Commit Graph

182 Commits

Author SHA1 Message Date
jakob
4b78108efb allocate user for mail/postgrey 2006-06-18 08:27:26 +00:00
jakob
10c54806e9 add user for net/smokeping (_smokeping) 2006-06-14 08:34:27 +00:00
alek
9ef1081f11 Add _rbldns user and group 2006-05-23 05:56:29 +00:00
bernd
80ff99b551 Add _mpd for audio/mpd. 2006-05-13 09:54:27 +00:00
pedro
8a993bd020 Permit __getcwd, noticed by uwe@, okay sturm@ 2006-05-02 19:14:37 +00:00
sturm
0948aaa6c9 fix maradns entry
allocate id for _freeradius
2006-04-16 12:51:55 +00:00
sturm
3c85bd3cdc add mknod() and a little cleanup 2006-04-03 21:12:06 +00:00
sturm
bfd3fed3c2 use a consistent set of paths whereever possible
this denies more manipulations outside the build area
2006-04-02 15:10:42 +00:00
sturm
58b010adf7 don't log accept()/listen()
mkfifo() is in fswrite
add quotactl
2006-04-02 15:02:06 +00:00
aanriot
0854d47f03 add _ipfreely:_ipfreely.
ok alek@ niallo@
2006-02-11 14:40:51 +00:00
david
d9861dc5fe +_nrpe and _snort 2006-02-04 13:21:27 +00:00
david
2bb1368a21 postgresql,-server user is not noauto; ok mbalmer@
exim user is also not noauto; no response from MAINTAINER
2006-01-25 03:36:35 +00:00
naddy
db1a7a5bc4 instruct configure scripts not to use our legacy malloc.h; ok espie@ 2006-01-13 15:34:06 +00:00
espie
5387da2262 remove autodetection of some headers until the dust settles. 2006-01-10 18:31:02 +00:00
jolan
a64ec6720a _akpop3d 2005-12-14 05:59:47 +00:00
sturm
ae0ccee5c8 _avenger, reminded by maintainer 2005-11-30 06:27:33 +00:00
pvalchev
d22d69bb02 sync 2005-11-28 01:12:29 +00:00
alek
d87c252496 Add _sane user and group 2005-10-03 21:23:28 +00:00
pedro
802e685b58 Add _xavante, okay jolan@ 2005-09-06 16:49:20 +00:00
marcm
a51e4cbcac add _gpsd 2005-09-05 00:36:49 +00:00
sturm
b5851b9917 fix uids
ok pval
2005-08-14 01:10:31 +00:00
mbalmer
e3a8473ecd Add uid/gid 549, _netplan:_netplan for misc/plan 2005-08-10 07:48:49 +00:00
aanriot
a4569e8894 add _polipo:_polipo for www/polipo. 2005-08-06 21:24:04 +00:00
robert
3455b52213 add _kismet 2005-07-28 10:04:34 +00:00
aanriot
7cd4e02269 add _honeyd user/group.
ok sturm@
2005-07-23 17:39:46 +00:00
sturm
4df85619a2 permit kqueue and kevent
noticed by Ray Lai <ray at cyth.net>
2005-07-09 07:29:01 +00:00
brad
104c67ad72 sync with CVS as of today 2005-07-03 01:00:54 +00:00
jcs
ffb3030fae _asterisk user and group, for telephony/asterisk
ok jolan@
2005-05-09 16:46:02 +00:00
jakob
6e1b8dacea add _openldap 2005-05-02 12:16:14 +00:00
mjc
16ccc57067 correct type for ac_cv_func_accept_arg3
ok espie@
thanks to naddy@ for the smart testing on this
2005-04-20 22:18:04 +00:00
pvalchev
00a8e6fa8c no x86_64 now; ok/from brad & kettenis 2005-04-09 07:38:27 +00:00
alek
8c8dc073fd Add _cyrus user used by mail/cyrus-imapd 2005-03-27 18:05:47 +00:00
pvalchev
b16d9789c3 er, should not have removed this 2005-03-11 22:36:24 +00:00
jakob
aada117edb add _flowd for pending net/flowd 2005-03-03 07:04:03 +00:00
pvalchev
7d1be9c589 not needed anymore 2005-03-01 17:36:11 +00:00
espie
b66eb54e50 don't cache termcap shit, unbreak bash. 2005-03-01 00:03:20 +00:00
espie
0b49fb825d add quite a few settings. Went through a full ports build... 2005-02-24 11:38:36 +00:00
brad
7f5084b430 for amd64 2005-02-06 04:58:45 +00:00
mbalmer
08040b9348 Enter uid/gid for print/cups. 2005-01-16 13:19:33 +00:00
jakob
f5d448568c add _dspam for mail/dspam 2005-01-11 16:02:27 +00:00
brad
62a14d75b6 simplify OpenBSD case by using arch(1) and sed to grab
the machine architecture. We now output amd64 instead
of x86_64 as it should be.

