diff options
| author | root <root@alpha.trunkmasters.com> | 2026-06-04 05:35:26 -0500 |
|---|---|---|
| committer | root <root@alpha.trunkmasters.com> | 2026-06-04 05:35:26 -0500 |
| commit | f716a9fe6455d39eef01e718aae68dae61c19704 (patch) | |
| tree | 0c52bbae1c242fbc296bd650fcd1167685f81492 /net-proxy/squid | |
| parent | 3f9cf298e89cd5037b982abba06091224ee76daf (diff) | |
| download | baldeagleos-repo-f716a9fe6455d39eef01e718aae68dae61c19704.tar.gz baldeagleos-repo-f716a9fe6455d39eef01e718aae68dae61c19704.tar.xz baldeagleos-repo-f716a9fe6455d39eef01e718aae68dae61c19704.zip | |
Adding metadata
Diffstat (limited to 'net-proxy/squid')
| -rw-r--r-- | net-proxy/squid/Manifest | 5 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-4.17-use-system-libltdl.patch | 16 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-6.12-ar.patch | 29 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-6.14-cachemgr-dont_show_hostname.patch | 17 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-6.14-proxy_auth_data.patch | 187 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-6.2-gentoo.patch | 76 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-7.5-ar.patch | 11 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-7.5-gentoo.patch | 76 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid-7.5-use-system-libltdl.patch | 13 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid.confd-r2 | 18 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid.cron-r1 | 15 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid.initd-r7 | 133 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid.logrotate-r1 | 11 | ||||
| -rw-r--r-- | net-proxy/squid/files/squid.pam | 7 | ||||
| -rw-r--r-- | net-proxy/squid/metadata.xml | 26 | ||||
| -rw-r--r-- | net-proxy/squid/squid-6.14-r1.ebuild | 421 | ||||
| -rw-r--r-- | net-proxy/squid/squid-7.5.ebuild | 410 |
17 files changed, 0 insertions, 1471 deletions
diff --git a/net-proxy/squid/Manifest b/net-proxy/squid/Manifest deleted file mode 100644 index b233f742d904..000000000000 --- a/net-proxy/squid/Manifest +++ /dev/null @@ -1,5 +0,0 @@ -DIST squid-6.14.tar.xz 2548456 BLAKE2B 286f54ac85cb98bf759d0591c458d27d060759f4156136edf785adce80e5a49fe4d8d6648fcb40e3bc6bf171fa0a341d2b76804702f486266fc8daec8e1d6d58 SHA512 5905060ae8d70128516c26cf379ed5b434c02525efe0e17ac56d4e060af7542b4a7a41ac3eca5ba5a00867791aed18ed5ed0e247b18a376e1ae7bc13039782f5 -DIST squid-6.14.tar.xz.asc 745 BLAKE2B 5aede7d130194463cfa6ffea866ab483859cf47a92504141a18774c0ffeb93033e9c3ff90dd91bb73095df345829121e8e28898bedcfce327ae9047664199fb9 SHA512 5cc102787796db1cf4c71e9e21d3462becdd869eb72cd69a5c4ca74f60628a98a5543aabe7a0d0bc74c99a62bae0678d3ae6eab9dfe0e4dfb9c063678005f2e3 -DIST squid-6.9-memleak_fix.patch 22178 BLAKE2B bf87a98ac3ddcf27b817b7b09a1a7656cb6547c7c157d02a3daf4b337669180718e1df06040b9b4be252a9f60fc767d94ed698014113c072dd9b91ada08a1adc SHA512 38754b1f593dde3e7ab70601bdaaabf8c1c40beea0ae9913684d3de78d76cec4243abac8e315af2009b98e096a3b04c56181940f0528716278aaf7c44ea76dad -DIST squid-7.5.tar.xz 2432664 BLAKE2B 3ceb6f9da34e9fdbf421de0058e211d1e71dcd2bffd6c26e139c01a272cdfe580b41ed4f3b11abd6a819fbeb6e37c8418824590a56058c369a8ca3efb5dbc5f3 SHA512 2abe4c7a719606b2f33a7e9af2a6e151a0c50bdf81210af5393f26d32fa3b3a4e88af2588b9b9d66513e83721e75a248c0891ee7099d32979948c2f3bb6c2a73 -DIST squid-7.5.tar.xz.asc 659 BLAKE2B f40d7575aa58111a85a71490a50ef5dde997d30cedd77cccb567a0bc2ed05d5a54e714415a0b9d72008ac64eab1d479d8aa23845ca0e8f2b6e43ca08da517fa0 SHA512 980bb4522d8b086c9ccee976d39dcd4d80a604f1720d44f6700c14d46418750c06b324b4394c648775e7306d5068b51ade8340c62215dbd20a8b665765518001 diff --git a/net-proxy/squid/files/squid-4.17-use-system-libltdl.patch b/net-proxy/squid/files/squid-4.17-use-system-libltdl.patch deleted file mode 100644 index 219f2ab6cf70..000000000000 --- a/net-proxy/squid/files/squid-4.17-use-system-libltdl.patch +++ /dev/null @@ -1,16 +0,0 @@ -https://bugs.gentoo.org/830099 ---- a/Makefile.am -+++ b/Makefile.am -@@ -6,11 +6,8 @@ - ## - - AUTOMAKE_OPTIONS = dist-bzip2 1.5 foreign --DIST_SUBDIRS = compat lib libltdl scripts icons errors contrib doc src test-suite tools -+DIST_SUBDIRS = compat lib scripts icons errors contrib doc src test-suite tools - SUBDIRS = compat lib --if ENABLE_LOADABLE_MODULES --SUBDIRS += libltdl --endif - SUBDIRS += scripts icons errors doc src tools test-suite - - DISTCLEANFILES = include/stamp-h include/stamp-h[0-9]* diff --git a/net-proxy/squid/files/squid-6.12-ar.patch b/net-proxy/squid/files/squid-6.12-ar.patch deleted file mode 100644 index babfae4f4547..000000000000 --- a/net-proxy/squid/files/squid-6.12-ar.patch +++ /dev/null @@ -1,29 +0,0 @@ -https://github.com/squid-cache/squid/pull/1920 - -From e9d43d7612ab7bd2b5d04ce0d24e06a342a506e1 Mon Sep 17 00:00:00 2001 -Message-ID: <e9d43d7612ab7bd2b5d04ce0d24e06a342a506e1.1729501292.git.sam@gentoo.org> -From: Sam James <sam@gentoo.org> -Date: Mon, 21 Oct 2024 09:56:38 +0100 -Subject: [PATCH] configure.ac: use AC_CHECK_TOOL for ar - -Use AC_CHECK_TOOL which checks the environment variable `$AR` as well, which -is useful for us in Gentoo when cross-compiling. - -We could use AC_PROG_AR in newer autoconf or AM_PROG_AR in automake but -the AR_R use is hardcoded in a bunch of places so not worth it. - -Bug: https://bugs.gentoo.org/911945 ---- a/configure.ac -+++ b/configure.ac -@@ -129,7 +129,7 @@ AS_IF([test "x$ac_cv_path_PERL" = "xnone"],[ - AC_PATH_PROG(POD2MAN, pod2man, $FALSE) - AM_CONDITIONAL(ENABLE_POD2MAN_DOC, test "x${ac_cv_path_POD2MAN}" != "x$FALSE") - --AC_PATH_PROG(AR, ar, $FALSE) -+AC_CHECK_TOOL(AR, ar, :) - AR_R="$AR r" - AC_SUBST(AR_R) - --- -2.47.0 - diff --git a/net-proxy/squid/files/squid-6.14-cachemgr-dont_show_hostname.patch b/net-proxy/squid/files/squid-6.14-cachemgr-dont_show_hostname.patch deleted file mode 100644 index 315208646474..000000000000 --- a/net-proxy/squid/files/squid-6.14-cachemgr-dont_show_hostname.patch +++ /dev/null @@ -1,17 +0,0 @@ -https://github.com/squid-cache/squid/commit/d94dbed6c700faeded8c4175f2a8d0f71c15755b.patch -From d94dbed6c700faeded8c4175f2a8d0f71c15755b Mon Sep 17 00:00:00 2001 -From: Amos Jeffries <amosjeffries@squid-cache.org> -Date: Wed, 5 Nov 2025 10:23:34 +1300 -Subject: [PATCH] Do not show arbitrary hostname in cachemgr.cgi output - ---- a/tools/cachemgr.cc -+++ b/tools/cachemgr.cc -@@ -819,7 +819,7 @@ process_request(cachemgr_request * req) - } - - if (!check_target_acl(req->hostname, req->port)) { -- snprintf(buf, sizeof(buf), "target %s:%d not allowed in cachemgr.conf\n", req->hostname, req->port); -+ snprintf(buf, sizeof(buf), "target host not allowed in cachemgr.conf\n"); - error_html(buf); - return 1; - } diff --git a/net-proxy/squid/files/squid-6.14-proxy_auth_data.patch b/net-proxy/squid/files/squid-6.14-proxy_auth_data.patch deleted file mode 100644 index fa0aaef12e43..000000000000 --- a/net-proxy/squid/files/squid-6.14-proxy_auth_data.patch +++ /dev/null @@ -1,187 +0,0 @@ -https://sources.debian.org/patches/squid/6.13-2+deb13u1/CVE-2025-62168.patch/ -From: Amos Jeffries <yadij@users.noreply.github.com> -Date: Sat, 11 Oct 2025 16:33:02 +1300 -Subject: [PATCH] Bug 3390: Proxy auth data visible to scripts (#2249) - -Original changes to redact credentials from error page %R code -expansion output was incomplete. It missed the parse failure -case where ErrorState::request_hdrs raw buffer contained -sensitive information. - -Also missed was the %W case where full request message headers -were generated in a mailto link. This case is especially -problematic as it may be delivered over insecure SMTP even if -the error was secured with HTTPS. - -After this change: -* The HttpRequest message packing code for error pages is de-duplicated - and elides authentication headers for both %R and %W code outputs. -* The %R code output includes the CRLF request message terminator. -* The email_err_data directive causing advanced details to be added to - %W mailto links is disabled by default. - -Also redact credentials from generated TRACE responses. - ---------- - -Co-authored-by: Alex Rousskov <rousskov@measurement-factory.com> - -origin: backport, https://github.com/squid-cache/squid/commit/0951a0681011dfca3d78c84fd7f1e19c78a4443f -bug: https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr -debian-bug: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1118341 ---- a/src/HttpRequest.cc -+++ b/src/HttpRequest.cc -@@ -341,7 +341,7 @@ HttpRequest::swapOut(StoreEntry * e) - - /* packs request-line and headers, appends <crlf> terminator */ - void --HttpRequest::pack(Packable * p) const -+HttpRequest::pack(Packable * const p, const bool maskSensitiveInfo) const - { - assert(p); - /* pack request-line */ -@@ -349,8 +349,8 @@ HttpRequest::pack(Packable * p) const - SQUIDSBUFPRINT(method.image()), SQUIDSBUFPRINT(url.path()), - http_ver.major, http_ver.minor); - /* headers */ -- header.packInto(p); -- /* trailer */ -+ header.packInto(p, maskSensitiveInfo); -+ /* indicate the end of the header section */ - p->append("\r\n", 2); - } - ---- a/src/HttpRequest.h -+++ b/src/HttpRequest.h -@@ -206,7 +206,7 @@ public: - - void swapOut(StoreEntry * e); - -- void pack(Packable * p) const; -+ void pack(Packable * p, bool maskSensitiveInfo = false) const; - - static void httpRequestPack(void *obj, Packable *p); - ---- a/src/cf.data.pre -+++ b/src/cf.data.pre -@@ -8944,12 +8944,18 @@ NAME: email_err_data - COMMENT: on|off - TYPE: onoff - LOC: Config.onoff.emailErrData --DEFAULT: on -+DEFAULT: off - DOC_START - If enabled, information about the occurred error will be - included in the mailto links of the ERR pages (if %W is set) - so that the email body contains the data. - Syntax is <A HREF="mailto:%w%W">%w</A> -+ -+ SECURITY WARNING: -+ Request headers and other included facts may contain -+ sensitive information about transaction history, the -+ Squid instance, and its environment which would be -+ unavailable to error recipients otherwise. - DOC_END - - NAME: deny_info ---- a/src/client_side_reply.cc -+++ b/src/client_side_reply.cc -@@ -94,7 +94,7 @@ clientReplyContext::clientReplyContext(ClientHttpRequest *clientContext) : - void - clientReplyContext::setReplyToError( - err_type err, Http::StatusCode status, char const *uri, -- const ConnStateData *conn, HttpRequest *failedrequest, const char *unparsedrequest, -+ const ConnStateData *conn, HttpRequest *failedrequest, const char *, - #if USE_AUTH - Auth::UserRequest::Pointer auth_user_request - #else -@@ -104,9 +104,6 @@ clientReplyContext::setReplyToError( - { - auto errstate = clientBuildError(err, status, uri, conn, failedrequest, http->al); - -- if (unparsedrequest) -- errstate->request_hdrs = xstrdup(unparsedrequest); -- - #if USE_AUTH - errstate->auth_user_request = auth_user_request; - #endif -@@ -995,11 +992,14 @@ clientReplyContext::traceReply() - triggerInitialStoreRead(); - http->storeEntry()->releaseRequest(); - http->storeEntry()->buffer(); -+ MemBuf content; -+ content.init(); -+ http->request->pack(&content, true /* hide authorization data */); - const HttpReplyPointer rep(new HttpReply); -- rep->setHeaders(Http::scOkay, nullptr, "text/plain", http->request->prefixLen(), 0, squid_curtime); -+ rep->setHeaders(Http::scOkay, nullptr, "message/http", content.contentSize(), 0, squid_curtime); -+ rep->body.set(SBuf(content.buf, content.size)); - http->storeEntry()->replaceHttpReply(rep); -- http->request->swapOut(http->storeEntry()); -- http->storeEntry()->complete(); -+ http->storeEntry()->completeSuccessfully("traceReply() stored the entire response"); - } - - #define SENDING_BODY 0 ---- a/src/errorpage.cc -+++ b/src/errorpage.cc -@@ -792,7 +792,6 @@ ErrorState::~ErrorState() - { - safe_free(redirect_url); - safe_free(url); -- safe_free(request_hdrs); - wordlistDestroy(&ftp.server_msg); - safe_free(ftp.request); - safe_free(ftp.reply); -@@ -850,7 +849,7 @@ ErrorState::Dump(MemBuf * mb) - SQUIDSBUFPRINT(request->url.path()), - AnyP::ProtocolType_str[request->http_ver.protocol], - request->http_ver.major, request->http_ver.minor); -- request->header.packInto(&str); -+ request->header.packInto(&str, true /* hide authorization data */); - } - - str.append("\r\n", 2); -@@ -1112,18 +1111,10 @@ ErrorState::compileLegacyCode(Build &build) - p = "[no request]"; - break; - } -- if (request) { -- mb.appendf(SQUIDSBUFPH " " SQUIDSBUFPH " %s/%d.