Compare commits

..

82 commits

Author SHA1 Message Date
Miro Hrončok
3fdca86988 Orphaned for 6+ weeks 2020-12-10 18:00:46 +01:00
Fedora Release Engineering
19d001a3d2 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-08-01 09:45:03 +00:00
Fedora Release Engineering
a87333fa2e - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-29 14:47:08 +00:00
Petr Lautrbach
a192cc0244 Remove deprecation warning about flask.h usage
flask.h has been deprecated for a long time and will be dropped completely from
the next SELinux userspace release.
2020-04-07 12:31:23 +02:00
Fedora Release Engineering
61bb1ddb16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-31 04:32:00 +00:00
Fedora Release Engineering
4e92b4d4d3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-07-27 04:16:13 +00:00
Peter Robinson
1183e1fae1 Own the xinetd.d config directory 2019-03-21 00:24:16 +00:00
Fedora Release Engineering
e9e47118fd - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-02-03 12:28:32 +00:00
57003fcd33 Remove obsolete Group tag
References: https://fedoraproject.org/wiki/Changes/Remove_Group_Tag
2019-01-28 20:24:55 +01:00
Fedora Release Engineering
1ce2df7c19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-07-14 09:20:35 +00:00
Igor Gnatenko
2d054054d6 add BuildRequires: gcc
Reference: https://fedoraproject.org/wiki/Changes/Remove_GCC_from_BuildRoot
2018-07-09 19:06:54 +02:00
Jan Synacek
2791b45cb0 fix xinetd infinite busy loop when datagram service has wait=yes (#1567239)
Resolves: #1567239
2018-06-05 10:08:54 +02:00
Jan Synacek
b1b78cba9f fix compilation, missing rpc headers (#1556550)
https://fedoraproject.org/wiki/Changes/SunRPCRemoval
2018-03-15 13:40:56 +01:00
Fedora Release Engineering
56be75c641 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-02-09 21:42:34 +00:00
Björn Esser
c96f805990
Rebuilt for switch to libxcrypt 2018-01-20 23:08:43 +01:00
Jan Synacek
3e8facaf86 remove build dependency on tcp_wrappers (#1518797) 2017-12-04 09:47:14 +01:00
58c8325db1 Remove old crufty coreutils requires
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2017-11-07 16:38:24 +01:00
Fedora Release Engineering
6f26ec9057 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild 2017-08-03 10:44:46 +00:00
Fedora Release Engineering
c53f29e0f2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild 2017-07-27 22:09:58 +00:00
Fedora Release Engineering
cbd04012d9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild 2017-02-11 17:54:05 +00:00
Fedora Release Engineering
1efe6840e8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild 2016-02-05 03:32:35 +00:00
Dennis Gilmore
d039cd1126 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild 2015-06-19 04:04:27 +00:00
6cd4261cfc - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild 2014-08-18 10:06:34 +00:00
Dennis Gilmore
af58233d58 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild 2014-06-08 00:56:52 -05:00
Jan Synacek
ad4bb86a1d add documentation reference to the service file 2014-02-24 15:08:57 +01:00
Jan Synacek
333ba8c787 drop sysconfig-related stuff 2014-02-24 15:06:51 +01:00
Jan Synacek
fa27fb3ef0 fix bad URL 2014-01-14 09:47:09 +01:00
Jan Synacek
07951ec3fc fixup of the previous patch
Don't show bogus messages about NAMEINARGS if the flag isn't there.

Related:  #1033528
Resolves: #1042652
2013-12-13 09:56:16 +01:00
Jan Synacek
d582efc717 xinetd segfaults when connecting to tcpmux service
Resolves: #1033528
2013-12-03 10:51:46 +01:00
Jan Synacek
59859d45af xinetd should not depend on NetworkManager-wait-online
From F20 onward, network.target automatically depends on
NetworkManager-wait-online if NetworkManager is enabled.

Resolves: #1002294
2013-10-04 08:27:31 +02:00
Jan Synacek
b7bfdb9d73 Honor user and group directives
Resolves: CVE-2013-4342
2013-10-03 08:45:27 +02:00
Dennis Gilmore
9e3440354e - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild 2013-08-04 03:19:52 -05:00
Jan Synacek
492bfbdc86 Use full path to server when checking selinux context
Resolves: #977873
2013-06-26 09:50:55 +02:00
Dennis Gilmore
2386b7c722 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild 2013-02-14 21:45:39 -06:00
Jan Synacek
575aba85b7 Change config files' permissions
Resolves: #853144
2012-09-03 10:33:17 +02:00
Jan Synacek
165251f091 Add systemd-rpm macros
Resolves: #850370
2012-08-22 10:56:50 +02:00
Jan Synacek
11b009e37c Replace the makeinstall macro 2012-08-22 10:25:15 +02:00
Dennis Gilmore
cf35130420 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild 2012-07-22 00:36:54 -05:00
Jan Synacek
63004d1702 Add -bad-port-check patch 2012-05-14 10:36:13 +02:00
Jan Synacek
620e84db8e Remove trailing spaces in spec 2012-05-14 10:01:44 +02:00
Jan Synacek
8b25de519c Update to 2.3.15
Drop patches merged by upstream
 (-log-crash, -tcp_rpc, -label, -contextconf, -ssize_t)
Update -pie, -PIE, -poll patch
Resolves: #820927
2012-05-14 09:57:03 +02:00
Jan Synacek
8335f46295 remove unnecessary patch after a faulty merge 2012-04-16 12:37:56 +02:00
Jan Synacek
82eddd5b4d Merge branch 'master' into f17, so they have the same history 2012-04-16 10:04:48 +02:00
Jan Synacek
8be953dc1f Fix: service file: avoid problems when name resolution is not ready
Resolves: #748931
2012-04-13 15:24:30 +02:00
Jan Synacek
49f479d3ff Fix: Service disabled due to bind failure
Update patch: xinetd-2.3.14-leaking-fds-2.patch
Resolves: #809272
2012-04-13 11:56:31 +02:00
Jan Synacek
5ae7170961 Fix: Instances limit in xinetd can be easily bypassed
Resolves: #770858
2012-03-06 10:29:03 +01:00
Jan Synacek
7b9af589de Implement reload in xinetd.service 2012-03-06 10:28:49 +01:00
Jan Synacek
d038b39414 Remove useless INSTALL from package documentation 2012-03-06 10:28:41 +01:00
Jan Synacek
23ddc9f8a3 Fix xinetd.service permissions 2012-03-06 10:28:32 +01:00
Jan Synacek
c789a7586f Fix: Instances limit in xinetd can be easily bypassed
Resolves: #770858
2012-03-05 15:03:46 +01:00
Jan Synacek
eced601a88 Implement reload in xinetd.service 2012-03-05 11:26:28 +01:00
Jan Synacek
49f62e47db Remove useless INSTALL from package documentation 2012-03-05 11:00:21 +01:00
Jan Synacek
ee9dff33c4 Fix xinetd.service permissions 2012-03-05 10:58:34 +01:00
Jan Synacek
f1cc4e9d32 Fix leaking descriptor when starting a service fails (#795188) 2012-03-02 09:39:26 +01:00
Jan Synacek
41152253b1 Fix leaking descriptor when starting a service fails (#795188) 2012-03-02 09:27:04 +01:00
Jan Synacek
84f1870618 Remove realloc inside svc_activate that was causing memory corruption
Number of alloc'd file descriptors is now determined by system limits (ulimit -n)
Add patch -realloc-remove
2012-01-18 14:41:53 +01:00
Jan Synacek
7de7f60c17 Fix memory corruption when loading a large number of services (#720390) 2012-01-17 09:51:04 +01:00
Jan Synacek
188e1584f7 Fix previous specfile changelog mistake 2012-01-16 12:03:10 +01:00
Jan Synacek
c92212b826 Fix leaking file descriptors (#702670) 2012-01-16 08:36:22 +01:00
Dennis Gilmore
e4eaa39d98 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild 2012-01-14 02:58:40 -06:00
Tom "spot" Callaway
0ed034f7e8 convert to systemd 2011-09-12 09:49:00 -04:00
Vojtech Vitek (V-Teq)
05d81c0613 Release build 2:2.3.14-36 2011-04-21 15:26:15 +02:00
Vojtech Vitek (V-Teq)
f48798436d - Fix build warning about "dereferencing type-punned pointer"
- Avoid possible hang while logging an unexpected signal
- Let RPC services bind to a specific port
2011-04-21 15:25:09 +02:00
Vojtech Vitek (V-Teq)
7888d11c91 Release build 2:2.3.14-35 2011-02-18 15:04:26 +01:00
Vojtech Vitek (V-Teq)
19197c2db5 - fix crash when application's logfile hit size limit
Related: #244063
2011-02-18 15:03:06 +01:00
Vojtech Vitek (V-Teq)
10720bbfa3 Add note about -pie -PIE patches to %build configure section 2011-02-18 14:29:06 +01:00
Vojtech Vitek (V-Teq)
66e1c3bfce Release build 2:2.3.14-34 2011-02-14 16:15:17 +01:00
Vojtech Vitek (V-Teq)
06f78f0c08 - Add -Wl,-z,relro,-z,now to LDFLAGS 2011-02-14 16:14:10 +01:00
Dennis Gilmore
78135a135a - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild 2011-02-07 23:16:36 -06:00
Fedora Release Engineering
ba9603988b dist-git conversion 2010-07-29 15:53:37 +00:00
Jan Zeleny
8c191cf66a fixed reconfiguration error when ending UDP services (#593904) 2010-06-02 08:38:49 +00:00
Jan Zeleny
c7a1500930 Corrected port parsing code (IPv4 and IPv6 were switched) Commented patches
I'm familiar with in spec file
2010-03-19 08:50:56 +00:00
Jan Zeleny
b84edf6c34 fixed flooding log with error messages when disabled service at runtime 2010-03-19 08:08:32 +00:00
Jan Zeleny
3e022482d1 fixed issue with tcpmux service (#543968) 2010-01-21 09:38:27 +00:00
Bill Nottingham
3354bbb91e Fix typo that causes a failure to update the common directory. (releng
#2781)
2009-11-25 22:40:59 +00:00
Jan Zeleny
811e1c67fe added patch file belonging to the previous commit 2009-10-20 12:08:42 +00:00
Jan Zeleny
e476844265 new config option - file limit, fixed init script issues with SELinux 2009-10-20 11:51:46 +00:00
Jan Zeleny
ad2263a160 updated init script (LSB compliance) 2009-10-12 08:56:17 +00:00
Jan Zeleny
6a4c285fa7 correction of last patch 2009-09-17 20:38:05 +00:00
Jan Zeleny
cd9fff6d3d Corrected previously forgotten release number. 2009-09-14 11:59:09 +00:00
Jan Zeleny
e2ea81b149 select() function and it's supporting macros replaced by poll() and it's
supporting macros
2009-09-14 11:55:32 +00:00
Jesse Keating
99c943080a - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild 2009-07-27 08:06:05 +00:00
16 changed files with 1 additions and 1631 deletions

