[CVS] OpenPKG: openpkg-src/inn/ inn.spec rc.inn openpkg-web/ news.txt
OpenPKG CVS Repository http://cvs.openpkg.org/ Server: cvs.openpkg.org Name: Michael van Elst Root: /e/openpkg/cvs Email: [EMAIL PROTECTED] Module: openpkg-src openpkg-web Date: 18-Jul-2003 11:09:31 Branch: HEAD Handle: 2003071810092901 Modified files: openpkg-src/inn inn.spec rc.inn openpkg-web news.txt Log: fix running as restricted user, add %status section Summary: RevisionChanges Path 1.74+45 -16 openpkg-src/inn/inn.spec 1.15+8 -0 openpkg-src/inn/rc.inn 1.5633 +1 -0 openpkg-web/news.txt patch -p0 '@@ .' Index: openpkg-src/inn/inn.spec $ cvs diff -u -r1.73 -r1.74 inn.spec --- openpkg-src/inn/inn.spec 17 Jul 2003 15:32:44 - 1.73 +++ openpkg-src/inn/inn.spec 18 Jul 2003 09:09:30 - 1.74 @@ -33,7 +33,7 @@ Group:News License: ISC Version: 2.4.0 -Release: 20030717 +Release: 20030718 # package options %option with_fsl yes @@ -98,9 +98,9 @@ --with-tmp-dir=%{l_prefix}/var/inn/tmp \ --with-openssl=%{l_prefix} \ --with-berkeleydb=%{l_prefix} \ ---with-news-user=%{l_musr} \ ---with-news-group=%{l_musr} \ ---with-news-master=%{l_musr} \ +--with-news-user=%{l_rusr} \ +--with-news-group=%{l_rgrp} \ +--with-news-master=%{l_rusr} \ --with-sendmail=%{l_prefix}/sbin/sendmail \ --enable-uucp-rnews \ --with-perl @@ -135,7 +135,7 @@ %{l_shtool} mkdir -f -p -m 755 $RPM_BUILD_ROOT%{l_prefix}/bin for bin in controlbatch controlchan news2mail startinnfeed overchan \ archive innmail innconfval ctlinnd inews rnews nntpsend; do -ln $RPM_BUILD_ROOT%{l_prefix}/libexec/inn/$bin \ +ln -s %{l_prefix}/libexec/inn/$bin \ $RPM_BUILD_ROOT%{l_prefix}/bin/$bin done @@ -163,12 +163,7 @@ ) $RPM_BUILD_ROOT%{l_prefix}/etc/inn/storage.conf # create initial history database -( cd $RPM_BUILD_ROOT%{l_prefix}/var/inn/db - touch history - INNCONF=$RPM_BUILD_ROOT%{l_prefix}/etc/inn/inn.conf \ - $RPM_BUILD_ROOT%{l_prefix}/libexec/inn/makedbz -i -f ./history - chmod 644 history* -) +touch $RPM_BUILD_ROOT%{l_prefix}/var/inn/db/history # adjust permissions chmod 664 $RPM_BUILD_ROOT%{l_prefix}/var/inn/db/active @@ -200,12 +195,40 @@ %{l_rpmtool} files -v -ofiles -r$RPM_BUILD_ROOT \ %{l_files_std} \ '%not %dir %{l_prefix}/etc/fsl' \ -'%config %{l_prefix}/etc/fsl/fsl.inn' \ -'%config %{l_prefix}/etc/inn/*' \ -'%attr(4550,%{l_susr},%{l_mgrp}) %{l_prefix}/bin/rnews' \ -'%attr(4755,%{l_susr},%{l_mgrp}) %{l_prefix}/libexec/inn/inndstart' \ -'%attr(4755,%{l_susr},%{l_mgrp}) %{l_prefix}/libexec/inn/startinnfeed' \ +'%config %attr(-,%{l_musr},%{l_rgrp}) %{l_prefix}/etc/fsl/fsl.inn' \ +'%config %attr(-,%{l_musr},%{l_rgrp}) %{l_prefix}/etc/inn/*' \ +'%attr(6550,%{l_rusr},%{l_rgrp}) %{l_prefix}/libexec/inn/rnews' \ +'%attr(6750,%{l_susr},%{l_rgrp}) %{l_prefix}/libexec/inn/inndstart' \ +'%attr(6750,%{l_susr},%{l_rgrp}) %{l_prefix}/libexec/inn/startinnfeed' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/cnfsheadconf' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/ctlinnd' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/expire' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/expireover' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/expirerm' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/imapfeed' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/inews' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/inncheck' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/innd' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/innfeed' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/innreport' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/innstat' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/innupgrade' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/innwatch' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/makedbz' \ +'%attr(750,%{l_musr},%{l_rgrp}) %{l_prefix}/libexec/inn/makehistory' \ +'%attr(750,%{l_musr},%{l_rgrp})
