Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 518828 - www-apache/mod_security-2.8.0 version bump
Summary: www-apache/mod_security-2.8.0 version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal enhancement (vote)
Assignee: No maintainer - Look at https://wiki.gentoo.org/wiki/Project:Proxy_Maintainers if you want to take care of it
URL:
Whiteboard:
Keywords: EBUILD
: 529614 (view as bug list)
Depends on:
Blocks: 615750
  Show dependency tree
 
Reported: 2014-08-02 13:55 UTC by Mario D. Santana
Modified: 2017-06-05 18:30 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
www-apache/mod_security-2.8.0.ebuild (Update) (mod_security-2.8.0.ebuild,2.50 KB, text/plain)
2014-08-02 13:55 UTC, Mario D. Santana
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Mario D. Santana 2014-08-02 13:55:51 UTC
Created attachment 382088 [details]
www-apache/mod_security-2.8.0.ebuild (Update)

The latest ebuild is a year old, time for a bump?  The same ebuild file still works for me.  I've added modsecurity.conf-recommended to the dodoc, though, since I always end up downloading a copy every time I install this software.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2014-11-17 12:39:19 UTC
*** Bug 529614 has been marked as a duplicate of this bug. ***
Comment 2 Travis Hansen 2014-11-18 22:52:52 UTC
Also, can we get some additional config options added as well to reduce the pcre errors (they render the output quite unusable)?

--enable-pcre-match-limit=no \
--enable-pcre-match-limit-recursion=no \
--enable-pcre-study \ 

http://www4.atomicorp.com/channels/source/mod_security/mod_security.spec

Without that it's impossible to get rid of the seemingly common error: Execution error - PCRE limits exceeded (-8): (null)

Thanks!
Comment 3 Tomáš Mózes 2015-05-21 19:38:08 UTC
Version 2.9.0 was released Feb 12 2015.
Comment 4 Josh G 2016-04-15 00:30:00 UTC
And version 2.9.1 was released on Mar 09, 2016.

How can I help move this along? 2.9.0 is in barzog-overlay
Comment 5 Tomáš Mózes 2016-04-15 14:16:18 UTC
Josh, you can maintain this as a proxy maintainer. Do you wish to?
Comment 6 Josh G 2016-04-15 16:14:15 UTC
(In reply to Tomáš Mózes from comment #5)
> Josh, you can maintain this as a proxy maintainer. Do you wish to?

If I knew how. :)

I don't (yet) know the depths of ebuilds & portage, and haven't yet used mod_security, but I can try to give it a go.

Let me see if I can take barzog's 2.9.0 ebuild and get it to work on 2.9.1.
Comment 7 Oleg Gawriloff 2016-04-15 16:15:33 UTC
I already updated it to 2.9.1. ALthough not tested.
Comment 8 Leho Kraav (:macmaN @lkraav) 2016-07-18 14:40:52 UTC
Just filing pull request against the main tree on github would get this bumped.
Comment 9 Mario D. Santana 2016-07-18 15:25:28 UTC
I'd happily add a pull request, but unfortunately I'm not running any Gentoo at the moment.  :(
Comment 10 Leho Kraav (:macmaN @lkraav) 2016-07-18 15:31:49 UTC
(In reply to Mario D. Santana from comment #9)
> I'd happily add a pull request, but unfortunately I'm not running any Gentoo
> at the moment.  :(

I'll see what I can do on my own.
Comment 11 Leho Kraav (:macmaN @lkraav) 2016-07-18 19:58:27 UTC
I'm a bit confused about `files/modsecurity-2.7.conf`.

1. It's gets moved to `79_modsecurity.conf`, while all other config files are `XX_mod_something.conf` format.

2. Why isn't https://github.com/SpiderLabs/ModSecurity/blob/master/modsecurity.conf-recommended copied into the initial config file outright, with a few `IfDefine` etc modifications. This config file seems much more useful, whereas Gentoo's currently literally seems to do nothing.

3. https://wiki.gentoo.org/wiki/Apache#Enabling_mod_security is of not much help, since it seems to indicate that things just work out of the box. Probably should be updated with `modsecurity.conf-recommended` or some other basic ruleset guide, or am I missing something?
Comment 12 Michael Orlitzky gentoo-dev 2017-05-08 01:58:59 UTC
I just committed mod_security-2.9.1 with a mixture of suggestions from here and bug 615294. Can you please give that a try to see if it at least works? Then we can work on polishing it up.