]> git.ipfire.org Git - ipfire-3.x.git/log
ipfire-3.x.git
2 years agosetup: Port sysctl hardening settings from IPFire 2.x
Peter Müller [Fri, 15 Sep 2023 12:41:42 +0000 (14:41 +0200)] 
setup: Port sysctl hardening settings from IPFire 2.x

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2 years agostrongswan: Update to 5.9.11
Peter Müller [Fri, 15 Sep 2023 12:39:12 +0000 (14:39 +0200)] 
strongswan: Update to 5.9.11

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2 years agoca-certificates: Update to 2023.09
Peter Müller [Fri, 15 Sep 2023 12:26:59 +0000 (14:26 +0200)] 
ca-certificates: Update to 2023.09

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
2 years agoqemu: update to 8.1.0
Arne Fitzenreiter [Sat, 16 Sep 2023 11:41:38 +0000 (13:41 +0200)] 
qemu: update to 8.1.0

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoqemu: update 8.0.4
Arne Fitzenreiter [Sat, 16 Sep 2023 11:21:26 +0000 (13:21 +0200)] 
qemu: update 8.0.4

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonano: Update to 7.2
Peter Müller [Sat, 16 Sep 2023 11:37:57 +0000 (13:37 +0200)] 
nano: Update to 7.2

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonftables: Update to 1.0.8
Peter Müller [Sat, 16 Sep 2023 11:24:52 +0000 (13:24 +0200)] 
nftables: Update to 1.0.8

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agolibnftnl: Update to 1.2.6
Peter Müller [Sat, 16 Sep 2023 11:24:26 +0000 (13:24 +0200)] 
libnftnl: Update to 1.2.6

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoUnbound: Update to 1.18.0
Peter Müller [Sat, 16 Sep 2023 08:18:11 +0000 (10:18 +0200)] 
Unbound: Update to 1.18.0

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopsmisc: The project's homepage moved to Gitlab
Peter Müller [Sat, 16 Sep 2023 08:10:48 +0000 (10:10 +0200)] 
psmisc: The project's homepage moved to Gitlab

However, its tarballs are still to be retrieved from SF.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agokernel: update to 6.5.3
Arne Fitzenreiter [Fri, 15 Sep 2023 18:32:38 +0000 (20:32 +0200)] 
kernel: update to 6.5.3

and also enable CONFIG_INPUT_EVDEV to handle ACPI power
button.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agostrace: Update to 6.5
Michael Tremer [Sat, 16 Sep 2023 07:37:53 +0000 (07:37 +0000)] 
strace: Update to 6.5

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopakfire: Update to 0.9.29
Michael Tremer [Fri, 15 Sep 2023 15:09:28 +0000 (15:09 +0000)] 
pakfire: Update to 0.9.29

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agolibbpf: New package
Michael Tremer [Fri, 15 Sep 2023 15:09:09 +0000 (15:09 +0000)] 
libbpf: New package

This is required by Pakfire.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopam: Update to 1.5.3
Michael Tremer [Fri, 15 Sep 2023 13:03:06 +0000 (13:03 +0000)] 
pam: Update to 1.5.3

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years ago.gitignore: Ignore .pfm files
Michael Tremer [Fri, 15 Sep 2023 13:02:47 +0000 (13:02 +0000)] 
.gitignore: Ignore .pfm files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agofontconfig: Require libuuid at build time
Michael Tremer [Thu, 14 Sep 2023 13:11:22 +0000 (13:11 +0000)] 
fontconfig: Require libuuid at build time

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agosystemd: Update to 254
Michael Tremer [Thu, 14 Sep 2023 13:09:25 +0000 (13:09 +0000)] 
systemd: Update to 254

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoMass rebuild for incorrectly packaged libtool archive files
Michael Tremer [Thu, 14 Sep 2023 13:02:35 +0000 (13:02 +0000)] 
Mass rebuild for incorrectly packaged libtool archive files

