diff --git a/org.wicd.daemon.service b/org.wicd.daemon.service new file mode 100644 index 0000000..b0287f3 --- /dev/null +++ b/org.wicd.daemon.service @@ -0,0 +1,11 @@ +# This D-Bus service activation file is only for systemd support since +# an auto-activated wicd would be quite surprising for those people +# who have wicd installed but turned off. Thus the Exec path available to +# D-Bus is /bin/false, but systemd knows the real Exec path due to the +# wicd systemd .service file. + +[D-BUS Service] +Name=org.wicd.daemon +Exec=/bin/false +User=root +SystemdService=dbus-org.wicd.daemon.service diff --git a/wicd-1.7.0-CVE-2012-0813.patch b/wicd-1.7.0-CVE-2012-0813.patch new file mode 100644 index 0000000..2c84e0e --- /dev/null +++ b/wicd-1.7.0-CVE-2012-0813.patch @@ -0,0 +1,19 @@ +diff -up wicd-1.7.0/wicd/configmanager.py.CVE-2012-0813 wicd-1.7.0/wicd/configmanager.py +--- wicd-1.7.0/wicd/configmanager.py.CVE-2012-0813 2012-01-27 14:34:12.779219466 -0500 ++++ wicd-1.7.0/wicd/configmanager.py 2012-01-27 14:34:33.534091679 -0500 +@@ -97,8 +97,13 @@ class ConfigManager(RawConfigParser): + ret = ret[3:-3] + if default: + if self.debug: +- print ''.join(['found ', option, ' in configuration ', +- str(ret)]) ++ # mask out sensitive information ++ if option in ['apsk', 'password', 'identity', 'private_key', \ ++ 'private_key_passwd', 'key', 'passphrase']: ++ print ''.join(['found ', option, ' in configuration *****']) ++ else: ++ print ''.join(['found ', option, ' in configuration ', ++ str(ret)]) + else: + if default != "__None__": + print 'did not find %s in configuration, setting default %s' % (option, str(default)) diff --git a/wicd-1.7.0-CVE-2012-2095.patch b/wicd-1.7.0-CVE-2012-2095.patch new file mode 100644 index 0000000..da6a4b3 --- /dev/null +++ b/wicd-1.7.0-CVE-2012-2095.patch @@ -0,0 +1,91 @@ +diff -up wicd-1.7.0/wicd/wicd-daemon.py.CVE-2012-2095 wicd-1.7.0/wicd/wicd-daemon.py +--- wicd-1.7.0/wicd/wicd-daemon.py.CVE-2012-2095 2012-04-13 10:17:46.356047035 -0400 ++++ wicd-1.7.0/wicd/wicd-daemon.py 2012-04-13 10:18:35.018046979 -0400 +@@ -978,6 +978,28 @@ class WirelessDaemon(dbus.service.Object + "wireless-settings.conf"), + debug=debug) + ++ self._validProperties = ( ++ 'bssid', ++ 'essid', ++ 'hidden', ++ 'channel', ++ 'mode', ++ 'enctype', ++ 'encryption_method', ++ 'key', ++ 'automatic', ++ 'ip', ++ 'netmask', ++ 'broadcast', ++ 'gateway', ++ 'use_static_dns', ++ 'use_global_dns', ++ 'dns1', ++ 'dns2', ++ 'dns3', ++ 'use_settings_globally', ++ ) ++ + def get_debug_mode(self): + return self._debug_mode + def set_debug_mode(self, mode): +@@ -1086,9 +1108,9 @@ class WirelessDaemon(dbus.service.Object + def SetWirelessProperty(self, netid, prop, value): + """ Sets property to value in network specified. """ + # We don't write script settings here. +- if (prop.strip()).endswith("script"): +- print "Setting script properties through the daemon is not" \ +- + " permitted." ++ if prop.strip() not in self._validProperties: ++ print "Trying to set invalid property (or property not " \ ++ "permitted): "+ prop.strip() + "." + return False + self.LastScan[netid][prop] = misc.to_unicode(misc.Noneify(value)) + +@@ -1365,6 +1387,25 @@ class WiredDaemon(dbus.service.Object): + "wired-settings.conf"), + debug=debug) + ++ self._validProperties = ( ++ 