2018-12-14 18:00:06 +00:00
|
|
|
%undefine _hardened_build
|
2007-10-29 23:05:53 +00:00
|
|
|
Name: conntrack-tools
|
2018-12-10 23:15:32 +00:00
|
|
|
Version: 1.4.5
|
2019-01-31 16:11:50 +00:00
|
|
|
Release: 3%{?dist}
|
2012-05-08 01:33:06 +00:00
|
|
|
Summary: Manipulate netfilter connection tracking table and run High Availability
|
2007-10-29 23:05:53 +00:00
|
|
|
License: GPLv2
|
2016-04-20 00:45:50 +00:00
|
|
|
URL: http://conntrack-tools.netfilter.org/
|
2008-07-16 21:40:28 +00:00
|
|
|
Source0: http://netfilter.org/projects/%{name}/files/%{name}-%{version}.tar.bz2
|
2012-05-08 01:33:06 +00:00
|
|
|
Source1: conntrackd.service
|
|
|
|
Source2: conntrackd.conf
|
2016-04-20 00:45:50 +00:00
|
|
|
|
2018-07-09 17:06:43 +00:00
|
|
|
BuildRequires: gcc
|
2018-12-10 23:15:32 +00:00
|
|
|
BuildRequires: libnfnetlink-devel >= 1.0.1, libnetfilter_conntrack-devel >= 1.0.7
|
2012-11-30 01:01:57 +00:00
|
|
|
BuildRequires: libnetfilter_cttimeout-devel >= 1.0.0, libnetfilter_cthelper-devel >= 1.0.0
|
|
|
|
BuildRequires: libmnl-devel >= 1.0.3, libnetfilter_queue-devel >= 1.0.2
|
2018-12-10 23:15:32 +00:00
|
|
|
BuildRequires: libtirpc-devel systemd-devel
|
2012-05-08 01:33:06 +00:00
|
|
|
BuildRequires: pkgconfig bison flex
|
2007-10-29 23:05:53 +00:00
|
|
|
Provides: conntrack = 1.0-1
|
|
|
|
Obsoletes: conntrack < 1.0-1
|
2013-09-07 17:42:37 +00:00
|
|
|
Requires(post): systemd
|
|
|
|
Requires(preun): systemd
|
|
|
|
Requires(postun): systemd
|
|
|
|
BuildRequires: systemd
|
2007-10-29 23:05:53 +00:00
|
|
|
|
|
|
|
%description
|
2012-05-08 01:33:06 +00:00
|
|
|
With conntrack-tools you can setup a High Availability cluster and
|
|
|
|
synchronize conntrack state between multiple firewalls.
|
|
|
|
|
2007-10-29 23:05:53 +00:00
|
|
|
The conntrack-tools package contains two programs:
|
|
|
|
- conntrack: the command line interface to interact with the connection
|
|
|
|
tracking system.
|
|
|
|
- conntrackd: the connection tracking userspace daemon that can be used to
|
|
|
|
deploy highly available GNU/Linux firewalls and collect
|
|
|
|
statistics of the firewall use.
|
|
|
|
|
|
|
|
conntrack is used to search, list, inspect and maintain the netfilter
|
|
|
|
connection tracking subsystem of the Linux kernel.
|
|
|
|
Using conntrack, you can dump a list of all (or a filtered selection of)
|
|
|
|
currently tracked connections, delete connections from the state table,
|
|
|
|
and even add new ones.
|
|
|
|
In addition, you can also monitor connection tracking events, e.g.
|
|
|
|
show an event message (one line) per newly established connection.