1
.gitignore vendored
View file

@ -1 +0,0 @@
xinetd-2.3.14.tar.gz

1
dead.package Normal file
View file

@ -0,0 +1 @@
Orphaned for 6+ weeks

View file

@ -1 +0,0 @@
567382d7972613090215c6c54f9b82d9 xinetd-2.3.14.tar.gz

View file

@ -1,22 +0,0 @@
--- xinetd/Makefile.in.pie 2003-06-07 09:47:24.000000000 -0700
+++ xinetd/Makefile.in 2003-10-28 10:59:55.000000000 -0800
@@ -119,7 +119,7 @@
$(CC) $(CFLAGS) $(DEBUG) $(SRCDIR)/itox.c -o $@ $(LDFLAGS) $(LIBS)
xinetd: $(OBJS)
- $(CC) $(CFLAGS) $(DEBUG) -o $@ $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
+ $(CC) $(CFLAGS) $(DEBUG) -o $@ -PIE $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
clean:
rm -f $(OBJS) $(NAME) core itox
--- Makefile.in.pie 2003-10-28 10:54:39.000000000 -0800
+++ Makefile.in 2003-10-28 10:54:39.000000000 -0800
@@ -14,7 +14,7 @@
LIBS = -lsio -lstr -lmisc -lxlog -lportable -lpset @LIBS@
-CFLAGS += @CFLAGS@
+CFLAGS += @CFLAGS@ -fPIE
DCFLAGS = -Wall -Wredundant-decls -W -Wfloat-equal -Wundef -Wcast-qual -Wwrite-strings -Wconversion -Wmissing-noreturn -Wmissing-format-attribute -Wshadow -Wpointer-arith -g

View file

@ -1,22 +0,0 @@
--- xinetd/Makefile.in.pie 2003-06-07 09:47:24.000000000 -0700
+++ xinetd/Makefile.in 2003-10-28 10:59:55.000000000 -0800
@@ -119,7 +119,7 @@
$(CC) $(CFLAGS) $(DEBUG) $(SRCDIR)/itox.c -o $@ $(LDFLAGS) $(LIBS)
xinetd: $(OBJS)
- $(CC) $(CFLAGS) $(DEBUG) -o $@ $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
+ $(CC) $(CFLAGS) $(DEBUG) -o $@ -pie $(OBJS) $(LDFLAGS) $(LIBS) || rm -f $@
clean:
rm -f $(OBJS) $(NAME) core itox
--- Makefile.in.pie 2003-10-28 10:54:39.000000000 -0800
+++ Makefile.in 2003-10-28 10:54:39.000000000 -0800
@@ -14,7 +14,7 @@
LIBS = -lsio -lstr -lmisc -lxlog -lportable -lpset @LIBS@
-CFLAGS += @CFLAGS@
+CFLAGS += @CFLAGS@ -fpie
DCFLAGS = -Wall -Wredundant-decls -W -Wfloat-equal -Wundef -Wcast-qual -Wwrite-strings -Wconversion -Wmissing-noreturn -Wmissing-format-attribute -Wshadow -Wpointer-arith -g

View file

@ -1,34 +0,0 @@
--- xinetd-2.3.12/xinetd/service.c.tcp_rpc 2003-06-27 21:05:06.000000000 -0400
+++ xinetd-2.3.12/xinetd/service.c 2004-01-29 23:09:29.000000000 -0500
@@ -181,6 +181,9 @@
else
memset( &tsin, 0, sizeof(tsin));
+ if ( SC_PROTOVAL ( scp ) == IPPROTO_TCP ) {
+ M_SET ( scp->sc_xflags, SF_NOLIBWRAP );
+ }
if( SC_IPV4( scp ) ) {
tsin.sa_in.sin_family = AF_INET ;
sin_len = sizeof(struct sockaddr_in);
--- xinetd-2.3.12/xinetd/xinetd.conf.man.tcp_rpc 2004-01-30 12:38:59.000000000 -0500
+++ xinetd-2.3.12/xinetd/xinetd.conf.man 2004-01-30 12:43:50.000000000 -0500
@@ -123,6 +123,8 @@
to the service. This may be needed in order to use libwrap functionality
not available to long-running processes such as xinetd; in this case,
the tcpd program can be called explicitly (see also the NAMEINARGS flag).
+For RPC services using TCP transport, this flag is automatically turned on,
+because xinetd cannot get remote host address information for the rpc port.
.TP
.B SENSOR
This replaces the service with a sensor that detects accesses to the
@@ -1215,6 +1217,10 @@
access control on the address of the remote host is not performed when
\fIwait\fP is \fIyes\fP and \fIsocket_type\fP is \fIstream\fP.
.LP
+The NOLIBWRAP flag is automatically turned on for RPC services whose
+\fIsocket_type\fP is \fIstream\fP because xinetd cannot determine the
+address of the remote host.
+.LP
If the
.B INTERCEPT
flag is not used,

View file

@ -1,29 +0,0 @@
--- xinetd-2.3.14/xinetd/service.c.old 2007-05-16 15:33:41.000000000 +0200
+++ xinetd-2.3.14/xinetd/service.c 2007-05-16 15:29:53.000000000 +0200
@@ -335,6 +335,15 @@
if ( SVC_FD(sp) == -1 )
{
+ if (SC_BIND_ADDR(scp) == NULL && SC_IPV6( scp ))
+ {
+ /* there was no bind address configured and IPv6 fails. Try IPv4 */
+ msg( LOG_NOTICE, func, "IPv6 socket creation failed for service %s, trying IPv4", SC_ID( scp ) ) ;
+ M_CLEAR(SC_XFLAGS(scp), SF_IPV6);
+ M_SET(SC_XFLAGS(scp), SF_IPV4);
+ return svc_activate(sp);
+ }
+
msg( LOG_ERR, func,
"socket creation failed (%m). service = %s", SC_ID( scp ) ) ;
return( FAILED ) ;
--- xinetd-2.3.14/xinetd/confparse.c.old 2007-05-16 15:33:26.000000000 +0200
+++ xinetd-2.3.14/xinetd/confparse.c 2007-05-16 15:15:22.000000000 +0200
@@ -245,7 +245,7 @@
M_SET(SC_XFLAGS(scp), SF_IPV6);
}
else
- M_SET(SC_XFLAGS(scp), SF_IPV4);
+ M_SET(SC_XFLAGS(scp), SF_IPV6); /*try bind IPv6 by default*/
}
if (SC_ORIG_BIND_ADDR(scp))

