]> git.ipfire.org Git - people/amarx/ipfire-2.x.git/log
people/amarx/ipfire-2.x.git
5 years agonano: Update to 2.9.8 BUG11805 BUG11825
Matthias Fischer [Tue, 21 Aug 2018 16:27:02 +0000 (18:27 +0200)] 
nano: Update to 2.9.8

For details see:
https://www.nano-editor.org/news.php

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore124: Ship updated backup include/exclude files
Michael Tremer [Tue, 21 Aug 2018 14:06:22 +0000 (15:06 +0100)] 
core124: Ship updated backup include/exclude files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agobackup: Add root's SSH keys and settings
Michael Tremer [Tue, 21 Aug 2018 14:05:40 +0000 (15:05 +0100)] 
backup: Add root's SSH keys and settings

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agobackup: Add custom squid configuration files
Michael Tremer [Tue, 21 Aug 2018 14:05:13 +0000 (15:05 +0100)] 
backup: Add custom squid configuration files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agobackup: Order incldue/exclude alphabetically
Michael Tremer [Tue, 21 Aug 2018 10:32:04 +0000 (11:32 +0100)] 
backup: Order incldue/exclude alphabetically

Nothing has been added or removed

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agogcc: x86_64 add libspp to rootfile
Arne Fitzenreiter [Mon, 20 Aug 2018 14:22:20 +0000 (16:22 +0200)] 
gcc: x86_64 add libspp to rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agobind: Update to 9.11.4-P1
Matthias Fischer [Thu, 16 Aug 2018 18:56:03 +0000 (20:56 +0200)] 
bind: Update to 9.11.4-P1

Fixes CVE-2018-5740 and CVE-2018-5738.

For details see:
http://ftp.isc.org/isc/bind9/9.11.4-P1/RELEASE-NOTES-bind-9.11.4-P1.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore124: Ship updated pciutils
Michael Tremer [Thu, 16 Aug 2018 17:55:49 +0000 (18:55 +0100)] 
core124: Ship updated pciutils

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopciutils: update to 3.5.6
Peter Müller [Thu, 16 Aug 2018 15:10:58 +0000 (17:10 +0200)] 
pciutils: update to 3.5.6

The third version of this patch superseds the first and
second one which were broken due to bugs in the MUAs GPG
implementation.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore124: Ship updated ids.cgi
Michael Tremer [Thu, 16 Aug 2018 17:54:41 +0000 (18:54 +0100)] 
core124: Ship updated ids.cgi

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agodownload ET IDS rules via HTTPS
Peter Müller [Thu, 16 Aug 2018 15:09:41 +0000 (17:09 +0200)] 
download ET IDS rules via HTTPS

The Emerging Threats ruleset server supports HTTPS. It should
be used for downloading the ruleset in IPFire, too.

This also needs to be applied on the upcoming ids.cgi file for Suricata
which I will do in a second patch.

The third version of this patch superseds the first and
second one which were broken due to bugs in the MUAs GPG
implementation.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoPostfix: update to 3.3.1
Peter Müller [Thu, 16 Aug 2018 15:08:04 +0000 (17:08 +0200)] 
Postfix: update to 3.3.1

This updates Postfix to recent 3.3.x series, which contains
some new features. Release announcement available at
http://www.postfix.org/announcements/postfix-3.3.1.html

The third version of this patch superseds the first and
second one which were broken due to bugs in the MUAs GPG
implementation.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore124: Ship updated bind
Michael Tremer [Thu, 16 Aug 2018 12:05:47 +0000 (13:05 +0100)] 
core124: Ship updated bind

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agobind: Update to 9.11.4
Matthias Fischer [Sun, 22 Jul 2018 15:11:53 +0000 (17:11 +0200)] 
bind: Update to 9.11.4

For details see:
http://ftp.isc.org/isc/bind9/9.11.4/RELEASE-NOTES-bind-9.11.4.html

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore124: Don't re-generate the initrd
Michael Tremer [Thu, 16 Aug 2018 12:02:56 +0000 (13:02 +0100)] 
core124: Don't re-generate the initrd

