]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
3 years agolibseccomp: Update to version 2.4.3
Erik Kapfer [Fri, 8 May 2020 06:23:19 +0000 (06:23 +0000)] 
libseccomp: Update to version 2.4.3

- Add list of authorized release signatures to README.md
- Fix multiplexing issue with s390/s390x shm* syscalls
- Remove the static flag from libseccomp tools compilation
- Add define for __SNR_ppoll
- Update our Travis CI configuration to use Ubuntu 18.04
- Disable live python tests in Travis CI
- Use default python, rather than nightly python, in TravisCI
- Fix potential memory leak identified by clang in the scmp_bpf_sim too

The changelog can be found in here https://github.com/seccomp/libseccomp/blob/master/CHANGELOG .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoshairport-sync: Update to 3.3.6
Michael Tremer [Thu, 7 May 2020 17:27:02 +0000 (17:27 +0000)] 
shairport-sync: Update to 3.3.6

This patch also fixes the backup.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoupdate.sh: Stop|Start OpenVPN for update
Erik Kapfer [Thu, 7 May 2020 10:46:16 +0000 (12:46 +0200)] 
update.sh: Stop|Start OpenVPN for update

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoOpenVPN: Update to version 2.4.9
Erik Kapfer [Thu, 7 May 2020 10:46:15 +0000 (12:46 +0200)] 
OpenVPN: Update to version 2.4.9

Beneath several smaller fixes, this version fixes also some OpenSSL problems but also CVE-2020-11810.
The full changelog can be found in here https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24 .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: update rng init
Arne Fitzenreiter [Sun, 17 May 2020 07:51:32 +0000 (07:51 +0000)] 
core145: update rng init

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agorandom: Initialise the kernel's PRNG earlier
Michael Tremer [Wed, 29 Apr 2020 19:33:04 +0000 (19:33 +0000)] 
random: Initialise the kernel's PRNG earlier

Since more processes depend on good randomness, we need to
make sure that the kernel's PRNG is initialized as early as
possible.

For systems without a HWRNG, we will need to fall back to our
noisy loop and wait until we have enough randomness.

This patch also removes saving and restoring the seed. This
is no longer useful because the kernel's PRNG only takes any
input after it has successfully been seeded from other sources.

Hence adding this seed does not increase its randomness.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agorandom: Launch rngd earlier in the boot process
Michael Tremer [Wed, 29 Apr 2020 19:33:03 +0000 (19:33 +0000)] 
random: Launch rngd earlier in the boot process

We should initialise the kernel's PRNG as early as we can.

Starting rngd very early will seed the random number generator
when RDRAND or other hardware random number generators are available.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add files linked against new libpng, libdb
Arne Fitzenreiter [Wed, 13 May 2020 20:02:36 +0000 (20:02 +0000)] 
core145: add files linked against new libpng, libdb

also bump cups-filters, ghostscript, minidlna and qemu

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add gnupg, squid and bump cups
Arne Fitzenreiter [Wed, 13 May 2020 18:46:04 +0000 (18:46 +0000)] 
core145: add gnupg, squid and bump cups

they are linked against updated openldap

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agorootfiles: change MACHINE to xxxMACHINExxx
Arne Fitzenreiter [Sun, 10 May 2020 17:27:28 +0000 (17:27 +0000)] 
rootfiles: change MACHINE to xxxMACHINExxx

berkeley has a file that nane contain MACHINE wich should not
replaced by the build architecture.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agomtools: update rootfile
Arne Fitzenreiter [Sun, 10 May 2020 07:36:12 +0000 (07:36 +0000)] 
mtools: update rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoberkelay-compat: fix build on aarch64
Arne Fitzenreiter [Sat, 9 May 2020 21:11:25 +0000 (21:11 +0000)] 
berkelay-compat: fix build on aarch64

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: fix firewall rules.pl path
Arne Fitzenreiter [Sat, 9 May 2020 19:27:02 +0000 (19:27 +0000)] 
core145: fix firewall rules.pl path

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoberkeley: fix typo
Arne Fitzenreiter [Sat, 9 May 2020 19:20:02 +0000 (19:20 +0000)] 
berkeley: fix typo

