles();
+ remove_pidfile(pidfilename);
script_unsetenv("IFNAME");
}
diff -Nru ppp-2.4.5.orig/pppd/pppd.h ppp-2.4.5/pppd/pppd.h
--- ppp-2.4.5.orig/pppd/pppd.h 2010-08-08 09:44:29.000000000 +0200
+++ ppp-2.4.5/pppd/pppd.h 2010-08-08 09:57:01.000000000 +0200
@@ -214,6 +214,7 @@
extern int ifunit; /* Interface unit number */
extern char ifname[]; /* Interface name */
extern char hostname[]; /* Our hostname */
+extern char pidfilename[]; /* name of pid file */
extern u_char outpacket_buf[]; /* Buffer for outgoing packets */
extern int devfd; /* fd of underlying device */
extern int fd_ppp; /* fd for talking PPP */
@@ -497,7 +498,7 @@
int ppp_send_config __P((int, int, u_int32_t, int, int));
int ppp_recv_config __P((int, int, u_int32_t, int, int));
const char *protocol_name __P((int));
-void remove_pidfiles __P((void));
+void remove_pidfile __P((char *));
void lock_db __P((void));
void unlock_db __P((void));
@@ -0,0 +1,141 @@
diff -Nru ppp-2.4.5.orig/pppd/auth.c ppp-2.4.5/pppd/auth.c
--- ppp-2.4.5.orig/pppd/auth.c 2010-08-08 09:58:19.000000000 +0200
+++ ppp-2.4.5/pppd/auth.c 2010-08-08 10:06:06.000000000 +0200
@@ -259,7 +259,7 @@
struct wordlist **, struct wordlist **,
char *, int));
static void free_wordlist __P((struct wordlist *));
-static void auth_script __P((char *));
+static void auth_script __P((char *, int));
static void auth_script_done __P((void *));
static void set_allowed_addrs __P((int, struct wordlist *, struct wordlist *));
static int some_ip_ok __P((struct wordlist *));
@@ -690,7 +690,7 @@
if (auth_script_state == s_up && auth_script_pid == 0) {
update_link_stats(unit);
auth_script_state = s_down;
- auth_script(_PATH_AUTHDOWN);
+ auth_script(_PATH_AUTHDOWN, 0);
}
}
if (!doing_multilink) {
@@ -822,7 +822,7 @@
auth_state = s_up;
if (auth_script_state == s_down && auth_script_pid == 0) {
auth_script_state = s_up;
- auth_script(_PATH_AUTHUP);
+ auth_script(_PATH_AUTHUP, 0);
}
}
@@ -923,6 +923,7 @@
* Authentication failure: take the link down
*/
status = EXIT_PEER_AUTH_FAILED;
+ auth_script(_PATH_AUTHFAIL, 1);
lcp_close(unit, "Authentication failed");
}
@@ -1001,6 +1002,7 @@
* authentication secrets.
*/
status = EXIT_AUTH_TOPEER_FAILED;
+ auth_script(_PATH_AUTHFAIL, 1);
lcp_close(unit, "Failed to authenticate ourselves to peer");
}
@@ -1233,6 +1235,8 @@
if (user[0] == 0 && !explicit_user)
strlcpy(user, our_name, sizeof(user));
+ script_setenv("LOCALNAME", user, 0);
+
/*
* If we have a default route, require the peer to authenticate
* unless the noauth option was given or the real user is root.
@@ -2314,13 +2318,13 @@
case s_up:
if (auth_state == s_down) {
auth_script_state = s_down;
- auth_script(_PATH_AUTHDOWN);
+ auth_script(_PATH_AUTHDOWN, 0);
}
break;
case s_down:
if (auth_state == s_up) {
auth_script_state = s_up;
- auth_script(_PATH_AUTHUP);
+ auth_script(_PATH_AUTHUP, 0);
}
break;
}
@@ -2331,8 +2335,9 @@
* interface-name peer-name real-user tty speed
*/
static void
-auth_script(script)
+auth_script(script, wait)
char *script;
+ int wait;
{
char strspeed[32];
struct passwd *pw;
@@ -2356,5 +2361,8 @@
argv[5] = strspeed;
argv[6] = NULL;
- auth_script_pid = run_program(script, argv, 0, auth_script_done, NULL, 0);
+ if (wait)
+ run_program(script, argv, 0, NULL, NULL, 1);
+ else
+ auth_script_pid = run_program(script, argv, 0, auth_script_done, NULL, 0);
}
diff -Nru ppp-2.4.5.orig/pppd/pathnames.h ppp-2.4.5/pppd/pathnames.h
--- ppp-2.4.5.orig/pppd/pathnames.h 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/pathnames.h 2010-08-08 10:06:06.000000000 +0200
@@ -27,6 +27,7 @@
#define _PATH_IPPREUP _ROOT_PATH "/etc/ppp/ip-pre-up"
#define _PATH_AUTHUP _ROOT_PATH "/etc/ppp/auth-up"
#define _PATH_AUTHDOWN _ROOT_PATH "/etc/ppp/auth-down"
+#define _PATH_AUTHFAIL _ROOT_PATH "/etc/ppp/auth-fail"
#define _PATH_TTYOPT _ROOT_PATH "/etc/ppp/options."
#define _PATH_CONNERRS _ROOT_PATH "/etc/ppp/connect-errors"
#define _PATH_PEERFILES _ROOT_PATH "/etc/ppp/peers/"
diff -Nru ppp-2.4.5.orig/pppd/pppd.8 ppp-2.4.5/pppd/pppd.8
--- ppp-2.4.5.orig/pppd/pppd.8 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/pppd.8 2010-08-08 10:06:06.000000000 +0200
@@ -1553,8 +1553,8 @@
Pppd invokes scripts at various stages in its processing which can be
used to perform site-specific ancillary processing. These scripts are
usually shell scripts, but could be executable code files instead.
-Pppd does not wait for the scripts to finish (except for the ip-pre-up
-script). The scripts are
+Pppd does not wait for the scripts to finish (except for the ip-pre-up,
+and auth-fail scripts). The scripts are
executed as root (with the real and effective user-id set to 0), so
that they can do things such as update routing tables or run
privileged daemons. Be careful that the contents of these scripts do
@@ -1582,6 +1582,11 @@
The authenticated name of the peer. This is only set if the peer
authenticates itself.
.TP
+.B LOCALNAME
+The username passed to the user option of the pppd daemon. This is
+handy to identify which account was used for authentication purposes
+when multiple accounts are available.
+.TP
.B SPEED
The baud rate of the tty device.
.TP
@@ -1634,6 +1639,11 @@
/etc/ppp/auth\-up was previously executed. It is executed in the same
manner with the same parameters as /etc/ppp/auth\-up.
.TP
+.B /etc/ppp/auth\-fail
+A program or script which is executed should authentication fail. pppd
+waits for this script to finish. It is executed in the same manner, with
+the same parameters as /etc/ppp/auth\-up.
+.TP
.B /etc/ppp/ip\-pre\-up
A program or script which is executed just before the ppp network
interface is brought up. It is executed with the same parameters as
@@ -0,0 +1,108 @@
diff -Nru ppp-2.4.5.orig/pppd/options.c ppp-2.4.5/pppd/options.c
--- ppp-2.4.5.orig/pppd/options.c 2010-08-08 09:44:29.000000000 +0200
+++ ppp-2.4.5/pppd/options.c 2010-08-08 10:07:50.000000000 +0200
@@ -94,6 +94,7 @@
int kdebugflag = 0; /* Tell kernel to print debug messages */
int default_device = 1; /* Using /dev/tty or equivalent */
char devnam[MAXPATHLEN]; /* Device name */
+int defaultmetric = 0; /* Metric of the default route */
bool nodetach = 0; /* Don't detach from controlling tty */
bool updetach = 0; /* Detach once link is up */
int maxconnect = 0; /* Maximum connect time */
@@ -289,6 +290,10 @@
"Number of seconds to wait for child processes at exit",
OPT_PRIO },
+ { "defaultmetric", o_int, &defaultmetric,
+ "The metric of the default route",
+ OPT_LIMITS, 0, 32766 },
+
#ifdef HAVE_MULTILINK
{ "multilink", o_bool, &multilink,
"Enable multilink operation", OPT_PRIO | 1 },
diff -Nru ppp-2.4.5.orig/pppd/pppd.8 ppp-2.4.5/pppd/pppd.8
--- ppp-2.4.5.orig/pppd/pppd.8 2010-08-08 10:06:57.000000000 +0200
+++ ppp-2.4.5/pppd/pppd.8 2010-08-08 10:07:50.000000000 +0200
@@ -121,6 +121,9 @@
This entry is removed when the PPP connection is broken. This option
is privileged if the \fInodefaultroute\fR option has been specified.
.TP
+.B defaultmetric \fIn
+The metric of the default route configured by pppd; default is 0.
+.TP
.B disconnect \fIscript
Execute the command specified by \fIscript\fR, by passing it to a
shell, after
diff -Nru ppp-2.4.5.orig/pppd/pppd.h ppp-2.4.5/pppd/pppd.h
--- ppp-2.4.5.orig/pppd/pppd.h 2010-08-08 09:58:19.000000000 +0200
+++ ppp-2.4.5/pppd/pppd.h 2010-08-08 10:07:50.000000000 +0200
@@ -276,6 +276,7 @@
extern int kdebugflag; /* Tell kernel to print debug messages */
extern int default_device; /* Using /dev/tty or equivalent */
extern char devnam[MAXPATHLEN]; /* Device name */
+extern int defaultmetric; /* Metric of the default route */
extern int crtscts; /* Use hardware flow control */
extern bool modem; /* Use modem control lines */
extern int inspeed; /* Input/Output speed requested */
diff -Nru ppp-2.4.5.orig/pppd/sys-linux.c ppp-2.4.5/pppd/sys-linux.c
--- ppp-2.4.5.orig/pppd/sys-linux.c 2010-08-08 09:53:56.000000000 +0200
+++ ppp-2.4.5/pppd/sys-linux.c 2010-08-08 10:07:50.000000000 +0200
@@ -1465,7 +1465,7 @@
FILE *route_fd = (FILE *) 0;
static char route_buffer[512];
static int route_dev_col, route_dest_col, route_gw_col;
-static int route_flags_col, route_mask_col;
+static int route_flags_col, route_mask_col, route_metric_col;
static int route_num_cols;
static int open_route_table (void);
@@ -1508,6 +1508,7 @@
route_dest_col = 1;
route_gw_col = 2;
route_flags_col = 3;
+ route_metric_col = 6;
route_mask_col = 7;
route_num_cols = 8;
@@ -1527,6 +1528,8 @@
route_gw_col = col;
else if (strcasecmp(q, "flags") == 0)
route_flags_col = col;
+ else if (strcasecmp(q, "metric") == 0)
+ route_metric_col = col;
else if (strcasecmp(q, "mask") == 0)
route_mask_col = col;
else
@@ -1569,6 +1572,7 @@
rt->rt_flags = (short) strtoul(cols[route_flags_col], NULL, 16);
rt->rt_dev = cols[route_dev_col];
+ rt->rt_metric = (short) strtoul(cols[route_metric_col], NULL, 16);
return 1;
}
@@ -1591,6 +1595,8 @@
if (kernel_version > KVERSION(2,1,0) && SIN_ADDR(rt->rt_genmask) != 0)
continue;
+ if (rt->rt_metric != defaultmetric) /* consider only routes with the same metric */
+ continue;
if (SIN_ADDR(rt->rt_dst) == 0L) {
result = 1;
break;
@@ -1661,6 +1667,7 @@
SIN_ADDR(rt.rt_gateway) = gateway;
rt.rt_flags = RTF_UP | RTF_GATEWAY;
+ rt.rt_metric = defaultmetric + 1; /* +1 for binary compatibility */
if (ioctl(sock_fd, SIOCADDRT, &rt) < 0) {
if ( ! ok_error ( errno ))
error("default route ioctl(SIOCADDRT): %m");
@@ -1696,6 +1703,7 @@
SIN_ADDR(rt.rt_gateway) = gateway;
rt.rt_flags = RTF_UP | RTF_GATEWAY;
+ rt.rt_metric = defaultmetric + 1; /* +1 for binary compatibility */
if (ioctl(sock_fd, SIOCDELRT, &rt) < 0 && errno != ESRCH) {
if (still_ppp()) {
if ( ! ok_error ( errno ))
@@ -0,0 +1,20 @@
--- ppp-2.4.6/pppd/sys-linux.c
+++ ppp-2.4.6/pppd/sys-linux.c
@@ -2031,6 +2031,17 @@
kernel_version = KVERSION(osmaj, osmin, ospatch);
fd = open("/dev/ppp", O_RDWR);
+ if (fd < 0) {
+ /* try making it and see if that helps. */
+ if (errno == ENOENT && mknod("/dev/ppp", S_IFCHR | S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP,
+ makedev(108, 0)) >= 0) {
+ fd = open("/dev/ppp", O_RDWR);
+ if (fd >= 0)
+ info("Created /dev/ppp device node");
+ else
+ unlink("/dev/ppp"); /* didn't work, undo the mknod */
+ }
+ }
if (fd >= 0) {
new_style_driver = 1;
@@ -0,0 +1,85 @@
diff -Nru ppp-2.4.5.orig/pppd/plugins/passwordfd.c ppp-2.4.5/pppd/plugins/passwordfd.c
--- ppp-2.4.5.orig/pppd/plugins/passwordfd.c 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/plugins/passwordfd.c 2010-08-08 10:41:39.000000000 +0200
@@ -16,11 +16,11 @@
char pppd_version[] = VERSION;
-static int passwdfd = -1;
static char save_passwd[MAXSECRETLEN];
+static int readpassword __P((char **));
static option_t options[] = {
- { "passwordfd", o_int, &passwdfd,
+ { "passwordfd", o_special, (void *)readpassword,
"Receive password on this file descriptor" },
{ NULL }
};
@@ -30,43 +30,39 @@
return 1;
}
-static int pwfd_passwd (char *user, char *passwd)
+static int readpassword(char **argv)
{
- int readgood, red;
-
- if (passwdfd == -1)
- return -1;
-
- if (passwd == NULL)
- return 1;
-
- if (passwdfd == -2) {
- strcpy (passwd, save_passwd);
- return 1;
+ char *arg = *argv;
+ int passwdfd = -1;
+ int chunk, len;
+
+ if (sscanf(arg, "%d", &passwdfd) != 1 || passwdfd < 0)
+ {
+ error ("\"%s\" is not a valid file descriptor number", arg);
+ return 0;
}
- readgood = 0;
+ len = 0;
do {
- red = read (passwdfd, passwd + readgood, MAXSECRETLEN - 1 - readgood);
- if (red == 0)
- break;
- if (red < 0) {
- error ("Can't read secret from fd\n");
- readgood = -1;
+ chunk = read (passwdfd, save_passwd + len, MAXSECRETLEN - 1 - len);
+ if (chunk == 0)
break;
+ if (chunk < 0) {
+ error ("Can't read secret from fd %d", passwdfd);
+ return 0;
}
- readgood += red;
- } while (readgood < MAXSECRETLEN - 1);
-
+ len += chunk;
+ } while (len < MAXSECRETLEN - 1);
+ save_passwd[len] = 0;
close (passwdfd);
- if (readgood < 0)
- return 0;
-
- passwd[readgood] = 0;
- strcpy (save_passwd, passwd);
- passwdfd = -2;
+ return 1;
+}
+static int pwfd_passwd (char *user, char *passwd)
+{
+ if (passwd != NULL)
+ strcpy (passwd, save_passwd);
return 1;
}
@@ -0,0 +1,256 @@
--- ppp-2.4.6/pppd/ipcp.c
+++ ppp-2.4.6/pppd/ipcp.c
@@ -91,6 +91,7 @@
static int default_route_set[NUM_PPP]; /* Have set up a default route */
static int proxy_arp_set[NUM_PPP]; /* Have created proxy arp entry */
static bool usepeerdns; /* Ask peer for DNS addrs */
+static bool usepeerwins; /* Ask peer for WINS addrs */
static int ipcp_is_up; /* have called np_up() */
static int ipcp_is_open; /* haven't called np_finished() */
static bool ask_for_local; /* request our address from peer */
@@ -210,6 +211,9 @@
{ "usepeerdns", o_bool, &usepeerdns,
"Ask peer for DNS address(es)", 1 },
+ { "usepeerwins", o_bool, &usepeerwins,
+ "Ask peer for WINS address(es)", 1 },
+
{ "netmask", o_special, (void *)setnetmask,
"set netmask", OPT_PRIO | OPT_A2STRVAL | OPT_STATIC, netmask_str },
@@ -703,6 +707,8 @@
wo->accept_remote = 1;
wo->req_dns1 = usepeerdns; /* Request DNS addresses from the peer */
wo->req_dns2 = usepeerdns;
+ wo->req_wins1 = usepeerwins; /* Request WINS addresses from the peer */
+ wo->req_wins2 = usepeerwins;
*go = *wo;
if (!ask_for_local)
go->ouraddr = 0;
@@ -755,8 +761,8 @@
LENCIADDR(go->neg_addr) +
LENCIDNS(go->req_dns1) +
LENCIDNS(go->req_dns2) +
- LENCIWINS(go->winsaddr[0]) +
- LENCIWINS(go->winsaddr[1])) ;
+ LENCIWINS(go->req_wins1) +
+ LENCIWINS(go->req_wins2)) ;
}
@@ -830,8 +836,8 @@
neg = 0; \
}
-#define ADDCIWINS(opt, addr) \
- if (addr) { \
+#define ADDCIWINS(opt, neg, addr) \
+ if (neg) { \
if (len >= CILEN_ADDR) { \
u_int32_t l; \
PUTCHAR(opt, ucp); \
@@ -840,7 +846,7 @@
PUTLONG(l, ucp); \
len -= CILEN_ADDR; \
} else \
- addr = 0; \
+ neg = 0; \
}
ADDCIADDRS(CI_ADDRS, !go->neg_addr && go->old_addrs, go->ouraddr,
@@ -855,9 +861,9 @@
ADDCIDNS(CI_MS_DNS2, go->req_dns2, go->dnsaddr[1]);
- ADDCIWINS(CI_MS_WINS1, go->winsaddr[0]);
+ ADDCIWINS(CI_MS_WINS1, go->req_wins1, go->winsaddr[0]);
- ADDCIWINS(CI_MS_WINS2, go->winsaddr[1]);
+ ADDCIWINS(CI_MS_WINS2, go->req_wins2, go->winsaddr[1]);
*lenp -= len;
}
@@ -962,8 +968,8 @@
goto bad; \
}
-#define ACKCIWINS(opt, addr) \
- if (addr) { \
+#define ACKCIWINS(opt, neg, addr) \
+ if (neg) { \
u_int32_t l; \
if ((len -= CILEN_ADDR) < 0) \
goto bad; \
@@ -989,9 +995,9 @@
ACKCIDNS(CI_MS_DNS2, go->req_dns2, go->dnsaddr[1]);
- ACKCIWINS(CI_MS_WINS1, go->winsaddr[0]);
+ ACKCIWINS(CI_MS_WINS1, go->req_wins1, go->winsaddr[0]);
- ACKCIWINS(CI_MS_WINS2, go->winsaddr[1]);
+ ACKCIWINS(CI_MS_WINS2, go->req_wins2, go->winsaddr[1]);
/*
* If there are any remaining CIs, then this packet is bad.
@@ -1026,7 +1032,7 @@
u_char cimaxslotindex, cicflag;
u_char citype, cilen, *next;
u_short cishort;
- u_int32_t ciaddr1, ciaddr2, l, cidnsaddr;
+ u_int32_t ciaddr1, ciaddr2, l, cidnsaddr, ciwinsaddr;
ipcp_options no; /* options we've seen Naks for */
ipcp_options try; /* options to request next time */
@@ -1091,6 +1097,19 @@
code \
}
+#define NAKCIWINS(opt, neg, code) \
+ if (go->neg && \
+ ((cilen = p[1]) == CILEN_ADDR) && \
+ len >= cilen && \
+ p[0] == opt) { \
+ len -= cilen; \
+ INCPTR(2, p); \
+ GETLONG(l, p); \
+ ciwinsaddr = htonl(l); \
+ no.neg = 1; \
+ code \
+ }
+
/*
* Accept the peer's idea of {our,his} address, if different
* from our idea, only if the accept_{local,remote} flag is set.
@@ -1167,6 +1186,22 @@
}
);
+ NAKCIWINS(CI_MS_WINS1, req_wins1,
+ if (treat_as_reject) {
+ try.req_wins1 = 0;
+ } else {
+ try.winsaddr[0] = ciwinsaddr;
+ }
+ );
+
+ NAKCIWINS(CI_MS_WINS2, req_wins2,
+ if (treat_as_reject) {
+ try.req_wins2 = 0;
+ } else {
+ try.winsaddr[1] = ciwinsaddr;
+ }
+ );
+
/*
* There may be remaining CIs, if the peer is requesting negotiation
* on an option that we didn't include in our request packet.
