pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
CVS commit: pkgsrc/security/fail2ban
Module Name: pkgsrc
Committed By: adam
Date: Tue Sep 22 12:04:33 UTC 2026
Modified Files:
pkgsrc/security/fail2ban: Makefile PLIST distinfo
Added Files:
pkgsrc/security/fail2ban: config.mk
Log Message:
fail2ban: updated to 1.1.1
1.1.1
Compatibility
action.d/iptables.conf rewritten due to support of multiple chains (gh-3909), therefore user-level derivations (action including iptables-based action) may become incompatible, e. g. some tags if
used need to be replaced, e. g. <chain> with $chain or <_ipt_for_proto-iter> with <_ipt-iter>;
filter.d/exim.conf - several rules of mode normal moved to new mode more, because of too risky handling (see gh-3940), to use it as before set mode = more for exim jail, but be aware of the
consequences.
Fixes
fixes catastrophic backtracking explosion for REs in domino-smtp and dovecot filters (GHSA-33wh-ccjc-p397, gh-4221)
fixes systemd bug with missing journal descriptor after rotation by reopening of journal if it is recognized as not alive (gh-3929)
improve threaded clean-up of all filters, new thread functions afterStop (to force clean-up after stop) and done, invoking afterStop once
ensure journal-reader is always closed (additional prevention against leaks and "too many open files"), thereby avoid sporadic segfault in systemd module
fixes systemd causing "too many open files" error for a lot of journal files and large amount of systemd jails (see new parameter rotated below, gh-3391);
passing of arguments from jails to action or filter will affect conditional section too (gh-4069), e. g. setting blocktype="DROP" via jail for action would now apply for IPv4 and IPv6 chains, to
submit different blocktype for IPv4 and IPv6 from jail, one can pass them like in this example: banaction = iptables-ipset[blocktype="...", blocktype?family=inet6="..."]
jail.conf:
default banactions need to be specified in paths-*.conf (maintainer level) now
since stock fail2ban includes paths-debian.conf by default, banactions are nftables (can be overwritten in jail.local by user)
paths-common.conf:
changed default mysql_log path (default logpath of mysqld-auth jail without maintainer overrides, gh-3932)
paths-debian.conf:
default banactions are nftables
sshd backend switched to systemd (gh-3292)
postfix backend switched to systemd (gh-3527)
action.d/firewallcmd-ipset.conf:
rename ipsettype to ipsetbackend (gh-2620), parameter ipsettype will be used now to the real set type (gh-3760)
action.d/nftables.conf:
action fixed for SELinux without execmem permission, rewrite capturing with grep -P using grep -E or sed (PCRE-JIT by grep -P may cause SELinux denial for execmem, see gh-4137)
action.d/xarf-login-attack.conf - ignore errors or warnings in output of dig provided as comment (gh-4068)
filter.d/apache-badbots.conf, filter.d/apache-fakegooglebot.conf:
regexs rewritten more strict (removed catch-alls, etc);
regexs fixed to match lines with vhost in accesslog (gh-1594)
filter.d/apache-noscript.conf - consider new log-format with "AH02811: stderr from /..." (gh-3900)
filter.d/apache-overflows.conf - consider AH10244: invalid URI path (gh-3778, gh-3900)
filter.d/asterisk.conf - fixed RE for "no matching endpoint" with retry info (like after X tries in Y ms) at end, loosening of end anchor (ignore any simple text tokens at end if no single quote
found), gh-4037
filter.d/exim.conf:
several rules of mode normal moved to new mode more, because of too risky handling (gh-3940), thereby mode aggressive is not affected, because it fully includes mode more now;
mode aggressive extended to catch dropped by ACL failures, e.g. "ACL: Country is banned"
filter.d/freeswitch.conf - bypass some new info in prefix before [WARNING] (changed default _pref_line), FreeSWITCH log line prefix has changed in newer versions (gh-3143)
filter.d/lighttpd-auth.conf - fixed regex (if failures generated by systemd-journal), bypass several prefixes now (gh-3955)
filter.d/postfix.conf:
extended prefregex to capture username in postfix SASL failures (gh-4165)
consider CONNECT and other rejected commands as a valid _pref (gh-3800)
default _daemon in prefix-line is loosened - can match everything starting with word postfix, like postfix-example.com/smtpd (gh-3297)
add optional NOQUEUE: prefix to ddos regex (gh-4072)
internal parameter _pref is renamed to _cmd, _pref matches now optional prefix like NOQUEUE: etc
modes ddos and aggressive extended to match rate limit exceeded for connection or message delivery request rates (gh-3265, gh-4073)
modes aggressive extended to match hostname does not resolve to address (gh-4218, gh-4078)
filter.d/dropbear.conf:
recognizes extra pid/timestamp if logged into stdout/journal, added journalmatch (gh-3597)
failregex extended to match different format of "Exit before auth" message (gh-3791)
filter.d/recidive.conf - restore possibility to set jail name in the filter, _jailname is positive now (gh-3769)
filter.d/roundcube-auth.conf - improved RE better matching log format of roundcube version 1.4+ (gh-3816)
filter.d/sendmail-reject.conf: (gh-4020)
support <F-MLFID> for BSD-style logfiles
add match for User unknown to default
the relay field may not always have a hostname before the ip address
mode aggressive enables match for lost input channel and Cannot resolve PTR record
filter.d/sshd.conf:
adapted to conform possible new daemon name sshd-session, since OpenSSH 9.8 several log messages will be tagged with as originating from a process named "sshd-session" rather than "sshd" (gh-3782)
ddos and aggressive modes: regex extended for timeout before authentication (optional connection from part, gh-3907)
filter.d/vsftpd.conf - fixed regex (if failures generated by systemd-journal, gh-3954)
filter.d/froxlor-auth.conf - updated the regex to the new logging situation for froxlor and changed logpath in jail.conf (gh-4075).
