From 2884f6b658cac94609af331df6e4dca7db4c5e6d Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 4 Feb 2016 18:36:35 +0000 Subject: [PATCH 01/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 21fca18..1fa306b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.42 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -242,6 +242,9 @@ fi %changelog +* Thu Feb 04 2016 Fedora Release Engineering - 1.0.42-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + * Wed Dec 23 2015 Robert Scheck - 1.0.42-3 - Remove executable permission bits from pure-ftpd systemd unit From 9c1956be7093ba8fec9cb539fe89d850c1b2b97a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= Date: Fri, 24 Jun 2016 10:02:39 +0200 Subject: [PATCH 02/51] Mandatory Perl build-requires added --- pure-ftpd.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 1fa306b..f5c511c 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -18,7 +18,7 @@ Patch0: pure-ftpd-1.0.35-config.patch Patch1: pure-ftpd-1.0.40-paminclude.patch Provides: ftpserver -BuildRequires: pam-devel, perl, python, libcap-devel +BuildRequires: pam-devel, perl, perl-generators, python, libcap-devel %{!?_without_ldap:BuildRequires: openldap-devel} %{!?_without_mysql:BuildRequires: mysql-devel} %{!?_without_pgsql:BuildRequires: postgresql-devel} From 718bbc9a666428f97b6e9adba506f3fd9c5ceb16 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 11 Feb 2017 07:58:52 +0000 Subject: [PATCH 03/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index f5c511c..e3aab9b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.42 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -242,6 +242,9 @@ fi %changelog +* Sat Feb 11 2017 Fedora Release Engineering - 1.0.42-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + * Thu Feb 04 2016 Fedora Release Engineering - 1.0.42-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild From 17e7e91e6a2c624add3c373d5aa4c9ead93a3c2c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= Date: Wed, 12 Jul 2017 14:07:04 +0200 Subject: [PATCH 04/51] perl dependency renamed to perl-interpreter --- pure-ftpd.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index e3aab9b..57a9adc 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -18,7 +18,7 @@ Patch0: pure-ftpd-1.0.35-config.patch Patch1: pure-ftpd-1.0.40-paminclude.patch Provides: ftpserver -BuildRequires: pam-devel, perl, perl-generators, python, libcap-devel +BuildRequires: pam-devel, perl-interpreter, perl-generators, python, libcap-devel %{!?_without_ldap:BuildRequires: openldap-devel} %{!?_without_mysql:BuildRequires: mysql-devel} %{!?_without_pgsql:BuildRequires: postgresql-devel} From 2e80e45a046c54f94e29e8869f25522bbf5d66e0 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 27 Jul 2017 09:11:21 +0000 Subject: [PATCH 05/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 57a9adc..89b2306 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.42 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -242,6 +242,9 @@ fi %changelog +* Thu Jul 27 2017 Fedora Release Engineering - 1.0.42-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + * Sat Feb 11 2017 Fedora Release Engineering - 1.0.42-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild From a5f4b2edabc6b7c33472f111f485237e28bb4e09 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 3 Aug 2017 06:27:24 +0000 Subject: [PATCH 06/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 89b2306..2e3b8ad 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.42 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -242,6 +242,9 @@ fi %changelog +* Thu Aug 03 2017 Fedora Release Engineering - 1.0.42-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + * Thu Jul 27 2017 Fedora Release Engineering - 1.0.42-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild From 9683b36f713878529beba846b764c4b4463ecf7c Mon Sep 17 00:00:00 2001 From: Martin Sehnoutka Date: Wed, 12 Jul 2017 12:30:42 +0200 Subject: [PATCH 07/51] Rebase to 1.0.46 --- .gitignore | 1 + ...-paminclude.patch => 0001-modify-pam.patch | 25 +++- 0002-fedora-specific-config-file.patch | 126 ++++++++++++++++++ pure-ftpd-1.0.35-config.patch | 115 ---------------- pure-ftpd.service | 2 +- pure-ftpd.spec | 42 +++--- sources | 2 +- 7 files changed, 171 insertions(+), 142 deletions(-) rename pure-ftpd-1.0.40-paminclude.patch => 0001-modify-pam.patch (60%) create mode 100644 0002-fedora-specific-config-file.patch delete mode 100644 pure-ftpd-1.0.35-config.patch diff --git a/.gitignore b/.gitignore index 63a8518..52988ca 100644 --- a/.gitignore +++ b/.gitignore @@ -7,3 +7,4 @@ pure-ftpd-1.0.29.tar.bz2 /pure-ftpd-1.0.39.tar.bz2 /pure-ftpd-1.0.40.tar.bz2 /pure-ftpd-1.0.42.tar.bz2 +/pure-ftpd-1.0.46.tar.bz2 diff --git a/pure-ftpd-1.0.40-paminclude.patch b/0001-modify-pam.patch similarity index 60% rename from pure-ftpd-1.0.40-paminclude.patch rename to 0001-modify-pam.patch index 83bcf70..094a5d1 100644 --- a/pure-ftpd-1.0.40-paminclude.patch +++ b/0001-modify-pam.patch @@ -1,7 +1,17 @@ -diff -Naur pure-ftpd-1.0.40.orig/pam/pure-ftpd pure-ftpd-1.0.40/pam/pure-ftpd ---- pure-ftpd-1.0.40.orig/pam/pure-ftpd 2015-06-13 12:26:37.000000000 +0200 -+++ pure-ftpd-1.0.40/pam/pure-ftpd 2015-06-01 16:36:31.000000000 +0200 -@@ -4,12 +4,14 @@ +From 0cabf3b8b952c6117d575360f793ba63fb53c7ba Mon Sep 17 00:00:00 2001 +From: rpm-build +Date: Wed, 12 Jul 2017 12:09:38 +0200 +Subject: [PATCH 1/2] modify pam + +--- + pam/pure-ftpd | 9 +++++---- + 1 file changed, 5 insertions(+), 4 deletions(-) + +diff --git a/pam/pure-ftpd b/pam/pure-ftpd +index 6611b87..ece8733 100644 +--- a/pam/pure-ftpd ++++ b/pam/pure-ftpd +@@ -4,12 +4,13 @@ # Install it in /etc/pam.d/pure-ftpd or add to /etc/pam.conf auth required pam_listfile.so item=user sense=deny file=/etc/ftpusers onerr=succeed @@ -13,9 +23,12 @@ diff -Naur pure-ftpd-1.0.40.orig/pam/pure-ftpd pure-ftpd-1.0.40/pam/pure-ftpd +account include password-auth -password required pam_stack.so service=system-auth +- +-session required pam_stack.so service=system-auth +password include password-auth --session required pam_stack.so service=system-auth +session required pam_loginuid.so +session include password-auth - +-- +2.13.0 + diff --git a/0002-fedora-specific-config-file.patch b/0002-fedora-specific-config-file.patch new file mode 100644 index 0000000..8244501 --- /dev/null +++ b/0002-fedora-specific-config-file.patch @@ -0,0 +1,126 @@ +From 7298eae83f798f572e33bce5cc5f0a43fabdf9ad Mon Sep 17 00:00:00 2001 +From: rpm-build +Date: Wed, 12 Jul 2017 13:17:05 +0200 +Subject: [PATCH] fedora specific config file + +--- + pure-ftpd.conf.in | 31 +++++++++++++++++-------------- + 1 file changed, 17 insertions(+), 14 deletions(-) + +diff --git a/pure-ftpd.conf.in b/pure-ftpd.conf.in +index fbaf9b4..b02617d 100644 +--- a/pure-ftpd.conf.in ++++ b/pure-ftpd.conf.in +@@ -9,7 +9,7 @@ + # instead of command-line options, please run the + # following command : + # +-# @prefix@/sbin/pure-ftpd @sysconfdir@/etc/pure-ftpd.conf ++# @sbindir@/pure-ftpd @sysconfdir@/pure-ftpd.conf + # + # Online documentation: + # https://www.pureftpd.org/project/pure-ftpd/doc +@@ -106,34 +106,34 @@ MaxIdleTime 15 + + # LDAP configuration file (see README.LDAP) + +-# LDAPConfigFile /etc/pureftpd-ldap.conf ++# LDAPConfigFile @sysconfigdir@/pureftpd-ldap.conf + + + + # MySQL configuration file (see README.MySQL) + +-# MySQLConfigFile /etc/pureftpd-mysql.conf ++# MySQLConfigFile @sysconfigdir@/pureftpd-mysql.conf + + + # PostgreSQL configuration file (see README.PGSQL) + +-# PGSQLConfigFile /etc/pureftpd-pgsql.conf ++# PGSQLConfigFile @sysconfigdir@/pureftpd-pgsql.conf + + + # PureDB user database (see README.Virtual-Users) + +-# PureDB /etc/pureftpd.pdb ++# PureDB @sysconfigdir@/pureftpd.pdb + + + # Path to pure-authd socket (see README.Authentication-Modules) + +-# ExtAuth /var/run/ftpd.sock ++# ExtAuth @localstatedir@/run/ftpd.sock + + + + # If you want to enable PAM authentication, uncomment the following line + +-# PAMAuthentication yes ++PAMAuthentication yes + + + +@@ -236,9 +236,12 @@ Umask 133:022 + + # Minimum UID for an authenticated user to log in. + +-MinUID 100 ++MinUID 1000 + ++# Do not use the /etc/ftpusers file to disable accounts. We're already ++# using MinUID to block users with uid < 1000 + ++UseFtpUsers no + + # Allow FXP transfers for authenticated users. + +@@ -275,7 +278,7 @@ AutoRename no + + # Prevent anonymous users from uploading new files (no = upload is allowed) + +-AnonymousCantUpload no ++AnonymousCantUpload yes + + + +@@ -299,21 +302,21 @@ AnonymousCantUpload no + # fw.c9x.org - jedi [13/Apr/2017:19:36:39] "GET /ftp/linux.tar.bz2" 200 21809338 + # This log file can then be processed by common HTTP traffic analyzers. + +-# AltLog clf:/var/log/pureftpd.log ++AltLog clf:@localstatedir@/log/pureftpd.log + + + + # Create an additional log file with transfers logged in a format optimized + # for statistic reports. + +-# AltLog stats:/var/log/pureftpd.log ++# AltLog stats:@localstatedir@/log/pureftpd.log + + + + # Create an additional log file with transfers logged in the standard W3C + # format (compatible with many HTTP log analyzers) + +-# AltLog w3c:/var/log/pureftpd.log ++# AltLog w3c:@localstatedir@/log/pureftpd.log + + + +@@ -344,9 +347,9 @@ AnonymousCantUpload no + + + # If your pure-ftpd has been compiled with standalone support, you can change +-# the location of the pid file. The default is /var/run/pure-ftpd.pid ++# the location of the pid file. The default is @localstatedir@/run/pure-ftpd.pid + +-# PIDFile /var/run/pure-ftpd.pid ++#PIDFile @localstatedir@/run/pure-ftpd.pid + + + +-- +2.13.0 + diff --git a/pure-ftpd-1.0.35-config.patch b/pure-ftpd-1.0.35-config.patch deleted file mode 100644 index 845379e..0000000 --- a/pure-ftpd-1.0.35-config.patch +++ /dev/null @@ -1,115 +0,0 @@ -diff -up ./configuration-file/pure-ftpd.conf.in.config ./configuration-file/pure-ftpd.conf.in ---- ./configuration-file/pure-ftpd.conf.in.config 2009-11-20 14:15:01.000000000 +0100 -+++ ./configuration-file/pure-ftpd.conf.in 2009-12-04 22:09:21.461504212 +0100 -@@ -9,7 +9,7 @@ - # instead of command-line options, please run the - # following command : - # --# @prefix@/sbin/pure-config.pl @prefix@/etc/pure-ftpd.conf -+# @sbindir@/pure-config.pl @sysconfdir@/pure-ftpd.conf - # - # Please don't forget to have a look at documentation at - # http://www.pureftpd.org/documentation.shtml for a complete list of -@@ -107,34 +107,34 @@ MaxIdleTime 15 - - # LDAP configuration file (see README.LDAP) - --# LDAPConfigFile /etc/pureftpd-ldap.conf -+# LDAPConfigFile @sysconfdir@/pureftpd-ldap.conf - - - - # MySQL configuration file (see README.MySQL) - --# MySQLConfigFile /etc/pureftpd-mysql.conf -+# MySQLConfigFile @sysconfdir@/pureftpd-mysql.conf - - - # Postgres configuration file (see README.PGSQL) - --# PGSQLConfigFile /etc/pureftpd-pgsql.conf -+# PGSQLConfigFile @sysconfdir@/pureftpd-pgsql.conf - - - # PureDB user database (see README.Virtual-Users) - --# PureDB /etc/pureftpd.pdb -+# PureDB @sysconfdir@/pureftpd.pdb - - - # Path to pure-authd socket (see README.Authentication-Modules) - --# ExtAuth /var/run/ftpd.sock -+# ExtAuth @localstatedir@/run/ftpd.sock - - - - # If you want to enable PAM authentication, uncomment the following line - --# PAMAuthentication yes -+PAMAuthentication yes - - - -@@ -237,7 +237,14 @@ Umask 133:022 - - # Minimum UID for an authenticated user to log in. - --MinUID 100 -+MinUID 1000 -+ -+ -+ -+# Do not use the /etc/ftpusers file to disable accounts. We're already -+# using MinUID to block users with uid < 1000 -+ -+UseFtpUsers no - - - -@@ -276,7 +283,7 @@ AutoRename no - - # Disallow anonymous users to upload new files (no = upload is allowed) - --AnonymousCantUpload no -+AnonymousCantUpload yes - - - -@@ -301,21 +308,21 @@ AnonymousCantUpload no - # fw.c9x.org - jedi [13/Dec/1975:19:36:39] "GET /ftp/linux.tar.bz2" 200 21809338 - # This log file can then be processed by www traffic analyzers. - --# AltLog clf:/var/log/pureftpd.log -+AltLog clf:@localstatedir@/log/pureftpd.log - - - - # Create an additional log file with transfers logged in a format optimized - # for statistic reports. - --# AltLog stats:/var/log/pureftpd.log -+# AltLog stats:@localstatedir@/log/pureftpd.log - - - - # Create an additional log file with transfers logged in the standard W3C - # format (compatible with most commercial log analyzers) - --# AltLog w3c:/var/log/pureftpd.log -+# AltLog w3c:@localstatedir@/log/pureftpd.log - - - -@@ -346,9 +353,9 @@ AnonymousCantUpload no - - - # If your pure-ftpd has been compiled with standalone support, you can change --# the location of the pid file. The default is /var/run/pure-ftpd.pid -+# the location of the pid file. The default is @localstatedir@/run/pure-ftpd.pid - --#PIDFile /var/run/pure-ftpd.pid -+#PIDFile @localstatedir@/run/pure-ftpd.pid - - - diff --git a/pure-ftpd.service b/pure-ftpd.service index e0b3dba..c26bfb6 100644 --- a/pure-ftpd.service +++ b/pure-ftpd.service @@ -5,7 +5,7 @@ After=syslog.target network.target [Service] Type=forking PIDFile=/var/run/pure-ftpd.pid -ExecStart=/usr/sbin/pure-config.pl /etc/pure-ftpd/pure-ftpd.conf --daemonize +ExecStart=/usr/sbin/pure-ftpd /etc/pure-ftpd/pure-ftpd.conf --daemonize [Install] WantedBy=multi-user.target diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 2e3b8ad..4029a2e 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd -Version: 1.0.42 -Release: 7%{?dist} +Version: 1.0.46 +Release: 1%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -14,17 +14,18 @@ Source4: pure-ftpd.pure-ftpwho.pam Source5: pure-ftpd.pure-ftpwho.consoleapp Source6: pure-ftpd.README.SELinux Source7: pure-ftpd.pureftpd.te -Patch0: pure-ftpd-1.0.35-config.patch -Patch1: pure-ftpd-1.0.40-paminclude.patch +Patch0: 0001-modify-pam.patch +Patch1: 0002-fedora-specific-config-file.patch Provides: ftpserver -BuildRequires: pam-devel, perl-interpreter, perl-generators, python, libcap-devel +BuildRequires: pam-devel, libcap-devel %{!?_without_ldap:BuildRequires: openldap-devel} %{!?_without_mysql:BuildRequires: mysql-devel} %{!?_without_pgsql:BuildRequires: postgresql-devel} %{!?_without_tls:BuildRequires: openssl-devel} BuildRequires: checkpolicy, selinux-policy-devel BuildRequires: systemd-units +BuildRequires: git Requires(post): systemd-sysv Requires(post): systemd-units Requires(preun): systemd-units @@ -65,9 +66,7 @@ Pure-FTPd to be protected in the same way other FTP servers are in Fedora %prep -%setup -q -%patch0 -p0 -b .config -%patch1 -p1 -b .paminclude +%autosetup -S git install -pm 644 %{SOURCE6} README.SELinux mkdir selinux cp -p %{SOURCE7} selinux/pureftpd.te @@ -78,7 +77,6 @@ cp -p %{SOURCE7} selinux/pureftpd.te --sysconfdir=%{_sysconfdir}/%{name} \ --with-capabilities \ --with-sendfile \ - --with-cork \ --with-paranoidmsg \ --with-altlog \ --with-puredb \ @@ -103,11 +101,10 @@ cp -p %{SOURCE7} selinux/pureftpd.te --with-rfc2640 \ --without-bonjour \ -make %{?