Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

This commit is contained in:
Michael Tremer
2014-03-07 16:33:42 +01:00
9 changed files with 291 additions and 85 deletions

View File

@@ -1,7 +1,10 @@
net.ipv4.ip_forward = 1 net.ipv4.ip_forward = 1
net.ipv4.ip_dynaddr = 1 net.ipv4.ip_dynaddr = 1
net.ipv4.icmp_echo_ignore_broadcasts = 1 net.ipv4.icmp_echo_ignore_broadcasts = 1
net.ipv4.icmp_ignore_bogus_error_responses = 1 net.ipv4.icmp_ignore_bogus_error_responses = 1
net.ipv4.icmp_ratelimit = 1000
net.ipv4.icmp_ratemask = 6168
net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_syncookies = 1
net.ipv4.tcp_fin_timeout = 30 net.ipv4.tcp_fin_timeout = 30

View File

@@ -70,6 +70,8 @@ my $netsettings = "${General::swroot}/ethernet/settings";
&General::readhasharray($configgrp, \%customgrp); &General::readhasharray($configgrp, \%customgrp);
&General::get_aliases(\%aliases); &General::get_aliases(\%aliases);
my @log_limit_options = &make_log_limit_options();
# MAIN # MAIN
&main(); &main();
@@ -305,7 +307,7 @@ sub buildrules {
} }
if ($LOG) { if ($LOG) {
run("$IPTABLES -t nat -A $CHAIN_NAT_DESTINATION @nat_options -j LOG --log-prefix 'DNAT '"); run("$IPTABLES -t nat -A $CHAIN_NAT_DESTINATION @nat_options @log_limit_options -j LOG --log-prefix 'DNAT '");
} }
run("$IPTABLES -t nat -A $CHAIN_NAT_DESTINATION @nat_options -j DNAT --to-destination $dnat_address"); run("$IPTABLES -t nat -A $CHAIN_NAT_DESTINATION @nat_options -j DNAT --to-destination $dnat_address");
@@ -317,7 +319,7 @@ sub buildrules {
push(@nat_options, @destination_options); push(@nat_options, @destination_options);
if ($LOG) { if ($LOG) {
run("$IPTABLES -t nat -A $CHAIN_NAT_SOURCE @nat_options -j LOG --log-prefix 'SNAT '"); run("$IPTABLES -t nat -A $CHAIN_NAT_SOURCE @nat_options @log_limit_options -j LOG --log-prefix 'SNAT '");
} }
run("$IPTABLES -t nat -A $CHAIN_NAT_SOURCE @nat_options -j SNAT --to-source $nat_address"); run("$IPTABLES -t nat -A $CHAIN_NAT_SOURCE @nat_options -j SNAT --to-source $nat_address");
} }
@@ -328,7 +330,7 @@ sub buildrules {
# Insert firewall rule. # Insert firewall rule.
if ($LOG && !$NAT) { if ($LOG && !$NAT) {
run("$IPTABLES -A $chain @options -j LOG"); run("$IPTABLES -A $chain @options @log_limit_options -j LOG --log-prefix '$chain '");
} }
run("$IPTABLES -A $chain @options -j $target"); run("$IPTABLES -A $chain @options -j $target");
} }
@@ -764,3 +766,18 @@ sub add_dnat_mangle_rules {
run("$IPTABLES -t mangle -A $CHAIN_MANGLE_NAT_DESTINATION_FIX @mangle_options"); run("$IPTABLES -t mangle -A $CHAIN_MANGLE_NAT_DESTINATION_FIX @mangle_options");
} }
} }
sub make_log_limit_options {
my @options = ("-m", "limit");
# Maybe we should get this from the configuration.
my $limit = 10;
# We limit log messages to $limit messages per minute.
push(@options, ("--limit", "$limit/min"));
# And we allow bursts of 2x $limit.
push(@options, ("--limit-burst", $limit * 2));
return @options;
}

