]> git.ipfire.org Git - people/ms/ipfire-2.x.git/log
people/ms/ipfire-2.x.git
4 years agoIPsec: Add support for SHA3 for IKE and ESP strongswan
Michael Tremer [Tue, 31 Mar 2020 09:27:16 +0000 (09:27 +0000)] 
IPsec: Add support for SHA3 for IKE and ESP

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 years agostrongswan: Build sha3 plugin
Michael Tremer [Mon, 30 Mar 2020 17:58:56 +0000 (17:58 +0000)] 
strongswan: Build sha3 plugin

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 years agostrongswan: Update to 5.8.4
Michael Tremer [Mon, 30 Mar 2020 17:45:18 +0000 (17:45 +0000)] 
strongswan: Update to 5.8.4

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
4 years agovpnmain.cgi: fix string
Arne Fitzenreiter [Mon, 30 Mar 2020 17:25:08 +0000 (17:25 +0000)] 
vpnmain.cgi: fix string

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoFix accidentially reverted IKE lifetime limit to 24 hours
Michael Tremer [Tue, 10 Mar 2020 13:37:18 +0000 (13:37 +0000)] 
Fix accidentially reverted IKE lifetime limit to 24 hours

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: apply changed sysctl settings
Arne Fitzenreiter [Mon, 30 Mar 2020 17:09:34 +0000 (17:09 +0000)] 
core143: apply changed sysctl settings

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agosysctl.conf: Turn on hard- and symlink protection
Peter Müller [Thu, 23 Jan 2020 21:28:00 +0000 (21:28 +0000)] 
sysctl.conf: Turn on hard- and symlink protection

Cc: Michael Tremer <michael.tremer@ipfire.org>
Cc: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoupdate language files for mail.cgi changes
Peter Müller [Mon, 3 Feb 2020 18:35:00 +0000 (18:35 +0000)] 
update language files for mail.cgi changes

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agomail.cgi: add support for implicit TLS usage
Peter Müller [Mon, 3 Feb 2020 18:35:00 +0000 (18:35 +0000)] 
mail.cgi: add support for implicit TLS usage

The second version of this patchset fixes reading empty configuration
files and superseds the first version (duh!).

Fixes #12161

Reported-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Tested-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agodma: update to 0.12
Peter Müller [Sat, 1 Feb 2020 20:26:00 +0000 (20:26 +0000)] 
dma: update to 0.12

All of the dma patches in src/patches/ were merged into its upstream
repository by now, thus becoming obsolete and deleted by this patch.

Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add oinkmaster.conf
Arne Fitzenreiter [Mon, 30 Mar 2020 16:43:50 +0000 (16:43 +0000)] 
core143: add oinkmaster.conf

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agooinkmaster: Do not skip threshold.conf
Stefan Schantl [Thu, 30 Jan 2020 12:58:16 +0000 (13:58 +0100)] 
oinkmaster: Do not skip threshold.conf

Fixes #12096.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: set user of /var/spool/cron to cron
Arne Fitzenreiter [Mon, 30 Mar 2020 16:39:06 +0000 (16:39 +0000)] 
core143: set user of /var/spool/cron to cron

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agofcron: Fix reloading crontab
Michael Tremer [Wed, 5 Feb 2020 11:23:34 +0000 (11:23 +0000)] 
fcron: Fix reloading crontab

fcrontab -z fails on a freshly installed system since
/var/spool/cron is now owned by cron:cron and a temporary
file cannot be created.