View file

@ -1,110 +0,0 @@
diff -rup xinetd-2.3.14-orig/xinetd/child.c xinetd-2.3.14/xinetd/child.c
--- xinetd-2.3.14-orig/xinetd/child.c 2006-11-28 14:03:07.000000000 -0500
+++ xinetd-2.3.14/xinetd/child.c 2006-11-29 17:04:19.000000000 -0500
@@ -33,6 +33,8 @@
#endif
#ifdef LABELED_NET
#include <selinux/selinux.h>
+#include <selinux/flask.h>
+#include <selinux/context.h>
#endif
#include "str.h"
@@ -49,7 +51,7 @@
/* Local declarations */
#ifdef LABELED_NET
-static int set_context_from_socket( int fd );
+static int set_context_from_socket( const struct service_config *scp, int fd );
#endif
@@ -158,7 +160,7 @@ void exec_server( const struct server *s
#ifdef LABELED_NET
if (SC_LABELED_NET(scp))
{
- if (set_context_from_socket( descriptor ) < 0) {
+ if (set_context_from_socket( scp, descriptor ) < 0) {
msg( LOG_ERR, func,
"Changing process context failed for %s", SC_ID( scp )) ;
_exit( 1 ) ;
@@ -485,16 +487,11 @@ void child_exit(void)
}
#ifdef LABELED_NET
-static int set_context_from_socket( int fd )
+static int set_context( security_context_t cntx )
{
- const char *func = "set_context_from_socket" ;
- security_context_t peer_context;
+ const char *func = "set_context" ;
- if (getpeercon(fd, &peer_context) < 0)
- return -1;
-
- int retval = setexeccon(peer_context);
- freecon( peer_context );
+ int retval = setexeccon(cntx);
if (debug.on)
{
@@ -513,4 +510,59 @@ static int set_context_from_socket( int
return retval;
}
+
+static int set_context_from_socket( const struct service_config *scp, int fd )
+{
+ security_context_t curr_context = NULL;
+ security_context_t peer_context = NULL;
+ security_context_t exec_context = NULL;
+ context_t bcon = NULL;
+ context_t pcon = NULL;
+ security_context_t new_context = NULL;
+ security_context_t new_exec_context = NULL;
+ int retval = -1;
+ const char *exepath = NULL;
+
+ if (getcon(&curr_context) < 0)
+ goto fail;
+
+ if (getpeercon(fd, &peer_context) < 0)
+ goto fail;
+
+ exepath = SC_SERVER( scp );
+ if (getfilecon(exepath, &exec_context) < 0)
+ goto fail;
+
+ if (!(bcon = context_new(curr_context)))
+ goto fail;
+
+ if (!(pcon = context_new(peer_context)))
+ goto fail;
+
+ if (!context_range_get(pcon))
+ goto fail;
+
+ if (context_range_set(bcon, context_range_get(pcon)))
+ goto fail;
+
+ if (!(new_context = context_str(bcon)))
+ goto fail;
+
+ if (security_compute_create(new_context, exec_context, SECCLASS_PROCESS,
+ &new_exec_context) < 0)
+ goto fail;
+
+ retval = set_context(new_exec_context);
+
+ freecon(new_exec_context);
+
+ fail:
+ context_free(pcon);
+ context_free(bcon);
+ freecon(exec_context);
+ freecon(peer_context);
+ freecon(curr_context);
+
+ return retval;
+}
#endif

View file

@ -1,42 +0,0 @@
448069: xinetd: socket bind: Invalid argument (errno = 22) when using USERID on ipv6
Use right size of addresses in bind() call. Also use getpeername addresses when
connecting to ident service to prevent address family mismatch between socket(),
bind() and connect() calls.
Author: Jan Safranek <jsafrane@redhat.com>
Reviewed-By: Adam Tkac <atkac@redhat.com>
diff -up xinetd-2.3.14/xinetd/ident.c.orig xinetd-2.3.14/xinetd/ident.c
--- xinetd-2.3.14/xinetd/ident.c.orig 2008-05-29 16:30:19.000000000 +0200
+++ xinetd-2.3.14/xinetd/ident.c 2008-05-29 16:29:57.000000000 +0200
@@ -97,7 +98,13 @@ idresult_e log_remote_user( const struct
}
CLEAR( sin_contact );
- sin_remote = *CONN_XADDRESS( SERVER_CONNECTION( serp ) ) ;
+
+ sin_len = sizeof( sin_remote );
+ if ( getpeername( SERVER_FD( serp ), &sin_remote.sa, &sin_len ) == -1 )
+ {
+ msg( LOG_ERR, func, "(%d) getpeername: %m", getpid() ) ;
+ return( IDR_ERROR ) ;
+ }
sin_contact = sin_remote;
memcpy( &sin_bind, &sin_local, sizeof(sin_bind) ) ;
local_port = 0;
@@ -121,7 +128,13 @@ idresult_e log_remote_user( const struct
msg( LOG_ERR, func, "socket creation: %m" ) ;
return( IDR_ERROR ) ;
}
- if ( bind(sd, &sin_bind.sa, sizeof(sin_bind.sa)) == -1 )
+
+ if ( sin_bind.sa.sa_family == AF_INET )
+ sin_len = sizeof( sin_bind.sa_in ) ;
+ else
+ sin_len = sizeof( sin_bind.sa_in6 ) ;
+
+ if ( bind(sd, &sin_bind.sa, sin_len) == -1 )
{
msg( LOG_ERR, func, "socket bind: %m" ) ;
(void) Sclose( sd ) ;

View file

@ -1,227 +0,0 @@
diff -urp xinetd-2.3.14.orig/config.h.in xinetd-2.3.14/config.h.in
--- xinetd-2.3.14.orig/config.h.in 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/config.h.in 2006-09-20 17:12:00.000000000 -0400
@@ -112,6 +112,7 @@
/* Options */
#undef HAVE_LIBWRAP
#undef LIBWRAP
+#undef LABELED_NET
#undef HAVE_LOADAVG
diff -urp xinetd-2.3.14.orig/configure.in xinetd-2.3.14/configure.in
--- xinetd-2.3.14.orig/configure.in 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/configure.in 2006-09-20 17:12:00.000000000 -0400
@@ -289,6 +289,34 @@ AC_ARG_WITH(libwrap,
AC_MSG_RESULT(no)
)
+AC_MSG_CHECKING(whether to use labeled-networking)
+AC_ARG_WITH(labeled-networking,
+[ --with-labeled-networking[=PATH] Compile in labeled networking support.],
+[ case "$withval" in
+ no)
+ AC_MSG_RESULT(no)
+ ;;
+ yes)
+ AC_MSG_RESULT(yes)
+ AC_CHECK_LIB(selinux, setexeccon, [
+ AC_DEFINE(LABELED_NET)
+ LABELLIBS="-lselinux" ])
+ LIBS="$LABELLIBS $LIBS"
+ ;;
+ *)
+ AC_MSG_RESULT(yes)
+ AC_DEFINE(LABELED_NET)
+ if test -d "$withval"; then
+ LABELLIBS="-L$withval -lselinux"
+ else
+ LABELLIBS="$withval"
+ fi
+ LIBS="$LABELLIBS $LIBS"
+ ;;
+ esac ],
+ AC_MSG_RESULT(no)
+)
+
AC_FUNC_MMAP
AC_CHECK_FUNCS(isatty)
diff -urp xinetd-2.3.14.orig/xinetd/child.c xinetd-2.3.14/xinetd/child.c
--- xinetd-2.3.14.orig/xinetd/child.c 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/xinetd/child.c 2006-09-20 17:12:00.000000000 -0400
@@ -31,6 +31,9 @@
#ifdef HAVE_NETDB_H
#include <netdb.h>
#endif
+#ifdef LABELED_NET
+#include <selinux/selinux.h>
+#endif
#include "str.h"
#include "child.h"
@@ -44,6 +47,12 @@
#include "options.h"
#include "redirect.h"
+/* Local declarations */
+#ifdef LABELED_NET
+static int set_context_from_socket( int fd );
+#endif
+
+
/*
* This function is running in the new process
*/
@@ -143,6 +152,20 @@ void exec_server( const struct server *s
}
#endif
+ /*
+ Set the context if the option was given
+ */
+#ifdef LABELED_NET
+ if (SC_LABELED_NET(scp))
+ {
+ if (set_context_from_socket( descriptor ) < 0) {
+ msg( LOG_ERR, func,
+ "Changing process context failed for %s", SC_ID( scp )) ;
+ _exit( 1 ) ;
+ }
+ }
+#endif
+
(void) Sclose( descriptor ) ;
#ifndef solaris
@@ -461,3 +484,33 @@ void child_exit(void)
}
}
+#ifdef LABELED_NET
+static int set_context_from_socket( int fd )
+{
+ const char *func = "set_context_from_socket" ;
+ security_context_t peer_context;
+
+ if (getpeercon(fd, &peer_context) < 0)
+ return -1;
+
+ int retval = setexeccon(peer_context);
+ freecon( peer_context );
+
+ if (debug.on)
+ {
+ security_context_t current_exec_context;
+ if ( getexeccon( &current_exec_context ) == 0 ) {
+
+ msg( LOG_DEBUG, func,
+ "current security exec context now: %s",
+ current_exec_context ? current_exec_context : "unknown" );
+
+ freecon( current_exec_context );
+ }
+ else
+ msg( LOG_DEBUG, func, "Error calling getexeccon: %m" );
+ }
+
+ return retval;
+}
+#endif
diff -urp xinetd-2.3.14.orig/xinetd/confparse.c xinetd-2.3.14/xinetd/confparse.c
--- xinetd-2.3.14.orig/xinetd/confparse.c 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/xinetd/confparse.c 2006-09-20 17:16:35.000000000 -0400
@@ -697,6 +697,35 @@ static status_e check_entry( struct serv
return( FAILED ) ;
}
+#ifdef LABELED_NET
+ if (SC_LABELED_NET(scp)) {
+ if ( SC_IS_INTERNAL( scp ) ) {
+ msg( LOG_ERR, func,
+ "Internal services cannot support labeled networking: %s",
+ SC_ID(scp) ) ;
+ return( FAILED ) ;
+ }
+ if ( SC_SOCKET_TYPE(scp) != SOCK_STREAM ) {
+ msg( LOG_ERR, func,
+ "Non-stream socket types cannot support labeled networking: %s",
+ SC_ID(scp) ) ;
+ return( FAILED ) ;
+ }
+ if ( SC_WAITS( scp ) ) {
+ msg( LOG_ERR, func,
+ "Tcp wait services cannot support labeled networking: %s",
+ SC_ID(scp) ) ;
+ return( FAILED ) ;
+ }
+ if ( SC_REDIR_ADDR( scp ) != NULL) {
+ msg( LOG_ERR, func,
+ "Redirected services cannot support labeled networking: %s",
+ SC_ID(scp) ) ;
+ return( FAILED ) ;
+ }
+ }
+#endif
+
if ( SC_IS_MUXCLIENT( scp ) )
{
if ( !SC_IS_UNLISTED( scp ) )
diff -urp xinetd-2.3.14.orig/xinetd/main.c xinetd-2.3.14/xinetd/main.c
--- xinetd-2.3.14.orig/xinetd/main.c 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/xinetd/main.c 2006-09-20 17:12:00.000000000 -0400
@@ -80,7 +80,10 @@ int main( int argc, char *argv[] )
#ifdef HAVE_DNSREGISTRATION
"rendezvous "
#endif
-#if !defined(LIBWRAP) && !defined(HAVE_LOADAVG) && !defined(HAVE_MDNS) && !defined(HAVE_HOWL) && !defined(HAVE_DNSREGISTRATION)
+#ifdef LABELED_NET
+ "labeled-networking "
+#endif
+#if !defined(LIBWRAP) && !defined(HAVE_LOADAVG) && !defined(HAVE_MDNS) && !defined(HAVE_HOWL) && !defined(HAVE_DNSREGISTRATION) && !defined(LABELED_NET)
"no "
#endif
"options compiled in."
diff -urp xinetd-2.3.14.orig/xinetd/nvlists.c xinetd-2.3.14/xinetd/nvlists.c
--- xinetd-2.3.14.orig/xinetd/nvlists.c 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/xinetd/nvlists.c 2006-09-20 17:12:00.000000000 -0400
@@ -47,6 +47,7 @@ const struct name_value service_flags[]
{ "SENSOR", SF_SENSOR },
{ "IPv4", SF_IPV4 },
{ "IPv6", SF_IPV6 },
+ { "LABELED", SF_LABELED },
{ CHAR_NULL, 0 }
} ;
diff -urp xinetd-2.3.14.orig/xinetd/sconf.h xinetd-2.3.14/xinetd/sconf.h
--- xinetd-2.3.14.orig/xinetd/sconf.h 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/xinetd/sconf.h 2006-09-20 17:12:00.000000000 -0400
@@ -58,6 +58,7 @@
#define SF_SENSOR 9
#define SF_IPV4 10
#define SF_IPV6 11
+#define SF_LABELED 12
/*
* Values for log options
@@ -239,6 +240,7 @@ struct service_config
#define SC_SENSOR( scp ) M_IS_SET( (scp)->sc_xflags, SF_SENSOR )
#define SC_IPV4( scp ) M_IS_SET( (scp)->sc_xflags, SF_IPV4 )
#define SC_IPV6( scp ) M_IS_SET( (scp)->sc_xflags, SF_IPV6 )
+#define SC_LABELED_NET( scp ) M_IS_SET( (scp)->sc_xflags, SF_LABELED )
#define SC_IS_RPC( scp ) ( M_IS_SET( (scp)->sc_type, ST_RPC ) )
#define SC_IS_INTERNAL( scp ) ( M_IS_SET( (scp)->sc_type, ST_INTERNAL ) )
diff -urp xinetd-2.3.14.orig/xinetd/xinetd.conf.man xinetd-2.3.14/xinetd/xinetd.conf.man
--- xinetd-2.3.14.orig/xinetd/xinetd.conf.man 2006-06-16 13:20:01.000000000 -0400
+++ xinetd-2.3.14/xinetd/xinetd.conf.man 2006-09-20 17:12:00.000000000 -0400
@@ -145,6 +145,9 @@ Sets the service to be an IPv4 service (
.B IPv6
Sets the service to be an IPv6 service (AF_INET6), if IPv6 is available on the system.
.TP
+.B LABELED
+The LABELED flag will tell xinetd to change the child processes SE Linux context to match that of the incoming connection as it starts the service. This only works for external tcp non-waiting servers and is an error if applied to an internal, udp, or tcp-wait server.
+.TP
.B REUSE
The REUSE flag is deprecated. All services now implicitly use the REUSE flag.
.RE

