diff --git a/org.wicd.daemon.service b/org.wicd.daemon.service
new file mode 100644
index 0000000..b0287f3
--- /dev/null
+++ b/org.wicd.daemon.service
@@ -0,0 +1,11 @@
+# This D-Bus service activation file is only for systemd support since
+# an auto-activated wicd would be quite surprising for those people
+# who have wicd installed but turned off. Thus the Exec path available to
+# D-Bus is /bin/false, but systemd knows the real Exec path due to the
+# wicd systemd .service file.
+
+[D-BUS Service]
+Name=org.wicd.daemon
+Exec=/bin/false
+User=root
+SystemdService=dbus-org.wicd.daemon.service
diff --git a/wicd-1.7.0-CVE-2012-0813.patch b/wicd-1.7.0-CVE-2012-0813.patch
new file mode 100644
index 0000000..2c84e0e
--- /dev/null
+++ b/wicd-1.7.0-CVE-2012-0813.patch
@@ -0,0 +1,19 @@
+diff -up wicd-1.7.0/wicd/configmanager.py.CVE-2012-0813 wicd-1.7.0/wicd/configmanager.py
+--- wicd-1.7.0/wicd/configmanager.py.CVE-2012-0813 2012-01-27 14:34:12.779219466 -0500
++++ wicd-1.7.0/wicd/configmanager.py 2012-01-27 14:34:33.534091679 -0500
+@@ -97,8 +97,13 @@ class ConfigManager(RawConfigParser):
+ ret = ret[3:-3]
+ if default:
+ if self.debug:
+- print ''.join(['found ', option, ' in configuration ',
+- str(ret)])
++ # mask out sensitive information
++ if option in ['apsk', 'password', 'identity', 'private_key', \
++ 'private_key_passwd', 'key', 'passphrase']:
++ print ''.join(['found ', option, ' in configuration *****'])
++ else:
++ print ''.join(['found ', option, ' in configuration ',
++ str(ret)])
+ else:
+ if default != "__None__":
+ print 'did not find %s in configuration, setting default %s' % (option, str(default))
diff --git a/wicd-1.7.0-CVE-2012-2095.patch b/wicd-1.7.0-CVE-2012-2095.patch
new file mode 100644
index 0000000..da6a4b3
--- /dev/null
+++ b/wicd-1.7.0-CVE-2012-2095.patch
@@ -0,0 +1,91 @@
+diff -up wicd-1.7.0/wicd/wicd-daemon.py.CVE-2012-2095 wicd-1.7.0/wicd/wicd-daemon.py
+--- wicd-1.7.0/wicd/wicd-daemon.py.CVE-2012-2095 2012-04-13 10:17:46.356047035 -0400
++++ wicd-1.7.0/wicd/wicd-daemon.py 2012-04-13 10:18:35.018046979 -0400
+@@ -978,6 +978,28 @@ class WirelessDaemon(dbus.service.Object
+ "wireless-settings.conf"),
+ debug=debug)
+
++ self._validProperties = (
++ 'bssid',
++ 'essid',
++ 'hidden',
++ 'channel',
++ 'mode',
++ 'enctype',
++ 'encryption_method',
++ 'key',
++ 'automatic',
++ 'ip',
++ 'netmask',
++ 'broadcast',
++ 'gateway',
++ 'use_static_dns',
++ 'use_global_dns',
++ 'dns1',
++ 'dns2',
++ 'dns3',
++ 'use_settings_globally',
++ )
++
+ def get_debug_mode(self):
+ return self._debug_mode
+ def set_debug_mode(self, mode):
+@@ -1086,9 +1108,9 @@ class WirelessDaemon(dbus.service.Object
+ def SetWirelessProperty(self, netid, prop, value):
+ """ Sets property to value in network specified. """
+ # We don't write script settings here.
+- if (prop.strip()).endswith("script"):
+- print "Setting script properties through the daemon is not" \
+- + " permitted."
++ if prop.strip() not in self._validProperties:
++ print "Trying to set invalid property (or property not " \
++ "permitted): "+ prop.strip() + "."
