]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
7 years agomake.sh: add autoamke to toolchain to fix coreutils build fail
Marcel Lorenz [Sat, 3 Sep 2016 08:28:57 +0000 (10:28 +0200)] 
make.sh: add autoamke to toolchain to fix coreutils build fail

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agopkg-config: update lfs file to build with new dejagnu
Marcel Lorenz [Sat, 3 Sep 2016 08:28:56 +0000 (10:28 +0200)] 
pkg-config: update lfs file to build with new dejagnu

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agodejagnu: update to 1.6
Marcel Lorenz [Sat, 3 Sep 2016 08:28:55 +0000 (10:28 +0200)] 
dejagnu: update to 1.6

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agotcl: update to 8.6.6
Marcel Lorenz [Sat, 3 Sep 2016 08:28:54 +0000 (10:28 +0200)] 
tcl: update to 8.6.6

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoflex: update to 2.6.1
Marcel Lorenz [Sat, 3 Sep 2016 08:28:53 +0000 (10:28 +0200)] 
flex: update to 2.6.1

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agodiffutils: update to 3.5
Marcel Lorenz [Sat, 3 Sep 2016 08:30:44 +0000 (10:30 +0200)] 
diffutils: update to 3.5

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agostrongswan 5.5.0: update for rootfile
Matthias Fischer [Fri, 23 Sep 2016 14:51:36 +0000 (16:51 +0200)] 
strongswan 5.5.0: update for rootfile

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoasterisk addon: update to 11.23.1
Dirk Wagner [Thu, 22 Sep 2016 07:05:10 +0000 (09:05 +0200)] 
asterisk addon: update to 11.23.1

Changelog: http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-11-current

Signed-off-by: Dirk Wagner <dirk.wagner@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agomonit addon: update to 5.19.0
Dirk Wagner [Thu, 22 Sep 2016 07:59:39 +0000 (09:59 +0200)] 
monit addon: update to 5.19.0

See changelog https://mmonit.com/monit/changes for details.

Signed-off-by: Dirk Wagner <dirk.wagner@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoFix URL to list of public name servers in dns.cgi
Jonatan Schlag [Thu, 22 Sep 2016 10:03:33 +0000 (12:03 +0200)] 
Fix URL to list of public name servers in dns.cgi

We have only one english wiki, so the link to the list of public
dns servers can point directly to the right page.
(The link was also not correct).

Fixes: #11191
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge remote-tracking branch 'origin/core105' into next
Arne Fitzenreiter [Fri, 23 Sep 2016 16:49:06 +0000 (18:49 +0200)] 
Merge remote-tracking branch 'origin/core105' into next

7 years agocore105: add openssl sse2 binaries core105 v2.19-core105
Arne Fitzenreiter [Fri, 23 Sep 2016 08:30:34 +0000 (10:30 +0200)] 
core105: add openssl sse2 binaries

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agocore105: fix rootfile.
Arne Fitzenreiter [Thu, 22 Sep 2016 15:44:06 +0000 (17:44 +0200)] 
core105: fix rootfile.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agostrongswan: Update to 5.5.0
Michael Tremer [Thu, 22 Sep 2016 13:47:47 +0000 (14:47 +0100)] 
strongswan: Update to 5.5.0

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge branch 'core105' into next
Michael Tremer [Thu, 22 Sep 2016 11:05:13 +0000 (12:05 +0100)] 
Merge branch 'core105' into next

7 years agoTag Core Update 105
Michael Tremer [Thu, 22 Sep 2016 11:04:18 +0000 (12:04 +0100)] 
Tag Core Update 105

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoopenssl: Update to 1.0.2i
Michael Tremer [Thu, 22 Sep 2016 11:02:32 +0000 (12:02 +0100)] 
openssl: Update to 1.0.2i

https://www.openssl.org/news/openssl-1.0.2-notes.html

This release fixes various security flaws:

