From 8a45d8adbc35a78c5bc3d18178f554c64afa4c0d Mon Sep 17 00:00:00 2001 From: "Gabriel L. Somlo" Date: Mon, 19 Jun 2017 09:51:32 -0400 Subject: [PATCH 1/5] import srpm into new epel7 branch --- .cvsignore | 0 .gitignore | 1 + Makefile | 21 ---- sources | 1 + vtun-nostrip.patch | 12 ++ vtun-openssl.patch | 287 +++++++++++++++++++++++++++++++++++++++++++++ vtun.service | 12 ++ vtun.socket | 8 ++ vtun.spec | 174 +++++++++++++++++++++++++++ vtun.sysconfig | 16 +++ 10 files changed, 511 insertions(+), 21 deletions(-) delete mode 100644 .cvsignore create mode 100644 .gitignore delete mode 100644 Makefile create mode 100644 vtun-nostrip.patch create mode 100644 vtun-openssl.patch create mode 100644 vtun.service create mode 100644 vtun.socket create mode 100644 vtun.spec create mode 100644 vtun.sysconfig diff --git a/.cvsignore b/.cvsignore deleted file mode 100644 index e69de29..0000000 diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..8d04f22 --- /dev/null +++ b/.gitignore @@ -0,0 +1 @@ +/vtun-3.0.4.tar.gz diff --git a/Makefile b/Makefile deleted file mode 100644 index 68b6d3f..0000000 --- a/Makefile +++ /dev/null @@ -1,21 +0,0 @@ -# Makefile for source rpm: vtun -# $Id$ -NAME := vtun -SPECFILE = $(firstword $(wildcard *.spec)) - -define find-makefile-common -for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done -endef - -MAKEFILE_COMMON := $(shell $(find-makefile-common)) - -ifeq ($(MAKEFILE_COMMON),) -# attept a checkout -define checkout-makefile-common -test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2 -endef - -MAKEFILE_COMMON := $(shell $(checkout-makefile-common)) -endif - -include $(MAKEFILE_COMMON) diff --git a/sources b/sources index e69de29..1487886 100644 --- a/sources +++ b/sources @@ -0,0 +1 @@ +SHA512 (vtun-3.0.4.tar.gz) = b1bb7294bd745c2ca888704e2b0f8e05447b5e01bec0f921648afe363d61a19508dea9e26663993cd69c506aa92621e76f36045bddf7c3723d13a72741ca6781 diff --git a/vtun-nostrip.patch b/vtun-nostrip.patch new file mode 100644 index 0000000..cd07a1a --- /dev/null +++ b/vtun-nostrip.patch @@ -0,0 +1,12 @@ +diff -NarU5 a/Makefile.in b/Makefile.in +--- a/Makefile.in 2016-10-01 17:46:00.000000000 -0400 ++++ b/Makefile.in 2017-03-17 16:49:16.195772745 -0400 +@@ -97,8 +97,7 @@ + $(INSTALL) -d -m 755 $(INSTALL_OWNER) $(DESTDIR)$(VAR_DIR)/run + $(INSTALL) -d -m 755 $(INSTALL_OWNER) $(DESTDIR)$(STAT_DIR) + $(INSTALL) -d -m 755 $(INSTALL_OWNER) $(DESTDIR)$(LOCK_DIR) + $(INSTALL) -d -m 755 $(INSTALL_OWNER) $(DESTDIR)$(SBIN_DIR) + $(INSTALL) -m 755 $(INSTALL_OWNER) vtund $(DESTDIR)$(SBIN_DIR) +- $(BIN_DIR)/strip $(DESTDIR)$(SBIN_DIR)/vtund + + # DO NOT DELETE THIS LINE -- make depend depends on it. diff --git a/vtun-openssl.patch b/vtun-openssl.patch new file mode 100644 index 0000000..c375789 --- /dev/null +++ b/vtun-openssl.patch @@ -0,0 +1,287 @@ +diff -NarU5 a/lfd_encrypt.c b/lfd_encrypt.c +--- a/lfd_encrypt.c 2016-10-01 17:27:51.000000000 -0400 ++++ b/lfd_encrypt.c 2017-03-20 08:43:48.013308435 -0400 +@@ -93,15 +93,15 @@ + static int dec_init_first_time; + static unsigned long sequence_num; + static char * pkey; + static char * iv_buf; + +-static EVP_CIPHER_CTX ctx_enc; /* encrypt */ +-static EVP_CIPHER_CTX ctx_dec; /* decrypt */ ++static EVP_CIPHER_CTX *ctx_enc; /* encrypt */ ++static EVP_CIPHER_CTX *ctx_dec; /* decrypt */ + +-static EVP_CIPHER_CTX ctx_enc_ecb; /* sideband ecb encrypt */ +-static EVP_CIPHER_CTX ctx_dec_ecb; /* sideband ecb decrypt */ ++static EVP_CIPHER_CTX *ctx_enc_ecb; /* sideband ecb encrypt */ ++static EVP_CIPHER_CTX *ctx_dec_ecb; /* sideband ecb decrypt */ + + static int send_msg(int len, char *in, char **out); + static int recv_msg(int len, char *in, char **out); + static int send_ib_mesg(int *len, char **in); + static int recv_ib_mesg(int *len, char **in); +@@ -180,37 +180,37 @@ + case VTUN_ENC_AES256CBC: + blocksize = 16; + keysize = 32; + sb_init = 1; + cipher_type = EVP_aes_256_ecb(); +- pctx_enc = &ctx_enc_ecb; +- pctx_dec = &ctx_dec_ecb; ++ pctx_enc = ctx_enc_ecb; ++ pctx_dec = ctx_dec_ecb; + break; + + case VTUN_ENC_AES256ECB: + blocksize = 16; + keysize = 32; +- pctx_enc = &ctx_enc; +- pctx_dec = &ctx_dec; ++ pctx_enc = ctx_enc; ++ pctx_dec = ctx_dec; + cipher_type = EVP_aes_256_ecb(); + strcpy(cipher_name,"AES-256-ECB"); + break; + case VTUN_ENC_AES128OFB: + case VTUN_ENC_AES128CFB: + case VTUN_ENC_AES128CBC: + blocksize = 16; + keysize = 16; + sb_init=1; + cipher_type = EVP_aes_128_ecb(); +- pctx_enc = &ctx_enc_ecb; +- pctx_dec = &ctx_dec_ecb; ++ pctx_enc = ctx_enc_ecb; ++ pctx_dec = ctx_dec_ecb; + break; + case VTUN_ENC_AES128ECB: + blocksize = 16; + keysize = 16; +- pctx_enc = &ctx_enc; +- pctx_dec = &ctx_dec; ++ pctx_enc = ctx_enc; ++ pctx_dec = ctx_dec; + cipher_type = EVP_aes_128_ecb(); + strcpy(cipher_name,"AES-128-ECB"); + break; + + case VTUN_ENC_BF256OFB: +@@ -219,20 +219,20 @@ + blocksize = 8; + keysize = 32; + var_key = 1; + sb_init = 1; + cipher_type = EVP_bf_ecb(); +- pctx_enc = &ctx_enc_ecb; +- pctx_dec = &ctx_dec_ecb; ++ pctx_enc = ctx_enc_ecb; ++ pctx_dec = ctx_dec_ecb; + break; + + case VTUN_ENC_BF256ECB: + blocksize = 8; + keysize = 32; + var_key = 1; +- pctx_enc = &ctx_enc; +- pctx_dec = &ctx_dec; ++ pctx_enc = ctx_enc; ++ pctx_dec = ctx_dec; + cipher_type = EVP_bf_ecb(); + strcpy(cipher_name,"Blowfish-256-ECB"); + break; + + case VTUN_ENC_BF128OFB: +@@ -241,26 +241,28 @@ + blocksize = 8; + keysize = 16; + var_key = 1; + sb_init = 1; + cipher_type = EVP_bf_ecb(); +- pctx_enc = &ctx_enc_ecb; +- pctx_dec = &ctx_dec_ecb; ++ pctx_enc = ctx_enc_ecb; ++ pctx_dec = ctx_dec_ecb; + break; + case VTUN_ENC_BF128ECB: /* blowfish 128 ecb is the default */ + default: + blocksize = 8; + keysize = 16; + var_key = 1; +- pctx_enc = &ctx_enc; +- pctx_dec = &ctx_dec; ++ pctx_enc = ctx_enc; ++ pctx_dec = ctx_dec; + cipher_type = EVP_bf_ecb(); + strcpy(cipher_name,"Blowfish-128-ECB"); + break; + } /* switch(host->cipher) */ + + if (prep_key(&pkey, keysize, host) != 0) return -1; ++ pctx_enc = EVP_CIPHER_CTX_new(); ++ pctx_dec = EVP_CIPHER_CTX_new(); + EVP_CIPHER_CTX_init(pctx_enc); + EVP_CIPHER_CTX_init(pctx_dec); + EVP_EncryptInit_ex(pctx_enc, cipher_type, NULL, NULL, NULL); + EVP_DecryptInit_ex(pctx_dec, cipher_type, NULL, NULL, NULL); + if (var_key) +@@ -292,14 +294,14 @@ + free_key(pkey); pkey = NULL; + + lfd_free(enc_buf); enc_buf = NULL; + lfd_free(dec_buf); dec_buf = NULL; + +- EVP_CIPHER_CTX_cleanup(&ctx_enc); +- EVP_CIPHER_CTX_cleanup(&ctx_dec); +- EVP_CIPHER_CTX_cleanup(&ctx_enc_ecb); +- EVP_CIPHER_CTX_cleanup(&ctx_dec_ecb); ++ EVP_CIPHER_CTX_free(ctx_enc); ++ EVP_CIPHER_CTX_free(ctx_dec); ++ EVP_CIPHER_CTX_free(ctx_enc_ecb); ++ EVP_CIPHER_CTX_free(ctx_dec_ecb); + + return 0; + } + + static int encrypt_buf(int len, char *in, char **out) +@@ -321,11 +323,11 @@ + + memset(in_ptr+len, pad, pad); + outlen=len+pad; + if (pad == blocksize) + RAND_bytes(in_ptr+len, blocksize-1); +- EVP_EncryptUpdate(&ctx_enc, out_ptr, &outlen, in_ptr, len+pad); ++ EVP_EncryptUpdate(ctx_enc, out_ptr, &outlen, in_ptr, len+pad); + *out = enc_buf; + + sequence_num++; + + return outlen+msg_len; +@@ -341,11 +343,11 @@ + in = *out; + in_ptr = in; + + outlen=len; + if (!len) return 0; +- EVP_DecryptUpdate(&ctx_dec, out_ptr, &outlen, in_ptr, len); ++ EVP_DecryptUpdate(ctx_dec, out_ptr, &outlen, in_ptr, len); + recv_ib_mesg(&outlen, &out_ptr); + if (!outlen) return 0; + tmp_ptr = out_ptr + outlen; tmp_ptr--; + pad = *tmp_ptr; + if (pad < 1 || pad > blocksize) { +@@ -429,17 +431,18 @@ + /* if we're here, something weird's going on */ + return -1; + break; + } /* switch(cipher) */ + +- EVP_CIPHER_CTX_init(&ctx_enc); +- EVP_EncryptInit_ex(&ctx_enc, cipher_type, NULL, NULL, NULL); ++ ctx_enc = EVP_CIPHER_CTX_new(); ++ EVP_CIPHER_CTX_init(ctx_enc); ++ EVP_EncryptInit_ex(ctx_enc, cipher_type, NULL, NULL, NULL); + if (var_key) +- EVP_CIPHER_CTX_set_key_length(&ctx_enc, keysize); +- EVP_EncryptInit_ex(&ctx_enc, NULL, NULL, pkey, NULL); +- EVP_EncryptInit_ex(&ctx_enc, NULL, NULL, NULL, iv); +- EVP_CIPHER_CTX_set_padding(&ctx_enc, 0); ++ EVP_CIPHER_CTX_set_key_length(ctx_enc, keysize); ++ EVP_EncryptInit_ex(ctx_enc, NULL, NULL, pkey, NULL); ++ EVP_EncryptInit_ex(ctx_enc, NULL, NULL, NULL, iv); ++ EVP_CIPHER_CTX_set_padding(ctx_enc, 0); + if (enc_init_first_time) + { + sprintf(tmpstr,"%s encryption initialized", cipher_name); + vtun_syslog(LOG_INFO, tmpstr); + enc_init_first_time = 0; +@@ -519,17 +522,18 @@ + /* if we're here, something weird's going on */ + return -1; + break; + } /* switch(cipher) */ + +- EVP_CIPHER_CTX_init(&ctx_dec); +- EVP_DecryptInit_ex(&ctx_dec, cipher_type, NULL, NULL, NULL); ++ ctx_dec = EVP_CIPHER_CTX_new(); ++ EVP_CIPHER_CTX_init(ctx_dec); ++ EVP_DecryptInit_ex(ctx_dec, cipher_type, NULL, NULL, NULL); + if (var_key) +- EVP_CIPHER_CTX_set_key_length(&ctx_dec, keysize); +- EVP_DecryptInit_ex(&ctx_dec, NULL, NULL, pkey, NULL); +- EVP_DecryptInit_ex(&ctx_dec, NULL, NULL, NULL, iv); +- EVP_CIPHER_CTX_set_padding(&ctx_dec, 0); ++ EVP_CIPHER_CTX_set_key_length(ctx_dec, keysize); ++ EVP_DecryptInit_ex(ctx_dec, NULL, NULL, pkey, NULL); ++ EVP_DecryptInit_ex(ctx_dec, NULL, NULL, NULL, iv); ++ EVP_CIPHER_CTX_set_padding(ctx_dec, 0); + if (dec_init_first_time) + { + sprintf(tmpstr,"%s decryption initialized", cipher_name); + vtun_syslog(LOG_INFO, tmpstr); + dec_init_first_time = 0; +@@ -557,11 +561,11 @@ + memset(iv,0,blocksize); free(iv); iv = NULL; + RAND_bytes(in_ptr, in - in_ptr); + + in_ptr = in - blocksize*2; + outlen = blocksize*2; +- EVP_EncryptUpdate(&ctx_enc_ecb, in_ptr, ++ EVP_EncryptUpdate(ctx_enc_ecb, in_ptr, + &outlen, in_ptr, blocksize*2); + *out = in_ptr; + len = outlen; + cipher_enc_state = CIPHER_SEQUENCE; + break; +@@ -584,11 +588,11 @@ + { + case CIPHER_INIT: + in_ptr = in; + iv = malloc(blocksize); + outlen = blocksize*2; +- EVP_DecryptUpdate(&ctx_dec_ecb, in_ptr, &outlen, in_ptr, blocksize*2); ++ EVP_DecryptUpdate(ctx_dec_ecb, in_ptr, &outlen, in_ptr, blocksize*2); + + if ( !strncmp(in_ptr, "ivec", 4) ) + { + memcpy(iv, in_ptr+4, blocksize); + cipher_dec_init(iv); +@@ -627,11 +631,11 @@ + "Max. gibberish threshold reached"); + #endif + if (cipher_enc_state != CIPHER_INIT) + { + cipher_enc_state = CIPHER_INIT; +- EVP_CIPHER_CTX_cleanup(&ctx_enc); ++ EVP_CIPHER_CTX_free(ctx_enc); + #ifdef LFD_ENCRYPT_DEBUG + vtun_syslog(LOG_INFO, + "Forcing local encryptor re-init"); + #endif + } +@@ -708,11 +712,11 @@ + *len -= blocksize; + + if (cipher_enc_state != CIPHER_INIT) + { + cipher_enc_state = CIPHER_INIT; +- EVP_CIPHER_CTX_cleanup(&ctx_enc); ++ EVP_CIPHER_CTX_free(ctx_enc); + } + #ifdef LFD_ENCRYPT_DEBUG + vtun_syslog(LOG_INFO, "Remote requests encryptor re-init"); + #endif + } +@@ -722,11 +726,11 @@ + + if (cipher_dec_state != CIPHER_INIT && + cipher_enc_state != CIPHER_REQ_INIT && + cipher_enc_state != CIPHER_INIT) + { +- EVP_CIPHER_CTX_cleanup (&ctx_dec); ++ EVP_CIPHER_CTX_free (ctx_dec); + cipher_dec_state = CIPHER_INIT; + cipher_enc_state = CIPHER_REQ_INIT; + } + #ifdef LFD_ENCRYPT_DEBUG + vtun_syslog(LOG_INFO, "Local decryptor out of sync"); diff --git a/vtun.service b/vtun.service new file mode 100644 index 0000000..d26d83c --- /dev/null +++ b/vtun.service @@ -0,0 +1,12 @@ +[Unit] +Description=Virtual Tunnels over TCP/IP networks +After=syslog.target network.target + +[Service] +EnvironmentFile=/etc/sysconfig/vtun +ExecStart=/usr/sbin/vtund -n $OPTIONS +ExecReload=/usr/bin/kill -HUP $MAINPID +Restart=on-failure + +[Install] +WantedBy=multi-user.target diff --git a/vtun.socket b/vtun.socket new file mode 100644 index 0000000..07f9d3d --- /dev/null +++ b/vtun.socket @@ -0,0 +1,8 @@ +[Unit] +Description=Vtun Activation Socket + +[Socket] +ListenStream=5000 + +[Install] +WantedBy=sockets.target diff --git a/vtun.spec b/vtun.spec new file mode 100644 index 0000000..bbd3c7d --- /dev/null +++ b/vtun.spec @@ -0,0 +1,174 @@ +Name: vtun +Version: 3.0.4 +Release: 1%{?dist} +Summary: Virtual tunnel over TCP/IP networks +License: GPLv2+ +Group: System Environment/Daemons +Url: http://vtun.sourceforge.net +Source0: http://prdownloads.sourceforge.net/%{name}/%{name}-%{version}.tar.gz +Source1: vtun.socket +Source2: vtun.service +Source3: vtun.sysconfig +Patch0: vtun-nostrip.patch +Patch1: vtun-openssl.patch + +Requires(post): systemd-units +Requires(preun): systemd-units +Requires(postun): systemd-units +BuildRequires: zlib-devel lzo-devel openssl-devel bison flex systemd-units autoconf + +#enable PIE/PIC: +%global _hardened_build 1 + +%description +VTun provides a method for creating Virtual Tunnels over TCP/IP networks +and allows one to shape, compress, and encrypt traffic in those tunnels. +Supported types of tunnels are: PPP, IP, Ethernet and most other serial +protocols and programs. +VTun is easily and highly configurable: it can be used for various +network tasks like VPN, Mobile IP, Shaped Internet access, IP address +saving, etc. It is completely a user space implementation and does not +require modification to any kernel parts. + +%prep +%setup -q +%patch0 -p1 +%patch1 -p1 + +%build +%{__autoconf} +# FIXME: Package suffers from c11/inline issues. +# Workaround by appending --std=gnu89 to CFLAGS +# Proper fix would be to fix the source-code +%configure CFLAGS="${RPM_OPT_FLAGS} --std=gnu89" +make %{?_smp_mflags} + +%install +install -D -m 0644 -p %{SOURCE1} %{buildroot}/%{_unitdir}/vtun.socket +install -D -m 0644 -p %{SOURCE2} %{buildroot}/%{_unitdir}/vtun.service +install -D -m 0644 -p %{SOURCE3} %{buildroot}/%{_sysconfdir}/sysconfig/vtun +make install DESTDIR=%{buildroot} INSTALL_OWNER= INSTALL="/usr/bin/install -p" + +%post +%systemd_post vtun.service vtun.socket + +%preun +%systemd_preun vtun.service vtun.socket + +%postun +%systemd_postun vtun.service vtun.socket + +%files +%defattr(-,root,root,-) +%doc ChangeLog Credits FAQ README README.LZO README.Setup README.Shaper TODO vtund.conf +%config(noreplace) %{_sysconfdir}/vtund.conf +%config(noreplace) %{_sysconfdir}/sysconfig/vtun +%{_unitdir}/vtun.socket +%{_unitdir}/vtun.service +%{_sbindir}/vtund +%dir %{_localstatedir}/log/vtund +%ghost %dir %{_localstatedir}/lock/vtund +%{_mandir}/man5/vtund.conf.5* +%{_mandir}/man8/vtun.8* +%{_mandir}/man8/vtund.8* + +%changelog +* Fri Mar 17 2017 Gabriel Somlo 3.0.3-1 +- update to 3.0.4 +- patch for openssl-1.1 transition + +* Sat Feb 11 2017 Fedora Release Engineering - 3.0.3-16 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Mon Mar 21 2016 Gabriel Somlo 3.0.3-15 +- patch to fix #1319858,#1319859,#1319861 + +* Fri Feb 05 2016 Fedora Release Engineering - 3.0.3-14 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Mon Jun 22 2015 Ralf Corsépius - 3.0.3-13 +- Append --stdc=gnu89 to CFLAGS (Work-around to c11/inline compatibility + issues. Fix FTBFS). + +* Fri Jun 19 2015 Fedora Release Engineering - 3.0.3-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Tue Dec 23 2014 Gabriel Somlo 3.0.3-11 +- enhanced service file (remove "KillMode", use default "cgroup" mode) + +* Thu Nov 20 2014 Gabriel Somlo 3.0.3-10 +- enhanced service file (-n to prevent daemonizing vtund) + +* Fri Nov 14 2014 Gabriel Somlo 3.0.3-9 +- added /etc/sysconfig/vtun environment file +- updated unit files + +* Mon Aug 18 2014 Fedora Release Engineering - 3.0.3-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Sun Jun 08 2014 Fedora Release Engineering - 3.0.3-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Sun Aug 04 2013 Fedora Release Engineering - 3.0.3-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Mon May 13 2013 Gabriel Somlo 3.0.3-5 +- added autoconf step to support aarch64 (#926708) + +* Wed May 01 2013 Gabriel Somlo 3.0.3-4 +- rebuild with PIE (#955286) + +* Fri Feb 15 2013 Fedora Release Engineering +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Sun