]> git.ipfire.org Git - ipfire-2.x.git/log
ipfire-2.x.git
2 years agoRevert "gcp-setup: Fixes bug12763"
Michael Tremer [Fri, 10 May 2024 12:02:33 +0000 (12:02 +0000)] 
Revert "gcp-setup: Fixes bug12763"

This reverts commit 2841a675482879a5eb6bfeaabb268066af762e9d.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "exoscale-setup: Fixes bug12763"
Michael Tremer [Fri, 10 May 2024 12:02:32 +0000 (12:02 +0000)] 
Revert "exoscale-setup: Fixes bug12763"

This reverts commit 3162b6ccfa2fb22513c7d23d29f0509343f46828.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "azure-setup: Fixes bug12763"
Michael Tremer [Fri, 10 May 2024 12:02:31 +0000 (12:02 +0000)] 
Revert "azure-setup: Fixes bug12763"

This reverts commit 1db5f96c5ebbb2074c9c0a3edf29866c4769da11.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "aws-setup: Fixes bug12763"
Michael Tremer [Fri, 10 May 2024 12:02:30 +0000 (12:02 +0000)] 
Revert "aws-setup: Fixes bug12763"

This reverts commit eb0de6531c441663477cf7e139f1bd5321630eef.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "ip-up: Fixes bug12763"
Michael Tremer [Fri, 10 May 2024 12:02:29 +0000 (12:02 +0000)] 
Revert "ip-up: Fixes bug12763"

This reverts commit 4f455c488ee8542bea4ccbe439351b3e9973c6e4.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "red: Fixes bug12763"
Michael Tremer [Fri, 10 May 2024 12:02:28 +0000 (12:02 +0000)] 
Revert "red: Fixes bug12763"

This reverts commit 9c28cd59c1b4f535382e5e4e7952d921af8cc03b.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "static-routes: Fixes bug12763"
Michael Tremer [Fri, 10 May 2024 12:02:27 +0000 (12:02 +0000)] 
Revert "static-routes: Fixes bug12763"

This reverts commit e33ee46e621eb6967c954a9d3b4683880e372579.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoipsec-interfaces: Don't throw away errors when creating routes
Michael Tremer [Fri, 10 May 2024 12:02:26 +0000 (12:02 +0000)] 
ipsec-interfaces: Don't throw away errors when creating routes

This partly reverts 87a97a431915849cf6d19e1b7137b4fb0b6dd91d.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agodhcp: Explicitely compile with support for execute()
Michael Tremer [Mon, 13 May 2024 14:42:26 +0000 (14:42 +0000)] 
dhcp: Explicitely compile with support for execute()

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Remove unused functions and module imports
Michael Tremer [Fri, 10 May 2024 16:53:22 +0000 (17:53 +0100)] 
unbound-dhcp-leases-bridge: Remove unused functions and module imports

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Make expiry check work for stub leases
Michael Tremer [Fri, 10 May 2024 16:51:41 +0000 (17:51 +0100)] 
unbound-dhcp-leases-bridge: Make expiry check work for stub leases

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Remove unused code
Michael Tremer [Fri, 10 May 2024 16:51:26 +0000 (17:51 +0100)] 
unbound-dhcp-leases-bridge: Remove unused code

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Don't parse any inactive leases
Michael Tremer [Fri, 10 May 2024 16:47:44 +0000 (17:47 +0100)] 
unbound-dhcp-leases-bridge: Don't parse any inactive leases

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Drop parsing MAC addresses
Michael Tremer [Fri, 10 May 2024 16:46:45 +0000 (17:46 +0100)] 
unbound-dhcp-leases-bridge: Drop parsing MAC addresses

We will represent the current state in DNS and we won't filter out
anything that we think might be no longer valid.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Remove fixed leases cache
Michael Tremer [Fri, 10 May 2024 16:40:27 +0000 (17:40 +0100)] 
unbound-dhcp-leases-bridge: Remove fixed leases cache

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Include traceback if the worker callback fails
Michael Tremer [Fri, 10 May 2024 16:36:40 +0000 (17:36 +0100)] 
unbound-dhcp-leases-bridge: Include traceback if the worker callback fails

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Log if a lease is not being added
Michael Tremer [Fri, 10 May 2024 16:31:25 +0000 (17:31 +0100)] 
unbound-dhcp-leases-bridge: Log if a lease is not being added

