]> git.ipfire.org Git - people/mlorenz/ipfire-2.x.git/log
people/mlorenz/ipfire-2.x.git
2 weeks agoflash-images: fix image creation - inc root size to 2.5GB mailserver
Marcel Lorenz [Fri, 19 Apr 2024 15:07:18 +0000 (17:07 +0200)] 
flash-images: fix image creation - inc root size to 2.5GB

2 weeks agoclamav: update to 1.3.1
Marcel Lorenz [Fri, 19 Apr 2024 15:03:38 +0000 (17:03 +0200)] 
clamav: update to 1.3.1

2 weeks agoupdate kernel to 6.6.28
Marcel Lorenz [Fri, 19 Apr 2024 15:03:06 +0000 (17:03 +0200)] 
update kernel to 6.6.28

2 weeks agoremove obsolete core update filelist files
Marcel Lorenz [Fri, 19 Apr 2024 15:02:23 +0000 (17:02 +0200)] 
remove obsolete core update filelist files

2 weeks agoMerge branch 'master' of ssh://people.ipfire.org/pub/git/ipfire-2.x into mailserver
Marcel Lorenz [Sun, 14 Apr 2024 16:01:05 +0000 (18:01 +0200)] 
Merge branch 'master' of ssh://people.ipfire.org/pub/git/ipfire-2.x into mailserver

3 weeks agophp-addons: small cleanup fix in lfs file
Marcel Lorenz [Fri, 12 Apr 2024 19:51:35 +0000 (21:51 +0200)] 
php-addons: small cleanup fix in lfs file

3 weeks agobuild alsa after linux-firmware
Marcel Lorenz [Fri, 12 Apr 2024 19:50:06 +0000 (21:50 +0200)] 
build alsa after linux-firmware

3 weeks agoghostscript: disable versioned path
Marcel Lorenz [Fri, 12 Apr 2024 19:48:50 +0000 (21:48 +0200)] 
ghostscript: disable versioned path

3 weeks agophp: update to 8.2.18
Marcel Lorenz [Fri, 12 Apr 2024 19:47:58 +0000 (21:47 +0200)] 
php: update to 8.2.18

3 weeks agogo: update to 1.22.2
Marcel Lorenz [Fri, 12 Apr 2024 19:47:30 +0000 (21:47 +0200)] 
go: update to 1.22.2

3 weeks agoopenssl: update to 3.3.0
Marcel Lorenz [Fri, 12 Apr 2024 19:47:00 +0000 (21:47 +0200)] 
openssl: update to 3.3.0

3 weeks agolinux-firmware: update to 20240312 and add support for raspberri pi 5
Marcel Lorenz [Thu, 11 Apr 2024 06:23:27 +0000 (08:23 +0200)] 
linux-firmware: update to 20240312 and add support for raspberri pi 5

3 weeks agodrop minidlna - project not more maintaiend since 06-2023
Marcel Lorenz [Wed, 10 Apr 2024 19:45:30 +0000 (21:45 +0200)] 
drop minidlna - project not more maintaiend since 06-2023

3 weeks agoffmepeg: update to 7.0
Marcel Lorenz [Wed, 10 Apr 2024 19:41:55 +0000 (21:41 +0200)] 
ffmepeg: update to 7.0

3 weeks agofix module compression of rtl8812au
Marcel Lorenz [Wed, 10 Apr 2024 19:40:17 +0000 (21:40 +0200)] 
fix module compression of rtl8812au

3 weeks agolinux-atm: update rootfile
Marcel Lorenz [Wed, 10 Apr 2024 19:39:18 +0000 (21:39 +0200)] 
linux-atm: update rootfile

3 weeks agoship gcc initscripts python3 vectorscan and kernel with aarch64 core update
Marcel Lorenz [Wed, 10 Apr 2024 19:38:40 +0000 (21:38 +0200)] 
ship gcc initscripts python3 vectorscan and kernel with aarch64 core update

3 weeks agophp-addons: update to 2024.4 - new redis 6.0.2, apcu 5.1.23, brotli 0.15.0
Marcel Lorenz [Wed, 10 Apr 2024 19:35:58 +0000 (21:35 +0200)] 
php-addons: update to 2024.4 - new redis 6.0.2, apcu 5.1.23, brotli 0.15.0

