Commit Graph

13381 Commits

Author SHA1 Message Date
Michael Tremer
d6d058a56b core120: Update pakfire keystore
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-03 17:34:24 +01:00
Michael Tremer
6ae5439e5c core120: Ship changed pakfire files
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-03 17:33:04 +01:00
Michael Tremer
9a507db2cb pakfire: Store key material in own directory
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-03 17:31:50 +01:00
Arne Fitzenreiter
592896d2f4 u-boot: update bootscript to boot from other devices than mmc
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-04-03 05:26:54 +00:00
Arne Fitzenreiter
783f6aa36d Merge remote-tracking branch 'origin/master' into kernel-4.14 2018-04-03 20:15:58 +02:00
Arne Fitzenreiter
6703371d2d Merge remote-tracking branch 'origin/core120' into kernel-4.14 2018-04-02 17:11:45 +02:00
Arne Fitzenreiter
718119b897 Merge branch 'master' into core119 2018-04-02 16:56:02 +02:00
Michael Tremer
4d888e6854 curl: Drop old compatibility symlink
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:50:09 +01:00
Michael Tremer
e7cda9ac7f curl: Rootfile update
Main library was missing

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:48:50 +01:00
Michael Tremer
0471d32b85 core120: Import new pakfire keys
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:46:40 +01:00
Michael Tremer
74e715a5a2 pakfire: Import old key, too
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:46:40 +01:00
Michael Tremer
397d3a8e15 pakfire: Rename new key to pakfire-2018.key
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:46:40 +01:00
Michael Tremer
3e29608f82 pakfire: Validate signatures when multiple are available
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:45:48 +01:00
Arne Fitzenreiter
3e7dee5951 core120: add pakfire script to updater
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-04-02 11:22:19 +02:00
Arne Fitzenreiter
0d98de5a44 kernel: update to 4.14.32
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-04-01 16:15:27 +02:00
Arne Fitzenreiter
1b06675c00 openssl: update rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-31 10:02:01 +02:00
Arne Fitzenreiter
e12d216eec kernel: x86_64 rootfile update
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-31 09:56:48 +02:00
Arne Fitzenreiter
b465322d7c kernel: x86_64 enable DEVFREQ modules
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-30 16:39:02 +02:00
Arne Fitzenreiter
302dba205b Merge remote-tracking branch 'origin/master' into kernel-4.14 2018-03-30 10:26:01 +02:00
Arne Fitzenreiter
018a19af64 kernel: update to 4.14.31
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-30 10:21:49 +02:00
Arne Fitzenreiter
36600cef36 Merge branch 'core119' into next 2018-03-30 09:35:28 +02:00
Arne Fitzenreiter
6a8b2ef977 core120: set pafire version to 120
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-30 09:25:06 +02:00
Michael Tremer
f7e9c14842 Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-29 13:49:44 +01:00
Michael Tremer
4b072d640e pakfire: Use upstream proxy for HTTPS, too
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-28 16:55:18 +01:00
Peter Müller
66a0f3646a use protocol defined in server-list.db for mirror communication
For each mirror server, a protocol can be specified in the
server-list.db database. However, it was not used for the
actual URL query to a mirror before.

This might be useful for deploy HTTPS pinning for Pakfire.
If a mirror is known to support HTTPS, all queries to it
will be made with this protocol.

This saves some overhead if HTTPS is enforced on a mirror
via 301 redirects. To enable this, the server-list.db
needs to be adjusted.

The second version of this patch only handles protocols
HTTP and HTTPS, since we do not expect anything else here
at the moment.

Partially fixes #11661.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-28 16:42:21 +01:00
Michael Tremer
9f0999325d unbound: Fix crash on startup
Zone names should not be terminated with a dot.