View File

@@ -333,7 +333,14 @@ CONFIG_ARCH_MULTIPLATFORM=y
CONFIG_ARCH_MULTI_V7=y CONFIG_ARCH_MULTI_V7=y
CONFIG_ARCH_MULTI_V6_V7=y CONFIG_ARCH_MULTI_V6_V7=y
# CONFIG_ARCH_MULTI_CPU_AUTO is not set # CONFIG_ARCH_MULTI_CPU_AUTO is not set
# CONFIG_ARCH_MVEBU is not set CONFIG_ARCH_MVEBU=y
#
# Marvell SOC with device tree
#
CONFIG_MACH_ARMADA_370_XP=y
CONFIG_MACH_ARMADA_370=y
CONFIG_MACH_ARMADA_XP=y
# CONFIG_ARCH_BCM is not set # CONFIG_ARCH_BCM is not set
# CONFIG_GPIO_PCA953X is not set # CONFIG_GPIO_PCA953X is not set
CONFIG_KEYBOARD_GPIO_POLLED=m CONFIG_KEYBOARD_GPIO_POLLED=m
@@ -443,7 +450,7 @@ CONFIG_MACH_OMAP4_PANDA=y
# CONFIG_OMAP3_SDRC_AC_TIMING is not set # CONFIG_OMAP3_SDRC_AC_TIMING is not set
# CONFIG_ARCH_SOCFPGA is not set # CONFIG_ARCH_SOCFPGA is not set
# CONFIG_PLAT_SPEAR is not set # CONFIG_PLAT_SPEAR is not set
# CONFIG_ARCH_SUNXI is not set CONFIG_ARCH_SUNXI=y
# CONFIG_ARCH_SIRF is not set # CONFIG_ARCH_SIRF is not set
# CONFIG_ARCH_TEGRA is not set # CONFIG_ARCH_TEGRA is not set
# CONFIG_ARCH_U8500 is not set # CONFIG_ARCH_U8500 is not set
@@ -460,12 +467,14 @@ CONFIG_ARCH_VIRT=y
CONFIG_ARCH_VT8500=y CONFIG_ARCH_VT8500=y
CONFIG_ARCH_WM8850=y CONFIG_ARCH_WM8850=y
CONFIG_ARCH_ZYNQ=y CONFIG_ARCH_ZYNQ=y
CONFIG_PLAT_ORION=y
CONFIG_PLAT_VERSATILE=y CONFIG_PLAT_VERSATILE=y
CONFIG_ARM_TIMER_SP804=y CONFIG_ARM_TIMER_SP804=y
# #
# Processor Type # Processor Type
# #
CONFIG_CPU_PJ4B=y
CONFIG_CPU_V7=y CONFIG_CPU_V7=y
CONFIG_CPU_32v6K=y CONFIG_CPU_32v6K=y
CONFIG_CPU_32v7=y CONFIG_CPU_32v7=y
@@ -502,6 +511,7 @@ CONFIG_ARM_L1_CACHE_SHIFT=6
CONFIG_ARM_DMA_MEM_BUFFERABLE=y CONFIG_ARM_DMA_MEM_BUFFERABLE=y
CONFIG_ARM_NR_BANKS=8 CONFIG_ARM_NR_BANKS=8
CONFIG_MULTI_IRQ_HANDLER=y CONFIG_MULTI_IRQ_HANDLER=y
CONFIG_PJ4B_ERRATA_4742=y
CONFIG_ARM_ERRATA_430973=y CONFIG_ARM_ERRATA_430973=y
CONFIG_PL310_ERRATA_588369=y CONFIG_PL310_ERRATA_588369=y
CONFIG_ARM_ERRATA_643719=y CONFIG_ARM_ERRATA_643719=y
@@ -1314,6 +1324,7 @@ CONFIG_CMA_AREAS=7
# #
# Bus devices # Bus devices
# #
CONFIG_MVEBU_MBUS=y
CONFIG_OMAP_OCP2SCP=y CONFIG_OMAP_OCP2SCP=y
CONFIG_OMAP_INTERCONNECT=y CONFIG_OMAP_INTERCONNECT=y
CONFIG_CONNECTOR=y CONFIG_CONNECTOR=y
@@ -1402,6 +1413,7 @@ CONFIG_MTD_NAND_IDS=y
CONFIG_MTD_NAND_GPMI_NAND=m CONFIG_MTD_NAND_GPMI_NAND=m
# CONFIG_MTD_NAND_PLATFORM is not set # CONFIG_MTD_NAND_PLATFORM is not set
# CONFIG_MTD_ALAUDA is not set # CONFIG_MTD_ALAUDA is not set
CONFIG_MTD_NAND_ORION=y
CONFIG_MTD_NAND_MXC=m CONFIG_MTD_NAND_MXC=m
# CONFIG_MTD_ONENAND is not set # CONFIG_MTD_ONENAND is not set
@@ -1945,7 +1957,9 @@ CONFIG_NET_VENDOR_I825XX=y
CONFIG_IP1000=m CONFIG_IP1000=m
CONFIG_JME=m CONFIG_JME=m
CONFIG_NET_VENDOR_MARVELL=y CONFIG_NET_VENDOR_MARVELL=y
CONFIG_MV643XX_ETH=m
CONFIG_MVMDIO=m CONFIG_MVMDIO=m
CONFIG_MVNETA=m
CONFIG_SKGE=m CONFIG_SKGE=m
# CONFIG_SKGE_DEBUG is not set # CONFIG_SKGE_DEBUG is not set
CONFIG_SKGE_GENESIS=y CONFIG_SKGE_GENESIS=y
@@ -2542,8 +2556,10 @@ CONFIG_SERIAL_8250_RSA=y
# #
# Non-8250 serial port support # Non-8250 serial port support
# #
CONFIG_SERIAL_AMBA_PL010=m CONFIG_SERIAL_AMBA_PL010=y
CONFIG_SERIAL_AMBA_PL011=m CONFIG_SERIAL_AMBA_PL010_CONSOLE=y
CONFIG_SERIAL_AMBA_PL011=y
CONFIG_SERIAL_AMBA_PL011_CONSOLE=y
# CONFIG_SERIAL_MFD_HSU is not set # CONFIG_SERIAL_MFD_HSU is not set
CONFIG_SERIAL_IMX=y CONFIG_SERIAL_IMX=y
CONFIG_SERIAL_IMX_CONSOLE=y CONFIG_SERIAL_IMX_CONSOLE=y
@@ -2627,6 +2643,7 @@ CONFIG_I2C_CBUS_GPIO=m
CONFIG_I2C_GPIO=m CONFIG_I2C_GPIO=m
CONFIG_I2C_IMX=m CONFIG_I2C_IMX=m
# CONFIG_I2C_INTEL_MID is not set # CONFIG_I2C_INTEL_MID is not set
CONFIG_I2C_MV64XXX=y
CONFIG_I2C_NOMADIK=y CONFIG_I2C_NOMADIK=y
# CONFIG_I2C_OCORES is not set # CONFIG_I2C_OCORES is not set
CONFIG_I2C_OMAP=y CONFIG_I2C_OMAP=y
@@ -2708,8 +2725,12 @@ CONFIG_PINCTRL_IMX51=y
CONFIG_PINCTRL_IMX53=y CONFIG_PINCTRL_IMX53=y
CONFIG_PINCTRL_IMX6Q=y CONFIG_PINCTRL_IMX6Q=y
CONFIG_PINCTRL_SINGLE=y CONFIG_PINCTRL_SINGLE=y
CONFIG_PINCTRL_SUNXI=y
# CONFIG_PINCTRL_EXYNOS is not set # CONFIG_PINCTRL_EXYNOS is not set
# CONFIG_PINCTRL_EXYNOS5440 is not set # CONFIG_PINCTRL_EXYNOS5440 is not set
CONFIG_PINCTRL_MVEBU=y
CONFIG_PINCTRL_ARMADA_370=y
CONFIG_PINCTRL_ARMADA_XP=y
CONFIG_PINCTRL_WMT=y CONFIG_PINCTRL_WMT=y
CONFIG_PINCTRL_WM8850=y CONFIG_PINCTRL_WM8850=y
CONFIG_ARCH_HAVE_CUSTOM_GPIO_H=y CONFIG_ARCH_HAVE_CUSTOM_GPIO_H=y
@@ -2727,6 +2748,7 @@ CONFIG_GPIO_GENERIC=y
# #
CONFIG_GPIO_GENERIC_PLATFORM=y CONFIG_GPIO_GENERIC_PLATFORM=y
# CONFIG_GPIO_EM is not set # CONFIG_GPIO_EM is not set
CONFIG_GPIO_MVEBU=y
CONFIG_GPIO_MXC=y CONFIG_GPIO_MXC=y
CONFIG_GPIO_PL061=y CONFIG_GPIO_PL061=y
# CONFIG_GPIO_RCAR is not set # CONFIG_GPIO_RCAR is not set
@@ -2828,6 +2850,7 @@ CONFIG_CHARGER_TWL4030=y
# CONFIG_BATTERY_GOLDFISH is not set # CONFIG_BATTERY_GOLDFISH is not set
CONFIG_POWER_RESET=y CONFIG_POWER_RESET=y
CONFIG_POWER_RESET_GPIO=y CONFIG_POWER_RESET_GPIO=y
CONFIG_POWER_RESET_QNAP=y
CONFIG_POWER_RESET_RESTART=y CONFIG_POWER_RESET_RESTART=y
CONFIG_POWER_RESET_VEXPRESS=y CONFIG_POWER_RESET_VEXPRESS=y
CONFIG_POWER_AVS=y CONFIG_POWER_AVS=y
@@ -2964,6 +2987,7 @@ CONFIG_THERMAL_GOV_USER_SPACE=y
CONFIG_CPU_THERMAL=y CONFIG_CPU_THERMAL=y
CONFIG_THERMAL_EMULATION=y CONFIG_THERMAL_EMULATION=y
CONFIG_IMX_THERMAL=m CONFIG_IMX_THERMAL=m
CONFIG_ARMADA_THERMAL=m
CONFIG_WATCHDOG=y CONFIG_WATCHDOG=y
CONFIG_WATCHDOG_CORE=y CONFIG_WATCHDOG_CORE=y
CONFIG_WATCHDOG_NOWAYOUT=y CONFIG_WATCHDOG_NOWAYOUT=y
@@ -4147,6 +4171,7 @@ CONFIG_USB_EHCI_TT_NEWSCHED=y
CONFIG_USB_EHCI_PCI=y CONFIG_USB_EHCI_PCI=y
CONFIG_USB_EHCI_MXC=m CONFIG_USB_EHCI_MXC=m
CONFIG_USB_EHCI_HCD_OMAP=y CONFIG_USB_EHCI_HCD_OMAP=y
CONFIG_USB_EHCI_HCD_ORION=y
CONFIG_USB_EHCI_HCD_PLATFORM=y CONFIG_USB_EHCI_HCD_PLATFORM=y
# CONFIG_USB_OXU210HP_HCD is not set # CONFIG_USB_OXU210HP_HCD is not set
# CONFIG_USB_ISP116X_HCD is not set # CONFIG_USB_ISP116X_HCD is not set
@@ -4345,6 +4370,7 @@ CONFIG_MMC_OMAP=y
CONFIG_MMC_OMAP_HS=y CONFIG_MMC_OMAP_HS=y
CONFIG_MMC_MXC=m CONFIG_MMC_MXC=m
# CONFIG_MMC_TIFM_SD is not set # CONFIG_MMC_TIFM_SD is not set
CONFIG_MMC_MVSDIO=y
# CONFIG_MMC_CB710 is not set # CONFIG_MMC_CB710 is not set
# CONFIG_MMC_VIA_SDMMC is not set # CONFIG_MMC_VIA_SDMMC is not set
CONFIG_MMC_DW=m CONFIG_MMC_DW=m
@@ -4495,6 +4521,7 @@ CONFIG_RTC_DRV_OMAP=y
CONFIG_RTC_DRV_PL030=m CONFIG_RTC_DRV_PL030=m
CONFIG_RTC_DRV_PL031=m CONFIG_RTC_DRV_PL031=m
CONFIG_RTC_DRV_VT8500=m CONFIG_RTC_DRV_VT8500=m
CONFIG_RTC_DRV_MV=m
CONFIG_RTC_DRV_MXC=m CONFIG_RTC_DRV_MXC=m
CONFIG_RTC_DRV_SNVS=m CONFIG_RTC_DRV_SNVS=m
@@ -4508,8 +4535,10 @@ CONFIG_DMADEVICES=y
# #
# DMA Devices # DMA Devices
# #
CONFIG_ASYNC_TX_ENABLE_CHANNEL_SWITCH=y
CONFIG_AMBA_PL08X=y CONFIG_AMBA_PL08X=y
# CONFIG_DW_DMAC is not set # CONFIG_DW_DMAC is not set
CONFIG_MV_XOR=y
CONFIG_MX3_IPU=y CONFIG_MX3_IPU=y
CONFIG_MX3_IPU_IRQS=4 CONFIG_MX3_IPU_IRQS=4
CONFIG_TIMB_DMA=m CONFIG_TIMB_DMA=m
@@ -4687,6 +4716,9 @@ CONFIG_COMMON_CLK=y
CONFIG_COMMON_CLK_VERSATILE=y CONFIG_COMMON_CLK_VERSATILE=y
CONFIG_COMMON_CLK_SI5351=m CONFIG_COMMON_CLK_SI5351=m
CONFIG_COMMON_CLK_AXI_CLKGEN=m CONFIG_COMMON_CLK_AXI_CLKGEN=m
CONFIG_MVEBU_CLK_CORE=y
CONFIG_MVEBU_CLK_CPU=y
CONFIG_MVEBU_CLK_GATING=y
CONFIG_HWSPINLOCK=y CONFIG_HWSPINLOCK=y
# #
@@ -4695,6 +4727,8 @@ CONFIG_HWSPINLOCK=y
CONFIG_HWSPINLOCK_OMAP=y CONFIG_HWSPINLOCK_OMAP=y
CONFIG_CLKSRC_OF=y CONFIG_CLKSRC_OF=y
CONFIG_CLKSRC_MMIO=y CONFIG_CLKSRC_MMIO=y
CONFIG_ARMADA_370_XP_TIMER=y
CONFIG_SUN4I_TIMER=y
CONFIG_VT8500_TIMER=y CONFIG_VT8500_TIMER=y
CONFIG_CADENCE_TTC_TIMER=y CONFIG_CADENCE_TTC_TIMER=y
CONFIG_ARM_ARCH_TIMER=y CONFIG_ARM_ARCH_TIMER=y
@@ -5457,7 +5491,9 @@ CONFIG_CRYPTO_USER_API=y
CONFIG_CRYPTO_USER_API_HASH=y CONFIG_CRYPTO_USER_API_HASH=y
CONFIG_CRYPTO_USER_API_SKCIPHER=y CONFIG_CRYPTO_USER_API_SKCIPHER=y
CONFIG_CRYPTO_HW=y CONFIG_CRYPTO_HW=y
# CONFIG_CRYPTO_DEV_HIFN_795X is not set CONFIG_CRYPTO_DEV_MV_CESA=m
CONFIG_CRYPTO_DEV_HIFN_795X=m
CONFIG_CRYPTO_DEV_HIFN_795X_RNG=y
CONFIG_CRYPTO_DEV_OMAP_SHAM=y CONFIG_CRYPTO_DEV_OMAP_SHAM=y
CONFIG_CRYPTO_DEV_OMAP_AES=y CONFIG_CRYPTO_DEV_OMAP_AES=y
CONFIG_ASYMMETRIC_KEY_TYPE=m CONFIG_ASYMMETRIC_KEY_TYPE=m

