pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

CVS commit: pkgsrc/net/tacacs



Module Name:    pkgsrc
Committed By:   he
Date:           Fri Sep 25 10:00:43 UTC 2026

Modified Files:
        pkgsrc/net/tacacs: Makefile PLIST distinfo
Added Files:
        pkgsrc/net/tacacs/patches: patch-configure patch-configure.ac

Log Message:
net/tacacs: update to version 4.0.4.32.

Pkgsrc changes:
 * whack configure.ac so that it manages to produce a working
   configure script.  There are more errors / warnings here...
 * Change test for libwrap to declare required global variables
   ... as globals, and not as locals in main() in the configure test.

Upstream changes (newest first):

F4.0.4.32
        - Remote pre-authentication format string vulnerability (CWE-134)

F4.0.4.31
        - update autoconf to search for libnsl instead of assume.  Debian
          no longer has one, at least not by default.

F4.0.4.30
        - pull do_auth 2.0 and the example config file from github, with
          python3 updates and more.
          https://github.com/helpdeskdan/do_auth
        - SafeConfigParser class has been renamed to ConfigParser
        - Misc C99 prototype clean-up

F4.0.4.29
        - spec file update - from Sten Spans
        - add SHA512 support to tac_pwd - from Sten Spans
          XXX needs a configure test to check for sha512 support.
        - fix libtacacs link - from Gentoo via Ruben Farrelly
        - fix -U decription in manpage
        - call correct function for host key look-up by hostname - Adam Dyess
        - GC regeerror() from the private regex lib.  Causing segfault
        - a bug with quoted strings was that whitespace was not handled
          reasonably.  since quoted strings may also be used for regex, it also
          needs to handle regex atoms.  so, quoted string parsing has been
          changed to only treat \" specially, all other backslash-quoted
          characters are simply copied, including the backslash.  add test
          example to the sample configuration.
        - fdes.c: add parens to make OoO explicit and shut-up compiler warnings


To generate a diff of this commit:
cvs rdiff -u -r1.27 -r1.28 pkgsrc/net/tacacs/Makefile
cvs rdiff -u -r1.3 -r1.4 pkgsrc/net/tacacs/PLIST
cvs rdiff -u -r1.10 -r1.11 pkgsrc/net/tacacs/distinfo
cvs rdiff -u -r0 -r1.1 pkgsrc/net/tacacs/patches/patch-configure \
    pkgsrc/net/tacacs/patches/patch-configure.ac

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: pkgsrc/net/tacacs/Makefile
diff -u pkgsrc/net/tacacs/Makefile:1.27 pkgsrc/net/tacacs/Makefile:1.28
--- pkgsrc/net/tacacs/Makefile:1.27     Tue Jun 28 11:35:20 2022
+++ pkgsrc/net/tacacs/Makefile  Fri Sep 25 10:00:42 2026
@@ -1,9 +1,8 @@
-# $NetBSD: Makefile,v 1.27 2022/06/28 11:35:20 wiz Exp $
+# $NetBSD: Makefile,v 1.28 2026/09/25 10:00:42 he Exp $
 
-VERSION=       4.0.4.28
+VERSION=       4.0.4.32
 DISTNAME=      tacacs-F${VERSION}
 PKGNAME=       tacacs-${VERSION}
-PKGREVISION=   9
 CATEGORIES=    net security
 MASTER_SITES+= ftp://ftp.shrubbery.net/pub/tac_plus/
 

Index: pkgsrc/net/tacacs/PLIST
diff -u pkgsrc/net/tacacs/PLIST:1.3 pkgsrc/net/tacacs/PLIST:1.4
--- pkgsrc/net/tacacs/PLIST:1.3 Fri Feb 20 22:26:13 2015
+++ pkgsrc/net/tacacs/PLIST     Fri Sep 25 10:00:42 2026
@@ -1,4 +1,4 @@
-@comment $NetBSD: PLIST,v 1.3 2015/02/20 22:26:13 joerg Exp $
+@comment $NetBSD: PLIST,v 1.4 2026/09/25 10:00:42 he Exp $
 bin/tac_pwd
 include/tacacs.h
 lib/libtacacs.la
@@ -6,6 +6,7 @@ man/man5/tac_plus.conf.5
 man/man8/tac_plus.8
 man/man8/tac_pwd.8
 sbin/tac_plus
+share/tacacs/do_auth.ini
 share/tacacs/do_auth.py
 share/tacacs/tac_convert
 share/tacacs/users_guide