|
|
|
|
|
|
|
|
%prep
|
2008-07-16 21:40:28 +00:00
|
|
|
%setup -q
|
2007-10-29 23:05:53 +00:00
|
|
|
|
|
|
|
%build
|
2018-12-10 23:15:32 +00:00
|
|
|
%configure --disable-static --enable-systemd
|
|
|
|
sed -i "s/DEFAULT_INCLUDES = -I./DEFAULT_INCLUDES = -I. -I\/usr\/include\/tirpc/" src/helpers/Makefile
|
|
|
|
CFLAGS="${CFLAGS} -Wl,-z,lazy"
|
|
|
|
CXXFLAGS="${CXXFLAGS} -Wl,-z,lazy"
|
2018-04-13 04:08:20 +00:00
|
|
|
%make_build
|
2012-05-08 01:33:06 +00:00
|
|
|
chmod 644 doc/sync/primary-backup.sh
|
2015-01-11 13:21:41 +00:00
|
|
|
rm -f doc/sync/notrack/conntrackd.conf.orig doc/sync/alarm/conntrackd.conf.orig doc/helper/conntrackd.conf.orig
|
2007-10-29 23:05:53 +00:00
|
|
|
|
|
|
|
%install
|
2018-04-13 04:08:20 +00:00
|
|
|
%make_install
|
2018-12-10 23:15:32 +00:00
|
|
|
find %{buildroot} -type f -name "*.la" -exec rm -f {} ';'
|
2012-05-08 01:33:06 +00:00
|
|
|
mkdir -p %{buildroot}%{_sysconfdir}/conntrackd
|
2018-12-10 23:15:32 +00:00
|
|
|
install -d -m 0755 %{buildroot}%{_unitdir}
|
2012-05-08 01:33:06 +00:00
|
|
|
install -m 0644 %{SOURCE1} %{buildroot}%{_unitdir}/
|
|
|
|
install -m 0644 %{SOURCE2} %{buildroot}%{_sysconfdir}/conntrackd/
|
2007-10-29 23:05:53 +00:00
|
|
|
|
|
|
|
%files
|
2018-04-13 04:08:20 +00:00
|
|
|
%license COPYING
|
|
|
|
%doc AUTHORS TODO doc
|
2012-05-08 01:33:06 +00:00
|
|
|
%dir %{_sysconfdir}/conntrackd
|
|
|
|
%config(noreplace) %{_sysconfdir}/conntrackd/conntrackd.conf
|
|
|
|
%{_unitdir}/conntrackd.service
|
2007-10-29 23:05:53 +00:00
|
|
|
%{_sbindir}/conntrack
|
|
|
|
%{_sbindir}/conntrackd
|
2012-11-30 01:01:57 +00:00
|
|
|
%{_sbindir}/nfct
|
2016-09-22 19:35:21 +00:00
|
|
|
%{_mandir}/man5/*
|
2007-10-29 23:05:53 +00:00
|
|
|
%{_mandir}/man8/*
|
2012-11-30 01:01:57 +00:00
|
|
|
%dir %{_libdir}/conntrack-tools
|
|
|
|
%{_libdir}/conntrack-tools/*
|
2007-10-29 23:05:53 +00:00
|
|
|
|
2013-09-07 17:42:37 +00:00
|
|
|
%post
|
|
|
|
%systemd_post conntrackd.service
|
|
|
|
|
2012-05-08 01:33:06 +00:00
|
|
|
%preun
|
2013-09-07 17:42:37 +00:00
|
|
|
%systemd_preun conntrackd.service
|
2012-05-08 01:33:06 +00:00
|
|
|
|
|
|
|
%postun
|
2013-09-07 17:42:37 +00:00
|
|
|
%systemd_postun conntrackd.service
|
2012-05-08 01:33:06 +00:00
|
|
|
|
2007-10-29 23:05:53 +00:00
|
|
|
%changelog
|
2019-01-31 16:11:50 +00:00
|
|
|
* Thu Jan 31 2019 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.5-3
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
|
|
|
|
|
2018-12-14 18:00:06 +00:00
|
|
|
* Fri Dec 14 2018 Paul Wouters <pwouters@redhat.com> - 1.4.5-2
|
|
|
|
- Disable hardened build to really fix rhbz#1413408
|
|
|
|
|
2018-12-10 23:15:32 +00:00
|
|
|
* Mon Dec 10 2018 Paul Wouters <pwouters@redhat.com> - 1.4.5-1
|
|
|
|
- Resolves: rhbz#1574091 conntrack-tools-1.4.5 is available
