Compare commits
27 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
57efd4bc2c | ||
|
|
3841494977 | ||
|
|
7d2dc21766 | ||
|
|
c778acb9b6 | ||
|
|
b314d2836f | ||
|
|
3e46c35d57 | ||
|
|
e50a9a834e | ||
|
|
2d7827722c | ||
|
|
d4daf5c72d | ||
|
|
c424d3171a | ||
|
|
4fe8b15f87 | ||
|
|
1d5d75ed59 | ||
|
|
5057f0cd10 | ||
|
|
24ef02c520 | ||
|
|
2e2911fb6d | ||
|
|
6f91fcbc5f | ||
|
|
3d5ccd04ae | ||
|
|
60065d487c | ||
|
|
9f3a9a3cd7 | ||
|
|
6e1f9b5dcf | ||
|
|
798cc68dc1 | ||
|
|
d46b0c4bb9 | ||
|
|
138da7918a | ||
|
|
bd74dec52f | ||
|
|
c9018b3ea2 | ||
|
|
5a3c09b944 | ||
|
|
3ba8798fc9 |
14 changed files with 1091 additions and 6 deletions
1
.gitignore
vendored
Normal file
1
.gitignore
vendored
Normal file
|
|
@ -0,0 +1 @@
|
|||
libcap-1.10.tar.bz2
|
||||
6
Makefile
6
Makefile
|
|
@ -1,6 +0,0 @@
|
|||
# Makefile for source rpm: libcap
|
||||
# $Id$
|
||||
NAME := libcap
|
||||
SPECFILE = $(firstword $(wildcard *.spec))
|
||||
|
||||
include ../common/Makefile.common
|
||||
264
capfaq-0.2.txt
Normal file
264
capfaq-0.2.txt
Normal file
|
|
@ -0,0 +1,264 @@
|
|||
This is the Linux kernel capabilities FAQ
|
||||
|
||||
Its history, to the extent that I am able to reconstruct it is that
|
||||
v2.0 was posted to the Linux kernel list on 1999/04/02 by Boris
|
||||
Tobotras. Thanks to Denis Ducamp for forwarding me a copy.
|
||||
|
||||
Cheers
|
||||
|
||||
Andrew
|
||||
|
||||
Linux Capabilities FAQ 0.2
|
||||
==========================
|
||||
|
||||
1) What is a capability?
|
||||
|
||||
The name "capabilities" as used in the Linux kernel can be confusing.
|
||||
First there are Capabilities as defined in computer science. A
|
||||
capability is a token used by a process to prove that it is allowed to
|
||||
do an operation on an object. The capability identifies the object
|
||||
and the operations allowed on that object. A file descriptor is a
|
||||
capability. You create the file descriptor with the "open" call and
|
||||
request read or write permissions. Later, when doing a read or write
|
||||
operation, the kernel uses the file descriptor as an index into a
|
||||
data structure that indicates what operations are allowed. This is an
|
||||
efficient way to check permissions. The necessary data structures are
|
||||
created once during the "open" call. Later read and write calls only
|
||||
have to do a table lookup. Operations on capabilities include copying
|
||||
capabilities, transferring capabilities between processes, modifying a
|
||||
capability, and revoking a capability. Modifying a capability can be
|
||||
something like taking a read-write filedescriptor and making it
|
||||
read-only. A capability often has a notion of an "owner" which is
|
||||
able to invalidate all copies and derived versions of a capability.
|
||||
Entire OSes are based on this "capability" model, with varying degrees
|
||||
of purity. There are other ways of implementing capabilities than the
|
||||
file descriptor model - traditionally special hardware has been used,
|
||||
but modern systems also use the memory management unit of the CPU.
|
||||
|
||||
Then there is something quite different called "POSIX capabilities"
|
||||
which is what Linux uses. These capabilities are a partitioning of
|
||||
the all powerful root privilege into a set of distinct privileges (but
|
||||
look at securelevel emulation to find out that this isn't necessary
|
||||
the whole truth). Users familiar with VMS or "Trusted" versions of
|
||||
other UNIX variants will know this under the name "privileges". The
|
||||
name "capabilities" comes from the now defunct POSIX draft 1003.1e
|
||||
which used this name.
|
||||
|
||||
2) So what is a "POSIX capability"?
|
||||
|
||||
A process has three sets of bitmaps called the inheritable(I),
|
||||
permitted(P), and effective(E) capabilities. Each capability is
|
||||
implemented as a bit in each of these bitmaps which is either set or
|
||||
unset. When a process tries to do a privileged operation, the
|
||||
operating system will check the appropriate bit in the effective set
|
||||
of the process (instead of checking whether the effective uid of the
|
||||
process i 0 as is normally done). For example, when a process tries
|
||||
to set the clock, the Linux kernel will check that the process has the
|
||||
CAP_SYS_TIME bit (which is currently bit 25) set in its effective set.
|
||||
|
||||
The permitted set of the process indicates the capabilities the
|
||||
process can use. The process can have capabilities set in the
|
||||
permitted set that are not in the effective set. This indicates that
|
||||
the process has temporarily disabled this capability. A process is
|
||||
allowed to set a bit in its effective set only if it is available in
|
||||
the permitted set. The distinction between effective and permitted
|
||||
exists so that processes can "bracket" operations that need privilege.
|
||||
|
||||
The inheritable capabilities are the capabilities of the current
|
||||
process that should be inherited by a program executed by the current
|
||||
process. The permitted set of a process is masked against the
|
||||
inheritable set during exec(). Nothing special happens during fork()
|
||||
or clone(). Child processes and threads are given an exact copy of
|
||||
the capabilities of the parent process.
|
||||
|
||||
3) What about other entities in the system? Users, Groups, Files?
|
||||
|
||||
Files have capabilities. Conceptually they have the same three
|
||||
bitmaps that processes have, but to avoid confusion we call them by
|
||||
other names. Only executable files have capabilities, libraries don't
|
||||
have capabilities (yet). The three sets are called the allowed set,
|
||||
the forced set, and the effective set.
|
||||
|
||||
The allowed set indicates what capabilities the executable is allowed
|
||||
to receive from an execing process. This means that during exec(),
|
||||
the capabilities of the old process are first masked against a set
|
||||
which indicates what the process gives away (the inheritable set of
|
||||
the process), and then they are masked against a set which indicates
|
||||
what capabilities the new process image is allowed to receive (the
|
||||
allowed set of the executable).
|
||||
|
||||
The forced set is a set of capabilities created out of thin air and
|
||||
given to the process after execing the executable. The forced set is
|
||||
similar in nature to the setuid feature. In fact, the setuid bit from
|
||||
the filesystem is "read" as a full forced set by the kernel.
|
||||
|
||||
The effective set indicates which bits in the permitted set of the new
|
||||
process should be transferred to the effective set of the new process.
|
||||
The effective set is best thought of as a "capability aware" set. It
|
||||
should consist of only 1s if the executable is capability-dumb, or
|
||||
only 0s if the executable is capability-smart. Since the effective
|
||||
set consists of only 0s or only 1s, the filesystem can implement this
|
||||
set using a single bit.
|
||||
|
||||
NOTE: Filesystem support for capabilities is not part of Linux 2.2.
