commit:     86fff0b3e052e21123855eada99fbff2aefde691
Author:     Aaron Bauman <bman <AT> gentoo <DOT> org>
AuthorDate: Mon Mar 11 07:48:01 2019 +0000
Commit:     Aaron Bauman <bman <AT> gentoo <DOT> org>
CommitDate: Mon Mar 11 07:48:01 2019 +0000
URL:        https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=86fff0b3

Revert "net-analyzer/wireshark: drop vulnerable wrt bug #661578"

This reverts commit d7b18f912d0c8622e8647cef757c715d6eb2eec8.

Signed-off-by: Aaron Bauman <bman <AT> gentoo.org>

 net-analyzer/wireshark/Manifest               |   1 +
 net-analyzer/wireshark/wireshark-2.4.5.ebuild | 291 ++++++++++++++++++++++++++
 2 files changed, 292 insertions(+)

diff --git a/net-analyzer/wireshark/Manifest b/net-analyzer/wireshark/Manifest
index c4ba02e145b..9e5bc3e93b8 100644
--- a/net-analyzer/wireshark/Manifest
+++ b/net-analyzer/wireshark/Manifest
@@ -1,3 +1,4 @@
+DIST wireshark-2.4.5.tar.xz 28836740 BLAKE2B 
797540daca259a2d5d7dc6e637f2b504b6d14191af4040e6b344c95db6c776b7de80c25c59c98ab84d0337cc96c7313b42c13103a3c3944768a793130deae258
 SHA512 
2f2c201d6b8a37dcbe03bc9affbf97d632d8e40e4fe5b3a3e79cbd5cfbeb5b9111919850546ccae355fcb042def3456438eb1c4d73f7d56d373e7898311b42f3
 DIST wireshark-2.6.3.tar.xz 28384004 BLAKE2B 
f275c73173fbaf3f819c58f28859362e9c53ae50cf2649ac42c8d172362241eb00d7f43d0aead184ec67cb8da34d405124be10c5bf31226c2cb4800b8a01955b
 SHA512 
87e5335840baa401a1064ee83e3f0ee859c059dd37a09f63f19eb5d91ad273e84f1c0e7a8fdd63fe8a7076abff5e79593827544c5796d921cf7dc7682c7c3f80
 DIST wireshark-2.6.6.tar.xz 28407404 BLAKE2B 
5135789d345b675814a6394d5ba1469585b9eab917885730125b8a007aecd9cb48a510fc9e7479148cadf625807bac9017b854797e4bb2e562d7dc7f76140826
 SHA512 
b781c3b34dc76a3d8e60dc2b9b4e46a11994440b8df7b56134521ea9a77b27b0719a600db60d7f3d65f15972a5db2a7e85a8bf60d7217fce498fb5668de8fe56
 DIST wireshark-2.6.7.tar.xz 28420060 BLAKE2B 
fda1fb2b9a8968916dd24c59c193854ab56dc13d5a69d2f589ae89b257f92794d092a3da75c2e20b1c83c902966db15527346dc4072a38d16a21ed095cde364e
 SHA512 
bd0f87debd8bd8947f386aaec9fc843148e3cdfbffc28ba499526c4053732becea606061deae6799da0cf52458fba840ba0ff8e4a034a671fa876b8a0ff25677

