40 Commits

Author SHA1 Message Date
boypt
c2568133b5 docs: cover both sshd_config paths in Install RPMs 2026-09-17 14:09:54 +08:00
boypt
1376163c2b docs: nest Use Docker under Build RPMs, add rollback and sshd -t config check 2026-09-17 14:06:45 +08:00
boypt
c31ccb379a docs: simplify Download RPMs, add rollback section 2026-09-17 13:53:15 +08:00
boypt
c4ee83e77e docs: refresh READMEs, fix stale build/output docs, add rollback section 2026-09-17 13:44:33 +08:00
boypt
cbc4df8b79 fix: harden distro detection fallback 2026-08-26 11:24:48 +08:00
boypt
3efa0bc606 fix: drop redundant EL5 dist define 2026-08-26 11:11:02 +08:00
boypt
754acf8bb6 fix: define EL5 dist macro 2026-08-26 10:50:17 +08:00
boypt
a8dec15f45 fix: restore EL5 distro detection 2026-08-26 10:35:48 +08:00
boypt
db84b53e9e version bump: 10.5p1/openssl 3.5.8 2026-08-26 10:21:01 +08:00
boypt
5235c2cf1d docs: trim el5/el6/el7 READMEs to per-dir specifics
Drop stale hardcoded versions (point to version.env) and content already
covered by the root README; fix el7 socket-activation wording, document
the openssh.initv.spec variant and SPECFILE switch.
2026-08-24 14:14:30 +08:00
boypt
370f4310df refactor: drop .keep placeholder files in favor of explicit mkdir
BUILD_RPM now creates the rpmbuild _topdir subdirs (BUILD/RPMS/SRPMS/
SOURCES/SPECS) itself, so the 11 tracked .keep placeholders (downloads,
output, el*/{BUILD,RPMS,SRPMS}) are no longer needed; output/ and
downloads/ were already created by compile.sh/pullsrc.sh.
2026-08-24 14:07:09 +08:00
boypt
a3be02a209 refactor: flatten GUESS_DIST -> TOPDIR_SELECT call chain
TOPDIR_SELECT now assigns rpmtopdir from GUESS_DIST directly and uses a
single -d guard instead of a 4-branch identity-mapping case; the el5/el6
WITH_OPENSSL=2 default is dropped (BUILD_RPM already falls back to 2),
keeping only the el7 system-openssl auto-detection. Main flow collapses
case fallthrough + manual-dir + trailing checks into one dispatch case.
2026-08-24 14:00:11 +08:00
boypt
e9a25bd29a refactor: simplify GUESS_DIST to generic el5/el6/el7 mapping
Drop per-distro special cases (Anolis an7/an8, UOS uel*) in favor of a
generic rule: only el5/el6 keep dedicated spec dirs, everything else
maps to el7. Collapse the redundant glibc fallback chain into default
branches.
2026-08-24 13:49:24 +08:00
boypt
568202d282 refactor: remove GH_PROXY mechanism 2026-08-22 00:12:13 +08:00
boypt
a33c6b5efe docs(docker): document repos must be rewritten before any dnf operation in modify_el8 2026-08-21 17:59:25 +08:00
boypt
ff80eac7f7 refactor(docker): rewrite_baseurls comments out original line and appends own baseurl 2026-08-21 16:47:00 +08:00
boypt
cabaf74682 fix(docker): match '# baseurl=' with space in rewrite_baseurls for el6 sclo 2026-08-21 16:29:56 +08:00
boypt
af284228a1 fix(docker): drop archives.fedoraproject.org from EPEL to avoid el5 https redirect 2026-08-21 16:24:20 +08:00
boypt
aa02c16f46 fix: use single-line baseurl list for DNF 4.x compatibility
DNF 4.x baseurl is list type (space-separated on one line per
dnf.readthedocs.io); repeated baseurl= keys overwrite and only the
last survives. Rewrite join_baseurls and add rewrite_baseurls helper
to emit single baseurl= line with space-separated mirrors while
preserving remainder after prefix (fixes multi-line sed truncation).
Keep official-first ordering for GitHub CI. Also quote ELDIR in
docker_compile.sh to pass shellcheck.
2026-08-21 16:10:27 +08:00
boypt
f85590a72e refactor(docker): rename to modify_vault/live_source and unify to bash
- git mv modify_yum_source.sh -> modify_vault_source.sh (vault: EL5/6/7/8)
- git mv modify_dnf_source.pl -> modify_live_source.sh and rewrite perl
  logic in bash (LIVE_MIRRORS array official-first: mirror.stream.centos.org,
  mirrors.kernel.org/centos, aliyun/ustc/iij/yandex; bash -n clean)
- update Dockerfile.centos/centos5 to call modify_vault_source.sh
- update Dockerfile.centos-stream EL8 to call modify_vault_source.sh and
  EL9 to call modify_live_source.sh via bash (drop perl dep for Stream 9)
- AGENTS.md: update vault script reference
2026-08-21 14:01:21 +08:00
boypt
4dbb7babec docs(docker): add live-source official mirrors and clarify vault/live scope
- modify_dnf_source.pl: prioritize official live mirrors
  https://mirror.stream.centos.org and https://mirrors.kernel.org/centos
  before aliyun/ustc/iij/yandex; add header comment that live handling is
  for still-supported Stream EL and vault handling lives in
  modify_yum_source.sh
2026-08-21 13:52:00 +08:00
boypt
67dbf9ae04 refactor(docker): reorganize vault mirrors to top arrays, merge shared vault/epel
- move EL8 vault sed from Dockerfile.centos-stream into modify_yum_source.sh:modify_el8()
  and simplify Dockerfile EL8 branch to bash ./docker/modify_yum_source.sh
- extract hardcoded one-line baseurl strings into top-level arrays for easy maintenance:
  VAULT (official-first HTTPS shared by el7/altarch/8-stream; yandex excluded),
  VAULT_HTTP (plain HTTP for el5/6), EPEL (merged EPEL_EL7+EPEL_HTTP)
- merge VAULT_EL7+VAULT_EL8 (verified 5/5 cross-available, domestic not prioritized for CI)
  and EPEL_EL7+EPEL_HTTP (both http); de-duplicate aliyun
- reprioritize VAULT official-first: vault.centos.org -> archive.kernel.org -> aliyun/iij
  (yandex excluded from VAULT, kept only in VAULT_HTTP/EPEL)
- rewrite VAULT/VAULT_HTTP header comments with selection rationale
2026-08-21 13:38:57 +08:00
boypt
88a11ca9ca docs: fix markdown table separator (use ---- not ====) 2026-08-21 12:13:10 +08:00
boypt
7ae3bb4d1e docs: align UOS20 to EL8 image and map Recommended RPMs to CI artifacts
- README.md table: replace meaningless aarch64_el7/8/9 tags with actual CI
  artifacts (rpm-el5-x86_64/i686, rpm-el6-x86_64, rpm-el7/8/9-*,
  rpm-uos20-*), fuzzy version via artifact name; fix UOS20 row from
  aarch64_el7 to rpm-uos20-*
- README.md: UOS20=1 ./compile.sh el7 -> el8 (spec remains el7 via
  GUESS_DIST), anchor #uos-20-variant-el7-family -> #uos-20-variant-el8
- docker/README.md: UOS 20 Variant (EL7-family) -> (EL8), reuse EL7
  image / Dockerfile.centos:7 -> reuse EL8 image via
  Dockerfile.centos-stream:8 (with GUESS_DIST note), uos20- -> uos20.,
  build-args table EL7 -> EL8
2026-08-21 12:09:34 +08:00
boypt
ad677a79a3 docs(docker): translate Chinese note to English for consistency
- Standalone Dockerfiles for Amazon Linux / openEuler / Rocky Linux have been
  consolidated into the generic EL images (reusing EL8/EL9 via glibc
  compatibility) and are no longer maintained separately.
2026-08-21 11:31:03 +08:00
boypt
234a5acf00 fix(docker): correct 8-stream vault baseurl to avoid duplication
- revert EL8 sed to use vault roots without /8-stream suffix:
  https://mirrors.aliyun.com/centos-vault
  https://ftp.iij.ad.jp/pub/linux/centos-vault
  https://ftp.yandex.ru/centos/centos
  (previously included /8-stream causing 8-stream/8-stream duplication
   since repo file retains /$releasever suffix; vault.centos.org logic
   confirmed single vault root works)
- fixes buildx failure in 32441214302 (el8 sed exit 1)
2026-08-21 10:52:50 +08:00
boypt
e062237c5c fix(docker): use verified vault/stream mirrors for 8/9-stream
- 8-stream (EOL): switch from single vault.centos.org to 3 verified vault mirrors
  https://mirrors.aliyun.com/centos-vault/8-stream/
  https://ftp.iij.ad.jp/pub/linux/centos-vault/8-stream/
  https://ftp.yandex.ru/centos/centos/8-stream/ (dual-path validated)
  via multi-baseurl sed in Dockerfile.centos-stream EL8 branch
- 9-stream: update modify_dnf_source.pl @mirrors to 4 verified stream mirrors
  (mirrors.aliyun, mirrors.ustc, ftp.iij, ftp.yandex /centos-stream)
  drop vault.centos.org (404 for active 9-stream, verified via HEAD)
- verified repodata (BaseOS/$basearch/os/repodata/repomd.xml) on both arches
2026-08-21 10:49:44 +08:00
boypt
464f44b1ed refactor(docker): remove MIRROR branching, use multi-baseurl failover
- drop ARG MIRROR / MIRROR_HOLDER sed injection across all Dockerfiles
- modify_yum_source.sh: EL5/6 use 4x HTTP centos-vault + 5x HTTP epel
  (ftp.iij, mirrors.aliyun, ftp.yandex, ftp.pasteur / sindad, debian.sbor)
  to avoid TLS/302 on Python2.4; EL7 keep 2x HTTPS vault + 2x epel
- modify_dnf_source.pl: replace single mirror holder with @mirrors array
  (vault.centos.org, mirrors.ustc, mirrors.aliyun) emitting multi baseurl
- Dockerfile.centos-stream: EL9 now unconditional perl, EL8 vault direct
- workflows/README: drop MIRROR docs and build-args
- shfmt fix docker_compile.sh (tabs)
2026-08-21 10:12:41 +08:00
boypt
e1da586e03 docs: update README/AGENTS for aarch64 support
- README: expand supported distro table to 4 cols with Arch (x86_64/aarch64) and per-arch tags aarch64_el7/8/9, add altarch note
- AGENTS: add Supported architectures (per-arch tags) and altarch vault handling, expand CI matrix details for build-images (5+3) and build-rpm (arm64@ubuntu-24.04-arm)
2026-08-20 17:28:34 +08:00
boypt
9e54e5d205 style: shfmt docker/modify_yum_source.sh (tabs) 2026-08-20 16:50:07 +08:00
boypt
c52b9968ed fix(docker): handle el7 aarch64 altarch baseurl and make epel sed robust 2026-08-20 16:42:48 +08:00
boypt
116e7ec791 fix(docker): use HTTP aliyun EPEL for el5 to avoid Python2.4 HTTPS redirect (302) 2026-08-20 16:38:52 +08:00
boypt
f961f49444 fix(pullsrc): download perl for DOCKERBUILD without GETEL check (fix el5 lstat) 2026-08-20 16:27:46 +08:00
boypt
d551b20885 ci: remove redundant Replace Mirror URL steps, keep source intact 2026-08-20 16:19:35 +08:00
boypt
f82afb75b3 fix(ci): correct Replace Mirror URL regex to avoid Dockerfile truncation 2026-08-20 16:17:27 +08:00
boypt
1a6c26eeba refactor(docker): simplify images, move el8 to centos-stream, isolate el5, fix altarch/metalink 2026-08-20 16:09:50 +08:00
boypt
43ff05ed49 fix: ignore dot files 2026-08-16 11:24:29 +08:00
boypt
cbb519644d lint: add shellcheck/shfmt rules to AGENTS.md, format compile.sh and pullsrc.sh 2026-08-16 11:21:01 +08:00
boypt
277ccf7ec4 cleanup: remove deprecated --with-md5-passwords, --with-smartcard, --with-systemd, and fix kerberos5 in initv spec 2026-08-16 10:59:00 +08:00
boypt
385c677425 config: add .opencode/opencode.json for edit/bash/external_directory permissions
Allow editing version.env without confirmation, allow /tmp external
directory access, and default bash commands to ask.