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Remove leases to keep the store up to date
Michael Tremer [Fri, 10 May 2024 16:28:58 +0000 (17:28 +0100)] 
unbound-dhcp-leases-bridge: Remove leases to keep the store up to date

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Skip updates if not necessary
Michael Tremer [Fri, 10 May 2024 16:25:13 +0000 (17:25 +0100)] 
unbound-dhcp-leases-bridge: Skip updates if not necessary

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Find existing leases to remove all data
Michael Tremer [Fri, 10 May 2024 16:20:30 +0000 (17:20 +0100)] 
unbound-dhcp-leases-bridge: Find existing leases to remove all data

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Store leases in a globally accessible set()
Michael Tremer [Fri, 10 May 2024 16:16:13 +0000 (17:16 +0100)] 
unbound-dhcp-leases-bridge: Store leases in a globally accessible set()

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Make Leases hashable and equal by IP address
Michael Tremer [Fri, 10 May 2024 16:07:23 +0000 (17:07 +0100)] 
unbound-dhcp-leases-bridge: Make Leases hashable and equal by IP address

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Use IPv4Address to store IP addresses
Michael Tremer [Fri, 10 May 2024 16:04:43 +0000 (17:04 +0100)] 
unbound-dhcp-leases-bridge: Use IPv4Address to store IP addresses

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Implement a worker thread to handle all events
Michael Tremer [Fri, 10 May 2024 16:01:50 +0000 (17:01 +0100)] 
unbound-dhcp-leases-bridge: Implement a worker thread to handle all events

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Store all messages in a queue
Michael Tremer [Fri, 10 May 2024 15:32:07 +0000 (16:32 +0100)] 
unbound-dhcp-leases-bridge: Store all messages in a queue

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agodhcp.cgi: Call the unbound-dhcp-leases-client for all events
Michael Tremer [Fri, 10 May 2024 15:07:05 +0000 (16:07 +0100)] 
dhcp.cgi: Call the unbound-dhcp-leases-client for all events

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-client: A new script to send events to the bridge
Michael Tremer [Fri, 10 May 2024 15:06:23 +0000 (16:06 +0100)] 
unbound-dhcp-leases-client: A new script to send events to the bridge

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Decode any incoming messages
Michael Tremer [Fri, 10 May 2024 13:50:30 +0000 (14:50 +0100)] 
unbound-dhcp-leases-bridge: Decode any incoming messages

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Remove running indicator
Michael Tremer [Fri, 10 May 2024 13:31:53 +0000 (14:31 +0100)] 
unbound-dhcp-leases-bridge: Remove running indicator

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Reload on SIGHUP
Michael Tremer [Fri, 10 May 2024 13:29:31 +0000 (14:29 +0100)] 
unbound-dhcp-leases-bridge: Reload on SIGHUP

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: No longer listen to any changed files
Michael Tremer [Fri, 10 May 2024 13:27:10 +0000 (14:27 +0100)] 
unbound-dhcp-leases-bridge: No longer listen to any changed files

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Initialize at startup
Michael Tremer [Fri, 10 May 2024 13:25:53 +0000 (14:25 +0100)] 
unbound-dhcp-leases-bridge: Initialize at startup

When the process starts, we will now load all static hosts and leases
and reload Unbound to have a defined state to start with.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Open a socket to listen for events
Michael Tremer [Fri, 10 May 2024 13:19:05 +0000 (14:19 +0100)] 
unbound-dhcp-leases-bridge: Open a socket to listen for events

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Terminate on SIGINT
Michael Tremer [Fri, 10 May 2024 13:18:12 +0000 (14:18 +0100)] 
unbound-dhcp-leases-bridge: Terminate on SIGINT

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agomympd: remove create config start
Arne Fitzenreiter [Fri, 10 May 2024 10:42:29 +0000 (12:42 +0200)] 
mympd: remove create config start

this now resets an existing option like the port to
default.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agokernel: update x86_64 rootfile
Arne Fitzenreiter [Wed, 8 May 2024 11:28:38 +0000 (13:28 +0200)] 
kernel: update x86_64 rootfile

now the correct file

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "kernel: update x86_64 rootfile"
Arne Fitzenreiter [Wed, 8 May 2024 11:27:24 +0000 (13:27 +0200)] 
Revert "kernel: update x86_64 rootfile"

This reverts commit 7b68ef8515f53e09bf8da9b68096e0cea4bcb017.

