|
From: Heiko Z. <smi...@us...> - 2007-04-19 15:39:26
|
Update of /cvsroot/devil-linux/build/scripts In directory sc8-pr-cvs12.sourceforge.net:/tmp/cvs-serv29723/scripts Modified Files: Python binutils busybox dbus gcc-4 glibc grsecurity grub heartbeat ipsec-tools libsafe minicom openssl sagator shorewall syslinux Log Message: lots of fixes for the security stuff Index: busybox =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/busybox,v retrieving revision 1.29 retrieving revision 1.30 diff -u -d -r1.29 -r1.30 --- busybox 3 Apr 2007 12:01:32 -0000 1.29 +++ busybox 19 Apr 2007 15:39:21 -0000 1.30 @@ -28,11 +28,11 @@ #export PATH=$(ls -d /usr/*-linux-uclibc/usr/bin):$(ls -d /usr/*-linux-uclibc/lib):$PATH cp $MYDIR/config/config_busybox .config #CROSS=$(ls -d /usr/*-linux-uclibc/bin)/i386-uclibc- - replace_str Makefile "-Wl,--gc-sections" "" + #replace_str Makefile "-Wl,--gc-sections" "" replace_str applets/applets.c "#if ENABLE_STATIC && defined(__GLIBC__) && !defined(__UCLIBC__)" "#if defined(GET_RID_OF_THIS_WARNING)" - make CROSS=$CROSS oldconfig || exit 1 - make CROSS=$CROSS dep || exit 1 - make CROSS=$CROSS $PMAKE all || exit 1 + make oldconfig || exit 1 + #make CROSS=$CROSS dep || exit 1 + make CC="gcc -D_FORTIFY_SOURCE=0" $PMAKE all || exit 1 ;; install ) Index: syslinux =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/syslinux,v retrieving revision 1.19 retrieving revision 1.20 diff -u -d -r1.19 -r1.20 --- syslinux 21 Jan 2005 01:43:52 -0000 1.19 +++ syslinux 19 Apr 2007 15:39:22 -0000 1.20 @@ -31,10 +31,10 @@ touch .done_dl_patch fi - if [ "$CONFIG_GCC_STACK_PROTECTOR" = "y" ]; then - make $PMAKE CC="gcc -fno-stack-protector" install|| exit 1 + if [ "$CONFIG_GCC_HARDENED" = "y" ]; then + make $PMAKE CC="gcc -D_FORTIFY_SOURCE=0" install || exit 1 else - make $PMAKE install|| exit 1 + make $PMAKE all install || exit 1 fi strip_debug #instal it, we need it later @@ -49,7 +49,7 @@ mkdir -p $CDDIR/boot/syslinux || exit 1 cp -v ldlinux.bss $CDDIR/boot/syslinux || exit 1 cp -v ldlinux.sys $CDDIR/boot/syslinux || exit 1 - cp -v mbr.bin $CDDIR/boot/syslinux || exit 1 + cp -v mbr/mbr.bin $CDDIR/boot/syslinux || exit 1 cp -v unix/syslinux $CDDIR/boot/syslinux || exit 1 ;; Index: grub =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/grub,v retrieving revision 1.13 retrieving revision 1.14 diff -u -d -r1.13 -r1.14 --- grub 6 Mar 2007 16:20:00 -0000 1.13 +++ grub 19 Apr 2007 15:39:21 -0000 1.14 @@ -30,10 +30,8 @@ if [ ! -f grub-patches.done ]; then touch grub-patches.done fi - if [ "$CONFIG_GCC_STACK_PROTECTOR" = "y" ]; then - CFLAGS="-Os -fno-stack-protector" - else - CFLAGS="-Os" + if [ "$CONFIG_GCC_HARDENED" = "y" ]; then + export CC="gcc -fno-stack-protector -fno-pic -fno-pie -nopie" fi CFLAGS="-static ${CFLAGS}" export CFLAGS Index: sagator =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/sagator,v retrieving revision 1.14 retrieving revision 1.15 diff -u -d -r1.14 -r1.15 --- sagator 20 Aug 2006 19:51:27 -0000 1.14 +++ sagator 19 Apr 2007 15:39:22 -0000 1.15 @@ -34,6 +34,8 @@ #export APACHE_ROOT=/etc/apache2 #[ "$CONFIG_DSPAM" = "y" ] && eval "export DSPAM=yes; export DSPAM_PREFIX=/usr" ./configure --prefix /usr || exit 1 + #replace_str libclamav/Makefile gcc "gcc -D_FORTIFY_SOURCE=0" + #replace_str pydspam/Makefile gcc "gcc -D_FORTIFY_SOURCE=0" make $PMAKE all || exit 1 strip_debug fi Index: libsafe =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/libsafe,v retrieving revision 1.2 retrieving revision 1.3 diff -u -d -r1.2 -r1.3 --- libsafe 11 Jan 2004 14:43:04 -0000 1.2 +++ libsafe 19 Apr 2007 15:39:21 -0000 1.3 @@ -26,7 +26,7 @@ case $1 in build ) if [ "$CONFIG_LIBSAFE" = "y" ]; then - make all || exit 1 + make CC="gcc -D_FORTIFY_SOURCE=0" || exit 1 strip_debug fi ;; Index: glibc =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/glibc,v retrieving revision 1.51 retrieving revision 1.52 diff -u -d -r1.51 -r1.52 --- glibc 23 Mar 2007 22:36:28 -0000 1.51 +++ glibc 19 Apr 2007 15:39:21 -0000 1.52 @@ -28,6 +28,7 @@ #cd $DL_DIR/tmp/glibc-2* || exit 1 touch /etc/ld.so.conf tar -xjf $DL_DIR/src/glibc-libidn-*tar.bz2 || exit 1 + rm -rf libidn mv glibc-libidn-* libidn || exit 1 if [ ! -f devil-linux-glibc-debian-patches.done ]; then @@ -47,18 +48,72 @@ touch devil-linux-glibc-patches.done fi - export CC="gcc -no-pie" - if [ "$CONFIG_GCC_STACK_PROTECTOR" = "y" ]; then - if [ ! -f devil-linux-glibc-ssp-patches.done ]; then - #cp -v ../glibc-ssp/ssp.c sysdeps/unix/sysv/linux/ || exit 1 - for PATCH in $(ls ../glibc-ssp/*patch) + if [ ! -f devil-linux-glibc-hardened.done ]; then + for PATCH in $(ls ../glibc-hardened/*) do echo applying patch: $PATCH patch -i $PATCH -p1 || exit 1 done - touch devil-linux-glibc-ssp-patches.done - fi - export CC="gcc -no-pie -fno-stack-protector-all" + touch devil-linux-glibc-hardened.done + fi + #export CC="gcc -no-pie" + #if [ "$CONFIG_GCC_STACK_PROTECTOR" = "y" ]; then + # if [ ! -f devil-linux-glibc-ssp-patches.done ]; then + # #cp -v ../glibc-ssp/ssp.c sysdeps/unix/sysv/linux/ || exit 1 + # for PATCH in $(ls ../glibc-ssp/*patch) + # do + # echo applying patch: $PATCH + # patch -i $PATCH -p1 || exit 1 + # done + # touch devil-linux-glibc-ssp-patches.done + # fi + # export CC="gcc -no-pie -fno-stack-protector-all" + #fi + + if [ "$CONFIG_GCC_HARDENED" = "y" ]; then + if [ ! -f .done_hardened ]; then + # all of this stuff is stolen from the HLFS book + + #Use PIC assembly code in the utility programs: + cp -vf sysdeps/unix/sysv/linux/i386/sysdep.h{,.orig} + sed 's/^# if defined I386_USE_SYSENTER$/& \&\& defined SHARED/' \ + sysdeps/unix/sysv/linux/i386/sysdep.h.orig \ + > sysdeps/unix/sysv/linux/i386/sysdep.h + + # Glibc's configure script will fail several tests because -fstack-protector[-all] and -nostdlib + # are being used together and the conftest program is not getting linked to libc.so, which causes + # the SSP symbols to be missing and the conftest test program fails. This won't be a problem after + # configure is run though. Fix configure so its tests pass correctly: + sed 's/-nostdlib/& -fno-stack-protector/g' -i.orig configure + + # The nscd program will be compiled with -fstack-protector by Glibc, but this will override + # -fstack-protector-all in our GCC specs. nscd can compile with -fstack-protector-all, so fix that: + sed 's/fstack-protector/&-all/' -i.orig nscd/Makefile + + # This next command adds the stack_chk_fail_local function to libc.so so that libc.so can be compiled + # with -fstack-protector (by the hardened GCC specs): + sed 's/^$(common-objpfx)libc.so: $(elfobjdir)\/soinit.os \\/&\ + \t\t\t $(common-objpfx)debug\/stack_chk_fail_local.oS \\/' \ + -i.orig Makerules + # These next commands add -fno-stack-protector to a few places: + sed 's/^CPPFLAGS += -DHAVE_INITFINI/& -fno-stack-protector/' \ + -i.orig csu/Makefile + sed 's/^CPPFLAGS-.os +=/& -fno-stack-protector/' \ + -i.orig elf/Makefile + sed 's/^CFLAGS-rtld :=/& -fno-stack-protector/' \ + -i.orig elf/rtld-Rules + sed -e 's/^CFLAGS-init.c =/& -fno-stack-protector/' \ + -e 's/^CFLAGS-unwind.