_smp_mflags} - +%make_build %install -make install DESTDIR=$RPM_BUILD_ROOT +%make_install install -d -m 755 $RPM_BUILD_ROOT%{_mandir}/man8 install -d -m 755 $RPM_BUILD_ROOT%{_sbindir} @@ -117,9 +114,7 @@ install -d -m 755 $RPM_BUILD_ROOT%{_localstatedir}/ftp %{!?_without_tls:install -d -m 700 $RPM_BUILD_ROOT%{_sysconfdir}/pki/%{name}} # Conf -install -p -m 755 configuration-file/pure-config.pl $RPM_BUILD_ROOT%{_sbindir} -install -p -m 644 configuration-file/pure-ftpd.conf $RPM_BUILD_ROOT%{_sysconfdir}/%{name} -install -p -m 755 configuration-file/pure-config.py $RPM_BUILD_ROOT%{_sbindir} +install -p -m 644 pure-ftpd.conf $RPM_BUILD_ROOT%{_sysconfdir}/%{name} install -p -m 644 pureftpd-ldap.conf $RPM_BUILD_ROOT%{_sysconfdir}/%{name} install -p -m 644 pureftpd-mysql.conf $RPM_BUILD_ROOT%{_sysconfdir}/%{name} install -p -m 644 pureftpd-pgsql.conf $RPM_BUILD_ROOT%{_sysconfdir}/%{name} @@ -157,13 +152,19 @@ install -p -m 644 %{SOURCE5} $RPM_BUILD_ROOT%{_sysconfdir}/security/console.apps ln -s consolehelper $RPM_BUILD_ROOT%{_bindir}/pure-ftpwho # SELinux support -cd selinux +pushd selinux echo "%{_sbindir}/pure-ftpd system_u:object_r:ftpd_exec_t:s0" > pureftpd.fc echo '%{_localstatedir}/log/pureftpd.log system_u:object_r:xferlog_t:s0' >> pureftpd.fc touch pureftpd.if make -f %{_datadir}/selinux/devel/Makefile install -p -m 644 -D pureftpd.pp $RPM_BUILD_ROOT%{_datadir}/selinux/packages/%{name}/pureftpd.pp +popd +# Docs +install -d -m 755 $RPM_BUILD_ROOT%{_docdir}/%{name} +rm -f README.{MacOS-X,Windows} +install -p -m 644 README.* $RPM_BUILD_ROOT%{_docdir}/%{name} +install -p -m 644 pureftpd.schema $RPM_BUILD_ROOT%{_docdir}/%{name} %post %systemd_post pure-ftpd.service @@ -171,7 +172,7 @@ install -p -m 644 -D pureftpd.pp $RPM_BUILD_ROOT%{_datadir}/selinux/packages/%{n %if 0%{!?_without_tls:1} # TLS Certificate if [ ! -f %{_sysconfdir}/pki/%{name}/%{name}.pem ]; then - %{_sysconfdir}/pki/tls/certs/make-dummy-cert \ + %{_bindir}/make-dummy-cert \ %{_sysconfdir}/pki/%{name}/%{name}.pem fi %endif @@ -219,9 +220,9 @@ fi %files %doc FAQ THANKS AUTHORS CONTACT HISTORY NEWS %doc README README.Authentication-Modules README.Configuration-File -%doc README.Contrib README.Donations README.LDAP README.MySQL +%doc README.Donations README.LDAP README.MySQL README.SELinux %doc README.PGSQL README.TLS README.Virtual-Users -%doc contrib/pure-vpopauth.pl pureftpd.schema contrib/pure-stat.pl +%doc pureftpd.schema %{_bindir}/pure-* %{_sbindir}/pure-* %{_unitdir}/%{name}.service @@ -242,6 +243,9 @@ fi %changelog +* Mon Aug 14 2017 Martin Sehnoutka - 1.0.46-1 +- Rebase to 1.0.46 + * Thu Aug 03 2017 Fedora Release Engineering - 1.0.42-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild diff --git a/sources b/sources index f3bc784..d223bc2 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -4022f38939f6a112b18c1a43dee552c1 pure-ftpd-1.0.42.tar.bz2 +SHA512 (pure-ftpd-1.0.46.tar.bz2) = e44c1842e6f101f4d7dd42617392f3d54ff58d68608f6a3bc5e612fc89bfd1da6935215a7e87c0d2bbd9fc9f0fa31a40ceb764fd67428dfdd8c5454e0d64e0ab From 749308ee9d298aae7dc182debdd77b702a6d7e46 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Thu, 14 Sep 2017 01:09:18 +0200 Subject: [PATCH 08/51] Fix loading the configuration file Also drop the 'UseFtpUsers' option from default config file The option has not been imlemented for over 12 years. The /etc/ftpusers file is used by PAM irrespectively of the option. --- 0002-fedora-specific-config-file.patch | 26 +++---- ...h-options-and-config-file-on-command.patch | 68 +++++++++++++++++++ pure-ftpd.spec | 7 +- 3 files changed, 85 insertions(+), 16 deletions(-) create mode 100644 0003-Allow-having-both-options-and-config-file-on-command.patch diff --git a/0002-fedora-specific-config-file.patch b/0002-fedora-specific-config-file.patch index 8244501..725184c 100644 --- a/0002-fedora-specific-config-file.patch +++ b/0002-fedora-specific-config-file.patch @@ -1,14 +1,14 @@ -From 7298eae83f798f572e33bce5cc5f0a43fabdf9ad Mon Sep 17 00:00:00 2001 +From 5023020a73f60d4d512f934cfb67d94d1efd921c Mon Sep 17 00:00:00 2001 From: rpm-build -Date: Wed, 12 Jul 2017 13:17:05 +0200 +Date: Thu, 14 Sep 2017 16:41:12 +0200 Subject: [PATCH] fedora specific config file --- - pure-ftpd.conf.in | 31 +++++++++++++++++-------------- - 1 file changed, 17 insertions(+), 14 deletions(-) + pure-ftpd.conf.in | 29 ++++++++++++++--------------- + 1 file changed, 14 insertions(+), 15 deletions(-) diff --git a/pure-ftpd.conf.in b/pure-ftpd.conf.in -index fbaf9b4..b02617d 100644 +index fbaf9b4..b4d6837 100644 --- a/pure-ftpd.conf.in +++ b/pure-ftpd.conf.in @@ -9,7 +9,7 @@ @@ -61,21 +61,17 @@ index fbaf9b4..b02617d 100644 -@@ -236,9 +236,12 @@ Umask 133:022 +@@ -236,8 +236,7 @@ Umask 133:022 # Minimum UID for an authenticated user to log in. -MinUID 100 +- +MinUID 1000 -+# Do not use the /etc/ftpusers file to disable accounts. We're already -+# using MinUID to block users with uid < 1000 - -+UseFtpUsers no # Allow FXP transfers for authenticated users. - -@@ -275,7 +278,7 @@ AutoRename no +@@ -275,7 +274,7 @@ AutoRename no # Prevent anonymous users from uploading new files (no = upload is allowed) @@ -84,7 +80,7 @@ index fbaf9b4..b02617d 100644 -@@ -299,21 +302,21 @@ AnonymousCantUpload no +@@ -299,21 +298,21 @@ AnonymousCantUpload no # fw.c9x.org - jedi [13/Apr/2017:19:36:39] "GET /ftp/linux.tar.bz2" 200 21809338 # This log file can then be processed by common HTTP traffic analyzers. @@ -109,7 +105,7 @@ index fbaf9b4..b02617d 100644 -@@ -344,9 +347,9 @@ AnonymousCantUpload no +@@ -344,9 +343,9 @@ AnonymousCantUpload no # If your pure-ftpd has been compiled with standalone support, you can change @@ -122,5 +118,5 @@ index fbaf9b4..b02617d 100644 -- -2.13.0 +2.9.5 diff --git a/0003-Allow-having-both-options-and-config-file-on-command.patch b/0003-Allow-having-both-options-and-config-file-on-command.patch new file mode 100644 index 0000000..7eb99b2 --- /dev/null +++ b/0003-Allow-having-both-options-and-config-file-on-command.patch @@ -0,0 +1,68 @@ +From f5617a4de54c313580fe39562f0d32e5c95f5212 Mon Sep 17 00:00:00 2001 +From: rpm-build +Date: Thu, 14 Sep 2017 01:05:53 +0200 +Subject: [PATCH] Allow having both options and config file on command line + +--- + src/ftpd.c | 2 +- + src/simpleconf.c | 23 +++++++++++++++++++++-- + 2 files changed, 22 insertions(+), 3 deletions(-) + +diff --git a/src/ftpd.c b/src/ftpd.c +index c5edac5..b13afc0 100644 +--- a/src/ftpd.c ++++ b/src/ftpd.c +@@ -5589,7 +5589,7 @@ int pureftpd_start(int argc, char *argv[], const char *home_directory_) + #endif + + #ifndef MINIMAL +- if (argc == 2 && *argv[1] != '-' && ++ if (argc >= 2 && *argv[1] != '-' && + sc_build_command_line_from_file(argv[1], NULL, simpleconf_options, + (sizeof simpleconf_options) / + (sizeof simpleconf_options[0]), +diff --git a/src/simpleconf.c b/src/simpleconf.c +index f296f54..505aee1 100644 +--- a/src/simpleconf.c ++++ b/src/simpleconf.c +@@ -674,9 +674,10 @@ sc_build_command_line_from_file(const char *file_name, + { + char **argv = NULL; + int argc = 0; ++ char **argv_tmp = NULL; ++ char *arg = NULL; ++ int i; + +- *argc_p = 0; +- *argv_p = NULL; + if ((argv = malloc(sizeof *argv)) == NULL || + (app_name = strdup(app_name)) == NULL) { + sc_argv_free(argc, argv); +@@ -689,6 +690,24 @@ sc_build_command_line_from_file(const char *file_name, + sc_argv_free(argc, argv); + return -1; + } ++ ++ for (i = 2; i < *argc_p; ++i) { ++ ++argc; ++ arg = strdup((*argv_p)[i]); ++ if (arg == NULL) { ++ return -1; ++ } ++ if ((argv_tmp = realloc(argv, (sizeof arg) * ++ ((size_t) argc + 1))) == NULL) { ++ return -1; ++ } ++ argv = argv_tmp; ++ argv[argc - 1] = arg; ++ } ++ if (*argc_p > 2) { ++ argv[argc] = NULL; ++ } ++ + *argc_p = argc; + *argv_p = argv; + +-- +2.9.5 + diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 4029a2e..6dd3e26 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.46 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -16,6 +16,7 @@ Source6: pure-ftpd.README.SELinux Source7: pure-ftpd.pureftpd.te Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch +Patch2: 0003-Allow-having-both-options-and-config-file-on-command.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel @@ -243,6 +244,10 @@ fi %changelog +* Thu Sep 14 2017 OndÅ™ej LysonÄ›k - 1.0.46-2 +- Fix loading the configuration file +- Drop unsupported UseFtpUsers option from configuration file + * Mon Aug 14 2017 Martin Sehnoutka - 1.0.46-1 - Rebase to 1.0.46 From 0a05cb720cdb07623fe5e1b500a631390f760d1e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Wed, 25 Oct 2017 13:52:13 +0200 Subject: [PATCH 09/51] Generate the TLS certificate using sscg in an initialization systemd service This is required by https://fedoraproject.org/wiki/Packaging:Initial_Service_Setup --- pure-ftpd-with-tls-init.service | 10 ++++++++++ pure-ftpd-with-tls.service | 12 ++++++++++++ pure-ftpd.spec | 34 +++++++++++++++++++++------------ 3 files changed, 44 insertions(+), 12 deletions(-) create mode 100644 pure-ftpd-with-tls-init.service create mode 100644 pure-ftpd-with-tls.service diff --git a/pure-ftpd-with-tls-init.service b/pure-ftpd-with-tls-init.service new file mode 100644 index 0000000..aab2191 --- /dev/null +++ b/pure-ftpd-with-tls-init.service @@ -0,0 +1,10 @@ +[Unit] +Description=One-time configuration for pure-ftpd + +ConditionPathExists=|!/etc/pki/pure-ftpd/pure-ftpd.pem + +[Service] +Type=oneshot +RemainAfterExit=no + +ExecStart=/usr/bin/sscg --ca-file /etc/pki/pure-ftpd/ca.crt --cert-file /etc/pki/pure-ftpd/pure-ftpd.pem --cert-key-file /etc/pki/pure-ftpd/pure-ftpd.pem diff --git a/pure-ftpd-with-tls.service b/pure-ftpd-with-tls.service new file mode 100644 index 0000000..95d982c --- /dev/null +++ b/pure-ftpd-with-tls.service @@ -0,0 +1,12 @@ +[Unit] +Description=Pure-FTPd FTP server +After=syslog.target network.target pure-ftpd-init.service +Requires=pure-ftpd-init.service + +[Service] +Type=forking +PIDFile=/var/run/pure-ftpd.pid +ExecStart=/usr/sbin/pure-ftpd /etc/pure-ftpd/pure-ftpd.conf --daemonize + +[Install] +WantedBy=multi-user.target diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 6dd3e26..b76e3ae 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.46 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -14,6 +14,8 @@ Source4: pure-ftpd.pure-ftpwho.pam Source5: pure-ftpd.pure-ftpwho.consoleapp Source6: pure-ftpd.README.SELinux Source7: pure-ftpd.pureftpd.te +Source8: pure-ftpd-with-tls-init.service +Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch Patch2: 0003-Allow-having-both-options-and-config-file-on-command.patch @@ -32,6 +34,7 @@ Requires(post): systemd-units Requires(preun): systemd-units Requires(postun): systemd-units Requires: logrotate, usermode +%{!?_without_tls:Requires: sscg} %description @@ -131,8 +134,13 @@ install -p -m 644 man/pure-statsdecode.8 $RPM_BUILD_ROOT%{_mandir}/man8 install -p -m 644 man/pure-quotacheck.8 $RPM_BUILD_ROOT%{_mandir}/man8 install -p -m 644 man/pure-authd.8 $RPM_BUILD_ROOT%{_mandir}/man8 -# Init script -install -p -m 644 %{SOURCE1} $RPM_BUILD_ROOT%{_unitdir}/%{name}.service +# Systemd services +%if 0%{!?_without_tls:1} +install -p -m 644 %{SOURCE8} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd-init.service +install -p -m 644 %{SOURCE9} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd.service +%else +install -p -m 644 %{SOURCE1} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd.service +%endif # Pam install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/pam.d @@ -170,14 +178,6 @@ install -p -m 644 pureftpd.schema $RPM_BUILD_ROOT%{_docdir}/%{name} %post %systemd_post pure-ftpd.service -%if 0%{!?_without_tls:1} -# TLS Certificate -if [ ! -f %{_sysconfdir}/pki/%{name}/%{name}.pem ]; then - %{_bindir}/make-dummy-cert \ - %{_sysconfdir}/pki/%{name}/%{name}.pem -fi -%endif - %preun %systemd_preun pure-ftpd.service @@ -226,7 +226,12 @@ fi %doc pureftpd.schema %{_bindir}/pure-* %{_sbindir}/pure-* -%{_unitdir}/%{name}.service +%if 0%{!?_without_tls:1} + %{_unitdir}/pure-ftpd-init.service + %{_unitdir}/pure-ftpd.service +%else + %{_unitdir}/pure-ftpd.service +%endif %config(noreplace) %{_sysconfdir}/%{name} %config(noreplace) %{_sysconfdir}/pam.d/%{name} %config(noreplace) %{_sysconfdir}/logrotate.d/%{name} @@ -244,6 +249,11 @@ fi %changelog +* Wed Oct 25 2017 OndÅ™ej LysonÄ›k - 1.0.46-3 +- Generate the TLS certificate using sscg in an initialization systemd service +- This is required by +- https://fedoraproject.org/wiki/Packaging:Initial_Service_Setup + * Thu Sep 14 2017 OndÅ™ej LysonÄ›k - 1.0.46-2 - Fix loading the configuration file - Drop unsupported UseFtpUsers option from configuration file From 7b8008a043645df482f2f64af6ccf6c03e371d25 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Wed, 25 Oct 2017 15:09:47 +0200 Subject: [PATCH 10/51] Depend on mariadb-connector-c-devel instead of mysql-devel Resolves: rhbz#1493658 --- pure-ftpd.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index b76e3ae..e6e7c60 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.46 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -23,7 +23,7 @@ Patch2: 0003-Allow-having-both-options-and-config-file-on-command.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel %{!?_without_ldap:BuildRequires: openldap-devel} -%{!?_without_mysql:BuildRequires: mysql-devel} +%{!?_without_mysql:BuildRequires: mariadb-connector-c-devel} %{!?_without_pgsql:BuildRequires: postgresql-devel} %{!?