I have copied the rootfile over the config...

2 years agokernel: update x86_64 rootfile
Arne Fitzenreiter [Wed, 8 May 2024 06:19:30 +0000 (06:19 +0000)] 
kernel: update x86_64 rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agobacula: Update to version 13.0.4
Adolf Belka [Mon, 6 May 2024 16:58:20 +0000 (18:58 +0200)] 
bacula: Update to version 13.0.4

- Update from version 11.0.6 to 13.0.4
- Update of rootfile
- Version 13.x has now been released for 12 months so updating the File Daemon to 13.x
   should be good.
- Version 11.x was released 40 months ago.
- Changelog
    The changes are all related to the Director and the Storage Daemon. The changelog states
    that older file daemons "should" be compatible with 13.x DIR & SD. This change ensures
    IPfire "is" compatible with the 13.x DIR & SD.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoupdate.sh: Add SPAMHAUS_DROP if SPAMHAUS_EDROP was previously used
Adolf Belka [Sat, 4 May 2024 13:05:20 +0000 (15:05 +0200)] 
update.sh: Add SPAMHAUS_DROP if SPAMHAUS_EDROP was previously used

- I realised that the previous patch for update.sh related to the ipblocklist removal
   of ALIENVAULT and SPAMHAUS_EDROP only removed the SPAMHAUS_EDROP setting. It makes sense
   to add SPAMHAUS_DROP to the settings file if SPAMHAUS_EDROP was previously used and
   SPAMHAUS_DROP was not selected.
- This patch adds the above change.

Tested-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoupdate contributors
Arne Fitzenreiter [Tue, 7 May 2024 05:04:41 +0000 (07:04 +0200)] 
update contributors

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agokernel: update aarch64 config and rootfile
Arne Fitzenreiter [Tue, 7 May 2024 05:03:38 +0000 (07:03 +0200)] 
kernel: update aarch64 config and rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agokernel: update to 6.6.30
Arne Fitzenreiter [Mon, 6 May 2024 16:03:05 +0000 (18:03 +0200)] 
kernel: update to 6.6.30

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agokernel: Enable XDP
Michael Tremer [Thu, 18 Apr 2024 21:08:55 +0000 (21:08 +0000)] 
kernel: Enable XDP

https://lists.ipfire.org/hyperkitty/list/development@lists.ipfire.org/thread/S4GPL3OBFZ6LMA52JNLHIOPMNA5C3V6R/

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agokernel: update to 6.6.29
Arne Fitzenreiter [Thu, 2 May 2024 10:35:08 +0000 (12:35 +0200)] 
kernel: update to 6.6.29

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agomympd: update to 14.1.2
Arne Fitzenreiter [Mon, 29 Apr 2024 10:40:37 +0000 (12:40 +0200)] 
mympd: update to 14.1.2

This is a small bugfix release.
Changelog:

    Fix: Output enabled state is bool type
    Fix: Add missing sort parameters to home icon for search
    Fix: Set default stream port if stream uri is defined

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agosuricata.yaml: Fix Landlock path settings
Peter Müller [Mon, 22 Apr 2024 16:44:00 +0000 (16:44 +0000)] 
suricata.yaml: Fix Landlock path settings

Suricata will complain if it cannot read its own configuration file,
hence read-only access to /etc/suricata must be allowed. Since the list
applies to directories, rather than files, restricting read access to
only /usr/share/misc/magic.mgc is not possible; reading /usr/share/misc
must be allowed instead.

Fixes: #13645
Tested-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoRevert "suricata: Disable Landlock support"
Peter Müller [Mon, 22 Apr 2024 16:43:00 +0000 (16:43 +0000)] 
Revert "suricata: Disable Landlock support"

This reverts commit b7da97fd59f010ea8fa7bca845d18e52ca89bc5a.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agolinux: Properly load Landlock module
Peter Müller [Mon, 22 Apr 2024 16:43:00 +0000 (16:43 +0000)] 
linux: Properly load Landlock module

Fixes: #13645
Tested-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agokmod: update rootfile
Arne Fitzenreiter [Sun, 28 Apr 2024 21:04:28 +0000 (21:04 +0000)] 
kmod: update rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agolynis: update rootfile
Arne Fitzenreiter [Sun, 28 Apr 2024 21:04:02 +0000 (21:04 +0000)] 
lynis: update rootfile

