]> git.ipfire.org Git - people/jschlag/ipfire-2.x.git/log
people/jschlag/ipfire-2.x.git
10 days agotest_that_key_in_arry_has_value: Check if a key in an array exists improve_network_startup_step_2
Jonatan Schlag [Tue, 23 Apr 2024 16:38:01 +0000 (18:38 +0200)] 
test_that_key_in_arry_has_value: Check if a key in an array exists

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
10 days agoUse namref to access an array
Jonatan Schlag [Tue, 23 Apr 2024 16:19:54 +0000 (18:19 +0200)] 
Use namref to access an array

! does not work here. So the solution here is:
https://unix.stackexchange.com/questions/60584/how-to-use-a-variable-as-part-of-an-array-name/60585#60585

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
10 days agotest_that_key_in_arry_has_value: Check if the key is defined
Jonatan Schlag [Tue, 23 Apr 2024 16:12:52 +0000 (18:12 +0200)] 
test_that_key_in_arry_has_value: Check if the key is defined

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
10 days agofixup
Jonatan Schlag [Tue, 23 Apr 2024 16:08:13 +0000 (18:08 +0200)] 
fixup

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
10 days agofixup check if array is defined
Jonatan Schlag [Tue, 23 Apr 2024 16:03:04 +0000 (18:03 +0200)] 
fixup check if array is defined

-v does a bad job here.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
12 days agoinitscripts fkt: readhash fix declaring of array
Jonatan Schlag [Sun, 21 Apr 2024 16:09:36 +0000 (18:09 +0200)] 
initscripts fkt: readhash fix declaring of array

From https://www.gnu.org/software/bash/manual/bash.html#Bourne-Shell-Builtins

"When used in a function, declare makes each name local, as with the local command, unless the -g option is used."

So we need to use -g here

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
12 days agofixup -v test var defined
Jonatan Schlag [Sun, 21 Apr 2024 16:05:21 +0000 (18:05 +0200)] 
fixup -v test var defined

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
12 days agotests/lib.sh: adjust to pytest logging style
Jonatan Schlag [Sun, 21 Apr 2024 15:55:46 +0000 (17:55 +0200)] 
tests/lib.sh: adjust to pytest logging style

Black on white is still the best to read. So we only style FAILED or
PASSED in green or red.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
12 days agotests/lib.sh: Add logging functions
Jonatan Schlag [Sun, 21 Apr 2024 15:52:22 +0000 (17:52 +0200)] 
tests/lib.sh: Add logging functions

So we can change the style of our log messages better.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
12 days agotests/lib.sh: Add check if variable exists to test_that_key_in_arry_has_value
Jonatan Schlag [Sun, 21 Apr 2024 15:48:17 +0000 (17:48 +0200)] 
tests/lib.sh: Add check if variable exists to test_that_key_in_arry_has_value

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
12 days agotests/lib.sh: Add function test_that_key_in_arry_has_value
Jonatan Schlag [Sun, 21 Apr 2024 15:42:32 +0000 (17:42 +0200)] 
tests/lib.sh: Add function test_that_key_in_arry_has_value

I think the name says it all.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
13 days agotests/scr/script/readhash: Use our new lib
Jonatan Schlag [Sat, 20 Apr 2024 15:10:58 +0000 (17:10 +0200)] 
tests/scr/script/readhash: Use our new lib

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
13 days agotests: Add bash lib
Jonatan Schlag [Sat, 20 Apr 2024 15:10:18 +0000 (17:10 +0200)] 
tests: Add bash lib

This allows use to write test with less effort as we can reuse functions

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
13 days agotest: Add bash lib for colors
Jonatan Schlag [Sat, 20 Apr 2024 15:08:03 +0000 (17:08 +0200)] 
test: Add bash lib for colors

This is borrowed from here: https://git.ipfire.org/?p=network.git;a=blob;f=src/functions/functions.colors;h=0bd6f97177c366f1d1ee4553043ae719430acdb2;hb=refs/heads/master