View file

@ -1,16 +0,0 @@
117746: xinetd.log man page in wrong section
Put xinetd.log to the right man section.
diff -up xinetd-2.3.13/Makefile.in.orig xinetd-2.3.13/Makefile.in
--- xinetd-2.3.13/Makefile.in.orig 2007-12-06 10:58:32.000000000 +0100
+++ xinetd-2.3.13/Makefile.in 2008-01-15 13:39:38.000000000 +0100
@@ -80,7 +80,7 @@ install: build
$(INSTALL_CMD) -m 755 xinetd/itox $(DAEMONDIR)
$(INSTALL_CMD) -m 755 $(SRCDIR)/xinetd/xconv.pl $(DAEMONDIR)
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.conf.man $(MANDIR)/man5/xinetd.conf.5
- $(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.log.man $(MANDIR)/man8/xinetd.log.8
+ $(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.log.man $(MANDIR)/man5/xinetd.log.5
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xinetd.man $(MANDIR)/man8/xinetd.8
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/itox.8 $(MANDIR)/man8/itox.8
$(INSTALL_CMD) -m 644 $(SRCDIR)/xinetd/xconv.pl.8 $(MANDIR)/man8/xconv.pl.8

View file

@ -1,77 +0,0 @@
Generate debuginfo package with all include files readable.
The support libraries would install their header files with 640 permissions,
which is not what we want.
diff -up xinetd-2.3.14/libs/src/misc/Makefile.in.orig xinetd-2.3.14/libs/src/misc/Makefile.in
--- xinetd-2.3.14/libs/src/misc/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
+++ xinetd-2.3.14/libs/src/misc/Makefile.in 2008-09-18 10:18:59.000000000 +0200
@@ -49,7 +49,7 @@ CC_FLAGS = $(DEBUG)
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS) -I$(INCLUDEDIR)
INSTALL = @INSTALL@
-FMODE = -m 640 # used by install
+FMODE = -m 644 # used by install
RANLIB = @RANLIB@
LIBNAME = lib$(NAME).a
diff -up xinetd-2.3.14/libs/src/portable/Makefile.in.orig xinetd-2.3.14/libs/src/portable/Makefile.in
--- xinetd-2.3.14/libs/src/portable/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
+++ xinetd-2.3.14/libs/src/portable/Makefile.in 2008-09-18 10:19:09.000000000 +0200
@@ -44,7 +44,7 @@ CC_FLAGS = $(DEBUG)
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS) -I$(INCLUDEDIR)
INSTALL = @INSTALL@
-FMODE = -m 640 # used by install
+FMODE = -m 644 # used by install
RANLIB = @RANLIB@
LIBNAME = lib$(NAME).a
diff -up xinetd-2.3.14/libs/src/pset/Makefile.in.orig xinetd-2.3.14/libs/src/pset/Makefile.in
--- xinetd-2.3.14/libs/src/pset/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
+++ xinetd-2.3.14/libs/src/pset/Makefile.in 2008-09-18 10:19:17.000000000 +0200
@@ -41,7 +41,7 @@ CC_FLAGS = $(DEBUG)
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS)
INSTALL = @INSTALL@
-FMODE = -m 640 # used by install
+FMODE = -m 644 # used by install
RANLIB = @RANLIB@
LIBNAME = lib$(NAME).a
diff -up xinetd-2.3.14/libs/src/sio/Makefile.in.orig xinetd-2.3.14/libs/src/sio/Makefile.in
--- xinetd-2.3.14/libs/src/sio/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
+++ xinetd-2.3.14/libs/src/sio/Makefile.in 2008-09-18 10:19:25.000000000 +0200
@@ -40,7 +40,7 @@ CC_FLAGS = $(DEBUG)
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS) -I$(INCLUDEDIR)
INSTALL = @INSTALL@
-FMODE = -m 640 # used by install
+FMODE = -m 644 # used by install
RANLIB = @RANLIB@
LIBNAME = lib$(NAME).a
diff -up xinetd-2.3.14/libs/src/str/Makefile.in.orig xinetd-2.3.14/libs/src/str/Makefile.in
--- xinetd-2.3.14/libs/src/str/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
+++ xinetd-2.3.14/libs/src/str/Makefile.in 2008-09-18 10:19:33.000000000 +0200
@@ -51,7 +51,7 @@ CC_FLAGS = $(DEBUG)
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS)
INSTALL = @INSTALL@
-FMODE = -m 640 # used by install
+FMODE = -m 644 # used by install
RANLIB = @RANLIB@
LIBNAME = lib$(NAME).a
diff -up xinetd-2.3.14/libs/src/xlog/Makefile.in.orig xinetd-2.3.14/libs/src/xlog/Makefile.in
--- xinetd-2.3.14/libs/src/xlog/Makefile.in.orig 2003-02-19 18:29:27.000000000 +0100
+++ xinetd-2.3.14/libs/src/xlog/Makefile.in 2008-09-18 10:19:41.000000000 +0200
@@ -46,7 +46,7 @@ CC_FLAGS = $(DEBUG)
CFLAGS = @CFLAGS@ $(CPP_FLAGS) $(CC_FLAGS)
INSTALL = @INSTALL@
-FMODE = -m 640 # used by install
+FMODE = -m 644 # used by install
RANLIB = @RANLIB@
LIBNAME = lib$(NAME).a