+ return False
+ self.LastScan[netid][prop] = misc.to_unicode(misc.Noneify(value))
+
+@@ -1365,6 +1387,25 @@ class WiredDaemon(dbus.service.Object):
+ "wired-settings.conf"),
+ debug=debug)
+
++ self._validProperties = (
++ 'ip',
++ 'broadcast',
++ 'netmask',
++ 'gateway',
++ 'search_domain',
++ 'dns_domain',
++ 'dns1',
++ 'dns2',
++ 'dns3',
++ 'encryption_enabled',
++ 'default',
++ 'dhcphostname',
++ 'lastused',
++ 'profilename',
++ 'use_global_dns',
++ 'use_static_dns',
++ )
++
+ def get_debug_mode(self):
+ return self._debug_mode
+ def set_debug_mode(self, mode):
+@@ -1405,14 +1446,14 @@ class WiredDaemon(dbus.service.Object):
+ return str(iface)
+
+ @dbus.service.method('org.wicd.daemon.wired')
+- def SetWiredProperty(self, property, value):
++ def SetWiredProperty(self, prop, value):
+ """ Sets the given property to the given value. """
+ if self.WiredNetwork:
+- if (property.strip()).endswith("script"):
+- print "Setting script properties through the daemon" \
+- + " is not permitted."
++ if prop.strip() not in self._validProperties:
++ print "Trying to set invalid property (or property not " \
++ "permitted): "+ prop.strip() + "."
+ return False
+- self.WiredNetwork[property] = misc.to_unicode(misc.Noneify(value))
++ self.WiredNetwork[prop] = misc.to_unicode(misc.Noneify(value))
+ return True
+ else:
+ print 'SetWiredProperty: WiredNetwork does not exist'
diff --git a/wicd-1.7.0-bz740256.patch b/wicd-1.7.0-bz740256.patch
new file mode 100644
index 0000000..18b625a
--- /dev/null
+++ b/wicd-1.7.0-bz740256.patch
@@ -0,0 +1,34 @@
+diff -up wicd-1.7.0/gtk/guiutil.py.orig wicd-1.7.0/gtk/guiutil.py
+--- wicd-1.7.0/gtk/guiutil.py.orig 2010-01-14 23:49:11.000000000 -0500
++++ wicd-1.7.0/gtk/guiutil.py 2012-04-25 11:40:30.747191654 -0400
+@@ -106,13 +106,12 @@ def string_input(prompt, secondary, text
+ dialog.vbox.pack_end(hbox, True, True, 0)
+ dialog.show_all()
+
++ text = ''
+ if dialog.run() == gtk.RESPONSE_OK:
+- text = entry.get_text()
+- dialog.destroy()
+- return text
+- else:
+- dialog.destroy()
+- return None
++ text = entry.get_text().strip()
++
++ dialog.destroy()
++ return text
+
+ class SmallLabel(gtk.Label):
+ def __init__(self, text=''):
+diff -up wicd-1.7.0/gtk/netentry.py.orig wicd-1.7.0/gtk/netentry.py
+--- wicd-1.7.0/gtk/netentry.py.orig 2010-01-14 23:49:11.000000000 -0500
++++ wicd-1.7.0/gtk/netentry.py 2012-04-25 11:41:06.364192922 -0400
+@@ -725,7 +725,7 @@ class WiredNetworkEntry(NetworkEntry):
+ "will not be used by the computer. It " +
+ "allows you to " +
+ "easily distinguish between different network " +
+- "profiles.", "Profile name:").strip()
++ "profiles.", "Profile name:")
+
+ # if response is "" or None
+ if not response:
diff --git a/wicd-1.7.0-dbus-failure.patch b/wicd-1.7.0-dbus-failure.patch
new file mode 100644
index 0000000..3d2eacf
--- /dev/null
+++ b/wicd-1.7.0-dbus-failure.patch
@@ -0,0 +1,50 @@
+diff -up wicd-1.7.0/cli/wicd-cli.py.orig wicd-1.7.0/cli/wicd-cli.py
+--- wicd-1.7.0/cli/wicd-cli.py.orig 2010-01-14 23:49:11.000000000 -0500
++++ wicd-1.7.0/cli/wicd-cli.py 2011-08-05 11:09:57.561058338 -0400
+@@ -43,6 +43,10 @@ except dbus.DBusException:
+ print 'Error: Could not connect to the daemon. Please make sure it is running.'
+ sys.exit(3)
+
++if daemon is None:
++ print 'Error connecting to wicd via D-Bus. Please make sure the wicd service is running.'