@@ -1259,7 +1294,6 @@
return 0;
}
-
/*
* ipcp_rejci - Reject some of our CIs.
* Callback from fsm_rconfnakrej.
@@ -1357,8 +1391,8 @@
try.neg = 0; \
}
-#define REJCIWINS(opt, addr) \
- if (addr && \
+#define REJCIWINS(opt, neg, addr) \
+ if (go->neg && \
((cilen = p[1]) == CILEN_ADDR) && \
len >= cilen && \
p[0] == opt) { \
@@ -1370,7 +1404,7 @@
/* Check rejected value. */ \
if (cilong != addr) \
goto bad; \
- try.winsaddr[opt == CI_MS_WINS2] = 0; \
+ try.neg = 0; \
}
REJCIADDRS(CI_ADDRS, !go->neg_addr && go->old_addrs,
@@ -1385,9 +1419,9 @@
REJCIDNS(CI_MS_DNS2, req_dns2, go->dnsaddr[1]);
- REJCIWINS(CI_MS_WINS1, go->winsaddr[0]);
+ REJCIWINS(CI_MS_WINS1, req_wins1, go->winsaddr[0]);
- REJCIWINS(CI_MS_WINS2, go->winsaddr[1]);
+ REJCIWINS(CI_MS_WINS2, req_wins2, go->winsaddr[1]);
/*
* If there are any remaining CIs, then this packet is bad.
@@ -1581,7 +1615,7 @@
/* Microsoft primary or secondary WINS request */
d = citype == CI_MS_WINS2;
- /* If we do not have a DNS address then we cannot send it */
+ /* If we do not have a WINS address then we cannot send it */
if (ao->winsaddr[d] == 0 ||
cilen != CILEN_ADDR) { /* Check CI length */
orc = CONFREJ; /* Reject CI */
@@ -1830,6 +1864,13 @@
create_resolv(go->dnsaddr[0], go->dnsaddr[1]);
}
+ if (go->winsaddr[0])
+ script_setenv("WINS1", ip_ntoa(go->winsaddr[0]), 0);
+ if (go->winsaddr[1])
+ script_setenv("WINS2", ip_ntoa(go->winsaddr[1]), 0);
+ if (usepeerwins && (go->winsaddr[0] || go->winsaddr[1]))
+ script_setenv("USEPEERWINS", "1", 0);
+
/*
* Check that the peer is allowed to use the IP address it wants.
*/
--- ppp-2.4.6/pppd/ipcp.h
+++ ppp-2.4.6/pppd/ipcp.h
@@ -77,6 +77,8 @@
bool accept_remote; /* accept peer's value for hisaddr */
bool req_dns1; /* Ask peer to send primary DNS address? */
bool req_dns2; /* Ask peer to send secondary DNS address? */
+ bool req_wins1; /* Ask peer to send primary WINS address? */
+ bool req_wins2; /* Ask peer to send secondary WINS address? */
int vj_protocol; /* protocol value to use in VJ option */
int maxslotindex; /* values for RFC1332 VJ compression neg. */
bool cflag;
--- ppp-2.4.6/pppd/pppd.8
+++ ppp-2.4.6/pppd/pppd.8
@@ -1102,6 +1102,16 @@
/etc/ppp/resolv.conf file containing one or two nameserver lines with
the address(es) supplied by the peer.
.TP
+.B usepeerwins
+Ask the peer for up to 2 WINS server addresses. The addresses supplied
+by the peer (if any) are passed to the /etc/ppp/ip\-up script in the
+environment variables WINS1 and WINS2, and the environment variable
+USEPEERWINS will be set to 1.
+.LP
+Please note that some modems (like the Huawei E220) requires this option in
+order to avoid a race condition that results in the incorrect DNS servers
+being assigned.
+.TP
.B user \fIname
Sets the name used for authenticating the local system to the peer to
\fIname\fR.
@@ -1650,6 +1660,15 @@
If the peer supplies DNS server addresses, this variable is set to the
second DNS server address supplied (whether or not the usepeerdns
option was given).
+.TP
+.B WINS1
+If the peer supplies WINS server addresses, this variable is set to the
+first WINS server address supplied.
+.TP
+.B WINS2
+If the peer supplies WINS server addresses, this variable is set to the
+second WINS server address supplied.
+.P
.P
Pppd invokes the following scripts, if they exist. It is not an error
if they don't exist.
@@ -0,0 +1,12 @@
diff -Nru ppp-2.4.5.orig/pppd/pathnames.h ppp-2.4.5/pppd/pathnames.h
--- ppp-2.4.5.orig/pppd/pathnames.h 2010-08-08 10:06:57.000000000 +0200
+++ ppp-2.4.5/pppd/pathnames.h 2010-08-08 10:53:51.000000000 +0200
@@ -29,7 +29,7 @@
#define _PATH_AUTHDOWN _ROOT_PATH "/etc/ppp/auth-down"
#define _PATH_AUTHFAIL _ROOT_PATH "/etc/ppp/auth-fail"
#define _PATH_TTYOPT _ROOT_PATH "/etc/ppp/options."
-#define _PATH_CONNERRS _ROOT_PATH "/etc/ppp/connect-errors"
+#define _PATH_CONNERRS _ROOT_PATH "/var/log/ppp-connect-errors"
#define _PATH_PEERFILES _ROOT_PATH "/etc/ppp/peers/"
#define _PATH_RESOLV _ROOT_PATH "/etc/ppp/resolv.conf"
@@ -0,0 +1,37 @@
Ensure that the build process aborts if there is an error in one of
the plugin subdirectories.
2010-09-01 Martin von Gagern
References:
http://bugs.gentoo.org/334727
Index: ppp-2.4.5/pppd/plugins/Makefile.linux
===================================================================
--- ppp-2.4.5.orig/pppd/plugins/Makefile.linux
+++ ppp-2.4.5/pppd/plugins/Makefile.linux
@@ -20,7 +20,7 @@ include .depend
endif
all: $(PLUGINS)
- for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d all; done
+ for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d all || exit $?; done
%.so: %.c
$(CC) -o $@ $(LDFLAGS) $(CFLAGS) $^
@@ -30,12 +30,12 @@ VERSION = $(shell awk -F '"' '/VERSION/
install: $(PLUGINS)
$(INSTALL) -d $(LIBDIR)
$(INSTALL) $? $(LIBDIR)
- for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d install; done
+ for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d install || exit $?; done
clean:
rm -f *.o *.so *.a
- for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d clean; done
+ for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d clean || exit $?; done
depend:
$(CPP) -M $(CFLAGS) *.c >.depend
- for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d depend; done
+ for d in $(SUBDIRS); do $(MAKE) $(MFLAGS) -C $$d depend || exit $?; done
@@ -0,0 +1,254 @@
--- ppp-2.4.6/pppd/plugins/rp-pppoe/discovery.c
+++ ppp-2.4.6/pppd/plugins/rp-pppoe/discovery.c
@@ -39,6 +39,7 @@
#endif
#include <signal.h>
+#include <time.h>
/* Calculate time remaining until *exp, return 0 if now >= *exp */
static int time_left(struct timeval *diff, struct timeval *exp)
@@ -251,6 +252,80 @@
}
/***********************************************************************
+*%FUNCTION: recvPacketForMe
+*%ARGUMENTS:
+* packet -- output parameter
+* len -- output parameter length
+* conn -- connection
+* start -- operation startup timestamp
+* timeout -- how long to wait (in seconds)
+*%RETURNS:
+* -1: error
+* 0: timed out
+* 1: packet received
+*%DESCRIPTION:
+* receive and filter junk packets
+***********************************************************************/
+
+static int
+recvPacketForMe(PPPoEPacket *packet, int *len, PPPoEConnection *conn, time_t start, int timeout)
+{
+ fd_set readable;
+ int r;
+ struct timeval tv;
+ time_t now;
+ int time_remain;
+
+ do {
+ time(&now);
+ time_remain = timeout - (int)difftime(now, start);
+ if (time_remain <= 0) return 0; /* Timed out */
+
+ if (BPF_BUFFER_IS_EMPTY) {
+ tv.tv_sec = time_remain;
+ tv.tv_usec = 0;
+
+ FD_ZERO(&readable);
+ FD_SET(conn->discoverySocket, &readable);
+
+ r = select(conn->discoverySocket+1, &readable, NULL, NULL, &tv);
+ if (r < 0)
+ {
+ if (errno == EINTR)
+ {
+ continue; /* interrupted, so retry */
+ }else
+ {
+ error("pppoe: recvPacketForMe: select: %m");
+ return -1;
+ }
+ }
+
+ if (r == 0) return 0; /* Timed out */
+ }
+
+ /* Get the packet */
+ receivePacket(conn->discoverySocket, packet, len);
+
+ /* Check length */
+ if (ntohs(packet->length) + HDR_SIZE > *len) {
+ error("Bogus PPPoE length field (%u)",
+ (unsigned int) ntohs(packet->length));
+ continue;
+ }
+
+#ifdef USE_BPF
+ /* If it's not a Discovery packet, loop again */
+ if (etherType(&packet) != Eth_PPPOE_Discovery) continue;
+#endif
+ /* If it's not for us, loop again */
+ }while ( ! packetIsForMe(conn, packet));
+
+ return 1;
+}
+
+
+/***********************************************************************
*%FUNCTION: sendPADI
*%ARGUMENTS:
* conn -- PPPoEConnection structure
@@ -344,13 +419,12 @@
void
waitForPADO(PPPoEConnection *conn, int timeout)
{
- fd_set readable;
int r;
- struct timeval tv;
struct timeval expire_at;
PPPoEPacket packet;
int len;
+ time_t start;
struct PacketCriteria pc;
pc.conn = conn;
@@ -367,43 +441,10 @@
}
expire_at.tv_sec += timeout;
+ time(&start);
do {
- if (BPF_BUFFER_IS_EMPTY) {
- if (!time_left(&tv, &expire_at))
- return; /* Timed out */
-
- FD_ZERO(&readable);
- FD_SET(conn->discoverySocket, &readable);
-
- while(1) {
- r = select(conn->discoverySocket+1, &readable, NULL, NULL, &tv);
- if (r >= 0 || errno != EINTR) break;
- }
- if (r < 0) {
- error("select (waitForPADO): %m");
- return;
- }
- if (r == 0)
- return; /* Timed out */
- }
-
- /* Get the packet */
- receivePacket(conn->discoverySocket, &packet, &len);
-
- /* Check length */
- if (ntohs(packet.length) + HDR_SIZE > len) {
- error("Bogus PPPoE length field (%u)",
- (unsigned int) ntohs(packet.length));
- continue;
- }
-
-#ifdef USE_BPF
- /* If it's not a Discovery packet, loop again */
- if (etherType(&packet) != Eth_PPPOE_Discovery) continue;
-#endif
-
- /* If it's not for us, loop again */
- if (!packetIsForMe(conn, &packet)) continue;
+ r = recvPacketForMe(&packet, &len, conn, start, timeout);
+ if (r<=0) return; /* Timed out or error */
if (packet.code == CODE_PADO) {
if (NOT_UNICAST(packet.ethHdr.h_source)) {
@@ -537,13 +578,12 @@
static void
waitForPADS(PPPoEConnection *conn, int timeout)
{
- fd_set readable;
int r;
- struct timeval tv;
struct timeval expire_at;
PPPoEPacket packet;
int len;
+ time_t start;
if (gettimeofday(&expire_at, NULL) < 0) {
error("gettimeofday (waitForPADS): %m");
@@ -551,48 +591,15 @@
}
expire_at.tv_sec += timeout;
+ time(&start);
conn->error = 0;
do {
- if (BPF_BUFFER_IS_EMPTY) {
- if (!time_left(&tv, &expire_at))
- return; /* Timed out */
-
- FD_ZERO(&readable);
- FD_SET(conn->discoverySocket, &readable);
-
- while(1) {
- r = select(conn->discoverySocket+1, &readable, NULL, NULL, &tv);
- if (r >= 0 || errno != EINTR) break;
- }
- if (r < 0) {
- error("select (waitForPADS): %m");
- return;
- }
- if (r == 0)
- return; /* Timed out */
- }
-
- /* Get the packet */
- receivePacket(conn->discoverySocket, &packet, &len);
-
- /* Check length */
- if (ntohs(packet.length) + HDR_SIZE > len) {
- error("Bogus PPPoE length field (%u)",
- (unsigned int) ntohs(packet.length));
- continue;
- }
-
-#ifdef USE_BPF
- /* If it's not a Discovery packet, loop again */
- if (etherType(&packet) != Eth_PPPOE_Discovery) continue;
-#endif
+ r = recvPacketForMe(&packet, &len, conn, start, timeout);
+ if (r<=0) return; /* Timed out or error */
/* If it's not from the AC, it's not for me */
if (memcmp(packet.ethHdr.h_source, conn->peerEth, ETH_ALEN)) continue;
- /* If it's not for us, loop again */
- if (!packetIsForMe(conn, &packet)) continue;
-
/* Is it PADS? */
if (packet.code == CODE_PADS) {
/* Parse for goodies */
--- ppp-2.4.6/pppd/plugins/rp-pppoe/pppoe-discovery.c
+++ ppp-2.4.6/pppd/plugins/rp-pppoe/pppoe-discovery.c
@@ -14,6 +14,7 @@
#include <unistd.h>
#include <errno.h>
#include <string.h>
+#include <time.h>
#include "pppoe.h"
@@ -513,6 +514,8 @@
struct timeval tv;
PPPoEPacket packet;
int len;
+ time_t start, now;
+ int time_remain;
struct PacketCriteria pc;
pc.conn = conn;
@@ -522,9 +525,13 @@
pc.seenServiceName = 0;
conn->error = 0;
+ time(&start);
do {
+ time(&now);
+ time_remain = timeout - (int)difftime(now, start);
+ if (time_remain <= 0) return; /* Timed out */
if (BPF_BUFFER_IS_EMPTY) {
- tv.tv_sec = timeout;
+ tv.tv_sec = time_remain;
tv.tv_usec = 0;
FD_ZERO(&readable);
@@ -0,0 +1,58 @@
diff -Nru ppp-2.4.5.orig/pppd/lcp.c ppp-2.4.5/pppd/lcp.c
--- ppp-2.4.5.orig/pppd/lcp.c 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/lcp.c 2010-11-27 10:46:26.000000000 +0100
@@ -73,6 +73,7 @@
*/
int lcp_echo_interval = 0; /* Interval between LCP echo-requests */
int lcp_echo_fails = 0; /* Tolerance to unanswered echo-requests */
+bool lcp_echo_adaptive = 0; /* request echo only if the link was idle */
bool lax_recv = 0; /* accept control chars in asyncmap */
bool noendpoint = 0; /* don't send/accept endpoint discriminator */
@@ -151,6 +152,8 @@
OPT_PRIO },
{ "lcp-echo-interval", o_int, &lcp_echo_interval,
"Set time in seconds between LCP echo requests", OPT_PRIO },
+ { "lcp-echo-adaptive", o_bool, &lcp_echo_adaptive,
+ "Suppress LCP echo requests if traffic was received", 1 },
{ "lcp-restart", o_int, &lcp_fsm[0].timeouttime,
"Set time in seconds between LCP retransmissions", OPT_PRIO },
{ "lcp-max-terminate", o_int, &lcp_fsm[0].maxtermtransmits,
@@ -2322,6 +2325,22 @@
}
/*
+ * If adaptive echos have been enabled, only send the echo request if
+ * no traffic was received since the last one.
+ */
+ if (lcp_echo_adaptive) {
+ static unsigned int last_pkts_in = 0;
+
+ update_link_stats(f->unit);
+ link_stats_valid = 0;
+
+ if (link_stats.pkts_in != last_pkts_in) {
+ last_pkts_in = link_stats.pkts_in;
+ return;
+ }
+ }
+
+ /*
* Make and send the echo request frame.
*/
if (f->state == OPENED) {
diff -Nru ppp-2.4.5.orig/pppd/pppd.8 ppp-2.4.5/pppd/pppd.8
--- ppp-2.4.5.orig/pppd/pppd.8 2009-11-16 23:26:07.000000000 +0100
+++ ppp-2.4.5/pppd/pppd.8 2010-11-27 10:44:58.000000000 +0100
@@ -549,6 +549,11 @@
dynamic IP address option (i.e. set /proc/sys/net/ipv4/ip_dynaddr to
1) in demand mode if the local address changes.
.TP
+.B lcp\-echo\-adaptive
+If this option is used with the \fIlcp\-echo\-failure\fR option then
+pppd will send LCP echo\-request frames only if no traffic was received
+from the peer since the last echo\-request was sent.
+.TP
.B lcp\-echo\-failure \fIn
If this option is given, pppd will presume the peer to be dead
if \fIn\fR LCP echo\-requests are sent without receiving a valid LCP
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,19 @@
--- ppp-2.4.3/pppd/plugins/dhcp/Makefile.linux
+++ ppp-2.4.3/pppd/plugins/dhcp/Makefile.linux
@@ -1,6 +1,6 @@
PLUGIN=dhcpc.so
-CFLAGS=-I../.. -I../../../include -O2
+CFLAGS=$(COPTS) -I../.. -I../../../include -fPIC
all: $(PLUGIN)
@@ -9,7 +9,7 @@
$(INSTALL) -s -c -m 755 dhcpc.so $(LIBDIR)
dhcpc.so: dhcpc.o clientpacket.o packet.o socket.o options.o
- gcc -o dhcpc.so -shared dhcpc.o clientpacket.o packet.o socket.o options.o
+ $(CC) $(LDFLAGS) $(CFLAGS) -o $@ $^
clean:
@@ -0,0 +1,128 @@
--- ppp-2.4.2/pppd/plugins/dhcp/dhcpc.c
+++ ppp-2.4.2/pppd/plugins/dhcp/dhcpc.c
@@ -144,7 +144,7 @@
fd = raw_socket(client_config.ifindex);
if (listen_mode != LISTEN_NONE && fd < 0) {
- fatal("DHCPC: couldn't listen on socket, %s", sys_errlist[errno]);
+ fatal("DHCPC: couldn't listen on socket, %s", strerror(errno));
}
}
@@ -208,7 +208,7 @@
len = get_packet(&packet, fd);
if (len == -1 && errno != EINTR) {
- dbglog("DHCPC: error on read, %s, reopening socket", sys_errlist[errno]);
+ dbglog("DHCPC: error on read, %s, reopening socket", strerror(errno));
change_mode(LISTEN_KERNEL);
}
if (len < 0) continue;
@@ -380,7 +380,7 @@
else len = get_raw_packet(&packet, fd);
if (len == -1 && errno != EINTR) {
- dbglog("DHCPC: error on read, %s, reopening socket", sys_errlist[errno]);
+ dbglog("DHCPC: error on read, %s, reopening socket", strerror(errno));
change_mode(listen_mode); /* just close and reopen */
}
if (len < 0) continue;
@@ -445,7 +445,7 @@
} else {
/* An error occured */
- dbglog("DHCPC: error on select, %s, reopening socket", sys_errlist[errno]);
+ dbglog("DHCPC: error on select, %s, reopening socket", strerror(errno));
change_mode(listen_mode); /* just close and reopen */
}
--- ppp-2.4.2/pppd/plugins/dhcp/packet.c
+++ ppp-2.4.2/pppd/plugins/dhcp/packet.c
@@ -125,7 +125,7 @@
return kernel_packet(payload,payload->giaddr,CLIENT_PORT,dest_ip,dest_port);
if ((fd = socket(PF_PACKET, SOCK_DGRAM, htons(ETH_P_IP))) < 0) {
- DEBUG(LOG_ERR, "socket call failed: %s", sys_errlist[errno]);
+ DEBUG(LOG_ERR, "socket call failed: %s", strerror(errno));
return -1;
}
@@ -138,7 +138,7 @@
dest.sll_halen = 6;
memcpy(dest.sll_addr, dest_arp, 6);
if (bind(fd, (struct sockaddr *)&dest, sizeof(struct sockaddr_ll)) < 0) {
- DEBUG(LOG_ERR, "bind call failed: %s", sys_errlist[errno]);
+ DEBUG(LOG_ERR, "bind call failed: %s", strerror(errno));
close(fd);
return -1;
}
@@ -161,7 +161,7 @@
result = sendto(fd, &packet, sizeof(struct udp_dhcp_packet), 0, (struct sockaddr *) &dest, sizeof(dest));
if (result <= 0) {
- DEBUG(LOG_ERR, "write on socket failed: %s", sys_errlist[errno]);
+ DEBUG(LOG_ERR, "write on socket failed: %s", strerror(errno));
}
close(fd);
return result;
--- ppp-2.4.2/pppd/plugins/dhcp/socket.c
+++ ppp-2.4.2/pppd/plugins/dhcp/socket.c
@@ -60,7 +60,7 @@
*addr = sin->sin_addr.s_addr;
DEBUG(LOG_INFO, "%s (our ip) = %s", ifr.ifr_name, inet_ntoa(sin->sin_addr));
} else {
- LOG(LOG_ERR, "SIOCGIFADDR failed!: %s", sys_errlist[errno]);
+ LOG(LOG_ERR, "SIOCGIFADDR failed!: %s", strerror(errno));
return -1;
}
}
@@ -69,7 +69,7 @@
DEBUG(LOG_INFO, "adapter index %d", ifr.ifr_ifindex);
*ifindex = ifr.ifr_ifindex;
} else {
- LOG(LOG_ERR, "SIOCGIFINDEX failed!: %s", sys_errlist[errno]);
+ LOG(LOG_ERR, "SIOCGIFINDEX failed!: %s", strerror(errno));
return -1;
}
if (ioctl(fd, SIOCGIFHWADDR, &ifr) == 0) {
@@ -77,11 +77,11 @@
DEBUG(LOG_INFO, "adapter hardware address %02x:%02x:%02x:%02x:%02x:%02x",
arp[0], arp[1], arp[2], arp[3], arp[4], arp[5]);
} else {
- LOG(LOG_ERR, "SIOCGIFHWADDR failed!: %s", sys_errlist[errno]);
+ LOG(LOG_ERR, "SIOCGIFHWADDR failed!: %s", strerror(errno));
return -1;
}
} else {
- LOG(LOG_ERR, "socket failed!: %s", sys_errlist[errno]);
+ LOG(LOG_ERR, "socket failed!: %s", strerror(errno));
return -1;
}
close(fd);
@@ -98,7 +98,7 @@
DEBUG(LOG_INFO, "Opening listen socket on 0x%08x:%d %s\n", ip, port, inf ? inf : "*");
if ((fd = socket(PF_INET, SOCK_DGRAM, IPPROTO_UDP)) < 0) {
- DEBUG(LOG_ERR, "socket call failed: %s", sys_errlist[errno]);
+ DEBUG(LOG_ERR, "socket call failed: %s", strerror(errno));
return -1;
}
@@ -144,7 +144,7 @@
DEBUG(LOG_INFO, "Opening raw socket on ifindex %d\n", ifindex);
if ((fd = socket(PF_PACKET, SOCK_DGRAM, htons(ETH_P_IP))) < 0) {
- DEBUG(LOG_ERR, "socket call failed: %s", sys_errlist[errno]);
+ DEBUG(LOG_ERR, "socket call failed: %s", strerror(errno));
return -1;
}
@@ -152,7 +152,7 @@
sock.sll_protocol = htons(ETH_P_IP);
sock.sll_ifindex = ifindex;
if (bind(fd, (struct sockaddr *) &sock, sizeof(sock)) < 0) {
- DEBUG(LOG_ERR, "bind call failed: %s", sys_errlist[errno]);
+ DEBUG(LOG_ERR, "bind call failed: %s", strerror(errno));
close(fd);
return -1;