|
|
|
|
- Resolves: rhbz#1413408 ct_helper_ftp not working
|
|
|
|
(I've reduced the hardening to use -z,lazy)
|
|
|
|
- Eanbled systemd support
|
|
|
|
- Bumped required libnetfilter_conntrack-devel to 1.0.7
|
|
|
|
- fixup harmless but broken mkdir in spec file
|
|
|
|
- Don't override CPPFLAGS and LIBS, instead fixup src/helpers/Makefile
|
|
|
|
|
2018-07-12 22:11:30 +00:00
|
|
|
* Thu Jul 12 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.4-8
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
|
|
|
|
|
2018-04-13 04:08:20 +00:00
|
|
|
* Thu Apr 12 2018 Orion Poplawski <orion@nwra.com> - 1.4.4-7
|
|
|
|
- Use libtirpc
|
|
|
|
- Use %%license
|
|
|
|
|
2018-02-07 05:38:44 +00:00
|
|
|
* Wed Feb 07 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.4-6
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
|
|
|
|
|
2017-08-02 19:08:24 +00:00
|
|
|
* Wed Aug 02 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.4-5
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
|
|
|
|
|
2017-07-26 05:24:34 +00:00
|
|
|
* Wed Jul 26 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.4-4
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
|
|
|
|
|
2017-02-22 16:01:02 +00:00
|
|
|
* Wed Feb 22 2017 Paul Wouters <pwouters@redhat.com> - 1.4.4-3
|
|
|
|
- Add upstream patches (free pktb after use, nat_tuple leak)
|
|
|
|
|
2017-02-10 07:51:29 +00:00
|
|
|
* Fri Feb 10 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.4-2
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
|
|
|
|
|
2016-09-22 19:35:21 +00:00
|
|
|
* Thu Sep 22 2016 Paul Wouters <pwouters@redhat.com> - 1.4.4-1
|
2017-01-01 23:41:03 +00:00
|
|
|
- Updated to 1.4.4 (rhbz#1370668)
|
2016-09-22 19:35:21 +00:00
|
|
|
- Include new man5 pages
|
|
|
|
|
2016-04-20 00:45:50 +00:00
|
|
|
* Wed Apr 20 2016 Paul Wouters <pwouters@redhat.com> - 1.4.3-1
|
|
|
|
- Resolves: rhbz#1261220 1.4.3 is available
|
|
|
|
- Update source url
|
|
|
|
- Remove incorporated patches
|
|
|
|
|
2016-02-03 18:04:21 +00:00
|
|
|
* Wed Feb 03 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1.4.2-11
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
|
|
|
|
|
2015-08-21 17:56:40 +00:00
|
|
|
* Fri Aug 21 2015 Paul Wouters <pwouters@redhat.com> - 1.4.2-10
|
|
|
|
- Resolves: 1255578 - conntrackd could neither be started nor be stopped
|
|
|
|
|
2015-08-18 18:10:17 +00:00
|
|
|
* Tue Aug 18 2015 Paul Wouters <pwouters@redhat.com> - 1.4.2-9
|
|
|
|
- Resolves: rhbz#CVE-2015-6496, rhbz#1253757
|
|
|
|
- Fold in upstream patches since 1.4.2 release up to git 900d7e8
|
|
|
|
- Fold in upstream patch set of 2015-08-18 for coverity issues
|
|
|
|
|
2015-06-17 03:11:43 +00:00
|
|
|
* Wed Jun 17 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-8