View File

@@ -5,6 +5,12 @@ boot/dtb-KVER-ipfire-multi
#boot/dtb-KVER-ipfire-multi/am335x-bone.dtb #boot/dtb-KVER-ipfire-multi/am335x-bone.dtb
#boot/dtb-KVER-ipfire-multi/am335x-evm.dtb #boot/dtb-KVER-ipfire-multi/am335x-evm.dtb
#boot/dtb-KVER-ipfire-multi/am335x-evmsk.dtb #boot/dtb-KVER-ipfire-multi/am335x-evmsk.dtb
#boot/dtb-KVER-ipfire-multi/armada-370-db.dtb
#boot/dtb-KVER-ipfire-multi/armada-370-mirabox.dtb
#boot/dtb-KVER-ipfire-multi/armada-370-rd.dtb
#boot/dtb-KVER-ipfire-multi/armada-xp-db.dtb
#boot/dtb-KVER-ipfire-multi/armada-xp-gp.dtb
#boot/dtb-KVER-ipfire-multi/armada-xp-openblocks-ax3-4.dtb
#boot/dtb-KVER-ipfire-multi/imx25-karo-tx25.dtb #boot/dtb-KVER-ipfire-multi/imx25-karo-tx25.dtb
#boot/dtb-KVER-ipfire-multi/imx25-pdk.dtb #boot/dtb-KVER-ipfire-multi/imx25-pdk.dtb
#boot/dtb-KVER-ipfire-multi/imx27-apf27.dtb #boot/dtb-KVER-ipfire-multi/imx27-apf27.dtb
@@ -45,6 +51,10 @@ boot/dtb-KVER-ipfire-multi
#boot/dtb-KVER-ipfire-multi/omap4-sdp.dtb #boot/dtb-KVER-ipfire-multi/omap4-sdp.dtb
#boot/dtb-KVER-ipfire-multi/omap4-var-som.dtb #boot/dtb-KVER-ipfire-multi/omap4-var-som.dtb
#boot/dtb-KVER-ipfire-multi/omap5-evm.dtb #boot/dtb-KVER-ipfire-multi/omap5-evm.dtb
#boot/dtb-KVER-ipfire-multi/sun4i-a10-cubieboard.dtb
#boot/dtb-KVER-ipfire-multi/sun4i-a10-hackberry.dtb
#boot/dtb-KVER-ipfire-multi/sun4i-a10-mini-xplus.dtb
#boot/dtb-KVER-ipfire-multi/sun5i-a13-olinuxino.dtb
#boot/dtb-KVER-ipfire-multi/vexpress-v2p-ca15-tc1.dtb #boot/dtb-KVER-ipfire-multi/vexpress-v2p-ca15-tc1.dtb
#boot/dtb-KVER-ipfire-multi/vexpress-v2p-ca15_a7.dtb #boot/dtb-KVER-ipfire-multi/vexpress-v2p-ca15_a7.dtb
#boot/dtb-KVER-ipfire-multi/vexpress-v2p-ca5s.dtb #boot/dtb-KVER-ipfire-multi/vexpress-v2p-ca5s.dtb
@@ -181,6 +191,9 @@ lib/modules/KVER-ipfire-multi
#lib/modules/KVER-ipfire-multi/kernel/drivers/clk/clk-si5351.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/clk/clk-si5351.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/cpufreq #lib/modules/KVER-ipfire-multi/kernel/drivers/cpufreq
#lib/modules/KVER-ipfire-multi/kernel/drivers/cpufreq/imx6q-cpufreq.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/cpufreq/imx6q-cpufreq.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/crypto
#lib/modules/KVER-ipfire-multi/kernel/drivers/crypto/hifn_795x.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/crypto/mv_cesa.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/dma #lib/modules/KVER-ipfire-multi/kernel/drivers/dma
#lib/modules/KVER-ipfire-multi/kernel/drivers/dma/timb_dma.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/dma/timb_dma.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/firewire #lib/modules/KVER-ipfire-multi/kernel/drivers/firewire
@@ -1135,7 +1148,9 @@ lib/modules/KVER-ipfire-multi
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/intel/ixgbe/ixgbe.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/intel/ixgbe/ixgbe.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/jme.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/jme.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell #lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/mv643xx_eth.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/mvmdio.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/mvmdio.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/mvneta.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/skge.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/skge.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/sky2.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/marvell/sky2.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/mellanox #lib/modules/KVER-ipfire-multi/kernel/drivers/net/ethernet/mellanox
@@ -1448,6 +1463,7 @@ lib/modules/KVER-ipfire-multi
#lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-m48t59.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-m48t59.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-max6900.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-max6900.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-msm6242.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-msm6242.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-mv.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-mxc.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-mxc.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-pcf8523.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-pcf8523.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-pcf8563.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/rtc/rtc-pcf8563.ko
@@ -1579,14 +1595,13 @@ lib/modules/KVER-ipfire-multi
#lib/modules/KVER-ipfire-multi/kernel/drivers/staging/usbip/usbip-host.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/staging/usbip/usbip-host.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/staging/usbip/vhci-hcd.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/staging/usbip/vhci-hcd.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/thermal #lib/modules/KVER-ipfire-multi/kernel/drivers/thermal
#lib/modules/KVER-ipfire-multi/kernel/drivers/thermal/armada_thermal.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/thermal/imx_thermal.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/thermal/imx_thermal.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty #lib/modules/KVER-ipfire-multi/kernel/drivers/tty
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/n_gsm.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/tty/n_gsm.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/n_hdlc.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/tty/n_hdlc.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/n_r3964.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/tty/n_r3964.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial #lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial/amba-pl010.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial/amba-pl011.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial/arc_uart.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial/arc_uart.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial/sccnxp.ko #lib/modules/KVER-ipfire-multi/kernel/drivers/tty/serial/sccnxp.ko
#lib/modules/KVER-ipfire-multi/kernel/drivers/uio #lib/modules/KVER-ipfire-multi/kernel/drivers/uio