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
13 days agofix assert in test
Jonatan Schlag [Sat, 20 Apr 2024 14:36:13 +0000 (14:36 +0000)] 
fix assert in test

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
13 days agoinitscript functions: add readhash
Jonatan Schlag [Sat, 20 Apr 2024 14:35:00 +0000 (14:35 +0000)] 
initscript functions: add readhash

To avoid the usage of eval and to store the config in an key value
array, we introduce an new function.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2 weeks agoInitial test
Jonatan Schlag [Thu, 18 Apr 2024 17:42:55 +0000 (19:42 +0200)] 
Initial test

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2 weeks agonetwork initscript: drop unused variable
Jonatan Schlag [Sun, 25 Feb 2024 14:05:47 +0000 (15:05 +0100)] 
network initscript: drop unused variable

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2 weeks agonetwork initscript: Avoid an infinite loop
Jonatan Schlag [Sun, 3 Dec 2023 15:38:12 +0000 (16:38 +0100)] 
network initscript: Avoid an infinite loop

If we only shift if $1 is red, green, blue or orange, $# never gets zero
when the input is:

/etc/init.d/network green stop

When we get an invalid zone we stop the script, as this happening should
not be masked.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2 weeks agonetwork initscript: Use network_zone_exists
Jonatan Schlag [Sun, 3 Dec 2023 15:36:57 +0000 (16:36 +0100)] 
network initscript: Use network_zone_exists

This only a cosmetic change but should making the code easier changeable
later on.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2 weeks agofunctions.network: Add network_zone_exists
Jonatan Schlag [Sun, 3 Dec 2023 15:16:55 +0000 (16:16 +0100)] 
functions.network: Add network_zone_exists

As our Network is quite static a case does the trick

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2 weeks agofunctions.network: Add proper Exit Codes
Jonatan Schlag [Sun, 3 Dec 2023 15:09:43 +0000 (16:09 +0100)] 
functions.network: Add proper Exit Codes

This ist borrowed from here:

https://git.ipfire.org/?p=network.git;a=blob_plain;f=src/functions/functions.constants;h=0d6cdd2fba47fa4db933b054496ed95cd3d905f3;hb=HEAD

and can be extended later on.

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
2 weeks agokernel: update to 6.6.28
Arne Fitzenreiter [Wed, 17 Apr 2024 17:39:14 +0000 (19:39 +0200)] 
kernel: update to 6.6.28

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 weeks agokernel: rootfile update
Arne Fitzenreiter [Tue, 16 Apr 2024 04:50:49 +0000 (06:50 +0200)] 
kernel: rootfile update

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 weeks agokernel: disable CONFIG_N_GSM
Arne Fitzenreiter [Sun, 14 Apr 2024 12:38:32 +0000 (14:38 +0200)] 
kernel: disable CONFIG_N_GSM

this feature should not used by IPFire and there
is a possible unfixed race condition that can
used for a privilege elevation attack.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 weeks agokernel: update to 6.6.27
Arne Fitzenreiter [Sun, 14 Apr 2024 12:38:00 +0000 (14:38 +0200)] 
kernel: update to 6.6.27

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 weeks agokernel: update to 6.6.26
Arne Fitzenreiter [Thu, 11 Apr 2024 10:55:25 +0000 (12:55 +0200)] 
kernel: update to 6.6.26

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Wed, 10 Apr 2024 05:11:02 +0000 (07:11 +0200)] 
Merge remote-tracking branch 'origin/master' into next

3 weeks agosuricata: Change midstream policy to "pass-flow"
Michael Tremer [Tue, 9 Apr 2024 09:51:18 +0000 (10:51 +0100)] 
suricata: Change midstream policy to "pass-flow"

Pass packet isn't allowed here.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Tue, 9 Apr 2024 04:52:42 +0000 (06:52 +0200)] 
Merge remote-tracking branch 'origin/master' into next