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoberkeley: update automake before build
Arne Fitzenreiter [Sat, 9 May 2020 15:21:27 +0000 (15:21 +0000)] 
berkeley: update automake before build

without build fails on aarch64

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agonano: Update to 4.9.2
Matthias Fischer [Fri, 1 May 2020 10:38:28 +0000 (12:38 +0200)] 
nano: Update to 4.9.2

For details see:
https://www.nano-editor.org/news.php

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agopcengines-apu-firmware: update to 4.11.0.6
Arne Fitzenreiter [Thu, 30 Apr 2020 14:39:36 +0000 (16:39 +0200)] 
pcengines-apu-firmware: update to 4.11.0.6

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoclamav: fix database present check
Arne Fitzenreiter [Thu, 30 Apr 2020 10:50:41 +0000 (12:50 +0200)] 
clamav: fix database present check

the mame of main.cvd has changed to main.cld on my system.
Add both types and also ad bytecode.c?d

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add suricata and libhtp
Arne Fitzenreiter [Sat, 9 May 2020 12:27:50 +0000 (12:27 +0000)] 
core145: add suricata and libhtp

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoSuricata: update to 5.0.3
Peter Müller [Tue, 28 Apr 2020 16:36:32 +0000 (18:36 +0200)] 
Suricata: update to 5.0.3

Release notes (https://suricata-ids.org/2020/04/28/suricata-5-0-3-released/, truncated):

    This is the first release after Suricata joined the Oss-Fuzz program, leading to
    discovery of a number of (potential) security issues. We expect that in the coming
    months we’ll fix more such issues, as the fuzzers increase their coverage and we
    continue to improve the seed corpus.

    Feature #3481: GRE ERSPAN Type 1 Support
    Feature #3613: Teredo port configuration
    Feature #3673: datasets: add ‘dataset-remove’ unix command
    Bug #3240: Dataset hash-size or prealloc invalid value logging
    Bug #3241: Dataset reputation invalid value logging
    Bug #3342: Suricata 5.0 crashes while parsing SMB data
    Bug #3450: signature with sticky buffer with subsequent pcre check in a different buffer loads but will never match
    Bug #3491: Backport 5 BUG_ON(strcasecmp(str, “any”) in DetectAddressParseString
    Bug #3507: rule parsing: memory leaks
    Bug #3526: 5.0.x Kerberos vulnerable to TCP splitting evasion
    Bug #3534: Skip over ERF_TYPE_META records
    Bug #3552: file logging: complete files sometimes marked ‘TRUNCATED’
    Bug #3571: rust: smb compile warnings
    Bug #3573: TCP Fast Open – Bypass of stateless alerts
    Bug #3574: Behavior for tcp fastopen
    Bug #3576: Segfault when facing malformed SNMP rules
    Bug #3577: SIP: Input not parsed when header values contain trailing spaces
    Bug #3580: Faulty signature with two threshold keywords does not generate an error and never match
    Bug #3582: random failures on sip and http-evader suricata-verify tests
    Bug #3585: htp: asan issue
    Bug #3592: Segfault on SMTP TLS
    Bug #3598: rules: memory leaks in pktvar keyword
    Bug #3600: rules: bad address block leads to stack exhaustion
    Bug #3602: rules: crash on ‘internal’-only keywords
    Bug #3604: rules: missing ‘consumption’ of transforms before pkt_data would lead to crash
    Bug #3606: rules: minor memory leak involving pcre_get_substring
    Bug #3609: ssl/tls: ASAN issue in SSLv3ParseHandshakeType
    Bug #3610: defrag: asan issue
    Bug #3612: rules/bsize: memory issue during parsing
    Bug #3614: build-info and configure wrongly display libnss status
    Bug #3644: Invalid memory read on malformed rule with Lua script
    Bug #3646: rules: memory leaks on failed rules
    Bug #3649: CIDR Parsing Issue
    Bug #3651: FTP response buffering against TCP stream
    Bug #3653: Recursion stack-overflow in parsing YAML configuration
    Bug #3660: Multiple DetectEngineReload and bad insertion into linked list lead to buffer overflow
    Bug #3665: FTP: Incorrect ftp_memuse calculation.
    Bug #3667: Signature with an IP range creates one IPOnlyCIDRItem by signe IP address
    Bug #3669: Rules reload with Napatech can hang Suricata UNIX manager process
    Bug #3672: coverity: data directory handling issues
    Bug #3674: Protocol detection evasion by packet splitting
    Optimization #3406: filestore rules are loaded without warning when filestore is not enabled
    Task #3478: libhtp 0.5.33
    Task #3514: SMTP should place restraints on variable length items (e.g., filenames)
    Documentation #3543: doc: add ipv4.hdr and ipv6.hdr
    Bundled libhtp 0.5.33
    Bundled Suricata-Update 1.1.2

