]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/log
people/pmueller/ipfire-2.x.git
2 years agoknot: Update to 3.0.6
Matthias Fischer [Tue, 25 May 2021 15:37:16 +0000 (17:37 +0200)] 
knot: Update to 3.0.6

For details see:
https://www.knot-dns.cz/2021-05-12-version-306.html

"Features:

        mod-probe: new module for simple traffic logging (Python API not yet included)

Improvements:

        keymgr: new mode for listing zones with at least one key stored
        keymgr: the pregenerate command accepts optional timestamp-from parameter
        kzonecheck: accept '-' as substitution for standard input #727
        knotd: print an error when unable to change owner of a logging file
        knotd: new warning log if no interface is configured
        knotd: new signing policy check for NSEC3 iterations higher than 20
        knotd: don't allow backup to/restore from the DB storage directory
        Various code (mostly zone backup/restore), tests, and documentation improvements

Bugfixes:

        knotd: secondary fails to load zone file if HTTPS or SVCB record is present #725
        knotd: (KSK roll-over) new KSK is not signing DNSKEY long enough before DS submission
        knotd: (KSK roll-over) old KSK uselessly published after roll-over finished
        knotd: malformed address in TCP-related logs when listening on a UNIX socket
        knotd: server responds FORMERR instead of BADTIME if TSIG signed time is zero #730
        modules: incorrect local and remote addresses in the XDP mode
        modules: failed to read configuration from a section without identifiers
        mod-synthrecord: queries on synthesized empty-non-terminals not answered with NODATA
        keymgr: confusing error if del-all-old command fails"

For 3.0.5 (skipped):
https://www.knot-dns.cz/2021-03-25-version-305.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship pakfire
Michael Tremer [Tue, 25 May 2021 09:52:59 +0000 (09:52 +0000)] 
core158: Ship pakfire

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopakfire.cgi: Check for locked pakfire before trying to perform operations.
Stefan Schantl [Mon, 24 May 2021 17:38:21 +0000 (19:38 +0200)] 
pakfire.cgi: Check for locked pakfire before trying to perform operations.

Fixes #12621.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopakfire: Prevent from get launched multiple times.
Stefan Schantl [Mon, 24 May 2021 17:38:20 +0000 (19:38 +0200)] 
pakfire: Prevent from get launched multiple times.

When pakfire gets launched a check if a so called lockfile exists and
the process will be aborted, otherwise the file will be created which
prevents any other pakfire instance to perform any operations until the
first process gets finished and the lock will be released again.

Because the release of the lock is located in an END block, the lock
also will be released in case the pakfire process gets interuped or
gains an error.

This prevents from an lock loop and an unuseable pakfire.

Reference: #12621.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship libusb
Michael Tremer [Tue, 25 May 2021 09:51:33 +0000 (09:51 +0000)] 
core158: Ship libusb

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agolibusb: update to 1.0.24
Peter Müller [Sun, 23 May 2021 15:43:38 +0000 (17:43 +0200)] 
libusb: update to 1.0.24

Full changelog as per CHANGELOG file:

2020-12-09: v1.0.24
* Add new platform abstraction (#252)
* Add Null POSIX backend
* Add support for eventfd
* Add support for thread IDs on Haiku, NetBSD and Solaris
* New API libusb_hotplug_get_user_data()
* Darwin (macOS): Fix race condition that results in segmentation fault (#701)
* Darwin (macOS): Fix stale descriptor information post reset (#733)
* Darwin (macOS): use IOUSBDevice as darwin_device_class explicitly (#693)
* Linux: Drop support for kernel older than 2.6.32
* Linux: Provide an event thread name (#689)
* Linux: Wait until all USBs have been reaped before freeing them (#607)
* NetBSD: Recognize device timeouts (#710)
* OpenBSD: Allow opening ugen devices multiple times (#763)
* OpenBSD: Support libusb_get_port_number() (#764)
* SunOS: Fix a memory leak (#756)
* SunOS: Various fixes (#627, #628, #629)
* Windows: Add Visual Studio 2019 support
* Windows: Drop support for WinCE and Visual Studio older than 2013
* Windows: Drop support for Windows XP
* Windows: Support building all examples using Visual Studio (#151)
* Documentation fixes and improvements
* Various other bug fixes and improvements

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship iputils
Michael Tremer [Tue, 25 May 2021 09:50:05 +0000 (09:50 +0000)] 
core158: Ship iputils

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoiputils: update to 20210202
Peter Müller [Sun, 23 May 2021 15:40:46 +0000 (17:40 +0200)] 
iputils: update to 20210202

The changelog between version "s20160803" is too large to include it
here, please refer to https://github.com/iputils/iputils/releases for a
human-readable version.

Due to build system changes, single binaries cannot be compiled by
running "make [program]" anymore, updated rootfiles to reflect that
change.