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore124: Re-install bootloader during update
Michael Tremer [Thu, 16 Aug 2018 12:02:37 +0000 (13:02 +0100)] 
core124: Re-install bootloader during update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore124: Ship EFI changes
Michael Tremer [Thu, 16 Aug 2018 12:01:01 +0000 (13:01 +0100)] 
core124: Ship EFI changes

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoMerge remote-tracking branch 'origin/efi' into next
Michael Tremer [Thu, 16 Aug 2018 11:49:13 +0000 (12:49 +0100)] 
Merge remote-tracking branch 'origin/efi' into next

5 years agocore124: Ship update localnet init script
Michael Tremer [Thu, 16 Aug 2018 11:47:55 +0000 (12:47 +0100)] 
core124: Ship update localnet init script

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoStart Core Update 124
Michael Tremer [Thu, 16 Aug 2018 11:47:06 +0000 (12:47 +0100)] 
Start Core Update 124

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agolocalnet: Properly format and quote variables
Michael Tremer [Thu, 16 Aug 2018 11:42:25 +0000 (12:42 +0100)] 
localnet: Properly format and quote variables

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agolocalnet: Correctly set domain name
Michael Tremer [Thu, 16 Aug 2018 11:41:52 +0000 (12:41 +0100)] 
localnet: Correctly set domain name

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore123: ship updated unbound initskript
Arne Fitzenreiter [Wed, 15 Aug 2018 11:30:07 +0000 (13:30 +0200)] 
core123: ship updated unbound initskript

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agoaws: Hide pakfire update output
Michael Tremer [Wed, 15 Aug 2018 10:50:14 +0000 (11:50 +0100)] 
aws: Hide pakfire update output

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Write user-data log to file only
Michael Tremer [Wed, 15 Aug 2018 10:49:30 +0000 (11:49 +0100)] 
aws: Write user-data log to file only

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Execute reboot when an update requires one
Michael Tremer [Wed, 15 Aug 2018 10:45:27 +0000 (11:45 +0100)] 
aws: Execute reboot when an update requires one

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoFix typo in unbound initscript
Michael Tremer [Wed, 15 Aug 2018 10:25:38 +0000 (11:25 +0100)] 
Fix typo in unbound initscript

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Set PATH to search in /usr/local/(s)bin
Michael Tremer [Wed, 15 Aug 2018 10:11:56 +0000 (11:11 +0100)] 
aws: Set PATH to search in /usr/local/(s)bin

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Import pakfire keys before the first launch
Michael Tremer [Wed, 15 Aug 2018 10:10:59 +0000 (11:10 +0100)] 
aws: Import pakfire keys before the first launch

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Log output of user-data script to /root/user-data.log
Michael Tremer [Wed, 15 Aug 2018 10:09:55 +0000 (11:09 +0100)] 
aws: Log output of user-data script to /root/user-data.log

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore123: ship updated logs.cgi/ids.dat
Arne Fitzenreiter [Wed, 15 Aug 2018 10:19:29 +0000 (12:19 +0200)] 
core123: ship updated logs.cgi/ids.dat

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agoaws: Install all available updates first
Michael Tremer [Wed, 15 Aug 2018 09:11:08 +0000 (10:11 +0100)] 
aws: Install all available updates first

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Setup DNS during init phase
Michael Tremer [Wed, 15 Aug 2018 09:10:13 +0000 (10:10 +0100)] 
aws: Setup DNS during init phase

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore123: set pakfire version
Arne Fitzenreiter [Wed, 15 Aug 2018 05:30:53 +0000 (07:30 +0200)] 
core123: set pakfire version

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agocore123: Ship updated backup.pl
Michael Tremer [Tue, 14 Aug 2018 19:39:17 +0000 (20:39 +0100)] 
core123: Ship updated backup.pl

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoFixes for 'backup.pl' (Bug #11816)
Matthias Fischer [Tue, 14 Aug 2018 19:34:38 +0000 (21:34 +0200)] 
Fixes for 'backup.pl' (Bug #11816)

Hi,

Fixes #11816
(https://bugzilla.ipfire.org/show_bug.cgi?id=11816 and
https://bugzilla.ipfire.org/attachment.cgi?id=608):

"[root@ipfire ~]# backupctrl exclude
...
tar: The following options were used after any non-optional arguments in
archive create or update mode.  These options are positional and affect
only arguments that follow them.  Please, rearrange them properly.
tar: --exclude-from '/var/ipfire/backup/exclude.user' has no effect
tar: Exiting with failure status due to previous errors"

Please test - I got no errors anymore.