diff --git a/net-analyzer/wireshark/wireshark-2.4.5.ebuild 
b/net-analyzer/wireshark/wireshark-2.4.5.ebuild
new file mode 100644
index 00000000000..c1819bafbf8
--- /dev/null
+++ b/net-analyzer/wireshark/wireshark-2.4.5.ebuild
@@ -0,0 +1,291 @@
+# Copyright 1999-2018 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=6
+inherit autotools eutils fcaps flag-o-matic gnome2-utils multilib qmake-utils 
user xdg-utils
+
+DESCRIPTION="A network protocol analyzer formerly known as ethereal"
+HOMEPAGE="https://www.wireshark.org/";
+SRC_URI="${HOMEPAGE}download/src/all-versions/${P/_/}.tar.xz"
+
+LICENSE="GPL-2"
+SLOT="0/${PV}"
+KEYWORDS="~arm64 ~x86-fbsd"
+IUSE="
+       adns androiddump +capinfos +caps +captype ciscodump cpu_flags_x86_sse4_2
+       +dftest doc doc-pdf +dumpcap +editcap geoip gtk kerberos libssh libxml2 
lua
+       lz4 +mergecap +netlink nghttp2 +pcap portaudio +qt5 +randpkt 
+randpktdump
+       +reordercap sbc selinux +sharkd smi snappy spandsp sshdump ssl 
+text2pcap
+       tfshark +tshark +udpdump zlib
+"
+REQUIRED_USE="
+       ciscodump? ( libssh )
+       sshdump? ( libssh )
+"
+
+S=${WORKDIR}/${P/_/}
+
+CDEPEND="
+       >=dev-libs/glib-2.14:2
+       dev-libs/libgcrypt:0
+       netlink? ( dev-libs/libnl:3 )
+       adns? ( >=net-dns/c-ares-1.5 )
+       caps? ( sys-libs/libcap )
+       geoip? ( dev-libs/geoip )
+       gtk? (
+               x11-libs/gdk-pixbuf
+               x11-libs/gtk+:3
+               x11-libs/pango
+               x11-misc/xdg-utils
+       )
+       kerberos? ( virtual/krb5 )
+       libssh? ( >=net-libs/libssh-0.6 )
+       libxml2? ( dev-libs/libxml2 )
+       lua? ( >=dev-lang/lua-5.1:* )
+       lz4? ( app-arch/lz4 )
+       nghttp2? ( net-libs/nghttp2 )
+       pcap? ( net-libs/libpcap )
+       portaudio? ( media-libs/portaudio )
+       qt5? (
+               dev-qt/qtcore:5
+               dev-qt/qtgui:5
+               dev-qt/qtmultimedia:5
+               dev-qt/qtprintsupport:5
+               dev-qt/qtwidgets:5
+               >=media-libs/speex-1.2.0
+               media-libs/speexdsp
+               x11-misc/xdg-utils
+       )
+       sbc? ( media-libs/sbc )
+       smi? ( net-libs/libsmi )
+       snappy? ( app-arch/snappy )
+       spandsp? ( media-libs/spandsp )
+       ssl? ( net-libs/gnutls:= )
+       zlib? ( sys-libs/zlib )
+"
+# We need perl for `pod2html`.  The rest of the perl stuff is to block older
+# and broken installs. #455122
+DEPEND="
+       ${CDEPEND}
+       dev-lang/perl
+       !<virtual/perl-Pod-Simple-3.170
+       !<perl-core/Pod-Simple-3.170
+       doc? (
+               app-doc/doxygen
+               app-text/asciidoc
+               dev-libs/libxml2
+               dev-libs/libxslt
+               doc-pdf? ( dev-java/fop )
+               www-client/lynx
+       )
+       qt5? (
+               dev-qt/linguist-tools:5
+       )
+       sys-devel/bison
+       sys-devel/flex
+       virtual/pkgconfig
+"
+RDEPEND="
+       ${CDEPEND}
+       gtk? ( virtual/freedesktop-icon-theme )
+       qt5? ( virtual/freedesktop-icon-theme )
+       selinux? ( sec-policy/selinux-wireshark )
+"
+PATCHES=(
+       "${FILESDIR}"/${PN}-1.99.8-qtchooser.patch
+       "${FILESDIR}"/${PN}-2.1.0-sse4_2-r1.patch
+       "${FILESDIR}"/${PN}-2.4-androiddump.patch
+       "${FILESDIR}"/${PN}-99999999-androiddump.patch
+       "${FILESDIR}"/${PN}-2.4.3-libsmi.patch
+)
+
+pkg_setup() {
+       enewgroup wireshark
+}
+
+src_prepare() {
+       default
+
+       eautoreconf
+}
+
+src_configure() {
+       local myconf
+
+       # Workaround bug #213705. If krb5-config --libs has -lcrypto then pass
+       # --with-ssl to ./configure. (Mimics code from acinclude.m4).
+       if use kerberos; then
+               case $(krb5-config --libs) in
+                       *-lcrypto*)
+                               ewarn "Kerberos was built with ssl support: 
linkage with openssl is enabled."
+                               ewarn "Note there are annoying license 
incompatibilities between the OpenSSL"
+                               ewarn "license and the GPL, so do your check 
before distributing such package."
+                               myconf+=( "--with-ssl" )
+                               ;;
+               esac
+       fi
+
+       # Enable wireshark binary with any supported GUI toolkit (bug #473188)
+       if use gtk || use qt5; then
+               myconf+=( "--enable-wireshark" )
+       else
+               myconf+=( "--disable-wireshark" )
+       fi
+
+       if ! use qt5; then
+               myconf+=( "--with-qt=no" )
+       fi
+
+       if use qt5; then
+               export QT_MIN_VERSION=5.3.0
+               append-cxxflags -fPIC -DPIC
+       fi
+
+       # Hack around inability to disable doxygen/fop doc generation
+       use doc || export ac_cv_prog_HAVE_DOXYGEN=false
+       use doc-pdf || export ac_cv_prog_HAVE_FOP=false
+
+       econf \
+               $(use androiddump && use pcap && echo 
--enable-androiddump-use-libpcap=yes) \
+               $(use dumpcap && use_with pcap dumpcap-group wireshark) \
