Logoj0ke.net Open Build Service > Projects > internetx > mod_security > Changes
Sign Up | Log In

Difference Between Revision 29 and internetx:managed:testing / mod_security

[-] Changed mod_security-ix.changes
x
 
1
@@ -1,112 +1,4 @@
2
 -------------------------------------------------------------------
3
-Wed Jan 11 06:34:21 UTC 2023 - Carsten Schoene <carsten.schoene@internetx.com>
4
-
5
-- Update to release 2.9.7 
6
-
7
--------------------------------------------------------------------
8
-Thu Mar 17 10:30:16 UTC 2022 - Local OBS User <cs@linux-administrator.com>
9
-
10
-- Update to release 2.9.5
11
-
12
--------------------------------------------------------------------
13
-Mon Aug 23 11:39:54 UTC 2021 - Local OBS User <cs@linux-administrator.com>
14
-
15
-- Update to release 2.9.4 
16
-
17
--------------------------------------------------------------------
18
-Wed Feb  5 09:52:49 UTC 2020 - Local OBS User <cs@linux-administrator.com>
19
-
20
-- Update to release 2.9.3
21
-
22
--------------------------------------------------------------------
23
-Wed May 16 06:44:59 UTC 2018 - cs@linux-administrator.com
24
-
25
-- Update to release 2.9.2 
26
-
27
--------------------------------------------------------------------
28
-Thu Apr  9 09:26:32 UTC 2015 - cs@linux-administrator.com
29
-
30
-- Update to relesae 2.9.0
31
-- set PERL ENV var to /usr/bin/perl
32
-- drop mlogc-disable-force-sslv3.patch (TLSv1 is default now)
33
-
34
--------------------------------------------------------------------
35
-Fri Aug  8 17:29:19 UTC 2014 - cs@linux-administrator.com
36
-
37
-- Update to release 2.8.0
38
-
39
--------------------------------------------------------------------
40
-Sun Jan  5 16:20:52 UTC 2014 - cs@linux-administrator.com
41
-
42
-- enable --enable-htaccess-config 
43
-
44
--------------------------------------------------------------------
45
-Thu Dec 19 23:23:46 UTC 2013 - cs@linux-administrator.com
46
-
47
-- Update to release 2.7.7 
48
-
49
--------------------------------------------------------------------
50
-Tue Jul 30 17:01:30 UTC 2013 - cs@linux-administrator.com
51
-
52
-- Update to release 2.7.5 
53
-
54
--------------------------------------------------------------------
55
-Thu Jul 11 19:33:18 UTC 2013 - cs@linux-administrator.com
56
-
57
-- build against asl-libxml2 for EL5 based systems
58
-
59
--------------------------------------------------------------------
60
-Sat Jun 29 17:00:16 UTC 2013 - cs@linux-administrator.com
61
-
62
-- added CVE-2013-2765.patch for 2.6.8 (included in 2.7.4)
63
-
64
--------------------------------------------------------------------
65
-Wed Jun  5 10:16:47 UTC 2013 - cs@linux-administrator.com
66
-
67
-- fix permissions in cleanup cron script 
68
-
69
--------------------------------------------------------------------
70
-Mon May 27 17:02:32 UTC 2013 - cs@linux-administrator.com
71
-
72
-- Update to release 2.7.4 (only for >= SLE_11, >= EL6) 
73
-
74
--------------------------------------------------------------------
75
-Fri Mar 29 17:31:45 UTC 2013 - cs@linux-administrator.com
76
-
77
-- Update to release 2.7.3 (only for >= SLE_11, >= EL6) 
78
-
79
--------------------------------------------------------------------
80
-Fri Jan 25 20:10:39 UTC 2013 - cs@linux-administrator.com
81
-
82
-- Update to release 2.7.2 (only for >= SLE_11, >= EL6) 
83
-
84
--------------------------------------------------------------------
85
-Sat Dec 29 10:33:37 UTC 2012 - cs@linux-administrator.com
86
-
87
-- Update to release 2.7.1 (only for >= SLE_11, >= EL6)
88
-
89
--------------------------------------------------------------------
90
-Wed Oct  3 08:10:36 UTC 2012 - cs@linux-administrator.com
91
-
92
-- Update to release 2.6.8 
93
-
94
--------------------------------------------------------------------
95
-Sun Jul 29 15:58:38 UTC 2012 - cs@linux-administrator.com
96
-
97
-- Update to release 2.6.7 
98
-
99
--------------------------------------------------------------------
100
-Wed Jul 18 07:05:49 UTC 2012 - cs@linux-administrator.com
101
-
102
-- disable Rule 340152
103
-
104
--------------------------------------------------------------------
105
-Tue Jul  3 08:30:53 UTC 2012 - cs@linux-administrator.com
106
-
107
-- disable Cross-Site Request Forgery (CSRF) rules
108
-- add cleanup cron for /var/asl/data/audit
109
-
110
--------------------------------------------------------------------
111
 Mon Jun 18 10:21:17 UTC 2012 - cs@linux-administrator.com
112
 