3 weeks agoconfigroot: Add in LOGDROPHOSTILExxx values
Adolf Belka [Mon, 8 Apr 2024 16:57:21 +0000 (18:57 +0200)] 
configroot: Add in LOGDROPHOSTILExxx values

- I checked out doing a fresh install of CU184 and found that although the
   LOGDROPHOSTILEIN and LOGDROPHOSTILEOUT entries were selected as "on" the values were not
   in the /var/ipfire/optionsfw/settings file.
- After some investigfation I realised that when I created the LOGDROPHOSTILE split into
   incoming and outgoing I had not added them into the configroot lfs file.
- This patch adds the two entries and this was tested out with a fresh install and
   confirmed to update the settings file.

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Disable Landlock support
Michael Tremer [Mon, 8 Apr 2024 16:01:20 +0000 (16:01 +0000)] 
suricata: Disable Landlock support

See #13645 for details.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Update require paths for Landlock
Michael Tremer [Mon, 8 Apr 2024 16:00:41 +0000 (16:00 +0000)] 
suricata: Update require paths for Landlock

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Enable midstream scanning
Michael Tremer [Mon, 8 Apr 2024 14:57:49 +0000 (14:57 +0000)] 
suricata: Enable midstream scanning

We require this because Suricata might be restarted due to development
or rule refreshment purposes. We should then try to resume any
decoders/app-layers wherever possible.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Set midstream-policy to pass-packet
Stefan Schantl [Fri, 5 Apr 2024 19:26:40 +0000 (21:26 +0200)] 
suricata: Set midstream-policy to pass-packet

Set this value to the same as the exception-policy to keep in sync and
hopefully have the same behaviour. In case this option is not set an
ugly message about a not correctly set value will be logged to syslog
during startup.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Enable landlock security feature
Stefan Schantl [Fri, 5 Apr 2024 19:26:39 +0000 (21:26 +0200)] 
suricata: Enable landlock security feature

This will limit the suricata process to only read and write to a certain
files/directories.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Set exception-policy to pass-packet
Stefan Schantl [Fri, 5 Apr 2024 19:26:38 +0000 (21:26 +0200)] 
suricata: Set exception-policy to pass-packet

This simply will skip processing a packet that caused an exception and will
allow Suricata to process all following packets of a flow.

Reference: #13638

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Update suricata.yaml
Stefan Schantl [Fri, 5 Apr 2024 19:26:37 +0000 (21:26 +0200)] 
suricata: Update suricata.yaml

Updata the configuration file for suricata 7.

This includes:
* Default values for newly introduced features and parsers
* Enable recently added protocol parsers for HTTP2, QUIC, Telnet and Torrent
* Update of URL for documentation
* Fixes of various typos and other clarifications

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agoattr: update rootfile
Arne Fitzenreiter [Mon, 8 Apr 2024 08:14:55 +0000 (10:14 +0200)] 
attr: update rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 weeks agoinitscripts: update riscv64 rootfile
Arne Fitzenreiter [Mon, 8 Apr 2024 08:14:17 +0000 (10:14 +0200)] 
initscripts: update riscv64 rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
3 weeks agokernel: update riscv64 config and rootfile
Arne Fitzenreiter [Mon, 8 Apr 2024 08:10:27 +0000 (10:10 +0200)] 
kernel: update riscv64 config and rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agokernel: enable CPUFREQ for Raspberry Pi
Arne Fitzenreiter [Sat, 6 Apr 2024 07:43:01 +0000 (07:43 +0000)] 
kernel: enable CPUFREQ for Raspberry Pi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agoinitskripts: update aarch64 rootfile
Arne Fitzenreiter [Sat, 6 Apr 2024 07:42:21 +0000 (07:42 +0000)] 
initskripts: update aarch64 rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Fri, 5 Apr 2024 20:29:37 +0000 (22:29 +0200)] 
Merge remote-tracking branch 'origin/master' into next

