head 1.1; access; symbols; locks; strict; comment @# @; 1.1 date 2026.09.25.10.00.42; author he; state Exp; branches; next ; commitid 85Yl25SMz5gcgZWG; desc @@ 1.1 log @net/tacacs: update to version 4.0.4.32. Pkgsrc changes: * whack configure.ac so that it manages to produce a working configure script. There are more errors / warnings here... * Change test for libwrap to declare required global variables ... as globals, and not as locals in main() in the configure test. Upstream changes (newest first): F4.0.4.32 - Remote pre-authentication format string vulnerability (CWE-134) F4.0.4.31 - update autoconf to search for libnsl instead of assume. Debian no longer has one, at least not by default. F4.0.4.30 - pull do_auth 2.0 and the example config file from github, with python3 updates and more. https://github.com/helpdeskdan/do_auth - SafeConfigParser class has been renamed to ConfigParser - Misc C99 prototype clean-up F4.0.4.29 - spec file update - from Sten Spans - add SHA512 support to tac_pwd - from Sten Spans XXX needs a configure test to check for sha512 support. - fix libtacacs link - from Gentoo via Ruben Farrelly - fix -U decription in manpage - call correct function for host key look-up by hostname - Adam Dyess - GC regeerror() from the private regex lib. Causing segfault - a bug with quoted strings was that whitespace was not handled reasonably. since quoted strings may also be used for regex, it also needs to handle regex atoms. so, quoted string parsing has been changed to only treat \" specially, all other backslash-quoted characters are simply copied, including the backslash. add test example to the sample configuration. - fdes.c: add parens to make OoO explicit and shut-up compiler warnings @ text @$NetBSD$ Fix test for librwap. Required declared global variables need to be ... global. Also try to adapt to newer autoconf. --- configure.ac.orig 2026-02-18 16:43:50.000000000 +0000 +++ configure.ac @@@@ -6,17 +6,23 @@@@ AC_PREREQ(2.69) dnl VERSION needs to be updated in version.h.in such that 'make dist' dnl uses the correct filename for the directory name and tarball and binaries dnl get the right version numbers. -PACKAGE=`sh ./aconf/package.sh` -VERSION=`sh ./aconf/version.sh` -AC_INIT(m4_esyscmd(sh ./aconf/package.sh), - m4_esyscmd(sh ./aconf/version.sh)) +dnl PACKAGE=`sh ./aconf/package.sh` +dnl VERSION=`sh ./aconf/version.sh` +dnl AC_INIT(m4_esyscmd(sh ./aconf/package.sh), +dnl m4_esyscmd(sh ./aconf/version.sh)) + +AC_INIT([tacacs], [F4.0.4.32], [some@@e-mail.com], [tacacs]) + AC_CONFIG_AUX_DIR([aconf]) AC_CONFIG_MACRO_DIR([aconf]) -AM_INIT_AUTOMAKE + +AC_LANG([C]) + +AM_INIT_AUTOMAKE([1.11 foreign]) AM_MAINTAINER_MODE() -dnl AC_CONFIG_SUBDIRS(etc man share) +AC_CONFIG_SUBDIRS(etc man share) # what OS dnl ---- XXX: these really should deal with the individual reasons why @@@@ -245,10 +251,11 @@@@ AC_ARG_WITH(libwrap, WRAPLIBS="-lwrap" OLDLIBS="$LIBS" LIBS="$WRAPLIBS $LIBS" - AC_TRY_LINK([ #include ], - [ int allow_severity; int deny_severity; + AC_TRY_LINK([ #include + int allow_severity; int deny_severity; struct request_info *request; - hosts_access(request); ], + ], + [ hosts_access(request); ], [AC_DEFINE(LIBWRAP) WRAPLIBS="-lwrap" AC_DEFINE(HAVE_LIBWRAP) ], @@@@ -268,10 +275,11 @@@@ AC_ARG_WITH(libwrap, OLDINCS="$INCLUDES" LIBS="$WRAPLIBS $LIBS" INCLUDES="$WRAPINCS" - AC_TRY_LINK([ #include ], - [ int allow_severity; int deny_severity; + AC_TRY_LINK([ #include + int allow_severity; int deny_severity; struct request_info *request; - hosts_access(request); ], + ], + [ hosts_access(request); ], [], [ AC_MSG_ERROR(Could not find libwrap. You must first install tcp_wrappers.) ]) LIBS="$OLDLIBS" @@@@ -284,10 +292,11 @@@@ AC_ARG_WITH(libwrap, WRAPLIBS="-lwrap" OLDLIBS="$LIBS" LIBS="$WRAPLIBS $LIBS" - AC_TRY_LINK([#include ], - [ int allow_severity; int deny_severity; + AC_TRY_LINK([#include + int allow_severity; int deny_severity; struct request_info *request; - hosts_access(request); ], + ], + [ hosts_access(request); ], [AC_DEFINE(LIBWRAP) WRAPLIBS="-lwrap" AC_DEFINE(HAVE_LIBWRAP) ], @