'ip', ++ 'broadcast', ++ 'netmask', ++ 'gateway', ++ 'search_domain', ++ 'dns_domain', ++ 'dns1', ++ 'dns2', ++ 'dns3', ++ 'encryption_enabled', ++ 'default', ++ 'dhcphostname', ++ 'lastused', ++ 'profilename', ++ 'use_global_dns', ++ 'use_static_dns', ++ ) ++ + def get_debug_mode(self): + return self._debug_mode + def set_debug_mode(self, mode): +@@ -1405,14 +1446,14 @@ class WiredDaemon(dbus.service.Object): + return str(iface) + + @dbus.service.method('org.wicd.daemon.wired') +- def SetWiredProperty(self, property, value): ++ def SetWiredProperty(self, prop, value): + """ Sets the given property to the given value. """ + if self.WiredNetwork: +- if (property.strip()).endswith("script"): +- print "Setting script properties through the daemon" \ +- + " is not permitted." ++ if prop.strip() not in self._validProperties: ++ print "Trying to set invalid property (or property not " \ ++ "permitted): "+ prop.strip() + "." + return False +- self.WiredNetwork[property] = misc.to_unicode(misc.Noneify(value)) ++ self.WiredNetwork[prop] = misc.to_unicode(misc.Noneify(value)) + return True + else: + print 'SetWiredProperty: WiredNetwork does not exist' diff --git a/wicd-1.7.0-bz740256.patch b/wicd-1.7.0-bz740256.patch new file mode 100644 index 0000000..18b625a --- /dev/null +++ b/wicd-1.7.0-bz740256.patch @@ -0,0 +1,34 @@ +diff -up wicd-1.7.0/gtk/guiutil.py.orig wicd-1.7.0/gtk/guiutil.py +--- wicd-1.7.0/gtk/guiutil.py.orig 2010-01-14 23:49:11.000000000 -0500 ++++ wicd-1.7.0/gtk/guiutil.py 2012-04-25 11:40:30.747191654 -0400 +@@ -106,13 +106,12 @@ def string_input(prompt, secondary, text + dialog.vbox.pack_end(hbox, True, True, 0) + dialog.show_all() + ++ text = '' + if dialog.run() == gtk.RESPONSE_OK: +- text = entry.get_text() +- dialog.destroy() +- return text +- else: +- dialog.destroy() +- return None ++ text = entry.get_text().strip() ++ ++ dialog.destroy() ++ return text + + class SmallLabel(gtk.Label): + def __init__(self, text=''): +diff -up wicd-1.7.0/gtk/netentry.py.orig wicd-1.7.0/gtk/netentry.py +--- wicd-1.7.0/gtk/netentry.py.orig 2010-01-14 23:49:11.000000000 -0500 ++++ wicd-1.7.0/gtk/netentry.py 2012-04-25 11:41:06.364192922 -0400 +@@ -725,7 +725,7 @@ class WiredNetworkEntry(NetworkEntry): + "will not be used by the computer. It " + + "allows you to " + + "easily distinguish between different network " + +- "profiles.", "Profile name:").strip() ++ "profiles.", "Profile name:") + + # if response is "" or None + if not response: diff --git a/wicd-1.7.0-dbus-failure.patch b/wicd-1.7.0-dbus-failure.patch new file mode 100644 index 0000000..3d2eacf --- /dev/null +++ b/wicd-1.7.0-dbus-failure.patch @@ -0,0 +1,50 @@ +diff -up wicd-1.7.0/cli/wicd-cli.py.orig wicd-1.7.0/cli/wicd-cli.py +--- wicd-1.7.0/cli/wicd-cli.py.orig 2010-01-14 23:49:11.000000000 -0500 ++++ wicd-1.7.0/cli/wicd-cli.py 2011-08-05 11:09:57.561058338 -0400 +@@ -43,6 +43,10 @@ except dbus.DBusException: + print 'Error: Could not connect to the daemon. Please make sure it is running.' + sys.exit(3) + ++if daemon is None: ++ print 'Error connecting to wicd via D-Bus. Please make sure the wicd service is running.' ++ sys.exit(3) ++ + parser = optparse.OptionParser() + + parser.add_option('--network', '-n', type='int', default=-1) +diff -up wicd-1.7.0/curses/wicd-curses.py.orig