Due to a pattern matching bug in Pakfire, those files have been
incorrectly packages instead of being deleted which results in build
errors when linking.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agovim: Rebuild against new glibc
Michael Tremer [Thu, 14 Sep 2023 12:06:39 +0000 (12:06 +0000)] 
vim: Rebuild against new glibc

VIM immediately crashes and rebuilding it fixes the problem.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoethtool: Update to 6.5
Michael Tremer [Thu, 14 Sep 2023 12:02:35 +0000 (12:02 +0000)] 
ethtool: Update to 6.5

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoglib2: Bump release to rebuild after Pakfire bug
Michael Tremer [Thu, 14 Sep 2023 12:01:17 +0000 (12:01 +0000)] 
glib2: Bump release to rebuild after Pakfire bug

The fix interpreter function has corrupted some scripts which no longer
can be executed any more and therefore this package needs to be rebuilt.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoperl: Fix that the package can be installed
Michael Tremer [Wed, 13 Sep 2023 18:07:59 +0000 (18:07 +0000)] 
perl: Fix that the package can be installed

Perl packages require "perl(strict)" which was accidentially dropped
from the manual provides list. Furthermore, perl(Test) is a common
package that is needed for building modules.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoca-certificates: Fix generating certificate store
Michael Tremer [Wed, 13 Sep 2023 17:55:49 +0000 (17:55 +0000)] 
ca-certificates: Fix generating certificate store

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agop11-kit: Update to 0.25.0
Michael Tremer [Wed, 13 Sep 2023 17:55:02 +0000 (17:55 +0000)] 
p11-kit: Update to 0.25.0

This change also sets the path for p11-kit to search for certificates.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agolibtool: Rebuild package because of a Pakfire bug
Michael Tremer [Wed, 13 Sep 2023 14:46:21 +0000 (14:46 +0000)] 
libtool: Rebuild package because of a Pakfire bug

Pakfire incorrectly changed the interpreter of the libtoolize script
which breaks it entirely.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoglibc: Update to 2.38
Michael Tremer [Sat, 9 Sep 2023 16:33:38 +0000 (16:33 +0000)] 
glibc: Update to 2.38

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agolibpwquality: Require zlib
Michael Tremer [Sat, 9 Sep 2023 15:03:58 +0000 (15:03 +0000)] 
libpwquality: Require zlib

This package requires zlib to build.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agompfr: Update to 4.2.1
Michael Tremer [Sat, 9 Sep 2023 14:45:33 +0000 (14:45 +0000)] 
mpfr: Update to 4.2.1

The testsuite keeps failing for a couple of releases now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopatchelf: Disable the testsuite
Michael Tremer [Sat, 9 Sep 2023 11:18:40 +0000 (11:18 +0000)] 
patchelf: Disable the testsuite

It currently fails on ARM and I don't have the time to debug this now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocyrus-sasl: Make the devel package require its libraries
Michael Tremer [Fri, 8 Sep 2023 16:32:06 +0000 (16:32 +0000)] 
cyrus-sasl: Make the devel package require its libraries

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoperl-File-HomeDir: Fix limiting to building only on noarch
Michael Tremer [Sat, 2 Sep 2023 09:48:44 +0000 (09:48 +0000)] 
perl-File-HomeDir: Fix limiting to building only on noarch

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoChange how we make packages "noarch"
Michael Tremer [Tue, 29 Aug 2023 19:49:51 +0000 (19:49 +0000)] 
Change how we make packages "noarch"

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agolibarchive: Update to 3.7.1
Michael Tremer [Tue, 29 Aug 2023 18:31:20 +0000 (18:31 +0000)] 
libarchive: Update to 3.7.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years ago*: Change how we define build architectures
Michael Tremer [Tue, 29 Aug 2023 15:57:13 +0000 (15:57 +0000)] 
*: Change how we define build architectures