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore123: Ship openssl-compat, too
Michael Tremer [Tue, 14 Aug 2018 19:37:54 +0000 (20:37 +0100)] 
core123: Ship openssl-compat, too

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore123: Ship updated openssl
Arne Fitzenreiter [Tue, 14 Aug 2018 18:29:03 +0000 (20:29 +0200)] 
core123: Ship updated openssl

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agoMerge remote-tracking branch 'ms/aws-cli' into next
Michael Tremer [Tue, 14 Aug 2018 18:14:58 +0000 (19:14 +0100)] 
Merge remote-tracking branch 'ms/aws-cli' into next

5 years agoopenssl: Update to 1.1.0i and 1.0.2p
Michael Tremer [Tue, 14 Aug 2018 18:12:53 +0000 (19:12 +0100)] 
openssl: Update to 1.1.0i and 1.0.2p

 Changes between 1.1.0h and 1.1.0i [14 Aug 2018]

  *) Client DoS due to large DH parameter

     During key agreement in a TLS handshake using a DH(E) based ciphersuite a
     malicious server can send a very large prime value to the client. This will
     cause the client to spend an unreasonably long period of time generating a
     key for this prime resulting in a hang until the client has finished. This
     could be exploited in a Denial Of Service attack.

     This issue was reported to OpenSSL on 5th June 2018 by Guido Vranken
     (CVE-2018-0732)
     [Guido Vranken]

  *) Cache timing vulnerability in RSA Key Generation

     The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to
     a cache timing side channel attack. An attacker with sufficient access to
     mount cache timing attacks during the RSA key generation process could
     recover the private key.

     This issue was reported to OpenSSL on 4th April 2018 by Alejandro Cabrera
     Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis Manuel Alvarez Tapia.
     (CVE-2018-0737)
     [Billy Brumley]

  *) Make EVP_PKEY_asn1_new() a bit stricter about its input.  A NULL pem_str
     parameter is no longer accepted, as it leads to a corrupt table.  NULL
     pem_str is reserved for alias entries only.
     [Richard Levitte]

  *) Revert blinding in ECDSA sign and instead make problematic addition
     length-invariant. Switch even to fixed-length Montgomery multiplication.
     [Andy Polyakov]

  *) Change generating and checking of primes so that the error rate of not
     being prime depends on the intended use based on the size of the input.
     For larger primes this will result in more rounds of Miller-Rabin.
     The maximal error rate for primes with more than 1080 bits is lowered
     to 2^-128.
     [Kurt Roeckx, Annie Yousar]

  *) Increase the number of Miller-Rabin rounds for DSA key generating to 64.
     [Kurt Roeckx]

  *) Add blinding to ECDSA and DSA signatures to protect against side channel
     attacks discovered by Keegan Ryan (NCC Group).
     [Matt Caswell]

  *) When unlocking a pass phrase protected PEM file or PKCS#8 container, we
     now allow empty (zero character) pass phrases.
     [Richard Levitte]

  *) Certificate time validation (X509_cmp_time) enforces stricter
     compliance with RFC 5280. Fractional seconds and timezone offsets
     are no longer allowed.
     [Emilia Käsper]