3 weeks agoiana-etc: update to 20240318
Marcel Lorenz [Wed, 10 Apr 2024 19:31:00 +0000 (21:31 +0200)] 
iana-etc: update to 20240318

3 weeks agocmake: update to 3.29.1
Marcel Lorenz [Wed, 10 Apr 2024 19:30:33 +0000 (21:30 +0200)] 
cmake: update to 3.29.1

3 weeks agobc: update to 6.7.5
Marcel Lorenz [Wed, 10 Apr 2024 19:30:11 +0000 (21:30 +0200)] 
bc: update to 6.7.5

3 weeks agosatip: update to 1.3.4
Marcel Lorenz [Wed, 10 Apr 2024 19:29:46 +0000 (21:29 +0200)] 
satip: update to 1.3.4

3 weeks agosquid: update to 6.9
Marcel Lorenz [Wed, 10 Apr 2024 19:29:15 +0000 (21:29 +0200)] 
squid: update to 6.9

3 weeks agorsync: update to 3.3.0
Marcel Lorenz [Wed, 10 Apr 2024 19:28:57 +0000 (21:28 +0200)] 
rsync: update to 3.3.0

3 weeks agozstd: update to 1.5.6
Marcel Lorenz [Wed, 10 Apr 2024 19:28:34 +0000 (21:28 +0200)] 
zstd: update to 1.5.6

3 weeks agoremove installing some firmware files form stage2 lfs file
Marcel Lorenz [Wed, 10 Apr 2024 19:28:02 +0000 (21:28 +0200)] 
remove installing some firmware files form stage2 lfs file

3 weeks agoupdate kernel do 6.6.25
Marcel Lorenz [Wed, 10 Apr 2024 19:25:13 +0000 (21:25 +0200)] 
update kernel do 6.6.25

3 weeks agopkgconf: update to 2.2.0
Marcel Lorenz [Wed, 10 Apr 2024 19:24:31 +0000 (21:24 +0200)] 
pkgconf: update to 2.2.0

3 weeks agoshadow: update to 4.15.1
Marcel Lorenz [Wed, 10 Apr 2024 19:23:57 +0000 (21:23 +0200)] 
shadow: update to 4.15.1

3 weeks agoapache: update to 2.4.59
Marcel Lorenz [Wed, 10 Apr 2024 19:23:07 +0000 (21:23 +0200)] 
apache: update to 2.4.59

3 weeks agocoreutils: update to 9.5
Marcel Lorenz [Wed, 10 Apr 2024 19:22:18 +0000 (21:22 +0200)] 
coreutils: update to 9.5

3 weeks agosuricata: Change midstream policy to "pass-flow"
Michael Tremer [Tue, 9 Apr 2024 09:51:18 +0000 (10:51 +0100)] 
suricata: Change midstream policy to "pass-flow"

Pass packet isn't allowed here.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agoconfigroot: Add in LOGDROPHOSTILExxx values
Adolf Belka [Mon, 8 Apr 2024 16:57:21 +0000 (18:57 +0200)] 
configroot: Add in LOGDROPHOSTILExxx values

- I checked out doing a fresh install of CU184 and found that although the
   LOGDROPHOSTILEIN and LOGDROPHOSTILEOUT entries were selected as "on" the values were not
   in the /var/ipfire/optionsfw/settings file.
- After some investigfation I realised that when I created the LOGDROPHOSTILE split into
   incoming and outgoing I had not added them into the configroot lfs file.
- This patch adds the two entries and this was tested out with a fresh install and
   confirmed to update the settings file.

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Disable Landlock support
Michael Tremer [Mon, 8 Apr 2024 16:01:20 +0000 (16:01 +0000)] 
suricata: Disable Landlock support

See #13645 for details.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Update require paths for Landlock
Michael Tremer [Mon, 8 Apr 2024 16:00:41 +0000 (16:00 +0000)] 
suricata: Update require paths for Landlock

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Enable midstream scanning
Michael Tremer [Mon, 8 Apr 2024 14:57:49 +0000 (14:57 +0000)] 
suricata: Enable midstream scanning

We require this because Suricata might be restarted due to development
or rule refreshment purposes. We should then try to resume any
decoders/app-layers wherever possible.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Set midstream-policy to pass-packet
Stefan Schantl [Fri, 5 Apr 2024 19:26:40 +0000 (21:26 +0200)] 
suricata: Set midstream-policy to pass-packet

