]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
3 years agosamba: Remove socket options
Michael Tremer [Thu, 8 Oct 2020 15:48:16 +0000 (16:48 +0100)] 
samba: Remove socket options

It is not useful to set this on a modern server. The Linux
kernel will be tuning any send and receive buffer sizes.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: Remove deprecated syslog options
Michael Tremer [Thu, 8 Oct 2020 15:46:33 +0000 (16:46 +0100)] 
samba: Remove deprecated syslog options

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: Migrate older backups too and use standard update mechasism
Michael Tremer [Thu, 8 Oct 2020 15:40:24 +0000 (16:40 +0100)] 
samba: Migrate older backups too and use standard update mechasism

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: Migrate configuration from Samba 3.6 to 4.x
Michael Tremer [Thu, 8 Oct 2020 15:38:41 +0000 (16:38 +0100)] 
samba: Migrate configuration from Samba 3.6 to 4.x

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoMerge remote-tracking branch 'origin/master' into next
Michael Tremer [Mon, 12 Oct 2020 20:21:09 +0000 (20:21 +0000)] 
Merge remote-tracking branch 'origin/master' into next

3 years agotor: Bump release
Michael Tremer [Mon, 12 Oct 2020 10:15:59 +0000 (10:15 +0000)] 
tor: Bump release

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agotor.cgi: fix calling Perl location module functions
Peter Müller [Fri, 9 Oct 2020 19:20:32 +0000 (19:20 +0000)] 
tor.cgi: fix calling Perl location module functions

The second version of this patch avoids re-defining $db_handle.

Fixes: #12492
Cc: Stefan Schantl <stefan.schantl@ipfire.org
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-By: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore151: Remove multiple calls of rm
Michael Tremer [Mon, 12 Oct 2020 20:07:30 +0000 (20:07 +0000)] 
core151: Remove multiple calls of rm

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoupdate.sh: Delete obsolete files from Net-DNS 1.25
Matthias Fischer [Mon, 12 Oct 2020 18:28:31 +0000 (20:28 +0200)] 
update.sh: Delete obsolete files from Net-DNS 1.25

Fixes Bug #12491

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoen: Fix typo in "Port Scans"
Michael Tremer [Mon, 12 Oct 2020 10:28:50 +0000 (10:28 +0000)] 
en: Fix typo in "Port Scans"

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agofirewall hits graph: Fix order of values
Michael Tremer [Mon, 12 Oct 2020 10:27:15 +0000 (10:27 +0000)] 
firewall hits graph: Fix order of values

The fields were mixed up and therefore graph showed incorrect
values.

Fixes: #12496
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agotor: Bump release
Michael Tremer [Mon, 12 Oct 2020 10:15:59 +0000 (10:15 +0000)] 
tor: Bump release

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agotor.cgi: fix calling Perl location module functions
Peter Müller [Fri, 9 Oct 2020 19:20:32 +0000 (19:20 +0000)] 
tor.cgi: fix calling Perl location module functions

The second version of this patch avoids re-defining $db_handle.

Fixes: #12492
Cc: Stefan Schantl <stefan.schantl@ipfire.org
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-By: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agonano: Update to 5.3
Matthias Fischer [Sun, 11 Oct 2020 16:54:19 +0000 (18:54 +0200)] 
nano: Update to 5.3

For details see:
https://www.nano-editor.org/news.php

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore152: Ship knot
Michael Tremer [Mon, 12 Oct 2020 10:07:27 +0000 (10:07 +0000)] 
core152: Ship knot

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoknot: Update to 3.0.1
Matthias Fischer [Sun, 11 Oct 2020 16:50:24 +0000 (18:50 +0200)] 
knot: Update to 3.0.1

For details see:
https://www.knot-dns.cz/2020-10-10-version-301.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore152: Ship unbound
Michael Tremer [Mon, 12 Oct 2020 10:06:22 +0000 (10:06 +0000)] 
core152: Ship unbound

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agounbound: Update to 1.12.0
Matthias Fischer [Sun, 11 Oct 2020 16:44:46 +0000 (18:44 +0200)] 
unbound: Update to 1.12.0