* OCSP Status Request extension unbounded memory growth (CVE-2016-6304)
* SWEET32 Mitigation (CVE-2016-2183)
* OOB write in MDC2_Update() (CVE-2016-6303)
* Malformed SHA512 ticket DoS (CVE-2016-6302)
* OOB write in BN_bn2dec() (CVE-2016-2182)
* OOB read in TS_OBJ_print_bio() (CVE-2016-2180)
* Pointer arithmetic undefined behaviour (CVE-2016-2177)
* Constant time flag not preserved in DSA signing (CVE-2016-2178)
* DTLS buffered message DoS (CVE-2016-2179)
* DTLS replay protection DoS (CVE-2016-2181)
* Certificate message OOB reads (CVE-2016-6306)

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore105: Ship security update for libgcrypt
Michael Tremer [Thu, 22 Sep 2016 09:30:28 +0000 (10:30 +0100)] 
core105: Ship security update for libgcrypt

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibgcrypt: Update to 1.7.3
Matthias Fischer [Sat, 20 Aug 2016 10:33:55 +0000 (12:33 +0200)] 
libgcrypt: Update to 1.7.3

Fixes CVE-2016-6313

For details, see:
https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html
https://bugzilla.redhat.com/show_bug.cgi?id=1366105

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoStart Core Update 105
Michael Tremer [Thu, 22 Sep 2016 09:28:36 +0000 (10:28 +0100)] 
Start Core Update 105

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: Fix update.sh script
Jonatan Schlag [Fri, 2 Sep 2016 18:35:23 +0000 (20:35 +0200)] 
Libvirt: Fix update.sh script

The virtlogd could only be restarted when the daemons run. The update.sh
script tried to restart the daemon no matter if the daemons run or not.
This behaviour produce problems.

An If statement now checks if the daemon runs or not and execute the
command that is suitable for the situation.

Fixes: #11172
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoUpdate libvirt to 2.1
Jonatan Schlag [Sun, 28 Aug 2016 17:59:19 +0000 (19:59 +0200)] 
Update libvirt to 2.1

This is the update of libvirt to the latest version 2.1.
The most important change from a packager view is the new virtlogd
daemon.
This daemon handles the qemu output and wrote it to log files.

The require some changes:
- A new init script to start, stop restart the daemon called virtlogd.
The daemon is restart with SIGUSR1 (this is important because the daemon
keeps all pipelines etc. open).

This introduces a problem with the uninstall.sh install.sh script.
It is not possible to stop the daemon while virtual machines are
running, so the script update.sh execute from now not uninstall.sh and
install.sh instead it contains all steps from uninstall.sh install.sh
expect the start / stop routine for virtlogd. The daemon is just
restarted after the update, which makes sure that all changes take
effect.

- new symlinks in the uninstall.sh and install.sh script and some root
file changes because of the new virtlogd init script.
- the archive format changes from tar.gz to tar.xz

For Changelogs see:

https://libvirt.org/news-2015.html
https://libvirt.org/news.html (2017 and later:
https://libvirt.org/news-2016.html )

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoBUG11184: Error if DNAT address ends with 0 or 255 now disabled
Alexander Marx [Thu, 15 Sep 2016 13:31:48 +0000 (15:31 +0200)] 
BUG11184: Error if DNAT address ends with 0 or 255 now disabled

When using dnat addresses, it is possible to use big subnets and host addresses like 172.16.0.0/12.
These addresses where rejected because it was recognised as network address.
The check is now removed.

Signed-off-by: Alexander Marx <alexander.marx@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoRootfile update
Michael Tremer [Thu, 15 Sep 2016 10:04:11 +0000 (11:04 +0100)] 
Rootfile update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 14 Sep 2016 15:41:38 +0000 (16:41 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

7 years agopython-ipaddress: New package
Michael Tremer [Wed, 14 Sep 2016 15:41:12 +0000 (16:41 +0100)] 
python-ipaddress: New package

Required for the unbound DHCP leases bridge

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound+DHCP: Make sure to only remove old leases and not static hosts
Michael Tremer [Wed, 14 Sep 2016 15:35:41 +0000 (16:35 +0100)] 
unbound+DHCP: Make sure to only remove old leases and not static hosts