Re: [CVS] OpenPKG: openpkg-src/inn/ inn.spec rc.inn openpkg-web/ news.txt
On Tue, Jun 24, 2003, Michael van Elst wrote: [...] run as restricted user [...] Looks like a reasonable change, but have you really tested this under run-time, Michael? I'm just wondering whether this opens a can of worms, because of side-effects... ;-) Ralf S. Engelschall [EMAIL PROTECTED] www.engelschall.com __ The OpenPKG Projectwww.openpkg.org Developer Communication List [EMAIL PROTECTED]
[CVS] OpenPKG: openpkg-src/inn/ inn.spec rc.inn openpkg-web/ news.txt
OpenPKG CVS Repository http://cvs.openpkg.org/ Server: cvs.openpkg.org Name: Ralf S. Engelschall Root: /e/openpkg/cvs Email: [EMAIL PROTECTED] Module: openpkg-src openpkg-web Date: 28-Jun-2003 16:28:32 Branch: HEAD Handle: 2003062815283001 Modified files: openpkg-src/inn inn.spec rc.inn openpkg-web news.txt Log: INN has own logfile rotation job which picks up our news.* files Summary: RevisionChanges Path 1.65+1 -1 openpkg-src/inn/inn.spec 1.11+1 -13 openpkg-src/inn/rc.inn 1.5057 +1 -0 openpkg-web/news.txt patch -p0 '@@ .' Index: openpkg-src/inn/inn.spec $ cvs diff -u -r1.64 -r1.65 inn.spec --- openpkg-src/inn/inn.spec 24 Jun 2003 16:17:31 - 1.64 +++ openpkg-src/inn/inn.spec 28 Jun 2003 14:28:31 - 1.65 @@ -33,7 +33,7 @@ Group:News License: ISC Version: 2.4.0 -Release: 20030624 +Release: 20030628 # package options %option with_fsl yes @@ . patch -p0 '@@ .' Index: openpkg-src/inn/rc.inn $ cvs diff -u -r1.10 -r1.11 rc.inn --- openpkg-src/inn/rc.inn24 Jun 2003 16:17:31 - 1.10 +++ openpkg-src/inn/rc.inn28 Jun 2003 14:28:31 - 1.11 @@ -6,11 +6,6 @@ %config inn_enable=yes inn_nntpsend_enable=no -inn_log_prolog=true -inn_log_epilog=true -inn_log_numfiles=10 -inn_log_minsize=1M -inn_log_complevel=9 %start -p 200 -u @l_rusr@ opServiceEnabled inn || exit 0 @@ -34,14 +29,7 @@ opServiceEnabled inn || exit 0 @l_prefix@/libexec/inn/news.daily expireover lowmark delayrm -# rotate logfile -shtool rotate -f \ --n${inn_log_numfiles} -s${inn_log_minsize} -d \ --z${inn_log_complevel} [EMAIL PROTECTED]@ [EMAIL PROTECTED]@ -m644 \ --P ${inn_log_prolog} \ --E ${inn_log_epilog} \ -@l_prefix@/var/inn/log/news.* - %quarterly -u @l_rusr@ opServiceEnabled inn || exit 0 opServiceEnabled inn_nntpsend @l_prefix@/bin/nntpsend || true + @@ . patch -p0 '@@ .' Index: openpkg-web/news.txt $ cvs diff -u -r1.5056 -r1.5057 news.txt --- openpkg-web/news.txt 28 Jun 2003 14:10:33 - 1.5056 +++ openpkg-web/news.txt 28 Jun 2003 14:28:30 - 1.5057 @@ -1,3 +1,4 @@ +28-Jun-2003: Upgraded package: Pinn-2.4.0-20030628 28-Jun-2003: Upgraded package: Ppowerdns-2.9.8-20030628 28-Jun-2003: Upgraded package: Ppound-1.4-20030628 28-Jun-2003: Upgraded package: Pportfwd-0.26rc6-20030628 @@ . __ The OpenPKG Projectwww.openpkg.org CVS Repository Commit List [EMAIL PROTECTED]
Re: [CVS] OpenPKG: openpkg-src/inn/ inn.spec rc.inn openpkg-web/ news.txt
On Sat, Jun 28, 2003, Ralf S. Engelschall wrote: Looks like a reasonable change, but have you really tested this under run-time, Michael? I'm just wondering whether this opens a can of worms, because of side-effects... ;-) Not really, but running under m_usr is a nono. Anyway, we must test all packages that got the new fsl support. I guess some of them require polishing on file permissions. -- ,eM=.a-. Michael van Elst dWWMWM - :GM==;[EMAIL PROTECTED] :WWMWMw=--. W=' cable wireless 9WWMm==-. -Wmw- CABLE WIRELESS __ The OpenPKG Projectwww.openpkg.org Developer Communication List [EMAIL PROTECTED]