20210202's version of /usr/bin/ping is bug-compatible to s20160803's
one, hence does not cause trouble in ~/src/ppp/ip-up. Tested, works.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoMerge branch 'master' into next
Michael Tremer [Tue, 25 May 2021 09:46:50 +0000 (09:46 +0000)] 
Merge branch 'master' into next

2 years agocore158: Ship bind
Michael Tremer [Tue, 25 May 2021 09:46:41 +0000 (09:46 +0000)] 
core158: Ship bind

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agobind: Update to 9.11.32
Matthias Fischer [Sat, 22 May 2021 13:29:30 +0000 (15:29 +0200)] 
bind: Update to 9.11.32

For details see:
https://downloads.isc.org/isc/bind9/9.11.31/RELEASE-NOTES-bind-9.11.32.html

"Notes for BIND 9.11.32
Feature Changes

    DNSSEC responses containing NSEC3 records with iteration counts
    greater than 150 are now treated as insecure. [GL #2445]

    The maximum supported number of NSEC3 iterations that can be
    configured for a zone has been reduced to 150. [GL #2642]

    The implementation of the ZONEMD RR type has been updated to match
    RFC 8976. [GL #2658]

Notes for BIND 9.11.31
Security Fixes

    A malformed incoming IXFR transfer could trigger an assertion
    failure in named, causing it to quit abnormally. (CVE-2021-25214)

    ISC would like to thank Greg Kuechle of SaskTel for bringing this
    vulnerability to our attention. [GL #2467]

    named crashed when a DNAME record placed in the ANSWER section
    during DNAME chasing turned out to be the final answer to a client
    query. (CVE-2021-25215)

    ISC would like to thank Siva Kakarla for bringing this vulnerability
    to our attention. [GL #2540]

    When a server's configuration set the tkey-gssapi-keytab
    or tkey-gssapi-credential option, a specially crafted GSS-TSIG query
    could cause a buffer overflow in the ISC implementation of SPNEGO
    (a protocol enabling negotiation of the security mechanism used for
    GSSAPI authentication). This flaw could be exploited to crash named
    binaries compiled for 64-bit platforms, and could enable remote code
    execution when named was compiled for 32-bit platforms.
    (CVE-2021-25216)

    This vulnerability was reported to us as ZDI-CAN-13347 by Trend
    Micro Zero Day Initiative. [GL #2604]

Feature Changes

    The ISC implementation of SPNEGO was removed from BIND 9 source
    code. Instead, BIND 9 now always uses the SPNEGO implementation
    provided by the system GSSAPI library when it is built with GSSAPI
    support. All major contemporary Kerberos/GSSAPI libraries contain
    an implementation of the SPNEGO mechanism. [GL #2607]

Notes for BIND 9.11.30

The BIND 9.11.30 release was withdrawn after a backporting bug was
discovered during pre-release testing. ISC would like to acknowledge the
assistance of Natan Segal of Bluecat Networks.2"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship vnstat
Michael Tremer [Tue, 25 May 2021 09:46:10 +0000 (09:46 +0000)] 
core158: Ship vnstat

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agovnstat 2.7: Adjusted 'traffic.cgi' to display 5-minute graphs
Matthias Fischer [Sat, 22 May 2021 13:25:56 +0000 (15:25 +0200)] 
vnstat 2.7: Adjusted 'traffic.cgi' to display 5-minute graphs

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agovnstat: Update to 2.7
Matthias Fischer [Sat, 22 May 2021 13:25:11 +0000 (15:25 +0200)] 
vnstat: Update to 2.7

For details see:

https://humdi[dot]net/vnstat/CHANGES

"2.7 / 16-May-2021

 - Fixed
   - Possibility of segmentation fault with image list output when database
     existed but no data was available
   - ./configure output could show invalid install paths with some parameter
     combinations (pull request by Severin Glöckner)
   - Columns in text hours graph output could get misaligned if the selected
     system locale used a UTF-8 sequence for the thousands separator instead
     of a single character
 - New
   - Add -5g / --fivegraph options to image output with sizing related
     parameters for the output of a 5 minute resolution bar graph
   - Add configuration option SummaryGraph and optional parameter for
     --hsummary and --vsummary for selecting which graph is shown next to
     the summary data in the horizontal and vertical summary image outputs
   - Add --large / --small options and configuration option LargeFonts for
     controlling the image output font size
   - Add --scale and configuration option ImageScale for scaling the image
     output to a given percent
   - Add configuration option LineSpacingAdjustment for adjusting the line
     spacing of list format image outputs
   - Add bar visualizations for traffic estimations in image output
   - Allow writing image output to a filename starting with -
   - Add --initdb to daemon for creating a new empty database without having
     the daemon process staying running, doesn't discard data if a database
     already exists
   - Add configuration option BarColumnShowsRate for having the bar column in
     image list outputs be scaled according to the average rate column values
     when those values are visible, disabled by default
   - Add --dbiflist for getting a list of interfaces in the database, both
     --iflist and --dbiflist also get alternative more parseable outputs
   - Add configuration option for large font output and make 5 minute
     resolution graph visible in vnstat.cgi"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship backup.pl script
Michael Tremer [Tue, 25 May 2021 09:44:20 +0000 (09:44 +0000)] 
core158: Ship backup.pl script

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agobackup.pl: Fix #12626 backup/include.user entries will not override backup/exclude
Adolf Belka [Fri, 21 May 2021 12:22:50 +0000 (14:22 +0200)] 
backup.pl: Fix #12626 backup/include.user entries will not override backup/exclude

- Current situation is that any restrictions in the exclude file will not
   be overwritten by the include.user file
- For example the global exclude file has *.tmp preventing any tmp files
   being backed up from the globally included IPFire files
   If a user has some specific tmp files they want to backup and include
   them in the include.user file they will not override the global
   exclude file.
- This fix does the backup of the global and user backups as two separate
   events and then appends them. This means that any tmp files in the
   include.user file will be backed up.
- The backups are created as a global tar file and then have the user
   tar file appended and then the combined file gzipped and given the .ipf
   suffix. This has to be done this was as gzipped files can not be
   appended to each other whereas tar files can.

