]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
3 years agodracut: add hyperv-keyboard module to initrd.
Arne Fitzenreiter [Wed, 16 Dec 2020 15:22:02 +0000 (16:22 +0100)] 
dracut: add hyperv-keyboard module to initrd.

the missing module should be the reason for not responding setup on some
hyper-v configurations.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoMerge branch 'master' into next
Michael Tremer [Wed, 16 Dec 2020 10:33:36 +0000 (10:33 +0000)] 
Merge branch 'master' into next

3 years agoUpdate contributors core153
Michael Tremer [Wed, 16 Dec 2020 10:33:23 +0000 (10:33 +0000)] 
Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agokernel: update to 4.14.212
Arne Fitzenreiter [Wed, 16 Dec 2020 06:33:57 +0000 (07:33 +0100)] 
kernel: update to 4.14.212

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibhtp: Update to 0.5.36
Matthias Fischer [Sat, 12 Dec 2020 09:18:30 +0000 (10:18 +0100)] 
libhtp: Update to 0.5.36

For details see:
https://github.com/OISF/libhtp/releases

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosuricata: Downgrade to 5.0.5
Matthias Fischer [Sat, 12 Dec 2020 09:14:35 +0000 (10:14 +0100)] 
suricata: Downgrade to 5.0.5

Triggered by https://lists.ipfire.org/pipermail/development/2020-December/008868.html

Workaround for https://bugzilla.ipfire.org/show_bug.cgi?id=12548

Downgrading to 'suricata 5.0.5' bypasses Bug #12548 for now,
but its only a temporary workaround...

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore154: Ship libhtp
Michael Tremer [Mon, 14 Dec 2020 09:35:37 +0000 (09:35 +0000)] 
core154: Ship libhtp

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibhtp: Update to 0.5.36
Matthias Fischer [Sat, 12 Dec 2020 09:18:30 +0000 (10:18 +0100)] 
libhtp: Update to 0.5.36

For details see:
https://github.com/OISF/libhtp/releases

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoshairport-sync: Update to 3.3.7
Michael Tremer [Thu, 10 Dec 2020 13:18:26 +0000 (13:18 +0000)] 
shairport-sync: Update to 3.3.7

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore154: Ship PAM
Michael Tremer [Thu, 10 Dec 2020 13:04:38 +0000 (13:04 +0000)] 
core154: Ship PAM

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoPam: Update to version 1.5.1
ummeegge [Sun, 6 Dec 2020 10:08:59 +0000 (10:08 +0000)] 
Pam: Update to version 1.5.1

Several fixes and improvements since the current available 1.3.1 version are included.
CVE-2020-27780 has also been fixed.
For a full release overview --> https://github.com/linux-pam/linux-pam/releases .

Signed-off-by: ummeegge <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore154: Ship unbound
Michael Tremer [Thu, 10 Dec 2020 13:02:43 +0000 (13:02 +0000)] 
core154: Ship unbound

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agounbound: Update to 1.13.0
Matthias Fischer [Sun, 6 Dec 2020 09:43:54 +0000 (10:43 +0100)] 
unbound: Update to 1.13.0

For details see:
https://lists.nlnetlabs.nl/pipermail/unbound-users/2020-December/007102.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore154: Ship dhcpcd
Michael Tremer [Thu, 10 Dec 2020 13:01:45 +0000 (13:01 +0000)] 
core154: Ship dhcpcd

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agodhcpcd: Update to 9.3.4
Matthias Fischer [Sun, 6 Dec 2020 09:39:05 +0000 (10:39 +0100)] 
dhcpcd: Update to 9.3.4

For details see:
https://roy.marples.name/blog/dhcpcd-9-3-4-released.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore154: Ship bind
Michael Tremer [Thu, 10 Dec 2020 13:00:51 +0000 (13:00 +0000)] 
core154: Ship bind