View File

@@ -21,7 +21,11 @@
use strict; use strict;
use Sort::Naturally; use Sort::Naturally;
use utf8;
use feature 'unicode_strings';
no warnings 'uninitialized'; no warnings 'uninitialized';
# enable only the following on debugging purpose # enable only the following on debugging purpose
#use warnings; #use warnings;
#use CGI::Carp 'fatalsToBrowser'; #use CGI::Carp 'fatalsToBrowser';
@@ -194,6 +198,7 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
$errormessage=&checksource; $errormessage=&checksource;
if(!$errormessage){&checktarget;} if(!$errormessage){&checktarget;}
if(!$errormessage){&checkrule;} if(!$errormessage){&checkrule;}
#check if manual ip (source) is orange network #check if manual ip (source) is orange network
if ($fwdfwsettings{'grp1'} eq 'src_addr'){ if ($fwdfwsettings{'grp1'} eq 'src_addr'){
my ($sip,$scidr) = split("/",$fwdfwsettings{$fwdfwsettings{'grp1'}}); my ($sip,$scidr) = split("/",$fwdfwsettings{$fwdfwsettings{'grp1'}});
@@ -223,6 +228,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && !&validremark($fwdfwsettings{'ruleremark'})){ if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && !&validremark($fwdfwsettings{'ruleremark'})){
$errormessage=$Lang::tr{'fwdfw err remark'}."<br>"; $errormessage=$Lang::tr{'fwdfw err remark'}."<br>";
} }
if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && &validremark($fwdfwsettings{'ruleremark'})){
$errormessage='';
}
if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){ if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){
$fwdfwsettings{'nosave'} = 'on'; $fwdfwsettings{'nosave'} = 'on';
} }
@@ -264,6 +272,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && !&validremark($fwdfwsettings{'ruleremark'})){ if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && !&validremark($fwdfwsettings{'ruleremark'})){
$errormessage=$Lang::tr{'fwdfw err remark'}."<br>"; $errormessage=$Lang::tr{'fwdfw err remark'}."<br>";
} }
if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && &validremark($fwdfwsettings{'ruleremark'})){
$errormessage='';
}
if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){ if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){
$fwdfwsettings{'nosave'} = 'on'; $fwdfwsettings{'nosave'} = 'on';
} }
@@ -307,6 +318,9 @@ if ($fwdfwsettings{'ACTION'} eq 'saverule')
if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && !&validremark($fwdfwsettings{'ruleremark'})){ if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && !&validremark($fwdfwsettings{'ruleremark'})){
$errormessage=$Lang::tr{'fwdfw err remark'}."<br>"; $errormessage=$Lang::tr{'fwdfw err remark'}."<br>";
} }
if($fwdfwsettings{'oldruleremark'} ne $fwdfwsettings{'ruleremark'} && $fwdfwsettings{'updatefwrule'} eq 'on' && $fwdfwsettings{'ruleremark'} ne '' && &validremark($fwdfwsettings{'ruleremark'})){
$errormessage='';
}
if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){ if ($fwdfwsettings{'oldruleremark'} eq $fwdfwsettings{'ruleremark'}){
$fwdfwsettings{'nosave'} = 'on'; $fwdfwsettings{'nosave'} = 'on';
} }
@@ -498,8 +512,8 @@ sub checksource
return $errormessage; return $errormessage;
} }
}elsif($fwdfwsettings{'src_addr'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'src_addr'} eq ''){ }elsif($fwdfwsettings{'src_addr'} eq $fwdfwsettings{$fwdfwsettings{'grp1'}} && $fwdfwsettings{'src_addr'} eq ''){
$errormessage.=$Lang::tr{'fwdfw err nosrcip'}; $fwdfwsettings{'grp1'}='std_net_src';
return $errormessage; $fwdfwsettings{$fwdfwsettings{'grp1'}} = 'ALL';
} }
#check empty fields #check empty fields
@@ -599,8 +613,8 @@ sub checktarget
return $errormessage; return $errormessage;
} }
}elsif($fwdfwsettings{'tgt_addr'} eq $fwdfwsettings{$fwdfwsettings{'grp2'}} && $fwdfwsettings{'tgt_addr'} eq ''){ }elsif($fwdfwsettings{'tgt_addr'} eq $fwdfwsettings{$fwdfwsettings{'grp2'}} && $fwdfwsettings{'tgt_addr'} eq ''){
$errormessage.=$Lang::tr{'fwdfw err notgtip'}; $fwdfwsettings{'grp2'}='std_net_tgt';
return $errormessage; $fwdfwsettings{$fwdfwsettings{'grp2'}} = 'ALL';
} }
#check for mac in targetgroup #check for mac in targetgroup
if ($fwdfwsettings{'grp2'} eq 'cust_grp_tgt'){ if ($fwdfwsettings{'grp2'} eq 'cust_grp_tgt'){
@@ -1286,6 +1300,12 @@ sub getcolor
my $val=shift; my $val=shift;
my $hash=shift; my $hash=shift;
if($optionsfw{'SHOWCOLORS'} eq 'on'){ if($optionsfw{'SHOWCOLORS'} eq 'on'){
# Don't colourise MAC addresses
if (&General::validmac($val)) {
$tdcolor = "";
return;
}
#custom Hosts #custom Hosts
if ($nettype eq 'cust_host_src' || $nettype eq 'cust_host_tgt'){ if ($nettype eq 'cust_host_src' || $nettype eq 'cust_host_tgt'){
foreach my $key (sort keys %$hash){ foreach my $key (sort keys %$hash){
@@ -1565,7 +1585,7 @@ sub newrule
my ($sip,$scidr) = split("/",$fwdfwsettings{$fwdfwsettings{'grp1'}}); my ($sip,$scidr) = split("/",$fwdfwsettings{$fwdfwsettings{'grp1'}});
if ($scidr eq '32'){$fwdfwsettings{$fwdfwsettings{'grp1'}}=$sip;} if ($scidr eq '32'){$fwdfwsettings{$fwdfwsettings{'grp1'}}=$sip;}
my ($dip,$dcidr) = split("/",$fwdfwsettings{$fwdfwsettings{'grp2'}}); my ($dip,$dcidr) = split("/",$fwdfwsettings{$fwdfwsettings{'grp2'}});
if ($scidr eq '32'){$fwdfwsettings{$fwdfwsettings{'grp2'}}=$dip;} if ($dcidr eq '32'){$fwdfwsettings{$fwdfwsettings{'grp2'}}=$dip;}
&Header::openbox('100%', 'left', $Lang::tr{'fwdfw source'}); &Header::openbox('100%', 'left', $Lang::tr{'fwdfw source'});
#------SOURCE------------------------------------------------------- #------SOURCE-------------------------------------------------------
print "<form method='post'>"; print "<form method='post'>";
@@ -2125,6 +2145,9 @@ sub saverule
&changerule($configfwdfw); &changerule($configfwdfw);
#print"6"; #print"6";
} }
$fwdfwsettings{'ruleremark'}=~ s/,/;/g;
utf8::decode($fwdfwsettings{'ruleremark'});
$fwdfwsettings{'ruleremark'}=&Header::escape($fwdfwsettings{'ruleremark'});
if ($fwdfwsettings{'updatefwrule'} ne 'on'){ if ($fwdfwsettings{'updatefwrule'} ne 'on'){
my $key = &General::findhasharraykey ($hash); my $key = &General::findhasharraykey ($hash);
$$hash{$key}[0] = $fwdfwsettings{'RULE_ACTION'}; $$hash{$key}[0] = $fwdfwsettings{'RULE_ACTION'};
@@ -2260,22 +2283,19 @@ sub saverule
sub validremark sub validremark
{ {
# Checks a hostname against RFC1035 # Checks a hostname against RFC1035
my $remark = $_[0]; my $remark = $_[0];
# Each part should be at least two characters in length # Try to decode $remark into UTF-8. If this doesn't work,
# but no more than 63 characters # we assume that the string it not sane.
if (length ($remark) < 1 || length ($remark) > 255) { if (!utf8::decode($remark)) {
return 0;} return 0;
# Only valid characters are a-z, A-Z, 0-9 and - }
if ($remark !~ /^[a-zäöüA-ZÖÄÜ0-9-.:;\|_()\/\s]*$/) {
return 0;} # Check if the string only contains of printable characters.
# First character can only be a letter or a digit if ($remark =~ /^[[:print:]]*$/) {
if (substr ($remark, 0, 1) !~ /^[a-zäöüA-ZÖÄÜ0-9(]*$/) { return 1;
return 0;} }
# Last character can only be a letter or a digit return 0;
if (substr ($remark, -1, 1) !~ /^[a-zöäüA-ZÖÄÜ0-9.:;_)]*$/) {
return 0;}
return 1;
} }
sub viewtablerule sub viewtablerule
{ {