  *) Fixed a text canonicalisation bug in CMS

     Where a CMS detached signature is used with text content the text goes
     through a canonicalisation process first prior to signing or verifying a
     signature. This process strips trailing space at the end of lines, converts
     line terminators to CRLF and removes additional trailing line terminators
     at the end of a file. A bug in the canonicalisation process meant that
     some characters, such as form-feed, were incorrectly treated as whitespace
     and removed. This is contrary to the specification (RFC5485). This fix
     could mean that detached text data signed with an earlier version of
     OpenSSL 1.1.0 may fail to verify using the fixed version, or text data
     signed with a fixed OpenSSL may fail to verify with an earlier version of
     OpenSSL 1.1.0. A workaround is to only verify the canonicalised text data
     and use the "-binary" flag (for the "cms" command line application) or set
     the SMIME_BINARY/PKCS7_BINARY/CMS_BINARY flags (if using CMS_verify()).
     [Matt Caswell]

 Changes between 1.0.2o and 1.0.2p [14 Aug 2018]

  *) Client DoS due to large DH parameter

     During key agreement in a TLS handshake using a DH(E) based ciphersuite a
     malicious server can send a very large prime value to the client. This will
     cause the client to spend an unreasonably long period of time generating a
     key for this prime resulting in a hang until the client has finished. This
     could be exploited in a Denial Of Service attack.

     This issue was reported to OpenSSL on 5th June 2018 by Guido Vranken
     (CVE-2018-0732)
     [Guido Vranken]

  *) Cache timing vulnerability in RSA Key Generation

     The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to
     a cache timing side channel attack. An attacker with sufficient access to
     mount cache timing attacks during the RSA key generation process could
     recover the private key.

     This issue was reported to OpenSSL on 4th April 2018 by Alejandro Cabrera
     Aldaya, Billy Brumley, Cesar Pereida Garcia and Luis Manuel Alvarez Tapia.
     (CVE-2018-0737)
     [Billy Brumley]

  *) Make EVP_PKEY_asn1_new() a bit stricter about its input.  A NULL pem_str
     parameter is no longer accepted, as it leads to a corrupt table.  NULL
     pem_str is reserved for alias entries only.
     [Richard Levitte]

  *) Revert blinding in ECDSA sign and instead make problematic addition
     length-invariant. Switch even to fixed-length Montgomery multiplication.
     [Andy Polyakov]

  *) Change generating and checking of primes so that the error rate of not
     being prime depends on the intended use based on the size of the input.
     For larger primes this will result in more rounds of Miller-Rabin.
     The maximal error rate for primes with more than 1080 bits is lowered
     to 2^-128.
     [Kurt Roeckx, Annie Yousar]

  *) Increase the number of Miller-Rabin rounds for DSA key generating to 64.
     [Kurt Roeckx]

  *) Add blinding to ECDSA and DSA signatures to protect against side channel
     attacks discovered by Keegan Ryan (NCC Group).
     [Matt Caswell]

  *) When unlocking a pass phrase protected PEM file or PKCS#8 container, we
     now allow empty (zero character) pass phrases.
     [Richard Levitte]

  *) Certificate time validation (X509_cmp_time) enforces stricter
     compliance with RFC 5280. Fractional seconds and timezone offsets
     are no longer allowed.
     [Emilia Käsper]

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-s3transfer: Fix rootfile
Michael Tremer [Tue, 14 Aug 2018 14:13:24 +0000 (15:13 +0100)] 
python3-s3transfer: Fix rootfile

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-pyasn1: New package as required by aws-cli
Michael Tremer [Tue, 14 Aug 2018 13:52:33 +0000 (14:52 +0100)] 
python3-pyasn1: New package as required by aws-cli

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-rsa: New package as required by aws-cli
Michael Tremer [Tue, 14 Aug 2018 13:44:30 +0000 (14:44 +0100)] 
python3-rsa: New package as required by aws-cli

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-s3transfer: New package as required by aws-cli
Michael Tremer [Tue, 14 Aug 2018 13:38:11 +0000 (14:38 +0100)] 
python3-s3transfer: New package as required by aws-cli

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-yaml: New paclage as required by aws-cli
Michael Tremer [Tue, 14 Aug 2018 13:19:33 +0000 (14:19 +0100)] 
python3-yaml: New paclage as required by aws-cli

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-docutils: New package as required by aws-cli
Michael Tremer [Tue, 14 Aug 2018 13:11:38 +0000 (14:11 +0100)] 
python3-docutils: New package as required by aws-cli

