Compare commits

..

41 commits

Author SHA1 Message Date
Richard W.M. Jones
cc66c46430 Merge remote-tracking branch 'origin/f30' into f29 2019-09-20 15:25:09 +01:00
Richard W.M. Jones
fe211a736a New upstream version 1.12.8.
Fixes second Denial of Service attack:
  https://www.redhat.com/archives/libguestfs/2019-September/msg00272.html
2019-09-20 15:24:24 +01:00
Richard W.M. Jones
4e660a995c Merge remote-tracking branch 'origin/f30' into f29 2019-09-12 18:48:02 +01:00
Richard W.M. Jones
7c1d7e123a New upstream version 1.12.7.
Fixes Denial of Service / Amplication Attack:
  https://www.redhat.com/archives/libguestfs/2019-September/msg00084.html
2019-09-12 18:47:38 +01:00
Richard W.M. Jones
da0254d5cb Merge remote-tracking branch 'origin/f30' into f29 2019-08-29 13:46:58 +01:00
Richard W.M. Jones
cf53426d08 New stable version 1.12.6. 2019-08-29 13:21:24 +01:00
Richard W.M. Jones
a34b33e5e0 Add provides for all basic plugins and filters.
(cherry picked from commit 331127737a)

For Fedora 29/30: Modified this to exclude the filters which are not
present in 1.12.
2019-08-29 13:10:32 +01:00
Richard W.M. Jones
c339d6bab7 Merge remote-tracking branch 'origin/f30' into f29 2019-08-02 13:48:57 +01:00
Richard W.M. Jones
97d61bff8a New stable version 1.12.5. 2019-08-02 13:48:21 +01:00
Richard W.M. Jones
fb35641328 Merge remote-tracking branch 'origin/f30' into f29 2019-07-26 10:56:02 +01:00
Richard W.M. Jones
d473b43527 New stable version 1.12.4. 2019-07-26 10:55:25 +01:00
Richard W.M. Jones
a2cb81da66 Merge remote-tracking branch 'origin/f30' into f29 2019-05-22 16:13:25 +01:00
Richard W.M. Jones
b3f9252811 New stable version 1.12.3. 2019-05-21 11:24:25 +01:00
Richard W.M. Jones
e737090f99 New stable version 1.12.2.
Distribute BENCHMARKING and SECURITY files.
Includes a fix for possible remote memory heap leak with user plugins.
2019-04-23 18:03:53 +01:00
Richard W.M. Jones
fbcb60f7b4 New upstream version 1.12.1. 2019-04-13 08:27:25 +01:00
Richard W.M. Jones
321197087d New upstream version 1.12.0.
Add noextents filter.

(cherry picked from commit 08e33b1f6d)
2019-04-10 13:45:44 +01:00
Richard W.M. Jones
5765a7dc6f New upstream version 1.11.15.
(cherry picked from commit 543e91948e)
2019-04-08 21:36:24 +01:00
Richard W.M. Jones
0f020dc1b1 New upstream version 1.11.14.
Remove deprecated nbdkit-xz-plugin (replaced by nbdkit-xz-filter).

(cherry picked from commit a7dbaded7d)
2019-04-06 16:18:12 +01:00
Richard W.M. Jones
18a7816b40 New upstream version 1.11.13.
(cherry picked from commit f2d242ec5d)
2019-04-02 22:14:59 +01:00
Richard W.M. Jones
7aff272652 New upstream version 1.10.4. 2019-04-02 12:54:18 +01:00
Richard W.M. Jones
7ad75a1b51 New upstream version 1.11.12.
New nbdkit-readahead-filter.