To generate a diff of this commit:
cvs rdiff -u -r1.34 -r1.35 pkgsrc/security/fail2ban/Makefile
cvs rdiff -u -r1.9 -r1.10 pkgsrc/security/fail2ban/PLIST
cvs rdiff -u -r0 -r1.1 pkgsrc/security/fail2ban/config.mk
cvs rdiff -u -r1.10 -r1.11 pkgsrc/security/fail2ban/distinfo
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: pkgsrc/security/fail2ban/Makefile
diff -u pkgsrc/security/fail2ban/Makefile:1.34 pkgsrc/security/fail2ban/Makefile:1.35
--- pkgsrc/security/fail2ban/Makefile:1.34 Tue Jan 6 11:18:16 2026
+++ pkgsrc/security/fail2ban/Makefile Tue Sep 22 12:04:33 2026
@@ -1,50 +1,38 @@
-# $NetBSD: Makefile,v 1.34 2026/01/06 11:18:16 wiz Exp $
+# $NetBSD: Makefile,v 1.35 2026/09/22 12:04:33 adam Exp $
-DISTNAME= fail2ban-1.0.2
-PKGREVISION= 2
+DISTNAME= fail2ban-1.1.1
CATEGORIES= security
MASTER_SITES= ${MASTER_SITE_GITHUB:=fail2ban/}
MAINTAINER= nils%NetBSD.org@localhost
-HOMEPAGE= http://www.fail2ban.org/
+HOMEPAGE= https://github.com/fail2ban/fail2ban
COMMENT= Scans log files and bans IP that makes too many password failures
LICENSE= gnu-gpl-v2
-TOOL_DEPENDS+= ${PYPKGPREFIX}-numpydoc-[0-9]*:../../textproc/py-numpydoc
-TOOL_DEPENDS+= ${PYPKGPREFIX}-sphinx-[0-9]*:../../textproc/py-sphinx
-
-PYTHON_VERSIONS_ACCEPTED= 312 # needs 2to3 and sphinx
+TOOL_DEPENDS+= ${PYPKGPREFIX}-numpydoc>=0:../../textproc/py-numpydoc
+TOOL_DEPENDS+= ${PYPKGPREFIX}-sphinx>=0:../../textproc/py-sphinx
+USE_LANGUAGES= # none
USE_TOOLS+= make:build
-USE_LANGUAGES= # none
+CHECK_INTERPRETER_SKIP+= ${PYSITELIB}/fail2ban/tests/files/config/apache-auth/digest.py
+CHECK_INTERPRETER_SKIP+= ${PYSITELIB}/fail2ban/tests/files/ignorecommand.py
+
EGDIR= ${PREFIX}/share/examples/fail2ban
PKG_SYSCONFSUBDIR= fail2ban
DOCDIR= ${PREFIX}/share/doc/fail2ban
-OWN_DIRS= ${PKG_SYSCONFDIR} ${PKG_SYSCONFDIR}/action.d/ ${PKG_SYSCONFDIR}/filter.d/ \
+OWN_DIRS= ${PKG_SYSCONFDIR} ${PKG_SYSCONFDIR}/action.d ${PKG_SYSCONFDIR}/filter.d \
${VARBASE}/run/fail2ban ${VARBASE}/db/fail2ban
-INSTALLATION_DIRS+= ${PKGMANDIR}/man1/ ${PKGMANDIR}/man5/ ${EGDIR} ${EGDIR}/action.d/ ${EGDIR}/filter.d/ ${EGDIR}/filter.d/ignorecommands/ \
- ${PKG_SYSCONFDIR} ${PKG_SYSCONFDIR}/action.d/ ${PKG_SYSCONFDIR}/filter.d/ ${PKG_SYSCONFDIR}/filter.d/ignorecommands/ \
- ${DOCDIR}
+INSTALLATION_DIRS+= ${DOCDIR} ${PKGMANDIR}/man1 ${PKGMANDIR}/man5
-.for config in paths-arch.conf paths-common.conf paths-debian.conf paths-fedora.conf paths-freebsd.conf paths-opensuse.conf paths-osx.conf paths-netbsd.conf fail2ban.conf jail.conf paths-pkgsrc.conf
-CONF_FILES+= ${EGDIR}/${config} ${PKG_SYSCONFDIR}/${config}
-.endfor
+.include "config.mk"
-.for action in abuseipdb.conf apf.conf blocklist_de.conf bsd-ipfw.conf cloudflare.conf complain.conf dshield.conf dummy.conf firewallcmd-allports.conf firewallcmd-common.conf firewallcmd-ipset.conf
firewallcmd-multiport.conf firewallcmd-new.conf firewallcmd-rich-logging.conf firewallcmd-rich-rules.conf helpers-common.conf hostsdeny.conf ipfilter.conf ipfw.conf iptables-allports.conf
iptables-ipset-proto4.conf iptables-ipset-proto6-allports.conf iptables-ipset-proto6.conf iptables-ipset.conf iptables-multiport-log.conf iptables-multiport.conf iptables-new.conf
iptables-xt_recent-echo.conf iptables.conf mail-buffered.conf mail-whois-common.conf mail-whois-lines.conf mail-whois.conf mail.conf mynetwatchman.conf netscaler.conf nftables-allports.conf
nftables-multiport.conf nftables.conf nginx-block-map.conf npf.conf nsupdate.conf osx-afctl.conf osx-ipfw.conf pf.conf route.conf sendmail-buffered.conf sendmail-common.conf sendmail-geoip-lines.conf
sendmail-whois-ipjailmatches.conf sendmai
l-whois-ipmatches.conf sendmail-whois-lines.conf sendmail-whois-matches.conf sendmail-whois.conf sendmail.conf shorewall-ipset-proto6.conf shorewall.conf smtp.py symbiosis-blacklist-allports.conf
ufw.conf xarf-login-attack.conf
-CONF_FILES+= ${EGDIR}/action.d/${action} ${PKG_SYSCONFDIR}/action.d/${action}
+.for f in ${EGFILES}
+CONF_FILES+= ${EGDIR}/${f} ${PKG_SYSCONFDIR}/${f}
.endfor
+TXTDOCFILES+= develop.txt fail2ban.client.actionreader.txt fail2ban.client.beautifier.txt fail2ban.client.configparserinc.txt fail2ban.client.configreader.txt