This will have to be manually changed in the updater by
calling:

  chown cron:cron /var/spool/cron

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agospectre-meltdown-checker: update to 0.43
Peter Müller [Sat, 21 Mar 2020 19:40:00 +0000 (19:40 +0000)] 
spectre-meltdown-checker: update to 0.43

Please refer to https://github.com/speed47/spectre-meltdown-checker/releases/tag/v0.43
for release notes.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoOpenVPN: Delete RRD dir if connection is deleted
Erik Kapfer [Sat, 28 Mar 2020 08:32:24 +0000 (09:32 +0100)] 
OpenVPN: Delete RRD dir if connection is deleted

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoMerge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Sun, 29 Mar 2020 06:35:21 +0000 (06:35 +0000)] 
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next

4 years agosmartmontools: update rootfile
Arne Fitzenreiter [Sun, 29 Mar 2020 06:34:18 +0000 (06:34 +0000)] 
smartmontools: update rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agobind: Update to 9.11.17
Matthias Fischer [Wed, 25 Mar 2020 11:33:49 +0000 (12:33 +0100)] 
bind: Update to 9.11.17

For details see:
https://downloads.isc.org/isc/bind9/9.11.17/RELEASE-NOTES-bind-9.11.17.html

"Notes for BIND 9.11.17

Feature Changes

The configure option --with-libxml2 now uses pkg-config to detect
libxml2 library availability. You will either have to install pkg-config
or specify the exact path where libxml2 has been installed on your
system. [GL #1635]

Bug Fixes

Fixed re-signing issues with inline zones which resulted in records
being re-signed late or not at all."

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoRevert "core143: add dhcp"
Arne Fitzenreiter [Sat, 28 Mar 2020 08:42:20 +0000 (09:42 +0100)] 
Revert "core143: add dhcp"

This reverts commit 804deb1b23f24daa35d0cf052d8d0eac82c3319f.

4 years agoRevert "dhcp: Update to 4.4.2"
Arne Fitzenreiter [Sat, 28 Mar 2020 08:40:21 +0000 (09:40 +0100)] 
Revert "dhcp: Update to 4.4.2"

dhcp 4.4.2 internally includes bind 9.11.14
this version not work on arm 32bit.

This reverts commit 417fd66045433d8101c11bea669e14a39af4db13.

4 years agocore143: update local openssh config
Arne Fitzenreiter [Thu, 26 Mar 2020 18:26:07 +0000 (18:26 +0000)] 
core143: update local openssh config

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add backup.pl
Arne Fitzenreiter [Thu, 26 Mar 2020 18:03:19 +0000 (18:03 +0000)] 
core143: add backup.pl

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agovnstat: remove wrong tag file
Arne Fitzenreiter [Thu, 26 Mar 2020 17:56:23 +0000 (17:56 +0000)] 
vnstat: remove wrong tag file

fixes #12305

I had created this tag file to ship the folder but vnstat doesn't like empty files.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agovnstat: Add restart command.
Markus Untersee [Thu, 30 Jan 2020 12:41:36 +0000 (13:41 +0100)] 
vnstat: Add restart command.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoovpnmain.cgi: Validate CCDNet name when renaming it.
Stefan Schantl [Tue, 28 Jan 2020 10:51:50 +0000 (11:51 +0100)] 
ovpnmain.cgi: Validate CCDNet name when renaming it.

Fixes #12282

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add firewall initskript
Arne Fitzenreiter [Thu, 26 Mar 2020 17:50:26 +0000 (17:50 +0000)] 
core143: add firewall initskript

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoavoid emitting VPN traffic to the internet if the IPS crashed
Peter Müller [Mon, 27 Jan 2020 15:04:00 +0000 (15:04 +0000)] 
avoid emitting VPN traffic to the internet if the IPS crashed

Due to strange NFQUEUE behaviour, traffic to remote VPN (IPsec or
OpenVPN) destinations was emitted to the internet (ppp0 or red0
interface) directly if the IPS was enabled but crashed during operation.

This patch places the IPSECBLOCK and OVPNBLOCK chains before the
ones responsible for forwarding traffic into the IPS.

Thanks to Michael for his debugging effort.