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agobind: Update to 9.11.25
Matthias Fischer [Sun, 6 Dec 2020 09:34:07 +0000 (10:34 +0100)] 
bind: Update to 9.11.25

For details see:
https://downloads.isc.org/isc/bind9/9.11.25/RELEASE-NOTES-bind-9.11.25.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore154: Ship services.cgi
Michael Tremer [Thu, 10 Dec 2020 13:00:06 +0000 (13:00 +0000)] 
core154: Ship services.cgi

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoFix for bug 12539
Adolf Belka [Mon, 7 Dec 2020 14:01:36 +0000 (15:01 +0100)] 
Fix for bug 12539

The installer recognises cups and cups-filters both as cups and puts
two instances of cups in the add-on services table.
Based on input from Michael Tremer this patch replaces the command
returning the second element between hyphens with one that takes
what comes after "meta-" using Perl code rather than a shell command.
The second find command was changed as per Michael's suggestion.

Tested in my ipfire test bed system and only results in one cups
entry.
Signed-off-by: Adolf Belka <ahb.ipfire@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agokerberos: Update to version 1.18.3
ummeegge [Mon, 7 Dec 2020 14:23:05 +0000 (14:23 +0000)] 
kerberos: Update to version 1.18.3

Since version 1.15.2 several fixes and enhancements has been introduced.
For a full overview the release notes can be found in the next lines.

https://web.mit.edu/kerberos/krb5-1.16/
https://web.mit.edu/kerberos/krb5-1.17/
https://web.mit.edu/kerberos/krb5-1.18/

Signed-off-by: ummeegge <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agotshark: Update to version 3.4.0
ummeegge [Sun, 6 Dec 2020 15:03:45 +0000 (15:03 +0000)] 
tshark: Update to version 3.4.0

- Since tshark uses since 3.4.0 an always enabled asynchronous DNS
resolution, c-ares is a needed dependency.
- Since the current actual version 3.2.6 a lot of bug fixes, fixed
vulnerabilities, updated features, new protocols but also updated
protocols has been integrated.
A full overview of all changes can be found in here -->
Update to version 3.2.7:
https://www.wireshark.org/docs/relnotes/wireshark-3.2.7.html
Update to version 3.2.8:
https://www.wireshark.org/docs/relnotes/wireshark-3.2.8.html
Update to version 3.4.0
https://www.wireshark.org/docs/relnotes/wireshark-3.4.0.html

Signed-off-by: ummeegge <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoc-ares: New package. Needed as tshark Dependency
ummeegge [Sun, 6 Dec 2020 15:03:44 +0000 (15:03 +0000)] 
c-ares: New package. Needed as tshark Dependency

- Since tshark uses with version 3.4.0 an always enabled asynchronous DNS
resolution c-ares is a needed dependency.
- Since curl can also use c-ares --> https://c-ares.haxx.se/ it has been
placed in make.sh before curl even no compiletime options has been set
to enable this. c-ares has also been placed in packages and not in common
which would be needed if it should be used for curl too.

Signed-off-by: ummeegge <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agonano: Update to 5.4
Matthias Fischer [Sun, 6 Dec 2020 09:46:36 +0000 (10:46 +0100)] 
nano: Update to 5.4

For details see:
https://www.nano-editor.org/news.php

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agomonit: Update to 5.27.1
Matthias Fischer [Sat, 5 Dec 2020 23:26:21 +0000 (00:26 +0100)] 
monit: Update to 5.27.1

For details see:
https://mmonit.com/monit/changes/

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agobacula: Update to use IPFire initscript
Adolf Belka [Sat, 5 Dec 2020 14:51:11 +0000 (15:51 +0100)] 
bacula: Update to use IPFire initscript

Bacula install used the bacula initscript for starting and stopping bacula.
This works fine but results in no pid or memory input in the addons table
under services.
Using the IPFire initscript also successfully starts and stops bacula with
no problems but also provides the pid and memory information in the services
addons table.
- rootfiles adjusted to remove the reference to bacula-ctl-fd
- lfs/bacula adjusted to remove the init.d/bacula link generation
             remove the "rm -f /root/.rnd" command. This file is not present
             and I have not seen this command in any other lfs file that I
             have looked at.
- new bacula initscript created

