Commit Graph

1480 Commits

Author SHA1 Message Date
Armin Kuster
09e316367a clamav: updated reciped
added packaged define and init scripts.

patches are all debian

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-02-01 08:12:16 -08:00
Armin Kuster
5303fcfcb6 libmspack: add new package
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-02-01 08:12:07 -08:00
Armin Kuster
8be6d8851b samhain: fix aarch64 build issues
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-02-01 08:11:59 -08:00
Armin Kuster
a58d09e2f5 checksec: fix rdepend issue
WARNING: QA Issue: checksec requires /bin/bash, but no providers in its RDEPENDS [file-rdeps]

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-02-01 08:11:45 -08:00
Armin Kuster
ada3eeef6d libseccomp: fix rdepends
WARNING: QA Issue: libseccomp requires /bin/bash, but no providers in its RDEPENDS [file-rdeps]

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-02-01 08:11:36 -08:00
Armin Kuster
d304579112 ccs-tools: remove unused variable.
There was a ref to  DEPEND  with is meaningless so remove it.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-02-01 08:11:28 -08:00
Armin Kuster
1aea14c3c8 samhain: client fix rdepends
WARNING: QA Issue: samhain-client requires /bin/bash, but no providers in its RDEPENDS [file-rdeps]

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-02-01 08:11:21 -08:00
Paul Eggleton
ea8f4661f4 nikto: fix SRC_URI for multilib
${BPN} should be used instead of ${PN} where you want the name without
any prefix (and ${BP} is short for ${BPN}-${PV}).

Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-13 12:10:48 -08:00
Paul Eggleton
903c19e322 libseccomp: fix SRC_URI for multilib
${BPN} should be used instead of ${PN} where you want the name without
any prefix (and ${BP} is short for ${BPN}-${PV}).

Signed-off-by: Paul Eggleton <paul.eggleton@linux.intel.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-13 12:10:40 -08:00
Armin Kuster
3ace992991 libcap-ng: fix checksums
the checksums did not get updated when upgrading package.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-13 12:10:29 -08:00
Armin Kuster
75d2b6620d nikto: fix launching errors
add several missing perl package depends so app can launch

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-03 21:21:53 -08:00
Armin Kuster
b265a8f1c7 libwhisker2-perl: fix build issue
minor formating clean ups.
add "ssl" depend packageconf option

Change inherit perlnative to BBCLASSEXTEND = "native" to fix build issue

error: Can't install libwhisker2-perl-2.5-r0@i586: no package provides /home/akuster/oss/maint/security/poky/build/tmp/sysroots/x86_64-linux/usr/bin/perl-native/perl.real

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-03 21:21:44 -08:00
Armin Kuster
397b35c028 nikto: fix depends
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-03 21:21:32 -08:00
Armin Kuster
b80abbf51d perl: reorg recipes to match meta-perl.
move security perl recipes to a more standardized
recipes-perl layout.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-03 21:21:11 -08:00
Armin Kuster
424473d61e remove: libcurses-perl, libhtml-parser-perl, libnet-dns-perl
those packages are being moved to meta-perl.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-03 21:21:03 -08:00
Armin Kuster
5294a2c603 libcap-ng: update to 7.4 plus security fix
0.7.4
- In pscap, remove unused code
- Add CAPNG_INIT_SUPP_GRP to capng_change_id
- Drop CAP_COMPROMISE_KERNEL
- Update the autotools components
- Dynamically detect last capability (#895105)
- Add PR_SET_NO_NEW_PRIVS to capng_lock if kernel supports it
  (CVE-2014-3215)

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2015-01-03 21:20:53 -08:00
Armin Kuster
76386bd2ca samhain: update to 3.1.3
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-11-28 19:14:10 -08:00
Armin Kuster
039c711f17 packagegroups [v2]: add a few more catagories
Add tripwire, samhain and checksec packages
fix ccs-tools to exclude if no kernel support

v2:
 fixed missing "}"

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-11-28 19:14:02 -08:00
Armin Kuster
4fe07fed2e pinentry: remove from layer
pinentry is now in oe-core so remove it from this layer.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-11-28 19:13:54 -08:00
Armin Kuster
93891d856d libseccomp: add package for tests.
I wanted to run the tests manually on a target. Tests are now
built and packaged.

to run: /usr/lib/libseccomp/tests/regression -a

will add ptest later.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-11-28 19:13:46 -08:00
Armin Kuster
b584aa13f6 checksecurity: update to version 2.0.15
update fixed:
 * Fix bug in the CS_NFSAFS definition in etc/check-setuid.conf that prevents
   the script from matching any filesystem. This bug was, actually, making the
   script not do anything in the default configuration.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-10-26 12:35:55 -07:00
Armin Kuster
33e45ec16c isic: Add new package
This adds the ISIC is a suite of utilities to exercise the stability of an IP and its component stacks (TCP/UDP/ICMP etc.) It generates piles of pseudo random packets with configurable tendancies, then sent to the target to penetrate its firewall rules or find bug

backported two patches from Redhat.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-10-26 12:35:48 -07:00
Armin Kuster
b59053a3dd samhain: update to 3.1.2
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-10-26 12:35:39 -07:00
Armin Kuster
b255a7137f README: update layers references
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:26:14 -07:00
Armin Kuster
39f1010f3a layer.conf: add layer depends.
added layerdepends check for  perl-layer and opemembedded-layer

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:25:35 -07:00
Armin Kuster
da8d7084fa libnet-ssleay-perl: remove from layer
libnet-ssleay-perl is now in meta-perl

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:25:28 -07:00
Armin Kuster
c00f6abe5d tripwire: ppc64 build failure.
| configure: error: /bin/sh ./config.sub powerpc64-poky-linux failed

config.sub did not understand the powerpc64 par.
this patch adds that understanding.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:25:19 -07:00
Armin Kuster
332b02ec89 nmap: New QA issue via ppc
Fixes:
WARNING: QA Issue: nmap rdepends on libpcap, but it isn't a build dependency? [build-deps]

nmap internal lua library does not compile with PPC so use OE version instead.