(cherry picked from commit 4e9723a107)
2019-04-02 12:14:12 +01:00
Richard W.M. Jones
e96c9ca23f New upstream version 1.11.11.
(cherry picked from commit 929d1f7a4e)
2019-03-29 13:55:03 +00:00
Richard W.M. Jones
306c612279 New upstream version 1.11.10.
(cherry picked from commit 60d0fe0e68)
2019-03-28 16:37:45 +00:00
Richard W.M. Jones
b459bddaad Forgot to upload sources to previous commit.
(cherry picked from commit 74708da224)
2019-03-23 12:19:31 +00:00
Richard W.M. Jones
50976ce9cb New upstream version 1.11.9.
(cherry picked from commit ff7421fe0e)
2019-03-23 12:16:28 +00:00
Richard W.M. Jones
2e222f7a50 +BR ssh-keygen.
(cherry picked from commit 214b66bb6f)
2019-03-12 22:22:47 +00:00
Richard W.M. Jones
719ba52061 tests: Use a more robust method to create the test disk atomically.
(cherry picked from commit 43f581b434)
2019-03-12 22:22:42 +00:00
Richard W.M. Jones
6054a9a50e New upstream version 1.11.8.
(cherry picked from commit 53b3645e71)
2019-03-12 21:56:53 +00:00
Richard W.M. Jones
9946ca4ae6 Remove workaround for QEMU bug which is fixed in Fedora 30+.
Make the tests run in parallel, otherwise they are too slow.

(cherry picked from commit 325808dc9d)
2019-03-12 21:55:46 +00:00
Richard W.M. Jones
d99c935aaa New upstream version 1.10.3. 2019-01-30 19:57:27 +00:00
Richard W.M. Jones
471f880fe0 New upstream version 1.10.2. 2019-01-28 14:22:48 +00:00
Richard W.M. Jones
4f96ab3c63 New upstream version 1.10.1. 2019-01-26 11:44:19 +00:00
Richard W.M. Jones
12f8665dd9 New upstream version 1.10.0.
Add: nbdkit-full-plugin.
Add: nbdkit-xz-filter.
Add: nbdkit-loop(1) man page.
Remove misguided LDFLAGS hack which removed server hardening.
  https://bugzilla.redhat.com/show_bug.cgi?id=1624149#c6
2019-01-18 15:40:00 +00:00
Richard W.M. Jones
9b5201c40f New upstream version 1.8.3. 2019-01-07 10:12:40 +00:00
Richard W.M. Jones
3619f43b96 New upstream version 1.8.2.
Fix low priority security issue with TLS:
  https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html
2018-12-04 10:31:05 +00:00
Richard W.M. Jones
78cf7a5bf2 New upstream version 1.8.1. 2018-11-18 10:35:12 +00:00
Richard W.M. Jones
fe95877cec Rebase to new stable version 1.8.0. 2018-11-12 21:08:22 +00:00
Richard W.M. Jones
445543b141 nbdkit metapackage should depend on versioned -server subpackage etc.
Fixes commit b772c3dfae.

(cherry picked from commit bc6a311564)
2018-11-06 21:37:48 +00:00
Richard W.M. Jones
8d3bd5336c New upstream version 1.6.3. 2018-11-06 19:45:05 +00:00
Richard W.M. Jones
0d304537b0 New upstream version 1.6.2. 2018-09-18 23:43:42 +01:00
Richard W.M. Jones
dd850f548b New upstream version 1.6.1. 2018-09-08 10:47:13 +01:00
14 changed files with 477 additions and 2620 deletions

1
.gitignore vendored
View file

@ -1,4 +1,3 @@
/clog
/nbdkit-*.tar.gz
/nbdkit-*.tar.gz.sig
/*~

View file

@ -1,31 +0,0 @@
From 4076ff58512ee98928b1bdb13274466b175e1a97 Mon Sep 17 00:00:00 2001
From: "Richard W.M. Jones" <rjones@redhat.com>
Date: Fri, 2 Jan 2026 11:59:11 +0000
Subject: [PATCH] tests/test-ocaml-debug-hexdump.sh: Fix test that plugin was
built
This is supposed to check that the test plugin was built and skip if
not. However because the 'requires' function call was missing, it
actually failed the test if not built.
Fixes: commit ec3be5030656a9126abbb0bceeb5a1ecf6898c6a
---
tests/test-ocaml-debug-hexdump.sh | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tests/test-ocaml-debug-hexdump.sh b/tests/test-ocaml-debug-hexdump.sh
index 5cc71375..3954225e 100755
--- a/tests/test-ocaml-debug-hexdump.sh
+++ b/tests/test-ocaml-debug-hexdump.sh
@@ -36,7 +36,7 @@ set -x
set -u
plugin=$abs_top_srcdir/tests/test-ocaml-debug-hexdump-plugin.$SOEXT
-test -x "$plugin"
+requires test -x "$plugin"
requires_run
requires_nbdsh_uri
--
2.52.0

