Commit Graph

9770 Commits

Author SHA1 Message Date
Arne Fitzenreiter
00ee4eb13c kernel: update to 3.14.59
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-25 20:15:06 +01:00
Michael Tremer
02a60a9b9e squid: Actually make --with-filedescriptors work
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-23 01:49:37 +00:00
Michael Tremer
cf82da6b37 core97: Ship updated CGI files
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-23 00:41:02 +00:00
Michael Tremer
c97698a8f4 Merge remote-tracking branch 'meitelwein/web-gui-ipv6' into next 2016-01-23 00:39:24 +00:00
Michael Tremer
665f79926d Merge remote-tracking branch 'origin/master' into next 2016-01-23 00:39:19 +00:00
Daniel Weismüller
92e4521572 cmake: Disable parallelism
Building cmake uses a high amount of memory (>2G) and
fails to build on my system. Using less processes reduces
memory usage and lets the build succeed.

Signed-off-by: Daniel Weismüller <daniel.weismueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-22 11:48:51 +00:00
Michael Tremer
20b27af863 Update translations
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-22 00:55:46 +00:00
Michael Tremer
2775ab9cc6 core97: Ship iptables conntrack changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-22 00:55:25 +00:00
Michael Tremer
8a1a3bf393 Merge remote-tracking branch 'ms/iptables-conntrack' into next 2016-01-22 00:54:14 +00:00
Michael Tremer
41410d197b Merge branch 'hyper-v-fixes' into next 2016-01-22 00:49:15 +00:00
Arne Fitzenreiter
22a504c69c toolchain: fix build on hosts that not support strong stackprotect
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-20 19:28:56 +01:00
Michael Tremer
928eba27a5 core97: Ship updated webaccess.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-19 00:07:07 +00:00
Erik Kapfer
bcb30674e2 webaccess.cgi: Fixed language settings.
Fix for #10879. Added also use strict.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-19 00:06:30 +00:00
Michael Tremer
857b2c795e Improve hardening by using -fstack-protector-strong
This functionality is now available for us since we updated
to GCC 4.9 and just improves the stack smashing protector
in GCC.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-18 22:26:23 +00:00
Matthias Fischer
cc9f461f74 nano: Update to 2.5.1
Excerpt form 'NEWS':
"It includes fixes for a syntax-highlighting bug and a positionlog bug,
it disables a time-eating multiline regex in the C syntax,
and it adds an escape hatch to the WriteOut menu when
--tempfile is used: the discardbuffer command, ^Q.  It
also has translation updates for fifteen languages, and
a small fix in the softwrap code."

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-17 18:52:09 +00:00
Michael Tremer
037cf8d20d core97: Ship updated openssh
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-17 18:51:47 +00:00
Matthias Fischer
43e5fe9ded openssh: Update to 7.1p2
Fixes CVE-2016-0777

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-17 18:49:38 +00:00
Michael Tremer
64285d23eb Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2016-01-17 18:49:03 +00:00
Arne Fitzenreiter
9b4f0e6397 toolchain: bump version number
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-15 07:20:34 +01:00
Arne Fitzenreiter
3da3ac9856 gcc: remove gdb python files also in root build.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-14 16:08:24 +01:00
Arne Fitzenreiter
8f2ac12a87 toolchain: move *.py remove to correct pass.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-14 03:55:54 +01:00
Arne Fitzenreiter
6e96dd142a toolchain: enable bootstrap and remove *.py files from lib.
only with bootstrap the gcc pass2 build works on arm.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-13 19:04:56 +01:00
Arne Fitzenreiter
905d1afd4e kernel: disable RANDSTRUCT
RANDSRUCT is incompatible with ccache build.

fixes #10905
fixes #11012

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-13 07:24:34 +01:00
Michael Tremer
cfdeb28050 core97: Ship updated ntp
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 21:20:49 +00:00
Matthias Fischer
db017b4b6e ntp 4.2.8p5: removed obsolete patch file
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 21:18:22 +00:00
Matthias Fischer
c1de76704a ntp: Update to 4.2.8p5
"...addresses 1 medium-severity security issue, 14 bugfixes,
and contains other improvements over 4.2.8p4."