Set this value to the same as the exception-policy to keep in sync and
hopefully have the same behaviour. In case this option is not set an
ugly message about a not correctly set value will be logged to syslog
during startup.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Enable landlock security feature
Stefan Schantl [Fri, 5 Apr 2024 19:26:39 +0000 (21:26 +0200)] 
suricata: Enable landlock security feature

This will limit the suricata process to only read and write to a certain
files/directories.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Set exception-policy to pass-packet
Stefan Schantl [Fri, 5 Apr 2024 19:26:38 +0000 (21:26 +0200)] 
suricata: Set exception-policy to pass-packet

This simply will skip processing a packet that caused an exception and will
allow Suricata to process all following packets of a flow.

Reference: #13638

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agosuricata: Update suricata.yaml
Stefan Schantl [Fri, 5 Apr 2024 19:26:37 +0000 (21:26 +0200)] 
suricata: Update suricata.yaml

Updata the configuration file for suricata 7.

This includes:
* Default values for newly introduced features and parsers
* Enable recently added protocol parsers for HTTP2, QUIC, Telnet and Torrent
* Update of URL for documentation
* Fixes of various typos and other clarifications

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
3 weeks agoexclude llvm and gdb from checking rootfiles for machine names
Marcel Lorenz [Sun, 7 Apr 2024 07:00:09 +0000 (09:00 +0200)] 
exclude llvm and gdb from checking rootfiles for machine names

3 weeks agollvm does not use fstack-clash-protection on aarch64
Marcel Lorenz [Sun, 7 Apr 2024 06:58:32 +0000 (08:58 +0200)] 
llvm does not use fstack-clash-protection on aarch64

3 weeks agolinux: update aarch64 rootfile
Marcel Lorenz [Sun, 7 Apr 2024 06:56:49 +0000 (08:56 +0200)] 
linux: update aarch64 rootfile

3 weeks agoutiil-linux: update aarch64 rootfile
Marcel Lorenz [Sun, 7 Apr 2024 06:56:38 +0000 (08:56 +0200)] 
utiil-linux: update aarch64 rootfile

4 weeks agosuricata: Disable fail-open on NFQUEUE
Michael Tremer [Wed, 3 Apr 2024 20:42:13 +0000 (21:42 +0100)] 
suricata: Disable fail-open on NFQUEUE

This change causes that if suricata crashes, the NFQUEUE will no longer
fall into a mode where ALL packets are being accepted. This used the be
the case before which opened the entire firewall.

If suricata randomly crashes, we will fall back to the "bypass" mode
where packets will bypass suricata, but nothing else.

Fixes: #13642
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoupdate arch specific CLAGS in make.sh
Marcel Lorenz [Tue, 2 Apr 2024 12:50:32 +0000 (14:50 +0200)] 
update arch specific CLAGS in make.sh

4 weeks agomerge origin master core 185 into mailserver
Marcel Lorenz [Mon, 1 Apr 2024 20:59:09 +0000 (22:59 +0200)] 
merge origin master core 185 into mailserver

4 weeks agocore185: excplicit erase liblzma.so.5.6.*
Arne Fitzenreiter [Sun, 31 Mar 2024 11:27:46 +0000 (13:27 +0200)] 
core185: excplicit erase liblzma.so.5.6.*

because if this file exist the cleanap script will remove the older version after downgrade
and the system still use the malewared version.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 weeks agosysvinit: update to 3.09
Marcel Lorenz [Sun, 31 Mar 2024 11:23:32 +0000 (13:23 +0200)] 
sysvinit: update to 3.09

4 weeks agospamassassin: update to 4.0.1
Marcel Lorenz [Sun, 31 Mar 2024 11:23:08 +0000 (13:23 +0200)] 
spamassassin: update to 4.0.1

4 weeks agoutil-linux: update to 2.40
Marcel Lorenz [Sun, 31 Mar 2024 11:22:37 +0000 (13:22 +0200)] 
util-linux: update to 2.40

4 weeks agocurl: update to 8.7.1
Marcel Lorenz [Sun, 31 Mar 2024 11:21:49 +0000 (13:21 +0200)] 
curl: update to 8.7.1