_without_tls:BuildRequires: openssl-devel} BuildRequires: checkpolicy, selinux-policy-devel @@ -249,6 +249,10 @@ fi %changelog +* Wed Oct 25 2017 OndÅ™ej LysonÄ›k - 1.0.46-4 +- Depend on mariadb-connector-c-devel instead of mysql-devel +- Resolves: rhbz#1493658 + * Wed Oct 25 2017 OndÅ™ej LysonÄ›k - 1.0.46-3 - Generate the TLS certificate using sscg in an initialization systemd service - This is required by From 92a7148671efa83943790381322765557a1ba3dd Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Sat, 20 Jan 2018 23:07:38 +0100 Subject: [PATCH 11/51] Rebuilt for switch to libxcrypt --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index e6e7c60..fbfad11 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.46 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -249,6 +249,9 @@ fi %changelog +* Sat Jan 20 2018 Björn Esser - 1.0.46-5 +- Rebuilt for switch to libxcrypt + * Wed Oct 25 2017 OndÅ™ej LysonÄ›k - 1.0.46-4 - Depend on mariadb-connector-c-devel instead of mysql-devel - Resolves: rhbz#1493658 From 5be41d7de13ac9803ebf97b9a2356085d3bb9064 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 9 Feb 2018 05:59:33 +0000 Subject: [PATCH 12/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index fbfad11..e837f99 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.46 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -249,6 +249,9 @@ fi %changelog +* Fri Feb 09 2018 Fedora Release Engineering - 1.0.46-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + * Sat Jan 20 2018 Björn Esser - 1.0.46-5 - Rebuilt for switch to libxcrypt From c4e0ccede6c53159d6b4584e0e4897cd03fb10d9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Tue, 13 Feb 2018 12:13:40 +0100 Subject: [PATCH 13/51] New version Dropped patch 0003-Allow-having-both-options-and-config-file-on-command.patch as it was rejected by upstream. Complain when invalid or excessive arguments are given on the command line. Resolves: rhbz#1508220 --- .gitignore | 1 + ...when-given-an-invalid-cmdline-option.patch | 25 ++ ...th-options-and-config-file-are-given.patch | 237 ++++++++++++++++++ 0002-fedora-specific-config-file.patch | 31 ++- pure-ftpd-with-tls.service | 2 +- pure-ftpd.service | 2 +- pure-ftpd.spec | 15 +- pure-ftpd.xinetd | 2 +- sources | 2 +- 9 files changed, 299 insertions(+), 18 deletions(-) create mode 100644 0001-Exit-when-given-an-invalid-cmdline-option.patch create mode 100644 0002-Complain-when-both-options-and-config-file-are-given.patch diff --git a/.gitignore b/.gitignore index 52988ca..3c3f0e2 100644 --- a/.gitignore +++ b/.gitignore @@ -8,3 +8,4 @@ pure-ftpd-1.0.29.tar.bz2 /pure-ftpd-1.0.40.tar.bz2 /pure-ftpd-1.0.42.tar.bz2 /pure-ftpd-1.0.46.tar.bz2 +/pure-ftpd-1.0.47.tar.bz2 diff --git a/0001-Exit-when-given-an-invalid-cmdline-option.patch b/0001-Exit-when-given-an-invalid-cmdline-option.patch new file mode 100644 index 0000000..2e069d8 --- /dev/null +++ b/0001-Exit-when-given-an-invalid-cmdline-option.patch @@ -0,0 +1,25 @@ +From 8b6e9370ccbdff47107963c352caab24fdb0fcaa Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= +Date: Wed, 7 Feb 2018 13:28:02 +0100 +Subject: [PATCH 1/2] Exit when given an invalid cmdline option + +--- + src/ftpd.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/ftpd.c b/src/ftpd.c +index e19d8de..5c77410 100644 +--- a/src/ftpd.c ++++ b/src/ftpd.c +@@ -6192,7 +6192,7 @@ int pureftpd_start(int argc, char *argv[], const char *home_directory_) + exit(EXIT_SUCCESS); + } + default: +- logfile(LOG_WARNING, MSG_ILLEGAL_OPTION); ++ die(421, LOG_ERR, MSG_ILLEGAL_OPTION); + } + } + #ifdef WITH_RFC2640 +-- +2.14.3 + diff --git a/0002-Complain-when-both-options-and-config-file-are-given.patch b/0002-Complain-when-both-options-and-config-file-are-given.patch new file mode 100644 index 0000000..12169f7 --- /dev/null +++ b/0002-Complain-when-both-options-and-config-file-are-given.patch @@ -0,0 +1,237 @@ +From 4328fd5142d0f981687a484f4be34333432d27d1 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= +Date: Wed, 7 Feb 2018 15:05:25 +0100 +Subject: [PATCH 2/2] Complain when both options and config file are given on + cmdline + +--- + src/ftpd.c | 3 +++ + src/messages_cs_cz.h | 1 + + src/messages_da.h | 1 + + src/messages_de.h | 1 + + src/messages_en.h | 1 + + src/messages_es.h | 1 + + src/messages_fr.h | 1 + + src/messages_fr_funny.h | 1 + + src/messages_hu.h | 1 + + src/messages_it.h | 1 + + src/messages_kr.h | 1 + + src/messages_nl.h | 1 + + src/messages_no.h | 1 + + src/messages_pl.h | 1 + + src/messages_pt_br.h | 1 + + src/messages_ro.h | 1 + + src/messages_ru.h | 1 + + src/messages_sk.h | 1 + + src/messages_sv.h | 1 + + src/messages_tr.h | 1 + + src/messages_zh_cn.h | 1 + + src/messages_zh_tw.h | 1 + + 22 files changed, 24 insertions(+) + +diff --git a/src/ftpd.c b/src/ftpd.c +index 5c77410..3f474d2 100644 +--- a/src/ftpd.c ++++ b/src/ftpd.c +@@ -6195,6 +6195,9 @@ int pureftpd_start(int argc, char *argv[], const char *home_directory_) + die(421, LOG_ERR, MSG_ILLEGAL_OPTION); + } + } ++ if (optind < argc) { ++ die(421, LOG_ERR, MSG_INVALID_ARGUMENT, argv[optind]); ++ } + #ifdef WITH_RFC2640 + if (charset_fs == NULL) { + charset_fs = (char *) "utf-8"; +diff --git a/src/messages_cs_cz.h b/src/messages_cs_cz.h +index ef225ba..e103b37 100644 +--- a/src/messages_cs_cz.h ++++ b/src/messages_cs_cz.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Neplatný argument: \"%s\"" +diff --git a/src/messages_da.h b/src/messages_da.h +index ed6f77c..c79ad5a 100644 +--- a/src/messages_da.h ++++ b/src/messages_da.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_de.h b/src/messages_de.h +index e7ae9a9..cd6bc08 100644 +--- a/src/messages_de.h ++++ b/src/messages_de.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_en.h b/src/messages_en.h +index e980131..cb9abf3 100644 +--- a/src/messages_en.h ++++ b/src/messages_en.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_es.h b/src/messages_es.h +index 0c27d4f..60ed849 100644 +--- a/src/messages_es.h ++++ b/src/messages_es.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_fr.h b/src/messages_fr.h +index 7f41dae..a012c05 100644 +--- a/src/messages_fr.h ++++ b/src/messages_fr.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT doit etre precede d'une commande PBSZ reussie" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP n'a pas retourne d'attribut userPassword, verifiez les droits d'acces LDAP." + #define MSG_LDAP_INVALID_AUTH_METHOD "Methode LDAPAuthMethod invalide dans le fichier de configuration. Ce doit etre 'bind' ou 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_fr_funny.h b/src/messages_fr_funny.h +index c77e5bc..dff760b 100644 +--- a/src/messages_fr_funny.h ++++ b/src/messages_fr_funny.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT ca marche qu'apres un PBSZ reussi" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP n'a pas retourne d'attribut userPassword, ptet que les droits d'acces LDAP chient." + #define MSG_LDAP_INVALID_AUTH_METHOD "LDAPAuthMethod dans le fichier de conf, ca doit etre 'bind' ou 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_hu.h b/src/messages_hu.h +index b3beead..7c5a101 100644 +--- a/src/messages_hu.h ++++ b/src/messages_hu.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_it.h b/src/messages_it.h +index 4e6e984..e30f517 100644 +--- a/src/messages_it.h ++++ b/src/messages_it.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_kr.h b/src/messages_kr.h +index 14d8300..c9faead 100644 +--- a/src/messages_kr.h ++++ b/src/messages_kr.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_nl.h b/src/messages_nl.h +index 77efbb4..5a60d9e 100644 +--- a/src/messages_nl.h ++++ b/src/messages_nl.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "Geen userPassword attribuut aangetroffen. Controleer de toegangsrechten." + #define MSG_LDAP_INVALID_AUTH_METHOD "Onjuiste LDAPAuthMethod in de configuratie. Moet 'bind' of 'password' zijn." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_no.h b/src/messages_no.h +index f0be1b4..4c84405 100644 +--- a/src/messages_no.h ++++ b/src/messages_no.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_pl.h b/src/messages_pl.h +index c0be4d8..89d5af1 100644 +--- a/src/messages_pl.h ++++ b/src/messages_pl.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_pt_br.h b/src/messages_pt_br.h +index e5557b9..1dcfb64 100644 +--- a/src/messages_pt_br.h ++++ b/src/messages_pt_br.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_ro.h b/src/messages_ro.h +index 7bbcefe..da16a49 100644 +--- a/src/messages_ro.h ++++ b/src/messages_ro.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_ru.h b/src/messages_ru.h +index e0c1842..f0e4031 100644 +--- a/src/messages_ru.h ++++ b/src/messages_ru.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_sk.h b/src/messages_sk.h +index 24eca1b..e0ddd2a 100644 +--- a/src/messages_sk.h ++++ b/src/messages_sk.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_sv.h b/src/messages_sv.h +index b55c474..be4bbc1 100644 +--- a/src/messages_sv.h ++++ b/src/messages_sv.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_tr.h b/src/messages_tr.h +index 7d6db57..3ee84d2 100644 +--- a/src/messages_tr.h ++++ b/src/messages_tr.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_zh_cn.h b/src/messages_zh_cn.h +index a8bfc6c..93844fd 100644 +--- a/src/messages_zh_cn.h ++++ b/src/messages_zh_cn.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +diff --git a/src/messages_zh_tw.h b/src/messages_zh_tw.h +index db99719..05581bb 100644 +--- a/src/messages_zh_tw.h ++++ b/src/messages_zh_tw.h +@@ -227,3 +227,4 @@ + #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" + #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." + #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." ++#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" +-- +2.14.3 + diff --git a/0002-fedora-specific-config-file.patch b/0002-fedora-specific-config-file.patch index 725184c..e50a695 100644 --- a/0002-fedora-specific-config-file.patch +++ b/0002-fedora-specific-config-file.patch @@ -1,14 +1,14 @@ -From 5023020a73f60d4d512f934cfb67d94d1efd921c Mon Sep 17 00:00:00 2001 +From 23e169081a6cff2b73e521991fd9e260b49e80fa Mon Sep 17 00:00:00 2001 From: rpm-build Date: Thu, 14 Sep 2017 16:41:12 +0200 Subject: [PATCH] fedora specific config file --- - pure-ftpd.conf.in | 29 ++++++++++++++--------------- - 1 file changed, 14 insertions(+), 15 deletions(-) + pure-ftpd.conf.in | 31 +++++++++++++++---------------- + 1 file changed, 15 insertions(+), 16 deletions(-) diff --git a/pure-ftpd.conf.in b/pure-ftpd.conf.in -index fbaf9b4..b4d6837 100644 +index a327844..597ed59 100644 --- a/pure-ftpd.conf.in +++ b/pure-ftpd.conf.in @@ -9,7 +9,7 @@ @@ -20,6 +20,15 @@ index fbaf9b4..b4d6837 100644 # # Online documentation: # https://www.pureftpd.org/project/pure-ftpd/doc +@@ -42,7 +42,7 @@ MaxClientsNumber 50 + + + # Run as a background process +- ++# Important: this must be set to 'yes' for the systemd service to work. + Daemonize yes + + @@ -106,34 +106,34 @@ MaxIdleTime 15 # LDAP configuration file (see README.LDAP) @@ -61,9 +70,9 @@ index fbaf9b4..b4d6837 100644 -@@ -236,8 +236,7 @@ Umask 133:022 - - # Minimum UID for an authenticated user to log in. +@@ -238,8 +238,7 @@ Umask 133:022 + # For example, a value of 100 prevents all users whose user id is below + # 100 from logging in. If you want "root" to be able to log in, use 0. -MinUID 100 - @@ -71,7 +80,7 @@ index fbaf9b4..b4d6837 100644 # Allow FXP transfers for authenticated users. -@@ -275,7 +274,7 @@ AutoRename no +@@ -277,7 +276,7 @@ AutoRename no # Prevent anonymous users from uploading new files (no = upload is allowed) @@ -80,7 +89,7 @@ index fbaf9b4..b4d6837 100644 -@@ -299,21 +298,21 @@ AnonymousCantUpload no +@@ -301,21 +300,21 @@ AnonymousCantUpload no # fw.c9x.org - jedi [13/Apr/2017:19:36:39] "GET /ftp/linux.tar.bz2" 200 21809338 # This log file can then be processed by common HTTP traffic analyzers. @@ -105,7 +114,7 @@ index fbaf9b4..b4d6837 100644 -@@ -344,9 +343,9 @@ AnonymousCantUpload no +@@ -346,9 +345,9 @@ AnonymousCantUpload no # If your pure-ftpd has been compiled with standalone support, you can change @@ -118,5 +127,5 @@ index fbaf9b4..b4d6837 100644 -- -2.9.5 +2.14.3 diff --git a/pure-ftpd-with-tls.service b/pure-ftpd-with-tls.service index 95d982c..d7abfec 100644 --- a/pure-ftpd-with-tls.service +++ b/pure-ftpd-with-tls.service @@ -6,7 +6,7 @@ Requires=pure-ftpd-init.service [Service] Type=forking PIDFile=/var/run/pure-ftpd.pid -ExecStart=/usr/sbin/pure-ftpd /etc/pure-ftpd/pure-ftpd.conf --daemonize +ExecStart=/usr/sbin/pure-ftpd /etc/pure-ftpd/pure-ftpd.conf [Install] WantedBy=multi-user.target diff --git a/pure-ftpd.service b/pure-ftpd.service index c26bfb6..05bb621 100644 --- a/pure-ftpd.service +++ b/pure-ftpd.service @@ -5,7 +5,7 @@ After=syslog.target network.target [Service] Type=forking PIDFile=/var/run/pure-ftpd.pid -ExecStart=/usr/sbin/pure-ftpd /etc/pure-ftpd/pure-ftpd.conf --daemonize +ExecStart=/usr/sbin/pure-ftpd /etc/pure-ftpd/pure-ftpd.conf [Install] WantedBy=multi-user.target diff --git a/pure-ftpd.spec b/pure-ftpd.spec index e837f99..2d3fbcd 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd -Version: 1.0.46 -Release: 6%{?dist} +Version: 1.0.47 +Release: 1%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -18,7 +18,10 @@ Source8: pure-ftpd-with-tls-init.service Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch -Patch2: 0003-Allow-having-both-options-and-config-file-on-command.patch +# Upstream patch: +Patch2: 0001-Exit-when-given-an-invalid-cmdline-option.patch +# Upstream patch: +Patch3: 0002-Complain-when-both-options-and-config-file-are-given.