fail2ban.client.configurator.txt fail2ban.client.csocket.txt fail2ban.client.fail2banreader.txt fail2ban.client.filterreader.txt fail2ban.client.jailreader.txt fail2ban.client.jailsreader.txt
fail2ban.client.txt fail2ban.exceptions.txt fail2ban.helpers.txt fail2ban.protocol.txt fail2ban.txt fail2ban.server.action.txt fail2ban.server.actions.txt fail2ban.server.asyncserver.txt
fail2ban.server.banmanager.txt fail2ban.server.database.txt fail2ban.server.datedetector.txt fail2ban.server.datetemplate.txt fail2ban.server.failmanager.txt fail2ban.server.failregex.txt
fail2ban.server.filter.txt fail2ban.server.filterpoll.txt fail2ban.server.filterpyinotify.txt fail2ban.server.filtersystemd.txt fail2ban.server.jail.txt fail2ban.server.jails.txt
fail2ban.server.jailthread.txt fail2ban.server.mytime.txt fail2ban.server.txt fail2ban.serv
er.server.txt fail2ban.server.strptime.txt fail2ban.server.ticket.txt fail2ban.server.transmitter.txt fail2ban.server.utils.txt fail2ban.version.txt filters.txt index.txt release.txt
-.for filter in 3proxy.conf apache-auth.conf apache-badbots.conf apache-botsearch.conf apache-common.conf apache-modsecurity.conf apache-nohome.conf apache-noscript.conf apache-overflows.conf
apache-pass.conf apache-shellshock.conf assp.conf asterisk.conf bitwarden.conf botsearch-common.conf centreon.conf common.conf counter-strike.conf courier-auth.conf courier-smtp.conf cyrus-imap.conf
directadmin.conf domino-smtp.conf dovecot.conf dropbear.conf drupal-auth.conf ejabberd-auth.conf exim-common.conf exim-spam.conf exim.conf freeswitch.conf froxlor-auth.conf groupoffice.conf
gssftpd.conf guacamole.conf haproxy-http-auth.conf horde.conf kerio.conf lighttpd-auth.conf mongodb-auth.conf monit.conf murmur.conf mysqld-auth.conf nagios.conf named-refused.conf
nginx-botsearch.conf nginx-http-auth.conf nginx-limit-req.conf nsd.conf openhab.conf openwebmail.conf oracleims.conf pam-generic.conf perdition.conf php-url-fopen.conf phpmyadmin-syslog.conf
portsentry.conf postfix.conf proftpd.conf pur
e-ftpd.conf qmail.conf recidive.conf roundcube-auth.conf screensharingd.conf selinux-common.conf selinux-ssh.conf sendmail-auth.conf sendmail-reject.conf sieve.conf slapd.conf sogo-auth.conf
solid-pop3d.conf squid.conf squirrelmail.conf sshd.conf stunnel.conf suhosin.conf tine20.conf traefik-auth.conf uwimap-auth.conf vsftpd.conf webmin-auth.conf wuftpd.conf xinetd-fail.conf
znc-adminlog.conf zoneminder.conf
-CONF_FILES+= ${EGDIR}/filter.d/${filter} ${PKG_SYSCONFDIR}/filter.d/${filter}
-.endfor
-
-CONF_FILES+= ${EGDIR}/filter.d/ignorecommands/apache-fakegooglebot ${PKG_SYSCONFDIR}/filter.d/ignorecommands/apache-fakegooglebot
-
-TXTDOCFILES+= develop.txt fail2ban.client.actionreader.txt fail2ban.client.beautifier.txt fail2ban.client.configparserinc.txt fail2ban.client.configreader.txt
fail2ban.client.configurator.txt fail2ban.client.csocket.txt fail2ban.client.fail2banreader.txt fail2ban.client.filterreader.txt fail2ban.client.jailreader.txt fail2ban.client.jailsreader.txt
fail2ban.client.txt fail2ban.exceptions.txt fail2ban.helpers.txt fail2ban.protocol.txt fail2ban.txt fail2ban.server.action.txt fail2ban.server.actions.txt fail2ban.server.asyncserver.txt
fail2ban.server.banmanager.txt fail2ban.server.database.txt fail2ban.server.datedetector.txt fail2ban.server.datetemplate.txt fail2ban.server.failmanager.txt fail2ban.server.failregex.txt
fail2ban.server.filter.txt fail2ban.server.filtergamin.txt fail2ban.server.filterpoll.txt fail2ban.server.filterpyinotify.txt fail2ban.server.filtersystemd.txt fail2ban.server.jail.txt
fail2ban.server.jails.txt fail2ban.server.jailthread.txt fail2ban.server.mytime.txt f
ail2ban.server.txt fail2ban.server.server.txt fail2ban.server.strptime.txt fail2ban.server.ticket.txt fail2ban.server.transmitter.txt fail2ban.server.utils.txt fail2ban.version.txt filters.txt
index.txt release.txt
-
-AUTO_MKDIRS= yes
MANPAGES1= fail2ban-client.1 fail2ban-regex.1 fail2ban-server.1 fail2ban-testcases.1 fail2ban.1
MANPAGES5= jail.conf.5
@@ -56,14 +44,13 @@ RCD_SCRIPTS= fail2ban
SUBST_CLASSES+= paths
SUBST_STAGE.paths= pre-configure
SUBST_MESSAGE.paths= Substituting paths variables.
