diff --git a/security/teleport/Makefile b/security/teleport/Makefile index 6e3442557a4b..68134871f0fd 100644 --- a/security/teleport/Makefile +++ b/security/teleport/Makefile @@ -1,73 +1,74 @@ PORTNAME= teleport DISTVERSIONPREFIX= v -DISTVERSION= 4.3.9 -PORTREVISION= 6 +DISTVERSION= 4.4.12 CATEGORIES= security -MAINTAINER= swills@FreeBSD.org -COMMENT= Gravitational Teleport SSH -WWW= https://gravitational.com/teleport/ +MAINTAINER= kraileth@elderlinux.org +COMMENT= Centralized access gateway using the SSH protocol +WWW= https://goteleport.com/teleport LICENSE= APACHE20 NOT_FOR_ARCHS= i386 NOT_FOR_ARCHS_REASON= Uses 64bit types BUILD_DEPENDS= zip:archivers/zip +# If you need the auth service to work, you need to compile this port with +# Go 1.17 or older. In case tsh is what you're after, Go 1.19 is fine. USES= compiler gmake go USE_GITHUB= yes GH_ACCOUNT= gravitational -GH_TUPLE= gravitational:webassets:eac734b:webassets/webassets +GH_TUPLE= gravitational:webassets:2ee76aa:webassets/webassets GH_COMMIT_SHORT= fabee242d GH_TAG_COMMIT= ${DISTVERSIONPREFIX}${DISTVERSION}-0-g${GH_COMMIT_SHORT} USE_RC_SUBR= teleport # Extra assets are stored in the binary and must not be inadvertently removed STRIP= NOPRECIOUSMAKEVARS= YES SUB_FILES= pkg-message PLIST_FILES= bin/tctl \ bin/teleport \ bin/tsh \ "@sample etc/teleport.yaml.sample" GO_TELEPORT_SRC_DIR= src/github.com/gravitational/teleport PRE_GOPATH_DIR= ${PORTNAME}-${DISTVERSION}${DISTVERSIONSUFFIX} post-patch: @${MKDIR} ${WRKDIR}/${GO_TELEPORT_SRC_DIR} @${REINPLACE_CMD} -e 's|%%GH_TAG_COMMIT%%|${GH_TAG_COMMIT}|' \ ${WRKSRC}/version.mk @${CP} -rpH ${WRKDIR}/${PRE_GOPATH_DIR}/vendor/* ${WRKDIR}/src/ @${CP} -rpH ${WRKDIR}/${PRE_GOPATH_DIR}/* ${WRKDIR}/${GO_TELEPORT_SRC_DIR}/ do-build: @cd ${WRKDIR}/${GO_TELEPORT_SRC_DIR} && \ ${SETENV} ${MAKE_ENV} ${BUILD_ENV} ${GO_ENV} \ CGO_ENABLED=1 GOPATH=${WRKDIR} \ ${GMAKE} full do-install: ${WRKDIR}/${GO_TELEPORT_SRC_DIR}/build/teleport configure > ${STAGEDIR}${PREFIX}/etc/teleport.yaml.sample @${SED} -i '' \ -e "s|nodename: .*|nodename: |g" \ -e "s|cluster-join-token||g" \ ${STAGEDIR}${PREFIX}/etc/teleport.yaml.sample ${INSTALL_PROGRAM} ${WRKDIR}/${GO_TELEPORT_SRC_DIR}/build/teleport ${STAGEDIR}${PREFIX}/bin ${INSTALL_PROGRAM} ${WRKDIR}/${GO_TELEPORT_SRC_DIR}/build/tsh ${STAGEDIR}${PREFIX}/bin ${INSTALL_PROGRAM} ${WRKDIR}/${GO_TELEPORT_SRC_DIR}/build/tctl ${STAGEDIR}${PREFIX}/bin .include # golang assumes that if clang is in use, it is called "clang" and not "cc". If # it's called "cc", go fails. .if ${COMPILER_TYPE} == clang BUILD_ENV= CC=clang .endif .include diff --git a/security/teleport/distinfo b/security/teleport/distinfo index 27c4250be5b5..362cf0489a3b 100644 --- a/security/teleport/distinfo +++ b/security/teleport/distinfo @@ -1,5 +1,5 @@ -TIMESTAMP = 1609025109 -SHA256 (gravitational-teleport-v4.3.9_GH0.tar.gz) = 6b095366cfe788ca72ef7dc2bb052ff258b0e48de82b05b34f935f928b1aa776 -SIZE (gravitational-teleport-v4.3.9_GH0.tar.gz) = 54786284 -SHA256 (gravitational-webassets-eac734b_GH0.tar.gz) = 3f78270f137d690adafd3ec918e51cebc0c2f18c6b3879a57eaa19a267bfc64c -SIZE (gravitational-webassets-eac734b_GH0.tar.gz) = 4683803 +TIMESTAMP = 1665730213 +SHA256 (gravitational-teleport-v4.4.12_GH0.tar.gz) = 097537273bd0579b3b833870cab74ce1da5432357a14c5501db7a2c525fbcb15 +SIZE (gravitational-teleport-v4.4.12_GH0.tar.gz) = 37824023 +SHA256 (gravitational-webassets-2ee76aa_GH0.tar.gz) = 16c5fbdc43723c392d46163073053c850cae7d355fb97b5ba8fd298246be85c4 +SIZE (gravitational-webassets-2ee76aa_GH0.tar.gz) = 4684443 diff --git a/security/teleport/files/patch-build.assets_pkg_etc_teleport.yaml b/security/teleport/files/patch-build.assets_pkg_etc_teleport.yaml deleted file mode 100644 index 7a370e692e2e..000000000000 --- a/security/teleport/files/patch-build.assets_pkg_etc_teleport.yaml +++ /dev/null @@ -1,51 +0,0 @@ ---- build.assets/pkg/etc/teleport.yaml.orig 2020-07-08 18:08:40 UTC -+++ build.assets/pkg/etc/teleport.yaml -@@ -9,7 +9,7 @@ teleport: - - # Data directory where Teleport daemon keeps its data. - # See "Filesystem Layout" section above for more details. -- # data_dir: /var/lib/teleport -+ # data_dir: /var/db/teleport - - # Invitation token used to join a cluster. it is not used on - # subsequent starts -@@ -54,8 +54,8 @@ teleport: - type: dir - - # Array of locations where the audit log events will be stored. by -- # default they are stored in `/var/lib/teleport/log` -- # audit_events_uri: ['file:///var/lib/teleport/log', 'dynamodb://events_table_name', 'stdout://'] -+ # default they are stored in `/var/db/teleport/log` -+ # audit_events_uri: ['file:///var/db/teleport/log', 'dynamodb://events_table_name', 'stdout://'] - - # Use this setting to configure teleport to store the recorded sessions in - # an AWS S3 bucket. see "Using Amazon S3" chapter for more information. -@@ -111,7 +111,7 @@ auth_service: - # By default an automatically generated name is used (not recommended) - # - # IMPORTANT: if you change cluster_name, it will invalidate all generated -- # certificates and keys (may need to wipe out /var/lib/teleport directory) -+ # certificates and keys (may need to wipe out /var/db/teleport directory) - # cluster_name: "main" - - authentication: -@@ -185,7 +185,7 @@ auth_service: - # - # If not set, by default Teleport will look for the `license.pem` file in - # the configured `data_dir`. -- # license_file: /var/lib/teleport/license.pem -+ # license_file: /var/db/teleport/license.pem - - # DEPRECATED in Teleport 3.2 (moved to proxy_service section) - # kubeconfig_file: /path/to/kubeconfig -@@ -258,8 +258,8 @@ proxy_service: - - # TLS certificate for the HTTPS connection. Configuring these properly is - # critical for Teleport security. -- # https_key_file: /var/lib/teleport/webproxy_key.pem -- # https_cert_file: /var/lib/teleport/webproxy_cert.pem -+ # https_key_file: /var/db/teleport/webproxy_key.pem -+ # https_cert_file: /var/db/teleport/webproxy_cert.pem - - # This section configures the Kubernetes proxy service - # kubernetes: diff --git a/security/teleport/files/patch-docs_pages_config-reference.mdx b/security/teleport/files/patch-docs_pages_config-reference.mdx new file mode 100644 index 000000000000..b5a8eabc6bb0 --- /dev/null +++ b/security/teleport/files/patch-docs_pages_config-reference.mdx @@ -0,0 +1,68 @@ +--- docs/pages/config-reference.mdx.orig 2022-02-23 04:58:43 UTC ++++ docs/pages/config-reference.mdx +@@ -21,7 +21,7 @@ teleport: + + # Data directory where Teleport daemon keeps its data. + # See "Filesystem Layout" section above for more