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-colorama: New package as required by aws-cli
Michael Tremer [Tue, 14 Aug 2018 13:04:03 +0000 (14:04 +0100)] 
python3-colorama: New package as required by aws-cli

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-jmespath: New package as required by python3-botocore
Michael Tremer [Tue, 14 Aug 2018 12:57:02 +0000 (13:57 +0100)] 
python3-jmespath: New package as required by python3-botocore

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-six: New package as required by python3-dateutil
Michael Tremer [Tue, 14 Aug 2018 12:18:00 +0000 (13:18 +0100)] 
python3-six: New package as required by python3-dateutil

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-dateutil: New package required by python3-botocore
Michael Tremer [Tue, 14 Aug 2018 12:13:07 +0000 (13:13 +0100)] 
python3-dateutil: New package required by python3-botocore

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopython3-botocore: Required by aws-cli
Michael Tremer [Tue, 14 Aug 2018 11:54:23 +0000 (12:54 +0100)] 
python3-botocore: Required by aws-cli

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws-cli: New package
Michael Tremer [Tue, 14 Aug 2018 11:45:38 +0000 (12:45 +0100)] 
aws-cli: New package

Needed to communicate with AWS services like EC2, S3, etc...

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agologs.cgi/ids.dat: Rework linking to external rule documentation.
Stefan Schantl [Tue, 14 Aug 2018 10:01:53 +0000 (12:01 +0200)] 
logs.cgi/ids.dat: Rework linking to external rule documentation.

Check if the sid of a rule belongs to sourcefire and link to the
changed URL for gathering more details. If the sid of the rule belongs
to emergingthreads now link to the emergingthreads documentation.

Fixes #11806.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoRootfile update
Michael Tremer [Tue, 14 Aug 2018 07:36:19 +0000 (08:36 +0100)] 
Rootfile update

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoRevert "usbutils: update to 010"
Michael Tremer [Mon, 13 Aug 2018 18:50:06 +0000 (19:50 +0100)] 
Revert "usbutils: update to 010"

This reverts commit b07b1bef22eae7038e7d0fcba0bfd53813f85258.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoRevert "core123: Ship updated usbutils"
Michael Tremer [Mon, 13 Aug 2018 18:49:58 +0000 (19:49 +0100)] 
Revert "core123: Ship updated usbutils"

This reverts commit a65d07ec6d36a712882294b608e718db2d56b24e.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoRevert "usbutils: Update rootfile"
Michael Tremer [Mon, 13 Aug 2018 18:49:48 +0000 (19:49 +0100)] 
Revert "usbutils: Update rootfile"

This reverts commit 9aefd1ed07eee7d83e5b274d4a83240811f9e091.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoRevert "avahi: Build without dbus"
Michael Tremer [Mon, 13 Aug 2018 17:59:10 +0000 (18:59 +0100)] 
Revert "avahi: Build without dbus"

This reverts commit 5221a852e80526d188306b05202e595616f0c065.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Execute user-data script while we have networking up
Michael Tremer [Mon, 13 Aug 2018 11:14:49 +0000 (12:14 +0100)] 
aws: Execute user-data script while we have networking up

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agointel-microcode: update to 20180807
Arne Fitzenreiter [Sat, 11 Aug 2018 12:45:56 +0000 (14:45 +0200)] 
intel-microcode: update to 20180807

fixes #11590

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agoavahi: Bump package version
Michael Tremer [Fri, 10 Aug 2018 11:20:38 +0000 (12:20 +0100)] 
avahi: Bump package version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoavahi: Build without dbus
Michael Tremer [Fri, 10 Aug 2018 11:20:06 +0000 (12:20 +0100)] 
avahi: Build without dbus

We don't have any services connected to dbus, so what is the
point of avahi trying to connect to it?