|
||||
|
||||
Users and Groups don't have associated capabilities from the kernel's
|
||||
point of view, but it is entirely reasonable to associate users or
|
||||
groups with capabilities. By letting the "login" program set some
|
||||
capabilities it is possible to make role users such as a backup user
|
||||
that will have the CAP_DAC_READ_SEARCH capability and be able to do
|
||||
backups. This could also be implemented as a PAM module, but nobody
|
||||
has implemented one yet.
|
||||
|
||||
4) What capabilities exist?
|
||||
|
||||
The capabilities available in Linux are listed and documented in the
|
||||
file /usr/src/linux/include/linux/capability.h.
|
||||
|
||||
5) Are Linux capabilities hierarchical?
|
||||
|
||||
No, you cannot make a "subcapability" out of a Linux capability as in
|
||||
capability-based OSes.
|
||||
|
||||
6) How can I use capabilities to make sure Mr. Evil Luser (eluser)
|
||||
can't exploit my "suid" programs?
|
||||
|
||||
This is the general outline of how this works given filesystem
|
||||
capability support exists. First, you have a PAM module that sets the
|
||||
inheritable capabilities of the login-shell of eluser. Then for all
|
||||
"suid" programs on the system, you decide what capabilities they need
|
||||
and set the _allowed_ set of the executable to that set of
|
||||
capabilities. The capability rules
|
||||
|
||||
new permitted = forced | (allowed & inheritable)
|
||||
|
||||
means that you should be careful about setting forced capabilities on
|
||||
executables. In a few cases, this can be useful though. For example
|
||||
the login program needs to set the inheritable set of the new user and
|
||||
therefore needs an almost full permitted set. So if you want eluser
|
||||
to be able to run login and log in as a different user, you will have
|
||||
to set some forced bits on that executable.
|
||||
|
||||
7) What about passing capabilities between processes?
|
||||
|
||||
Currently this is done by the system call "setcap" which can set the
|
||||
capabilities of another process. This requires the CAP_SETPCAP
|
||||
capability which you really only want to grant a _few_ processes.
|
||||
CAP_SETPCAP was originally intended as a workaround to be able to
|
||||
implement filesystem support for capabilities using a daemon outside
|
||||
the kernel.
|
||||
|
||||
There has been discussions about implementing socket-level capability
|
||||
passing. This means that you can pass a capability over a socket. No
|
||||
support for this exists in the official kernel yet.
|
||||
|
||||
8) I see securelevel has been removed from 2.2 and are superceeded by
|
||||
capabilities. How do I emulate securelevel using capabilities?
|
||||
|
||||
The setcap system call can remove a capability from _all_ processes on
|
||||
the system in one atomic operation. The setcap utility from the
|
||||
libcap distribution will do this for you. The utility requires the
|
||||
CAP_SETPCAP privilege to do this. The CAP_SETPCAP capability is not
|
||||
enabled by default.
|
||||
|
||||
libcap is available from
|
||||
ftp://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.2/
|
||||
|
||||
9) I noticed that the capability.h file lacks some capabilities that
|
||||
are needed to fully emulate 2.0 securelevel. Is there a patch for
|
||||
this?
|
||||
|
||||
Actually yes - funny you should ask :-). The problem with 2.0
|
||||
securelevel is that they for example stop root from accessing block
|
||||
devices. At the same time they restrict the use of iopl. These two
|
||||
changes are fundamentally different. Blocking access to block devices
|
||||
means restricting something that usually isn't restricted.
|
||||
Restricting access to the use of iopl on the other hand means
|
||||
restricting (blocking) access to something that is already blocked.
|
||||
Emulating the parts of 2.0 securelevel that restricts things that are
|
||||
normally not restricted means that the capabilites in the kernel has
|
||||
to have a set of capabilities that are usually _on_ for a normal
|
||||
process (note that this breaks the explanation that capabilities are a
|
||||
partitioning of the root privileges). There is an experimental patch at
|
||||
|
||||
ftp://ftp.guardian.no/pub/free/linux/capabilities/patch-cap-exp-1
|
||||
|
||||
which implements a set of capabilities with the "CAP_USER" prefix:
|
||||
|
||||
cap_user_sock - allowed to use socket()
|
||||
cap_user_dev - allowed to open char/block devices
|
||||
cap_user_fifo - allowed to use pipes
|
||||
|
||||
These should be enough to emulate 2.0 securelevel (tell me if we need
|
||||
something more).
|
||||
|
||||
10) Seems I need a CAP_SETPCAP capability that I don't have to make use
|
||||
of capabilities. How do I enable this capability?
|
||||
|
||||
Change the definition of CAP_INIT_EFF_SET and CAP_INIT_INH_SET to the
|
||||
following in include/linux/capability.h:
|
||||
|
||||
#define CAP_INIT_EFF_SET { ~0 }
|
||||
#define CAP_INIT_INH_SET { ~0 }
|
||||
|
||||
This will start init with a full capability set and not with
|
||||
CAP_SETPCAP removed.
|
||||
|
||||
11) How do I start a process with a limited set of capabilities?
|
||||
|
||||
Get the libcap library and use the execcap utility. The following
|
||||
example starts the update daemon with only the CAP_SYS_ADMIN
|
||||
capability.
|
||||
|
||||
execcap 'cap_sys_admin=eip' update
|
||||
|
||||
12) How do I start a process with a limited set of capabilities under
|
||||
another uid?
|
||||
|
||||
Use the sucap utility which changes uid from root without loosing any
|
||||
capabilities. Normally all capabilities are cleared when changing uid
|
||||
from root. The sucap utility requires the CAP_SETPCAP capability.
|
||||
The following example starts updated under uid updated and gid updated
|
||||
with CAP_SYS_ADMIN raised in the Effective set.
|
||||
|
||||
sucap updated updated execcap 'cap_sys_admin=eip' update
|
||||
|
||||
[ Sucap is currently available from
|
||||
ftp://ftp.guardian.no/pub/free/linux/capabilities/sucap.c. Put it in
|
||||
the progs directory of libcap to compile.]
|
||||
|
||||
13) What are the "capability rules"
|
||||
|
||||
The capability rules are the rules used to set the capabilities of the
|
||||
new process image after an exec. They work like this:
|
||||
|
||||
pI' = pI
|
||||
(***) pP' = fP | (fI & pI)
|
||||
pE' = pP' & fE [NB. fE is 0 or ~0]
|
||||
|
||||
I=Inheritable, P=Permitted, E=Effective // p=process, f=file
|
||||
' indicates post-exec().
|
||||
|
||||
Now to make sense of the equations think of fP as the Forced set of
|
||||
the executable, and fI as the Allowed set of the executable. Notice
|
||||
how the Inheritable set isn't touched at all during exec().
|
||||
|
||||
14) What are the laws for setting capability bits in the Inheritable,
|
||||
Permitted, and Effective sets?
|
||||
|
||||
Bits can be transferred from Permitted to either Effective or
|
||||
Inheritable set.
|
||||
|
||||
Bits can be removed from all sets.
|
||||
|
||||
15) Where is the standard on which the Linux capabilities are based?
|
||||
|
||||
There used to be a POSIX draft called POSIX.6 and later POSIX 1003.1e.