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound+DHCP: Read correct DHCP domain name for lease
Michael Tremer [Wed, 14 Sep 2016 15:29:53 +0000 (16:29 +0100)] 
unbound+DHCP: Read correct DHCP domain name for lease

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound+DHCP: Read existing leases from unbound
Michael Tremer [Wed, 14 Sep 2016 14:54:36 +0000 (15:54 +0100)] 
unbound+DHCP: Read existing leases from unbound

This allows us to restart unbound and all DHCP leases
will be re-imported even if the unbound-dhcp-leases-bridge is
not restarted.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge branch 'core104' into next
Arne Fitzenreiter [Tue, 13 Sep 2016 17:41:36 +0000 (19:41 +0200)] 
Merge branch 'core104' into next

7 years agokernel: update to 3.14.79. core104
Arne Fitzenreiter [Tue, 13 Sep 2016 17:39:43 +0000 (19:39 +0200)] 
kernel: update to 3.14.79.

7 years agoxen-image: fix kernel installation.
Arne Fitzenreiter [Tue, 13 Sep 2016 17:37:58 +0000 (19:37 +0200)] 
xen-image: fix kernel installation.

linux-pae will refuse to install if pae is not detected but /proc was not exist at image cration. fixed by adding a fake cpuinfo file...

7 years agounbound+DHCP: Set TTL for local leases to 1m
Michael Tremer [Mon, 12 Sep 2016 20:14:44 +0000 (21:14 +0100)] 
unbound+DHCP: Set TTL for local leases to 1m

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Start service after network has been brought up
Michael Tremer [Mon, 12 Sep 2016 20:13:25 +0000 (21:13 +0100)] 
unbound: Start service after network has been brought up

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Restart after local hosts have been modified
Michael Tremer [Mon, 12 Sep 2016 19:52:51 +0000 (20:52 +0100)] 
unbound: Restart after local hosts have been modified

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoDNS: Import local hosts into unbound
Michael Tremer [Mon, 12 Sep 2016 19:46:02 +0000 (20:46 +0100)] 
DNS: Import local hosts into unbound

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoStart unbound+DHCP bridge only when DHCP server is running
Michael Tremer [Mon, 12 Sep 2016 19:20:08 +0000 (20:20 +0100)] 
Start unbound+DHCP bridge only when DHCP server is running

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Start service at system boot
Michael Tremer [Mon, 12 Sep 2016 19:11:47 +0000 (20:11 +0100)] 
unbound: Start service at system boot

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoRootfile update
Michael Tremer [Mon, 12 Sep 2016 10:07:44 +0000 (11:07 +0100)] 
Rootfile update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agonext: rootfile updates for 'unbound' and 'initscripts'
Matthias Fischer [Sat, 10 Sep 2016 17:25:22 +0000 (19:25 +0200)] 
next: rootfile updates for 'unbound' and 'initscripts'

These two came to my view during the last builds. I hope they're ok now.

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agosquid: Update to 3.5.21
Matthias Fischer [Sat, 10 Sep 2016 12:35:39 +0000 (14:35 +0200)] 
squid: Update to 3.5.21

For details, see:
http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID_3_5_21.html

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoRootfile update
Michael Tremer [Fri, 9 Sep 2016 13:57:07 +0000 (14:57 +0100)] 
Rootfile update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge branch 'unbound' into next
Michael Tremer [Thu, 8 Sep 2016 18:50:45 +0000 (19:50 +0100)] 
Merge branch 'unbound' into next

7 years agounbound: Automatically scale configuration to system
Michael Tremer [Thu, 8 Sep 2016 18:46:43 +0000 (19:46 +0100)] 
unbound: Automatically scale configuration to system

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoBUG11177: pppoe password not required anymore
Alexander Marx [Thu, 8 Sep 2016 06:36:58 +0000 (08:36 +0200)] 
BUG11177: pppoe password not required anymore

fixes: #11177

There are providers which do not use passwords anymore.
For this reason the password field is no longer mandatory.

Signed-off-by: Alexander Marx <alexander.marx@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: Fix update.sh script
Jonatan Schlag [Fri, 2 Sep 2016 18:35:23 +0000 (20:35 +0200)] 
Libvirt: Fix update.sh script

The virtlogd could only be restarted when the daemons run. The update.sh
script tried to restart the daemon no matter if the daemons run or not.
This behaviour produce problems.

An If statement now checks if the daemon runs or not and execute the
command that is suitable for the situation.

Fixes: #11172
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoUpdate libvirt to 2.1
Jonatan Schlag [Sun, 28 Aug 2016 17:59:19 +0000 (19:59 +0200)] 
Update libvirt to 2.1

This is the update of libvirt to the latest version 2.1.
The most important change from a packager view is the new virtlogd
daemon.
This daemon handles the qemu output and wrote it to log files.

The require some changes:
- A new init script to start, stop restart the daemon called virtlogd.
The daemon is restart with SIGUSR1 (this is important because the daemon
keeps all pipelines etc. open).

This introduces a problem with the uninstall.sh install.sh script.
It is not possible to stop the daemon while virtual machines are
running, so the script update.sh execute from now not uninstall.sh and
install.sh instead it contains all steps from uninstall.sh install.sh
expect the start / stop routine for virtlogd. The daemon is just
restarted after the update, which makes sure that all changes take
effect.

- new symlinks in the uninstall.sh and install.sh script and some root
file changes because of the new virtlogd init script.
- the archive format changes from tar.gz to tar.xz

For Changelogs see:

https://libvirt.org/news-2015.html
https://libvirt.org/news.html (2017 and later:
https://libvirt.org/news-2016.html )

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 31 Aug 2016 21:40:16 +0000 (22:40 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

7 years agodnsmasq 2.76: latest patches (015-016)
Matthias Fischer [Wed, 17 Aug 2016 16:30:02 +0000 (18:30 +0200)] 
dnsmasq 2.76: latest patches (015-016)

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agognupg: Update to 1.4.21
Matthias Fischer [Tue, 23 Aug 2016 16:30:03 +0000 (18:30 +0200)] 
gnupg: Update to 1.4.21

Second try:

Update from 1.4.18 to 1.4.21, based on current 'next'.

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agonano: Update to 2.6.3
Matthias Fischer [Tue, 23 Aug 2016 16:32:54 +0000 (18:32 +0200)] 
nano: Update to 2.6.3

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge branch 'core104' into next
Arne Fitzenreiter [Mon, 22 Aug 2016 05:26:37 +0000 (07:26 +0200)] 
Merge branch 'core104' into next

7 years agosmartmontools: Update to 6.5
Matthias Fischer [Sat, 20 Aug 2016 21:51:20 +0000 (23:51 +0200)] 
smartmontools: Update to 6.5

For details, see:
https://www.smartmontools.org/browser/tags/RELEASE_6_5/smartmontools/NEWS

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibgpg-error: Update to 1.24
Matthias Fischer [Sat, 20 Aug 2016 10:39:17 +0000 (12:39 +0200)] 
libgpg-error: Update to 1.24

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibgcrypt: Update to 1.7.3
Matthias Fischer [Sat, 20 Aug 2016 10:33:55 +0000 (12:33 +0200)] 
libgcrypt: Update to 1.7.3

Fixes CVE-2016-6313

For details, see:
https://lists.gnupg.org/pipermail/gnupg-announce/2016q3/000395.html
https://bugzilla.redhat.com/show_bug.cgi?id=1366105

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibassuan: Update to 2.4.3
Matthias Fischer [Sat, 20 Aug 2016 10:20:10 +0000 (12:20 +0200)] 
libassuan: Update to 2.4.3

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agosquid: Update to 3.5.20 with latest patches (14067-14075)
Matthias Fischer [Fri, 19 Aug 2016 22:15:55 +0000 (00:15 +0200)] 
squid: Update to 3.5.20 with latest patches (14067-14075)

For details, see:
http://www.squid-cache.org/Versions/v3/3.5/changesets/

Since there were problems with "trailing white spaces" I started a new 'squid_3'
branch from scratch, based on current 'next'.
I hope this is what is needed and that it helps.

This one was built without errors and is running here without seen problems.

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agokernel: fix grsecurity patch.
Arne Fitzenreiter [Sun, 21 Aug 2016 20:40:12 +0000 (22:40 +0200)] 
kernel: fix grsecurity patch.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agokernel: update to 3.14.77
Arne Fitzenreiter [Sun, 21 Aug 2016 15:56:47 +0000 (17:56 +0200)] 
kernel: update to 3.14.77

fix performance issue with tcp ack security fix.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agokernel: update arm-multi grsec compile fix patch
Arne Fitzenreiter [Thu, 18 Aug 2016 20:35:43 +0000 (22:35 +0200)] 
kernel: update arm-multi grsec compile fix patch

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agokernel: add hyper-v: mark tsc unstable patch
Arne Fitzenreiter [Wed, 17 Aug 2016 18:37:07 +0000 (20:37 +0200)] 
kernel: add hyper-v: mark tsc unstable patch

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agokernel: update to 3.14.76
Arne Fitzenreiter [Wed, 17 Aug 2016 17:52:09 +0000 (19:52 +0200)] 
kernel: update to 3.14.76

this kernel has important tcp and ext4 fixes.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agoMerge branch 'core104' into next
Arne Fitzenreiter [Wed, 17 Aug 2016 17:51:01 +0000 (19:51 +0200)] 
Merge branch 'core104' into next

7 years agoLibvirt: load vhost_net before libvirtd start.
Jonatan Schlag [Sun, 14 Aug 2016 09:25:01 +0000 (11:25 +0200)] 
Libvirt: load vhost_net before libvirtd start.

If the  kernel module vhot_net is loaded, the performance of virtio
networking is better then without vhost_net.
So the module is loaded before libvirtd ist started to get the benefit
of vhost_net.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: fix configuration options
Jonatan Schlag [Sun, 14 Aug 2016 09:10:36 +0000 (11:10 +0200)] 
Libvirt: fix configuration options

Adds a missed - to -without-dbus and -with-interface.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: enable storage-fs
Jonatan Schlag [Sun, 14 Aug 2016 08:55:38 +0000 (10:55 +0200)] 
Libvirt: enable storage-fs

Fixes: 11154
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: load vhost_net before libvirtd start.
Jonatan Schlag [Sun, 14 Aug 2016 09:25:01 +0000 (11:25 +0200)] 
Libvirt: load vhost_net before libvirtd start.

If the  kernel module vhot_net is loaded, the performance of virtio
networking is better then without vhost_net.
So the module is loaded before libvirtd ist started to get the benefit
of vhost_net.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: fix configuration options
Jonatan Schlag [Sun, 14 Aug 2016 09:10:36 +0000 (11:10 +0200)] 
Libvirt: fix configuration options

Adds a missed - to -without-dbus and -with-interface.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: enable storage-fs
Jonatan Schlag [Sun, 14 Aug 2016 08:55:38 +0000 (10:55 +0200)] 
Libvirt: enable storage-fs

Fixes: 11154
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore104: revert adding customservices.
Arne Fitzenreiter [Sun, 7 Aug 2016 15:08:44 +0000 (17:08 +0200)] 
core104: revert adding customservices.

simply adding may use id's twice if the user has
added other services so we don't update this files.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agodnsmasq 2.76: latest patches (013-014)
Matthias Fischer [Sun, 7 Aug 2016 11:09:39 +0000 (13:09 +0200)] 
dnsmasq 2.76: latest patches (013-014)

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoAdd new package libusbredir
Jonatan Schlag [Sun, 7 Aug 2016 13:29:44 +0000 (15:29 +0200)] 
Add new package libusbredir

This package adds support for the use redirection of spice.
It is now possible to attach USB devices of the host where the spice
client run to the virtual machine.

The binary is not needed for this functionality and that's why they is
not shipped with the package

This feature is also enabled in qemu.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoRootfile update
Michael Tremer [Sun, 7 Aug 2016 14:02:08 +0000 (15:02 +0100)] 
Rootfile update

Forgot to commit this one

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound is not supposed to be a package
Michael Tremer [Sun, 7 Aug 2016 11:45:11 +0000 (12:45 +0100)] 
unbound is not supposed to be a package

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agomake.sh: Unbound depends on libevent
Michael Tremer [Sat, 6 Aug 2016 19:58:50 +0000 (20:58 +0100)] 
make.sh: Unbound depends on libevent

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Update dynamically configured DNS servers after connecting RED
Michael Tremer [Sat, 6 Aug 2016 18:41:27 +0000 (19:41 +0100)] 
unbound: Update dynamically configured DNS servers after connecting RED

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoAdd unboundctrl
Michael Tremer [Sat, 6 Aug 2016 18:32:34 +0000 (19:32 +0100)] 
Add unboundctrl

Control binary to relaunch unbound from the web user interface

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agowebinterface: Replace dnsmasq with unbound
Michael Tremer [Sat, 6 Aug 2016 18:30:14 +0000 (19:30 +0100)] 
webinterface: Replace dnsmasq with unbound

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoDrop dnsmasq
Michael Tremer [Sat, 6 Aug 2016 18:25:48 +0000 (19:25 +0100)] 
Drop dnsmasq

This will be replaced by unbound

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Rewrite configuration and initscript
Michael Tremer [Sat, 6 Aug 2016 18:20:27 +0000 (19:20 +0100)] 
unbound: Rewrite configuration and initscript

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoImport Unbound DHCP Lease Bridge
Michael Tremer [Sat, 6 Aug 2016 15:48:39 +0000 (16:48 +0100)] 
Import Unbound DHCP Lease Bridge

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Ship ICANN's certificates for trust anchor validation
Michael Tremer [Sat, 6 Aug 2016 14:24:00 +0000 (15:24 +0100)] 
unbound: Ship ICANN's certificates for trust anchor validation

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Update trust anchor once a day
Michael Tremer [Sat, 6 Aug 2016 14:20:07 +0000 (15:20 +0100)] 
unbound: Update trust anchor once a day

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agounbound: Install trust anchor in /var/lib/unbound
Michael Tremer [Sat, 6 Aug 2016 14:12:01 +0000 (15:12 +0100)] 
unbound: Install trust anchor in /var/lib/unbound

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agopython-daemon: New package
Michael Tremer [Sat, 6 Aug 2016 13:43:47 +0000 (14:43 +0100)] 
python-daemon: New package

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoset version to core104
Arne Fitzenreiter [Sat, 6 Aug 2016 10:21:42 +0000 (12:21 +0200)] 
set version to core104

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agoMerge remote-tracking branch 'origin/master' into next v2.19-core104
Arne Fitzenreiter [Sat, 6 Aug 2016 10:11:46 +0000 (12:11 +0200)] 
Merge remote-tracking branch 'origin/master' into next

7 years agocore104: add changed files
Arne Fitzenreiter [Sat, 6 Aug 2016 10:09:44 +0000 (12:09 +0200)] 
core104: add changed files

customservices and openssh.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agoNew package: python inotify
Michael Tremer [Fri, 5 Aug 2016 12:33:47 +0000 (13:33 +0100)] 
New package: python inotify

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoNew package: unbound 1.5.9
Marcel Lorenz [Tue, 2 Aug 2016 18:48:17 +0000 (20:48 +0200)] 
New package: unbound 1.5.9

Unbound is a validating, recursive, and caching DNS resolver.

https://www.unbound.net

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: Remove delay from start command in install.sh
Jonatan Schlag [Wed, 3 Aug 2016 07:47:13 +0000 (09:47 +0200)] 
Libvirt: Remove delay from start command in install.sh

Fixes: #11152
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agodnsmasq 2.76: latest patches from upstream (010-012)
Matthias Fischer [Sat, 23 Jul 2016 21:03:14 +0000 (23:03 +0200)] 
dnsmasq 2.76: latest patches from upstream (010-012)

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoLibvirt: Add backup
Jonatan Schlag [Tue, 2 Aug 2016 12:01:05 +0000 (14:01 +0200)] 
Libvirt: Add backup

The directory /etc/libvirt is backed up on uninstallation  and is
restored on installation.

Alle Files in  /var are commented in the rootfile so they are not
removed on uninstallation.
Because of the fact that the directories are not shipped with the
package they were created at installation time.
The permissions of 3 directories are changed because the qemu user is
nobody and the qemu group is kvm, so the permissions must be nobody:kvm

Fixes: #11151
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoopenssh: Update to 7.3p1
Michael Tremer [Tue, 2 Aug 2016 15:06:35 +0000 (16:06 +0100)] 
openssh: Update to 7.3p1

Includes various security fixes:

 * sshd(8): Mitigate a potential denial-of-service attack against
   the system's crypt(3) function via sshd(8). An attacker could
   send very long passwords that would cause excessive CPU use in
   crypt(3). sshd(8) now refuses to accept password authentication
   requests of length greater than 1024 characters. Independently
   reported by Tomas Kuthan (Oracle), Andres Rojas and Javier Nieto.

 * sshd(8): Mitigate timing differences in password authentication
   that could be used to discern valid from invalid account names
   when long passwords were sent and particular password hashing
   algorithms are in use on the server. CVE-2016-6210, reported by
   EddieEzra.Harari at verint.com

 * ssh(1), sshd(8): Fix observable timing weakness in the CBC padding
   oracle countermeasures. Reported by Jean Paul Degabriele, Kenny
   Paterson, Torben Hansen and Martin Albrecht. Note that CBC ciphers
   are disabled by default and only included for legacy compatibility.

 * ssh(1), sshd(8): Improve operation ordering of MAC verification for
   Encrypt-then-MAC (EtM) mode transport MAC algorithms to verify the
   MAC before decrypting any ciphertext. This removes the possibility
   of timing differences leaking facts about the plaintext, though no
   such leakage has been observed.  Reported by Jean Paul Degabriele,
   Kenny Paterson, Torben Hansen and Martin Albrecht.

 * sshd(8): (portable only) Ignore PAM environment vars when
   UseLogin=yes. If PAM is configured to read user-specified
   environment variables and UseLogin=yes in sshd_config, then a
   hostile local user may attack /bin/login via LD_PRELOAD or
   similar environment variables set via PAM. CVE-2015-8325,
   found by Shayan Sadigh.

Fixes: #11160
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoImprove wording of the Guardian translations
Michael Tremer [Tue, 2 Aug 2016 11:43:01 +0000 (12:43 +0100)] 
Improve wording of the Guardian translations

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoUpdate translation
Michael Tremer [Tue, 2 Aug 2016 11:18:45 +0000 (12:18 +0100)] 
Update translation

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMerge remote-tracking branch 'stevee/guardian-2.0' into next
Michael Tremer [Tue, 2 Aug 2016 11:18:29 +0000 (12:18 +0100)] 
Merge remote-tracking branch 'stevee/guardian-2.0' into next

7 years agohtop: Update to 2.0.2
Matthias Fischer [Sun, 31 Jul 2016 17:43:26 +0000 (19:43 +0200)] 
htop: Update to 2.0.2

For details, see:
http://hisham.hm/htop/index.php?page=downloads

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoguardian: Update to the tagged release version.
Stefan Schantl [Sat, 30 Jul 2016 09:31:08 +0000 (11:31 +0200)] 
guardian: Update to the tagged release version.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Fri, 29 Jul 2016 16:58:56 +0000 (18:58 +0200)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next