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agolibhtp: update to 0.5.33
Peter Müller [Tue, 28 Apr 2020 16:35:56 +0000 (18:35 +0200)] 
libhtp: update to 0.5.33

(Scanty) release notes:

0.5.33 (27 April 2020)
----------------------
- compression bomb protection
- memory handling issue found by Oss-Fuzz
- improve handling of anomalies in traffic

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoWIO: wiographs.cgi - New position for back image
Stephan Feddersen [Tue, 28 Apr 2020 16:06:47 +0000 (18:06 +0200)] 
WIO: wiographs.cgi - New position for back image

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoWIO: wio-lib.pl - Patch Bug 12284 - IPSec Connected since information was added
Stephan Feddersen [Tue, 28 Apr 2020 16:04:33 +0000 (18:04 +0200)] 
WIO: wio-lib.pl - Patch Bug 12284 - IPSec Connected since information was added

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoWIO: wio.cgi - Patch Bug 12284 - IPSec Connected since information was added
Stephan Feddersen [Tue, 28 Apr 2020 15:57:42 +0000 (17:57 +0200)] 
WIO: wio.cgi - Patch Bug 12284 - IPSec Connected since information was added

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoWIO: wio.fr.pl - some typos were correct by Stéphane Pautrel
Stephan Feddersen [Tue, 28 Apr 2020 15:53:23 +0000 (17:53 +0200)] 
WIO: wio.fr.pl - some typos were correct by Stéphane Pautrel

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoNew WIO PAK_ver
Stephan Feddersen [Tue, 28 Apr 2020 15:48:35 +0000 (17:48 +0200)] 
New WIO PAK_ver

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoPostfix: update to 3.5.1
Peter Müller [Tue, 28 Apr 2020 14:47:01 +0000 (16:47 +0200)] 
Postfix: update to 3.5.1

Please refer to http://www.postfix.org/announcements/postfix-3.5.1.html
for further information.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add firewall rules.pl
Arne Fitzenreiter [Sat, 9 May 2020 12:23:49 +0000 (12:23 +0000)] 
core145: add firewall rules.pl

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agofirewall: Log accepted connections even when NAT is active
Michael Tremer [Tue, 28 Apr 2020 11:10:15 +0000 (12:10 +0100)] 
firewall: Log accepted connections even when NAT is active

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add optionsfw.cgi
Arne Fitzenreiter [Sat, 9 May 2020 12:18:48 +0000 (12:18 +0000)] 
core145: add optionsfw.cgi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agooptionsfw.cgi: properly translate on/off radio buttons
Peter Müller [Mon, 27 Apr 2020 15:56:16 +0000 (17:56 +0200)] 
optionsfw.cgi: properly translate on/off radio buttons

This patch also scrubs a forgotten Smoothwall comment and replaces it by
our IPFire template. :-)

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agograph.pl: fix intendation of user CPU load
Peter Müller [Mon, 27 Apr 2020 15:41:47 +0000 (17:41 +0200)] 
graph.pl: fix intendation of user CPU load

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agosystem.cgi: properly translate load average graph
Peter Müller [Mon, 27 Apr 2020 15:37:41 +0000 (17:37 +0200)] 
system.cgi: properly translate load average graph