Fixes: 12626
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoIcinga: Do not ship event handlers for Nagios
Peter Müller [Fri, 21 May 2021 13:42:36 +0000 (15:42 +0200)] 
Icinga: Do not ship event handlers for Nagios

These are owned (hence being writable) by "nobody", posing a potential
security risk. Since the files itself were already exluded from being
shipped, their parent directory should be as well.

This patch should reduce the amount of executable files being owned by
nobody to zero after upgrading to Core Update 157. Due to complexity
reasons, not all applications available in Pakfire could be tested,
though, so your mileage may vary.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonagios-plugins: Set SUID bit for plugins which need it to function properly
Peter Müller [Fri, 21 May 2021 13:42:14 +0000 (15:42 +0200)] 
nagios-plugins: Set SUID bit for plugins which need it to function properly

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Delete shared object files leftover from pppd 2.4.8
Peter Müller [Fri, 21 May 2021 13:41:50 +0000 (15:41 +0200)] 
Core Update 157: Delete shared object files leftover from pppd 2.4.8

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopppd: Explicitly ship pppd shared object files
Peter Müller [Fri, 21 May 2021 13:41:29 +0000 (15:41 +0200)] 
pppd: Explicitly ship pppd shared object files

These are needed by pppd, but were not previously shipped as such.
Instead, since their parent directory at /usr/lib/pppd/${version}/ was
not commented out, we implicitly shipped the entire directory.

This patch does not change our behaviour in the end, but makes things
more transparent to developers.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Ship backup package to apply changed permissions
Peter Müller [Fri, 21 May 2021 13:41:05 +0000 (15:41 +0200)] 
Core Update 157: Ship backup package to apply changed permissions

This is required as "backup" itself does not gets updated automatically,
contrary to it's LFS file suggesting by having a "PAK_VER" number.

In order to fix #12619, it is therefore necessary to ship the backup
files with Core Update 157.

Partially fixes: #12619

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Apply changed SSH configurations
Peter Müller [Fri, 21 May 2021 13:40:38 +0000 (15:40 +0200)] 
Core Update 157: Apply changed SSH configurations

This is necessary to fix SSH not starting after upgrading to Core Update
157 unless it's settings are manually written via the WebUI.

Reported-by: Erik Kapfer <ummeegge@ipfire.org>
Reported-by: Tom Rymes <tom@rymes.net>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship ca-certificates
Michael Tremer [Fri, 21 May 2021 08:53:16 +0000 (08:53 +0000)] 
core158: Ship ca-certificates

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoupdate ca-certificates CA bundle
Peter Müller [Thu, 20 May 2021 22:06:14 +0000 (00:06 +0200)] 
update ca-certificates CA bundle

Update the CA certificates list to what Mozilla NSS ships currently.

The original file can be retrieved from:
https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoClean up various files left from dropped add-ons and packages
Peter Müller [Thu, 20 May 2021 21:25:05 +0000 (23:25 +0200)] 
Clean up various files left from dropped add-ons and packages

Since I only ran "find . -type f -name ...", I missed mostly directories
containing configuration and initscripts of recently dropped add-ons and
packages.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython-pyparsing: Update to 2.4.7 and migrate to python3
Adolf Belka [Sun, 16 May 2021 11:46:20 +0000 (13:46 +0200)] 
python-pyparsing: Update to 2.4.7 and migrate to python3

- Update from 2.2.0 to 2.4.7
- Migrate from python2 to python3
- Move the rootfile from common to packages as pyparsing is an addon

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoelinks: Bump package version
Michael Tremer [Thu, 20 May 2021 10:02:43 +0000 (10:02 +0000)] 
elinks: Bump package version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoconfig/elinks/elinks.conf does not have to be executable
Peter Müller [Tue, 18 May 2021 19:50:47 +0000 (21:50 +0200)] 
config/elinks/elinks.conf does not have to be executable

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython3-setuptools: Create a python3 version of python-setuptools
Adolf Belka [Sun, 16 May 2021 17:25:49 +0000 (19:25 +0200)] 
python3-setuptools: Create a python3 version of python-setuptools

- python3-setuptools works with python3-daemon but not with
   python-m2crypto. m2crypto has to stay with python2 because crda
   will not find the python3 version of m2crypto.
- python-m2crypto only works with python-setuptools so both the
   python2 and python3 versions of setuptools need to stay in place.
- Therefore this patch only creates python3-setuptools, it does not
   remove python-setuptools