For details see:
https://lists.nlnetlabs.nl/pipermail/unbound-users/2020-October/006979.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoMerge branch 'master' into next
Michael Tremer [Sat, 10 Oct 2020 11:49:07 +0000 (11:49 +0000)] 
Merge branch 'master' into next

3 years agocore151: Apply local SSH configuration
Michael Tremer [Sat, 10 Oct 2020 11:48:26 +0000 (11:48 +0000)] 
core151: Apply local SSH configuration

Fixes: #12494
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore151: Ship /etc/os-release
Michael Tremer [Sat, 10 Oct 2020 11:43:44 +0000 (11:43 +0000)] 
core151: Ship /etc/os-release

Fixes: #12495
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoborgbackup: Bump release
Michael Tremer [Sat, 10 Oct 2020 11:42:37 +0000 (11:42 +0000)] 
borgbackup: Bump release

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoBorgbackup: Ship testsuite also for i586 and armv5tel
Jonatan Schlag [Sat, 10 Oct 2020 07:29:07 +0000 (07:29 +0000)] 
Borgbackup: Ship testsuite also for i586 and armv5tel

Fixes: #12438
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore152: Fix typo in rootfile
Michael Tremer [Wed, 7 Oct 2020 14:27:29 +0000 (14:27 +0000)] 
core152: Fix typo in rootfile

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years ago/var/ipfire/ethernet/settings: Drop BROADCAST variable
Michael Tremer [Wed, 7 Oct 2020 11:46:46 +0000 (11:46 +0000)] 
/var/ipfire/ethernet/settings: Drop BROADCAST variable

This variable is no longer being used and was only used to
assign IP addresses to the individual interfaces.

However, the kernel knows best which IP address to select
as broadcast address for each network. Therefore we depend
on the kernel which allows us to support RFC3021.

Fixes: #12486 - no /31 transfer net available on red
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: Link against avahi
Michael Tremer [Wed, 7 Oct 2020 08:09:36 +0000 (08:09 +0000)] 
samba: Link against avahi

We should use avahi to announce file sharing services to
the network using mDNS, too.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoavahi: Disable custom stack protector configuration
Michael Tremer [Wed, 7 Oct 2020 08:04:38 +0000 (08:04 +0000)] 
avahi: Disable custom stack protector configuration

We already pass -fstack-protector-strong, which might be overridden
by -fstack-protector-all. We also know that SSP works in our version
of libc and do not need to link against libssp.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibtalloc: Move to /usr and drop Python module
Michael Tremer [Tue, 6 Oct 2020 16:35:26 +0000 (16:35 +0000)] 
libtalloc: Move to /usr and drop Python module

We do not use the Python module and can therefore
only have one rootfile for all architectures.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3: Rootfile update for i586
Michael Tremer [Tue, 6 Oct 2020 16:21:09 +0000 (16:21 +0000)] 
python3: Rootfile update for i586

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3: Update rootfile for armv5tel
Michael Tremer [Tue, 6 Oct 2020 15:13:54 +0000 (15:13 +0000)] 
python3: Update rootfile for armv5tel

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoRevert "core152: Load changed /etc/sysctl.conf"
Michael Tremer [Tue, 6 Oct 2020 12:26:43 +0000 (12:26 +0000)] 
Revert "core152: Load changed /etc/sysctl.conf"

This reverts commit b125988d3fe0e9f9ac231bf821e59365cf74f268.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoRevert "sysctl.conf: prevent autoloading of TTY line disciplines"
Michael Tremer [Tue, 6 Oct 2020 12:26:26 +0000 (12:26 +0000)] 
Revert "sysctl.conf: prevent autoloading of TTY line disciplines"

This reverts commit 14c65ab71ccbe3b0810ac6986d6ad02486f9f9a4.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibtalloc: add new package because samba4 not provide this anymore
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:11 +0000 (22:17 +0200)] 
libtalloc: add new package because samba4 not provide this anymore

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: update to 4.13.0
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:10 +0000 (22:17 +0200)] 
samba: update to 4.13.0

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: remove SO_xxxBUF size definitions from default config
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:09 +0000 (22:17 +0200)] 
samba: remove SO_xxxBUF size definitions from default config

this option is not recommended for samba4

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agorpcsvc-proto: build before samba
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:08 +0000 (22:17 +0200)] 
rpcsvc-proto: build before samba

samba4 depends on this package

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoperl-Parse-Yapp: add package
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:07 +0000 (22:17 +0200)] 
perl-Parse-Yapp: add package

samba4 depends on this perl module

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba initskript: create needed subdirs for pipes in /var/run/samba
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:06 +0000 (22:17 +0200)] 
samba initskript: create needed subdirs for pipes in /var/run/samba