113
 - Update to release 2.6.6
114
[-] Changed mod_security-ix.spec ^
129
 
1
@@ -1,36 +1,11 @@
2
-%define aslxml 1
3
-%define pkgname modsecurity-
4
 Summary:   Security module for the Apache HTTP Server
5
 Name:      mod_security 
6
-%if 0%{?centos_version} >= 6 || 0%{?rhel_version} >= 600 || 0%{?sl_version} >= 600 || 0%{?suse_version} >= 1110 || 0%{?sles_version} >= 11
7
-%define        pkgversion  2.9.7
8
-%define        oldver      0
9
-%define        _aslxml     0
10
-%define        epoch       1
11
-BuildRequires: libxml2-devel
12
-%else
13
-%if %{aslxml}
14
-%define        pkgversion  2.9.7
15
-%define        oldver      0
16
-%define        _aslxml     1
17
-%define        epoch       1
18
-BuildRequires: asl-libxml2-devel
19
-%else
20
-%define        pkgversion  2.6.8
21
-%define        pkgname     modsecurity-apache_
22
-%define        oldver      1
23
-%define        _aslxml     0
24
-%define        epoch       0
25
-BuildRequires: libxml2-devel
26
-%endif
27
-%endif
28
-Version:   %{pkgversion}
29
-Epoch:     %{epoch}
30
-Release:   35
31
+Version:   2.6.6
32
+Release:   30
33
 License:   GPLv2
34
 URL:       http://www.modsecurity.org/
35
 Group:     System Environment/Daemons
36
-Source:        http://www.modsecurity.org/download/%{pkgname}%{version}.tar.bz2
37
+Source:        http://www.modsecurity.org/download/modsecurity-apache_%{version}.tar.bz2
38
 %if 0%{?rhel_version} || 0%{?centos_version} || 0%{?sl_version} || 0%{?redhat_version}
39
 Source1:   00_mod_security.conf
40
 Source2:   modsecurity_crs_10_config-default.conf
41
@@ -42,20 +17,14 @@
42
 Source3:   zzz_asl_custom_exclude.conf
43
 Source4:   zzz_asl_custom_local_exclude.conf
44
 Source5:   modsec-clamscan.pl
45
-Source6:   modsec-clean_var-asl-data-audit
46
 Patch1:        waf-label.patch
47
-Patch2:        modsecurity-2.9.1_curl-lower_7.34.patch
48
-Patch50:   CVE-2013-2765.patch
49
+Patch2:        mlogc-disable-force-sslv3.patch
50
 BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
51
 %if 0%{?rhel_version} || 0%{?centos_version} || 0%{?sl_version} || 0%{?redhat_version}
52
 Requires:  httpd httpd-mmn = %([ -a %{_includedir}/httpd/.mmn ] && cat %{_includedir}/httpd/.mmn || echo missing)
53
 BuildRequires: httpd-devel pkgconfig lua-devel
54
 Requires:  lua
55
-%if 0%{?rhel} >= 7 
56
-%define        apxs            %{_bindir}/apxs
57
-%else
58
 %define        apxs            %{_sbindir}/apxs
59
-%endif
60
 %define        apache_libexecdir   %(%{apxs} -q LIBEXECDIR)                                       
61
 ##%define      apache_sysconfdir   %(%{apxs} -q SYSCONFDIR)
62
 %define        apache_sysconfdir   /etc/httpd
63
@@ -79,10 +48,9 @@
64
 Provides:  apache2-mod_security2 = %{version}
65
 %endif
66
 
67
-BuildRequires: pcre-devel libtool curl-devel 
68
+BuildRequires: libxml2-devel pcre-devel libtool curl-devel 
69
 BuildRequires: curl
70
 
