diff --git a/openhpi-3.8.0-openssl-no-engine.patch b/openhpi-3.8.0-openssl-no-engine.patch new file mode 100644 index 0000000..40d7cdd --- /dev/null +++ b/openhpi-3.8.0-openssl-no-engine.patch @@ -0,0 +1,20 @@ +diff --git a/ssl/oh_ssl.c b/ssl/oh_ssl.c +index 45748d40..b5499eb2 100644 +--- a/ssl/oh_ssl.c ++++ b/ssl/oh_ssl.c +@@ -66,7 +66,6 @@ + #include + #include + #include +-#include + #include + #include + #include +@@ -363,7 +362,6 @@ void oh_ssl_finit(void) + { + /* TODO: Check whether any other SSL library cleanup should be called */ + thread_cleanup(); +- ENGINE_cleanup(); + CONF_modules_unload(0); + ERR_free_strings(); + EVP_cleanup(); diff --git a/openhpi-c99.patch b/openhpi-c99.patch new file mode 100644 index 0000000..99a18bb --- /dev/null +++ b/openhpi-c99.patch @@ -0,0 +1,17 @@ +Avoid an int-conversion C type error and a build failure with GCC 14. + +Submitted upstream: + +diff --git a/plugins/ov_rest/ov_rest_re_discover.c b/plugins/ov_rest/ov_rest_re_discover.c +index 5ad542793f628041..7cdd13d8c395f5d6 100644 +--- a/plugins/ov_rest/ov_rest_re_discover.c ++++ b/plugins/ov_rest/ov_rest_re_discover.c +@@ -704,7 +704,7 @@ SaErrorT remove_composer(struct oh_handler_state *handler, + byte bayNumber) + { + +- SaErrorT rv = NULL; ++ SaErrorT rv = 0; + SaHpiResourceIdT resource_id = 0; + struct oh_event event = {0}; + struct ovRestHotswapState *hotswap_state = NULL; diff --git a/openhpi-snmp-disable-des.patch b/openhpi-snmp-disable-des.patch new file mode 100644 index 0000000..8280e86 --- /dev/null +++ b/openhpi-snmp-disable-des.patch @@ -0,0 +1,35 @@ +This patch is required because net-smp is not build with DES support, +so usmDESPrivProtocol is not available. + +diff --git a/plugins/snmp_bc/snmp_bc_session.c b/plugins/snmp_bc/snmp_bc_session.c +index 767cdb1a77ee420e..cb724fcee0668bd5 100644 +--- a/plugins/snmp_bc/snmp_bc_session.c ++++ b/plugins/snmp_bc/snmp_bc_session.c +@@ -239,23 +239,10 @@ void *snmp_bc_open(GHashTable *handler_config, + err("Cannot find \"privacy_passwd\" configuration parameter."); + return NULL; + } +- +- custom_handle->session.securityLevel = SNMP_SEC_LEVEL_AUTHPRIV; +- custom_handle->session.securityPrivProto = usmDESPrivProtocol; +- custom_handle->session.securityPrivProtoLen = USM_PRIV_PROTO_DES_LEN; +- custom_handle->session.securityPrivKeyLen = USM_PRIV_KU_LEN; +- if (generate_Ku(custom_handle->session.securityAuthProto, +- custom_handle->session.securityAuthProtoLen, +- (u_char *) privacy_passwd, strlen(privacy_passwd), +- custom_handle->session.securityPrivKey, +- &(custom_handle->session.securityPrivKeyLen)) != SNMPERR_SUCCESS) { +- snmp_perror("snmp_bc"); +- snmp_log(LOG_ERR, +- "Error generating Ku from private passphrase.\n"); +- err("Unable to establish SNMP authpriv session."); +- return NULL; +- } +- ++ snmp_perror("snmp_bc"); ++ snmp_log(LOG_ERR, "DES authentication is not supported.\n"); ++ err("Unable to establish SNMP authpriv session."); ++ return NULL; + } + + diff --git a/openhpi.spec b/openhpi.spec index 459ca14..fad680a 100644 --- a/openhpi.spec +++ b/openhpi.spec @@ -1,19 +1,35 @@ +# defining macros needed by SELinux +%global selinuxtype targeted +%global modulename openhpid +%global with_selinux 1 + Summary: Hardware Platform Interface library and tools Name: openhpi Version: 3.8.0 -Release: 10%{?dist} -License: BSD +Release: 32%{?dist} +# Automatically converted from old format: BSD - review is highly recommended. +License: LicenseRef-Callaway-BSD URL: http://www.openhpi.org Source0: http://downloads.sourceforge.net/%{name}/%{name}-%{version}.tar.gz -# convert from initscript to systemd unit +# selinux policy for openhpi, Policy files where extracted from +# https://github.com/fedora-selinux/selinux-policy +Source1: openhpid.fc +Source2: openhpid.if +Source3: openhpid.te Patch0: %{name}-3.4.0-systemd.patch Patch1: %{name}-3.6.1-ssl.patch