Compare commits

..

5 commits

Author SHA1 Message Date
Ryan O'Hara
c209254ea6 Fix dbus policy (#2027158, CVE-2021-442255) 2021-12-14 10:42:47 -06:00
Ryan O'Hara
2646ddf124 Update to 2.2.4 (#1996274) 2021-12-14 10:40:37 -06:00
Ryan O'Hara
97d33f6661 Fix rhbz# in changelog 2021-04-13 11:50:49 -05:00
Ryan O'Hara
f0a26611a2 Add BuildRequires for file-devel 2021-04-12 13:33:12 -05:00
Ryan O'Hara
4da4e45468 Update to 2.2.2 (#1935590) 2021-04-07 10:14:32 -05:00
6 changed files with 55 additions and 142 deletions

3
.gitignore vendored
View file

@ -36,7 +36,4 @@
/keepalived-2.2.0.tar.gz
/keepalived-2.2.1.tar.gz
/keepalived-2.2.2.tar.gz
/keepalived-2.2.3.tar.gz
/keepalived-2.2.4.tar.gz
/keepalived-2.2.7.tar.gz
/keepalived-2.2.8.tar.gz

View file

@ -0,0 +1,41 @@
From 7977fec0be89ae6fe87405b3f8da2f0b5e415e3d Mon Sep 17 00:00:00 2001
From: Vincent Bernat <vincent@bernat.ch>
Date: Tue, 23 Nov 2021 06:50:59 +0100
Subject: [PATCH] dbus: fix policy to not be overly broad
The DBus policy did not restrict the message destination, allowing any
user to inspect and manipulate any property.
Signed-off-by: Vincent Bernat <vincent@bernat.ch>
---
keepalived/dbus/org.keepalived.Vrrp1.conf | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/keepalived/dbus/org.keepalived.Vrrp1.conf b/keepalived/dbus/org.keepalived.Vrrp1.conf
index 2b78a575..b5ced608 100644
--- a/keepalived/dbus/org.keepalived.Vrrp1.conf
+++ b/keepalived/dbus/org.keepalived.Vrrp1.conf
@@ -3,12 +3,15 @@
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
<busconfig>
<policy user="root">
- <allow own="org.keepalived.Vrrp1"/>
- <allow send_destination="org.keepalived.Vrrp1"/>
+ <allow own="org.keepalived.Vrrp1" />
+ <allow send_destination="org.keepalived.Vrrp1" />
</policy>
<policy context="default">
- <allow send_interface="org.freedesktop.DBus.Introspectable" />
- <allow send_interface="org.freedesktop.DBus.Peer" />
- <allow send_interface="org.freedesktop.DBus.Properties" />
+ <allow send_destination="org.keepalived.Vrrp1"
+ send_interface="org.freedesktop.DBus.Introspectable" />
+ <allow send_destination="org.keepalived.Vrrp1"
+ send_interface="org.freedesktop.DBus.Peer" />
+ <allow send_destination="org.keepalived.Vrrp1"
+ send_interface="org.freedesktop.DBus.Properties" />
</policy>
</busconfig>
--
2.33.1

View file

@ -1,51 +0,0 @@
Fix a configure check that happens to trigger and implicit function
declaration error.
Fixed slightly differently in upstream via:
commit 516032ec39169d05c613de0e8ee10845658748ff
Author: Quentin Armitage <quentin@armitage.org.uk>
Date: Sun Apr 17 18:02:18 2022 +0100
config parser: Fix segfault caused by extra '}' and other parser fixes
If there was a configuration error in a block, e.g. a vrrp_instance,
keepalived would apply the configuration in the rest of the block to
the previous object of that type, e.g. the previous vrrp instance. If
there had been no previous instance, keepalived would probably segfault.
This commit changes the way the parser works. A new instance of an
object, e.g. a VRRP instance or a virtual server, is only added to the
list of those objects once the configuration of that object is complete.
In particular it no longer applies the configuration to the last entry
on the list of the relevant object type, but keeps a point to the
object currently being configured.
Signed-off-by: Quentin Armitage <quentin@armitage.org.uk>
diff --git a/configure b/configure
index 7cd6c4f614930391..b099b8f42aca1cba 100755
--- a/configure
+++ b/configure
@@ -6382,7 +6382,7 @@ cat confdefs.h - <<_ACEOF >conftest.$ac_ext
#include <stdio.h>
- static int func(int i) __attribute__((error("deliberate error")))
+ static int __attribute__((error("deliberate error"))) func(int i)
{
return i * 2;
}
diff --git a/configure.ac b/configure.ac
index 350a9f4e9567518c..5546143b4630aff6 100644
--- a/configure.ac
+++ b/configure.ac
@@ -792,7 +792,7 @@ AC_COMPILE_IFELSE(
[[
#include <stdio.h>
- static int func(int i) __attribute__((error("deliberate error")))
+ static int __attribute__((error("deliberate error"))) func(int i)
{
return i * 2;
}

View file

@ -4,12 +4,11 @@ After=network-online.target syslog.target
Wants=network-online.target
[Service]
Type=notify
NotifyAccess=all
Type=forking
PIDFile=/run/keepalived.pid
KillMode=process
EnvironmentFile=-/etc/sysconfig/keepalived
ExecStart=/usr/sbin/keepalived --dont-fork $KEEPALIVED_OPTIONS
ExecStart=/usr/sbin/keepalived $KEEPALIVED_OPTIONS
ExecReload=/bin/kill -HUP $MAINPID
[Install]