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
|
|
|
|
|
2015-01-12 14:50:49 +00:00
|
|
|
* Mon Jan 12 2015 Paul Komkoff <i@stingr.net> - 1.4.2-7
|
|
|
|
- bz#1181119 - wait for network to be on before starting conntrackd
|
|
|
|
|
2015-01-11 13:21:41 +00:00
|
|
|
* Sun Jan 11 2015 Paul Komkoff <i@stingr.net> - 1.4.2-6
|
2015-01-12 14:50:49 +00:00
|
|
|
- bz#998105 - remove patch residues from doc
|
2015-01-11 13:21:41 +00:00
|
|
|
|
2014-08-16 01:11:23 +00:00
|
|
|
* Sat Aug 16 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-5
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
|
|
|
|
|
2014-06-07 05:47:46 +00:00
|
|
|
* Sat Jun 07 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.2-4
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
|
|
|
|
|
2013-12-21 14:21:59 +00:00
|
|
|
* Sat Dec 21 2013 Paul Komkoff <i@stingr.net> - 1.4.2-3
|
|
|
|
- rebuilt
|
|
|
|
|
2013-09-07 17:42:37 +00:00
|
|
|
* Sat Sep 7 2013 Paul P. Komkoff Jr <i@stingr.net> - 1.4.2-2
|
|
|
|
- bz#850067
|
|
|
|
|
2013-09-07 16:51:10 +00:00
|
|
|
* Sat Sep 7 2013 Paul P. Komkoff Jr <i@stingr.net> - 1.4.2-1
|
2013-09-07 16:46:00 +00:00
|
|
|
- new upstream version
|
|
|
|
|
2013-08-03 05:46:57 +00:00
|
|
|
* Sat Aug 03 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.4.0-3
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
|
|
|
|
|
2013-02-08 16:57:24 +00:00
|
|
|
* Fri Feb 08 2013 Paul Komkoff <i@stingr.net> - 1.4.0-2
|
|
|
|
- fix bz#909128
|
|
|
|
|
2012-11-30 01:01:57 +00:00
|
|
|
* Mon Nov 26 2012 Paul P. Komkoff Jr <i@stingr.net> - 1.4.0-1
|
|
|
|
- new upstream version
|
|
|
|
|
|
|
|
* Tue Jul 24 2012 Paul P. Komkoff Jr <i@stingr.net> - 1.2.1
|
|
|
|
- new upstream version
|
|
|
|
|
2012-07-18 19:37:32 +00:00
|
|
|
* Wed Jul 18 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.1-2
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
|
|
|
|
|
2012-05-08 01:33:06 +00:00
|
|
|
* Mon May 07 2012 Paul Wouters <pwouters@redhat.com> - 1.0.1-1
|
|
|
|
- Updated to 1.0.1
|
|
|
|
- Added daemon using systemd and configuration file
|
|
|
|
- Removed legacy spec requirements
|
2012-05-08 02:53:56 +00:00
|
|
|
- Patch for: parse.c:240:34: error: 'NULL' undeclared
|
2012-05-08 01:33:06 +00:00
|
|
|
|
2012-01-12 23:49:36 +00:00
|
|
|
* Thu Jan 12 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.0-2
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
|
|
|
|
|
2011-05-05 10:27:59 +00:00
|
|
|
* Thu May 5 2011 Paul P. Komkoff Jr <i@stingr.net> - 1.0.0
|
|
|
|
- new upstream version
|
|
|
|
|
2011-02-09 18:22:47 +00:00
|
|
|
* Wed Feb 09 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.9.15-2
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
|
|
|
|
|
2010-11-19 17:49:07 +00:00
|
|
|
* Fri Nov 19 2010 Paul P. Komkoff Jr <i@stingr.net> - 0.9.15-1