4 weeks agofrr: Bump release version
Michael Tremer [Sat, 30 Mar 2024 12:14:51 +0000 (12:14 +0000)] 
frr: Bump release version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agofrr: Update reloading all services
Michael Tremer [Thu, 28 Mar 2024 17:41:12 +0000 (17:41 +0000)] 
frr: Update reloading all services

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agofrr: Start the management daemon, too
Michael Tremer [Thu, 28 Mar 2024 17:41:11 +0000 (17:41 +0000)] 
frr: Start the management daemon, too

This daemon is running the configuration validation and required to run
at all times.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoprotobuf-c: Ship libraries
Michael Tremer [Thu, 28 Mar 2024 17:41:10 +0000 (17:41 +0000)] 
protobuf-c: Ship libraries

FRR links against this and fails to start without.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agomake.sh: Update contributors
Michael Tremer [Sat, 30 Mar 2024 12:13:08 +0000 (12:13 +0000)] 
make.sh: Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoREADME.md: fix minor typo
Rico Hoppe [Thu, 28 Mar 2024 09:51:53 +0000 (09:51 +0000)] 
README.md: fix minor typo

Signed-off-by: Rico Hoppe <rico.hoppe@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoREADME.md: update text & adjust links to new URLs
Rico Hoppe [Thu, 28 Mar 2024 09:51:52 +0000 (09:51 +0000)] 
README.md: update text & adjust links to new URLs

- links for: about, documentation, help
- wording: wiki to documentation

Signed-off-by: Rico Hoppe <rico.hoppe@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agocore185: Ship new perl modules for libarchive
Michael Tremer [Sat, 30 Mar 2024 12:11:42 +0000 (12:11 +0000)] 
core185: Ship new perl modules for libarchive

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoids-functions.pl: Use libarchive to extract archives
Stefan Schantl [Sat, 30 Mar 2024 11:35:30 +0000 (12:35 +0100)] 
ids-functions.pl: Use libarchive to extract archives

This gives us a lot of benefits:

* Speed up the extraction process
* More supported archive types due the power of libarchive
* Support of passphrase protected archives

It also fixes a problem with non extracted files next to a zero sized
file inside an archive.

Fixes #13632.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoperl-Archive-Peek-Libarchive: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:29 +0000 (12:35 +0100)] 
perl-Archive-Peek-Libarchive: New package

As very simple XS based perl binding for libarchive
to get header data and extract files.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoperl-Object-Tiny: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:28 +0000 (12:35 +0100)] 
perl-Object-Tiny: New package

This is a runtime dependency of perl-Archive-Peek-Libarchive

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoperl-Config-AutoConf: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:27 +0000 (12:35 +0100)] 
perl-Config-AutoConf: New package

This is only a build dependency for perl-Arhive-Peek-Libarchive and
will not be installed on a system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoperl-Capture-Tiny: New package
Stefan Schantl [Sat, 30 Mar 2024 11:35:26 +0000 (12:35 +0100)] 
perl-Capture-Tiny: New package

This is only a build dependency for perl-Config-AutoConf and
will not be installed on a system

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agocore185: Ship everything that is linked against XZ
Michael Tremer [Sat, 30 Mar 2024 12:07:22 +0000 (12:07 +0000)] 
core185: Ship everything that is linked against XZ

This is a precautionary step to avoid that we have any issues to face
because of a downgrade as new symbols have been added to liblzma 5.6.0.

Furthermore, this should avoid shipping any traces of any other
potential malware in XZ that has been added in 5.6.0 or after.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoxz: Remove excess whitespace
Michael Tremer [Sat, 30 Mar 2024 11:58:24 +0000 (11:58 +0000)] 
xz: Remove excess whitespace

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 weeks agoxz: Revert back to version 5.4.5 due to backdoor issue
Adolf Belka [Sat, 30 Mar 2024 08:14:58 +0000 (09:14 +0100)] 
xz: Revert back to version 5.4.5 due to backdoor issue

- xz version 5.6.0 and 5.6.1 discovered to have been backdoored by what looks to have
   been one of the xz devs.
- IPFire looks not to be affected by the problem as we don't patch openssh to be linked
   with liblzma
- However due to question marks about what else might be in these 5.6.x versions it is
   better to revert back to a version that did not have the build-to-host.m4 file with the
   code that modifies the build if it meets certain criteria.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoupdate kernel to 6.6.22
Marcel Lorenz [Wed, 27 Mar 2024 10:28:01 +0000 (11:28 +0100)] 
update kernel to 6.6.22