Patch2: %{name}-3.7.0-multilib.patch Patch3: %{name}-3.8.0-manpage-scan.patch Patch4: %{name}-3.8.0-ipv6-ipmidirect.patch Patch5: %{name}-3.8.0-link-libopenhpi.patch +Patch6: %{name}-snmp-disable-des.patch +Patch7: %{name}-c99.patch +Patch8: %{name}-3.8.0-openssl-no-engine.patch +BuildRequires: make BuildRequires: gcc-c++ +%if 0%{?fedora} || 0%{?rhel} < 9 BuildRequires: libsysfs-devel +%endif BuildRequires: net-snmp-devel BuildRequires: OpenIPMI-devel BuildRequires: glib2-devel @@ -30,6 +46,11 @@ BuildRequires: systemd BuildRequires: autoconf automake libtool BuildRequires: libgcrypt-devel BuildRequires: net-snmp +%if 0%{?with_selinux} +# This ensures that the *-selinux package and all it’s dependencies are not pulled +# into containers and other systems that do not use SELinux +Requires: (%{name}-selinux if selinux-policy-%{selinuxtype}) +%endif Requires(post): systemd Requires(preun): systemd Requires(postun): systemd @@ -50,14 +71,12 @@ easily. Many plug-ins exist in the OpenHPI source tree to provide access to various types of hardware. This includes, but is not limited to, IPMI based servers, Blade Center, and machines which export data via sysfs. - %package libs Summary: The system libraries for the OpenHPI project %description libs The system libraries for the OpenHPI project. - %package devel Summary: The development environment for the OpenHPI project Requires: %{name}-libs%{?_isa} = %{version}-%{release} @@ -66,6 +85,19 @@ Requires: glib2-devel %description devel The development libraries and header files for the OpenHPI project. +%if 0%{?with_selinux} +# SELinux subpackage +%package selinux +Summary: openhpi SELinux policy +BuildArch: noarch +Requires: selinux-policy-%{selinuxtype} +Requires(post): selinux-policy-%{selinuxtype} +BuildRequires: selinux-policy-devel +%{?selinux_requires} + +%description selinux +Custom SELinux policy module +%endif %prep %autosetup -p1 @@ -85,7 +117,6 @@ if [ $UID -eq 0 ]; then find . -name openhpi.conf -execdir chown root:root . \; fi - %build export CFLAGS="$RPM_OPT_FLAGS -fno-strict-aliasing" %configure --disable-static --with-systemdsystemunitdir=%{_unitdir} --docdir=%{_docdir}/%{name}-%{version} @@ -96,6 +127,14 @@ sed -i 's|^runpath_var=LD_RUN_PATH|runpath_var=DIE_RPATH_DIE|g' libtool make %{?_smp_mflags} +%if 0%{?with_selinux} +# SELinux policy (originally from selinux-policy-contrib) +# this policy module will override the production module +mkdir selinux +cp -p %{SOURCE1} %{SOURCE2} %{SOURCE3} selinux/ +make -f %{_datadir}/selinux/devel/Makefile %{modulename}.pp +bzip2 -9 %{modulename}.pp +%endif %install mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/%{name} @@ -107,9 +146,33 @@ rm -rf $RPM_BUILD_ROOT/%{_libdir}/%{name}/*.la cp plugins/dynamic_simulator/README $RPM_BUILD_ROOT/%{_docdir}/%{name}-%{version}/README-dynamic_simulator +# install selinux module +install -D -m 0644 %{modulename}.pp.bz2 %{buildroot}%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 + %check make check +%if 0%{?with_selinux} +# SELinux contexts are saved so that only affected files can be +# relabeled after the policy module installation +%pre selinux +%selinux_relabel_pre -s %{selinuxtype} + +%post selinux +%selinux_modules_install -s %{selinuxtype} %{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.bz2 +%selinux_relabel_post -s %{selinuxtype} + +if [ "$1" -le "1" ]; then # First install + %systemd_postun_with_restart openhpid.service +fi + +%postun selinux +if [ $1 -eq 0 ]; then + %selinux_modules_uninstall -s %{selinuxtype} %{modulename} + %selinux_relabel_post -s %{selinuxtype} + %systemd_postun_with_restart openhpid.service +fi +%endif %post %systemd_post openhpid.service @@ -120,7 +183,6 @@ make check %postun %systemd_postun_with_restart openhpid.service - %files %license %{_docdir}/%{name}-%{version}/COPYING %doc %{_docdir}/%{name}-%{version}/ChangeLog @@ -147,8 +209,79 @@ make check %{_includedir}/%{name} %{_libdir}/pkgconfig/*.pc +%if 0%{?with_selinux} +%files selinux +%{_datadir}/selinux/packages/%{selinuxtype}/%{modulename}.pp.