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship ethtool
Michael Tremer [Thu, 20 May 2021 09:47:57 +0000 (09:47 +0000)] 
core158: Ship ethtool

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoethtool: Update to 5.12
Adolf Belka [Mon, 17 May 2021 15:10:38 +0000 (17:10 +0200)] 
ethtool: Update to 5.12

- Update from 3.16 (2014) to 5.12 (2021)
- Update of rootfile
- Changelog is too large to include here. Changelog details are available
   at https://git.kernel.org/pub/scm/network/ethtool/ethtool.git/log/

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship qpdf
Michael Tremer [Thu, 20 May 2021 09:47:26 +0000 (09:47 +0000)] 
core158: Ship qpdf

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoqpdf: Update to 10.3.2
Adolf Belka [Mon, 17 May 2021 12:31:22 +0000 (14:31 +0200)] 
qpdf: Update to 10.3.2

- Update from 10.3.0 to 10.3.2
- Update rootfiles
- Changelog
   * 10.3.2: release
     * Fix problem that caused the generated manual from being included
       in the Windows distributions. Fixes #521.
     * Fix 11-year-old bug of leaving unreferenced objects in preserved
       object streams. Fixes #520.
     * Portability fix: use tm_gmtoff rather than global timezone
       variable if available to get timezone offset. This fixes
       compilation on BSD and also results in a daylight saving
       time-aware offset for Linux or other GNU systems. Fixes #515.
     * When adding a page, if the page already exists, make a shallow
       copy of the page instead of throwing an exception. This makes the
       behavior of adding a page from the library consistent with what
       the CLI does and also with what the library does if it starts with
       a file that already has a duplicated page. Note that this means
       that, in some cases, the page you pass to addPage or addPageAt
       (either in QPDF or QPDFPageDocumentHelper) will not be the same
       object that actually gets added. (This has actually always been
       the case.) That means that, if you are going to do subsequent
       modification on the page, you should retrieve it again.
   * 10.3.1: release
     * Bug fix: allow /DR to be direct in /AcroForm

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship perl-CGI
Michael Tremer [Thu, 20 May 2021 09:47:00 +0000 (09:47 +0000)] 
core158: Ship perl-CGI

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoperl-CGI: Update to 4.52
Adolf Belka [Mon, 17 May 2021 12:31:06 +0000 (14:31 +0200)] 
perl-CGI: Update to 4.52

- Update from 4.44 to 4.52
- Update of rootfile not needed
- Changelog
   4.52 2021-05-04
     [ FIX ]
     - sort hash keys for deterministic behaviour (GH #245, GH #246)
   4.51 2020-10-01
     [ DOCUMENTATION ]
     - Document support for SameSite=None cookies in CGI::Cookie (GH #244)
   4.50 2020-06-22
     [ ENHANCEMENT ]
     - Add APPEND_QUERY_STRING option (GH #243, thanks to stevenh)
   4.49 2020-06-08
     [ FIX ]
     - remove deprecation warning as no longer in core (GH #221)
   4.48 2020-06-02
     [ FIX ]
     - fix CGI::Cookie->bake() doesn't work with mod_perl redirects (GH #240)
     - thanks to sherrardb for the PR (GH #241)
   4.47 2020-05-01
     [ FIX / TESTING ]
     - fix typo in variable name (GH #239)
   4.46 2020-02-03
     [ DOCUMENTATION ]
     - Document support for SameSite=None cookies (GH #238)
   4.45 2019-06-03
     [ ENHANCEMENT ]
     - Add support for SameSite=None cookies (GH #237, thanks to Dur09)

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship glib
Michael Tremer [Thu, 20 May 2021 09:46:36 +0000 (09:46 +0000)] 
core158: Ship glib

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoglib: Update to 2.68.2
Adolf Belka [Mon, 17 May 2021 12:30:48 +0000 (14:30 +0200)] 
glib: Update to 2.68.2

- Update from 2.68.1 to 2.68.2
- Update rootfiles
- Changelog
   Overview of changes in GLib 2.68.2
    * Fix building third-party projects against GLib on CentOS 7 (work by
      Ignacio Casal Quinteiro) (#2387)
    * Bugs fixed:
      - #2387 json-glib does not build with glib 2.68.1
      - !2060 gmacros: check that __cplusplus or _MSC_VER is defined
      - !2068 gmacros: missing check if __STDC_VERSION__ is defined
      - !2079 Backport !2078 “gthreadedresolver: don't ignore flags in lookup_by_name_with_flags” to glib-2-68
    * Translation updates:
      - Nepali
      - Serbian

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoflac: Update to 1.3.3
Adolf Belka [Mon, 17 May 2021 12:30:12 +0000 (14:30 +0200)] 
flac: Update to 1.3.3