View file

@ -1,660 +0,0 @@
--- xinetd-2.3.14/libs/src/sio/impl.h.ssize_t 2006-10-27 12:33:29.000000000 -0400
+++ xinetd-2.3.14/libs/src/sio/impl.h 2006-10-27 12:40:21.000000000 -0400
@@ -142,9 +142,9 @@
* Internal functions that are visible
*/
int __sio_writef( __sio_od_t *odp, int fd ) ;
-int __sio_extend_buffer( __sio_id_t *idp, int fd, int b_left ) ;
+ssize_t __sio_extend_buffer( __sio_id_t *idp, int fd, ssize_t b_left ) ;
int __sio_init( __sio_descriptor_t *dp, int fd, enum __sio_stream stream_type );
-int __sio_more( __sio_id_t *idp, int fd ) ;
+ssize_t __sio_more( __sio_id_t *idp, int fd ) ;
sio_status_e __sio_switch( __sio_id_t *idp, int fd ) ;
--- xinetd-2.3.14/libs/src/sio/siosup.c.ssize_t 2003-09-06 10:41:59.000000000 -0400
+++ xinetd-2.3.14/libs/src/sio/siosup.c 2006-10-27 12:40:23.000000000 -0400
@@ -599,9 +599,9 @@
* If it does not return SIO_ERR, it sets start, nextb, end
* If it returns SIO_ERR, it does not change anything
*/
-static int __sio_readf( __sio_id_t *idp, int fd )
+static ssize_t __sio_readf( __sio_id_t *idp, int fd )
{
- int cc ;
+ ssize_t cc ;
/*
* First check for a tied fd and flush the stream if necessary
@@ -634,7 +634,7 @@
{
if ( __sio_switch( idp, fd ) == FAILURE )
return( SIO_ERR ) ;
- cc = -1 ;
+ cc = (ssize_t)-1 ;
}
}
else
@@ -680,7 +680,7 @@
for ( ;; )
{
cc = read( fd, idp->buf, (int) idp->buffer_size ) ;
- if ( cc == -1 )
+ if ( cc == (ssize_t)-1 )
if ( errno == EINTR )
continue ;
else
@@ -705,9 +705,9 @@
* auxiliary buffer)
* Also, if successful, idp->nextb is set to idp->buf, idp->end is modified.
*/
-int __sio_extend_buffer( __sio_id_t *idp, int fd, int b_left )
+ssize_t __sio_extend_buffer( __sio_id_t *idp, int fd, ssize_t b_left )
{
- int b_read ;
+ ssize_t b_read ;
/*
* copy to auxiliary buffer
@@ -733,10 +733,10 @@
*
* Return value: the number of bytes read.
*/
-int __sio_more( __sio_id_t *idp, int fd )
+ssize_t __sio_more( __sio_id_t *idp, int fd )
{
int b_left = &idp->buf[ idp->buffer_size ] - idp->end ;
- int cc ;
+ ssize_t cc ;
if ( b_left <= 0 )
return( 0 ) ;
--- xinetd-2.3.14/libs/src/sio/sprint.c.ssize_t 2006-10-27 13:14:49.000000000 -0400
+++ xinetd-2.3.14/libs/src/sio/sprint.c 2006-10-27 13:14:51.000000000 -0400
@@ -18,7 +18,7 @@
typedef unsigned long long u_wide_int ;
typedef int bool_int ;
-static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, int *len );
+static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, size_t *len );
#define S_NULL_LEN 6
static char S_NULL[S_NULL_LEN+1] = "(null)";
@@ -69,7 +69,7 @@
} \
if ( __SIO_MUST_FLUSH( *odp, c ) && fd >= 0 ) \
{ \
- int b_in_buffer = sp - odp->start ; \
+ ssize_t b_in_buffer = sp - odp->start ; \
\
odp->nextb = sp ; \
if ( __sio_writef( odp, fd ) != b_in_buffer ) \
@@ -122,11 +122,11 @@
* - all floating point arguments are passed as doubles
*/
/* VARARGS2 */
-int Sprint( int fd, const char *fmt, ...)
+ssize_t Sprint( int fd, const char *fmt, ...)
{
__sio_descriptor_t *dp ;
__sio_od_t *odp ;
- int cc ;
+ ssize_t cc ;
va_list ap ;
if( sio_setup( fd, &dp, __SIO_OUTPUT_STREAM ) == SIO_ERR )
@@ -143,7 +143,7 @@
/*
* This is the equivalent of vfprintf for SIO
*/
-int Sprintv( int fd, const char *fmt, va_list ap)
+ssize_t Sprintv( int fd, const char *fmt, va_list ap)
{
__sio_descriptor_t *dp ;
__sio_od_t *odp ;
@@ -162,7 +162,7 @@
* in buf).
*/
static char *conv_fp( char format, double num, boolean_e add_dp,
- int precision, bool_int *is_negative, char buf[], int *len )
+ size_t precision, bool_int *is_negative, char buf[], size_t *len )
/* always add decimal point if YES */
{
char *s = buf ;
@@ -220,7 +220,7 @@
if ( format != 'f' )
{
char temp[ EXPONENT_LENGTH ] ; /* for exponent conversion */
- int t_len ;
+ size_t t_len ;
bool_int exponent_is_negative ;
*s++ = format ; /* either e or E */
@@ -261,7 +261,7 @@
* which is a pointer to the END of the buffer + 1 (i.e. if the buffer
* is declared as buf[ 100 ], buf_end should be &buf[ 100 ])
*/
-static char *conv_p2( u_wide_int num, int nbits, char format, char *buf_end, int *len )
+static char *conv_p2( u_wide_int num, int nbits, char format, char *buf_end, size_t *len )
{
int mask = ( 1 << nbits ) - 1 ;
char *p = buf_end ;
@@ -292,7 +292,7 @@
* which is a pointer to the END of the buffer + 1 (i.e. if the buffer
* is declared as buf[ 100 ], buf_end should be &buf[ 100 ])
*/
-static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, int *len )
+static char *conv_10( wide_int num, bool_int is_unsigned, bool_int *is_negative, char *buf_end, size_t *len )
{
char *p = buf_end ;
u_wide_int magnitude ;
@@ -346,19 +346,19 @@
* Do format conversion placing the output in odp.
* Note: we do not support %n for security reasons.
*/
-int __sio_converter( __sio_od_t *odp, int fd, const char *fmt, va_list ap )
+ssize_t __sio_converter( __sio_od_t *odp, int fd, const char *fmt, va_list ap )
{
char *sp = NULL;
char *bep = NULL;
- int cc = 0 ;
- int i ;
+ ssize_t cc = 0 ;
+ size_t i ;
char *s = NULL;
char *q = NULL;
- int s_len ;
+ size_t s_len ;
int min_width = 0 ;
- int precision = 0 ;
+ size_t precision = 0 ;
enum { LEFT, RIGHT } adjust ;
char pad_char ;
char prefix_char ;
--- xinetd-2.3.14/libs/src/sio/sio.c.ssize_t 2006-10-27 12:35:12.000000000 -0400
+++ xinetd-2.3.14/libs/src/sio/sio.c 2006-10-27 13:28:09.000000000 -0400
@@ -28,17 +28,17 @@
/*
* Stream write call: arguments same as those of write(2)
*/
-int Swrite( int fd, const char *addr, unsigned int nbytes )
+ssize_t Swrite( int fd, const char *addr, size_t nbytes )
{
__sio_descriptor_t *dp ;
__sio_od_t *odp ;
- unsigned int b_transferred ;
- unsigned int b_avail ;
- int total_b_transferred ;
- int b_written ;
- int b_in_buffer ;
+ size_t b_transferred ;
+ size_t b_avail ;
+ ssize_t total_b_transferred ;
+ ssize_t b_written ;
+ ssize_t b_in_buffer ;
- if ( nbytes > INT_MAX )
+ if ( nbytes > SSIZE_MAX )
return( SIO_ERR );
if( sio_setup( fd, &dp, __SIO_OUTPUT_STREAM ) == SIO_ERR )
return( SIO_ERR );
@@ -62,7 +62,7 @@
b_in_buffer = odp->buf_end - odp->start ;
b_written = __sio_writef( odp, fd ) ;
if ( b_written != b_in_buffer )
- return( (b_written >= (int)nbytes) ? (int)nbytes : b_written ) ;
+ return( (b_written >= (ssize_t)nbytes) ? (ssize_t)nbytes : b_written ) ;
total_b_transferred = b_transferred ;
addr += b_transferred ;
@@ -83,7 +83,7 @@
* the buffer is full
*/
b_written = __sio_writef( odp, fd ) ;
- if ( b_written != (int)odp->buffer_size )
+ if ( b_written != (ssize_t)odp->buffer_size )
{
if ( b_written != SIO_ERR )
{
@@ -157,8 +157,8 @@
__sio_id_t *idp ;
char *cp ;
char *line_start ;
- int b_left ;
- int extension ;
+ ssize_t b_left ;
+ ssize_t extension ;
if( sio_setup( fd, &dp, __SIO_INPUT_STREAM ) == SIO_ERR )
return( NULL );
@@ -361,7 +361,7 @@
#ifndef sio_memscan
-static char *sio_memscan( const char *from, int how_many, char ch )
+static char *sio_memscan( const char *from, size_t how_many, char ch )
{
char *p ;
char *last = from + how_many ;
@@ -377,7 +377,7 @@
#ifdef NEED_MEMCOPY
-void __sio_memcopy( const char *from, char *to, int nbytes )
+void __sio_memcopy( const char *from, char *to, size_t nbytes )
{
while ( nbytes-- )
*to++ = *from++ ;
--- xinetd-2.3.14/xinetd/udpint.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
+++ xinetd-2.3.14/xinetd/udpint.c 2006-10-27 12:17:10.000000000 -0400
@@ -226,7 +226,7 @@
{
char *p ;
int left ;
- int cc ;
+ ssize_t cc ;
const char *func = "send_data" ;
for ( p = buf, left = len ; left > 0 ; left -= cc, p+= cc )
@@ -236,7 +236,7 @@
else
cc = sendto( sd, p, left, 0, SA( addr ), sizeof( *addr ) ) ;
- if ( cc == -1 ) {
+ if ( cc == (ssize_t)-1 ) {
if ( errno == EINTR )
{
cc = 0 ;
@@ -264,12 +264,12 @@
for ( ;; )
{
- int cc ;
+ ssize_t cc ;
from_len = sizeof( pp->from ) ;
cc = recvfrom( INT_REMOTE( ip ), pp->data, pp->size,
0, SA( &pp->from ), &from_len ) ;
- if ( cc == -1 )
+ if ( cc == (ssize_t)-1 )
{
if ( errno != EINTR )
{
@@ -306,14 +306,14 @@
static status_e udp_local_to_remote( channel_s *chp )
{
char buf[ MAX_DATAGRAM_SIZE ] ;
- int cc ;
+ ssize_t cc ;
const char *func = "udp_local_to_remote" ;
for ( ;; )
{
cc = recv( chp->ch_local_socket, buf, sizeof( buf ), 0 ) ;
- if ( cc == -1 )
+ if ( cc == (ssize_t)-1 )
{
if ( errno != EINTR )
{
--- xinetd-2.3.14/xinetd/service.c.ssize_t 2006-10-27 12:17:10.000000000 -0400
+++ xinetd-2.3.14/xinetd/service.c 2006-10-27 12:17:10.000000000 -0400
@@ -610,7 +610,7 @@
/* print the banner regardless of access control */
if ( SC_BANNER(scp) != NULL ) {
char tmpbuf[TMPSIZE];
- int retval;
+ ssize_t retval;
int bannerfd = open(SC_BANNER(scp), O_RDONLY);
if( bannerfd < 0 ) {
@@ -620,7 +620,7 @@
}
while( (retval = read(bannerfd, tmpbuf, sizeof(tmpbuf))) ) {
- if (retval == -1)
+ if (retval == (ssize_t)-1)
{
if (errno == EINTR)
continue;
--- xinetd-2.3.14/xinetd/signals.c.ssize_t 2003-12-23 10:30:10.000000000 -0500
+++ xinetd-2.3.14/xinetd/signals.c 2006-10-27 12:17:10.000000000 -0400
@@ -402,7 +402,7 @@
*/
static void my_handler( int sig )
{
- int ret_val;
+ ssize_t ret_val;
int saved_errno = errno;
#if NSIG < 256
unsigned char sig_byte;
@@ -412,13 +412,13 @@
do
{
ret_val = write(signals_pending[1], &sig_byte, 1);
- } while (ret_val == -1 && errno == EINTR);