* +%ghost %{_sharedstatedir}/selinux/%{selinuxtype}/active/modules/200/%{modulename} +%endif %changelog +* Thu Jul 24 2025 Fedora Release Engineering - 3.8.0-32 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Fri Jan 17 2025 Fedora Release Engineering - 3.8.0-31 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Mon Sep 02 2024 Miroslav Suchý - 3.8.0-30 +- convert license to SPDX + +* Fri Jul 19 2024 Dan Horák - 3.8.0-29 +- fix build without OpenSSL engines + +* Thu Jul 18 2024 Fedora Release Engineering - 3.8.0-28 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Thu Jan 25 2024 Fedora Release Engineering - 3.8.0-27 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sun Jan 21 2024 Fedora Release Engineering - 3.8.0-26 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Fri Jan 05 2024 Florian Weimer - 3.8.0-25 +- Fix C compatibility issue + +* Thu Jul 20 2023 Fedora Release Engineering - 3.8.0-24 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu Jan 19 2023 Fedora Release Engineering - 3.8.0-23 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Fri Jul 22 2022 Fedora Release Engineering - 3.8.0-22 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Thu Jan 20 2022 Fedora Release Engineering - 3.8.0-21 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Tue Sep 14 2021 Sahana Prasad - 3.8.0-20 +- Rebuilt with OpenSSL 3.0.0 + +* Thu Jul 22 2021 Fedora Release Engineering - 3.8.0-19 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Sat Jul 10 2021 Björn Esser - 3.8.0-18 +- Rebuild for versioned symbols in json-c + +* Wed Jun 30 2021 Than Ngo - 3.8.0-17 +- Port to net-snmp without DES support + +* Wed Mar 31 2021 Than Ngo - 3.8.0-16 +- Add openhpi-selinux subpackage containing selinux policy for openhpi + +* Tue Mar 02 2021 Than Ngo - 3.8.0-15 +- drop BR on sysfs in rhel >=9 + +* Tue Jan 26 2021 Fedora Release Engineering - 3.8.0-14 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Thu Aug 27 2020 Josef Řídký - 3.8.0-13 +- Rebuilt for new net-snmp release + +* Tue Jul 28 2020 Fedora Release Engineering - 3.8.0-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Tue Apr 21 2020 Björn Esser - 3.8.0-11 +- Rebuild (json-c) + * Wed Jan 29 2020 Fedora Release Engineering - 3.8.0-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild diff --git a/openhpid.fc b/openhpid.fc new file mode 100644 index 0000000..df219e6 --- /dev/null +++ b/openhpid.fc @@ -0,0 +1,10 @@ + +/etc/rc\.d/init\.d/openhpid -- gen_context(system_u:object_r:openhpid_initrc_exec_t,s0) + +/usr/sbin/openhpid -- gen_context(system_u:object_r:openhpid_exec_t,s0) + +/var/lib/openhpi(/.*)? gen_context(system_u:object_r:openhpid_var_lib_t,s0) + +/var/log/dynsim[0-9]*\.log -- gen_context(system_u:object_r:openhpid_log_t,s0) + +/var/run/openhpid\.pid -- gen_context(system_u:object_r:openhpid_var_run_t,s0) diff --git a/openhpid.if b/openhpid.if new file mode 100644 index 0000000..598789a --- /dev/null +++ b/openhpid.if @@ -0,0 +1,159 @@ + +## policy for openhpid + + +######################################## +## +## Transition to openhpid. +## +## +## +## Domain allowed to transition. +## +## +# +interface(`openhpid_domtrans',` + gen_require(` + type openhpid_t, openhpid_exec_t; + ') + + corecmd_search_bin($1) + domtrans_pattern($1, openhpid_exec_t, openhpid_t) +') + + +######################################## +## +## Execute openhpid server in the openhpid domain. +## +## +## +## Domain allowed access. +## +## +# +interface(`openhpid_initrc_domtrans',` + gen_require(` + type openhpid_initrc_exec_t; + ') + + init_labeled_script_domtrans($1, openhpid_initrc_exec_t) +') + + +######################################## +## +## Search