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoavahi: Build with -U_FORTIFY_SOURCE
Michael Tremer [Fri, 10 Aug 2018 11:18:29 +0000 (12:18 +0100)] 
avahi: Build with -U_FORTIFY_SOURCE

Avahi locks up when built with -D_FORTIFY_SOURCE=2

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoavahi: Update to 0.7
Michael Tremer [Fri, 10 Aug 2018 10:19:25 +0000 (11:19 +0100)] 
avahi: Update to 0.7

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoRevert "avahi: Drop package"
Michael Tremer [Fri, 10 Aug 2018 10:08:09 +0000 (11:08 +0100)] 
Revert "avahi: Drop package"

This reverts commit aa6ee515c59cd42b12d69981329a2438e4d6e933.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoopenssh: Disable password authentication by default
Michael Tremer [Thu, 9 Aug 2018 15:28:14 +0000 (16:28 +0100)] 
openssh: Disable password authentication by default

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agokernel: fix build on x86_64
Arne Fitzenreiter [Wed, 8 Aug 2018 08:26:38 +0000 (10:26 +0200)] 
kernel: fix build on x86_64

oops i deleted a wrong line...

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agokernel: fix build on armv5tel
Arne Fitzenreiter [Tue, 7 Aug 2018 17:05:35 +0000 (19:05 +0200)] 
kernel: fix build on armv5tel

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agokernel: apu2 leds: update string for newer bios
Arne Fitzenreiter [Sun, 5 Aug 2018 15:19:52 +0000 (17:19 +0200)] 
kernel: apu2 leds: update string for newer bios

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Sun, 5 Aug 2018 15:19:36 +0000 (17:19 +0200)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next

5 years agoinitrd: add early microcode load
Arne Fitzenreiter [Sun, 5 Aug 2018 11:32:36 +0000 (13:32 +0200)] 
initrd: add early microcode load

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agotor: Update to version 0.3.3.9
Erik Kapfer [Sat, 4 Aug 2018 11:52:32 +0000 (13:52 +0200)] 
tor: Update to version 0.3.3.9

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agonginx: Update to version 1.15.1
Erik Kapfer [Sat, 4 Aug 2018 11:49:00 +0000 (13:49 +0200)] 
nginx: Update to version 1.15.1

Deleted last slash in --prefix configure option to prevent such -->
https://forum.ipfire.org/viewtopic.php?t=19213#p109787 problems.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agorng-tools: Update to 6.3.1
Matthias Fischer [Sat, 4 Aug 2018 06:35:05 +0000 (08:35 +0200)] 
rng-tools: Update to 6.3.1

Bugfix release, for details see:
https://github.com/nhorman/rng-tools/releases

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agomake.sh: Add command to update list of contributors
Michael Tremer [Sat, 4 Aug 2018 12:39:00 +0000 (13:39 +0100)] 
make.sh: Add command to update list of contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocollectd: fix cpufreq plugin enable
Arne Fitzenreiter [Fri, 3 Aug 2018 14:13:12 +0000 (16:13 +0200)] 
collectd: fix cpufreq plugin enable

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agobackup: Bump release number in ISO download script
Michael Tremer [Tue, 31 Jul 2018 15:23:07 +0000 (16:23 +0100)] 
backup: Bump release number in ISO download script

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agolinux-firmware: update to 30.7.2018
Arne Fitzenreiter [Thu, 2 Aug 2018 19:15:11 +0000 (21:15 +0200)] 
linux-firmware: update to 30.7.2018

include new amd microcodes for Spectre updates

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agobackup: Make backup ISO bootable on EFI
Michael Tremer [Tue, 31 Jul 2018 15:36:09 +0000 (16:36 +0100)] 
backup: Make backup ISO bootable on EFI

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Disable SSH password authentication by default
Michael Tremer [Mon, 30 Jul 2018 15:54:50 +0000 (16:54 +0100)] 
aws: Disable SSH password authentication by default

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocore123: Ship and restart squid and apache
Michael Tremer [Thu, 26 Jul 2018 13:46:53 +0000 (14:46 +0100)] 
core123: Ship and restart squid and apache

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agosquid: Update to 3.5.28
Matthias Fischer [Tue, 17 Jul 2018 18:50:41 +0000 (20:50 +0200)] 
squid: Update to 3.5.28