2026-08-11 15:42:00 +08:00
37 changed files with 738 additions and 774 deletions

View File

@@ -19,27 +19,22 @@ jobs:
- tag_suffix: el5
dockerfile: ./docker/Dockerfile.centos5
build_args: |
MIRROR=0
- tag_suffix: el6
dockerfile: ./docker/Dockerfile.centos
build_args: |
VERSION_NUM=6
MIRROR=0
- tag_suffix: el7
dockerfile: ./docker/Dockerfile.centos
build_args: |
VERSION_NUM=7
MIRROR=0
- tag_suffix: el8
dockerfile: ./docker/Dockerfile.centos
dockerfile: ./docker/Dockerfile.centos-stream
build_args: |
VERSION_NUM=8
MIRROR=0
- tag_suffix: el9
dockerfile: ./docker/Dockerfile.centos-stream
build_args: |
VERSION_NUM=9
MIRROR=0
steps:
- name: Checkout repository
@@ -53,10 +48,6 @@ jobs:
run: |
env DOCKERBUILD=1 ./pullsrc.sh
- name: Replace Mirror URL
run: |
sed -i 's|mirrors.\+\.cn|mirror.centos.org|g' ./docker/*
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v4
@@ -90,17 +81,14 @@ jobs:
dockerfile: ./docker/Dockerfile.centos
build_args: |
VERSION_NUM=7
MIRROR=0
- tag_suffix: aarch64_el8
dockerfile: ./docker/Dockerfile.centos-stream
build_args: |
VERSION_NUM=8
MIRROR=0
- tag_suffix: aarch64_el9
dockerfile: ./docker/Dockerfile.centos-stream
build_args: |
VERSION_NUM=9
MIRROR=0
steps:
- name: Checkout repository
@@ -109,10 +97,6 @@ jobs:
fetch-depth: 0
persist-credentials: false
- name: Replace Mirror URL
run: |
sed -i 's|mirrors.\+\.cn|mirror.centos.org|g' ./docker/*
- name: Set up QEMU
uses: docker/setup-qemu-action@v4

1
.gitignore vendored
View File

@@ -1,5 +1,6 @@
BUILD/
output/
.*
*-local*
*.orig
*.swp

View File

@@ -17,23 +17,22 @@ Shell scripts to backport and build OpenSSH RPMs for CentOS/RHEL-like distros (E
./compile.sh el7
# Docker-based build (see docker/README.md for per-version commands)
docker build -t elssh:el8 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=8 --build-arg MIRROR=0 .
docker build -t elssh:el8 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=8 .
docker run --rm -v .:/data elssh:el8
```
## Configuration
- `version.env` — source versions (OpenSSH, OpenSSL, Perl). Committed.
- `version-local.env` — user overrides like `PKGREL`, `WITH_OPENSSL`, `GH_PROXY`. Gitignored (`*-local*`).
- `version-local.env` — user overrides like `PKGREL`, `WITH_OPENSSL`. Gitignored (`*-local*`).
- `compile.sh` sources `version.env` then `version-local.env` (if present), so `version-local.env` wins.
## Key variables
- `WITH_OPENSSL`: `0` = no OpenSSL (no ssh-rsa keys), `1` = system OpenSSL, `2` = static OpenSSL (default for EL5/6/7, EL8 defaults to `1`)
- `WITH_OPENSSL`: `0` = no OpenSSL (no ssh-rsa keys), `1` = system OpenSSL, `2` = static OpenSSL. Only the `el7` spec dir (covering EL7/8/9) auto-detects in `compile.sh` TOPDIR_SELECT: system OpenSSL >= 3 -> `1`, else `2`. EL5/EL6 leave it unset and rpmbuild falls back to `2` via `${WITH_OPENSSL:-2}`. Note `docker/docker_compile.sh` has its own overlapping auto-detect (checks openssl-devel presence + version), so behavior inside Docker may differ from a direct `./compile.sh` run.
- `PKGREL`: package release number (defaults to `1`)
- `M32=1`: build 32-bit RPMs (EL5 only)
- `DOCKERBUILD=1`: when set, `pullsrc.sh` skips downloading (assumes Docker image has the sources)
- `GH_PROXY`: GitHub proxy URL for Chinese users (e.g. `https://gh-proxy.com/`)
- `DOCKERBUILD=1`: when set, `pullsrc.sh` skips the openssh/openssl/askpass downloads but still fetches PERLSRC
- `UOS20=1`: build the UOS 20 variant — enables the kernel-panic patch (`openssh-uos20-kernel-panic-fix.patch`) and prefixes `PKGREL` with `uos20.` so resulting RPMs are distinguishable.
## Architecture notes
@@ -41,44 +40,69 @@ docker run --rm -v .:/data elssh:el8
- **EL8 and EL9 both use `el7/`** as the spec directory, since they share systemd. `compile.sh` GUESS_DIST returns `el7` for all versions >= EL7.
- EL6 uses `el6/` (SysVinit).
- EL5 uses `el5/` (SysVinit, requires Perl bootstrap for building OpenSSL).
- **Supported architectures**: `x86_64` for all EL versions; `aarch64` for EL7/8/9 and UOS20 via per-arch tags (`aarch64_el7`, `aarch64_el8`, `aarch64_el9`). Docker tags are per-arch (e.g. `ghcr.io/boypt/openssh-rpms:aarch64_el7`), not multi-arch manifests.
- `WITH_OPENSSL` auto-detection: for `el7` (which covers EL7/8/9), if system OpenSSL >= 3, defaults to `1` (system), otherwise `2` (static).
- `compile.sh` has subcommands: `GETEL` (print detected distro), `GETRPM` (list RPM paths), `RPMDIR` (print RPM output dir).
- `el7/SPECS/` has two spec files: `openssh.spec` (default, systemd) and `openssh.initv.spec` (SysVinit). The default spec is selected via `SPECFILE` env var. The UOS 20 build uses the default spec with `UOS20=1`.
- `docker/docker_compile.sh` is the entrypoint inside Docker images — it copies the appropriate `el*` dir to `/BUILD` and runs `compile.sh` against it.
- `docker/modify_vault_source.sh` handles vault mirrors; for `aarch64` it appends `/altarch` (CentOS AltArch vault, e.g. `.../centos-vault/altarch/7.9.2009/`). For EL5 `EPEL` always uses `http://mirrors.aliyun.com/epel-archive` (avoids Python 2.4 TLS 1.0 → 302 → https failure on `archives.fedoraproject.org`).
## CI
- `.github/workflows/build-images.yml` — manually triggered (`workflow_dispatch`), builds Docker images for each EL version and pushes to `ghcr.io`.
- `.github/workflows/build-rpm.yml` — runs on `v*` tags, builds RPMs inside Docker containers and creates a GitHub release.
- `.github/workflows/build-images.yml` — manually triggered (`workflow_dispatch`), builds Docker images and pushes to `ghcr.io`. Matrix: `build-amd64` (5 images: `el5`, `el6`, `el7`, `el8`, `el9` on `ubuntu-latest`) + `build-arm64` (3 images: `aarch64_el7`, `aarch64_el8`, `aarch64_el9` on `ubuntu-latest` with `setup-qemu-action` + `platforms: linux/arm64`). Cache: `type=gha`.
- `.github/workflows/build-rpm.yml` — runs on `v*` tags, builds RPMs inside Docker containers and creates a GitHub release. Jobs: `build-arm64` (`ubuntu-24.04-arm`, natively runs `aarch64_*` images), `build-amd64` (`ubuntu-latest`), `build-el5` (`ubuntu-latest`, handles `m32` for i686). Final `release` needs all three and zips artifacts as `openssh_<tag>_<artifact>.zip`.
## Linting & formatting
All shell scripts (`*.sh`) must pass `shellcheck` and `shfmt` before committing:
```bash
# Lint (warnings are errors)
shellcheck -S warning compile.sh pullsrc.sh
# Format check (must produce no diff)
shfmt -d -i 0 -bn -ci compile.sh pullsrc.sh
# Auto-fix formatting in-place
shfmt -w -i 0 -bn -ci compile.sh pullsrc.sh
```
- **shellcheck** `-S warning`: treat warnings as failures; informational/style notes may be suppressed inline with `# shellcheck disable=SCxxxx`.
- **shfmt** `-i 0 -bn -ci`: tabs for indentation (no extra indent), binary operators (`&&`, `||`, `|`) at start of next line, case body indented.
- Both tools must exit 0 before any commit touching `*.sh` files.
## Gitignore
`*-local*` is gitignored — version-local.env, editor swap files, etc. `*.tar.gz` is gitignored everywhere, including `downloads/`. Generated RPMs go to `output/` (also gitignored).
## Release workflow
## Version bump workflow
When a new upstream OpenSSH version is available:
When the user says "update to &lt;version&gt;" (e.g. "update to 10.5", "update to 10.6p1"), perform the following steps autonomously. Only update `README.md` and `version.env` — do not touch other files unless explicitly asked.
```bash
# 1. Check latest version
./pullsrc.sh --latest
1. **Normalize the version**: append `p1` if not already present (all portable releases use `p1`). E.g. `10.5``10.5p1`.
# 2. Update version.env: OPENSSHSRC and OPENSSHVER
# Update README.md: "Current Version" section
2. **Update `version.env`**: change the `OPENSSHSRC` line to `openssh-<version>.tar.gz`. `OPENSSHVER` is derived automatically from `OPENSSHSRC`. Do NOT change `OPENSSLSRC`/`OPENSSLVER` or any other line unless the user explicitly asks.
# 3. Determine build number for this version
TAG_PREFIX="v${NEW_VERSION}_b"
BUILD_NUM=$(git tag | grep "^${TAG_PREFIX}" | sed "s/^${TAG_PREFIX}//" | sort -n | tail -1)
BUILD_NUM=$(( ${BUILD_NUM:-0} + 1 ))
3. **Update `README.md`**: in the "Current Version" section, update only the OpenSSH version line. Leave the OpenSSL line unchanged.
# 4. Commit and tag
git add version.env README.md
git commit -m "bump: OpenSSH ${NEW_VERSION}_b${BUILD_NUM}"
git tag "v${NEW_VERSION}_b${BUILD_NUM}"
4. **Determine the next build number**:
```bash
TAG_PREFIX="v${NEW_VERSION}_b"
BUILD_NUM=$(git tag | grep "^${TAG_PREFIX}" | sed "s/^${TAG_PREFIX}//" | sort -n | tail -1)
BUILD_NUM=$(( ${BUILD_NUM:-0} + 1 ))
```
# 5. Push
git push origin main
git push origin "v${NEW_VERSION}_b${BUILD_NUM}"
```
5. **Commit and tag** (do not push yet):
```bash
git add version.env README.md
git commit -m "bump: OpenSSH ${NEW_VERSION}_b${BUILD_NUM}"
git tag "v${NEW_VERSION}_b${BUILD_NUM}"
```
Pushing the tag triggers `.github/workflows/build-rpm.yml` which builds RPMs for all EL versions and creates a GitHub release.
6. **Ask the user for confirmation to push** to remote. This is the only confirmation needed — do not ask about file changes, commit message, tag name, or anything else.
7. **After pushing**, the tag triggers `.github/workflows/build-rpm.yml` which builds RPMs for all EL versions and creates a GitHub release. Monitor CI using `gh` commands and report the status:
```bash
gh run list --limit 5
gh run watch # watch the latest run to completion
```

155
README.md
View File

@@ -6,32 +6,39 @@ Similar Project: [Backport OpenSSH for Debian / Ubuntu distros](https://github.c
## Supported (tested) Distro:
| Distro | Version | Recommanded EL RPMs |
|----------------|----------------|-----------------------------|
| CentOS | 5 | EL 5 |
| CentOS | 6 | EL 6 |
| CentOS | 7 | EL 7 |
| CentOS | 8 | EL 8 |
| CentOS Stream | 8 | EL 8 |
| CentOS Stream | 9 | EL 9 |
| Rocky Linux | 8 | EL 8 |
| Rocky Linux | 9 | EL 9 |
| Amazon Linux | 1 | EL 6 |
| Amazon Linux | 2 | EL 7 |
| Amazon Linux | 2023 | EL 9 |
| UnionTech UOS | V20 | **UOS20** |
| openEuler | 20.03 | EL 8 |
| openEuler | 22.03 | EL 8 |
| openEuler | 24.03 | EL 9 |
| AnolisOS | 7 | EL 7 |
| AnolisOS | 8 | EL 8 |
| AnolisOS | 2023 | EL 9 |
| Distro | Version | Arch | Recommended EL RPMs |
|----------------|----------------|---------------------|----------------------------------------------------------------------|
| CentOS | 5 | x86_64 / i686 | EL 5 (`rpm-el5-x86_64`, `rpm-el5-i686`) |
| CentOS | 6 | x86_64 | EL 6 (`rpm-el6-x86_64`) |
| CentOS | 7 | x86_64 / aarch64 | EL 7 (`rpm-el7-x86_64`, `rpm-el7-aarch64`) |
| CentOS | 8 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| CentOS Stream | 8 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| CentOS Stream | 9 | x86_64 / aarch64 | EL 9 (`rpm-el9-x86_64`, `rpm-el9-aarch64`) |
| Rocky Linux | 8 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| Rocky Linux | 9 | x86_64 / aarch64 | EL 9 (`rpm-el9-x86_64`, `rpm-el9-aarch64`) |
| AlmaLinux | 8 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| AlmaLinux | 9 | x86_64 / aarch64 | EL 9 (`rpm-el9-x86_64`, `rpm-el9-aarch64`) |
| Oracle Linux | 7 | x86_64 / aarch64 | EL 7 (`rpm-el7-x86_64`, `rpm-el7-aarch64`) |
| Oracle Linux | 8 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| Oracle Linux | 9 | x86_64 / aarch64 | EL 9 (`rpm-el9-x86_64`, `rpm-el9-aarch64`) |
| Amazon Linux | 1 | x86_64 | EL 6 (`rpm-el6-x86_64`) |
| Amazon Linux | 2 | x86_64 / aarch64 | EL 7 (`rpm-el7-x86_64`, `rpm-el7-aarch64`) |
| Amazon Linux | 2023 | x86_64 / aarch64 | EL 9 (`rpm-el9-x86_64`, `rpm-el9-aarch64`) |
| UnionTech UOS | V20 | x86_64 / aarch64 | **UOS20** (`rpm-uos20-x86_64`, `rpm-uos20-aarch64`) |
| openEuler | 20.03 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| openEuler | 22.03 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| openEuler | 24.03 | x86_64 / aarch64 | EL 9 (`rpm-el9-x86_64`, `rpm-el9-aarch64`) |
| AnolisOS | 7 | x86_64 / aarch64 | EL 7 (`rpm-el7-x86_64`, `rpm-el7-aarch64`) |
| AnolisOS | 8 | x86_64 / aarch64 | EL 8 (`rpm-el8-x86_64`, `rpm-el8-aarch64`) |
| AnolisOS | 2023 | x86_64 / aarch64 | EL 9 (`rpm-el9-x86_64`, `rpm-el9-aarch64`) |
> `aarch64` RPMs are built from the same `el7/` spec via `aarch64_el7/8/9` Docker tags (`ghcr.io/boypt/openssh-rpms:aarch64_el7` etc., QEMU-built, per-arch tags — not multi-arch manifests).
