diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..4bd8b9d --- /dev/null +++ b/.gitignore @@ -0,0 +1 @@ +sectool-0.9.3.tar.bz2 diff --git a/dead.package b/dead.package deleted file mode 100644 index 0e76cf2..0000000 --- a/dead.package +++ /dev/null @@ -1 +0,0 @@ -The sectool project is no longer developed nor maintained upstream. As a replacement, try the OpenSCAP project (https://www.open-scap.org) and its sectool SCL content (openscap-content-sectool package). diff --git a/sectool-0.9.2-optflags.patch b/sectool-0.9.2-optflags.patch new file mode 100644 index 0000000..9779cf7 --- /dev/null +++ b/sectool-0.9.2-optflags.patch @@ -0,0 +1,12 @@ +diff -up sectool-0.9.2/src/Makefile~ sectool-0.9.2/src/Makefile +--- sectool-0.9.2/src/Makefile~ 2008-11-13 11:08:40.000000000 +0200 ++++ sectool-0.9.2/src/Makefile 2009-04-23 00:19:30.000000000 +0300 +@@ -1,7 +1,7 @@ + include ../sectool.mk + + CC= gcc +-CFLAGS= -Wall -O2 -ffast-math -I. -D_FILE_OFFSET_BITS=64 -DTEST_SELINUX -I/usr/include/rpm ++CFLAGS= -Wall -O2 -ffast-math $(RPM_OPT_FLAGS) -I. -D_FILE_OFFSET_BITS=64 -DTEST_SELINUX -I/usr/include/rpm + LDFLAGS= -lrpm -lselinux + + SRCS_sectool=sectool.c diff --git a/sectool-0.9.3-ext4.patch b/sectool-0.9.3-ext4.patch new file mode 100644 index 0000000..b06d0b8 --- /dev/null +++ b/sectool-0.9.3-ext4.patch @@ -0,0 +1,12 @@ +diff -up sectool-0.9.3/tests/03_filesystem.dsc.ext4 sectool-0.9.3/tests/03_filesystem.dsc +--- sectool-0.9.3/tests/03_filesystem.dsc.ext4 2009-07-14 15:18:11.472860778 +0200 ++++ sectool-0.9.3/tests/03_filesystem.dsc 2009-07-14 15:18:32.558798787 +0200 +@@ -15,7 +15,7 @@ GROUPS="filesystem packages selinux" + AUTHOR="Dan Kopecek " + + [DEFAULT] +-FSTYPES="ext2 ext3 reiserfs xfs" ++FSTYPES="ext2 ext3 ext4 reiserfs xfs" + EXCLUDE="/var/lib/misc + /var/lib/mock" + INCLUDE="/bin diff --git a/sectool.log b/sectool.log new file mode 100644 index 0000000..b8c5f70 --- /dev/null +++ b/sectool.log @@ -0,0 +1,7 @@ +/var/log/sectool.log { + missingok + notifempty + size 250k + create 0644 root root +} + diff --git a/sectool.spec b/sectool.spec new file mode 100644 index 0000000..9ab2f0a --- /dev/null +++ b/sectool.spec @@ -0,0 +1,223 @@ +Summary: A security audit system and intrusion detection system +Name: sectool +Version: 0.9.3 +Release: 2%{?dist} +URL: https://hosted.fedoraproject.org/sectool/wiki/WikiStart +Source0: %{name}-%{version}.tar.bz2 +Source1: sectool.log +Patch1: sectool-0.9.2-optflags.patch +Patch2: sectool-0.9.3-ext4.patch +License: GPLv2+ +Group: Applications/System +Requires: gettext coreutils libselinux +Requires: python2 rpm-python libselinux-python glibc-headers +BuildRequires: desktop-file-utils gettext intltool asciidoc +BuildRequires: rpm-devel >= 4.6.0 +BuildRequires: libselinux-devel glibc-headers +BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n) + +%package gui +Summary: GUI for sectool - security audit system and intrusion detection system +License: GPLv2+ +Group: Applications/System +Requires: sectool = %{version}-%{release} +Requires: pygtk2 usermode + +%description +sectool is a security tool that can be used both as a security audit +and intrusion detection system. It consists of set of tests, library +and command line interface tool. Tests are sorted into groups and security +levels. Admins can run certain tests, groups or whole security levels. +The library and the tools are implemented in python and tests are +language independent. + +%description gui +sectool-gui provides a GTK-based graphical user interface to sectool. + +%prep +%setup -q +%patch1 -p1 -b .optflags +%patch2 -p1 -b .ext4 + +%build +make %{?_smp_mflags} + +%install +rm -rf $RPM_BUILD_ROOT +make DESTDIR=$RPM_BUILD_ROOT install +desktop-file-install --delete-original \ + --dir $RPM_BUILD_ROOT%{_datadir}/applications \ + --vendor=fedora \ + $RPM_BUILD_ROOT%{_datadir}/applications/sectool.desktop + +#logrotate +install -d -m 755 $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d +install -p -m 644 %{SOURCE1} $RPM_BUILD_ROOT%{_sysconfdir}/logrotate.d/sectool +#adjust paths in sectool.conf +sed -i 's,DSC_DIR=\(.*\),DSC_DIR=%{_sysconfdir}/sectool/tests,' $RPM_BUILD_ROOT%{_sysconfdir}/sectool/sectool.conf +sed -i 's,TESTS_DIRS=\(.*\),TESTS_DIRS=%{_datadir}/sectool/tests,' $RPM_BUILD_ROOT%{_sysconfdir}/sectool/sectool.conf +sed -i 's,TDATA_DIR_BASE=\(.*\),TDATA_DIR_BASE=%{_localstatedir}/lib/sectool,' $RPM_BUILD_ROOT%{_sysconfdir}/sectool/sectool.conf +#adjust icons path in guiOutput.py +sed -i 's,__ico_path = \(.*\),__ico_path = "%{_datadir}/pixmaps/sectool/",' $RPM_BUILD_ROOT%{_datadir}/sectool/guiOutput.py +#this file is just for development +rm $RPM_BUILD_ROOT/%{_datadir}/sectool/scheduler/selftest.py + +%find_lang %{name} + +%clean +rm -rf $RPM_BUILD_ROOT + +%files -f %{name}.lang +%defattr(-,root,root) +%doc COPYING AUTHORS README doc/tests_documentation.html +%config(noreplace) %{_sysconfdir}/sectool/ +%config(noreplace) %{_sysconfdir}/logrotate.d/sectool +%dir %{_localstatedir}/lib/sectool +%dir %{_datadir}/sectool +%{_sbindir}/sectool +#library with tests +%{_datadir}/sectool/scheduler +%{_datadir}/sectool/tests +# command line tool +%{_datadir}/sectool/actions.py* +%{_datadir}/sectool/__init__.py* +%{_datadir}/sectool/output.py* +%{_datadir}/sectool/mailoutput.py* +%{_datadir}/sectool/sectool.py* +%{_datadir}/sectool/tuierrors.py* +%{_mandir}/man8/sectool.8.gz + + +%files gui +%defattr(-,root,root) +%config(noreplace) %{_sysconfdir}/pam.d/sectool-gui +%config(noreplace) %{_sysconfdir}/security/console.apps/sectool-gui +%{_bindir}/sectool-gui +%{_datadir}/sectool/gui*.py* +%{_datadir}/sectool/sectool-gui.py* +%{_datadir}/pixmaps/sectool-gui.png +%{_datadir}/pixmaps/sectool-min.png +%{_datadir}/applications/fedora-sectool.desktop +%{_datadir}/pixmaps/sectool/*.png + + +%changelog +* Tue Jul 14 2009 Peter Vrabec - 0.9.3-2 +- handle ext4 fs in filesystem test (#510646) + +* Wed Jun 03 2009 Peter Vrabec - 0.9.3-1 +- upgrade, bugfix release + +* Thu May 21 2009 Ville Skyttä - 0.9.2-5 +- Build