Fixes: #11689

Reported-by: Pontus Larsson <pontuslarsson51@yahoo.se>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-28 16:39:35 +01:00
Michael Tremer
d97f43b309 Rootfile update for curl
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-28 11:22:06 +01:00
Michael Tremer
d9e656bb82 asterisk: Ship documentation
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-27 20:56:31 +01:00
Michael Tremer
d3cd99830a fetchmail: Permit building without SSLv3
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-27 20:53:31 +01:00
Michael Tremer
76f422025f openssl: Update to 1.0.2o
CVE-2018-0739 (OpenSSL advisory) [Moderate severity] 27 March 2018:

Constructed ASN.1 types with a recursive definition (such as can be
found in PKCS7) could eventually exceed the stack given malicious
input with excessive recursion. This could result in a Denial Of
Service attack. There are no such structures used within SSL/TLS
that come from untrusted sources so this is considered safe.
Reported by OSS-fuzz.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-27 16:05:07 +01:00
Michael Tremer
166ceacd6b openssl: Update to 1.1.0h
CVE-2018-0739 (OpenSSL advisory) [Moderate severity] 27 March 2018:

Constructed ASN.1 types with a recursive definition (such as can be
found in PKCS7) could eventually exceed the stack given malicious
input with excessive recursion. This could result in a Denial Of
Service attack. There are no such structures used within SSL/TLS
that come from untrusted sources so this is considered safe.
Reported by OSS-fuzz.

This patch also entirely removes support for SSLv3. The patch to
disable it didn't apply and since nobody has been using this before,
we will not compile it into OpenSSL any more.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-27 16:03:44 +01:00
Michael Tremer
c98304604b core120: Ship updated QoS script and gnupg
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-26 19:04:41 +01:00
Matthias Fischer
be7878d5c9 Fix typo in 'makeqosscripts.pl'
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-26 19:03:30 +01:00
Peter Müller
dd48a7aac8 curl: update to 7.59.0
Update curl to 7.59.0 which fixes a number of bugs and
some minor security issues.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-26 19:03:29 +01:00
Peter Müller
689fed340a gnupg: update to 1.4.22
Update GnuPG to 1.4.22, which fixes some security vulnerabilities,
such as the memory side channel attack CVE-2017-7526.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-26 19:03:24 +01:00
Arne Fitzenreiter
50bee0291d xr819-firmware: move rootfile to common
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-26 07:29:51 +02:00
Arne Fitzenreiter
66b5b4d12c kernel: update to 4.14.30
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-25 20:26:47 +02:00
Arne Fitzenreiter
37b86fa99b xr819-firmware: add firmware for xradio xr-819 wlan
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-25 13:27:03 +02:00
Arne Fitzenreiter
0a21d63f26 kernel: updated arm config and image build
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-25 11:41:20 +02:00
Arne Fitzenreiter
ea9d53c822 inittab: change tty1 to console
this reduce the differences between tty and scon installations
and make it easier to switch between.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-24 13:26:32 +01:00
Arne Fitzenreiter
5bc33236ca swconfig: remove old swconfig utility
this is not compatible with kernel 4.14
todo: replace swconfig calls in initskript

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-24 12:49:10 +01:00
Arne Fitzenreiter
4df5cc2f75 rpi-firmware: update to 2018-03-16
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-24 12:41:57 +01:00
Arne Fitzenreiter
151c8dfc0b checknewlog: don't report u-boot mkimage rootfile.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-24 11:41:45 +01:00
Arne Fitzenreiter
2a0947f2e3 u-boot: update to 2018.03
todo: check wandboard version. there are internal changes to merge
the different wandboard images to one and u-boot.imx is not build
anymore. Which file is needed to boot on wandboard?

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-24 11:14:24 +01:00
Arne Fitzenreiter
832770a868 kernel: update to 4.14.29
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-03-22 13:16:37 +01:00
Michael Tremer
dfdfafc7af core120: Ship updated vnstat
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-20 20:36:15 +00:00
Matthias Fischer
a05af852c5 vnstat: Update to 1.18
For details see: https://humdi.net/vnstat/CHANGES

Changed "SaveInterval 5" to "SaveInterval 1" in '/etc/vnstat.conf', triggered by
https://forum.ipfire.org/viewtopic.php?f=22&t=20448 to avoid data loss with 1Gbit
connections and high traffic.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-20 20:35:30 +00:00
Michael Tremer
e7ea357cec Forgot to "git add" the new pakfire init script
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-20 11:08:58 +00:00
Michael Tremer
42deeb3b45 Revert "installer: Import the Pakfire key at install time"
This reverts commit 7d995c9f56.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-19 19:45:24 +00:00
Michael Tremer
eb68e27dd2 pakfire: Import key when system boots up
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-19 19:44:50 +00:00