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogcc: Update to 12.3.0
Michael Tremer [Tue, 29 Aug 2023 15:56:40 +0000 (15:56 +0000)] 
gcc: Update to 12.3.0

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agowget: Update to 1.12.4
Michael Tremer [Thu, 17 Aug 2023 10:24:16 +0000 (10:24 +0000)] 
wget: Update to 1.12.4

Fixes: #13218 - wget 1.21.4 has been released
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agokernel: Enable IBT on x86
Michael Tremer [Wed, 19 Jul 2023 10:05:25 +0000 (10:05 +0000)] 
kernel: Enable IBT on x86

This change has recently been made in IPFire 2 and is being backported
in this patch.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agokernel: Disable the entire sound subsystem
Michael Tremer [Wed, 19 Jul 2023 09:56:28 +0000 (09:56 +0000)] 
kernel: Disable the entire sound subsystem

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agokernel: Update to Linux 6.4
Michael Tremer [Wed, 19 Jul 2023 09:44:16 +0000 (09:44 +0000)] 
kernel: Update to Linux 6.4

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agokernel: Update to Linux 6.3
Michael Tremer [Wed, 19 Jul 2023 09:30:11 +0000 (09:30 +0000)] 
kernel: Update to Linux 6.3

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agokernel: Replace Python 2 interpreter by Python 3
Michael Tremer [Sun, 4 Jun 2023 11:33:05 +0000 (11:33 +0000)] 
kernel: Replace Python 2 interpreter by Python 3

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonghttp2: Replace Python 2 by Python 3
Michael Tremer [Fri, 2 Jun 2023 15:51:09 +0000 (15:51 +0000)] 
nghttp2: Replace Python 2 by Python 3

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agolibevent: Run event_rpcgen.py with Python 3
Michael Tremer [Fri, 2 Jun 2023 15:28:34 +0000 (15:28 +0000)] 
libevent: Run event_rpcgen.py with Python 3

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoinitscripts: Fix running the testsuite
Michael Tremer [Fri, 2 Jun 2023 12:03:28 +0000 (12:03 +0000)] 
initscripts: Fix running the testsuite

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agodbus-glib: Disable the testsuite
Michael Tremer [Mon, 29 May 2023 16:32:00 +0000 (16:32 +0000)] 
dbus-glib: Disable the testsuite

It requires dbus-run-session which we do not package any more.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogawk: Update to 5.2.2 and disable PMA tests
Michael Tremer [Mon, 29 May 2023 16:26:43 +0000 (16:26 +0000)] 
gawk: Update to 5.2.2 and disable PMA tests

Those tests cannot be run as root, so we have to disable them.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agodhcpcd: Update to 10.0.1
Michael Tremer [Mon, 29 May 2023 16:09:22 +0000 (16:09 +0000)] 
dhcpcd: Update to 10.0.1

The project has been moved to GitHub.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoopenssl: Make sure we perform a parallel build
Michael Tremer [Mon, 8 May 2023 13:40:07 +0000 (13:40 +0000)] 
openssl: Make sure we perform a parallel build

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agosystemd: Use sysusers mechanism inside the jail
Stefan Schantl [Wed, 29 Mar 2023 14:07:15 +0000 (16:07 +0200)] 
systemd: Use sysusers mechanism inside the jail

Change the old user/group creation mechanism to use systemd's
sysusers mechanism instead.

This is a bit of a tricky part, because before systemd we do not have
this binary. So at first we have to push the sysusers files to the jails
sysusers directory and use the previous compiled and installed systemd-sysusers
binary in order to create the groups/users which are part of systemd
inside the jail.