5 weeks agoIPS: Fix how we show EOL providers
Michael Tremer [Tue, 26 Mar 2024 15:08:01 +0000 (15:08 +0000)] 
IPS: Fix how we show EOL providers

There is no need to add a legend as I find it confusing. The change that
people are using an EOL is rather slim and so I don't to waste space.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agocore185: Fix update.sh syntax issues
Michael Tremer [Tue, 26 Mar 2024 14:43:39 +0000 (14:43 +0000)] 
core185: Fix update.sh syntax issues

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoCU185-update.sh: Add drop hostile in & out logging entries if not already present
Adolf Belka [Mon, 25 Mar 2024 17:44:56 +0000 (18:44 +0100)] 
CU185-update.sh: Add drop hostile in & out logging entries if not already present

- This v2 patch corrects that the previous script was looking for =on. If a user had
   modified the preferences to change it to =off then the script would have resulted in
   both =on and =off versions being in the settings file.
- This patch ensures that those people who updated to CU184 before the CU184-update.sh
   patch fix to add the logging entries was added will get their optionsfw settings file
   correctly updated with CU185
- This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do not already
   exist in the optionsfw settings file.
- This change also does the check for LOGDROPHOSTILEIN and LOGDROPHOSTILEOUT as two
   separate checks and then runs the firewall update command

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agofix hostile drop function in rules.pl
Marcel Lorenz [Tue, 26 Mar 2024 09:54:14 +0000 (10:54 +0100)] 
fix hostile drop function in rules.pl

5 weeks agobind: update to 9.18.25
Marcel Lorenz [Tue, 26 Mar 2024 07:05:37 +0000 (08:05 +0100)] 
bind: update to 9.18.25

5 weeks agoexpat: update to 2.6.2
Marcel Lorenz [Tue, 26 Mar 2024 07:05:08 +0000 (08:05 +0100)] 
expat: update to 2.6.2

5 weeks agomeson: update to 1.4.0
Marcel Lorenz [Tue, 26 Mar 2024 07:04:43 +0000 (08:04 +0100)] 
meson: update to 1.4.0

5 weeks agopython3-wheel: update to 0.43.0
Marcel Lorenz [Tue, 26 Mar 2024 07:04:21 +0000 (08:04 +0100)] 
python3-wheel: update to 0.43.0

5 weeks agoxz: update to 5.6.1
Marcel Lorenz [Tue, 26 Mar 2024 07:03:47 +0000 (08:03 +0100)] 
xz: update to 5.6.1

5 weeks agopostfix: update to 3.9.0
Marcel Lorenz [Tue, 26 Mar 2024 07:03:16 +0000 (08:03 +0100)] 
postfix: update to 3.9.0

5 weeks agozoneconf.cgi: allow add red0 as VLAN device
Marcel Lorenz [Tue, 26 Mar 2024 07:02:49 +0000 (08:02 +0100)] 
zoneconf.cgi: allow add red0 as VLAN device

5 weeks agoshadow: Update login.defs to remove reference to cracklib
Adolf Belka [Mon, 25 Mar 2024 13:41:38 +0000 (14:41 +0100)] 
shadow: Update login.defs to remove reference to cracklib

- From shadow-15.0.0 all references to cracklib were removed from shadow. Apparently
   some functions were no longer accessible and the shadow team decided to remove cracklib
   references completely. This was not mentioned in the changelkog for 15.0.0
- This resulkts in gettinbg the message configuration error - unknown item
   'CRACKKLIB_DICTPATH' ( notify administrator ) when logging in to the console.
- The login to the console occurs successfully so the message is only a warning that
   cracklib is no longer used.
- IPfire does not use cracklkib anyway so this patch removes the section referring to
   cracklib from the login.defs configuration file.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agosamba: Add wsdd as a dependency to samba
Adolf Belka [Mon, 25 Mar 2024 11:17:52 +0000 (12:17 +0100)] 
samba: Add wsdd as a dependency to samba

- Add wsdd as a dependency to samba so it will be installed together with samba

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
5 weeks agoupdate rpi-firmware to 20240220 with initial support for Rapsberry PI 5
Marcel Lorenz [Sun, 24 Mar 2024 06:44:31 +0000 (07:44 +0100)] 
update rpi-firmware to 20240220 with initial support for Rapsberry PI 5