View File

@@ -48,7 +48,7 @@ my %fwfwd=();
my %fwinp=(); my %fwinp=();
my %fwout=(); my %fwout=();
my %ovpnsettings=(); my %ovpnsettings=();
my %netsettings=();
my $errormessage; my $errormessage;
my $hint; my $hint;
@@ -80,7 +80,7 @@ unless (-e $configsrvgrp) { system("touch $configsrvgrp"); }
&General::readhash("$configovpn", \%ovpnsettings); &General::readhash("$configovpn", \%ovpnsettings);
&General::readhasharray("$configipsec", \%ipsecconf); &General::readhasharray("$configipsec", \%ipsecconf);
&General::readhash("$configipsecrw", \%ipsecsettings); &General::readhash("$configipsecrw", \%ipsecsettings);
&General::readhash("/var/ipfire/ethernet/settings", \%netsettings);
&Header::getcgihash(\%fwhostsettings); &Header::getcgihash(\%fwhostsettings);
&Header::showhttpheaders(); &Header::showhttpheaders();
@@ -1211,12 +1211,12 @@ sub addgrp
print<<END; print<<END;
<table width='100%' border='0'> <table width='100%' border='0'>
<tr> <tr>
<td width='10%'>$Lang::tr{'fwhost addgrpname'}</td> <td style='width:15%;'>$Lang::tr{'fwhost addgrpname'}</td>
<td><form method='post'><input type='TEXT' name='grp_name' value='$fwhostsettings{'grp_name'}' size='20'></td> <td><form method='post'><input type='TEXT' name='grp_name' value='$fwhostsettings{'grp_name'}' size='30'></td>
</tr> </tr>
<tr> <tr>
<td width='10%'>$Lang::tr{'remark'}:</td> <td>$Lang::tr{'remark'}:</td>
<td ><input type='TEXT' name='remark' value='$fwhostsettings{'remark'}' style='width: 98%;'></td> <td ><input type='TEXT' name='remark' value='$fwhostsettings{'remark'}' style='width: 99%;'></td>
</tr> </tr>
<tr> <tr>
<td colspan='2'><br></td> <td colspan='2'><br></td>
@@ -1225,16 +1225,16 @@ sub addgrp
END END
}else{ }else{
print<<END; print<<END;
<table width='100%' border='0'><form method='post' style='display:inline'> <table width='100%' border='0'><form method='post'>
<tr> <tr>
<td nowrap='nowrap' width='12%'>$Lang::tr{'fwhost addgrpname'}</td> <td style='width:15%;'>$Lang::tr{'fwhost addgrpname'}</td>
<td width='20%'><input type='TEXT' name='grp' value='$fwhostsettings{'grp_name'}' ></td> <td style='width:30%;'><input type='TEXT' name='grp' value='$fwhostsettings{'grp_name'}' size='30'></td>
<td><input type='submit' value='$Lang::tr{'fwhost change'}'><input type='hidden' name='oldgrpname' value='$fwhostsettings{'oldgrpname'}'><input type='hidden' name='ACTION' value='changegrpname'></td> <td><input type='submit' value='$Lang::tr{'fwhost change'}'><input type='hidden' name='oldgrpname' value='$fwhostsettings{'oldgrpname'}'><input type='hidden' name='ACTION' value='changegrpname'></td>
<td></td></form> <td></td></form>
</tr> </tr>
<tr><form method='post' style='display:inline'> <tr><form method='post' style='display:inline'>
<td>$Lang::tr{'remark'}:</td> <td>$Lang::tr{'remark'}:</td>
<td colspan='2'><input type='TEXT' name='newrem' size='45' value='$fwhostsettings{'remark'}' style='width:98%'></td> <td colspan='2' style='width:98%;'><input type='TEXT' name='newrem' value='$fwhostsettings{'remark'}' style='width:98%;'></td>
<td align='right'><input type='submit' value='$Lang::tr{'fwhost change'}'><input type='hidden' name='oldrem' value='$fwhostsettings{'oldremark'}'><input type='hidden' name='ACTION' value='changegrpremark' ></td> <td align='right'><input type='submit' value='$Lang::tr{'fwhost change'}'><input type='hidden' name='oldrem' value='$fwhostsettings{'oldremark'}'><input type='hidden' name='ACTION' value='changegrpremark' ></td>
</tr> </tr>
</table></form> </table></form>
@@ -1246,8 +1246,16 @@ END
<form method='post'><input type='hidden' name='remark' value='$rem'><input type='hidden' name='grp_name' value='$grp'> <form method='post'><input type='hidden' name='remark' value='$rem'><input type='hidden' name='grp_name' value='$grp'>
<table width='100%' border='0'> <table width='100%' border='0'>
<tr><td width=50% valign='top'> <tr><td width=50% valign='top'>
<table width='100%' border='0'> <table width='90%' border='0'>
<tr><td width='1%'><input type='radio' name='grp2' value='std_net' id='DEFAULT_SRC_ADR' checked></td><td nowrap='nowrap' width='16%'>$Lang::tr{'fwhost stdnet'}</td><td><select name='DEFAULT_SRC_ADR' style='min-width:185px;'> <tr>
<td style='width:15em;'>
<label>
<input type='radio' name='grp2' value='std_net' id='DEFAULT_SRC_ADR' checked>
$Lang::tr{'fwhost stdnet'}
</label>
</td>
<td style='text-align:right;'>
<select name='DEFAULT_SRC_ADR' style='min-width:16em;'>
END END
foreach my $network (sort keys %defaultNetworks) foreach my $network (sort keys %defaultNetworks)
{ {
@@ -1267,14 +1275,34 @@ END
} }
print"</select></td></tr>"; print"</select></td></tr>";
if (! -z $confignet){ if (! -z $confignet){
print"<tr><td><input type='radio' name='grp2' id='CUST_SRC_NET' value='cust_net' $checked{'grp2'}{'cust_net'}></td><td>$Lang::tr{'fwhost cust net'}:</td><td><select name='CUST_SRC_NET' style='min-width:185px;'>"; print<<END;
<tr>
<td>
<label>
<input type='radio' name='grp2' id='CUST_SRC_NET' value='cust_net' $checked{'grp2'}{'cust_net'}>
$Lang::tr{'fwhost cust net'}:
</label>
</td>
<td style='text-align:right;'>
<select name='CUST_SRC_NET' style='min-width:16em;'>";
END
foreach my $key (sort { ncmp($customnetwork{$a}[0],$customnetwork{$b}[0]) } keys %customnetwork) { foreach my $key (sort { ncmp($customnetwork{$a}[0],$customnetwork{$b}[0]) } keys %customnetwork) {
print"<option>$customnetwork{$key}[0]</option>"; print"<option>$customnetwork{$key}[0]</option>";
} }
print"</select></td></tr>"; print"</select></td></tr>";
} }
if (! -z $confighost){ if (! -z $confighost){
print"<tr><td valign='top'><input type='radio' name='grp2' id='CUST_SRC_HOST' value='cust_host' $checked{'grp2'}{'cust_host'}></td><td valign='top'>$Lang::tr{'fwhost cust addr'}:</td><td><select name='CUST_SRC_HOST' style='min-width:185px;'>"; print<<END;
<tr>
<td valign='top'>
<label>
<input type='radio' name='grp2' id='CUST_SRC_HOST' value='cust_host' $checked{'grp2'}{'cust_host'}>
$Lang::tr{'fwhost cust addr'}:
</label>
</td>
<td style='text-align:right;'>
<select name='CUST_SRC_HOST' style='min-width:16em;'>";
END
foreach my $key (sort { ncmp($customhost{$a}[0],$customhost{$b}[0]) } keys %customhost) { foreach my $key (sort { ncmp($customhost{$a}[0],$customhost{$b}[0]) } keys %customhost) {
print"<option>$customhost{$key}[0]</option>"; print"<option>$customhost{$key}[0]</option>";
} }
@@ -1282,10 +1310,19 @@ END
} }