* =/& -fno-stack-protector/' \ + -i nptl/Makefile + # Add MUDFLAP_OPTIONS to the list of environment variables which are removed by libc for suid programs. + # This will keep local users, including root, from disabling bounds checking on suid programs linked to libmudflap.so: + sed 's/#define UNSECURE_ENVVARS.*/&\ + "MUDFLAP_OPTIONS\\0" \\/' -i.orig sysdeps/generic/unsecvars.h + + # Add -nonow to CC so the testsuite will have better results. When Glibc's build uses -Wl,-z,now it will supersede this -nonow option: + sed 's/^CC =.*/& -nonow/' -i.orig config.make + touch .done_hardened + fi fi rm -rf ../glibc-build @@ -70,7 +125,7 @@ #../glibc-2*/configure --prefix=/usr --disable-profile --enable-add-ons --libexecdir=/usr/bin \ # -without-cvs --enable-bind-now || exit 1 ../glibc-2*/configure --prefix=/usr --disable-profile --enable-add-ons --libexecdir=/usr/lib/glibc \ - --enable-kernel=2.6.0 || exit 1 + --enable-kernel=2.6.0 --enable-bind-now --enable-stackguard-randomization || exit 1 make $PMAKE || exit 1 strip_debug || exit 1 Index: minicom =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/minicom,v retrieving revision 1.7 retrieving revision 1.8 diff -u -d -r1.7 -r1.8 --- minicom 13 Dec 2004 16:41:11 -0000 1.7 +++ minicom 19 Apr 2007 15:39:21 -0000 1.8 @@ -29,7 +29,7 @@ build ) if [ "$CONFIG_MINICOM" = "y" ]; then ./configure --prefix=/usr --sysconfdir=/etc --disable-nls || exit 1 - make $PMAKE all || exit 1 + make CC="gcc -D_FORTIFY_SOURCE=0" $PMAKE all || exit 1 strip_debug fi ;; Index: grsecurity =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/grsecurity,v retrieving revision 1.28 retrieving revision 1.29 diff -u -d -r1.28 -r1.29 --- grsecurity 29 Sep 2005 16:07:21 -0000 1.28 +++ grsecurity 19 Apr 2007 15:39:21 -0000 1.29 @@ -30,7 +30,8 @@ if [ "$CONFIG_GRSECURITY" = "y" ] ; then cd $KERNELDIR if [ ! -f devil-linux-grsec-kernel-patches.done ]; then - zcat $DL_DIR/src/grsecurity-2.*$CONFIG_LINUX_VERSION*.patch.gz | sed -e 's/EXTRAVERSION = -as2/EXTRAVERSION = -as3/' -e 's/NAME=Woozy Numbat + fixes/NAME=Rocket/' | patch -p1 + bzcat $DL_DIR/src/grsecurity-2.*$CONFIG_LINUX_VERSION*.patch.bz2 | sed -e 's/EXTRAVERSION = -as2/EXTRAVERSION = -as3/' -e 's/NAME=Woozy Numbat + fixes/NAME=Rocket/' | patch -p1 + bzcat $DL_DIR/src/grsecurity-2.*$CONFIG_LINUX_VERSION*.patch.bz2 | patch -p1 touch devil-linux-grsec-kernel-patches.done fi # add configuration to kernel config Index: openssl =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/openssl,v retrieving revision 1.24 retrieving revision 1.25 diff -u -d -r1.24 -r1.25 --- openssl 12 Dec 2004 21:48:08 -0000 1.24 +++ openssl 19 Apr 2007 15:39:21 -0000 1.25 @@ -27,7 +27,7 @@ case $1 in build ) - ./Configure linux-elf shared threads zlib --prefix=/usr --openssldir=/etc/ssl || exit 1 + ./Configure linux-elf shared threads zlib-dynamic --prefix=/usr --openssldir=/etc/ssl || exit 1 make depend || exit 1 # openssl 0.9.7 doesn't like the parallel builds :-(( Index: Python =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/Python,v retrieving revision 1.22 retrieving revision 1.23 diff -u -d -r1.22 -r1.23 --- Python 29 Dec 2004 03:14:12 -0000 1.22 +++ Python 19 Apr 2007 15:39:21 -0000 1.23 @@ -36,8 +36,10 @@ strip_debug # we need to install it, because Python-LDAP needs it make install || exit 1 - ln -sf python2.3 $WORKDIR/Python-install/usr/bin/python || exit 1 - ln -sf python2.3 $WORKDIR/Python-install/usr/bin/python2 || exit 1 + #ln -sf python2.5 $WORKDIR/Python-install/usr/bin/python || exit 1 + #ln -sf python2.5 $WORKDIR/Python-install/usr/bin/python2 || exit 1 + ln -sf python2.4 $WORKDIR/Python-install/usr/bin/python || exit 1 + ln -sf python2.4 $WORKDIR/Python-install/usr/bin/python2 || exit 1 mkdir -p $WORKDIR/Python-install/usr/share mv $WORKDIR/Python-install/usr/man $WORKDIR/Python-install/usr/share cp -dpR $WORKDIR/Python-install/* / || exit 1 Index: ipsec-tools =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/ipsec-tools,v retrieving revision 1.7 retrieving revision 1.8 diff -u -d -r1.7 -r1.8 --- ipsec-tools 22 Feb 2007 13:43:16 -0000 1.7 +++ ipsec-tools 19 Apr 2007 15:39:21 -0000 1.8 @@ -32,7 +32,7 @@ case $1 in build ) ./bootstrap - ./configure --prefix=/usr --sysconfdir=/etc/ipsec-tools --with-kernel-headers=/usr/include \ + CC="gcc -D_FORTIFY_SOURCE=0" ./configure --prefix=/usr --sysconfdir=/etc/ipsec-tools --with-kernel-headers=/usr/include \ --enable-frag --enable-stats --enable-dpd --enable-natt || exit 1 make || exit 1 make install || exit 1 Index: gcc-4 =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/gcc-4,v retrieving revision 1.1 retrieving revision 1.2 diff -u -d -r1.1 -r1.2 --- gcc-4 23 Mar 2007 22:37:04 -0000 1.1 +++ gcc-4 19 Apr 2007 15:39:21 -0000 1.2 @@ -28,10 +28,7 @@ case $1 in build ) CONFIG_EXTRA="" - #if [ "$CONFIG_GCC_STACK_PROTECTOR" = "y" ]; then - # that's already part of gcc-4 - # but gcc-3 needs to do it to - #fi + EXTRA_OPTIONS="" if [ ! -f gcc-patches.done ]; then #echo "applying gcc patches" @@ -46,6 +43,93 @@ sed -i 's@\./fixinc\.sh@-c true@' gcc/Makefile.in sed -i 's/@have_mktemp_command@/yes/' gcc/gccbug.in + if [ "$CONFIG_GCC_HARDENED" = "y" ]; then + # and now make sure we use SSP and other stuff when compiling + # thanks to Robert Connolly and the HLFS project + + #The following file redefines GCC's default behaviour to add various options: +echo '#ifndef HARDENED_SPECS_H +#define HARDENED_SPECS_H + +#if defined(__i386__) && defined(__linux__) && defined(__ELF__) \ + && defined(HAVE_LD_PIE) && defined(TARGET_LIBC_PROVIDES_SSP) + +#undef CPP_SPEC +#define CPP_SPEC "%{posix:-D_POSIX_SOURCE} %{pthread:-D_REENTRANT} \ + %{D_FORTIFY_SOURCE*|D_LIBC_REENTRANT:;:-D_FORTIFY_SOURCE=2}" + +#undef CC1_SPEC +#define CC1_SPEC "%(cc1_cpu) %{profile:-p} \ + %{D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pic|fno-PIC \ + :;shared|nostdlib|nostartfiles:-fPIC} \ + %{static|D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pie|fno-PIE| \ + shared|nostdlib|nostartfiles:;:-fPIE} \ + %{D__KERNEL__|fno-stack-protector|fstack-protector| \ + fstack-protector-all:;D_LIBC_REENTRANT:-fstack-protector;: \ + -fstack-protector-all} %{D_FORTIFY_SOURCE*|D_LIBC_REENTRANT|O*:;:-O}" + +#undef