%d\n", -- SQUIDSBUFPRINT(request->method.image()), -- SQUIDSBUFPRINT(request->url.path()), -- AnyP::ProtocolType_str[request->http_ver.protocol], -- request->http_ver.major, request->http_ver.minor); -- request->header.packInto(&mb, true); //hide authorization data -- } else if (request_hdrs) { -- p = request_hdrs; -- } else { -+ else if (request) -+ request->pack(&mb, true /* hide authorization data */); -+ else - p = "[no request]"; -- } - break; - - case 's': ---- a/src/errorpage.h -+++ b/src/errorpage.h -@@ -194,7 +194,6 @@ public: - MemBuf *listing = nullptr; - } ftp; - -- char *request_hdrs = nullptr; - char *err_msg = nullptr; /* Preformatted error message from the cache */ - - AccessLogEntryPointer ale; ///< transaction details (or nil) ---- a/src/tests/stub_HttpRequest.cc -+++ b/src/tests/stub_HttpRequest.cc -@@ -45,7 +45,7 @@ bool HttpRequest::expectingBody(const HttpRequestMethod &, int64_t &) const STUB - bool HttpRequest::bodyNibbled() const STUB_RETVAL(false) - int HttpRequest::prefixLen() const STUB_RETVAL(0) - void HttpRequest::swapOut(StoreEntry *) STUB --void HttpRequest::pack(Packable *) const STUB -+void HttpRequest::pack(Packable *, bool) const STUB - void HttpRequest::httpRequestPack(void *, Packable *) STUB - HttpRequest * HttpRequest::FromUrl(const SBuf &, const MasterXaction::Pointer &, const HttpRequestMethod &) STUB_RETVAL(nullptr) - HttpRequest * HttpRequest::FromUrlXXX(const char *, const MasterXaction::Pointer &, const HttpRequestMethod &) STUB_RETVAL(nullptr) diff --git a/net-proxy/squid/files/squid-6.2-gentoo.patch b/net-proxy/squid/files/squid-6.2-gentoo.patch deleted file mode 100644 index 2444c74a71d0..000000000000 --- a/net-proxy/squid/files/squid-6.2-gentoo.patch +++ /dev/null @@ -1,76 +0,0 @@ ---- a/configure.ac -+++ b/configure.ac -@@ -33,9 +33,6 @@ PRESET_CFLAGS="$CFLAGS" - PRESET_CXXFLAGS="$CXXFLAGS" - PRESET_LDFLAGS="$LDFLAGS" - --dnl Set default LDFLAGS --AS_IF([test "x$LDFLAGS" = "x"],[LDFLAGS="-g"]) -- - # check for host OS detail - AC_CANONICAL_HOST - AC_MSG_CHECKING([simplified host os]) ---- a/src/cf.data.pre -+++ b/src/cf.data.pre -@@ -1669,6 +1669,7 @@ acl Safe_ports port 280 # http-mgmt - acl Safe_ports port 488 # gss-http - acl Safe_ports port 591 # filemaker - acl Safe_ports port 777 # multiling http -+acl Safe_ports port 901 # SWAT - CONFIG_END - DOC_END - -@@ -7447,11 +7448,11 @@ COMMENT_END - - NAME: cache_mgr - TYPE: string --DEFAULT: webmaster -+DEFAULT: root - LOC: Config.adminEmail - DOC_START - Email-address of local cache manager who will receive -- mail if the cache dies. The default is "webmaster". -+ mail if the cache dies. The default is "root". - DOC_END - - NAME: mail_from ---- a/src/debug/debug.cc -+++ b/src/debug/debug.cc -@@ -1144,7 +1144,7 @@ Debug::SettleSyslog() - #if HAVE_SYSLOG && defined(LOG_LOCAL4) - - if (Debug::log_syslog) { -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, syslog_facility); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, syslog_facility); - Module().syslogChannel.markOpened(); - } - ---- a/src/main.cc -+++ b/src/main.cc -@@ -1867,7 +1867,7 @@ watch_child(const CommandLine &masterCommand) - - enter_suid(); - -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, LOG_LOCAL4); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, LOG_LOCAL4); - - if (!opt_foreground) - GoIntoBackground(); -@@ -1959,7 +1959,7 @@ watch_child(const CommandLine &masterCommand) - - if ((pid = fork()) == 0) { - /* child */ -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, LOG_LOCAL4); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, LOG_LOCAL4); - (void)execvp(masterCommand.arg0(), kidCommand.argv()); - int xerrno = errno; - syslog(LOG_ALERT, "execvp failed: %s", xstrerr(xerrno)); -@@ -1971,7 +1971,7 @@ watch_child(const CommandLine &masterCommand) - } - - /* parent */ -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, LOG_LOCAL4); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, LOG_LOCAL4); - - // If Squid received a signal while checking for dying kids (below) or - // starting new kids (above), then do a fast check for a new dying kid diff --git a/net-proxy/squid/files/squid-7.5-ar.patch b/net-proxy/squid/files/squid-7.5-ar.patch deleted file mode 100644 index f71573b4fdee..000000000000 --- a/net-proxy/squid/files/squid-7.5-ar.patch +++ /dev/null @@ -1,11 +0,0 @@ ---- a/configure.ac -+++ b/configure.ac -@@ -140,7 +140,7 @@ - AC_PATH_PROG(POD2MAN, pod2man, $FALSE) - AM_CONDITIONAL(ENABLE_POD2MAN_DOC, test "x${ac_cv_path_POD2MAN}" != "x$FALSE") - --AC_PATH_PROG(AR, ar, $FALSE) -+AC_CHECK_TOOL(AR, ar, :) - AR_R="$AR r" - AC_SUBST(AR_R) - diff --git a/net-proxy/squid/files/squid-7.5-gentoo.patch b/net-proxy/squid/files/squid-7.5-gentoo.patch deleted file mode 100644 index 5e5dbfd32061..000000000000 --- a/net-proxy/squid/files/squid-7.5-gentoo.patch +++ /dev/null @@ -1,76 +0,0 @@ ---- a/configure.ac -+++ b/configure.ac -@@ -33,9 +33,6 @@ - PRESET_CXXFLAGS="$CXXFLAGS" - PRESET_LDFLAGS="$LDFLAGS" - --dnl Set default LDFLAGS --AS_IF([test "x$LDFLAGS" = "x"],[LDFLAGS="-g"]) -- - # check for host OS detail - AC_CANONICAL_HOST - AC_MSG_CHECKING([simplified host os]) ---- a/src/cf.data.pre -+++ b/src/cf.data.pre -@@ -1752,6 +1752,7 @@ - acl Safe_ports port 488 # gss-http - acl Safe_ports port 591 # filemaker - acl Safe_ports port 777 # multiling http -+acl Safe_ports port 901 # SWAT - CONFIG_END - DOC_END - -@@ -7547,11 +7548,11 @@ - - NAME: cache_mgr - TYPE: string --DEFAULT: webmaster -+DEFAULT: root - LOC: Config.adminEmail - DOC_START - Email-address of local cache manager who will receive -- mail if the cache dies. The default is "webmaster". -+ mail if the cache dies. The default is "root". - DOC_END - - NAME: mail_from ---- a/src/debug/debug.cc -+++ b/src/debug/debug.cc -@@ -1147,7 +1147,7 @@ - #if HAVE_SYSLOG && defined(LOG_LOCAL4) - - if (Debug::log_syslog) { -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, syslog_facility); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, syslog_facility); - Module().syslogChannel.markOpened(); - } - ---- a/src/main.cc -+++ b/src/main.cc -@@ -1912,7 +1912,7 @@ - - enter_suid(); - -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, LOG_LOCAL4); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, LOG_LOCAL4); - - if (!opt_foreground) - GoIntoBackground(); -@@ -2004,7 +2004,7 @@ - - if ((pid = fork()) == 0) { - /* child */ -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, LOG_LOCAL4); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, LOG_LOCAL4); - (void)execvp(masterCommand.arg0(), kidCommand.argv()); - int xerrno = errno; - syslog(LOG_ALERT, "execvp failed: %s", xstrerr(xerrno)); -@@ -2016,7 +2016,7 @@ - } - - /* parent */ -- openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY | LOG_CONS, LOG_LOCAL4); -+ openlog(APP_SHORTNAME, LOG_PID | LOG_NDELAY, LOG_LOCAL4); - - // If Squid received a signal while checking for dying kids (below) or - // starting new kids (above), then do a fast check for a new dying kid diff --git a/net-proxy/squid/files/squid-7.5-use-system-libltdl.patch b/net-proxy/squid/files/squid-7.5-use-system-libltdl.patch deleted file mode 100644 index 7b1ffbbd8431..000000000000 --- a/net-proxy/squid/files/squid-7.5-use-system-libltdl.patch +++ /dev/null @@ -1,13 +0,0 @@ ---- a/Makefile.am -+++ b/Makefile.am -@@ -14,10 +14,6 @@ - errors \ - icons - --if ENABLE_LOADABLE_MODULES --SUBDIRS += libltdl --endif -- - SUBDIRS += \ - lib \ - scripts \ diff --git a/net-proxy/squid/files/squid.confd-r2 b/net-proxy/squid/files/squid.confd-r2 deleted file mode 100644 index fea9a067a83b..000000000000 --- a/net-proxy/squid/files/squid.confd-r2 +++ /dev/null @@ -1,18 +0,0 @@ -# Copyright 1999-2019 Gentoo Authors -# Distributed under the terms of the GNU General Public License v2 - -# Config file for /etc/init.d/squid - -SQUID_OPTS="-YC" - -# Kerberos keytab file to use. This is required if you enable kerberos authentication. -SQUID_KEYTAB="" - -# Use max_filedescriptors setting in squid.conf to determine the maximum number -# of filedescriptors squid can open. - -# Set whether Squid should receive two shutdown signals instead of one. If set to "yes", -# Squid will skip the graceful shutdown step, and will try to immediately close all open -# file descriptors and helpers. This is useful if you experience very long delays when -# shutting down the caching proxy. -SQUID_FAST_SHUTDOWN="no" diff --git a/net-proxy/squid/files/squid.cron-r1 b/net-proxy/squid/files/squid.cron-r1 deleted file mode 100644 index f0fa84ed2cb3..000000000000 --- a/net-proxy/squid/files/squid.cron-r1 +++ /dev/null @@ -1,15 +0,0 @@ -#!/bin/sh - -# OpenRC init script supports multiple Squid instances, and exposes 'rotate'. -if command -v rc-service >/dev/null; then - SQUID_SERVICES=$(rc-status | awk '/ *squid.* started /{print $1}') - for SQUID_SERVICE in $SQUID_SERVICES ; do - rc-service "${SQUID_SERVICE}" rotate - done - -# Systemd unit file supports only a single default squid instance, -# and no 'rotate' support, so call squid directly. -elif command -v systemctl >/dev/null; then - SQUID_ACTIVE=$(systemctl --type=service --state=active | awk '/^ *squid\.service / {print $1}') - [ -n "${SQUID_ACTIVE}" ] && squid -k rotate -fi diff --git a/net-proxy/squid/files/squid.initd-r7 b/net-proxy/squid/files/squid.initd-r7 deleted file mode 100644 index 7215b774736d..000000000000 --- a/net-proxy/squid/files/squid.initd-r7 +++ /dev/null @@ -1,133 +0,0 @@ -#!/sbin/openrc-run -# Copyright 1999-2024 Gentoo Authors -# Distributed under the terms of the GNU General Public License v2 - -SQUID_SVCNAME=$( echo "${RC_SVCNAME}" | tr -cd '[a-zA-Z0-9]' ) - -extra_started_commands="reload rotate" - -depend() { - use dns net -} - -_getconfig() { - # Make PIDFILE, CHROOTDIR, and CACHE_SWAP visible to other functions - local CONFFILES="/etc/squid/${RC_SVCNAME}.conf /etc/squid/${RC_SVCNAME}.include /etc/squid/${RC_SVCNAME}.include.*" - if [ ! -f /etc/squid/${RC_SVCNAME}.conf ]; then - eerror "You need to create /etc/squid/${RC_SVCNAME}.conf first." - eerror "The main configuration file and all included file names should have the following format:" - eerror "${CONFFILES}" - eerror "An example can be found in /etc/squid/squid.conf.default" - return 1 - fi - PIDFILE=$(cat ${CONFFILES} 2>/dev/null 3>/dev/null | awk '/^[ \t]*pid_filename[ \t]+/ { print $2 }') - CHROOTDIR=$(cat ${CONFFILES} 2>/dev/null 3>/dev/null | awk '/^[ \t]*chroot[ \t]+/ { print $2 }') - if [ -n "${CHROOTDIR}" ] && [ -n "${PIDFILE}" ]; then - CHROOTDIR="${CHROOTDIR%/}" - PIDFILE="${CHROOTDIR}${PIDFILE}" - fi - [ -z ${PIDFILE} ] && PIDFILE=/run/squid.pid - if [ "${CHROOTDIR}/run/${RC_SVCNAME}.pid" != ${PIDFILE} ]; then - eerror "/etc/squid/${RC_SVCNAME}.conf must set pid_filename to" - eerror " /run/${RC_SVCNAME}.pid" - if [ -n "${CHROOTDIR}" ]; then - eerror "with chrootdir ${CHROOTDIR} set." - fi - eerror "CAUTION: http_port, cache_dir and *_log parameters must be different than" - eerror " in any other instance of squid." - eerror "Make sure the main configuration file and all included file names have the following format:" - eerror "${CONFFILES}" - return 1 - fi - CACHE_SWAP=$(cat ${CONFFILES} 2>/dev/null 3>/dev/null | awk '/^[ \t]*cache_dir[ \t]+/ { if ( $2 == "rock" ) printf "%s/rock ", $3; else if ( $2 == "coss" ) printf "%s/stripe ", $3; else printf "%s/00 ", $3; }') - [ -z "$CACHE_SWAP" ] && CACHE_SWAP="/var/cache/squid/00" - - return 0 -} - -checkconfig() { - _getconfig || return 1 - local x - for x in $CACHE_SWAP ; do - if [ ! -e $x ] ; then - ebegin "Initializing cache directory ${x%/*}" - local ORIG_UMASK=$(umask) - umask 027 - - if ! (mkdir -p ${x%/*} && chown squid ${x%/*}) ; then - eend 1 - return 1 - fi - - local INIT_CACHE_RESPONSE="$(/usr/sbin/squid -z -N -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME} 2>&1)" - if [ $? != 0 ] || echo "$INIT_CACHE_RESPONSE" | grep -q "erminated abnormally" ; then - umask $ORIG_UMASK - eend 1 - echo "$INIT_CACHE_RESPONSE" - return 1 - fi - - umask $ORIG_UMASK - eend 0 - break - fi - done - - return 0 -} - -start() { - checkconfig || return 1 - checkpath -d -q -m 0750 -o squid:squid /run/${RC_SVCNAME} - - # see https://wiki.squid-cache.org/MultipleInstances - ebegin "Starting ${RC_SVCNAME} (service name ${SQUID_SVCNAME}) with KRB5_KTNAME=\"${SQUID_KEYTAB}\" /usr/sbin/squid ${SQUID_OPTS} -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME}" - KRB5_KTNAME="${SQUID_KEYTAB}" /usr/sbin/squid ${SQUID_OPTS} -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME} - eend $? && sleep 1 -} - -stop() { - _getconfig || return 1 - ebegin "Stopping ${RC_SVCNAME} with /usr/sbin/squid -k shutdown -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME}" - if /usr/sbin/squid -k shutdown -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME} ; then - if [ "x${SQUID_FAST_SHUTDOWN}" = "xyes" ]; then - einfo "Attempting fast shutdown." - /usr/sbin/squid -k shutdown -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME} - fi - # Now we have to wait until squid has _really_ stopped. - sleep 1 - if [ -f ${PIDFILE} ] ; then - einfon "Waiting for squid to shutdown ." - cnt=0 - while [ -f ${PIDFILE} ] ; do - cnt=$(expr $cnt + 1) - if [ $cnt -gt 90 ] ; then - # Waited 180 seconds now. Fail. - echo - eend 1 "Failed." - break - fi - sleep 2 - printf "." - done - echo - fi - else - eerror "Squid shutdown failed, probably service is already down." - fi - eend 0 -} - -reload() { - checkconfig || return 1 - ebegin "Reloading ${RC_SVCNAME} with /usr/sbin/squid -k reconfigure -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME}" - /usr/sbin/squid -k reconfigure -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME} - eend $? -} - -rotate() { - service_started ${RC_SVCNAME} || return 1 - ebegin "Rotating ${RC_SVCNAME} logs with /usr/sbin/squid -k rotate -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME}" - /usr/sbin/squid -k rotate -f /etc/squid/${RC_SVCNAME}.conf -n ${SQUID_SVCNAME} - eend $? -} diff --git a/net-proxy/squid/files/squid.logrotate-r1 b/net-proxy/squid/files/squid.logrotate-r1 deleted file mode 100644 index 03cbca9b5f4a..000000000000 --- a/net-proxy/squid/files/squid.logrotate-r1 +++ /dev/null @@ -1,11 +0,0 @@ -/var/log/squid/*.log { - copytruncate - compress - notifempty - missingok - sharedscripts - postrotate - squid -k rotate 2>/dev/null - endscript -} - diff --git a/net-proxy/squid/files/squid.pam b/net-proxy/squid/files/squid.pam deleted file mode 100644 index 75eeaa9db38d..000000000000 --- a/net-proxy/squid/files/squid.pam +++ /dev/null @@ -1,7 +0,0 @@ -#%PAM-1.0 -auth required pam_nologin.so -auth include system-auth -account include system-auth -password include system-auth -session optional pam_limits.so -session include system-auth diff --git a/net-proxy/squid/metadata.xml b/net-proxy/squid/metadata.xml deleted file mode 100644 index 8a427f9e8ce6..000000000000 --- a/net-proxy/squid/metadata.xml +++ /dev/null @@ -1,26 +0,0 @@ -<?xml version="1.0" encoding="UTF-8"?> -<!DOCTYPE pkgmetadata SYSTEM "https://www.gentoo.org/dtd/metadata.dtd"> -<pkgmetadata> - <maintainer type="person" proxied="yes"> - <email>hlein@korelogic.com</email> - <name>Hank Leininger</name> - </maintainer> - <maintainer type="project" proxied="proxy"> - <email>proxy-maint@gentoo.org</email> - <name>Proxy Maintainers</name> - </maintainer> - <use> - <flag name="ecap">Adds support for loadable content adaptation modules (http://www.e-cap.org)</flag> - <flag name="esi">Enable ESI for accelerators, will cause squid reverse proxies to be capable of the Edge Acceleration Specification (www.esi.org)</flag> - <flag name="htcp">Enable HTCP protocol</flag> - <flag name="logrotate">Use <pkg>app-admin/logrotate</pkg> for rotating logs</flag> - <flag name="qos">Adds support for Quality of Service using netfilter conntrack - see qos_flow directive for more info</flag> - <flag name="ssl-crtd">Adds support for dynamic SSL certificate generation in SslBump environments</flag> - <flag name="tproxy">Enables real Transparent Proxy support for Linux Netfilter TPROXY</flag> - <flag name="wccp">Enable Web Cache Coordination Protocol</flag> - <flag name="wccpv2">Enable Web Cache Coordination V2 Protocol</flag> - </use> - <upstream> - <remote-id type="github">squid-cache/squid</remote-id> - </upstream> -</pkgmetadata> diff --git a/net-proxy/squid/squid-6.14-r1.ebuild b/net-proxy/squid/squid-6.14-r1.ebuild deleted file mode 100644 index a65ddc3b159b..000000000000 --- a/net-proxy/squid/squid-6.14-r1.ebuild +++ /dev/null @@ -1,421 +0,0 @@ -# Copyright 1999-2026 Gentoo Authors -# Distributed under the terms of the GNU General Public License v2 - -EAPI=8 - -VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/squid.gpg -inherit autotools flag-o-matic linux-info pam systemd toolchain-funcs verify-sig - -DESCRIPTION="Full-featured web proxy cache" -HOMEPAGE="https://www.squid-cache.org/" - -MY_PV_MAJOR=$(ver_cut 1) -MY_PV_MINOR=$(ver_cut 2) -# Upstream patch ID for the most recent bug-fixed update to the formal release. -#r=-20181117-r0022167 -r= -if [[ -z ${r} ]]; then - SRC_URI=" - https://github.com/squid-cache/squid/releases/download/SQUID_${MY_PV_MAJOR}_${MY_PV_MINOR}/${P}.tar.xz - https://dev.gentoo.org/~juippis/distfiles/squid-6.9-memleak_fix.patch - verify-sig? ( https://github.com/squid-cache/squid/releases/download/SQUID_${MY_PV_MAJOR}_${MY_PV_MINOR}/${P}.tar.xz.asc ) - " -else - SRC_URI=" - http://static.squid-cache.org/Versions/v${MY_PV_MAJOR}/${P}${r}.tar.bz2 - https://dev.gentoo.org/~juippis/distfiles/squid-6.9-memleak_fix.patch - " - S="${S}${r}" -fi - -LICENSE="GPL-2+" -SLOT="0" -KEYWORDS="~alpha amd64 arm arm64 ~hppa ~mips ~ppc ~ppc64 ~riscv ~sparc x86" -IUSE="caps gnutls pam ldap samba sasl kerberos nis radius ssl snmp selinux logrotate test ecap" -IUSE+=" esi ssl-crtd mysql postgres sqlite systemd perl qos tproxy +htcp valgrind +wccp +wccpv2" -RESTRICT="!test? ( test )" -REQUIRED_USE="tproxy? ( caps ) qos? ( caps ) ssl-crtd? ( ssl )" - -DEPEND=" - acct-group/squid - acct-user/squid - dev-libs/libltdl - sys-libs/tdb - virtual/libcrypt:= - caps? ( >=sys-libs/libcap-2.16 ) - ecap? ( net-libs/libecap:1 ) - esi? ( - dev-libs/expat - dev-libs/libxml2:= - ) - ldap? ( net-nds/openldap:= ) - gnutls? ( >=net-libs/gnutls-3.1.5:= ) - logrotate? ( app-admin/logrotate ) - nis? ( - net-libs/libtirpc:= - net-libs/libnsl:= - ) - kerberos? ( virtual/krb5 ) - pam? ( sys-libs/pam ) - qos? ( net-libs/libnetfilter_conntrack ) - ssl? ( - dev-libs/nettle:= - !gnutls? ( - dev-libs/openssl:= - ) - ) - sasl? ( dev-libs/cyrus-sasl ) - systemd? ( sys-apps/systemd:= ) -" -RDEPEND=" - ${DEPEND} - mysql? ( dev-perl/DBD-mysql ) - postgres? ( dev-perl/DBD-Pg ) - perl? ( dev-lang/perl ) - samba? ( net-fs/samba ) - selinux? ( sec-policy/selinux-squid ) - sqlite? ( dev-perl/DBD-SQLite ) -" -DEPEND+=" valgrind? ( dev-debug/valgrind )" -BDEPEND=" - dev-lang/perl - ecap? ( virtual/pkgconfig ) - test? ( dev-util/cppunit ) - verify-sig? ( sec-keys/openpgp-keys-squid ) -" - -PATCHES=( - "${FILESDIR}"/${PN}-6.2-gentoo.patch - "${FILESDIR}"/${PN}-4.17-use-system-libltdl.patch - "${DISTDIR}"/${PN}-6.9-memleak_fix.patch - "${FILESDIR}"/${PN}-6.12-ar.patch - "${FILESDIR}"/${PN}-6.14-proxy_auth_data.patch - "${FILESDIR}"/${PN}-6.14-cachemgr-dont_show_hostname.patch -) - -pkg_pretend() { - if use tproxy; then - local CONFIG_CHECK="~NF_CONNTRACK ~NETFILTER_XT_MATCH_SOCKET ~NETFILTER_XT_TARGET_TPROXY" - linux-info_pkg_setup - fi -} - -src_unpack() { - if use verify-sig ; then - # Needed for downloaded patch (which is unsigned, which is fine) - verify-sig_verify_detached "${DISTDIR}"/${P}.tar.xz{,.asc} - fi - - default -} - -src_prepare() { - default - - # Fixup various paths - sed -i -e 's:/usr/local/squid/etc:/etc/squid:' \ - INSTALL QUICKSTART \ - scripts/fileno-to-pathname.pl \ - scripts/check_cache.pl \ - tools/cachemgr.cgi.8 \ - tools/purge/conffile.hh \ - tools/purge/purge.1 || die - sed -i -e 's:/usr/local/squid/sbin:/usr/sbin:' \ - INSTALL QUICKSTART || die - sed -i -e 's:/usr/local/squid/var/cache:/var/cache/squid:' \ - QUICKSTART || die - sed -i -e 's:/usr/local/squid/var/logs:/var/log/squid:' \ - QUICKSTART \ - src/log/access_log.cc || die - sed -i -e 's:/usr/local/squid/logs:/var/log/squid:' \ - src/log/access_log.cc || die - sed -i -e 's:/usr/local/squid/libexec:/usr/libexec/squid:' \ - src/acl/external/unix_group/ext_unix_group_acl.8 \ - src/acl/external/session/ext_session_acl.8 || die - sed -i -e 's:/usr/local/squid/cache:/var/cache/squid:' \ - scripts/check_cache.pl || die - # /var/run/squid to /run/squid - sed -i -e 's:$(localstatedir)::' \ - src/ipc/Makefile.am || die - sed -i 's:/var/run/:/run/:g' tools/systemd/squid.service || die - - sed -i -e 's:_LTDL_SETUP:LTDL_INIT([installable]):' \ - libltdl/configure.ac || die - - # https://bugs.gentoo.org/956509 - AT_NO_RECURSIVE="yes" eautoreconf -} - -src_configure() { - # Workaround for bug #921688 - append-cxxflags -std=gnu++17 - - local myeconfargs=( - --cache-file="${S}"/config.cache - - --datadir=/usr/share/squid - --libexecdir=/usr/libexec/squid - --localstatedir=/var - --sysconfdir=/etc/squid - --with-default-user=squid - --with-logdir=/var/log/squid - --with-pidfile=/run/squid.pid - - --enable-build-info="Gentoo ${PF} (r: ${r:-NONE})" - --enable-log-daemon-helpers - --enable-url-rewrite-helpers - --enable-cache-digests - --enable-delay-pools - --enable-disk-io - --enable-eui - --enable-icmp - --enable-ipv6 - --enable-follow-x-forwarded-for - --enable-removal-policies="lru,heap" - --disable-strict-error-checking - --disable-arch-native - - --with-large-files - --with-build-environment=default - - --with-tdb - - --without-included-ltdl - --with-ltdl-include="${ESYSROOT}"/usr/include - --with-ltdl-lib="${ESYSROOT}"/usr/$(get_libdir) - - $(use_with caps cap) - $(use_enable snmp) - $(use_with ssl openssl) - $(use_with ssl nettle) - $(use_with gnutls) - $(use_with ldap) - $(use_enable ssl-crtd) - $(use_with systemd) - $(use_with test cppunit) - $(use_enable ecap) - $(use_enable esi) - $(use_enable esi expat) - $(use_enable esi xml2) - $(use_enable htcp) - $(use_with valgrind valgrind-debug) - $(use_enable wccp) - $(use_enable wccpv2) - ) - - # Basic modules - local basic_modules=( - NCSA - POP3 - getpwnam - - $(usev samba 'SMB') - $(usev ldap 'SMB_LM LDAP') - $(usev pam 'PAM') - $(usev sasl 'SASL') - $(usev nis 'NIS') - $(usev radius 'RADIUS') - ) - - use nis && append-cppflags "-I${ESYSROOT}/usr/include/tirpc" - - if use mysql || use postgres || use sqlite; then - basic_modules+=( DB ) - fi - - # Digests - local digest_modules=( - file - - $(usev ldap 'LDAP eDirectory') - ) - - # Kerberos - local negotiate_modules=( none ) - - myeconfargs+=( --without-mit-krb5 --without-heimdal-krb5 ) - - if use kerberos; then - # We intentionally overwrite negotiate_modules here to lose - # the 'none'. - negotiate_modules=( kerberos wrapper ) - - if has_version app-crypt/heimdal; then - myeconfargs+=( - --without-mit-krb5 - --with-heimdal-krb5 - ) - else - myeconfargs+=( - --with-mit-krb5 - --without-heimdal-krb5 - ) - fi - fi - - # NTLM modules - local ntlm_modules=( none ) - - if use samba ; then - # We intentionally overwrite ntlm_modules here to lose - # the 'none'. - ntlm_modules=( SMB_LM ) - fi - - # External helpers - local ext_helpers=( - file_userip - session - unix_group - delayer - time_quota - - $(usev samba 'wbinfo_group') - $(usev ldap 'LDAP_group eDirectory_userip') - ) - - use ldap && use kerberos && ext_helpers+=( kerberos_ldap_group ) - if use mysql || use postgres || use sqlite; then - ext_helpers+=( SQL_session ) - fi - - # Storage modules - local storeio_modules=( - aufs - diskd - rock - ufs - ) - - # - local transparent - if use kernel_linux; then - myeconfargs+=( - --enable-linux-netfilter - $(usev qos '--enable-zph-qos --with-netfilter-conntrack') - ) - fi - - tc-export_build_env BUILD_CXX - export BUILDCXX="${BUILD_CXX}" - export BUILDCXXFLAGS="${BUILD_CXXFLAGS}" - tc-export CC AR - - # Should be able to drop this workaround with newer versions. - # https://bugs.squid-cache.org/show_bug.cgi?id=4224 - tc-is-cross-compiler && export squid_cv_gnu_atomics=no - - # Bug #719662 - append-atomic-flags - - print_options_without_comma() { - # IFS as ',' will cut off any trailing commas - ( - IFS=',' - options=( $(printf "%s," "${@}") ) - echo "${options[*]}" - ) - } - - myeconfargs+=( - --enable-storeio=$(print_options_without_comma "${storeio_modules[@]}") - --enable-auth-basic=$(print_options_without_comma "${basic_modules[@]}") - --enable-auth-digest=$(print_options_without_comma "${digest_modules[@]}") - --enable-auth-ntlm=$(print_options_without_comma "${ntlm_modules[@]}") - --enable-auth-negotiate=$(print_options_without_comma "${negotiate_modules[@]}") - --enable-external-acl-helpers=$(print_options_without_comma "${ext_helpers[@]}") - ) - - econf "${myeconfargs[@]}" -} - -src_test() { - default - - # Suppress QA warning (bug #877729) for no tests executed - # for some subsuites. The layout is odd and there's a bunch - # of useless/stub directories which confuses it. - find "${S}" -iname test-suite.log -delete || die -} - -src_install() { - default - - systemd_dounit tools/systemd/squid.service - - # Need suid root for looking into /etc/shadow - fowners root:squid /usr/libexec/squid/basic_ncsa_auth - fperms 4750 /usr/libexec/squid/basic_ncsa_auth - - if use pam; then - fowners root:squid /usr/libexec/squid/basic_pam_auth - fperms 4750 /usr/libexec/squid/basic_pam_auth - fi - - # Pinger needs suid as well - fowners root:squid /usr/libexec/squid/pinger - fperms 