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship apache initskript
Arne Fitzenreiter [Sun, 28 Apr 2024 13:14:32 +0000 (13:14 +0000)] 
core186: ship apache initskript

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoinitscripts: Correctly wait for Apache2 to terminate
Michael Tremer [Fri, 26 Apr 2024 15:28:38 +0000 (15:28 +0000)] 
initscripts: Correctly wait for Apache2 to terminate

This is achieved by telling killproc which PIDs to wait for.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship unbound-dhcp-leses-bridge
Arne Fitzenreiter [Sun, 28 Apr 2024 13:12:04 +0000 (13:12 +0000)] 
core186: ship unbound-dhcp-leses-bridge

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Make comparison work if old file does not exist
Michael Tremer [Fri, 26 Apr 2024 15:09:19 +0000 (15:09 +0000)] 
unbound-dhcp-leases-bridge: Make comparison work if old file does not exist

This patch catches any errors if the file did not previously exist and
therefore skips the comparison.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Only reload if leases have actually changed
Michael Tremer [Fri, 26 Apr 2024 15:09:18 +0000 (15:09 +0000)] 
unbound-dhcp-leases-bridge: Only reload if leases have actually changed

This patches changes that leases will always be written in
alphanumerical order so that we can later compare the newly generated
file with the previous version. If it has not changed, we skip reload
Unbound.

Suggested-by: Nick Howitt <nick@howitts.co.uk>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agounbound-dhcp-leases-bridge: Implement atomic file replacement
Michael Tremer [Fri, 26 Apr 2024 15:09:17 +0000 (15:09 +0000)] 
unbound-dhcp-leases-bridge: Implement atomic file replacement

This change no longer renames the file, but removes the old link and
creates a new link for the temporary file. That helps us to jump out of
the code at any point without worrying about cleaning up the temporary
file.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship tzdata
Arne Fitzenreiter [Sun, 28 Apr 2024 13:07:50 +0000 (13:07 +0000)] 
core186: ship tzdata

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agotzdata: Update to version 2024a
Adolf Belka [Thu, 25 Apr 2024 20:43:02 +0000 (22:43 +0200)] 
tzdata: Update to version 2024a

- Update from version 2023d to 2024a
- Update of rootfile not required
- Changelog
    2024a
  Briefly:
    Kazakhstan unifies on UTC+5 beginning 2024-03-01.
    Palestine springs forward a week later after Ramadan.
    zic no longer pretends to support indefinite-past DST.
    localtime no longer mishandles Ciudad Juárez in 2422.
  Changes to future timestamps
    Kazakhstan unifies on UTC+5.  This affects Asia/Almaty and
     Asia/Qostanay which together represent the eastern portion of the
     country that will transition from UTC+6 on 2024-03-01 at 00:00 to
     join the western portion.  (Thanks to Zhanbolat Raimbekov.)
    Palestine springs forward a week later than previously predicted
     in 2024 and 2025.  (Thanks to Heba Hamad.)  Change spring-forward
     predictions to the second Saturday after Ramadan, not the first;
     this also affects other predictions starting in 2039.
  Changes to past timestamps
    Asia/Ho_Chi_Minh's 1955-07-01 transition occurred at 01:00
     not 00:00.  (Thanks to Đoàn Trần Công Danh.)
    From 1947 through 1949, Toronto's transitions occurred at 02:00
     not 00:00.  (Thanks to Chris Walton.)
    In 1911 Miquelon adopted standard time on June 15, not May 15.
  Changes to code
    The FROM and TO columns of Rule lines can no longer be "minimum"
     or an abbreviation of "minimum", because TZif files do not support
     DST rules that extend into the indefinite past - although these
     rules were supported when TZif files had only 32-bit data, this
     stopped working when 64-bit TZif files were introduced in 1995.
     This should not be a problem for realistic data, since DST was
     first used in the 20th century.  As a transition aid, FROM columns
     like "minimum" are now diagnosed and then treated as if they were
     the year 1900; this should suffice for TZif files on old systems
     with only 32-bit time_t, and it is more compatible with bugs in
     2023c-and-earlier localtime.c.  (Problem reported by Yoshito
     Umaoka.)
    localtime and related functions no longer mishandle some
     timestamps that occur about 400 years after a switch to a time
     zone with a DST schedule.  In 2023d data this problem was visible
     for some timestamps in November 2422, November 2822, etc. in
     America/Ciudad_Juarez.  (Problem reported by Gilmore Davidson.)
    strftime %s now uses tm_gmtoff if available.  (Problem and draft
     patch reported by Dag-Erling Smørgrav.)
  Changes to build procedure
    The leap-seconds.list file is now copied from the IERS instead of
     from its downstream counterpart at NIST, as the IERS version is
     now in the public domain too and tends to be more up-to-date.
     (Thanks to Martin Burnicki for liaisoning with the IERS.)
  Changes to documentation
    The strftime man page documents which struct tm members affect
     which conversion specs, and that tzset is called.  (Problems
     reported by Robert Elz and Steve Summit.)