Signed-off-by: Adolf Belka <ahb.ipfire@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoStart Core Update 154
Michael Tremer [Thu, 10 Dec 2020 12:28:12 +0000 (12:28 +0000)] 
Start Core Update 154

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore153: add ddns.cgi to update
Arne Fitzenreiter [Tue, 8 Dec 2020 17:40:57 +0000 (17:40 +0000)] 
core153: add ddns.cgi to update

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoddns.cgi: Drop static provider list for token based auth.
Stefan Schantl [Wed, 2 Dec 2020 11:30:11 +0000 (12:30 +0100)] 
ddns.cgi: Drop static provider list for token based auth.

This is really hard to maintain when adding new or altering existing
providers.

Reference #12415.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore153: add openssl to updater
Arne Fitzenreiter [Tue, 8 Dec 2020 17:33:47 +0000 (18:33 +0100)] 
core153: add openssl to updater

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoopenssl: update to 1.1.1i
Arne Fitzenreiter [Tue, 8 Dec 2020 17:27:00 +0000 (18:27 +0100)] 
openssl: update to 1.1.1i

fix: EDIPARTYNAME NULL pointer de-reference (CVE-2020-1971)

Severity: High

The X.509 GeneralName type is a generic type for representing different types
of names. One of those name types is known as EDIPartyName. OpenSSL provides a
function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME
to see if they are equal or not. This function behaves incorrectly when both
GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash
may occur leading to a possible denial of service attack.

OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes:
1) Comparing CRL distribution point names between an available CRL and a CRL
   distribution point embedded in an X509 certificate
2) When verifying that a timestamp response token signer matches the timestamp
   authority name (exposed via the API functions TS_RESP_verify_response and
   TS_RESP_verify_token)

If an attacker can control both items being compared then that attacker could
trigger a crash. For example if the attacker can trick a client or server into
checking a malicious certificate against a malicious CRL then this may occur.
Note that some applications automatically download CRLs based on a URL embedded
in a certificate. This checking happens prior to the signatures on the
certificate and CRL being verified. OpenSSL's s_server, s_client and verify
tools have support for the "-crl_download" option which implements automatic
CRL downloading and this attack has been demonstrated to work against those
tools.

Note that an unrelated bug means that affected versions of OpenSSL cannot parse
or construct correct encodings of EDIPARTYNAME. However it is possible to
construct a malformed EDIPARTYNAME that OpenSSL's parser will accept and hence
trigger this attack.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agokernel: update to 4.14.211
Arne Fitzenreiter [Tue, 8 Dec 2020 17:26:37 +0000 (18:26 +0100)] 
kernel: update to 4.14.211

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agovdr: version 2.4.4 still use plugin API 2.4.3
Arne Fitzenreiter [Sat, 5 Dec 2020 10:09:03 +0000 (10:09 +0000)] 
vdr: version 2.4.4 still use plugin API 2.4.3

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoMerge branch 'next' into master
Arne Fitzenreiter [Thu, 3 Dec 2020 12:55:36 +0000 (12:55 +0000)] 
Merge branch 'next' into master

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agorootfile-check: exclude gdb
Arne Fitzenreiter [Thu, 3 Dec 2020 06:50:41 +0000 (07:50 +0100)] 
rootfile-check: exclude gdb

gdb always contain aarch64 in a syscall list.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Wed, 2 Dec 2020 22:43:15 +0000 (23:43 +0100)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next

3 years agointel-microcode: update to 20201118
Arne Fitzenreiter [Wed, 2 Dec 2020 22:42:29 +0000 (23:42 +0100)] 
intel-microcode: update to 20201118

