summaryrefslogtreecommitdiff
blob: 6bf20dbcc7066f9f53ac2df04f1a6392a9066b11 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
# Copyright 1999-2008 Gentoo Foundation
# Distributed under the terms of the GNU General Public License v2
# $Header: /var/cvsroot/gentoo-x86/net-misc/scponly/scponly-4.8.ebuild,v 1.3 2008/01/18 20:21:59 dertobi123 Exp $

inherit eutils multilib

DESCRIPTION="A tiny pseudoshell which only permits scp and sftp"
HOMEPAGE="http://www.sublimation.org/scponly/"
SRC_URI="mirror://sourceforge/scponly/${P}.tgz"

LICENSE="as-is"
SLOT="0"
KEYWORDS="~amd64 ~mips ppc ~sparc x86"
IUSE="rsync subversion"

DEPEND="virtual/libc
	net-misc/openssh
	rsync? ( net-misc/rsync )
	subversion? ( dev-util/subversion )"

myuser="scponly"
myhome="/home/${myuser}"

pkg_setup() {
	if use subversion || use rsync ; then
		ewarn
		ewarn "read the \"SECURITY\" document in ${P}.tgz before enabling 'rsync' or 'subversion' USE flag"
		ewarn
		ebeep 5
	fi
}

src_compile() {
	econf \
		--disable-wildcards \
		--enable-chrooted-binary \
		--disable-gftp-compat \
		--with-sftp-server="/usr/$(get_libdir)/misc/sftp-server" \
		$(use_enable rsync rsync-compat) \
		$(use_enable subversion svn-compat) \
		$(use_enable subversion svnserv-compat) \
		|| die "./configure failed"
	emake || die
}

src_install() {
	emake DESTDIR="${D}" install || die

	dodoc AUTHOR BUILDING-JAILS.TXT CHANGELOG CONTRIB README SECURITY TODO
	dodoc setup_chroot.sh
}

pkg_postinst() {
	elog "You might want to run:"
	elog "\"emerge --config =${CATEGORY}/${PF}\""
	elog "to setup the chroot."
	elog "Otherwise you will have to setup chroot manually."

	# two slashes ('//') are used by scponlyc to determine the chroot point.
	enewgroup "${myuser}"
	enewuser "${myuser}" -1 /usr/sbin/scponlyc "${myhome}//" "${myuser}"
}

pkg_config() {
	# pkg_postinst is based on ${S}/setup_chroot.sh.

	einfo "Updating /etc/shells"
	{ grep -v "^/usr/bin/scponly$" /etc/shells;
	echo "/usr/bin/scponly"
	} > "${T}"/shells
	cp "${T}"/shells /etc/shells

	{ grep -v "^/usr/sbin/scponlyc$" /etc/shells;
	echo "/usr/sbin/scponlyc"
	} > "${T}"/shells
	cp "${T}"/shells /etc/shells

	BINARIES="/usr/$(get_libdir)/misc/sftp-server /bin/ls /usr/bin/scp /bin/rm /bin/ln /bin/mv /bin/chmod /bin/chown /bin/chgrp /bin/mkdir /bin/rmdir /bin/pwd /bin/groups /usr/bin/ld /bin/echo"
	if built_with_use =${CATEGORY}/${PF} rsync; then
		BINARIES="$BINARIES /usr/bin/rsync"
	fi
	if built_with_use =${CATEGORY}/${PF} subversion; then
	    BINARIES="$BINARIES /usr/bin/svn /usr/bin/svnserve"
	fi
	LIB_LIST=`ldd $BINARIES 2> /dev/null | cut -f2 -d\> | cut -f1 -d\( | grep "^[ 	]" | sort -u`
	LDSO_LIST="/$(get_libdir)/ld.so /libexec/ld-elf.so /libexec/ld-elf.so.1 /usr/libexec/ld.so /$(get_libdir)/ld-linux.so.2 /usr/libexec/ld-elf.so.1"
	for lib in $LDSO_LIST; do
		if [ -f $lib ]; then
		    LIB_LIST="$LIB_LIST $lib"
		fi
	done
	ls /$(get_libdir)/libnss_compat* > /dev/null 2>&1
	if [ $? -eq 0 ]; then
	    LIB_LIST="$LIB_LIST /$(get_libdir)/libnss_compat*"
	fi

	ldconfig
	LIB_LIST="$LIB_LIST /etc/ld.so.cache /etc/ld.so.conf"

	if [ ! -d ${myhome} ]; then
		install -c -d ${myhome}
		chmod 755 ${myhome}
	fi
	if [ ! -d ${myhome} ]; then
		install -c -d ${myhome}/etc
		chown 0:0 ${myhome}/etc
		chmod 755 ${myhome}/etc
	fi
	if [ ! -d ${myhome}/$(get_libdir) ]; then
		install -c -d ${myhome}/$(get_libdir)
		chmod 755 ${myhome}/$(get_libdir)
	fi
	if [ ! -d ${myhome}/lib ]; then
		ln -s $(get_libdir) ${myhome}/lib
	fi
	if [ ! -d ${myhome}/usr/$(get_libdir) ]; then
		install -c -d ${myhome}/usr/$(get_libdir)
		chmod 755 ${myhome}/usr/$(get_libdir)
	fi
	if [ ! -d ${myhome}/usr/lib ]; then
		ln -s $(get_libdir) ${myhome}/usr/lib
	fi

	for bin in $BINARIES; do
		install -c -d ${myhome}/`/bin/dirname $bin`
		install -c $bin ${myhome}/$bin
	done
	for lib in $LIB_LIST; do
		install -c -d ${myhome}/`/bin/dirname $lib`
		install -c $lib ${myhome}/$lib
	done

	chown 0:0 ${myhome}
	if [ -d ${myhome}/.ssh ]; then
		chown 0:0 ${myhome}/.ssh
	fi

	if [ ! -d ${myhome}/incoming ]; then
		einfo "creating ${myhome}/incoming directory for uploading files"
		install -c -o ${myuser} -d ${myhome}/incoming
	fi
	chown $myuser:$myuser ${myhome}/incoming

	if [ ! -e ${myhome}/etc/passwd ]; then
		grep "^${myuser}" /etc/passwd > ${myhome}/etc/passwd
	fi

	# Bug 135505
	if [ ! -e ${myhome}/dev/null ]; then
		install -c -d ${myhome}/dev
		mknod -m 777 ${myhome}/dev/null c 1 3
	fi
}