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: default.global: remove unsuppoted "map to guest = false"
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:05 +0000 (22:17 +0200)] 
samba: default.global: remove unsuppoted "map to guest = false"

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba.cgi: remove unsupported DISPLAY CHARSET
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:04 +0000 (22:17 +0200)] 
samba.cgi: remove unsupported DISPLAY CHARSET

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba.cgi: remove unsupported security = share
Arne Fitzenreiter [Mon, 5 Oct 2020 20:17:03 +0000 (22:17 +0200)] 
samba.cgi: remove unsupported security = share

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore152: Ship Python 3
Michael Tremer [Tue, 6 Oct 2020 12:16:46 +0000 (12:16 +0000)] 
core152: Ship Python 3

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoPython3: update to 3.8.2
Peter Müller [Sat, 2 May 2020 19:57:54 +0000 (21:57 +0200)] 
Python3: update to 3.8.2

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-botocore: update to 1.16.1
Peter Müller [Sun, 3 May 2020 10:02:27 +0000 (12:02 +0200)] 
python3-botocore: update to 1.16.1

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-colorama: update to 0.4.3
Peter Müller [Sun, 3 May 2020 10:04:50 +0000 (12:04 +0200)] 
python3-colorama: update to 0.4.3

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-dateutil: update to 2.8.1
Peter Müller [Sun, 3 May 2020 10:07:33 +0000 (12:07 +0200)] 
python3-dateutil: update to 2.8.1

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-docutils: update to 0.16
Peter Müller [Sun, 3 May 2020 10:09:49 +0000 (12:09 +0200)] 
python3-docutils: update to 0.16

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-jmespath: update to 0.9.5
Peter Müller [Sun, 3 May 2020 10:11:19 +0000 (12:11 +0200)] 
python3-jmespath: update to 0.9.5

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-pyasn1: update to 0.4.8
Peter Müller [Sun, 3 May 2020 10:15:45 +0000 (12:15 +0200)] 
python3-pyasn1: update to 0.4.8

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-rsa: update to 4.0
Peter Müller [Sun, 3 May 2020 10:17:51 +0000 (12:17 +0200)] 
python3-rsa: update to 4.0

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-s3transfer: update to 0.3.3
Peter Müller [Sun, 3 May 2020 10:19:21 +0000 (12:19 +0200)] 
python3-s3transfer: update to 0.3.3

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-six: update to 1.14.0
Peter Müller [Sun, 3 May 2020 10:23:55 +0000 (12:23 +0200)] 
python3-six: update to 1.14.0

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore152: Ship Python
Michael Tremer [Tue, 6 Oct 2020 12:09:07 +0000 (12:09 +0000)] 
core152: Ship Python

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython: update to 2.7.18
Arne Fitzenreiter [Sat, 12 Sep 2020 21:46:34 +0000 (23:46 +0200)] 
python: update to 2.7.18

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore152: Load changed /etc/sysctl.conf
Michael Tremer [Tue, 6 Oct 2020 12:05:11 +0000 (12:05 +0000)] 
core152: Load changed /etc/sysctl.conf

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosysctl.conf: prevent autoloading of TTY line disciplines
Peter Müller [Mon, 5 Oct 2020 19:45:31 +0000 (19:45 +0000)] 
sysctl.conf: prevent autoloading of TTY line disciplines

Malicious/vulnerable TTY line disciplines have been subject of some
kernel exploits such as CVE-2017-2636, and since - to put it in Greg
Kroah-Hatrman's words - we do not "trust the userspace to do the right
thing", this reduces local kernel attack surface.

Further, there is no legitimate reason why an unprivileged user should
load kernel modules during runtime, anyway.