4 weeks agokernel: update to 6.6.25
Arne Fitzenreiter [Fri, 5 Apr 2024 20:27:55 +0000 (22:27 +0200)] 
kernel: update to 6.6.25

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agosuricata: Disable fail-open on NFQUEUE
Michael Tremer [Wed, 3 Apr 2024 20:42:13 +0000 (21:42 +0100)] 
suricata: Disable fail-open on NFQUEUE

This change causes that if suricata crashes, the NFQUEUE will no longer
fall into a mode where ALL packets are being accepted. This used the be
the case before which opened the entire firewall.

If suricata randomly crashes, we will fall back to the "bypass" mode
where packets will bypass suricata, but nothing else.

Fixes: #13642
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agokernel: update to 6.6.24
Arne Fitzenreiter [Thu, 4 Apr 2024 21:33:01 +0000 (23:33 +0200)] 
kernel: update to 6.6.24

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agocore186: add collectd to updater
Arne Fitzenreiter [Thu, 4 Apr 2024 16:26:55 +0000 (18:26 +0200)] 
core186: add collectd to updater

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agocollectd: fix cpufreq graph if virtual cores are offline
Arne Fitzenreiter [Thu, 4 Apr 2024 16:23:29 +0000 (18:23 +0200)] 
collectd: fix cpufreq graph if virtual cores are offline

the kernel doesn't allow to read the frequency of a offline virtual core
if smt is disabled so now no error is reported in this case and NaN submited to the
database.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agocore186: add grub-btrfs initskript changes to updater
Arne Fitzenreiter [Tue, 2 Apr 2024 19:36:46 +0000 (19:36 +0000)] 
core186: add grub-btrfs initskript changes to updater

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agogrub-btrfsd: Drop redundant used PIDFILE mechanism
Stefan Schantl [Wed, 27 Mar 2024 19:39:20 +0000 (20:39 +0100)] 
grub-btrfsd: Drop redundant used PIDFILE mechanism

This case is already covered by the PID mechanism of the used functions

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agogrub-btrfsd: Adjust displayed starting message
Stefan Schantl [Wed, 27 Mar 2024 19:39:19 +0000 (20:39 +0100)] 
grub-btrfsd: Adjust displayed starting message

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agogrub-btrfsd: Use generic volume_fs_type function for FS detection
Stefan Schantl [Wed, 27 Mar 2024 19:39:18 +0000 (20:39 +0100)] 
grub-btrfsd: Use generic volume_fs_type function for FS detection

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agoinitscripts: Add generic function to get the filesystem type of a volume
Stefan Schantl [Wed, 27 Mar 2024 19:39:17 +0000 (20:39 +0100)] 
initscripts: Add generic function to get the filesystem type of a volume

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agogrub-btrfs: fix grub-btrfs build and remove bugtracker url
Arne Fitzenreiter [Sun, 31 Mar 2024 14:30:50 +0000 (16:30 +0200)] 
grub-btrfs: fix grub-btrfs build and remove bugtracker url

grub-btrfs try to reconfigure grub in the buildsystem and print always the bugtracker url on every error even when its not a bug

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Sun, 31 Mar 2024 11:36:08 +0000 (13:36 +0200)] 
Merge remote-tracking branch 'origin/master' into next

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agocore185: excplicit erase liblzma.so.5.6.*
Arne Fitzenreiter [Sun, 31 Mar 2024 11:27:46 +0000 (13:27 +0200)] 
core185: excplicit erase liblzma.so.5.6.*

because if this file exist the cleanap script will remove the older version after downgrade
and the system still use the malewared version.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agokernel: update to 6.6.23
Arne Fitzenreiter [Sun, 31 Mar 2024 08:49:46 +0000 (10:49 +0200)] 
kernel: update to 6.6.23

