diff options
author | Menno Duursma <druiloor@zonnet.nl> | 2010-09-17 04:47:52 -0400 |
---|---|---|
committer | Robby Workman <rworkman@slackbuilds.org> | 2010-09-21 22:09:37 -0500 |
commit | bb94b73abd64a8108a904be8134b876b71484acf (patch) | |
tree | 4b5baaef354606a6207f7f5cb50d99753ae6c9de | |
parent | 3dae1846b0ad71c7528dd955362f6064f837f22a (diff) |
libraries/php-suhosin: Added (PHP security extension)
Signed-off-by: dsomero <xgizzmo@slackbuilds.org>
-rw-r--r-- | libraries/php-suhosin/README | 4 | ||||
-rw-r--r-- | libraries/php-suhosin/README.SLACKWARE | 17 | ||||
-rw-r--r-- | libraries/php-suhosin/doinst.sh | 15 | ||||
-rw-r--r-- | libraries/php-suhosin/php-suhosin.SlackBuild | 92 | ||||
-rw-r--r-- | libraries/php-suhosin/php-suhosin.info | 10 | ||||
-rw-r--r-- | libraries/php-suhosin/slack-desc | 19 |
6 files changed, 157 insertions, 0 deletions
diff --git a/libraries/php-suhosin/README b/libraries/php-suhosin/README new file mode 100644 index 000000000000..a83958e8325f --- /dev/null +++ b/libraries/php-suhosin/README @@ -0,0 +1,4 @@ +Suhosin is an advanced protection system for PHP installations. + +It was designed to protect servers and users from known and unknown flaws +in PHP applications and the PHP core. See also: README.SLACKWARE diff --git a/libraries/php-suhosin/README.SLACKWARE b/libraries/php-suhosin/README.SLACKWARE new file mode 100644 index 000000000000..a02bb51c0a80 --- /dev/null +++ b/libraries/php-suhosin/README.SLACKWARE @@ -0,0 +1,17 @@ +Suhosin comes in two independent parts, that can be used separately or +in combination. The first part is a small patch against the PHP core, +that implements a few low-level protections against bufferoverflows or +format string vulnerabilities. + +The second part is a powerful PHP extension that implements all the other +protections. Suhosin is binary compatible with normal PHP installations, +which means it is compatible to 3rd party binary extensions like +ZendOptimizer. + +This package includes only the extention. + +After installation the 'php -v' command should list it as loaded. +For more info try: + +php -i | grep suhosin + diff --git a/libraries/php-suhosin/doinst.sh b/libraries/php-suhosin/doinst.sh new file mode 100644 index 000000000000..f6da772a2506 --- /dev/null +++ b/libraries/php-suhosin/doinst.sh @@ -0,0 +1,15 @@ +config() { + NEW="$1" + OLD="$(dirname $NEW)/$(basename $NEW .new)" + # If there's no config file by that name, mv it over: + if [ ! -r $OLD ]; then + mv $NEW $OLD + elif [ "$(cat $OLD | md5sum)" = "$(cat $NEW | md5sum)" ]; then + # toss the redundant copy + rm $NEW + fi + # Otherwise, we leave the .new copy for the admin to consider... +} + +config etc/php/suhosin.ini.new + diff --git a/libraries/php-suhosin/php-suhosin.SlackBuild b/libraries/php-suhosin/php-suhosin.SlackBuild new file mode 100644 index 000000000000..5529126ee6e9 --- /dev/null +++ b/libraries/php-suhosin/php-suhosin.SlackBuild @@ -0,0 +1,92 @@ +#!/bin/sh + +# Slackware build script for Suhosin + +# Written by Menno Duursma <druiloor@zonnet.nl> + +# This program is free software. It comes without any warranty. +# Granted WTFPL, Version 2, as published by Sam Hocevar. See +# http://sam.zoy.org/wtfpl/COPYING for more details. + +# Modified by SlackBuilds.org +# Re-modified by Menno Duursma to match perl-template example + +SRCNAM=suhosin +PRGNAM=php-$SRCNAM +VERSION=${VERSION:-0.9.32.1} +BUILD=${BUILD:-1} +TAG=${TAG:-_SBo} + +if [ -z "$ARCH" ]; then + case "$( uname -m )" in + i?86) ARCH=i486 ;; + arm*) ARCH=arm ;; + *) ARCH=$( uname -m ) ;; + esac +fi + +CWD=$(pwd) +TMP=${TMP:-/tmp/SBo} +PKG=$TMP/package-$PRGNAM +OUTPUT=${OUTPUT:-/tmp} + +if [ "$ARCH" = "i486" ]; then + SLKCFLAGS="-O2 -march=i486 -mtune=i686" + LIBDIRSUFFIX="" +elif [ "$ARCH" = "i686" ]; then + SLKCFLAGS="-O2 -march=i686 -mtune=i686" + LIBDIRSUFFIX="" +elif [ "$ARCH" = "x86_64" ]; then + SLKCFLAGS="-O2 -fPIC" + LIBDIRSUFFIX="64" +else + SLKCFLAGS="-O2" + LIBDIRSUFFIX="" +fi + +set -e # Exit on most errors + +rm -rf $PKG +mkdir -p $TMP $PKG $OUTPUT +cd $TMP +rm -rf $SRCNAM-$VERSION +tar xvf $CWD/$SRCNAM-$VERSION.tar.gz +cd $SRCNAM-$VERSION +chown -R root:root . +find . -type d | xargs chmod 0755 +find . -type f | xargs chmod a-s,go-w + +# With PHP extentions apparently this is needed +phpize + +CFLAGS="$SLKCFLAGS" \ +CXXFLAGS="$SLKCFLAGS" \ +EXTENSION_DIR="$PKG/usr/lib$LIBDIRSUFFIX/php/extensions" \ +./configure \ + --prefix=/usr \ + --libdir=/usr/lib$LIBDIRSUFFIX \ + --sysconfdir=/etc \ + --localstatedir=/var + +make + +install -D -m755 modules/suhosin.so $PKG/usr/lib$LIBDIRSUFFIX/php/extensions/suhosin.so + +# Add to the PHP config +mkdir -p $PKG/etc/php +echo "extension=suhosin.so" > $PKG/etc/php/suhosin.ini.new + +find $PKG | xargs file | grep -e "executable" -e "shared object" | grep ELF \ + | cut -f 1 -d : | xargs strip --strip-unneeded 2> /dev/null || true + +mkdir -p $PKG/usr/doc/$PRGNAM-$VERSION +cp -a [A-Z][A-Z]* Changelog $PKG/usr/doc/$PRGNAM-$VERSION +cat $CWD/$PRGNAM.SlackBuild > $PKG/usr/doc/$PRGNAM-$VERSION/$PRGNAM.SlackBuild +cat $CWD/README.SLACKWARE > $PKG/usr/doc/$PRGNAM-$VERSION/README.SLACKWARE + +mkdir -p $PKG/install +cat $CWD/slack-desc > $PKG/install/slack-desc +cat $CWD/doinst.sh > $PKG/install/doinst.sh + +cd $PKG +/sbin/makepkg -l y -c n $OUTPUT/$PRGNAM-$VERSION-$ARCH-$BUILD$TAG.${PKGTYPE:-tgz} diff --git a/libraries/php-suhosin/php-suhosin.info b/libraries/php-suhosin/php-suhosin.info new file mode 100644 index 000000000000..083f7b24d201 --- /dev/null +++ b/libraries/php-suhosin/php-suhosin.info @@ -0,0 +1,10 @@ +PRGNAM="php-suhosin" +VERSION="0.9.32.1" +HOMEPAGE="http://www.hardened-php.net/suhosin/index.html" +DOWNLOAD="http://download.suhosin.org/suhosin-0.9.32.1.tar.gz" +MD5SUM="26a86f0f684a656c3e789e3eb4ec1db3" +DOWNLOAD_x86_64="" +MD5SUM_x86_64="" +MAINTAINER="Menno Duursma" +EMAIL="druiloor@zonnet.nl" +APPROVED="dsomero" diff --git a/libraries/php-suhosin/slack-desc b/libraries/php-suhosin/slack-desc new file mode 100644 index 000000000000..98d908005e66 --- /dev/null +++ b/libraries/php-suhosin/slack-desc @@ -0,0 +1,19 @@ +# HOW TO EDIT THIS FILE: +# The "handy ruler" below makes it easier to edit a package description. Line +# up the first '|' above the ':' following the base package name, and the '|' +# on the right side marks the last column you can put a character in. You must +# make exactly 11 lines for the formatting to be correct. It's also +# customary to leave one space after the ':'. + + |-----handy-ruler------------------------------------------------------| +php-suhosin: Suhosin (PHP security extension) +php-suhosin: +php-suhosin: Suhosin is an advanced protection system for PHP installations. It +php-suhosin: was designed to protect servers and users from known and unknown +php-suhosin: flaws in PHP applications and the PHP core. +php-suhosin: +php-suhosin: Suhosin is developed and maintained by the hardened-php project. +php-suhosin: +php-suhosin: +php-suhosin: +php-suhosin: |