Sep 16 2012 Gabriel Somlo 3.0.3-2 +- avoid stripping too early to preserve debuginfo (#857716) + +* Thu Sep 13 2012 Gabriel Somlo 3.0.3-1 +- update to 3.0.3 +- new systemd-rpm macros (#850362) + +* Sun Jul 22 2012 Fedora Release Engineering - 3.0.1-15 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Mon May 21 2012 Peter Robinson - 3.0.1-14 +- Fix unit file location, cleanup and modernise spec + +* Sat Jan 14 2012 Fedora Release Engineering - 3.0.1-13 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Sat Sep 10 2011 Gabriel Somlo 3.0.1-12 +- removed xinetd and sysvinit support + +* Sat Sep 10 2011 Gabriel Somlo 3.0.1-11 +- update support for systemd (#737195) + +* Mon Feb 07 2011 Fedora Release Engineering - 3.0.1-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild + +* Thu Jan 06 2011 Gabriel Somlo 3.0.1-9 +- add support for systemd (#661331) + +* Tue Nov 30 2010 Gabriel Somlo 3.0.1-8 +- using ghost on /var/lock/vtund directory (#656720) + +* Fri Aug 21 2009 Tomas Mraz - 3.0.1-7 +- rebuilt with new openssl + +* Sun Jul 26 2009 Fedora Release Engineering - 3.0.1-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild + +* Wed Feb 25 2009 Fedora Release Engineering - 3.0.1-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild + +* Sun Jan 18 2009 Tomas Mraz 3.0.1-4 +- rebuild with new openssl + +* Mon Nov 17 2008 Gabriel Somlo 3.0.1-3 +- scriptlets fixes + +* Fri Nov 14 2008 Gabriel Somlo 3.0.1-2 +- spec file fixes: defattr, -p flag to install program + +* Mon Oct 20 2008 Gabriel Somlo 3.0.1-1 +- initial fedora package diff --git a/vtun.sysconfig b/vtun.sysconfig new file mode 100644 index 0000000..467bd8b --- /dev/null +++ b/vtun.sysconfig @@ -0,0 +1,16 @@ +# Comment out one of the following for client or server mode +# +# To run vtun as a server: +# +#OPTIONS='-s' +# +# +# +#To run vtun as a client, we need: +# +# - session name, e.g. "lion"; must be present in both client and server +# config files. +# +# - server address or host name. +# +#OPTIONS='lion vtun-server.example.com' From 8af59462109b37f5a829790789b284200fad98ba Mon Sep 17 00:00:00 2001 From: "Gabriel L. Somlo" Date: Mon, 31 Jul 2017 14:45:03 -0400 Subject: [PATCH 2/5] add /usr/lib/tmpfiles.d/vtun.conf to enable lock dir. on tmpfs --- vtun.spec | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/vtun.spec b/vtun.spec index bbd3c7d..f98c756 100644 --- a/vtun.spec +++ b/vtun.spec @@ -1,6 +1,6 @@ Name: vtun Version: 3.0.4 -Release: 1%{?dist} +Release: 2%{?dist} Summary: Virtual tunnel over TCP/IP networks License: GPLv2+ Group: System Environment/Daemons @@ -48,6 +48,11 @@ install -D -m 0644 -p %{SOURCE1} %{buildroot}/%{_unitdir}/vtun.socket install -D -m 0644 -p %{SOURCE2} %{buildroot}/%{_unitdir}/vtun.service install -D -m 0644 -p %{SOURCE3} %{buildroot}/%{_sysconfdir}/sysconfig/vtun make install DESTDIR=%{buildroot} INSTALL_OWNER= INSTALL="/usr/bin/install -p" +# tmpfiles.d configuration for /var/lock/vtund: +mkdir -p %{buildroot}/%{_tmpfilesdir} +cat > %{buildroot}/%{_tmpfilesdir}/%{name}.conf << EOT +d %{_localstatedir}/lock/vtund 0755 root root - +EOT %post %systemd_post vtun.service vtun.socket @@ -66,13 +71,17 @@ make install DESTDIR=%{buildroot} INSTALL_OWNER= INSTALL="/usr/bin/install -p" %{_unitdir}/vtun.socket %{_unitdir}/vtun.service %{_sbindir}/vtund +%{_tmpfilesdir}/%{name}.conf %dir %{_localstatedir}/log/vtund -%ghost %dir %{_localstatedir}/lock/vtund +%dir %{_localstatedir}/lock/vtund %{_mandir}/man5/vtund.conf.5* %{_mandir}/man8/vtun.8* %{_mandir}/man8/vtund.8* %changelog +* Mon Jul 31 2017 Gabriel Somlo 3.0.3-2 +- add /usr/lib/tmpfiles.d/vtun.conf to enable lock dir. on tmpfs + * Fri Mar 17 2017 Gabriel Somlo 3.0.3-1 - update to 3.0.4 - patch for openssl-1.1 transition From 867c7ebfce88dcf134560fcaf75eff02bde7808f Mon Sep 17 00:00:00 2001 From: "Gabriel L. Somlo" Date: Sat, 2 Sep 2017 18:36:50 -0400 Subject: [PATCH 3/5] apply openssl-1.1 patch