]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
8 years agosarg: Update to 2.3.9
Matthias Fischer [Tue, 26 May 2015 12:09:40 +0000 (14:09 +0200)] 
sarg: Update to 2.3.9

8 years agodnsmasq: Apply patches from upstream
Michael Tremer [Wed, 20 May 2015 21:37:54 +0000 (23:37 +0200)] 
dnsmasq: Apply patches from upstream

8 years agodnsmasq: Import patches from upstream
Michael Tremer [Wed, 20 May 2015 21:35:38 +0000 (23:35 +0200)] 
dnsmasq: Import patches from upstream

8 years agofirewall: Disable the P2P blocker by default
Michael Tremer [Wed, 20 May 2015 11:37:35 +0000 (13:37 +0200)] 
firewall: Disable the P2P blocker by default

P2P networks have come a bit out of fashion. Disabling
the P2P blocker by default will save us some CPU cycles
for each packet that goes through the firewall.

The P2P blocker has also caused lots of false-positives
and has therefore become a bit more of a problem than
a solution.

8 years agocore90: set pakfire version to 90
Arne Fitzenreiter [Fri, 8 May 2015 16:30:31 +0000 (18:30 +0200)] 
core90: set pakfire version to 90

8 years agokernel: update to 3.14.41
Arne Fitzenreiter [Fri, 8 May 2015 11:25:36 +0000 (13:25 +0200)] 
kernel: update to 3.14.41

8 years agoapache2: Ship all config files
Michael Tremer [Thu, 7 May 2015 20:46:59 +0000 (22:46 +0200)] 
apache2: Ship all config files

8 years agocore90: Ship changed ipsecctrl
Michael Tremer [Thu, 7 May 2015 20:42:04 +0000 (22:42 +0200)] 
core90: Ship changed ipsecctrl

8 years agostrongswan: Use --wait option for iptables commands
Michael Tremer [Thu, 7 May 2015 20:40:08 +0000 (22:40 +0200)] 
strongswan: Use --wait option for iptables commands

8 years agoipsecctrl: Use --wait switch for all iptables commands
Michael Tremer [Thu, 7 May 2015 19:06:44 +0000 (21:06 +0200)] 
ipsecctrl: Use --wait switch for all iptables commands

8 years agoipsecctrl: Remove unused code block
Michael Tremer [Thu, 7 May 2015 19:05:50 +0000 (21:05 +0200)] 
ipsecctrl: Remove unused code block

8 years agocore90: supply new kernel version to user update script
Arne Fitzenreiter [Wed, 6 May 2015 17:38:07 +0000 (19:38 +0200)] 
core90: supply new kernel version to user update script

8 years agocore90: run user update script at kernel update.
Arne Fitzenreiter [Wed, 6 May 2015 17:28:40 +0000 (19:28 +0200)] 
core90: run user update script at kernel update.

fixes #10767

8 years agocore90: restart init after glibc update.
Arne Fitzenreiter [Wed, 6 May 2015 17:21:05 +0000 (19:21 +0200)] 
core90: restart init after glibc update.

8 years agoqemu: update to 2.3.0
Arne Fitzenreiter [Wed, 6 May 2015 17:12:06 +0000 (19:12 +0200)] 
qemu: update to 2.3.0

8 years agocore90: update kernel version in uEnv.txt
Arne Fitzenreiter [Wed, 6 May 2015 17:10:47 +0000 (19:10 +0200)] 
core90: update kernel version in uEnv.txt

8 years agocore90: add Locale-Country to update
Arne Fitzenreiter [Wed, 6 May 2015 17:08:09 +0000 (19:08 +0200)] 
core90: add Locale-Country to update

8 years agoMerge remote-tracking branch 'amarx/BUG10834' into next
Michael Tremer [Wed, 6 May 2015 14:57:55 +0000 (16:57 +0200)] 
Merge remote-tracking branch 'amarx/BUG10834' into next

8 years agoBUG10834: fixes ovpn-ccd-convert
Alexander Marx [Wed, 6 May 2015 14:18:00 +0000 (16:18 +0200)] 
BUG10834: fixes ovpn-ccd-convert

When restoring an old backup, all OpenVPN RW's get the dynamic network.

8 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 6 May 2015 07:44:03 +0000 (09:44 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

8 years agoRootfile update
Michael Tremer [Wed, 6 May 2015 07:43:53 +0000 (09:43 +0200)] 
Rootfile update

8 years agodracut: add sdhci-pci module to initrd.
Arne Fitzenreiter [Tue, 5 May 2015 20:34:30 +0000 (22:34 +0200)] 
dracut: add sdhci-pci module to initrd.

fixes #10792

8 years agoMerge remote-tracking branch 'stevee/next' into next
Michael Tremer [Tue, 5 May 2015 18:20:29 +0000 (20:20 +0200)] 
Merge remote-tracking branch 'stevee/next' into next

8 years agoSplit web-user-interface from apache2 LFS file
Michael Tremer [Tue, 5 May 2015 12:00:20 +0000 (14:00 +0200)] 
Split web-user-interface from apache2 LFS file

It is completely unnecssary to have this in one file
and using options for the LFS is more of a hack than
a solution.

8 years agocore90: Ship updated CGI files
Michael Tremer [Tue, 5 May 2015 10:19:11 +0000 (12:19 +0200)] 
core90: Ship updated CGI files

8 years agoMerge remote-tracking branch 'stevee/next-cgi-geoip' into next
Michael Tremer [Tue, 5 May 2015 10:16:58 +0000 (12:16 +0200)] 
Merge remote-tracking branch 'stevee/next-cgi-geoip' into next

8 years agoMerge remote-tracking branch 'stevee/next-flag-icons' into next
Michael Tremer [Tue, 5 May 2015 10:15:55 +0000 (12:15 +0200)] 
Merge remote-tracking branch 'stevee/next-flag-icons' into next

8 years agoCore 90: Add modified cgi files for firewall log statistics.
Stefan Schantl [Mon, 4 May 2015 18:19:19 +0000 (20:19 +0200)] 
Core 90: Add modified cgi files for firewall log statistics.

8 years agoMerge remote-tracking branch 'stevee/next-cgi-geoip' into next
Stefan Schantl [Mon, 4 May 2015 18:16:24 +0000 (20:16 +0200)] 
Merge remote-tracking branch 'stevee/next-cgi-geoip' into next

8 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Stefan Schantl [Mon, 4 May 2015 18:15:24 +0000 (20:15 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

8 years agogeoip-functions: Adjust for new flag-icons and usage of "unknown" icon.
Stefan Schantl [Mon, 4 May 2015 18:13:52 +0000 (20:13 +0200)] 
geoip-functions: Adjust for new flag-icons and usage of "unknown" icon.

8 years agoCore90: Drop old and add new flag-icons.
Stefan Schantl [Mon, 4 May 2015 18:10:46 +0000 (20:10 +0200)] 
Core90: Drop old and add new flag-icons.

8 years agocore90: Ship updated fireinfo
Michael Tremer [Mon, 4 May 2015 14:18:24 +0000 (16:18 +0200)] 
core90: Ship updated fireinfo

8 years agofireinfo: Fix SEGV on QEMU without KVM
Michael Tremer [Mon, 4 May 2015 14:02:39 +0000 (16:02 +0200)] 
fireinfo: Fix SEGV on QEMU without KVM

8 years agosquid: rootfile update.
Arne Fitzenreiter [Mon, 4 May 2015 05:40:30 +0000 (07:40 +0200)] 
squid: rootfile update.

8 years agoDrop old flag icons.
Stefan Schantl [Sun, 3 May 2015 19:53:03 +0000 (21:53 +0200)] 
Drop old flag icons.

8 years agoUpdate flag icon-set.
Stefan Schantl [Sun, 3 May 2015 19:51:04 +0000 (21:51 +0200)] 
Update flag icon-set.

Move the flag icon-set into an own lfs file and replace the current
used one by a more recent version.

8 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Sun, 3 May 2015 11:03:25 +0000 (13:03 +0200)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next

8 years agotoolchain: set version to 9.
Arne Fitzenreiter [Sun, 3 May 2015 11:02:30 +0000 (13:02 +0200)] 
toolchain: set version to 9.

8 years agosquid-accounting: fix monthly dbmove funktion to put values in history table
Alexander Marx [Sun, 3 May 2015 03:24:39 +0000 (05:24 +0200)] 
squid-accounting: fix monthly dbmove funktion to put values in history table

8 years agocore90: Add updated netovpnsrv.cgi to update
Michael Tremer [Sun, 3 May 2015 10:53:28 +0000 (12:53 +0200)] 
core90: Add updated netovpnsrv.cgi to update

8 years agoMerge remote-tracking branch 'amarx/core90' into next
Michael Tremer [Sun, 3 May 2015 10:52:50 +0000 (12:52 +0200)] 
Merge remote-tracking branch 'amarx/core90' into next

8 years agoCore90: make N2N Graphs higher to them correctly
Alexander Marx [Sun, 3 May 2015 03:12:13 +0000 (05:12 +0200)] 
Core90: make N2N Graphs higher to them correctly

Graphs in core 89 where not heigh enough so that they where zoomed which
looked bad

8 years agocore90: Also regenerate IPsec configuration during the update
Michael Tremer [Sat, 2 May 2015 12:29:46 +0000 (14:29 +0200)] 
core90: Also regenerate IPsec configuration during the update

8 years agoMultiple CGI's: Use &GeoIP::get_flag_icon for getting country flags.
Stefan Schantl [Sat, 2 May 2015 11:45:50 +0000 (13:45 +0200)] 
Multiple CGI's: Use &GeoIP::get_flag_icon for getting country flags.

8 years agosquid: Disable SSL support
Michael Tremer [Sat, 2 May 2015 10:56:09 +0000 (12:56 +0200)] 
squid: Disable SSL support

The SSL support parts of squid are a great security
risk. The majority of all security issues has been
in this area. As we are not using any of that in
production we can as well disable SSL support.

This won't affect squid's possibility to forward
SSL connections with the CONNECT method.

8 years agosquid: Update to 3.4.13
Michael Tremer [Sat, 2 May 2015 09:20:37 +0000 (11:20 +0200)] 
squid: Update to 3.4.13

8 years agovpnmain.cgi: Fix ECP regex again for Brainpool curves
Michael Tremer [Fri, 1 May 2015 14:57:13 +0000 (16:57 +0200)] 
vpnmain.cgi: Fix ECP regex again for Brainpool curves

The regular expression did not take into account that
there could be characters like "bp" in case of the Brainpool
curves (ecp512bp).

8 years agoclamav: update to 0.98.7
Arne Fitzenreiter [Thu, 30 Apr 2015 04:50:15 +0000 (06:50 +0200)] 
clamav: update to 0.98.7

8 years agoxz: update to 5.2.1
Arne Fitzenreiter [Wed, 29 Apr 2015 17:47:44 +0000 (19:47 +0200)] 
xz: update to 5.2.1

8 years agokernel: update to 3.14.40
Arne Fitzenreiter [Wed, 29 Apr 2015 17:42:06 +0000 (19:42 +0200)] 
kernel: update to 3.14.40

8 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 29 Apr 2015 09:26:35 +0000 (11:26 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

8 years agoMerge remote-tracking branch 'stevee/core-90-ddnsctrl' into next
Michael Tremer [Wed, 29 Apr 2015 09:26:20 +0000 (11:26 +0200)] 
Merge remote-tracking branch 'stevee/core-90-ddnsctrl' into next

8 years agodnsmasq: Import more upstream fixes
Michael Tremer [Wed, 29 Apr 2015 09:24:23 +0000 (11:24 +0200)] 
dnsmasq: Import more upstream fixes

Fixes: #10786
Fixes DNSSEC validation when falling back to TCP.

8 years agoCore90: Regenerate ddns config file.
Stefan Schantl [Tue, 28 Apr 2015 19:16:54 +0000 (21:16 +0200)] 
Core90: Regenerate ddns config file.

8 years agoddns: Add more upstream patches.
Stefan Schantl [Tue, 28 Apr 2015 19:06:19 +0000 (21:06 +0200)] 
ddns: Add more upstream patches.

8 years agoopenssl: disable ssse3 on amd cpu's
Arne Fitzenreiter [Tue, 28 Apr 2015 18:51:03 +0000 (20:51 +0200)] 
openssl: disable ssse3 on amd cpu's

amd with ssse3 (bulldozer and fusion) has serious performance problems
with the vpaes code. (-evp is 40% slower)

8 years agovpnmain.cgi: Fix prefix for elliptic curve algorithms
Michael Tremer [Tue, 28 Apr 2015 11:22:00 +0000 (13:22 +0200)] 
vpnmain.cgi: Fix prefix for elliptic curve algorithms

8 years agovpnmain.cgi: dpd_delay/dpd_timeout wrong entry in ipsec.conf
Jochen Kauz [Tue, 28 Apr 2015 09:30:05 +0000 (11:30 +0200)] 
vpnmain.cgi: dpd_delay/dpd_timeout wrong entry in ipsec.conf

Fixes #10636

8 years agoopenssl: Don't ship an SSE-optimised version of libssl
Michael Tremer [Tue, 28 Apr 2015 09:15:38 +0000 (11:15 +0200)] 
openssl: Don't ship an SSE-optimised version of libssl

This one does not benefit at all from any optimisations
of this kind. Only libcrypto.so.10 which holds the implementation
of ciphers and hashes gains better performance by using SSE2.

8 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Tue, 28 Apr 2015 09:14:45 +0000 (11:14 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

8 years agotzdata: Update to version 2015d
Michael Tremer [Tue, 28 Apr 2015 09:13:03 +0000 (11:13 +0200)] 
tzdata: Update to version 2015d

8 years agoopenssl: auto enable padlock engine.
Arne Fitzenreiter [Mon, 27 Apr 2015 20:15:20 +0000 (22:15 +0200)] 
openssl: auto enable padlock engine.

8 years agoglibc: Fix CVE-2013-7423 and CVE-2015-1781
Michael Tremer [Mon, 27 Apr 2015 19:17:17 +0000 (21:17 +0200)] 
glibc: Fix CVE-2013-7423 and CVE-2015-1781

CVE-2013-7423: Fix invalid file descriptor reuse while sending DNS query
CVE-2015-1781: Fix buffer overflow in gethostbyname_r with misaligned buffer

8 years agoopenssl: change sse2 optimization to i686.
Arne Fitzenreiter [Mon, 27 Apr 2015 19:19:46 +0000 (21:19 +0200)] 
openssl: change sse2 optimization to i686.

8 years agostrongswan: Increase stroke buffer size to 8k
Michael Tremer [Mon, 27 Apr 2015 18:58:45 +0000 (20:58 +0200)] 
strongswan: Increase stroke buffer size to 8k

8 years agodnsmasq: Import latest fixes from upstream
Michael Tremer [Mon, 27 Apr 2015 16:10:34 +0000 (18:10 +0200)] 
dnsmasq: Import latest fixes from upstream

8 years agoAdd patched ddns to core 90.
Stefan Schantl [Sun, 26 Apr 2015 15:17:36 +0000 (17:17 +0200)] 
Add patched ddns to core 90.

8 years agoDrop obsolete ddns patches.
Stefan Schantl [Sun, 26 Apr 2015 15:14:36 +0000 (17:14 +0200)] 
Drop obsolete ddns patches.

8 years agoddns: Add upstream patch for fixing bug 10815.
Stefan Schantl [Sun, 26 Apr 2015 15:12:55 +0000 (17:12 +0200)] 
ddns: Add upstream patch for fixing bug 10815.

8 years agoAdd ddns related files to core 90.
Stefan Schantl [Sun, 26 Apr 2015 14:56:24 +0000 (16:56 +0200)] 
Add ddns related files to core 90.

8 years agoddns.cgi: Use ddnsctrl for instant update.
Stefan Schantl [Sun, 26 Apr 2015 14:52:52 +0000 (16:52 +0200)] 
ddns.cgi: Use ddnsctrl for instant update.

8 years agoddnsctrl: New binary.
Stefan Schantl [Sun, 26 Apr 2015 14:48:45 +0000 (16:48 +0200)] 
ddnsctrl: New binary.

This helper binary is used to grand the ddns update client super user rights,
when launched out of the webinterface.

8 years agoAdd rootfile check for hardcoded machine type.
Arne Fitzenreiter [Sat, 25 Apr 2015 11:23:34 +0000 (13:23 +0200)] 
Add rootfile check for hardcoded machine type.

8 years agolibsrtp: update rootfile.
Arne Fitzenreiter [Sat, 25 Apr 2015 07:49:37 +0000 (09:49 +0200)] 
libsrtp: update rootfile.

8 years agocore90: remove missing file from openssl-0.9.8-files.
Arne Fitzenreiter [Fri, 24 Apr 2015 18:06:13 +0000 (20:06 +0200)] 
core90: remove missing file from openssl-0.9.8-files.

8 years agoopenssl: fix ssl2 rootfile handling.
Arne Fitzenreiter [Fri, 24 Apr 2015 18:03:45 +0000 (20:03 +0200)] 
openssl: fix ssl2 rootfile handling.

KCFG will added to the lfs filename at determine the filename in config/rootfiles folder.

8 years agoasterisk addon: upate to 11.17.1
Dirk Wagner [Wed, 15 Apr 2015 12:17:34 +0000 (14:17 +0200)] 
asterisk addon: upate to 11.17.1

8 years agolibsrtp: upgrade to 1.5.2
Dirk Wagner [Wed, 15 Apr 2015 12:16:36 +0000 (14:16 +0200)] 
libsrtp: upgrade to 1.5.2

8 years agoopenssl: fix typo on arm config.
Arne Fitzenreiter [Thu, 23 Apr 2015 21:31:58 +0000 (23:31 +0200)] 
openssl: fix typo on arm config.

8 years agocore90: ship backupiso withupdate.
Arne Fitzenreiter [Thu, 23 Apr 2015 19:18:42 +0000 (21:18 +0200)] 
core90: ship backupiso withupdate.

this file was missing in core87.

8 years agoDrop openssl-compat package
Michael Tremer [Thu, 23 Apr 2015 12:28:41 +0000 (14:28 +0200)] 
Drop openssl-compat package

8 years agoopenssl: Enable all assembly optimisations build SSE2 optimised version
Michael Tremer [Thu, 23 Apr 2015 11:33:35 +0000 (13:33 +0200)] 
openssl: Enable all assembly optimisations build SSE2 optimised version

Fixes #10814

8 years agoBUG10812: fix missing slash in path
Alexander Marx [Thu, 23 Apr 2015 07:20:00 +0000 (09:20 +0200)] 
BUG10812: fix missing slash in path

8 years agorootfiles: fix build on arm.
Arne Fitzenreiter [Wed, 22 Apr 2015 20:15:27 +0000 (22:15 +0200)] 
rootfiles: fix build on arm.

i586 -> MACHINE

8 years agoCore 90: Ship modified country.cgi.
Stefan Schantl [Wed, 22 Apr 2015 16:35:00 +0000 (18:35 +0200)] 
Core 90: Ship modified country.cgi.

8 years agotor: Increase PAK_VER for shipping modified CGI file.
Stefan Schantl [Wed, 22 Apr 2015 16:28:58 +0000 (18:28 +0200)] 
tor: Increase PAK_VER for shipping modified CGI file.

8 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Stefan Schantl [Wed, 22 Apr 2015 16:25:25 +0000 (18:25 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

8 years agoRename Locale::Country to Locale::Codes::Country in various scripts.
Stefan Schantl [Wed, 22 Apr 2015 16:18:38 +0000 (18:18 +0200)] 
Rename Locale::Country to Locale::Codes::Country in various scripts.

The new Locale-Country version needs to be loaded and used by specifing
Locale::Codes::Country since an upstream API change. Adjusting various perl
scripts to use the module in the proper way again.

9 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 22 Apr 2015 14:08:42 +0000 (16:08 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

9 years agoBUG10812: change ovpnserver config if needed
Alexander Marx [Wed, 22 Apr 2015 13:02:02 +0000 (15:02 +0200)] 
BUG10812: change ovpnserver config if needed

9 years agovpnmain.cgi: Order ciphers by strength
Michael Tremer [Wed, 22 Apr 2015 12:45:10 +0000 (14:45 +0200)] 
vpnmain.cgi: Order ciphers by strength

strongSwan uses them in the defined order. Hence it makes
much more sense to present them to the user as well in that
order.

9 years agovpnmain.cgi: Use integrity functions as PRF for AEAD
Michael Tremer [Wed, 22 Apr 2015 12:44:16 +0000 (14:44 +0200)] 
vpnmain.cgi: Use integrity functions as PRF for AEAD

9 years agovpnmain.cgi: Rewrite algorithm generation code
Michael Tremer [Wed, 22 Apr 2015 12:08:41 +0000 (14:08 +0200)] 
vpnmain.cgi: Rewrite algorithm generation code

9 years agosquid-accounting: fix mistakenly deleted lines from last commit
Alexander Marx [Wed, 22 Apr 2015 11:32:04 +0000 (13:32 +0200)] 
squid-accounting: fix mistakenly deleted lines from last commit

9 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 22 Apr 2015 11:07:30 +0000 (13:07 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

9 years agoindex.cgi: Hide blue and green if not enabled
Michael Tremer [Wed, 22 Apr 2015 11:06:52 +0000 (13:06 +0200)] 
index.cgi: Hide blue and green if not enabled

Those were shown when a blue or orange interface
was assigned which is not the same as enabled.

9 years agoSquid-accounting: new Version 1.0.3 (graph updates, movedb update)
Alexander Marx [Tue, 21 Apr 2015 09:25:29 +0000 (11:25 +0200)] 
Squid-accounting: new Version 1.0.3 (graph updates, movedb update)

New Version. Now the data is correctly moved to hist table when month
has changed.
Also the graphs for old month starts by zero. In old version graphdata
was started by total amount of bytes.

9 years agoipsec: Always enable support for IKE fragmentation
Michael Tremer [Tue, 21 Apr 2015 17:36:40 +0000 (19:36 +0200)] 
ipsec: Always enable support for IKE fragmentation

9 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Stefan Schantl [Tue, 21 Apr 2015 17:20:26 +0000 (19:20 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next