|
||||
However after the committee had spent over 10 years, POSIX decided
|
||||
that enough is enough and dropped the draft. There will therefore not
|
||||
be a POSIX standard covering security anytime soon. This may lead to
|
||||
that the POSIX draft is available for free, however.
|
||||
|
||||
--
|
||||
Best regards, -- Boris.
|
||||
|
||||
13
libcap-1.10-audit.patch
Normal file
13
libcap-1.10-audit.patch
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
--- libcap-1.10/libcap/include/sys/capability.h.audit 2007-02-23 23:18:15.000000000 +0100
|
||||
+++ libcap-1.10/libcap/include/sys/capability.h 2007-02-23 23:18:54.000000000 +0100
|
||||
@@ -302,6 +302,10 @@
|
||||
|
||||
#define CAP_LEASE 28
|
||||
|
||||
+#define CAP_AUDIT_WRITE 29
|
||||
+
|
||||
+#define CAP_AUDIT_CONTROL 30
|
||||
+
|
||||
#endif /* !_LINUX_CAPABILITY_H */
|
||||
|
||||
|
||||
460
libcap-1.10-debian.patch
Normal file
460
libcap-1.10-debian.patch
Normal file
|
|
@ -0,0 +1,460 @@
|
|||
--- libcap-1.10/Makefile.debian 1999-04-18 00:16:31.000000000 +0200
|
||||
+++ libcap-1.10/Makefile 2007-02-21 14:56:33.000000000 +0100
|
||||
@@ -3,17 +3,20 @@
|
||||
#
|
||||
# Makefile for libcap
|
||||
|
||||
+ifndef topdir
|
||||
topdir=$(shell pwd)
|
||||
-include Make.Rules
|
||||
+endif
|
||||
+include $(topdir)/Make.Rules
|
||||
+DESTDIR=
|
||||
|
||||
#
|
||||
# flags
|
||||
#
|
||||
|
||||
all install clean: %: %-here
|
||||
- make -C libcap $(MAKE_DEFS) $@
|
||||
- make -C progs $(MAKE_DEFS) $@
|
||||
- make -C doc $(MAKE_DEFS) $@
|
||||
+ make -C $(topdir)/libcap $(MAKE_DEFS) $@
|
||||
+ make -C $(topdir)/progs $(MAKE_DEFS) $@
|
||||
+ make -C $(topdir)/doc $(MAKE_DEFS) $@
|
||||
|
||||
all-here:
|
||||
|
||||
--- libcap-1.10/Make.Rules.debian 1999-11-18 07:06:02.000000000 +0100
|
||||
+++ libcap-1.10/Make.Rules 2007-02-21 14:56:33.000000000 +0100
|
||||
@@ -8,7 +8,7 @@
|
||||
|
||||
# common 'packaging' directoty
|
||||
|
||||
-FAKEROOT=
|
||||
+FAKEROOT=$(DESTDIR)
|
||||
|
||||
# Autoconf-style prefixes are activated when $(prefix) is defined.
|
||||
# Otherwise binaries and libraraies are installed in /{lib,sbin}/,
|
||||
@@ -18,13 +18,13 @@
|
||||
exec_prefix=$(prefix)
|
||||
lib_prefix=$(exec_prefix)
|
||||
inc_prefix=$(lib_prefix)
|
||||
-man_prefix=$(prefix)
|
||||
+man_prefix=$(prefix)/share
|
||||
else
|
||||
prefix=/usr
|
||||
exec_prefix=
|
||||
lib_prefix=$(exec_prefix)
|
||||
inc_prefix=$(prefix)
|
||||
-man_prefix=$(prefix)
|
||||
+man_prefix=$(prefix)/share
|
||||
endif
|
||||
|
||||
# Target directories
|
||||
--- libcap-1.10/libcap/cap_sys.c.debian 1999-04-18 00:16:31.000000000 +0200
|
||||
+++ libcap-1.10/libcap/cap_sys.c 2007-02-21 14:56:33.000000000 +0100
|
||||
@@ -11,6 +11,8 @@
|
||||
#define __LIBRARY__
|
||||
#include <linux/unistd.h>
|
||||
|
||||
+/* glibc >= 2.1 knows capset/capget. no need to define it here */
|
||||
+/*
|
||||
_syscall2(int, capget,
|
||||
cap_user_header_t, header,
|
||||
cap_user_data_t, data)
|
||||
@@ -18,6 +20,7 @@
|
||||
_syscall2(int, capset,
|
||||
cap_user_header_t, header,
|
||||
const cap_user_data_t, data)
|
||||
+*/
|
||||
|
||||
/*
|
||||
* $Log: cap_sys.c,v $
|
||||
--- libcap-1.10/libcap/Makefile.debian 2007-02-21 14:56:33.000000000 +0100
|
||||
+++ libcap-1.10/libcap/Makefile 2007-02-21 14:56:33.000000000 +0100
|
||||
@@ -24,12 +24,14 @@
|
||||
#
|
||||
# defines
|
||||
#
|
||||
+ifndef topdir
|
||||
topdir=$(shell pwd)/..
|
||||
-include ../Make.Rules
|
||||
+endif
|
||||
+include $(topdir)/Make.Rules
|
||||
#
|
||||
# Library version
|
||||
#
|
||||
-LIBNAME=libcap.so
|
||||
+LIBNAME=libcap
|
||||
#
|
||||
|
||||
FILES=cap_alloc cap_proc cap_extint cap_flag cap_text cap_sys
|
||||
@@ -39,10 +41,11 @@
|
||||
|
||||
INCLS=libcap.h cap_names.h $(INCS)
|
||||
OBJS=$(addsuffix .o, $(FILES))
|
||||
-MAJLIBNAME=$(LIBNAME).$(VERSION)
|
||||
+LOBJS=$(addsuffix .lo, $(FILES))
|
||||
+MAJLIBNAME=$(LIBNAME).so.$(VERSION)
|
||||
MINLIBNAME=$(MAJLIBNAME).$(MINOR)
|
||||
|
||||
-all: $(MINLIBNAME)
|
||||
+all: $(MINLIBNAME) $(LIBNAME).a
|
||||
|
||||
_makenames: _makenames.c cap_names.sed
|
||||
$(CC) $(CFLAGS) $(LDFLAGS) $< -o $@
|
||||
@@ -51,30 +54,38 @@
|
||||
./_makenames > cap_names.h
|
||||
|
||||
cap_names.sed: Makefile /usr/include/linux/capability.h
|
||||
- @echo "=> making cap_names.c from <linux/capability.h>"
|
||||
- @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define \([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||
-# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||