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agofrr: Bump release version
Michael Tremer [Sat, 30 Mar 2024 12:14:51 +0000 (12:14 +0000)] 
frr: Bump release version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agofrr: Update reloading all services
Michael Tremer [Thu, 28 Mar 2024 17:41:12 +0000 (17:41 +0000)] 
frr: Update reloading all services

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agofrr: Start the management daemon, too
Michael Tremer [Thu, 28 Mar 2024 17:41:11 +0000 (17:41 +0000)] 
frr: Start the management daemon, too

This daemon is running the configuration validation and required to run
at all times.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoprotobuf-c: Ship libraries
Michael Tremer [Thu, 28 Mar 2024 17:41:10 +0000 (17:41 +0000)] 
protobuf-c: Ship libraries

FRR links against this and fails to start without.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agomake.sh: Update contributors
Michael Tremer [Sat, 30 Mar 2024 12:13:08 +0000 (12:13 +0000)] 
make.sh: Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoREADME.md: fix minor typo
Rico Hoppe [Thu, 28 Mar 2024 09:51:53 +0000 (09:51 +0000)] 
README.md: fix minor typo

Signed-off-by: Rico Hoppe <rico.hoppe@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoREADME.md: update text & adjust links to new URLs
Rico Hoppe [Thu, 28 Mar 2024 09:51:52 +0000 (09:51 +0000)] 
README.md: update text & adjust links to new URLs

- links for: about, documentation, help
- wording: wiki to documentation

Signed-off-by: Rico Hoppe <rico.hoppe@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agocore185: Ship new perl modules for libarchive
Michael Tremer [Sat, 30 Mar 2024 12:11:42 +0000 (12:11 +0000)] 
core185: Ship new perl modules for libarchive

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoids-functions.pl: Use libarchive to extract archives
Stefan Schantl [Sat, 30 Mar 2024 11:35:30 +0000 (12:35 +0100)] 
ids-functions.pl: Use libarchive to extract archives

This gives us a lot of benefits:

* Speed up the extraction process
* More supported archive types due the power of libarchive
* Support of passphrase protected archives

It also fixes a problem with non extracted files next to a zero sized
file inside an archive.

Fixes #13632.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoperl-Archive-Peek-Libarchive: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:29 +0000 (12:35 +0100)] 
perl-Archive-Peek-Libarchive: New package

As very simple XS based perl binding for libarchive
to get header data and extract files.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoperl-Object-Tiny: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:28 +0000 (12:35 +0100)] 
perl-Object-Tiny: New package

This is a runtime dependency of perl-Archive-Peek-Libarchive

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoperl-Config-AutoConf: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:27 +0000 (12:35 +0100)] 
perl-Config-AutoConf: New package

This is only a build dependency for perl-Arhive-Peek-Libarchive and
will not be installed on a system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoperl-Capture-Tiny: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:26 +0000 (12:35 +0100)] 
perl-Capture-Tiny: New package

This is only a build dependency for perl-Config-AutoConf and
will not be installed on a system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agocore185: Ship everything that is linked against XZ
Michael Tremer [Sat, 30 Mar 2024 12:07:22 +0000 (12:07 +0000)] 
core185: Ship everything that is linked against XZ

This is a precautionary step to avoid that we have any issues to face
because of a downgrade as new symbols have been added to liblzma 5.6.0.

Furthermore, this should avoid shipping any traces of any other
potential malware in XZ that has been added in 5.6.0 or after.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoxz: Remove excess whitespace
Michael Tremer [Sat, 30 Mar 2024 11:58:24 +0000 (11:58 +0000)] 
xz: Remove excess whitespace

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoxz: Revert back to version 5.4.5 due to backdoor issue
Adolf Belka [Sat, 30 Mar 2024 08:14:58 +0000 (09:14 +0100)] 
xz: Revert back to version 5.4.5 due to backdoor issue

