Commit Graph

27 Commits

Author SHA256 Message Date
Tomáš Chvátal
f0ed59c0a7 Accepting request 652406 from home:darix:playground
- update to 2.0.10
  - Fix compiling on Alpine Linux.
  - Stop printf compiler warning on Alpine Linux due to rlim_t. 
  - manpage cosmetic.
  - Fix removing snmpd read threads when snmpd becomes unavailable.
  - Update to support libipset version 7.
  - Use ipset_printf for ipset messages so can go to log. 
  - When opening files for write, ensure files can only be read by
    root.  Issue #1048 referred to CVE-2018-19046 regarding files
    used for debugging purposes could potentially be read by non
    root users.  This commit ensures that such log files cannot be
    opened by non root users.
  - Disable fopen_safe() append mode by default If a non privileged
    user creates /tmp/keepalived.log and has it open for read (e.g.
    tail -f), then even though keepalived will change the owner to
    root and remove all read/write permissions from non owners, the
    application which already has the file open will be able to
    read the added log entries.  Accordingly, opening a file in
    append mode is disabled by default, and only enabled if
    --enable-smtp-alert-debug or --enable-log-file (which are
    debugging options and unset by default) are enabled.  This
    should further alleviate security concerns related to
    CVE-2018-19046.
  - vrrp: add support to constant time memcmp.  Just an update to
    use best practise security design pattern. While comparing
    password or hmac you need to ensure comparison function is time
    constant in order to figth against any timing attacks. We turn
    off potential compiler optimizations for this particular
    function to avoid any short circuit.
  - Make sure a non privileged user cannot read keepalived file
    output Ensure that when a file such as /tmp/keepalived.data is
    written, no non privileged can have a previous version of that
    file already open, thereby allowing them to read the data.
    This should fully resolve CVE-2018-19046.
- drop b7a98f9265ffb5927c4d54c9a30726c76e65bb52.patch: included in
  update

OBS-URL: https://build.opensuse.org/request/show/652406
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=48
2018-11-28 12:34:36 +00:00
Lars Vogdt
8b0ed32b30 Accepting request 648192 from home:darix:playground
- update to 2.0.9

OBS-URL: https://build.opensuse.org/request/show/648192
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=47
2018-11-12 10:09:35 +00:00
dd6b0b7e43 Accepting request 602574 from home:elvigia:branches:network
- Only Require insserv on distributions without systemd.
- Fix systemd related requires/buildRequires
- Do not run scriptlets that use insserv when using systemd

OBS-URL: https://build.opensuse.org/request/show/602574
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=45
2018-05-01 08:53:34 +00:00
2627baaa6d - add linux-4.15.patch
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=43
2018-02-22 10:07:39 +00:00
5f5ed9e175 - update to 1.4.1:
* Improve and fix use of getopt_long().
      We musn't use a long option val of 1, since getopt_long() can return
      that value.
      getopt_long() also returns longindex == 0 when there is no matching
      long option, and there needs to be careful checking if there is an
      error to work out whether a long or short option was used, which is
      needed for meaningful error messages.
    * Write assert() messages to syslog.
      assert()s are nasty things, but at least let's get the benefit of
      them, and write the messages to syslog, rather than losing them down
      stderr.
    * Enable sorry server at startup if quorum down due to alpha mode
      If alpha mode is configured on sufficient checkers so that a
      virtual server doesn't have a quorum, we need to add the sorry
      server at startup, otherwise it won't be added until a quorum has
      been achieved and subsequently lost again. In the case where some
      of the checkers remain in the down state at startup, this would have
      meant that the sorry server never got added.
    * For virtual servers, ensure quorum <= number of real servers
      If the quorum were gigher than the number of real servers, the
      quorum for the real server to come up could never be achieved, so
      if the quorum is greater than the number of real servers, reduce it
      to the number of real servers.
    * Fix some SNMP keepalived checker integer types and default values.
      Some virtual server and real server values were being sent to SNMP
      with a signed type whereas the value is unsigned, so set the type
      field correctly.
      Some virtual server and real server values that apply to checkers
      are set to nonsense default values in order to determine if a

OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=42
2018-02-21 23:10:27 +00:00
Lars Vogdt
349045239f Accepting request 568173 from home:darix:playground
- enable json stats and config dump support
  new BR: pkgconfig(json-c)
- disable dynamic loading of libipset and link it instead
- enable stacktrace support
- turn on snmp-rfcv2 and snmp-rfcv3 support
- do not reference the keepalived.socket in the rpm scriptlets