+ } while (ret_val == (ssize_t)-1 && errno == EINTR);
#else
if (signals_pending[1] < 0) return;
do
{
ret_val = write(signals_pending[1], &sig, sizeof(int));
- } while (ret_val == -1 && errno == EINTR);
+ } while (ret_val == (ssize_t)-1 && errno == EINTR);
#endif
errno = saved_errno;
}
@@ -470,12 +470,12 @@
#endif
while( --i >= 0 ) {
- int ret_val;
+ ssize_t ret_val;
do
{
ret_val = read(signals_pending[0], &sig, sizeof(sig));
- } while (ret_val == -1 && errno == EINTR);
- if (ret_val != sizeof(sig) ) {
+ } while (ret_val == (ssize_t)-1 && errno == EINTR);
+ if (ret_val != (ssize_t)sizeof(sig) ) {
msg(LOG_ERR, func, "Error retrieving pending signal: %m");
return;
}
--- xinetd-2.3.14/xinetd/connection.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
+++ xinetd-2.3.14/xinetd/connection.c 2006-10-27 12:17:10.000000000 -0400
@@ -96,13 +96,15 @@
if ( SVC_SOCKET_TYPE( sp ) == SOCK_DGRAM )
{
char t_ch ;
+ ssize_t val;
/*
* This trick is done to get the remote address.
* select(2) guaranteed that we won't block on the recvfrom
*/
- if ( recvfrom( SVC_FD( sp ), &t_ch, 1, MSG_PEEK,
- &cp->co_remote_address.sa, &sin_len ) == -1 )
+ val = recvfrom( SVC_FD( sp ), &t_ch, 1, MSG_PEEK,
+ &cp->co_remote_address.sa, &sin_len );
+ if ( val == (ssize_t)-1 )
{
msg( LOG_ERR, func, "service %s, recvfrom: %m", SVC_ID( sp ) ) ;
return( FAILED ) ;
--- xinetd-2.3.14/xinetd/util.c.ssize_t 2005-10-05 17:45:41.000000000 -0400
+++ xinetd-2.3.14/xinetd/util.c 2006-10-27 12:17:10.000000000 -0400
@@ -198,7 +198,8 @@
*/
status_e write_buf( int fd, const char *buf, int len )
{
- int cc, i ;
+ int i ;
+ ssize_t cc;
for ( i = 0 ; len > 0 ; i += cc, len -= cc )
{
@@ -234,7 +235,7 @@
void drain( int sd )
{
char buf[ 256 ] ; /* This size is arbitrarily chosen */
- int ret ;
+ ssize_t ret ;
int old_val ;
/* Put in non-blocking mode so we don't hang. */
--- xinetd-2.3.14/xinetd/redirect.c.ssize_t 2003-08-06 02:12:10.000000000 -0400
+++ xinetd-2.3.14/xinetd/redirect.c 2006-10-27 12:17:10.000000000 -0400
@@ -58,7 +58,8 @@
struct service *sp = SERVER_SERVICE( serp );
struct service_config *scp = SVC_CONF( sp );
int RedirDescrip = SERVER_FD( serp );
- int maxfd, num_read, num_wrote=0, ret=0;
+ int maxfd;
+ ssize_t num_read, num_wrote=0, ret=0;
unsigned int sin_len = 0;
unsigned long bytes_in = 0, bytes_out = 0;
int no_to_nagle = 1;
@@ -156,7 +157,7 @@
do {
num_read = read(RedirDescrip,
buff, sizeof(buff));
- if (num_read == -1 && errno == EINTR)
+ if (num_read == (ssize_t)-1 && errno == EINTR)
continue;
if (num_read <= 0)
goto REDIROUT;
--- xinetd-2.3.14/xinetd/tcpint.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
+++ xinetd-2.3.14/xinetd/tcpint.c 2006-10-27 12:17:10.000000000 -0400
@@ -273,7 +273,7 @@
static stream_status_e tcp_local_to_remote( channel_s *chp )
{
char buf[ DATAGRAM_SIZE ] ;
- int rcc, wcc ;
+ ssize_t rcc, wcc ;
char *p ;
int left ;
const char *func = "tcp_local_to_remote" ;
@@ -283,7 +283,7 @@
rcc = recv( chp->ch_local_socket, buf, sizeof( buf ), 0 ) ;
if ( rcc == 0 )
return( S_SERVER_ERR ) ;
- else if ( rcc == -1 )
+ else if ( rcc == (ssize_t)-1 )
{
if ( errno != EINTR )
{
@@ -300,7 +300,7 @@
wcc = send( chp->ch_remote_socket, p, left, 0 ) ;
if ( wcc == 0 )
return( S_CLIENT_ERR ) ;
- else if ( wcc == -1 )
+ else if ( wcc == (ssize_t)-1 )
{
if ( errno == EINTR )
wcc = 0 ;
@@ -326,7 +326,7 @@
static stream_status_e tcp_remote_to_local( channel_s *chp )
{
char buf[ DATAGRAM_SIZE ] ;
- int rcc, wcc ;
+ ssize_t rcc, wcc ;
int left ;
char *p ;
const char *func = "tcp_remote_to_local" ;
@@ -336,7 +336,7 @@
rcc = recv( chp->ch_remote_socket, buf, sizeof( buf ), 0 ) ;
if ( rcc == 0 )
return( S_CLIENT_ERR ) ;
- else if ( rcc == -1 )
+ else if ( rcc == (ssize_t)-1 )
{
if ( errno != EINTR )
{
@@ -353,7 +353,7 @@
wcc = send( chp->ch_local_socket, p, left, 0 ) ;
if ( wcc == 0 ) {
return( S_SERVER_ERR ) ;
- } else if ( wcc == -1 ) {
+ } else if ( wcc == (ssize_t)-1 ) {
if ( errno == EINTR ) {
rcc = 0 ;
} else {
--- xinetd-2.3.14/xinetd/builtins.c.ssize_t 2005-10-06 11:38:04.000000000 -0400
+++ xinetd-2.3.14/xinetd/builtins.c 2006-10-27 12:17:10.000000000 -0400
@@ -129,7 +129,7 @@
static void stream_echo( const struct server *serp )
{
char buf[ BUFFER_SIZE ] ;
- int cc ;
+ ssize_t cc ;
int descriptor = SERVER_FD( serp ) ;
struct service *svc = SERVER_SERVICE( serp ) ;;
@@ -149,7 +149,7 @@
cc = read( descriptor, buf, sizeof( buf ) ) ;
if ( cc == 0 )
break ;
- if ( cc == -1 ) {
+ if ( cc == (ssize_t)-1 ) {
if ( errno == EINTR )
continue ;
else
@@ -167,7 +167,7 @@
{
char buf[ DATAGRAM_SIZE ] ;
union xsockaddr lsin;
- int cc ;
+ ssize_t cc ;
socklen_t sin_len = 0;
int descriptor = SERVER_FD( serp ) ;
const char *func = "dgram_echo";
@@ -178,15 +178,15 @@
sin_len = sizeof( struct sockaddr_in6 );
cc = recvfrom( descriptor, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len ) ;
- if ( cc != -1 ) {
- (void) sendto( descriptor, buf, cc, 0, SA( &lsin ), sizeof( lsin ) ) ;
+ if ( cc != (ssize_t)-1 ) {
+ (void) sendto( descriptor, buf, (size_t)cc, 0, SA( &lsin ), sizeof( lsin ) ) ;
}
}
static void stream_discard( const struct server *serp )
{
char buf[ BUFFER_SIZE ] ;
- int cc ;
+ ssize_t cc ;
int descriptor = SERVER_FD( serp ) ;
struct service *svc = SERVER_SERVICE( serp ) ;;
@@ -204,7 +204,7 @@
for ( ;; )
{
cc = read( descriptor, buf, sizeof( buf ) ) ;
- if ( (cc == 0) || ((cc == -1) && (errno != EINTR)) )
+ if ( (cc == 0) || ((cc == (ssize_t)-1) && (errno != EINTR)) )
break ;
}
if( SVC_WAITS( svc ) ) /* Service forks, so close it */
@@ -293,14 +293,16 @@
unsigned int buflen = sizeof( time_buf ) ;
int descriptor = SERVER_FD( serp ) ;
const char *func = "dgram_daytime";
+ ssize_t val;
if ( SC_IPV4( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
sin_len = sizeof( struct sockaddr_in );
else if ( SC_IPV6( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
sin_len = sizeof( struct sockaddr_in6 );
- if ( recvfrom( descriptor, time_buf, sizeof( time_buf ), 0,
- SA( &lsin ), &sin_len ) == -1 )
+ val = recvfrom( descriptor, time_buf, sizeof( time_buf ), 0,
+ SA( &lsin ), &sin_len );
+ if ( val == (ssize_t)-1 )
return ;
daytime_protocol( time_buf, &buflen ) ;
@@ -359,13 +361,15 @@
socklen_t sin_len = 0 ;
int fd = SERVER_FD( serp ) ;
const char *func = "dgram_daytime";
+ ssize_t val;
if ( SC_IPV4( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
sin_len = sizeof( struct sockaddr_in );
else if ( SC_IPV6( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
sin_len = sizeof( struct sockaddr_in6 );
- if ( recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len ) == -1 )
+ val = recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len );
+ if ( val == (ssize_t)-1 )
return ;
time_protocol( time_buf ) ;
@@ -465,13 +469,15 @@
int fd = SERVER_FD( serp ) ;
unsigned int left = sizeof( buf ) ;
const char *func = "dgram_chargen";
+ ssize_t val;
if ( SC_IPV4( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
sin_len = sizeof( struct sockaddr_in );
else if ( SC_IPV6( SVC_CONF( SERVER_SERVICE( serp ) ) ) )
sin_len = sizeof( struct sockaddr_in6 );
- if ( recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len ) == -1 )
+ val = recvfrom( fd, buf, sizeof( buf ), 0, SA( &lsin ), &sin_len );
+ if ( val == (ssize_t)-1 )
return ;
#if BUFFER_SIZE < LINE_LENGTH+2
--- xinetd-2.3.14/xinetd/ident.c.ssize_t 2005-10-05 13:20:11.000000000 -0400
+++ xinetd-2.3.14/xinetd/ident.c 2006-10-27 12:17:10.000000000 -0400
@@ -267,7 +267,7 @@
static char *get_line( int sd, char *buf, unsigned bufsize )
{
int size ;
- int cc ;
+ ssize_t cc ;
char *p ;
char *s ;
const char *func = "get_line" ;
@@ -275,7 +275,7 @@
for ( p = buf, size = bufsize ; size > 0 ; p += cc, size -= cc )
{
cc = read( sd, p, size ) ;
- if ( cc == -1 ) {
+ if ( cc == (ssize_t)-1 ) {
if ( errno == EINTR )
{
cc = 0 ;
--- xinetd-2.3.14/libs/src/sio/sio.h.ssize_t 2003-06-10 09:15:44.000000000 -0400
+++ xinetd-2.3.14/libs/src/sio/sio.h 2006-10-27 15:47:37.000000000 -0400
@@ -12,6 +12,8 @@
#define __SIO_H
#include <errno.h>
+#include <string.h>
+#include <unistd.h>
#include <stdarg.h>
/*
@@ -56,7 +58,7 @@
* buffer is right below buf and is of the same size.
*/
char *buf ;
- unsigned buffer_size ;
+ size_t buffer_size ;
char *start ; /* start of valid buffer contents */
char *end ; /* end of valid buffer contents + 1 */
@@ -163,15 +165,15 @@
/*
* The Write functions
*/
-int Swrite ( int fd, const char *buf, unsigned int nbytes );
-int Sprint ( int fd, const char *format, ... )
+ssize_t Swrite ( int fd, const char *buf, size_t );
+ssize_t Sprint ( int fd, const char *format, ... )
#ifdef __GNUC__
__attribute__ ((format (printf, 2, 3)));
#else
;
#endif
int Sputchar( int fd, char c );
-int Sprintv ( int fd, const char *format, va_list ap )
+ssize_t Sprintv ( int fd, const char *format, va_list ap )
#ifdef __GNUC__
__attribute__ ((format (printf, 2, 0)));
#else
@@ -186,7 +188,7 @@
int Sclose ( int fd ) ;
int Sbuftype ( int fd, int type ) ;
int Smorefds ( int ) ;
-int __sio_converter( __sio_od_t *, int , const char *, va_list );
+ssize_t __sio_converter( __sio_od_t *, int , const char *, va_list );
int sio_setup(int fd, __sio_descriptor_t **dp, unsigned int type );
#ifdef __GNUC__