++ sys.exit(3)
++
+ parser = optparse.OptionParser()
+
+ parser.add_option('--network', '-n', type='int', default=-1)
+diff -up wicd-1.7.0/curses/wicd-curses.py.orig wicd-1.7.0/curses/wicd-curses.py
+--- wicd-1.7.0/curses/wicd-curses.py.orig 2010-01-14 23:49:11.000000000 -0500
++++ wicd-1.7.0/curses/wicd-curses.py 2011-08-05 11:09:00.248056606 -0400
+@@ -1016,6 +1016,10 @@ def setup_dbus(force=True):
+ wireless = dbus_ifaces['wireless']
+ wired = dbus_ifaces['wired']
+
++ if daemon is None:
++ print 'Error connecting to wicd via D-Bus. Please make sure the wicd service is running.'
++ sys.exit(3)
++
+ netentry_curses.dbus_init(dbus_ifaces)
+ return True
+
+diff -up wicd-1.7.0/gtk/gui.py.orig wicd-1.7.0/gtk/gui.py
+--- wicd-1.7.0/gtk/gui.py.orig 2010-01-14 23:49:11.000000000 -0500
++++ wicd-1.7.0/gtk/gui.py 2011-08-05 10:49:08.392177338 -0400
+@@ -146,6 +146,17 @@ class appGui(object):
+ """ Initializes everything needed for the GUI. """
+ setup_dbus()
+
++ if daemon is None:
++ errmsg = "Error connecting to wicd service via D-Bus." + \
++ "Please ensure the wicd service is running."
++ d = gtk.MessageDialog(parent=None,
++ flags=gtk.DIALOG_MODAL,
++ type=gtk.MESSAGE_ERROR,
++ buttons=gtk.BUTTONS_OK,
++ message_format=errmsg)
++ d.run()
++ sys.exit(1)
++
+ self.tray = tray
+
+ gladefile = os.path.join(wpath.gtk, "wicd.glade")
+diff -up wicd-1.7.0/gtk/wicd-client.py.orig wicd-1.7.0/gtk/wicd-client.py
diff --git a/wicd-1.7.0-dbus-policy.patch b/wicd-1.7.0-dbus-policy.patch
new file mode 100644
index 0000000..9b722ec
--- /dev/null
+++ b/wicd-1.7.0-dbus-policy.patch
@@ -0,0 +1,54 @@
+diff -up wicd-1.7.0/in/other=wicd.conf.in.orig wicd-1.7.0/in/other=wicd.conf.in
+--- wicd-1.7.0/in/other=wicd.conf.in.orig 2010-01-14 23:49:11.000000000 -0500
++++ wicd-1.7.0/in/other=wicd.conf.in 2011-08-11 16:57:20.818332542 -0400
+@@ -7,41 +7,24 @@
+
+
+
+-
+-
+-
+-
++
++
++
++
+
+
+
+
+
+
+-
+-
+-
+-
+-
+-
+-
+-
+-
+-
+
+
+
+-
+-
+-
+-
+-
++
++
++
++
++
+
+
+
diff --git a/wicd-1.7.0-error-messages.patch b/wicd-1.7.0-error-messages.patch
new file mode 100644
index 0000000..1de0cc8
--- /dev/null
+++ b/wicd-1.7.0-error-messages.patch
@@ -0,0 +1,27 @@
+diff -up wicd-1.7.0/curses/wicd-curses.py.orig wicd-1.7.0/curses/wicd-curses.py
+--- wicd-1.7.0/curses/wicd-curses.py.orig 2011-08-11 17:01:29.969340068 -0400
++++ wicd-1.7.0/curses/wicd-curses.py 2011-08-11 17:01:30.159340092 -0400
+@@ -1033,7 +1033,7 @@ if __name__ == '__main__':
+ parser = OptionParser(version="wicd-curses-%s (using wicd %s)" % (CURSES_REV,daemon.Hello()))
+ except Exception, e:
+ if "DBus.Error.AccessDenied" in e.get_dbus_name():
+- print language['access_denied_wc'].replace('$A','\033[1;34m'+wpath.wicd_group+'\033[0m')
++ print language['access_denied_wc']
+ sys.exit(1)
+ else:
+ raise
+diff -up wicd-1.7.0/wicd/translations.py.orig wicd-1.7.0/wicd/translations.py
+--- wicd-1.7.0/wicd/translations.py.orig 2010-01-14 23:49:23.000000000 -0500
++++ wicd-1.7.0/wicd/translations.py 2011-08-11 17:01:30.179340042 -0400
+@@ -214,9 +214,9 @@ language['connection_established'] = _('
+ language['disconnected'] = _('''Disconnected''')
+ language['establishing_connection'] = _('''Establishing connection...''')