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agokernel: update to 4.14.210
Arne Fitzenreiter [Wed, 2 Dec 2020 22:42:04 +0000 (23:42 +0100)] 
kernel: update to 4.14.210

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoaws-cli: Update to 1.18.188
Michael Tremer [Wed, 2 Dec 2020 17:55:51 +0000 (17:55 +0000)] 
aws-cli: Update to 1.18.188

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-botocore: Update to 1.19.28
Michael Tremer [Wed, 2 Dec 2020 17:55:22 +0000 (17:55 +0000)] 
python3-botocore: Update to 1.19.28

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopython3-urllib3: New package
Michael Tremer [Wed, 2 Dec 2020 17:54:32 +0000 (17:54 +0000)] 
python3-urllib3: New package

Required by botocore

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore153: Ship DDNS
Michael Tremer [Wed, 2 Dec 2020 14:57:17 +0000 (14:57 +0000)] 
core153: Ship DDNS

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoddns: Import upstream patch for provider DuckDNS.
Stefan Schantl [Wed, 2 Dec 2020 11:33:22 +0000 (12:33 +0100)] 
ddns: Import upstream patch for provider DuckDNS.

Fixes #12415.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoddns: Import upstream patch for provider DDNSS.
Stefan Schantl [Wed, 2 Dec 2020 09:13:52 +0000 (10:13 +0100)] 
ddns: Import upstream patch for provider DDNSS.

Fixes #12328.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agotor.cgi: fix location function call again
Peter Müller [Tue, 1 Dec 2020 21:45:43 +0000 (21:45 +0000)] 
tor.cgi: fix location function call again

This line was accidentially messed up while merging two patchsets
together, causing tor.cgi to crash with an HTTP error 500 in testing.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolocation-functions.pl: Remove accidently keept 2nd DB init call.
Stefan Schantl [Wed, 2 Dec 2020 14:04:08 +0000 (15:04 +0100)] 
location-functions.pl: Remove accidently keept 2nd DB init call.

The get_full_country_name() function had an accidenlty and not longer
required call of the DB init function.

This is a waste of memory and a known problem, especially on systems
with less than 1GB of RAM, where the application which uses libloc in
such a redundant way crashes.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibloc: Import latest fixes from upstream
Michael Tremer [Tue, 1 Dec 2020 17:05:43 +0000 (17:05 +0000)] 
libloc: Import latest fixes from upstream

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoRevert "OpenVPN: Add start of static routes in client N2N"
Michael Tremer [Tue, 1 Dec 2020 16:32:03 +0000 (16:32 +0000)] 
Revert "OpenVPN: Add start of static routes in client N2N"

This reverts commit 1c612d9e326a477bb1cbad719702c51c35f11d62.

https://lists.ipfire.org/pipermail/development/2020-November/008773.html

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoCore 153: Update ownership of "/var/ipfire/red".
Stefan Schantl [Sun, 29 Nov 2020 10:52:18 +0000 (11:52 +0100)] 
Core 153: Update ownership of "/var/ipfire/red".

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoconfigroot: Change ownership of "/var/ipfire/red" to nobody.
Stefan Schantl [Sun, 29 Nov 2020 10:52:17 +0000 (11:52 +0100)] 
configroot: Change ownership of "/var/ipfire/red" to nobody.

Otherwise the WUI is not allowed to put and release the nobeep file in
this folder and the desired functionality does not work.

Fixes #12385.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore153: Ship openvpn
Michael Tremer [Tue, 1 Dec 2020 16:12:43 +0000 (16:12 +0000)] 
core153: Ship openvpn

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoOpenVPN: Update to version 2.5.0
Erik Kapfer [Wed, 25 Nov 2020 22:26:03 +0000 (22:26 +0000)] 
OpenVPN: Update to version 2.5.0

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Tested-by: Adolf Belka <ahb.ipfire@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agologwatch: Disable iptables output in summary.dat, fixes #12533
Matthias Fischer [Thu, 26 Nov 2020 18:27:33 +0000 (19:27 +0100)] 
logwatch: Disable iptables output in summary.dat, fixes #12533