OBS-URL: https://build.opensuse.org/request/show/568173
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=40
2018-01-22 14:07:53 +00:00
7302425093 Accepting request 563827 from home:lrupp:branches:network
- update to 1.4.0
  * Add Linux build and runtime versions to -v output.
  * Log kernel version and build kernel version to log at startup.
  * Don't sleep for 1 send when exiting vrrp process if no vrrp instances.
  * With large configurations the syslog can get flooded and drop output.
    This commit adds options to not log to syslog, and also to log all
    output to files.
  * Add option to only flush log files before forking.
  * Don't poll netlink for all interfaces each time add a VMAC.
    We can poll for the individual interface details which significantly
    reduces what we have to process.
  * Print interface details in keepalived.data output.
  * Add high performace child finder code.
    The code to find the relevant thread to execute afer a child process
    (either a vrrp track script or a misc_check healthchecker) was doing
    a linear search for the matching pid, which if there are a large number
    of child processes running could become time consuming.
    The code now will enable high performance child finding, based on using
    mlists hashed by the pid, if there are 32 or more vrrp track scripts or
    misc check healthcheckers. The size of the mlist is based on the number
    of scripts, with a limit of 256.
  * Improve high performance child termination timeout code.
  * Preserve filename in script path name resolution.
    Some executables change their behaviour depending on the name by
    which they are invoked (e.g. /usr/sbin/pidof when it is a link to
    /usr/sbin/killall5). Using realpath() changes the file name part
    if it is a symbolic link. This commit resolves all symbolic links
    to directories, but leaves the file name part unaltered. It then
    checks the security of both the path to the link and the path to
    the real file.

OBS-URL: https://build.opensuse.org/request/show/563827
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=38
2018-01-15 15:17:04 +00:00
c9e3f60abb Accepting request 545974 from home:jengelh:branches:network
- Do not suppress errors from useradd.
- Ensure neutrality of description.

OBS-URL: https://build.opensuse.org/request/show/545974
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=36
2017-11-27 14:04:41 +00:00
e2fdff3ae9 Accepting request 545873 from home:itxaka:branches:network
Revert using github tarball and use original source again.

Update to 1.3.9: Too many fixes and features to list, refer to
  /usr/share/doc/packages/keepalived/ChangeLog for a detailed list.

OBS-URL: https://build.opensuse.org/request/show/545873
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=35
2017-11-27 10:49:50 +00:00
0272e4868b Accepting request 544663 from home:RBrownSUSE:branches:network
Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)

OBS-URL: https://build.opensuse.org/request/show/544663
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=33
2017-11-24 08:44:30 +00:00
Lars Vogdt
e56f6d28b5 Accepting request 458470 from home:darix:branches:network
- use tarball from https://github.com/acassen/keepalived/issues/524
  the original tarball did not build. This has the necessary fix
  applied. for the 1.3.4 update see the TODO entry in the preamble.

- update to 1.3.3
  Some minor fix, extensions and updates. snapcraft support. Refer
  to /usr/share/doc/packages/keepalived/ChangeLog for more infos.

OBS-URL: https://build.opensuse.org/request/show/458470
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=31
2017-02-24 09:47:13 +00:00
Lars Vogdt
06c19d3eaf Accepting request 445445 from home:darix:branches:network
- fix building with libnfnetlink. the additional include path needs
  to be in CPPFLAGS instead of CFLAGS now.
- enabled a few more features:
  - enhanced snmp support (V2/V3 RFC)
  - make sure we build with ipset/libiptc and routes support
- prepared dbus support: waiting for boo#1015141

- update 1.3.2
    - Security focused on notify heplers. Some minor fix and
      extensions.
  - changes from 1.3.1
    - Quick script fix for regression brought by last release.
  - changes from 1.3.0
    - New MAJOR release with stabilization fixes. Support to DBus.
      Conf extensions. Parser error log. Security extensions to run
      scripts more secure.
  - changes from 1.2.24
    - MAJOR release with stabilization fixes and new features like
      support to network namespace.
  Refer to /usr/share/doc/packages/keepalived/ChangeLog
  for more infos.