+cap_names.sed: Makefile include/sys/capability.h
|
||||
+ @echo "=> making cap_names.c from <sys/capability.h>"
|
||||
+ @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define \([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < include/sys/capability.h | fgrep -v 0x > cap_names.sed
|
||||
+# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||
|
||||
-$(MINLIBNAME): $(OBJS)
|
||||
- $(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||
+$(LIBNAME).a: $(OBJS)
|
||||
+ ar cruv $(LIBNAME).a $(OBJS)
|
||||
+
|
||||
+$(MINLIBNAME): $(LOBJS)
|
||||
+ $(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -fPIC -o $@ $(LOBJS)
|
||||
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||
- ln -sf $(MAJLIBNAME) $(LIBNAME)
|
||||
+ ln -sf $(MAJLIBNAME) $(LIBNAME).so
|
||||
|
||||
%.o: %.c $(INCLS)
|
||||
$(CC) $(CFLAGS) -fpic -c $< -o $@
|
||||
|
||||
+%.lo: %.c $(INCLS)
|
||||
+ $(CC) $(CFLAGS) -c $< -o $@
|
||||
+
|
||||
install: all
|
||||
mkdir -p -m 0755 $(INCDIR)/sys
|
||||
install -m 0644 include/sys/capability.h $(INCDIR)/sys
|
||||
mkdir -p -m 0755 $(LIBDIR)
|
||||
+ install -m 0644 $(LIBNAME).a $(LIBDIR)
|
||||
install -m 0644 $(MINLIBNAME) $(LIBDIR)/$(MINLIBNAME)
|
||||
ln -sf $(MINLIBNAME) $(LIBDIR)/$(MAJLIBNAME)
|
||||
- ln -sf $(MAJLIBNAME) $(LIBDIR)/$(LIBNAME)
|
||||
+ ln -sf $(MAJLIBNAME) $(LIBDIR)/$(LIBNAME).so
|
||||
-/sbin/ldconfig
|
||||
|
||||
clean:
|
||||
$(LOCALCLEAN)
|
||||
- rm -f $(OBJS) $(LIBNAME)*
|
||||
+ rm -f $(OBJS) $(LOBJS) $(LIBNAME).a $(LIBNAME).so*
|
||||
rm -f cap_names.h cap_names.sed _makenames
|
||||
cd include/sys && $(LOCALCLEAN)
|
||||
|
||||
--- libcap-1.10/libcap/_makenames.c.debian 1999-05-14 06:46:15.000000000 +0200
|
||||
+++ libcap-1.10/libcap/_makenames.c 2007-02-21 14:56:33.000000000 +0100
|
||||
@@ -9,7 +9,7 @@
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
-#include <linux/capability.h>
|
||||
+#include <sys/capability.h>
|
||||
|
||||
/*
|
||||
* #include 'sed' generated array
|
||||
--- libcap-1.10/libcap/include/sys/capability.h.debian 2007-02-21 14:56:45.000000000 +0100
|
||||
+++ libcap-1.10/libcap/include/sys/capability.h 2007-02-21 14:58:18.000000000 +0100
|
||||
@@ -24,14 +24,286 @@
|
||||
#include <stdint.h>
|
||||
|
||||
/*
|
||||
- * Make sure we can be included from userland by preventing
|
||||
- * capability.h from including other kernel headers
|
||||
- */
|
||||
-#define _LINUX_TYPES_H
|
||||
-#define _LINUX_FS_H
|
||||
-typedef unsigned int __u32;
|
||||
+ * This is <linux/capability.h>
|
||||
+ *
|
||||
+ * Andrew G. Morgan <morgan@transmeta.com>
|
||||
+ * Alexander Kjeldaas <astor@guardian.no>
|
||||
+ * with help from Aleph1, Roland Buresund and Andrew Main.
|
||||
+ *
|
||||
+ * See here for the libcap library ("POSIX draft" compliance):
|
||||
+ *
|
||||
+ * ftp://linux.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.2/
|
||||
+ */
|
||||
+
|
||||
+#ifndef _LINUX_CAPABILITY_H
|
||||
+#define _LINUX_CAPABILITY_H
|
||||
+
|
||||
+#include <linux/types.h>
|
||||
+/*#include <linux/fs.h>*/
|
||||
+
|
||||
+/* User-level do most of the mapping between kernel and user
|
||||
+ capabilities based on the version tag given by the kernel. The
|
||||
+ kernel might be somewhat backwards compatible, but don't bet on
|
||||
+ it. */
|
||||
+
|
||||
+/* XXX - Note, cap_t, is defined by POSIX to be an "opaque" pointer to
|
||||
+ a set of three capability sets. The transposition of 3*the
|
||||
+ following structure to such a composite is better handled in a user
|
||||
+ library since the draft standard requires the use of malloc/free
|
||||
+ etc.. */
|
||||
+
|
||||
+#define _LINUX_CAPABILITY_VERSION 0x19980330
|
||||
+
|
||||
+typedef struct __user_cap_header_struct {
|
||||
+ __u32 version;
|
||||
+ int pid;
|
||||
+} *cap_user_header_t;
|
||||
+
|
||||
+typedef struct __user_cap_data_struct {
|
||||
+ __u32 effective;
|
||||
+ __u32 permitted;
|
||||
+ __u32 inheritable;
|
||||
+} *cap_user_data_t;
|
||||
+
|
||||
+#ifdef __KERNEL__
|
||||
+
|
||||
+/* #define STRICT_CAP_T_TYPECHECKS */
|
||||
+
|
||||
+#ifdef STRICT_CAP_T_TYPECHECKS
|
||||
+
|
||||
+typedef struct kernel_cap_struct {
|
||||
+ __u32 cap;
|
||||
+} kernel_cap_t;
|
||||
+
|
||||
+#else
|
||||
+
|
||||
+typedef __u32 kernel_cap_t;
|
||||
+
|
||||
+#endif
|
||||
+
|
||||
+#define _USER_CAP_HEADER_SIZE (2*sizeof(__u32))
|
||||
+#define _KERNEL_CAP_T_SIZE (sizeof(kernel_cap_t))
|
||||
+
|
||||
+#endif
|
||||
+
|
||||
+
|
||||
+/**
|
||||
+ ** POSIX-draft defined capabilities.