71
-BuildRequires:  autoconf automake
72
 Requires:  libxml2 pcre
73
 Provides:  ix-mod_security = %{version}
74
 
75
@@ -92,28 +60,20 @@
76
 as a powerful umbrella - shielding web applications from attacks.
77
 
78
 %prep
79
-%setup -n %{pkgname}%{version}
80
+%setup -n modsecurity-apache_%{version}
81
 %patch1 -p1
82
-%patch2 -p0
83
-%if 0%{?oldver} == 1
84
-%patch50 -p1
85
-%endif
86
+%patch2
87
 
88
 %build
89
 CFLAGS="%{optflags}"
90
 export CFLAGS
91
-export PERL=/usr/bin/perl
92
-
93
-[ ! -f configure ] && ./autogen.sh
94
 
95
 %configure \
96
-%if 0%{_aslxml} == 1
97
-   --with-libxml=/var/asl/usr/ \
98
-%endif
99
-        --enable-pcre-match-limit=no \
100
-        --enable-pcre-match-limit-recursion=no \
101
-   --enable-pcre-study \
102
-   --enable-htaccess-config
103
+   --disable-pcre-match-limit \
104
+   --disable-pcre-match-limit-recursion
105
+
106
+# Legacy from LoadFile
107
+#perl -pi.orig -e 's|LIBDIR|%{_libdir}|;' %{SOURCE1}
108
 
109
 make  %{_smp_mflags}
110
 
111
@@ -133,9 +93,6 @@
112
 install -D -m644 %{SOURCE3} %{buildroot}/%{apache_sysconfdir}/modsec/zzz_asl_custom_exclude.conf
113
 install -D -m644 %{SOURCE4} %{buildroot}/%{apache_sysconfdir}/modsec/zzz_asl_custom_local_exclude.conf
114
 install -D -m755 %{SOURCE5} %{buildroot}%{_bindir}/modsec-clamscan.pl
115
-install -D -m755 %{SOURCE6} %{buildroot}%{_sysconfdir}/cron.daily/modsec-clean_var-asl-data-audit
116
-sed -i s@"%APAUSR%:%APAGRP%"@"%{apache_usr}:%{apache_grp}"@g %{buildroot}%{_sysconfdir}/cron.daily/modsec-clean_var-asl-data-audit
117
-
118
 mkdir -p %{buildroot}/var/log/mlogc/data
119
 install -D -m755 mlogc/mlogc %{buildroot}%{_bindir}/mlogc
120
 install -m755 mlogc/mlogc-batch-load.pl %{buildroot}%{_bindir}/mlogc-batch-load.pl
121
@@ -166,7 +123,6 @@
122
 %config(noreplace) %{apache_sysconfdir}/modsec/zzz_asl_custom_local_exclude.conf
123
 %config(noreplace) %{_sysconfdir}/mlogc.conf
124
 %config %{_sysconfdir}/mlogc-default.conf
125
-%config %{_sysconfdir}/cron.daily/modsec-clean_var-asl-data-audit
126
 %defattr(-,%{apache_usr},%{apache_grp})
127
 %dir /var/asl
128
 %dir /var/asl/data
129
[+] Deleted CVE-2013-2765.patch ^
[+] Deleted modsecurity-2.9.1_curl-lower_7.34.patch ^
[+] Changed modsec-clamscan.pl ^
[+] Deleted modsec-clean_var-asl-data-audit ^
Deleted modsecurity-2.8.0.tar.bz2 ^
Deleted modsecurity-2.9.0.tar.bz2 ^
Deleted modsecurity-2.9.2.tar.bz2 ^
Deleted modsecurity-2.9.3.tar.bz2 ^
Deleted modsecurity-2.9.4.tar.bz2 ^
Deleted modsecurity-2.9.5.tar.bz2 ^
Deleted modsecurity-2.9.7.tar.bz2 ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/CHANGES ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/apache2/mod_security2.c ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/apache2/modsecurity.c ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/apache2/modsecurity.h ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/apache2/msc_release.h ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/apache2/re.c ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/apache2/re_actions.c ^
[+] Changed modsecurity-apache_2.6.6.tar.bz2/doc/Reference_Manual.html ^
Deleted modsecurity-apache_2.7.4.tar.bz2 ^
Deleted modsecurity-apache_2.7.5.tar.bz2 ^
Deleted modsecurity-apache_2.7.7.tar.bz2 ^
[+] Changed zzz_asl_custom_exclude.conf ^