with $RPM_OPT_FLAGS (#497231). + +* Mon Jan 26 2009 Daniel Kopecek - 0.9.2-4 +- removed showvars.dsc + +* Fri Jan 23 2009 Daniel Kopecek - 0.9.2-3 +- removed showvars.sh +- added dist macro to Release: + +* Tue Dec 02 2008 Daniel Kopecek - 0.9.2-2 +- bugfix release + +* Mon Nov 24 2008 Daniel Kopecek - 0.9.2-1 +- upgrade, see changelog for changes + +* Mon Nov 03 2008 Peter Vrabec - 0.9.1-4 +- checking zsh home files (#469913) +- fix selinux test failure (#469910) + +* Mon Nov 03 2008 Peter Vrabec - 0.9.1-3 +- fix getValueFromH() (#469368) +- fix GUI: set REFRESH, DEBUG, LEVEL + +* Thu Oct 23 2008 Peter Vrabec - 0.9.1-2 +- add missing requirement (468033) +- fix deps of cron test (468033) + +* Wed Oct 22 2008 Peter Vrabec - 0.9.1-1 +- upgrade, bugfix release + +* Thu Oct 09 2008 Peter Vrabec - 0.9.0-1 +- upgrade, see changelog for changes + +* Sat Sep 06 2008 Peter Vrabec - 0.8.6-2 +- fix selinux DEPS, quick workaround + +* Fri Sep 05 2008 Peter Vrabec - 0.8.6-1 +- upgrade, see changelog + +* Thu Jul 03 2008 Peter Vrabec - 0.8.0-1 +- upgrade + +* Fri Jun 06 2008 Peter Vrabec - 0.7.6-1 +- upgrade + +* Mon May 26 2008 Peter Vrabec - 0.7.5-1 +- upgrade + +* Wed May 21 2008 Peter Vrabec - 0.7.4-1 +- new upstream release, lots of fixes and improvements, + see changelog + +* Mon Apr 28 2008 Peter Vrabec - 0.7.3-1 +- new upstream release +- better test integration + +* Fri Apr 25 2008 Peter Vrabec - 0.7.2-1 +- new upstream release +- Support overriding level configuration in ~/.sectoolrc +- Add saving level configuration in GUI: + +* Mon Apr 21 2008 Peter Vrabec - 0.7.1-1 +- new upstream release + +* Tue Apr 08 2008 Peter Vrabec - 0.7.0-1 +- new upstream release + +* Mon Mar 31 2008 Maros Barabas - 0.6.0-4 +- improved killing system in gui + +* Fri Mar 28 2008 Maros Barabas - 0.6.0-3 +- code review: cleaning code in OuputFormatter + adding comments + migrating public formatter methods to private + +* Tue Mar 25 2008 Maros Barabas - 0.6.0-2 +- repaired sensitivity of popup buttons +- code review: migrating public methods to private + more comments + +* Fri Mar 21 2008 Peter Vrabec - 0.6.0-1 +- gui improvements +- new feature include/exclude tests +- new sectool.conf + +* Mon Mar 18 2008 Jakub Hrozek - 0.5.1-1 +- Fix mail output + +* Wed Mar 05 2008 Peter Vrabec - 0.5.0-1 +- email sending support + +* Wed Mar 05 2008 Peter Vrabec - 0.4.0-1 +- new tests +- bugfixes +- support diff results +- improved GUI + +* Wed Jan 23 2008 Peter Vrabec - 0.2.0-1 +- stable demo release + +* Fri Jan 18 2008 Peter Vrabec - 0.1.0-4 +- fix rpmbuild on fc8 + +* Wed Jan 16 2008 Peter Vrabec - 0.1.0-3 +- fix license issues +- some macros clean up in makefile and spec + +* Wed Jan 16 2008 Peter Vrabec - 0.1.0-2 +- make rpmlint happy, very important cleanup + +* Tue Jan 15 2008 Peter Vrabec - 0.1.0-1 +- initial packaging diff --git a/sources b/sources new file mode 100644 index 0000000..11ac280 --- /dev/null +++ b/sources @@ -0,0 +1 @@ +c159880406a54463609f60a714db22a8 sectool-0.9.3.tar.bz2