Index: pkgsrc/net/tacacs/distinfo
diff -u pkgsrc/net/tacacs/distinfo:1.10 pkgsrc/net/tacacs/distinfo:1.11
--- pkgsrc/net/tacacs/distinfo:1.10     Tue Oct 26 11:06:59 2021
+++ pkgsrc/net/tacacs/distinfo  Fri Sep 25 10:00:42 2026
@@ -1,5 +1,7 @@
-$NetBSD: distinfo,v 1.10 2021/10/26 11:06:59 nia Exp $
+$NetBSD: distinfo,v 1.11 2026/09/25 10:00:42 he Exp $
 
-BLAKE2s (tacacs-F4.0.4.28.tar.gz) = 55b31ba1342eb2a09ca3aa27b59312ddedc172ea8a9ce4160e0a30d7b14c5d96
-SHA512 (tacacs-F4.0.4.28.tar.gz) = aec97bf1c2ea4171ba1aeabeb6ac7405ca693439c15a9f09868b77932a1ed72036043c05d8bfcfc938c43549318e41fd1ab4f3251ce2536278318d6a318c53cb
-Size (tacacs-F4.0.4.28.tar.gz) = 530049 bytes
+BLAKE2s (tacacs-F4.0.4.32.tar.gz) = 91d4f621426fad76948a84c142f6762c0bf727385f3004602f6edf37fc90933a
+SHA512 (tacacs-F4.0.4.32.tar.gz) = 4a962383cc82562197d37848b1b5bbe29a6437fa316f218a569380b37cfcbb948e3a2b526b32ec1e5341cd958b43846aabb85e277bca2df81602acb308a27ca8
+Size (tacacs-F4.0.4.32.tar.gz) = 570098 bytes
+SHA1 (patch-configure) = a7ecaa1d2d73e40c8ba3832b159a9e9d7a606ea2
+SHA1 (patch-configure.ac) = 286ea9ee56b7e673e8987e7313c0eedbd4b6d2ab

Added files:

Index: pkgsrc/net/tacacs/patches/patch-configure
diff -u /dev/null pkgsrc/net/tacacs/patches/patch-configure:1.1
--- /dev/null   Fri Sep 25 10:00:43 2026
+++ pkgsrc/net/tacacs/patches/patch-configure   Fri Sep 25 10:00:42 2026
@@ -0,0 +1,306 @@
+$NetBSD: patch-configure,v 1.1 2026/09/25 10:00:42 he Exp $
+
+Regenerate...
+
+--- configure.orig     2026-09-24 21:56:38.877169172 +0000
++++ configure
+@@ -2,6 +2,8 @@
+ # Guess values for system-dependent variables and create Makefiles.
+ # Generated by GNU Autoconf 2.73 for tacacs F4.0.4.32.
+ #
++# Report bugs to <some%e-mail.com@localhost>.
++#
+ #
+ # Copyright (C) 1992-1996, 1998-2017, 2020-2026 Free Software Foundation,
+ # Inc.
+@@ -282,10 +284,11 @@ then :
+     printf '%s\n' "$0: In particular, zsh $ZSH_VERSION has bugs and should"
+     printf '%s\n' "$0: be upgraded to zsh 4.3.4 or later."
+   else
+-    printf '%s\n' "$0: Please tell bug-autoconf%gnu.org@localhost about your system,
+-$0: including any error possibly output before this
+-$0: message. Then install a modern shell, or manually run
+-$0: the script under such a shell if you do have one."
++    printf '%s\n' "$0: Please tell bug-autoconf%gnu.org@localhost and some%e-mail.com@localhost
++$0: about your system, including any error possibly output
++$0: before this message. Then install a modern shell, or
++$0: manually run the script under such a shell if you do
++$0: have one."
+   fi
+   exit 1
+ fi ;;
+@@ -597,9 +600,10 @@ PACKAGE_NAME='tacacs'
+ PACKAGE_TARNAME='tacacs'
+ PACKAGE_VERSION='F4.0.4.32'
+ PACKAGE_STRING='tacacs F4.0.4.32'
+-PACKAGE_BUGREPORT=''
++PACKAGE_BUGREPORT='some%e-mail.com@localhost'
+ PACKAGE_URL=''
+ 
++enable_option_checking=no
+ ac_default_prefix=/usr/local
+ # Factoring default headers for most tests.
+ ac_includes_default="\
+@@ -724,6 +728,7 @@ build_os
+ build_vendor
+ build_cpu
+ build
++subdirs
+ MAINT
+ MAINTAINER_MODE_FALSE
+ MAINTAINER_MODE_TRUE
+@@ -847,7 +852,7 @@ LT_SYS_LIBRARY_PATH
+ CPP
+ YACC
+ YFLAGS'
+-
++ac_subdirs_all='etc man share'
+ 
+ # Initialize some variables set by options.
+ ac_init_help=
+@@ -1544,7 +1549,7 @@ Some influential environment variables:
+ Use these variables to override the choices made by 'configure' or to help
+ it to find libraries and programs with nonstandard names/locations.
+ 
+-Report bugs to the package provider.
++Report bugs to <some%e-mail.com@localhost>.
+ _ACEOF
+ ac_status=$?
+ fi
+@@ -3080,6 +3085,15 @@ ac_compiler_gnu=$ac_cv_c_compiler_gnu
+ 
+ 
+ 
++
++
++ac_ext=c
++ac_cpp='$CPP $CPPFLAGS'
++ac_compile='$CC -c $CFLAGS $CPPFLAGS conftest.$ac_ext >&5'
++ac_link='$CC -o conftest$ac_exeext $CFLAGS $CPPFLAGS $LDFLAGS conftest.$ac_ext $LIBS >&5'
++ac_compiler_gnu=$ac_cv_c_compiler_gnu
++
++
+ am__api_version='1.18'
+ 
+ 
+@@ -4001,6 +4015,10 @@ fi
+ 
+ 
+ 
++
++subdirs="$subdirs etc man share"
++
++
+ # what OS
+ 
+ 
+@@ -16947,12 +16965,13 @@ printf '%s\n' "yes" >&6; }
+     cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+ /* end confdefs.h.  */
+  #include <tcpd.h>
++                  int allow_severity; int deny_severity;
++                  struct request_info *request;
++
+ int
+ main (void)
+ {
+- int allow_severity; int deny_severity;
+-                  struct request_info *request;
+-                hosts_access(request);
++ hosts_access(request);
+   ;
+   return 0;
+ }
