From nobody Fri Jul 28 06:31:52 2023 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RByTh4Zs6z4pbMQ; Fri, 28 Jul 2023 06:31:52 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RByTh3xj7z3Qkx; Fri, 28 Jul 2023 06:31:52 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1690525912; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=1fpzJ+bDutAMKPqFVoq033e5s8X/1ambXAk8Sp56yV4=; b=ShEaxnsPOcNNm6Xv3RTOLEbdqHkpE44wIoOkXmBGwiVmtWZdR/lqUT1tGx7AH9zVRzpLGP wDQ/9lfPZ3Ahwi/w9m+UdtgM02GUmXmgM3LTU12FMqJex9lUzAw1WD6jr/HKvNhnStDWNE HasctdA9gcnvd7i3zuMToi+t4sT8f3hHF+zz7b4uH7VjSKPm454fpO9Q6otXdyydJbn4qu M8bj9TlfRLvZhzKyC+qVOBsWwSyWi3+n/xPIplX2s0esklSg9Zyap2GtcqI2OTlKnCZXl0 4vKUxmh+ed4O8MiC43NhxyKnptZnrbHz55rYu4qX6aSgLo6bLeJ9IQceuPM3gQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1690525912; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=1fpzJ+bDutAMKPqFVoq033e5s8X/1ambXAk8Sp56yV4=; b=nPbjyCWDdUTpIboeOjJD+XWQwD3RkOZ/B8+PuuHe0M7s4UmV5xCPdvU+4Avp9hnxkdOb+a r5My+Rn++ceL5hqYgNHvrWH8JTd3X1qOsZcBTZRnDnbPxA6yoqAatjE/Qi4SHy1otHddn8 kalPadI1aAy+EIQDYGh1Eznl9fcwbH3IpAcvZn02sEzQV7PY1QFs5U2beNYU75ImnwLjx3 //cVEUbLu0hbvpZ8R1kldeu1puOH2d+qizbom1OwPIEN18ghDcp2jykgqtAJfJj/PD6ho8 IJ91ia0c5t1FZ26IzyNzqy/3bWWMlWERAgfipYJwqEEl0u5zEYs0s6QO1+oCtQ== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1690525912; a=rsa-sha256; cv=none; b=rnyBWFA4gzA/t6PcSiTXuJqb+XYt0N3O0OZLFaas25TlPxub+iABk8NmcwKHmENuYV1hMo fYgbaM3CJ2RNYozT5NXELj0vgKwA1g1ZjDhUELVjuitzKisZBCytnKXXXOAzyUnKGKbBYE w+SfJObbluxD5XGdOptGsbDBB4+u/Kt2T7t2e3olheIRmFrrSC25ZGmucrEBCl83qBXXFw TyRleiuDI22/BRhzbAs8cTCwW0dn5+SS0PedaCrlR6hAmjCXGE2vz8DaLUdeUTopYW+Tnv 3foF41Dih5aTV5MuCrnamiPSJReOzYL8j3R9FwuJlsrpR1nKreOyvxh6JRZnyw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RByTh31MYzh20; Fri, 28 Jul 2023 06:31:52 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 36S6Vq0q012511; Fri, 28 Jul 2023 06:31:52 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 36S6Vqct012510; Fri, 28 Jul 2023 06:31:52 GMT (envelope-from git) Date: Fri, 28 Jul 2023 06:31:52 GMT Message-Id: <202307280631.36S6Vqct012510@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: =?utf-8?Q?Fernando=20Apestegu=C3=ADa?= Subject: git: c85caa3933d0 - main - security/rkhunter: Modernize and correct the periodic script List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-ports-all@freebsd.org X-BeenThere: dev-commits-ports-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: fernape X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: c85caa3933d08274a9ba9b1be16ee8af5583b99a Auto-Submitted: auto-generated The branch main has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=c85caa3933d08274a9ba9b1be16ee8af5583b99a commit c85caa3933d08274a9ba9b1be16ee8af5583b99a Author: Helge Oldach AuthorDate: 2023-07-27 06:42:27 +0000 Commit: Fernando ApesteguĂ­a CommitDate: 2023-07-28 06:31:32 +0000 security/rkhunter: Modernize and correct the periodic script Modernize the script but use a compatibility shim to maintain previous variables. PR: 272516 Reported by: freebsd@oldach.net Approved by: lukasz@wasikowski.net (maintainer) --- security/rkhunter/Makefile | 2 +- security/rkhunter/files/415.rkhunter.in | 67 ++++++++++++++++----------------- security/rkhunter/pkg-message | 10 +++-- 3 files changed, 40 insertions(+), 39 deletions(-) diff --git a/security/rkhunter/Makefile b/security/rkhunter/Makefile index f5ed7d474a72..f5c2ef749bdd 100644 --- a/security/rkhunter/Makefile +++ b/security/rkhunter/Makefile @@ -1,6 +1,6 @@ PORTNAME= rkhunter PORTVERSION= 1.4.6 -PORTREVISION= 1 +PORTREVISION= 2 CATEGORIES= security MASTER_SITES= SF diff --git a/security/rkhunter/files/415.rkhunter.in