+               $(use_enable androiddump) \
+               $(use_enable capinfos) \
+               $(use_enable captype) \
+               $(use_enable ciscodump) \
+               $(use_enable dftest) \
+               $(use_enable dumpcap) \
+               $(use_enable editcap) \
+               $(use_enable mergecap) \
+               $(use_enable randpkt) \
+               $(use_enable randpktdump) \
+               $(use_enable reordercap) \
+               $(use_enable sharkd) \
+               $(use_enable sshdump) \
+               $(use_enable text2pcap) \
+               $(use_enable tfshark) \
+               $(use_enable tshark) \
+               $(use_enable udpdump) \
+               $(use_with adns c-ares) \
+               $(use_with caps libcap) \
+               $(use_with geoip) \
+               $(use_with gtk gtk 3) \
+               $(use_with kerberos krb5) \
+               $(use_with libssh) \
+               $(use_with libxml2) \
+               $(use_with lua) \
+               $(use_with lz4) \
+               $(use_with nghttp2) \
+               $(use_with pcap) \
+               $(use_with portaudio) \
+               $(use_with sbc) \
+               $(use_with smi libsmi) \
+               $(use_with snappy) \
+               $(use_with spandsp) \
+               $(use_with ssl gnutls) \
+               $(use_with zlib) \
+               $(usex cpu_flags_x86_sse4_2 --enable-sse4_2 '') \
+               $(usex netlink --with-libnl=3 --without-libnl) \
+               $(usex qt5 --with-qt=5 '') \
+               $(usex qt5 LRELEASE=$(qt5_get_bindir)/lrelease '') \
+               $(usex qt5 MOC=$(qt5_get_bindir)/moc '') \
+               $(usex qt5 RCC=$(qt5_get_bindir)/rcc '') \
+               $(usex qt5 UIC=$(qt5_get_bindir)/uic '') \
+               --disable-profile-build \
+               --disable-warnings-as-errors \
+               --sysconfdir="${EPREFIX}"/etc/wireshark \
+               ${myconf[@]}
+}
+
+src_compile() {
+       default
+
+       if use doc; then
+               emake -j1 -C docbook
+               if use doc-pdf; then
+                       addpredict "/root/.java"
+                       emake -C docbook all-pdf
+               fi
+       fi
+}
+
+src_install() {
+       default
+
+       # FAQ is not required as is installed from help/faq.txt
+       dodoc AUTHORS ChangeLog NEWS README{,.bsd,.linux,.macos,.vmware} \
+               doc/{randpkt.txt,README*}
+
+       if use doc; then
+               docinto /usr/share/doc/${PF}/html
+               dodoc -r docbook/{release-notes.html,ws{d,u}g_html{,_chunked}}
+               if use doc-pdf; then
+                       docinto /usr/share/doc/${PF}/pdf/
+                       dodoc docbook/{developer,user}-guide-{a4,us}.pdf 
docbook/release-notes.pdf
+               fi
+       fi
+
+       # install headers
+       local wsheader
+       for wsheader in \
+               config.h \
+               epan/*.h \
+               epan/crypt/*.h \
+               epan/dfilter/*.h \
+               epan/dissectors/*.h \
+               epan/ftypes/*.h \
+               epan/wmem/*.h \
+               register.h \
+               wiretap/*.h \
+               ws_diag_control.h \
+               ws_symbol_export.h \
+               wsutil/*.h
+       do
+               insinto /usr/include/wireshark/$( dirname ${wsheader} )
+               doins ${wsheader}
+       done
+
+       #with the above this really shouldn't be needed, but things may be 
looking in wiretap/ instead of wireshark/wiretap/
+       insinto /usr/include/wiretap
+       doins wiretap/wtap.h
+
+       if use gtk || use qt5; then
+               local c d
+               for c in hi lo; do
+                       for d in 16 32 48; do
+                               insinto 
/usr/share/icons/${c}color/${d}x${d}/apps
+                               newins image/${c}${d}-app-wireshark.png 
wireshark.png
+                       done
+               done
+               for d in 16 24 32 48 64 128 256 ; do
+                       insinto /usr/share/icons/hicolor/${d}x${d}/mimetypes
+                       newins image/WiresharkDoc-${d}.png 
application-vnd.tcpdump.pcap.png
+               done
+       fi
+
+       prune_libtool_files
+}
+
+pkg_postinst() {
+       gnome2_icon_cache_update
+       xdg_desktop_database_update
+       xdg_mimeinfo_database_update
+
+       # Add group for users allowed to sniff.
+       enewgroup wireshark
+
+       if use dumpcap && use pcap; then
+               fcaps -o 0 -g wireshark -m 4710 -M 0710 \
+                       cap_dac_read_search,cap_net_raw,cap_net_admin \
+                       "${EROOT}"/usr/bin/dumpcap
+       fi
+
+       ewarn "NOTE: To capture traffic with wireshark as normal user you have 
to"
+       ewarn "add yourself to the wireshark group. This security measure 
ensures"
+       ewarn "that only trusted users are allowed to sniff your traffic."
+}
+
+pkg_postrm() {
+       gnome2_icon_cache_update
+       xdg_desktop_database_update
+       xdg_mimeinfo_database_update
+}

Reply via email to