- Update from 1.3.2 to 1.3.3
- Update rootfiles
- Changelog
    General:
        Fix CPU detection (Janne Hyvärinen).
        Switch from unsigned types to uint32_t (erikd).
        CppCheck fixes (erikd).
        Improve SIMD decoding of 24 bit files (lvqcl).
        POWER* amnd POWER9 improvements (Anton Blanchard).
        More tests.
    FLAC format:
        (none)
    Ogg FLAC format:
        (none)
    flac:
        When converting to WAV, use WAVEFORMATEXTENSIBLE when bits per
         second is not 8 or 16 (erikd).
        Fix --output-prefix with input-files in sub-directories (orbea).
    metaflac:
        (none)
    plugins:
        (none)
    build system:
        Cmake support (Vitaliy Kirsanov, evpobr).
        Visual Studio updates (Janne Hyvärinen).
        Fix for MSVC when UNICODE is enabled (lvqcl).
        Fix for OpenBSD/i386 (Christian Weisgerber).
    documentation:
        (none)
    libraries:
        (none).
    Interface changes:
        libFLAC:
            (none)
        libFLAC++:
            (none)

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship dhcp.cgi
Michael Tremer [Thu, 20 May 2021 09:45:43 +0000 (09:45 +0000)] 
core158: Ship dhcp.cgi

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agodhcp.cgi: Bug 10400 - Add Additional DHCP Options - change default
Adolf Belka [Wed, 19 May 2021 14:52:13 +0000 (16:52 +0200)] 
dhcp.cgi: Bug 10400 - Add Additional DHCP Options - change default

- Make the default that Additional DHCP options Enabled checkbox is
   checked when entering a new option.
- For existing options the Enabled checkbox status is honoured.

Fixes: #10400
Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDelete UPnP initscript for ARM64 as well
Peter Müller [Tue, 18 May 2021 21:34:49 +0000 (23:34 +0200)] 
Delete UPnP initscript for ARM64 as well

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agompd: build without UPnP support
Peter Müller [Tue, 18 May 2021 21:34:32 +0000 (23:34 +0200)] 
mpd: build without UPnP support

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship updated firewall initscript
Michael Tremer [Thu, 20 May 2021 09:44:56 +0000 (09:44 +0000)] 
core158: Ship updated firewall initscript

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Drop upnpd initscript
Michael Tremer [Thu, 20 May 2021 09:43:30 +0000 (09:43 +0000)] 
core158: Drop upnpd initscript

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDelete the remainings of libupnp and upnpd
Peter Müller [Tue, 18 May 2021 21:34:14 +0000 (23:34 +0200)] 
Delete the remainings of libupnp and upnpd

These include rootfiles, firewall menue entries that have been
unmaintained for a long time, and firewall chains which were never used
in recent time.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Uninstall libupnp
Michael Tremer [Thu, 20 May 2021 09:41:39 +0000 (09:41 +0000)] 
core158: Uninstall libupnp

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop libupnp
Peter Müller [Tue, 18 May 2021 21:33:43 +0000 (23:33 +0200)] 
Drop libupnp

This library has received no attention within the last three years. By
design, UPnP is a security risk on any firewall, and and outdated
version of a UPnP library definitely is.

This patch therefore drops libupnp completely.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agointltool: Move into the core system and don't ship any more
Michael Tremer [Thu, 20 May 2021 09:39:12 +0000 (09:39 +0000)] 
intltool: Move into the core system and don't ship any more

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop miniupnpd stuff from rootfiles and all systems
Michael Tremer [Thu, 20 May 2021 09:38:02 +0000 (09:38 +0000)] 
Drop miniupnpd stuff from rootfiles and all systems

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agominiupnpd: Delete files that would have become orphaned after deletion of miniupnpd...
Peter Müller [Tue, 18 May 2021 19:58:27 +0000 (21:58 +0200)] 
miniupnpd: Delete files that would have become orphaned after deletion of miniupnpd add-on as well

This patch requires
https://patchwork.ipfire.org/project/ipfire/list/?series=2059 to be
applied in the first place.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agomake.sh: Do no longer build fbset and sendEmail
Peter Müller [Mon, 17 May 2021 21:59:12 +0000 (23:59 +0200)] 
make.sh: Do no longer build fbset and sendEmail

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop sendEmail add-on
Peter Müller [Mon, 17 May 2021 21:58:54 +0000 (23:58 +0200)] 
Drop sendEmail add-on

As discussed in https://wiki.ipfire.org/devel/telco/2021-05-03.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop fbset
Peter Müller [Mon, 17 May 2021 21:58:35 +0000 (23:58 +0200)] 
Drop fbset

As discussed in https://wiki.ipfire.org/devel/telco/2021-05-03.

Please note this patch does not remove fbset on existing installations,
that has to be done via the corresponding upgrade script.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop miniupnpd add-on
Peter Müller [Mon, 17 May 2021 21:58:18 +0000 (23:58 +0200)] 
Drop miniupnpd add-on

As discussed in https://wiki.ipfire.org/devel/telco/2021-05-03.

Frankly, if you need or use UPnP, you probably do not even need to _think_
about running a firewall...