|
||||
+ **/
|
||||
+
|
||||
+/* In a system with the [_POSIX_CHOWN_RESTRICTED] option defined, this
|
||||
+ overrides the restriction of changing file ownership and group
|
||||
+ ownership. */
|
||||
+
|
||||
+#define CAP_CHOWN 0
|
||||
+
|
||||
+/* Override all DAC access, including ACL execute access if
|
||||
+ [_POSIX_ACL] is defined. Excluding DAC access covered by
|
||||
+ CAP_LINUX_IMMUTABLE. */
|
||||
+
|
||||
+#define CAP_DAC_OVERRIDE 1
|
||||
+
|
||||
+/* Overrides all DAC restrictions regarding read and search on files
|
||||
+ and directories, including ACL restrictions if [_POSIX_ACL] is
|
||||
+ defined. Excluding DAC access covered by CAP_LINUX_IMMUTABLE. */
|
||||
+
|
||||
+#define CAP_DAC_READ_SEARCH 2
|
||||
+
|
||||
+/* Overrides all restrictions about allowed operations on files, where
|
||||
+ file owner ID must be equal to the user ID, except where CAP_FSETID
|
||||
+ is applicable. It doesn't override MAC and DAC restrictions. */
|
||||
+
|
||||
+#define CAP_FOWNER 3
|
||||
+
|
||||
+/* Overrides the following restrictions that the effective user ID
|
||||
+ shall match the file owner ID when setting the S_ISUID and S_ISGID
|
||||
+ bits on that file; that the effective group ID (or one of the
|
||||
+ supplementary group IDs) shall match the file owner ID when setting
|
||||
+ the S_ISGID bit on that file; that the S_ISUID and S_ISGID bits are
|
||||
+ cleared on successful return from chown(2) (not implemented). */
|
||||
+
|
||||
+#define CAP_FSETID 4
|
||||
+
|
||||
+/* Used to decide between falling back on the old suser() or fsuser(). */
|
||||
+
|
||||
+#define CAP_FS_MASK 0x1f
|
||||
+
|
||||
+/* Overrides the restriction that the real or effective user ID of a
|
||||
+ process sending a signal must match the real or effective user ID
|
||||
+ of the process receiving the signal. */
|
||||
+
|
||||
+#define CAP_KILL 5
|
||||
+
|
||||
+/* Allows setgid(2) manipulation */
|
||||
+/* Allows setgroups(2) */
|
||||
+/* Allows forged gids on socket credentials passing. */
|
||||
+
|
||||
+#define CAP_SETGID 6
|
||||
+
|
||||
+/* Allows set*uid(2) manipulation (including fsuid). */
|
||||
+/* Allows forged pids on socket credentials passing. */
|
||||
+
|
||||
+#define CAP_SETUID 7
|
||||
+
|
||||
+
|
||||
+/**
|
||||
+ ** Linux-specific capabilities
|
||||
+ **/
|
||||
+
|
||||
+/* Transfer any capability in your permitted set to any pid,
|
||||
+ remove any capability in your permitted set from any pid */
|
||||
+
|
||||
+#define CAP_SETPCAP 8
|
||||
+
|
||||
+/* Allow modification of S_IMMUTABLE and S_APPEND file attributes */
|
||||
+
|
||||
+#define CAP_LINUX_IMMUTABLE 9
|
||||
+
|
||||
+/* Allows binding to TCP/UDP sockets below 1024 */
|
||||
+/* Allows binding to ATM VCIs below 32 */
|
||||
+
|
||||
+#define CAP_NET_BIND_SERVICE 10
|
||||
+
|
||||
+/* Allow broadcasting, listen to multicast */
|
||||
+
|
||||
+#define CAP_NET_BROADCAST 11
|
||||
+
|
||||
+/* Allow interface configuration */
|
||||
+/* Allow administration of IP firewall, masquerading and accounting */
|
||||
+/* Allow setting debug option on sockets */
|
||||
+/* Allow modification of routing tables */
|
||||
+/* Allow setting arbitrary process / process group ownership on
|
||||
+ sockets */
|
||||
+/* Allow binding to any address for transparent proxying */
|
||||
+/* Allow setting TOS (type of service) */
|
||||
+/* Allow setting promiscuous mode */
|
||||
+/* Allow clearing driver statistics */
|
||||
+/* Allow multicasting */
|
||||
+/* Allow read/write of device-specific registers */
|
||||
+/* Allow activation of ATM control sockets */
|
||||
+
|
||||
+#define CAP_NET_ADMIN 12
|
||||
+
|
||||
+/* Allow use of RAW sockets */
|
||||
+/* Allow use of PACKET sockets */
|
||||
+
|
||||
+#define CAP_NET_RAW 13
|
||||
+
|
||||
+/* Allow locking of shared memory segments */
|
||||
+/* Allow mlock and mlockall (which doesn't really have anything to do
|
||||
+ with IPC) */
|
||||
+
|
||||
+#define CAP_IPC_LOCK 14
|
||||
+
|
||||
+/* Override IPC ownership checks */
|
||||
+
|
||||
+#define CAP_IPC_OWNER 15
|
||||
+
|
||||
+/* Insert and remove kernel modules - modify kernel without limit */
|
||||
+/* Modify cap_bset */
|
||||
+#define CAP_SYS_MODULE 16
|
||||
+
|
||||
+/* Allow ioperm/iopl access */
|
||||
+/* Allow sending USB messages to any device via /proc/bus/usb */
|
||||
+
|
||||
+#define CAP_SYS_RAWIO 17
|
||||
+
|
||||
+/* Allow use of chroot() */
|
||||
+
|
||||
+#define CAP_SYS_CHROOT 18
|
||||
+
|
||||
+/* Allow ptrace() of any process */
|
||||
+
|
||||
+#define CAP_SYS_PTRACE 19
|
||||
+
|
||||
+/* Allow configuration of process accounting */
|
||||
+
|
||||
+#define CAP_SYS_PACCT 20
|
||||
+
|
||||
+/* Allow configuration of the secure attention key */
|
||||
+/* Allow administration of the random device */
|
||||
+/* Allow examination and configuration of disk quotas */
|
||||
+/* Allow configuring the kernel's syslog (printk behaviour) */
|
||||
+/* Allow setting the domainname */
|
||||
+/* Allow setting the hostname */
|
||||
+/* Allow calling bdflush() */
|
||||
+/* Allow mount() and umount(), setting up new smb connection */
|
||||
+/* Allow some autofs root ioctls */
|
||||
+/* Allow nfsservctl */
|
||||
+/* Allow VM86_REQUEST_IRQ */
|
||||
+/* Allow to read/write pci config on alpha */
|
||||
+/* Allow irix_prctl on mips (setstacksize) */
|
||||
+/* Allow flushing all cache on m68k (sys_cacheflush) */
|
||||
+/* Allow removing semaphores */
|
||||
+/* Used instead of CAP_CHOWN to "chown" IPC message queues, semaphores
|
||||
+ and shared memory */
|
||||
+/* Allow locking/unlocking of shared memory segment */