After that, everything works quite normal when modifying the files or
direcotry owners.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agosystemd: Build manpages again
Stefan Schantl [Wed, 29 Mar 2023 14:05:17 +0000 (16:05 +0200)] 
systemd: Build manpages again

This "optional" feature now has to be enabled.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agosystemd: Move some basic tools into own package
Stefan Schantl [Tue, 28 Mar 2023 17:35:05 +0000 (19:35 +0200)] 
systemd: Move some basic tools into own package

The systemd-sysusers and systemd-tmpfiles tools
are used by various services and the build system in order
to install / build packages.

Moving this tools into an own package allows us to early access
them without requiremet to install the whole systemd package.

Anyway the systemd package requires those tools to proper get
installed and handle their own sysusers files.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoglibc: Disable multilib support on X86_64
Stefan Schantl [Sat, 25 Mar 2023 19:22:54 +0000 (20:22 +0100)] 
glibc: Disable multilib support on X86_64

This requires a 32bit glibc to link against, which we do not have.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agounbound: Create missing directory for root anchor
Stefan Schantl [Sat, 25 Mar 2023 19:20:30 +0000 (20:20 +0100)] 
unbound: Create missing directory for root anchor

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agowhois: Change download location
Stefan Schantl [Sat, 25 Mar 2023 19:09:15 +0000 (20:09 +0100)] 
whois: Change download location

Debian moved to a recent version of which and dropped
the source tarball from their server.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agosystemd: Enable sysusers subsystem
Stefan Schantl [Sat, 25 Mar 2023 18:17:04 +0000 (19:17 +0100)] 
systemd: Enable sysusers subsystem

This allows dynamically user and group creation based on
sysusers config files.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agosystemd: Update to 253
Stefan Schantl [Sat, 25 Mar 2023 18:16:30 +0000 (19:16 +0100)] 
systemd: Update to 253

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoglibc: Fix runtime linker path chaos
Michael Tremer [Fri, 24 Mar 2023 17:15:02 +0000 (17:15 +0000)] 
glibc: Fix runtime linker path chaos

Some architectures have a specific path for their runtime linker
hardcoded and in order to avoid installing them into /lib or /lib64
instead of /usr/lib or /usr/lib64, we are adding artificial provides.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogcc: Harden this package
Michael Tremer [Fri, 24 Mar 2023 10:55:33 +0000 (10:55 +0000)] 
gcc: Harden this package

This is a major rewrite of this package which should probably be broken
down into several commits, but since GCC takes many hours to build, this
has now been mushed into one to keep us moving forward.

This patch re-introduces a full bootstrap of GCC.

We also build GCC with our own compiler flags and make it pass our
hardening checks which includes patching the build system to build GCC
itself as PIE.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoglibc: Fix RUNPATH in gconv libraries
Stefan Schantl [Tue, 21 Mar 2023 18:49:23 +0000 (19:49 +0100)] 
glibc: Fix RUNPATH in gconv libraries

Those libraries uses a special RUNPATH called $ORIGIN which we
do not support in IPFire. So changing this to the directory where
the are installed.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agochrpath: Drop package
Stefan Schantl [Tue, 21 Mar 2023 19:42:41 +0000 (20:42 +0100)] 
chrpath: Drop package

This package has seen no updates for a long time and has been
replaced by the similar and better supported patchelf.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agogettext: Switch to patchelf to remove the RPATH
Stefan Schantl [Tue, 21 Mar 2023 19:41:37 +0000 (20:41 +0100)] 
gettext: Switch to patchelf to remove the RPATH

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agolibldb: Switch to patchelf to remove the RPATH
Stefan Schantl [Tue, 21 Mar 2023 19:33:36 +0000 (20:33 +0100)] 
libldb: Switch to patchelf to remove the RPATH

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agolibdb: Switch to patchelf to remove the RPATH
Stefan Schantl [Tue, 21 Mar 2023 19:23:41 +0000 (20:23 +0100)] 
libdb: Switch to patchelf to remove the RPATH

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agonet-snmp: Switch to patchelf to remove the RPATH
Stefan Schantl [Tue, 21 Mar 2023 19:17:46 +0000 (20:17 +0100)] 
net-snmp: Switch to patchelf to remove the RPATH