details. +- data_dir: /var/lib/teleport ++ data_dir: /var/db/teleport + + # Invitation token used to join a cluster. it is not used on + # subsequent starts +@@ -52,11 +52,11 @@ teleport: + max_connections: 1000 + max_users: 250 + +- # Logging configuration. Possible output values to disk via '/var/lib/teleport/teleport.log', ++ # Logging configuration. Possible output values to disk via '/var/db/teleport/teleport.log', + # 'stdout', 'stderr' and 'syslog'. Possible severity values are INFO, WARN + # and ERROR (default). Possible format values include: timestamp, component, caller, and level. + log: +- output: /var/lib/teleport/teleport.log ++ output: /var/db/teleport/teleport.log + severity: ERROR + format: [level, timestamp, component, caller] + # Configuration for the storage back-end used for the cluster state and the +@@ -68,11 +68,11 @@ teleport: + type: dir + + # List of locations where the audit log events will be stored. By default, +- # they are stored in `/var/lib/teleport/log` ++ # they are stored in `/var/db/teleport/log` + # When specifying multiple destinations like this, make sure that any highly-available + # storage methods (like DynamoDB or Firestore) are specified first, as this is what the + # Teleport web UI uses as its source of events to display. +- audit_events_uri: ['dynamodb://events_table_name', 'firestore://events_table_name', 'file:///var/lib/teleport/log', 'stdout://'] ++ audit_events_uri: ['dynamodb://events_table_name', 'firestore://events_table_name', 'file:///var/db/teleport/log', 'stdout://'] + + # Use this setting to configure teleport to store the recorded sessions in + # an AWS S3 bucket or use GCP Storage with 'gs://'. See "Using Amazon S3" +@@ -131,7 +131,7 @@ auth_service: + # By default an automatically generated name is used (not recommended) + # + # IMPORTANT: if you change cluster_name, it will invalidate all generated +- # certificates and keys (may need to wipe out /var/lib/teleport directory) ++ # certificates and keys (may need to wipe out /var/db/teleport directory) + cluster_name: "main" + + authentication: +@@ -223,7 +223,7 @@ auth_service: + # + # If not set, by default Teleport will look for the `license.pem` file in + # the configured `data_dir` . +- license_file: /var/lib/teleport/license.pem ++ license_file: /var/db/teleport/license.pem + + # This section configures the 'node service': + ssh_service: +@@ -320,8 +320,8 @@ proxy_service: + + # TLS certificate for the HTTPS connection. Configuring these properly is + # critical for Teleport security. +- https_key_file: /var/lib/teleport/webproxy_key.pem +- https_cert_file: /var/lib/teleport/webproxy_cert.pem ++ https_key_file: /var/db/teleport/webproxy_key.pem ++ https_cert_file: /var/db/teleport/webproxy_cert.pem + + # This section configures the Kubernetes proxy service + kubernetes: diff --git a/security/teleport/files/patch-lib_config_fileconf.go b/security/teleport/files/patch-lib_config_fileconf.go deleted file mode 100644 index 5f8e7c1374a6..000000000000 --- a/security/teleport/files/patch-lib_config_fileconf.go +++ /dev/null @@ -1,11 +0,0 @@ ---- lib/config/fileconf.go.orig 2020-07-08 18:08:40 UTC -+++ lib/config/fileconf.go -@@ -281,7 +281,7 @@ func MakeSampleFileConfig() (fc *FileConfig, err error - s.Commands = []CommandLabel{ - { - Name: "hostname", -- Command: []string{"/usr/bin/hostname"}, -+ Command: []string{"/bin/hostname"}, - Period: time.Minute, - }, - { diff --git a/security/teleport/files/patch-lib_defaults_defaults.go b/security/teleport/files/patch-lib_defaults_defaults.go index 7fbb9101de4f..a0ec9693613e 100644 --- a/security/teleport/files/patch-lib_defaults_defaults.go +++ b/security/teleport/files/patch-lib_defaults_defaults.go @@ -1,11 +1,11 @@ ---- lib/defaults/defaults.go.orig 2020-07-08 18:08:40 UTC +--- lib/defaults/defaults.go.orig 2022-02-23 04:58:43 UTC +++ lib/defaults/defaults.go -@@ -436,7 +436,7 @@ var ( +@@ -466,7 +466,7 @@ var ( // DataDir is where all mutable data is stored (user keys, recorded sessions, // registered SSH servers, etc): - DataDir = "/var/lib/teleport" + DataDir = "/var/db/teleport" // StartRoles is default roles teleport assumes when started via 'start' command StartRoles = []string{RoleProxy, RoleNode, RoleAuthService} diff --git a/security/teleport/files/patch-lib_events_auditlog.go b/security/teleport/files/patch-lib_events_auditlog.go index 5d4bf68432a4..ab0c4e04e7bf 100644 --- a/security/teleport/files/patch-lib_events_auditlog.go +++ b/security/teleport/files/patch-lib_events_auditlog.go @@ -1,11 +1,11 @@ ---- lib/events/auditlog.go.orig 2020-07-08 18:08:40 UTC +--- lib/events/auditlog.go.orig 2022-02-23 04:58:43 UTC +++ lib/events/auditlog.go @@ -45,7 +45,7 @@ import ( const ( // SessionLogsDir is a subdirectory inside the eventlog data dir // where all session-specific logs and streams are stored, like - // in /var/lib/teleport/logs/sessions + // in /var/db/teleport/logs/sessions SessionLogsDir = "sessions" - // PlaybacksDir is a directory for playbacks + // StreamingLogsDir is a subdirectory of sessions /var/lib/teleport/logs/streaming diff --git a/security/teleport/files/patch-lib_events_doc.go b/security/teleport/files/patch-lib_events_doc.go index bc308eaeec0e..570c0aba3879 100644 --- a/security/teleport/files/patch-lib_events_doc.go +++ b/security/teleport/files/patch-lib_events_doc.go @@ -1,110 +1,110 @@ ---- lib/events/doc.go.orig 2020-07-08 18:08:40 UTC +--- lib/events/doc.go.orig 2022-02-23 04:58:43 UTC +++ lib/events/doc.go @@ -85,7 +85,7 @@ Main Audit Log Format The main log files are saved as: - /var/lib/teleport/log//.log + /var/db/teleport/log//.log The log file is rotated every 24 hours. The old files must be cleaned up or archived by an external tool. @@ -111,7 +111,7 @@ Each session has its own session log stored as several Index file contains a list of event files and chunks files associated with a session: - /var/lib/teleport/log/sessions//.index + /var/db/teleport/log/sessions//.index The format of the index file contains of two or more lines with pointers to other files: @@ -120,8 +120,8 @@ The format of the index file contains of two or more l Files: - /var/lib/teleport/log//-.events - /var/lib/teleport/log//-.chunks + /var/db/teleport/log//-.events + /var/db/teleport/log//-.chunks Where: - .events (same events as in the main log, but related to the session) @@ -135,7 +135,7 @@ Examples In the simplest case, single auth server a1 log for a single session id s1 will consist of three files: -/var/lib/teleport/a1/s1.index +/var/db/teleport/a1/s1.index With contents: @@ -146,14 +146,14 @@ This means that all session events are located in s1-0 the first event with index 0 and all chunks are located in file s1-0.chunks file with the byte offset from the start - 0. -File with session events /var/lib/teleport/a1/s1-0.events will contain: +File with session events /var/db/teleport/a1/s1-0.events will contain: {"ei":0,"event":"session.start", ...