|
||||
+/* Allow turning swap on/off */
|
||||
+/* Allow forged pids on socket credentials passing */
|
||||
+/* Allow setting readahead and flushing buffers on block devices */
|
||||
+/* Allow setting geometry in floppy driver */
|
||||
+/* Allow turning DMA on/off in xd driver */
|
||||
+/* Allow administration of md devices (mostly the above, but some
|
||||
+ extra ioctls) */
|
||||
+/* Allow tuning the ide driver */
|
||||
+/* Allow access to the nvram device */
|
||||
+/* Allow administration of apm_bios, serial and bttv (TV) device */
|
||||
+/* Allow manufacturer commands in isdn CAPI support driver */
|
||||
+/* Allow reading non-standardized portions of pci configuration space */
|
||||
+/* Allow DDI debug ioctl on sbpcd driver */
|
||||
+/* Allow setting up serial ports */
|
||||
+/* Allow sending raw qic-117 commands */
|
||||
+/* Allow enabling/disabling tagged queuing on SCSI controllers and sending
|
||||
+ arbitrary SCSI commands */
|
||||
+/* Allow setting encryption key on loopback filesystem */
|
||||
+
|
||||
+#define CAP_SYS_ADMIN 21
|
||||
+
|
||||
+/* Allow use of reboot() */
|
||||
+
|
||||
+#define CAP_SYS_BOOT 22
|
||||
+
|
||||
+/* Allow raising priority and setting priority on other (different
|
||||
+ UID) processes */
|
||||
+/* Allow use of FIFO and round-robin (realtime) scheduling on own
|
||||
+ processes and setting the scheduling algorithm used by another
|
||||
+ process. */
|
||||
+
|
||||
+#define CAP_SYS_NICE 23
|
||||
+
|
||||
+/* Override resource limits. Set resource limits. */
|
||||
+/* Override quota limits. */
|
||||
+/* Override reserved space on ext2 filesystem */
|
||||
+/* NOTE: ext2 honors fsuid when checking for resource overrides, so
|
||||
+ you can override using fsuid too */
|
||||
+/* Override size restrictions on IPC message queues */
|
||||
+/* Allow more than 64hz interrupts from the real-time clock */
|
||||
+/* Override max number of consoles on console allocation */
|
||||
+/* Override max number of keymaps */
|
||||
+
|
||||
+#define CAP_SYS_RESOURCE 24
|
||||
+
|
||||
+/* Allow manipulation of system clock */
|
||||
+/* Allow irix_stime on mips */
|
||||
+/* Allow setting the real-time clock */
|
||||
+
|
||||
+#define CAP_SYS_TIME 25
|
||||
+
|
||||
+/* Allow configuration of tty devices */
|
||||
+/* Allow vhangup() of tty */
|
||||
+
|
||||
+#define CAP_SYS_TTY_CONFIG 26
|
||||
+
|
||||
+/* Allow the privileged aspects of mknod() */
|
||||
+
|
||||
+#define CAP_MKNOD 27
|
||||
+
|
||||
+/* Allow taking of leases on files */
|
||||
+
|
||||
+#define CAP_LEASE 28
|
||||
+
|
||||
+#endif /* !_LINUX_CAPABILITY_H */
|
||||
|
||||
-#include <linux/capability.h>
|
||||
|
||||
/*
|
||||
* POSIX capability types
|
||||
15
libcap-1.10-fPIC.patch
Normal file
15
libcap-1.10-fPIC.patch
Normal file
|
|
@ -0,0 +1,15 @@
|
|||
--- libcap-1.10/libcap/Makefile.rh2 2007-02-21 15:21:12.000000000 +0100
|
||||
+++ libcap-1.10/libcap/Makefile 2007-02-21 15:22:00.000000000 +0100
|
||||
@@ -65,10 +65,10 @@
|
||||
ln -sf $(MAJLIBNAME) $(LIBNAME).so
|
||||
|
||||
%.o: %.c $(INCLS)
|
||||
- $(CC) $(CFLAGS) -fpic -c $< -o $@
|
||||
+ $(CC) $(CFLAGS) -fPIC -c $< -o $@
|
||||
|
||||
%.lo: %.c $(INCLS)
|
||||
- $(CC) $(CFLAGS) -c $< -o $@
|
||||
+ $(CC) $(CFLAGS) -fPIC -c $< -o $@
|
||||
|
||||
install: all
|
||||
mkdir -p -m 0755 $(INCDIR)/sys
|
||||
47
libcap-1.10-ia64.patch
Normal file
47
libcap-1.10-ia64.patch
Normal file
|
|
@ -0,0 +1,47 @@
|
|||
--- libcap-1.10/libcap/cap_sys.c.ia64 Mon May 21 16:23:27 2001
|
||||
+++ libcap-1.10/libcap/cap_sys.c Mon May 21 16:24:09 2001
|
||||
@@ -11,14 +11,6 @@
|
||||
#define __LIBRARY__
|
||||
#include <linux/unistd.h>
|
||||
|
||||
-_syscall2(int, capget,
|
||||
- cap_user_header_t, header,
|
||||
- cap_user_data_t, data)
|
||||
-
|
||||
-_syscall2(int, capset,
|
||||
- cap_user_header_t, header,
|
||||
- const cap_user_data_t, data)
|
||||
-
|
||||
/*
|
||||
* $Log: libcap-1.10-ia64.patch,v $
|
||||
* Revision 1.1 2004/09/09 07:21:23 cvsdist
|
||||
* auto-import changelog data from libcap-1.10-4.src.rpm
|
||||
* * Tue Jul 10 2001 Jakub Jelinek <jakub@redhat.com>
|
||||
* - don't build libcap.so.1 with ld -shared, but gcc -shared
|
||||
*
|
||||
* * Wed Jun 20 2001 Trond Eivind Glomsrød <teg@redhat.com>
|
||||
* - Rebuild - it was missing for alpha
|
||||
*
|
||||
* * Wed Jun 06 2001 Florian La Roche <Florian.LaRoche@redhat.de>
|
||||
* - add s390/s390x support
|
||||
*
|
||||
* * Thu May 17 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-1
|
||||
* - initial RPM
|
||||
* - fix build on ia64
|
||||
*
|
||||
* Revision 1.1.1.1 1999/04/17 22:16:31 morgan
|
||||
--- libcap-1.10/Make.Rules.ia64 Mon May 21 16:22:08 2001
|
||||
+++ libcap-1.10/Make.Rules Mon May 21 16:22:32 2001
|
||||
@@ -44,10 +44,10 @@
|
||||
CC=gcc
|
||||
COPTFLAGS=-O2
|
||||
DEBUG=-g #-DDEBUG
|
||||
-WARNINGS=-ansi -D_POSIX_SOURCE -Wall -Wwrite-strings \
|
||||
+WARNINGS=-D_POSIX_SOURCE -Wall -Wwrite-strings \
|
||||
-Wpointer-arith -Wcast-qual -Wcast-align \
|
||||
-Wtraditional -Wstrict-prototypes -Wmissing-prototypes \
|
||||
- -Wnested-externs -Winline -Wshadow -pedantic
|
||||
+ -Wnested-externs -Winline -Wshadow
|
||||
LD=ld
|
||||
LDFLAGS=-s #-g
|
||||
|
||||
38
libcap-1.10-nostaticlib.patch
Normal file
38
libcap-1.10-nostaticlib.patch
Normal file
|
|
@ -0,0 +1,38 @@
|
|||
--- libcap-1.10/libcap/Makefile.rh1 2007-02-21 15:00:01.000000000 +0100
|
||||
+++ libcap-1.10/libcap/Makefile 2007-02-21 15:00:53.000000000 +0100
|
||||
@@ -45,7 +45,7 @@
|
||||
MAJLIBNAME=$(LIBNAME).so.$(VERSION)
|
||||
MINLIBNAME=$(MAJLIBNAME).$(MINOR)
|
||||
|
||||
-all: $(MINLIBNAME) $(LIBNAME).a