+@@ -16990,12 +17009,13 @@ printf '%s\n' "yes" >&6; }
+     cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+ /* end confdefs.h.  */
+  #include <tcpd.h>
++                  int allow_severity; int deny_severity;
++                  struct request_info *request;
++
+ int
+ main (void)
+ {
+- int allow_severity; int deny_severity;
+-                  struct request_info *request;
+-                hosts_access(request);
++ hosts_access(request);
+   ;
+   return 0;
+ }
+@@ -17025,12 +17045,13 @@ printf '%s\n' "yes" >&6; }
+   cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+ /* end confdefs.h.  */
+ #include <tcpd.h>
++                int allow_severity; int deny_severity;
++                struct request_info *request;
++
+ int
+ main (void)
+ {
+- int allow_severity; int deny_severity;
+-                struct request_info *request;
+-              hosts_access(request);
++ hosts_access(request);
+   ;
+   return 0;
+ }
+@@ -19489,7 +19510,7 @@ $config_headers
+ Configuration commands:
+ $config_commands
+ 
+-Report bugs to the package provider."
++Report bugs to <some%e-mail.com@localhost>."
+ 
+ _ACEOF
+ ac_cs_config=`printf '%s\n' "$ac_configure_args" | sed "$ac_safe_unquote"`
+@@ -21209,6 +21228,149 @@ esac
+   # would make configure fail if this is the last instruction.
+   $ac_cs_success || as_fn_exit 1
+ fi
++
++#
++# CONFIG_SUBDIRS section.
++#
++if test "$no_recursion" != yes; then
++
++  # Remove --cache-file, --srcdir, and --disable-option-checking arguments
++  # so they do not pile up.
++  ac_sub_configure_args=
++  ac_prev=
++  eval "set x $ac_configure_args"
++  shift
++  for ac_arg
++  do
++    if test -n "$ac_prev"; then
++      ac_prev=
++      continue
++    fi
++    case $ac_arg in
++    -cache-file | --cache-file | --cache-fil | --cache-fi \
++    | --cache-f | --cache- | --cache | --cach | --cac | --ca | --c)
++      ac_prev=cache_file ;;
++    -cache-file=* | --cache-file=* | --cache-fil=* | --cache-fi=* \
++    | --cache-f=* | --cache-=* | --cache=* | --cach=* | --cac=* | --ca=* \
++    | --c=*)
++      ;;
++    --config-cache | -C)
++      ;;
++    -srcdir | --srcdir | --srcdi | --srcd | --src | --sr)
++      ac_prev=srcdir ;;
++    -srcdir=* | --srcdir=* | --srcdi=* | --srcd=* | --src=* | --sr=*)
++      ;;
++    -prefix | --prefix | --prefi | --pref | --pre | --pr | --p)
++      ac_prev=prefix ;;
++    -prefix=* | --prefix=* | --prefi=* | --pref=* | --pre=* | --pr=* | --p=*)
++      ;;
++    --disable-option-checking)
++      ;;
++    *)
++      case $ac_arg in
++      *\'*) ac_arg=`printf '%s\n' "$ac_arg" | sed "s/'/'\\\\\\\\''/g"` ;;
++      esac
++      as_fn_append ac_sub_configure_args " '$ac_arg'" ;;
++    esac
++  done
++
++  # Always prepend --prefix to ensure using the same prefix
++  # in subdir configurations.
++  ac_arg="--prefix=$prefix"
++  case $ac_arg in
++  *\'*) ac_arg=`printf '%s\n' "$ac_arg" | sed "s/'/'\\\\\\\\''/g"` ;;
++  esac
++  ac_sub_configure_args="'$ac_arg' $ac_sub_configure_args"
++
++  # Pass --silent
++  if test "$silent" = yes; then
++    ac_sub_configure_args="--silent $ac_sub_configure_args"
++  fi
++
++  # Always prepend --disable-option-checking to silence warnings, since
++  # different subdirs can have different --enable and --with options.
++  ac_sub_configure_args="--disable-option-checking $ac_sub_configure_args"