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add graphs.pl
Arne Fitzenreiter [Sat, 9 May 2020 12:15:51 +0000 (12:15 +0000)] 
core145: add graphs.pl

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agographs.pl: use brackets instead of hypens
Peter Müller [Mon, 27 Apr 2020 15:25:15 +0000 (17:25 +0200)] 
graphs.pl: use brackets instead of hypens

This simply makes more sense in most languages, as INPUT, OUTPUT and
FORWARD are special cases of firewall hits in general.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agode.pl: mention technical detail regarding new not SYN packets
Peter Müller [Mon, 27 Apr 2020 15:24:52 +0000 (17:24 +0200)] 
de.pl: mention technical detail regarding new not SYN packets

Since an appropriate translation of the firewall hits graph is not
possible due to limited space, mentioning "NewNotSYN" at least clarifies
the relationship between "Verworfene neue Pakete ohne SYN-Markierung
protokollieren" and "NewNotSYN".

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoen.pl: fix spelling of "SYN"
Peter Müller [Mon, 27 Apr 2020 15:24:27 +0000 (17:24 +0200)] 
en.pl: fix spelling of "SYN"

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agographs.pl: fix spelling of "SYN"
Peter Müller [Mon, 27 Apr 2020 15:24:06 +0000 (17:24 +0200)] 
graphs.pl: fix spelling of "SYN"

This merely is a cosmetic change, but since we are dealing with network
packets here, the SYN flag must be capitalised.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agotmux: Update to 3.1
Matthias Fischer [Sat, 25 Apr 2020 05:00:33 +0000 (07:00 +0200)] 
tmux: Update to 3.1

For details see:
https://raw.githubusercontent.com/tmux/tmux/3.1/CHANGES

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add BerkeleyDB, berkeley, berkeley-compat and openldap
Arne Fitzenreiter [Sat, 9 May 2020 12:09:35 +0000 (12:09 +0000)] 
core145: add BerkeleyDB, berkeley, berkeley-compat and openldap

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agonetatalk: New package
Michael Tremer [Fri, 24 Apr 2020 10:28:12 +0000 (10:28 +0000)] 
netatalk: New package

This package adds a daemon for Apple's File Protocol

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoberkeley: Re-add 4.4 as compat package
Michael Tremer [Fri, 24 Apr 2020 10:28:11 +0000 (10:28 +0000)] 
berkeley: Re-add 4.4 as compat package

We have loads of packages linked against the older
version which is difficult to update.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoberkeley: Update to 5.3.28
Michael Tremer [Fri, 24 Apr 2020 10:28:10 +0000 (10:28 +0000)] 
berkeley: Update to 5.3.28

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoopenldap: Update to 2.4.49
Michael Tremer [Fri, 24 Apr 2020 10:28:09 +0000 (10:28 +0000)] 
openldap: Update to 2.4.49

This patch removes slapd which is unused in IPFire.

Everything linked against the old version needs to
be shipped with this update.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoBerkeleyDB: Update to 0.63
Michael Tremer [Fri, 24 Apr 2020 10:28:08 +0000 (10:28 +0000)] 
BerkeleyDB: Update to 0.63

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agolang: Update French translation
Stéphane Pautrel [Thu, 23 Apr 2020 12:23:29 +0000 (12:23 +0000)] 
lang: Update French translation

* Adds testing and unstable repository via Pakfire
* TLS email modes
* etc.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoUpdate translations
Michael Tremer [Thu, 23 Apr 2020 12:23:28 +0000 (12:23 +0000)] 
Update translations

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add hyperscan
Arne Fitzenreiter [Sat, 9 May 2020 12:01:03 +0000 (12:01 +0000)] 
core145: add hyperscan

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agohyperscan: Update to version 5.2.1
Erik Kapfer [Wed, 22 Apr 2020 16:01:13 +0000 (16:01 +0000)] 
hyperscan: Update to version 5.2.1

Several bugfixes, improvements and extra detection has been added.
For the full changelog, take a look into here -->
https://github.com/intel/hyperscan/blob/master/CHANGELOG.md .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add libenvent2
Arne Fitzenreiter [Sat, 9 May 2020 11:52:14 +0000 (11:52 +0000)] 
core145: add libenvent2

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoTor: bump package version
Peter Müller [Sat, 18 Apr 2020 12:49:29 +0000 (14:49 +0200)] 
Tor: bump package version

This is required in order to ship Tor compiled against libevent
2.1.11-stable.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agolibevent2: update to 2.1.11-stable
Peter Müller [Sat, 18 Apr 2020 12:49:05 +0000 (14:49 +0200)] 
libevent2: update to 2.1.11-stable

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add libusb
Arne Fitzenreiter [Sat, 9 May 2020 11:49:19 +0000 (11:49 +0000)] 
core145: add libusb

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agolibusb: update to 1.0.23
Peter Müller [Sat, 18 Apr 2020 10:06:02 +0000 (12:06 +0200)] 
libusb: update to 1.0.23

Fixes: #11480
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoOpenVPN: Fix for N2N plausibility checks
Erik Kapfer [Wed, 15 Apr 2020 13:24:04 +0000 (15:24 +0200)] 
OpenVPN: Fix for N2N plausibility checks

Fixes #12335
If no N2N name has been set, no directory and config has been created so it can not be deleted.

'goto VPNCONF_ERROR;' has been missing for N2N checks.
Fixed also code formatting.

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years ago70-log.menu: Fix ovpnclients section.
Stefan Schantl [Mon, 4 May 2020 18:10:56 +0000 (20:10 +0200)] 
70-log.menu: Fix ovpnclients section.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agompd: bump version that is linked against new ffmpeg
Arne Fitzenreiter [Sun, 3 May 2020 16:02:06 +0000 (16:02 +0000)] 
mpd: bump version that is linked against new ffmpeg

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoborgbackup: fix 32bit rootfiles
Arne Fitzenreiter [Sun, 3 May 2020 07:47:44 +0000 (09:47 +0200)] 
borgbackup: fix 32bit rootfiles

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoLangs/de.pl: Add translations for OpenVPN roadwarrior connection log.
Stefan Schantl [Mon, 13 Apr 2020 07:45:50 +0000 (09:45 +0200)] 
Langs/de.pl: Add translations for OpenVPN roadwarrior connection log.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agovnstat: remove unmount ramdisk message
Arne Fitzenreiter [Sat, 2 May 2020 18:01:35 +0000 (18:01 +0000)] 
vnstat: remove unmount ramdisk message

this message will also print if no ramdisk is used at all.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agovnstat 2.6: Fix for initscript - removed 'evaluate_retval'
Matthias Fischer [Mon, 13 Apr 2020 12:50:58 +0000 (14:50 +0200)] 
vnstat 2.6: Fix for initscript - removed 'evaluate_retval'

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agowebui: update rootfile
Arne Fitzenreiter [Sat, 2 May 2020 10:43:20 +0000 (10:43 +0000)] 
webui: update rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocoreutils: add uptream patch to fix build on aarch64
Arne Fitzenreiter [Sat, 2 May 2020 10:39:19 +0000 (10:39 +0000)] 
coreutils: add uptream patch to fix build on aarch64

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add vnstat
Arne Fitzenreiter [Sat, 2 May 2020 10:38:51 +0000 (10:38 +0000)] 
core145: add vnstat

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add open vpn changes
Arne Fitzenreiter [Fri, 1 May 2020 19:28:08 +0000 (19:28 +0000)] 
core145: add open vpn changes

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoopenvpn: Store connection times in ASCII timestamps
Michael Tremer [Mon, 13 Apr 2020 11:50:18 +0000 (11:50 +0000)] 
openvpn: Store connection times in ASCII timestamps

This format seems to be a lot easier to handle in SQLite queries.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoopenvpn: Add metrics script
Michael Tremer [Mon, 13 Apr 2020 11:50:17 +0000 (11:50 +0000)] 
openvpn: Add metrics script

This script is called when an OpenVPN Roadwarrior client
connects or disconnect and logs the start and duration
of the session.

This can be used to monitor session duration and data transfer.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoLangs/en.pl: Add duration.
Stefan Schantl [Mon, 13 Apr 2020 07:45:49 +0000 (09:45 +0200)] 
Langs/en.pl: Add duration.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoAdd ovpnclients page to log menu.
Stefan Schantl [Mon, 13 Apr 2020 07:45:48 +0000 (09:45 +0200)] 
Add ovpnclients page to log menu.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoOpenVPN Log: Add connection duration
Michael Tremer [Mon, 13 Apr 2020 07:45:47 +0000 (09:45 +0200)] 
OpenVPN Log: Add connection duration

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoOpenVPN: Capitalise some headings and labels
Michael Tremer [Mon, 13 Apr 2020 07:45:46 +0000 (09:45 +0200)] 
OpenVPN: Capitalise some headings and labels

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Align traffic values to the right side.
Stefan Schantl [Mon, 13 Apr 2020 07:45:45 +0000 (09:45 +0200)] 
ovpnclients.dat: Align traffic values to the right side.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Fix type in received.
Stefan Schantl [Mon, 13 Apr 2020 07:45:44 +0000 (09:45 +0200)] 
ovpnclients.dat: Fix type in received.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agogeneral-functions.pl: formatBytes() Fix computing the correct unit.
Stefan Schantl [Mon, 13 Apr 2020 07:45:43 +0000 (09:45 +0200)] 
general-functions.pl: formatBytes() Fix computing the correct unit.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Do not perform DB actions if there is an error message.
Stefan Schantl [Mon, 13 Apr 2020 07:45:42 +0000 (09:45 +0200)] 
ovpnclients.dat: Do not perform DB actions if there is an error message.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Display error when the to date is not later than the from date.
Stefan Schantl [Mon, 13 Apr 2020 07:45:41 +0000 (09:45 +0200)] 
ovpnclients.dat: Display error when the to date is not later than the from date.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Display a notice if there are no entries.
Stefan Schantl [Mon, 13 Apr 2020 07:45:40 +0000 (09:45 +0200)] 
ovpnclients.dat: Display a notice if there are no entries.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Convert timestamps into localtime.
Stefan Schantl [Mon, 13 Apr 2020 07:45:39 +0000 (09:45 +0200)] 
ovpnclients.dat: Convert timestamps into localtime.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Add table header.
Stefan Schantl [Mon, 13 Apr 2020 07:45:38 +0000 (09:45 +0200)] 
ovpnclients.dat: Add table header.

The header will be dynamically generated, according the items which will
be displayed.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoLangs: Add strings for disconnect, sent and recieved.
Stefan Schantl [Mon, 13 Apr 2020 07:45:37 +0000 (09:45 +0200)] 
Langs: Add strings for disconnect, sent and recieved.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Display traffic details in a human-readable format.
Stefan Schantl [Mon, 13 Apr 2020 07:45:36 +0000 (09:45 +0200)] 
ovpnclients.dat: Display traffic details in a human-readable format.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agogeneral-functions.pl: Add formatBytes() function.
Stefan Schantl [Mon, 13 Apr 2020 07:45:35 +0000 (09:45 +0200)] 
general-functions.pl: Add formatBytes() function.

This function can be used to convert an amount of bytes to a
humand-readable format.

For example "3221225472" will become "3MB".

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoovpnclients.dat: Fix hard coded language string
Stefan Schantl [Mon, 13 Apr 2020 07:45:34 +0000 (09:45 +0200)] 
ovpnclients.dat: Fix hard coded language string

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoOpenVPN: Fix query when selecting sessions only
Michael Tremer [Mon, 13 Apr 2020 07:45:33 +0000 (09:45 +0200)] 
OpenVPN: Fix query when selecting sessions only

Previously some sessions were selected which did not qualify
for the search.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoopenvpn: Add WUI page for client usage statistics
Stefan Schantl [Mon, 13 Apr 2020 07:45:32 +0000 (09:45 +0200)] 
openvpn: Add WUI page for client usage statistics

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add coreutils
Arne Fitzenreiter [Fri, 1 May 2020 19:10:17 +0000 (19:10 +0000)] 
core145: add coreutils

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocoreutils: update to 8.32
Peter Müller [Sat, 11 Apr 2020 17:22:58 +0000 (19:22 +0200)] 
coreutils: update to 8.32

Cc: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoautomake: update to 1.16.2
Peter Müller [Sat, 11 Apr 2020 17:22:12 +0000 (19:22 +0200)] 
automake: update to 1.16.2

This is required in order to build coreutils 8.32.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoRevert "libwww-perl: update to 6.43"
Arne Fitzenreiter [Fri, 1 May 2020 13:04:09 +0000 (13:04 +0000)] 
Revert "libwww-perl: update to 6.43"

This reverts commit 3bcd393e18c76683f7649368bd30c5c57789f7e5.
this has a corrupt rootfile:
Error! '/x86_64' in rootfiles files found!
./config/rootfiles/common/libwww-perl:#usr/lib/perl5/site_perl/5.30.0/x86_64-linux-thread-multi/auto/libwww
./config/rootfiles/common/libwww-perl:#usr/lib/perl5/site_perl/5.30.0/x86_64-linux-thread-multi/auto/libwww/perl
./config/rootfiles/common/libwww-perl:usr/lib/perl5/site_perl/5.30.0/x86_64-linux-thread-multi/auto/libwww/perl/.packlist
Replace by MACHINE !

and if i fix this it break pakfire.

3 years agoiproute2: fix rootfile
Arne Fitzenreiter [Thu, 30 Apr 2020 22:38:20 +0000 (00:38 +0200)] 
iproute2: fix rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add vnstat changes
Arne Fitzenreiter [Thu, 30 Apr 2020 15:26:59 +0000 (15:26 +0000)] 
core145: add vnstat changes

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add libwww-perl
Arne Fitzenreiter [Thu, 30 Apr 2020 15:15:24 +0000 (15:15 +0000)] 
core145: add libwww-perl

3 years agolibwww-perl: update to 6.43
Peter Müller [Sat, 11 Apr 2020 14:14:44 +0000 (16:14 +0200)] 
libwww-perl: update to 6.43

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add pakfire functions.pl
Arne Fitzenreiter [Thu, 30 Apr 2020 15:13:37 +0000 (15:13 +0000)] 
core145: add pakfire functions.pl

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoPakfire: do not leak upstream proxy password in log messages
Peter Müller [Sat, 11 Apr 2020 10:20:01 +0000 (12:20 +0200)] 
Pakfire: do not leak upstream proxy password in log messages

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoPakfire: fix upstream proxy usage
Peter Müller [Sat, 11 Apr 2020 10:19:20 +0000 (12:19 +0200)] 
Pakfire: fix upstream proxy usage

This patch ensures Pakfire will download updates via the configured
upstream proxy (if any) for both HTTP and HTTPS.

Fixes: #12357
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agocore145: add system.cgi
Arne Fitzenreiter [Thu, 30 Apr 2020 15:10:08 +0000 (15:10 +0000)] 
core145: add system.cgi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agosystem.cgi: correctly translate CPU frequency
Peter Müller [Sat, 11 Apr 2020 09:02:26 +0000 (11:02 +0200)] 
system.cgi: correctly translate CPU frequency

The CPU frequency diagram used the same "translation" as the CPU load,
which was confusing. This patch introduces a dedicated translation for
"CPU frequency", which makes things a little bit better but still does
not solve a Deppenleerzeichen ("CPU-Frequenz Diagramm") in the German
translation.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agolang: fix typo (MacVTtap != MacVTap)
Peter Müller [Sat, 11 Apr 2020 08:25:29 +0000 (10:25 +0200)] 
lang: fix typo (MacVTtap != MacVTap)

Fixes: #12339
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 years agoborgbackup: Fixes DEP error. Update to 1.1.11
Erik Kapfer [Sat, 11 Apr 2020 05:26:58 +0000 (07:26 +0200)] 
borgbackup: Fixes DEP error. Update to 1.1.11

Fixes #12356

Several fixes but also new features has been added with this version.
Full changelog can be found in here --> https://github.com/borgbackup/borg/blob/1.1.11/docs/changes.rst#version-1111-2020-03-08 .

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>