|
||||
+all: $(MINLIBNAME)
|
||||
|
||||
_makenames: _makenames.c cap_names.sed
|
||||
$(CC) $(CFLAGS) $(LDFLAGS) $< -o $@
|
||||
@@ -59,9 +59,6 @@
|
||||
@sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define \([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < include/sys/capability.h | fgrep -v 0x > cap_names.sed
|
||||
# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||
|
||||
-$(LIBNAME).a: $(OBJS)
|
||||
- ar cruv $(LIBNAME).a $(OBJS)
|
||||
-
|
||||
$(MINLIBNAME): $(LOBJS)
|
||||
$(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -fPIC -o $@ $(LOBJS)
|
||||
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||
@@ -77,7 +74,6 @@
|
||||
mkdir -p -m 0755 $(INCDIR)/sys
|
||||
install -m 0644 include/sys/capability.h $(INCDIR)/sys
|
||||
mkdir -p -m 0755 $(LIBDIR)
|
||||
- install -m 0644 $(LIBNAME).a $(LIBDIR)
|
||||
install -m 0644 $(MINLIBNAME) $(LIBDIR)/$(MINLIBNAME)
|
||||
ln -sf $(MINLIBNAME) $(LIBDIR)/$(MAJLIBNAME)
|
||||
ln -sf $(MAJLIBNAME) $(LIBDIR)/$(LIBNAME).so
|
||||
@@ -85,7 +81,7 @@
|
||||
|
||||
clean:
|
||||
$(LOCALCLEAN)
|
||||
- rm -f $(OBJS) $(LOBJS) $(LIBNAME).a $(LIBNAME).so*
|
||||
+ rm -f $(OBJS) $(LOBJS) $(LIBNAME).so*
|
||||
rm -f cap_names.h cap_names.sed _makenames
|
||||
cd include/sys && $(LOCALCLEAN)
|
||||
|
||||
17
libcap-1.10-shared.patch
Normal file
17
libcap-1.10-shared.patch
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
--- libcap-1.11/libcap/Makefile.shared 1999-04-17 18:16:31.000000000 -0400
|
||||
+++ libcap-1.11/libcap/Makefile 2002-07-19 06:24:23.000000000 -0400
|
||||
@@ -56,12 +56,12 @@ cap_names.sed: Makefile /usr/include/lin
|
||||
# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||
|
||||
$(MINLIBNAME): $(OBJS)
|
||||
- $(LD) -soname $(MAJLIBNAME) -x -shared -o $@ $(OBJS)
|
||||
+ $(CC) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||
ln -sf $(MAJLIBNAME) $(LIBNAME)
|
||||
|
||||
%.o: %.c $(INCLS)
|
||||
- $(CC) $(CFLAGS) -c $< -o $@
|
||||
+ $(CC) $(CFLAGS) -fpic -c $< -o $@
|
||||
|
||||
install: all
|
||||
mkdir -p -m 0755 $(INCDIR)/sys
|
||||
22
libcap-1.10-useCFLAGSwithCC.patch
Normal file
22
libcap-1.10-useCFLAGSwithCC.patch
Normal file
|
|
@ -0,0 +1,22 @@
|
|||
--- libcap-1.10/libcap/Makefile.BAD 2006-07-13 20:42:35.000000000 -0400
|
||||
+++ libcap-1.10/libcap/Makefile 2006-07-13 20:42:53.000000000 -0400
|
||||
@@ -56,7 +56,7 @@
|
||||
# @sed -ne '/^#define[ \t]CAP[_A-Z]\+[ \t]\+[0-9]\+/{s/^#define CAP_\([^ \t]*\)[ \t]*\([^ \t]*\)/ \{ \2, \"\1\" \},/;y/ABCDEFGHIJKLMNOPQRSTUVWXYZ/abcdefghijklmnopqrstuvwxyz/;p;}' < /usr/include/linux/capability.h | fgrep -v 0x > cap_names.sed
|
||||
|
||||
$(MINLIBNAME): $(OBJS)
|
||||
- $(CC) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||
+ $(CC) $(COPTFLAG) -Wl,-soname,$(MAJLIBNAME) -Wl,-x -shared -o $@ $(OBJS)
|
||||
ln -sf $(MINLIBNAME) $(MAJLIBNAME)
|
||||
ln -sf $(MAJLIBNAME) $(LIBNAME)
|
||||
|
||||
--- libcap-1.10/progs/Makefile.BAD 2006-07-13 20:48:44.000000000 -0400
|
||||
+++ libcap-1.10/progs/Makefile 2006-07-13 20:48:54.000000000 -0400
|
||||
@@ -36,7 +36,7 @@
|
||||
all: $(PROGS)
|
||||
|
||||
$(PROGS): %: %.o
|
||||
- $(CC) $(LDFLAGS) -o $@ $< $(LIBS)
|
||||
+ $(CC) $(COPTFLAG) $(LDFLAGS) -o $@ $< $(LIBS)
|
||||
|
||||
%.o: %.c $(INCS)
|
||||
$(CC) $(CFLAGS) -c $< -o $@
|
||||
19
libcap-1.10-userland.patch
Normal file
19
libcap-1.10-userland.patch
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
--- libcap-1.10/libcap/include/sys/capability.h.foo Fri Nov 9 16:26:25 2001
|
||||
+++ libcap-1.10/libcap/include/sys/capability.h Fri Nov 9 16:28:47 2001
|
||||
@@ -21,6 +21,16 @@
|
||||
*/
|
||||
|
||||
#include <sys/types.h>
|
||||
+#include <stdint.h>
|
||||
+
|
||||
+/*
|
||||
+ * Make sure we can be included from userland by preventing
|
||||
+ * capability.h from including other kernel headers
|
||||
+ */
|
||||
+#define _LINUX_TYPES_H
|
||||
+#define _LINUX_FS_H
|
||||
+typedef unsigned int __u32;
|
||||
+
|
||||
#include <linux/capability.h>
|
||||
|
||||
/*
|
||||
194
libcap.spec
Normal file
194
libcap.spec
Normal file
|
|
@ -0,0 +1,194 @@
|
|||
Name: libcap
|
||||
Version: 1.10
|
||||
Release: 29
|
||||
Summary: Library for getting and setting POSIX.1e capabilities
|
||||
Source: ftp://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.4/%{name}-%{version}.tar.bz2
|
||||
Source1: http://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.4/capfaq-0.2.txt
|
||||
URL: http://ftp.kernel.org/pub/linux/libs/security/linux-privs/kernel-2.4/
|
||||
License: BSD-like and LGPL
|
||||
Patch1: libcap-1.10-userland.patch
|
||||
Patch2: libcap-1.10-shared.patch
|
||||
Patch3: libcap-1.10-useCFLAGSwithCC.patch
|
||||
Patch4: libcap-1.10-debian.patch
|
||||
Patch5: libcap-1.10-nostaticlib.patch
|
||||
Patch6: libcap-1.10-fPIC.patch
|
||||
Patch7: libcap-1.10-audit.patch
|
||||
Group: System Environment/Libraries
|
||||
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
||||
Requires(post): /sbin/ldconfig
|
||||
Requires(postun): /sbin/ldconfig
|
||||
|
||||
%description
|
||||
libcap is a library for getting and setting POSIX.1e (formerly POSIX 6)
|
||||
draft 15 capabilities.
|
||||
|
||||
%package devel
|
||||
Summary: Development files for libcap
|
||||
Group: Development/Libraries
|
||||
Requires: %{name} = %{version}-%{release}
|
||||
|
||||
%description devel
|
||||
Development files (Headers, libraries for static linking, etc) for libcap.
|
||||
|
||||
libcap is a library for getting and setting POSIX.1e (formerly POSIX 6)
|
||||
draft 15 capabilities.
|
||||
|
||||
Install libcap-devel if you want to develop or compile applications using
|
||||
libcap.