[CVS] OpenPKG: openpkg-src/inn/ inn.spec rc.inn openpkg-web/ news.txt
OpenPKG CVS Repository http://cvs.openpkg.org/ Server: cvs.openpkg.org Name: Michael van Elst Root: /e/openpkg/cvs Email: [EMAIL PROTECTED] Module: openpkg-src openpkg-web Date: 24-Jun-2003 13:37:52 Branch: HEAD Handle: 2003062412375001 Modified files: openpkg-src/inn inn.spec rc.inn openpkg-web news.txt Log: run as restricted user Summary: RevisionChanges Path 1.63+9 -4 openpkg-src/inn/inn.spec 1.6 +17 -6 openpkg-src/inn/rc.inn 1.4982 +1 -0 openpkg-web/news.txt patch -p0 '@@ .' Index: openpkg-src/inn/inn.spec $ cvs diff -u -r1.62 -r1.63 inn.spec --- openpkg-src/inn/inn.spec 23 Jun 2003 20:48:05 - 1.62 +++ openpkg-src/inn/inn.spec 24 Jun 2003 11:37:51 - 1.63 @@ -33,7 +33,7 @@ Group:News License: ISC Version: 2.4.0 -Release: 20030623 +Release: 20030624 # package options %option with_fsl yes @@ -204,9 +204,14 @@ '%not %dir %{l_prefix}/etc/fsl' \ '%config %{l_prefix}/etc/fsl/fsl.%{name}' \ '%config %{l_prefix}/etc/inn/*' \ -'%attr(4550,root,%{l_mgrp}) %{l_prefix}/bin/rnews' \ -'%attr(4755,root,%{l_mgrp}) %{l_prefix}/libexec/inn/inndstart' \ -'%attr(4755,root,%{l_mgrp}) %{l_prefix}/libexec/inn/startinnfeed' \ +'%attr(4550,%{l_susr},%{l_mgrp}) %{l_prefix}/bin/rnews' \ +'%attr(4755,%{l_susr},%{l_mgrp}) %{l_prefix}/libexec/inn/inndstart' \ +'%attr(4755,%{l_susr},%{l_mgrp}) %{l_prefix}/libexec/inn/startinnfeed' \ +'%attr(775,%{l_musr},%{l_rgrp}) %{l_prefix}/var/inn/db' \ +'%attr(775,%{l_musr},%{l_rgrp}) %{l_prefix}/var/inn/log' \ +'%attr(775,%{l_musr},%{l_rgrp}) %{l_prefix}/var/inn/run' \ +'%attr(775,%{l_musr},%{l_rgrp}) %{l_prefix}/var/inn/spool' \ +'%attr(775,%{l_musr},%{l_rgrp}) %{l_prefix}/var/inn/tmp' \ '%config %{l_prefix}/var/inn/db/*' %files -f files @@ . patch -p0 '@@ .' Index: openpkg-src/inn/rc.inn $ cvs diff -u -r1.5 -r1.6 rc.inn --- openpkg-src/inn/rc.inn7 Feb 2002 14:20:58 - 1.5 +++ openpkg-src/inn/rc.inn24 Jun 2003 11:37:51 - 1.6 @@ -6,30 +6,41 @@ %config inn_enable=yes inn_nntpsend_enable=no +inn_log_prolog=true +inn_log_epilog=true +inn_log_numfiles=10 +inn_log_minsize=1M +inn_log_complevel=9 -%start -p 200 -u @l_musr@ +%start -p 200 -u @l_rusr@ opServiceEnabled inn || exit 0 @l_prefix@/libexec/inn/rc.news -%stop -p 200 -u @l_musr@ +%stop -p 200 -u @l_rusr@ opServiceEnabled inn || exit 0 @l_prefix@/libexec/inn/rc.news stop -%restart -u @l_musr@ +%restart -u @l_rusr@ opServiceEnabled inn || exit 0 @l_prefix@/libexec/inn/rc.news stop sleep 2 @l_prefix@/libexec/inn/rc.news -%reload -u root +%reload -u @l_rusr@ opServiceEnabled inn || exit 0 @l_prefix@/bin/ctlinnd reload all rc.inn:reload -%daily -u @l_musr@ +%daily -u @l_rusr@ opServiceEnabled inn || exit 0 @l_prefix@/libexec/inn/news.daily expireover lowmark delayrm +shtool rotate -f \ +-n${inn_log_numfiles} -s${inn_log_minsize} -d \ +-z${inn_log_complevel} [EMAIL PROTECTED]@ [EMAIL PROTECTED]@ -m644 \ +-P ${inn_log_prolog} \ +-E ${inn_log_epilog} \ +@l_prefix@/var/FOO/log/*.log -%quarterly -u root +%quarterly -u @l_rusr@ opServiceEnabled inn || exit 0 opServiceEnabled inn_nntpsend @l_prefix@/bin/nntpsend || true @@ . patch -p0 '@@ .' Index: openpkg-web/news.txt $ cvs diff -u -r1.4981 -r1.4982 news.txt --- openpkg-web/news.txt 24 Jun 2003 09:47:26 - 1.4981 +++ openpkg-web/news.txt 24 Jun 2003 11:37:50 - 1.4982 @@ -1,3 +1,4 @@ +24-Jun-2003: Upgraded package: Pinn-2.4.0-20030624 24-Jun-2003: Upgraded package: Ppostfix-2.0.12-20030624 24-Jun-2003: Upgraded package: Pautogen-5.5.5-20030624 24-Jun-2003: Upgraded package: Plibiconv-1.9.1-20030624 @@ . __ The OpenPKG Projectwww.openpkg.org CVS Repository Commit List [EMAIL PROTECTED]