## Project Structure
- `pullsrc.sh`: Script to download source packages.
- `compile.sh`: Script to build RPMs.
- `version.env`: config file for variables (versions, release number, OPENSSL MODE, proxy ...)
- `version.env`: config file for variables (versions, release number, OPENSSL MODE ...)
The directory (`el5`, `el6`, `el7`) serve as functional templates for different environment types. The `openssh.spec` are modified based on the shipped spec file from OpenSSH project.
@@ -44,7 +51,7 @@ The directory (`el5`, `el6`, `el7`) serve as functional templates for different
## Current Version:
- OpenSSH 10.5p1 (see: [OpenSSH Official](https://www.openssh.com/))
- OpenSSL 3.5.7 (see: [OpenSSL Official](https://openssl-library.org/source/))
- OpenSSL 3.5.8 (see: [OpenSSL Official](https://openssl-library.org/source/))
The build script reads `version.env` for version definitions.
@@ -62,28 +69,31 @@ yum install -y systemd-devel
yum install -y gcc44
```
`libXt-devel`, `libX11-devel` and `gtk2-devel` are only relevant to the EL6/EL7-era askpass subpackages — the EL8+ spec skips them (`compile.sh` passes `no_gtk2` / `skip_gnome_askpass` / `skip_x11_askpass = 1`) and the centos-stream Dockerfile doesn't install them.
## Usage
### Download RPMs
You can download the needed RPMs from the GitHub Release using the GitHub
API. The script below auto-detects your architecture and EL version from
the running system, then fetches the matching asset from the latest
release.
Go to the [Releases page](https://github.com/boypt/openssh-rpms/releases)
and download the zip file that matches your system. No script or GitHub
API needed.
Each release provides one zip per tag, named like:
```
openssh_<version>_<tag>.zip
```
e.g. `openssh_v10.5p1_b1_rpm-el8-x86_64.zip`.
1. Find your distro in the "Supported (tested) Distro" table above, and
note the tag in the "Recommended EL RPMs" column (e.g. `rpm-el8-x86_64`).
2. Download the zip whose name ends with that tag.
3. Unzip it and install:
```bash
ARCH=$(uname -m)
# Read the system's own rpm dist tag (.el8 -> el8, .el7 -> el7, ...).
# Override for non-elN dists (e.g. UOS 20) or when auto-detect fails.
# If unsure which EL value to use, see the "Supported (tested) Distro"
# table at the top of this README.
EL=$(rpm --eval '%{?dist}' 2>/dev/null | grep -oE 'el[0-9]+' | head -1)
[[ -z "$EL" ]] && EL=el7
curl -s https://api.github.com/repos/boypt/openssh-rpms/releases/latest \
| jq -r --arg el "$EL" --arg arch "$ARCH" \
'.assets[] | select(.name | ascii_downcase | contains($el) and contains($arch)) | .browser_download_url' \
| wget -i - --show-progress -c
unzip openssh*.zip
```
### Build RPMs
@@ -103,6 +113,10 @@ Note: It is unnecessary to build on each system, as most RPM-based Linux distrib
```
5. The generated RPM files will be copied to the `output` directory.
#### Use Docker
For more details, see [docker/README.md](docker/README.md)
### Install RPMs
```bash
@@ -110,25 +124,37 @@ ls output
# you will find multiple RPM files in this directory.
# you may copy them to other machines, and continue following steps there.
# Backup current SSH config
# Backup current SSH config by moving it away — the new package then
# lays down a fresh stock config, which also avoids breakage from old
# directives (notably the GSSAPI* series) removed upstream.
[[ -f /etc/ssh/sshd_config ]] && mv /etc/ssh/sshd_config /etc/ssh/sshd_config.$(date +%Y%m%d)
# Install rpm packages.
# Install rpm packages (`dnf` works the same on EL8/EL9).
sudo yum --disablerepo=* localinstall -y ./openssh*.rpm
# Check Installed version:
ssh -V && /usr/sbin/sshd -V
# If you skipped the backup step above, rpm kept your old config and
# saved the package defaults as sshd_config.rpmnew (the spec marks it
# %config(noreplace)). An old config can keep the new sshd from
# starting, so test it — on failure either fix the offending
# directives, or swap in the .rpmnew defaults, then re-test until it
# passes silently:
ls /etc/ssh/sshd_config.rpmnew
sudo /usr/sbin/sshd -t -f /etc/ssh/sshd_config || sudo mv /etc/ssh/sshd_config{.rpmnew,}
sudo /usr/sbin/sshd -t -f /etc/ssh/sshd_config
# Restart service
sudo service sshd restart
sudo systemctl restart sshd # (`service sshd restart` also works)
# Test a new ssh connection
ssh localhost
```
**DO NOT DISCONNECET** current ssh shell yet, open a **NEW** shell and login to you machine to verify that sshd is working properly.
**DO NOT DISCONNECT** current ssh shell yet, open a **NEW** shell and login to you machine to verify that sshd is working properly.
#### Trouble shooting
#### Troubleshooting
You may get complains during the `yum localinstall` process. It's mostly because some subpackages depend on the main openssh package, upgrading only the main package won't fit in their dependencies.
@@ -144,9 +170,42 @@ If still not satisfied, you may try the final weapon: FORCED INSTALL.
rpm -ivh --force --nodeps --replacepkgs --replacefiles openssh-*.rpm
```
## Use Docker
### Rollback to distro stock OpenSSH
For more details, see [docker/README.md](docker/README.md)
If the custom build doesn't work for you, remove it and reinstall the
version shipped by your distro. Keep your current SSH session open until
the rollback is verified.
```bash
# 1. Downgrade back to the distro's own versions in one yum transaction.
# (Single yum transaction -> dependencies are handled properly and there
# is no "RPMDB altered outside of yum" warning afterwards. If you
# installed extra subpackages, list them here too.)
sudo yum downgrade openssh openssh-clients openssh-server
# On EL8/EL9, `dnf` works the same.
# Fallback if downgrade is unavailable: erase first, then reinstall
# from the distro repos (re-enable the repos if you disabled them).
sudo rpm -e --nodeps openssh openssh-clients openssh-server
sudo yum install -y openssh openssh-clients openssh-server
# 2. Restart and verify
sudo systemctl restart sshd # EL7 and above (systemd)
# sudo service sshd restart # EL5/EL6 (SysVinit)
ssh -V && /usr/sbin/sshd -V
ssh localhost
```
Notes:
- The default build bundles OpenSSL statically (`WITH_OPENSSL=2`), so
the system OpenSSL is untouched — only the `openssh` packages need
rolling back.
- If the downgrade/install step can't find the packages, your base repos may be disabled or
(on EOL releases like EL5/EL6) moved to vault — fix the repo config
first.
- Same rule as install: **DO NOT** close your current shell, open a
**NEW** shell to verify that login works before disconnecting.
## Other Notes
@@ -171,17 +230,17 @@ which closes the target fd before each `dup2()` in `sshd.c`), set
`UOS20=1`:
```bash
UOS20=1 ./compile.sh el7
UOS20=1 ./compile.sh el8
```
The flag also prefixes `PKGREL` with `uos20.` so the resulting RPMs are distinguishable from the standard build (e.g. PKGREL `1` becomes `uos20.1`, producing `openssh-XXXXX-uos20.1.el7.x86_64.rpm`). The patch is only
applied when the `uos20` macro is set, so ordinary EL7/8/9 builds are
unaffected. For the Docker-based build, see
[docker/README.md](docker/README.md#uos-20-variant-el7-family).
[docker/README.md](docker/README.md#uos-20-variant-el8).
### Install on uniontech UOS 20
UOS's `openssh-help` subpackage has files that confilict with the package. It's must be removed before installing the compiled RPMs:
UOS's `openssh-help` subpackage has files that conflict with the package. It's must be removed before installing the compiled RPMs:
```bash
sudo rpm --nodeps -e openssh-help

View File

@@ -11,7 +11,7 @@ trap 'echo -e "Aborted, error $? in command: $BASH_COMMAND"; trap ERR; exit 1' E
# Set magic variables for current file & dir
__dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
__file="${__dir}/$(basename "${BASH_SOURCE[0]}")"
__base="$(basename ${__file} .sh)"
__base="$(basename "${__file}" .sh)"
__root="$(cd "$(dirname "${__dir}")" && pwd)" # <-- change this as it depends on your app
arg1="${1:-}"
@@ -24,200 +24,187 @@ rpmtopdir=
# 2: build openssl statically
CHECKEXISTS() {
if [[ ! -f $__dir/downloads/$1 ]];then
echo "$1 not found, run 'pullsrc.sh', or manually put it in the downloads dir."
exit 1
fi
if [[ ! -f $__dir/downloads/$1 ]]; then
echo "$1 not found, run 'pullsrc.sh', or manually put it in the downloads dir."
exit 1
fi
}
GUESS_DIST() {
# will not work if rpm cmd not exists
if ! type -p rpm > /dev/null;then
echo 'unknown' && return 0
fi
# will not work if rpm cmd not exists
if ! type -p rpm >/dev/null; then
echo 'unknown'
return 0
fi
local dist=$(rpm --eval '%{?dist}' | tr -d '.')
local dist
if ! dist=$(rpm --eval '%{?dist}' 2>/dev/null); then
dist=
fi
dist=${dist//./}
# fallback to el7
[[ $dist == "el9" ]] && dist="el7"
[[ $dist == "el8" ]] && dist="el7"
[[ $dist == "an8" ]] && dist="el7" # Anolis 8
[[ $dist == "an7" ]] && dist="el7" # Anolis 7
[[ $dist == uel* ]] && dist="el7" # UOS20+
# Only el5/el6 have dedicated spec dirs; EL7+ (incl. EL-like rebuilds)
# all share the el7 systemd layout.
case $dist in
el5) echo 'el5' && return 0 ;;
el6) echo 'el6' && return 0 ;;
el*) echo 'el7' && return 0 ;;
esac
[[ -n $dist ]] && echo $dist && return 0
local glibcver=$(ldd --version | head -n1 | grep -Eo '[0-9]+' | tr -d '\n')
# centos 5 uses glibc 2.5
[[ $glibcver -eq 25 ]] && echo 'el5' && return 0
# centos 6 uses glibc 2.12
[[ $glibcver -eq 212 ]] && echo 'el6' && return 0
# centos 7 uses glibc 2.17
[[ $glibcver -eq 217 ]] && echo 'el7' && return 0
# centos 8 uses glibc 2.28, also map to el7
[[ $glibcver -eq 228 ]] && echo 'el7' && return 0
# some centos-like dists ships higher version of glibc, fallback to el7
[[ $glibcver -gt 217 ]] && echo 'el7' && return 0
# fallback via glibc version when %{?dist} is undefined:
# el5 uses glibc 2.5, el6 uses 2.12, anything newer maps to el7
local glibcver ldd_version
ldd_version=$(ldd --version 2>&1) || true
ldd_version=${ldd_version%%$'\n'*}
if [[ $ldd_version =~ ([0-9]+\.[0-9]+) ]]; then
glibcver=${BASH_REMATCH[1]}
else
glibcver=
fi
case $glibcver in
2.5) echo 'el5' ;;
2.12) echo 'el6' ;;
*) echo 'el7' ;;
esac
}
# Map GUESS_DIST output to the spec dir and set per-dist build defaults.
# Sets globals: rpmtopdir; WITH_OPENSSL (el7 only, unless already set)
TOPDIR_SELECT() {
local DISTVER=$(GUESS_DIST)
case $DISTVER in
el7)
rpmtopdir=el7
if [[ -z ${WITH_OPENSSL+x} ]]; then
local opensslver=$(rpm -q openssl --qf "%{VERSION}" 2>/dev/null | cut -d. -f1)
[[ $opensslver -ge 3 ]] && WITH_OPENSSL=1 || WITH_OPENSSL=2
fi
;;
el6)
rpmtopdir=el6
WITH_OPENSSL=${WITH_OPENSSL:-2}
;;
el5)
rpmtopdir=el5
WITH_OPENSSL=${WITH_OPENSSL:-2}
;;
*)
echo "Distro undefined, please specify manually: el5 el6 el7"
echo -e "\nCurrent OS:"
[[ -f /etc/os-release ]] && cat /etc/os-release
[[ -f /etc/redhat-release ]] && cat /etc/redhat-release
[[ -f /etc/system-release ]] && cat /etc/system-release
echo -e "Current OS vendor: $(rpm --eval '%{?_vendor}') \n"
return 1
;;
esac
rpmtopdir=$(GUESS_DIST)
if [[ ! -d $rpmtopdir ]]; then
echo "Distro undefined, please specify manually: el5 el6 el7"
echo "eg: ${0} el7"
echo -e "\nCurrent OS:"
[[ -f /etc/os-release ]] && cat /etc/os-release
[[ -f /etc/redhat-release ]] && cat /etc/redhat-release
[[ -f /etc/system-release ]] && cat /etc/system-release
echo -e "Current OS vendor: $(rpm --eval '%{?_vendor}') \n"
return 1
fi
# default WITH_OPENSSL for el7: system openssl >=3 -> 1, else static(2);
# el5/el6 stay unset, BUILD_RPM defaults them to static(2)
if [[ $rpmtopdir == el7 && -z ${WITH_OPENSSL+x} ]]; then
local opensslver
opensslver=$(rpm -q openssl --qf "%{VERSION}" 2>/dev/null | cut -d. -f1)
[[ $opensslver -ge 3 ]] && WITH_OPENSSL=1 || WITH_OPENSSL=2
fi
}
BUILD_RPM() {
source version.env
[[ -f version-local.env ]] && source version-local.env
# shellcheck disable=SC1091
source version.env
# shellcheck disable=SC1091
[[ -f version-local.env ]] && source version-local.env
local SOURCES=( $OPENSSHSRC \
$OPENSSLSRC \
$ASKPASSSRC \
)