-SUBST_FILES.paths= fail2ban/client/*.py
+SUBST_FILES.paths= config/fail2ban.conf
+SUBST_FILES.paths+= config/jail.conf
+SUBST_FILES.paths+= config/paths-pkgsrc.conf
+SUBST_FILES.paths+= fail2ban/client/*.py
SUBST_FILES.paths+= fail2ban/tests/utils.py
SUBST_FILES.paths+= man/fail2ban-client.1
SUBST_FILES.paths+= man/fail2ban-client.h2m
-SUBST_FILES.paths+= setup.py
-SUBST_FILES.paths+= config/fail2ban.conf
-SUBST_FILES.paths+= config/jail.conf
-SUBST_FILES.paths+= config/paths-pkgsrc.conf
SUBST_SED.paths= -e 's,/etc,${PREFIX}/etc,g'
SUBST_SED.paths+= -e 's,/var/lib,${VARBASE}/db,g'
SUBST_SED.paths+= -e 's,/var,${VARBASE},g'
@@ -71,12 +58,6 @@ SUBST_SED.paths+= -e 's,/usr/share,${PRE
SUBST_SED.paths+= -e 's,paths-debian.conf,paths-pkgsrc.conf,g'
SUBST_VARS.paths= VARBASE
-SUBST_CLASSES+= install
-SUBST_STAGE.install= pre-install
-SUBST_MESSAGE.install= correcting installation path
-SUBST_FILES.install= setup.py
-SUBST_SED.install= -e 's,${PREFIX}/etc/fail2ban,${EGDIR},g'
-
.include "../../mk/bsd.prefs.mk"
SUBST_CLASSES+= ostype
@@ -98,13 +79,11 @@ post-extract:
${CP} ${FILESDIR}/paths-netbsd.conf ${WRKSRC}/config/paths-netbsd.conf
${CP} ${FILESDIR}/paths-pkgsrc.conf ${WRKSRC}/config/paths-pkgsrc.conf
-pre-patch:
- cd ${WRKSRC}/ && ${PREFIX}/bin/2to3-${PYVERSSUFFIX} --no-diffs --write --nobackups --fix=all bin/* fail2ban
-
post-build:
- cd ${WRKSRC}/doc/ && make SPHINXBUILD=${PREFIX}/bin/sphinx-build-${PYVERSSUFFIX} text
+ cd ${WRKSRC}/doc/ && ${MAKE} SPHINXBUILD=${PREFIX}/bin/sphinx-build-${PYVERSSUFFIX} text
post-install:
+ ${MV} ${DESTDIR}${PREFIX}/${PYSITELIB}/etc/fail2ban ${DESTDIR}${EGDIR}
.for manfile1 in ${MANPAGES1}
${INSTALL_MAN} ${WRKSRC}/man/${manfile1} ${DESTDIR}${PREFIX}/${PKGMANDIR}/man1/
.endfor
@@ -121,5 +100,5 @@ post-install:
.include "options.mk"
.include "../../lang/python/batteries-included.mk"
-.include "../../lang/python/egg.mk"
+.include "../../lang/python/wheel.mk"
.include "../../mk/bsd.pkg.mk"
Index: pkgsrc/security/fail2ban/PLIST
diff -u pkgsrc/security/fail2ban/PLIST:1.9 pkgsrc/security/fail2ban/PLIST:1.10
--- pkgsrc/security/fail2ban/PLIST:1.9 Sun Jul 2 08:03:38 2023
+++ pkgsrc/security/fail2ban/PLIST Tue Sep 22 12:04:33 2026
@@ -1,13 +1,14 @@
-@comment $NetBSD: PLIST,v 1.9 2023/07/02 08:03:38 wiz Exp $
+@comment $NetBSD: PLIST,v 1.10 2026/09/22 12:04:33 adam Exp $
bin/fail2ban-client
bin/fail2ban-python
bin/fail2ban-regex
bin/fail2ban-server
bin/fail2ban-testcases
-${PYSITELIB}/${EGG_INFODIR}/PKG-INFO
-${PYSITELIB}/${EGG_INFODIR}/SOURCES.txt
-${PYSITELIB}/${EGG_INFODIR}/dependency_links.txt
-${PYSITELIB}/${EGG_INFODIR}/top_level.txt
+${PYSITELIB}/${WHEEL_INFODIR}/METADATA
+${PYSITELIB}/${WHEEL_INFODIR}/RECORD
+${PYSITELIB}/${WHEEL_INFODIR}/WHEEL
+${PYSITELIB}/${WHEEL_INFODIR}/licenses/COPYING
+${PYSITELIB}/${WHEEL_INFODIR}/top_level.txt
${PYSITELIB}/fail2ban/__init__.py
${PYSITELIB}/fail2ban/__init__.pyc
${PYSITELIB}/fail2ban/__init__.pyo
@@ -56,6 +57,12 @@ ${PYSITELIB}/fail2ban/client/jailreader.