+ language['association_failed'] = _('''Connection failed: Could not contact the wireless access point.''')
+-language['access_denied'] = _('''Unable to contact the Wicd daemon due to an access denied error from DBus. Please check that your user is in the $A group.''')
++language['access_denied'] = _('''Unable to contact the Wicd daemon due to an access denied error from DBus. Please check your D-Bus policy configuration.''')
+ language['disconnecting_active'] = _('''Disconnecting active connections...''')
+-language['access_denied_wc'] = _('''ERROR: wicd-curses was denied access to the wicd daemon: please check that your user is in the "$A" group.''')
++language['access_denied_wc'] = _('''ERROR: wicd-curses was denied access to the wicd daemon: please check your D-Bus policy configuration.''')
+ language['post_disconnect_script'] = _('''Run post-disconnect script''')
+ language['resume_script'] = _('''Resume script''')
+ language['suspend_script'] = _('''Suspend script''')
diff --git a/wicd-1.7.0-initialize-check-and-message.patch b/wicd-1.7.0-initialize-check-and-message.patch
new file mode 100644
index 0000000..323e549
--- /dev/null
+++ b/wicd-1.7.0-initialize-check-and-message.patch
@@ -0,0 +1,13 @@
+diff -up wicd-1.7.0/cli/wicd-cli.py.orig wicd-1.7.0/cli/wicd-cli.py
+--- wicd-1.7.0/cli/wicd-cli.py.orig 2011-08-19 15:24:57.413159478 -0400
++++ wicd-1.7.0/cli/wicd-cli.py 2011-08-19 15:31:49.790055545 -0400
+@@ -195,6 +195,9 @@ if options.connect:
+
+ check = lambda: wired.CheckIfWiredConnecting()
+ message = lambda: wired.CheckWiredConnectingMessage()
++ else:
++ check = lambda: False
++ message = lambda: False
+
+ # update user on what the daemon is doing
+ last = None
diff --git a/wicd-1.7.0-wired_showing.patch b/wicd-1.7.0-wired_showing.patch
new file mode 100644
index 0000000..275e4f3
--- /dev/null
+++ b/wicd-1.7.0-wired_showing.patch
@@ -0,0 +1,11 @@
+diff -up wicd-1.7.0/gtk/gui.py.orig wicd-1.7.0/gtk/gui.py
+--- wicd-1.7.0/gtk/gui.py.orig 2011-08-19 14:53:37.667180427 -0400
++++ wicd-1.7.0/gtk/gui.py 2011-08-19 14:55:43.657056952 -0400
+@@ -220,6 +220,7 @@ class appGui(object):
+ self.refreshing = False
+ self.prev_state = None
+ self.update_cb = None
++ self._wired_showing = False
+ self.network_list.set_sensitive(False)
+ label = gtk.Label("%s..." % language['scanning'])
+ self.network_list.pack_start(label)
diff --git a/wicd.service b/wicd.service
index f30fc3a..68d2437 100644
--- a/wicd.service
+++ b/wicd.service
@@ -1,11 +1,15 @@
[Unit]
Description=Wicd a wireless and wired network manager for Linux
After=syslog.target
+Wants=network.target
+Before=network.target
+Conflicts=NetworkManager.service
[Service]
-Type=forking
-ExecStart=/usr/sbin/wicd
-ExecStop=/usr/sbin/wicd -k
+Type=dbus
+BusName=org.wicd.daemon
+ExecStart=/usr/sbin/wicd --no-daemon
[Install]
WantedBy=multi-user.target
+Alias=dbus-org.wicd.daemon.service
diff --git a/wicd.spec b/wicd.spec
index 457462c..c099d70 100644
--- a/wicd.spec
+++ b/wicd.spec
@@ -9,7 +9,7 @@
Name: wicd
Version: 1.7.0
-Release: 8%{?dist}
+Release: 13%{?dist}
Summary: Wireless and wired network connection manager
Group: System Environment/Base
@@ -18,8 +18,18 @@ URL: http://wicd.sourceforge.net/
Source0: http://downloads.sourceforge.net/%{name}/%{name}-%{version}.tar.bz2
Source1: wicd.logrotate
Source2: wicd.service
+Source3: org.wicd.daemon.service
+
Patch0: wicd-1.7.0-remove-WHEREAREMYFILES.patch
Patch1: wicd-1.7.0-deepcopy.patch
+Patch2: wicd-1.7.0-dbus-failure.patch
+Patch3: wicd-1.7.0-error-messages.patch
+Patch4: wicd-1.7.0-dbus-policy.patch
+Patch5: wicd-1.7.0-wired_showing.patch
+Patch6: wicd-1.7.0-initialize-check-and-message.patch
+Patch7: wicd-1.7.0-CVE-2012-0813.patch
+Patch8: wicd-1.7.0-CVE-2012-2095.patch
+Patch9: wicd-1.7.0-bz740256.patch
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(id -u -n)
BuildRequires: python2-devel
@@ -90,6 +100,34 @@ Client program for wicd that uses a GTK+ interface.