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agotcpdump: Switch to patchelf to remove the RPATH
Stefan Schantl [Tue, 21 Mar 2023 19:09:35 +0000 (20:09 +0100)] 
tcpdump: Switch to patchelf to remove the RPATH

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agopatchelf: New package
Stefan Schantl [Tue, 21 Mar 2023 18:07:43 +0000 (19:07 +0100)] 
patchelf: New package

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agofilesystem: Make filesystem structure FHS compliant
Stefan Schantl [Mon, 20 Mar 2023 17:47:48 +0000 (18:47 +0100)] 
filesystem: Make filesystem structure FHS compliant

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agokernel: Proper build the helper binaries with our C and LDFLAGS
Stefan Schantl [Tue, 21 Mar 2023 10:20:16 +0000 (11:20 +0100)] 
kernel: Proper build the helper binaries with our C and LDFLAGS

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoliboping: Re-enable setting capabilities
Stefan Schantl [Mon, 20 Mar 2023 11:41:11 +0000 (12:41 +0100)] 
liboping: Re-enable setting capabilities

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoiputils: Re-enable setting capabilities
Stefan Schantl [Mon, 20 Mar 2023 11:40:19 +0000 (12:40 +0100)] 
iputils: Re-enable setting capabilities

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoutil-linux: Re-enable setting capabilities
Stefan Schantl [Mon, 20 Mar 2023 11:39:16 +0000 (12:39 +0100)] 
util-linux: Re-enable setting capabilities

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agonfs-utils: mount.nfs - Use capabilities instead of suid bit
Stefan Schantl [Mon, 20 Mar 2023 11:35:52 +0000 (12:35 +0100)] 
nfs-utils: mount.nfs - Use capabilities instead of suid bit

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoshadow-utils: Use capabilites and remove more unused binaries
Stefan Schantl [Mon, 20 Mar 2023 11:04:14 +0000 (12:04 +0100)] 
shadow-utils: Use capabilites and remove more unused binaries

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agounbound: Use /run instead of /var/run
Stefan Schantl [Mon, 20 Mar 2023 11:01:37 +0000 (12:01 +0100)] 
unbound: Use /run instead of /var/run

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoscreen: Make screen FHS compliant
Stefan Schantl [Mon, 20 Mar 2023 10:43:42 +0000 (11:43 +0100)] 
screen: Make screen FHS compliant

* Explicit use pam.
* Change socket dir to /run and add tmpfiles file.
* Only ship a simple screen binary without version
  fragments
* Remove SUID bit from binary

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agosudo: Fix library permissions
Stefan Schantl [Mon, 20 Mar 2023 10:31:49 +0000 (11:31 +0100)] 
sudo: Fix library permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agonetwork: Add patch to fix logdir
Stefan Schantl [Sun, 19 Mar 2023 15:02:04 +0000 (16:02 +0100)] 
network: Add patch to fix logdir

Add upstream patch to proper set the location
to the logdir.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoopenssh: Change privsep directory to /var/lib/sshd
Stefan Schantl [Sun, 19 Mar 2023 14:49:00 +0000 (15:49 +0100)] 
openssh: Change privsep directory to /var/lib/sshd

The old one /var/empty/sshd violated our FHS

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agosamba: Drop /var/run
Stefan Schantl [Sun, 19 Mar 2023 14:48:19 +0000 (15:48 +0100)] 
samba: Drop /var/run

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agounbound: Do not create /var/run
Stefan Schantl [Sun, 19 Mar 2023 14:19:41 +0000 (15:19 +0100)] 
unbound: Do not create /var/run

This violates our FHS specs.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agotcl: Fix library permissions
Stefan Schantl [Sun, 19 Mar 2023 14:13:54 +0000 (15:13 +0100)] 
tcl: Fix library permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agosssd: Use /var/lib/sss and drop /var/run
Stefan Schantl [Sun, 19 Mar 2023 14:01:44 +0000 (15:01 +0100)] 
sssd: Use /var/lib/sss and drop /var/run