View file

@ -1,55 +0,0 @@
#!/bin/bash -
set -e
# Maintainer script to copy patches from the git repo to the current
# directory. Use it like this:
# ./copy-patches.sh
rhel_version=8.3
# Check we're in the right directory.
if [ ! -f nbdkit.spec ]; then
echo "$0: run this from the directory containing 'nbdkit.spec'"
exit 1
fi
git_checkout=$HOME/d/nbdkit-rhel-$rhel_version
if [ ! -d $git_checkout ]; then
echo "$0: $git_checkout does not exist"
echo "This script is only for use by the maintainer when preparing a"
echo "nbdkit release on RHEL."
exit 1
fi
# Get the base version of nbdkit.
version=`grep '^Version:' nbdkit.spec | awk '{print $2}'`
tag="v$version"
# Remove any existing patches.
git rm -f [0-9]*.patch ||:
rm -f [0-9]*.patch
# Get the patches.
(cd $git_checkout; rm -f [0-9]*.patch; git format-patch -N $tag)
mv $git_checkout/[0-9]*.patch .
# Remove any not to be applied.
rm -f *NOT-FOR-RPM*.patch
# Add the patches.
git add [0-9]*.patch
# Print out the patch lines.
echo
echo "--- Copy the following text into nbdkit.spec file"
echo
echo "# Patches."
for f in [0-9]*.patch; do
n=`echo $f | awk -F- '{print $1}'`
echo "Patch$n: $f"
done
echo
echo "--- End of text"

View file

@ -1,6 +0,0 @@
--- !Policy
product_versions:
- rhel-*
decision_context: osci_compose_gate
rules:
- !PassingTestCaseRule {test_case_name: osci.brew-build.tier0.functional}

Binary file not shown.

View file

@ -1,23 +0,0 @@
#!/bin/bash -
# Generate RPM provides automatically for nbdkit packages and filters.
# Copyright (C) 2009-2022 Red Hat Inc.
# To test:
# find /usr/lib64/nbdkit/plugins | ./nbdkit-find-provides VER REL
# find /usr/lib64/nbdkit/filters | ./nbdkit-find-provides VER REL
ver="$1"
rel="$2"
function process_file
{
if [[ $1 =~ /plugins/nbdkit-.*-plugin ]] ||
[[ $1 =~ /filters/nbdkit-.*-filter ]]; then
echo "Provides:" "$(basename $1 .so)" "=" "$ver-$rel"
fi
}
while read line; do
process_file "$line"
done

View file

@ -1,3 +0,0 @@
%__nbdkit_provides %{_rpmconfigdir}/nbdkit-find-provides %{version} %{release}
%__nbdkit_path %{_libdir}/nbdkit/(plugins|filters)/nbdkit-.*-(plugin|filter)(\.so)?$
%__nbdkit_flags exeonly

View file

@ -1,3 +0,0 @@
/usr/sbin/nbdkit -- gen_context(system_u:object_r:nbdkit_exec_t,s0)
/usr/lib/systemd/system/nbdkit.* gen_context(system_u:object_r:nbdkit_unit_file_t,s0)