This patch disables the output of 'iptables' in 'summary.dat' by
modifying '/usr/share/conf/logwatch.conf'.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore153: Ship knot
Michael Tremer [Fri, 27 Nov 2020 15:50:49 +0000 (15:50 +0000)] 
core153: Ship knot

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoknot: Update to 3.0.2
Matthias Fischer [Thu, 26 Nov 2020 17:36:53 +0000 (18:36 +0100)] 
knot: Update to 3.0.2

for details see:
https://www.knot-dns.cz/2020-11-11-version-302.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoghostscript: Update to 9.53.3
Matthias Fischer [Thu, 26 Nov 2020 17:34:23 +0000 (18:34 +0100)] 
ghostscript: Update to 9.53.3

For details see:
https://www.ghostscript.com/doc/current/History9.htm#Version9.53.3

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore153: Ship updated zone configuration page
Michael Tremer [Fri, 27 Nov 2020 15:49:03 +0000 (15:49 +0000)] 
core153: Ship updated zone configuration page

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agozoneconf.cgi: Add NIC selection highlighting
Leo-Andres Hofmann [Tue, 17 Nov 2020 06:29:04 +0000 (07:29 +0100)] 
zoneconf.cgi: Add NIC selection highlighting

This improves the usability of the zone configuration by marking assigned
NICs in the zone color. The highlighting is initially applied to the static
HTML output, and JavaScript is used to follow changes made by the user.

Signed-off-by: Leo-Andres Hofmann <hofmann@leo-andres.de>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agozoneconf.cgi: Improve CSS
Leo-Andres Hofmann [Tue, 17 Nov 2020 06:29:03 +0000 (07:29 +0100)] 
zoneconf.cgi: Improve CSS

- Add an element id so that the styling only affects the zone table
- Alternating row colors are now generated by CSS, remove unneeded Perl code

Signed-off-by: Leo-Andres Hofmann <hofmann@leo-andres.de>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agozoneconf.cgi: Make output HTML 5 standard compliant
Leo-Andres Hofmann [Tue, 17 Nov 2020 06:29:02 +0000 (07:29 +0100)] 
zoneconf.cgi: Make output HTML 5 standard compliant

This fixes two minor violations of the HTML standard:
- <a> elements may not contain nested <button> elements:
Replace the button with a simple hyperlink, because it was only used as a link anyway.

- "id" attributes may not contain whitespace:
Remove unneeded attribute, use hyphens instead of spaces.

Signed-off-by: Leo-Andres Hofmann <hofmann@leo-andres.de>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agozoneconf.cgi: Clean up HTML output
Leo-Andres Hofmann [Tue, 17 Nov 2020 06:29:01 +0000 (07:29 +0100)] 
zoneconf.cgi: Clean up HTML output

This adds missing brackets, cleans up the indentation and removes unnecessary CSS.

Signed-off-by: Leo-Andres Hofmann <hofmann@leo-andres.de>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibloc: Import changes from upstream
Michael Tremer [Fri, 27 Nov 2020 15:46:39 +0000 (15:46 +0000)] 
libloc: Import changes from upstream

This fixes the segmentation fault on 32 bit systems.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agogdb: Build package to be available in the build environment
Michael Tremer [Fri, 27 Nov 2020 15:19:53 +0000 (15:19 +0000)] 
gdb: Build package to be available in the build environment

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agotransmission: update to 3.00
Arne Fitzenreiter [Tue, 24 Nov 2020 19:51:25 +0000 (20:51 +0100)] 
transmission: update to 3.00

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibloc: Import latest changes from upstream
Michael Tremer [Thu, 26 Nov 2020 16:15:07 +0000 (16:15 +0000)] 
libloc: Import latest changes from upstream

This is now a unified patch instead of being split into
individual commits from upstream.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoopenvpn: Actually apply configured parameters
Michael Tremer [Tue, 20 Oct 2020 13:28:25 +0000 (13:28 +0000)] 
openvpn: Actually apply configured parameters

OpenVPN is an absolute mess. The behaviour of configuration
parameters has been changed over the time; default values have been
changed over time; and it looks like nobody is actually testing
anything any more.