With input from millert@, drahn@ and kettenis@
2005-01-10 07:25:38 +00:00
mbalmer
85b377a1c7 Added uid/gid 539 for security/clamav.
ok alek@
2005-01-09 17:12:03 +00:00
pvalchev
0eecd57502 add zaurus 2005-01-02 20:47:21 +00:00
espie
edaa7db625 forgot to commit: we have proper get*_r functions. 2004-12-31 12:47:25 +00:00
sturm
44bbe01a92 set maximum length of command line arguments to 128k in order to reduce
systrace warnings
2004-11-27 12:01:16 +00:00
sturm
7c92ca48c2 deny writing empty filenames on the spot 2004-11-27 11:59:25 +00:00
sturm
95b2d10495 restrict link() and symlink() 2004-11-21 11:38:04 +00:00
mbalmer
bce2473cd5 Added uid/gid _vilter for mail/smtp-vilter.
ok naddy@, alek@
2004-11-17 10:45:25 +00:00
sturm
78074d531a add _maradns 2004-11-14 11:59:31 +00:00
sturm
7a4d2974e7 sparc64.p -> localhost 2004-11-14 11:56:07 +00:00
alek
0caade6762 User and group _xcept are now created automagically.
looks good pvalchev@
2004-11-13 01:52:25 +00:00
pvalchev
0a88d9c9c2 amd64.ports is now SMP 2004-11-07 18:32:01 +00:00
espie
63f4447086 avoid more get*_r functions until we decide upon an API... 2004-10-21 20:47:38 +00:00
espie
4ddb942744 getservbyname_r doesn't work/ doesn't have a prototype/ will vanish soon
from libc.

Make sure we don't pick it up in the interim.
2004-10-13 17:23:38 +00:00
jolan
c20baa5bed +_nostromo 2004-10-13 06:29:22 +00:00
espie
dfe26ec92e prime autoconf scripts with useful stuff.
okay naddy@
2004-10-03 09:50:44 +00:00
jolan
df8ad03ef6 scanlogd is auto now 2004-09-28 01:57:51 +00:00
naddy
1db4c1063b Changes for symon 2.65 - 2.67:
- removed netiso depends
- _symon uid 535, 525 never made it into ports/infrastructure/db/user.list
- ntp clockadjusts no longer trigger extra measurements
- daemon parts ported to freebsd/netbsd/linux

From: Willem Dijkstra <wpd@xs4all.nl>
2004-09-21 16:44:04 +00:00
brad
e12fe83b57 mips stuff 2004-08-11 20:45:38 +00:00
pvalchev
aa821a5387 sparc cluster too 2004-08-10 20:57:03 +00:00
sturm
02a925a3c7 Distributed Package Build is a helper script to permit several hosts
working together in doing a bulk package build.

ok pvalchev@, espie@
2004-08-10 20:54:38 +00:00
espie
364cdb1dee Add perl documentation directories. 2004-08-04 16:26:42 +00:00
xsa
c9544845f2 + _zope for www/zope 2004-08-03 10:17:50 +00:00
brad
350f1c87d9 sync with CVS as of today, adds luna88k and removes pegasos. 2004-06-15 04:06:26 +00:00
sturm
67a6ca5fda honour TMPDIR and PKG_TMPDIR in systrace policies
prodded by jolan@
2004-05-31 12:27:07 +00:00
jakob
043b234ca3 _jabberd 2004-05-29 13:08:54 +00:00
dhartmei
1f479b8766 milter-spamd is a sendmail milter plugin that passes mails through
SpamAssassin's spamd, rejecting mails inline that are considered
spam. ok sturm@
2004-05-24 07:35:47 +00:00
grange
f7ae4fc70a _cnupm user for net/cnupm
ok pval@
2004-05-13 06:52:12 +00:00
sturm
5a70af0a5f according to Niels, execve needs "true then permit" in order for emulation
changes to work correctly. This allows fixes for emulation issues with
some linux-compat ports (jdk, netscape).
2004-05-01 14:23:27 +00:00
robert
ca9b819469 Add the _vscan user/group (used by mail/amavisd-new); ok jolan@ 2004-04-30 21:32:56 +00:00
sturm
1f4d6d2e3b permit closefrom() 2004-04-24 07:17:44 +00:00
marcm
52c519feda Ok, actually commit the changes to user.list this time. 2004-02-21 06:16:58 +00:00
jakob
765d22c660 add user for security/stunnel 2004-02-16 12:04:29 +00:00
brad
1884bf6660 sync with CVS as of today, now includes entries for AMD64 and CATS. 2004-02-16 10:01:12 +00:00
sturm
8cae9bc0af permit fswrite to empty filename, syscalls are supposed to fail on this 2004-01-31 11:40:39 +00:00
sturm
403f6f070b permit osigaltstack 2004-01-24 13:02:11 +00:00
sturm
449fce82f8 more 2004-01-18 11:12:24 +00:00
sturm
77310a5629 don't log permitted bind() and connect()
permit connect() to /dev/log
2004-01-15 22:41:37 +00:00
sturm
b326e8c555 permit msync() and setreuid() 2004-01-14 19:54:09 +00:00
dhartmei
ad9e816cd5 update to 0.9, drop privileges to user _milter-regex.
note: local socket changed to /var/spool/milter-regex/spool, adjust
sendmail.cf/.mc accordingly when updating:

-`S=unix:/var/spool/milter-regex, T=S:30s;R:2m'
+`S=unix:/var/spool/milter-regex/sock, T=S:30s;R:2m'
2004-01-07 14:57:34 +00:00
sturm
0afcb3ce68 use WRKDIR instead of WRKOBJDIR for systrace, as the latter is not defined
unconditionally

found by Michael Coulter <mjc at bitz dot ca>
2004-01-04 09:07:19 +00:00
jolan
4144c08861 no need for ${PORTSDIR}/{cdrom,ftp}-packages anymore
ok pval sturm
2004-01-04 08:01:10 +00:00
sturm
d15dcf1e2c +_tomcat 2003-12-15 22:33:57 +00:00
david
376e947e23 +_quagga 2003-12-11 19:05:38 +00:00
sturm
acfab03a8c +compat_43_ogetpagesize and compat_43_olseek to allow systrace'd build
of archivers/rar on i386
+setgroups
2003-11-27 20:01:49 +00:00
kevlo
03ccfcbace +_mail 2003-11-03 06:14:07 +00:00
brad
231f90d5d2 add pegasos 2003-10-31 06:13:22 +00:00
pvalchev
71a69fd1d6 add missing /var/games; ok espie nikolay 2003-10-16 15:38:50 +00:00
sturm
7d49a4123d - _mixmaster 2003-09-29 20:23:41 +00:00
pvalchev
577a7d34de delete; i386-only list superceded with data under infrastructure/plist/ 2003-09-23 01:32:12 +00:00
pvalchev
13fc8444b0 sync to my lists, this is probably going to close to what 3.4 will have 2003-09-06 05:11:11 +00:00
sturm
a9836ab377 +getpeername
ok naddy@
2003-08-24 20:38:25 +00:00
pvalchev
af2cc467d1 remove unzels with bad licenses that cannot go to the CD 2003-08-09 20:22:36 +00:00
pvalchev
6eb4275ce4 update 2003-08-09 17:48:21 +00:00
sturm
16ce58292a this makes our build infrastructure systrace aware
original idea from jsyn@, discussed and first tests at c2k3

Warning!
- this commit is different from all patches sent around, please remove
  them before updating
- due to a few bugs in systrace this is currently not ready for the casual
  porter and several ports will fail to build, you've been warned

The idea of this patch is to help a porter when developing a new port.
With systrace the configure, build and fake stages are not allowed to
open network connections or write outside some well defined directories.
This way misbehaving programs will be noticed due to logfile entries in
/var/log/messages and the port can be fixed. There is generally no need
for endusers to use this, as the checksum ensures that ports in the
future will behave the same as they did when porting. :)

To activate systrace'd port building, set USE_SYSTRACE=Yes (e.g. in
/etc/mk.conf)

tested by some people, ok espie@
2003-07-28 17:17:04 +00:00
jolan
03feeb8ee3 +_ffproxy 2003-07-25 04:59:54 +00:00
jolan
43f21093a4 +dovecot 2003-07-14 23:49:32 +00:00
sturm
1448268198 be more specific wrt/ fixed uids/gids 2003-06-23 19:20:58 +00:00
sturm
a01b82e1b5 New user- and groupname schema for ports. All users and groups created
by ports have to have a leading '_' and a fixed id. They have also to
be added to db/user.list.

user.db and createuser are not used and are superfluous now.
2003-06-22 09:59:35 +00:00
pvalchev
17c64f0933 update to reality 2003-03-31 03:53:23 +00:00