wicd-1.7.0/curses/wicd-curses.py +--- wicd-1.7.0/curses/wicd-curses.py.orig 2010-01-14 23:49:11.000000000 -0500 ++++ wicd-1.7.0/curses/wicd-curses.py 2011-08-05 11:09:00.248056606 -0400 +@@ -1016,6 +1016,10 @@ def setup_dbus(force=True): + wireless = dbus_ifaces['wireless'] + wired = dbus_ifaces['wired'] + ++ if daemon is None: ++ print 'Error connecting to wicd via D-Bus. Please make sure the wicd service is running.' ++ sys.exit(3) ++ + netentry_curses.dbus_init(dbus_ifaces) + return True + +diff -up wicd-1.7.0/gtk/gui.py.orig wicd-1.7.0/gtk/gui.py +--- wicd-1.7.0/gtk/gui.py.orig 2010-01-14 23:49:11.000000000 -0500 ++++ wicd-1.7.0/gtk/gui.py 2011-08-05 10:49:08.392177338 -0400 +@@ -146,6 +146,17 @@ class appGui(object): + """ Initializes everything needed for the GUI. """ + setup_dbus() + ++ if daemon is None: ++ errmsg = "Error connecting to wicd service via D-Bus." + \ ++ "Please ensure the wicd service is running." ++ d = gtk.MessageDialog(parent=None, ++ flags=gtk.DIALOG_MODAL, ++ type=gtk.MESSAGE_ERROR, ++ buttons=gtk.BUTTONS_OK, ++ message_format=errmsg) ++ d.run() ++ sys.exit(1) ++ + self.tray = tray + + gladefile = os.path.join(wpath.gtk, "wicd.glade") +diff -up wicd-1.7.0/gtk/wicd-client.py.orig wicd-1.7.0/gtk/wicd-client.py diff --git a/wicd-1.7.0-dbus-policy.patch b/wicd-1.7.0-dbus-policy.patch new file mode 100644 index 0000000..9b722ec --- /dev/null +++ b/wicd-1.7.0-dbus-policy.patch @@ -0,0 +1,54 @@ +diff -up wicd-1.7.0/in/other=wicd.conf.in.orig wicd-1.7.0/in/other=wicd.conf.in +--- wicd-1.7.0/in/other=wicd.conf.in.orig 2010-01-14 23:49:11.000000000 -0500 ++++ wicd-1.7.0/in/other=wicd.conf.in 2011-08-11 16:57:20.818332542 -0400 +@@ -7,41 +7,24 @@ + + + +- +- +- +- ++ ++ ++ ++ + + + + + + +- +- +- +- +- +- +- +- +- +- + + + +- +- +- +- +- ++ ++ ++ ++ ++ + + + diff --git a/wicd-1.7.0-error-messages.patch b/wicd-1.7.0-error-messages.patch new file mode 100644 index 0000000..1de0cc8 --- /dev/null +++ b/wicd-1.7.0-error-messages.patch @@ -0,0 +1,27 @@ +diff -up wicd-1.7.0/curses/wicd-curses.py.orig wicd-1.7.0/curses/wicd-curses.py +--- wicd-1.7.0/curses/wicd-curses.py.orig 2011-08-11 17:01:29.969340068 -0400 ++++ wicd-1.7.0/curses/wicd-curses.py 2011-08-11 17:01:30.159340092 -0400 +@@ -1033,7 +1033,7 @@ if __name__ == '__main__': + parser = OptionParser(version="wicd-curses-%s (using wicd %s)" % (CURSES_REV,daemon.Hello())) + except Exception, e: + if "DBus.Error.AccessDenied" in e.get_dbus_name(): +- print language['access_denied_wc'].replace('$A','\033[1;34m'+wpath.wicd_group+'\033[0m') ++ print language['access_denied_wc'] + sys.exit(1) + else: + raise +diff -up wicd-1.7.0/wicd/translations.py.orig wicd-1.7.0/wicd/translations.py +--- wicd-1.7.0/wicd/translations.py.orig 2010-01-14 23:49:23.000000000 -0500 ++++ wicd-1.7.0/wicd/translations.py 2011-08-11 17:01:30.179340042 -0400 +@@ -214,9 +214,9 @@ language['connection_established'] = _(' + language['disconnected'] = _('''Disconnected''') + language['establishing_connection'] = _('''Establishing connection...''') + language['association_failed'] = _('''Connection failed: Could not contact the wireless access point.''') +-language['access_denied'] = _('''Unable to contact the Wicd daemon due to an access denied error from DBus. Please check that your user is in the $A