]> git.ipfire.org Git - people/pmueller/ipfire-3.x.git/commitdiff
openssh: Change privsep directory to /var/lib/sshd
authorStefan Schantl <stefan.schantl@ipfire.org>
Sun, 19 Mar 2023 14:49:00 +0000 (15:49 +0100)
committerMichael Tremer <michael.tremer@ipfire.org>
Tue, 21 Mar 2023 18:25:40 +0000 (18:25 +0000)
The old one /var/empty/sshd violated our FHS

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
openssh/openssh.nm

index 9ccff01e5c46ba2f78195244770c116492aba81b..2d90ee6bac427d291e8ac4ba9d991f4de3720964 100644 (file)
@@ -5,7 +5,7 @@
 
 name       = openssh
 version    = 9.1p1
-release    = 3
+release    = 4
 
 groups     = Application/Internet
 url        = https://www.openssh.com/portable.html
@@ -41,7 +41,7 @@ build
                --libexecdir=%{libdir}/openssh \
                --with-default-path=/usr/local/bin:/bin:/usr/bin \
                --with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
-               --with-privsep-path=/var/empty/sshd \
+               --with-privsep-path=%{sharedstatedir}/sshd \
                --enable-vendor-patchlevel="%{DISTRO_NAME} %{thisver}" \
                --disable-strip \
                --with-ssl-engine \
@@ -147,7 +147,7 @@ packages
                        %{mandir}/man5/moduli.5*
                        %{mandir}/man8/sshd.8*
                        %{mandir}/man8/sftp-server.8*
-                       /var/empty/sshd
+                       %{sharedstatedir}/sshd
                end
 
                configfiles
@@ -164,7 +164,7 @@ packages
                        getent group sshd >/dev/null || groupadd -r sshd
                        getent passwd sshd >/dev/null || useradd -r -g sshd \
                                -c "Privilege-separated SSH" \
-                               -d /var/empty/sshd -s /sbin/nologin sshd
+                               -d /var/lib/sshd -s /sbin/nologin sshd
                end
 
                script postin