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel @@ -249,6 +252,12 @@ fi %changelog +* Tue Feb 13 2018 OndÅ™ej LysonÄ›k - 1.0.47-1 +- New version +- Dropped patch 0003-Allow-having-both-options-and-config-file-on-command.patch + as it was rejected by upstream +- Complain when invalid or excessive arguments are given on the command line + * Fri Feb 09 2018 Fedora Release Engineering - 1.0.46-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild diff --git a/pure-ftpd.xinetd b/pure-ftpd.xinetd index e980e94..f3d3015 100644 --- a/pure-ftpd.xinetd +++ b/pure-ftpd.xinetd @@ -9,7 +9,7 @@ service ftp socket_type = stream wait = no user = root - server = /usr/sbin/pure-config.pl + server = /usr/sbin/pure-ftpd server_args = /etc/pure-ftpd/pure-ftpd.conf log_on_success += DURATION USERID log_on_failure += USERID diff --git a/sources b/sources index d223bc2..a5bbab1 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (pure-ftpd-1.0.46.tar.bz2) = e44c1842e6f101f4d7dd42617392f3d54ff58d68608f6a3bc5e612fc89bfd1da6935215a7e87c0d2bbd9fc9f0fa31a40ceb764fd67428dfdd8c5454e0d64e0ab +SHA512 (pure-ftpd-1.0.47.tar.bz2) = c1920a3f67f04635fde600fe226a7730b801e7e64658b25f1d9f9c0b35a704664be4adfb0b291594f7e0f10beade25eae9a5e6cc3b6777a3b413f3c2d9574e63 From b1400ae94bc5bec7b9501d84ce2c5d2ba315b3d4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Tue, 13 Feb 2018 14:45:02 +0100 Subject: [PATCH 14/51] Remove 0003-Allow-having-both-options-and-config-file-on-command.patch from the repo --- ...h-options-and-config-file-on-command.patch | 68 ------------------- 1 file changed, 68 deletions(-) delete mode 100644 0003-Allow-having-both-options-and-config-file-on-command.patch diff --git a/0003-Allow-having-both-options-and-config-file-on-command.patch b/0003-Allow-having-both-options-and-config-file-on-command.patch deleted file mode 100644 index 7eb99b2..0000000 --- a/0003-Allow-having-both-options-and-config-file-on-command.patch +++ /dev/null @@ -1,68 +0,0 @@ -From f5617a4de54c313580fe39562f0d32e5c95f5212 Mon Sep 17 00:00:00 2001 -From: rpm-build -Date: Thu, 14 Sep 2017 01:05:53 +0200 -Subject: [PATCH] Allow having both options and config file on command line - ---- - src/ftpd.c | 2 +- - src/simpleconf.c | 23 +++++++++++++++++++++-- - 2 files changed, 22 insertions(+), 3 deletions(-) - -diff --git a/src/ftpd.c b/src/ftpd.c -index c5edac5..b13afc0 100644 ---- a/src/ftpd.c -+++ b/src/ftpd.c -@@ -5589,7 +5589,7 @@ int pureftpd_start(int argc, char *argv[], const char *home_directory_) - #endif - - #ifndef MINIMAL -- if (argc == 2 && *argv[1] != '-' && -+ if (argc >= 2 && *argv[1] != '-' && - sc_build_command_line_from_file(argv[1], NULL, simpleconf_options, - (sizeof simpleconf_options) / - (sizeof simpleconf_options[0]), -diff --git a/src/simpleconf.c b/src/simpleconf.c -index f296f54..505aee1 100644 ---- a/src/simpleconf.c -+++ b/src/simpleconf.c -@@ -674,9 +674,10 @@ sc_build_command_line_from_file(const char *file_name, - { - char **argv = NULL; - int argc = 0; -+ char **argv_tmp = NULL; -+ char *arg = NULL; -+ int i; - -- *argc_p = 0; -- *argv_p = NULL; - if ((argv = malloc(sizeof *argv)) == NULL || - (app_name = strdup(app_name)) == NULL) { - sc_argv_free(argc, argv); -@@ -689,6 +690,24 @@ sc_build_command_line_from_file(const char *file_name, - sc_argv_free(argc, argv); - return -1; - } -+ -+ for (i = 2; i < *argc_p; ++i) { -+ ++argc; -+ arg = strdup((*argv_p)[i]); -+ if (arg == NULL) { -+ return -1; -+ } -+ if ((argv_tmp = realloc(argv, (sizeof arg) * -+ ((size_t) argc + 1))) == NULL) { -+ return -1; -+ } -+ argv = argv_tmp; -+ argv[argc - 1] = arg; -+ } -+ if (*argc_p > 2) { -+ argv[argc] = NULL; -+ } -+ - *argc_p = argc; - *argv_p = argv; - --- -2.9.5 - From 19810353e47a3fabcbadef6142e1369ee3075911 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Mon, 19 Feb 2018 14:52:33 +0100 Subject: [PATCH 15/51] Add gcc to BuildRequires --- pure-ftpd.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 2d3fbcd..eecef77 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -32,6 +32,7 @@ BuildRequires: pam-devel, libcap-devel BuildRequires: checkpolicy, selinux-policy-devel BuildRequires: systemd-units BuildRequires: git +BuildRequires: gcc Requires(post): systemd-sysv Requires(post): systemd-units Requires(preun): systemd-units @@ -252,6 +253,9 @@ fi %changelog +* Mon Feb 19 2018 OndÅ™ej LysonÄ›k - 1.0.47-2 +- Add gcc to BuildRequires + * Tue Feb 13 2018 OndÅ™ej LysonÄ›k - 1.0.47-1 - New version - Dropped patch 0003-Allow-having-both-options-and-config-file-on-command.patch From ac1fd363aecb17a1d57cbe49baf462088fa4d8bb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Thu, 15 Mar 2018 17:21:18 +0100 Subject: [PATCH 16/51] Increase max size of process's data segment Apply upstream patch to increase the size limit of the process's data segment. Upstream bug report: https://github.com/jedisct1/pure-ftpd/issues/82 Resolves: rhbz#1490354 --- ...TA_SIZE-due-to-Argon2id-requirements.patch | 25 +++++++++++++++++++ pure-ftpd.spec | 9 ++++++- 2 files changed, 33 insertions(+), 1 deletion(-) create mode 100644 0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch diff --git a/0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch b/0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch new file mode 100644 index 0000000..f9545bd --- /dev/null +++ b/0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch @@ -0,0 +1,25 @@ +From 27a5c200f9643ce907118aad169279b3a66a9e8a Mon Sep 17 00:00:00 2001 +From: Frank Denis +Date: Sat, 4 Nov 2017 20:46:16 +0100 +Subject: [PATCH] Increase MAX_DATA_SIZE due to Argon2id requirements + +--- + src/ftpd.h | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/ftpd.h b/src/ftpd.h +index 1beeab8..5bb1f6b 100644 +--- a/src/ftpd.h ++++ b/src/ftpd.h +@@ -557,7 +557,7 @@ Your platform has a very large PATH_MAX, we should not trust it. + + #ifndef MAX_DATA_SIZE + # ifdef HAVE_LIBSODIUM +-# define MAX_DATA_SIZE (40 * 1024 * 1024) ++# define MAX_DATA_SIZE (70 * 1024 * 1024) + # elif defined(WITH_LDAP) || defined(WITH_MYSQL) || defined(WITH_PGSQL) + # define MAX_DATA_SIZE (16 * 1024 * 1024) /* Max memory usage - SQL/LDAP need more */ + # else +-- +2.14.3 + diff --git a/pure-ftpd.spec b/pure-ftpd.spec index eecef77..02eb8db 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -22,6 +22,8 @@ Patch1: 0002-fedora-specific-config-file.patch Patch2: 0001-Exit-when-given-an-invalid-cmdline-option.patch # Upstream patch: Patch3: 0002-Complain-when-both-options-and-config-file-are-given.patch +# Upstream patch: +Patch4: 0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel @@ -253,6 +255,11 @@ fi %changelog +* Thu Mar 15 2018 OndÅ™ej LysonÄ›k - 1.0.47-3 +- Apply upstream patch to increase the size limit of the process's data segment +- https://github.com/jedisct1/pure-ftpd/issues/82 +- Resolves: rhbz#1490354 + * Mon Feb 19 2018 OndÅ™ej LysonÄ›k - 1.0.47-2 - Add gcc to BuildRequires From 0e9f57032281024755cf1e91b1010ab86fa212a4 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 13 Jul 2018 23:00:44 +0000 Subject: [PATCH 17/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 02eb8db..50da87b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Lightweight, fast and secure FTP server Group: System Environment/Daemons @@ -255,6 +255,9 @@ fi %changelog +* Fri Jul 13 2018 Fedora Release Engineering - 1.0.47-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + * Thu Mar 15 2018 OndÅ™ej LysonÄ›k - 1.0.47-3 - Apply upstream patch to increase the size limit of the process's data segment - https://github.com/jedisct1/pure-ftpd/issues/82 From 67313c1a47d588bd52bec374312586ccddf61266 Mon Sep 17 00:00:00 2001 From: Pavel Raiskup Date: Thu, 6 Sep 2018 10:10:15 +0200 Subject: [PATCH 18/51] BuildRequires: s/postgresql-devel/libpq-devel/ That's because we moved libpq.so.5 into libpq package. Related: rhbz#1618698, rhbz#1623764 --- pure-ftpd.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 50da87b..3dd1b75 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -29,7 +29,7 @@ Provides: ftpserver BuildRequires: pam-devel, libcap-devel %{!?_without_ldap:BuildRequires: openldap-devel} %{!?_without_mysql:BuildRequires: mariadb-connector-c-devel} -%{!?_without_pgsql:BuildRequires: postgresql-devel} +%{!?_without_pgsql:BuildRequires: libpq-devel} %{!?_without_tls:BuildRequires: openssl-devel} BuildRequires: checkpolicy, selinux-policy-devel BuildRequires: systemd-units From 1a87daeffae5fc92d0498f4660b645dd2c21acfd Mon Sep 17 00:00:00 2001 From: Peter Robinson Date: Sun, 18 Nov 2018 22:35:35 +0000 Subject: [PATCH 19/51] Drop sysv legacy bits --- pure-ftpd-with-tls-init.service | 10 ------- pure-ftpd.spec | 52 +++++++++------------------------ pure-ftpd.xinetd | 17 ----------- 3 files changed, 14 insertions(+), 65 deletions(-) delete mode 100644 pure-ftpd-with-tls-init.service delete mode 100644 pure-ftpd.xinetd diff --git a/pure-ftpd-with-tls-init.service b/pure-ftpd-with-tls-init.service deleted file mode 100644 index aab2191..0000000 --- a/pure-ftpd-with-tls-init.service +++ /dev/null @@ -1,10 +0,0 @@ -[Unit] -Description=One-time configuration for pure-ftpd - -ConditionPathExists=|!/etc/pki/pure-ftpd/pure-ftpd.pem - -[Service] -Type=oneshot -RemainAfterExit=no - -ExecStart=/usr/bin/sscg --ca-file /etc/pki/pure-ftpd/ca.crt --cert-file /etc/pki/pure-ftpd/pure-ftpd.pem --cert-key-file /etc/pki/pure-ftpd/pure-ftpd.pem diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 3dd1b75..5c6c3dc 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,20 +1,17 @@ Name: pure-ftpd Version: 1.0.47 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Lightweight, fast and secure FTP server - -Group: System Environment/Daemons License: BSD URL: http://www.pureftpd.org + Source0: http://download.pureftpd.org/pub/pure-ftpd/releases/pure-ftpd-%{version}.tar.bz2 Source1: pure-ftpd.service Source2: pure-ftpd.logrotate -Source3: pure-ftpd.xinetd Source4: pure-ftpd.pure-ftpwho.pam Source5: pure-ftpd.pure-ftpwho.consoleapp Source6: pure-ftpd.README.SELinux Source7: pure-ftpd.pureftpd.te -Source8: pure-ftpd-with-tls-init.service Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch @@ -32,13 +29,12 @@ BuildRequires: pam-devel, libcap-devel %{!?_without_pgsql:BuildRequires: libpq-devel} %{!?_without_tls:BuildRequires: openssl-devel} BuildRequires: checkpolicy, selinux-policy-devel -BuildRequires: systemd-units +BuildRequires: systemd BuildRequires: git BuildRequires: gcc -Requires(post): systemd-sysv -Requires(post): systemd-units -Requires(preun): systemd-units -Requires(postun): systemd-units +Requires(post): systemd +Requires(preun): systemd +Requires(postun): systemd Requires: logrotate, usermode %{!?_without_tls:Requires: sscg} @@ -62,10 +58,9 @@ Rebuild switches: %package selinux Summary: SELinux support for Pure-FTPD -Group: System Environment/Daemons Requires: %{name} = %{version} -Requires(post): policycoreutils, initscripts, %{name} -Requires(preun): policycoreutils, initscripts, %{name} +Requires(post): policycoreutils, %{name} +Requires(preun): policycoreutils, %{name} Requires(postun): policycoreutils %description selinux @@ -142,7 +137,6 @@ install -p -m 644 man/pure-authd.8 $RPM_BUILD_ROOT%{_mandir}/man8 # Systemd services %if 0%{!?_without_tls:1} -install -p -m 644 %{SOURCE8} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd-init.service install -p -m 644 %{SOURCE9} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd.service %else install -p -m 644 %{SOURCE1} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd.service @@ -156,10 +150,6 @@ install -p -m 644 pam/pure-ftpd $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/ install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d install -p -m 644 %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/%{name} -# xinetd support -install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/xinetd.d -install -p -m 644 %{SOURCE3} $RPM_BUILD_ROOT%{_sysconfdir}/xinetd.d/%{name} - # pure-ftpwho and non-root users install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/security/console.apps install -p -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/pure-ftpwho @@ -195,14 +185,14 @@ install -p -m 644 pureftpd.schema $RPM_BUILD_ROOT%{_docdir}/%{name} if [ "$1" -le "1" ]; then # Fist install semodule -i %{_datadir}/selinux/packages/%{name}/pureftpd.pp 2>/dev/null || : fixfiles -R pure-ftpd restore || : - /sbin/service pure-ftpd condrestart > /dev/null 2>&1 || : + /bin/systemctl condrestart pure-ftpd > /dev/null 2>&1 || : fi %preun selinux if [ "$1" -lt "1" ]; then # Final removal semodule -r pureftpd 2>/dev/null || : fixfiles -R pure-ftpd restore || : - /sbin/service pure-ftpd condrestart > /dev/null 2>&1 || : + /bin/systemctl condrestart pure-ftpd > /dev/null 2>&1 || : fi %postun selinux @@ -213,17 +203,6 @@ if [ "$1" -ge "1" ]; then # Upgrade fi -%triggerun -- pure-ftpd < 1.0.32-2 -# Save the current service runlevel info -# User must manually run systemd-sysv-convert --apply pure-ftpd -# to migrate them to systemd targets -/usr/bin/systemd-sysv-convert --save pure-ftpd >/dev/null 2>&1 ||: - -# Run these because the SysV package being removed won't do them -/sbin/chkconfig --del pure-ftpd >/dev/null 2>&1 || : -/bin/systemctl try-restart pure-ftpd.service >/dev/null 2>&1 || : - - %files %doc FAQ THANKS AUTHORS CONTACT HISTORY NEWS %doc README README.Authentication-Modules README.Configuration-File @@ -232,16 +211,10 @@ fi %doc pureftpd.schema %{_bindir}/pure-* %{_sbindir}/pure-* -%if 0%{!?_without_tls:1} - %{_unitdir}/pure-ftpd-init.service - %{_unitdir}/pure-ftpd.service -%else - %{_unitdir}/pure-ftpd.service -%endif +%{_unitdir}/pure-ftpd.service %config(noreplace) %{_sysconfdir}/%{name} %config(noreplace) %{_sysconfdir}/pam.d/%{name} %config(noreplace) %{_sysconfdir}/logrotate.d/%{name} -%config(noreplace) %{_sysconfdir}/xinetd.d/%{name} %config(noreplace) %{_sysconfdir}/pam.d/pure-ftpwho %config(noreplace) %{_sysconfdir}/security/console.apps/pure-ftpwho %{!?_without_tls:%{_sysconfdir}/pki/%{name}} @@ -255,6 +228,9 @@ fi %changelog +* Sun Nov 18 2018 Peter Robinson 1.0.47-5 +- Drop sysv legacy bits + * Fri Jul 13 2018 Fedora Release Engineering - 1.0.47-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild diff --git a/pure-ftpd.xinetd b/pure-ftpd.xinetd deleted file mode 100644 index f3d3015..0000000 --- a/pure-ftpd.xinetd +++ /dev/null @@ -1,17 +0,0 @@ -# default: off -# description: pure-ftpd server, xinetd version. \ -# Don't run the standalone version if you run \ -# this and remember do set "Daemonize" to "no" \ -# in /etc/pure-ftpd/pure-ftpd.conf -service ftp -{ - disable = yes - socket_type = stream - wait = no - user = root - server = /usr/sbin/pure-ftpd - server_args = /etc/pure-ftpd/pure-ftpd.conf - log_on_success += DURATION USERID - log_on_failure += USERID - nice = 10 -} From a887e6bdeb0158a22e971b49fefc6166f158e240 Mon Sep 17 00:00:00 2001 From: Peter Robinson Date: Mon, 19 Nov 2018 22:27:23 +0000 Subject: [PATCH 20/51] Fix for oversight in previous change --- pure-ftpd-with-tls-init.service | 10 ++++++++++ pure-ftpd.spec | 12 +++++++++++- 2 files changed, 21 insertions(+), 1 deletion(-) create mode 100644 pure-ftpd-with-tls-init.service diff --git a/pure-ftpd-with-tls-init.service b/pure-ftpd-with-tls-init.service new file mode 100644 index 0000000..aab2191 --- /dev/null +++ b/pure-ftpd-with-tls-init.service @@ -0,0 +1,10 @@ +[Unit] +Description=One-time configuration for pure-ftpd + +ConditionPathExists=|!/etc/pki/pure-ftpd/pure-ftpd.pem + +[Service] +Type=oneshot +RemainAfterExit=no + +ExecStart=/usr/bin/sscg --ca-file /etc/pki/pure-ftpd/ca.crt --cert-file /etc/pki/pure-ftpd/pure-ftpd.pem --cert-key-file /etc/pki/pure-ftpd/pure-ftpd.pem diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 5c6c3dc..3ac34e9 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -12,6 +12,7 @@ Source4: pure-ftpd.pure-ftpwho.pam Source5: pure-ftpd.pure-ftpwho.consoleapp Source6: pure-ftpd.README.SELinux Source7: pure-ftpd.pureftpd.te +Source8: pure-ftpd-with-tls-init.service Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch @@ -137,6 +138,7 @@ install -p -m 644 man/pure-authd.8 $RPM_BUILD_ROOT%{_mandir}/man8 # Systemd services %if 0%{!?