Files
buildroot/package/ntpsec/ntpsec.mk
Peter Seiderer 1caeb632a6 package/ntpsec: security bump version to 1.2.5
Fixes: CVE-2026-18321:
https://nvd.nist.gov/vuln/detail/cve-2026-18321

- bump version to 1.2.5 (for details see [1])
- rebased 0001-wscript-remove-checks-for-bsd-string.h-fixes-host-co.patch
- rebased 0002-disable-PIE-support.patch
- removed 0003-ntpd-refclock_gpsd.c-Add-missing-time.h-for-strptim.patch
  (from upstream [2])
- moved 0004-refclock_gpsd-add-build-fix-for-gcc-14.x.patch to
  0003-refclock_gpsd-add-build-fix-for-gcc-14.x.patch, rebased and enhanced
  as the original conflicts with upstream commit 5505260c ("Fix redefined
  _XOPEN_SOURCE warning in refclock_gpsd.c") [3] and leads to the following
  compile failure:

    ../../ntpd/refclock_gpsd.c:113:21: error: operator ‘<’ has no left operand
      113 |   #if _XOPEN_SOURCE < 700
          |                     ^

[1] https://lists.ntpsec.org/pipermail/devel/2026-July/011029.html
[2] 5137c155d8
[3] 5505260cd1

Signed-off-by: Peter Seiderer <ps.report@gmx.net>
[Julien: mark commit as "security bump"]
Signed-off-by: Julien Olivain <ju.o@free.fr>
2026-09-27 10:23:34 +02:00

92 lines
2.3 KiB
Makefile

################################################################################
#
# ntpsec
#
################################################################################
NTPSEC_VERSION = 1.2.5
NTPSEC_SOURCE = ntpsec-NTPsec_$(subst .,_,$(NTPSEC_VERSION)).tar.bz2
NTPSEC_SITE = https://gitlab.com/NTPsec/ntpsec/-/archive/NTPsec_$(subst .,_,$(NTPSEC_VERSION))
NTPSEC_LICENSE = Apache-2.0, \
Beerware, \
BSD-2-Clause.txt, \
BSD-3-Clause.txt, \
BSD-4-Clause.txt, \
ISC.txt, \
MIT.txt, \
NTP.txt, \
CC-BY-4.0.txt (docs)
NTPSEC_LICENSE_FILES = \
LICENSES/Apache-2.0.txt \
LICENSES/Beerware.txt \
LICENSES/BSD-2-Clause.txt \
LICENSES/BSD-3-Clause.txt \
LICENSES/BSD-4-Clause.txt \
LICENSES/ISC.txt \
LICENSES/MIT.txt \
LICENSES/NTP.txt \
LICENSES/CC-BY-4.0.txt \
docs/copyright.adoc
NTPSEC_CPE_ID_VENDOR = ntpsec
NTPSEC_DEPENDENCIES = \
host-bison \
host-pkgconf \
python3 \
libcap \
openssl
NTPSEC_CONF_ENV = \
CC="$(HOSTCC)" \
CFLAGS="$(HOST_CFLAGS)" \
PYTHON_CONFIG="$(STAGING_DIR)/usr/bin/python3-config"
# CC="$(HOSTCC)" is strange but needed to build some host tools, the
# cross-compiler will properly be used to build target code thanks to
# --cross-compiler
NTPSEC_CONF_OPTS = \
--libdir=/usr/lib/python$(PYTHON3_VERSION_MAJOR)/site-packages/ntp \
--cross-compiler="$(TARGET_CC)" \
--cross-cflags="$(TARGET_CFLAGS) -std=gnu99" \
--cross-ldflags="$(TARGET_LDFLAGS)" \
--notests \
--enable-early-droproot \
--disable-mdns-registration \
--enable-pylib=ffi \
--nopyc \
--nopyo \
--nopycache \
--disable-doc \
--disable-manpage
ifeq ($(BR2_PACKAGE_NTPSEC_CLASSIC_MODE),y)
NTPSEC_CONF_OPTS += --enable-classic-mode
endif
# no '--enable-nts' option available
ifeq ($(BR2_PACKAGE_NTPSEC_NTS),)
NTPSEC_CONF_OPTS += --disable-nts
endif
# refclocks are disabled by default, can only be enabled
ifeq ($(BR2_PACKAGE_NTPSEC_REFCLOCK_ALL),y)
NTPSEC_DEPENDENCIES += pps-tools
NTPSEC_CONF_OPTS += --refclock=all
endif
define NTPSEC_INSTALL_NTPSEC_CONF
$(INSTALL) -m 644 package/ntpsec/ntpd.etc.conf $(TARGET_DIR)/etc/ntp.conf
endef
NTPSEC_POST_INSTALL_TARGET_HOOKS += NTPSEC_INSTALL_NTPSEC_CONF
define NTPSEC_INSTALL_INIT_SYSV
$(INSTALL) -D -m 755 package/ntpsec/S49ntpd $(TARGET_DIR)/etc/init.d/S49ntpd
endef
define NTPSEC_USERS
ntp -1 ntp -1 * - - - ntpd user
endef
$(eval $(waf-package))