print"</table>"; print"</table>";
#Inner table right #Inner table right
print"</td><td valign='top'><table width='100%' border='0'>"; print"</td><td align='right' style='vertical-align:top;'><table width='90%' border='0'>";
#OVPN networks #OVPN networks
if (! -z $configccdnet){ if (! -z $configccdnet){
print"<td width='1%'><input type='radio' name='grp2' id='OVPN_CCD_NET' value='ovpn_net' $checked{'grp2'}{'ovpn_net'}></td><td nowrap='nowrap' width='16%'>$Lang::tr{'fwhost ccdnet'}</td><td nowrap='nowrap' width='1%'><select name='OVPN_CCD_NET' style='min-width:185px;'>"; print<<END;
<td style='width:15em;'>
<label>
<input type='radio' name='grp2' id='OVPN_CCD_NET' value='ovpn_net' $checked{'grp2'}{'ovpn_net'}>
$Lang::tr{'fwhost ccdnet'}
</label>
</td>
<td style='text-align:right;'>
<select name='OVPN_CCD_NET' style='min-width:16em;'>";
END
foreach my $key (sort { ncmp($ccdnet{$a}[0],$ccdnet{$b}[0]) } keys %ccdnet) foreach my $key (sort { ncmp($ccdnet{$a}[0],$ccdnet{$b}[0]) } keys %ccdnet)
{ {
print"<option value='$ccdnet{$key}[0]'>$ccdnet{$key}[0]</option>"; print"<option value='$ccdnet{$key}[0]'>$ccdnet{$key}[0]</option>";
@@ -1296,7 +1333,16 @@ END
foreach my $key (sort { ncmp($ccdhost{$a}[0],$ccdhost{$b}[0]) } keys %ccdhost) foreach my $key (sort { ncmp($ccdhost{$a}[0],$ccdhost{$b}[0]) } keys %ccdhost)
{ {
if ($ccdhost{$key}[33] ne ''){ if ($ccdhost{$key}[33] ne ''){
print"<td width='1%'><input type='radio' name='grp2' value='ovpn_host' $checked{'grp2'}{'ovpn_host'}></td><td nowrap='nowrap' width='16%'>$Lang::tr{'fwhost ccdhost'}</td><td nowrap='nowrap' width='1%'><select name='OVPN_CCD_HOST' style='min-width:185px;'>" if ($show eq ''); print<<END;
<td style='width:15em;'>
<label>
<input type='radio' name='grp2' value='ovpn_host' $checked{'grp2'}{'ovpn_host'}>
$Lang::tr{'fwhost ccdhost'}
</label>
</td>
<td style='text-align:right;'>
<select name='OVPN_CCD_HOST' style='min-width:16em;'>" if ($show eq '');
END
$show='1'; $show='1';
print"<option value='$ccdhost{$key}[1]'>$ccdhost{$key}[1]</option>"; print"<option value='$ccdhost{$key}[1]'>$ccdhost{$key}[1]</option>";
} }
@@ -1305,7 +1351,16 @@ END
#OVPN n2n networks #OVPN n2n networks
foreach my $key (sort { ncmp($ccdhost{$a}[1],$ccdhost{$b}[1]) } keys %ccdhost) { foreach my $key (sort { ncmp($ccdhost{$a}[1],$ccdhost{$b}[1]) } keys %ccdhost) {
if($ccdhost{$key}[3] eq 'net'){ if($ccdhost{$key}[3] eq 'net'){
print"<td width='1%'><input type='radio' name='grp2' id='OVPN_N2N' value='ovpn_n2n' $checked{'grp2'}{'ovpn_n2n'}></td><td valign='top'>$Lang::tr{'fwhost ovpn_n2n'}:</td><td colspan='3'><select name='OVPN_N2N' style='min-width:185px;'>" if ($show eq ''); print<<END;
<td style='width:15em;'>
<label>
<input type='radio' name='grp2' id='OVPN_N2N' value='ovpn_n2n' $checked{'grp2'}{'ovpn_n2n'}>
$Lang::tr{'fwhost ovpn_n2n'}:
</label>
</td>
<td style='text-align:right;'>
<select name='OVPN_N2N' style='min-width:16em;'>"
END
$show='1'; $show='1';
print"<option>$ccdhost{$key}[1]</option>"; print"<option>$ccdhost{$key}[1]</option>";
} }
@@ -1314,7 +1369,16 @@ END
#IPsec networks #IPsec networks
foreach my $key (sort { ncmp($ipsecconf{$a}[0],$ipsecconf{$b}[0]) } keys %ipsecconf) { foreach my $key (sort { ncmp($ipsecconf{$a}[0],$ipsecconf{$b}[0]) } keys %ipsecconf) {
if ($ipsecconf{$key}[3] eq 'net'){ if ($ipsecconf{$key}[3] eq 'net'){
print"<td valign='top'><input type='radio' name='grp2' id='IPSEC_NET' value='ipsec_net' $checked{'grp2'}{'ipsec_net'}></td><td valign='top'>$Lang::tr{'fwhost ipsec net'}</td><td><select name='IPSEC_NET' style='min-width:185px;'>" if ($show eq ''); print<<END;
<td style='width:15em;'>
<label>
<input type='radio' name='grp2' id='IPSEC_NET' value='ipsec_net' $checked{'grp2'}{'ipsec_net'}>
$Lang::tr{'fwhost ipsec net'}
</label>
</td>
<td style='text-align:right;'>
<select name='IPSEC_NET' style='min-width:16em;'>"
END
$show='1'; $show='1';
print"<option value='$ipsecconf{$key}[1]'>$ipsecconf{$key}[1]</option>"; print"<option value='$ipsecconf{$key}[1]'>$ipsecconf{$key}[1]</option>";
} }
@@ -1325,7 +1389,7 @@ END
print"<br><br>"; print"<br><br>";
} }
print"<table width='100%'>"; print"<table width='100%'>";
print"<tr><td align='right'><input type='submit' value='$Lang::tr{'add'}' style='min-width:100px;' /><input type='hidden' name='oldremark' value='$fwhostsettings{'oldremark'}'><input type='hidden' name='update' value=\"$fwhostsettings{'update'}\"><input type='hidden' name='ACTION' value='savegrp' ></form><form method='post' style='display:inline'><input type='submit' value='$Lang::tr{'fwhost back'}' style='min-width:100px;'><input type='hidden' name='ACTION' value='resetgrp'></form></td></table>"; print"<tr><td style='text-align:right;'><input type='submit' value='$Lang::tr{'add'}' style='min-width:100px;' /><input type='hidden' name='oldremark' value='$fwhostsettings{'oldremark'}'><input type='hidden' name='update' value=\"$fwhostsettings{'update'}\"><input type='hidden' name='ACTION' value='savegrp' ></form><form method='post' style='display:inline'><input type='submit' value='$Lang::tr{'fwhost back'}' style='min-width:100px;'><input type='hidden' name='ACTION' value='resetgrp'></form></td></table>";
&Header::closebox(); &Header::closebox();
} }
sub addservice sub addservice
@@ -1464,6 +1528,7 @@ sub viewtablenet
&General::readhasharray("$fwconfigfwd", \%fwfwd); &General::readhasharray("$fwconfigfwd", \%fwfwd);
&General::readhasharray("$fwconfiginp", \%fwinp); &General::readhasharray("$fwconfiginp", \%fwinp);
&General::readhasharray("$fwconfigout", \%fwout); &General::readhasharray("$fwconfigout", \%fwout);
if (!keys %customnetwork) if (!keys %customnetwork)
{ {
print "<center><b>$Lang::tr{'fwhost empty'}</b>"; print "<center><b>$Lang::tr{'fwhost empty'}</b>";
@@ -1490,7 +1555,7 @@ END
} }
my $colnet="$customnetwork{$key}[1]/".&General::subtocidr($customnetwork{$key}[2]); my $colnet="$customnetwork{$key}[1]/".&General::subtocidr($customnetwork{$key}[2]);
my $netcount=&getnetcount($customnetwork{$key}[0]); my $netcount=&getnetcount($customnetwork{$key}[0]);
print"<td width='20%' $col><form method='post'>$customnetwork{$key}[0]</td><td width='15%' align='center' $col>".&Header::colorize($colnet)."</td><td width='40%' $col>$customnetwork{$key}[3]</td><td align='center' $col>$netcount x</td>"; print"<td width='20%' $col><form method='post'>$customnetwork{$key}[0]</td><td width='15%' align='center' $col>".&getcolor($colnet)."</td><td width='40%' $col>$customnetwork{$key}[3]</td><td align='center' $col>$netcount x</td>";