4750 /usr/libexec/squid/pinger - - # These scripts depend on perl - if ! use perl; then - local perl_scripts=( - basic_pop3_auth ext_delayer_acl helper-mux - log_db_daemon security_fake_certverify - storeid_file_rewrite url_lfs_rewrite - ) - - local script - for script in "${perl_scripts[@]}"; do - rm "${ED}"/usr/libexec/squid/${script} || die - done - fi - - # Cleanup - rm -r "${D}"/run "${D}"/var/cache || die - - dodoc CONTRIBUTORS CREDITS ChangeLog INSTALL QUICKSTART README SPONSORS doc/*.txt - newdoc src/auth/negotiate/kerberos/README README.kerberos - newdoc src/auth/basic/RADIUS/README README.RADIUS - newdoc src/acl/external/kerberos_ldap_group/README README.kerberos_ldap_group - dodoc RELEASENOTES.html - - if use pam; then - newpamd "${FILESDIR}"/squid.pam squid - fi - - newconfd "${FILESDIR}"/squid.confd-r2 squid - newinitd "${FILESDIR}"/squid.initd-r7 squid - - if use logrotate ; then - insinto /etc/logrotate.d - newins "${FILESDIR}"/squid.logrotate-r1 squid - else - exeinto /etc/cron.weekly - newexe "${FILESDIR}"/squid.cron-r1 squid.cron - fi - - diropts -m0750 -o squid -g squid - keepdir /var/log/squid /etc/ssl/squid /var/lib/squid - - # Hack for bug #834503 (see also bug #664940) - # Please keep this for a few years until it's no longer plausible - # someone is upgrading from < squid 5.7. - mv "${ED}"/usr/share/squid/errors{,.new} || die -} - -pkg_preinst() { - # Remove file in EROOT that the directory collides with. - rm -rf "${EROOT}"/usr/share/squid/errors || die - - # Following the collision protection check, reverse - # src_install's rename in ED. - mv "${ED}"/usr/share/squid/errors{.new,} || die -} - -pkg_postinst() { - elog "A good starting point to debug Squid issues is to use 'squidclient mgr:' commands such as 'squidclient mgr:info'." - - if [[ ${#r} -gt 0 ]]; then - elog "You are using a release with the official ${r} patch! Make sure you mention that, or send the output of 'squidclient mgr:info' when asking for support." - fi -} diff --git a/net-proxy/squid/squid-7.5.ebuild b/net-proxy/squid/squid-7.5.ebuild deleted file mode 100644 index 1a3ffe6562f8..000000000000 --- a/net-proxy/squid/squid-7.5.ebuild +++ /dev/null @@ -1,410 +0,0 @@ -# Copyright 1999-2026 Gentoo Authors -# Distributed under the terms of the GNU General Public License v2 - -EAPI=8 - -VERIFY_SIG_OPENPGP_KEY_PATH=/usr/share/openpgp-keys/squid.gpg -inherit autotools flag-o-matic linux-info pam systemd toolchain-funcs verify-sig - -DESCRIPTION="Full-featured web proxy cache" -HOMEPAGE="https://www.squid-cache.org/" - -MY_PV_MAJOR=$(ver_cut 1) -MY_PV_MINOR=$(ver_cut 2) -# Upstream patch ID for the most recent bug-fixed update to the formal release. -#r=-20181117-r0022167 -r= -if [[ -z ${r} ]]; then - SRC_URI=" - https://github.com/squid-cache/squid/releases/download/SQUID_${MY_PV_MAJOR}_${MY_PV_MINOR}/${P}.tar.xz - verify-sig? ( https://github.com/squid-cache/squid/releases/download/SQUID_${MY_PV_MAJOR}_${MY_PV_MINOR}/${P}.tar.xz.asc ) - " -else - SRC_URI=" - http://static.squid-cache.org/Versions/v${MY_PV_MAJOR}/${P}${r}.tar.bz2 - " - S="${S}${r}" -fi - -LICENSE="GPL-2+" -SLOT="0" -KEYWORDS="~alpha ~amd64 ~arm ~arm64 ~hppa ~mips ~ppc ~ppc64 ~riscv ~sparc ~x86" -IUSE="caps gnutls pam ldap samba sasl kerberos nis radius ssl snmp selinux logrotate test ecap" -IUSE+=" esi ssl-crtd mysql postgres sqlite systemd perl qos tproxy +htcp valgrind +wccp +wccpv2" -RESTRICT="!test? ( test )" -REQUIRED_USE="tproxy? ( caps ) qos? ( caps ) ssl-crtd? ( ssl )" - -DEPEND=" - acct-group/squid - acct-user/squid - dev-libs/libltdl - sys-libs/tdb - virtual/libcrypt:= - caps? ( >=sys-libs/libcap-2.16 ) - ecap? ( net-libs/libecap:1 ) - esi? ( - dev-libs/expat - dev-libs/libxml2:= - ) - ldap? ( net-nds/openldap:= ) - gnutls? ( >=net-libs/gnutls-3.4.0:= ) - logrotate? ( app-admin/logrotate ) - nis? ( - net-libs/libtirpc:= - net-libs/libnsl:= - ) - kerberos? ( virtual/krb5 ) - pam? ( sys-libs/pam ) - qos? ( net-libs/libnetfilter_conntrack ) - ssl? ( - >=dev-libs/nettle-3.4:= - !gnutls? ( - dev-libs/openssl:= - ) - ) - sasl? ( dev-libs/cyrus-sasl ) - systemd? ( sys-apps/systemd:= ) -" -RDEPEND=" - ${DEPEND} - mysql? ( dev-perl/DBD-mysql ) - postgres? ( dev-perl/DBD-Pg ) - perl? ( dev-lang/perl ) - samba? ( net-fs/samba ) - selinux? ( sec-policy/selinux-squid ) - sqlite? ( dev-perl/DBD-SQLite ) -" -DEPEND+=" valgrind? ( dev-debug/valgrind )" -BDEPEND=" - dev-lang/perl - virtual/pkgconfig - test? ( dev-util/cppunit ) - verify-sig? ( sec-keys/openpgp-keys-squid ) -" - -PATCHES=( - "${FILESDIR}"/${PN}-7.5-gentoo.patch - "${FILESDIR}"/${PN}-7.5-use-system-libltdl.patch - "${FILESDIR}"/${PN}-7.5-ar.patch -) - -pkg_pretend() { - if use tproxy; then - local CONFIG_CHECK="~NF_CONNTRACK ~NETFILTER_XT_MATCH_SOCKET ~NETFILTER_XT_TARGET_TPROXY" - linux-info_pkg_setup - fi -} - -src_unpack() { - if use verify-sig ; then - # Needed for downloaded patch (which is unsigned, which is fine) - verify-sig_verify_detached "${DISTDIR}"/${P}.tar.xz{,.asc} - fi - - default -} - -src_prepare() { - default - - # Fixup various paths - sed -i -e 's:/usr/local/squid/etc:/etc/squid:' \ - INSTALL QUICKSTART \ - scripts/fileno-to-pathname.pl \ - scripts/check_cache.pl || die - sed -i -e 's:/usr/local/squid/sbin:/usr/sbin:' \ - INSTALL QUICKSTART || die - sed -i -e 's:/usr/local/squid/var/cache:/var/cache/squid:' \ - QUICKSTART || die - sed -i -e 's:/usr/local/squid/var/logs:/var/log/squid:' \ - QUICKSTART \ - src/log/access_log.cc || die - sed -i -e 's:/usr/local/squid/logs:/var/log/squid:' \ - src/log/access_log.cc || die - sed -i -e 's:/usr/local/squid/libexec:/usr/libexec/squid:' \ - src/acl/external/unix_group/ext_unix_group_acl.8 \ - src/acl/external/session/ext_session_acl.8 || die - sed -i -e 's:/usr/local/squid/cache:/var/cache/squid:' \ - scripts/check_cache.pl || die - # /var/run/squid to /run/squid - sed -i -e 's:$(localstatedir)::' \ - src/ipc/Makefile.am || die - sed -i 's:/var/run/:/run/:g' tools/systemd/squid.service || die - - sed -i -e 's:_LTDL_SETUP:LTDL_INIT([installable]):' \ - libltdl/configure.ac || die - - # https://bugs.gentoo.org/956509 - AT_NO_RECURSIVE="yes" eautoreconf -} - -src_configure() { - # Workaround for bug #921688 - append-cxxflags -std=gnu++17 - - local myeconfargs=( - --cache-file="${S}"/config.cache - - --datadir=/usr/share/squid - --libexecdir=/usr/libexec/squid - --localstatedir=/var - --sysconfdir=/etc/squid - --with-default-user=squid - --with-logdir=/var/log/squid - --with-pidfile=/run/squid.pid - - --enable-build-info="Gentoo ${PF} (r: ${r:-NONE})" - --enable-log-daemon-helpers - --enable-url-rewrite-helpers - --enable-cache-digests - --enable-delay-pools - --enable-disk-io - --enable-eui - --enable-icmp - --enable-ipv6 - --enable-follow-x-forwarded-for - --enable-removal-policies="lru,heap" - --disable-strict-error-checking - --disable-arch-native - - --with-large-files - --with-build-environment=default - - --with-tdb - - --without-included-ltdl - --with-ltdl-include="${ESYSROOT}"/usr/include - --with-ltdl-lib="${ESYSROOT}"/usr/$(get_libdir) - - $(use_with caps cap) - $(use_enable snmp) - $(use_with ssl openssl) - $(use_with ssl nettle) - $(use_with gnutls) - $(use_with ldap) - $(use_enable ssl-crtd) - $(use_with systemd) - $(use_with test cppunit) - $(use_enable ecap) - $(use_enable esi) - $(use_enable esi expat) - $(use_enable esi xml2) - $(use_enable htcp) - $(use_with valgrind valgrind-debug) - $(use_enable wccp) - $(use_enable wccpv2) - ) - - # Basic modules - local basic_modules=( - NCSA - POP3 - getpwnam - - $(usev samba 'SMB') - $(usev ldap 'LDAP') - $(usev pam 'PAM') - $(usev sasl 'SASL') - $(usev nis 'NIS') - $(usev radius 'RADIUS') - ) - - use nis && append-cppflags "-I${ESYSROOT}/usr/include/tirpc" - - if use mysql || use postgres || use sqlite; then - basic_modules+=( DB ) - fi - - # Digests - local digest_modules=( - file - - $(usev ldap 'LDAP eDirectory') - ) - - # Kerberos - local negotiate_modules=( none ) - - myeconfargs+=( --without-mit-krb5 --without-heimdal-krb5 ) - - if use kerberos; then - # We intentionally overwrite negotiate_modules here to lose - # the 'none'. - negotiate_modules=( kerberos wrapper ) - - if has_version app-crypt/heimdal; then - myeconfargs+=( - --without-mit-krb5 - --with-heimdal-krb5 - ) - else - myeconfargs+=( - --with-mit-krb5 - --without-heimdal-krb5 - ) - fi - fi - - # NTLM modules - local ntlm_modules=( none ) - - if use samba ; then - # We intentionally overwrite ntlm_modules here to lose - # the 'none'. - ntlm_modules=( SMB_LM ) - fi - - # External helpers - local ext_helpers=( - file_userip - session - unix_group - delayer - time_quota - - $(usev samba 'wbinfo_group') - $(usev ldap 'LDAP_group eDirectory_userip') - ) - - use ldap && use kerberos && ext_helpers+=( kerberos_ldap_group ) - if use mysql || use postgres || use sqlite; then - ext_helpers+=( SQL_session ) - fi - - # Storage modules - local storeio_modules=( - aufs - diskd - rock - ufs - ) - - # - local transparent - if use kernel_linux; then - myeconfargs+=( - --enable-linux-netfilter - $(usev qos '--enable-zph-qos --with-netfilter-conntrack') - ) - fi - - tc-export_build_env BUILD_CXX - export BUILDCXX="${BUILD_CXX}" - export BUILDCXXFLAGS="${BUILD_CXXFLAGS}" - tc-export CC AR - - # Should be able to drop this workaround with newer versions. - # https://bugs.squid-cache.org/show_bug.cgi?id=4224 - tc-is-cross-compiler && export squid_cv_gnu_atomics=no - - # Bug #719662 - append-atomic-flags - - print_options_without_comma() { - # IFS as ',' will cut off any trailing commas - ( - IFS=',' - options=( $(printf "%s," "${@}") ) - echo "${options[*]}" - ) - } - - myeconfargs+=( - --enable-storeio=$(print_options_without_comma "${storeio_modules[@]}") - --enable-auth-basic=$(print_options_without_comma "${basic_modules[@]}") - --enable-auth-digest=$(print_options_without_comma "${digest_modules[@]}") - --enable-auth-ntlm=$(print_options_without_comma "${ntlm_modules[@]}") - --enable-auth-negotiate=$(print_options_without_comma "${negotiate_modules[@]}") - --enable-external-acl-helpers=$(print_options_without_comma "${ext_helpers[@]}") - ) - - econf "${myeconfargs[@]}" -} - -src_test() { - default - - # Suppress QA warning (bug #877729) for no tests executed - # for some subsuites. The layout is odd and there's a bunch - # of useless/stub directories which confuses it. - find "${S}" -iname test-suite.log -delete || die -} - -src_install() { - default - - systemd_dounit tools/systemd/squid.service - - # Need suid root for looking into /etc/shadow - fowners root:squid /usr/libexec/squid/basic_ncsa_auth - fperms 4750 /usr/libexec/squid/basic_ncsa_auth - - if use pam; then - fowners root:squid /usr/libexec/squid/basic_pam_auth - fperms 4750 /usr/libexec/squid/basic_pam_auth - fi - - # Pinger needs suid as well - fowners root:squid /usr/libexec/squid/pinger - fperms 4750 /usr/libexec/squid/pinger - - # These scripts depend on perl - if ! use perl; then - local perl_scripts=( - basic_pop3_auth ext_delayer_acl helper-mux - log_db_daemon security_fake_certverify - storeid_file_rewrite url_lfs_rewrite - ) - - local script - for script in "${perl_scripts[@]}"; do - rm "${ED}"/usr/libexec/squid/${script} || die - done - fi - - # Cleanup - rm -r "${D}"/run "${D}"/var/cache || die - - dodoc CONTRIBUTORS CREDITS ChangeLog INSTALL QUICKSTART README SPONSORS doc/*.txt - newdoc src/auth/negotiate/kerberos/README README.kerberos - newdoc src/auth/basic/RADIUS/README README.RADIUS - newdoc src/acl/external/kerberos_ldap_group/README README.kerberos_ldap_group - - if use pam; then - newpamd "${FILESDIR}"/squid.pam squid - fi - - newconfd "${FILESDIR}"/squid.confd-r2 squid - newinitd "${FILESDIR}"/squid.initd-r7 squid - - if use logrotate ; then - insinto /etc/logrotate.d - newins "${FILESDIR}"/squid.logrotate-r1 squid - else - exeinto /etc/cron.weekly - newexe "${FILESDIR}"/squid.cron-r1 squid.cron - fi - - diropts -m0750 -o squid -g squid - keepdir /var/log/squid /etc/ssl/squid /var/lib/squid - - # Hack for bug #834503 (see also bug #664940) - # Please keep this for a few years until it's no longer plausible - # someone is upgrading from < squid 5.7. - mv "${ED}"/usr/share/squid/errors{,.new} || die -} - -pkg_preinst() { - # Remove file in EROOT that the directory collides with. - rm -rf "${EROOT}"/usr/share/squid/errors || die - - # Following the collision protection check, reverse - # src_install's rename in ED. - mv "${ED}"/usr/share/squid/errors{.new,} || die -} - -pkg_postinst() { - if [[ ${#r} -gt 0 ]]; then - elog "You are using a release with the official ${r} patch! Make sure you mention that when asking for support." - fi -} |