_without_tls:1} +install -p -m 644 %{SOURCE8} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd-init.service install -p -m 644 %{SOURCE9} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd.service %else install -p -m 644 %{SOURCE1} $RPM_BUILD_ROOT%{_unitdir}/pure-ftpd.service @@ -211,7 +213,12 @@ fi %doc pureftpd.schema %{_bindir}/pure-* %{_sbindir}/pure-* +%if 0%{!?_without_tls:1} +%{_unitdir}/pure-ftpd-init.service %{_unitdir}/pure-ftpd.service +%else +%{_unitdir}/pure-ftpd.service +%endif %config(noreplace) %{_sysconfdir}/%{name} %config(noreplace) %{_sysconfdir}/pam.d/%{name} %config(noreplace) %{_sysconfdir}/logrotate.d/%{name} @@ -228,6 +235,9 @@ fi %changelog +* Mon Nov 19 2018 Peter Robinson 1.0.47-6 +- Fix for oversight in previous change + * Sun Nov 18 2018 Peter Robinson 1.0.47-5 - Drop sysv legacy bits From 510001054437cae71f76cef74dbc4fb053b57062 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Mon, 14 Jan 2019 19:13:51 +0100 Subject: [PATCH 21/51] Rebuilt for libcrypt.so.2 (#1666033) --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 3ac34e9..8e8c219 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -235,6 +235,9 @@ fi %changelog +* Mon Jan 14 2019 Björn Esser - 1.0.47-7 +- Rebuilt for libcrypt.so.2 (#1666033) + * Mon Nov 19 2018 Peter Robinson 1.0.47-6 - Fix for oversight in previous change From f5c72017e3c4248c815b39367cf12e997560d41c Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 2 Feb 2019 05:00:55 +0000 Subject: [PATCH 22/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 8e8c219..c26bcb2 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -235,6 +235,9 @@ fi %changelog +* Sat Feb 02 2019 Fedora Release Engineering - 1.0.47-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + * Mon Jan 14 2019 Björn Esser - 1.0.47-7 - Rebuilt for libcrypt.so.2 (#1666033) From 926e446efe55258eec6a3a638ed4a5b1e3485120 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Tue, 5 Feb 2019 16:18:56 +0100 Subject: [PATCH 23/51] Fixed TLSv1.3 support, fixed postgresql authentication Resolves: rhbz#1654838 --- 0001-Fix-postgresql-authenticate-bug.patch | 25 +++++++++++ 0001-TLS1.3-compatibility.patch | 49 ++++++++++++++++++++++ pure-ftpd.spec | 11 ++++- 3 files changed, 84 insertions(+), 1 deletion(-) create mode 100644 0001-Fix-postgresql-authenticate-bug.patch create mode 100644 0001-TLS1.3-compatibility.patch diff --git a/0001-Fix-postgresql-authenticate-bug.patch b/0001-Fix-postgresql-authenticate-bug.patch new file mode 100644 index 0000000..b6044be --- /dev/null +++ b/0001-Fix-postgresql-authenticate-bug.patch @@ -0,0 +1,25 @@ +From 6a256a21e48177e1d73d7e70b2292c76ac40ffb7 Mon Sep 17 00:00:00 2001 +From: t-asaka +Date: Mon, 28 May 2018 22:29:25 +0900 +Subject: [PATCH] Fix postgresql authenticate bug + +--- + src/log_pgsql.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/log_pgsql.c b/src/log_pgsql.c +index 4df654e..3825afb 100644 +--- a/src/log_pgsql.c ++++ b/src/log_pgsql.c +@@ -504,7 +504,7 @@ void pw_pgsql_check(AuthResult * const result, + crypto_crypt++; + crypto_md5++; + crypto_sha1++; +- } else if (strcasecmp(crypto, PASSWD_SQL_ARGON2)) { ++ } else if (strcasecmp(crypto, PASSWD_SQL_ARGON2) == 0) { + crypto_argon2++; + } else if (strcasecmp(crypto, PASSWD_SQL_SCRYPT) == 0) { + crypto_scrypt++; +-- +2.20.1 + diff --git a/0001-TLS1.3-compatibility.patch b/0001-TLS1.3-compatibility.patch new file mode 100644 index 0000000..9604c7a --- /dev/null +++ b/0001-TLS1.3-compatibility.patch @@ -0,0 +1,49 @@ +From 4a495c61ce22c893aed5ee57f6ce0b43c3be59ad Mon Sep 17 00:00:00 2001 +From: Frank Denis +Date: Wed, 19 Sep 2018 23:53:45 +0200 +Subject: [PATCH] TLS1.3 compatibility + +Fixes #94 +--- + src/tls.c | 17 +++++++++++++---- + 1 file changed, 13 insertions(+), 4 deletions(-) + +diff --git a/src/tls.c b/src/tls.c +index c693d3b..f383ed9 100644 +--- a/src/tls.c ++++ b/src/tls.c +@@ -228,7 +228,16 @@ static void ssl_info_cb(const SSL *cnx, int where, int ret) + if ((where & SSL_CB_HANDSHAKE_START) != 0) { + if ((cnx == tls_cnx && tls_cnx_handshook != 0) || + (cnx == tls_data_cnx && tls_data_cnx_handshook != 0)) { +- die(400, LOG_ERR, "TLS renegociation"); ++ const SSL_CIPHER *cipher; ++ const char *cipher_version; ++ if ((cipher = SSL_get_current_cipher(cnx)) == NULL || ++ (cipher_version = SSL_CIPHER_get_version(cipher)) == NULL) { ++ die(400, LOG_ERR, "No cipher"); ++ } ++ if (strcmp(cipher_version, "TLSv1.3") != 0) { ++ die(400, LOG_ERR, "TLS renegociation"); ++ return; ++ } + } + return; + } +@@ -264,10 +273,10 @@ int tls_init_library(void) + OpenSSL_add_all_algorithms(); + # else + OPENSSL_init_ssl(OPENSSL_INIT_LOAD_SSL_STRINGS | +- OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL); ++ OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL); + OPENSSL_init_crypto(OPENSSL_INIT_ADD_ALL_CIPHERS | +- OPENSSL_INIT_ADD_ALL_DIGESTS | +- OPENSSL_INIT_LOAD_CONFIG, NULL); ++ OPENSSL_INIT_ADD_ALL_DIGESTS | ++ OPENSSL_INIT_LOAD_CONFIG, NULL); + # endif + while (RAND_status() == 0) { + rnd = zrand(); +-- +2.20.1 + diff --git a/pure-ftpd.spec b/pure-ftpd.spec index c26bcb2..7116c1b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -22,6 +22,10 @@ Patch2: 0001-Exit-when-given-an-invalid-cmdline-option.patch Patch3: 0002-Complain-when-both-options-and-config-file-are-given.patch # Upstream patch: Patch4: 0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch +# Upstream patch: +Patch5: 0001-TLS1.3-compatibility.patch +# Upstream patch: +Patch6: 0001-Fix-postgresql-authenticate-bug.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel @@ -235,6 +239,11 @@ fi %changelog +* Tue Feb 05 2019 OndÅ™ej LysonÄ›k - 1.0.47-9 +- Fixed TLSv1.3 support +- Resolves: rhbz#1654838 +- Fixed postgresql authentication + * Sat Feb 02 2019 Fedora Release Engineering - 1.0.47-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild From 9911e254ecce86af8ebcec59ad2d2955d902545c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Tue, 12 Feb 2019 12:51:37 +0100 Subject: [PATCH 24/51] Temporarily disable TLSv1.3 support until it's fully fixed --- 0001-TLS1.3-compatibility.patch | 49 ------------------- ...-Temporarily-disable-TLSv1.3-support.patch | 30 ++++++++++++ pure-ftpd.spec | 11 +++-- 3 files changed, 38 insertions(+), 52 deletions(-) delete mode 100644 0001-TLS1.3-compatibility.patch create mode 100644 0001-Temporarily-disable-TLSv1.3-support.patch diff --git a/0001-TLS1.3-compatibility.patch b/0001-TLS1.3-compatibility.patch deleted file mode 100644 index 9604c7a..0000000 --- a/0001-TLS1.3-compatibility.patch +++ /dev/null @@ -1,49 +0,0 @@ -From 4a495c61ce22c893aed5ee57f6ce0b43c3be59ad Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Wed, 19 Sep 2018 23:53:45 +0200 -Subject: [PATCH] TLS1.3 compatibility - -Fixes #94 ---- - src/tls.c | 17 +++++++++++++---- - 1 file changed, 13 insertions(+), 4 deletions(-) - -diff --git a/src/tls.c b/src/tls.c -index c693d3b..f383ed9 100644 ---- a/src/tls.c -+++ b/src/tls.c -@@ -228,7 +228,16 @@ static void ssl_info_cb(const SSL *cnx, int where, int ret) - if ((where & SSL_CB_HANDSHAKE_START) != 0) { - if ((cnx == tls_cnx && tls_cnx_handshook != 0) || - (cnx == tls_data_cnx && tls_data_cnx_handshook != 0)) { -- die(400, LOG_ERR, "TLS renegociation"); -+ const SSL_CIPHER *cipher; -+ const char *cipher_version; -+ if ((cipher = SSL_get_current_cipher(cnx)) == NULL || -+ (cipher_version = SSL_CIPHER_get_version(cipher)) == NULL) { -+ die(400, LOG_ERR, "No cipher"); -+ } -+ if (strcmp(cipher_version, "TLSv1.3") != 0) { -+ die(400, LOG_ERR, "TLS renegociation"); -+ return; -+ } - } - return; - } -@@ -264,10 +273,10 @@ int tls_init_library(void) - OpenSSL_add_all_algorithms(); - # else - OPENSSL_init_ssl(OPENSSL_INIT_LOAD_SSL_STRINGS | -- OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL); -+ OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL); - OPENSSL_init_crypto(OPENSSL_INIT_ADD_ALL_CIPHERS | -- OPENSSL_INIT_ADD_ALL_DIGESTS | -- OPENSSL_INIT_LOAD_CONFIG, NULL); -+ OPENSSL_INIT_ADD_ALL_DIGESTS | -+ OPENSSL_INIT_LOAD_CONFIG, NULL); - # endif - while (RAND_status() == 0) { - rnd = zrand(); --- -2.20.1 - diff --git a/0001-Temporarily-disable-TLSv1.3-support.patch b/0001-Temporarily-disable-TLSv1.3-support.patch new file mode 100644 index 0000000..5297028 --- /dev/null +++ b/0001-Temporarily-disable-TLSv1.3-support.patch @@ -0,0 +1,30 @@ +From f9e232ffb44c96538f2a12c4bc4970f228f971cd Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= +Date: Tue, 12 Feb 2019 11:17:16 +0100 +Subject: [PATCH] Temporarily disable TLSv1.3 support + +Disable TLSv1.3 until support for it is fixed in pure-ftpd. This is a +workaround for the following issue: +https://github.com/jedisct1/pure-ftpd/issues/102 +--- + src/tls.c | 4 ++++ + 1 file changed, 4 insertions(+) + +diff --git a/src/tls.c b/src/tls.c +index c4e2a1b..41d619f 100644 +--- a/src/tls.c ++++ b/src/tls.c +@@ -301,6 +301,10 @@ int tls_init_library(void) + # endif + # ifdef SSL_OP_NO_TLSv1_2 + SSL_CTX_clear_options(tls_ctx, SSL_OP_NO_TLSv1_2); ++# endif ++ /* Disable TLSv1.3 support until it works properly in pure-ftpd */ ++# ifdef SSL_OP_NO_TLSv1_3 ++ SSL_CTX_set_options(tls_ctx, SSL_OP_NO_TLSv1_3); + # endif + if (tlsciphersuite != NULL) { + if (SSL_CTX_set_cipher_list(tls_ctx, tlsciphersuite) != 1) { +-- +2.20.1 + diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 7116c1b..32416a7 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.47 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -23,10 +23,12 @@ Patch3: 0002-Complain-when-both-options-and-config-file-are-given.patch # Upstream patch: Patch4: 0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch # Upstream patch: -Patch5: 0001-TLS1.3-compatibility.patch -# Upstream patch: Patch6: 0001-Fix-postgresql-authenticate-bug.patch +# Temporarily disable TLSv1.3 to workaround +# https://github.com/jedisct1/pure-ftpd/issues/102 +Patch7: 0001-Temporarily-disable-TLSv1.3-support.patch + Provides: ftpserver BuildRequires: pam-devel, libcap-devel %{!?_without_ldap:BuildRequires: openldap-devel} @@ -239,6 +241,9 @@ fi %changelog +* Tue Feb 12 2019 OndÅ™ej LysonÄ›k - 1.0.47-10 +- Temporarily disable TLSv1.3 support until it's fully fixed + * Tue Feb 05 2019 OndÅ™ej LysonÄ›k - 1.0.47-9 - Fixed TLSv1.3 support - Resolves: rhbz#1654838 From 40501949977d87db5cf54f19ecd1bdcd88046dec Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Fri, 29 Mar 2019 13:22:58 +0100 Subject: [PATCH 25/51] New version Resolves: rhbz#1692539 Resolves: rhbz#1672494 Resolves: rhbz#1654838 --- .gitignore | 1 + ...when-given-an-invalid-cmdline-option.patch | 25 -- 0001-Fix-postgresql-authenticate-bug.patch | 25 -- ...TA_SIZE-due-to-Argon2id-requirements.patch | 25 -- ...-Temporarily-disable-TLSv1.3-support.patch | 30 --- ...th-options-and-config-file-are-given.patch | 237 ------------------ 0002-fedora-specific-config-file.patch | 8 +- pure-ftpd.spec | 32 +-- sources | 2 +- 9 files changed, 18 insertions(+), 367 deletions(-) delete mode 100644 0001-Exit-when-given-an-invalid-cmdline-option.patch delete mode 100644 0001-Fix-postgresql-authenticate-bug.patch delete mode 100644 0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch delete mode 100644 0001-Temporarily-disable-TLSv1.3-support.patch delete mode 100644 0002-Complain-when-both-options-and-config-file-are-given.patch diff --git a/.gitignore b/.gitignore index 3c3f0e2..da05c2a 100644 --- a/.gitignore +++ b/.gitignore @@ -9,3 +9,4 @@ pure-ftpd-1.0.29.tar.bz2 /pure-ftpd-1.0.42.tar.bz2 /pure-ftpd-1.0.46.tar.bz2 /pure-ftpd-1.0.47.tar.bz2 +/pure-ftpd-1.0.48.tar.bz2 diff --git a/0001-Exit-when-given-an-invalid-cmdline-option.patch b/0001-Exit-when-given-an-invalid-cmdline-option.patch deleted file mode 100644 index 2e069d8..0000000 --- a/0001-Exit-when-given-an-invalid-cmdline-option.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 8b6e9370ccbdff47107963c352caab24fdb0fcaa Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= -Date: Wed, 7 Feb 2018 13:28:02 +0100 -Subject: [PATCH 1/2] Exit when given an invalid cmdline option - ---- - src/ftpd.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/ftpd.c b/src/ftpd.c -index e19d8de..5c77410 100644 ---- a/src/ftpd.c -+++ b/src/ftpd.c -@@ -6192,7 +6192,7 @@ int pureftpd_start(int argc, char *argv[], const char *home_directory_) - exit(EXIT_SUCCESS); - } - default: -- logfile(LOG_WARNING, MSG_ILLEGAL_OPTION); -+ die(421, LOG_ERR, MSG_ILLEGAL_OPTION); - } - } - #ifdef WITH_RFC2640 --- -2.14.3 - diff --git a/0001-Fix-postgresql-authenticate-bug.patch b/0001-Fix-postgresql-authenticate-bug.patch deleted file mode 100644 index b6044be..0000000 --- a/0001-Fix-postgresql-authenticate-bug.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 6a256a21e48177e1d73d7e70b2292c76ac40ffb7 Mon Sep 17 00:00:00 2001 -From: t-asaka -Date: Mon, 28 May 2018 22:29:25 +0900 -Subject: [PATCH] Fix postgresql authenticate bug - ---- - src/log_pgsql.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/log_pgsql.c b/src/log_pgsql.c -index 4df654e..3825afb 100644 ---- a/src/log_pgsql.c -+++ b/src/log_pgsql.c -@@ -504,7 +504,7 @@ void pw_pgsql_check(AuthResult * const result, - crypto_crypt++; - crypto_md5++; - crypto_sha1++; -- } else if (strcasecmp(crypto, PASSWD_SQL_ARGON2)) { -+ } else if (strcasecmp(crypto, PASSWD_SQL_ARGON2) == 0) { - crypto_argon2++; - } else if (strcasecmp(crypto, PASSWD_SQL_SCRYPT) == 0) { - crypto_scrypt++; --- -2.20.1 - diff --git a/0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch b/0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch deleted file mode 100644 index f9545bd..0000000 --- a/0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch +++ /dev/null @@ -1,25 +0,0 @@ -From 27a5c200f9643ce907118aad169279b3a66a9e8a Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Sat, 4 Nov 2017 20:46:16 +0100 -Subject: [PATCH] Increase MAX_DATA_SIZE due to Argon2id requirements - ---- - src/ftpd.h | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/ftpd.h b/src/ftpd.h -index 1beeab8..5bb1f6b 100644 ---- a/src/ftpd.h -+++ b/src/ftpd.h -@@ -557,7 +557,7 @@ Your platform has a very large PATH_MAX, we should not trust it. - - #ifndef MAX_DATA_SIZE - # ifdef HAVE_LIBSODIUM --# define MAX_DATA_SIZE (40 * 1024 * 1024) -+# define MAX_DATA_SIZE (70 * 1024 * 1024) - # elif defined(WITH_LDAP) || defined(WITH_MYSQL) || defined(WITH_PGSQL) - # define MAX_DATA_SIZE (16 * 1024 * 1024) /* Max memory usage - SQL/LDAP need more */ - # else --- -2.14.3 - diff --git a/0001-Temporarily-disable-TLSv1.3-support.patch b/0001-Temporarily-disable-TLSv1.3-support.patch deleted file mode 100644 index 5297028..0000000 --- a/0001-Temporarily-disable-TLSv1.3-support.patch +++ /dev/null @@ -1,30 +0,0 @@ -From f9e232ffb44c96538f2a12c4bc4970f228f971cd Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= -Date: Tue, 12 Feb 2019 11:17:16 +0100 -Subject: [PATCH] Temporarily disable TLSv1.3 support - -Disable TLSv1.3 until support for it is fixed in pure-ftpd. This is a -workaround for the following issue: -https://github.com/jedisct1/pure-ftpd/issues/102 ---- - src/tls.