View file

@ -1,150 +0,0 @@
#!/bin/bash
#
# xinetd This starts and stops xinetd.
#
# chkconfig: 345 56 50
# description: xinetd is a powerful replacement for inetd. \
# xinetd has access control mechanisms, extensive \
# logging capabilities, the ability to make services \
# available based on time, and can place \
# limits on the number of servers that can be started, \
# among other things.
#
# processname: /usr/sbin/xinetd
# config: /etc/sysconfig/network
# config: /etc/xinetd.conf
# pidfile: /var/run/xinetd.pid
### BEGIN INIT INFO
# Provides:
# Required-Start: $network
# Required-Stop:
# Should-Start:
# Should-Stop:
# Default-Start: 3 4 5
# Default-Stop: 0 1 2 6
# Short-Description: start and stop xinetd
# Description: xinetd is a powerful replacement for inetd. \
# xinetd has access control mechanisms, extensive \
# logging capabilities, the ability to make services \
# available based on time, and can place \
# limits on the number of servers that can be started, \
# among other things.
### END INIT INFO
PATH=/sbin:/bin:/usr/bin:/usr/sbin
# Source function library.
. /etc/init.d/functions
# Get config.
test -f /etc/sysconfig/network && . /etc/sysconfig/network
# More config
test -f /etc/sysconfig/xinetd && . /etc/sysconfig/xinetd
RETVAL=0
prog="xinetd"
start(){
[ -f /usr/sbin/xinetd ] || exit 5
[ -f /etc/xinetd.conf ] || exit 6
echo -n $"Starting $prog: "
# Localization for xinetd is controlled in /etc/synconfig/xinetd
if [ -z "$XINETD_LANG" -o "$XINETD_LANG" = "none" -o "$XINETD_LANG" = "NONE" ]; then
unset LANG LC_TIME LC_ALL LC_MESSAGES LC_NUMERIC LC_MONETARY LC_COLLATE
else
LANG="$XINETD_LANG"
LC_TIME="$XINETD_LANG"
LC_ALL="$XINETD_LANG"
LC_MESSAGES="$XINETD_LANG"
LC_NUMERIC="$XINETD_LANG"
LC_MONETARY="$XINETD_LANG"
LC_COLLATE="$XINETD_LANG"
export LANG LC_TIME LC_ALL LC_MESSAGES LC_NUMERIC LC_MONETARY LC_COLLATE
fi
unset HOME MAIL USER USERNAME
daemon $prog -stayalive -pidfile /var/run/xinetd.pid "$EXTRAOPTIONS"
RETVAL=$?
echo
[ $RETVAL -eq 0 ] && touch /var/lock/subsys/xinetd
return $RETVAL
}
stop(){
[ -f /usr/sbin/xinetd ] || exit 5
[ -f /etc/xinetd.conf ] || exit 6
echo -n $"Stopping $prog: "
killproc -p /var/run/xinetd.pid $prog
RETVAL=$?
echo
[ $RETVAL -eq 0 ] && rm -f /var/lock/subsys/xinetd
return $RETVAL
}
reload(){
[ -f /usr/sbin/xinetd ] || exit 5
[ -f /etc/xinetd.conf ] || exit 6
echo -n $"Reloading configuration: "
killproc $prog -HUP
RETVAL=$?
echo
return $RETVAL
}
restart(){
stop
start
}
condrestart(){
if [ -e /var/lock/subsys/xinetd ] ; then
restart
RETVAL=$?
return $RETVAL
fi
RETVAL=0
return $RETVAL
}
# See how we were called.
case "$1" in
start)
start
RETVAL=$?
;;
stop)
stop
RETVAL=$?
;;
status)
status $prog
RETVAL=$?
;;
restart)
restart
RETVAL=$?
;;
reload|force-reload)
reload
RETVAL=$?
;;
condrestart|try-restart)
condrestart
RETVAL=$?
;;
*)
echo $"Usage: $0 {start|stop|status|restart|condrestart|reload}"
RETVAL=2
esac
exit $RETVAL