- xz version 5.6.0 and 5.6.1 discovered to have been backdoored by what looks to have
   been one of the xz devs.
- IPFire looks not to be affected by the problem as we don't patch openssh to be linked
   with liblzma
- However due to question marks about what else might be in these 5.6.x versions it is
   better to revert back to a version that did not have the build-to-host.m4 file with the
   code that modifies the build if it meets certain criteria.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Wed, 27 Mar 2024 17:27:30 +0000 (18:27 +0100)] 
Merge remote-tracking branch 'origin/master' into next

5 weeks agogrub-btrfs: remove boot/grub/grubenv
Arne Fitzenreiter [Wed, 27 Mar 2024 01:59:07 +0000 (02:59 +0100)] 
grub-btrfs: remove boot/grub/grubenv

this file should created by grub-install at installation.
Also it is not present on aarch64 builds of grub.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoIPS: Fix how we show EOL providers
Michael Tremer [Tue, 26 Mar 2024 15:08:01 +0000 (15:08 +0000)] 
IPS: Fix how we show EOL providers

There is no need to add a legend as I find it confusing. The change that
people are using an EOL is rather slim and so I don't to waste space.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agocore185: Fix update.sh syntax issues
Michael Tremer [Tue, 26 Mar 2024 14:43:39 +0000 (14:43 +0000)] 
core185: Fix update.sh syntax issues

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoCU185-update.sh: Add drop hostile in & out logging entries if not already present
Adolf Belka [Mon, 25 Mar 2024 17:44:56 +0000 (18:44 +0100)] 
CU185-update.sh: Add drop hostile in & out logging entries if not already present

- This v2 patch corrects that the previous script was looking for =on. If a user had
   modified the preferences to change it to =off then the script would have resulted in
   both =on and =off versions being in the settings file.
- This patch ensures that those people who updated to CU184 before the CU184-update.sh
   patch fix to add the logging entries was added will get their optionsfw settings file
   correctly updated with CU185
- This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do not already
   exist in the optionsfw settings file.
- This change also does the check for LOGDROPHOSTILEIN and LOGDROPHOSTILEOUT as two
   separate checks and then runs the firewall update command

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agocore186: add brtfs related changes to updater
Arne Fitzenreiter [Tue, 26 Mar 2024 07:40:56 +0000 (07:40 +0000)] 
core186: add brtfs related changes to updater

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agogrub-btrfs: New package
Stefan Schantl [Sun, 24 Mar 2024 12:39:53 +0000 (13:39 +0100)] 
grub-btrfs: New package

This kind of grub addon will extend the grub boot menu by a additional
submenu where a BTRFS snapshot can be selected to directly use as root
volume and boot into it.

The grub-btrfsd daemon is using inotify(tools) to watch the snapshot directory for
new or deleted snapshots and calls grub-mkconfig to adjust the snapshot grub submenu

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinotify-tools: New package
Stefan Schantl [Sun, 24 Mar 2024 12:39:52 +0000 (13:39 +0100)] 
inotify-tools: New package

This package is required for the grub-btrfs daemon

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Pass choosen filesystem to hw_make_destination
Stefan Schantl [Sun, 24 Mar 2024 12:37:35 +0000 (13:37 +0100)] 
installer: Pass choosen filesystem to hw_make_destination

This is required to proper choose if a seperate boot partition should be
created or must not created (BTRFS)

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Add code to correctly write the fstab when installing on BTRFS
Stefan Schantl [Sat, 23 Mar 2024 10:56:29 +0000 (11:56 +0100)] 
installer: Add code to correctly write the fstab when installing on BTRFS

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Add code to proper unmount the BTRFS layout
Stefan Schantl [Sat, 23 Mar 2024 10:56:28 +0000 (11:56 +0100)] 
installer: Add code to proper unmount the BTRFS layout

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Define common mount options for BTRFS volumes
Stefan Schantl [Sat, 23 Mar 2024 10:56:27 +0000 (11:56 +0100)] 
installer: Define common mount options for BTRFS volumes