${PYSITELIB}/fail2ban/client/jailsreader.py
${PYSITELIB}/fail2ban/client/jailsreader.pyc
${PYSITELIB}/fail2ban/client/jailsreader.pyo
+${PYSITELIB}/fail2ban/compat/asynchat.py
+${PYSITELIB}/fail2ban/compat/asynchat.pyc
+${PYSITELIB}/fail2ban/compat/asynchat.pyo
+${PYSITELIB}/fail2ban/compat/asyncore.py
+${PYSITELIB}/fail2ban/compat/asyncore.pyc
+${PYSITELIB}/fail2ban/compat/asyncore.pyo
${PYSITELIB}/fail2ban/exceptions.py
${PYSITELIB}/fail2ban/exceptions.pyc
${PYSITELIB}/fail2ban/exceptions.pyo
@@ -98,9 +105,6 @@ ${PYSITELIB}/fail2ban/server/failregex.p
${PYSITELIB}/fail2ban/server/filter.py
${PYSITELIB}/fail2ban/server/filter.pyc
${PYSITELIB}/fail2ban/server/filter.pyo
-${PYSITELIB}/fail2ban/server/filtergamin.py
-${PYSITELIB}/fail2ban/server/filtergamin.pyc
-${PYSITELIB}/fail2ban/server/filtergamin.pyo
${PYSITELIB}/fail2ban/server/filterpoll.py
${PYSITELIB}/fail2ban/server/filterpoll.pyc
${PYSITELIB}/fail2ban/server/filterpoll.pyo
@@ -237,7 +241,7 @@ ${PYSITELIB}/fail2ban/tests/files/config
${PYSITELIB}/fail2ban/tests/files/config/apache-auth/noentry/.htaccess
${PYSITELIB}/fail2ban/tests/files/database_v1.db
${PYSITELIB}/fail2ban/tests/files/database_v2.db
-${PYSITELIB}/fail2ban/tests/files/filter.d/substition.conf
+${PYSITELIB}/fail2ban/tests/files/filter.d/substitution.conf
${PYSITELIB}/fail2ban/tests/files/filter.d/testcase-common.conf
${PYSITELIB}/fail2ban/tests/files/filter.d/testcase01.conf
${PYSITELIB}/fail2ban/tests/files/filter.d/testcase02.conf
@@ -267,6 +271,7 @@ ${PYSITELIB}/fail2ban/tests/files/logs/c
${PYSITELIB}/fail2ban/tests/files/logs/courier-auth
${PYSITELIB}/fail2ban/tests/files/logs/courier-smtp
${PYSITELIB}/fail2ban/tests/files/logs/cyrus-imap
+${PYSITELIB}/fail2ban/tests/files/logs/dante
${PYSITELIB}/fail2ban/tests/files/logs/directadmin
${PYSITELIB}/fail2ban/tests/files/logs/domino-smtp
${PYSITELIB}/fail2ban/tests/files/logs/dovecot
@@ -296,10 +301,12 @@ ${PYSITELIB}/fail2ban/tests/files/logs/n
${PYSITELIB}/fail2ban/tests/files/logs/named-refused
${PYSITELIB}/fail2ban/tests/files/logs/nginx-bad-request
${PYSITELIB}/fail2ban/tests/files/logs/nginx-botsearch
+${PYSITELIB}/fail2ban/tests/files/logs/nginx-forbidden
${PYSITELIB}/fail2ban/tests/files/logs/nginx-http-auth
${PYSITELIB}/fail2ban/tests/files/logs/nginx-limit-req
${PYSITELIB}/fail2ban/tests/files/logs/nsd
${PYSITELIB}/fail2ban/tests/files/logs/openhab
+${PYSITELIB}/fail2ban/tests/files/logs/openvpn
${PYSITELIB}/fail2ban/tests/files/logs/openwebmail
${PYSITELIB}/fail2ban/tests/files/logs/oracleims
${PYSITELIB}/fail2ban/tests/files/logs/pam-generic
@@ -309,10 +316,12 @@ ${PYSITELIB}/fail2ban/tests/files/logs/p
${PYSITELIB}/fail2ban/tests/files/logs/portsentry
${PYSITELIB}/fail2ban/tests/files/logs/postfix
${PYSITELIB}/fail2ban/tests/files/logs/proftpd
+${PYSITELIB}/fail2ban/tests/files/logs/proxmox
${PYSITELIB}/fail2ban/tests/files/logs/pure-ftpd
${PYSITELIB}/fail2ban/tests/files/logs/qmail
${PYSITELIB}/fail2ban/tests/files/logs/recidive
${PYSITELIB}/fail2ban/tests/files/logs/roundcube-auth
+${PYSITELIB}/fail2ban/tests/files/logs/routeros-auth
${PYSITELIB}/fail2ban/tests/files/logs/scanlogd
${PYSITELIB}/fail2ban/tests/files/logs/screensharingd
${PYSITELIB}/fail2ban/tests/files/logs/selinux-ssh
@@ -332,14 +341,17 @@ ${PYSITELIB}/fail2ban/tests/files/logs/s
${PYSITELIB}/fail2ban/tests/files/logs/tine20
${PYSITELIB}/fail2ban/tests/files/logs/traefik-auth
${PYSITELIB}/fail2ban/tests/files/logs/uwimap-auth
+${PYSITELIB}/fail2ban/tests/files/logs/vaultwarden
${PYSITELIB}/fail2ban/tests/files/logs/vsftpd
${PYSITELIB}/fail2ban/tests/files/logs/webmin-auth
${PYSITELIB}/fail2ban/tests/files/logs/wuftpd
${PYSITELIB}/fail2ban/tests/files/logs/xinetd-fail
+${PYSITELIB}/fail2ban/tests/files/logs/xrdp
${PYSITELIB}/fail2ban/tests/files/logs/znc-adminlog
${PYSITELIB}/fail2ban/tests/files/logs/zoneminder
${PYSITELIB}/fail2ban/tests/files/logs/zzz-generic-example
${PYSITELIB}/fail2ban/tests/files/logs/zzz-sshd-obsolete-multiline
+${PYSITELIB}/fail2ban/tests/files/test-ign-ips-file
${PYSITELIB}/fail2ban/tests/files/testcase-journal.log
${PYSITELIB}/fail2ban/tests/files/testcase-multiline.log