I have been spending hours today on figuring out why OpenVPN
is so damn slow. On a Lightning Wire Labs IPFire Mini Appliance
it achieves about 100 MBit/s in the default configuration when
"openssl speed -evp aes-256-gcm" achieves over 3.5 GBit/s.

Changing any of the cryptography parameters does not change
anything. Throughput remains around 100 MBit/s.

I finally set "cipher none" and "auth none" which disables
encryption and authentication altogether but does not increase
throughput. From here on it was absolutely clear that it was
not a crypto issue.

OpenVPN tries to be smart here and does its own fragmentation.
This is the worst idea I have heard of all day, because that job
is normally done best by the OS.

Various settings which allow the user to "tune" this are grossly
ineffective - let alone it isn't even clear what I am supposed
to configure anywhere. Setting "fragment 1500" weirdly still
does not convince openvpn to generate a packet that is longer
than 1400 bytes. Who'd a thunk?

There is a number of other parameters to set the MTU or which
are related to it (tun-mtu, link-mtu, fragment, mssfix).

On top of all of this we have two "bugs" in ovpnmain.cgi which
are being fixed in this patch:

1) mssfix can be configured by the user. However, we always
   enable it in openvpn. The default is on, we only add "mssfix"
   which simply turns it on.
   It is now being disabled when the user has chosen so in the
   web UI. I do not know if this is backwards-compatible.

2) We cap the MTU (tun-mtu) at 1500 bytes when fragment is being
   used. So it becomes pointless that the user can this and the
   user is not being made aware of this when they hit the save
   button.
   This was added when we added path MTU discovery. Since that
   did not work and was removed, we can remove this now, too.

I archived a solid 500-600 MBit/s of goodput with these settings:

* Disable mssfix
* Set "fragment" to 0
* Set MTU to 9000

I am sure the MTU could be further increased to have bigger packets,
but I did not test how badly this will affect latency of the tunnel.

OpenVPN seems to only be able to handle a certain amount of packets
a second - no matter what. With larger packets, the throughput of
the tunnel increases, but latency might as well.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Cc: Erik Kapfer <erik.kapfer@ipfire.org>
Cc: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibloc: Import changes from upstream
Michael Tremer [Wed, 25 Nov 2020 20:02:30 +0000 (20:02 +0000)] 
libloc: Import changes from upstream

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoRun "./make.sh lang"
Michael Tremer [Wed, 25 Nov 2020 17:21:56 +0000 (17:21 +0000)] 
Run "./make.sh lang"

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoupdate translation files for changed Tor CGI strings
Peter Müller [Wed, 4 Nov 2020 21:29:14 +0000 (22:29 +0100)] 
update translation files for changed Tor CGI strings

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoTor: allow enforcing distinct Guard relays or countries
Peter Müller [Wed, 4 Nov 2020 21:28:50 +0000 (22:28 +0100)] 
Tor: allow enforcing distinct Guard relays or countries

In order to make deanonymisation harder, especially high-risk Tor users
might want to use certain Guard relays only (for example operated by
people they trust), enforce Tor to use Guard relays in certain countries
only (for example countries with very strict data protection laws or
poor diplomatic relations), or avoid Guard relays in certain countries
entirely.

Since Tor sticks to sampled Guards for a long time (usually within the
range of months), restricting those is believed to cause less harm to a
users' anonymity than restricting Exit relays, since their diversity of
a generic Tor user is significantly higher.