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop SANE add-on
Peter Müller [Mon, 17 May 2021 21:57:37 +0000 (23:57 +0200)] 
Drop SANE add-on

As discussed in https://wiki.ipfire.org/devel/telco/2021-05-03.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoZut alors, delete motion initiscript as well :-/
Peter Müller [Mon, 17 May 2021 21:57:18 +0000 (23:57 +0200)] 
Zut alors, delete motion initiscript as well :-/

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop orphaned dependency "libsrtp"
Peter Müller [Mon, 17 May 2021 21:56:50 +0000 (23:56 +0200)] 
Drop orphaned dependency "libsrtp"

This was solely needed by Asterisk and is no longer used anymore.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop Asterisk add-on
Peter Müller [Mon, 17 May 2021 21:56:30 +0000 (23:56 +0200)] 
Drop Asterisk add-on

As discussed in https://wiki.ipfire.org/devel/telco/2021-05-03.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop orphaned dependency add-on libmicrohttpd
Peter Müller [Mon, 17 May 2021 21:56:09 +0000 (23:56 +0200)] 
Drop orphaned dependency add-on libmicrohttpd

This was solely needed by "motion". It can be safely removed now.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDrop motion add-on
Peter Müller [Mon, 17 May 2021 21:55:46 +0000 (23:55 +0200)] 
Drop motion add-on

As discussed in https://wiki.ipfire.org/devel/telco/2021-05-03.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agosarg: Update to 2.4.0
Adolf Belka [Tue, 18 May 2021 16:58:31 +0000 (18:58 +0200)] 
sarg: Update to 2.4.0

- Update from 2.3.11 to 2.4.0
- Update of rootfile not required
- Update of patches as the source code is different enough that the
   patches failed to work.
- Changelog has information on changes for version 2.4.0. Prior version
   information is for 2.3.3 from 2012. All intervening versions have no
   changelog information available.
   Version 2.4.0
    - Update translations.
    - Useragent report is produced if information is available.
    - Don't abort if DNS resolution is failing to resolve a host IP address.
    - xz compressed log files are supported.
    - Compressed redirector logs are now supported.
    - Filter converted and split logs using -t command line option.
    - Add many new buffer overflow checks.
    - Use random temporary directory name by default.
    - Many bug fixed.
    - Many new features added.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agocore158: Ship IPsec changes for iOS
Michael Tremer [Thu, 20 May 2021 09:28:21 +0000 (09:28 +0000)] 
core158: Ship IPsec changes for iOS

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoRevert "IPsec: Ensure that iOS VPNs are always connected"
Michael Tremer [Thu, 20 May 2021 09:26:13 +0000 (09:26 +0000)] 
Revert "IPsec: Ensure that iOS VPNs are always connected"

This reverts commit 8ce6222a1002a669cb511ba75b9e4e57810a4432.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoMerge remote-tracking branch 'ms/ipsec-ios' into next
Michael Tremer [Thu, 20 May 2021 09:25:05 +0000 (09:25 +0000)] 
Merge remote-tracking branch 'ms/ipsec-ios' into next

2 years agofireinfo: Update to 2.2.0
Michael Tremer [Tue, 18 May 2021 13:52:11 +0000 (13:52 +0000)] 
fireinfo: Update to 2.2.0

This release ports fireinfo to Python 3

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoStart Core Update 158
Michael Tremer [Tue, 18 May 2021 13:34:15 +0000 (13:34 +0000)] 
Start Core Update 158

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoFix merge error in samba rootfiles
Michael Tremer [Tue, 18 May 2021 12:51:59 +0000 (12:51 +0000)] 
Fix merge error in samba rootfiles

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoUpdate contributors
Michael Tremer [Tue, 18 May 2021 09:33:47 +0000 (09:33 +0000)] 
Update contributors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoUpdate language errors
Michael Tremer [Tue, 18 May 2021 09:33:32 +0000 (09:33 +0000)] 
Update language errors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoMerge branch 'next'
Michael Tremer [Tue, 18 May 2021 09:33:05 +0000 (09:33 +0000)] 
Merge branch 'next'

2 years agoelfutils: Update to 0.184
Adolf Belka [Mon, 17 May 2021 12:29:44 +0000 (14:29 +0200)] 
elfutils: Update to 0.184

- Update from 0.183 to 0.184
- Update rootfiles
- Changelog
     2021-05-10  Mark Wielaard  <mark@klomp.org>
* configure.ac (AC_INIT): Set version to 0.184.
* NEWS: Add libdw, translation and debuginfod-client entries.
     2021-03-30  Frank Ch. Eigler  <fche@redhat.com>
* configure.ac: Look for pthread_setname_np.
     2021-02-17  Timm Bäder  <tbaeder@redhat.com>
* configure.ac: Add -Wno-packed-not-aligned check.
     2021-02-17  Timm Bäder  <tbaeder@redhat.com>
* configure.ac: Add -Wtrampolines check.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Reviewed-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogdb: Update to 10.2
Adolf Belka [Mon, 17 May 2021 12:30:32 +0000 (14:30 +0200)] 
gdb: Update to 10.2