For a complete list, see:
http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 21:18:20 +00:00
Michael Tremer
b75b6382ab grub: Disable hardening for grub-script-check
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 19:35:42 +00:00
Michael Tremer
1d9be34e2a ccache: Include hash of compiler specs in hashing
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-09 19:48:48 +00:00
Michael Eitelwein
43638be58b No code changes, fixed formatting by replacing spaces with tabs 2016-01-09 20:09:58 +01:00
Michael Tremer
cec5c724f5 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2016-01-09 14:56:33 +00:00
Michael Tremer
16260e2c69 timectrl: Stop ntp daemon when disabled
Fixes #11000

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-07 23:47:39 +00:00
Michael Eitelwein
1b5b6c91da Fixed detection of firewall chain when bridge is used for ipv6
Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
2016-01-07 19:40:24 +01:00
Michael Eitelwein
a249e865bd Firewall chain was not extracted correctly when ipv6 uses bridge
Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
2016-01-07 19:26:46 +01:00
Arne Fitzenreiter
764a3f1ff2 toolchain: fix full toolchain crossbuild
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-07 17:41:43 +01:00
Arne Fitzenreiter
2eb67894ef binutils: update to 2.24
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-07 17:41:16 +01:00
Michael Eitelwein
f97c6774ef Fix regex to extract firewall chain for ipv6 in showrequestfrom*.dat
If bridged ipv6 is used, $iface is taken from PHYSIN
In the log line the order of fields is "... IN=XY OUT=XY PHYSIN=XY ..."

Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
2016-01-07 15:24:13 +01:00
Michael Eitelwein
9877d28d9e Enable correct display of ipv6 entries in Firewall log pages of web UI.
3 main changes:
 - Fill $iface and $out from PHYSIN and PHYSOUT when looking at bridged packets, othwerwise fill from IN and OUT
 - Recognize ipv4 and ipv6 address style for $srcaddr and $dstaddr
 - Match color coding of tables to pie charts (see seperate patch sent earlier)

I am using the bridged ipv6 setup as proposed in the wiki. I do not think this breaks anything when not using ipv6. So it would be nice to include this even if ipv6 is not officially supported yet. It is quite useful when using the ipv6 setup.

Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
---
2016-01-07 14:00:01 +01:00
Daniel Weismüller
820a4ab564 owncloud: updated to version 7.0.11
Signed-off-by: Daniel Weismüller <daniel.weismueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-06 15:09:16 +00:00
Michael Tremer
f81e27e1c8 dnsdist: Don't build on ARM
There seem to be some serious C++ issues in this so that
it won't build on ARM.

At the moment I do not have any resources to look further
into this, so I just disable building this package for
all ARM architectures.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-06 15:05:37 +00:00
Michael Tremer
b0a014b7f8 QoS: Improve saving enabled/disable state
It was reported that the QoS did not stop when
the user clicked the "stop" button. This patch
fixes that.

Fixes #10664

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Acked-by: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org>
2016-01-05 21:04:05 +00:00
Michael Tremer
9a09d94ee3 qosctrl: Cleanup code by replacing hardcoded paths
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-05 20:44:26 +00:00
Michael Tremer
84032d0845 core97: Ship updated openvpn package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-04 22:46:13 +00:00
Erik Kapfer
964700d414 openvpn: Update to version 2.3.7, added --verify-x509-name directive.
The tls-remote directive is deprecated and will be removed with
OpenVPN version 2.4 . Added instead --verify-x509-name HOST name
into ovpnmain.cgi.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-04 22:41:46 +00:00
Matthias Fischer
9977da131b bind: Update to 9.10.3-P2
Changelog:

[security]
Update allowed OpenSSL versions as named is potentially
vulnerable to CVE-2015-3193.

[maint]
H.ROOT-SERVERS.NET is 198.97.190.53 and 2001:500:1::53. [RT #40556]

[security]
Insufficient testing when parsing a message allowed
records with an incorrect class to be be accepted,
triggering a REQUIRE failure when those records
were subsequently cached. (CVE-2015-8000) [RT #40987]

[security]
Address fetch context reference count handling error
on socket error. (CVE-2015-8461) [RT#40945]

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-28 15:37:41 +01:00
Michael Tremer
21ac63688a core97: Ship dnsmasq
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-28 15:37:02 +01:00
Matthias Fischer
c3b4c861f5 dnsmasq 2.75: latest patches from upstream
Same procedure as... :-)

Best to all for xmas and 2016!

Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-28 15:35:34 +01:00
Michael Tremer
2135528774 core97: Ship pgrep with the updater
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2015-12-28 15:30:13 +01:00
Arne Fitzenreiter
4df3276bb4 ncurses: rootfile update.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-12-26 17:37:53 +01:00
Arne Fitzenreiter
b94e0ffc68 dnsdist: rootfile update.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-12-26 17:34:13 +01:00
Arne Fitzenreiter
b37e91c3b5 diffutils: rootfile update.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2015-12-26 17:33:30 +01:00