See also:
- https://lkml.org/lkml/2019/4/15/890
- https://a13xp0p0v.github.io/2017/03/24/CVE-2017-2636.html

Cc: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org>
Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoStart Core Update 152
Michael Tremer [Tue, 6 Oct 2020 12:03:34 +0000 (12:03 +0000)] 
Start Core Update 152

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoMerge branch 'next'
Arne Fitzenreiter [Mon, 5 Oct 2020 20:24:35 +0000 (20:24 +0000)] 
Merge branch 'next'

3 years agosysctl.conf: prevent unintentional writes into attacker-controlled files and FIFOs
Peter Müller [Mon, 5 Oct 2020 14:12:18 +0000 (14:12 +0000)] 
sysctl.conf: prevent unintentional writes into attacker-controlled files and FIFOs

Similar to hard- and symlink protection introduced a while ago, this
patch enables protections against unintentional writes into
attacker-controlled regular files or FIFOs, where a program expected to
create new ones. This makes exploiting TOCTOU flaws harder.

See also: https://www.kernel.org/doc/Documentation/sysctl/fs.txt

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agofreeradius: Update to version 3.0.21
Erik Kapfer [Thu, 1 Oct 2020 13:19:22 +0000 (15:19 +0200)] 
freeradius: Update to version 3.0.21

Update includes several fixes (incl. CVE-2019-17185) and feature improvements.
A full overview of all changes can be found in here --> https://raw.githubusercontent.com/FreeRADIUS/freeradius-server/v3.0.x/doc/ChangeLog .

The freeradius-no-buildtime-cert-gen patch applies also with this version.

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolynis: Update to version 3.0.0
Erik Kapfer [Thu, 1 Oct 2020 12:45:48 +0000 (14:45 +0200)] 
lynis: Update to version 3.0.0

Several Fixes (incl. CVE-2019-13033 and CVE-2020-13882) and features has been added since the last version 2.6.4 .
For a full overview of the changes take a look in here --> https://cisofy.com/changelog/lynis/ .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibsolv: Update to version 0.7.14
Erik Kapfer [Thu, 1 Oct 2020 12:37:14 +0000 (14:37 +0200)] 
libsolv: Update to version 0.7.14

Several fixes and features has been added.
A full overview of all changes can be found in here --> https://github.com/openSUSE/libsolv/blob/master/package/libsolv.changes .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agohaproxy: Update to 2.2.4
Michael Tremer [Thu, 1 Oct 2020 09:30:48 +0000 (09:30 +0000)] 
haproxy: Update to 2.2.4

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agodnsdist: Update to 1.5.1
Michael Tremer [Thu, 1 Oct 2020 09:20:48 +0000 (09:20 +0000)] 
dnsdist: Update to 1.5.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore151: Ship & load /etc/sysctl.conf
Michael Tremer [Wed, 30 Sep 2020 17:16:12 +0000 (17:16 +0000)] 
core151: Ship & load /etc/sysctl.conf

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosysctl.conf: drop RST packets for sockets in TIME-WAIT state
Peter Müller [Wed, 30 Sep 2020 14:46:07 +0000 (14:46 +0000)] 
sysctl.conf: drop RST packets for sockets in TIME-WAIT state

RFC 1337 describes various TCP (side channel) attacks against
prematurely closed connections stalling in TIME-WAIT state, such as DoS
or injecting arbitrary TCP segments, and recommends to silently discard
RST packets for sockets in this state.

While applications still tied to such sockets should tolerate invalid
input (thanks to Jon Postel), there is little legitimate reason to send
such RST packets altogether.

At the time of writing, no collateral damage related to active RFC 1337
implementations is known. Measuerements in productive environments did
not reveal any side effects either, which is why I consider enabling RFC
1337 implementation to be a safe change.

See also: https://tools.ietf.org/html/rfc1337

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agostunnel: Package /var/lib/stunnel
Michael Tremer [Wed, 30 Sep 2020 17:10:39 +0000 (17:10 +0000)] 
stunnel: Package /var/lib/stunnel

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agostunnel: Update to version 5.56
Erik Kapfer [Wed, 30 Sep 2020 13:06:07 +0000 (15:06 +0200)] 
stunnel: Update to version 5.56

The version jump from 5.44 to 5.56 includes several 'LOW' and 'HIGH' urgent bugfixes which are also secure relevant.
A full overview of fixes and new features can be found in here --> https://www.stunnel.org/NEWS.html .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agokeepalived: Update to version 2.1.5
Erik Kapfer [Wed, 30 Sep 2020 13:18:49 +0000 (15:18 +0200)] 
keepalived: Update to version 2.1.5