} {"ei":1,"event":"resize",...} {"ei":2,"ci":0, "event":"print","bytes":40,"offset":0} {"ei":3,"event":"session.end", ...} -File with recorded session /var/lib/teleport/a1/s1-0.chunks will contain 40 bytes +File with recorded session /var/db/teleport/a1/s1-0.chunks will contain 40 bytes emitted by print event with chunk index 0 **Multiple Auth Servers** @@ -164,7 +164,7 @@ In high availability mode scenario, multiple auth serv Any auth server can go down during session and clients will retry the delivery to the other auth server. -Both auth servers have mounted /var/lib/teleport/log as a shared NFS folder. +Both auth servers have mounted /var/db/teleport/log as a shared NFS folder. To make sure that only one auth server writes to a file at a time, each auth server writes to it's own file in a sub folder named @@ -176,37 +176,37 @@ and the second batch of event to the second server a2. Server a1 will produce the following file: -/var/lib/teleport/a1/s1.index +/var/db/teleport/a1/s1.index With contents: {"file_name":"s1-0.events","type":"events","index":0} {"file_name":"s1-0.chunks","type":"chunks","offset":0} -Events file /var/lib/teleport/a1/s1-0.events will contain: +Events file /var/db/teleport/a1/s1-0.events will contain: {"ei":0,"event":"session.start", ...} {"ei":1,"event":"resize",...} {"ei":2,"ci":0, "event":"print","bytes":40,"offset":0} -Events file /var/lib/teleport/a1/s1-0.chunks will contain 40 bytes +Events file /var/db/teleport/a1/s1-0.chunks will contain 40 bytes emitted by print event with chunk index. Server a2 will produce the following file: -/var/lib/teleport/a2/s1.index +/var/db/teleport/a2/s1.index With contents: {"file_name":"s1-3.events","type":"events","index":3} {"file_name":"s1-40.chunks","type":"chunks","offset":40} -Events file /var/lib/teleport/a2/s1-4.events will contain: +Events file /var/db/teleport/a2/s1-4.events will contain: {"ei":3,"ci":1, "event":"print","bytes":15,"ms":713,"offset":40} {"ei":4,"event":"session.end", ...} -Events file /var/lib/teleport/a2/s1-40.chunks will contain 15 bytes emitted +Events file /var/db/teleport/a2/s1-40.chunks will contain 15 bytes emitted by print event with chunk index 1 and comes after delay of 713 milliseconds. Offset 40 indicates that the first chunk stored in the file s1-40.chunks diff --git a/security/teleport/files/patch-lib_services_server.go b/security/teleport/files/patch-lib_services_server.go index f763c90a51db..a93f72ee384f 100644 --- a/security/teleport/files/patch-lib_services_server.go +++ b/security/teleport/files/patch-lib_services_server.go @@ -1,11 +1,11 @@ ---- lib/services/server.go.orig 2020-07-08 18:08:40 UTC +--- lib/services/server.go.orig 2022-02-23 04:58:43 UTC +++ lib/services/server.go -@@ -546,7 +546,7 @@ type CommandLabelV1 struct { +@@ -578,7 +578,7 @@ type CommandLabelV1 struct { // Period is a time between command runs