# UOS20 build: prefix PKGREL with "uos20." so the resulting RPMs are
# distinguishable from the standard build (e.g. PKGREL `1` becomes
# `uos20.1`, not `uos201`), and pass `uos20 1` to the spec to enable
# the kernel-panic patch.
# NOTE: RPM does not allow '-' in the Release field (it is the
# Version/Release delimiter), so '.' is used as the separator.
local _pkgrel="${PKGREL:-1}"
if [[ ${UOS20:-0} == 1 ]]; then
_pkgrel="uos20.${_pkgrel}"
fi
local RPMBUILDOPTS=( \
--define "with_openssl ${WITH_OPENSSL:-2}" \
--define "opensslver ${OPENSSLVER}" \
--define "opensshver ${OPENSSHVER}" \
--define "opensshpkgrel ${_pkgrel}" \
--define 'debug_package %{nil}' \
--define 'no_gtk2 1' \
--define 'skip_gnome_askpass 1' \
--define 'skip_x11_askpass 1' \
)
[[ ${UOS20:-0} == 1 ]] && RPMBUILDOPTS+=('--define' 'uos20 1')
local SOURCES=("$OPENSSHSRC"
"$OPENSSLSRC"
"$ASKPASSSRC"
)
# UOS20 build: prefix PKGREL with "uos20." so the resulting RPMs are
# distinguishable from the standard build (e.g. PKGREL `1` becomes
# `uos20.1`, not `uos201`), and pass `uos20 1` to the spec to enable
# the kernel-panic patch.
# NOTE: RPM does not allow '-' in the Release field (it is the
# Version/Release delimiter), so '.' is used as the separator.
local _pkgrel="${PKGREL:-1}"
if [[ ${UOS20:-0} == 1 ]]; then
_pkgrel="uos20.${_pkgrel}"
fi
local RPMBUILDOPTS=(
--define "with_openssl ${WITH_OPENSSL:-2}"
--define "opensslver ${OPENSSLVER}"
--define "opensshver ${OPENSSHVER}"
--define "opensshpkgrel ${_pkgrel}"
--define 'debug_package %{nil}'
--define 'no_gtk2 1'
--define 'skip_gnome_askpass 1'
--define 'skip_x11_askpass 1'
)
[[ ${UOS20:-0} == 1 ]] && RPMBUILDOPTS+=('--define' 'uos20 1')
# EL5 dist fixes
if [[ $rpmtopdir == *el5 ]]; then
SOURCES+=($PERLSRC)
# EL5 dist fixes
if [[ $rpmtopdir == *el5 ]]; then
SOURCES+=("$PERLSRC")
# Hack: fake the perl src when perl is ready already(docker images)
[[ $(perl -e 'print $] >= 5.010 ? 1 : 0') -eq 1 ]] && \
touch ./downloads/$PERLSRC
RPMBUILDOPTS+=('--define' "perlver ${PERLVER}" '--define' 'dist .el5')
export CC=gcc44
fi
# Hack: fake the perl src when perl is ready already(docker images)
[[ $(perl -e 'print $] >= 5.010 ? 1 : 0') -eq 1 ]] \
&& touch ./downloads/"$PERLSRC"
# add dist variable if not defined
[[ $rpmtopdir == *el7 ]] && [[ -z $(rpm --eval '%{?dist}') ]] && \
RPMBUILDOPTS+=('--define' "dist .$(rpm -q glibc | rev | cut -d. -f2 | rev)")
RPMBUILDOPTS+=('--define' "perlver ${PERLVER}")
local dist
dist=$(rpm --eval '%{?dist}')
[[ -n $dist ]] || RPMBUILDOPTS+=('--define' 'dist .el5')
export CC=gcc44
fi
pushd $rpmtopdir
RPMBUILDOPTS+=('--define' "_topdir $PWD")
for fn in ${SOURCES[@]}; do
CHECKEXISTS $fn && \
install -v -m666 $__dir/downloads/$fn ./SOURCES/
done
# add dist variable if not defined
[[ $rpmtopdir == *el7 ]] && [[ -z $(rpm --eval '%{?dist}') ]] \
&& RPMBUILDOPTS+=('--define' "dist .$(rpm -q glibc | rev | cut -d. -f2 | rev)")
if [[ ${M32:-0} != 0 ]]; then
local SETARCH="setarch i386"
RPMBUILDOPTS+=('--target' i686)
export CFLAGS="${CFLAGS:-} -m32" LDFLAGS="${LDFLAGS:-} -m32"
fi
pushd $rpmtopdir
# ensure the rpmbuild _topdir tree exists (fresh clone has no empty dirs)
mkdir -p BUILD RPMS SRPMS SOURCES SPECS
RPMBUILDOPTS+=('--define' "_topdir $PWD")
for fn in "${SOURCES[@]}"; do
CHECKEXISTS "$fn" \
&& install -v -m666 "$__dir"/downloads/"$fn" ./SOURCES/
done
${SETARCH:-} \
rpmbuild -bb ./SPECS/${SPECFILE:-openssh.spec} "${RPMBUILDOPTS[@]}"
if [[ $? -ne 0 ]]; then
echo "Error: rpmbuild failed with exit code $?"
exit 1
fi
if [[ ${M32:-0} != 0 ]]; then
local SETARCH="setarch i386"
RPMBUILDOPTS+=('--target' i686)
export CFLAGS="${CFLAGS:-} -m32" LDFLAGS="${LDFLAGS:-} -m32"
fi
mkdir -p $__dir/output
find ./RPMS -type f -name '*.rpm' -exec install -v -m644 {} $__dir/output/ \;
popd
if ! ${SETARCH:-} rpmbuild -bb ./SPECS/"${SPECFILE:-openssh.spec}" "${RPMBUILDOPTS[@]}"; then
echo "Error: rpmbuild failed with exit code $?"
exit 1
fi
mkdir -p "$__dir"/output
find ./RPMS -type f -name '*.rpm' -exec install -v -m644 {} "$__dir"/output/ \;
popd
}
LIST_RPMDIR(){
local RPMDIR=$__dir/${rpmtopdir}/RPMS/$(rpm --eval '%{_arch}')
[[ -d $RPMDIR ]] && echo $RPMDIR
LIST_RPMDIR() {
local RPMDIR
RPMDIR=$__dir/${rpmtopdir}/RPMS/$(rpm --eval '%{_arch}')
[[ -d $RPMDIR ]] && echo "$RPMDIR"
}
LIST_RPMS() {
local RPMDIR=$(LIST_RPMDIR)
[[ -d $RPMDIR ]] && find $RPMDIR -type f -name '*.rpm'
local RPMDIR
RPMDIR=$(LIST_RPMDIR)
[[ -d $RPMDIR ]] && find "$RPMDIR" -type f -name '*.rpm'
}
# sub cmds
# entry points
case $arg1 in
GETEL)
GUESS_DIST
exit 0
;;
GETRPM)
TOPDIR_SELECT
LIST_RPMS
exit 0
;;
RPMDIR)
TOPDIR_SELECT
LIST_RPMDIR
exit 0
;;
*)
if [[ -n $arg1 && ! -d $arg1 ]]; then
echo -e "Subcmd: $arg1 not found.\n GETEL, GETRPM, RPMDIR"
exit 1
fi
;;
GETEL)
GUESS_DIST
;;
GETRPM)
TOPDIR_SELECT
LIST_RPMS
;;
RPMDIR)
TOPDIR_SELECT
LIST_RPMDIR
;;
"")
# auto select dist
TOPDIR_SELECT
BUILD_RPM
;;
*)
# manual specified dist dir
if [[ ! -d $arg1 ]]; then
echo -e "Subcmd: $arg1 not found.\n GETEL, GETRPM, RPMDIR"
exit 1
fi
rpmtopdir=$arg1
BUILD_RPM
;;
esac
# manual specified dist
if [[ -n $arg1 && -d $arg1 ]]; then
rpmtopdir=$arg1
BUILD_RPM
exit 0
fi
# auto select dist
TOPDIR_SELECT
if [[ ! -d $rpmtopdir ]]; then
echo "This script works only in el5/el6/el7"
echo "eg: ${0} el7"
exit 1
fi
if [[ -d $rpmtopdir ]]; then
BUILD_RPM
fi

View File

@@ -1,24 +0,0 @@
ARG VERSION_NUM="2023"
FROM amazonlinux:$VERSION_NUM
ARG VERSION_NUM
ARG MIRROR=0
LABEL Author="Rex Zhou <zrx879582094@gmail.com>"
WORKDIR /data
# Copy all files
COPY . /data
RUN export MIRROR="$MIRROR" && \
bash ./docker/modify_yum_source.sh && \
if [ "$VERSION_NUM" = "2023" ]; then \
yum makecache timer && yum install -y libnsl systemd-devel; \
elif [ "$VERSION_NUM" = "2" ]; then \
yum makecache fast && yum install -y gtk2-devel systemd-devel; \
elif [ "$VERSION_NUM" = "1" ]; then \
yum makecache fast \
fi && \
yum install -y wget autoconf automake gcc make rpm-build openssl-devel pam-devel krb5-devel zlib-devel libXt-devel libX11-devel perl perl-IPC-Cmd perl-Time-Piece && \
yum clean all
CMD ["./docker/docker_compile.sh"]

View File

@@ -1,7 +1,6 @@
ARG VERSION_NUM="7"
FROM centos:$VERSION_NUM
ARG VERSION_NUM
ARG MIRROR=0
LABEL Author="Rex Zhou <zrx879582094@gmail.com>"
WORKDIR /data
@@ -9,18 +8,11 @@ WORKDIR /data
# Copy all files
COPY ./docker/ /data/docker/
RUN export MIRROR="$MIRROR" && \
bash ./docker/modify_yum_source.sh && \
if [ "$VERSION_NUM" = "8" ]; then \
yum install -y perl perl-IPC-Cmd perl-Time-Piece systemd-devel openssl-devel && \
yum install -y 'dnf-command(config-manager)' && \
yum config-manager --set-enabled powertools; \
elif [ "$VERSION_NUM" = "7" ]; then \
RUN bash ./docker/modify_vault_source.sh && \
if [ "$VERSION_NUM" = "7" ]; then \
yum install -y systemd-devel perl perl-IPC-Cmd perl-Time-Piece ;\
elif [ "$VERSION_NUM" = "6" ]; then \
yum install -y util-linux-ng perl perl-IPC-Cmd perl-Time-Piece ;\
elif [ "$VERSION_NUM" = "5" ]; then \
yum install -y gcc44; \
fi && \
yum install -y wget autoconf automake gcc make rpm-build pam-devel krb5-devel zlib-devel libXt-devel libX11-devel gtk2-devel e2fsprogs-devel && \
yum clean all && \

View File

@@ -2,7 +2,6 @@
ARG VERSION_NUM="9"
FROM quay.io/centos/centos:stream$VERSION_NUM
ARG VERSION_NUM
ARG MIRROR=0
LABEL Author="Rex Zhou <zrx879582094@gmail.com>"
WORKDIR /data
@@ -10,22 +9,14 @@ WORKDIR /data
# Copy all files
COPY ./docker/ /data/docker/
# CentOS 8 stream had NO valid mirrors.
# CentOS 8 stream had NO valid mirrors; modify_vault_source.sh rewrites the
# repo baseurls for .el8 (auto-detected via rpm --eval '%{?dist}').
RUN if [ "$VERSION_NUM" = "8" ]; then \
MIRROR_URL="https://vault.centos.org" && \
sed -e 's|^mirrorlist=|#mirrorlist=|g' \
-e "s|^#baseurl=http://mirror.centos.org/\$contentdir|baseurl=$MIRROR_URL|g" \
-i.bak \
/etc/yum.repos.d/CentOS-*.repo && \
bash ./docker/modify_vault_source.sh && \
yum install -y perl 'dnf-command(config-manager)' && \
yum config-manager --set-enabled powertools; \
else \
if [ "$MIRROR" != "0" ]; then \
MIRROR_URL="https://mirrors.ustc.edu.cn" && \
sed -i "s|MIRROR_HOLDER|$MIRROR_URL/centos-stream|" /data/docker/modify_dnf_source.pl && \
yum install -y perl && \
perl /data/docker/modify_dnf_source.pl /etc/yum.repos.d/*.repo; \
fi; \
bash /data/docker/modify_live_source.sh /etc/yum.repos.d/*.repo; \
fi && \
yum clean all && yum makecache && \
yum install -y wget autoconf automake gcc make perl rpm-build pam-devel krb5-devel zlib-devel openssl-devel systemd-devel e2fsprogs-devel && \

View File

@@ -1,12 +1,10 @@
FROM centos:5 AS builder
ARG MIRROR=1
WORKDIR /data
COPY ./docker/*.sh /data/docker/
COPY ./downloads/perl* /data/
RUN export MIRROR="$MIRROR" && \
bash ./docker/modify_yum_source.sh && \
RUN bash ./docker/modify_vault_source.sh && \
yum install -y gcc44 make
RUN mkdir -p perl && tar xfz perl-*.tar.gz --strip-components=1 -C perl && pushd perl && \
@@ -16,15 +14,14 @@ RUN rm -rf perl-*.tar.gz perl
FROM centos:5
ARG MIRROR=1
ENV PATH=/usr/local/perl/bin:$PATH
WORKDIR /data
COPY --from=builder /usr/local/perl /usr/local/perl
COPY ./docker/*.sh /data/docker/
RUN export MIRROR="$MIRROR" && \
bash ./docker/modify_yum_source.sh && \
yum install -y gcc44 autoconf automake make rpm-build setarch pam-devel krb5-devel zlib-devel && \
RUN bash ./docker/modify_vault_source.sh && \
yum install -y gcc44 autoconf automake make rpm-build redhat-rpm-config setarch pam-devel krb5-devel zlib-devel && \
mkdir -p /etc/rpm && printf '%s\n' '%dist .el5' > /etc/rpm/macros.dist && \
sed 's|]$|-i386]|;s|\$basearch|i386|g' /etc/yum.repos.d/CentOS-Base.repo > /etc/yum.repos.d/CentOS-Base-i386.repo && \
yum makecache && \
yum install -y glibc-devel.i386 libgcc.i386 pam-devel.i386 krb5-devel.i386 zlib-devel.i386 e2fsprogs-devel.i386 && \

View File

@@ -1,34 +0,0 @@
# Official: https://hub.docker.com/r/openeuler/openeuler
ARG VERSION_NUM="24.03"
FROM openeuler/openeuler:$VERSION_NUM
ARG VERSION_NUM
ARG MIRROR=0
LABEL Author="Rex Zhou <zrx879582094@gmail.com>"
WORKDIR /data
# Copy all files
COPY . /data
# Official webpage: https://www.openeuler.openatom.cn/zh/blog/2024-10-15-boostYum/2024-10-15-boostYum.html
RUN if [ "$MIRROR" != "0" ]; then \
MIRROR_URL="mirrors.163.com/openeuler" && \
sed -i.bak \
"s|repo.openeuler.org|$MIRROR_URL|g;s|^metalink|#metalink|g" \
/etc/yum.repos.d/openEuler.repo; \
else \
MIRROR_URL="mirrors.ocf.berkeley.edu/openeuler" && \
sed -i.bak \
"s|repo.openeuler.org|$MIRROR_URL|g;s|^metalink|#metalink|g" \
/etc/yum.repos.d/openEuler.repo; \
fi && \
if [[ "$VERSION_NUM" == 20* ]]; then sed -i \
"s|gpgcheck=1|gpgcheck=0|g" /etc/yum.repos.d/openEuler.repo; \
fi && \
rm -rf /var/cache/yum/ && \
yum clean all && yum makecache timer && \
yum install -y autoconf automake gcc make rpm-build pam-devel krb5-devel zlib-devel systemd-devel openssl-devel \
perl perl-IPC-Cmd perl-Time-Piece wget && \
yum clean all
CMD ["./docker/docker_compile.sh"]

View File

@@ -1,32 +0,0 @@
# Official: https://hub.docker.com/_/rockylinux
ARG VERSION_NUM="9"
FROM rockylinux:$VERSION_NUM
ARG VERSION_NUM
ARG MIRROR=0
LABEL Author="Rex Zhou <zrx879582094@gmail.com>"
WORKDIR /data
# Copy all files
COPY . /data
# Official webpage: https://developer.aliyun.com/mirror/rockylinux
RUN if [ "$MIRROR" != "0" ]; then \
MIRROR_URL="https://mirrors.aliyun.com/rockylinux" && \
sed -e 's|^mirrorlist=|#mirrorlist=|g' \
-e "s|^#baseurl=http://dl.rockylinux.org/\$contentdir|baseurl=$MIRROR_URL|g" \
-i.bak \
/etc/yum.repos.d/*.repo; \
else \
MIRROR_URL="https://mirrors.ocf.berkeley.edu/rocky" && \
sed -e 's|^mirrorlist=|#mirrorlist=|g' \
-e "s|^#baseurl=http://dl.rockylinux.org/\$contentdir|baseurl=$MIRROR_URL|g" \
-i.bak \
/etc/yum.repos.d/*.repo; \
fi && \
rm -rf /var/cache/yum/ && \
yum clean all && yum makecache timer && \
yum install -y wget autoconf automake gcc perl make rpm-build pam-devel krb5-devel zlib-devel libXt-devel libX11-devel gtk2-devel systemd-devel openssl-devel && \
yum clean all
CMD ["./docker/docker_compile.sh"]

View File

@@ -18,11 +18,11 @@ All built RPM packages will be automatically placed in the `./output/` directory
You must download the source code and tarballs before building:
```bash
# Download all required sources
env ALL=1 ./pullsrc.sh
# Download the pinned sources from version.env
./pullsrc.sh
```
> **Note**: Run this command only once before starting any builds. It prepares all necessary files for every supported platform.
> **Note**: Run this command only once before starting any builds. It downloads the single pinned set of sources defined in `version.env`. With `DOCKERBUILD=1 ./pullsrc.sh` only the Perl tarball is fetched (used for EL5 image builds).
## Step 2: Building RPMs for Specific Platforms
@@ -34,7 +34,7 @@ Choose only the platforms you need and run the corresponding commands.
```bash
# Build Docker image
docker build -t elssh:el5 -f ./docker/Dockerfile.centos5 --build-arg MIRROR=0 .
docker build -t elssh:el5 -f ./docker/Dockerfile.centos5 .
# Build 64-bit packages (recommended)
docker run --rm -v .:/data -e "M32=0" elssh:el5
@@ -46,50 +46,62 @@ docker run --rm -v .:/data -e "M32=1" elssh:el5
#### For EL6 (CentOS 6)
```bash
docker build -t elssh:el6 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=6 --build-arg MIRROR=0 .
docker build -t elssh:el6 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=6 .
docker run --rm -v .:/data elssh:el6
```
#### For EL7 (CentOS 7)
```bash
docker build -t elssh:el7 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=7 --build-arg MIRROR=0 .
docker build -t elssh:el7 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=7 .
docker run --rm -v .:/data elssh:el7
```
#### UOS 20 Variant (EL7-family)
#### UOS 20 Variant (EL8)
Reuse the EL7 image and pass `UOS20=1` to enable the kernel-panic fix in `sshd.c` and prefix `PKGREL` with `uos20-` (so the resulting RPMs are distinguishable from the standard build).
Reuse the EL8 image (CentOS Stream 8, `el7/` spec via `GUESS_DIST` mapping) and pass `UOS20=1` to enable the kernel-panic fix in `sshd.c` and prefix `PKGREL` with `uos20.` (so the resulting RPMs are distinguishable from the standard build).
```bash
docker build -t elssh:el7 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=7 --build-arg MIRROR=0 .
docker run --rm -v .:/data -e "UOS20=1" elssh:el7
docker build -t elssh:el8 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=8 .
docker run --rm -v .:/data -e "UOS20=1" elssh:el8
```
The aarch64 UOS20 build (CI artifact `rpm-uos20-aarch64`) uses the aarch64 EL8 image with `-e "UOS20=1"`.
#### For EL8 (CentOS 8 / RHEL 8 / Rocky 8 / AlmaLinux 8)
```bash
docker build -t elssh:el8 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=8 --build-arg MIRROR=0 .
docker build -t elssh:el8 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=8 .
docker run --rm -v .:/data elssh:el8
```
#### For EL9 (CentOS Stream 9 / RHEL 9 / Rocky 9 / AlmaLinux 9)
```bash
docker build -t elssh:el9 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=9 --build-arg MIRROR=0 .
docker build -t elssh:el9 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=9 .
docker run --rm -v .:/data elssh:el9
```
### aarch64 (ARM64) Builds
#### For EL7 aarch64
```bash
docker build -t elssh_aarch64:el7 \
--platform linux/arm64 \
-f ./docker/Dockerfile.centos \
--build-arg VERSION_NUM=7 .
docker run --rm -v .:/data --platform linux/arm64 elssh_aarch64:el7
```
#### For EL8 aarch64
```bash
docker build -t elssh_aarch64:el8 \
--platform linux/arm64 \
-f ./docker/Dockerfile.centos-stream \
--build-arg VERSION_NUM=8 \
--build-arg MIRROR=0 .
--build-arg VERSION_NUM=8 .
docker run --rm -v .:/data --platform linux/arm64 elssh_aarch64:el8
```
@@ -100,8 +112,7 @@ docker run --rm -v .:/data --platform linux/arm64 elssh_aarch64:el8
docker build -t elssh_aarch64:el9 \
--platform linux/arm64 \
-f ./docker/Dockerfile.centos-stream \
--build-arg VERSION_NUM=9 \
--build-arg MIRROR=0 .
--build-arg VERSION_NUM=9 .
docker run --rm -v .:/data --platform linux/arm64 elssh_aarch64:el9
```
@@ -110,66 +121,50 @@ docker run --rm -v .:/data --platform linux/arm64 elssh_aarch64:el9
| Argument | Values | Description |
|-------------------|--------|-----------|
| `MIRROR` | 0 or 1 | Set to `1` if you are in China and want to use faster domestic mirrors |
| `VERSION_NUM` | 6,7,8,9| Specifies the target EL version (used in most Dockerfiles) |
| `M32` (EL5 only) | 0 or 1 | `0` = 64-bit, `1` = 32-bit |
| `UOS20` | 0 or 1 | `1` = build the UOS 20 variant (EL7 image); enables the kernel-panic patch and prefixes `PKGREL` with `uos20.` |
| `UOS20` | 0 or 1 | `1` = build the UOS 20 variant (EL8 image); enables the kernel-panic patch and prefixes `PKGREL` with `uos20.` |
**Example for users in China:**
Add `--build-arg MIRROR=1` to the `docker build` command.
> Note: Standalone Dockerfiles for Amazon Linux / openEuler / Rocky Linux have been consolidated into the generic EL images (reusing EL8/EL9 via glibc compatibility) and are no longer maintained separately.
## Output Location
After each successful build, the RPM packages are copied to:
```
./output/
```
Typical output structure:
After each successful build, all built `.rpm` files land directly in `./output/` (flat, no per-version subdirs):
```
output/
├── el5/
│ ├── x86_64/
│ └── i686/ # only if M32=1
├── el6/
├── el7/
├── el8/
├── el9/
├── el8-aarch64/
└── el9-aarch64/
├── openssh-*.rpm
├── openssh-clients-*.rpm
└── ...
```
Each subdirectory contains the generated `.rpm` files (including debuginfo if available).
Every build (native `./compile.sh` or Docker via `docker/docker_compile.sh`) funnels through the same copy step, so building another EL version adds to / overwrites the same flat directory — copy the files out first if you need to keep versions separate.
## Quick Start Examples
### Build only for modern systems (EL8 + EL9)
```bash
env ALL=1 ./pullsrc.sh
./pullsrc.sh
docker build -t elssh:el8 -f ./docker/Dockerfile.centos --build-arg VERSION_NUM=8 --build-arg MIRROR=0 .
docker build -t elssh:el8 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=8 .
docker run --rm -v .:/data elssh:el8
docker build -t elssh:el9 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=9 --build-arg MIRROR=0 .
docker build -t elssh:el9 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=9 .
docker run --rm -v .:/data elssh:el9
```
### Build only for ARM64
```bash
env ALL=1 ./pullsrc.sh
./pullsrc.sh
docker build -t elssh_aarch64:el9 --platform linux/arm64 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=9 --build-arg MIRROR=0 .
docker build -t elssh_aarch64:el9 --platform linux/arm64 -f ./docker/Dockerfile.centos-stream --build-arg VERSION_NUM=9 .
docker run --rm -v .:/data --platform linux/arm64 elssh_aarch64:el9
```
## Troubleshooting
- **Slow downloads**: Use `MIRROR=1`
- **Permission issues**: Run `chown -R $USER output/` after building
- **Docker build fails on first run**: This is normal — it needs to download base images and dependencies
- **ARM64 builds**: Requires a machine with ARM64 support or Docker Buildx multi-platform enabled

View File

@@ -4,17 +4,17 @@ mkdir -p $DOCKER_BUILD_DIR
ELDIR=$(./compile.sh GETEL)
if ! rpm -q openssl-devel; then
WITH_OPENSSL=2
WITH_OPENSSL=2
fi
OPENSSLVER=$(rpm -q openssl --qf "%{VERSION}" | cut -d. -f1)
if [[ ${WITH_OPENSSL+x} == "" ]]; then
if [[ $OPENSSLVER -ge 3 ]]; then
export WITH_OPENSSL=1
else
export WITH_OPENSSL=2
fi
if [[ $OPENSSLVER -ge 3 ]]; then
export WITH_OPENSSL=1
else
export WITH_OPENSSL=2
fi
fi
cp -r $ELDIR $DOCKER_BUILD_DIR
./compile.sh $DOCKER_BUILD_DIR/$ELDIR
cp -r "$ELDIR" $DOCKER_BUILD_DIR
./compile.sh "$DOCKER_BUILD_DIR/$ELDIR"

View File

@@ -1,37 +0,0 @@
#!/usr/bin/perl
use strict;
use warnings;
use autodie;
my $mirrors = 'MIRROR_HOLDER';
if (@ARGV < 1) {
die "Usage: $0 <filename1> <filename2> ...\n";
}
while (my $filename = shift @ARGV) {
my $backup_filename = $filename . '.bak';
rename $filename, $backup_filename;
open my $input, "<", $backup_filename;
open my $output, ">", $filename;
while (<$input>) {
s/^metalink/# metalink/;
if (m/^name/) {
my (undef, $repo, $arch) = split /-/;
$repo =~ s/^\s+|\s+$//g;
($arch = defined $arch ? lc($arch) : '') =~ s/^\s+|\s+$//g;
if ($repo =~ /^Extras/) {
$_ .= "baseurl=${mirrors}/SIGs/\$releasever-stream/extras" . ($arch eq 'source' ? "/${arch}/" : "/\$basearch/") . "extras-common\n";
} else {
$_ .= "baseurl=${mirrors}/\$releasever-stream/$repo" . ($arch eq 'source' ? "/" : "/\$basearch/") . ($arch ne '' ? "${arch}/tree/" : "os") . "\n";
}
}
print $output $_;
}
}

86
docker/modify_live_source.sh Executable file
View File

@@ -0,0 +1,86 @@
#!/bin/bash
# Rewrite DNF repository baseurls for still-supported CentOS Stream EL
# (e.g. 9-stream). Uses multiple failover baseurls; vault handling for
# EOL 8-stream lives in docker/modify_vault_source.sh.
#
# DNF 4.x `baseurl` is `list` type: space-or-comma-separated URLs on ONE line;
# repeated `baseurl=` keys overwrite (only the last survives) — see
# dnf.readthedocs.io/conf_ref.html — so all mirrors go on a single baseurl= line.
#
# Note on mirror base paths: each entry is a prefix; the script appends
# "/${path}" (e.g. "9-stream/BaseOS/x86_64/os") to build the final URL.
# We use https://mirrors.kernel.org/centos (kernel.org official mirror) as
# the second entry; https://mirrors.kernel.org/centos-stream is an equally
# valid alternative that also resolves to the same kernel.org edge mirror.
# Official-first mirror list for still-supported Stream releases
LIVE_MIRRORS=(
"https://mirror.stream.centos.org"
"https://mirrors.kernel.org/centos"
"https://mirrors.aliyun.com/centos-stream"
"https://mirrors.ustc.edu.cn/centos-stream"
"https://ftp.iij.ad.jp/pub/linux/centos-stream"
"https://ftp.yandex.ru/centos-stream"
)
usage() {
echo "Usage: $0 <filename1> <filename2> ..." >&2
exit 1
}
if [[ $# -lt 1 ]]; then
usage
fi
# Trim leading/trailing whitespace from a string (result on stdout)
trim() {
local s="$1"
s="${s#"${s%%[![:space:]]*}"}"
s="${s%"${s##*[![:space:]]}"}"
printf '%s' "$s"
}
while [[ $# -gt 0 ]]; do
filename="$1"
shift
backup="${filename}.bak"
mv "$filename" "$backup" || continue
while IFS= read -r line; do
# comment out any metalink line (mirrors are preferred)
if [[ $line == metalink* ]]; then
line="# ${line}"
fi
if [[ $line == name* ]]; then
# split the "name=... - <repo> - <arch>" line on dashes
IFS='-' read -ra parts <<<"$line"
repo=$(trim "${parts[1]:-}")
arch=$(trim "${parts[2]:-}")
arch=${arch,,}
if [[ $repo == Extras* ]]; then
if [[ $arch == source ]]; then
path="SIGs/\$releasever-stream/extras/${arch}/extras-common"
else
path="SIGs/\$releasever-stream/extras/\$basearch/extras-common"
fi
else
if [[ $arch == source ]]; then
path="\$releasever-stream/${repo}/source/tree/"
else
path="\$releasever-stream/${repo}/\$basearch/os"
fi
fi
printf '%s\n' "$line"
# Single baseurl= line with all mirrors space-separated (DNF `list`
# type: repeated `baseurl=` keys overwrite, so one line is required).
urls=""
sep=""
for mirror in "${LIVE_MIRRORS[@]}"; do
urls+="${sep}${mirror}/${path}"
sep=" "
done
printf 'baseurl=%s\n' "$urls"
else
printf '%s\n' "$line"
fi
done <"$backup" >"$filename"
done

208
docker/modify_vault_source.sh Executable file
View File

@@ -0,0 +1,208 @@
#!/bin/bash
# Rewrite yum repository baseurls to use multiple (failover) mirrors.
# yum/dnf try each baseurl in order, so listing several provides resilience.
# EL5/EL6 use plain HTTP mirrors only (Python 2.4 / old curl cannot handle
# HTTPS redirects); EL7/EL8 keep HTTPS mirrors. EL8-stream is also EOL and lives
# in the vault, so it is handled here too. EL7 and EL8 share the VAULT array
# (yandex has no altarch tree, but the earlier failover mirrors cover aarch64).
# VAULT is ordered official-first (the canonical CentOS vault, then the kernel.org
# archive) so GitHub CI uses the canonical source; the remaining mirrors are
# failover only. Only EL5/EL6 fall back to VAULT_HTTP (plain HTTP) due to the
# Python 2.4 TLS limitation; EL7/EL8 always use the HTTPS VAULT array.
# EPEL archive mirrors (EPEL array) are plain HTTP and shared by EL7/EL6/EL5.
#
# Mirror base URLs are kept in the arrays below (no version suffix, no trailing
# slash) so they are easy to add/remove when a mirror goes stale. Use the
# join_baseurls / rewrite_baseurls helpers to turn an array + suffix into a
# SINGLE "baseurl=<url1> <url2> ..." line (DNF 4.x `baseurl` is `list` type:
# space-separated URLs on ONE line; repeated `baseurl=` keys overwrite — only
# the last survives — see dnf.readthedocs.io/conf_ref.html. YUM also accepts
# this form.)
RELEASE_VER=$(rpm --eval '%{?dist}')
[ -z "$RELEASE_VER" ] && RELEASE_VER=".el5"
# aarch64 builds use the altarch (CentOS AltArch) vault tree
ALTARCH=""
[ "$(uname -m)" = "aarch64" ] && ALTARCH="/altarch"
# CentOS vault mirrors - official-first HTTPS, shared by el7/el7-altarch/el8
# Criteria: hosts 7.9.2009, altarch/7.9.2009 (aarch64) and 8-stream; HTTPS valid
# (cert OK, no forced http->https 302, good for GitHub CI TLS); official priority
# (canonical CentOS vault, then kernel.org archive)
# shellcheck disable=SC2034
VAULT=(
"https://vault.centos.org"
"https://archive.kernel.org/centos-vault"
"https://mirrors.aliyun.com/centos-vault"
"https://ftp.iij.ad.jp/pub/linux/centos-vault"
)
# CentOS vault mirrors - plain HTTP for EL5/6 (hosts 5.11, 6.10 and 6.10/sclo;
# http only, no forced https redirect, avoids EL5 Python 2.4 / old curl TLS 1.0 failure)
# shellcheck disable=SC2034
VAULT_HTTP=(
"http://ftp.iij.ad.jp/pub/linux/centos-vault"
"http://mirrors.aliyun.com/centos-vault"
"http://ftp.yandex.ru/centos"
"http://ftp.pasteur.fr/mirrors/centos-vault"
)
# EPEL archive mirrors (plain HTTP for all EL, 7/6/5 share).
# archives.fedoraproject.org is excluded: it 302-redirects http->https, which
# EL5 Python 2.4 / M2Crypto cannot follow (uncaught SSLError aborts yum before
# mirror failover). All remaining mirrors serve plain HTTP without redirect.
# shellcheck disable=SC2034
EPEL=(
"http://mirrors.aliyun.com/epel-archive"
"http://ftp.iij.ad.jp/pub/linux/Fedora/archive/epel"
"http://mirrors.sindad.cloud/epel-archive"
"http://ftp.yandex.ru/epel-archive"
"http://debian.sbor.net/epel-archive"
)
disable_fastestmirror() {
sed -e 's|enabled=1|enabled=0|' -i /etc/yum/pluginconf.d/fastestmirror.conf 2>/dev/null || true
}
# Join array elements into a SINGLE "baseurl=<url1> <url2> ..." line
# (DNF 4.x `baseurl` is `list` type: space-or-comma-separated on ONE line;
# repeated `baseurl=` keys overwrite — only the last survives — see
# dnf.readthedocs.io/conf_ref.html. YUM also accepts this form.)
# Usage: join_baseurls <suffix> <array_name>
# e.g. join_baseurls "/7.9.2009" VAULT
# Uses eval instead of a nameref so it works on bash 4.2 (CentOS 7).
join_baseurls() {
local suffix="$1"
local arr_name="$2"
local arr
eval "arr=(\"\${${arr_name}[@]}\")"
local out="baseurl="
local sep=""
for m in "${arr[@]}"; do
out+="${sep}${m}${suffix}"
sep=" "
done
printf '%s' "$out"
}
# For every "baseurl=<prefix>..." line (whatever its content or comment
# format): comment the original line out by prepending "#", then add our own
# SINGLE active "baseurl=<url1> <url2> ..." line right below it. This makes
# the rewrite independent of how the repo file wrote the line ("#baseurl=",
# "# baseurl=", or an active "baseurl="). DNF 4.x `baseurl` is `list` type:
# space-separated URLs on ONE line; repeated `baseurl=` keys overwrite — only
# the last survives — so our added line wins (see dnf.readthedocs.io/
# conf_ref.html. YUM also accepts this form). Each added URL keeps the
# remainder after <prefix>; <suffix> is inserted between mirror and remainder
# (e.g. the vault version). Works on bash 3.2 (el5).
# Usage: rewrite_baseurls <glob> <prefix> <suffix> <array_name>
# e.g. rewrite_baseurls "/etc/yum.repos.d/CentOS-*.repo" \
# "http://mirror.centos.org/\$contentdir" "" VAULT
rewrite_baseurls() {
local glob="$1" prefix="$2" suffix="$3" arr_name="$4"
local arr out line rest m file urls sep
eval "arr=(\"\${${arr_name}[@]}\")"
for file in $glob; do
out=""
while IFS= read -r line || [ -n "$line" ]; do
if [[ $line == *"baseurl=$prefix"* ]]; then
rest="${line##*"$prefix"}"
urls=""
sep=""
for m in "${arr[@]}"; do
urls+="${sep}${m}${suffix}${rest}"
sep=" "
done
out+="#${line}\nbaseurl=${urls}\n"
else
out+="$line\n"
fi
done <"$file"
printf '%b' "$out" >"$file"
done
}
modify_el8() {
disable_fastestmirror
# Rewrite the repos BEFORE any dnf operation: the stream8/GA8 repo files
# still carry an active mirrorlist=http://mirrorlist.centos.org/... line,
# and that host is decommissioned (NXDOMAIN), so any dnf metadata refresh
# before the fixup aborts with "Couldn't resolve host name". (The
# dnf-plugins-core install for `dnf config-manager` lives in
# Dockerfile.centos-stream, AFTER this script.)
sed -e 's|^mirrorlist=|#mirrorlist=|g' \
-e 's|^metalink|#metalink|' \
-i.bak /etc/yum.repos.d/CentOS-*.repo
# EL8 GA repos use "$contentdir/$releasever" and EL8-stream repos use
# "$contentdir/$stream"; the remainder after the prefix (which contains
# $releasever or $stream) is preserved, so one rewrite covers both. Emits a
# single baseurl= line with space-separated URLs (DNF `list` type).
rewrite_baseurls "/etc/yum.repos.d/CentOS-*.repo" "http://mirror.centos.org/\$contentdir" "" VAULT
}
modify_el7() {
disable_fastestmirror
sed -e '/^mirrorlist=/s|^|#|g' \
-e 's|^metalink|#metalink|' \
-i.bak /etc/yum.repos.d/CentOS-*.repo
rewrite_baseurls "/etc/yum.repos.d/CentOS-*.repo" "http://mirror.centos.org/centos/\$releasever" "${ALTARCH}/7.9.2009" VAULT
rewrite_baseurls "/etc/yum.repos.d/CentOS-*.repo" "http://mirror.centos.org/altarch/\$releasever" "/altarch/7.9.2009" VAULT
yum install -y epel-release
sed -e '/^mirrorlist=/s|^|#|g' \
-e 's|^metalink|#metalink|' \
-i.bak /etc/yum.repos.d/epel*.repo 2>/dev/null || true
rewrite_baseurls "/etc/yum.repos.d/epel*.repo" "http://download.fedoraproject.org/pub/epel/7" "/7" EPEL
rm -rf /var/cache/yum/
yum makecache fast
}
modify_el6() {
disable_fastestmirror
sed -e "s|^mirrorlist=|#mirrorlist=|g" \
-e 's|^metalink|#metalink|' \
-i.bak /etc/yum.repos.d/CentOS-*.repo
rewrite_baseurls "/etc/yum.repos.d/CentOS-*.repo" "http://mirror.centos.org/centos/\$releasever" "/6.10" VAULT_HTTP
rewrite_baseurls "/etc/yum.repos.d/CentOS-*.repo" "http://mirror.centos.org/\$contentdir/\$releasever" "/6.10" VAULT_HTTP
yum install -y epel-release centos-release-scl-rh centos-release-scl
sed -e "s|^mirrorlist=|#mirrorlist=|g" \
-e 's|^metalink|#metalink|' \
-i.bak /etc/yum.repos.d/epel*.repo /etc/yum.repos.d/*scl*.repo 2>/dev/null || true
rewrite_baseurls "/etc/yum.repos.d/*scl*.repo" "http://mirror.centos.org/centos/6/sclo" "/6.10/sclo" VAULT_HTTP
rewrite_baseurls "/etc/yum.repos.d/epel*.repo" "http://download.fedoraproject.org/pub/epel/6" "/6" EPEL
rm -rf /var/cache/yum/
yum makecache fast
}
modify_el5() {
disable_fastestmirror
sed -e "s|^mirrorlist=|#mirrorlist=|g" \
-e 's|^metalink|#metalink|' \
-i.bak /etc/yum.repos.d/*.repo
rewrite_baseurls "/etc/yum.repos.d/*.repo" "http://mirror.centos.org/centos/\$releasever" "/5.11" VAULT_HTTP
rewrite_baseurls "/etc/yum.repos.d/*.repo" "http://mirror.centos.org/\$contentdir/\$releasever" "/5.11" VAULT_HTTP
yum install -y epel-release
sed -e "/^mirrorlist/s|^|#|g" \
-e 's|^metalink|#metalink|' \
-i.bak /etc/yum.repos.d/epel*.repo 2>/dev/null || true
rewrite_baseurls "/etc/yum.repos.d/epel*.repo" "http://download.fedoraproject.org/pub/epel/5" "/5" EPEL
rm -rf /var/cache/yum/
yum makecache
}
case $RELEASE_VER in
.el7)
modify_el7
;;
.el6)
modify_el6
;;
.el5)
modify_el5
;;
.el8)
modify_el8
;;
*)
echo "Unsupported dist: $RELEASE_VER, expected el5/el6/el7/el8"
exit 1
;;
esac

View File

@@ -1,102 +0,0 @@
#!/bin/bash
# Author: Rex Chow
# Modified: 2024-07-08 09:29:45
# Description: This script will modify yum repositories to Tsinghua University mirror.
# Copyright: Copyright © 2024 Rex Zhou. All rights reserved.
RELEASE_VER=$(rpm --eval '%{?dist}')
[ -z "$RELEASE_VER" ] && RELEASE_VER=".el5"
# Cent OS 5 is NOT support modern SSL protocol, so use plain HTTP protocol.
if [ "$RELEASE_VER" != ".el5" ]; then
if [ "$MIRROR" != "0" ]; then
# Using USTC mirror, which is much useful for Chinese users.
MIRROR_URL="https://mirrors.ustc.edu.cn/centos-vault";
AWS_DOMAIN="amazonaws.com.cn"
AWS_REGION="cn-northwest-1"
else
# Default mirror, the official mirror link.
MIRROR_URL="https://vault.centos.org/";
AWS_DOMAIN="amazonaws.com"
AWS_REGION="us-east-2"
fi
else
MIRROR_URL="http://mirrors.huaweicloud.com"
fi
# For ARM platform, the mirror url needs a suffix `altarch`
if [ "$(uname -m)" = "aarch64" ]; then
OS_KEY="altarch"
if [ "$RELEASE_VER" != ".el8" ]; then
MIRROR_URL="$MIRROR_URL/$OS_KEY";
fi
else
OS_KEY="centos"
fi
function modify_el8() {
sed -e "s|^mirrorlist=|#mirrorlist=|g" \
-e "s|^#baseurl=http://mirror.centos.org/\$contentdir/\$releasever|baseurl=${MIRROR_URL}/8.5.2111|g" \
-i.bak /etc/yum.repos.d/CentOS-*.repo && \
rm -rf /var/cache/yum/ && \
yum makecache timer
}
function modify_el7() {
sed -e 's|^mirrorlist=|#mirrorlist=|g' \
-e "s@^#baseurl=http://mirror.centos.org/$OS_KEY/\$releasever@baseurl=${MIRROR_URL}/7.9.2009@g" \
-e "s|^#baseurl=http://mirror.centos.org/\$contentdir/\$releasever|baseurl=${MIRROR_URL}/7.9.2009|g" \
-i.bak /etc/yum.repos.d/CentOS-*.repo && \
rm -rf /var/cache/yum/ && \
yum makecache fast
}
function modify_el6() {
sed -e "s|^mirrorlist=|#mirrorlist=|g" \
-e "s|^#baseurl=http://mirror.centos.org/$OS_KEY/\$releasever|baseurl=${MIRROR_URL}/6.10|g" \
-e "s|^#baseurl=http://mirror.centos.org/\$contentdir/\$releasever|baseurl=${MIRROR_URL}/6.10|g" \
-i.bak /etc/yum.repos.d/CentOS-*.repo && \
rm -rf /var/cache/yum/ && \
yum makecache fast
}
function modify_el5() {
sed -e "s|^mirrorlist=|#mirrorlist=|g" \
-e "s|^#baseurl=http://mirror.centos.org/centos/\$releasever|baseurl=${MIRROR_URL}/centos-vault/5.11|g" \
-e "s|^#baseurl=http://mirror.centos.org/\$contentdir/\$releasever|baseurl=${MIRROR_URL}/centos-vault/5.11|g" \
-i.bak /etc/yum.repos.d/*.repo && \
rm -rf /var/cache/yum/ && \
yum makecache fast
}
case $RELEASE_VER in
.el8)
modify_el8
;;
.el7)
modify_el7
;;
.el6)
modify_el6
;;
.el5)
modify_el5
;;
.amzn1)
echo "$AWS_DOMAIN" > /etc/yum/vars/awsdomain
echo "$AWS_REGION" > /etc/yum/vars/awsregion
;;
.amzn2)
echo "$AWS_DOMAIN" > /etc/yum/vars/awsdomain
echo "$AWS_REGION" > /etc/yum/vars/awsregion
;;
.amzn2023)
echo "$AWS_DOMAIN" > /etc/dnf/vars/awsdomain
echo "$AWS_REGION" > /etc/dnf/vars/awsregion
;;
*)
echo "rpm dist undefined, please specify: el5 el6 el7"
exit 1
;;
esac

View File

View File

View File

@@ -1,36 +1,17 @@
# OpenSSH RPM Build for EL5
# EL5 Build Tree (`el5/`)
This project provides an RPM Spec file designed to build a modern version of OpenSSH on legacy Enterprise Linux 5 (EL5) systems.
RPM spec for backporting OpenSSH on Enterprise Linux 5 (SysVinit).
## Key Features
## Notes
### 1. Legacy Environment Support (EL5)
Building modern software on EL5 is challenging due to outdated system libraries and build tools. This spec file contains specific logic to overcome these limitations without replacing core system packages.
- **Perl bootstrap**: modern OpenSSL requires Perl >= 5.10, while EL5
ships Perl 5.8. If the system Perl is too old, a private Perl
(`PERLSRC` in `version.env`) is built inside the build tree and used
only to compile OpenSSL; it is neither packaged nor installed.
`compile.sh` adds `PERLSRC` to the source list automatically for this
directory.
- **Toolchain**: built with `CC=gcc44`; OpenSSL is linked statically
(`WITH_OPENSSL=2`).
### 2. Perl Bootstrap
Modern versions of OpenSSL (which are required for modern OpenSSH) depend on Perl version 5.10.0 or higher for their build system. EL5 repositories typically provide Perl 5.8, which is insufficient.
To address this, the spec file implements a **Perl bootstrap process**:
* It checks the version of the system's Perl.
* If the system Perl is too old, it compiles a modern version of Perl (default: 5.38.2) from source inside the build directory.
* This custom Perl is used exclusively during the build process to compile OpenSSL and is not installed into the final RPM or the system.
### 3. Static OpenSSL Compilation
Using the bootstrapped Perl, the spec file compiles a modern version of OpenSSL (default: 3.0.8).
* OpenSSL is built statically within the build tree.
* It is linked directly into the OpenSSH binaries.
* This ensures the new OpenSSH has access to modern cryptography (like TLS 1.3 support) while leaving the system's original OpenSSL libraries untouched to prevent dependency conflicts.
### 4. Final OpenSSH Build
The process culminates in building OpenSSH (default: 9.6p1), linked against the custom-built static OpenSSL library.
## Build Flow Summary
1. **Detect Perl Version**: If system Perl < 5.10, build custom Perl.
2. **Build OpenSSL**: Use the custom Perl to configure and build OpenSSL.
3. **Build OpenSSH**: Configure OpenSSH to use the custom OpenSSL headers and libraries.
## Default Versions
* **OpenSSH**: 9.6p1
* **OpenSSL**: 3.0.8
* **Perl**: 5.38.2
Versions come from `version.env`. For usage, config variables, and
supported distros see the root [README.md](../README.md).

View File

View File

@@ -29,9 +29,6 @@
%global no_gnome_askpass 0
# Do we want smartcard support (1=yes 0=no)
%global scard 0
# Use GTK2 instead of GNOME in gnome-ssh-askpass
%global gtk2 1
@@ -75,10 +72,6 @@
%endif
# Options for Smartcard support: (needs libsectok and openssl-engine)
# rpm -ba|--rebuild --define "smartcard 1"
%{?smartcard:%global scard 1}
# Is this a build for the rescue CD (without PAM)? (1=yes 0=no)
%global rescue 0
%{?build_rescue:%global rescue 1}
@@ -314,7 +307,6 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-default-path=/usr/local/bin:/bin:/usr/bin \
--with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
--with-privsep-path=%{_var}/empty/sshd \
--with-md5-passwords \
--mandir=%{_mandir} \
--with-mantype=man \
--disable-strip \
@@ -328,9 +320,6 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-ssl-engine \
%endif
--with-zlib \
%if %{scard}
--with-smartcard \
%endif
%if %{rescue}
--without-pam \
%else
@@ -423,9 +412,6 @@ ln -s x11-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/ssh-askpass
install contrib/gnome-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/gnome-ssh-askpass
%endif
%if ! %{scard}
rm -f $RPM_BUILD_ROOT/usr/share/openssh/Ssh.bin
%endif
%if ! %{no_gnome_askpass}
install -m 755 -d $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
@@ -502,10 +488,6 @@ fi
%attr(0644,root,root) %{_mandir}/man8/ssh-pkcs11-helper.8*
%attr(0644,root,root) %{_mandir}/man8/ssh-sk-helper.8*
%endif
%if %{scard}
%attr(0755,root,root) %dir %{_datadir}/openssh
%attr(0644,root,root) %{_datadir}/openssh/Ssh.bin
%endif
%files clients
%defattr(-,root,root)

View File

View File

View File

@@ -1,29 +1,13 @@
# OpenSSH RPM Build for EL6
# EL6 Build Tree (`el6/`)
This project provides an RPM Spec file designed to build a modern version of OpenSSH on Enterprise Linux 6 (EL6) systems.
RPM spec for backporting OpenSSH on Enterprise Linux 6 (SysVinit).
## Key Features
## Notes
### 1. Legacy Environment Support (EL6)
Building modern software on EL6 requires handling outdated system libraries. This spec file addresses these limitations to provide a secure, modern SSH server.
- System Perl (>= 5.10) is sufficient, so unlike `el5/` no Perl
bootstrap is needed.
- OpenSSL is built statically and linked into the OpenSSH binaries
(`WITH_OPENSSL=2`); system OpenSSL stays untouched.
### 2. Static OpenSSL Compilation
Modern versions of OpenSSH require newer OpenSSL libraries than those provided by EL6.
* The spec file compiles a modern version of OpenSSL from source within the build environment.
* **Static Linking**: OpenSSL is built statically and linked directly into the OpenSSH binaries.
* **System Integrity**: This ensures the new OpenSSH has access to modern cryptography while leaving the system's original OpenSSL libraries untouched to prevent dependency conflicts.
### 3. System Perl
Unlike the EL5 build process, EL6 provides a version of Perl (5.10+) that is sufficient for building modern OpenSSL. Therefore, the **Perl bootstrap process is not required**, and the system Perl is used directly.
## Build Flow Summary
1. **Build OpenSSL**: Use system Perl to configure and build OpenSSL statically.
2. **Build OpenSSH**: Configure OpenSSH to use the custom OpenSSL headers and libraries.
## Default Versions
Versions are typically defined in the `version.env` file in the project root.
* **OpenSSH**: (e.g., 10.2p1)
* **OpenSSL**: (e.g., 3.0.18)
Versions come from `version.env`. For usage and supported distros see
the root [README.md](../README.md).

View File

View File

@@ -28,9 +28,6 @@
# Do we want to disable building of gnome-askpass? (1=yes 0=no)
%global no_gnome_askpass 0
# Do we want smartcard support (1=yes 0=no)
%global scard 0
# Use GTK2 instead of GNOME in gnome-ssh-askpass
%global gtk2 1
@@ -63,10 +60,6 @@
%global _sysconfdir /etc
%endif
# Options for Smartcard support: (needs libsectok and openssl-engine)
# rpm -ba|--rebuild --define "smartcard 1"
%{?smartcard:%global scard 1}
# Is this a build for the rescue CD (without PAM)? (1=yes 0=no)
%global rescue 0
%{?build_rescue:%global rescue 1}
@@ -236,7 +229,6 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-default-path=/usr/local/bin:/bin:/usr/bin \
--with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
--with-privsep-path=%{_var}/empty/sshd \
--with-md5-passwords \
--mandir=%{_mandir} \
--with-mantype=man \
--disable-strip \
@@ -250,9 +242,6 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-ssl-engine \
%endif
--with-zlib \
%if %{scard}
--with-smartcard \
%endif
%if %{rescue}
--without-pam \
%else
@@ -347,9 +336,6 @@ ln -s x11-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/ssh-askpass
install contrib/gnome-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/gnome-ssh-askpass
%endif
%if ! %{scard}
rm -f $RPM_BUILD_ROOT/usr/share/openssh/Ssh.bin
%endif
%if ! %{no_gnome_askpass}
install -m 755 -d $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
@@ -426,10 +412,6 @@ fi
%attr(0644,root,root) %{_mandir}/man8/ssh-pkcs11-helper.8*
%attr(0644,root,root) %{_mandir}/man8/ssh-sk-helper.8*
%endif
%if %{scard}
%attr(0755,root,root) %dir %{_datadir}/openssh
%attr(0644,root,root) %{_datadir}/openssh/Ssh.bin
%endif
%files clients
%defattr(-,root,root)

View File

View File

View File

@@ -1,46 +1,25 @@
# OpenSSH RPM Build for EL7+ (EL8/EL9)
# EL7+ Build Tree (`el7/`)
This project provides an RPM Spec file designed to build a modern version of OpenSSH on Enterprise Linux 7 (EL7). Thanks to the implementation of **systemd**, this configuration is also compatible with newer distributions like EL8 and EL9 (including RHEL, CentOS, Rocky Linux, and AlmaLinux).
RPM spec for backporting OpenSSH on Enterprise Linux 7 and newer
(EL7/EL8/EL9 incl. RHEL, CentOS, Rocky, AlmaLinux) using native systemd
services.
## Key Features
## Notes
### 1. Systemd Native Support
Unlike the EL5 and EL6 builds which rely on SysVinit scripts (`/etc/init.d/sshd`), this spec file configures OpenSSH to run as a native systemd service.
* **Unit File**: Installs a standard `sshd.service` unit file.
* **Management**: Fully integrated with `systemctl` for service management.
- Installs systemd units into `%{_unitdir}`: `sshd.service`,
`sshd.socket` (socket activation), `sshd@.service`, and
`sshd-keygen.service`.
- Two specs available: `openssh.spec` (default, systemd) and
`openssh.initv.spec` (SysVinit), selected via the `SPECFILE` env var.
- OpenSSL mode: system OpenSSL >= 3 is used directly
(`WITH_OPENSSL=1`), otherwise OpenSSL is built statically
(`WITH_OPENSSL=2`). Override via env, see `version.env`.
### 2. Forward Compatibility (EL8/EL9)
Because EL7, EL8, and EL9 all share the systemd architecture, this spec file allows the same source configuration to be built and deployed across these major versions with minimal or no changes.
### 3. Static OpenSSL Compilation
To support the latest OpenSSH features (which require newer cryptography than what EL7 provides by default), this build process:
* Compiles a modern version of OpenSSL (e.g., 3.0.x) from source.
* Links it **statically** into the OpenSSH binaries.
* Ensures no conflict with the system's default OpenSSL libraries.
## Systemd Integration Details
The spec file utilizes specific RPM macros and configurations to handle the systemd lifecycle:
* **Unit Installation**: The `sshd.service` file is installed into `%{_unitdir}` (typically `/usr/lib/systemd/system/`).
* **Socket Activation**: (If configured) The spec may also include support for `sshd.socket` for on-demand activation, though the standard service is the default.
## Usage
After installing the generated RPM, manage the service using standard systemd commands:
After installing the RPMs:
```bash
# Enable the service to start at boot
systemctl enable sshd
# Start the service immediately
systemctl start sshd
# Check status
systemctl status sshd
systemctl enable --now sshd
```
## Default Versions
* **OpenSSH**: (Defined in `version.env`, e.g., 10.2p1)
* **OpenSSL**: (Defined in `version.env`, e.g., 3.0.18)
Versions come from `version.env`. For usage and supported distros see
the root [README.md](../README.md).

View File

View File

@@ -23,9 +23,6 @@
# Do we want to disable building of gnome-askpass? (1=yes 0=no)
%global no_gnome_askpass 0
# Do we want smartcard support (1=yes 0=no)
%global scard 0
# Use GTK2 instead of GNOME in gnome-ssh-askpass
%global gtk2 1
@@ -58,10 +55,6 @@
%global _sysconfdir /etc
%endif
# Options for Smartcard support: (needs libsectok and openssl-engine)
# rpm -ba|--rebuild --define "smartcard 1"
%{?smartcard:%global scard 1}
# Is this a build for the rescue CD (without PAM)? (1=yes 0=no)
%global rescue 0
%{?build_rescue:%global rescue 1}
@@ -223,7 +216,6 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-default-path=/usr/local/bin:/bin:/usr/bin \
--with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
--with-privsep-path=%{_var}/empty/sshd \
--with-md5-passwords \
--mandir=%{_mandir} \
--with-mantype=man \
--disable-strip \
@@ -236,16 +228,13 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-ssl-engine \
%endif
--with-zlib \
%if %{scard}
--with-smartcard \
%endif
%if %{rescue}
--without-pam \
%else
--with-pam \
%endif
%if %{kerberos5}
--with-kerberos5=$K5DIR \
--with-kerberos5 \
%endif
@@ -332,9 +321,6 @@ ln -s x11-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/ssh-askpass
install contrib/gnome-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/gnome-ssh-askpass
%endif
%if ! %{scard}
rm -f $RPM_BUILD_ROOT/usr/share/openssh/Ssh.bin
%endif
%if ! %{no_gnome_askpass}
install -m 755 -d $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
@@ -411,10 +397,6 @@ fi
%attr(0644,root,root) %{_mandir}/man8/ssh-pkcs11-helper.8*
%attr(0644,root,root) %{_mandir}/man8/ssh-sk-helper.8*
%endif
%if %{scard}
%attr(0755,root,root) %dir %{_datadir}/openssh
%attr(0644,root,root) %{_datadir}/openssh/Ssh.bin
%endif
%files clients
%defattr(-,root,root)

View File

@@ -23,9 +23,6 @@
# Do we want to disable building of gnome-askpass? (1=yes 0=no)
%global no_gnome_askpass 0
# Do we want smartcard support (1=yes 0=no)
%global scard 0
# Use GTK2 instead of GNOME in gnome-ssh-askpass
%global gtk2 1
@@ -42,10 +39,6 @@
# rpm -ba|--rebuild --define 'no_gtk2 1'
%{?no_gtk2:%global gtk2 0}
# Options for Smartcard support: (needs libsectok and openssl-engine)
# rpm -ba|--rebuild --define "smartcard 1"
%{?smartcard:%global scard 1}
# Is this a build for the rescue CD (without PAM)? (1=yes 0=no)
%global rescue 0
%{?build_rescue:%global rescue 1}
@@ -238,10 +231,8 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-default-path=/usr/local/bin:/bin:/usr/bin \
--with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
--with-privsep-path=%{_var}/empty/sshd \
--with-md5-passwords \
--mandir=%{_mandir} \
--with-mantype=man \
--with-systemd \
--disable-strip \
%if %{with_openssl} == 2
--with-ssl-dir="%{openssl_dir}" \
@@ -252,9 +243,6 @@ export LD_LIBRARY_PATH="%{openssl_dir}"
--with-ssl-engine \
%endif
--with-zlib \
%if %{scard}
--with-smartcard \
%endif
%if %{rescue}
--without-pam \
%else
@@ -358,9 +346,6 @@ ln -s x11-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/ssh-askpass
install contrib/gnome-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/gnome-ssh-askpass
%endif
%if ! %{scard}
rm -f $RPM_BUILD_ROOT/usr/share/openssh/Ssh.bin
%endif
%if ! %{no_gnome_askpass}
install -m 755 -d $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
@@ -447,10 +432,6 @@ done
%attr(0644,root,root) %{_mandir}/man8/ssh-pkcs11-helper.8*
%attr(0644,root,root) %{_mandir}/man8/ssh-sk-helper.8*
%endif
%if %{scard}
%attr(0755,root,root) %dir %{_datadir}/openssh
%attr(0644,root,root) %{_datadir}/openssh/Ssh.bin
%endif
%files clients
%defattr(-,root,root)

View File

View File

View File

@@ -11,7 +11,7 @@ trap 'echo -e "Aborted, error $? in command: $BASH_COMMAND"; trap ERR; exit 1' E
# Set magic variables for current file & dir
__dir="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
__file="${__dir}/$(basename "${BASH_SOURCE[0]}")"
__base="$(basename ${__file} .sh)"
__base="$(basename "${__file}" .sh)"
__root="$(cd "$(dirname "${__dir}")" && pwd)" # <-- change this as it depends on your app
arg1="${1:-}"
@@ -20,57 +20,59 @@ arg1="${1:-}"
# allow command fail:
# fail_command || true
# shellcheck disable=SC1091
source version.env
# shellcheck disable=SC1091
[[ -f version-local.env ]] && source version-local.env
OPENSSHMIR=https://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable
OPENSSLMIR=https://www.openssl.org/source/
OPENSSLMIR=${GH_PROXY:-}https://github.com/openssl/openssl/releases/download/openssl-${OPENSSLVER}/
ASKPASSMIR=https://src.fedoraproject.org/repo/pkgs/openssh/x11-ssh-askpass-1.2.4.1.tar.gz/8f2e41f3f7eaa8543a2440454637f3c3
PERLMIR=https://www.cpan.org/src/5.0
LATEST_OPENSSH() {
curl -s "$OPENSSHMIR/" 2>/dev/null | \
grep -o 'openssh-[0-9.]*p[0-9]*\.tar\.gz' | \
sed 's/openssh-//; s/\.tar\.gz//' | \
sort -Vu | tail -1 || true
curl -s "$OPENSSHMIR/" 2>/dev/null \
| grep -o 'openssh-[0-9.]*p[0-9]*\.tar\.gz' \
| sed 's/openssh-//; s/\.tar\.gz//' \
| sort -Vu | tail -1 || true
}
if [[ $arg1 == "--latest" ]]; then
latest=$(LATEST_OPENSSH)
current="${OPENSSHVER}"
echo "Current version: $current"
echo "Latest version: $latest"
if [[ "$latest" == "$current" ]]; then
echo "Already up to date."
else
echo "NEW VERSION AVAILABLE: $latest"
fi
exit 0
latest=$(LATEST_OPENSSH)
# shellcheck disable=SC2153
current="${OPENSSHVER}"
echo "Current version: $current"
echo "Latest version: $latest"
if [[ "$latest" == "$current" ]]; then
echo "Already up to date."
else
echo "NEW VERSION AVAILABLE: $latest"
fi
exit 0
fi
mkdir -p downloads
pushd downloads
if [[ ! -f $OPENSSLSRC && ${DOCKERBUILD:-0} == 0 ]]; then
echo "Get:" $OPENSSLMIR/$OPENSSLSRC
wget --no-check-certificate $OPENSSLMIR/$OPENSSLSRC || \
echo "!!! Please download $OPENSSLSRC in $PWD by yourself."
echo "Get:" "$OPENSSLMIR"/"$OPENSSLSRC"
wget --no-check-certificate "$OPENSSLMIR"/"$OPENSSLSRC" \
|| echo "!!! Please download $OPENSSLSRC in $PWD by yourself."
fi
if [[ ! -f $OPENSSHSRC && ${DOCKERBUILD:-0} == 0 ]]; then
echo Get: $OPENSSHMIR/$OPENSSHSRC
wget --no-check-certificate $OPENSSHMIR/$OPENSSHSRC || \
echo "!!! Please download $OPENSSHSRC in $PWD by yourself."
echo Get: "$OPENSSHMIR"/"$OPENSSHSRC"
wget --no-check-certificate "$OPENSSHMIR"/"$OPENSSHSRC" \
|| echo "!!! Please download $OPENSSHSRC in $PWD by yourself."
fi
if [[ ! -f $ASKPASSSRC && ${DOCKERBUILD:-0} == 0 ]]; then
echo Get: $ASKPASSMIR/$ASKPASSSRC
wget --no-check-certificate $ASKPASSMIR/$ASKPASSSRC || \
echo "!!! Please download $ASKPASSSRC in $PWD by yourself."
echo Get: "$ASKPASSMIR"/"$ASKPASSSRC"
wget --no-check-certificate "$ASKPASSMIR"/"$ASKPASSSRC" \
|| echo "!!! Please download $ASKPASSSRC in $PWD by yourself."
fi
if [[ $($__dir/compile.sh GETEL) == "el5" && ${DOCKERBUILD:-0} == 1 && ! -f $PERLSRC ]]; then
echo Get: $PERLMIR/$PERLSRC
wget --no-check-certificate $PERLMIR/$PERLSRC || \
echo "!!! Please download $PERLSRC in $PWD by yourself."
if [[ ${DOCKERBUILD:-0} == 1 && ! -f $PERLSRC ]]; then
echo Get: "$PERLMIR"/"$PERLSRC"
wget --no-check-certificate "$PERLMIR"/"$PERLSRC" \
|| echo "!!! Please download $PERLSRC in $PWD by yourself."
fi

View File

@@ -1,5 +1,5 @@
# custom defined components
OPENSSLSRC=openssl-3.5.7.tar.gz
OPENSSLSRC=openssl-3.5.8.tar.gz
OPENSSHSRC=openssh-10.5p1.tar.gz
ASKPASSSRC=x11-ssh-askpass-1.2.4.1.tar.gz
@@ -23,7 +23,3 @@ OPENSSLVER=${OPENSSLSRC%%.tar.gz}
OPENSSLVER=${OPENSSLVER##openssl-}
PERLVER=${PERLSRC%%.tar.gz}
PERLVER=${PERLVER##perl-}
# Github Proxy, this arg is very useful for Chinese users.
# You can try this: https://github.akams.cn/
# GH_PROXY=""