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agosquid: Drop /var/run
Stefan Schantl [Sun, 19 Mar 2023 13:39:26 +0000 (14:39 +0100)] 
squid: Drop /var/run

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agosnort: Set correct permissions of helper script
Stefan Schantl [Sun, 19 Mar 2023 11:07:16 +0000 (12:07 +0100)] 
snort: Set correct permissions of helper script

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agospectre-meltdown-checker: Install binary with correct permissions
Stefan Schantl [Sun, 19 Mar 2023 10:43:19 +0000 (11:43 +0100)] 
spectre-meltdown-checker: Install binary with correct permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agopython3-pygobject3: Fix header file permissions
Stefan Schantl [Sun, 19 Mar 2023 10:36:03 +0000 (11:36 +0100)] 
python3-pygobject3: Fix header file permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agopython3-cairo: Fix header permissions
Stefan Schantl [Sun, 19 Mar 2023 10:26:55 +0000 (11:26 +0100)] 
python3-cairo: Fix header permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoppp: Fix binary permissions and drop deprecated dirs in /var
Stefan Schantl [Sun, 19 Mar 2023 10:25:03 +0000 (11:25 +0100)] 
ppp: Fix binary permissions and drop deprecated dirs in /var

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoplymouth: Drop /var/run
Stefan Schantl [Sun, 19 Mar 2023 10:16:49 +0000 (11:16 +0100)] 
plymouth: Drop /var/run

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-WWW-Curl: Fix library permissions
Stefan Schantl [Sun, 19 Mar 2023 10:09:57 +0000 (11:09 +0100)] 
perl-WWW-Curl: Fix library permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-WWW-Curl: Enable testsuite
Stefan Schantl [Sun, 19 Mar 2023 10:09:24 +0000 (11:09 +0100)] 
perl-WWW-Curl: Enable testsuite

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-XML-Parser: Fix library permissions
Stefan Schantl [Sun, 19 Mar 2023 10:07:39 +0000 (11:07 +0100)] 
perl-XML-Parser: Fix library permissions

* Also enable the testsuite
* Drop old fragment from QA

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-XML-Parser: Set correct perl dependencies
Stefan Schantl [Sun, 19 Mar 2023 10:06:31 +0000 (11:06 +0100)] 
perl-XML-Parser: Set correct perl dependencies

Do not longer use perl-core/perl-devel as build
dependencies.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-TermReadkey: Enable testsuite
Stefan Schantl [Sun, 19 Mar 2023 09:53:45 +0000 (10:53 +0100)] 
perl-TermReadkey: Enable testsuite

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-TermReadkey: Fix library permissions
Stefan Schantl [Sun, 19 Mar 2023 09:53:08 +0000 (10:53 +0100)] 
perl-TermReadkey: Fix library permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-SGMLSpm: Drop unneccessary perl script
Stefan Schantl [Sun, 19 Mar 2023 09:47:48 +0000 (10:47 +0100)] 
perl-SGMLSpm: Drop unneccessary perl script

We do not need this and it violates our FHS specs.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-Parse-Yapp: Fix library and binary permissions
Stefan Schantl [Sun, 19 Mar 2023 09:37:25 +0000 (10:37 +0100)] 
perl-Parse-Yapp: Fix library and binary permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-Net-SSLeay: Fix library permissions
Stefan Schantl [Sun, 19 Mar 2023 09:32:49 +0000 (10:32 +0100)] 
perl-Net-SSLeay: Fix library permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
2 years agoperl-libintl-perl: Fix library permissions
Stefan Schantl [Sun, 19 Mar 2023 09:31:06 +0000 (10:31 +0100)] 
perl-libintl-perl: Fix library permissions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>