]> git.ipfire.org Git - people/teissler/ipfire-2.x.git/blobdiff - lfs/squid
squid: Fix two security issues.
[people/teissler/ipfire-2.x.git] / lfs / squid
index 3a5e2659e92e3cd4510028957b7dedd2111b05a7..81118c2c39663bb2cdf5280b316a3c47ead22124 100644 (file)
--- a/lfs/squid
+++ b/lfs/squid
@@ -1,7 +1,7 @@
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007  Michael Tremer & Christian Schmidt                      #
+# Copyright (C) 2007-2012  IPFire Team  <info@ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
 
 include Config
 
-VER        = 2.7.STABLE9
+VER        = 3.1.23
 
 THISAPP    = squid-$(VER)
-DL_FILE    = $(THISAPP).tar.gz
+DL_FILE    = $(THISAPP).tar.bz2
 DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_MD5 = 7d3b8b0bdda3ae56e438d4a95a97d3b3
+$(DL_FILE)_MD5 = e15fdb8c615cf1f9525be0a2b75c60a7
 
 install : $(TARGET)
 
@@ -69,26 +69,47 @@ $(subst %,%_MD5,$(objects)) :
 
 $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
        @$(PREBUILD)
-       @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE)
+       @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar xjf $(DIR_DL)/$(DL_FILE)
+
+       cd $(DIR_APP) && patch -Np0 -i $(DIR_SRC)/src/patches/squid-3.1-10486.patch
+       cd $(DIR_APP) && patch -Np0 -i $(DIR_SRC)/src/patches/squid-3.1-10487.patch
 
        cd $(DIR_APP) && ./configure --prefix=/usr --disable-nls \
           --datadir=/usr/lib/squid \
           --mandir=/usr/share/man --libexecdir=/usr/lib/squid \
           --localstatedir=/var --sysconfdir=/etc/squid \
-          --disable-poll --disable-icmp --disable-wccp \
+          --enable-poll --enable-icmp --disable-wccp \
           --enable-ident-lookups \
-          --enable-storeio="aufs,coss,diskd,ufs,null" --enable-ssl \
+          --enable-storeio="aufs,diskd,ufs" --enable-ssl \
           --enable-underscores --enable-ntlm-fail-open --enable-arp-acl \
           --enable-http-violations --enable-auth=basic,ntlm \
           --enable-removal-policies="heap,lru" \
           --enable-delay-pools --enable-linux-netfilter \
-          --enable-basic-auth-helpers="NCSA,SMB,MSNT,LDAP,multi-domain-NTLM" \
-          --enable-ntlm-auth-helpers="SMB" \
+          --enable-basic-auth-helpers="NCSA,SMB,MSNT,LDAP,multi-domain-NTLM,PAM,squid_radius_auth" \
           --enable-useragent-log \
           --enable-referer-log \
              --enable-snmp \
           --with-pthreads --with-dl \
-          --with-maxfd="16384"
+          --with-maxfd="65536" \
+          --with-filedescriptors=65536 \
+          --with-large-files \
+          --with-aio \
+          --enable-async-io=8 \
+          --enable-unlinkd \
+          --enable-ntln-fail-open \
+          --enable-ntlm-auth-helpers="smb_lm,no_check,fakeauth" \
+          --enable-internal-dns \
+          --enable-epoll \
+          --disable-kqueue \
+          --enable-select \
+          --enable-cache-digests \
+          --enable-forw-via-db \
+          --enable-htcp \
+          --enable-ipf-transparent \
+          --enable-kill-parent-hack \
+          --disable-wccpv2 \
+          --enable-icap-client \
+          --disable-esi
 
        cd $(DIR_APP) && make $(MAKETUNING)
        cd $(DIR_APP) && make install
@@ -98,7 +119,7 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
        rm -f /etc/squid/cachemgr.conf
        ln -sf /var/ipfire/proxy/cachemgr.conf /etc/squid/cachemgr.conf
        rm -f /etc/squid/errors
-       ln -sf /usr/lib/squid/errors/English /etc/squid/errors
+       ln -sf /usr/lib/squid/errors/en /etc/squid/errors
 
        -mkdir -p /var/log/cache /var/log/squid /var/log/updatexlrator
        touch /var/log/squid/access.log
@@ -116,8 +137,6 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 
        cp -f $(DIR_SRC)/config/updxlrator/updxlrator-lib.pl /var/ipfire/updatexlrator//updxlrator-lib.pl
 
-       -mkdir -p /usr/lib/squid/errors.ipfire
-       cp -fr $(DIR_SRC)/config/proxy/errors.ipfire/* /usr/lib/squid/errors.ipfire/
        chmod 755 /usr/sbin/updxlrator /var/ipfire/updatexlrator/bin/checkup \
                /var/ipfire/updatexlrator/bin/download \
                /var/ipfire/updatexlrator/bin/convert \
@@ -144,5 +163,9 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
        chown nobody.nobody /srv/web/ipfire/html/proxy.pac
        ln -sf /srv/web/ipfire/html/proxy.pac /srv/web/ipfire/html/wpad.dat
 
+       #Copy stylesheets for the errorpages
+       cp -f $(DIR_SRC)/config/proxy/errorpage-ipfire.css /var/ipfire/proxy/
+       cp -f /etc/squid/errorpage.css /var/ipfire/proxy/errorpage-squid.css
+
        @rm -rf $(DIR_APP)
        @$(POSTBUILD)