diff --git a/85932ec5.patch b/85932ec5.patch new file mode 100644 index 0000000..8b919ef --- /dev/null +++ b/85932ec5.patch @@ -0,0 +1,62 @@ +From 85932ec5d89041424cf6d20c71b482e23cf17d2f Mon Sep 17 00:00:00 2001 +From: "Antonio \"Criddi\" Mammita" + <77116213+ammammita@users.noreply.github.com> +Date: Wed, 13 Jan 2021 17:17:31 +0000 +Subject: [PATCH] Ticket 18 and 19 (#22) + +Fix issue #18 and issue #19 + +Base template replacement issue +--- + rbldnsd.8 | 4 ++-- + rbldnsd_util.c | 8 ++++++-- + 2 files changed, 8 insertions(+), 4 deletions(-) + +diff --git a/rbldnsd.8 b/rbldnsd.8 +index 36e70fa..addb737 100644 +--- a/rbldnsd.8 ++++ b/rbldnsd.8 +@@ -726,7 +726,7 @@ the above example may be simplified to: + .fi + There is no default TXT value, so + .B rbldnsd +-will not return anything for TXT queries it TXT isn't ++will not return anything for TXT queries unless TXT isn't + specified. + .PP + When A value is specified for a given entry, but TXT template +@@ -782,7 +782,7 @@ text given for individual entries. In order to stop usage of base template + \fB$=\fR for a single record, start it with \fB=\fR (which will be omitted + from the resulting TXT value). For example, + .nf +- $0 See http://www.example.com/bl?$= ($) for details ++ $= See http://www.example.com/bl?$= ($) for details + 127.0.0.2 r123 + 127.0.0.3 + 127.0.0.4 =See other blocklists for details about $ +diff --git a/rbldnsd_util.c b/rbldnsd_util.c +index c6d628d..eeafd07 100644 +--- a/rbldnsd_util.c ++++ b/rbldnsd_util.c +@@ -243,6 +243,8 @@ int txtsubst(char sb[TXTBUFSIZ], const char *txt, + char *const e = sb + 254; + char *lp = sb; + const char *s, *si, *sx; ++ const char *srec = s0; ++ + if (txt[0] == '=') + sx = ++txt; + else if (sn[SUBST_BASE_TEMPLATE] && *sn[SUBST_BASE_TEMPLATE]) { +@@ -273,8 +275,10 @@ int txtsubst(char sb[TXTBUFSIZ], const char *txt, + sl = strlen(si); + ++s; + } +- else +- sl = strlen(si = s0); ++ else { ++ sl = strlen(si = srec); ++ } ++ + if (lp + sl > e) /* silently truncate TXT RR >255 bytes */ + sl = e - lp; + memcpy(lp, si, sl); diff --git a/rbldnsctl b/rbldnsctl index cc9e181..f5bb1b9 100755 --- a/rbldnsctl +++ b/rbldnsctl @@ -82,48 +82,49 @@ for_all_daemons() { } start_one_daemon() { - /bin/systemctl start "rbldnsd-${name}.service" + /usr/bin/systemctl start "rbldnsd-${name}.service" } stop_one_daemon() { - /bin/systemctl stop "rbldnsd-${name}.service" + /usr/bin/systemctl stop "rbldnsd-${name}.service" } reload_one_daemon() { - /bin/systemctl reload "rbldnsd-${name}.service" + /usr/bin/systemctl reload "rbldnsd-${name}.service" } check_one_daemon() { - /bin/systemctl status "rbldnsd-${name}.service" + /usr/bin/systemctl status "rbldnsd-${name}.service" } restart_one_daemon() { - /bin/systemctl restart "rbldnsd-${name}.service" + /usr/bin/systemctl restart "rbldnsd-${name}.service" } condrestart_one_daemon() { - /bin/systemctl try-restart "rbldnsd-${name}.service" + /usr/bin/systemctl try-restart "rbldnsd-${name}.service" } create_one_daemon() { - cat > "/etc/systemd/system/rbldnsd-${name}.service" <<-END_OF_UNIT - .include /etc/systemd/rbldnsd.conf - - [Unit] - Description=DNSBL (rbldnsd) ${name} instance - - [Service] - ExecStart=/sbin/rbldnsd -n ${args} - END_OF_UNIT + { + awk '/^\[Unit\]/, 1 == 2' /etc/systemd/rbldnsd.conf + cat <<-END_OF_UNIT + [Unit] + Description=DNSBL (rbldnsd) ${name} instance + + [Service] + ExecStart=/sbin/rbldnsd -n ${args} + END_OF_UNIT + } > "/etc/systemd/system/rbldnsd-${name}.service" echo "Created unit file /etc/systemd/system/rbldnsd-${name}.service" } enable_one_daemon() { - /bin/systemctl enable "rbldnsd-${name}.service" + /usr/bin/systemctl enable "rbldnsd-${name}.service" } disable_one_daemon() { - /bin/systemctl disable "rbldnsd-${name}.service" + /usr/bin/systemctl disable "rbldnsd-${name}.service" } # See how we were called. @@ -131,7 +132,7 @@ case "$1" in create) for_all_daemons create_one_daemon RETVAL=$? - /bin/systemctl daemon-reload + /usr/bin/systemctl daemon-reload ;; enable) for_all_daemons enable_one_daemon diff --git a/rbldnsd-0.998b-version.patch b/rbldnsd-0.998b-version.patch new file mode 100644 index 0000000..a193fd9 --- /dev/null +++ b/rbldnsd-0.998b-version.patch @@ -0,0 +1,16 @@ +This addition of the release date for version 0.998b fixes the +version number that rbldnsd reports in its logging output. The +version is extracted from the NEWS file by the configure script +but the pattern matching requires the date to be present. + +--- NEWS ++++ NEWS +@@ -1,7 +1,7 @@ + This file describes user-visible changes in rbldnsd. + Newer news is at the top. + +-0.998b ++0.998b (21 Dec 2016) + - Fix for memory errors on very large datasets. + Patch by Andrew Clayton + diff --git a/rbldnsd-configure-c99.patch b/rbldnsd-configure-c99.patch new file mode 100644 index 0000000..3eb7970 --- /dev/null +++ b/rbldnsd-configure-c99.patch @@ -0,0 +1,20 @@ +Avoid implicit declarations of gethostbyname and connect in the +non-autoconf configure script. This prevents altering the test result +with compilers which do not support implicit function declarations. + +A more elaborate pull request has been submitted upstream: + + + +diff --git a/configure b/configure +index b0cb655797639dac..978f480e391a46a8 100755 +--- a/configure ++++ b/configure +@@ -173,6 +173,7 @@ else + fi + + if ac_library_find_v 'connect()' "" "-lsocket -lnsl" < ") - # Configure script is not from autotools addFilter("configure-without-libdir-spec") @@ -12,3 +7,8 @@ addFilter("no-manual-page-for-binary rbldnsctl") # Not a strange permission for a script addFilter("strange-permission rbldnsctl 775") +# DNS server +addFilter("spelling-error \('nameserver',") + +# List of unwelcome IP addresses, made available over DNS using rbldnsd +addFilter("spelling-error \('blocklists',") diff --git a/rbldnsd.spec b/rbldnsd.spec index e779d94..14e90fd 100644 --- a/rbldnsd.spec +++ b/rbldnsd.spec @@ -1,23 +1,33 @@ # systemd-rpm-macros split out from systemd at Fedora 30 -%if (0%{?fedora} && 0%{?fedora} <= 29) || 0%{?rhel} +%if (0%{?fedora} && 0%{?fedora} <= 29) || (0%{?rhel} && 0%{?rhel} <= 8) %global systemd_rpm_macros systemd %else %global systemd_rpm_macros systemd-rpm-macros %endif +# Use sysusers from Fedora 43 onwards +%if (0%{?rhel} && 0%{?rhel} <= 10) || (0%{?fedora} && 0%{?fedora} <= 42) +%global use_sysusers 0 +%else +%global use_sysusers 1 +%endif + # Build hardened (PIE) where possible %global _hardened_build 1 Summary: Small, fast daemon to serve DNSBLs