5 ms·
If anyone needs to patch CentOS 6 like I had to (I know, I know..), it's possible. You'll need to install gcc, pam-devel and openldap-devel if you need it. The
by YurtyAherne 6y ago
If anyone needs to patch CentOS 6 like I had to (I know, I know..), it's possible.
You'll need to install gcc, pam-devel and openldap-devel if you need it.
Then you can build from source using ./configure --prefix=/usr && make && make install
Oh and remember to switch your repos to CentOS Vault instead of the default mirrorlist if you need the packages mentioned above.
- xorcist 6y agoNormally you should use the source packages available to you. If you run configure and make on the upstream package, you will not only lose the patches CentOS normally applies to the package to integrate it better with the system, but your patch will also be untracked by the package manager. Building a source package is trivial. Just download the srpm, run rpm -i just like you normally would. This will extract the package. Look at rpmbuild/SPECS directory. There is your "spec file" which is a list of patches to apply and the exact commands used to build the package. Add the upstream patch that fixes the security problem and step the least significant version number. Run rpmbuild -ba on the spec file. A binary rpm will now be built that can be installed in the normal way. This may sound intimidating at first, but it is really very simple. Also, congratulations on your first step on maintaining a package. Alternatively, you can also grab the latest version from Rawhide if it has the fix. This will often have the patch and you can lift it straight out and use on the old version. Or you could just build the new version, but there can be hard dependencies on newer libraries which may not be easily available to you.
- YurtyAherne 6y agoNot sure what you're on about. CentOS 6 doesn't receive updates anymore. It's EOL. Why go through all that effort if nothing will ever replace the package I compiled from source and installed?
- xorcist 6y agoBecause there may be another security patch after this one. Because otherwise it is easy to lose track of which hosts have the patch. Because it integrates well with configuration management systems. Because you want to keep whatever other patches Red Hat has applied.