207
nbdkit.if
View file

@ -1,207 +0,0 @@
## <summary>policy for nbdkit</summary>
########################################
## <summary>
## Execute nbdkit_exec_t in the nbdkit domain.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed to transition.
## </summary>
## </param>
#
interface(`nbdkit_domtrans',`
gen_require(`
type nbdkit_t, nbdkit_exec_t;
')
corecmd_search_bin($1)
domtrans_pattern($1, nbdkit_exec_t, nbdkit_t)
')
######################################
## <summary>
## Execute nbdkit in the caller domain.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`nbdkit_exec',`
gen_require(`
type nbdkit_exec_t;
')
corecmd_search_bin($1)
can_exec($1, nbdkit_exec_t)
')
########################################
## <summary>
## Execute nbdkit in the nbdkit domain, and
## allow the specified role the nbdkit domain.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed to transition
## </summary>
## </param>
## <param name="role">
## <summary>
## The role to be allowed the nbdkit domain.
## </summary>
## </param>
#
interface(`nbdkit_run',`
gen_require(`
type nbdkit_t;
attribute_role nbdkit_roles;
')
nbdkit_domtrans($1)
roleattribute $2 nbdkit_roles;
')
########################################
## <summary>
## Role access for nbdkit
## </summary>
## <param name="role">
## <summary>
## Role allowed access
## </summary>
## </param>
## <param name="domain">
## <summary>
## User domain for the role
## </summary>
## </param>
#
interface(`nbdkit_role',`
gen_require(`
type nbdkit_t;
attribute_role nbdkit_roles;
')
roleattribute $1 nbdkit_roles;
nbdkit_domtrans($2)
ps_process_pattern($2, nbdkit_t)
allow $2 nbdkit_t:process { signull signal sigkill };
')
########################################
## <summary>
## Allow attempts to connect to nbdkit
## with a unix stream socket.
## </summary>
## <param name="domain">
## <summary>
## Domain to not audit.
## </summary>
## </param>
#
interface(`nbdkit_stream_connect',`
gen_require(`
type nbdkit_t;
')
allow $1 nbdkit_t:unix_stream_socket connectto;
')
########################################
## <summary>
## Allow nbdkit_exec_t to be an entrypoint
## of the specified domain
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
## <rolecap/>
#
interface(`nbdkit_entrypoint',`
gen_require(`
type nbdkit_exec_t;
')
allow $1 nbdkit_exec_t:file entrypoint;
')
# ----------------------------------------------------------------------
# RWMJ: See:
# https://issues.redhat.com/browse/RHEL-5174?focusedId=23387259&page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#comment-23387259
# Remove this when virt.if gets updated.
########################################
#
# Interface compatibility blocks
#
# The following definitions ensure compatibility with distribution policy
# versions that do not contain given interfaces (epel, or older Fedora
# releases).
# Each block tests for existence of given interface and defines it if needed.
#
########################################
## <summary>
## Read and write to svirt_image dirs.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
ifndef(`virt_rw_svirt_image_dirs',`
interface(`virt_rw_svirt_image_dirs',`
gen_require(`
type svirt_image_t;
')
allow $1 svirt_image_t:dir rw_dir_perms;
')
')
########################################
## <summary>
## Create svirt_image sock_files.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
ifndef(`virt_create_svirt_image_sock_files',`
interface(`virt_create_svirt_image_sock_files',`
gen_require(`
type svirt_image_t;
')
allow $1 svirt_image_t:sock_file create_sock_file_perms;
')
')
########################################
## <summary>
## Read and write virtlogd pipes.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
ifndef(`virtlogd_rw_pipes',`
interface(`virtlogd_rw_pipes',`
gen_require(`
type virtlogd_t;
')
allow $1 virtlogd_t:fifo_file rw_fifo_file_perms;
')
')