- Update from 10.1 to 10.2
- Update rootfiles
- Changelog
   GDB 10.2 brings the following fixes and enhancements over GDB 10.1:
    * PR remote/26614 (AddressSanitizer: heap-use-after-free of extended_remote_target in remote_async_inferior_event_handler)
    * PR gdb/26828 (SIGSEGV in follow_die_offset dwarf2/read.c:22950)
    * PR gdb/26861 (internal-error: void target_mourn_inferior(ptid_t): Assertion `ptid == inferior_ptid' failed. OS: Mac OSX Catalina; Compiler: GCC; Language: C)
    * PR gdb/26876 (gdb error: internal-error: Unknown CFA rule when debugging the linux kernel with qemu)
    * PR breakpoints/26881 (infrun.c:6384: internal-error: void process_event_stop_test(execution_control_state*): Assertion `ecs->event_thread->control.exception_resume_breakpoint != NULL' failed)
    * PR gdb/26901 (Array subscript fails with flexible array member without size)
    * PR tui/26973 (gdb crashes when not including the status window in a new layout)
    * PR python/26974 (Wrong Value.format_string docu for static members argument)
    * PR breakpoints/27009 ([s390] GDB branches randomly for BC instruction while displaced stepping)
    * PR tdep/27015 (ARC: "eret" value is collected from the wrong data in register cache)
    * PR backtrace/27147 ([GNU/Linux, sparc64] GDB is unable to print full stack trace (got "previous frame inner to this frame" errors))
    * PR rust/27194 (put rust demangler on 10.x branch)
    * PR threads/27239 (gdb/cp-support.c:1619:(.text+0x5502): relocation truncated to fit: R_X86_64_PC32 against undefined symbol `TLS init function for thread_local_segv_handler')
    * PR breakpoints/27330 (nextoverthrow.exp FAILs on arm-none-eabi)
    * PR symtab/27333 ([dwarf-5] abort on unhandled DW_TAG_type_unit in process_psymtab_comp_unit)
    * PR fortran/27341 ([dwarf-5] FAIL: gdb.fortran/function-calls.exp: p derived_types_and_module_calls::pass_cart_nd(c_nd))
    * PR tdep/27369 (ARC: Stepping over atomic instruction sequences loops infinitely)
    * PR build/27385 (Cannot compile arc.c with gcc-4.8 (error: no matching function for call to 'std::pair...'))
    * PR gdb/27435 (Attach on solaris segfaults GDB)
    * PR build/27535 (amd64-linux-siginfo.c fails to compile after updating to glibc-2.33 headers)
    * PR build/27536 (aarch64-linux-hw-point.c fails to compile after updating to glibc-2.33)
    * PR symtab/27541 (gdb crashes on "file -readnow")
    * PR gdb/27750 (local variables have wrong address and values on sparc64)
    * PR varobj/27757 (-var-list-children coredump)

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Apply changed permissions to /srv/web/ipfire/cgi-bin/cachemgr.cgi
Peter Müller [Mon, 17 May 2021 19:07:52 +0000 (21:07 +0200)] 
Core Update 157: Apply changed permissions to /srv/web/ipfire/cgi-bin/cachemgr.cgi

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoSquid: cachemgr.cgi does not have to be owned (hence writeable) by nobody
Peter Müller [Mon, 17 May 2021 19:07:32 +0000 (21:07 +0200)] 
Squid: cachemgr.cgi does not have to be owned (hence writeable) by nobody

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonagios-plugins: Prevent Nagios plugins from being owned by nobody
Peter Müller [Mon, 17 May 2021 19:07:11 +0000 (21:07 +0200)] 
nagios-plugins: Prevent Nagios plugins from being owned by nobody

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoNRPE: Prevent NRPE binary from being owned by "nobody"
Peter Müller [Mon, 17 May 2021 19:06:50 +0000 (21:06 +0200)] 
NRPE: Prevent NRPE binary from being owned by "nobody"

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Remove executable bit less ugly
Peter Müller [Mon, 17 May 2021 19:06:32 +0000 (21:06 +0200)] 
Core Update 157: Remove executable bit less ugly

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Apply changed permissions to /var/ipfire/ovpn/ovpn-leases.db
Peter Müller [Mon, 17 May 2021 19:06:12 +0000 (21:06 +0200)] 
Core Update 157: Apply changed permissions to /var/ipfire/ovpn/ovpn-leases.db

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoOpenVPN: ovpn-leases.db for sure does not have to be executable
Peter Müller [Mon, 17 May 2021 19:05:49 +0000 (21:05 +0200)] 
OpenVPN: ovpn-leases.db for sure does not have to be executable

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Apply changed permissions to /var/ipfire/updatexlrator/bin/
Peter Müller [Mon, 17 May 2021 19:05:26 +0000 (21:05 +0200)] 
Core Update 157: Apply changed permissions to /var/ipfire/updatexlrator/bin/

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoSquid: Prevent binaries within /var/ipfire/updatexlrator/bin/ from being owned by...
Peter Müller [Mon, 17 May 2021 19:05:07 +0000 (21:05 +0200)] 
Squid: Prevent binaries within /var/ipfire/updatexlrator/bin/ from being owned by nobody

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Apply changed permissions to /var/ipfire/urlfilter/bin/
Peter Müller [Mon, 17 May 2021 19:04:41 +0000 (21:04 +0200)] 
Core Update 157: Apply changed permissions to /var/ipfire/urlfilter/bin/

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoSquidGuard: Prevent binaries within /var/ipfire/urlfilter/bin/ from being owned by...
Peter Müller [Mon, 17 May 2021 19:04:23 +0000 (21:04 +0200)] 
SquidGuard: Prevent binaries within /var/ipfire/urlfilter/bin/ from being owned by nobody

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agobackup: prevent /var/ipfire/backup/bin/backup.pl from being owned by nobody
Peter Müller [Mon, 17 May 2021 19:04:00 +0000 (21:04 +0200)] 
backup: prevent /var/ipfire/backup/bin/backup.pl from being owned by nobody

This is dangerous as nobody could write arbitrary contents to this file
and execute it afterwards.