}
+37
View File
@@ -0,0 +1,37 @@
#!/bin/sh
# this is a script which is executed after disconnecting the ppp interface.
# look at man pppd for details
# the followings parameters are available:
# $1 = interface-name
# $2 = tty-device
# $3 = speed
# $4 = local-IP-address
# $5 = remote-IP-address
# $6 = ipparam
if [ "$USEPEERDNS" ]; then
# taken from debian's 0000usepeerdns
# follow any symlink to find the real file
REALRESOLVCONF=$(readlink --canonicalize /etc/resolv.conf)
if [ "$REALRESOLVCONF" != "/etc/ppp/resolv.conf" ]; then
# if an old resolv.conf file exists, restore it
if [ -e $REALRESOLVCONF.pppd-backup ]; then
mv $REALRESOLVCONF.pppd-backup $REALRESOLVCONF
fi
fi
fi
# Recreate the default route so autodial works
[ -s /etc/conf.d/net ] && . /etc/conf.d/net
if [ -n "${gateway}" ] && [ "${gateway%/*}" = "$1" ]; then
/sbin/route add default dev ${gateway%/*}
fi
[ -f /etc/ppp/ip-down.local ] && . /etc/ppp/ip-down.local "$@"
+42
View File
@@ -0,0 +1,42 @@
#!/bin/sh
# this is a script which is executed after connecting the ppp interface.
# look at man pppd for details
# the followings parameters are available:
# $1 = interface-name
# $2 = tty-device
# $3 = speed
# $4 = local-IP-address
# $5 = remote-IP-address
# $6 = ipparam
if [ "$USEPEERDNS" ]; then
# add the server supplied DNS entries to /etc/resolv.conf
# (taken from debian's 0000usepeerdns)
# follow any symlink to find the real file
REALRESOLVCONF=$(readlink --canonicalize /etc/resolv.conf)
if [ "$REALRESOLVCONF" != "/etc/ppp/resolv.conf" ]; then
# merge the new nameservers with the other options from the old configuration
{
grep '^nameserver[[:space:]]' $REALRESOLVCONF
cat /etc/ppp/resolv.conf
} > $REALRESOLVCONF.tmp
# backup the old configuration and install the new one
cp -a $REALRESOLVCONF $REALRESOLVCONF.pppd-backup
mv $REALRESOLVCONF.tmp $REALRESOLVCONF
# correct permissions
chmod 0644 /etc/resolv.conf
chown root:root /etc/resolv.conf
fi
fi
[ -f /etc/ppp/ip-up.local ] && . /etc/ppp/ip-up.local "$@"
@@ -0,0 +1,92 @@
Index: ppp-2.4.5/chat/Makefile.linux
===================================================================
--- ppp-2.4.5.orig/chat/Makefile.linux
+++ ppp-2.4.5/chat/Makefile.linux
@@ -25,7 +25,7 @@ chat.o: chat.c
install: chat
mkdir -p $(BINDIR) $(MANDIR)
- $(INSTALL) -s -c chat $(BINDIR)
+ $(INSTALL) -c chat $(BINDIR)
$(INSTALL) -c -m 644 chat.8 $(MANDIR)
clean:
Index: ppp-2.4.5/pppd/Makefile.linux
===================================================================
--- ppp-2.4.5.orig/pppd/Makefile.linux
+++ ppp-2.4.5/pppd/Makefile.linux
@@ -100,7 +100,7 @@ ifdef USE_SRP
CFLAGS += -DUSE_SRP -DOPENSSL -I/usr/local/ssl/include
LIBS += -lsrp -L/usr/local/ssl/lib -lcrypto
TARGETS += srp-entry
-EXTRAINSTALL = $(INSTALL) -s -c -m 555 srp-entry $(BINDIR)/srp-entry
+EXTRAINSTALL = $(INSTALL) -c -m 555 srp-entry $(BINDIR)/srp-entry
MANPAGES += srp-entry.8
EXTRACLEAN += srp-entry.o
NEEDDES=y
@@ -201,7 +201,7 @@ all: $(TARGETS)
install: pppd
mkdir -p $(BINDIR) $(MANDIR)
$(EXTRAINSTALL)
- $(INSTALL) -s -c -m 555 pppd $(BINDIR)/pppd
+ $(INSTALL) -c -m 555 pppd $(BINDIR)/pppd
if chgrp pppusers $(BINDIR)/pppd 2>/dev/null; then \
chmod o-rx,u+s $(BINDIR)/pppd; fi
$(INSTALL) -c -m 444 pppd.8 $(MANDIR)
Index: ppp-2.4.5/pppd/plugins/radius/Makefile.linux
===================================================================
--- ppp-2.4.5.orig/pppd/plugins/radius/Makefile.linux
+++ ppp-2.4.5/pppd/plugins/radius/Makefile.linux
@@ -36,9 +36,9 @@ all: $(PLUGIN)
install: all
$(INSTALL) -d -m 755 $(LIBDIR)
- $(INSTALL) -s -c -m 755 radius.so $(LIBDIR)
- $(INSTALL) -s -c -m 755 radattr.so $(LIBDIR)
- $(INSTALL) -s -c -m 755 radrealms.so $(LIBDIR)
+ $(INSTALL) -c -m 755 radius.so $(LIBDIR)
+ $(INSTALL) -c -m 755 radattr.so $(LIBDIR)
+ $(INSTALL) -c -m 755 radrealms.so $(LIBDIR)
$(INSTALL) -c -m 444 pppd-radius.8 $(MANDIR)
$(INSTALL) -c -m 444 pppd-radattr.8 $(MANDIR)
Index: ppp-2.4.5/pppd/plugins/rp-pppoe/Makefile.linux
===================================================================
--- ppp-2.4.5.orig/pppd/plugins/rp-pppoe/Makefile.linux
+++ ppp-2.4.5/pppd/plugins/rp-pppoe/Makefile.linux
@@ -43,9 +43,9 @@ rp-pppoe.so: plugin.o discovery.o if.o c
install: all
$(INSTALL) -d -m 755 $(LIBDIR)
- $(INSTALL) -s -c -m 4550 rp-pppoe.so $(LIBDIR)
+ $(INSTALL) -c -m 4550 rp-pppoe.so $(LIBDIR)
$(INSTALL) -d -m 755 $(BINDIR)
- $(INSTALL) -s -c -m 555 pppoe-discovery $(BINDIR)
+ $(INSTALL) -c -m 555 pppoe-discovery $(BINDIR)
clean:
rm -f *.o *.so pppoe-discovery
Index: ppp-2.4.5/pppdump/Makefile.linux
===================================================================
--- ppp-2.4.5.orig/pppdump/Makefile.linux
+++ ppp-2.4.5/pppdump/Makefile.linux
@@ -17,5 +17,5 @@ clean:
install:
mkdir -p $(BINDIR) $(MANDIR)
- $(INSTALL) -s -c pppdump $(BINDIR)
+ $(INSTALL) -c pppdump $(BINDIR)
$(INSTALL) -c -m 444 pppdump.8 $(MANDIR)
Index: ppp-2.4.5/pppstats/Makefile.linux
===================================================================
--- ppp-2.4.5.orig/pppstats/Makefile.linux
+++ ppp-2.4.5/pppstats/Makefile.linux
@@ -22,7 +22,7 @@ all: pppstats
install: pppstats
-mkdir -p $(MANDIR)
- $(INSTALL) -s -c pppstats $(BINDIR)
+ $(INSTALL) -c pppstats $(BINDIR)
$(INSTALL) -c -m 444 pppstats.8 $(MANDIR)
pppstats: $(PPPSTATSRCS)
@@ -0,0 +1,6 @@
noipdefault
hide-password
defaultroute
persist
lock
+18
View File
@@ -0,0 +1,18 @@
#192.168.1.0:
netmask 255.255.255.0
#debug
#kdebug 1
lock
mtu 1490
mru 1490
proxyarp
auth
require-chap
passive
ipcp-accept-local
ipcp-accept-remote
lcp-echo-failure 3
lcp-echo-interval 5
deflate 0
#ms-dns 192.168.1.1
#ms-wins 192.168.1.1
@@ -0,0 +1,295 @@
--- ppp-2.3.3/sample/auth-down.sample Tue Jan 6 17:53:27 1998
+++ ppp-2.3.3/sample/auth-down Tue Jan 6 17:53:27 1998
@@ -0,0 +1,17 @@
+#!/bin/sh
+#
+# A program or script which is executed after the remote system
+# successfully authenticates itself. It is executed with the parameters
+# <interface-name> <peer-name> <user-name> <tty-device> <speed>
+#
+
+#
+# The environment is cleared before executing this script
+# so the path must be reset
+#
+PATH=/usr/sbin:/sbin:/usr/bin:/bin
+export PATH
+
+echo auth-down `date +'%y/%m/%d %T'` $* >> /var/log/pppstats
+
+# last line
--- ppp-2.3.3/sample/auth-up.sample Tue Jan 6 17:53:27 1998
+++ ppp-2.3.3/sample/auth-up Tue Jan 6 17:53:27 1998
@@ -0,0 +1,17 @@
+#!/bin/sh
+#
+# A program or script which is executed after the remote system
+# successfully authenticates itself. It is executed with the parameters
+# <interface-name> <peer-name> <user-name> <tty-device> <speed>
+#
+
+#
+# The environment is cleared before executing this script
+# so the path must be reset
+#
+PATH=/usr/sbin:/sbin:/usr/bin:/bin
+export PATH
+
+echo auth-up `date +'%y/%m/%d %T'` $* >> /var/log/pppstats
+
+# last line
--- ppp-2.3.3/sample/ip-down.sample Tue Jan 6 17:53:27 1998
+++ ppp-2.3.3/sample/ip-down Tue Jan 6 17:53:27 1998
@@ -0,0 +1,22 @@
+#!/bin/sh
+#
+# This script is run by the pppd _after_ the link is brought down.
+# It should be used to delete routes, unset IP addresses etc.
+#
+# This script is called with the following arguments:
+# Arg Name Example
+# $1 Interface name ppp0
+# $2 The tty ttyS1
+# $3 The link speed 38400
+# $4 Local IP number 12.34.56.78
+# $5 Peer IP number 12.34.56.99
+#
+
+#
+# The environment is cleared before executing this script
+# so the path must be reset
+#
+PATH=/usr/sbin:/sbin:/usr/bin:/bin
+export PATH
+
+# last line
--- ppp-2.3.3/sample/ip-up.sample Tue Jan 6 17:53:27 1998
+++ ppp-2.3.3/sample/ip-up Tue Jan 6 17:53:27 1998
@@ -0,0 +1,23 @@
+#!/bin/sh
+#
+# This script is run by the pppd after the link is established.
+# It should be used to add routes, set IP address, run the mailq
+# etc.
+#
+# This script is called with the following arguments:
+# Arg Name Example
+# $1 Interface name ppp0
+# $2 The tty ttyS1
+# $3 The link speed 38400
+# $4 Local IP number 12.34.56.78
+# $5 Peer IP number 12.34.56.99
+#
+
+#
+# The environment is cleared before executing this script
+# so the path must be reset
+#
+PATH=/usr/sbin:/sbin:/usr/bin:/bin
+export PATH
+
+# last line
--- ppp-2.3.3/sample/options.sample Tue Jan 6 17:53:27 1998
+++ ppp-2.3.3/sample/options Tue Jan 6 17:53:27 1998
@@ -0,0 +1,153 @@
+# /etc/ppp/options
+
+# The name of this server. Often, the FQDN is used here.
+#name <host>
+
+# Enforce the use of the hostname as the name of the local system for
+# authentication purposes (overrides the name option).
+usehostname
+
+# If no local IP address is given, pppd will use the first IP address
+# that belongs to the local hostname. If "noipdefault" is given, this
+# is disabled and the peer will have to supply an IP address.
+noipdefault
+
+# With this option, pppd will accept the peer's idea of our local IP
+# address, even if the local IP address was specified in an option.
+#ipcp-accept-local
+
+# With this option, pppd will accept the peer's idea of its (remote) IP
+# address, even if the remote IP address was specified in an option.
+#ipcp-accept-remote
+
+# Specify which DNS Servers the incoming Win95 or WinNT Connection should use
+# Two Servers can be remotely configured
+#ms-dns 192.168.1.1
+#ms-dns 192.168.1.2
+
+# Specify which WINS Servers the incoming connection Win95 or WinNT should use
+#wins-addr 192.168.1.50
+#wins-addr 192.168.1.51
+
+# enable this on a server that already has a permanent default route
+#nodefaultroute
+
+# Run the executable or shell command specified after pppd has terminated
+# the link. This script could, for example, issue commands to the modem
+# to cause it to hang up if hardware modem control signals were not
+# available.
+# If mgetty is running, it will reset the modem anyway. So there is no need
+# to do it here.
+#disconnect "chat -- \d+++\d\c OK ath0 OK"
+
+# Increase debugging level (same as -d). The debug output is written
+# to syslog LOG_LOCAL2.
+debug
+
+# Enable debugging code in the kernel-level PPP driver. The argument n
+# is a number which is the sum of the following values: 1 to enable
+# general debug messages, 2 to request that the contents of received
+# packets be printed, and 4 to request that the contents of transmitted
+# packets be printed.
+#kdebug n
+
+# Require the peer to authenticate itself before allowing network
+# packets to be sent or received.
+# Please do not disable this setting. It is expected to be standard in
+# future releases of pppd. Use the call option (see manpage) to disable
+# authentication for specific peers.
+#auth
+
+# authentication can either be pap or chap. As most people only want to
+# use pap, you can also disable chap:
+#require-pap
+#refuse-chap
+
+# Use hardware flow control (i.e. RTS/CTS) to control the flow of data
+# on the serial port.
+crtscts
+
+# Specifies that pppd should use a UUCP-style lock on the serial device
+# to ensure exclusive access to the device.
+lock
+
+# Use the modem control lines.
+modem
+
+# async character map -- 32-bit hex; each bit is a character
+# that needs to be escaped for pppd to receive it. 0x00000001
+# represents '\x01', and 0x80000000 represents '\x1f'.
+# To allow pppd to work over a rlogin/telnet connection, ou should escape
+# XON (^Q), XOFF (^S) and ^]: (The peer should use "escape ff".)
+#asyncmap 200a0000
+asyncmap 0
+
+# Specifies that certain characters should be escaped on transmission
+# (regardless of whether the peer requests them to be escaped with its
+# async control character map). The characters to be escaped are
+# specified as a list of hex numbers separated by commas. Note that
+# almost any character can be specified for the escape option, unlike
+# the asyncmap option which only allows control characters to be
+# specified. The characters which may not be escaped are those with hex
+# values 0x20 - 0x3f or 0x5e.
+#escape 11,13,ff
+
+# Set the MRU [Maximum Receive Unit] value to <n> for negotiation. pppd
+# will ask the peer to send packets of no more than <n> bytes. The
+# minimum MRU value is 128. The default MRU value is 1500. A value of
+# 296 is recommended for slow links (40 bytes for TCP/IP header + 256
+# bytes of data).
+#mru 542
+
+# Set the MTU [Maximum Transmit Unit] value to <n>. Unless the peer
+# requests a smaller value via MRU negotiation, pppd will request that
+# the kernel networking code send data packets of no more than n bytes
+# through the PPP network interface.
+#mtu <n>
+
+# Set the interface netmask to <n>, a 32 bit netmask in "decimal dot"
+# notation (e.g. 255.255.255.0).
+#netmask 255.255.255.0
+
+# Don't fork to become a background process (otherwise pppd will do so
+# if a serial device is specified).
+nodetach
+
+# Set the assumed name of the remote system for authentication purposes
+# to <n>.
+#remotename <n>
+
+# Add an entry to this system's ARP [Address Resolution Protocol]
+# table with the IP address of the peer and the Ethernet address of this
+# system. {proxyarp,noproxyarp}
+proxyarp
+
+# Use the system password database for authenticating the peer using
+# PAP. Note: mgetty already provides this option. If this is specified
+# then dialin from users using a script under Linux to fire up ppp wont work.
+#login
+
+# If this option is given, pppd will send an LCP echo-request frame to
+# the peer every n seconds. Under Linux, the echo-request is sent when
+# no packets have been received from the peer for n seconds. Normally
+# the peer should respond to the echo-request by sending an echo-reply.
+# This option can be used with the lcp-echo-failure option to detect
+# that the peer is no longer connected.
+lcp-echo-interval 30
+
+# If this option is given, pppd will presume the peer to be dead if n
+# LCP echo-requests are sent without receiving a valid LCP echo-reply.
+# If this happens, pppd will terminate the connection. Use of this
+# option requires a non-zero value for the lcp-echo-interval parameter.
+# This option can be used to enable pppd to terminate after the physical
+# connection has been broken (e.g., the modem has hung up) in
+# situations where no hardware modem control lines are available.
+lcp-echo-failure 4
+
+# Specifies that pppd should disconnect if the link is idle for n seconds.
+idle 600
+
+# Disable the IPXCP and IPX protocols.
+noipx
+
+# ---<End of File>---
--- ppp-2.3.3/sample/options.ttyXX.sample Tue Jan 6 17:53:27 1998
+++ ppp-2.3.3/sample/options.ttyXX Tue Jan 6 17:53:27 1998
@@ -0,0 +1,14 @@
+# If you need to set up multiple serial lines then copy this file to
+# options.<ttyname> for each tty with a modem on it.
+#
+# The options.tty file will assign an IP address to each PPP connection
+# as it comes up. They must all be distinct!
+#
+# Example:
+# options.ttyS1 for com2 under DOS.
+#
+# Edit the following line so that the first IP address
+# mentioned is the ip address of the serial port while the second
+# is the IP address of your host
+#
+hostname-s1:hostname
--- ppp-2.3.3/sample/pap-secrets.sample Tue Jan 6 17:53:27 1998
+++ ppp-2.3.3/sample/pap-secrets Tue Jan 6 17:53:27 1998
@@ -0,0 +1,28 @@
+# Secrets for authentication using PAP
+# client server secret IP addresses
+
+# OUTBOUND CONNECTIONS
+# Here you should add your userid password to connect to your providers via
+# pap. The * means that the password is to be used for ANY host you connect
+# to. Thus you do not have to worry about the foreign machine name. Just
+# replace password with your password.
+# If you have different providers with different passwords then you better
+# remove the following line.
+#hostname * password
+
+# INBOUND CONNECTIONS
+#client hostname <password> 192.168.1.1
+
+# If you add "auth login -chap +pap" to /etc/mgetty+sendfax/login.config,
+# all users in /etc/passwd can use their password for pap-authentication.