Name: rbldnsd Version: 0.998b -Release: 7%{?dist} -License: GPLv2+ +Release: 19%{?dist} +License: GPL-2.0-or-later URL: https://rbldnsd.io/ Source0: https://rbldnsd.io/dwl/rbldnsd-%{version}.tgz Source2: rbldnsd.conf Source3: rbldnsctl Source4: README.systemd +Patch0: rbldnsd-configure-c99.patch +Patch1: rbldnsd-0.998b-version.patch +Patch2: https://github.com/spamhaus/rbldnsd/commit/85932ec5.patch BuildRequires: coreutils BuildRequires: gawk BuildRequires: gcc @@ -25,7 +35,10 @@ BuildRequires: make BuildRequires: sed BuildRequires: %{systemd_rpm_macros} BuildRequires: zlib-devel +%if !%{use_sysusers} Requires(pre): shadow-utils +%endif +Requires: gawk %{?systemd_requires} %description @@ -36,10 +49,27 @@ blocklists. %prep %setup -q +# Port non-autoconf configure script to C99 +%patch -P 0 -p1 + +# Fix version number reported by rbldnsd +%patch -P 1 + +# Fix base template replacement issue +# https://github.com/spamhaus/rbldnsd/issues/18 +# https://github.com/spamhaus/rbldnsd/issues/19 +# https://github.com/spamhaus/rbldnsd/pull/22 +%patch -P 2 -p1 + sed -i -e 's@/var/lib/rbldns\([/ ]\)@%{_localstatedir}/lib/rbldnsd\1@g' \ -e 's@\(-r/[a-z/]*\) -b@\1 -q -b@g' contrib/debian/rbldnsd.default cp -p %{SOURCE2} %{SOURCE3} %{SOURCE4} ./ +# Create a sysusers.d config file +cat >rbldnsd.sysusers.conf </dev/null || groupadd -r rbldns getent passwd rbldns >/dev/null || \ useradd -r -g rbldns -d %{_localstatedir}/lib/rbldnsd \ -s /sbin/nologin -c "rbldns daemon" rbldns exit 0 +%endif %post systemctl daemon-reload &>/dev/null || : @@ -90,8 +125,50 @@ fi %doc README.systemd %config(noreplace) %{_sysconfdir}/systemd/rbldnsd.conf %{_sbindir}/rbldnsctl +%if %{use_sysusers} +%{_sysusersdir}/rbldnsd.conf +%endif %changelog +* Fri Sep 26 2025 Paul Howarth - 0.998b-19 +- Fix base template replacement issue (GH#18, GH#19, GH#22, rhbz#2398024) + +* Fri Jul 25 2025 Fedora Release Engineering - 0.998b-18 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild + +* Wed Feb 12 2025 Paul Howarth - 0.998b-17 +- Add sysusers.d config file to allow rpm to create users/groups automatically + from Fedora 43 onwards + +* Sat Jan 18 2025 Fedora Release Engineering - 0.998b-16 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Fri Jul 19 2024 Fedora Release Engineering - 0.998b-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Fri Jan 26 2024 Fedora Release Engineering - 0.998b-14 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Mon Jan 22 2024 Fedora Release Engineering - 0.998b-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Fri Jul 21 2023 Fedora Release Engineering - 0.998b-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Fri Jun 23 2023 Paul Howarth - 0.998b-11 +- Avoid use of systemd ".include" directive (rhbz#2216790) +- Avoid use of deprecated patch syntax +- Fix version number reported by rbldnsd + +* Mon Jan 30 2023 Paul Howarth - 0.998b-10 +- Use SPDX-format license tag + +* Mon Jan 30 2023 Florian Weimer - 0.998b-9 +- Port non-autoconf configure script to C99 + +* Fri Jan 20 2023 Fedora Release Engineering - 0.998b-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + * Sat Jul 23 2022 Fedora Release Engineering - 0.998b-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild