]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
7 years agoUpdate spice to version 0.12.8
Jonatan Schlag [Sat, 16 Jul 2016 10:18:52 +0000 (12:18 +0200)] 
Update spice to version 0.12.8

This is an security update.
Recent were 2 serious security vulnerabilities published.
This patch update spice to a version which is not vulnerable.

Changelog:

Changes in 0.12.8:

==================
* Fixes for CVE-2016-0749 and CVE-2016-2150

Changes in 0.12.7:
==================
* spice-server will now send TCP keepalive probes on the TCP connections
  it
  uses. This can prevent unwanted idle disconnections if proxies are
  used
  between the client and the host.
* Fix important memory usage when the webdav channel is used
* Do not disconnect when the client requests an unsupported compression
  type
* Fix a few race conditions
* Fix display glitch when using XSpice
* Improve help string for 'replay -s'
* Fix crashes in corner cases (buggy spice-html5 + win10, vnc + SPICE
  port
  configured, USB webcam redirection over a slow link)
* Fix various compilation warning when building on 32 bit machines
* Some fixes for big-endian machines, more work is likely to be needed
* Do not build static libraries by default, this can be reenabled with
  --enable-static
* Fix small leak in MJPEG code

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibtiff: Bump release
Michael Tremer [Sat, 16 Jul 2016 10:24:41 +0000 (11:24 +0100)] 
libtiff: Bump release

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibtiff: update to 4.0.6
Marcel Lorenz [Fri, 15 Jul 2016 17:13:07 +0000 (19:13 +0200)] 
libtiff: update to 4.0.6

The pak version from spandsp sane and foomatic are increased by one
to ship packages build against new libtiff.

A compat is not needed

http://www.remotesensing.org/libtiff/v4.0.6.html

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Reviewed-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore104: Ship recently updated which
Michael Tremer [Sat, 16 Jul 2016 09:57:04 +0000 (10:57 +0100)] 
core104: Ship recently updated which

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agowhich: update to 2.21
Marcel Lorenz [Fri, 15 Jul 2016 16:42:46 +0000 (18:42 +0200)] 
which: update to 2.21

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoUpdate spice-protocol to 0.12.11
Jonatan Schlag [Fri, 15 Jul 2016 15:27:15 +0000 (17:27 +0200)] 
Update spice-protocol to 0.12.11

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agokernel: Fix broken syntax in configuration file
Michael Tremer [Fri, 15 Jul 2016 10:08:56 +0000 (11:08 +0100)] 
kernel: Fix broken syntax in configuration file

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoBuild bzip2 before pcre
Michael Tremer [Fri, 15 Jul 2016 08:55:49 +0000 (09:55 +0100)] 
Build bzip2 before pcre

pcre is now depending on bzip2

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoFix in libvirt install.sh/uninstall.sh
Jonatan Schlag [Fri, 15 Jul 2016 08:28:17 +0000 (10:28 +0200)] 
Fix in libvirt install.sh/uninstall.sh

The libvirt daemon was not started after installation because the
initscritp is named 'libvirtd' not like the package 'libvirt'.
The same problem appear in the uninstall.sh. The service was not
stopped.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore104: Ship recently updated packages
Michael Tremer [Thu, 14 Jul 2016 22:36:49 +0000 (23:36 +0100)] 
core104: Ship recently updated packages

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoacpid: update to 2.0.26
Marcel Lorenz [Sun, 26 Jun 2016 07:58:14 +0000 (09:58 +0200)] 
acpid: update to 2.0.26

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agopcre: update to 8.39
Marcel Lorenz [Sun, 26 Jun 2016 07:42:04 +0000 (09:42 +0200)] 
pcre: update to 8.39

http://www.pcre.org/original/changelog.txt

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agopopt: update to 1.16
Marcel Lorenz [Sun, 26 Jun 2016 08:02:54 +0000 (10:02 +0200)] 
popt: update to 1.16

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocurl: update to 7.49.1
Marcel Lorenz [Sun, 26 Jun 2016 08:07:44 +0000 (10:07 +0200)] 
curl: update to 7.49.1

https://curl.haxx.se/changes.html#7_49_1

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoiputils: update to s20160308
Marcel Lorenz [Sun, 26 Jun 2016 08:08:58 +0000 (10:08 +0200)] 
iputils: update to s20160308

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoacl: update to 2.2.52
Marcel Lorenz [Sun, 26 Jun 2016 08:38:18 +0000 (10:38 +0200)] 
acl: update to 2.2.52

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibcap: update to 2.25
Marcel Lorenz [Sun, 26 Jun 2016 08:33:03 +0000 (10:33 +0200)] 
libcap: update to 2.25

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocollectd: Ignore *phys, macvtap* and vnet* interfaces
Michael Tremer [Wed, 13 Jul 2016 15:55:29 +0000 (16:55 +0100)] 
collectd: Ignore *phys, macvtap* and vnet* interfaces

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agodnsmasq 2.76: latest patches from upstream (004-009)
Matthias Fischer [Tue, 12 Jul 2016 10:37:19 +0000 (12:37 +0200)] 
dnsmasq 2.76: latest patches from upstream (004-009)

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agodnsmasq 2.76: latest patches from upstream (001-003)
Matthias Fischer [Sat, 9 Jul 2016 10:27:37 +0000 (12:27 +0200)] 
dnsmasq 2.76: latest patches from upstream (001-003)

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agop7zip: add CVE-2016-2334 and CVE-2016-2335 patches
Arne Fitzenreiter [Mon, 11 Jul 2016 14:27:58 +0000 (16:27 +0200)] 
p7zip: add CVE-2016-2334 and CVE-2016-2335 patches

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Mon, 11 Jul 2016 13:39:53 +0000 (15:39 +0200)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next

7 years agokernel: disable amd ccp support
Arne Fitzenreiter [Mon, 11 Jul 2016 08:42:51 +0000 (10:42 +0200)] 
kernel: disable amd ccp support

ccp based trng of the apu2 produce none random data.
Aes accleration is also not used because IPFire prefere
AES-NI if this is supported.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agoFix compound nouns for mail service feature
Michael Tremer [Sat, 2 Jul 2016 10:18:38 +0000 (12:18 +0200)] 
Fix compound nouns for mail service feature

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agokernel: arm7-multi: enable ohci_hcd
Arne Fitzenreiter [Thu, 30 Jun 2016 18:29:40 +0000 (20:29 +0200)] 
kernel: arm7-multi: enable ohci_hcd

needed for usb1.1 support on BananaPi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agokernel: update to 3.14.74
Arne Fitzenreiter [Wed, 29 Jun 2016 15:04:28 +0000 (17:04 +0200)] 
kernel: update to 3.14.74

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agobackports: r8152 add lenovo and nvidia usb id
Arne Fitzenreiter [Wed, 29 Jun 2016 15:00:29 +0000 (17:00 +0200)] 
backports: r8152 add lenovo and nvidia usb id

this id's are blacklisted in new cdc_ether module
because the r8152 module should used but the
3.14 module not know this id's.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agocore104: Ship updated libarchive
Michael Tremer [Mon, 27 Jun 2016 22:18:39 +0000 (23:18 +0100)] 
core104: Ship updated libarchive

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibarchive: update to 3.2.1
Marcel Lorenz [Sun, 26 Jun 2016 07:27:58 +0000 (09:27 +0200)] 
libarchive: update to 3.2.1

Fixes CVE-2016-4301
Libarchive mtree parse_device Code Execution Vulnerability

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore 104: Add updated snort.
Stefan Schantl [Wed, 22 Jun 2016 12:19:24 +0000 (14:19 +0200)] 
core 104: Add updated snort.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agocore 104: Add changed ids.cgi.
Stefan Schantl [Wed, 22 Jun 2016 12:18:36 +0000 (14:18 +0200)] 
core 104: Add changed ids.cgi.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agosnort: Rootfile update.
Stefan Schantl [Wed, 22 Jun 2016 12:13:49 +0000 (14:13 +0200)] 
snort: Rootfile update.

Rootfile update for snort 2.9.8.2 which has been overlocked in
commit 5a5e5f04a7cb2a6c39be2a53205d42b99ab80885.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agoAdd updated ddns to core 104.
Stefan Schantl [Tue, 21 Jun 2016 10:02:49 +0000 (12:02 +0200)] 
Add updated ddns to core 104.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agoddns: Update to version 010.
Stefan Schantl [Tue, 21 Jun 2016 09:59:18 +0000 (11:59 +0200)] 
ddns: Update to version 010.

This update fixes some smaller issues on various dynamic DNS
providers and adds support for DuckDNS as new provider.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Stefan Schantl [Tue, 21 Jun 2016 08:08:07 +0000 (10:08 +0200)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

7 years agoChange the default qemu user and group of libvirt
Jonatan Schlag [Fri, 17 Jun 2016 11:06:41 +0000 (13:06 +0200)] 
Change the default qemu user and group of libvirt

Changes the libvirt user to nobody and the group to kvm this is a bit
safer as to use root for both.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoQemu: add a group kvm to access /dev/kvm eaiser
Jonatan Schlag [Fri, 17 Jun 2016 11:06:40 +0000 (13:06 +0200)] 
Qemu: add a group kvm to access /dev/kvm eaiser

As a normal user, it is not possible to use qemu with KVM. This is bad
because it is better when it is possible to start the machine with a
less privileged user. To achieve this a group KVM is created and the
access to /dev/kvm is allowed for this group. So every user in this
group can use qemu with KVM.
This change is also useful for libvirt because the VMs can be started
with user nobody and group kvm.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoRootfile update
Michael Tremer [Sun, 19 Jun 2016 08:54:32 +0000 (09:54 +0100)] 
Rootfile update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore104: Ship updated shadow-utils and remove old files
Michael Tremer [Fri, 17 Jun 2016 12:07:10 +0000 (13:07 +0100)] 
core104: Ship updated shadow-utils and remove old files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoshadow: update to 4.2.1
Marcel Lorenz [Sat, 19 Mar 2016 07:10:25 +0000 (08:10 +0100)] 
shadow: update to 4.2.1

The "groups" from the coreutils package is used (/usr/bin/groups)

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore104: Ship updated pakfire functions.sh
Michael Tremer [Thu, 16 Jun 2016 08:34:24 +0000 (09:34 +0100)] 
core104: Ship updated pakfire functions.sh

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoFix in pakfire functions.sh
Jonatan Schlag [Fri, 10 Jun 2016 08:13:41 +0000 (10:13 +0200)] 
Fix in pakfire functions.sh

The if statement in line 89 and 99 are useless with the -e
conditional expression because it returns true if the path ist a
regular file or a directory.
So "/etc/init.d/ " returns true and "/etc/init.d/avahi" return also true,
but the statement should return only true if we have a regular file.
So -f if the right conditional expression, and we only try to execute
the init script if the path "/etc/init.d/${1}" points to a regular file.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoChange the default libvirt remote user to libvirt-remote
Jonatan Schlag [Fri, 10 Jun 2016 08:57:13 +0000 (10:57 +0200)] 
Change the default libvirt remote user to libvirt-remote

It is possible to communicate per ssh via a socket with libvirt. It is
not a good idea to do this as root, so the remote user is now
libvirt-remote. Only this user or users in the group libvirt-remote can
communicate with the socket.
The user libvirt-remote is created without a password. The users have to
set a password for this user after installation.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore104: Add ntp update
Michael Tremer [Thu, 16 Jun 2016 08:28:34 +0000 (09:28 +0100)] 
core104: Add ntp update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agontp: Update to 4.2.8p8
Matthias Fischer [Tue, 14 Jun 2016 10:44:48 +0000 (12:44 +0200)] 
ntp: Update to 4.2.8p8

It addresses 1 high- and 4 low--severity security issues, 4 bugfixes,
and contains other improvements over 4.2.8p7.

For a complete list, see:
http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agontp: Update to 4.2.8p7
Matthias Fischer [Sun, 1 May 2016 10:29:02 +0000 (12:29 +0200)] 
ntp: Update to 4.2.8p7

It addresses 11 low- and medium-severity security issues, 16 bugfixes,
and contains other improvements over 4.2.8p6.

For a complete list, see:
http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agontp: Update to 4.2.8p6
Matthias Fischer [Sat, 6 Feb 2016 22:37:50 +0000 (23:37 +0100)] 
ntp: Update to 4.2.8p6

"...addresses 9 low- and medium-severity security issues, 10 bugfixes,
and contains other improvements over 4.2.8p5."

For a complete list, see:
http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore104: Add wget update
Michael Tremer [Thu, 16 Jun 2016 08:26:55 +0000 (09:26 +0100)] 
core104: Add wget update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agowget: Update to 1.18
Matthias Fischer [Tue, 14 Jun 2016 10:33:00 +0000 (12:33 +0200)] 
wget: Update to 1.18

Excerpt from annoncement:

"This version fixes a security vulnerability (CVE-2016-4971) present in
all old versions of wget.  The vulnerability was discovered by Dawid
Golunski which were reported to us by Beyond Security's SecuriTeam.

On a server redirect from HTTP to a FTP resource, wget would trust the
HTTP server and uses the name in the redirected URL as the destination
filename.
This behaviour was changed and now it works similarly as a redirect from
HTTP to another HTTP resource so the original name is used as
the destination file.  To keep the previous behaviour the user must
provide --trust-server-names."

Best,
Mat-backfromholidays-thias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agowget: Update to 1.17.1
Matthias Fischer [Mon, 8 Feb 2016 13:10:57 +0000 (14:10 +0100)] 
wget: Update to 1.17.1

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoStart Core Update 104
Michael Tremer [Thu, 16 Jun 2016 08:24:22 +0000 (09:24 +0100)] 
Start Core Update 104

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore103: Restart squid and rebuild cache core103
Michael Tremer [Wed, 15 Jun 2016 17:47:29 +0000 (18:47 +0100)] 
core103: Restart squid and rebuild cache

The swap.state file may be broken and so we delete this here and
let squid rebuild the cache at the next start.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agofinish core 103 v2.19-core103
Arne Fitzenreiter [Mon, 13 Jun 2016 19:40:00 +0000 (21:40 +0200)] 
finish core 103

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agorootfile updates: newt, linux-rpi
Arne Fitzenreiter [Mon, 13 Jun 2016 19:37:11 +0000 (21:37 +0200)] 
rootfile updates: newt, linux-rpi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agolibvirt: move initskript to package.
Arne Fitzenreiter [Mon, 13 Jun 2016 05:19:05 +0000 (07:19 +0200)] 
libvirt: move initskript to package.

this also fix build on arm.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agoexpect: fix toolchain build on arm.
Arne Fitzenreiter [Sat, 11 Jun 2016 14:02:34 +0000 (16:02 +0200)] 
expect: fix toolchain build on arm.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agocore103: forgot to add the packages
Arne Fitzenreiter [Sat, 11 Jun 2016 14:00:50 +0000 (16:00 +0200)] 
core103: forgot to add the packages

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agocore103: Ship more updated files and packages.
Arne Fitzenreiter [Sat, 11 Jun 2016 07:19:10 +0000 (09:19 +0200)] 
core103: Ship more updated files and packages.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agocore103: Ship updated files and packages
Michael Tremer [Fri, 3 Jun 2016 15:42:01 +0000 (16:42 +0100)] 
core103: Ship updated files and packages

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoBump toolchain version
Michael Tremer [Fri, 3 Jun 2016 15:23:59 +0000 (16:23 +0100)] 
Bump toolchain version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoBUG11131: fix errormessage when more ipsec subnets defined
Heino Gutschmidt [Thu, 2 Jun 2016 14:39:35 +0000 (16:39 +0200)] 
BUG11131: fix errormessage when more ipsec subnets defined

When having more than one subnet in an ipsec connection it is not
possible to create a new openvpn static subnet.

Signed-off-by: Alexander Marx <alexander.marx@ipfire.org>
Signed-off-by: Heino Gutschmidt <heino.gutschmidt@managedhosting.de>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoncurses: update to 6.0 and rename 5.9 to ncurses-compat v3
Marcel Lorenz [Thu, 2 Jun 2016 17:39:51 +0000 (19:39 +0200)] 
ncurses: update to 6.0 and rename 5.9 to ncurses-compat v3

This patch updates the ncurses to 6.0. The old 5.9 are renamed to ncurses-compat.
The compat makes the old libs maintainable and the compat rootfile is cleaned up.
The 6.0 is build after 5.9 and all IPFire componentes will build with 6.0
In version 6 only the wide-character libraries are build. The are usable
in both multibyte and traditional 8-bit locales while normal libraries work
properly only in 8-bit locales. The toolchain is only bild with 6.0.

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agopkg-config: update lfs to build in toolchain
Marcel Lorenz [Thu, 2 Jun 2016 17:39:50 +0000 (19:39 +0200)] 
pkg-config: update lfs to build in toolchain

This is needed by ncureses 6.0

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoigmpproxy: fix build fail and move binary to /usr/sbin
Marcel Lorenz [Thu, 2 Jun 2016 14:09:18 +0000 (16:09 +0200)] 
igmpproxy: fix build fail and move binary to /usr/sbin

Add "--prefix=/usr" to lfs file

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolog.dat: Fix identation for clamav
Matthias Fischer [Sun, 22 May 2016 22:56:27 +0000 (00:56 +0200)] 
log.dat: Fix identation for clamav

Fixes unneeded tabs in 'log.dat'.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agofindutils: update to 4.6.0
Marcel Lorenz [Sat, 28 May 2016 18:57:40 +0000 (20:57 +0200)] 
findutils: update to 4.6.0

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoexpect: update to 5.45
Marcel Lorenz [Sun, 29 May 2016 06:15:11 +0000 (08:15 +0200)] 
expect: update to 5.45

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocoreutils: update to 8.25 v3
Marcel Lorenz [Tue, 3 May 2016 15:28:25 +0000 (17:28 +0200)] 
coreutils: update to 8.25 v3

Coreutils 8.25 needs the automake 1.15
I have send this patch earlier.
Plaese merge automake before coreutils 8.25

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoautomake: update to 1.15
Marcel Lorenz [Wed, 9 Mar 2016 06:26:47 +0000 (07:26 +0100)] 
automake: update to 1.15

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolibyajl: Fix broken syntax
Michael Tremer [Wed, 1 Jun 2016 21:32:33 +0000 (22:32 +0100)] 
libyajl: Fix broken syntax

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoNew package libvirt
Jonatan Schlag [Sat, 7 May 2016 14:01:13 +0000 (16:01 +0200)] 
New package libvirt

Libvirt is buidl only on i585 and x86_64 because qemu is build only
on this arches.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoNew package libyajl
Jonatan Schlag [Sat, 7 May 2016 14:01:11 +0000 (16:01 +0200)] 
New package libyajl

libyajl is a dependency of libvirt

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoShip gettext, gettext.sh, envsubst
Jonatan Schlag [Sat, 7 May 2016 14:01:12 +0000 (16:01 +0200)] 
Ship gettext, gettext.sh, envsubst

Libvirt needs gettest.sh gettext and envsubst for the libvirt-guests
init script.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoNew package libpciaccess
Jonatan Schlag [Sat, 7 May 2016 14:01:10 +0000 (16:01 +0200)] 
New package libpciaccess

libpciacces is a dependdency of libvirt

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoNew package util-macros
Jonatan Schlag [Sat, 7 May 2016 14:01:09 +0000 (16:01 +0200)] 
New package util-macros

This package is a build dependency of libpciaccess, we do not need this
as a package. That's why the rootfiles goes into common and all lines
are excluded.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoNetwork: add macvtap mode
Jonatan Schlag [Sat, 7 May 2016 14:01:08 +0000 (16:01 +0200)] 
Network: add macvtap mode

This change make it possible to use a macvtap interface as a
standard interface (green0).
This is required by libvirt, because libvirt adds macvtap interfaces to
the physical interface, but this causes a problem. A VM  with this
configuration can communicate with the whole network,
but not with the Host (IPFire).
To solve this problem, the host interface must be also a macvtap interface.
This is achieved by:
1. In /var/ipfire/ethernet/settings the mode of a interface could set
with GREEN_MODE= ...
When the mode is macvtap the physical interface is renamed to green0phys
instead of green0. If the mode is not set the normal configuration is
applied .
2. The  network-hotplug-macvtap script checks if a physical nic ends
with "phys".
When the interface ends with "phys", the script adds a macvtap interface
to the physical nic which is named green0. The MAC address of this
interface is set to the MAC address of the physical nic. The MAC address
of the physical is set to a random value. We do this because the MAC
address of green0 should not change.
All services, IP addresses then binds to the macvatap interface, the
physical nic is not used.
PS.:  The script works also with the orange or blue interface, just
replace green with orange or blue.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agobuildsystem: Escape curly brackets
Michael Tremer [Wed, 1 Jun 2016 21:17:10 +0000 (22:17 +0100)] 
buildsystem: Escape curly brackets

Newer versions of perl complain about using unescaped
left curly brackets.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolog.dat: Added 'squid' and 'snort' plus translations
Matthias Fischer [Mon, 23 May 2016 13:55:13 +0000 (15:55 +0200)] 
log.dat: Added 'squid' and 'snort' plus translations

Added 'squid' and 'snort' to section dropdown in LOGS / SYSTEM LOGS,
added translations.

Added translation string for 'web proxy' in '30-network.menu'.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agolog.dat: fix missing quotation marks for 'ddns'
Matthias Fischer [Mon, 23 May 2016 13:55:12 +0000 (15:55 +0200)] 
log.dat: fix missing quotation marks for 'ddns'

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agosquid 3.5.19: latest patches from upstream
Matthias Fischer [Mon, 23 May 2016 12:16:43 +0000 (14:16 +0200)] 
squid 3.5.19: latest patches from upstream

For details, see:
http://www.squid-cache.org/Versions/v3/3.5/changesets/

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoflex: update rootfile
Marcel Lorenz [Mon, 30 May 2016 19:27:35 +0000 (21:27 +0200)] 
flex: update rootfile

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agosamba: import updated rpc security patchset from red hat.
Arne Fitzenreiter [Mon, 23 May 2016 21:08:01 +0000 (23:08 +0200)] 
samba: import updated rpc security patchset from red hat.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agogcc: fix bootstrap with gcc-6
Arne Fitzenreiter [Sun, 22 May 2016 08:56:57 +0000 (10:56 +0200)] 
gcc: fix bootstrap with gcc-6

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
7 years agosnort 2.9.8.2: update snort download url
Matthias Fischer [Sun, 1 May 2016 05:35:32 +0000 (07:35 +0200)] 
snort 2.9.8.2: update snort download url

Update for
http://git.ipfire.org/?p=ipfire-2.x.git;a=commit;h=0aff7b81965c06756ff42482ef0aa3ccfa68bf8f

Update url is set to 'snortrules-snapshot-2982.tar.gz'

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agosnort: Update to 2.9.8.2
Matthias Fischer [Fri, 1 Apr 2016 06:40:00 +0000 (08:40 +0200)] 
snort: Update to 2.9.8.2

Release notes:

2016-03-09 - Snort 2.9.8.2
[*] New additions
 *  Future-flow and DNS API exposed to lua detector.
 *  Double VLAN tagging support.
[*] Improvements
 *  Performance improvements to AppID.
 *  Stability improvements to file and ftp_telnet preprocessor.
 *  Fixed several issues with SDF and obfuscation.
 *  Resolved an issue of improper handling of malformed DNS host
    in AppID.
 *  HTTP PAF accepts all tokens between method and version strings
    in a request URI.
 *  Resolved snort build issue with "--disable-perfprofiling" configure
    option.
 *  Enhanced mime parsing by adding support for detecting files
    after unknown headers and no headers.
 *  Fixed issue with gzip decompression. If the server response specifies
    Content-Encoding as GZIP, but no Content-Length field for HTTP ver 1.0.
 *  End of Header(EOH) identification for HTTP response header spanning multiple
    packets.
 *  Improved packet reassembly for HTTP.
 *  Fixed Flash LZMA decompression issue.

For details see:
https://www.snort.org/downloads/snort/changelog_2.9.8.2.txt

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agosnort 2.9.8.0: Updated rootfile
Matthias Fischer [Fri, 11 Dec 2015 18:38:26 +0000 (19:38 +0100)] 
snort 2.9.8.0: Updated rootfile

snort 2.9.8.0: Updated rootfile

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agosnort: Update to 2.9.8.0
Matthias Fischer [Thu, 10 Dec 2015 06:40:18 +0000 (07:40 +0100)] 
snort: Update to 2.9.8.0

snort: Update to 2.9.8.0

Release notes: https://snort.org/downloads/snort/release_notes_2.9.8.0.txt
Changelog: https://snort.org/downloads/snort/changelog_2.9.8.0.txt

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
7 years agodnsmasq: Update to 2.76
Matthias Fischer [Thu, 19 May 2016 17:19:36 +0000 (19:19 +0200)] 
dnsmasq: Update to 2.76

Final version.

For a detailed changelog, see:
http://www.thekelleys.org.uk/dnsmasq/CHANGELOG

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoMidnight Commander: Update to 4.8.17
Matthias Fischer [Tue, 17 May 2016 18:44:33 +0000 (20:44 +0200)] 
Midnight Commander: Update to 4.8.17

For Details see:
http://www.midnight-commander.org/wiki/NEWS-4.8.17

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoRootfile update
Michael Tremer [Wed, 18 May 2016 18:28:01 +0000 (19:28 +0100)] 
Rootfile update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agonfs: Bump release to install rpcbind dependency
Michael Tremer [Wed, 18 May 2016 15:41:51 +0000 (16:41 +0100)] 
nfs: Bump release to install rpcbind dependency

This update will pull in rpcbind as new dependency which
will automatically remove portmap when installed.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agosquid: Fix indentation
Michael Tremer [Wed, 18 May 2016 15:17:21 +0000 (16:17 +0100)] 
squid: Fix indentation

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agosquid: Kill redirector processes only after squid has stopped
Michael Tremer [Wed, 18 May 2016 15:16:12 +0000 (16:16 +0100)] 
squid: Kill redirector processes only after squid has stopped

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agosquid: Rework initscript
Matthias Fischer [Tue, 17 May 2016 19:33:24 +0000 (21:33 +0200)] 
squid: Rework initscript

The initscript now takes care that the squid proxy server process
is properly shut down. If that fails, it will remove the cache
index and let it be recreated at the next start. A warning is
shown to the user.

The "flush" command will now remove the entire proxy cache.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoReplace portmap with rpcbind
Jonatan Schlag [Sat, 7 May 2016 14:16:35 +0000 (16:16 +0200)] 
Replace portmap with rpcbind

Portmap is not maintained anymore that's why it is replaced by rpcbind.
Rpcbind provides also rpcinfo which is quite useful for debugging.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agoNew package libtirpc
Jonatan Schlag [Sat, 7 May 2016 14:16:34 +0000 (16:16 +0200)] 
New package libtirpc

libtirpc is a dependency of rpcbind

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years ago7zip: update to 15.14.1
Marcel Lorenz [Fri, 13 May 2016 15:50:57 +0000 (17:50 +0200)] 
7zip: update to 15.14.1

Signed-off-by: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agocore103: Ship updated dnsmasq
Michael Tremer [Mon, 16 May 2016 17:02:03 +0000 (18:02 +0100)] 
core103: Ship updated dnsmasq

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agodnsmasq: Update to 2.76rc2
Matthias Fischer [Sun, 15 May 2016 11:29:54 +0000 (13:29 +0200)] 
dnsmasq: Update to 2.76rc2

- Updated to 2.76rc2 and deleted obsolete patch files from 2.76rc1

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
7 years agodnsmasq: Update to 2.76rc1 - added latest patches (001-002)
Matthias Fischer [Fri, 13 May 2016 17:06:10 +0000 (19:06 +0200)] 
dnsmasq: Update to 2.76rc1 - added latest patches (001-002)

Update, added latest patches and deleted obsolete patch files.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>