View file

@ -1,7 +1,6 @@
%bcond_without snmp
%bcond_without vrrp
%bcond_without sha1
%bcond_without json
%bcond_without nftables
%bcond_with profile
%bcond_with debug
@ -10,14 +9,15 @@
Name: keepalived
Summary: High Availability monitor built upon LVS, VRRP and service pollers
Version: 2.2.8
Release: 8%{?dist}
License: GPL-2.0-or-later
Version: 2.2.4
Release: 2%{?dist}
License: GPLv2+
URL: http://www.keepalived.org/
Source0: http://www.keepalived.org/software/keepalived-%{version}.tar.gz
Source1: keepalived.service
#Patch0: keepalived-configure-c99.patch
Patch1: bz2027158-fix-dbus-policy.patch
Requires(post): systemd
Requires(preun): systemd
@ -35,7 +35,6 @@ BuildRequires: iptables-devel
%endif
BuildRequires: gcc
BuildRequires: systemd-units
BuildRequires: systemd-devel
BuildRequires: openssl-devel
BuildRequires: libnl3-devel
BuildRequires: libnfnetlink-devel
@ -57,10 +56,8 @@ can be used independently or all together to provide resilient
infrastructures.
%prep
%autosetup -p1
# Prevent re-running autotools.
touch aclocal.m4 Makefile.in lib/config.h.in configure
%setup -q
%patch1 -p1
%build
%configure \
@ -69,7 +66,6 @@ touch aclocal.m4 Makefile.in lib/config.h.in configure
%{!?with_vrrp:--disable-vrrp} \
%{?with_snmp:--enable-snmp --enable-snmp-rfc} \
%{?with_nftables:--enable-nftables --disable-iptables} \
%{?with_json:--enable-json} \
%{?with_sha1:--enable-sha1} \
--with-init=systemd
%{__make} %{?_smp_mflags} STRIP=/bin/true
@ -79,8 +75,6 @@ rm -rf %{buildroot}
make install DESTDIR=%{buildroot}
rm -rf %{buildroot}%{_initrddir}/
rm -rf %{buildroot}%{_sysconfdir}/keepalived/samples/
mv %{buildroot}%{_sysconfdir}/keepalived/keepalived.conf.sample \
%{buildroot}%{_sysconfdir}/keepalived/keepalived.conf
%{__install} -p -D -m 0644 %{SOURCE1} %{buildroot}%{_unitdir}/keepalived.service
mkdir -p %{buildroot}%{_libexecdir}/keepalived
@ -113,84 +107,17 @@ mkdir -p %{buildroot}%{_libexecdir}/keepalived
%{_mandir}/man8/keepalived.8*
%changelog
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.8-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Dec 14 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.4-2
- Fix dbus policy (#2027158, CVE-2021-442255)
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.8-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.8-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Jan 24 2024 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.8-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.8-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Aug 04 2023 Ryan O'Hara <rohara@redhat.com> - 2.2.8-3
- Migrate to SPDX license
* Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jun 08 2023 Ryan O'Hara <rohara@redhat.com> - 2.2.8-1
- Update to 2.2.8 (#2211385)
* Thu Jan 19 2023 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.7-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Tue Dec 20 2022 Ryan O'Hara <rohara@redhat.com> - 2.2.7-5
- Enable JSON support
* Wed Dec 7 2022 Florian Weimer <fweimer@redhat.com> - 2.2.7-4
- Fix spurious implicit function declaration in broken configure check
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.7-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jul 07 2022 Ryan O'Hara <rohara@redhat.com> - 2.2.7-2
- Move keepalived.conf.sample to keepalived.conf
* Mon Feb 14 2022 Ryan O'Hara <rohara@redhat.com> - 2.2.7-1
- Update to 2.2.7 (#2041231)
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.4-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Tue Dec 14 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.4-4
- Fix dbus policy (#2027158, CVE-2021-44225)
* Sat Nov 27 2021 Kevin Fenzi <kevin@scrye.com> - 2.2.4-3
- Rebuild for new libnftnl
* Tue Sep 14 2021 Sahana Prasad <sahana@redhat.com> - 2.2.4-2
- Rebuilt with OpenSSL 3.0.0
* Mon Aug 23 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.4-1
* Tue Dec 14 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.4-1
- Update to 2.2.4 (#1996274)
* Sat Aug 14 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.3-1
- Update to 2.2.3 (#1993601)
* Tue Aug 03 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.2-5
- Add systemd notify support
* Tue Aug 03 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.2-4
- Fix build errors (#1987620)
* Thu Jul 22 2021 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Mon Apr 12 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.2-2
- Add BuildRequires for file-devel
* Wed Apr 07 2021 Ryan O'Hara <rohara@redhat.com> - 2.2.2-1
- Update to 2.2.2 (#1935590)
* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 2.2.1-3
- Rebuilt for updated systemd-rpm-macros
See https://pagure.io/fesco/issue/2583.
- Update to 2.2.2 (#1935990)
* Tue Jan 26 2021 Fedora Release Engineering <releng@fedoraproject.org> - 2.2.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild

View file

@ -1 +1 @@
SHA512 (keepalived-2.2.8.tar.gz) = dc0ab5b0ef8911a7859422eccc2771a40e942236c855a628158ed748eb5f7dc4b6f4850e9c3057e81fd9d2daa640ab51fb1d7af12748a613280a217b333eb06b
SHA512 (keepalived-2.2.4.tar.gz) = b8b0f3e7092b7b7093a9927259928076ee95ed176dd26b3a5c38e8c0dc7b83468433944905618dbc9e4b73b81b0cd3f16c2db4234ed4fcdf30f4fc0e532f9422