This patch extends the Tor CGI for restricting Guard nodes to certain
countries or relays matching certain fingerprints.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoTor: allow multiple countries to be selected for Exit relays
Peter Müller [Wed, 4 Nov 2020 21:28:22 +0000 (22:28 +0100)] 
Tor: allow multiple countries to be selected for Exit relays

This extends the functionality of the Tor CGI in order to be able to
select multiple countries for possible Exit relays, which is - in terms
of anonymity - less worse than limiting all Tor circuits to a single
country.

For example, a user might want to avoid Exit relays in more than one
country, and permit Tor to use Exit relays elesewhere, and vice versa.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoTor: update to 0.4.4.6
Peter Müller [Wed, 25 Nov 2020 17:15:17 +0000 (17:15 +0000)] 
Tor: update to 0.4.4.6

Full changelog can be obtained from https://gitweb.torproject.org/tor.git/plain/ChangeLog?h=tor-0.4.4.6 .

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agokernel: update to 4.14.209
Arne Fitzenreiter [Tue, 24 Nov 2020 19:52:22 +0000 (20:52 +0100)] 
kernel: update to 4.14.209

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore153: ship strongswan
Arne Fitzenreiter [Tue, 24 Nov 2020 10:08:13 +0000 (11:08 +0100)] 
core153: ship strongswan

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agostrongswan: update to 5.9.1
Arne Fitzenreiter [Tue, 24 Nov 2020 09:52:45 +0000 (10:52 +0100)] 
strongswan: update to 5.9.1

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agovdr-dvbapi: fix rootfile
Arne Fitzenreiter [Tue, 24 Nov 2020 07:18:09 +0000 (08:18 +0100)] 
vdr-dvbapi: fix rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agovdr: update to 2.4.4
Arne Fitzenreiter [Mon, 23 Nov 2020 17:27:46 +0000 (18:27 +0100)] 
vdr: update to 2.4.4

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agofreeradius: Depend on samba again
Michael Tremer [Mon, 23 Nov 2020 15:11:43 +0000 (15:11 +0000)] 
freeradius: Depend on samba again

The package requires more libraries than libtalloc from
the samba package and therefore we need this dependency
again.

Fixes: #12538
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoapcupsd: addition of backup/includes definition
Adolf Belka [Mon, 23 Nov 2020 12:08:48 +0000 (13:08 +0100)] 
apcupsd: addition of backup/includes definition

Added a backup/includes file for apcupsd to backup the
/etc/apcupsd/ directory where all the configuration files
are stored. Currently there is no backup available to
save the state of any changes carried out to the configuration
or action files.
Signed-off-by: Adolf Belka <ahb.ipfire@gmail.com>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agopcengines-firmware: update to 4.12.0.6
Arne Fitzenreiter [Mon, 23 Nov 2020 14:24:37 +0000 (15:24 +0100)] 
pcengines-firmware: update to 4.12.0.6

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agokernel: update to 4.14.208
Arne Fitzenreiter [Mon, 23 Nov 2020 13:24:15 +0000 (14:24 +0100)] 
kernel: update to 4.14.208

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore153: Remove reloading microcode
Michael Tremer [Fri, 20 Nov 2020 20:04:13 +0000 (20:04 +0000)] 
core153: Remove reloading microcode

This requires that we can load the "microcode" module, but
since the kernel was replaced in this release, we can't load
it any more.

Fixes: #12537
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agonetwork-hotplug-bridges: Apply STP_PRIORITY
Daniel Weismüller [Fri, 20 Nov 2020 17:35:52 +0000 (18:35 +0100)] 
network-hotplug-bridges: Apply STP_PRIORITY

Signed-off-by: Daniel Weismüller <daniel.weismueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agocore153: Ship network-hotplug-bridges
Michael Tremer [Fri, 20 Nov 2020 13:47:01 +0000 (13:47 +0000)] 
core153: Ship network-hotplug-bridges

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoCore 152: the script "network-hotplug-bridges" now reads the variable ${ZONE}_STP...
Daniel Weismüller [Thu, 19 Nov 2020 13:18:49 +0000 (14:18 +0100)] 
Core 152: the script "network-hotplug-bridges" now reads the variable ${ZONE}_STP from /var/ipfire/ethernet/settings so that STP can be turned on and off for each bridge

Signed-off-by: Daniel Weismüller <daniel.weismueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoCore 153: Ship libhtp
Stefan Schantl [Thu, 19 Nov 2020 19:01:19 +0000 (20:01 +0100)] 
Core 153: Ship libhtp

libhtp has been updated and suricata 6 requires the new version, so
this lib has to be shipped with the core update.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoamazon-ssm-agent: Package /usr/bin/ssm-agent-worker
Michael Tremer [Thu, 19 Nov 2020 18:35:36 +0000 (18:35 +0000)] 
amazon-ssm-agent: Package /usr/bin/ssm-agent-worker

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agokernel: update to 4.14.207
Arne Fitzenreiter [Thu, 19 Nov 2020 18:08:33 +0000 (19:08 +0100)] 
kernel: update to 4.14.207

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agolibloc: Import more changes from upstream
Michael Tremer [Thu, 19 Nov 2020 13:08:22 +0000 (13:08 +0000)] 
libloc: Import more changes from upstream

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agolibloc: Import recent patches from upstream
Michael Tremer [Wed, 18 Nov 2020 13:30:15 +0000 (13:30 +0000)] 
libloc: Import recent patches from upstream

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agonetwork: Mount/umount network file systems at the correct time
Michael Tremer [Tue, 17 Nov 2020 16:35:13 +0000 (16:35 +0000)] 
network: Mount/umount network file systems at the correct time

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoipinfo.cgi: Align flag icon
Michael Tremer [Tue, 17 Nov 2020 16:04:10 +0000 (16:04 +0000)] 
ipinfo.cgi: Align flag icon

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoen.pl: fix accidentially removed line by ./make.sh langs
Peter Müller [Mon, 16 Nov 2020 17:42:12 +0000 (18:42 +0100)] 
en.pl: fix accidentially removed line by ./make.sh langs

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agosamba: remove pid at killproc in initscript core152 v2.25-core152
Arne Fitzenreiter [Sun, 1 Nov 2020 17:06:08 +0000 (18:06 +0100)] 
samba: remove pid at killproc in initscript

sometime a stale nmbd or smbd process prevent start of samba.
this change should kill all processes.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Fri, 13 Nov 2020 18:20:59 +0000 (18:20 +0000)] 
Merge remote-tracking branch 'origin/master' into next

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoUpdate contributors
Michael Tremer [Fri, 13 Nov 2020 11:13:08 +0000 (11:13 +0000)] 
Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoOpenVPN: Add start of static routes in client N2N
ummeegge [Wed, 11 Nov 2020 18:12:25 +0000 (18:12 +0000)] 
OpenVPN: Add start of static routes in client N2N

Fixes: #12529
- If a client N2N configuration will be imported into IPFire systems,
a line will be added which calls the --up script to restart the
static route initscript. Since this is IPFire specific, i will only be
added via import on IPFire system.
- Deleted unneeded line in CLIENTCONF section.
- Added description to SERVERCONF section.

Signed-off-by: ummeegge <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agoamazon-ssm-agent: Update to 3.0.356.0
Michael Tremer [Fri, 13 Nov 2020 11:10:49 +0000 (11:10 +0000)] 
amazon-ssm-agent: Update to 3.0.356.0

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agogo: Update to 1.15.4
Michael Tremer [Fri, 13 Nov 2020 11:10:33 +0000 (11:10 +0000)] 
go: Update to 1.15.4

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 years agointel-microcode: update to 20201112
Arne Fitzenreiter [Fri, 13 Nov 2020 08:03:00 +0000 (09:03 +0100)] 
intel-microcode: update to 20201112

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agokernel: update to 4.14.206
Arne Fitzenreiter [Thu, 12 Nov 2020 08:02:02 +0000 (09:02 +0100)] 
kernel: update to 4.14.206

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>