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship sqlite
Arne Fitzenreiter [Sun, 28 Apr 2024 13:05:17 +0000 (13:05 +0000)] 
core186: ship sqlite

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agosqlite: Update to version 3450300
Adolf Belka [Thu, 25 Apr 2024 20:43:01 +0000 (22:43 +0200)] 
sqlite: Update to version 3450300

- Update from version 3450200 to 3450300
- Update of rootfile not required
- Changelog
    3450300
Fix a long-standing bug (going back to version 3.24.0) that might (rarely) cause
 the "old.*" values of an UPDATE trigger to be incorrect if that trigger fires in
 response to an UPSERT. Forum post 284955a3cd454a15.
Fix a bug in sum() that could cause it to return NULL when it should return
 Infinity. Forum post 23b8688ef4.
Other trifling corrections and compiler warning fixes that have come up since the
 previous patch release. See the timeline for details.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship suricata and libhtp
Arne Fitzenreiter [Sun, 28 Apr 2024 13:01:49 +0000 (13:01 +0000)] 
core186: ship suricata and libhtp

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agosuricata: Update to 7.0.5
Michael Tremer [Wed, 24 Apr 2024 08:49:01 +0000 (08:49 +0000)] 
suricata: Update to 7.0.5

This update contains fixes for the following issues:

* CVE-2024-32664 CRITICAL
* CVE-2024-32867 MODERATE

  https://forum.suricata.io/t/suricata-7-0-5-and-6-0-19-released/4617

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agolibhtp: Update to 0.5.48
Michael Tremer [Wed, 24 Apr 2024 08:49:00 +0000 (08:49 +0000)] 
libhtp: Update to 0.5.48

https://github.com/OISF/libhtp/releases/tag/0.5.48

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship kmod
Arne Fitzenreiter [Sun, 28 Apr 2024 12:58:05 +0000 (12:58 +0000)] 
core186: ship kmod

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agokmod: Update to 32
Peter Müller [Mon, 22 Apr 2024 16:48:00 +0000 (16:48 +0000)] 
kmod: Update to 32

Changelog according to the tarball's NEWS file:

- Improvements

        - Use any hash algo known by kernel/openssl instead of keep needing
          to update the mapping

        - Teach kmod to load modprobe.d/depmod.d configuration from ${prefix}/lib
          and allow it to be overriden during build with --with-distconfdir=DIR

        - Make kernel modules directory configurable. This allows distro to
          make kmod use only files from /usr regardless of having a compat
          symlink in place.

        - Install kmod.pc containing the features selected at build time.

        - Install all tools and symlinks by default. Previously kmod relied on
          distro packaging to set up the symlinks in place like modprobe,
          depmod, lsmod, etc. Now those symlinks are created by kmod itself
          and they are always placed in $bindir.

- Bug Fixes

        - Fix warnings due to -Walloc-size

- Others

        - Drop python bindings. Those were not update in ages and not compatible
          with latest python releases.