print<<END; print<<END;
<td width='1%' $col><input type='image' src='/images/edit.gif' align='middle' alt='$Lang::tr{'edit'}' title='$Lang::tr{'edit'}' /> <td width='1%' $col><input type='image' src='/images/edit.gif' align='middle' alt='$Lang::tr{'edit'}' title='$Lang::tr{'edit'}' />
<input type='hidden' name='ACTION' value='editnet'> <input type='hidden' name='ACTION' value='editnet'>
@@ -1516,50 +1581,79 @@ END
sub getcolor sub getcolor
{ {
my $c=shift; my $c=shift;
my $sip;
my $scidr;
#Check if MAC
if (&General::validmac($c)){ return $c;}
#Check if we got a full IP with subnet then split it
if($c =~ /^(.*?)\/(.*?)$/){
($sip,$scidr) = split ("/",$c);
}else{
$sip=$c;
}
#Now check if IP is part of ORANGE,BLUE or GREEN
if ( &General::IpInSubnet($sip,$netsettings{'ORANGE_ADDRESS'},$netsettings{'ORANGE_NETMASK'})){
$tdcolor="<font style='color: $Header::colourorange;'>$c</font>";
return $tdcolor;
}
if ( &General::IpInSubnet($sip,$netsettings{'GREEN_ADDRESS'},$netsettings{'GREEN_NETMASK'})){
$tdcolor="<font style='color: $Header::colourgreen;'>$c</font>";
return $tdcolor;
}
if ( &General::IpInSubnet($sip,$netsettings{'BLUE_ADDRESS'},$netsettings{'BLUE_NETMASK'})){
$tdcolor="<font style='color: $Header::colourblue;'>$c</font>";
return $tdcolor;
}
#Check if IP is part of OpenVPN N2N subnet #Check if IP is part of OpenVPN N2N subnet
foreach my $key (sort keys %ccdhost){ foreach my $key (sort keys %ccdhost){
if ($ccdhost{$key}[3] eq 'net'){ if ($ccdhost{$key}[3] eq 'net'){
my ($a,$b) = split("/",$ccdhost{$key}[11]); my ($a,$b) = split("/",$ccdhost{$key}[11]);
if (&General::IpInSubnet($c,$a,$b)){ if (&General::IpInSubnet($sip,$a,$b)){
$tdcolor="style='color:$Header::colourovpn ;'"; $tdcolor="<font style='color:$Header::colourovpn ;'>$c</font>";
return $tdcolor; return $tdcolor;
} }
} }
} }
#Check if IP is part of OpenVPN dynamic subnet #Check if IP is part of OpenVPN dynamic subnet
my ($a,$b) = split("/",$ovpnsettings{'DOVPN_SUBNET'}); my ($a,$b) = split("/",$ovpnsettings{'DOVPN_SUBNET'});
if (&General::IpInSubnet($c,$a,$b)){ if (&General::IpInSubnet($sip,$a,$b)){
$tdcolor="style='color: $Header::colourovpn;'"; $tdcolor="<font style='color: $Header::colourovpn;'>$c</font>";
return $tdcolor; return $tdcolor;
} }
#Check if IP is part of OpenVPN static subnet #Check if IP is part of OpenVPN static subnet
foreach my $key (sort keys %ccdnet){ foreach my $key (sort keys %ccdnet){
my ($a,$b) = split("/",$ccdnet{$key}[1]); my ($a,$b) = split("/",$ccdnet{$key}[1]);
$b =&General::iporsubtodec($b); $b =&General::iporsubtodec($b);
if (&General::IpInSubnet($c,$a,$b)){ if (&General::IpInSubnet($sip,$a,$b)){
$tdcolor="style='color: $Header::colourovpn;'"; $tdcolor="<font style='color: $Header::colourovpn;'>$c</font>";
return $tdcolor; return $tdcolor;
} }
} }
#Check if IP is part of IPsec RW network #Check if IP is part of IPsec RW network
if ($ipsecsettings{'RW_NET'} ne ''){ if ($ipsecsettings{'RW_NET'} ne ''){
my ($a,$b) = split("/",$ipsecsettings{'RW_NET'}); my ($a,$b) = split("/",$ipsecsettings{'RW_NET'});
$b=&General::iporsubtodec($b); $b=&General::iporsubtodec($b);
if (&General::IpInSubnet($c,$a,$b)){ if (&General::IpInSubnet($sip,$a,$b)){
$tdcolor="style='color: $Header::colourvpn;'"; $tdcolor="<font style='color: $Header::colourvpn;'>$c</font>";
return $tdcolor; return $tdcolor;
} }
} }
#Check if IP is part of a IPsec N2N network #Check if IP is part of a IPsec N2N network
foreach my $key (sort keys %ipsecconf){ foreach my $key (sort keys %ipsecconf){
my ($a,$b) = split("/",$ipsecconf{$key}[11]); my ($a,$b) = split("/",$ipsecconf{$key}[11]);
if (&General::IpInSubnet($c,$a,$b)){ if (&General::IpInSubnet($sip,$a,$b)){
$tdcolor="style='color: $Header::colourvpn;'"; $tdcolor="<font style='color: $Header::colourvpn;'>$c</font>";
return $tdcolor; return $tdcolor;
} }
} }
$tdcolor=''; return "$c";
return $tdcolor;
} }
sub viewtablehost sub viewtablehost
{ {
@@ -1598,7 +1692,7 @@ END
$customhost{$key}[4]=~s/\s+//g; $customhost{$key}[4]=~s/\s+//g;
my $hostcount=0; my $hostcount=0;
$hostcount=&gethostcount($customhost{$key}[0]); $hostcount=&gethostcount($customhost{$key}[0]);
print"<td width='20%' $col>$customhost{$key}[0]</td><td width='20%' align='center' $col ".&getcolor($ip).">".&Header::colorize($ip)."</td><td width='50%' align='left' $col>$customhost{$key}[3]</td><td align='center' $col>$hostcount x</td>"; print"<td width='20%' $col>$customhost{$key}[0]</td><td width='20%' align='center' $col >".&getcolor($ip)."</td><td width='50%' align='left' $col>$customhost{$key}[3]</td><td align='center' $col>$hostcount x</td>";
print<<END; print<<END;
<td width='1%' $col><form method='post'><input type='image' src='/images/edit.gif' align='middle' alt='$Lang::tr{'edit'}' title='$Lang::tr{'edit'}' /> <td width='1%' $col><form method='post'><input type='image' src='/images/edit.gif' align='middle' alt='$Lang::tr{'edit'}' title='$Lang::tr{'edit'}' />
<input type='hidden' name='ACTION' value='edithost' /> <input type='hidden' name='ACTION' value='edithost' />
@@ -1709,7 +1803,7 @@ sub viewtablegrp
}else{ }else{
my ($colip,$colsub) = split("/",$ip); my ($colip,$colsub) = split("/",$ip);
$ip="$colip/".&General::subtocidr($colsub) if ($colsub); $ip="$colip/".&General::subtocidr($colsub) if ($colsub);
print"<td align='center' $col ".&getcolor($colip).">".&Header::colorize($ip)."</td><td align='center' $col>$customgrp{$key}[3]</td><td width='1%' $col><form method='post'>"; print"<td align='center' $col>".&getcolor($ip)."</td><td align='center' $col>$customgrp{$key}[3]</td><td width='1%' $col><form method='post'>";
} }
if ($delflag > 0 && $ip ne ''){ if ($delflag > 0 && $ip ne ''){
print"<input type='image' src='/images/delete.gif' align='middle' alt='$Lang::tr{'delete'}' title='$Lang::tr{'delete'}' />"; print"<input type='image' src='/images/delete.gif' align='middle' alt='$Lang::tr{'delete'}' title='$Lang::tr{'delete'}' />";
@@ -1920,7 +2014,7 @@ sub checkname
} }
sub checkgroup sub checkgroup
{ {
&General::readhasharray("$configsrvgrp", \%customservicegrp ); &General::readhasharray("$configgrp", \%customgrp );
my $name=shift; my $name=shift;
foreach my $key (keys %customservicegrp) { foreach my $key (keys %customservicegrp) {
if($customservicegrp{$key}[0] eq $name){ if($customservicegrp{$key}[0] eq $name){