5 weeks agophp: update to 8.2.17
Marcel Lorenz [Sun, 24 Mar 2024 06:30:41 +0000 (07:30 +0100)] 
php: update to 8.2.17

5 weeks agoremove rrd ramdisk code from sensors init script, already in collectd script
Marcel Lorenz [Sun, 24 Mar 2024 06:30:16 +0000 (07:30 +0100)] 
remove rrd ramdisk code from sensors init script, already in collectd script

5 weeks agoadd create /run/var die to cleanfs init script
Marcel Lorenz [Sun, 24 Mar 2024 06:29:05 +0000 (07:29 +0100)] 
add create /run/var die to cleanfs init script

6 weeks agoCU185-update.sh: Add drop hostile in & out logging entries if not already present
Adolf Belka [Wed, 20 Mar 2024 14:43:27 +0000 (15:43 +0100)] 
CU185-update.sh: Add drop hostile in & out logging entries if not already present

- This patch ensures that those people who updated to CU184 before the CU184-update.sh
   patch fix to add the logging entries was added will get their optionsfw settings file
   correctly updated with CU185
- This only adds the LOGDROPHOSTILEIN & LOGDROPHOSTILEOUT entries if they do noit already
   exist in the optionsfw settings file.

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoids.cgi: Improve add provider logic
Stefan Schantl [Fri, 22 Mar 2024 05:01:45 +0000 (06:01 +0100)] 
ids.cgi: Improve add provider logic

Do not longer add unsupported/removed providers as an option
when adding a new/first ruleset provider.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agocore185: Ship IPS files
Michael Tremer [Fri, 22 Mar 2024 15:29:22 +0000 (15:29 +0000)] 
core185: Ship IPS files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoids.cgi: Adjust code for marking unsupported providers
Stefan Schantl [Thu, 21 Mar 2024 20:51:18 +0000 (21:51 +0100)] 
ids.cgi: Adjust code for marking unsupported providers

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoruleset-sources: Restore generic details about recently dropped providers
Stefan Schantl [Thu, 21 Mar 2024 20:51:17 +0000 (21:51 +0100)] 
ruleset-sources: Restore generic details about recently dropped providers

At least these informations are required to display something usefull
on the webgui, even if a provider has been dropped.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoupdate-ids-ruleset: Disable provider if not dl_url can be obtained
Stefan Schantl [Thu, 21 Mar 2024 20:51:16 +0000 (21:51 +0100)] 
update-ids-ruleset: Disable provider if not dl_url can be obtained

Unsupported/Removed provides does not longer have these information

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoids.cgi: Change check if a provider is not longer supported
Stefan Schantl [Thu, 21 Mar 2024 20:51:15 +0000 (21:51 +0100)] 
ids.cgi: Change check if a provider is not longer supported

This check is now based on a download URL instead of checking if
an entry in the ruleset sources is present.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoids-functions.pl: Improve logic to get the cached rulesfile of a provider
Stefan Schantl [Thu, 21 Mar 2024 20:51:14 +0000 (21:51 +0100)] 
ids-functions.pl: Improve logic to get the cached rulesfile of a provider

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agocore185: Ship IPS ruleset sources
Michael Tremer [Thu, 21 Mar 2024 14:56:41 +0000 (14:56 +0000)] 
core185: Ship IPS ruleset sources

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agosuricata: Update to 7.0.4
Michael Tremer [Wed, 20 Mar 2024 10:03:51 +0000 (10:03 +0000)] 
suricata: Update to 7.0.4

  https://suricata.io/2024/03/19/suricata-7-0-4-and-6-0-17-released/

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agocore185: Ship libhtp
Michael Tremer [Wed, 20 Mar 2024 10:01:13 +0000 (10:01 +0000)] 
core185: Ship libhtp

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agolibhtp: Update to 0.5.47
Michael Tremer [Wed, 20 Mar 2024 10:00:51 +0000 (10:00 +0000)] 
libhtp: Update to 0.5.47

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agoConfig: Update source upload URL
Michael Tremer [Wed, 20 Mar 2024 09:56:14 +0000 (09:56 +0000)] 
Config: Update source upload URL

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
6 weeks agowsdd: Remove dropped initscript
Michael Tremer [Tue, 19 Mar 2024 11:14:42 +0000 (11:14 +0000)] 
wsdd: Remove dropped initscript

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>