${PYSITELIB}/fail2ban/tests/files/testcase-usedns.log
@@ -412,7 +424,6 @@ share/doc/fail2ban/fail2ban.server.datet
share/doc/fail2ban/fail2ban.server.failmanager.txt
share/doc/fail2ban/fail2ban.server.failregex.txt
share/doc/fail2ban/fail2ban.server.filter.txt
-share/doc/fail2ban/fail2ban.server.filtergamin.txt
share/doc/fail2ban/fail2ban.server.filterpoll.txt
share/doc/fail2ban/fail2ban.server.filterpyinotify.txt
share/doc/fail2ban/fail2ban.server.filtersystemd.txt
@@ -440,6 +451,7 @@ share/examples/fail2ban/action.d/bsd-ipf
share/examples/fail2ban/action.d/cloudflare-token.conf
share/examples/fail2ban/action.d/cloudflare.conf
share/examples/fail2ban/action.d/complain.conf
+share/examples/fail2ban/action.d/csf.conf
share/examples/fail2ban/action.d/dshield.conf
share/examples/fail2ban/action.d/dummy.conf
share/examples/fail2ban/action.d/firewallcmd-allports.conf
@@ -469,6 +481,7 @@ share/examples/fail2ban/action.d/mail-wh
share/examples/fail2ban/action.d/mail-whois-lines.conf
share/examples/fail2ban/action.d/mail-whois.conf
share/examples/fail2ban/action.d/mail.conf
+share/examples/fail2ban/action.d/mikrotik.conf
share/examples/fail2ban/action.d/mynetwatchman.conf
share/examples/fail2ban/action.d/netscaler.conf
share/examples/fail2ban/action.d/nftables-allports.conf
@@ -493,6 +506,8 @@ share/examples/fail2ban/action.d/sendmai
share/examples/fail2ban/action.d/shorewall-ipset-proto6.conf
share/examples/fail2ban/action.d/shorewall.conf
share/examples/fail2ban/action.d/smtp.py
+share/examples/fail2ban/action.d/smtp.pyc
+share/examples/fail2ban/action.d/smtp.pyo
share/examples/fail2ban/action.d/symbiosis-blacklist-allports.conf
share/examples/fail2ban/action.d/ufw.conf
share/examples/fail2ban/action.d/xarf-login-attack.conf
@@ -519,6 +534,7 @@ share/examples/fail2ban/filter.d/counter
share/examples/fail2ban/filter.d/courier-auth.conf
share/examples/fail2ban/filter.d/courier-smtp.conf
share/examples/fail2ban/filter.d/cyrus-imap.conf
+share/examples/fail2ban/filter.d/dante.conf
share/examples/fail2ban/filter.d/directadmin.conf
share/examples/fail2ban/filter.d/domino-smtp.conf
share/examples/fail2ban/filter.d/dovecot.conf
@@ -550,10 +566,13 @@ share/examples/fail2ban/filter.d/nagios.
share/examples/fail2ban/filter.d/named-refused.conf
share/examples/fail2ban/filter.d/nginx-bad-request.conf
share/examples/fail2ban/filter.d/nginx-botsearch.conf
+share/examples/fail2ban/filter.d/nginx-error-common.conf
+share/examples/fail2ban/filter.d/nginx-forbidden.conf
share/examples/fail2ban/filter.d/nginx-http-auth.conf
share/examples/fail2ban/filter.d/nginx-limit-req.conf
share/examples/fail2ban/filter.d/nsd.conf
share/examples/fail2ban/filter.d/openhab.conf
+share/examples/fail2ban/filter.d/openvpn.conf
share/examples/fail2ban/filter.d/openwebmail.conf
share/examples/fail2ban/filter.d/oracleims.conf
share/examples/fail2ban/filter.d/pam-generic.conf
@@ -563,10 +582,12 @@ share/examples/fail2ban/filter.d/phpmyad
share/examples/fail2ban/filter.d/portsentry.conf
share/examples/fail2ban/filter.d/postfix.conf
share/examples/fail2ban/filter.d/proftpd.conf
+share/examples/fail2ban/filter.d/proxmox.conf
share/examples/fail2ban/filter.d/pure-ftpd.conf
share/examples/fail2ban/filter.d/qmail.conf
share/examples/fail2ban/filter.d/recidive.conf
share/examples/fail2ban/filter.d/roundcube-auth.conf
+share/examples/fail2ban/filter.d/routeros-auth.conf
share/examples/fail2ban/filter.d/scanlogd.conf
share/examples/fail2ban/filter.d/screensharingd.conf
share/examples/fail2ban/filter.d/selinux-common.conf
@@ -586,10 +607,12 @@ share/examples/fail2ban/filter.d/suhosin
share/examples/fail2ban/filter.d/tine20.conf
share/examples/fail2ban/filter.d/traefik-auth.conf
share/examples/fail2ban/filter.d/uwimap-auth.conf
+share/examples/fail2ban/filter.d/vaultwarden.conf
share/examples/fail2ban/filter.d/vsftpd.conf
share/examples/fail2ban/filter.d/webmin-auth.conf
share/examples/fail2ban/filter.d/wuftpd.conf
share/examples/fail2ban/filter.d/xinetd-fail.conf
+share/examples/fail2ban/filter.d/xrdp.conf
share/examples/fail2ban/filter.d/znc-adminlog.conf
share/examples/fail2ban/filter.d/zoneminder.conf
share/examples/fail2ban/jail.conf