Partially fixes #12257

Cc: Michael Tremer <michael.tremer@ipfire.org>
Cc: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add libtool
Arne Fitzenreiter [Thu, 26 Mar 2020 17:48:18 +0000 (17:48 +0000)] 
core143: add libtool

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agolibtool: Update 2.4.6
Matthias Fischer [Sat, 25 Jan 2020 19:13:06 +0000 (20:13 +0100)] 
libtool: Update 2.4.6

For details see:
https://savannah.gnu.org/forum/forum.php?forum_id=8210

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add dhcp
Arne Fitzenreiter [Thu, 26 Mar 2020 17:46:05 +0000 (17:46 +0000)] 
core143: add dhcp

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agodhcp: Update to 4.4.2
Matthias Fischer [Sat, 25 Jan 2020 19:04:26 +0000 (20:04 +0100)] 
dhcp: Update to 4.4.2

For details see:
https://downloads.isc.org/isc/dhcp/4.4.2/dhcp-4.4.2-RELNOTES

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add logwatch
Arne Fitzenreiter [Thu, 26 Mar 2020 17:44:08 +0000 (17:44 +0000)] 
core143: add logwatch

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agologwatch: Update to 7.5.3
Matthias Fischer [Sat, 25 Jan 2020 18:57:24 +0000 (19:57 +0100)] 
logwatch: Update to 7.5.3

For details see:
https://sourceforge.net/p/logwatch/activity/?page=0&limit=100#5e27da933241d23c845e8cce

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add openssh
Arne Fitzenreiter [Thu, 26 Mar 2020 17:41:57 +0000 (17:41 +0000)] 
core143: add openssh

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agossh_config: Do not set defaults explicitly
Peter Müller [Mon, 20 Jan 2020 20:05:00 +0000 (20:05 +0000)] 
ssh_config: Do not set defaults explicitly

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agosshd_config: Do not set defaults explicitly
Peter Müller [Mon, 20 Jan 2020 20:04:00 +0000 (20:04 +0000)] 
sshd_config: Do not set defaults explicitly

In order to keep configurations as small as possible and to make them
easier to read/audit, this patch omits all default configuration in the
OpenSSH server configuration file.

Further, it mentions where to refer for the full documentation.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoOpenSSH: update to 8.2p1
Peter Müller [Sat, 21 Mar 2020 20:08:00 +0000 (20:08 +0000)] 
OpenSSH: update to 8.2p1

Please refer to https://www.openssh.com/txt/release-8.2 for release
announcements. Since glibc < 2.31 is used, no additional patching was
required in order to restore correct login functionality.

Cc: Marcel Lorenz <marcel.lorenz@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agosmartmontools: update rootfile
Arne Fitzenreiter [Thu, 26 Mar 2020 17:38:32 +0000 (17:38 +0000)] 
smartmontools: update rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add localnet initscript
Arne Fitzenreiter [Thu, 26 Mar 2020 10:09:14 +0000 (10:09 +0000)] 
core143: add localnet initscript

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoresolv.conf: Add "trust-ad" option
Michael Tremer [Wed, 5 Feb 2020 11:45:47 +0000 (11:45 +0000)] 
resolv.conf: Add "trust-ad" option

Since we are running unbound locally which always runs DNSSEC
validation, we can simply trust it and pass the ad flag on to
applications which make use of it.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: netother.cgi
Arne Fitzenreiter [Thu, 26 Mar 2020 10:04:15 +0000 (10:04 +0000)] 
core143: netother.cgi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agonetother.cgi: show content of routing table 220
Peter Müller [Sat, 21 Mar 2020 16:03:00 +0000 (16:03 +0000)] 
netother.cgi: show content of routing table 220

Since IPsec routing information do not show up in the normal routing
table, also displaying the contents of table 220 on netother.cgi might
be useful for debugging purposes.

The second version of this patch omits the output if routing table 220
is empty and introduces a custom translation for IPsec routing table
entries instead of just adding the table number to the generic translation.

Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add smartmontools
Arne Fitzenreiter [Thu, 26 Mar 2020 10:00:20 +0000 (10:00 +0000)] 
core143: add smartmontools

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agosmartmontools: update to 7.1
Peter Müller [Sat, 21 Mar 2020 19:59:00 +0000 (19:59 +0000)] 
smartmontools: update to 7.1

Summary: smartmontools release 7.1
-----------------------------------------------------------
- smartctl: Fixed bogus exception on unknown form factor value (regression).
- smartctl '--json=cg': Suppresses extra spaces also in 'g' format.
- smartctl '-i': ATA ACS-4 and ACS-5 enhancements.
- smartd: No longer truncates very long device names in warning emails.
- smartd: No longer skips scheduled tests if system clock has been adjusted
  to the past.
- smartd '-A': Attribute logs now use local time instead of UTC.
- ATA: Device type '-d jmb39x,N' for drives behind JMicron JMB39x RAID port
  multipliers.
- SCSI: Workaround for incomplete Log subpages response from some SAS SSDs.
- HDD, SSD and USB additions to drive database.
- Autodetection of '-d sntjmicron' type for JMicron USB to NVMe bridges.
- configure: Defines '_FORTIFY_SOURCE=2' if supported and not defined.
- Linux/FreeBSD: Fixed segfault on CCISS transfer sizes > 512 bytes.
- Linux: Fixed smartd.service 'Type' if libsystemd-dev is not available.
- Linux: Fixed '/dev/megaraid_sas_ioctl_node' fd leak.
- Linux: Fixed GPL licensing problem of 'linux_nvme_ioctl.h'.
- FreeBSD update-smart-drivedb: Now uses 'fetch' as default download tool.
- FreeBSD big endian: Fixed NVMe access.
- FreeBSD: Compile fix for FreeBSD 12.
- NetBSD: Fixed device scan crash on empty name list.
- NetBSD: Fixed memory leak in device scan.
- Windows: Fixed log page access via Windows 10 NVMe driver for NVMe 1.2.1+.
- Windows: Allow drive letters as device names for Windows 10 NVMe driver.
- Windows: Workround to allow CSMI access to devices behind AMD RAID drivers.
- Windows: Fixed MinGW options to add relocation info if ASLR is enabled.
- Windows wtssendmsg: No longer writes '\n' line endings to event log.
- Windows wtssendmsg: New options '-t' and '-w'.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add ovpnmain.cgi
Arne Fitzenreiter [Thu, 26 Mar 2020 09:45:17 +0000 (09:45 +0000)] 
core143: add ovpnmain.cgi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoOpenVPN: Stop N2N connection before remove.
Erik Kapfer [Tue, 24 Mar 2020 10:29:05 +0000 (11:29 +0100)] 
OpenVPN: Stop N2N connection before remove.

Fix #12334

Signed-off-by: Erik Kapfer <ummeegge@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocollectd: run sensors-detect in background
Arne Fitzenreiter [Wed, 25 Mar 2020 06:35:38 +0000 (07:35 +0100)] 
collectd: run sensors-detect in background

on some machines the i2c sensor search take very long time
which cause hang at first boot.

Now the search is started in background and waited for max one
minute before continue load of collectd.
On such machines collectd will not get all sensors at first startup.

fixes #12329

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoncurses: Update to 6.2
Matthias Fischer [Wed, 25 Mar 2020 11:38:02 +0000 (12:38 +0100)] 
ncurses: Update to 6.2

For details see:
https://invisible-island.net/ncurses/announce.html#h2-release-notes

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agonano: Update to 4.9
Matthias Fischer [Wed, 25 Mar 2020 11:51:07 +0000 (12:51 +0100)] 
nano: Update to 4.9

For details see:
https://www.nano-editor.org/news.php

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoconsort.sh: Shebang-Typo
Matthias Fischer [Wed, 25 Mar 2020 11:54:20 +0000 (12:54 +0100)] 
consort.sh: Shebang-Typo

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agopixman: fix build on arm
Arne Fitzenreiter [Thu, 26 Mar 2020 06:02:41 +0000 (06:02 +0000)] 
pixman: fix build on arm

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add xz
Arne Fitzenreiter [Tue, 24 Mar 2020 08:59:58 +0000 (08:59 +0000)] 
core143: add xz

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agomake.sh: bump toolchain version
Arne Fitzenreiter [Tue, 24 Mar 2020 08:59:11 +0000 (08:59 +0000)] 
make.sh: bump toolchain version

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore-updates: Ensure we have no temporary data in the package
Michael Tremer [Mon, 23 Mar 2020 19:34:59 +0000 (19:34 +0000)] 
core-updates: Ensure we have no temporary data in the package

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoConfig: Refactor mastering packages
Michael Tremer [Mon, 23 Mar 2020 19:34:58 +0000 (19:34 +0000)] 
Config: Refactor mastering packages

Those are now created in their own temporary directory, so that
no other files can be included by accident.