# Use cPickle instead of deepcopy in configmanager.py
%patch1 -p1
+# Handle D-Bus connection failures a little better
+%patch2 -p1
+
+# Direct users to D-Bus policy configuration on connection failure
+%patch3 -p1
+
+# Allow users at the console to control wicd
+%patch4 -p1
+
+# Initialize appGui._wired_showing in __init__
+%patch5 -p1
+
+# Make sure check and message are always a lambda
+%patch6 -p1
+
+# Fix CVE-2012-0813
+# Patch based on upstream:
+# http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/682
+%patch7 -p1
+
+# Fix CVE-2012-2095
+# Patch based on upstream:
+# http://bazaar.launchpad.net/~wicd-devel/wicd/experimental/revision/751
+%patch8 -p1
+
+# Fix BZ #740256
+%patch9 -p1
+
%build
# NOTE: --etc is where dhclient.conf.template goes
%{__python} setup.py configure \
@@ -136,6 +174,9 @@ install -m 0644 %{SOURCE1} %{buildroot}%{_sysconfdir}/logrotate.d/wicd
mkdir -p %{buildroot}%{_systemd_unitdir}
install -m 0644 %{SOURCE2} %{buildroot}%{_systemd_unitdir}/wicd.service
+mkdir -p %{buildroot}%{_datadir}/dbus-1/system-services
+install -m 0644 %{SOURCE3} %{buildroot}%{_datadir}/dbus-1/system-services/org.wicd.daemon.service
+
desktop-file-install \
--remove-category="Application" \
--delete-original \
@@ -190,11 +231,11 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || :
%files
%defattr(-,root,root,-)
-%doc AUTHORS CHANGES LICENSE NEWS README other/WHEREAREMYFILES
%{_libdir}/pm-utils/sleep.d/91wicd
%files common -f %{name}.lang
%defattr(-,root,root,-)
+%doc AUTHORS CHANGES LICENSE NEWS README other/WHEREAREMYFILES
%dir %{python_sitelib}/wicd
%dir %{_sysconfdir}/wicd
%dir %{_sysconfdir}/wicd/encryption
@@ -228,6 +269,7 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || :
%{_bindir}/wicd-client
%{_sbindir}/wicd
%{_datadir}/applications/wicd.desktop
+%{_datadir}/dbus-1/system-services/org.wicd.daemon.service
%{_datadir}/man/man1/wicd-client.1*
%{_datadir}/man/man5/wicd-manager-settings.conf.5*
%{_datadir}/man/man5/wicd-wired-settings.conf.5*
@@ -270,6 +312,25 @@ gtk-update-icon-cache %{_datadir}/icons/hicolor &>/dev/null || :
%{_datadir}/icons/hicolor/scalable/apps/wicd-gtk.svg
%changelog
+* Wed Apr 25 2012 David Cantrell - 1.7.0-13
+- Fix 'guiutil.py:147:set_text:TypeError: Gtk.Entry.set_text()
+ argument 1 must be string, not dbus.Boolean' (#740256)
+
+* Fri Apr 13 2012 David Cantrell - 1.7.0-12
+- Fix CVE-2012-2095 (#811763)
+
+* Fri Jan 27 2012 David Cantrell - 1.7.0-11
+- Fix CVE-2012-0813 (#785147)
+
+* Fri Aug 19 2011 David Cantrell - 1.7.0-10
+- Initialize appGui._wired_showing in __init__ (#723553)
+- Make sure check and message in wicd-cli are a lambda (#712435)
+
+* Thu Aug 11 2011 David Cantrell - 1.7.0-9
+- Correct systemd unit file for wicd, add D-Bus service file (#699116)
+- Move docs to the wicd-common subpackage
+- Correct /etc/dbus-1/system.d/wicd.conf (#699116)
+
* Mon May 09 2011 Bill Nottingham - 1.7.0-8
- fix systemd scriptlets for upgrade