        - Cleanup test infra, dropping what was not used anymore

        - Drop experimental tools `kmod insert` / `kmod remove`. Building those
          was protected by a configure option never set by distros. They also
          didn't gain enough traction to replace the older interfaces via
          modprobe/insmod/rmmod.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship strongswan
Arne Fitzenreiter [Sun, 28 Apr 2024 12:55:54 +0000 (12:55 +0000)] 
core186: ship strongswan

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agostrongSwan: Update to 5.9.14
Peter Müller [Mon, 22 Apr 2024 16:03:00 +0000 (16:03 +0000)] 
strongSwan: Update to 5.9.14

Please see https://github.com/strongswan/strongswan/releases/tag/5.9.14
for the changelog of this version.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoLynis: Update to 3.1.1
Peter Müller [Mon, 22 Apr 2024 16:01:00 +0000 (16:01 +0000)] 
Lynis: Update to 3.1.1

Please see https://cisofy.com/changelog/lynis/#311 for the changelogs
since version 3.0.9.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agoTor: Update to 0.4.8.11
Peter Müller [Mon, 22 Apr 2024 15:58:00 +0000 (15:58 +0000)] 
Tor: Update to 0.4.8.11

Full changelog according to https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.8.11/ChangeLog:

Changes in version 0.4.8.11 - 2024-04-10
  This is a minor release mostly to upgrade the fallbackdir list. Worth noting
  also that directory authority running this version will now automatically
  reject relays running the end of life 0.4.7.x version.

  o Minor feature (authority):
    - Reject 0.4.7.x series at the authority level. Closes ticket 40896.

  o Minor feature (dirauth, tor26):
    - New IP address and keys.

  o Minor feature (directory authority):
    - Allow BandwidthFiles "node_id" KeyValue without the dollar sign at
      the start of the hexdigit, in order to easier database queries
      combining Tor documents in which the relays fingerprint does not
      include it. Fixes bug 40891; bugfix on 0.4.7 (all supported
      versions of Tor).

  o Minor features (fallbackdir):
    - Regenerate fallback directories generated on April 10, 2024.

  o Minor features (geoip data):
    - Update the geoip files to match the IPFire Location Database, as
      retrieved on 2024/04/10.

  o Minor bugfixes (directory authorities):
    - Add a warning when publishing a vote or signatures to another
      directory authority fails. Fixes bug 40910; bugfix
      on 0.2.0.3-alpha.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agocore186: ship squid
Arne Fitzenreiter [Sun, 28 Apr 2024 12:46:30 +0000 (12:46 +0000)] 
core186: ship squid

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agosquid: Update to 6.9
Matthias Fischer [Wed, 10 Apr 2024 16:16:52 +0000 (18:16 +0200)] 
squid: Update to 6.9

For details see:
https://github.com/squid-cache/squid/commits/v6

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2 years agogeneral-function.pl: Add a function to easily set defaults
Michael Tremer [Tue, 16 Apr 2024 13:02:33 +0000 (15:02 +0200)] 
general-function.pl: Add a function to easily set defaults

This function can be used to set values in a hash if they have not been
set, yet.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoweb: Refactor graphs
Michael Tremer [Sat, 23 Mar 2024 19:56:58 +0000 (20:56 +0100)] 
web: Refactor graphs

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoweb: Introduce sections
Michael Tremer [Sat, 23 Mar 2024 19:09:16 +0000 (20:09 +0100)] 
web: Introduce sections

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agovulnerabilities.cgi: Use CSS to colour the table
Michael Tremer [Sat, 23 Mar 2024 18:57:49 +0000 (19:57 +0100)] 
vulnerabilities.cgi: Use CSS to colour the table

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agovulnerabilities.cgi: Remove manual alternation of colours
Michael Tremer [Sat, 23 Mar 2024 18:42:24 +0000 (19:42 +0100)] 
vulnerabilities.cgi: Remove manual alternation of colours

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoheader.pl: Simplify boxes
Michael Tremer [Sat, 23 Mar 2024 18:39:40 +0000 (19:39 +0100)] 
header.pl: Simplify boxes

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoheader.pl: Remove unused openpagewithoutmenu function
Michael Tremer [Sat, 23 Mar 2024 18:21:56 +0000 (19:21 +0100)] 
header.pl: Remove unused openpagewithoutmenu function

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoCSS: Automatically stripe all tables
Michael Tremer [Sat, 23 Mar 2024 18:00:49 +0000 (19:00 +0100)] 
CSS: Automatically stripe all tables

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoRemove RECONNECTION=dialondemand
Michael Tremer [Sat, 23 Mar 2024 15:55:41 +0000 (16:55 +0100)] 
Remove RECONNECTION=dialondemand

We don't support this at all and so we don't need to check any more.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonetwork-functions.pl: Read PPP settings globally
Michael Tremer [Sat, 23 Mar 2024 15:51:27 +0000 (16:51 +0100)] 
network-functions.pl: Read PPP settings globally

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoweb: Read ethernet settings file only once in headers
Michael Tremer [Sat, 23 Mar 2024 15:42:16 +0000 (16:42 +0100)] 
web: Read ethernet settings file only once in headers

The web UI is rather slow and one of the reasons for that is that we are
reading the same files over and over again...

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogeneral-functions.pl: Don't use line buffering
Michael Tremer [Sat, 23 Mar 2024 15:31:38 +0000 (16:31 +0100)] 
general-functions.pl: Don't use line buffering

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoweb-user-interface: Move theme functions back into header.pl
Michael Tremer [Sat, 23 Mar 2024 15:28:38 +0000 (16:28 +0100)] 
web-user-interface: Move theme functions back into header.pl

Since we no longer support other themes, the web UI should load quicker
if not importing too many other files.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoheader.pl: Remove unused function "is_modem"
Michael Tremer [Sat, 23 Mar 2024 15:21:34 +0000 (16:21 +0100)] 
header.pl: Remove unused function "is_modem"

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoheader.pl: Fix whitespace errors
Michael Tremer [Sat, 23 Mar 2024 14:59:59 +0000 (15:59 +0100)] 
header.pl: Fix whitespace errors

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogeneral-functions.pl: Remove unused NextIP* functions
Michael Tremer [Sat, 23 Mar 2024 14:54:02 +0000 (15:54 +0100)] 
general-functions.pl: Remove unused NextIP* functions

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogeneral-functions.pl: Remove unused srtarray function
Michael Tremer [Sat, 23 Mar 2024 14:52:17 +0000 (15:52 +0100)] 
general-functions.pl: Remove unused srtarray function

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogeneral-functions.pl: Remove getlastip/getnextip
Michael Tremer [Sat, 23 Mar 2024 14:49:54 +0000 (15:49 +0100)] 
general-functions.pl: Remove getlastip/getnextip

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogeneral-functions.pl: Drop unused getccdbc function
Michael Tremer [Sat, 23 Mar 2024 14:38:48 +0000 (15:38 +0100)] 
general-functions.pl: Drop unused getccdbc function

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogeneral-functions.pl: Drop unused "writehashpart" function
Michael Tremer [Sat, 23 Mar 2024 14:36:12 +0000 (15:36 +0100)] 
general-functions.pl: Drop unused "writehashpart" function

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agogeneral-functions.pl: Fix various whitespace issues
Michael Tremer [Sat, 23 Mar 2024 14:35:48 +0000 (15:35 +0100)] 
general-functions.pl: Fix various whitespace issues

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoinitscripts: Don't overwrite the PID file
Michael Tremer [Sat, 23 Mar 2024 13:35:39 +0000 (14:35 +0100)] 
initscripts: Don't overwrite the PID file

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoinitscripts: Add some basic functions for IP address maths
Michael Tremer [Sat, 23 Mar 2024 13:32:30 +0000 (14:32 +0100)] 
initscripts: Add some basic functions for IP address maths

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoinitscripts: Fix reading PIDs
Michael Tremer [Sat, 23 Mar 2024 13:31:49 +0000 (14:31 +0100)] 
initscripts: Fix reading PIDs

An incorrect variable has been used.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agoinitscripts: Handle command arguments as array
Michael Tremer [Sat, 23 Mar 2024 13:30:33 +0000 (14:30 +0100)] 
initscripts: Handle command arguments as array

For some reason, the function is refusing to launch a command that has
extra arguments.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonetwork: Don't include initscript headers twice
Michael Tremer [Fri, 22 Mar 2024 16:40:15 +0000 (17:40 +0100)] 
network: Don't include initscript headers twice

Everywhere we import the functions, we have already imported the
standard includes.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonetwork-functions.pl: Add function to get netmask in dotted format
Michael Tremer [Wed, 20 Mar 2024 16:19:50 +0000 (17:19 +0100)] 
network-functions.pl: Add function to get netmask in dotted format

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2 years agonetwork-functions.pl: Fix return code check
Michael Tremer [Wed, 20 Mar 2024 11:10:50 +0000 (12:10 +0100)] 
network-functions.pl: Fix return code check

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>