|
|
|
|
- new upstream version
|
|
|
|
|
2010-03-25 15:46:57 +00:00
|
|
|
* Thu Mar 25 2010 Paul P. Komkoff Jr <i@stingr.net> - 0.9.14-1
|
|
|
|
- update, at last
|
|
|
|
|
2009-11-10 22:35:37 +00:00
|
|
|
* Tue Nov 10 2009 Paul P. Komkoff Jr <i@stingr.net> - 0.9.13-2
|
|
|
|
- failed to properly commit the package :(
|
|
|
|
|
2009-10-13 12:12:46 +00:00
|
|
|
* Tue Oct 13 2009 Paul P. Komkoff Jr <i@stingr.net> - 0.9.13-1
|
|
|
|
- new upstream version
|
|
|
|
|
2009-07-24 19:26:59 +00:00
|
|
|
* Fri Jul 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.9.12-4
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
|
|
|
|
|
2009-05-24 10:02:41 +00:00
|
|
|
* Sun May 24 2009 Paul P. Komkoff Jr <i@stingr.net> - 0.9.12-3
|
|
|
|
- new upstream version
|
|
|
|
|
|
|
|
* Sun May 24 2009 Paul P. Komkoff Jr <i@stingr.net> - 0.9.12-2
|
|
|
|
- versioning screwup
|
|
|
|
|
2009-05-24 09:51:00 +00:00
|
|
|
* Sun May 24 2009 Paul P. Komkoff Jr <i@stingr.net> - 0.9.12-1
|
|
|
|
- new upstream version
|
|
|
|
|
2009-02-24 09:00:34 +00:00
|
|
|
* Tue Feb 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.9.9-2
|
|
|
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
|
|
|
|
|
2009-01-13 01:24:26 +00:00
|
|
|
* Tue Jan 13 2009 Paul P. Komkoff Jr <i@stingr.net> - 0.9.9-1
|
|
|
|
- new upstream version
|
|
|
|
|
2008-10-26 15:34:50 +00:00
|
|
|
* Sun Oct 26 2008 Paul P. Komkoff Jr <i@stingr.net> - 0.9.8-1
|
|
|
|
- new upstream version
|
|
|
|
- remove rollup patch
|
|
|
|
|
2008-07-17 17:12:02 +00:00
|
|
|
* Wed Jul 16 2008 Paul P. Komkoff Jr <i@stingr.net> - 0.9.7-2
|
2012-05-08 01:33:06 +00:00
|
|
|
- fix Patch0/%%patch.
|
2008-07-17 17:12:02 +00:00
|
|
|
|
2008-07-16 21:40:28 +00:00
|
|
|
* Wed Jul 16 2008 Paul P. Komkoff Jr <i@stingr.net> - 0.9.7-1
|
|
|
|
- new upstream version
|
|
|
|
|
2008-02-23 04:14:49 +00:00
|
|
|
* Sat Feb 23 2008 Paul P. Komkoff Jr <i@stingr.net> - 0.9.6-0.1.svn7382
|
|
|
|
- new version from svn
|
|
|
|
|
2008-02-22 22:58:59 +00:00
|
|
|
* Fri Feb 22 2008 Paul P. Komkoff Jr <i@stingr.net> - 0.9.5-5
|
|
|
|
- fix the PATH_MAX-related compilation problem
|
|
|
|
|
2008-02-20 03:19:52 +00:00
|
|
|
* Tue Feb 19 2008 Fedora Release Engineering <rel-eng@fedoraproject.org> - 0.9.5-4
|
|
|
|
- Autorebuild for GCC 4.3
|
|
|
|
|
2007-10-29 23:05:53 +00:00
|
|
|
* Tue Oct 23 2007 Paul P. Komkoff Jr <i@stingr.net> - 0.9.5-3
|
|
|
|
- review fixes
|
|
|
|
|
|
|
|
* Sun Oct 21 2007 Paul P. Komkoff Jr <i@stingr.net> - 0.9.5-2
|
|
|
|
- review fixes
|
|
|
|
|
|
|
|
* Fri Oct 19 2007 Paul P. Komkoff Jr <i@stingr.net> - 0.9.5-1
|
|
|
|
- new upstream version
|
|
|
|
|
|
|
|
* Sun Jul 22 2007 Paul P. Komkoff Jr <i@stingr.net> - 0.9.4-1
|
|
|
|
- replace conntrack with conntrack-tools
|