b/security/rkhunter/files/415.rkhunter.in index b35e70f724b1..4e33dc5ab443 100644 --- a/security/rkhunter/files/415.rkhunter.in +++ b/security/rkhunter/files/415.rkhunter.in @@ -2,10 +2,12 @@ # This is a maintenance shell script for the rkhunter security tool. # You can enable this script in /etc/periodic.conf file by putting these lines into it: -# daily_rkhunter_update_enable="YES" -# daily_rkhunter_update_flags="--update --nocolors" -# daily_rkhunter_check_enable="YES" -# daily_rkhunter_check_flags="--checkall --nocolors --skip-keypress" +# security_rkhunter_update_enable="YES" +# security_rkhunter_update_period="daily" +# security_rkhunter_update_flags="--update --nocolors" +# security_rkhunter_check_enable="YES" +# security_rkhunter_check_period="daily" +# security_rkhunter_check_flags="--checkall --nocolors --skip-keypress" # # Written by: Gabor Kovesdan @@ -14,40 +16,37 @@ if [ -r /etc/defaults/periodic.conf ]; then source_periodic_confs fi -SLEEP=/bin/sleep -JOT=/usr/bin/jot - -random() { - ${JOT} -r 1 0 900 -} - -: ${daily_rkhunter_update_flags="--update --nocolors"} -: ${daily_rkhunter_check_flags="--checkall --nocolors --skip-keypress"} +# compatibility with pre-stable/12 style variables +for type in update check +do + for mode in enable flags + do + eval old=\"\$daily_rkhunter_${type}_${mode}\" + if test -n "$old" + then + echo "Warning: Variable \$daily_rkhunter_${type}_${mode} is deprecated, use \$security_rkhunter_${type}_${mode} instead." >&2 + eval : \${security_rkhunter_${type}_${mode}:="\$daily_rkhunter_${type}_${mode}"} + fi + done +done -case "$daily_rkhunter_update_enable" in - [Yy][Ee][Ss]) +# defaults +: ${security_rkhunter_update_period:="daily"} +: ${security_rkhunter_check_period:="daily"} +: ${security_rkhunter_update_flags:="--update --nocolors"} +: ${security_rkhunter_check_flags:="--checkall --nocolors --skip-keypress"} +if check_yesno_period security_rkhunter_update_enable +then echo "" echo "Updating the rkhunter database..." - # When non-interactive, sleep to reduce congestion on rkhunter site - if [ "$1" != -nodelay ]; then - # In FreeBSD 12.0 the anticongestion function should be used - # instead of a hard-coded sleep - if [ -n "$anticongestion_sleeptime" ]; then - anticongestion - else - ${SLEEP} $(random) - fi - fi - %%PREFIX%%/bin/rkhunter ${daily_rkhunter_update_flags} - ;; -esac - -case "$daily_rkhunter_check_enable" in - [Yy][Ee][Ss]) + anticongestion + %%PREFIX%%/bin/rkhunter ${security_rkhunter_update_flags} +fi +if check_yesno_period security_rkhunter_check_enable +then echo "" echo "Running rkhunter..." - %%PREFIX%%/bin/rkhunter ${daily_rkhunter_check_flags} - ;; -esac + %%PREFIX%%/bin/rkhunter ${security_rkhunter_check_flags} +fi diff --git a/security/rkhunter/pkg-message b/security/rkhunter/pkg-message index ee7fe15bd879..3a4a2f1bb6ad 100644 --- a/security/rkhunter/pkg-message +++ b/security/rkhunter/pkg-message @@ -4,14 +4,16 @@ You should keep your rkhunter database up-to-date. This can be done automatically by putting this line to periodic.conf(5) files: -daily_rkhunter_update_enable="YES" -daily_rkhunter_update_flags="--update --nocolors" +security_rkhunter_update_enable="YES" +security_rkhunter_update_period="daily" +security_rkhunter_update_flags="--update --nocolors" Also, you can run rkhunter as a part of the daily security check by putting this line to periodic.conf(5) files: -daily_rkhunter_check_enable="YES" -daily_rkhunter_check_flags="--checkall --nocolors --skip-keypress" +security_rkhunter_check_enable="YES" +security_rkhunter_check_period="daily" +security_rkhunter_check_flags="--checkall --nocolors --skip-keypress" EOM } ]