The version jump from 2.0.20 to 2.1.5 includes several improvemnts and fixes.
The release notes can be overviewed in here --> https://www.keepalived.org/release-notes/Release-2.1.4.html .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoUpdate contributors
Michael Tremer [Wed, 30 Sep 2020 10:30:14 +0000 (10:30 +0000)] 
Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoUpdate French translation
Stéphane Pautrel [Wed, 30 Sep 2020 10:26:33 +0000 (10:26 +0000)] 
Update French translation

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore151: Ship OpenSSH
Michael Tremer [Wed, 30 Sep 2020 10:01:37 +0000 (10:01 +0000)] 
core151: Ship OpenSSH

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoopenssh: Update to 8.4p1
Adolf Belka [Tue, 29 Sep 2020 07:21:30 +0000 (09:21 +0200)] 
openssh: Update to 8.4p1

- Update openssh from version 8.3p1 to 8.4p1
See https://www.openssh.com/releasenotes.html
See https://www.openssh.com/portable.html#http for mirrors for source file
- No change to rootfiles
- Installed on virtual ipfire testbed and ssh connection successfully operated
Signed-off-by: Adolf Belka <ahb.ipfire@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agobacula: Update to 9.6.6
Adolf Belka [Tue, 29 Sep 2020 18:48:05 +0000 (20:48 +0200)] 
bacula: Update to 9.6.6

- Update bacula from version 9.6.5 to 9.6.6
This is a minor bug release
See https://sourceforge.net/projects/bacula/files/bacula/9.6.6/ReleaseNotes/
Source file available at https://sourceforge.net/projects/bacula/files/bacula/9.6.6/bacula-9.6.6.tar.gz
Signed-off-by: Adolf Belka <ahb.ipfire@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agobacula: Update to backup/includes definition
Adolf Belka [Tue, 29 Sep 2020 18:48:29 +0000 (20:48 +0200)] 
bacula: Update to backup/includes definition

- Modified backup/includes file to backup the /var/bacula/working directory contents
rather than explicitly naming the state filename.
State filename could be varied if user modifies the port number for the file daemon
as the port number is part of the state filename
Signed-off-by: Adolf Belka <ahb.ipfire@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoiptraf-ng: Update to version 1.2.1
Erik Kapfer [Tue, 29 Sep 2020 08:45:27 +0000 (10:45 +0200)] 
iptraf-ng: Update to version 1.2.1

Update includes several fixes and enhancements.
The full overview of changes are located in here --> https://github.com/iptraf-ng/iptraf-ng/blob/master/CHANGES .

rvnamed has been merged into iptraf-ng. Fix division by zero patch has been merged into new version, patch is not needed anymore. logrotate configuration for iptraf-ng has been included.

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agonginx: Update to version 1.19.2
Erik Kapfer [Tue, 29 Sep 2020 08:53:21 +0000 (10:53 +0200)] 
nginx: Update to version 1.19.2

Several bugfixes and features has been integrated since version 1.17.8.
A full overview of all changes are located in here --> https://github.com/nginx/nginx-releases/blob/master/CHANGES .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agogit: Update to version 2.28.0
Erik Kapfer [Tue, 29 Sep 2020 09:17:33 +0000 (11:17 +0200)] 
git: Update to version 2.28.0

Several changes s been made since version 2.12.2 .
The documentation RelNotes of Git can be found in here --> https://github.com/git/git/tree/master/Documentation/RelNotes .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agonetother.cgi: Fix typo in Connection Tracking headline
Michael Tremer [Tue, 29 Sep 2020 13:49:59 +0000 (13:49 +0000)] 
netother.cgi: Fix typo in Connection Tracking headline

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoexoscale: Fix assigning domain name
Michael Tremer [Tue, 29 Sep 2020 13:47:09 +0000 (13:47 +0000)] 
exoscale: Fix assigning domain name

The whole hostname was used as domain name because there
was no . in it where the string could have been split.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoqpdf: Tell configure to use our CFLAGS/LDFLAGS
Michael Tremer [Tue, 29 Sep 2020 12:27:20 +0000 (12:27 +0000)] 
qpdf: Tell configure to use our CFLAGS/LDFLAGS