++
++  ac_popdir=`pwd`
++  for ac_dir in : $subdirs; do test "x$ac_dir" = x: && continue
++
++    # Do not complain, so a configure script can configure whichever
++    # parts of a large source tree are present.
++    test -d "$srcdir/$ac_dir" || continue
++
++    ac_msg="=== configuring in $ac_dir (`pwd`/$ac_dir)"
++    printf '%s\n' "$as_me:${as_lineno-$LINENO}: $ac_msg" >&5
++    printf '%s\n' "$ac_msg" >&6
++    as_dir="$ac_dir"; as_fn_mkdir_p
++    ac_builddir=.
++
++case "$ac_dir" in
++.) ac_dir_suffix= ac_top_builddir_sub=. ac_top_build_prefix= ;;
++*)
++  ac_dir_suffix=/`printf '%s\n' "$ac_dir" | sed 's|^\.[\\/]||'`
++  # A ".." for each directory in $ac_dir_suffix.
++  ac_top_builddir_sub=`printf '%s\n' "$ac_dir_suffix" | sed 's|/[^\\/]*|/..|g;s|/||'`
++  case $ac_top_builddir_sub in
++  "") ac_top_builddir_sub=. ac_top_build_prefix= ;;
++  *)  ac_top_build_prefix=$ac_top_builddir_sub/ ;;
++  esac ;;
++esac
++ac_abs_top_builddir=$ac_pwd
++ac_abs_builddir=$ac_pwd$ac_dir_suffix
++# for backward compatibility:
++ac_top_builddir=$ac_top_build_prefix
++
++case $srcdir in
++  .)  # We are building in place.
++    ac_srcdir=.
++    ac_top_srcdir=$ac_top_builddir_sub
++    ac_abs_top_srcdir=$ac_pwd ;;
++  [\\/]* | ?:[\\/]* )  # Absolute name.
++    ac_srcdir=$srcdir$ac_dir_suffix;
++    ac_top_srcdir=$srcdir
++    ac_abs_top_srcdir=$srcdir ;;
++  *) # Relative name.
++    ac_srcdir=$ac_top_build_prefix$srcdir$ac_dir_suffix
++    ac_top_srcdir=$ac_top_build_prefix$srcdir
++    ac_abs_top_srcdir=$ac_pwd/$srcdir ;;
++esac
++ac_abs_srcdir=$ac_abs_top_srcdir$ac_dir_suffix
++
++
++    cd "$ac_dir"
++
++    # Check for configure.gnu first; this name is used for a wrapper for
++    # Metaconfig's "Configure" on case-insensitive file systems.
++    if test -f "$ac_srcdir/configure.gnu"; then
++      ac_sub_configure=$ac_srcdir/configure.gnu
++    elif test -f "$ac_srcdir/configure"; then
++      ac_sub_configure=$ac_srcdir/configure
++    else
++      { printf '%s\n' "$as_me:${as_lineno-$LINENO}: WARNING: no configuration information is in $ac_dir" >&5
++printf '%s\n' "$as_me: WARNING: no configuration information is in $ac_dir" >&2;}
++      ac_sub_configure=
++    fi
++
++    # The recursion is here.
++    if test -n "$ac_sub_configure"; then
++      # Make the cache file name correct relative to the subdirectory.
++      case $cache_file in
++      [\\/]* | ?:[\\/]* ) ac_sub_cache_file=$cache_file ;;
++      *) # Relative name.
++      ac_sub_cache_file=$ac_top_build_prefix$cache_file ;;
++      esac
++
++      { printf '%s\n' "$as_me:${as_lineno-$LINENO}: running $SHELL $ac_sub_configure $ac_sub_configure_args --cache-file=$ac_sub_cache_file --srcdir=$ac_srcdir" >&5
++printf '%s\n' "$as_me: running $SHELL $ac_sub_configure $ac_sub_configure_args --cache-file=$ac_sub_cache_file --srcdir=$ac_srcdir" >&6;}
++      # The eval makes quoting arguments work.
++      eval "\$SHELL \"\$ac_sub_configure\" $ac_sub_configure_args \
++         --cache-file=\"\$ac_sub_cache_file\" --srcdir=\"\$ac_srcdir\"" ||
++      as_fn_error $? "$ac_sub_configure failed for $ac_dir" "$LINENO" 5
++    fi
++
++    cd "$ac_popdir"
++  done
++fi
+ if test -n "$ac_unrecognized_opts" && test "$enable_option_checking" != no; then
+   { printf '%s\n' "$as_me:${as_lineno-$LINENO}: WARNING: unrecognized options: $ac_unrecognized_opts" >&5