We also package with fewer temporary files.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agolfs: Drop quotes in DEPS variable
Michael Tremer [Mon, 23 Mar 2020 19:34:57 +0000 (19:34 +0000)] 
lfs: Drop quotes in DEPS variable

Not sure why this has ever been there. This simply makes it
nicer to read and edit because we can have line-breaks now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocdrom: Cleanup everything after mastering
Michael Tremer [Mon, 23 Mar 2020 19:34:56 +0000 (19:34 +0000)] 
cdrom: Cleanup everything after mastering

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoxz: update to 5.2.5
Marcel Lorenz [Thu, 19 Mar 2020 20:20:49 +0000 (21:20 +0100)] 
xz: update to 5.2.5

4 years agocore143: add coreutils
Arne Fitzenreiter [Mon, 23 Mar 2020 18:33:39 +0000 (18:33 +0000)] 
core143: add coreutils

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocoreutils: update rootfiles
Peter Müller [Mon, 3 Feb 2020 17:39:00 +0000 (17:39 +0000)] 
coreutils: update rootfiles

Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocoreutils: update to 8.31
Peter Müller [Mon, 3 Feb 2020 17:39:00 +0000 (17:39 +0000)] 
coreutils: update to 8.31

Refer to https://lists.gnu.org/archive/html/coreutils-announce/2019-03/msg00000.html
for release announcements.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add glibc
Arne Fitzenreiter [Sun, 22 Mar 2020 19:10:46 +0000 (19:10 +0000)] 
core143: add glibc

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agovdr: fix build with glibc 2.31
Arne Fitzenreiter [Sun, 22 Mar 2020 19:04:14 +0000 (19:04 +0000)] 
vdr: fix build with glibc 2.31

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoglibc: Update to 2.31
Michael Tremer [Wed, 5 Feb 2020 11:45:46 +0000 (11:45 +0000)] 
glibc: Update to 2.31

Fixes: #12288
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoqemu: Fix build against glibc >= 2.31
Michael Tremer [Wed, 5 Feb 2020 11:45:45 +0000 (11:45 +0000)] 
qemu: Fix build against glibc >= 2.31

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add hwdata
Arne Fitzenreiter [Sat, 21 Mar 2020 16:30:15 +0000 (16:30 +0000)] 
core143: add hwdata

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agohwdata: update PCI/USB databases
Peter Müller [Wed, 19 Feb 2020 19:58:00 +0000 (19:58 +0000)] 
hwdata: update PCI/USB databases

PCI IDs: 2020-02-16 03:15:02
USB IDs: 2020-01-09 20:34:06

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add strongswan
Arne Fitzenreiter [Sat, 21 Mar 2020 16:28:04 +0000 (16:28 +0000)] 
core143: add strongswan

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agostrongSwan: update to 5.8.2
Peter Müller [Wed, 19 Feb 2020 21:48:00 +0000 (21:48 +0000)] 
strongSwan: update to 5.8.2

Please refer to https://wiki.strongswan.org/versions/75 for release notes.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add rules.pl
Arne Fitzenreiter [Sat, 21 Mar 2020 16:26:38 +0000 (16:26 +0000)] 
core143: add rules.pl

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agorules.pl: Fix SNAT over VPN.
Stefan Schantl [Thu, 20 Feb 2020 16:24:23 +0000 (17:24 +0100)] 
rules.pl: Fix SNAT over VPN.

This commit adds flags which will are applied if SNAT should be used on
the red address or any configured alias.

They prevent doing the SNAT when tranismitting packet through a VPN over the red interface.

