# ChangeLog for net-analyzer/nagios-core # Copyright 1999-2016 Gentoo Foundation; Distributed under the GPL v2 # (auto-generated from git log) *nagios-core-4.0.8-r2 (09 Aug 2015) *nagios-core-4.0.8-r1 (09 Aug 2015) *nagios-core-3.5.1 (09 Aug 2015) 09 Aug 2015; Robin H. Johnson +files/99_nagios3.conf, +files/99_nagios4.conf, +files/conf.d, +files/fix-bogus-perf-data-warnings.patch, +files/lighttpd_nagios3-r1.conf, +files/lighttpd_nagios4.conf, +files/nagios, +files/nagios-3.3.1-htmlmakefile.patch, +files/nagios-core-3.5.1-process_cgivars.patch, +files/nagios3, +files/nagios4, +files/statuswml-bug275288.patch, +files/use-INSTALL-to-install-themes.patch, +files/use-MAKE-instead-of-bare-make.patch, +metadata.xml, +nagios-core-3.5.1.ebuild, +nagios-core-4.0.8-r1.ebuild, +nagios-core-4.0.8-r2.ebuild: proj/gentoo: Initial commit This commit represents a new era for Gentoo: Storing the gentoo-x86 tree in Git, as converted from CVS. This commit is the start of the NEW history. Any historical data is intended to be grafted onto this point. Creation process: 1. Take final CVS checkout snapshot 2. Remove ALL ChangeLog* files 3. Transform all Manifests to thin 4. Remove empty Manifests 5. Convert all stale $Header$/$Id$ CVS keywords to non-expanded Git $Id$ 5.1. Do not touch files with -kb/-ko keyword flags. Signed-off-by: Robin H. Johnson X-Thanks: Alec Warner - did the GSoC 2006 migration tests X-Thanks: Robin H. Johnson - infra guy, herding this project X-Thanks: Nguyen Thai Ngoc Duy - Former Gentoo developer, wrote Git features for the migration X-Thanks: Brian Harring - wrote much python to improve cvs2svn X-Thanks: Rich Freeman - validation scripts X-Thanks: Patrick Lauer - Gentoo dev, running new 2014 work in migration X-Thanks: Michał Górny - scripts, QA, nagging X-Thanks: All of other Gentoo developers - many ideas and lots of paint on the bikeshed 24 Aug 2015; Justin Lecher metadata.xml, nagios-core-4.0.8-r1.ebuild, nagios-core-4.0.8-r2.ebuild: Use https by default Convert all URLs for sites supporting encrypted connections from http to https Signed-off-by: Justin Lecher 24 Aug 2015; Mike Gilbert metadata.xml: Revert DOCTYPE SYSTEM https changes in metadata.xml repoman does not yet accept the https version. This partially reverts eaaface92ee81f30a6ac66fe7acbcc42c00dc450. Bug: https://bugs.gentoo.org/552720 *nagios-core-4.1.1 (31 Aug 2015) 31 Aug 2015; Michael Orlitzky +nagios-core-4.1.1.ebuild: version bump to v4.1.1. In addition to the version bump, we now have to make the "html" target in src_compile. This requires DEPEND="app-arch/unzip" to unpack AngularJS. The perf data warnings patch has been applied upstream, so the corresponding epatch has been removed. "Any slot" operators were also added to the dev-lang/php deps to appease repoman. Package-Manager: portage-2.2.20.1 24 Jan 2016; Michał Górny metadata.xml: Replace all herds with appropriate projects (GLEP 67) Replace all uses of herd with appropriate project maintainers, or no maintainers in case of herds requested to be disbanded. 24 Jan 2016; Michał Górny metadata.xml: Set appropriate maintainer types in metadata.xml (GLEP 67) 15 Mar 2016; Agostino Sarubbo nagios-core-4.0.8-r2.ebuild: amd64 stable wrt bug #532744 Package-Manager: portage-2.2.26 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo 26 Apr 2016; Michael Orlitzky -nagios-core-4.0.8-r1.ebuild: remove old revision nagios-core-4.0.8-r1. Package-Manager: portage-2.2.26 *nagios-core-4.1.1-r1 (26 Apr 2016) 26 Apr 2016; Michael Orlitzky +files/use-INSTALL-to-install-themes-r1.patch, -nagios-core-4.1.1.ebuild, +nagios-core-4.1.1-r1.ebuild: new patch and revision to fix logo installation. The fix for bug 388321 required a patch, but that patch broke the installation of the theme logos (which live in their own directory). That patch has been updated as a new revision, use-INSTALL-to-install-themes-r1.patch, to avoid impacting nagios-core-4.0.8-r2.ebuild which is stable on amd64. The new revision nagios-4.1.1-r1 should pick up the new patch. Gentoo-Bug: 388321 Gentoo-Bug: 581148 Package-Manager: portage-2.2.26 18 May 2016; Austin English files/nagios, files/nagios3, files/nagios4: use #!/sbin/openrc-run instead of #!