+#
+# Every regular user can use PPP and has to use passwords from /etc/passwd
+#* hostname ""
+# UserIDs that cannot use PPP at all. Check your /etc/passwd and add any
+# other accounts that should not be able to use pppd! Replace hostname
+# with your local hostname.
+#guest hostname "*" -
+#master hostname "*" -
+#root hostname "*" -
+#support hostname "*" -
+#stats hostname "*" -
@@ -0,0 +1,61 @@
diff -urNp --exclude-from=/mdomsch2/excludes --minimal ppp-2.4.3.orig/pppd/pppd.8 ppp-2.4.3/pppd/pppd.8
--- ppp-2.4.3.orig/pppd/pppd.8 2004-11-13 06:22:49.000000000 -0600
+++ ppp-2.4.3/pppd/pppd.8 2005-08-03 22:10:34.000000000 -0500
@@ -1035,7 +1035,7 @@ Ask the peer for up to 2 DNS server addr
by the peer (if any) are passed to the /etc/ppp/ip\-up script in the
environment variables DNS1 and DNS2, and the environment variable
USEPEERDNS will be set to 1. In addition, pppd will create an
-/etc/ppp/resolv.conf file containing one or two nameserver lines with
+/run/ppp/resolv.conf file containing one or two nameserver lines with
the address(es) supplied by the peer.
.TP
.B user \fIname
--- ppp-2.4.2/scripts/ip-down.local.add.change_resolv_conf 1999-02-27 05:32:42.000000000 +0100
+++ ppp-2.4.2/scripts/ip-down.local.add 2004-09-14 14:36:20.058008752 +0200
@@ -9,12 +9,13 @@
#
# Nick Walker (nickwalker@email.com)
#
+. /etc/sysconfig/network-scripts/network-functions
-if [ -n "$USEPEERDNS" -a -f /etc/ppp/resolv.conf ]; then
- if [ -f /etc/ppp/resolv.prev ]; then
- cp -f /etc/ppp/resolv.prev /etc/resolv.conf
+if [ -n "$USEPEERDNS" -a -f /run/ppp/resolv.conf ]; then
+ if [ -f /run/ppp/resolv.prev ]; then
+ change_resolv_conf /run/ppp/resolv.prev
else
- rm -f /etc/resolv.conf
+ change_resolv_conf
fi
fi
--- ppp-2.4.2/scripts/ip-up.local.add.change_resolv_conf 1999-11-15 04:28:10.000000000 +0100
+++ ppp-2.4.2/scripts/ip-up.local.add 2004-09-14 14:37:39.129061828 +0200
@@ -9,16 +9,19 @@
#
# Nick Walker (nickwalker@email.com)
#
+. /etc/sysconfig/network-scripts/network-functions
-if [ -n "$USEPEERDNS" -a -f /etc/ppp/resolv.conf ]; then
- rm -f /etc/ppp/resolv.prev
+if [ -n "$USEPEERDNS" -a -f /run/ppp/resolv.conf ]; then
+ rm -f /run/ppp/resolv.prev
if [ -f /etc/resolv.conf ]; then
- cp /etc/resolv.conf /etc/ppp/resolv.prev
- grep domain /etc/ppp/resolv.prev > /etc/resolv.conf
- grep search /etc/ppp/resolv.prev >> /etc/resolv.conf
- cat /etc/ppp/resolv.conf >> /etc/resolv.conf
+ cp /etc/resolv.conf /run/ppp/resolv.prev
+ rscf=/run/ppp/resolv.new
+ grep domain /run/ppp/resolv.prev > $rscf
+ grep search /run/ppp/resolv.prev >> $rscf
+ change_resolv_conf $rscf
+ rm -f $rscf
else
- cp /etc/ppp/resolv.conf /etc
+ change_resolv_conf /run/ppp/resolv.conf
fi
fi
@@ -0,0 +1,10 @@
--- ppp-2.4.3/pppd/sha1.c.fix64 2004-10-25 01:28:02.000000000 +0200
+++ ppp-2.4.3/pppd/sha1.c 2004-11-22 16:44:16.850768926 +0100
@@ -18,6 +18,7 @@
#include <string.h>
#include <netinet/in.h> /* htonl() */
+#include <sys/types.h> /* u_int32_t */
#include <net/ppp_defs.h>
#include "sha1.h"
@@ -0,0 +1,40 @@
--- ppp-2.4.3/pppd/ipv6cp.c~ 2005-11-04 09:40:10.000000000 +0000
+++ ppp-2.4.3/pppd/ipv6cp.c 2005-11-04 10:20:14.000000000 +0000
@@ -235,6 +235,8 @@ static option_t ipv6cp_option_list[] = {
{ "ipv6cp-accept-local", o_bool, &ipv6cp_allowoptions[0].accept_local,
"Accept peer's interface identifier for us", 1 },
+ { "ipv6cp-accept-remote", o_bool, &ipv6cp_allowoptions[0].accept_remote,
+ "Accept peer's interface identifier for itself", 1 },
{ "ipv6cp-use-ipaddr", o_bool, &ipv6cp_allowoptions[0].use_ip,
"Use (default) IPv4 address as interface identifier", 1 },
@@ -427,6 +429,7 @@ ipv6cp_init(unit)
memset(ao, 0, sizeof(*ao));
wo->accept_local = 1;
+ wo->accept_remote = 1;
wo->neg_ifaceid = 1;
ao->neg_ifaceid = 1;
@@ -952,7 +955,7 @@ ipv6cp_reqci(f, inp, len, reject_if_disa
orc = CONFREJ; /* Reject CI */
break;
}
- if (!eui64_iszero(wo->hisid) &&
+ if (!eui64_iszero(wo->hisid) && !wo->accept_remote &&
!eui64_equals(ifaceid, wo->hisid) &&
eui64_iszero(go->hisid)) {
--- ppp-2.4.3/pppd/ipv6cp.h~ 2002-12-04 23:03:32.000000000 +0000
+++ ppp-2.4.3/pppd/ipv6cp.h 2005-11-04 10:20:55.000000000 +0000
@@ -150,7 +150,8 @@
typedef struct ipv6cp_options {
int neg_ifaceid; /* Negotiate interface identifier? */
int req_ifaceid; /* Ask peer to send interface identifier? */
- int accept_local; /* accept peer's value for iface id? */
+ int accept_local; /* accept peer's value for our iface id? */
+ int accept_remote; /* accept peer's value for his iface id? */
int opt_local; /* ourtoken set by option */
int opt_remote; /* histoken set by option */
int use_ip; /* use IP as interface identifier */
@@ -0,0 +1,68 @@
diff -up ppp-2.4.4/configure.local ppp-2.4.4/configure
--- ppp-2.4.4/configure.local 2005-07-08 20:23:05.000000000 -0400
+++ ppp-2.4.4/configure 2008-08-28 17:38:04.000000000 -0400
@@ -2,7 +2,7 @@
# $Id: configure,v 1.38 2008/06/15 07:08:49 paulus Exp $
# Where to install stuff by default
-DESTDIR=/usr/local
+DESTDIR=/usr
SYSCONF=/etc
# if [ -d /NextApps ]; then
diff -up ppp-2.4.4/pppd/Makefile.linux.local ppp-2.4.4/pppd/Makefile.linux
--- ppp-2.4.4/pppd/Makefile.linux.local 2008-08-28 17:37:33.000000000 -0400
+++ ppp-2.4.4/pppd/Makefile.linux 2008-08-28 17:37:33.000000000 -0400
@@ -97,8 +97,8 @@ endif
# EAP SRP-SHA1
ifdef USE_SRP
-CFLAGS += -DUSE_SRP -DOPENSSL -I/usr/local/ssl/include
-LIBS += -lsrp -L/usr/local/ssl/lib -lcrypto
+CFLAGS += -DUSE_SRP -DOPENSSL -I/usr/include/openssl
+LIBS += -lsrp -L/usr/lib -lcrypto
TARGETS += srp-entry
EXTRAINSTALL = $(INSTALL) -c -m 555 srp-entry $(BINDIR)/srp-entry
MANPAGES += srp-entry.8
diff -up ppp-2.4.4/scripts/ppp-on-rsh.local ppp-2.4.4/scripts/ppp-on-rsh
--- ppp-2.4.4/scripts/ppp-on-rsh.local 2000-04-15 05:49:28.000000000 -0400
+++ ppp-2.4.4/scripts/ppp-on-rsh 2008-08-28 17:37:33.000000000 -0400
@@ -26,7 +26,7 @@ PPPD_RHOST=myremotehost
# For this example, we assume that pppd on both local and remote
# machines reside in the same place, /usr/local/bin/pppd
#
-PPPD_LOC=/usr/local/bin/pppd
+PPPD_LOC=/usr/sbin/pppd
#
# The location of local options file (where rsh client is running).
diff -up ppp-2.4.4/scripts/ppp-on-ssh.local ppp-2.4.4/scripts/ppp-on-ssh
--- ppp-2.4.4/scripts/ppp-on-ssh.local 2000-04-15 05:49:42.000000000 -0400
+++ ppp-2.4.4/scripts/ppp-on-ssh 2008-08-28 17:37:33.000000000 -0400
@@ -26,7 +26,7 @@ PPPD_RHOST=myremotehost
# For this example, we assume that pppd on both local and remote
# machines reside in the same place, /usr/local/bin/pppd
#
-PPPD_LOC=/usr/local/bin/pppd
+PPPD_LOC=/usr/sbin/pppd
#
# The location of local options file (where ssh client is running).
@@ -52,7 +52,7 @@ PPPD_REM_OPT=/etc/ppp/options-ssh-rem
#
# The location of ssh client on the local machine
#
-SSH_LOC=/usr/local/bin/ssh
+SSH_LOC=/usr/bin/ssh
export PPPD_LOC PPPD_LOC_OPT PPPD_REM_OPT PPPD_RHOST SSH_LOC
diff -up ppp-2.4.4/scripts/secure-card.local ppp-2.4.4/scripts/secure-card
--- ppp-2.4.4/scripts/secure-card.local 2004-02-01 22:36:46.000000000 -0500
+++ ppp-2.4.4/scripts/secure-card 2008-08-28 17:37:33.000000000 -0400
@@ -1,4 +1,4 @@
-#!/usr/local/bin/expect -f
+#!/usr/bin/expect -f
#
# This script was written by Jim Isaacson <jcisaac@crl.com>. It is
# designed to work as a script to use the SecureCARD(tm) device. This
@@ -0,0 +1,13 @@
diff -up ppp-2.4.5/scripts/ip-up.local.add.ppp_resolv ppp-2.4.5/scripts/ip-up.local.add
--- ppp-2.4.5/scripts/ip-up.local.add.ppp_resolv 2010-07-13 10:29:23.227943994 +0200
+++ ppp-2.4.5/scripts/ip-up.local.add 2010-07-13 10:32:27.729695487 +0200
@@ -18,6 +18,9 @@ if [ -n "$USEPEERDNS" -a -f /run/ppp
rscf=/run/ppp/resolv.new
grep domain /run/ppp/resolv.prev > $rscf
grep search /run/ppp/resolv.prev >> $rscf
+ if [ -f /run/ppp/resolv.conf ]; then
+ cat /run/ppp/resolv.conf >> $rscf
+ fi
change_resolv_conf $rscf
rm -f $rscf
else
@@ -0,0 +1,30 @@
diff -up ppp-2.4.5/pppd/pathnames.h.var_run_ppp ppp-2.4.5/pppd/pathnames.h
--- ppp-2.4.5/pppd/pathnames.h.var_run_ppp 2010-02-12 16:36:14.479362718 +0100
+++ ppp-2.4.5/pppd/pathnames.h 2010-02-12 16:38:24.995330994 +0100
@@ -7,9 +7,13 @@
#ifdef HAVE_PATHS_H
#include <paths.h>
+#define _SUBPATH_PPP "ppp/"
#else /* HAVE_PATHS_H */
#ifndef _PATH_VARRUN
#define _PATH_VARRUN "/etc/ppp/"
+#define _SUBPATH_PPP
+#else
+#define _SUBPATH_PPP "ppp/"
#endif
#define _PATH_DEVNULL "/dev/null"
#endif /* HAVE_PATHS_H */
@@ -46,10 +50,10 @@
#endif /* IPX_CHANGE */
#ifdef __STDC__
-#define _PATH_PPPDB _ROOT_PATH _PATH_VARRUN "pppd2.tdb"
+#define _PATH_PPPDB _ROOT_PATH _PATH_VARRUN _SUBPATH_PPP "pppd2.tdb"
#else /* __STDC__ */
#ifdef HAVE_PATHS_H
-#define _PATH_PPPDB "/var/run/pppd2.tdb"
+#define _PATH_PPPDB "/run/ppp/pppd2.tdb"
#else
#define _PATH_PPPDB "/etc/ppp/pppd2.tdb"
#endif
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,10 @@
# Logrotate file for ppp RPM
/var/log/ppp/connect-errors {
missingok
compress
notifempty
daily
rotate 5
create 0600 root root
}
+5
View File
@@ -0,0 +1,5 @@
#%PAM-1.0
auth include system-auth
account required pam_nologin.so
account include system-auth
session include system-auth
@@ -0,0 +1 @@
d /run/ppp 0755 root root
+124
View File
@@ -0,0 +1,124 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>ppp</Name>
<Homepage>http://samba.org/ppp</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>BSD</License>
<License>GPLv2</License>
<IsA>service</IsA>
<Summary>Point-to-point protocol - patched for PPPOE</Summary>
<Description>The Point-to-Point Protocol (PPP) provides a standard way to transmit datagrams over a serial link.</Description>
<Archive sha1sum="0fd188b28cb8fdc81d2eaa15b78d3ad9c93344f4" type="targz">http://samba.org/ftp/ppp/ppp-2.4.6.tar.gz</Archive>
<Archive sha1sum="1a0b02788d522f2137d0b66c749ffe6c96cceb94" type="targz">http://www.netservers.net.uk/gpl/ppp-dhcpc.tgz</Archive>
<BuildDependencies>
<Dependency>libpcap-devel</Dependency>
</BuildDependencies>
<Patches>
<Patch level="1">gentoo/02_all_make-vars.patch</Patch>
<Patch level="1">gentoo/04_all_mpls.patch</Patch>
<Patch level="1">gentoo/06_all_killaddr-smarter.patch</Patch>
<Patch level="1">gentoo/08_all_wait-children.patch</Patch>
<Patch level="1">gentoo/10_all_defaultgateway.patch</Patch>
<Patch level="1">gentoo/12_all_linkpidfile.patch</Patch>
<Patch level="1">gentoo/16_all_auth-fail.patch</Patch>
<Patch level="1">gentoo/18_all_defaultmetric.patch</Patch>
<Patch level="1">gentoo/20_all_dev-ppp.patch</Patch>
<Patch level="1">gentoo/24_all_passwordfd-read-early.patch</Patch>
<Patch level="1">gentoo/26_all_pppd-usepeerwins.patch</Patch>
<Patch level="1">gentoo/28_all_connect-errors.patch</Patch>
<Patch level="1">gentoo/30_all_Makefile.patch</Patch>
<Patch level="1">gentoo/32_all_pado-timeout.patch</Patch>
<Patch level="1">gentoo/34_all_lcp-echo-adaptive.patch</Patch>
<Patch level="1">ppp-2.3.6-sample.patch</Patch>
<Patch level="1">ppp-2.4.3-fix64.patch</Patch>
<Patch level="1">ppp-2.4.2-change_resolv_conf.patch</Patch>
<Patch level="1">nostrip.patch</Patch>
<Patch level="1">ppp-2.4.3-local.patch</Patch>
<Patch level="1">ppp-2.4.3-ipv6-accept-remote.patch</Patch>
<Patch level="1">ppp-2.4.5-ppp_resolv.patch</Patch>
<Patch level="1">ppp-2.4.5-var_run_ppp.patch</Patch>
<Patch level="1">ppp-2.4.6-eaptls-mppe-0.99.patch</Patch>
</Patches>
</Source>
<Package>
<Name>ppp</Name>
<RuntimeDependencies>
<Dependency>libpcap</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="config">/etc</Path>
<Path fileType="config">/usr/lib/tmpfiles.d/ppp.conf</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="doc">/usr/share/doc</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="data">/run/ppp</Path>
</Files>
<AdditionalFiles>
<AdditionalFile owner="root" permission="0644" target="/usr/lib/tmpfiles.d/ppp.conf">tmpfiles.conf</AdditionalFile>
<AdditionalFile target="/etc/ppp/options-pptp" permission="0644" owner="root">options-pptp</AdditionalFile>
<AdditionalFile target="/etc/ppp/options-pppoe" permission="0644" owner="root">options-pppoe</AdditionalFile>
<AdditionalFile target="/etc/ppp/chat-default" permission="0644" owner="root">chat-default</AdditionalFile>
<AdditionalFile target="/etc/ppp/ip-up" permission="0755" owner="root">ip-up</AdditionalFile>
<AdditionalFile target="/etc/ppp/ip-down" permission="0755" owner="root">ip-down</AdditionalFile>
<AdditionalFile target="/etc/conf.d/net.ppp0" permission="0600" owner="root">confd.ppp0</AdditionalFile>
<AdditionalFile target="/etc/pam.d/ppp" permission="0644" owner="root">ppp.pamd</AdditionalFile>
<AdditionalFile target="/etc/logrotate.d/ppp" permission="0644" owner="root">ppp.logrotate</AdditionalFile>
</AdditionalFiles>
</Package>
<Package>
<Name>ppp-devel</Name>
<Summary>Development files for ppp</Summary>
<RuntimeDependencies>
<Dependency release="current">ppp</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include</Path>
</Files>
</Package>
<History>
<Update release="5">
<Date>2014-04-03</Date>
<Version>2.4.6</Version>
<Comment>Version bump.</Comment>
<Name>Marcin Bojara</Name>
<Email>marcin@pisilinux.org</Email>
</Update>
<Update release="4">
<Date>2014-01-10</Date>
<Version>2.4.5</Version>
<Comment>Add tmpfiles.conf</Comment>
<Name>Marcin Bojara</Name>
<Email>marcin@pisilinux.org</Email>
</Update>
<Update release="3">
<Date>2013-09-12</Date>
<Version>2.4.5</Version>
<Comment>service.py no longer needed.</Comment>
<Name>Marcin Bojara</Name>
<Email>marcin@pisilinux.org</Email>
</Update>
<Update release="2">
<Date>2013-05-23</Date>
<Version>2.4.5</Version>
<Comment>Add service.py</Comment>
<Name>Marcin Bojara</Name>
<Email>marcin@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2010-10-13</Date>
<Version>2.4.5</Version>
<Comment>First release</Comment>
<Name>Gökcen Eraslan</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
+13
View File
@@ -0,0 +1,13 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>ppp</Name>
<Summary xml:lang="tr">Modem ile internet erişimi için PPP (point to point protocol) noktadan noktaya erişim protokolü</Summary>
<Description xml:lang="tr">PPP protokolü veriyi seri bir bağlantı üzerinden transfer etmek için standart bir yol sağlar.</Description>
</Source>
<Package>
<Name>ppp-devel</Name>
<Summary xml:lang="tr">ppp için geliştirme dosyaları</Summary>
</Package>
</PISI>
@@ -0,0 +1,36 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import shelltools
from pisi.actionsapi import get
def build():
shelltools.cd("wpa_supplicant")
#Enable syslog output
cflags = get.CFLAGS() + " -DCONFIG_DEBUG_SYSLOG"
shelltools.export("CFLAGS", cflags)
autotools.make("V=1")
autotools.make("eapol_test")
def install():
shelltools.cd("wpa_supplicant")
for bin in ["wpa_supplicant", "wpa_cli", "wpa_passphrase", "eapol_test"]:
pisitools.dosbin(bin)
# Install dbus files
pisitools.insinto("/usr/share/dbus-1/system-services", "dbus/*.service")
pisitools.insinto("/etc/dbus-1/system.d", "dbus/dbus-wpa_supplicant.conf", "wpa_supplicant.conf")
pisitools.doman("doc/docbook/*.5")
pisitools.doman("doc/docbook/*.8")
pisitools.newdoc("wpa_supplicant.conf", "wpa_supplicant.conf.example")
pisitools.dodoc("ChangeLog", "../COPYING", "eap_testing.txt", "../README", "todo.txt")
@@ -0,0 +1,24 @@
# -*- coding: utf-8 -*-
from comar.service import *
serviceType = "local"
serviceDefault = "off" #NM starts wpa_supp automatically. Use at your own risk if you start manually
serviceDesc = _({"en": "WPA Daemon",
"tr": "WPA Hizmeti"})
PIDFILE = "/run/wpa_supplicant.pid"
@synchronized
def start():
startService(command="/usr/sbin/wpa_supplicant",
args="-WuB -P%s %s" % (PIDFILE, config.get("OPTS", "")),
pidfile=PIDFILE,
donotify=True)
@synchronized
def stop():
stopService(pidfile=PIDFILE,
donotify=True)
def status():
return isServiceRunning(PIDFILE)
@@ -0,0 +1,52 @@
From dea50507861b79f522c70500fe978072f143af8f Mon Sep 17 00:00:00 2001
From: Jouni Malinen <jouni.malinen@atheros.com>
Date: Fri, 12 Nov 2010 18:31:56 +0200
Subject: [PATCH 1/3] AP: Verify that HT40 secondary channel is supported
Refuse to enable HT40 mode AP unless both the primary and secondary
channels are enabled for AP use.