Changed PACKAGECONFIG assignment from "??=" to "=". It was empty when using
PPC.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:25:08 -07:00
Armin Kuster
1f28cd51dc nmap: Add gui support
Add zenmap to work with gtk+/x11

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:25:00 -07:00
Armin Kuster
20776618f2 v2] nmap: use pkgconfig and reorg
Added pkgconfig support
Since most binaries provided by nmap can be excluded via configure
  manage via pkgconfig
Aligned python packages with binaries so nmap-python is no longer needed

V2: Missed some options in EXTRA_OECONF changes

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:24:53 -07:00
Armin Kuster
2682cd4105 nmap: build QA Warnings
WARNING: QA Issue: nmap rdepends on libcrypto, but it isn't a build dependency? [build-deps]
WARNING: QA Issue: nmap rdepends on libssl, but it isn't a build dependency? [build-deps]

This fixes the above QA warnings.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-09-13 10:24:47 -07:00
Armin Kuster
b3f08c7b2b samhain: arm build failure
| x_sh_error.c: In function 'sh_error_string':
| x_sh_error.c:1580:31: error: incompatible type for argument 1 of 'memmove'
|  #define VA_COPY(ap1, ap2)     memmove ((ap1), (ap2), sizeof (va_list))
|                                ^
| x_sh_error.c:1720:14: note: in expansion of macro 'VA_COPY'
|        /*@i@*/VA_COPY(vl2, vl);
|               ^

this patch fixes the arm build failure.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-08-27 21:12:47 -07:00
Armin Kuster
6328a58612 pinentry: Fix QA error
This fixes: WARNING: QA Issue: pinentry rdepends on libcap, but it isn't a build dependency? [build-deps]

Also add pkgconfig support.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-08-27 21:12:31 -07:00
Armin Kuster
6e72910b3e samhain: server package
This is the server portion.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-08-27 21:11:32 -07:00
Armin Kuster
2559581eaa samhain: client package
This is the client portion.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-08-27 21:11:21 -07:00
Armin Kuster
f0f670c2fe samhain: New ISD package
These are the base files needed by both
client and server recipes.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2014-08-27 21:11:12 -07:00
Armin Kuster
e6b6816192 tripwire: Add files for package support
Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-27 21:09:49 -07:00
Armin Kuster
fa3c8b475c tripwire: Add new package to layer
Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-27 21:09:40 -07:00
Armin Kuster
14b15cc276 tomoyo: Add kconfig
V2:
Fixed path to init program
Fix typo in name

Add kernel config to enable tomoyo

Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-20 21:19:04 -07:00
Armin Kuster
43ce4b4889 tomoyo: ccs-tools
Add userland support program ccs-tools

V2:
Added RDEPEND on systemd
Fixed Description
Moved man page to doc packaged
Added Requiered distro feature on kernel component.
Fixed typo in path for init program

Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-20 21:18:48 -07:00
Armin Kuster
621f30abed libnetaddr-ip-perl: Blacklist recipe
As far as I can tell, this is not used by any reciped in meta-security.

It does not build so I am Black listing it.

Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-10 20:17:07 -07:00
Armin Kuster
17d2fc38a7 libcurses-perl: Fix build issue
Update to later vesrion to fix build issue.

Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-10 20:16:57 -07:00
Armin Kuster
a1f10775fe V2 packagegroup: Add initial set of package groups
Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-06 08:06:36 -07:00
Armin Kuster
f20ff5c45c checksec: Add new alsr pic pie test script
Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-06 07:57:16 -07:00
Armin Kuster
6a4b2849a1 pinentry: Fix do_package_qa issue
This fixes;
ERROR: QA Issue: pinentry: The compile log indicates that host include and/or library paths were used.

Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-06 07:56:49 -07:00
Armin Kuster
6f64473a40 nmap: update to 6.46
Updated to later version on nmap.
remove patch which is included in update
Added ndiff package
Include zenmap build changes but commented out for now and untested

Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-08-06 07:56:14 -07:00
Alexandru.Vaduva
914128d8c9 libcap-ng: resolved issue related with LONG_BIT definition
The problem is well known for 64 bits architectures and the solution
is offered in the same recibe but in the meta-selinux layer.

Signed-off-by: Alexandru.Vaduva <Alexandru.Vaduva at enea.com>
Signed-off-by: Armin Kuster <akuster@mvista.com>
2014-07-02 19:46:00 -07:00
Armin Kuster
3689209e52 meta-security: Add Maintainers
Add Maintainers statement to README and add self to list.

Signed-off-by: Armin Kuster <akuster@mvista.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
2014-07-02 16:59:42 -07:00
Nick D'Ademo
9104e24e38 nmap: inherit autotools-brokensep to allow B=S build.
Signed-off-by: Nick D'Ademo <nickdademo@gmail.com>
Signed-off-by: Saul Wold <sgw@linux.intel.com>
2014-05-07 07:50:49 -07:00
Saul Wold
7e8c7918d9 lib-perl: Fix quoting in DESCRIPTION
My mistake for taking the older version, I thought I had the latest

Signed-off-by: Saul Wold <sgw@linux.intel.com>
2013-11-05 11:00:08 -08:00