/sbin/runscript 23 May 2016; Tobias Klausmann nagios-core-4.0.8-r2.ebuild: 4.0.8-r2: add alpha keyword Gentoo-Bug: 532744 Package-Manager: portage-2.3.0_rc1 *nagios-core-4.2.1 (26 Sep 2016) 26 Sep 2016; Michael Orlitzky +nagios-core-4.2.1.ebuild: new version v4.2.1 with security fixes. This new version adds fixes for CVE-2008-4796 and CVE-2013-4214. The ebuild itself was updated to EAPI=6. That required dropping the depend.apache eclass, but that eclass was only used to define the $APACHE2_MODULES_CONFDIR variable, and it was easily inlined. The eutils and multilib eclasses were also dropped; the former because our patches are now obsolete, and the latter because get_libdir() is in EAPI=6. Gentoo-Bug: 595194 Package-Manager: portage-2.2.28 *nagios-core-4.2.2 (28 Oct 2016) 28 Oct 2016; Michael Orlitzky +nagios-core-4.2.2.ebuild: new version 4.2.2 with a fix for CVE-2008-4796. Gentoo-Bug: 598104 Reported-By: Tomáš Mózes Package-Manager: portage-2.3.0 28 Oct 2016; Michael Orlitzky -nagios-core-4.1.1-r1.ebuild, -nagios-core-4.2.1.ebuild: remove older versions not stabilized anywhere. Package-Manager: portage-2.3.0 *nagios-core-4.2.3 (04 Dec 2016) 04 Dec 2016; Michael Orlitzky -nagios-core-4.2.2.ebuild, +nagios-core-4.2.3.ebuild: net-analyzer/nagios{,-core}: new version 4.2.3 to fix CVE-2016-8641. Gentoo-Bug: 600864 Package-Manager: portage-2.3.0 *nagios-core-4.2.3-r1 (04 Dec 2016) 04 Dec 2016; Michael Orlitzky +files/nagios4-r1, -nagios-core-4.2.3.ebuild, +nagios-core-4.2.3-r1.ebuild: new revision and init script to fix CVE-2016-8641. The new version 4.2.3 was added to fix CVE-2016-8641 in commit c9f880e. However, the root privilege exploit results from the use of "chown" in the init script. We don't use upstream's init script, so a proper fix requires an update to our init script as well. The following changes were made to the init script: * We no longer attempt to delete the external command file before starting or stopping the daemon. It's not clear why this was done, and that file should not exist unless the user intentionally creates it. * We do not create or change ownership of /var/nagios/nagios.log or /var/nagios/status.sav when starting the daemon. The log file path is defined in the config file, so the hard-coded path in the init script might not have referred to the true location of the log file. And when the nagios daemon creates these files on its own, they should already have the correct permissions and ownership. By removing the "chown", we have actually fixed the root privilege exploit in CVE-2016-8641. * The two files /var/nagios/status.log and /var/nagios/nagios.tmp are not deleted after the daemon has shut down. I can come up with no compelling argument to do so. Gentoo-Bug: 600864 Package-Manager: portage-2.3.0 05 Dec 2016; Tobias Klausmann nagios-core-4.2.3-r1.ebuild: 4.2.3-r1: stable on alpha Gentoo-Bug: 600864 06 Dec 2016; Agostino Sarubbo nagios-core-4.2.3-r1.ebuild: amd64 stable wrt bug #600864 Package-Manager: portage-2.3.0 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo 06 Dec 2016; Agostino Sarubbo nagios-core-4.2.3-r1.ebuild: x86 stable wrt bug #600864 Package-Manager: portage-2.3.0 RepoMan-Options: --include-arches="x86" Signed-off-by: Agostino Sarubbo *nagios-core-4.2.4 (11 Dec 2016) 11 Dec 2016; Michael Orlitzky +nagios-core-4.2.4.ebuild: new version 4.2.4 to fix CVE-2016-9566. Gentoo-Bug: 602216 Package-Manager: portage-2.3.0 11 Dec 2016; Michael Orlitzky metadata.xml: remove proxy maintainers from the metadata. We haven't heard from this package's proxy maintainer in a while, but new bugs are still being assigned to him. As long as I'm the de-facto maintainer, I would prefer that they be assigned to me. This commit removes both the proxied and proxy maintainers, as well as the proxy-maint project (who gave the OK for this removal). Package-Manager: portage-2.3.0 12 Dec 2016; Tobias Klausmann nagios-core-4.2.4.ebuild: 4.2.4-r0: stable on alpha Gentoo-Bug: 602216 13 Dec 2016; Agostino Sarubbo nagios-core-4.2.4.ebuild: amd64 stable wrt bug #602216 Package-Manager: portage-2.3.0 RepoMan-Options: --include-arches="amd64" Signed-off-by: Agostino Sarubbo 13 Dec 2016; Agostino Sarubbo nagios-core-4.2.4.ebuild: x86 stable wrt bug #602216 Package-Manager: portage-2.3.0 RepoMan-Options: --include-arches="x86" Signed-off-by: Agostino Sarubbo