|
||||
|
||||
%prep
|
||||
%setup -q
|
||||
%patch1 -p1
|
||||
%patch2 -p1
|
||||
%patch3 -p1
|
||||
%patch4 -p1
|
||||
%patch5 -p1
|
||||
%patch6 -p1
|
||||
%patch7 -p1
|
||||
|
||||
%build
|
||||
make PREFIX=%{_prefix} LIBDIR=%{_libdir} SBINDIR=%{_sbindir} \
|
||||
INCDIR=%{_includedir} MANDIR=%{_mandir} COPTFLAG="$RPM_OPT_FLAGS" \
|
||||
%{?_smp_mflags}
|
||||
|
||||
%install
|
||||
rm -rf ${RPM_BUILD_ROOT}
|
||||
make install DESTDIR=${RPM_BUILD_ROOT} \
|
||||
LIBDIR=${RPM_BUILD_ROOT}/%{_lib} \
|
||||
SBINDIR=${RPM_BUILD_ROOT}/%{_sbindir} \
|
||||
INCDIR=${RPM_BUILD_ROOT}/%{_includedir} \
|
||||
MANDIR=${RPM_BUILD_ROOT}/%{_mandir}/ \
|
||||
COPTFLAG="$RPM_OPT_FLAGS"
|
||||
mkdir -p ${RPM_BUILD_ROOT}/%{_mandir}/man{2,3,8}
|
||||
mv -f doc/*.2 ${RPM_BUILD_ROOT}/%{_mandir}/man2/
|
||||
mv -f doc/*.3 ${RPM_BUILD_ROOT}/%{_mandir}/man3/
|
||||
cp %{SOURCE1} doc/
|
||||
|
||||
chmod +x ${RPM_BUILD_ROOT}/%{_lib}/*.so.*
|
||||
|
||||
%post -p /sbin/ldconfig
|
||||
%postun -p /sbin/ldconfig
|
||||
|
||||
%files
|
||||
%defattr(-,root,root)
|
||||
/%{_lib}/*.so.*
|
||||
%{_sbindir}/*
|
||||
%doc doc/capability.notes doc/capfaq-0.2.txt
|
||||
|
||||
%files devel
|
||||
%defattr(-,root,root)
|
||||
%{_includedir}/*
|
||||
/%{_lib}/*.so
|
||||
%{_mandir}/man2/*
|
||||
%{_mandir}/man3/*
|
||||
|
||||
%clean
|
||||
rm -rf ${RPM_BUILD_ROOT}
|
||||
|
||||
%changelog
|
||||
* Fri Feb 23 2007 Karsten Hopp <karsten@redhat.com> 1.10-29
|
||||
- add CAP_AUDIT_WRITE and CAP_AUDIT_CONTROL (#229833)
|
||||
|
||||
* Wed Feb 21 2007 Karsten Hopp <karsten@redhat.com> 1.10-28
|
||||
- drop obsolete ia64 patch
|
||||
- rpmlint fixes
|
||||
|
||||
* Wed Feb 21 2007 Karsten Hopp <karsten@redhat.com> 1.10-27
|
||||
- misc. review fixes
|
||||
- add debian patch to make it build with a recent glibc
|
||||
- remove static lib
|
||||
|
||||
* Wed Jul 19 2006 Karsten Hopp <karsten@redhat.de> 1.10-25
|
||||
- add patch to support COPTFLAG (#199365)
|
||||
|
||||
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 1.10-24.2.1
|
||||
- rebuild
|
||||
|
||||
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 1.10-24.2
|
||||
- bump again for double-long bug on ppc(64)
|
||||
|
||||
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 1.10-24.1
|
||||
- rebuilt for new gcc4.1 snapshot and glibc changes
|
||||
|
||||
* Mon Dec 19 2005 Karsten Hopp <karsten@redhat.de> 1.10-24
|
||||
- added development manpages
|
||||
- as there are no manpages for the executables available, added at least
|
||||
a FAQ (#172324)
|
||||
|
||||
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Mon Oct 31 2005 Steve Grubb <sgrubb@redhat.com> 1.10-23
|
||||
- rebuild to pick up audit capabilities
|
||||
|
||||
* Wed Mar 02 2005 Karsten Hopp <karsten@redhat.de> 1.10-22
|
||||
- build with gcc-4
|
||||
|
||||
* Wed Feb 09 2005 Karsten Hopp <karsten@redhat.de> 1.10-21
|
||||
- rebuilt
|
||||
|
||||
* Tue Aug 31 2004 Phil Knirsch <pknirsch@redhat.com> 1.10-20
|
||||
- Fix wrong typedef in userland patch (#98801)
|
||||
|
||||
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Tue Mar 02 2004 Elliot Lee <sopwith@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Tue Jan 27 2004 Karsten Hopp <karsten@redhat.de> 1.10-17
|
||||
- use _manpath
|
||||
|
||||
* Wed Jun 04 2003 Elliot Lee <sopwith@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Wed Jan 22 2003 Tim Powers <timp@redhat.com>
|
||||
- rebuilt
|
||||
|
||||
* Sat Jan 4 2003 Jeff Johnson <jbj@redhat.com> 1.10-14
|
||||
- set execute bits on library so that requires are generated.
|
||||
|
||||
* Thu Nov 21 2002 Mike A. Harris <mharris@redhat.com> 1.10-13
|
||||
- Removed %%name macro sillyness from package Summary, description text, etc.
|
||||
- Removed archaic Prefix: tag
|
||||
- lib64 fixes everywhere to use _lib, _libdir, etc
|
||||
- Removed deletion of RPM_BUILD_DIR from %%clean section
|
||||
- Added -q flag to setup macro
|
||||
- Severely cleaned up spec file, and removed usage of perl
|
||||
|
||||
* Fri Jul 19 2002 Jakub Jelinek <jakub@redhat.com> 1.10-12
|
||||
- CFLAGS was using COPTFLAG variable, not COPTFLAGS
|
||||
- build with -fpic
|
||||
- apply the IA-64 patch everywhere, use capget/capset from glibc,
|
||||
not directly as _syscall (as it is broken on IA-32 with -fpic)
|
||||
- reenable alpha
|
||||
|
||||
* Fri Jun 21 2002 Tim Powers <timp@redhat.com>
|
||||
- automated rebuild
|
||||
|
||||
* Wed May 29 2002 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-10
|
||||
- Exclude alpha for now, apparent gcc bug.
|
||||
|
||||
* Fri Nov 9 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-6
|
||||
- Fix sys/capabilities.h header (#55727)
|
||||
- Move to /lib, some applications seem to be using this rather early
|
||||
(#55733)
|
||||
|
||||
* Mon Jul 16 2001 Trond Eivind Glomsrød <teg@redhat.com>
|
||||
- Add post,postun scripts
|
||||
|
||||
* Tue Jul 10 2001 Jakub Jelinek <jakub@redhat.com>
|
||||
- don't build libcap.so.1 with ld -shared, but gcc -shared
|
||||
|
||||
* Wed Jun 20 2001 Trond Eivind Glomsrød <teg@redhat.com>
|
||||
- Rebuild - it was missing for alpha
|
||||
|
||||
* Wed Jun 06 2001 Florian La Roche <Florian.LaRoche@redhat.de>
|
||||
- add s390/s390x support
|
||||
|
||||
* Thu May 17 2001 Bernhard Rosenkraenzer <bero@redhat.com> 1.10-1
|
||||
- initial RPM
|
||||
- fix build on ia64
|
||||
1
sources
1
sources
|
|
@ -0,0 +1 @@
|
|||
4426a413128142cab89eb2e6f13d8571 libcap-1.10.tar.bz2
|
||||
Loading…
Add table
Add a link
Reference in a new issue