(cherry picked from commit 8ea3dd21d2e8b760612af0c7b6a3bb5b89ba7304)
---
src/ap/hw_features.c | 26 ++++++++++++++++++++++++++
1 files changed, 26 insertions(+), 0 deletions(-)
diff --git a/src/ap/hw_features.c b/src/ap/hw_features.c
index 0159c72..7fc5b83 100644
--- a/src/ap/hw_features.c
+++ b/src/ap/hw_features.c
@@ -642,6 +642,32 @@ int hostapd_select_hw_mode(struct hostapd_iface *iface)
break;
}
}
+ if (ok && iface->conf->secondary_channel) {
+ int sec_ok = 0;
+ int sec_chan = iface->conf->channel +
+ iface->conf->secondary_channel * 4;
+ for (j = 0; j < iface->current_mode->num_channels; j++) {
+ struct hostapd_channel_data *chan =
+ &iface->current_mode->channels[j];
+ if (!(chan->flag & HOSTAPD_CHAN_DISABLED) &&
+ (chan->chan == sec_chan)) {
+ sec_ok = 1;
+ break;
+ }
+ }
+ if (!sec_ok) {
+ hostapd_logger(iface->bss[0], NULL,
+ HOSTAPD_MODULE_IEEE80211,
+ HOSTAPD_LEVEL_WARNING,
+ "Configured HT40 secondary channel "
+ "(%d) not found from the channel list "
+ "of current mode (%d) %s",
+ sec_chan, iface->current_mode->mode,
+ hostapd_hw_mode_txt(
+ iface->current_mode->mode));
+ ok = 0;
+ }
+ }
if (iface->conf->channel == 0) {
/* TODO: could request a scan of neighboring BSSes and select
* the channel automatically */
--
1.7.3.4
@@ -0,0 +1,16 @@
diff -up wpa_supplicant-0.7.3/wpa_supplicant/wpa_supplicant.c.assoc-timeout wpa_supplicant-0.7.3/wpa_supplicant/wpa_supplicant.c
--- wpa_supplicant-0.7.3/wpa_supplicant/wpa_supplicant.c.assoc-timeout 2010-09-07 10:43:39.000000000 -0500
+++ wpa_supplicant-0.7.3/wpa_supplicant/wpa_supplicant.c 2010-12-07 18:57:45.163457000 -0600
@@ -1262,10 +1262,10 @@ void wpa_supplicant_associate(struct wpa
if (assoc_failed) {
/* give IBSS a bit more time */
- timeout = ssid->mode == WPAS_MODE_IBSS ? 10 : 5;
+ timeout = ssid->mode == WPAS_MODE_IBSS ? 20 : 10;
} else if (wpa_s->conf->ap_scan == 1) {
/* give IBSS a bit more time */
- timeout = ssid->mode == WPAS_MODE_IBSS ? 20 : 10;
+ timeout = ssid->mode == WPAS_MODE_IBSS ? 20 : 20;
}
wpa_supplicant_req_auth_timeout(wpa_s, timeout, 0);
}
@@ -0,0 +1,49 @@
--- wpa_supplicant-0.6.3/src/utils/wpa_debug.c.flush-debug 2007-07-30 23:15:34.000000000 -0400
+++ wpa_supplicant-0.6.3/src/utils/wpa_debug.c 2007-07-30 23:17:06.000000000 -0400
@@ -157,6 +157,7 @@ void wpa_debug_print_timestamp(void)
if (out_file) {
fprintf(out_file, "%ld.%06u: ", (long) tv.sec,
(unsigned int) tv.usec);
+ fflush(out_file);
} else
#endif /* CONFIG_DEBUG_FILE */
printf("%ld.%06u: ", (long) tv.sec, (unsigned int) tv.usec);
@@ -185,6 +186,7 @@ void wpa_printf(int level, char *fmt, ..
if (out_file) {
vfprintf(out_file, fmt, ap);
fprintf(out_file, "\n");
+ fflush(out_file);
} else {
#endif /* CONFIG_DEBUG_FILE */
vprintf(fmt, ap);
@@ -217,6 +219,7 @@ static void _wpa_hexdump(int level, cons
fprintf(out_file, " [REMOVED]");
}
fprintf(out_file, "\n");
+ fflush(out_file);
} else {
#endif /* CONFIG_DEBUG_FILE */
printf("%s - hexdump(len=%lu):", title, (unsigned long) len);
@@ -262,12 +265,14 @@ static void _wpa_hexdump_ascii(int level
fprintf(out_file,
"%s - hexdump_ascii(len=%lu): [REMOVED]\n",
title, (unsigned long) len);
+ fflush(out_file);
return;
}
if (buf == NULL) {
fprintf(out_file,
"%s - hexdump_ascii(len=%lu): [NULL]\n",
title, (unsigned long) len);
+ fflush(out_file);
return;
}
fprintf(out_file, "%s - hexdump_ascii(len=%lu):\n",
@@ -292,6 +297,7 @@ static void _wpa_hexdump_ascii(int level
pos += llen;
len -= llen;
}
+ fflush(out_file);
} else {
#endif /* CONFIG_DEBUG_FILE */
if (!show) {
@@ -0,0 +1,15 @@
diff -up wpa_supplicant-0.7.3/src/crypto/tls_openssl.c.more-openssl-algs wpa_supplicant-0.7.3/src/crypto/tls_openssl.c
--- wpa_supplicant-0.7.3/src/crypto/tls_openssl.c.more-openssl-algs 2010-09-07 10:43:39.000000000 -0500
+++ wpa_supplicant-0.7.3/src/crypto/tls_openssl.c 2010-12-08 10:01:02.967664004 -0600
@@ -710,6 +710,11 @@ void * tls_init(const struct tls_config
#endif /* OPENSSL_FIPS */
#endif /* CONFIG_FIPS */
SSL_load_error_strings();
+ /* Only add potentially weak hashes and encryption algorithms
+ * when FIPS mode is not enabled.
+ */
+ if (!conf || !conf->fips_mode)
+ OpenSSL_add_all_algorithms();
SSL_library_init();
#ifndef OPENSSL_NO_SHA256
EVP_add_digest(EVP_sha256());
@@ -0,0 +1,12 @@
diff -up wpa_supplicant-0.6.7/wpa_supplicant/events.c.scan-results-msg wpa_supplicant-0.6.7/wpa_supplicant/events.c
--- wpa_supplicant-0.6.7/wpa_supplicant/events.c.scan-results-msg 2009-01-30 12:08:34.000000000 -0500
+++ wpa_supplicant-0.6.7/wpa_supplicant/events.c 2009-01-30 12:08:37.000000000 -0500
@@ -911,7 +911,7 @@ static void wpa_supplicant_event_scan_re
}
wpa_dbg(wpa_s, MSG_DEBUG, "New scan results available");
- wpa_msg_ctrl(wpa_s, MSG_INFO, WPA_EVENT_SCAN_RESULTS);
+ wpa_msg_ctrl(wpa_s, MSG_DEBUG, WPA_EVENT_SCAN_RESULTS);
wpas_notify_scan_results(wpa_s);
wpas_notify_scan_done(wpa_s, 1);
@@ -0,0 +1,12 @@
diff -p -up wpa_supplicant-0.6.3/wpa_supplicant/config_ssid.h.WEP232 wpa_supplicant-0.6.3/wpa_supplicant/config_ssid.h
--- wpa_supplicant-0.6.3/wpa_supplicant/config_ssid.h.WEP232 2008-02-23 03:45:24.000000000 +0100
+++ wpa_supplicant-0.6.3/wpa_supplicant/config_ssid.h 2008-03-31 22:28:29.000000000 +0200
@@ -189,7 +189,7 @@ struct wpa_ssid {
#endif /* IEEE8021X_EAPOL */
#define NUM_WEP_KEYS 4
-#define MAX_WEP_KEY_LEN 16
+#define MAX_WEP_KEY_LEN 32
/**
* wep_key - WEP keys
*/
@@ -0,0 +1,143 @@
Index: src/drivers/driver_wext.c
===================================================================
--- src/drivers/driver_wext.c.orig
+++ src/drivers/driver_wext.c
@@ -1901,19 +1901,26 @@ int wpa_driver_wext_associate(void *priv
* SIOCSIWENCODE here.
*/
if (drv->auth_alg_fallback &&
- wpa_driver_wext_auth_alg_fallback(drv, params) < 0)
+ wpa_driver_wext_auth_alg_fallback(drv, params) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because auth_alg_fallback failed", __FUNCTION__);
ret = -1;
+ }
if (!params->bssid &&
- wpa_driver_wext_set_bssid(drv, NULL) < 0)
+ wpa_driver_wext_set_bssid(drv, NULL) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_bssid failed", __FUNCTION__);
ret = -1;
+ }
/* TODO: should consider getting wpa version and cipher/key_mgmt suites
* from configuration, not from here, where only the selected suite is
* available */
if (wpa_driver_wext_set_gen_ie(drv, params->wpa_ie, params->wpa_ie_len)
- < 0)
+ < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_gen_ie failed", __FUNCTION__);
ret = -1;
+ }
+
if (params->wpa_ie == NULL || params->wpa_ie_len == 0)
value = IW_AUTH_WPA_VERSION_DISABLED;
else if (params->wpa_ie[0] == WLAN_EID_RSN)
@@ -1921,27 +1928,41 @@ int wpa_driver_wext_associate(void *priv
else
value = IW_AUTH_WPA_VERSION_WPA;
if (wpa_driver_wext_set_auth_param(drv,
- IW_AUTH_WPA_VERSION, value) < 0)
+ IW_AUTH_WPA_VERSION, value) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_auth_param(WPA_VERSION) failed", __FUNCTION__);
ret = -1;
+ }
+
value = wpa_driver_wext_cipher2wext(params->pairwise_suite);
if (wpa_driver_wext_set_auth_param(drv,
- IW_AUTH_CIPHER_PAIRWISE, value) < 0)
+ IW_AUTH_CIPHER_PAIRWISE, value) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_auth_param(CIPHER_PAIRWISE) failed", __FUNCTION__);
ret = -1;
+ }
+
value = wpa_driver_wext_cipher2wext(params->group_suite);
if (wpa_driver_wext_set_auth_param(drv,
- IW_AUTH_CIPHER_GROUP, value) < 0)
+ IW_AUTH_CIPHER_GROUP, value) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_auth_param(CIPHER_GROUP) failed", __FUNCTION__);
ret = -1;
+ }
+
value = wpa_driver_wext_keymgmt2wext(params->key_mgmt_suite);
if (wpa_driver_wext_set_auth_param(drv,
- IW_AUTH_KEY_MGMT, value) < 0)
+ IW_AUTH_KEY_MGMT, value) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_auth_param(KEY_MGMT) failed", __FUNCTION__);
ret = -1;
+ }
+
value = params->key_mgmt_suite != KEY_MGMT_NONE ||
params->pairwise_suite != CIPHER_NONE ||
params->group_suite != CIPHER_NONE ||
params->wpa_ie_len;
if (wpa_driver_wext_set_auth_param(drv,
- IW_AUTH_PRIVACY_INVOKED, value) < 0)
+ IW_AUTH_PRIVACY_INVOKED, value) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_auth_param(PRIVACY_INVOKED) failed", __FUNCTION__);
ret = -1;
+ }
/* Allow unencrypted EAPOL messages even if pairwise keys are set when
* not using WPA. IEEE 802.1X specifies that these frames are not
@@ -1952,12 +1973,18 @@ int wpa_driver_wext_associate(void *priv
else
allow_unencrypted_eapol = 1;
- if (wpa_driver_wext_set_psk(drv, params->psk) < 0)
+ if (wpa_driver_wext_set_psk(drv, params->psk) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_psk failed", __FUNCTION__);
ret = -1;
+ }
+
if (wpa_driver_wext_set_auth_param(drv,
IW_AUTH_RX_UNENCRYPTED_EAPOL,
- allow_unencrypted_eapol) < 0)
+ allow_unencrypted_eapol) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_auth_param(RX_UNENCRYPTED_EAPOL) failed", __FUNCTION__);
ret = -1;
+ }
+
#ifdef CONFIG_IEEE80211W
switch (params->mgmt_frame_protection) {
case NO_MGMT_FRAME_PROTECTION:
@@ -1970,17 +1997,25 @@ int wpa_driver_wext_associate(void *priv
value = IW_AUTH_MFP_REQUIRED;
break;
};
- if (wpa_driver_wext_set_auth_param(drv, IW_AUTH_MFP, value) < 0)
+ if (wpa_driver_wext_set_auth_param(drv, IW_AUTH_MFP, value) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_auth_param(IW_AUTH_MFP) failed", __FUNCTION__);
ret = -1;
+ }
#endif /* CONFIG_IEEE80211W */
- if (params->freq && wpa_driver_wext_set_freq(drv, params->freq) < 0)
+ if (params->freq && wpa_driver_wext_set_freq(drv, params->freq) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_freq failed", __FUNCTION__);
ret = -1;
+ }
if (!drv->cfg80211 &&
- wpa_driver_wext_set_ssid(drv, params->ssid, params->ssid_len) < 0)
+ wpa_driver_wext_set_ssid(drv, params->ssid, params->ssid_len) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_ssid failed", __FUNCTION__);
ret = -1;
+ }
if (params->bssid &&
- wpa_driver_wext_set_bssid(drv, params->bssid) < 0)
+ wpa_driver_wext_set_bssid(drv, params->bssid) < 0) {
+ wpa_printf(MSG_DEBUG, "%s: assoc failed because set_bssid failed", __FUNCTION__);
ret = -1;
+ }
if (drv->cfg80211 &&
wpa_driver_wext_set_ssid(drv, params->ssid, params->ssid_len) < 0)
ret = -1;
@@ -2008,6 +2043,10 @@ static int wpa_driver_wext_set_auth_alg(
res = wpa_driver_wext_set_auth_param(drv, IW_AUTH_80211_AUTH_ALG,
algs);
drv->auth_alg_fallback = res == -2;
+
+ if (res == -2)
+ wpa_printf(MSG_DEBUG, "%s: falling back to ENCODE for AUTH", __FUNCTION__);
+
return res;
}
@@ -0,0 +1,19 @@
Index: src/drivers/driver_wext.c
===================================================================
--- src/drivers/driver_wext.c.orig
+++ src/drivers/driver_wext.c
@@ -54,12 +54,13 @@ int wpa_driver_wext_set_auth_param(struc
iwr.u.param.value = value;
if (ioctl(drv->ioctl_sock, SIOCSIWAUTH, &iwr) < 0) {
+ int saved_errno = errno;
if (errno != EOPNOTSUPP) {
wpa_printf(MSG_DEBUG, "WEXT: SIOCSIWAUTH(param %d "
"value 0x%x) failed: %s)",
idx, value, strerror(errno));
}
- ret = errno == EOPNOTSUPP ? -2 : -1;
+ ret = saved_errno == EOPNOTSUPP ? -2 : -1;
}
return ret;
@@ -0,0 +1,17 @@
From: Reinhard Tartler <siretart@tauware.de>
References: none
Description: Use pkg-config for libpcsclite linkage flags
At least in debian, we can rely on pkg-config being available and
returning more accurate ldflags.
--- a/wpa_supplicant/Makefile
+++ b/wpa_supplicant/Makefile
@@ -691,7 +691,7 @@ ifdef CONFIG_NATIVE_WINDOWS
#dynamic symbol loading that is now used in pcsc_funcs.c
#LIBS += -lwinscard
else
-LIBS += -lpcsclite -lpthread
+LIBS += $(shell pkg-config --libs libpcsclite)
endif
endif
@@ -0,0 +1,20 @@
diff -aurp a/wpa_supplicant/dbus/fi.epitest.hostap.WPASupplicant.service.in b/wpa_supplicant/dbus/fi.epitest.hostap.WPASupplicant.service.in
--- a/wpa_supplicant/dbus/fi.epitest.hostap.WPASupplicant.service.in 2012-05-15 09:00:03.048545044 +0000
+++ b/wpa_supplicant/dbus/fi.epitest.hostap.WPASupplicant.service.in 2012-05-15 09:01:19.759550509 +0000
@@ -1,5 +1,5 @@
[D-BUS Service]
Name=fi.epitest.hostap.WPASupplicant
-Exec=@BINDIR@/wpa_supplicant -u
+Exec=/usr/sbin/wpa_supplicant -u
User=root
SystemdService=wpa_supplicant.service
diff -aurp a/wpa_supplicant/dbus/fi.w1.wpa_supplicant1.service.in b/wpa_supplicant/dbus/fi.w1.wpa_supplicant1.service.in
--- a/wpa_supplicant/dbus/fi.w1.wpa_supplicant1.service.in 2012-05-15 09:00:03.048545044 +0000
+++ b/wpa_supplicant/dbus/fi.w1.wpa_supplicant1.service.in 2012-05-15 09:01:28.727551913 +0000
@@ -1,5 +1,5 @@
[D-BUS Service]
Name=fi.w1.wpa_supplicant1
-Exec=@BINDIR@/wpa_supplicant -u
+Exec=/usr/sbin/wpa_supplicant -u
User=root
SystemdService=wpa_supplicant.service
@@ -0,0 +1,60 @@
diff -aurp a/wpa_supplicant/dbus/dbus_new_helpers.c b/wpa_supplicant/dbus/dbus_new_helpers.c
--- a/wpa_supplicant/dbus/dbus_new_helpers.c 2012-05-15 07:28:37.616150164 +0000
+++ b/wpa_supplicant/dbus/dbus_new_helpers.c 2012-05-15 07:30:21.904157611 +0000
@@ -882,7 +882,7 @@ void wpa_dbus_mark_property_changed(stru
const struct wpa_dbus_property_desc *dsc;
int i = 0;
- if (iface == NULL)
+ if (iface == NULL || path == NULL)
return;
dbus_connection_get_object_path_data(iface->con, path,
diff -aurp a/wpa_supplicant/dbus/dbus_old.c b/wpa_supplicant/dbus/dbus_old.c
--- a/wpa_supplicant/dbus/dbus_old.c 2012-05-15 07:28:29.502149373 +0000
+++ b/wpa_supplicant/dbus/dbus_old.c 2012-05-15 07:30:48.859162441 +0000
@@ -379,7 +379,7 @@ void wpa_supplicant_dbus_notify_scan_res
DBusMessage *_signal;
/* Do nothing if the control interface is not turned on */
- if (iface == NULL)
+ if (iface == NULL || wpa_s->dbus_path == NULL)
return;
_signal = dbus_message_new_signal(wpa_s->dbus_path,
@@ -419,7 +419,7 @@ void wpa_supplicant_dbus_notify_state_ch
if (wpa_s->global == NULL)
return;
iface = wpa_s->global->dbus;
- if (iface == NULL)
+ if (iface == NULL || wpa_s->dbus_path == NULL)
return;
/* Only send signal if state really changed */
@@ -478,7 +478,7 @@ void wpa_supplicant_dbus_notify_scanning
dbus_bool_t scanning = wpa_s->scanning ? TRUE : FALSE;
/* Do nothing if the control interface is not turned on */
- if (iface == NULL)
+ if (iface == NULL || wpa_s->dbus_path == NULL)
return;
_signal = dbus_message_new_signal(wpa_s->dbus_path,
@@ -513,7 +513,7 @@ void wpa_supplicant_dbus_notify_wps_cred
if (wpa_s->global == NULL)
return;
iface = wpa_s->global->dbus;
- if (iface == NULL)
+ if (iface == NULL || wpa_s->dbus_path == NULL)
return;
_signal = dbus_message_new_signal(wpa_s->dbus_path,
@@ -564,7 +564,7 @@ void wpa_supplicant_dbus_notify_certific
if (wpa_s->global == NULL)
return;
iface = wpa_s->global->dbus;
- if (iface == NULL)
+ if (iface == NULL || wpa_s->dbus_path == NULL)
return;
_signal = dbus_message_new_signal(wpa_s->dbus_path,
@@ -0,0 +1,347 @@
diff -Naurp a/src/eap_peer/eap_methods.c b/src/eap_peer/eap_methods.c
--- a/src/eap_peer/eap_methods.c 2012-05-15 08:23:17.151386999 +0000
+++ b/src/eap_peer/eap_methods.c 2012-05-15 08:23:57.403389760 +0000
@@ -342,6 +342,120 @@ int eap_peer_method_register(struct eap_
/**
+ * eap_peer_register_methods - Register all known EAP peer methods
+ *
+ * This function is called at program start to register all compiled
+ * in EAP peer methods.