Index: pkgsrc/security/fail2ban/distinfo
diff -u pkgsrc/security/fail2ban/distinfo:1.10 pkgsrc/security/fail2ban/distinfo:1.11
--- pkgsrc/security/fail2ban/distinfo:1.10 Sun Jul 2 08:03:38 2023
+++ pkgsrc/security/fail2ban/distinfo Tue Sep 22 12:04:33 2026
@@ -1,6 +1,6 @@
-$NetBSD: distinfo,v 1.10 2023/07/02 08:03:38 wiz Exp $
+$NetBSD: distinfo,v 1.11 2026/09/22 12:04:33 adam Exp $
-BLAKE2s (fail2ban-1.0.2.tar.gz) = 976d8b8b54f316d54f1ca975f1f0aebf3b151260c1af07a29ee2f9a8fea836ca
-SHA512 (fail2ban-1.0.2.tar.gz) = 688a84361b5794e1658f53d2d200ce752fe1e3320ddb1742c32c4b4b82a79ace16ae464e7ea3eeb94a0e862bcac73c2d3a0e61dd7b28e179a4c857f950d74dbb
-Size (fail2ban-1.0.2.tar.gz) = 583295 bytes
+BLAKE2s (fail2ban-1.1.1.tar.gz) = d9629823e792835048345a84b13b410fffc2d83055418f95d3f8508ac8e74a42
+SHA512 (fail2ban-1.1.1.tar.gz) = 1bf3c62711d5ac03a567af52dd6535e2d51d1191892de5348a617fa7be5a0b0fba4404e624af2fa5dd7d74c6b6a8c892b773b44353ec2f2c98d35be6b0909b04
+Size (fail2ban-1.1.1.tar.gz) = 627126 bytes
SHA1 (patch-doc_Makefile) = b17d28b1ef79b0cf86e4cd5d6eaa3e3d1bc2da39
Added files:
Index: pkgsrc/security/fail2ban/config.mk
diff -u /dev/null pkgsrc/security/fail2ban/config.mk:1.1
--- /dev/null Tue Sep 22 12:04:33 2026
+++ pkgsrc/security/fail2ban/config.mk Tue Sep 22 12:04:33 2026
@@ -0,0 +1,185 @@
+# $NetBSD: config.mk,v 1.1 2026/09/22 12:04:33 adam Exp $
+
+# cd ${DESTDIR}${EGDIR}/fail2ban; find . -type f | sort | sed 's,^./,EGFILES+=\t,'
+EGFILES+= action.d/__pycache__/smtp.cpython-314.opt-1.pyc
+EGFILES+= action.d/__pycache__/smtp.cpython-314.pyc
+EGFILES+= action.d/abuseipdb.conf
+EGFILES+= action.d/apf.conf
+EGFILES+= action.d/apprise.conf
+EGFILES+= action.d/blocklist_de.conf
+EGFILES+= action.d/bsd-ipfw.conf
+EGFILES+= action.d/cloudflare-token.conf
+EGFILES+= action.d/cloudflare.conf
+EGFILES+= action.d/complain.conf
+EGFILES+= action.d/csf.conf
+EGFILES+= action.d/dshield.conf
+EGFILES+= action.d/dummy.conf
+EGFILES+= action.d/firewallcmd-allports.conf
+EGFILES+= action.d/firewallcmd-common.conf
+EGFILES+= action.d/firewallcmd-ipset.conf
+EGFILES+= action.d/firewallcmd-multiport.conf
+EGFILES+= action.d/firewallcmd-new.conf
+EGFILES+= action.d/firewallcmd-rich-logging.conf
+EGFILES+= action.d/firewallcmd-rich-rules.conf
+EGFILES+= action.d/helpers-common.conf
+EGFILES+= action.d/hostsdeny.conf
+EGFILES+= action.d/ipfilter.conf
+EGFILES+= action.d/ipfw.conf
+EGFILES+= action.d/iptables-allports.conf
+EGFILES+= action.d/iptables-ipset-proto4.conf
+EGFILES+= action.d/iptables-ipset-proto6-allports.conf
+EGFILES+= action.d/iptables-ipset-proto6.conf
+EGFILES+= action.d/iptables-ipset.conf
+EGFILES+= action.d/iptables-multiport-log.conf
+EGFILES+= action.d/iptables-multiport.conf
+EGFILES+= action.d/iptables-new.conf
+EGFILES+= action.d/iptables-xt_recent-echo.conf
+EGFILES+= action.d/iptables.conf
+EGFILES+= action.d/ipthreat.conf
+EGFILES+= action.d/mail-buffered.conf
+EGFILES+= action.d/mail-whois-common.conf
+EGFILES+= action.d/mail-whois-lines.conf
+EGFILES+= action.d/mail-whois.conf
+EGFILES+= action.d/mail.conf
+EGFILES+= action.d/mikrotik.conf
+EGFILES+= action.d/mynetwatchman.conf
+EGFILES+= action.d/netscaler.conf
+EGFILES+= action.d/nftables-allports.conf
+EGFILES+= action.d/nftables-multiport.conf
+EGFILES+= action.d/nftables.conf
+EGFILES+= action.d/nginx-block-map.conf
+EGFILES+= action.d/npf.conf
+EGFILES+= action.d/nsupdate.conf
+EGFILES+= action.d/osx-afctl.conf
+EGFILES+= action.d/osx-ipfw.conf
+EGFILES+= action.d/pf.conf
+EGFILES+= action.d/route.conf
+EGFILES+= action.d/sendmail-buffered.conf
+EGFILES+= action.d/sendmail-common.conf
+EGFILES+= action.d/sendmail-geoip-lines.conf
+EGFILES+= action.d/sendmail-whois-ipjailmatches.conf
+EGFILES+= action.d/sendmail-whois-ipmatches.conf
+EGFILES+= action.d/sendmail-whois-lines.conf
+EGFILES+= action.d/sendmail-whois-matches.conf
+EGFILES+= action.d/sendmail-whois.conf
+EGFILES+= action.d/sendmail.conf
+EGFILES+= action.d/shorewall-ipset-proto6.conf
+EGFILES+= action.d/shorewall.conf
+EGFILES+= action.d/smtp.py
+EGFILES+= action.d/symbiosis-blacklist-allports.conf
+EGFILES+= action.d/ufw.conf