View File

@@ -29,28 +29,29 @@ require "${General::swroot}/lang.pl";
require "${General::swroot}/header.pl"; require "${General::swroot}/header.pl";
require "/opt/pakfire/lib/functions.pl"; require "/opt/pakfire/lib/functions.pl";
# If the license has already been accepted.
if ( -e "/var/ipfire/main/gpl_accepted" ) {
&redirect();
}
my %cgiparams; my %cgiparams;
my $refresh;
if ( -e "/var/ipfire/main/gpl_accepted" ) {
print "Status: 302 Moved Temporarily\n";
print "Location: index.cgi\n\n";
exit (0);
}
&Header::showhttpheaders();
$cgiparams{'ACTION'} = ''; $cgiparams{'ACTION'} = '';
&Header::getcgihash(\%cgiparams); &Header::getcgihash(\%cgiparams);
&Header::openpage($Lang::tr{'main page'}, 1, $refresh); # Check if the license agreement has been accepted.
&Header::openbigbox('', 'center'); if ($cgiparams{'ACTION'} eq "$Lang::tr{'yes'}" && $cgiparams{'gpl_accepted'} eq '1') {
open(FILE, ">/var/ipfire/main/gpl_accepted");
close(FILE);
# licence agreement &redirect();
if ($cgiparams{'ACTION'} eq $Lang::tr{'yes'} && $cgiparams{'gpl_accepted'} eq '1') {
system('touch /var/ipfire/main/gpl_accepted');
} }
&Header::showhttpheaders();
&Header::openpage($Lang::tr{'main page'}, 1);
&Header::openbigbox('', 'center');
&Header::openbox('100%', 'left', $Lang::tr{'gpl license agreement'}); &Header::openbox('100%', 'left', $Lang::tr{'gpl license agreement'});
print <<END; print <<END;
$Lang::tr{'gpl please read carefully the general public license and accept it below'}. $Lang::tr{'gpl please read carefully the general public license and accept it below'}.
@@ -80,3 +81,9 @@ END
&Header::closebox(); &Header::closebox();
&Header::closebigbox(); &Header::closebigbox();
&Header::closepage(); &Header::closepage();
sub redirect {
print "Status: 302 Moved Temporarily\n";
print "Location: index.cgi\n\n";
exit (0);
}

View File

@@ -24,10 +24,10 @@
include Config include Config
VER = 3.10.32 VER = 3.10.33
RPI_PATCHES = linux-3.10.27-grsec-943b563 RPI_PATCHES = linux-3.10.27-grsec-943b563
GRS_PATCHES = grsecurity-2.9.1-3.10.32-ipfire1.patch.xz GRS_PATCHES = grsecurity-2.9.1-3.10.33-ipfire1.patch.xz
THISAPP = linux-$(VER) THISAPP = linux-$(VER)
DL_FILE = linux-$(VER).tar.xz DL_FILE = linux-$(VER).tar.xz
@@ -36,7 +36,7 @@ DIR_APP = $(DIR_SRC)/$(THISAPP)
CFLAGS = CFLAGS =
CXXFLAGS = CXXFLAGS =
PAK_VER = 37 PAK_VER = 38
DEPS = "" DEPS = ""
VERSUFIX=ipfire$(KCFG) VERSUFIX=ipfire$(KCFG)
@@ -74,9 +74,9 @@ $(DL_FILE) = $(URL_IPFIRE)/$(DL_FILE)
rpi-patches-$(RPI_PATCHES).patch.xz = $(URL_IPFIRE)/rpi-patches-$(RPI_PATCHES).patch.xz rpi-patches-$(RPI_PATCHES).patch.xz = $(URL_IPFIRE)/rpi-patches-$(RPI_PATCHES).patch.xz
$(GRS_PATCHES) = $(URL_IPFIRE)/$(GRS_PATCHES) $(GRS_PATCHES) = $(URL_IPFIRE)/$(GRS_PATCHES)
$(DL_FILE)_MD5 = 58bfaf95f4e23be2d658dab0a7fb9615 $(DL_FILE)_MD5 = 01865f9c129f3c7eee51e25b3781a364
rpi-patches-$(RPI_PATCHES).patch.xz_MD5 = 8cf81f48408306d93ccee59b58af2e92 rpi-patches-$(RPI_PATCHES).patch.xz_MD5 = 8cf81f48408306d93ccee59b58af2e92
$(GRS_PATCHES)_MD5 = b67dbf569e3f3657dad0e64ec951e1cc $(GRS_PATCHES)_MD5 = c99be0018e8bc55fb2e2b8f0ea9783d5
install : $(TARGET) install : $(TARGET)

View File

@@ -230,6 +230,20 @@ iptables_init() {
iptables -t nat -N REDNAT iptables -t nat -N REDNAT
iptables -t nat -A POSTROUTING -j REDNAT iptables -t nat -A POSTROUTING -j REDNAT
# Filter logging of incoming broadcasts.
iptables -N BROADCAST_FILTER
iptables -A INPUT -j BROADCAST_FILTER
iptables -A BROADCAST_FILTER -i "${GREEN_DEV}" -d "${GREEN_BROADCAST}" -j DROP
if [ -n "${BLUE_DEV}" -a -n "${BLUE_BROADCAST}" ]; then
iptables -A BROADCAST_FILTER -i "${BLUE_DEV}" -d "${BLUE_BROADCAST}" -j DROP
fi
if [ -n "${ORANGE_DEV}" -a -n "${ORANGE_BROADCAST}" ]; then
iptables -A BROADCAST_FILTER -i "${ORANGE_DEV}" -d "${ORANGE_BROADCAST}" -j DROP
fi
# Apply OpenVPN firewall rules # Apply OpenVPN firewall rules
/usr/local/bin/openvpnctrl --firewall-rules /usr/local/bin/openvpnctrl --firewall-rules