Fixes #12162.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Tested-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add swap changes
Arne Fitzenreiter [Sat, 21 Mar 2020 16:23:36 +0000 (16:23 +0000)] 
core143: add swap changes

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoswap: Start swap after mounting filesystems
Michael Tremer [Thu, 20 Feb 2020 19:04:30 +0000 (19:04 +0000)] 
swap: Start swap after mounting filesystems

When using a swap file, it is not being activated correctly
when the filesystem it is residing on is not mounted, yet.

The root file system is mounted read-only here before
S40mountfs is being executed.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add unbound
Arne Fitzenreiter [Sat, 21 Mar 2020 16:17:11 +0000 (16:17 +0000)] 
core143: add unbound

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agounbound: Update to 1.10.0
Matthias Fischer [Sat, 22 Feb 2020 10:04:17 +0000 (11:04 +0100)] 
unbound: Update to 1.10.0

For details see:
https://lists.nlnetlabs.nl/pipermail/unbound-users/2020-February/006711.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add apr and pcre
Arne Fitzenreiter [Sat, 21 Mar 2020 16:15:00 +0000 (16:15 +0000)] 
core143: add apr and pcre

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoUpdate Apache Dependencies
Wolfgang Apolinarski [Mon, 2 Mar 2020 19:06:53 +0000 (20:06 +0100)] 
Update Apache Dependencies

Update apache dependencies:
APR: update to version 1.7.0
PCRE: update to version 8.44
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add dhcp.cgi and fireinfo.cgi
Arne Fitzenreiter [Sat, 21 Mar 2020 16:12:54 +0000 (16:12 +0000)] 
core143: add dhcp.cgi and fireinfo.cgi

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agofireinfo.cgi: improve readability of command outputs
Peter Müller [Sat, 7 Mar 2020 18:58:00 +0000 (18:58 +0000)] 
fireinfo.cgi: improve readability of command outputs

Especially when it comes to the output of "uname -a", <code> tags
greatly improve readability.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agodhcp.cgi: avoid unnecessary line break
Peter Müller [Sat, 7 Mar 2020 19:01:00 +0000 (19:01 +0000)] 
dhcp.cgi: avoid unnecessary line break

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add ntp
Arne Fitzenreiter [Sat, 21 Mar 2020 16:06:21 +0000 (16:06 +0000)] 
core143: add ntp

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agontp: Update to 4.2.8p14
Matthias Fischer [Mon, 9 Mar 2020 18:45:36 +0000 (19:45 +0100)] 
ntp: Update to 4.2.8p14

For details see:
http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add libssh
Arne Fitzenreiter [Sat, 21 Mar 2020 16:04:58 +0000 (16:04 +0000)] 
core143: add libssh

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agotshark: Update to version 3.2.2 .
Erik Kapfer [Tue, 10 Mar 2020 08:21:08 +0000 (09:21 +0100)] 
tshark: Update to version 3.2.2 .

Update to 3.2.x includes, several bugfixes, updated protocols, new and updated features.
For the complete changelog, take a look into here --> https://www.wireshark.org/docs/relnotes/ .

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agolibssh: Update to version 0.9.3 .
Erik Kapfer [Tue, 10 Mar 2020 08:21:07 +0000 (09:21 +0100)] 
libssh: Update to version 0.9.3 .

Fixes CVE-2019-14889 and several issues after an security audit.
The complete changelog can be found in here --> https://www.libssh.org/category/release/ .
This version is also needed for tshark-3.2.2 to prevent
'error while loading shared libraries: libssh.so.4' for sshdump and ciscodump.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agomake.sh: Umount /tmp when it is a ramdisk
Michael Tremer [Tue, 10 Mar 2020 13:28:53 +0000 (13:28 +0000)] 
make.sh: Umount /tmp when it is a ramdisk

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agomake.sh: Move ccache's temp directory into /tmp
Michael Tremer [Tue, 10 Mar 2020 13:26:06 +0000 (13:26 +0000)] 
make.sh: Move ccache's temp directory into /tmp

