From owner-freebsd-ports-bugs@FreeBSD.ORG Mon Apr 21 01:30:00 2014 Return-Path: Delivered-To: freebsd-ports-bugs@smarthost.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id DF218C46 for ; Mon, 21 Apr 2014 01:30:00 +0000 (UTC) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:1900:2254:206c::16:87]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id B48FC195A for ; Mon, 21 Apr 2014 01:30:00 +0000 (UTC) Received: from freefall.freebsd.org (localhost [127.0.0.1]) by freefall.freebsd.org (8.14.8/8.14.8) with ESMTP id s3L1U0Sb075909 for ; Mon, 21 Apr 2014 01:30:00 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.8/8.14.8/Submit) id s3L1U0iC075899; Mon, 21 Apr 2014 01:30:00 GMT (envelope-from gnats) Resent-Date: Mon, 21 Apr 2014 01:30:00 GMT Resent-Message-Id: <201404210130.s3L1U0iC075899@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-ports-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, John Marshall Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id EE226BD1 for ; Mon, 21 Apr 2014 01:22:40 +0000 (UTC) Received: from mta1.riverwillow.net.au (mta1.riverwillow.net.au [IPv6:2001:8000:1000:1801::36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client CN "mta1.riverwillow.net.au", Issuer "Riverwillow Root Certificate 2010-04-12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 5EE61191D for ; Mon, 21 Apr 2014 01:22:40 +0000 (UTC) Received: from rwsrv08.gfn.riverwillow.net.au (rwsrv08.gfn.riverwillow.net.au [IPv6:2001:8000:1000:18e1::28]) by mta1.riverwillow.net.au (8.14.8/8.14.7) with ESMTP id s3L1MYhe060470 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Mon, 21 Apr 2014 11:22:34 +1000 (AEST) (envelope-from john.marshall@riverwillow.com.au) Received: from rwsrv08.gfn.riverwillow.net.au (localhost [IPv6:::1]) by rwsrv08.gfn.riverwillow.net.au (8.14.8/8.14.8) with ESMTP id s3L1MYoR060466 for ; Mon, 21 Apr 2014 11:22:34 +1000 (AEST) Received: (from john@localhost) by rwsrv08.gfn.riverwillow.net.au (8.14.8/8.14.8/Submit) id s3L1MXtf060465; Mon, 21 Apr 2014 11:22:33 +1000 (AEST) Message-Id: <201404210122.s3L1MXtf060465@rwsrv08.gfn.riverwillow.net.au> Date: Mon, 21 Apr 2014 11:22:33 +1000 (AEST) From: John Marshall To: FreeBSD-gnats-submit@freebsd.org X-Send-Pr-Version: 3.114 Subject: ports/188835: [PATCH] security/sshguard unbreak rc file. X-BeenThere: freebsd-ports-bugs@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list Reply-To: John Marshall List-Id: Ports bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 21 Apr 2014 01:30:00 -0000 >Number: 188835 >Category: ports >Synopsis: [PATCH] security/sshguard unbreak rc file. >Confidential: no >Severity: serious >Priority: medium >Responsible: freebsd-ports-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Mon Apr 21 01:30:00 UTC 2014 >Closed-Date: >Last-Modified: >Originator: John Marshall >Release: FreeBSD 9.2-RELEASE-p4 amd64 >Organization: Riverwillow Pty Ltd >Environment: System: FreeBSD rwsrv08.gfn.riverwillow.net.au 9.2-RELEASE-p4 FreeBSD 9.2-RELEASE-p4 #0 r264290M: Wed Apr 9 15:46:58 AEST 2014 root@rwsrv08.gfn.riverwillow.net.au:/usr/obj/usr/src/sys/RWSRV08 amd64 >Description: r350643 made modifications to the rc file (files/sshguard.in) which prevent the daemon starting. 1. pidfile=${sshguard_pidfile:-"/var/run/${name}.pid"} The use of :- will not assign the default pidfile value to sshguard_pidfile. sshguard_pidfile is required by the later command_args assignment. Passing a null ${sshguard_pidfile} value to the daemon's -i argument results in the daemon failing to start. 2. ${sshguard_watch_params} no longer set before command_args assignment Failing to set ${sshguard_watch_params} prior to the command_args assigment means that the list of log files to monitor is empty. Again, the daemon will not start. >How-To-Repeat: >Fix: Suggested patch attached. Works fine for me. --- sshguard_r350643.diff begins here --- Index: security/sshguard/files/sshguard.in =================================================================== --- security/sshguard/files/sshguard.in (revision 351653) +++ security/sshguard/files/sshguard.in (working copy) @@ -74,7 +74,8 @@ : ${sshguard_whitelistfile="%%PREFIX%%/etc/sshguard.whitelist"} : ${sshguard_watch_logs="/var/log/auth.log:/var/log/maillog"} -pidfile=${sshguard_pidfile:-"/var/run/${name}.pid"} +pidfile=${sshguard_pidfile:="/var/run/${name}.pid"} +sshguard_watch_params=`echo ${sshguard_watch_logs} | tr : \\\n | sed -e s/^/-l\ /g | tr \\\n \ ` command="/usr/sbin/daemon" actual_command="%%PREFIX%%/sbin/${name}" @@ -87,7 +88,6 @@ { mkdir -p `dirname ${sshguard_blacklist##*:}` [ -e ${sshguard_whitelistfile} ] || touch ${sshguard_whitelistfile} - sshguard_watch_params=`echo ${sshguard_watch_logs} | tr : \\\n | sed -e s/^/-l\ /g | tr \\\n \ ` } run_rc_command "$1" --- sshguard_r350643.diff ends here --- >Release-Note: >Audit-Trail: >Unformatted: