source: branches/backfire/package/iptables/Makefile @ 25744

Last change on this file since 25744 was 25744, checked in by jow, 6 years ago

[backfire] package: fix iptables after libtool changes

  • Property svn:copyright set to Copyright (C) 2006 OpenWrt.org
  • Property svn:eol-style set to native
File size: 10.0 KB
Line 
1#
2# Copyright (C) 2006-2010 OpenWrt.org
3#
4# This is free software, licensed under the GNU General Public License v2.
5# See /LICENSE for more information.
6#
7
8include $(TOPDIR)/rules.mk
9include $(INCLUDE_DIR)/kernel.mk
10
11PKG_NAME:=iptables
12PKG_VERSION:=1.4.6
13PKG_RELEASE:=2
14
15PKG_MD5SUM:=c67cf30e281a924def6426be0973df56
16PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION).tar.bz2
17PKG_SOURCE_URL:=http://www.netfilter.org/projects/iptables/files \
18        ftp://ftp.be.netfilter.org/pub/netfilter/iptables/ \
19        ftp://ftp.de.netfilter.org/pub/netfilter/iptables/ \
20        ftp://ftp.no.netfilter.org/pub/netfilter/iptables/
21
22PKG_FIXUP:=libtool
23
24include $(INCLUDE_DIR)/package.mk
25ifeq ($(DUMP),)
26  -include $(LINUX_DIR)/.config
27  include $(INCLUDE_DIR)/netfilter.mk
28  STAMP_CONFIGURED:=$(strip $(STAMP_CONFIGURED))_$(shell grep 'NETFILTER' $(LINUX_DIR)/.config | md5s)
29endif
30
31
32define Package/iptables/Default
33  SECTION:=net
34  CATEGORY:=Network
35  URL:=http://netfilter.org/
36endef
37
38define Package/iptables/Module
39$(call Package/iptables/Default)
40  DEPENDS:=iptables $(1)
41endef
42
43define Package/iptables
44$(call Package/iptables/Default)
45  TITLE:=IPv4 firewall administration tool
46  MENU:=1
47  DEPENDS+= +kmod-ipt-core +libiptc +libxtables
48endef
49
50define Package/iptables/description
51IPv4 firewall administration tool.
52Includes support for:
53- comment
54- limit
55- LOG
56- mac
57- multiport
58- REJECT
59- TCPMSS
60endef
61
62define Package/iptables-mod-conntrack
63$(call Package/iptables/Module, +kmod-ipt-conntrack)
64  TITLE:=Basic connection tracking extensions
65endef
66
67define Package/iptables-mod-conntrack/description
68Basic iptables extensions for connection tracking.
69Includes:
70- state
71- raw
72- NOTRACK
73endef
74
75define Package/iptables-mod-conntrack-extra
76$(call Package/iptables/Module, +kmod-ipt-conntrack-extra)
77  TITLE:=Extra connection tracking extensions
78endef
79
80define Package/iptables-mod-conntrack-extra/description
81Extra iptables extensions for connection tracking.
82Includes:
83- libipt_conntrack
84- libipt_helper
85- libipt_connmark/CONNMARK
86endef
87
88define Package/iptables-mod-filter
89$(call Package/iptables/Module, +kmod-ipt-filter)
90  TITLE:=Content inspection extensions
91endef
92
93define Package/iptables-mod-filter/description
94iptables extensions for packet content inspection.
95Includes:
96- libipt_string
97- libipt_layer7
98endef
99
100define Package/iptables-mod-imq
101$(call Package/iptables/Module, +kmod-ipt-imq)
102  TITLE:=IMQ support
103endef
104
105define Package/iptables-mod-imq/description
106iptables extension for IMQ support.
107Includes:
108- libipt_IMQ
109endef
110
111define Package/iptables-mod-ipopt
112$(call Package/iptables/Module, +kmod-ipt-ipopt)
113  TITLE:=IP/Packet option extensions
114endef
115
116define Package/iptables-mod-ipopt/description
117iptables extensions for matching/changing IP packet options.
118Includes:
119- libipt_CLASSIFY
120- libipt_dscp/DSCP
121- libipt_ecn/ECN
122- libipt_length
123- libipt_mac
124- libipt_mark/MARK
125- libipt_statistic
126- libipt_tcpmms
127- libipt_tos/TOS
128- libipt_ttl/TTL
129- libipt_unclean
130endef
131
132define Package/iptables-mod-ipsec
133$(call Package/iptables/Module, +kmod-ipt-ipsec)
134  TITLE:=IPsec extensions
135endef
136
137define Package/iptables-mod-ipsec/description
138iptables extensions for matching ipsec traffic.
139Includes:
140- libipt_ah
141- libipt_esp
142- libipt_policy
143endef
144
145define Package/iptables-mod-ipset
146$(call Package/iptables/Module, @LINUX_2_6)
147  TITLE:=IPset iptables extensions
148endef
149
150define Package/iptables-mod-ipset/description
151IPset iptables extensions.
152Includes:
153- libipt_set
154- libipt_SET
155endef
156
157define Package/iptables-mod-nat
158$(call Package/iptables/Module, +kmod-ipt-nat)
159  TITLE:=Basic NAT extensions
160endef
161
162define Package/iptables-mod-nat/description
163iptables extensions for basic NAT targets.
164Includes:
165- MASQUERADE
166- SNAT
167- DNAT
168endef
169
170define Package/iptables-mod-nat-extra
171$(call Package/iptables/Module, +kmod-ipt-nat-extra)
172  TITLE:=Extra NAT extensions
173endef
174
175define Package/iptables-mod-nat-extra/description
176iptables extensions for extra NAT targets.
177Includes:
178- REDIRECT
179endef
180
181define Package/iptables-mod-ulog
182$(call Package/iptables/Module, +kmod-ipt-ulog)
183  TITLE:=user-space packet logging
184endef
185
186define Package/iptables-mod-ulog/description
187iptables extensions for user-space packet logging.
188Includes:
189- libipt_ULOG
190endef
191
192define Package/iptables-mod-iprange
193$(call Package/iptables/Module, +kmod-ipt-iprange)
194  TITLE:=IP range extension
195endef
196
197define Package/iptables-mod-iprange/description
198iptables extensions for matching ip ranges.
199Includes:
200- libipt_iprange
201endef
202
203define Package/iptables-mod-extra
204$(call Package/iptables/Module, +kmod-ipt-extra)
205  TITLE:=Other extra iptables extensions
206endef
207
208define Package/iptables-mod-extra/description
209Other extra iptables extensions.
210Includes:
211- libipt_owner
212- libipt_physdev
213- libipt_pkttype
214- libipt_recent
215endef
216
217define Package/iptables-utils
218$(call Package/iptables/Module, )
219  TITLE:=iptables save and restore utilities
220endef
221
222define Package/ip6tables
223$(call Package/iptables/Default)
224  DEPENDS:=+kmod-ip6tables
225  CATEGORY:=IPv6
226  TITLE:=IPv6 firewall administration tool
227  MENU:=1
228endef
229
230define Package/ip6tables-utils
231$(call Package/iptables/Default)
232  DEPENDS:=ip6tables
233  CATEGORY:=IPv6
234  TITLE:=ip6tables save and restore utilities
235endef
236
237define Package/libiptc
238$(call Package/iptables/Default)
239  SECTION:=libs
240  CATEGORY:=Libraries
241  TITLE:=IPv4/IPv6 firewall - shared libiptc library
242endef
243
244define Package/libxtables
245 $(call Package/iptables/Default)
246 SECTION:=libs
247 CATEGORY:=Libraries
248 TITLE:=IPv4/IPv6 firewall - shared xtables library
249endef
250
251
252TARGET_CPPFLAGS := \
253        -I$(PKG_BUILD_DIR)/include \
254        -I$(LINUX_DIR)/arch/$(LINUX_KARCH)/include \
255        $(TARGET_CPPFLAGS)
256
257CONFIGURE_ARGS += \
258        --enable-shared \
259        --enable-devel \
260        --enable-ipv6 \
261        --with-kernel="$(LINUX_DIR)" \
262        --with-xtlibdir=/usr/lib/iptables
263
264IPTABLES_MAKEOPTS = \
265                $(TARGET_CONFIGURE_OPTS) \
266                COPT_FLAGS="$(TARGET_CFLAGS)" \
267                LDFLAGS="-rdynamic -static-libgcc" \
268                KERNEL_DIR="$(LINUX_DIR)" PREFIX=/usr \
269                KBUILD_OUTPUT="$(LINUX_DIR)" \
270                DESTDIR="$(PKG_INSTALL_DIR)" \
271                $(MAKE_TARGETS)
272
273define Build/Compile
274        $(INSTALL_DIR) $(PKG_INSTALL_DIR)
275        $(MAKE) -C $(PKG_BUILD_DIR) $(IPTABLES_MAKEOPTS)
276        $(MAKE) -C $(PKG_BUILD_DIR) $(IPTABLES_MAKEOPTS) install
277        $(MAKE) -C $(PKG_BUILD_DIR)/libipq $(IPTABLES_MAKEOPTS)
278        $(MAKE) -C $(PKG_BUILD_DIR)/libipq $(IPTABLES_MAKEOPTS) install
279endef
280
281define Build/InstallDev
282        $(INSTALL_DIR) $(1)/usr/include
283        $(INSTALL_DIR) $(1)/usr/include/iptables
284        $(INSTALL_DIR) $(1)/usr/include/net/netfilter
285
286        # XXX: iptables header fixup, some headers are not installed by iptables anymore
287        $(CP) $(PKG_BUILD_DIR)/include/net/netfilter/*.h $(1)/usr/include/net/netfilter/
288        $(CP) $(PKG_BUILD_DIR)/include/iptables/*.h $(1)/usr/include/iptables/
289        $(CP) $(PKG_BUILD_DIR)/include/iptables.h $(1)/usr/include/
290        $(CP) $(PKG_BUILD_DIR)/include/libipq/libipq.h $(1)/usr/include/
291        $(CP) $(PKG_BUILD_DIR)/include/libipulog $(1)/usr/include/
292        $(CP) $(PKG_BUILD_DIR)/include/libiptc $(1)/usr/include/
293
294        $(CP) $(PKG_INSTALL_DIR)/usr/include/* $(1)/usr/include/
295        $(INSTALL_DIR) $(1)/usr/lib
296        $(CP) $(PKG_INSTALL_DIR)/usr/lib/libxtables.so* $(1)/usr/lib/
297        $(CP) $(PKG_INSTALL_DIR)/usr/lib/libip*tc.so* $(1)/usr/lib/
298        $(CP) $(PKG_INSTALL_DIR)/usr/lib/libipq.a $(1)/usr/lib/
299        $(INSTALL_DIR) $(1)/usr/lib/pkgconfig
300        $(CP) $(PKG_INSTALL_DIR)/usr/lib/pkgconfig/xtables.pc $(1)/usr/lib/pkgconfig/
301        $(CP) $(PKG_INSTALL_DIR)/usr/lib/pkgconfig/libiptc.pc $(1)/usr/lib/pkgconfig/
302endef
303
304define Package/iptables/install
305        $(INSTALL_DIR) $(1)/usr/sbin
306        $(INSTALL_BIN) $(PKG_INSTALL_DIR)/usr/sbin/iptables $(1)/usr/sbin/
307        $(INSTALL_DIR) $(1)/usr/lib/iptables
308        (cd $(PKG_INSTALL_DIR)/usr/lib/iptables ; \
309                for m in $(patsubst xt_%,ipt_%,$(IPT_BUILTIN)) $(patsubst ipt_%,xt_%,$(IPT_BUILTIN)); do \
310                        if [ -f $(PKG_INSTALL_DIR)/usr/lib/iptables/lib$$$${m}.so ]; then \
311                                $(CP) $(PKG_INSTALL_DIR)/usr/lib/iptables/lib$$$${m}.so $(1)/usr/lib/iptables/ ;\
312                        fi; \
313                done \
314        )
315endef
316
317define Package/iptables-utils/install
318        $(INSTALL_DIR) $(1)/usr/sbin
319        $(INSTALL_BIN) $(PKG_INSTALL_DIR)/usr/sbin/iptables-{save,restore} $(1)/usr/sbin/
320endef
321
322define Package/ip6tables/install
323        $(INSTALL_DIR) $(1)/usr/sbin
324        $(INSTALL_BIN) $(PKG_INSTALL_DIR)/usr/sbin/ip6tables $(1)/usr/sbin/
325        $(INSTALL_DIR) $(1)/usr/lib/iptables
326        (cd $(PKG_INSTALL_DIR)/usr/lib/iptables ; \
327                $(CP) libip6t_*.so $(1)/usr/lib/iptables/ \
328        )
329endef
330
331define Package/ip6tables-utils/install
332        $(INSTALL_DIR) $(1)/usr/sbin
333        $(INSTALL_BIN) $(PKG_INSTALL_DIR)/usr/sbin/ip6tables-{save,restore} $(1)/usr/sbin/
334endef
335
336define Package/libiptc/install
337        $(INSTALL_DIR) $(1)/usr/lib
338        $(CP) $(PKG_INSTALL_DIR)/usr/lib/libip*tc.so* $(1)/usr/lib/
339endef
340
341define Package/libxtables/install
342        $(INSTALL_DIR) $(1)/usr/lib
343        $(CP) $(PKG_INSTALL_DIR)/usr/lib/libxtables.so* $(1)/usr/lib/
344endef
345
346define BuildPlugin
347  define Package/$(1)/install
348        $(INSTALL_DIR) $$(1)/usr/lib/iptables
349        for m in $(patsubst xt_%,ipt_%,$(2)) $(patsubst ipt_%,xt_%,$(2)); do \
350                if [ -f $(PKG_INSTALL_DIR)/usr/lib/iptables/lib$$$$$$$${m}.so ]; then \
351                        $(CP) $(PKG_INSTALL_DIR)/usr/lib/iptables/lib$$$$$$$${m}.so $$(1)/usr/lib/iptables/ ; \
352                fi; \
353        done
354        $(3)
355  endef
356
357  $$(eval $$(call BuildPackage,$(1)))
358endef
359
360L7_INSTALL:=\
361        $(INSTALL_DIR) $$(1)/etc/l7-protocols; \
362        $(CP) files/l7/*.pat $$(1)/etc/l7-protocols/
363
364
365$(eval $(call BuildPackage,iptables))
366$(eval $(call BuildPackage,iptables-utils))
367$(eval $(call BuildPlugin,iptables-mod-conntrack,$(IPT_CONNTRACK-m)))
368$(eval $(call BuildPlugin,iptables-mod-conntrack-extra,$(IPT_CONNTRACK_EXTRA-m)))
369$(eval $(call BuildPlugin,iptables-mod-extra,$(IPT_EXTRA-m)))
370$(eval $(call BuildPlugin,iptables-mod-filter,$(IPT_FILTER-m),$(L7_INSTALL)))
371$(eval $(call BuildPlugin,iptables-mod-imq,$(IPT_IMQ-m)))
372$(eval $(call BuildPlugin,iptables-mod-ipopt,$(IPT_IPOPT-m)))
373$(eval $(call BuildPlugin,iptables-mod-ipsec,$(IPT_IPSEC-m)))
374$(eval $(call BuildPlugin,iptables-mod-ipset,ipt_set ipt_SET))
375$(eval $(call BuildPlugin,iptables-mod-nat,$(IPT_NAT-m)))
376$(eval $(call BuildPlugin,iptables-mod-nat-extra,$(IPT_NAT_EXTRA-m)))
377$(eval $(call BuildPlugin,iptables-mod-iprange,$(IPT_IPRANGE-m)))
378$(eval $(call BuildPlugin,iptables-mod-ulog,$(IPT_ULOG-m)))
379$(eval $(call BuildPackage,ip6tables))
380$(eval $(call BuildPackage,ip6tables-utils))
381$(eval $(call BuildPackage,libiptc))
382$(eval $(call BuildPackage,libxtables))
Note: See TracBrowser for help on using the repository browser.