Period time.Duration `json:"period"` // Command is a command to run - Command []string `json:"command"` //["/usr/bin/hostname", "--long"] + Command []string `json:"command"` //["/bin/hostname", "--long"] // Result captures standard output Result string `json:"result"` } diff --git a/security/teleport/files/patch-tool_teleport_common_teleport__test.go b/security/teleport/files/patch-tool_teleport_common_teleport__test.go index d2f64d5757d3..cccc072a243f 100644 --- a/security/teleport/files/patch-tool_teleport_common_teleport__test.go +++ b/security/teleport/files/patch-tool_teleport_common_teleport__test.go @@ -1,20 +1,20 @@ ---- tool/teleport/common/teleport_test.go.orig 2020-07-08 18:08:40 UTC +--- tool/teleport/common/teleport_test.go.orig 2022-02-23 04:58:43 UTC +++ tool/teleport/common/teleport_test.go @@ -62,7 +62,7 @@ func (s *MainTestSuite) SetUpSuite(c *check.C) { // set imprtant defaults to test-mode (non-existing files&locations) defaults.ConfigFilePath = "/tmp/teleport/etc/teleport.yaml" - defaults.DataDir = "/tmp/teleport/var/lib/teleport" + defaults.DataDir = "/tmp/teleport/var/db/teleport" } func (s *MainTestSuite) TestDefault(c *check.C) { @@ -72,7 +72,7 @@ func (s *MainTestSuite) TestDefault(c *check.C) { }) c.Assert(cmd, check.Equals, "start") c.Assert(conf.Hostname, check.Equals, s.hostname) - c.Assert(conf.DataDir, check.Equals, "/tmp/teleport/var/lib/teleport") + c.Assert(conf.DataDir, check.Equals, "/tmp/teleport/var/db/teleport") c.Assert(conf.Auth.Enabled, check.Equals, true) c.Assert(conf.SSH.Enabled, check.Equals, true) c.Assert(conf.Proxy.Enabled, check.Equals, true) diff --git a/security/teleport/files/patch-vendor_github.com_kr_pty_ztypes__freebsd__arm64.go b/security/teleport/files/patch-vendor_github.com_kr_pty_ztypes__freebsd__arm64.go index 1362356deb92..3178f17f721b 100644 --- a/security/teleport/files/patch-vendor_github.com_kr_pty_ztypes__freebsd__arm64.go +++ b/security/teleport/files/patch-vendor_github.com_kr_pty_ztypes__freebsd__arm64.go @@ -1,16 +1,16 @@ ---- vendor/github.com/kr/pty/ztypes_freebsd_arm64.go.orig 2020-07-24 04:36:27 UTC +--- vendor/github.com/kr/pty/ztypes_freebsd_arm64.go.orig 2022-10-14 07:07:07 UTC +++ vendor/github.com/kr/pty/ztypes_freebsd_arm64.go @@ -0,0 +1,13 @@ +// Created by cgo -godefs - DO NOT EDIT +// cgo -godefs types_freebsd.go + +package pty + +const ( + _C_SPECNAMELEN = 0x3f +) + +type fiodgnameArg struct { + Len int32 + Buf *byte +} diff --git a/security/teleport/files/patch-version.mk b/security/teleport/files/patch-version.mk index ee12c2c4fbe7..1457af7a19fc 100644 --- a/security/teleport/files/patch-version.mk +++ b/security/teleport/files/patch-version.mk @@ -1,8 +1,8 @@ ---- version.mk.orig 2020-07-08 18:08:40 UTC +--- version.mk.orig 2022-02-23 04:58:43 UTC +++ version.mk @@ -1,4 +1,4 @@ -GITREF=`git describe --dirty --long --tags` +GITREF=%%GH_TAG_COMMIT%% # $(VERSION_GO) will be written to version.go VERSION_GO="/* DO NOT EDIT THIS FILE. IT IS GENERATED BY 'make setver'*/\n\n\ diff --git a/security/teleport/files/pkg-message.in b/security/teleport/files/pkg-message.in index 2a874bdc7840..f15cd53d3bfc 100644 --- a/security/teleport/files/pkg-message.in +++ b/security/teleport/files/pkg-message.in @@ -1,26 +1,33 @@ [ { type: install message: <