+ printf '%s\n' "$as_me: WARNING: unrecognized options: $ac_unrecognized_opts" >&2;}
Index: pkgsrc/net/tacacs/patches/patch-configure.ac
diff -u /dev/null pkgsrc/net/tacacs/patches/patch-configure.ac:1.1
--- /dev/null   Fri Sep 25 10:00:43 2026
+++ pkgsrc/net/tacacs/patches/patch-configure.ac        Fri Sep 25 10:00:42 2026
@@ -0,0 +1,84 @@
+$NetBSD: patch-configure.ac,v 1.1 2026/09/25 10:00:42 he Exp $
+
+Fix test for librwap.  Required declared global variables
+need to be ... global.
+
+Also try to adapt to newer autoconf.
+
+--- configure.ac.orig  2026-02-18 16:43:50.000000000 +0000
++++ configure.ac
+@@ -6,17 +6,23 @@ AC_PREREQ(2.69)
+ dnl VERSION needs to be updated in version.h.in such that 'make dist'
+ dnl uses the correct filename for the directory name and tarball and binaries
+ dnl get the right version numbers.
+-PACKAGE=`sh ./aconf/package.sh`
+-VERSION=`sh ./aconf/version.sh`
+-AC_INIT(m4_esyscmd(sh ./aconf/package.sh),
+-      m4_esyscmd(sh ./aconf/version.sh))
++dnl PACKAGE=`sh ./aconf/package.sh`
++dnl VERSION=`sh ./aconf/version.sh`
++dnl AC_INIT(m4_esyscmd(sh ./aconf/package.sh),
++dnl   m4_esyscmd(sh ./aconf/version.sh))
++
++AC_INIT([tacacs], [F4.0.4.32], [some%e-mail.com@localhost], [tacacs])
++
+ AC_CONFIG_AUX_DIR([aconf])
+ AC_CONFIG_MACRO_DIR([aconf])
+-AM_INIT_AUTOMAKE
++
++AC_LANG([C])
++
++AM_INIT_AUTOMAKE([1.11 foreign])
+ 
+ AM_MAINTAINER_MODE()
+ 
+-dnl AC_CONFIG_SUBDIRS(etc man share)
++AC_CONFIG_SUBDIRS(etc man share)
+ 
+ # what OS
+ dnl ---- XXX: these really should deal with the individual reasons why
+@@ -245,10 +251,11 @@ AC_ARG_WITH(libwrap,
+     WRAPLIBS="-lwrap"
+     OLDLIBS="$LIBS"
+     LIBS="$WRAPLIBS $LIBS"
+-    AC_TRY_LINK([ #include <tcpd.h> ],
+-              [ int allow_severity; int deny_severity;
++    AC_TRY_LINK([ #include <tcpd.h>
++                  int allow_severity; int deny_severity;
+                   struct request_info *request;
+-                hosts_access(request); ],
++                ],
++              [ hosts_access(request); ],
+       [AC_DEFINE(LIBWRAP)
+        WRAPLIBS="-lwrap"
+        AC_DEFINE(HAVE_LIBWRAP) ],
+@@ -268,10 +275,11 @@ AC_ARG_WITH(libwrap,
+     OLDINCS="$INCLUDES"
+     LIBS="$WRAPLIBS $LIBS"
+     INCLUDES="$WRAPINCS"
+-    AC_TRY_LINK([ #include <tcpd.h> ],
+-              [ int allow_severity; int deny_severity;
++    AC_TRY_LINK([ #include <tcpd.h>
++                  int allow_severity; int deny_severity;
+                   struct request_info *request;
+-                hosts_access(request); ],
++                ],
++              [ hosts_access(request); ],
+               [],
+               [ AC_MSG_ERROR(Could not find libwrap.  You must first install tcp_wrappers.) ])
+     LIBS="$OLDLIBS"
+@@ -284,10 +292,11 @@ AC_ARG_WITH(libwrap,
+   WRAPLIBS="-lwrap"
+   OLDLIBS="$LIBS"
+   LIBS="$WRAPLIBS $LIBS"
+-  AC_TRY_LINK([#include <tcpd.h> ],
+-            [ int allow_severity; int deny_severity;
++  AC_TRY_LINK([#include <tcpd.h>
++                int allow_severity; int deny_severity;
+                 struct request_info *request;
+-              hosts_access(request); ],
++              ],
++            [ hosts_access(request); ],
+       [AC_DEFINE(LIBWRAP)
+        WRAPLIBS="-lwrap"
+        AC_DEFINE(HAVE_LIBWRAP) ],



Home | Main Index | Thread Index | Old Index