openhpid lib directories. +## +## +## +## Domain allowed access. +## +## +# +interface(`openhpid_search_lib',` + gen_require(` + type openhpid_var_lib_t; + ') + + allow $1 openhpid_var_lib_t:dir search_dir_perms; + files_search_var_lib($1) +') + +######################################## +## +## Read openhpid lib files. +## +## +## +## Domain allowed access. +## +## +# +interface(`openhpid_read_lib_files',` + gen_require(` + type openhpid_var_lib_t; + ') + + files_search_var_lib($1) + read_files_pattern($1, openhpid_var_lib_t, openhpid_var_lib_t) +') + +######################################## +## +## Manage openhpid lib files. +## +## +## +## Domain allowed access. +## +## +# +interface(`openhpid_manage_lib_files',` + gen_require(` + type openhpid_var_lib_t; + ') + + files_search_var_lib($1) + manage_files_pattern($1, openhpid_var_lib_t, openhpid_var_lib_t) +') + +######################################## +## +## Manage openhpid lib directories. +## +## +## +## Domain allowed access. +## +## +# +interface(`openhpid_manage_lib_dirs',` + gen_require(` + type openhpid_var_lib_t; + ') + + files_search_var_lib($1) + manage_dirs_pattern($1, openhpid_var_lib_t, openhpid_var_lib_t) +') + + +######################################## +## +## All of the rules required to administrate +## an openhpid environment +## +## +## +## Domain allowed access. +## +## +## +## +## Role allowed access. +## +## +## +# +interface(`openhpid_admin',` + gen_require(` + type openhpid_t; + type openhpid_initrc_exec_t; + type openhpid_var_lib_t; + ') + + allow $1 openhpid_t:process { ptrace signal_perms }; + ps_process_pattern($1, openhpid_t) + + openhpid_initrc_domtrans($1) + domain_system_change_exemption($1) + role_transition $2 openhpid_initrc_exec_t system_r; + allow $2 system_r; + + files_search_var_lib($1) + admin_pattern($1, openhpid_var_lib_t) + + + +') + diff --git a/openhpid.te b/openhpid.te new file mode 100644 index 0000000..a0e0eaf --- /dev/null +++ b/openhpid.te @@ -0,0 +1,67 @@ +policy_module(openhpid, 1.0.0) + +######################################## +# +# Declarations +# + +type openhpid_t; +type openhpid_exec_t; +init_daemon_domain(openhpid_t, openhpid_exec_t) + +type openhpid_initrc_exec_t; +init_script_file(openhpid_initrc_exec_t) + +type openhpid_log_t; +logging_log_file(openhpid_log_t) + +type openhpid_var_lib_t; +files_type(openhpid_var_lib_t) + +type openhpid_var_run_t; +files_pid_file(openhpid_var_run_t) + +######################################## +# +# openhpid local policy +# + +allow openhpid_t self:capability { kill }; +allow openhpid_t self:process signal_perms; + +allow openhpid_t self:fifo_file rw_fifo_file_perms; +allow openhpid_t self:netlink_route_socket r_netlink_socket_perms; +allow openhpid_t self:unix_stream_socket create_stream_socket_perms; +allow openhpid_t self:tcp_socket create_stream_socket_perms; +allow openhpid_t self:udp_socket create_socket_perms; + + +manage_files_pattern(openhpid_t, openhpid_log_t, openhpid_log_t) +logging_log_filetrans(openhpid_t, openhpid_log_t, file) + +manage_dirs_pattern(openhpid_t, openhpid_var_lib_t, openhpid_var_lib_t) +manage_files_pattern(openhpid_t, openhpid_var_lib_t, openhpid_var_lib_t) +files_var_lib_filetrans(openhpid_t, openhpid_var_lib_t, { dir file }) + +manage_files_pattern(openhpid_t, openhpid_var_run_t, openhpid_var_run_t) +files_pid_filetrans(openhpid_t, openhpid_var_run_t, { file }) + +kernel_read_system_state(openhpid_t) + +corenet_tcp_bind_generic_node(openhpid_t) +corenet_tcp_bind_openhpid_port(openhpid_t) +corenet_tcp_connect_http_port(openhpid_t) + +dev_read_urand(openhpid_t) +dev_rw_watchdog(openhpid_t) + +logging_send_syslog_msg(openhpid_t) + +miscfiles_read_generic_certs(openhpid_t) + +sysnet_read_config(openhpid_t) + +optional_policy(` + snmp_manage_var_lib_files(openhpid_t) + snmp_manage_var_lib_dirs(openhpid_t) +')