View file

@ -1,230 +0,0 @@
Summary: A secure replacement for inetd
Name: xinetd
Version: 2.3.14
Release: 22%{?dist}
License: xinetd
Group: System Environment/Daemons
Epoch: 2
URL: http://www.xinetd.org
Source: http://www.xinetd.org/xinetd-%{version}.tar.gz
Source1: xinetd.init
Source3: xinetd.sysconf
Patch0: xinetd-2.3.11-pie.patch
Patch1: xinetd-2.3.12-tcp_rpc.patch
Patch2: xinetd-2.3.14-label.patch
Patch3: xinetd-2.3.14-contextconf.patch
Patch4: xinetd-2.3.14-bind-ipv6.patch
Patch5: xinetd-2.3.14-ssize_t.patch
Patch6: xinetd-2.3.14-man-section.patch
Patch7: xinetd-2.3.11-PIE.patch
Patch8: xinetd-2.3.14-ident-bind.patch
Patch9: xinetd-2.3.14-readable-debuginfo.patch
BuildRequires: autoconf, automake
BuildRequires: libselinux-devel >= 1.30
Requires: /sbin/chkconfig /etc/init.d /sbin/service
%{!?tcp_wrappers:BuildRequires: tcp_wrappers-devel}
Requires: filesystem >= 2.0.1, initscripts, setup, fileutils
Provides: inetd
BuildRoot: %{_tmppath}/%{name}-%{version}-root
%description
Xinetd is a secure replacement for inetd, the Internet services
daemon. Xinetd provides access control for all services based on the
address of the remote host and/or on time of access and can prevent
denial-of-access attacks. Xinetd provides extensive logging, has no
limit on the number of server arguments, and lets you bind specific
services to specific IP addresses on your host machine. Each service
has its own specific configuration file for Xinetd; the files are
located in the /etc/xinetd.d directory.
%prep
%setup -q
# SPARC/SPARC64 needs -fPIE/-PIE
# This really should be detected by configure.
%ifarch sparcv9 sparc64
%patch7 -p0 -b .PIE
%else
%patch0 -p0 -b .pie
%endif
%patch1 -p1 -b .tcp_rpc
%patch2 -p1 -b .lspp
%patch3 -p1 -b .confcntx
%patch4 -p1 -b .bind
%patch5 -p1 -b .ssize_t
%patch6 -p1 -b .man-section
%patch8 -p1 -b .ident-bind
%patch9 -p1 -b .readable-debuginfo
aclocal
autoconf
%build
%configure --with-loadavg --with-inet6 %{!?tcp_wrappers:--with-libwrap} --with-labeled-networking
make
%install
rm -rf $RPM_BUILD_ROOT
mkdir -p $RPM_BUILD_ROOT/etc/rc.d/init.d
mkdir -p $RPM_BUILD_ROOT/etc/xinetd.d/
# Remove unneeded service
rm -f contrib/xinetd.d/ftp-sensor
%makeinstall DAEMONDIR=$RPM_BUILD_ROOT/usr/sbin MANDIR=$RPM_BUILD_ROOT/%{_mandir}
install -m 644 contrib/xinetd.conf $RPM_BUILD_ROOT/etc
install -m 644 contrib/xinetd.d/* $RPM_BUILD_ROOT/etc/xinetd.d
install -m 755 %SOURCE1 $RPM_BUILD_ROOT/etc/rc.d/init.d/xinetd
rm -f $RPM_BUILD_ROOT/%{_mandir}/man8/itox*
rm -f $RPM_BUILD_ROOT/usr/sbin/itox
rm -f $RPM_BUILD_ROOT/%{_mandir}/man8/xconv.pl*
rm -f $RPM_BUILD_ROOT/usr/sbin/xconv.pl
mkdir -p $RPM_BUILD_ROOT/etc/sysconfig
install -m 644 %SOURCE3 $RPM_BUILD_ROOT/etc/sysconfig/xinetd
%clean
rm -rf $RPM_BUILD_ROOT
%post
if [ $1 = 1 ]; then
/sbin/chkconfig --add xinetd
fi
%preun
if [ $1 = 0 ]; then
/sbin/service xinetd stop > /dev/null 2>&1
/sbin/chkconfig --del xinetd
fi
%postun
if [ $1 -ge 1 ]; then
/sbin/service xinetd condrestart >/dev/null 2>&1
fi
%files
%defattr(-,root,root)
%doc INSTALL CHANGELOG COPYRIGHT README xinetd/sample.conf contrib/empty.conf
%config(noreplace) /etc/xinetd.conf
%config(noreplace) /etc/sysconfig/xinetd
/etc/rc.d/init.d/xinetd
%config(noreplace) /etc/xinetd.d/*
/usr/sbin/xinetd
%{_mandir}/*/*
%changelog
* Thu Feb 26 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2:2.3.14-22
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
* Thu Sep 18 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-21
- fix glitches found during package review (#226560)
- make all files in .debuginfo package readable by everyone
* Wed Jul 16 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-20
- fix wrong bind() call (#448069)
* Thu May 29 2008 Tom "spot" Callaway <tcallawa@redhat.com> - 2:2.3.14-19
- fix sparc fPIE issues
* Thu Jan 31 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-18
- fixed LABEL flag (#430929)
* Wed Jan 30 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-17
- fixing init scripts (#430816)
* Mon Jan 28 2008 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-16
- xinetd.log man page is in the right section now (#428812)
* Thu Sep 6 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-15
- initscript made LSB compliant (#247099)
* Thu Sep 6 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-14
- removed inetdconvert script, nobody is using inetd
* Wed Aug 22 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-13
- updated license field
* Wed May 16 2007 Jan Safranek <jsafranek@redhat.com> - 2:2.3.14-12
- bind IPv6 socket by default and switch to IPv4 on error
(bz#195265)
- service xinetd status returns actual status (bz#232887)
- use ssize_t instead of int (bz#211776)
* Mon Dec 4 2006 Thomas Woerner <twoerner@redhat.com> - 2:2.3.14-11
- tcp_wrappers has a new devel and libs sub package, therefore changing build
requirement for tcp_wrappers to tcp_wrappers-devel
* Fri Dec 01 2006 James Antill <james.antill@redhat.com> - 2:2.3.14-9
- Fix getpeercon() for LABELED networking MLS environments
- Resolves: rhbz#209379
* Sun Oct 01 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.14-8
- rebuilt for unwind info generation, broken in gcc-4.1.1-21
* Wed Sep 20 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-7
- Revised labeled networking patch to not allow redirection
* Tue Aug 29 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-6
- Revised labeled networking patch again
* Thu Aug 24 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-5
- Revised labeled networking patch
* Wed Aug 23 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-4
- Added labeled networking patch
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.14-3.1
- rebuild
* Fri Jun 16 2006 Steve Grubb <sgrubb@redhat.com> 2:2.3.14-3
- Rework spec file & use xinetd's sevice config files
* Fri Mar 24 2006 Jay Fenlason <fenlason@redhat.com> 2:2.3.14-2
- Upgrade to new upstream version. This obsoletes the -libwrap,
-rpc, -banner, -bug140084 and -gcc4 patches.
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.13-6.2.1
- bump again for double-long bug on ppc(64)
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 2:2.3.13-6.2
- rebuilt for new gcc4.1 snapshot and glibc changes
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
- rebuilt
* Thu Feb 17 2005 Jay Fenlason <fenlason@redhat.com> 2:2.3.13-6
- include new patch to allow gcc4 to compile xinetd.
* Sat Jan 8 2005 Jay Fenlason <fenlason@redhat.com> 2:2.3.13-4
- Added patch committed to upstream CVS to fix bz#140084
(error logging accidentally using one of [012] as the syslog
descriptor)
* Fri Jun 18 2004 Jay Fenlason <fenlason@redhat.com> 2:2.3.13-3
- Add patch to fix #126242: banner's don't work
* Thu Jun 17 2004 Jay Fenlason <fenlason@redhat.com>
- Remove the configuration for the no-longer-present "services" service.
Closes #126169
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
- rebuilt
* Fri May 14 2004 Jay Fenlason <fenlason@redhat.com>
- Add patch to allow multiple rpc services to cooexist as long as they're
different program numbers or different versions.
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
- rebuilt
* Thu Jan 29 2004 Jay Fenlason <fenlason@redhat.com> 2.3.13-1
- Upgrade to new upstream version, which obsoletes most patches.
- Add new tcp_rpc patch, to turn on the nolibwrap flag on tcp rpc services,
since libwrap cannot be used on them.
* Sun Dec 28 2003 Florian La Roche <Florian.LaRoche@redhat.de>
- use new technology to filter python dep for inetdconvert instead
of changing the -x bit on file permissions

View file

@ -1,10 +0,0 @@
# Add extra options here
EXTRAOPTIONS=""
#
# This is the locale information that xinetd uses. It is passed to every
# server that xinetd starts. It is set to en_US to maintain compatability
# with previous Red Hat Linux releases.
#
# To remove all locale information from xinetd's environment, set
# XINETD_LANG to the empty string or the string "none".
XINETD_LANG="en_US"