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocdrom+flash-image: Move all temporary files to /tmp
Michael Tremer [Tue, 10 Mar 2020 13:26:05 +0000 (13:26 +0000)] 
cdrom+flash-image: Move all temporary files to /tmp

Since /tmp is now a ramdisk, we move all temporary files into it.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocdrom: Do not write the temporary tarball to disk
Michael Tremer [Tue, 10 Mar 2020 13:26:04 +0000 (13:26 +0000)] 
cdrom: Do not write the temporary tarball to disk

In order to remove any duplicate files in the tarball, we
have to unpack it again. The whole filesystem is written
to disk twice which is unnecessary.

This patch removes that temporary step and reduces IO
during the build.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agomake.sh: Make /tmp a ramdisk if ramdisks are enabled
Michael Tremer [Tue, 10 Mar 2020 13:26:03 +0000 (13:26 +0000)] 
make.sh: Make /tmp a ramdisk if ramdisks are enabled

The build system is writing a large amount of temporary file
systems that might land on disk or at least in the journal.

This change will speed up the build and remove a lot of I/O
usage.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agonginx: Update to version 1.17.8 .
Erik Kapfer [Tue, 10 Mar 2020 15:28:56 +0000 (16:28 +0100)] 
nginx: Update to version 1.17.8 .

New mainlain version which includes hugh amount of changes.
For a complete overview, please take alook in here -->
http://nginx.org/en/CHANGES .

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoxinetd: Delete symlinks with uninstallation .
Erik Kapfer [Tue, 10 Mar 2020 15:36:38 +0000 (16:36 +0100)] 
xinetd: Delete symlinks with uninstallation .

Fixes #12303

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agode.pl: update German translations
Peter Müller [Sun, 15 Mar 2020 13:38:00 +0000 (13:38 +0000)] 
de.pl: update German translations

This patch adds German translations for the new DNS CGI, some parts of
the hardware vulnerability mitigation CGI, improves some existing
translations and corrects some Deppenleerzeichen and Bildzeitungsbindestriche.

The third version of this patch is correctly based against upstream 'next',
honours Michaels opinion and contains updated language_issues.de and
language_missings files.

Since "./make lang" complains about missing translations marked as unused
in first place, no changes have been made to them in order to avoid
collateral damage.

Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Acked-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agokeepalived: Update to version 2.0.20 .
Erik Kapfer [Mon, 16 Mar 2020 12:42:59 +0000 (13:42 +0100)] 
keepalived: Update to version 2.0.20 .

Since this update is a mayor version update, it brings a lot of changes.
The changelog can be found in here --> http://www.keepalived.com/changelog.html .
Added /etc/sysconfig/keepalived in ROOTFILE and in backup/includes.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore143: add openssl
Arne Fitzenreiter [Sat, 21 Mar 2020 15:58:31 +0000 (15:58 +0000)] 
core143: add openssl

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoopenssl: Update to 1.1.1e
Michael Tremer [Wed, 18 Mar 2020 14:04:27 +0000 (14:04 +0000)] 
openssl: Update to 1.1.1e

Fixed an overflow bug in the x64_64 Montgomery squaring procedure used
in exponentiation with 512-bit moduli (CVE-2019-1551).

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoPostfix: update to 3.5.0
Peter Müller [Wed, 18 Mar 2020 21:16:00 +0000 (21:16 +0000)] 
Postfix: update to 3.5.0

Please refer to http://www.postfix.org/announcements/postfix-3.5.0.html
for release announcements.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agoTor: update to 0.4.2.7
Peter Müller [Thu, 19 Mar 2020 09:11:00 +0000 (09:11 +0000)] 
Tor: update to 0.4.2.7

Please refer to https://blog.torproject.org/new-releases-03510-0419-0427
for release announcement.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
4 years agocore142: add gcc, binutils and cairo to update
Arne Fitzenreiter [Sat, 21 Mar 2020 15:51:03 +0000 (15:51 +0000)] 
core142: add gcc, binutils and cairo to update

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>