Partially fixes: #12619

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Ship changed iputils due to /usr/bin/ping changes
Peter Müller [Mon, 17 May 2021 19:03:36 +0000 (21:03 +0200)] 
Core Update 157: Ship changed iputils due to /usr/bin/ping changes

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: /var/ipfire/fwhosts/icmp-types does not have to be executable
Peter Müller [Mon, 17 May 2021 19:03:13 +0000 (21:03 +0200)] 
Core Update 157: /var/ipfire/fwhosts/icmp-types does not have to be executable

See commit 183ccaa5a5c95f4cb2b639360f3c1465567577e9.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Delete orphaned DMA mail box creation binary as well
Peter Müller [Mon, 17 May 2021 19:02:56 +0000 (21:02 +0200)] 
Core Update 157: Delete orphaned DMA mail box creation binary as well

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoDMA: do not ship a binary for creating mail boxes
Peter Müller [Mon, 17 May 2021 19:02:36 +0000 (21:02 +0200)] 
DMA: do not ship a binary for creating mail boxes

This is only needed in case of bounces generated by locally emitted
messages. We neither store these, nor do we create mail boxes on a
firewall. Safe to drop.

Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: Delete ssh-keysign binary
Peter Müller [Mon, 17 May 2021 19:02:20 +0000 (21:02 +0200)] 
Core Update 157: Delete ssh-keysign binary

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years ago/usr/bin/ping does not need a SUID bit if appropriate capabilities are set
Peter Müller [Mon, 17 May 2021 19:01:54 +0000 (21:01 +0200)] 
/usr/bin/ping does not need a SUID bit if appropriate capabilities are set

Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCore Update 157: remove SUID bit from /usr/bin/gpg
Peter Müller [Mon, 17 May 2021 19:01:34 +0000 (21:01 +0200)] 
Core Update 157: remove SUID bit from /usr/bin/gpg

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoGnuPG does not need to have a SUID bit set
Peter Müller [Mon, 17 May 2021 19:00:33 +0000 (21:00 +0200)] 
GnuPG does not need to have a SUID bit set

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Fix exception when running without debug
Michael Tremer [Mon, 17 May 2021 15:33:13 +0000 (15:33 +0000)] 
unbound-dhcp-leases-bridge: Fix exception when running without debug

Fixes: https://bugzilla.ipfire.org/show_bug.cgi?id=12622
Fixes: #12622
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoOpenSSH: do not ship ssh-keysign anymore
Peter Müller [Sun, 16 May 2021 20:48:58 +0000 (22:48 +0200)] 
OpenSSH: do not ship ssh-keysign anymore

To my surprise, this binary comes with suid flag set, and since we do
not have SSH key signing enabled, there is no need to ship it with
IPFire.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython3-docutils: Bump package version
Michael Tremer [Sun, 16 May 2021 13:23:37 +0000 (13:23 +0000)] 
python3-docutils: Bump package version

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython-docutils: drop python2 docutils
Arne Fitzenreiter [Sun, 16 May 2021 13:18:07 +0000 (15:18 +0200)] 
python-docutils: drop python2 docutils

we merging from python2 to 3 and this is not needed anymore

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython3-docutils: build prior python3-daemon
Arne Fitzenreiter [Sun, 16 May 2021 13:18:06 +0000 (15:18 +0200)] 
python3-docutils: build prior python3-daemon

python3-daemon has a builddepency to python3-docutils

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython-distutils-extra: Removal of this python2 module
Adolf Belka [Sat, 15 May 2021 21:50:34 +0000 (23:50 +0200)] 
python-distutils-extra: Removal of this python2 module

- python-distutils-extra is linked to python-distutils which is no longer
   used as it has been replaced by setuptools.
- python-distutils-extra is currently from 2011 and the latest version
   is from 2016. No development occurring on this.
- No problem on a clean build with this module being removed.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython-distutils: Removal of this python2 module
Adolf Belka [Sat, 15 May 2021 21:50:33 +0000 (23:50 +0200)] 
python-distutils: Removal of this python2 module

- python-distutils has been replaced by setuptools.
- python-distutils was not being built anyway as it was not listed in
   make.sh
- lfs has missing sections. There are no source and no build sections

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agopython-optional-src: Removal of this python2 module
Adolf Belka [Sat, 15 May 2021 21:50:32 +0000 (23:50 +0200)] 
python-optional-src: Removal of this python2 module

- python-optional-src was not getting built anyway as it was not listed
   in make.sh
- lfs file was missing most of the standard content. No source info
   and no build instructions
- missing source file from IPFire source system
- grep on build/ found no dependencies on this module

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>