OBS-URL: https://build.opensuse.org/request/show/445445
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=29
2016-12-14 17:08:35 +00:00
Ismail Dönmez
5b63d9d826 Accepting request 412303 from home:stroeder:branches:network
update to 1.2.23

OBS-URL: https://build.opensuse.org/request/show/412303
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=27
2016-07-20 09:34:17 +00:00
b0d004a3c6 Accepting request 407252 from home:darix:playground
- update to 1.2.22
  Some VRRP fixes. Refer to ChangeLog for more infos.
- update to 1.2.21
  Some fixes for last major release 1.2.20. Extensions on vrrp
  framework. Refer to ChangeLog for more infos. 
- update to 1.2.20
  BUNCH of extensions, fixes, cleanup & production considerations.
  Distro packages maintainers are strongly encouraged to upgrade.
- new BR libnfnetlink-devel
- we no longer ship the VRRP-MIB

OBS-URL: https://build.opensuse.org/request/show/407252
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=25
2016-07-08 12:18:45 +00:00
Ismail Dönmez
ee7b5faade Accepting request 358848 from home:lrupp:branches:network
- enhanced keepalive-init.patch :
  + replace tabs with spaces
  + read /etc/sysconfig/keepalived, if exists and use the settings
    there instead of the default KEEPALIVED_OPTIONS in case the 
    user changed them

OBS-URL: https://build.opensuse.org/request/show/358848
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=23
2016-03-09 17:20:53 +00:00
6f60e9f95f Accepting request 356497 from home:darix:branches:network
- use package name buildrequires on sle11 to fix building

OBS-URL: https://build.opensuse.org/request/show/356497
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=21
2016-01-28 13:11:17 +00:00
fe77381aac Accepting request 356492 from home:darix:branches:network
- enable snmp for better monitoring
- enable sha1 support

OBS-URL: https://build.opensuse.org/request/show/356492
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=20
2016-01-28 11:52:05 +00:00
6902ce257c Accepting request 337023 from home:darix:branches:network
- no longer install the init script on systemd systems

OBS-URL: https://build.opensuse.org/request/show/337023
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=18
2015-10-13 17:33:57 +00:00
Rusmir Duško
5f7aa9cd9e Accepting request 336980 from home:dimstar:Factory
Update to 1.2.19

OBS-URL: https://build.opensuse.org/request/show/336980
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=16
2015-10-07 12:01:29 +00:00
8ac4fde276 Accepting request 290296 from home:dimstar:keepalived
- Update to version 1.2.15:
  + Bugfixes.
- Changes from version 1.2.14:
  + VRRP bugfixes and extensions. IPVS bugfixes and code code
    cleanup. 
- Changes from version 1.2.13:
  + VRRP fixes and extensions. Extrend and unify checker
    framework.

OBS-URL: https://build.opensuse.org/request/show/290296
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=14
2015-03-13 16:39:01 +00:00
Ismail Dönmez
87552b5509 Accepting request 283710 from home:elvigia:branches:network
- Build with -DOPENSSL_NO_SSL_INTERN, if package starts accessing
  the SSL library internals it must fail to build now, in upcoming
  openSSL versions structures are opaque.
- BuildRequire libnl3
- Do not strip binaries, fix -debuginfo packages.

OBS-URL: https://build.opensuse.org/request/show/283710
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=12
2015-02-02 12:54:29 +00:00
eb2710c2ad Accepting request 260489 from home:Ledest:misc
fix bashisms in pre script

OBS-URL: https://build.opensuse.org/request/show/260489
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=10
2014-11-10 10:17:04 +00:00
709681f4fa Accepting request 243203 from home:dimstar:rpmlintrc
Rename rpmlintrc as per pkg guideline to %{name}-rpmlintrc

OBS-URL: https://build.opensuse.org/request/show/243203
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=8
2014-07-31 15:36:14 +00:00
927e0c6d93 Accepting request 221839 from home:bmanojlovic:branches:network
latest version and systemd support
- updated to latest upstream version 1.2.12
  + Fix reallocation issue introduced in last merge.
  + Fix some minor memory leaks.
  + Better libnl support and selection.
  + VRRP unicast TTL fix.
  + Support to newer libnl.
  + More IPv6 support.
  + Fix/extend VRRP gratuitous ARP handling. 
  + Support xmit VRRP packets from base VMAC interface.
  + VRRP multicast group tweaking.
  + Fixed VRRP socket sync while leaving FAULT state.
  + Code cleanup and cosmetics.

OBS-URL: https://build.opensuse.org/request/show/221839
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=6
2014-02-12 11:12:18 +00:00
Sascha Peilicke
ced3249630 - Add cyrus-sasl for old distros
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=4
2014-01-07 10:55:56 +00:00
Sascha Peilicke
0c07d7c6b3 fix changelog
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=2
2013-11-19 15:13:03 +00:00
Sascha Peilicke
31629e3733 Accepting request 207596 from home:saschpe
OBS-URL: https://build.opensuse.org/request/show/207596
OBS-URL: https://build.opensuse.org/package/show/network/keepalived?expand=0&rev=1
2013-11-19 15:12:38 +00:00