+ */
+int eap_peer_register_methods(void)
+{
+ int ret = 0;
+
+#ifdef EAP_MD5
+ if (ret == 0)
+ ret = eap_peer_md5_register();
+#endif /* EAP_MD5 */
+
+#ifdef EAP_TLS
+ if (ret == 0)
+ ret = eap_peer_tls_register();
+#endif /* EAP_TLS */
+
+#ifdef EAP_MSCHAPv2
+ if (ret == 0)
+ ret = eap_peer_mschapv2_register();
+#endif /* EAP_MSCHAPv2 */
+
+#ifdef EAP_PEAP
+ if (ret == 0)
+ ret = eap_peer_peap_register();
+#endif /* EAP_PEAP */
+
+#ifdef EAP_TTLS
+ if (ret == 0)
+ ret = eap_peer_ttls_register();
+#endif /* EAP_TTLS */
+
+#ifdef EAP_GTC
+ if (ret == 0)
+ ret = eap_peer_gtc_register();
+#endif /* EAP_GTC */
+
+#ifdef EAP_OTP
+ if (ret == 0)
+ ret = eap_peer_otp_register();
+#endif /* EAP_OTP */
+
+#ifdef EAP_SIM
+ if (ret == 0)
+ ret = eap_peer_sim_register();
+#endif /* EAP_SIM */
+
+#ifdef EAP_LEAP
+ if (ret == 0)
+ ret = eap_peer_leap_register();
+#endif /* EAP_LEAP */
+
+#ifdef EAP_PSK
+ if (ret == 0)
+ ret = eap_peer_psk_register();
+#endif /* EAP_PSK */
+
+#ifdef EAP_AKA
+ if (ret == 0)
+ ret = eap_peer_aka_register();
+#endif /* EAP_AKA */
+
+#ifdef EAP_AKA_PRIME
+ if (ret == 0)
+ ret = eap_peer_aka_prime_register();
+#endif /* EAP_AKA_PRIME */
+
+#ifdef EAP_FAST
+ if (ret == 0)
+ ret = eap_peer_fast_register();
+#endif /* EAP_FAST */
+
+#ifdef EAP_PAX
+ if (ret == 0)
+ ret = eap_peer_pax_register();
+#endif /* EAP_PAX */
+
+#ifdef EAP_SAKE
+ if (ret == 0)
+ ret = eap_peer_sake_register();
+#endif /* EAP_SAKE */
+
+#ifdef EAP_GPSK
+ if (ret == 0)
+ ret = eap_peer_gpsk_register();
+#endif /* EAP_GPSK */
+
+#ifdef EAP_WSC
+ if (ret == 0)
+ ret = eap_peer_wsc_register();
+#endif /* EAP_WSC */
+
+#ifdef EAP_IKEV2
+ if (ret == 0)
+ ret = eap_peer_ikev2_register();
+#endif /* EAP_IKEV2 */
+
+#ifdef EAP_VENDOR_TEST
+ if (ret == 0)
+ ret = eap_peer_vendor_test_register();
+#endif /* EAP_VENDOR_TEST */
+
+#ifdef EAP_TNC
+ if (ret == 0)
+ ret = eap_peer_tnc_register();
+#endif /* EAP_TNC */
+
+ return ret;
+}
+
+
+/**
* eap_peer_unregister_methods - Unregister EAP peer methods
*
* This function is called at program termination to unregister all EAP peer
diff -Naurp a/src/eap_peer/eap_methods.h b/src/eap_peer/eap_methods.h
--- a/src/eap_peer/eap_methods.h 2012-05-15 08:23:17.151386999 +0000
+++ b/src/eap_peer/eap_methods.h 2012-05-15 08:23:57.404389735 +0000
@@ -32,6 +32,7 @@ EapType eap_peer_get_type(const char *na
const char * eap_get_name(int vendor, EapType type);
size_t eap_get_names(char *buf, size_t buflen);
char ** eap_get_names_as_string_array(size_t *num);
+int eap_peer_register_methods(void);
void eap_peer_unregister_methods(void);
#else /* IEEE8021X_EAPOL */
diff -Naurp a/src/eap_peer/libeap0.pc b/src/eap_peer/libeap0.pc
--- a/src/eap_peer/libeap0.pc 1970-01-01 00:00:00.000000000 +0000
+++ b/src/eap_peer/libeap0.pc 2012-05-15 08:23:57.404389735 +0000
@@ -0,0 +1,10 @@
+prefix=/usr
+exec_prefix=/usr
+libdir=${exec_prefix}/lib
+includedir=${prefix}/include/eap_peer
+
+Name: libeap0
+Description: EAP Peer Library API
+Version: 0.7.2
+Libs: -L${libdir} -leap
+Cflags: -I${includedir}
diff -Naurp a/src/eap_peer/Makefile b/src/eap_peer/Makefile
--- a/src/eap_peer/Makefile 2012-05-15 08:23:17.152386964 +0000
+++ b/src/eap_peer/Makefile 2012-05-15 08:23:57.403389760 +0000
@@ -1,11 +1,186 @@
-all:
- @echo Nothing to be made.
+LIBEAP_NAME = libeap
+LIBEAP_CURRENT = 0
+LIBEAP_REVISION = 0
+LIBEAP_AGE = 0
+
+LIBEAP = $(LIBEAP_NAME).so.$(LIBEAP_CURRENT).$(LIBEAP_REVISION).$(LIBEAP_AGE)
+LIBEAP_SO = $(LIBEAP_NAME).so.$(LIBEAP_CURRENT)
+
+.PHONY: all clean install uninstall
+
+all: $(LIBEAP)
+
+ifndef CC
+CC=gcc
+endif
+
+ifndef CFLAGS
+CFLAGS = -MMD -O0 -Wall -g
+endif
+
+CONFIG_TLS=openssl
+
+INCLUDE_INSTALL_DIR=/usr/include/eap_peer
+
+# Got to use override all across the board, otherwise a 'make
+# CFLAGS=XX' will kill us because the command line's CFLAGS will
+# overwrite Make's and we'll loose all the infrastructure it sets.
+override CFLAGS += -I. -I.. -I../crypto -I../utils -I../common
+
+# at least for now, need to include config_ssid.h and config_blob.h from
+# wpa_supplicant directory
+override CFLAGS += -I ../../wpa_supplicant
+
+OBJS_both += ../utils/common.o
+OBJS_both += ../utils/os_unix.o
+OBJS_both += ../utils/wpa_debug.o
+OBJS_both += ../utils/base64.o
+OBJS_both += ../utils/wpabuf.o
+OBJS_both += ../crypto/md5.o
+OBJS_both += ../crypto/sha1.o
+OBJS_both += ../crypto/sha1-tlsprf.o
+OBJS_both += ../crypto/aes-encblock.o
+OBJS_both += ../crypto/aes-wrap.o
+OBJS_both += ../crypto/aes-ctr.o
+OBJS_both += ../crypto/aes-eax.o
+OBJS_both += ../crypto/aes-omac1.o
+OBJS_both += ../crypto/ms_funcs.o
+OBJS_both += ../crypto/sha256.o
+
+
+OBJS_both += ../eap_common/eap_peap_common.o
+OBJS_both += ../eap_common/eap_psk_common.o
+OBJS_both += ../eap_common/eap_pax_common.o
+OBJS_both += ../eap_common/eap_sake_common.o
+OBJS_both += ../eap_common/eap_gpsk_common.o
+OBJS_both += ../eap_common/chap.o
+
+OBJS_peer += ../eap_peer/eap_tls.o
+OBJS_peer += ../eap_peer/eap_peap.o
+OBJS_peer += ../eap_peer/eap_ttls.o
+OBJS_peer += ../eap_peer/eap_md5.o
+OBJS_peer += ../eap_peer/eap_mschapv2.o
+OBJS_peer += ../eap_peer/mschapv2.o
+OBJS_peer += ../eap_peer/eap_otp.o
+OBJS_peer += ../eap_peer/eap_gtc.o
+OBJS_peer += ../eap_peer/eap_leap.o
+OBJS_peer += ../eap_peer/eap_psk.o
+OBJS_peer += ../eap_peer/eap_pax.o
+OBJS_peer += ../eap_peer/eap_sake.o
+OBJS_peer += ../eap_peer/eap_gpsk.o
+OBJS_peer += ../eap_peer/eap.o
+OBJS_peer += ../eap_common/eap_common.o
+OBJS_peer += ../eap_peer/eap_methods.o
+OBJS_peer += ../eap_peer/eap_tls_common.o
+
+override CFLAGS += -DEAP_TLS
+override CFLAGS += -DEAP_PEAP
+override CFLAGS += -DEAP_TTLS
+override CFLAGS += -DEAP_MD5
+override CFLAGS += -DEAP_MSCHAPv2
+override CFLAGS += -DEAP_GTC
+override CFLAGS += -DEAP_OTP
+override CFLAGS += -DEAP_LEAP
+override CFLAGS += -DEAP_PSK
+override CFLAGS += -DEAP_PAX
+override CFLAGS += -DEAP_SAKE
+override CFLAGS += -DEAP_GPSK -DEAP_GPSK_SHA256
+override CFLAGS += -DEAP_TLS_FUNCS
+
+override CFLAGS += -DIEEE8021X_EAPOL
+
+ifeq ($(CONFIG_TLS), openssl)
+override CFLAGS += -DEAP_TLS_OPENSSL
+OBJS_both += ../crypto/tls_openssl.o
+OBJS_both += ../crypto/crypto_openssl.o
+LIBS += -lssl -lcrypto
+override CFLAGS += -DINTERNAL_SHA256
+endif
+
+ifeq ($(CONFIG_TLS), internal)
+OBJS_both += ../crypto/tls_internal.o
+OBJS_both += ../tls/tlsv1_common.o ../../tls/tlsv1_record.o
+OBJS_both += ../tls/tlsv1_cred.o
+OBJS_both += ../tls/asn1.o ../../tls/x509v3.o
+OBJS_both += ../crypto/crypto_internal.o ../../tls/rsa.o ../../tls/bignum.o
+
+OBJS_peer += ../tls/tlsv1_client.o
+OBJS_peer += ../tls/tlsv1_client_write.o ../../tls/tlsv1_client_read.o
+override CFLAGS += -DCONFIG_TLS_INTERNAL_CLIENT
+
+OBJS_server += ../tls/tlsv1_server.o
+OBJS_server += ../tls/tlsv1_server_write.o ../../tls/tlsv1_server_read.o
+override CFLAGS += -DCONFIG_TLS_INTERNAL_SERVER
+
+override CFLAGS += -DCONFIG_TLS_INTERNAL
+override CFLAGS += -DCONFIG_CRYPTO_INTERNAL
+override CFLAGS += -DCONFIG_INTERNAL_X509
+override CFLAGS += -DINTERNAL_AES
+override CFLAGS += -DINTERNAL_SHA1
+override CFLAGS += -DINTERNAL_SHA256
+override CFLAGS += -DINTERNAL_MD5
+override CFLAGS += -DINTERNAL_MD4
+override CFLAGS += -DINTERNAL_DES
+ifdef CONFIG_INTERNAL_LIBTOMMATH
+override CFLAGS += -DCONFIG_INTERNAL_LIBTOMMATH
+else
+LIBS += -ltommath
+endif
+endif
+
+ifndef LDO
+LDO=$(CC)
+endif
+
+
+OBJS_lib=$(OBJS_both) $(OBJS_peer)
+
+ #$(OBJS_server)
+
+override CFLAGS += -fPIC -DPIC
+LDFLAGS += -shared
+
+$(LIBEAP): $(OBJS_lib)
+ $(LDO) $(LDFLAGS) $(OBJS_lib) -Wl,-soname -Wl,$(LIBEAP_SO) -o $(LIBEAP) $(LIBS)
+
+
+UTIL_HEADERS = ../utils/includes.h ../utils/common.h \
+ ../utils/wpabuf.h ../utils/build_config.h \
+ ../utils/os.h ../utils/wpa_debug.h
+COMMON_HEADERS = ../common/defs.h
+EAP_COMMON_HEADERS = ../eap_common/eap_defs.h
+MAIN_HEADERS = eap.h eap_methods.h eap_config.h
+CRYPTO_HEADERS = ../crypto/tls.h
+
+install:
+
+ mkdir -p $(DESTDIR)/usr/lib
+# copy the lib file to std lib location
+ cp $(LIBEAP) $(DESTDIR)/usr/lib
+ ln -fs $(LIBEAP_SO) $(DESTDIR)/usr/lib/$(LIBEAP_NAME).so
+ ln -fs $(LIBEAP_NAME).so.0.0.0 $(DESTDIR)/usr/lib/$(LIBEAP_NAME).so.0
+
+# copy the headers reqd by apps using eap peer library in its own subfolder under /usr/include
+ mkdir -p \
+ $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/eap_common \
+ $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/common \
+ $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/util \
+ $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/crypto
+ install -m 0644 $(EAP_COMMON_HEADERS) $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/eap_common
+ install -m 0644 $(COMMON_HEADERS) $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/common
+ install -m 0644 $(CRYPTO_HEADERS) $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/crypto
+ install -m 0644 $(UTIL_HEADERS) $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/util
+ install -m 0644 $(MAIN_HEADERS) $(DESTDIR)/$(INCLUDE_INSTALL_DIR)/
+
+ mkdir -p $(DESTDIR)/usr/lib/pkgconfig
+ cp libeap0.pc $(DESTDIR)/usr/lib/pkgconfig
+
+uninstall:
+
+ rm $(DESTDIR)/usr/lib/$(LIBEAP)
+ rm -fr $(DESTDIR)/$(INCLUDE_INSTALL_DIR)
+ rm -f $(DESTDIR)/usr/lib/pkgconfig/libeap0.pc
clean:
- rm -f *~ *.o *.so *.d
+ rm -f *~ *.o *.so *.d libeap.a $(LIBEAP) $(OBJS_lib)
-install:
- if ls *.so >/dev/null 2>&1; then \
- install -d $(DESTDIR)$(LIBDIR)/wpa_supplicant && \
- cp *.so $(DESTDIR)$(LIBDIR)/wpa_supplicant \
- ; fi
@@ -0,0 +1,35 @@
# wpa_supplicant.conf
# WPA-PSK ile kimlikleme yapılmasını zorunlu kılan kablosuz erişim noktaları ile
# Microsoft IAS Radius sunucu kimliklemesinin wpa_supplicant ile nasıl yapılacağını
# örnekleyen ayar dosyası. İlgili yerleri doldurmanız gerekir.
#
# wpa_supplicant'ın desteklediği diğer ayar işlemleri için:
# /usr/share/doc/wpasupplicant/wpa_supplicant.conf.example dosyasına bakınız.
# Root'un wpa_cli ile bağlantıyı izlemesi için
ctrl_interface=/run/wpa_supplicant
eapol_version=1
ap_scan=1
fast_reauth=1
# WPA-PSK kimlikleme gerektiren kablosuz erişim noktaları için ayarlar
network={
# Erişim noktasının SSID'si
ssid="SSID"
# Erişim cihazının WPA parolası
psk="Parola1234"
# Bu bağlantının önceliğinin 1. sırada olduğu belirtiliyor
priority=1
}
# MS IAS Radius sunucusunda kimlikleme için gereken ayarlar
network={
ssid="SSID"
key_mgmt=WPA-EAP
eap=PEAP
identity="ALAN_ADI\KULLANICI"
password="Parola1234"
phase1="auth=MSCHAPV2"
priority=2
}
@@ -0,0 +1,3 @@
ctrl_interface=/run/wpa_supplicant
ctrl_interface_group=wheel
@@ -0,0 +1,16 @@
# Use the flag "-i" before each of your interfaces, like so:
# INTERFACES="-ieth1 -iwlan0"
INTERFACES=""
# Use the flag "-D" before each driver, like so:
# DRIVERS="-Dwext"
DRIVERS=""
# Other arguments
# -u Enable the D-Bus interface (required for use with NetworkManager)
# -f Log to /var/log/wpa_supplicant.log
# -P Write pid file to /run/wpa_supplicant.pid
# required to return proper codes by init scripts (e.g. double "start" action)
# -B to daemonize that has to be used together with -P is already in wpa_supplicant.init.d
OTHER_ARGS="-u -f /var/log/wpa_supplicant.log -P /run/wpa_supplicant.pid"
@@ -0,0 +1,47 @@
CONFIG_CTRL_IFACE=y
CONFIG_CTRL_IFACE_DBUS=y
CONFIG_CTRL_IFACE_DBUS_NEW=y
CONFIG_CTRL_IFACE_DBUS_INTRO=y
#CONFIG_DRIVER_HOSTAP=y
#CONFIG_DRIVER_HERMES=y
#CONFIG_DRIVER_MADWIFI=y
CONFIG_DRIVER_ATMEL=y
CONFIG_DRIVER_WEXT=y
CONFIG_DRIVER_NL80211=y
CONFIG_DRIVER_NDISWRAPPER=y
#CONFIG_DRIVER_PRISM54=y
CONFIG_DRIVER_WIRED=y
#CONFIG_DRIVER_BROADCOM=y
#CONFIG_DRIVER_IPW=y
#CONFIG_DRIVER_BSD=y
#CONFIG_DRIVER_NDIS=y
CONFIG_WIRELESS_EXTENSION=y
CONFIG_IEEE8021X_EAPOL=y
CONFIG_EAP_MD5=y
CONFIG_EAP_MSCHAPV2=y
CONFIG_EAP_TLS=y
CONFIG_EAP_PEAP=y
CONFIG_EAP_TTLS=y
CONFIG_EAP_FAST=y
CONFIG_EAP_GTC=y
CONFIG_EAP_OTP=y
CONFIG_EAP_SIM=y
CONFIG_EAP_AKA=y
CONFIG_EAP_PSK=y
CONFIG_EAP_PAX=y
CONFIG_EAP_LEAP=y
#CONFIG_PCSC=y
CONFIG_EAP_SAKE=y
CONFIG_EAP_GPSK=y
CONFIG_EAP_GPSK_SHA256=y
CONFIG_EAP_TNC=y
CONFIG_WPS=y
CONFIG_EAP_IKEV2=y
CONFIG_PKCS12=y
CONFIG_SMARTCARD=y
CONFIG_DEBUG_FILE=y
CFLAGS += -I/usr/include/libnl3
CONFIG_IPV6=y
CONFIG_LIBNL32=y
CONFIG_PEERKEY=y
CONFIG_READLINE=y
@@ -0,0 +1,6 @@
/var/log/wpa_supplicant.log {
missingok
notifempty
size 30k
create 0600 root root
}
@@ -0,0 +1,250 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
import dbus
WPAS_DBUS_OPATH = "/fi/epitest/hostap/WPASupplicant"
WPAS_DBUS_INTERFACES_OPATH = "/fi/epitest/hostap/WPASupplicant/Interfaces"
WPAS_DBUS_SERVICE = "fi.epitest.hostap.WPASupplicant"
WPAS_DBUS_INTERFACE = "fi.epitest.hostap.WPASupplicant"
WPAS_DBUS_INTERFACES_INTERFACE = "fi.epitest.hostap.WPASupplicant.Interface"
WPAS_DBUS_NETWORK_INTERFACE = "fi.epitest.hostap.WPASupplicant.Network"
WPAS_DBUS_BSSID_INTERFACE = "fi.epitest.hostap.WPASupplicant.BSSID"
TIMEOUT = 60
class PasswordLengthError(Exception):
pass
class WPA_Supplicant_Network:
def __init__(self, bus, path):
self.bus = bus
self.path = path
self.net_obj = self.bus.get_object(WPAS_DBUS_SERVICE, path)
self.net = dbus.Interface(self.net_obj, WPAS_DBUS_NETWORK_INTERFACE)
# dict keys: ssid, bssid, key_mgmt, psk, scan_ssid, pairwise, group, eap, identity,
# anonymous_identity, ca_cert, ca_cert2, client_cert, client_cert2, private_key, private_key2,
# private_key_passwd, private_key2_passwd, phase1, phase2, eapol_flags
#
# Example: setNetwork({"ssid":dbus.String("MySSID", variant_level=1)),
# "psk":dbus.String("MyPassword", variant_level=1))})
def setNetwork(self, options):
self.net.set(options)
def enableNetwork(self):
self.net.enable()
def disableNetwork(self):
self.net.disable()
class WPA_Supplicant_Interface:
def __init__(self, bus, ifname, path):
self.bus = bus
self.ifname = ifname
self.path = path
self.if_obj = self.bus.get_object(WPAS_DBUS_SERVICE, path)
self.iface = dbus.Interface(self. if_obj, WPAS_DBUS_INTERFACES_INTERFACE)
def scan(self):
self.iface.scan()
def scanResults(self):
return self.iface.scanResults()
def addNetwork(self):
path = self.iface.addNetwork()
return self.getNetwork(path)
def removeNetwork(self, network):
self.iface.removeNetwork(network)
def selectNetwork(self, network):
self.iface.selectNetwork(network)
def getNetworkPath(self, network_id):
return "%s/Networks/%d" % (self.path, network_id)
def getNetworkById(self, network_id):
return WPA_Supplicant_Network(self.bus, self.getNetworkPath(network_id))
def getNetwork(self, network):
return WPA_Supplicant_Network(self.bus, network)
# mode should be between 0 and 2
def setAPScan(self, mode):
self.iface.setAPScan(dbus.UInt32(mode))
def disconnect(self):
self.iface.disconnect()
def getState(self):
return self.iface.state()
def getCapabilities(self):
return self.iface.capabilities()
class WPA_Supplicant:
def __init__(self):
self.bus = dbus.SystemBus()
self.wpas_obj = self.bus.get_object(WPAS_DBUS_SERVICE, WPAS_DBUS_OPATH)
self.wpas = dbus.Interface(self.wpas_obj, WPAS_DBUS_INTERFACE)
def getInterface(self, ifname):
path = self.wpas.getInterface(ifname)
return WPA_Supplicant_Interface(self.bus, ifname, path)
# driver=wext, hostap, prism54, madwifi, atmel, ndiswrapper, ipw, wired
def addInterface(self, ifname, driver):
self.wpas.addInterface(ifname, {'driver': dbus.String(driver, variant_level=1)})
return self.getInterface(ifname)
def removeInterface(self, ifname):
try:
iface_path = self.wpas.getInterface(ifname)
except dbus.DBusException:
iface_path = None
if iface_path:
self.wpas.removeInterface(dbus.ObjectPath(iface_path))
def detectWpaDriver(ifname):
import os
import sys
import pardus.netutils
# if device is an ethernet device, driver is "wired"
device = pardus.netutils.IF(ifname)
if (device.isEthernet()) and (not device.isWireless()):
return "wired"
path = os.path.join("/sys/class/net/", ifname, "device/driver/module")
modname = None
if os.path.exists(path):
modname = os.readlink(path).split("/")[-1]
if "hostap" in modname:
return "hostap"
if "prism54" in modname:
return "prism54"
if "atmel" in modname:
return "atmel"