CC1PLUS_SPEC +#define CC1PLUS_SPEC \ + "%{D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pic|fno-PIC \ + :;shared|nostdlib|nostartfiles:-fPIC} \ + %{static|D__KERNEL__|fpic|fPIC|fpie|fPIE|fno-pie|fno-PIE| \ + shared|nostdlib|nostartfiles:;:-fPIE} \ + %{D__KERNEL__|fno-stack-protector|fstack-protector| \ + fstack-protector-all:;D_LIBC_REENTRANT:-fstack-protector;: \ + -fstack-protector-all} %{D_FORTIFY_SOURCE*|D_LIBC_REENTRANT|O*:;:-O}" + +#undef ENDFILE_SPEC +#define ENDFILE_SPEC "%{ffast-math|funsafe-math-optimizations: \ + crtfastmath.o%s} \ + %{static|nopie:crtend.o%s;:crtendS.o%s} crtn.o%s" + +#undef STARTFILE_SPEC +#define STARTFILE_SPEC "%{shared:;pg|p|profile:gcrt1.o%s; \ + static|nopie:crt1.o%s;:Scrt1.o%s} crti.o%s \ + %{static:crtbeginT.o%s;nopie:crtbegin.o%s;:crtbeginS.o%s}" + +#undef LINK_PIE_SPEC +#define LINK_PIE_SPEC "%{pie:-pie} %{!static:%{!Bstatic: \ + %{nonow:-z lazy;:-z now} %{norelro:-z norelro;:-z relro} \ + %{nocombreloc:-z nocombreloc;:-z combreloc} \ + %{shared|Bshareable|i|r|pie|nopie:;:-pie}}}" + +#else /* __i386__ && __linux__ && __ELF__ && HAVE_LD_PIE */ +#error "You are using an unsupported system. This header can not be used." +#endif /* __i386__ && __linux__ && __ELF__ && HAVE_LD_PIE */ +#endif /* HARDENED_SPECS_H */' > gcc/hardened-specs.h + + #This command includes the hardened-specs header in the right place: + cp -vi gcc/gcc.c{,.orig} + sed '0,/.*config.h can define.*/s//#include "hardened-specs.h"\n&/' \ + gcc/gcc.c.orig > gcc/gcc.c + + # Don't build libssp.[a,so] with -fstack-protector[-all]. This library + # won't be used but will be built and installed: + cp -vi libssp/Makefile.in{,.orig} + sed 's/^AM_CFLAGS =/& -fno-stack-protector/' \ + libssp/Makefile.in.orig > libssp/Makefile.in + + # Don't build libgcc.[a,so] with -fstack-protector[-all]. libgcc.a is often linked into + # other static libraries and they will fail to resolve __stack_chk symbols: + cp -vi gcc/Makefile.in{,.orig3} + sed 's/^LIBGCC2_CFLAGS =/& -fno-stack-protector/' \ + gcc/Makefile.in.orig3 > gcc/Makefile.in + + # Don't build crtbegin[,S,T].o or crtend[,S].o files with -fstack-protector[-all]. These libraries should be + # devoid of dependencies (including the depenency to libc for SSP functions): + cp -vi gcc/Makefile.in{,.orig4} + sed 's/^CRTSTUFF_CFLAGS =/& -fno-stack-protector/' \ + gcc/Makefile.in.orig4 > gcc/Makefile.in + + sed 's/violation_mode = viol_nop/violation_mode = viol_abort/' \ + -i.orig libmudflap/mf-runtime.c + + # + EXTRAOPTIONS="$EXTRAOPTIONS gcc_cv_libc_provides_ssp=yes" + CONFIG_EXTRA="$CONFIG_EXTRA --disable-werror" + fi + rm -rf ../gcc4-build mkdir ../gcc4-build || exit 1 cd ../gcc4-build || exit 1 @@ -53,18 +137,12 @@ ../gcc-4*/configure --prefix=/usr --localstatedir=/var --enable-shared --enable-CONFIG_SHELL=/bin/bash \ --enable-threads=posix --libexecdir=/usr/lib --enable-__cxa_atexit --enable-clocale=gnu \ --enable-languages=c,c++,objc --disable-nls --with-gnu-ld $CONFIG_EXTRA $CONF_HOST || exit 1 - make MAKE="make $PMAKE" $PMAKE bootstrap || exit 1 + make MAKE="make $PMAKE" $PMAKE $EXTRAOPTIONS || exit 1 strip_debug # install it, so we use the same version everywhere - make install-no-fixedincludes || exit 1 + make install || exit 1 - #if [ "$CONFIG_GCC_STACK_PROTECTOR" = "y" ]; then - # and now make sure we use SSP when compiling - # thanks to Robert Connolly - - # we disable all of this for now until we get through compiling everything with the standard settings - #fi ;; Index: binutils =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/binutils,v retrieving revision 1.14 retrieving revision 1.15 diff -u -d -r1.14 -r1.15 --- binutils 30 Sep 2005 02:17:26 -0000 1.14 +++ binutils 19 Apr 2007 15:39:21 -0000 1.15 @@ -27,25 +27,28 @@ case $1 in build ) # Apply additional Linux patches. - if [ ! -f binutils-patches.done ]; then - /bin/sh patches/README - bzcat $DL_DIR/src/binutils-2*-pt_pax-*.patch.bz2 | patch -p1 || exit 1 - touch binutils-patches.done - fi + if [ ! -f binutils-patches.done ]; then + for PATCH in $(ls ../binutils-patches/*) + do + echo applying patch: $PATCH + patch -i $PATCH -p1 || exit 1 + done + touch binutils-patches.done + fi rm -rf $WORKDIR/binutils-build mkdir $WORKDIR/binutils-build || exit 1 cd $WORKDIR/binutils-build || exit 1 - mkdir bfd || exit 1 - cd bfd - $WORKDIR/binutils-2*/bfd/configure --disable-nls || exit 1 - cd .. || exit 1 + #mkdir bfd || exit 1 + #cd bfd + #$WORKDIR/binutils-2*/bfd/configure --disable-nls || exit 1 + #cd .. || exit 1 - make headers -C bfd || exit 1 + #make headers -C bfd || exit 1 $WORKDIR/binutils-2*/configure --prefix=/usr --localstatedir=/var --enable-shared || exit 1 - make tooldir=/usr $PMAKE all || exit 1 + make tooldir=/usr all || exit 1 strip_debug # install it and make sure the system uses this version Index: heartbeat =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/heartbeat,v retrieving revision 1.10 retrieving revision 1.11 diff -u -d -r1.10 -r1.11 --- heartbeat 10 Jan 2007 02:12:00 -0000 1.10 +++ heartbeat 19 Apr 2007 15:39:21 -0000 1.11 @@ -32,9 +32,9 @@ SNMP="--disable-snmp" fi - ./configure --prefix=/usr --localstatedir=/var --sysconfdir=/etc ${SNMP} || exit 1 + CFLAGS="-D_FORTIFY_SOURCE=0" ./configure --prefix=/usr --localstatedir=/var --sysconfdir=/etc ${SNMP} || exit 1 - make $PMAKE all || exit 1 + make $PMAKE all || exit 1 strip_debug fi ;; Index: dbus =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/dbus,v retrieving revision 1.2 retrieving revision 1.3 diff -u -d -r1.2 -r1.3 --- dbus 21 Mar 2007 13:34:34 -0000 1.2 +++ dbus 19 Apr 2007 15:39:21 -0000 1.3 @@ -49,7 +49,7 @@ copy_docs $TMPDIR/usr || exit 1 copy_files $TMPDIR/etc $ETCDIR/ || exit 1 rm -rf $TMPDIR/etc || exit 1 - copy_files $TMPDIR/ $CDDIR/ || exit 1 + copy_files $TMPDIR/* $CDDIR/ || exit 1 rm -rf $TMPDIR || exit 1 Index: shorewall =================================================================== RCS file: /cvsroot/devil-linux/build/scripts/shorewall,v retrieving revision 1.7 retrieving revision 1.8 diff -u -d -r1.7 -r1.8 --- shorewall 12 Dec 2004 21:48:09 -0000 1.7 +++ shorewall 19 Apr 2007 15:39:22 -0000 1.8 @@ -46,6 +46,8 @@ copy_files $TMPDIR/sbin $CDDIR || exit 1 copy_files $TMPDIR/usr/share/shorewall $CDDIR/usr/share || exit 1 copy_files $TMPDIR/etc/shorewall $ETCDIR/etc || exit 1 + mv $CDDIR/usr/share/shorewall/modules $ETCDIR/etc/shorewall/ || exit 1 + ln -sf /etc/shorewall/modules $CDDIR/usr/share/shorewall/modules || exit 1 # Copy the shorewall documentation onto the cd # never versions don't seem to have the documentation included anymore |