As default we are using zstd for compression with level 1

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Mount BTRFS layout before installing the system
Stefan Schantl [Sat, 23 Mar 2024 10:56:26 +0000 (11:56 +0100)] 
installer: Mount BTRFS layout before installing the system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Allow writing to the debug console from anywhere
Stefan Schantl [Sat, 23 Mar 2024 10:56:25 +0000 (11:56 +0100)] 
installer: Allow writing to the debug console from anywhere

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Add recurisve mkdir function
Stefan Schantl [Sat, 23 Mar 2024 10:56:24 +0000 (11:56 +0100)] 
installer: Add recurisve mkdir function

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Add code to create a BTRFS subvolume layout
Stefan Schantl [Sat, 23 Mar 2024 10:56:23 +0000 (11:56 +0100)] 
installer: Add code to create a BTRFS subvolume layout

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Disable own boot partition when using BTRFS
Stefan Schantl [Sat, 23 Mar 2024 10:56:22 +0000 (11:56 +0100)] 
installer: Disable own boot partition when using BTRFS

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Ensure to always create the /boot directory.
Stefan Schantl [Sat, 23 Mar 2024 10:56:21 +0000 (11:56 +0100)] 
installer: Ensure to always create the /boot directory.

Ensure to always create the /boot directory during the mounting
of the various created file systems. If the /boot directory does not
exist some following mount operations could not be performed correctly
and the installation/mounting will fail.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agodracut: Ship BTRFS related modules
Stefan Schantl [Sat, 23 Mar 2024 10:56:20 +0000 (11:56 +0100)] 
dracut: Ship BTRFS related modules

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoinstaller: Allow to install IPFire on BTRFS
Stefan Schantl [Sat, 23 Mar 2024 10:56:19 +0000 (11:56 +0100)] 
installer: Allow to install IPFire on BTRFS

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agobtrfs-progs: New package
Stefan Schantl [Sat, 23 Mar 2024 10:56:18 +0000 (11:56 +0100)] 
btrfs-progs: New package

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
5 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Tue, 26 Mar 2024 07:28:20 +0000 (07:28 +0000)] 
Merge remote-tracking branch 'origin/master' into next

5 weeks agoshadow: Update login.defs to remove reference to cracklib
Adolf Belka [Mon, 25 Mar 2024 13:41:38 +0000 (14:41 +0100)] 
shadow: Update login.defs to remove reference to cracklib

- From shadow-15.0.0 all references to cracklib were removed from shadow. Apparently
   some functions were no longer accessible and the shadow team decided to remove cracklib
   references completely. This was not mentioned in the changelkog for 15.0.0
- This resulkts in gettinbg the message configuration error - unknown item
   'CRACKKLIB_DICTPATH' ( notify administrator ) when logging in to the console.
- The login to the console occurs successfully so the message is only a warning that
   cracklib is no longer used.
- IPfire does not use cracklkib anyway so this patch removes the section referring to
   cracklib from the login.defs configuration file.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agosamba: Add wsdd as a dependency to samba
Adolf Belka [Mon, 25 Mar 2024 11:17:52 +0000 (12:17 +0100)] 
samba: Add wsdd as a dependency to samba

- Add wsdd as a dependency to samba so it will be installed together with samba

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoMerge remote-tracking branch 'origin/master' into next
Arne Fitzenreiter [Sun, 24 Mar 2024 07:48:51 +0000 (08:48 +0100)] 
Merge remote-tracking branch 'origin/master' into next

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
6 weeks agoCU185-update.sh: Add drop hostile in & out logging entries if not already present
Adolf Belka [Wed, 20 Mar 2024 14:43:27 +0000 (15:43 +0100)] 
CU185-update.sh: Add drop hostile in & out logging entries if not already present

- This patch ensures that those people who updated to CU184 before the CU184-update.sh
   patch fix to add the logging entries was added will get their optionsfw settings file
   correctly updated with CU185
- This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do noit already
   exist in the optionsfw settings file.

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>