only on Fedora >= 26, to avoid epel7 (#1487003) --- vtun.spec | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/vtun.spec b/vtun.spec index f98c756..8f135f1 100644 --- a/vtun.spec +++ b/vtun.spec @@ -1,6 +1,6 @@ Name: vtun Version: 3.0.4 -Release: 2%{?dist} +Release: 3%{?dist} Summary: Virtual tunnel over TCP/IP networks License: GPLv2+ Group: System Environment/Daemons @@ -33,7 +33,9 @@ require modification to any kernel parts. %prep %setup -q %patch0 -p1 +%if 0%{?fedora} >= 26 %patch1 -p1 +%endif %build %{__autoconf} @@ -79,6 +81,9 @@ EOT %{_mandir}/man8/vtund.8* %changelog +* Sat Sep 02 2017 Gabriel Somlo 3.0.3-3 +- apply openssl-1.1 patch only on Fedora >= 26, to avoid epel7 (#1487003) + * Mon Jul 31 2017 Gabriel Somlo 3.0.3-2 - add /usr/lib/tmpfiles.d/vtun.conf to enable lock dir. on tmpfs From e0cbbdcf7aa65a7065c359886a8e3bf0ff984f67 Mon Sep 17 00:00:00 2001 From: "Gabriel L. Somlo" Date: Sat, 2 Sep 2017 18:41:22 -0400 Subject: [PATCH 4/5] apply openssl-1.1 patch only on Fedora >= 26, to avoid epel7 (#1487003) --- vtun.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/vtun.spec b/vtun.spec index 8f135f1..dd77184 100644 --- a/vtun.spec +++ b/vtun.spec @@ -1,6 +1,6 @@ Name: vtun Version: 3.0.4 -Release: 3%{?dist} +Release: 4%{?dist} Summary: Virtual tunnel over TCP/IP networks License: GPLv2+ Group: System Environment/Daemons @@ -81,9 +81,12 @@ EOT %{_mandir}/man8/vtund.8* %changelog -* Sat Sep 02 2017 Gabriel Somlo 3.0.3-3 +* Sat Sep 02 2017 Gabriel Somlo 3.0.3-4 - apply openssl-1.1 patch only on Fedora >= 26, to avoid epel7 (#1487003) +* Thu Aug 03 2017 Fedora Release Engineering - 3.0.4-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + * Mon Jul 31 2017 Gabriel Somlo 3.0.3-2 - add /usr/lib/tmpfiles.d/vtun.conf to enable lock dir. on tmpfs From 6102af41926a779f93ad8fc0f2e60ebfc0a76f38 Mon Sep 17 00:00:00 2001 From: "Gabriel L. Somlo" Date: Wed, 11 Oct 2017 13:57:09 -0400 Subject: [PATCH 5/5] requiring compat-openssl1.0 on >= f26 --- vtun-openssl.patch | 287 --------------------------------------------- vtun.spec | 16 ++- 2 files changed, 10 insertions(+), 293 deletions(-) delete mode 100644 vtun-openssl.patch diff --git a/vtun-openssl.patch b/vtun-openssl.patch deleted file mode 100644 index c375789..0000000 --- a/vtun-openssl.patch +++ /dev/null @@ -1,287 +0,0 @@ -diff -NarU5 a/lfd_encrypt.c b/lfd_encrypt.c ---- a/lfd_encrypt.c 2016-10-01 17:27:51.000000000 -0400 -+++ b/lfd_encrypt.c 2017-03-20 08:43:48.013308435 -0400 -@@ -93,15 +93,15 @@ - static int dec_init_first_time; - static unsigned long sequence_num; - static char * pkey; - static char * iv_buf; - --static EVP_CIPHER_CTX ctx_enc; /* encrypt */ --static EVP_CIPHER_CTX ctx_dec; /* decrypt */ -+static EVP_CIPHER_CTX *ctx_enc; /* encrypt */ -+static EVP_CIPHER_CTX *ctx_dec; /* decrypt */ - --static EVP_CIPHER_CTX ctx_enc_ecb; /* sideband ecb encrypt */ --static EVP_CIPHER_CTX ctx_dec_ecb; /* sideband ecb decrypt */ -+static EVP_CIPHER_CTX *ctx_enc_ecb; /* sideband ecb encrypt */ -+static EVP_CIPHER_CTX *ctx_dec_ecb; /* sideband ecb decrypt */ - - static int send_msg(int len, char *in, char **out); - static int recv_msg(int len, char *in, char **out); - static int send_ib_mesg(int *len, char **in); - static int recv_ib_mesg(int *len, char **in); -@@ -180,37 +180,37 @@ - case VTUN_ENC_AES256CBC: - blocksize = 16; - keysize = 32; - sb_init = 1; - cipher_type = EVP_aes_256_ecb(); -- pctx_enc = &ctx_enc_ecb; -- pctx_dec = &ctx_dec_ecb; -+ pctx_enc = ctx_enc_ecb; -+ pctx_dec = ctx_dec_ecb; - break; - - case VTUN_ENC_AES256ECB: - blocksize = 16; - keysize = 32; -- pctx_enc = &ctx_enc; -- pctx_dec = &ctx_dec; -+ pctx_enc = ctx_enc; -+ pctx_dec = ctx_dec; - cipher_type = EVP_aes_256_ecb(); - strcpy(cipher_name,"AES-256-ECB"); - break; - case VTUN_ENC_AES128OFB: - case VTUN_ENC_AES128CFB: - case VTUN_ENC_AES128CBC: - blocksize = 16; - keysize = 16; - sb_init=1; - cipher_type = EVP_aes_128_ecb(); -- pctx_enc = &ctx_enc_ecb; -- pctx_dec = &ctx_dec_ecb; -+ pctx_enc = ctx_enc_ecb; -+ pctx_dec = ctx_dec_ecb; - break; - case VTUN_ENC_AES128ECB: - blocksize = 16; - keysize = 16; -- pctx_enc = &ctx_enc; -- pctx_dec = &ctx_dec; -+ pctx_enc = ctx_enc; -+ pctx_dec = ctx_dec; - cipher_type = EVP_aes_128_ecb(); - strcpy(cipher_name,"AES-128-ECB"); - break; - - case VTUN_ENC_BF256OFB: -@@ -219,20 +219,20 @@ - blocksize = 8; - keysize = 32; - var_key = 1; - sb_init = 1; - cipher_type = EVP_bf_ecb(); -- pctx_enc = &ctx_enc_ecb; -- pctx_dec = &ctx_dec_ecb; -+ pctx_enc = ctx_enc_ecb; -+ pctx_dec = ctx_dec_ecb; - break; - - case VTUN_ENC_BF256ECB: - blocksize = 8; - keysize = 32; - var_key = 1; -- pctx_enc = &ctx_enc; -- pctx_dec = &ctx_dec; -+ pctx_enc = ctx_enc; -+ pctx_dec = ctx_dec; - cipher_type = EVP_bf_ecb(); - strcpy(cipher_name,"Blowfish-256-ECB"); - break; - - case VTUN_ENC_BF128OFB: -@@ -241,26 +241,28 @@ - blocksize = 8; - keysize = 16; - var_key = 1; - sb_init = 1; - cipher_type = EVP_bf_ecb(); -- pctx_enc = &ctx_enc_ecb; -- pctx_dec = &ctx_dec_ecb; -+ pctx_enc = ctx_enc_ecb; -+ pctx_dec = ctx_dec_ecb; - break; - case VTUN_ENC_BF128ECB: /* blowfish 128 ecb is the default */ - default: - blocksize = 8; - keysize = 16; - var_key = 1; -- pctx_enc = &ctx_enc; -- pctx_dec = &ctx_dec; -+ pctx_enc = ctx_enc; -+ pctx_dec = ctx_dec; - cipher_type = EVP_bf_ecb(); - strcpy(cipher_name,"Blowfish-128-ECB"); - break; - } /* switch(host->cipher) */ - - if (prep_key(&pkey, keysize, host) != 0) return -1; -+ pctx_enc = EVP_CIPHER_CTX_new(); -+ pctx_dec = EVP_CIPHER_CTX_new(); - EVP_CIPHER_CTX_init(pctx_enc); - EVP_CIPHER_CTX_init(pctx_dec); - EVP_EncryptInit_ex(pctx_enc, cipher_type, NULL, NULL, NULL); - EVP_DecryptInit_ex(pctx_dec, cipher_type, NULL, NULL, NULL); - if (var_key) -@@ -292,14 +294,14 @@ - free_key(pkey); pkey = NULL; - - lfd_free(enc_buf); enc_buf = NULL; - lfd_free(dec_buf); dec_buf = NULL; - -- EVP_CIPHER_CTX_cleanup(&ctx_enc); -- EVP_CIPHER_CTX_cleanup(&ctx_dec); -- EVP_CIPHER_CTX_cleanup(&ctx_enc_ecb); -- EVP_CIPHER_CTX_cleanup(&ctx_dec_ecb); -+ EVP_CIPHER_CTX_free(ctx_enc); -+ EVP_CIPHER_CTX_free(ctx_dec); -+ EVP_CIPHER_CTX_free(ctx_enc_ecb); -+ EVP_CIPHER_CTX_free(ctx_dec_ecb); - - return 0; - } - - static int encrypt_buf(int len, char *in, char **out) -@@ -321,11 +323,11 @@ - - memset(in_ptr+len, pad, pad); - outlen=len+pad; - if (pad == blocksize) - RAND_bytes(in_ptr+len, blocksize-1); -- EVP_EncryptUpdate(&ctx_enc, out_ptr, &outlen, in_ptr, len+pad); -+ EVP_EncryptUpdate(ctx_enc, out_ptr, &outlen, in_ptr, len+pad); - *out = enc_buf; - - sequence_num++; - - return outlen+msg_len; -@@ -341,11 +343,11 @@ - in = *out; - in_ptr = in; - - outlen=len; - if (!len) return 0; -- EVP_DecryptUpdate(&ctx_dec, out_ptr, &outlen, in_ptr, len); -+ EVP_DecryptUpdate(ctx_dec, out_ptr, &outlen, in_ptr, len); - recv_ib_mesg(&outlen, &out_ptr); - if (!outlen) return 0; - tmp_ptr = out_ptr + outlen; tmp_ptr--; - pad = *tmp_ptr; - if (pad < 1 || pad > blocksize) { -@@ -429,17 +431,18 @@ - /* if we're here, something weird's going on */ - return -1; - break; - } /* switch(cipher) */ - -- EVP_CIPHER_CTX_init(&ctx_enc); -- EVP_EncryptInit_ex(&ctx_enc, cipher_type, NULL, NULL, NULL); -+ ctx_enc = EVP_CIPHER_CTX_new(); -+ EVP_CIPHER_CTX_init(ctx_enc); -+ EVP_EncryptInit_ex(ctx_enc, cipher_type, NULL, NULL, NULL); - if (var_key) -- EVP_CIPHER_CTX_set_key_length(&ctx_enc, keysize); -- EVP_EncryptInit_ex(&ctx_enc, NULL, NULL, pkey, NULL); -- EVP_EncryptInit_ex(&ctx_enc, NULL, NULL, NULL, iv); -- EVP_CIPHER_CTX_set_padding(&ctx_enc, 0); -+ EVP_CIPHER_CTX_set_key_length(ctx_enc, keysize); -+ EVP_EncryptInit_ex(ctx_enc, NULL, NULL, pkey, NULL); -+ EVP_EncryptInit_ex(ctx_enc, NULL, NULL, NULL, iv); -+ EVP_CIPHER_CTX_set_padding(ctx_enc, 0); - if (enc_init_first_time) - { - sprintf(tmpstr,"%s encryption initialized", cipher_name); - vtun_syslog(LOG_INFO, tmpstr); - enc_init_first_time = 0; -@@ -519,17 +522,18 @@ - /* if we're here, something weird's going on */ - return -1; - break; - } /* switch(cipher) */ - -- EVP_CIPHER_CTX_init(&ctx_dec); -- EVP_DecryptInit_ex(&ctx_dec, cipher_type, NULL, NULL, NULL); -+ ctx_dec = EVP_CIPHER_CTX_new(); -+ EVP_CIPHER_CTX_init(ctx_dec); -+ EVP_DecryptInit_ex(ctx_dec, cipher_type, NULL, NULL, NULL); - if (var_key) -- EVP_CIPHER_CTX_set_key_length(&ctx_dec, keysize); -- EVP_DecryptInit_ex(&ctx_dec, NULL, NULL, pkey, NULL); -- EVP_DecryptInit_ex(&ctx_dec, NULL, NULL, NULL, iv); -- EVP_CIPHER_CTX_set_padding(&ctx_dec, 0); -+ EVP_CIPHER_CTX_set_key_length(ctx_dec, keysize); -+ EVP_DecryptInit_ex(ctx_dec, NULL, NULL, pkey, NULL); -+ EVP_DecryptInit_ex(ctx_dec, NULL, NULL, NULL, iv); -+ EVP_CIPHER_CTX_set_padding(ctx_dec, 0); - if (dec_init_first_time) - { - sprintf(tmpstr,"%s decryption initialized", cipher_name); - vtun_syslog(LOG_INFO, tmpstr); - dec_init_first_time = 0; -@@ -557,11 +561,11 @@ - memset(iv,0,blocksize); free(iv); iv = NULL; - RAND_bytes(in_ptr, in - in_ptr); - - in_ptr = in - blocksize*2; - outlen = blocksize*2; -- EVP_EncryptUpdate(&ctx_enc_ecb, in_ptr, -+ EVP_EncryptUpdate(ctx_enc_ecb, in_ptr, - &outlen, in_ptr, blocksize*2); - *out = in_ptr; - len = outlen; - cipher_enc_state = CIPHER_SEQUENCE; - break; -@@ -584,11 +588,11 @@ - { - case CIPHER_INIT: - in_ptr = in; - iv = malloc(blocksize); - outlen = blocksize*2; -- EVP_DecryptUpdate(&ctx_dec_ecb, in_ptr, &outlen, in_ptr, blocksize*2); -+ EVP_DecryptUpdate(ctx_dec_ecb, in_ptr, &outlen, in_ptr, blocksize*2); - - if ( !strncmp(in_ptr, "ivec", 4) ) - { - memcpy(iv, in_ptr+4, blocksize); - cipher_dec_init(iv); -@@ -627,11 +631,11 @@ - "Max. gibberish threshold reached"); - #endif - if (cipher_enc_state != CIPHER_INIT) - { - cipher_enc_state = CIPHER_INIT; -- EVP_CIPHER_CTX_cleanup(&ctx_enc); -+ EVP_CIPHER_CTX_free(ctx_enc); - #ifdef LFD_ENCRYPT_DEBUG - vtun_syslog(LOG_INFO, - "Forcing local encryptor re-init"); - #endif - } -@@ -708,11 +712,11 @@ - *len -= blocksize; - - if (cipher_enc_state != CIPHER_INIT) - { - cipher_enc_state = CIPHER_INIT; -- EVP_CIPHER_CTX_cleanup(&ctx_enc); -+ EVP_CIPHER_CTX_free(ctx_enc); - } - #ifdef LFD_ENCRYPT_DEBUG - vtun_syslog(LOG_INFO, "Remote requests encryptor re-init"); - #endif - } -@@ -722,11 +726,11 @@ - - if (cipher_dec_state != CIPHER_INIT && - cipher_enc_state != CIPHER_REQ_INIT && - cipher_enc_state != CIPHER_INIT) - { -- EVP_CIPHER_CTX_cleanup (&ctx_dec); -+ EVP_CIPHER_CTX_free (ctx_dec); - cipher_dec_state = CIPHER_INIT; - cipher_enc_state = CIPHER_REQ_INIT; - } - #ifdef LFD_ENCRYPT_DEBUG - vtun_syslog(LOG_INFO, "Local decryptor out of sync"); diff --git a/vtun.spec b/vtun.spec index dd77184..8c642de 100644 --- a/vtun.spec +++ b/vtun.spec @@ -1,6 +1,6 @@ Name: vtun Version: 3.0.4 -Release: 4%{?dist} +Release: 5%{?dist} Summary: Virtual tunnel over TCP/IP networks License: GPLv2+ Group: System Environment/Daemons @@ -10,12 +10,16 @@ Source1: vtun.socket Source2: vtun.service Source3: vtun.sysconfig Patch0: vtun-nostrip.patch -Patch1: vtun-openssl.patch Requires(post): systemd-units Requires(preun): systemd-units Requires(postun): systemd-units -BuildRequires: zlib-devel lzo-devel openssl-devel bison flex systemd-units autoconf +BuildRequires: zlib-devel lzo-devel bison flex systemd-units autoconf +%if 0%{?fedora} >= 26 +BuildRequires: compat-openssl10-devel +%else +BuildRequires: openssl-devel +%endif #enable PIE/PIC: %global _hardened_build 1 @@ -33,9 +37,6 @@ require modification to any kernel parts. %prep %setup -q %patch0 -p1 -%if 0%{?fedora} >= 26 -%patch1 -p1 -%endif %build %{__autoconf} @@ -81,6 +82,9 @@ EOT %{_mandir}/man8/vtund.8* %changelog +* Sat Sep 02 2017 Gabriel Somlo 3.0.3-5 +- remove segfaulting openssl-1.1 patch; use compat-openssl10 instead + * Sat Sep 02 2017 Gabriel Somlo 3.0.3-4 - apply openssl-1.1 patch only on Fedora >= 26, to avoid epel7 (#1487003)