# we fallback to wext
# wext is the generic driver for ipw2100, ipw2200, ndiswrapper > 1.12, madwifi etc...
return "wext"
def getWpaInterface(ifname):
wpa = WPA_Supplicant()
try:
iface = wpa.getInterface(ifname)
except dbus.DBusException:
driver = detectWpaDriver(ifname)
iface = wpa.addInterface(ifname, driver)
return iface
def waitForAuthenticationComplete(iface, timeout, wait = 0.1):
import time
while timeout > 0:
if iface.getState() == "COMPLETED":
return True
else:
timeout -= wait
time.sleep(wait)
return False
def checkServiceState(serviceName):
bus = dbus.SystemBus()
obj = bus.get_object("tr.org.pardus.comar", "/package/%s" % serviceName)
state = obj.info(dbus_interface="tr.org.pardus.comar.System.Service")[2]
return state in ("on", "started")
def isDBusServiceActive():
return True
def isWpaServiceActive():
return checkServiceState("wpa_supplicant")
def isWpaServiceUsable():
return isDBusServiceActive() and isWpaServiceActive()
def startWpaService():
if not isWpaServiceActive():
bus = dbus.SystemBus()
obj = bus.get_object("tr.org.pardus.comar", "/package/wpa_supplicant")
obj.start(dbus_interface="tr.org.pardus.comar.System.Service")
import time
timeout = 10
while timeout > 0:
try:
bus = dbus.SystemBus()
net_obj = bus.get_object(WPAS_DBUS_SERVICE, WPAS_DBUS_OPATH)
net = dbus.Interface(net_obj, WPAS_DBUS_NETWORK_INTERFACE)
except dbus.DBusException:
time.sleep(0.1)
timeout -= 0.2
continue
return True
return False
def setWpaAuthentication(ifname, ssid, password, timeout = TIMEOUT):
password_length = len(password)
if (password_length < 8) or (password_length > 63):
raise PasswordLengthError("Password length should be between 8 and 63")
iface = getWpaInterface(ifname)
network = iface.addNetwork()
network.setNetwork({"ssid": dbus.String(ssid, variant_level=1), "psk": dbus.String(password, variant_level=1)})
iface.selectNetwork(network.path)
authentication = waitForAuthenticationComplete(iface, timeout)
if not authentication:
disableAuthentication(ifname)
return authentication
def disableAuthentication(ifname):
wpa = WPA_Supplicant()
wpa.removeInterface(ifname)
bus = dbus.SystemBus()
obj = bus.get_object("tr.org.pardus.comar", "/package/wpa_supplicant")
obj.stop(dbus_interface="tr.org.pardus.comar.System.Service")
class Wpa_EAP:
ssid = ""
phase1 = ""
phase2 = ""
key_mgmt = "IEEE8021X"
eap = "PEAP"
anonymous_identity = ""
ca_cert = ""
client_cert = ""
private_key = ""
private_key_passwd = ""
def __init__(self, ifname):
self.ifname = ifname
self.iface = getWpaInterface(ifname)
self.network = self.iface.addNetwork()
def authenticate(self, username, password, timeout = TIMEOUT):
basic = {"ssid": dbus.String(self.ssid, variant_level=1),
"key_mgmt": dbus.String(self.key_mgmt, variant_level=1),
"eap": dbus.String(self.eap, variant_level=1),
"identity": dbus.String(username, variant_level=1)}
if self.client_cert:
basic["client_cert"] = dbus.String(self.client_cert, variant_level=1)
if self.ca_cert:
basic["ca_cert"] = dbus.String(self.ca_cert, variant_level=1)
if self.private_key:
basic["private_key"] = dbus.String(self.private_key, variant_level=1)
if self.private_key_passwd:
basic["private_key_passwd"] = dbus.String(self.private_key_passwd, variant_level=1)
if self.phase2:
basic["phase2"] = dbus.String("auth=%s"%self.phase2, variant_level=1)
if password:
basic["password"] = dbus.String(password, variant_level=1)
if self.anonymous_identity:
basic["anonymous_identity"] = dbus.String(self.anonymous_identity, variant_level=1)
self.network.setNetwork(basic)
self.iface.selectNetwork(self.network.path)
authentication = waitForAuthenticationComplete(self.iface, timeout)
if not authentication:
disableAuthentication(self.ifname)
return authentication
+100
View File
@@ -0,0 +1,100 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>wpa_supplicant</Name>
<Homepage>http://hostap.epitest.fi/wpa_supplicant/</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>GPLv2</License>
<License>BSD</License>
<IsA>service</IsA>
<Summary>IEEE 802.1X/WPA supplicant for secure wireless transfers</Summary>
<Description>wpa_supplicant is a WPA supplicant with support for WPA and WPA2.</Description>
<Archive sha1sum="25b9cb997cd9d2e84cf1ab73fac71b717cbb5f65" type="targz">http://hostap.epitest.fi/releases/wpa_supplicant-2.1.tar.gz</Archive>
<AdditionalFiles>
<AdditionalFile target="wpa_supplicant/.config">wpa_supplicant.config</AdditionalFile>
</AdditionalFiles>
<BuildDependencies>
<Dependency>libnl-devel</Dependency>
</BuildDependencies>
<Patches>
<Patch level="1">ubuntu/01_use_pkg-config_for_pcsc-lite_module.patch</Patch>
<!--<Patch level="1">wpa_supplicant-1.0-generate-libeap-peer.patch</Patch>-->
<Patch level="1">wpa_supplicant-1.0-dbus-path-fix.patch</Patch>
<Patch level="1">wpa_supplicant-1.0-do-not-call-dbus-functions-with-NULL-path.patch</Patch>
<Patch level="1">mandriva/wpa_supplicant-0.6.3-WEP232.patch</Patch>
<Patch level="1">fedora/wpa_supplicant-openssl-more-algs.patch</Patch>
<Patch level="1">fedora/wpa_supplicant-flush-debug-output.patch</Patch>
<!--<Patch level="1">fedora/wpa_supplicant-squelch-driver-disconnect-spam.patch</Patch>-->
<!--<Patch level="1">fedora/wpa_supplicant-dbus-service-file-args.patch</Patch>-->
<Patch level="1">fedora/wpa_supplicant-assoc-timeout.patch</Patch>
<!--<Patch level="1">fedora/wpa_supplicant-quiet-scan-results-message.patch</Patch>-->
<!--<Patch>suse/wpa_supplicant-driver-wext-debug.patch</Patch>-->
<Patch>suse/wpa_supplicant-errormsg.patch</Patch>
<!-- Add 3 patches from git://w1.fi/srv/git/hostap-07.git -->
<!--<Patch level="1">0001-AP-Verify-that-HT40-secondary-channel-is-supported.patch</Patch>-->
<!--<Patch level="1">0002-nl80211-Set-cipher-suites-when-using-user-space-SME.patch</Patch>-->
<!--<Patch level="1">0003-dbus-Emit-property-changed-events-when-adding-removi.patch</Patch>-->
</Patches>
</Source>
<Package>
<Name>wpa_supplicant</Name>
<RuntimeDependencies>
<Dependency>libnl</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="config">/etc</Path>
<Path fileType="data">/etc/dbus-1</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="doc">/usr/share/doc</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="data">/usr/share/dbus-1/system-services</Path>
<Path fileType="data">/run</Path>
</Files>
<AdditionalFiles>
<AdditionalFile owner="root" permission="0600" target="/etc/wpa_supplicant.conf">wpa_supplicant.conf</AdditionalFile>
<!-- This is the fedora one
<AdditionalFile owner="root" permission="0600" target="/etc/wpa_supplicant.conf">wpa_supplicant.conf.fedora</AdditionalFile>
-->
<AdditionalFile owner="root" permission="0644" target="/etc/conf.d/wpa_supplicant">wpa_supplicant.confd</AdditionalFile>
<AdditionalFile owner="root" permission="0644" target="/etc/logrotate.d/wpa_supplicant">wpa_supplicant.logrotate</AdditionalFile>
<AdditionalFile owner="root" permission="0644" target="/usr/lib/python2.7/site-packages/wpa_supplicant.py">wpa_supplicant.py</AdditionalFile>
</AdditionalFiles>
<!-- This service is not started by default since NM starts it automatically. Keep service for those not using NM and start wpa-supp service manually -->
<Provides>
<COMAR script="service.py">System.Service</COMAR>
</Provides>
</Package>
<History>
<Update release="3">
<Date>2014-06-02</Date>
<Version>2.1</Version>
<Comment>Version Bump.</Comment>
<Name>Aydın Demirel</Name>
<Email>aydin.demirel@pisilinux.org</Email>
</Update>
<Update release="2">
<Date>2013-03-02</Date>
<Version>2.0</Version>
<Comment>V.Bump</Comment>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2012-10-14</Date>
<Version>1.0</Version>
<Comment>First release</Comment>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
@@ -0,0 +1,8 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>wpa_supplicant</Name>
<Summary xml:lang="tr">Güvenli kablosuz erişim için IEEE 802.1X/WPA sağlayıcı</Summary>
<Description xml:lang="tr">WPA ve WPA2 desteği olan ve Linux, BSD ve Windows ortamları için bir WPA istemcisidir.</Description>
</Source>
</PISI>
+3
View File
@@ -0,0 +1,3 @@
<PISI>
<Name>network.filter</Name>
</PISI>
+25
View File
@@ -0,0 +1,25 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import get
def setup():
autotools.configure()
def build():
autotools.make('CC="%s" RPM_OPT_FLAGS="%s"' % (get.CC(), get.CFLAGS()))
def install():
autotools.rawInstall("DESTDIR=\"%s\" \
SBINDIR=/sbin \
DOCDIR=/%s/%s \
MANDIR=/usr/share/man \
" % (get.installDIR(), get.docDIR(), get.srcNAME()))
pisitools.dodir("/usr/sbin")
pisitools.dodir("/var/lib/arpd")
@@ -0,0 +1,11 @@
diff -up iproute2-2.6.29/ip/ipxfrm.c.old iproute2-2.6.29/ip/ipxfrm.c
--- iproute2-2.6.29/ip/ipxfrm.c.old 2009-03-24 23:15:14.000000000 +0100
+++ iproute2-2.6.29/ip/ipxfrm.c 2009-04-24 09:35:58.203735119 +0200
@@ -1156,6 +1156,7 @@ static int xfrm_selector_upspec_parse(st
case IPPROTO_UDP:
case IPPROTO_SCTP:
case IPPROTO_DCCP:
+ case IPPROTO_IP: /* to allow shared SA for different protocols */
break;
default:
fprintf(stderr, "\"sport\" and \"dport\" are invalid with proto=%s\n", strxf_proto(sel->proto));
@@ -0,0 +1,11 @@
diff -up iproute2-20091009/Makefile.kernel iproute2-20091009/Makefile
--- iproute2-20091009/Makefile.kernel 2009-09-21 10:26:11.000000000 +0200
+++ iproute2-20091009/Makefile 2009-10-09 12:27:03.687382422 +0200
@@ -6,6 +6,7 @@ CONFDIR=/etc/iproute2
DOCDIR=/share/doc/iproute2
MANDIR=/share/man
ARPDDIR=/var/lib/arpd
+KERNEL_INCLUDE=/usr/include
# Path to db_185.h include
DBM_INCLUDE:=$(ROOTDIR)/usr/include
@@ -0,0 +1,12 @@
diff -up iproute2-2.6.31/Makefile.old iproute2-2.6.31/Makefile
--- iproute2-2.6.31/Makefile.old 2010-01-04 12:46:47.000000000 +0100
+++ iproute2-2.6.31/Makefile 2010-01-04 12:50:17.396384644 +0100
@@ -13,7 +13,7 @@ DBM_INCLUDE:=$(ROOTDIR)/usr/include
SHARED_LIBS = y
-DEFINES= -DRESOLVE_HOSTNAMES -DLIBDIR=\"$(LIBDIR)\"
+DEFINES= -DRESOLVE_HOSTNAMES -DLIBDIR=\"$(LIBDIR)\" -DIPT_LIB_DIR=\"$(IPT_LIB_DIR)\"
ifneq ($(SHARED_LIBS),y)
DEFINES+= -DNO_SHARED_LIBS
endif
@@ -0,0 +1,22 @@
diff -up iproute2-20091106/examples/cbq.init-v0.7.3.fix iproute2-20091106/examples/cbq.init-v0.7.3
--- iproute2-20091106/examples/cbq.init-v0.7.3.fix 2009-11-10 19:41:44.000000000 +0100
+++ iproute2-20091106/examples/cbq.init-v0.7.3 2009-11-27 13:36:07.957310549 +0100
@@ -579,14 +579,14 @@ cbq_show () {
### Check configuration and load DEVICES, DEVFIELDS and CLASSLIST from $1
cbq_init () {
### Get a list of configured classes
- CLASSLIST=`find $1 \( -type f -or -type l \) -name 'cbq-*' \
- -not -name '*~' -maxdepth 1 -printf "%f\n"| sort`
+ CLASSLIST=`find $1 -maxdepth 1 \( -type f -or -type l \) -name 'cbq-*' \
+ -not -name '*~' -printf "%f\n"| sort`
[ -z "$CLASSLIST" ] &&
cbq_failure "no configuration files found in $1!"
### Gather all DEVICE fields from $1/cbq-*
- DEVFIELDS=`find $1 \( -type f -or -type l \) -name 'cbq-*' \
- -not -name '*~' -maxdepth 1| xargs sed -n 's/#.*//; \
+ DEVFIELDS=`find $1 -maxdepth 1 \( -type f -or -type l \) -name 'cbq-*' \
+ -not -name '*~' | xargs sed -n 's/#.*//; \
s/[[:space:]]//g; /^DEVICE=[^,]*,[^,]*\(,[^,]*\)\?/ \
{ s/.*=//; p; }'| sort -u`
[ -z "$DEVFIELDS" ] &&
@@ -0,0 +1,31 @@
From: Jan Engelhardt <jengelh@medozas.de>
Date: 2011-06-01 00:52:29+0200
---
tc/m_xt.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
Index: iproute2-2.6.38/tc/m_xt.c
===================================================================
--- iproute2-2.6.38.orig/tc/m_xt.c
+++ iproute2-2.6.38/tc/m_xt.c
@@ -162,7 +162,8 @@ static int parse_ipt(struct action_util
return -1;
}
tcipt_globals.opts =
- xtables_merge_options(tcipt_globals.opts,
+ xtables_merge_options(tcipt_globals.orig_opts,
+ tcipt_globals.opts,
m->extra_opts,
&m->option_offset);
} else {
@@ -307,7 +308,8 @@ print_ipt(struct action_util *au,FILE *
}
tcipt_globals.opts =
- xtables_merge_options(tcipt_globals.opts,
+ xtables_merge_options(tcipt_globals.orig_opts,
+ tcipt_globals.opts,
m->extra_opts,
&m->option_offset);
} else {
@@ -0,0 +1,22 @@
From: Jan Engelhardt <jengelh@medozas.de>
Date: 2011-06-01 00:52:07+0200
---
tc/m_xt.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
Index: iproute2-2.6.37/tc/m_xt.c
===================================================================
--- iproute2-2.6.37.orig/tc/m_xt.c
+++ iproute2-2.6.37/tc/m_xt.c
@@ -343,8 +343,8 @@ print_ipt(struct action_util *au,FILE *
return 0;
}
-struct action_util ipt_action_util = {
- .id = "ipt",
+struct action_util xt_action_util = {
+ .id = "xt",
.parse_aopt = parse_ipt,
.print_aopt = print_ipt,
};
+65
View File
@@ -0,0 +1,65 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>iproute2</Name>
<Homepage>http://linux-net.osdl.org/index.php/Iproute2</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>GPLv2</License>
<IsA>app:console</IsA>
<Summary>Kernel routing and traffic control utilities</Summary>
<Description>Iproute2 is a collection of utilites for controlling TCP/IP networking and traffic control in Linux.</Description>
<Archive sha1sum="d24385ae619966d1bd71e146322d6035d60aaa1a" type="tarxz">https://www.kernel.org/pub/linux/utils/net/iproute2/iproute2-4.0.0.tar.xz</Archive>
<BuildDependencies>
<Dependency>iptables-devel</Dependency>
<Dependency>linux-atm-devel</Dependency>
<Dependency>db-devel</Dependency>
</BuildDependencies>
</Source>
<Package>
<Name>iproute2</Name>
<RuntimeDependencies>
<Dependency>linux-atm</Dependency>
<Dependency>iptables</Dependency>
<Dependency>db</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="config">/etc</Path>
<Path fileType="executable">/sbin</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="library">/lib</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="doc">/usr/share/doc</Path>
<Path fileType="data">/var/lib</Path>
</Files>
</Package>
<History>
<Update release="3">
<Date>2015-04-13</Date>
<Version>4.0.0</Version>
<Comment>Version bump.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="2">
<Date>2013-11-23</Date>
<Version>3.12.0</Version>
<Comment>Version bump</Comment>
<Name>Richard de Bruin</Name>
<Email>richdb@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2012-09-01</Date>
<Version>3.5.1</Version>
<Comment>First release</Comment>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
+8
View File
@@ -0,0 +1,8 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>iproute2</Name>
<Summary xml:lang="tr">Çekirdek içinde yer alan ağ trafiği yönlendirme ve trafik kontrol araçları.</Summary>
<Description xml:lang="tr">Iproute2 TCP/IP ağları ve trafik kontrolü için araçlar içeren bir koolleksiyondur.</Description>
</Source>
</PISI>
+32
View File
@@ -0,0 +1,32 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import shelltools
from pisi.actionsapi import get
def setup():
autotools.configure("--sbindir=/sbin \
--libexecdir=/usr/lib \
--without-kernel \
--enable-devel \
--enable-libipq \
--enable-shared \
--enable-static")
def build():
autotools.make("V=1")
def install():
autotools.rawInstall('DESTDIR="%s"' % get.installDIR())
pisitools.insinto("/usr/include", "include/iptables.h")
pisitools.insinto("/usr/include", "include/ip6tables.h")
pisitools.insinto("/usr/include/libiptc", "include/libiptc/*.h")
pisitools.dodir("/var/lib/iptables")
pisitools.dodir("/etc/iptables")
+528
View File
@@ -0,0 +1,528 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
# i18n
MSG_CONNECTION_NAME = {
"en": "Internet Sharing",
"tr": "Internet Paylaşımı",
"sv": "Internetdelning",
"fr": "Partage de connexion Internet",
"es": "Compartir Internet",
"de": "Internet Freigabe",
"nl": "Internetverbinding delen",
}
MSG_ALLOWED_PORTS = {
"en": "Allowed Port Numbers",
"tr": "İzin Verilen Port Numaraları",
"sv": "Tillåtna portar",
"fr": "Numéros de port autorisés",
"es": "Números de puertos permitidos",
"de": "Erlaubte Ports",
"nl": "Toegestane poortnummers",
}
MSG_FORBIDDEN_PORTS = {
"en": "Forbidden Port Numbers",
"tr": "İzin Verilmeyen Port Numaraları",
"sv": "Otillåtna portar",
"nl": "Verboden poortnummers",
}
MSG_GATEWAY_HOME = {
"en": "Gate to Home Network",
"tr": "Ev Ağına Çıkış",
"sv": "Länk till lokalt nätverk",
"fr": "Passerelle vers le réseau local",
"es": "Enlace a la red doméstica",
"de": "Gateway zum Haus-Netzwerk",
"nl": "Gateway naar thuisnetwerk",
}
MSG_GATEWAY_INTERNET = {
"en": "Gate to Internet",
"tr": "Internet'e Çıkış",
"sv": "Länk till internet",
"fr": "Passerelle vers Internet",
"es": "Enlace a Internet",
"de": "Gateway zum Internet",
"nl": "Gateway naar Internet",
}
TITLE_BLOCK_INCOMING = {
"en": "Block Incoming Connections",
"tr": "Gelen Bağlantıları Engelle",
"sv": "Blockera inkommande anslutningar",
"fr": "Bloquer les connexions entrantes",
"es": "Bloquear conexiones entrantes",
"de": "Eingehende Verbindungen blockieren",
"nl": "Inkomende verbindingen blokkeren",
}
DESCRIPTION_BLOCK_INCOMING = {
"en": "Blocks all incoming connections to the computer. Exceptions can be set from configuration dialog.",
"tr": "Bilgisayara gelen tüm bağlantıları engeller. İstisnalar ayarlar penceresinden belirlenebilir.",
"sv": "Blockerar alla inkommande anslutningar till datorn. Undantag kan läggas till under inställningar.",
"fr": "Bloque toute les connexions entrantes dans l'ordinateur. Des exceptions peuvent être définies dans la fenêtre de configuration.",
"es": "Bloquea todas las conexiones entrantes a la computadora. Se puede especificar excepciones desde el dialogo de configuración.",
"de": "Blockiert alle eingehenden Verbindungen. Im Konfigurations-Dialog können Ausnahmen angegeben werden.",
"nl": "Alle inkomende verbindingen naar deze computer blokkeren. Uitzonderingen kunnen in een configuratiedialoog ingesteld worden.",
}
TITLE_BLOCK_OUTGOING = {
"en": "Block Outgoing Connections",
"tr": "Giden Bağlantıları Engelle",
"sv": "Blockera utgående anslutningar",
"fr": "Bloquer les connexions sortantes",
"es": "Bloquear conexiones salientes",
"de": "Ausgehende Verbindungen blockieren",
"nl": "Uitgaande verbindingen blokkeren",
}
DESCRIPTION_BLOCK_OUTGOING = {
"en": "Blocks outgoing connections. Forbidden ports can be set from configuration dialog.",
"tr": "Dışarı yapılan bağlantıları engeller. Yasaklı port numaraları ayarlar penceresinden belirlenebilir.",
"sv": "Blockerar alla utgående anslutningar till datorn. Undantag kan läggas till under inställningar.",
"nl": "Uitgaande verbindingen blokkeren. Verboden poorten kunnen in een configuratiedialoog ingesteld worden.",
}
TITLE_INTERNET_SHARING = {
"en": "Internet Sharing",
"tr": "Internet Paylaşımı",
"sv": "Internetdelning",
"fr": "Partage de connexion Internet",
"es": "Compartir Internet",
"de": "Internet Freigabe",
"nl": "Internetverbinding delen",
}
DESCRIPTION_INTERNET_SHARING = {
"en": "Allows computers in your local network to connect Internet through this computer.",
"tr": "Yerel ağınızdaki bilgisayarların, bu bilgisayarı kullanarak Internet'e bağlanmalarını sağlar.",
"sv": "Låter datorer i det lokala nätverket ansluta till internet via den här datorn.",
"fr": "Permet aux ordinateurs de votre réseau domestique de se connecter à Internet via cet ordinateur.",
"es": "Permitir a otros computadoras en su red local acceder a la Internet, a través de ésta computadora",
"de": "Gibt anderen Computern aus dem lokalen Netzwer die Mäglichkeit, Internet durch diesen Computer hier zu benutzen.",
"nl": "Geeft andere computers in het lokale netwerk via deze computer toegang tot het internet.",
}
# Don't touch below, if you don't know what you're doing.
# Module configuration settings and templates
FIREWALL_CONF = "/etc/firewall.conf"
IPTABLES_RULES = {
'filter': [
'-P INPUT DROP', # Default policies
'-P FORWARD DROP',
'-P OUTPUT ACCEPT',
'-N PARDUS-IN', # Module container table for INPUT
'-N PARDUS-IN-MOD-BLOCK', # Table for BlockIncoming rules
'-N PARDUS-FW', # Module container table for FORWARD
'-N PARDUS-FW-MOD-SHARING', # Table for InternetSharingModule rules
'-N PARDUS-FW-MOD-BLOCK', # Table for BlockOutgoing rules
'-N PARDUS-OUT', # Module container table for OUTPUT
'-N PARDUS-OUT-MOD-BLOCK', # Table for BlockOutgoing rules
'-A INPUT -i lo -j ACCEPT', # Accept local
'-A FORWARD -o lo -j ACCEPT',
'-A INPUT -m state --state INVALID -j DROP',
'-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT',
'-A INPUT -j PARDUS-IN', # Jump into container tables
'-A FORWARD -j PARDUS-FW',
'-A OUTPUT -j PARDUS-OUT',
'-A PARDUS-IN -j PARDUS-IN-MOD-BLOCK' , # Jump into module tables
'-A PARDUS-FW -j PARDUS-FW-MOD-BLOCK',
'-A PARDUS-FW -j PARDUS-FW-MOD-SHARING',
'-A PARDUS-OUT -j PARDUS-OUT-MOD-BLOCK',
'-A INPUT -m state --state NEW -j ACCEPT',
],
'nat': [
'-P PREROUTING ACCEPT',
'-P POSTROUTING ACCEPT',
'-P OUTPUT ACCEPT',
'-N PARDUS-POST',
'-N PARDUS-POST-MOD-SHARING',
'-A POSTROUTING -j PARDUS-POST',
'-A PARDUS-POST -j PARDUS-POST-MOD-SHARING',
],
}
DHCPD_CONF = """
ddns-update-style interim;
ignore client-updates;
max-lease-time 500;
default-lease-time 500;
option domain-name-servers 193.140.100.220;
option routers 172.16.0.1;
option subnet-mask 255.255.255.0;
subnet 172.16.0.0 netmask 255.255.255.0 {
range 172.16.0.2 172.16.0.254;
}
"""
# Utils
import os
import subprocess
from pardus import iniutils
from pardus import netutils
from pardus import netfilterutils
INI = iniutils.iniParser(FIREWALL_CONF)
def listModuleConfigs():
"""
Returns a list of modules that are configured.
"""
try:
modules = INI.listSections()
except iniutils.iniParserError:
return
if "general" in modules:
modules.remove("general")
return modules
class ModuleConfig:
"""
Module configuration parser.
"""
def __init__(self, name):
self.name = name
try:
self.info = INI.getSection(name)
except iniutils.iniParserError:
self.info = {}
def delete(self):
INI.removeSection(self.name)
def save(self):
is_new = self.name not in listModuleConfigs()
INI.setSection(self.name, self.info)
def getServiceState(package):
"""
Returns state of a service.
"""
return call(package, "System.Service", "info")[2] in ["on", "started"]
def stopService(package, permanent=False):
"""
Stops a service.
"""
call(package, "System.Service", "stop")
if permanent:
call(package, "System.Service", "setState", ("off"))
def startService(package, restart=False, auto_start=False):
"""
Starts a service.
"""
if restart:
stopService(package)
if not getServiceState(package):
call(package, "System.Service", "start")
if auto_start:
call(package, "System.Service", "setState", ("on"))
def initializeIPTables():
"""
Initializes IPTables.
"""
# Active rules
rules_active = netfilterutils.parseConf(netfilterutils.getRules())
# Compare rules
for chain, rules in IPTABLES_RULES.iteritems():
if chain not in rules_active or len(set(rules) - set(rules_active[chain])):
# At least one different rule, need re-initialization
netfilterutils.clear()
conf = netfilterutils.makeConf(IPTABLES_RULES)
netfilterutils.restoreRules(conf)
break
def execRule(rule):
"""
Executes IPTables rule
"""
rule = rule.split()
rule.insert(0, "/sbin/iptables")
subprocess.call(rule)
def createConnection(package, device):
import comar
link = comar.Link()
connection = _(MSG_CONNECTION_NAME)
link.Network.Link[package].setDevice(connection, device)
link.Network.Link[package].setAddress(connection, "manual", "172.16.0.1", "255.255.255.0", "")
return connection
def findOrCreateConnection(link, device):
o_package, o_connecion = None, None
for package in link.Network.Link:
if device in link.Network.Link[package].deviceList():
for connection in link.Network.Link[package].connections():
info = link.Network.Link[package].connectionInfo(connection)
if info.get("net_address", "") == "172.16.0.1":
return package, connection
return package, createConnection(package, device)
def makeDHCPConf(interface):
file("/etc/dhcp/dhcpd.conf", "w").write(DHCPD_CONF)
file("/etc/conf.d/dhcpd", "w").write("DHCPD_IFACE=%s" % interface)
# Modules
class BlockIncoming:
def __init__(self):
self.parametersLast = {}
def getInfo(self):
title = _(TITLE_BLOCK_INCOMING)
description = _(DESCRIPTION_BLOCK_INCOMING)
icon = "network-server"
return (title, description, icon)
def getParameters(self):
parameters = [
("port_exceptions", _(MSG_ALLOWED_PORTS), "editlist", {"format": "[0-9\-]+"}),
]
return parameters
def checkModule(self, parameters={}, quiet=False):
pass
def loadModule(self, parameters={}):
# Initialize IPTables
initializeIPTables()
# Flush rules
self.unloadModule()
# Load rules
for port in parameters.get("port_exceptions", "").split():
if "-" in port:
port = port.replace("-", ":")
execRule("-A PARDUS-IN-MOD-BLOCK -p tcp -m multiport --dports %s -j ACCEPT" % port)
execRule("-A PARDUS-IN-MOD-BLOCK -p udp -m multiport --dports %s -j ACCEPT" % port)
# Block else...
execRule("-A PARDUS-IN-MOD-BLOCK -p tcp -m multiport --dports 0:1024 -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -j REJECT --reject-with icmp-port-unreachable")
execRule("-A PARDUS-IN-MOD-BLOCK -p udp -m multiport --dports 0:1024 -j REJECT --reject-with icmp-port-unreachable")
execRule("-A PARDUS-IN-MOD-BLOCK -j REJECT --reject-with icmp-host-prohibited")
def unloadModule(self, shutdown=False):
if not shutdown:
# Unload rules
execRule("-F PARDUS-IN-MOD-BLOCK")
class BlockOutgoing:
def __init__(self):
self.parametersLast = {}
def getInfo(self):
title = _(TITLE_BLOCK_OUTGOING)
description = _(DESCRIPTION_BLOCK_OUTGOING)
icon = "security-medium"
return (title, description, icon)
def getParameters(self):
parameters = [
("port_exceptions", _(MSG_FORBIDDEN_PORTS), "editlist", {"format": "[0-9\-]+"}),
]
return parameters
def checkModule(self, parameters={}, quiet=False):
pass
def loadModule(self, parameters={}):
# Initialize IPTables
initializeIPTables()
# Flush rules
self.unloadModule()
# Load rules
for port in parameters.get("port_exceptions", "").split():
if "-" in port:
port = port.replace("-", ":")
execRule("-A PARDUS-OUT-MOD-BLOCK -p tcp -m multiport --dports %s -j DROP" % port)
execRule("-A PARDUS-OUT-MOD-BLOCK -p udp -m multiport --dports %s -j DROP" % port)
execRule("-A PARDUS-FW-MOD-BLOCK -p tcp -m multiport --dports %s -j DROP" % port)
execRule("-A PARDUS-FW-MOD-BLOCK -p udp -m multiport --dports %s -j DROP" % port)
def unloadModule(self, shutdown=False):
if not shutdown:
# Unload rules
execRule("-F PARDUS-OUT-MOD-BLOCK")
execRule("-F PARDUS-FW-MOD-BLOCK")
class InternetSharingModule:
def __init__(self):
self.parametersLast = {}
def getInfo(self):
title = _(TITLE_INTERNET_SHARING)
description = _(DESCRIPTION_INTERNET_SHARING)
icon = "network-workgroup"
return (title, description, icon)
def getParameters(self):
def findInterfaces(wireless=True):
ifaces = []
for iface in netutils.interfaces():
if iface.name.startswith("lo") or iface.name.startswith("pan"):
continue
if not wireless and iface.isWireless():
continue
if iface.isEthernet():
dev_id = iface.deviceUID()
dev_name = netutils.deviceName(iface.deviceUID())
if " - " in dev_name:
dev_name = dev_name.split(" - ")[1]
ifaces.append("%s\t%s" % (dev_id, dev_name))
return ifaces
options_in = {
"choose": "\n".join(findInterfaces())
}
options_out = {
"choose": "\n".join(findInterfaces(wireless=False))
}
parameters = [
("device-input", _(MSG_GATEWAY_INTERNET), "combo", options_in),
("device-output", _(MSG_GATEWAY_HOME), "combo", options_out),
]
return parameters
def checkModule(self, parameters={}, quiet=False):
pass
def loadModule(self, parameters={}):
# Initialize IPTables
initializeIPTables()
# Flush rules
self.unloadModule()
# Enable forwarding
os.system("echo 1 > /proc/sys/net/ipv4/ip_forward")
os.system("echo 1 > /proc/sys/net/ipv4/ip_dynaddr")
# Load rules
input = parameters.get("device-input", "")
output = parameters.get("device-output", "")
if input and output and input != output:
in_name = input.split("_")[-1]
out_name = output.split("_")[-1]
execRule("-A PARDUS-FW-MOD-SHARING -i %s -o %s -m state --state ESTABLISHED,RELATED -j ACCEPT" % (in_name, out_name))
execRule("-A PARDUS-FW-MOD-SHARING -i %s -o %s -j ACCEPT" % (out_name, in_name))
execRule("-t nat -A PARDUS-POST-MOD-SHARING -o %s -j MASQUERADE" % in_name)
# Create local NAT profile
import comar
link = comar.Link()
package, connection = findOrCreateConnection(link, output)
link.Network.Link[package].setState(connection, "up")
# Configure DHCP
makeDHCPConf(out_name)
# Start DHCP
startService("dhcpd", restart=True)
def unloadModule(self, shutdown=False):
# Stop DHCP
stopService("dhcpd")
if not shutdown:
# Unload rules
execRule("-F PARDUS-FW-MOD-SHARING")
execRule("-P PARDUS-FW-MOD-SHARING ACCEPT")
execRule("-t nat -F PARDUS-POST-MOD-SHARING")
# Usable modules
MODULES = {
"internet_sharing": InternetSharingModule,
"block_incoming": BlockIncoming,
"block_outgoing": BlockOutgoing,
}
# Network.Firewall model
def listModules():
return MODULES.keys()
def moduleInfo(module):
inst = MODULES[module]()
return inst.getInfo()
def moduleParameters(module):
inst = MODULES[module]()
return inst.getParameters()
def getModuleState(module):
info = ModuleConfig(module).info
return info.get("state", "off")
def setModuleState(name, state):
if state in ["on", "off"]:
# Save state
module = ModuleConfig(name)
module.info["state"] = state
module.save()
# Execute module if firewall is active
if getState() == "on":
inst = MODULES[name]()
if state == "on":
inst.loadModule(getModuleParameters(name))
else:
inst.unloadModule()
# Notify clients
notify("Network.Firewall", "moduleStateChanged", (name, state))
def getModuleParameters(module):
info = ModuleConfig(module).info
return info
def setModuleParameters(name, parameters):
# Save module parameters
module = ModuleConfig(name)
for key, value in parameters.iteritems():
module.info[key] = value
module.save()
# Execute module if it's active
if getState() == "on" and getModuleState(name) == "on":
inst = MODULES[name]()
inst.checkModule(parameters)
inst.loadModule(parameters)
# Notify clients
notify("Network.Firewall", "moduleSettingsChanged", (name))
def getState():
state = ModuleConfig("general").info.get("state", "off")
if state not in ["on", "off"] or not getServiceState(script()):
return "off"
return state
def setState(state):
if state in ["on", "off"]:
# Save state
general = ModuleConfig("general")
general.info["state"] = state
general.save()
if state == "on":
# Start IPTables
startService(script(), auto_start=True)
# Execute active modules
for module in listModuleConfigs():
if module not in MODULES:
continue
info = ModuleConfig(module).info
if info.get("state", "off") == "on":
inst = MODULES[module]()
inst.loadModule(getModuleParameters(module))
else:
# Flush IPTables since every module depends on it
netfilterutils.clear()
# Stop IPTables
stopService(script(), permanent=True)
# Unload modules
for module in listModuleConfigs():
if module not in MODULES:
continue
inst = MODULES[module]()
inst.unloadModule(shutdown=True)
# Notify clients
notify("Network.Firewall", "stateChanged", (state))
+69
View File
@@ -0,0 +1,69 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
from comar.service import *
serviceType = "local"
serviceDesc = _({"en": "Firewall",
"tr": "Güvenlik Duvarı"})
LOCK_FILE = "/var/lock/subsys/iptables"
FIREWALL_PATH = "/etc/firewall.conf"
import os
import pardus.netfilterutils as iptables
from pardus import iniutils
def writeFile(filename, content="", mode=0600):
'''Writes content to filename and sets file mode.'''
file(filename, "w").write(content)
os.chmod(filename, mode)
def readFile(filename):
"""Return content of a file"""
return file(filename, "r").read()
def startNetworkFirewall():
INI = iniutils.iniParser(FIREWALL_PATH)
try:
info = INI.getSection("general")
except iniutils.iniParserError:
return
if info.get("state", "off") == "on":
call(script(), "Network.Firewall", "setState", ("on"))
def stop():
# Save rules
writeFile("/var/lib/iptables/rules", iptables.getRules())
# Clear chains & rules
iptables.clear()
# Remove lock file
if os.access(LOCK_FILE, os.F_OK):
os.unlink(LOCK_FILE)
# Notify clients
notify("System.Service", "Changed", (script(), "stopped"))
def start():
# Clear chains & rules
iptables.clear()
# Load rules
profile_file = "/var/lib/iptables/rules"
if os.path.exists(profile_file):
rules = readFile(profile_file)
iptables.restoreRules(rules)
# Create lock file
writeFile(LOCK_FILE, "")
# Initialize Network.Firewall, if necessary
startNetworkFirewall()
# Notify clients
notify("System.Service", "Changed", (script(), "started"))
def status():
return os.access(LOCK_FILE, os.F_OK)
+89
View File
@@ -0,0 +1,89 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>iptables</Name>
<Homepage>http://www.iptables.org/</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>GPLv2</License>
<IsA>app:console</IsA>
<Summary>Firewall, NAT and packet mangling tools</Summary>
<Description>Contains iptables firewall, NAT and packet mangling tools.</Description>
<Archive sha1sum="85d4160537546a23a7e42bc26dd7ee62a0ede4c8" type="tarbz2">ftp://ftp.netfilter.org/pub/iptables/iptables-1.4.21.tar.bz2</Archive>
<BuildDependencies>
<Dependency>libnfnetlink-devel</Dependency>
</BuildDependencies>
<Patches>
<!-- these got in
<Patch>iptables-1.4.2-as-needed.patch</Patch>
<Patch>iptables-1.4.2-no-ldconfig.patch</Patch>
-->
<!--<Patch>iptables-1.4.2-glibc.patch</Patch>-->
</Patches>
</Source>
<Package>
<Name>iptables</Name>
<RuntimeDependencies>
<Dependency>libnfnetlink</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="executable">/sbin</Path>
<Path fileType="library">/lib</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="config">/etc</Path>
<Path fileType="data">/var</Path>
<Path fileType="data">/usr/share/xtables</Path>
</Files>
<Provides>
<COMAR script="service.py">System.Service</COMAR>
<COMAR script="firewall.py">Network.Firewall</COMAR>
</Provides>
</Package>
<Package>
<Name>iptables-devel</Name>
<Summary>Development files for iptables</Summary>
<RuntimeDependencies>
<Dependency release="current">iptables</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include</Path>
<Path fileType="library">/usr/lib/*.a</Path>
<Path fileType="data">/usr/lib/pkgconfig</Path>
<Path fileType="man">/usr/share/man/man3</Path>
</Files>
</Package>
<History>
<Update release="3">
<Date>2013-11-23</Date>
<Version>1.4.21</Version>
<Comment>Version bump</Comment>
<Name>Richard de Bruin</Name>
<Email>richdb@pisilinux.org</Email>
</Update>
<Update release="2">
<Date>2013-03-04</Date>
<Version>1.4.17</Version>
<Comment>Version bump</Comment>
<Name>Yusuf Aydemir</Name>
<Email>yusuf.aydemir@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2012-10-21</Date>
<Version>1.4.16.3</Version>
<Comment>First release</Comment>
<Requires>
<Action>reverseDependencyUpdate</Action>
</Requires>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>

Some files were not shown because too many files have changed in this diff Show More