group.''') ++language['access_denied'] = _('''Unable to contact the Wicd daemon due to an access denied error from DBus. Please check your D-Bus policy configuration.''') + language['disconnecting_active'] = _('''Disconnecting active connections...''') +-language['access_denied_wc'] = _('''ERROR: wicd-curses was denied access to the wicd daemon: please check that your user is in the "$A" group.''') ++language['access_denied_wc'] = _('''ERROR: wicd-curses was denied access to the wicd daemon: please check your D-Bus policy configuration.''') + language['post_disconnect_script'] = _('''Run post-disconnect script''') + language['resume_script'] = _('''Resume script''') + language['suspend_script'] = _('''Suspend script''') diff --git a/wicd-1.7.0-initialize-check-and-message.patch b/wicd-1.7.0-initialize-check-and-message.patch new file mode 100644 index 0000000..323e549 --- /dev/null +++ b/wicd-1.7.0-initialize-check-and-message.patch @@ -0,0 +1,13 @@ +diff -up wicd-1.7.0/cli/wicd-cli.py.orig wicd-1.7.0/cli/wicd-cli.py +--- wicd-1.7.0/cli/wicd-cli.py.orig 2011-08-19 15:24:57.413159478 -0400 ++++ wicd-1.7.0/cli/wicd-cli.py 2011-08-19 15:31:49.790055545 -0400 +@@ -195,6 +195,9 @@ if options.connect: + + check = lambda: wired.CheckIfWiredConnecting() + message = lambda: wired.CheckWiredConnectingMessage() ++ else: ++ check = lambda: False ++ message = lambda: False + + # update user on what the daemon is doing + last = None diff --git a/wicd-1.7.0-wired_showing.patch b/wicd-1.7.0-wired_showing.patch new file mode 100644 index 0000000..275e4f3 --- /dev/null +++ b/wicd-1.7.0-wired_showing.patch @@ -0,0 +1,11 @@ +diff -up wicd-1.7.0/gtk/gui.py.orig wicd-1.7.0/gtk/gui.py +--- wicd-1.7.0/gtk/gui.py.orig 2011-08-19 14:53:37.667180427 -0400 ++++ wicd-1.7.0/gtk/gui.py 2011-08-19 14:55:43.657056952 -0400 +@@ -220,6 +220,7 @@ class appGui(object): + self.refreshing = False + self.prev_state = None + self.update_cb = None ++ self._wired_showing = False + self.network_list.set_sensitive(False) + label = gtk.Label("%s..." % language['scanning']) + self.network_list.pack_start(label) diff --git a/wicd.service b/wicd.service index f30fc3a..68d2437 100644 --- a/wicd.service +++ b/wicd.service @@ -1,11 +1,15 @@ [Unit] Description=Wicd a wireless and wired network manager for Linux After=syslog.target +Wants=network.target +Before=network.target +Conflicts=NetworkManager.service [Service] -Type=forking -ExecStart=/usr/sbin/wicd -ExecStop=/usr/sbin/wicd -k +Type=dbus +BusName=org.wicd.daemon +ExecStart=/usr/sbin/wicd --no-daemon [Install] WantedBy=multi-user.target +Alias=dbus-org.wicd.daemon.service diff --git a/wicd.spec b/wicd.spec index 457462c..c099d70 100644 --- a/wicd.spec +++ b/wicd.spec @@ -9,7 +9,7 @@ Name: wicd Version: 1.7.0 -Release: 8%{?dist} +Release: 13%{?dist} Summary: Wireless and wired network connection manager Group: System Environment/Base @@ -18,8 +18,18 @@ URL: http://wicd.sourceforge.net/ Source0: http://downloads.sourceforge.net/%{name}/%{name}-%{version}.tar.bz2 Source1: wicd.logrotate Source2: wicd.service +Source3: org.wicd.daemon.service + Patch0: wicd-1.7.0-remove-WHEREAREMYFILES.patch Patch1: wicd-1.7.0-deepcopy.patch +Patch2: wicd-1.7.0-dbus-failure.patch +Patch3: wicd-1.7.0-error-messages.patch +Patch4: wicd-1.7.0-dbus-policy.patch +Patch5: wicd-1.7.0-wired_showing.patch +Patch6: wicd-1.7.0-initialize-check-and-message.patch +Patch7: wicd-1.7.0-CVE-2012-0813.patch +Patch8: wicd-1.7.0-CVE-2012-2095.patch +Patch9: wicd-1.7.0-bz740256.patch BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(id -u -n) BuildRequires: python2-devel @@ -90,6 +100,34 @@ Client program for wicd that uses a GTK+ interface. # Use cPickle instead of deepcopy in configmanager.py %patch1 -p1 +# Handle D-Bus connection failures a little better +%patch2 -p1 + +# Direct users to D-Bus policy configuration on connection failure +%patch3 -p1 + +# Allow users at the console to control wicd +%patch4 -p1 + +# Initialize appGui._wired_showing in __init__ +%patch5 -p1 + +# Make sure check and message are always a lambda +%patch6 -p1 + +# Fix CVE-2012-0813 +# Patch based on upstream: +# http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/682 +%patch7 -p1 + +# Fix CVE-2012-2095 +# Patch based on upstream: +# http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/751 +%patch8 -p1 + +# Fix BZ #740256 +%patch9 -p1 + %build # NOTE: --etc is where dhclient.conf.template goes %{__python} setup.py configure \ @@ -136,6 +174,9 @@ install -m 0644 %{SOURCE1} %{buildroot}%{_sysconfdir}/logrotate.d/wicd mkdir -p %{buildroot}%{_systemd_unitdir} install -m 0644 %{SOURCE2} %{buildroot}%{_systemd_unitdir}/wicd.service +mkdir -p %{buildroot}%{_datadir}/dbus-1/system-services +install -m 0644 %{SOURCE3} %{buildroot}%{_datadir}/dbus-1/system-services/org.wicd.daemon.service + desktop-file-install \ --remove-category="Application" \ --delete-original \ @@ -190,11 +231,11 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || : %files %defattr(-,root,root,-) -%doc AUTHORS CHANGES LICENSE NEWS README other/WHEREAREMYFILES %{_libdir}/pm-utils/sleep.d/91wicd %files common -f %{name}.lang %defattr(-,root,root,-) +%doc AUTHORS CHANGES LICENSE NEWS README other/WHEREAREMYFILES %dir %{python_sitelib}/wicd %dir %{_sysconfdir}/wicd %dir %{_sysconfdir}/wicd/encryption @@ -228,6 +269,7 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || : %{_bindir}/wicd-client %{_sbindir}/wicd %{_datadir}/applications/wicd.desktop +%{_datadir}/dbus-1/system-services/org.wicd.daemon.service %{_datadir}/man/man1/wicd-client.1* %{_datadir}/man/man5/wicd-manager-settings.conf.5* %{_datadir}/man/man5/wicd-wired-settings.conf.5* @@ -270,6 +312,25 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || : %{_datadir}/icons/hicolor/scalable/apps/wicd-gtk.svg %changelog +* Wed Apr 25 2012 David Cantrell - 1.7.0-13 +- Fix 'guiutil.py:147:set_text:TypeError: Gtk.Entry.set_text() + argument 1 must be string, not dbus.Boolean' (#740256) + +* Fri Apr 13 2012 David Cantrell - 1.7.0-12 +- Fix CVE-2012-2095 (#811763) + +* Fri Jan 27 2012 David Cantrell - 1.7.0-11 +- Fix CVE-2012-0813 (#785147) + +* Fri Aug 19 2011 David Cantrell - 1.7.0-10 +- Initialize appGui._wired_showing in __init__ (#723553) +- Make sure check and message in wicd-cli are a lambda (#712435) + +* Thu Aug 11 2011 David Cantrell - 1.7.0-9 +- Correct systemd unit file for wicd, add D-Bus service file (#699116) +- Move docs to the wicd-common subpackage +- Correct /etc/dbus-1/system.d/wicd.conf (#699116) + * Mon May 09 2011 Bill Nottingham - 1.7.0-8 - fix systemd scriptlets for upgrade