File diff suppressed because it is too large Load diff

100
nbdkit.te
View file

@ -1,100 +0,0 @@
policy_module(nbdkit, 1.0.0)
########################################
#
# Declarations
#
gen_require(`
type unconfined_t;
')
type nbdkit_t;
type nbdkit_exec_t;
application_domain(nbdkit_t, nbdkit_exec_t)
mcs_constrained(nbdkit_t)
role system_r types nbdkit_t;
type nbdkit_home_t;
userdom_user_home_content(nbdkit_home_t)
type nbdkit_tmp_t;
files_tmp_file(nbdkit_tmp_t)
type nbdkit_unit_file_t;
systemd_unit_file(nbdkit_unit_file_t)
permissive nbdkit_t;
########################################
#
# nbdkit local policy
#
allow nbdkit_t self:capability { setgid setuid };
allow nbdkit_t self:fifo_file rw_fifo_file_perms;
allow nbdkit_t self:netlink_route_socket rw_netlink_socket_perms;
allow nbdkit_t self:process { fork setsockcreate signal_perms };
allow nbdkit_t self:tcp_socket create_stream_socket_perms;
allow nbdkit_t self:udp_socket create_socket_perms;
manage_dirs_pattern(nbdkit_t, nbdkit_tmp_t, nbdkit_tmp_t)
manage_files_pattern(nbdkit_t, nbdkit_tmp_t, nbdkit_tmp_t)
userdom_user_tmp_filetrans(nbdkit_t, nbdkit_tmp_t, { dir file })
manage_dirs_pattern(nbdkit_t, nbdkit_home_t, nbdkit_home_t)
manage_files_pattern(nbdkit_t, nbdkit_home_t, nbdkit_home_t)
userdom_user_home_dir_filetrans(nbdkit_t, nbdkit_home_t, { dir file })
corenet_tcp_connect_http_port(nbdkit_t)
corenet_tcp_connect_ssh_port(nbdkit_t)
corenet_tcp_connect_tftp_port(nbdkit_t)
corenet_tcp_bind_generic_port(nbdkit_t)
corenet_tcp_bind_generic_node(nbdkit_t)
domain_use_interactive_fds(nbdkit_t)
files_read_etc_files(nbdkit_t)
init_abstract_socket_activation(nbdkit_t)
init_ioctl_stream_sockets(nbdkit_t)
init_rw_stream_sockets(nbdkit_t)
optional_policy(`
auth_use_nsswitch(nbdkit_t)
')
optional_policy(`
logging_send_syslog_msg(nbdkit_t)
')
optional_policy(`
miscfiles_read_localization(nbdkit_t)
miscfiles_read_generic_certs(nbdkit_t)
')
optional_policy(`
sysnet_dns_name_resolve(nbdkit_t)
sysnet_read_config(nbdkit_t)
')
optional_policy(`
userdom_read_user_home_content_files(nbdkit_t)
userdom_use_inherited_user_ptys(nbdkit_t)
')
optional_policy(`
virt_create_svirt_image_sock_files(nbdkit_t)
virt_read_qemu_pid_files(nbdkit_t)
virtlogd_rw_pipes(nbdkit_t)
virt_rw_svirt_image(nbdkit_t)
virt_rw_svirt_image_dirs(nbdkit_t)
virt_search_lib(nbdkit_t)
virt_stream_connect_svirt(nbdkit_t)
')
# FIXME: It would be nice to allow libvirt to transition nbdkit_exec_t to
# nbdkit_t when libvirtd was started manually from the commandline (i.e. in
# unconfined_t), but we don't want this transition to happen automatically
# when starting directly from the shell. I'm not sure how to achieve this...
#nbdkit_domtrans(unconfined_t, nbdkit_exec_t, nbdkit_t)

View file

@ -1,2 +1,2 @@
SHA512 (nbdkit-1.47.1.tar.gz) = 0c9d1da067bf1f7b6ba38dad33e86dff1fe893ff2e4a349dfcd6b259295fd00670e6af6c195e130d8a847520a78a730003315e60afda8eb94758e2195bd1a775
SHA512 (nbdkit-1.47.1.tar.gz.sig) = 131d9bc191155186408ef7a577f9d2a2cc1fd1b53cbda755d19ff8de1341479a517fab79cc87f04a1bca5518046c24a8647cb4949d5c4d6fdca19ca968604c16
SHA512 (nbdkit-1.12.8.tar.gz) = 68814d77e08436b21cf4d10e6b3e735417b837d6d538ebc7f28d616ebf6540a9c3e86e19e6e250500dbc8c418075bb5320d1f7c30761e1d412d9f0927a9b35a0
SHA512 (nbdkit-1.12.8.tar.gz.sig) = f89015863069b4635d6793e815412979fd1963bdb4cc4b2f7c845211a222b833e143ce39a7eea9301a90d740247f00c02042a6cde0794655a6b2083f8a5b31cb

View file

@ -1,6 +0,0 @@
#!/bin/bash -
set -e
set -x
# Run nbdkit and check that nbdinfo can connect back to it.
nbdkit -U - memory 1G --run 'nbdinfo "$uri"'

View file

@ -1,12 +0,0 @@
- hosts: localhost
roles:
- role: standard-test-basic
tags:
- classic
required_packages:
- libnbd
- nbdkit
tests:
- simple:
dir: .
run: ./basic-test.sh