+EGFILES+= action.d/xarf-login-attack.conf
+EGFILES+= fail2ban.conf
+EGFILES+= filter.d/3proxy.conf
+EGFILES+= filter.d/apache-auth.conf
+EGFILES+= filter.d/apache-badbots.conf
+EGFILES+= filter.d/apache-botsearch.conf
+EGFILES+= filter.d/apache-common.conf
+EGFILES+= filter.d/apache-fakegooglebot.conf
+EGFILES+= filter.d/apache-modsecurity.conf
+EGFILES+= filter.d/apache-nohome.conf
+EGFILES+= filter.d/apache-noscript.conf
+EGFILES+= filter.d/apache-overflows.conf
+EGFILES+= filter.d/apache-pass.conf
+EGFILES+= filter.d/apache-shellshock.conf
+EGFILES+= filter.d/assp.conf
+EGFILES+= filter.d/asterisk.conf
+EGFILES+= filter.d/bitwarden.conf
+EGFILES+= filter.d/botsearch-common.conf
+EGFILES+= filter.d/centreon.conf
+EGFILES+= filter.d/common.conf
+EGFILES+= filter.d/counter-strike.conf
+EGFILES+= filter.d/courier-auth.conf
+EGFILES+= filter.d/courier-smtp.conf
+EGFILES+= filter.d/cyrus-imap.conf
+EGFILES+= filter.d/dante.conf
+EGFILES+= filter.d/directadmin.conf
+EGFILES+= filter.d/domino-smtp.conf
+EGFILES+= filter.d/dovecot.conf
+EGFILES+= filter.d/dropbear.conf
+EGFILES+= filter.d/drupal-auth.conf
+EGFILES+= filter.d/ejabberd-auth.conf
+EGFILES+= filter.d/exim-common.conf
+EGFILES+= filter.d/exim-spam.conf
+EGFILES+= filter.d/exim.conf
+EGFILES+= filter.d/freeswitch.conf
+EGFILES+= filter.d/froxlor-auth.conf
+EGFILES+= filter.d/gitlab.conf
+EGFILES+= filter.d/grafana.conf
+EGFILES+= filter.d/groupoffice.conf
+EGFILES+= filter.d/gssftpd.conf
+EGFILES+= filter.d/guacamole.conf
+EGFILES+= filter.d/haproxy-http-auth.conf
+EGFILES+= filter.d/horde.conf
+EGFILES+= filter.d/ignorecommands/apache-fakegooglebot
+EGFILES+= filter.d/kerio.conf
+EGFILES+= filter.d/lighttpd-auth.conf
+EGFILES+= filter.d/mongodb-auth.conf
+EGFILES+= filter.d/monit.conf
+EGFILES+= filter.d/monitorix.conf
+EGFILES+= filter.d/mssql-auth.conf
+EGFILES+= filter.d/murmur.conf
+EGFILES+= filter.d/mysqld-auth.conf
+EGFILES+= filter.d/nagios.conf
+EGFILES+= filter.d/named-refused.conf
+EGFILES+= filter.d/nginx-bad-request.conf
+EGFILES+= filter.d/nginx-botsearch.conf
+EGFILES+= filter.d/nginx-error-common.conf
+EGFILES+= filter.d/nginx-forbidden.conf
+EGFILES+= filter.d/nginx-http-auth.conf
+EGFILES+= filter.d/nginx-limit-req.conf
+EGFILES+= filter.d/nsd.conf
+EGFILES+= filter.d/openhab.conf
+EGFILES+= filter.d/openvpn.conf
+EGFILES+= filter.d/openwebmail.conf
+EGFILES+= filter.d/oracleims.conf
+EGFILES+= filter.d/pam-generic.conf
+EGFILES+= filter.d/perdition.conf
+EGFILES+= filter.d/php-url-fopen.conf
+EGFILES+= filter.d/phpmyadmin-syslog.conf
+EGFILES+= filter.d/portsentry.conf
+EGFILES+= filter.d/postfix.conf
+EGFILES+= filter.d/proftpd.conf
+EGFILES+= filter.d/proxmox.conf
+EGFILES+= filter.d/pure-ftpd.conf
+EGFILES+= filter.d/qmail.conf
+EGFILES+= filter.d/recidive.conf
+EGFILES+= filter.d/roundcube-auth.conf
+EGFILES+= filter.d/routeros-auth.conf
+EGFILES+= filter.d/scanlogd.conf
+EGFILES+= filter.d/screensharingd.conf
+EGFILES+= filter.d/selinux-common.conf
+EGFILES+= filter.d/selinux-ssh.conf
+EGFILES+= filter.d/sendmail-auth.conf
+EGFILES+= filter.d/sendmail-reject.conf
+EGFILES+= filter.d/sieve.conf
+EGFILES+= filter.d/slapd.conf
+EGFILES+= filter.d/softethervpn.conf
+EGFILES+= filter.d/sogo-auth.conf
+EGFILES+= filter.d/solid-pop3d.conf
+EGFILES+= filter.d/squid.conf
+EGFILES+= filter.d/squirrelmail.conf
+EGFILES+= filter.d/sshd.conf
+EGFILES+= filter.d/stunnel.conf
+EGFILES+= filter.d/suhosin.conf
+EGFILES+= filter.d/tine20.conf
+EGFILES+= filter.d/traefik-auth.conf
+EGFILES+= filter.d/uwimap-auth.conf
+EGFILES+= filter.d/vaultwarden.conf
+EGFILES+= filter.d/vsftpd.conf
+EGFILES+= filter.d/webmin-auth.conf
+EGFILES+= filter.d/wuftpd.conf
+EGFILES+= filter.d/xinetd-fail.conf
+EGFILES+= filter.d/xrdp.conf
+EGFILES+= filter.d/znc-adminlog.conf
+EGFILES+= filter.d/zoneminder.conf
+EGFILES+= jail.conf
+EGFILES+= paths-arch.conf
+EGFILES+= paths-common.conf
+EGFILES+= paths-debian.conf
+EGFILES+= paths-fedora.conf
+EGFILES+= paths-freebsd.conf
+EGFILES+= paths-netbsd.conf
+EGFILES+= paths-opensuse.conf
+EGFILES+= paths-osx.conf
+EGFILES+= paths-pkgsrc.conf
Home |
Main Index |
Thread Index |
Old Index