For details see:
http://www.squid-cache.org/Versions/v3/3.5/changesets/

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoApache: Update to 2.4.34
Wolfgang Apolinarski [Tue, 17 Jul 2018 18:13:30 +0000 (20:13 +0200)] 
Apache: Update to 2.4.34

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocdrom: Move list of EFI modules to lfs/cdrom
Michael Tremer [Wed, 25 Jul 2018 09:54:35 +0000 (10:54 +0100)] 
cdrom: Move list of EFI modules to lfs/cdrom

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocdrom: Re-order arguments again
Michael Tremer [Mon, 23 Jul 2018 22:10:36 +0000 (23:10 +0100)] 
cdrom: Re-order arguments again

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agocdrom: The order of arguments for mkisofs seems to be relevant
Michael Tremer [Sun, 22 Jul 2018 21:31:30 +0000 (22:31 +0100)] 
cdrom: The order of arguments for mkisofs seems to be relevant

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agogrub: apply vga fallback disable patch again
Arne Fitzenreiter [Sun, 22 Jul 2018 11:41:38 +0000 (13:41 +0200)] 
grub: apply vga fallback disable patch again

on some systems (e.g. J1900 based) grub detects a too low resolution
and use it. This is no problem in grub itself but the kernel not render
the consoles in this mode.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agosyslinux: update i586 rootfile
Arne Fitzenreiter [Sat, 21 Jul 2018 14:39:46 +0000 (16:39 +0200)] 
syslinux: update i586 rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agoflash-images: fix partition layout on i586
Arne Fitzenreiter [Sat, 21 Jul 2018 14:33:29 +0000 (16:33 +0200)] 
flash-images: fix partition layout on i586

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 years agoaws: Add support for a script that can be executed at first boot
Michael Tremer [Fri, 20 Jul 2018 15:19:46 +0000 (16:19 +0100)] 
aws: Add support for a script that can be executed at first boot

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoaws: Always exit the init script cleanly
Michael Tremer [Tue, 17 Jul 2018 17:05:07 +0000 (18:05 +0100)] 
aws: Always exit the init script cleanly

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoasterisk: Don't optimise for builder
Michael Tremer [Fri, 20 Jul 2018 14:21:36 +0000 (14:21 +0000)] 
asterisk: Don't optimise for builder

Asterisk enables -march=native which renders the code
incompatible to most systems.

Fixes: #11793
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoMerge branch 'next' into efi
Michael Tremer [Fri, 20 Jul 2018 12:47:20 +0000 (12:47 +0000)] 
Merge branch 'next' into efi

5 years agofireinfo: Import latest patches
Michael Tremer [Fri, 20 Jul 2018 12:06:11 +0000 (12:06 +0000)] 
fireinfo: Import latest patches

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoinstaller: Run install-bootloader script instead of own code
Michael Tremer [Fri, 20 Jul 2018 11:59:00 +0000 (11:59 +0000)] 
installer: Run install-bootloader script instead of own code

This allows us to keep the GRUB installation routine in one
place only.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopartresize: Remove debugging line
Michael Tremer [Fri, 20 Jul 2018 11:53:55 +0000 (11:53 +0000)] 
partresize: Remove debugging line

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agopartresize: Only regenerate configuration instead of re-installing GRUB
Michael Tremer [Fri, 20 Jul 2018 11:53:24 +0000 (11:53 +0000)] 
partresize: Only regenerate configuration instead of re-installing GRUB

This should not be necessary

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoMove update-bootloader script into installer
Michael Tremer [Fri, 20 Jul 2018 11:51:50 +0000 (11:51 +0000)] 
Move update-bootloader script into installer

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoupdate-bootloader: Allow passing device to install GRUB on
Michael Tremer [Fri, 20 Jul 2018 11:47:35 +0000 (11:47 +0000)] 
update-bootloader: Allow passing device to install GRUB on

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 years agoupdate-bootloader: Extend script to support EFI
Michael Tremer [Fri, 20 Jul 2018 11:34:55 +0000 (11:34 +0000)] 
update-bootloader: Extend script to support EFI

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>