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/src/tls.c b/src/tls.c -index c4e2a1b..41d619f 100644 ---- a/src/tls.c -+++ b/src/tls.c -@@ -301,6 +301,10 @@ int tls_init_library(void) - # endif - # ifdef SSL_OP_NO_TLSv1_2 - SSL_CTX_clear_options(tls_ctx, SSL_OP_NO_TLSv1_2); -+# endif -+ /* Disable TLSv1.3 support until it works properly in pure-ftpd */ -+# ifdef SSL_OP_NO_TLSv1_3 -+ SSL_CTX_set_options(tls_ctx, SSL_OP_NO_TLSv1_3); - # endif - if (tlsciphersuite != NULL) { - if (SSL_CTX_set_cipher_list(tls_ctx, tlsciphersuite) != 1) { --- -2.20.1 - diff --git a/0002-Complain-when-both-options-and-config-file-are-given.patch b/0002-Complain-when-both-options-and-config-file-are-given.patch deleted file mode 100644 index 12169f7..0000000 --- a/0002-Complain-when-both-options-and-config-file-are-given.patch +++ /dev/null @@ -1,237 +0,0 @@ -From 4328fd5142d0f981687a484f4be34333432d27d1 Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= -Date: Wed, 7 Feb 2018 15:05:25 +0100 -Subject: [PATCH 2/2] Complain when both options and config file are given on - cmdline - ---- - src/ftpd.c | 3 +++ - src/messages_cs_cz.h | 1 + - src/messages_da.h | 1 + - src/messages_de.h | 1 + - src/messages_en.h | 1 + - src/messages_es.h | 1 + - src/messages_fr.h | 1 + - src/messages_fr_funny.h | 1 + - src/messages_hu.h | 1 + - src/messages_it.h | 1 + - src/messages_kr.h | 1 + - src/messages_nl.h | 1 + - src/messages_no.h | 1 + - src/messages_pl.h | 1 + - src/messages_pt_br.h | 1 + - src/messages_ro.h | 1 + - src/messages_ru.h | 1 + - src/messages_sk.h | 1 + - src/messages_sv.h | 1 + - src/messages_tr.h | 1 + - src/messages_zh_cn.h | 1 + - src/messages_zh_tw.h | 1 + - 22 files changed, 24 insertions(+) - -diff --git a/src/ftpd.c b/src/ftpd.c -index 5c77410..3f474d2 100644 ---- a/src/ftpd.c -+++ b/src/ftpd.c -@@ -6195,6 +6195,9 @@ int pureftpd_start(int argc, char *argv[], const char *home_directory_) - die(421, LOG_ERR, MSG_ILLEGAL_OPTION); - } - } -+ if (optind < argc) { -+ die(421, LOG_ERR, MSG_INVALID_ARGUMENT, argv[optind]); -+ } - #ifdef WITH_RFC2640 - if (charset_fs == NULL) { - charset_fs = (char *) "utf-8"; -diff --git a/src/messages_cs_cz.h b/src/messages_cs_cz.h -index ef225ba..e103b37 100644 ---- a/src/messages_cs_cz.h -+++ b/src/messages_cs_cz.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Neplatný argument: \"%s\"" -diff --git a/src/messages_da.h b/src/messages_da.h -index ed6f77c..c79ad5a 100644 ---- a/src/messages_da.h -+++ b/src/messages_da.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_de.h b/src/messages_de.h -index e7ae9a9..cd6bc08 100644 ---- a/src/messages_de.h -+++ b/src/messages_de.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_en.h b/src/messages_en.h -index e980131..cb9abf3 100644 ---- a/src/messages_en.h -+++ b/src/messages_en.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_es.h b/src/messages_es.h -index 0c27d4f..60ed849 100644 ---- a/src/messages_es.h -+++ b/src/messages_es.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_fr.h b/src/messages_fr.h -index 7f41dae..a012c05 100644 ---- a/src/messages_fr.h -+++ b/src/messages_fr.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT doit etre precede d'une commande PBSZ reussie" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP n'a pas retourne d'attribut userPassword, verifiez les droits d'acces LDAP." - #define MSG_LDAP_INVALID_AUTH_METHOD "Methode LDAPAuthMethod invalide dans le fichier de configuration. Ce doit etre 'bind' ou 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_fr_funny.h b/src/messages_fr_funny.h -index c77e5bc..dff760b 100644 ---- a/src/messages_fr_funny.h -+++ b/src/messages_fr_funny.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT ca marche qu'apres un PBSZ reussi" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP n'a pas retourne d'attribut userPassword, ptet que les droits d'acces LDAP chient." - #define MSG_LDAP_INVALID_AUTH_METHOD "LDAPAuthMethod dans le fichier de conf, ca doit etre 'bind' ou 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_hu.h b/src/messages_hu.h -index b3beead..7c5a101 100644 ---- a/src/messages_hu.h -+++ b/src/messages_hu.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_it.h b/src/messages_it.h -index 4e6e984..e30f517 100644 ---- a/src/messages_it.h -+++ b/src/messages_it.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_kr.h b/src/messages_kr.h -index 14d8300..c9faead 100644 ---- a/src/messages_kr.h -+++ b/src/messages_kr.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_nl.h b/src/messages_nl.h -index 77efbb4..5a60d9e 100644 ---- a/src/messages_nl.h -+++ b/src/messages_nl.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "Geen userPassword attribuut aangetroffen. Controleer de toegangsrechten." - #define MSG_LDAP_INVALID_AUTH_METHOD "Onjuiste LDAPAuthMethod in de configuratie. Moet 'bind' of 'password' zijn." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_no.h b/src/messages_no.h -index f0be1b4..4c84405 100644 ---- a/src/messages_no.h -+++ b/src/messages_no.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_pl.h b/src/messages_pl.h -index c0be4d8..89d5af1 100644 ---- a/src/messages_pl.h -+++ b/src/messages_pl.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_pt_br.h b/src/messages_pt_br.h -index e5557b9..1dcfb64 100644 ---- a/src/messages_pt_br.h -+++ b/src/messages_pt_br.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_ro.h b/src/messages_ro.h -index 7bbcefe..da16a49 100644 ---- a/src/messages_ro.h -+++ b/src/messages_ro.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_ru.h b/src/messages_ru.h -index e0c1842..f0e4031 100644 ---- a/src/messages_ru.h -+++ b/src/messages_ru.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_sk.h b/src/messages_sk.h -index 24eca1b..e0ddd2a 100644 ---- a/src/messages_sk.h -+++ b/src/messages_sk.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_sv.h b/src/messages_sv.h -index b55c474..be4bbc1 100644 ---- a/src/messages_sv.h -+++ b/src/messages_sv.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_tr.h b/src/messages_tr.h -index 7d6db57..3ee84d2 100644 ---- a/src/messages_tr.h -+++ b/src/messages_tr.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_zh_cn.h b/src/messages_zh_cn.h -index a8bfc6c..93844fd 100644 ---- a/src/messages_zh_cn.h -+++ b/src/messages_zh_cn.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" -diff --git a/src/messages_zh_tw.h b/src/messages_zh_tw.h -index db99719..05581bb 100644 ---- a/src/messages_zh_tw.h -+++ b/src/messages_zh_tw.h -@@ -227,3 +227,4 @@ - #define MSG_PROT_BEFORE_PBSZ "PROT must be preceded by a successful PBSZ command" - #define MSG_WARN_LDAP_USERPASS_EMPTY "LDAP returned no userPassword attribute, check LDAP access rights." - #define MSG_LDAP_INVALID_AUTH_METHOD "Invalid LDAPAuthMethod in the configuration file. Should be 'bind' or 'password'." -+#define MSG_INVALID_ARGUMENT "Invalid argument: \"%s\"" --- -2.14.3 - diff --git a/0002-fedora-specific-config-file.patch b/0002-fedora-specific-config-file.patch index e50a695..afa6fcf 100644 --- a/0002-fedora-specific-config-file.patch +++ b/0002-fedora-specific-config-file.patch @@ -1,4 +1,4 @@ -From 23e169081a6cff2b73e521991fd9e260b49e80fa Mon Sep 17 00:00:00 2001 +From 5dbbb2948bee45ec0115146efb4a090df00f5530 Mon Sep 17 00:00:00 2001 From: rpm-build Date: Thu, 14 Sep 2017 16:41:12 +0200 Subject: [PATCH] fedora specific config file @@ -8,14 +8,14 @@ Subject: [PATCH] fedora specific config file 1 file changed, 15 insertions(+), 16 deletions(-) diff --git a/pure-ftpd.conf.in b/pure-ftpd.conf.in -index a327844..597ed59 100644 +index aeb093a..e93053a 100644 --- a/pure-ftpd.conf.in +++ b/pure-ftpd.conf.in @@ -9,7 +9,7 @@ # instead of command-line options, please run the # following command : # --# @prefix@/sbin/pure-ftpd @sysconfdir@/etc/pure-ftpd.conf +-# @sbindir@/sbin/pure-ftpd @sysconfdir@/pure-ftpd.conf +# @sbindir@/pure-ftpd @sysconfdir@/pure-ftpd.conf # # Online documentation: @@ -127,5 +127,5 @@ index a327844..597ed59 100644 -- -2.14.3 +2.20.1 diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 32416a7..4466de9 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd -Version: 1.0.47 -Release: 10%{?dist} +Version: 1.0.48 +Release: 1%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -16,18 +16,6 @@ Source8: pure-ftpd-with-tls-init.service Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch -# Upstream patch: -Patch2: 0001-Exit-when-given-an-invalid-cmdline-option.patch -# Upstream patch: -Patch3: 0002-Complain-when-both-options-and-config-file-are-given.patch -# Upstream patch: -Patch4: 0001-Increase-MAX_DATA_SIZE-due-to-Argon2id-requirements.patch -# Upstream patch: -Patch6: 0001-Fix-postgresql-authenticate-bug.patch - -# Temporarily disable TLSv1.3 to workaround -# https://github.com/jedisct1/pure-ftpd/issues/102 -Patch7: 0001-Temporarily-disable-TLSv1.3-support.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel @@ -173,11 +161,8 @@ make -f %{_datadir}/selinux/devel/Makefile install -p -m 644 -D pureftpd.pp $RPM_BUILD_ROOT%{_datadir}/selinux/packages/%{name}/pureftpd.pp popd -# Docs -install -d -m 755 $RPM_BUILD_ROOT%{_docdir}/%{name} -rm -f README.{MacOS-X,Windows} -install -p -m 644 README.* $RPM_BUILD_ROOT%{_docdir}/%{name} -install -p -m 644 pureftpd.schema $RPM_BUILD_ROOT%{_docdir}/%{name} +# Remove unnecessary docs +rm $RPM_BUILD_ROOT%{_docdir}/%{name}/README.MacOS-X %post %systemd_post pure-ftpd.service @@ -212,11 +197,12 @@ fi %files -%doc FAQ THANKS AUTHORS CONTACT HISTORY NEWS +%doc FAQ THANKS AUTHORS HISTORY NEWS %doc README README.Authentication-Modules README.Configuration-File %doc README.Donations README.LDAP README.MySQL README.SELinux %doc README.PGSQL README.TLS README.Virtual-Users %doc pureftpd.schema +%doc %{_docdir}/%{name}/*.conf %{_bindir}/pure-* %{_sbindir}/pure-* %if 0%{!?_without_tls:1} @@ -241,6 +227,12 @@ fi %changelog +* Fri Mar 29 2019 OndÅ™ej LysonÄ›k - 1.0.48-1 +- New version +- Resolves: rhbz#1692539 +- Resolves: rhbz#1672494 +- Resolves: rhbz#1654838 + * Tue Feb 12 2019 OndÅ™ej LysonÄ›k - 1.0.47-10 - Temporarily disable TLSv1.3 support until it's fully fixed diff --git a/sources b/sources index a5bbab1..da9075a 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (pure-ftpd-1.0.47.tar.bz2) = c1920a3f67f04635fde600fe226a7730b801e7e64658b25f1d9f9c0b35a704664be4adfb0b291594f7e0f10beade25eae9a5e6cc3b6777a3b413f3c2d9574e63 +SHA512 (pure-ftpd-1.0.48.tar.bz2) = eabcc8ba6d37e3aceb57871e80129a1db1a3ea7d2b9f57626a21f42b4978570a84006a941fe254b6af50b2432d1d391725ea512f7569fcaecfa7eb77179c2f54 From 8e6120de593a1b76a71b9fe34ae27cb38460dd29 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Wed, 3 Apr 2019 13:31:27 +0200 Subject: [PATCH 26/51] New version Resolves: rhbz#1695561 --- .gitignore | 1 + pure-ftpd.spec | 6 +++++- sources | 2 +- 3 files changed, 7 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index da05c2a..5710765 100644 --- a/.gitignore +++ b/.gitignore @@ -10,3 +10,4 @@ pure-ftpd-1.0.29.tar.bz2 /pure-ftpd-1.0.46.tar.bz2 /pure-ftpd-1.0.47.tar.bz2 /pure-ftpd-1.0.48.tar.bz2 +/pure-ftpd-1.0.49.tar.bz2 diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 4466de9..94c7dfd 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,5 +1,5 @@ Name: pure-ftpd -Version: 1.0.48 +Version: 1.0.49 Release: 1%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD @@ -227,6 +227,10 @@ fi %changelog +* Wed Apr 03 2019 OndÅ™ej LysonÄ›k - 1.0.49-1 +- New version +- Resolves: rhbz#1695561 + * Fri Mar 29 2019 OndÅ™ej LysonÄ›k - 1.0.48-1 - New version - Resolves: rhbz#1692539 diff --git a/sources b/sources index da9075a..0709f30 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (pure-ftpd-1.0.48.tar.bz2) = eabcc8ba6d37e3aceb57871e80129a1db1a3ea7d2b9f57626a21f42b4978570a84006a941fe254b6af50b2432d1d391725ea512f7569fcaecfa7eb77179c2f54 +SHA512 (pure-ftpd-1.0.49.tar.bz2) = b44896d6fe2cda9169b1db93c5260bb892af14a173f2d25e60dd6530afe85d8e9156985609e35da7e5550dc123afb42bc5012beb9fca9011054cf0ed8b2eddef From b80572389b2e7548f93c5babfd431e1bab64cefd Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 26 Jul 2019 11:31:26 +0000 Subject: [PATCH 27/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 94c7dfd..24d2838 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -227,6 +227,9 @@ fi %changelog +* Fri Jul 26 2019 Fedora Release Engineering - 1.0.49-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + * Wed Apr 03 2019 OndÅ™ej LysonÄ›k - 1.0.49-1 - New version - Resolves: rhbz#1695561 From 9073da9177afbab893880c355266cf282fd6836c Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Mon, 27 Jan 2020 13:54:59 +0100 Subject: [PATCH 28/51] Fix potential stack exhaustion in function listdir (CVE-2019-20176) Resolves: rhbz#1795152 --- ...single-buffer-to-store-every-file-na.patch | 70 +++++++++++++++++++ pure-ftpd.spec | 8 ++- 2 files changed, 77 insertions(+), 1 deletion(-) create mode 100644 0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch diff --git a/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch b/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch new file mode 100644 index 0000000..efed2f3 --- /dev/null +++ b/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch @@ -0,0 +1,70 @@ +From aea56f4bcb9948d456f3fae4d044fd3fa2e19706 Mon Sep 17 00:00:00 2001 +From: Frank Denis +Date: Mon, 30 Dec 2019 17:40:04 +0100 +Subject: [PATCH] listdir(): reuse a single buffer to store every file name to + display + +Allocating a new buffer for each entry is useless. + +And as these buffers are allocated on the stack, on systems with a +small stack size, with many entries, the limit can easily be reached, +causing a stack exhaustion and aborting the user session. + +Reported by Antonio Morales from the GitHub Security Lab team, thanks! +--- + src/ls.c | 15 ++++++++------- + 1 file changed, 8 insertions(+), 7 deletions(-) + +diff --git a/src/ls.c b/src/ls.c +index cf804c7..f8a588f 100644 +--- a/src/ls.c ++++ b/src/ls.c +@@ -661,6 +661,8 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, + char *names; + PureFileInfo *s; + PureFileInfo *r; ++ char *alloca_subdir; ++ size_t sizeof_subdir; + int d; + + if (depth >= max_ls_depth || matches >= max_ls_files) { +@@ -690,14 +692,12 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, + } + outputfiles(f, tls_fd); + r = dir; ++ sizeof_subdir = PATH_MAX + 1U; ++ if ((alloca_subdir = ALLOCA(sizeof_subdir)) == NULL) { ++ goto toomany; ++ } + while (opt_R && r != s) { + if (r->name_offset != (size_t) -1 && !chdir(FI_NAME(r))) { +- char *alloca_subdir; +- const size_t sizeof_subdir = PATH_MAX + 1U; +- +- if ((alloca_subdir = ALLOCA(sizeof_subdir)) == NULL) { +- goto toomany; +- } + if (SNCHECK(snprintf(alloca_subdir, sizeof_subdir, "%s/%s", + name, FI_NAME(r)), sizeof_subdir)) { + goto nolist; +@@ -706,8 +706,8 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, + wrstr(f, tls_fd, alloca_subdir); + wrstr(f, tls_fd, ":\r\n\r\n"); + listdir(depth + 1U, f, tls_fd, alloca_subdir); ++ + nolist: +- ALLOCA_FREE(alloca_subdir); + if (matches >= max_ls_files) { + goto toomany; + } +@@ -720,6 +720,7 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, + r++; + } + toomany: ++ ALLOCA_FREE(alloca_subdir); + free(names); + free(dir); + names = NULL; +-- +2.20.1 + diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 24d2838..afc2ef3 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -16,6 +16,8 @@ Source8: pure-ftpd-with-tls-init.service Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch +# Upstream patch: +Patch2: 0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel @@ -227,6 +229,10 @@ fi %changelog +* Mon Jan 27 2020 OndÅ™ej LysonÄ›k - 1.0.49-3 +- Fix potential stack exhaustion in function listdir (CVE-2019-20176) +- Resolves: rhbz#1795152 + * Fri Jul 26 2019 Fedora Release Engineering - 1.0.49-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild From 07656be37eb46816a406dcde0506dda3f80150d0 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Thu, 30 Jan 2020 09:59:24 +0000 Subject: [PATCH 29/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index afc2ef3..d266ea4 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -229,6 +229,9 @@ fi %changelog +* Thu Jan 30 2020 Fedora Release Engineering - 1.0.49-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + * Mon Jan 27 2020 OndÅ™ej LysonÄ›k - 1.0.49-3 - Fix potential stack exhaustion in function listdir (CVE-2019-20176) - Resolves: rhbz#1795152 From a8e246895844b624a0b71b14aaed20bda5702ef4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ond=C5=99ej=20Lyson=C4=9Bk?= Date: Wed, 6 May 2020 18:27:45 +0200 Subject: [PATCH 30/51] Fix CVE-2020-9365 and CVE-2020-9274 Resolves: rhbz#1828688 Resolves: rhbz#1831059 --- ...ays-set-the-tail-of-the-list-to-NULL.patch | 34 +++++++++++++++++++ 0001-pure_strcmp-len-s2-can-be-len-s1.patch | 28 +++++++++++++++ pure-ftpd.spec | 11 +++++- 3 files changed, 72 insertions(+), 1 deletion(-) create mode 100644 0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch create mode 100644 0001-pure_strcmp-len-s2-can-be-len-s1.patch diff --git a/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch b/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch new file mode 100644 index 0000000..d5b2523 --- /dev/null +++ b/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch @@ -0,0 +1,34 @@ +From 8d0d42542e2cb7a56d645fbe4d0ef436e38bcefa Mon Sep 17 00:00:00 2001 +From: Frank Denis +Date: Tue, 18 Feb 2020 18:36:58 +0100 +Subject: [PATCH] diraliases: always set the tail of the list to NULL + +Spotted and reported by Antonio Norales from GitHub Security Labs. +Thanks! +--- + src/diraliases.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/diraliases.c b/src/diraliases.c +index 4002a36..fb70273 100644 +--- a/src/diraliases.c ++++ b/src/diraliases.c +@@ -93,7 +93,6 @@ int init_aliases(void) + (tail->dir = strdup(dir)) == NULL) { + die_mem(); + } +- tail->next = NULL; + } else { + DirAlias *curr; + +@@ -105,6 +104,7 @@ int init_aliases(void) + tail->next = curr; + tail = curr; + } ++ tail->next = NULL; + } + fclose(fp); + aliases_up++; +-- +2.25.4 + diff --git a/0001-pure_strcmp-len-s2-can-be-len-s1.patch b/0001-pure_strcmp-len-s2-can-be-len-s1.patch new file mode 100644 index 0000000..375b970 --- /dev/null +++ b/0001-pure_strcmp-len-s2-can-be-len-s1.patch @@ -0,0 +1,28 @@ +From bf6fcd4935e95128cf22af5924cdc8fe5c0579da Mon Sep 17 00:00:00 2001 +From: Frank Denis +Date: Mon, 24 Feb 2020 15:19:43 +0100 +Subject: [PATCH] pure_strcmp(): len(s2) can be > len(s1) + +Reported by Antonio Morales from GitHub Security Labs, thanks! +--- + src/utils.c | 6 +++++- + 1 file changed, 5 insertions(+), 1 deletion(-) + +diff --git a/src/utils.c b/src/utils.c +index f41492d..5e88104 100644 +--- a/src/utils.c ++++ b/src/utils.c +@@ -45,5 +45,9 @@ int pure_memcmp(const void * const b1_, const void * const b2_, size_t len) + + int pure_strcmp(const char * const s1, const char * const s2) + { +- return pure_memcmp(s1, s2, strlen(s1) + 1U); ++ const size_t s1_len = strlen(s1); ++ const size_t s2_len = strlen(s2); ++ const size_t len = (s1_len < s2_len) ? s1_len : s2_len; ++ ++ return pure_memcmp(s1, s2, len + 1); + } +-- +2.25.4 + diff --git a/pure-ftpd.spec b/pure-ftpd.spec index d266ea4..6fa83bb 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -18,6 +18,10 @@ Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch # Upstream patch: Patch2: 0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch +# Upstream patch: +Patch3: 0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch +# Upstream patch: +Patch4: 0001-pure_strcmp-len-s2-can-be-len-s1.patch Provides: ftpserver BuildRequires: pam-devel, libcap-devel @@ -229,6 +233,11 @@ fi %changelog +* Wed May 06 2020 OndÅ™ej LysonÄ›k - 1.0.49-5 +- Fix CVE-2020-9365 and CVE-2020-9274 +- Resolves: rhbz#1828688 +- Resolves: rhbz#1831059 + * Thu Jan 30 2020 Fedora Release Engineering - 1.0.49-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild From 9b9a61bcc6dbb98bf7c2d9f6c46b90ac9781139e Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Tue, 28 Jul 2020 23:11:18 +0000 Subject: [PATCH 31/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 6fa83bb..a821cb0 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -233,6 +233,9 @@ fi %changelog +* Tue Jul 28 2020 Fedora Release Engineering - 1.0.49-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + * Wed May 06 2020 OndÅ™ej LysonÄ›k - 1.0.49-5 - Fix CVE-2020-9365 and CVE-2020-9274 - Resolves: rhbz#1828688 From 31773595729d16ea14571ffc2f5d2be1519e67d2 Mon Sep 17 00:00:00 2001 From: Tom Stellard Date: Fri, 8 Jan 2021 19:38:28 +0000 Subject: [PATCH 32/51] Add BuildRequires: make https://fedoraproject.org/wiki/Changes/Remove_make_from_BuildRoot --- pure-ftpd.spec | 1 + 1 file changed, 1 insertion(+) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index a821cb0..68d0d37 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -24,6 +24,7 @@ Patch3: 0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch Patch4: 0001-pure_strcmp-len-s2-can-be-len-s1.patch Provides: ftpserver +BuildRequires: make BuildRequires: pam-devel, libcap-devel %{!?_without_ldap:BuildRequires: openldap-devel} %{!?_without_mysql:BuildRequires: mariadb-connector-c-devel} From 413183aa914be26711498bb775da712436787c60 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Wed, 27 Jan 2021 08:45:39 +0000 Subject: [PATCH 33/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 68d0d37..49f15bc 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -234,6 +234,9 @@ fi %changelog +* Wed Jan 27 2021 Fedora Release Engineering - 1.0.49-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + * Tue Jul 28 2020 Fedora Release Engineering - 1.0.49-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild From bda0bb39680cedc80e779658f9873a4766c5cfde Mon Sep 17 00:00:00 2001 From: Pavel Raiskup Date: Mon, 8 Feb 2021 10:26:30 +0100 Subject: [PATCH 34/51] rebuild for libpq ABI fix Related: rhbz#1908268 --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 49f15bc..42fd2e5 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -234,6 +234,9 @@ fi %changelog +* Mon Feb 08 2021 Pavel Raiskup - 1.0.49-8 +- rebuild for libpq ABI fix rhbz#1908268 + * Wed Jan 27 2021 Fedora Release Engineering - 1.0.49-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild From ef5dfb65053980833efa57e8c63861df0de816c2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Tue, 2 Mar 2021 16:13:00 +0100 Subject: [PATCH 35/51] Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. --- pure-ftpd.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 42fd2e5..803b3a0 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -234,6 +234,10 @@ fi %changelog +* Tue Mar 02 2021 Zbigniew JÄ™drzejewski-Szmek - 1.0.49-9 +- Rebuilt for updated systemd-rpm-macros + See https://pagure.io/fesco/issue/2583. + * Mon Feb 08 2021 Pavel Raiskup - 1.0.49-8 - rebuild for libpq ABI fix rhbz#1908268 From 5ac4cfdf6a8ccf3feedc6b55ac9a9926d64188b2 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 23 Jul 2021 04:16:34 +0000 Subject: [PATCH 36/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 803b3a0..25e985b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 9%{?dist} +Release: 10%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -234,6 +234,9 @@ fi %changelog +* Fri Jul 23 2021 Fedora Release Engineering - 1.0.49-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + * Tue Mar 02 2021 Zbigniew JÄ™drzejewski-Szmek - 1.0.49-9 - Rebuilt for updated systemd-rpm-macros See https://pagure.io/fesco/issue/2583. From e7c6a52ff46509364852cb2f91e6bf8000bf7b05 Mon Sep 17 00:00:00 2001 From: Sahana Prasad Date: Tue, 14 Sep 2021 19:12:20 +0200 Subject: [PATCH 37/51] Rebuilt with OpenSSL 3.0.0 --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 25e985b..1e50c8b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 10%{?dist} +Release: 11%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -234,6 +234,9 @@ fi %changelog +* Tue Sep 14 2021 Sahana Prasad - 1.0.49-11 +- Rebuilt with OpenSSL 3.0.0 + * Fri Jul 23 2021 Fedora Release Engineering - 1.0.49-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild From 9f2939929d7336b928682af0181071b218b2f411 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 21 Jan 2022 09:39:46 +0000 Subject: [PATCH 38/51] - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 1e50c8b..f680985 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.49 -Release: 11%{?dist} +Release: 12%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -234,6 +234,9 @@ fi %changelog +* Fri Jan 21 2022 Fedora Release Engineering - 1.0.49-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + * Tue Sep 14 2021 Sahana Prasad - 1.0.49-11 - Rebuilt with OpenSSL 3.0.0 From 0afeb1b790e6a3005500ca605859cd53f8606182 Mon Sep 17 00:00:00 2001 From: jonathanspw Date: Thu, 21 Jul 2022 11:19:13 -0500 Subject: [PATCH 39/51] New version 1.0.51 --- .gitignore | 1 + ...ays-set-the-tail-of-the-list-to-NULL.patch | 34 --------- ...single-buffer-to-store-every-file-na.patch | 70 ------------------- 0001-pure_strcmp-len-s2-can-be-len-s1.patch | 28 -------- pure-ftpd.spec | 14 ++-- 5 files changed, 7 insertions(+), 140 deletions(-) delete mode 100644 0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch delete mode 100644 0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch delete mode 100644 0001-pure_strcmp-len-s2-can-be-len-s1.patch diff --git a/.gitignore b/.gitignore index 5710765..f418bc6 100644 --- a/.gitignore +++ b/.gitignore @@ -11,3 +11,4 @@ pure-ftpd-1.0.29.tar.bz2 /pure-ftpd-1.0.47.tar.bz2 /pure-ftpd-1.0.48.tar.bz2 /pure-ftpd-1.0.49.tar.bz2 +/pure-ftpd-1.0.51.tar.bz2 diff --git a/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch b/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch deleted file mode 100644 index d5b2523..0000000 --- a/0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch +++ /dev/null @@ -1,34 +0,0 @@ -From 8d0d42542e2cb7a56d645fbe4d0ef436e38bcefa Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Tue, 18 Feb 2020 18:36:58 +0100 -Subject: [PATCH] diraliases: always set the tail of the list to NULL - -Spotted and reported by Antonio Norales from GitHub Security Labs. -Thanks! ---- - src/diraliases.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/src/diraliases.c b/src/diraliases.c -index 4002a36..fb70273 100644 ---- a/src/diraliases.c -+++ b/src/diraliases.c -@@ -93,7 +93,6 @@ int init_aliases(void) - (tail->dir = strdup(dir)) == NULL) { - die_mem(); - } -- tail->next = NULL; - } else { - DirAlias *curr; - -@@ -105,6 +104,7 @@ int init_aliases(void) - tail->next = curr; - tail = curr; - } -+ tail->next = NULL; - } - fclose(fp); - aliases_up++; --- -2.25.4 - diff --git a/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch b/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch deleted file mode 100644 index efed2f3..0000000 --- a/0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch +++ /dev/null @@ -1,70 +0,0 @@ -From aea56f4bcb9948d456f3fae4d044fd3fa2e19706 Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Mon, 30 Dec 2019 17:40:04 +0100 -Subject: [PATCH] listdir(): reuse a single buffer to store every file name to - display - -Allocating a new buffer for each entry is useless. - -And as these buffers are allocated on the stack, on systems with a -small stack size, with many entries, the limit can easily be reached, -causing a stack exhaustion and aborting the user session. - -Reported by Antonio Morales from the GitHub Security Lab team, thanks! ---- - src/ls.c | 15 ++++++++------- - 1 file changed, 8 insertions(+), 7 deletions(-) - -diff --git a/src/ls.c b/src/ls.c -index cf804c7..f8a588f 100644 ---- a/src/ls.c -+++ b/src/ls.c -@@ -661,6 +661,8 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - char *names; - PureFileInfo *s; - PureFileInfo *r; -+ char *alloca_subdir; -+ size_t sizeof_subdir; - int d; - - if (depth >= max_ls_depth || matches >= max_ls_files) { -@@ -690,14 +692,12 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - } - outputfiles(f, tls_fd); - r = dir; -+ sizeof_subdir = PATH_MAX + 1U; -+ if ((alloca_subdir = ALLOCA(sizeof_subdir)) == NULL) { -+ goto toomany; -+ } - while (opt_R && r != s) { - if (r->name_offset != (size_t) -1 && !chdir(FI_NAME(r))) { -- char *alloca_subdir; -- const size_t sizeof_subdir = PATH_MAX + 1U; -- -- if ((alloca_subdir = ALLOCA(sizeof_subdir)) == NULL) { -- goto toomany; -- } - if (SNCHECK(snprintf(alloca_subdir, sizeof_subdir, "%s/%s", - name, FI_NAME(r)), sizeof_subdir)) { - goto nolist; -@@ -706,8 +706,8 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - wrstr(f, tls_fd, alloca_subdir); - wrstr(f, tls_fd, ":\r\n\r\n"); - listdir(depth + 1U, f, tls_fd, alloca_subdir); -+ - nolist: -- ALLOCA_FREE(alloca_subdir); - if (matches >= max_ls_files) { - goto toomany; - } -@@ -720,6 +720,7 @@ static void listdir(unsigned int depth, int f, void * const tls_fd, - r++; - } - toomany: -+ ALLOCA_FREE(alloca_subdir); - free(names); - free(dir); - names = NULL; --- -2.20.1 - diff --git a/0001-pure_strcmp-len-s2-can-be-len-s1.patch b/0001-pure_strcmp-len-s2-can-be-len-s1.patch deleted file mode 100644 index 375b970..0000000 --- a/0001-pure_strcmp-len-s2-can-be-len-s1.patch +++ /dev/null @@ -1,28 +0,0 @@ -From bf6fcd4935e95128cf22af5924cdc8fe5c0579da Mon Sep 17 00:00:00 2001 -From: Frank Denis -Date: Mon, 24 Feb 2020 15:19:43 +0100 -Subject: [PATCH] pure_strcmp(): len(s2) can be > len(s1) - -Reported by Antonio Morales from GitHub Security Labs, thanks! ---- - src/utils.c | 6 +++++- - 1 file changed, 5 insertions(+), 1 deletion(-) - -diff --git a/src/utils.c b/src/utils.c -index f41492d..5e88104 100644 ---- a/src/utils.c -+++ b/src/utils.c -@@ -45,5 +45,9 @@ int pure_memcmp(const void * const b1_, const void * const b2_, size_t len) - - int pure_strcmp(const char * const s1, const char * const s2) - { -- return pure_memcmp(s1, s2, strlen(s1) + 1U); -+ const size_t s1_len = strlen(s1); -+ const size_t s2_len = strlen(s2); -+ const size_t len = (s1_len < s2_len) ? s1_len : s2_len; -+ -+ return pure_memcmp(s1, s2, len + 1); - } --- -2.25.4 - diff --git a/pure-ftpd.spec b/pure-ftpd.spec index f680985..6fe714f 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd -Version: 1.0.49 -Release: 12%{?dist} +Version: 1.0.51 +Release: 1%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -16,12 +16,6 @@ Source8: pure-ftpd-with-tls-init.service Source9: pure-ftpd-with-tls.service Patch0: 0001-modify-pam.patch Patch1: 0002-fedora-specific-config-file.patch -# Upstream patch: -Patch2: 0001-listdir-reuse-a-single-buffer-to-store-every-file-na.patch -# Upstream patch: -Patch3: 0001-diraliases-always-set-the-tail-of-the-list-to-NULL.patch -# Upstream patch: -Patch4: 0001-pure_strcmp-len-s2-can-be-len-s1.patch Provides: ftpserver BuildRequires: make @@ -234,6 +228,10 @@ fi %changelog +* Thu Jul 21 2022 Jonathan Wright - 1.0.51-1 +- New version +- Resolves: rhbz#2026153 + * Fri Jan 21 2022 Fedora Release Engineering - 1.0.49-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild From c0f1b9f8469391349dd73e6169c257aee55ad84d Mon Sep 17 00:00:00 2001 From: jonathanspw Date: Thu, 21 Jul 2022 11:54:40 -0500 Subject: [PATCH 40/51] remove usermode/consolehelper --- pure-ftpd.pure-ftpwho.consoleapp | 3 --- pure-ftpd.pure-ftpwho.pam | 4 ---- pure-ftpd.spec | 14 +++----------- 3 files changed, 3 insertions(+), 18 deletions(-) delete mode 100644 pure-ftpd.pure-ftpwho.consoleapp delete mode 100644 pure-ftpd.pure-ftpwho.pam diff --git a/pure-ftpd.pure-ftpwho.consoleapp b/pure-ftpd.pure-ftpwho.consoleapp deleted file mode 100644 index 8452f88..0000000 --- a/pure-ftpd.pure-ftpwho.consoleapp +++ /dev/null @@ -1,3 +0,0 @@ -USER=root -PROGRAM=/usr/sbin/pure-ftpwho -GUI=no diff --git a/pure-ftpd.pure-ftpwho.pam b/pure-ftpd.pure-ftpwho.pam deleted file mode 100644 index 268cc92..0000000 --- a/pure-ftpd.pure-ftpwho.pam +++ /dev/null @@ -1,4 +0,0 @@ -#%PAM-1.0 -auth sufficient pam_rootok.so -auth required pam_localuser.so -account required pam_permit.so diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 6fe714f..b02106c 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -8,8 +8,6 @@ URL: http://www.pureftpd.org Source0: http://download.pureftpd.org/pub/pure-ftpd/releases/pure-ftpd-%{version}.tar.bz2 Source1: pure-ftpd.service Source2: pure-ftpd.logrotate -Source4: pure-ftpd.pure-ftpwho.pam -Source5: pure-ftpd.pure-ftpwho.consoleapp Source6: pure-ftpd.README.SELinux Source7: pure-ftpd.pureftpd.te Source8: pure-ftpd-with-tls-init.service @@ -31,7 +29,7 @@ BuildRequires: gcc Requires(post): systemd Requires(preun): systemd Requires(postun): systemd -Requires: logrotate, usermode +Requires: logrotate %{!?_without_tls:Requires: sscg} @@ -147,12 +145,6 @@ install -p -m 644 pam/pure-ftpd $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/ install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d install -p -m 644 %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/%{name} -# pure-ftpwho and non-root users -install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/security/console.apps -install -p -m 644 %{SOURCE4} $RPM_BUILD_ROOT%{_sysconfdir}/pam.d/pure-ftpwho -install -p -m 644 %{SOURCE5} $RPM_BUILD_ROOT%{_sysconfdir}/security/console.apps/pure-ftpwho -ln -s consolehelper $RPM_BUILD_ROOT%{_bindir}/pure-ftpwho - # SELinux support pushd selinux echo "%{_sbindir}/pure-ftpd system_u:object_r:ftpd_exec_t:s0" > pureftpd.fc @@ -215,8 +207,6 @@ fi %config(noreplace) %{_sysconfdir}/%{name} %config(noreplace) %{_sysconfdir}/pam.d/%{name} %config(noreplace) %{_sysconfdir}/logrotate.d/%{name} -%config(noreplace) %{_sysconfdir}/pam.d/pure-ftpwho -%config(noreplace) %{_sysconfdir}/security/console.apps/pure-ftpwho %{!?_without_tls:%{_sysconfdir}/pki/%{name}} %{_mandir}/man8/* %dir /var/ftp/ @@ -231,6 +221,8 @@ fi * Thu Jul 21 2022 Jonathan Wright - 1.0.51-1 - New version - Resolves: rhbz#2026153 +- Remove usermode dependency and non-root "ftpwho" +- Resolves: rhbz#502754 * Fri Jan 21 2022 Fedora Release Engineering - 1.0.49-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild From f430a125ef87f22dafe60b2d624de7922c46cb59 Mon Sep 17 00:00:00 2001 From: jonathanspw Date: Thu, 21 Jul 2022 12:32:06 -0500 Subject: [PATCH 41/51] Update sources for 1.0.51 --- sources | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sources b/sources index 0709f30..37f9178 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (pure-ftpd-1.0.49.tar.bz2) = b44896d6fe2cda9169b1db93c5260bb892af14a173f2d25e60dd6530afe85d8e9156985609e35da7e5550dc123afb42bc5012beb9fca9011054cf0ed8b2eddef +SHA512 (pure-ftpd-1.0.51.tar.bz2) = 3615ac1ec42813855f3328dde200f60025e1f2ca7d1e17ea042967fd4164079260d058f3e2586acd778334660f387a280b35850a9e2091dd913fb84ef929bdca From 7f021a55262c2951a002d81e5bc65212bd505932 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 20 Jan 2023 10:30:05 +0000 Subject: [PATCH 42/51] Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index b02106c..d0fefc6 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.51 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -218,6 +218,9 @@ fi %changelog +* Fri Jan 20 2023 Fedora Release Engineering - 1.0.51-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + * Thu Jul 21 2022 Jonathan Wright - 1.0.51-1 - New version - Resolves: rhbz#2026153 From bc7a24037ec1eb9c0b7c90aa350d8b87db1c532d Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 21 Jul 2023 06:31:42 +0000 Subject: [PATCH 43/51] Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild Signed-off-by: Fedora Release Engineering --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index d0fefc6..d35a4aa 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.51 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -218,6 +218,9 @@ fi %changelog +* Fri Jul 21 2023 Fedora Release Engineering - 1.0.51-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + * Fri Jan 20 2023 Fedora Release Engineering - 1.0.51-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild From c205926cb97ee590f76f7ac6ece24f10594a4b19 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sun, 21 Jan 2024 22:36:02 +0000 Subject: [PATCH 44/51] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index d35a4aa..80b5fb0 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.51 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -218,6 +218,9 @@ fi %changelog +* Sun Jan 21 2024 Fedora Release Engineering - 1.0.51-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Fri Jul 21 2023 Fedora Release Engineering - 1.0.51-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild From c7a2892b46ee2212fd460e36a7b55e4d5a90932a Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 26 Jan 2024 00:22:09 +0000 Subject: [PATCH 45/51] Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 80b5fb0..1067166 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.51 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -218,6 +218,9 @@ fi %changelog +* Fri Jan 26 2024 Fedora Release Engineering - 1.0.51-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + * Sun Jan 21 2024 Fedora Release Engineering - 1.0.51-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From ce04bd4e302cbd2f3bdf0a006357dc41a11cc5a7 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 19 Jul 2024 08:44:33 +0000 Subject: [PATCH 46/51] Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 1067166..339dc80 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.51 -Release: 5%{?dist} +Release: 6%{?dist} Summary: Lightweight, fast and secure FTP server License: BSD URL: http://www.pureftpd.org @@ -218,6 +218,9 @@ fi %changelog +* Fri Jul 19 2024 Fedora Release Engineering - 1.0.51-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + * Fri Jan 26 2024 Fedora Release Engineering - 1.0.51-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild From 6bf60785e9bf5c882ce5c5e1ea8a6298c1cd9bc1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Miroslav=20Such=C3=BD?= Date: Wed, 4 Sep 2024 19:20:19 +0200 Subject: [PATCH 47/51] convert license to SPDX This is part of https://fedoraproject.org/wiki/Changes/SPDX_Licenses_Phase_4 --- pure-ftpd.spec | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 339dc80..f2d62ee 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,8 +1,9 @@ Name: pure-ftpd Version: 1.0.51 -Release: 6%{?dist} +Release: 7%{?dist} Summary: Lightweight, fast and secure FTP server -License: BSD +# Automatically converted from old format: BSD - review is highly recommended. +License: LicenseRef-Callaway-BSD URL: http://www.pureftpd.org Source0: http://download.pureftpd.org/pub/pure-ftpd/releases/pure-ftpd-%{version}.tar.bz2 @@ -218,6 +219,9 @@ fi %changelog +* Wed Sep 04 2024 Miroslav Suchý - 1.0.51-7 +- convert license to SPDX + * Fri Jul 19 2024 Fedora Release Engineering - 1.0.51-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild From e8cfc944a0223f648925708e1f3dd0939b680ec8 Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Sat, 18 Jan 2025 11:05:16 +0000 Subject: [PATCH 48/51] Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index f2d62ee..014c803 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.51 -Release: 7%{?dist} +Release: 8%{?dist} Summary: Lightweight, fast and secure FTP server # Automatically converted from old format: BSD - review is highly recommended. License: LicenseRef-Callaway-BSD @@ -219,6 +219,9 @@ fi %changelog +* Sat Jan 18 2025 Fedora Release Engineering - 1.0.51-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + * Wed Sep 04 2024 Miroslav Suchý - 1.0.51-7 - convert license to SPDX From 3c73e2bc6fcae9b66141db52811a93b1fbb429df Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B6rn=20Esser?= Date: Sat, 1 Feb 2025 19:56:51 +0100 Subject: [PATCH 49/51] Add explicit BR: libxcrypt-devel MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Björn Esser --- pure-ftpd.spec | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 014c803..7a1f6df 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.51 -Release: 8%{?dist} +Release: 9%{?dist} Summary: Lightweight, fast and secure FTP server # Automatically converted from old format: BSD - review is highly recommended. License: LicenseRef-Callaway-BSD @@ -19,6 +19,7 @@ Patch1: 0002-fedora-specific-config-file.patch Provides: ftpserver BuildRequires: make BuildRequires: pam-devel, libcap-devel +BuildRequires: libxcrypt-devel %{!?_without_ldap:BuildRequires: openldap-devel} %{!?_without_mysql:BuildRequires: mariadb-connector-c-devel} %{!?_without_pgsql:BuildRequires: libpq-devel} @@ -219,6 +220,9 @@ fi %changelog +* Sat Feb 01 2025 Björn Esser - 1.0.51-9 +- Add explicit BR: libxcrypt-devel + * Sat Jan 18 2025 Fedora Release Engineering - 1.0.51-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild From 5104a55ce6835e72e5c4dcc11c3caf0504675bcb Mon Sep 17 00:00:00 2001 From: Jonathan Wright Date: Mon, 19 May 2025 19:36:21 -0500 Subject: [PATCH 50/51] update to 1.0.52 --- .gitignore | 1 + pure-ftpd.spec | 8 ++++++-- sources | 2 +- 3 files changed, 8 insertions(+), 3 deletions(-) diff --git a/.gitignore b/.gitignore index f418bc6..1b740aa 100644 --- a/.gitignore +++ b/.gitignore @@ -12,3 +12,4 @@ pure-ftpd-1.0.29.tar.bz2 /pure-ftpd-1.0.48.tar.bz2 /pure-ftpd-1.0.49.tar.bz2 /pure-ftpd-1.0.51.tar.bz2 +/pure-ftpd-1.0.52.tar.bz2 diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 7a1f6df..21e8abb 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd -Version: 1.0.51 -Release: 9%{?dist} +Version: 1.0.52 +Release: 1%{?dist} Summary: Lightweight, fast and secure FTP server # Automatically converted from old format: BSD - review is highly recommended. License: LicenseRef-Callaway-BSD @@ -220,6 +220,10 @@ fi %changelog +* Tue May 20 2025 Jonathan Wright - 1.0.52-1 +- update to 1.0.52 rhbz#2313435 +- Fixes CVE-2024-48208 rhbz#2343476 + * Sat Feb 01 2025 Björn Esser - 1.0.51-9 - Add explicit BR: libxcrypt-devel diff --git a/sources b/sources index 37f9178..920b4eb 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -SHA512 (pure-ftpd-1.0.51.tar.bz2) = 3615ac1ec42813855f3328dde200f60025e1f2ca7d1e17ea042967fd4164079260d058f3e2586acd778334660f387a280b35850a9e2091dd913fb84ef929bdca +SHA512 (pure-ftpd-1.0.52.tar.bz2) = c7b6f76c1429d2cbf9d740c3408464564e023716ebf8361231ba5021f81804575049910c9874970c83c98f927cd496899e5c30625e4dee6538497f9179632c23 From 6712c15acc5950c705d6b7bde3376c478222e7bf Mon Sep 17 00:00:00 2001 From: Fedora Release Engineering Date: Fri, 25 Jul 2025 06:17:07 +0000 Subject: [PATCH 51/51] Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild --- pure-ftpd.spec | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/pure-ftpd.spec b/pure-ftpd.spec index 21e8abb..9159c7b 100644 --- a/pure-ftpd.spec +++ b/pure-ftpd.spec @@ -1,6 +1,6 @@ Name: pure-ftpd Version: 1.0.52 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Lightweight, fast and secure FTP server # Automatically converted from old format: BSD - review is highly recommended. License: LicenseRef-Callaway-BSD @@ -220,6 +220,9 @@ fi %changelog +* Fri Jul 25 2025 Fedora Release Engineering - 1.0.52-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + * Tue May 20 2025 Jonathan Wright - 1.0.52-1 - update to 1.0.52 rhbz#2313435 - Fixes CVE-2024-48208 rhbz#2343476