From nobody Tue May 14 15:27:50 2024 X-Original-To: dev-commits-ports-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Vf0bp60xGz5KXMS; Tue, 14 May 2024 15:27:50 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Vf0bp5Kc4z4hWJ; Tue, 14 May 2024 15:27:50 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1715700470; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=vx4A6UyhG6Bg8FrHdG7C0f8w0a4V9BH9/f1FHxSWEfU=; b=JJdmkOyspd04Qs/OgenT7MZHLRdg6sURqgSomFHxSn3s3DQPAujaoHqsH9O2p5Ne8gNgWv D0Cu7K2z0hr4m6CPLbX+o+DiiFBSSHADLDit6P8QE8knpHxvyDCk5Vu1KJHxzYl1V3BW3x Of5ek6PF/EURmngWs4MS8Hsz6ZlqfFmGdre70QSIKOsLl6PFs4NOrigM2IuJquYl6qOUms qMHVzoQbFcsIfIikypb4o1/GT5qGHyT+MsqMjEumNMZKHRBMzv29sXA3YcDKy2dXr7QVTc oPbAEn6CFzx0cVkCvbo1/UiREp7+EYJrlrLq1NP9y7wK60gHg+NCylIR0lNe+w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1715700470; a=rsa-sha256; cv=none; b=l6JO6dxDZuhl7X70gO+28VdeSStw5w8ElNiMhyLWmGoflV0icyv3/Hzj3mabspOJ+aktgW HdCh/OIMflwB0X5xKVqiqe2Z7kBJ4SLzlqcHnBSN9HBn0/mLtztK6tJYqTsGtFL2JDKsbx bi0YBFcvSgLS0HXpuhVWVbe0dLqj41EkpR/cr9dnTav/PHaq1QQ8etRn62PkcHEJ4wmqLt f8ihvRHGon8pCXL7Rdd/jEM6LtO2sgG3xBzQsw9le3/iH3cDm2TXW7DkS+eSUoK5hgcaHs dS2j/BefZIlTQXYRReMBqLOXUo6q8JHExlmxlBSFuKOSfHDj/tUoMbWdnUrYIw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1715700470; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=vx4A6UyhG6Bg8FrHdG7C0f8w0a4V9BH9/f1FHxSWEfU=; b=XiT9usXNQKD5okR+L6Qof10qw2gRJpCieclLORUOQBUjp6d5JnGfA6IhPGCHCUc6i0kG/0 icgQw0pM0Wfk8x5A4ZgbH2yVJhvBqFBgCKcUrN7ZKyeMqSvpGXEqD+Nj4B2t1LiQzhMwpT Bt3Q3WpobdbZNZBLnFr30xTTHC6VFAXTJu8TQqu9whoGx0kGXRre2zvlACRZlRnXuCejP9 S39aPyDDq5Xq/wu69p2uxGquEeAgjbjIMy0kIRUcxc5i1O91V77b93//h9h8GvCEV6wCoH zX+kG0UX/TPbVghgKWci8R5ZdOYA+klObnFkQfTy2fvBk4H2Cq8sJDFdie+31Q== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Vf0bp4p33zcpr; Tue, 14 May 2024 15:27:50 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 44EFRo6q066648; Tue, 14 May 2024 15:27:50 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 44EFRoqD066645; Tue, 14 May 2024 15:27:50 GMT (envelope-from git) Date: Tue, 14 May 2024 15:27:50 GMT Message-Id: <202405141527.44EFRoqD066645@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Mark Johnston Subject: git: 52fe0689eac7 - main - net-mgmt/net-snmp: Avoid changing to the snmpd user for now List-Id: Commit messages for all branches of the ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-all@freebsd.org Sender: owner-dev-commits-ports-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 52fe0689eac79f0287cd884f526d33d44237869a Auto-Submitted: auto-generated The branch main has been updated by markj: URL: https://cgit.FreeBSD.org/ports/commit/?id=52fe0689eac79f0287cd884f526d33d44237869a commit 52fe0689eac79f0287cd884f526d33d44237869a Author: Mark Johnston AuthorDate: 2024-05-14 14:43:03 +0000 Commit: Mark Johnston CommitDate: 2024-05-14 15:27:26 +0000 net-mgmt/net-snmp: Avoid changing to the snmpd user for now Switching the user might break existing configurations, for reasons that are not fully clear yet. Avoid surprises by letting users opt-in to that change, for now. Also provide an rc.conf variable to make it easy to configure snmpd to drop privileges if they so choose. Reported by: dvl Approved by: zi Sponsored by: Klara, Inc. Sponsored by: Stormshield Differential Revision: https://reviews.freebsd.org/D45199 --- net-mgmt/net-snmp/Makefile | 2 +- net-mgmt/net-snmp/files/snmpd.in | 13 ++++++++++++- 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/net-mgmt/net-snmp/Makefile b/net-mgmt/net-snmp/Makefile index 5fca4ba36051..01534364feb8 100644 --- a/net-mgmt/net-snmp/Makefile +++ b/net-mgmt/net-snmp/Makefile @@ -1,7 +1,7 @@ PORTNAME= snmp PORTVERSION= 5.9.4 PORTEPOCH= 1 -PORTREVISION= 1 +PORTREVISION= 2 CATEGORIES= net-mgmt MASTER_SITES= SF/net-${PORTNAME}/net-${PORTNAME}/${PORTVERSION} \ ZI diff --git a/net-mgmt/net-snmp/files/snmpd.in b/net-mgmt/net-snmp/files/snmpd.in index 7f140200aa45..7f75cacad813 100644 --- a/net-mgmt/net-snmp/files/snmpd.in +++ b/net-mgmt/net-snmp/files/snmpd.in @@ -8,6 +8,12 @@ # snmpd_enable="YES" # snmpd_flags="" # snmpd_conffile="" +# +# Add the following line to make snmpd drop privileges after initialization. +# This might invalidate existing SNMPv3 users. +# +# snmpd_sugid="YES" +# . /etc/rc.subr @@ -18,6 +24,7 @@ load_rc_config snmpd snmpd_enable=${snmpd_enable:-"NO"} snmpd_flush_cache=${snmpd_flush_cache-"NO"} +snmpd_sugid=${snmpd_sugid:-"NO"} pidfile=${snmpd_pidfile:-"/var/run/net_snmpd.pid"} @@ -57,7 +64,11 @@ net_snmpd_precmd () { if [ -n "${snmpd_conffile_set}" ]; then rc_flags="-c ${snmpd_conffile_set#,} ${rc_flags}" fi - rc_flags="-u snmpd -g snmpd -p ${pidfile} ${rc_flags}" + if checkyesno snmpd_sugid; then + rc_flags="-u snmpd -g snmpd ${rc_flags}" + fi + + rc_flags="-p ${pidfile} ${rc_flags}" } run_rc_command "$1"