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore151: Ship exoscale files
Michael Tremer [Tue, 29 Sep 2020 08:28:23 +0000 (08:28 +0000)] 
core151: Ship exoscale files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoMerge remote-tracking branch 'ms/exoscale' into next
Michael Tremer [Tue, 29 Sep 2020 08:22:58 +0000 (08:22 +0000)] 
Merge remote-tracking branch 'ms/exoscale' into next

3 years agocore151: Link to individual rootfiles for boost for each arch
Michael Tremer [Tue, 29 Sep 2020 08:22:32 +0000 (08:22 +0000)] 
core151: Link to individual rootfiles for boost for each arch

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agobinutils: Update to 2.35.1
Michael Tremer [Tue, 29 Sep 2020 08:21:08 +0000 (08:21 +0000)] 
binutils: Update to 2.35.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoexoscale: Get SSH key from meta-data API
Michael Tremer [Tue, 29 Sep 2020 08:05:44 +0000 (08:05 +0000)] 
exoscale: Get SSH key from meta-data API

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoboost: Add rootfile for armv5tel
Michael Tremer [Tue, 29 Sep 2020 07:59:46 +0000 (07:59 +0000)] 
boost: Add rootfile for armv5tel

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoqpdf: Link against libatomic on armv5tel
Michael Tremer [Tue, 29 Sep 2020 07:55:38 +0000 (07:55 +0000)] 
qpdf: Link against libatomic on armv5tel

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocredits.cgi: update contributors core150 v2.25-core150
Arne Fitzenreiter [Mon, 28 Sep 2020 10:27:24 +0000 (10:27 +0000)] 
credits.cgi: update contributors

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoShip testsuite of BorgBackup
Jonatan Schlag [Sat, 26 Sep 2020 07:19:58 +0000 (07:19 +0000)] 
Ship testsuite of BorgBackup

BorgBackup seems to need this testsuite on all systems, because it does
some selftests when starting a backup.

Fixes: #12438
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocmake: Update to 3.18.3
Matthias Fischer [Sun, 27 Sep 2020 08:42:01 +0000 (10:42 +0200)] 
cmake: Update to 3.18.3

For details see:
https://cmake.org/cmake/help/v3.18/release/3.18.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosetup: Remove tampering with MAC addresses
Michael Tremer [Sun, 27 Sep 2020 11:19:56 +0000 (11:19 +0000)] 
setup: Remove tampering with MAC addresses

There are NICs with 06: and we cannot simply replace the
first byte of the address.

I have no idea why this hack is needed and I believe we
do not need it at all.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoexoscale: Add cloud setup script
Michael Tremer [Fri, 25 Sep 2020 16:08:46 +0000 (16:08 +0000)] 
exoscale: Add cloud setup script

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocloud-init: Extend to support Exoscale
Michael Tremer [Fri, 25 Sep 2020 10:37:06 +0000 (10:37 +0000)] 
cloud-init: Extend to support Exoscale

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agonetsnmpd: Disable parallel build
Michael Tremer [Fri, 25 Sep 2020 08:41:46 +0000 (08:41 +0000)] 
netsnmpd: Disable parallel build

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoboost: Add rootfile for i586
Michael Tremer [Fri, 25 Sep 2020 08:35:24 +0000 (08:35 +0000)] 
boost: Add rootfile for i586

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoboost: Move x86_64 rootfile to arch subdir
Michael Tremer [Fri, 25 Sep 2020 08:34:57 +0000 (08:34 +0000)] 
boost: Move x86_64 rootfile to arch subdir

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoboost: Update rootfile for aarch64
Michael Tremer [Fri, 25 Sep 2020 08:31:19 +0000 (08:31 +0000)] 
boost: Update rootfile for aarch64

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoUpdate list of contributors
Michael Tremer [Thu, 24 Sep 2020 17:48:27 +0000 (17:48 +0000)] 
Update list of contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoRevert "core151: Ship libloc"
Michael Tremer [Thu, 24 Sep 2020 17:43:10 +0000 (17:43 +0000)] 
Revert "core151: Ship libloc"

This reverts commit 6cfa52d99e19dfcba47c7aca25ce0a38ec4ab25d.

libloc is now being updated in Core Update 150.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>