Commit Graph

9780 Commits

Author SHA1 Message Date
Arne Fitzenreiter
552fb4b8b5 dhcpcd: rework mtu handling on buggy nic's
some nic's loose the carrier after setting new mtu.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-02-01 07:31:46 +01:00
Arne Fitzenreiter
57d98918a1 kernel: update to 3.14.60
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-29 14:25:25 +01:00
Arne Fitzenreiter
35b24ff8a9 set core to 98 and move 97 to oldcore
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-28 22:10:11 +01:00
Arne Fitzenreiter
78574c1846 finish core97
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-28 16:20:16 +01:00
Arne Fitzenreiter
a6c7164277 openssl: security update to 1.0.2f
changes:
* DH small subgroups - CVE-2016-0701
* SSLv2 doesn't block disabled ciphers - CVE-2015-3197
* Reject DH handshakes with parameters shorter than 1024 bits

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-28 15:58:46 +01:00
Arne Fitzenreiter
eb2f4a4d26 hwdate: update databases
pci.ids: 2016.01.28
usb.ids: 2015.12.17

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-28 13:24:50 +01:00
Arne Fitzenreiter
ecd5019097 core97: prepare new core97 with openssl and openssh update.
the update itself has to be done...

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-28 13:08:59 +01:00
Arne Fitzenreiter
6fa8a1a9cc rename core97 to 98 because we have to insert OpenSSL security update
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-28 13:03:39 +01:00
Arne Fitzenreiter
235888599a backports: update to 4.2.6
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-28 13:02:09 +01:00
Arne Fitzenreiter
8998dde892 rsync: update to 3.1.2
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-26 18:02:00 +01:00
Arne Fitzenreiter
00ee4eb13c kernel: update to 3.14.59
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-25 20:15:06 +01:00
Michael Tremer
02a60a9b9e squid: Actually make --with-filedescriptors work
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-23 01:49:37 +00:00
Michael Tremer
cf82da6b37 core97: Ship updated CGI files
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-23 00:41:02 +00:00
Michael Tremer
c97698a8f4 Merge remote-tracking branch 'meitelwein/web-gui-ipv6' into next 2016-01-23 00:39:24 +00:00
Michael Tremer
665f79926d Merge remote-tracking branch 'origin/master' into next 2016-01-23 00:39:19 +00:00
Daniel Weismüller
92e4521572 cmake: Disable parallelism
Building cmake uses a high amount of memory (>2G) and
fails to build on my system. Using less processes reduces
memory usage and lets the build succeed.

Signed-off-by: Daniel Weismüller <daniel.weismueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-22 11:48:51 +00:00
Michael Tremer
20b27af863 Update translations
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-22 00:55:46 +00:00
Michael Tremer
2775ab9cc6 core97: Ship iptables conntrack changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-22 00:55:25 +00:00
Michael Tremer
8a1a3bf393 Merge remote-tracking branch 'ms/iptables-conntrack' into next 2016-01-22 00:54:14 +00:00
Michael Tremer
41410d197b Merge branch 'hyper-v-fixes' into next 2016-01-22 00:49:15 +00:00
Arne Fitzenreiter
22a504c69c toolchain: fix build on hosts that not support strong stackprotect
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-20 19:28:56 +01:00
Michael Tremer
928eba27a5 core97: Ship updated webaccess.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-19 00:07:07 +00:00
Erik Kapfer
bcb30674e2 webaccess.cgi: Fixed language settings.
Fix for #10879. Added also use strict.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-19 00:06:30 +00:00
Michael Tremer
857b2c795e Improve hardening by using -fstack-protector-strong
This functionality is now available for us since we updated
to GCC 4.9 and just improves the stack smashing protector
in GCC.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-18 22:26:23 +00:00
Matthias Fischer
cc9f461f74 nano: Update to 2.5.1
Excerpt form 'NEWS':
"It includes fixes for a syntax-highlighting bug and a positionlog bug,
it disables a time-eating multiline regex in the C syntax,
and it adds an escape hatch to the WriteOut menu when
--tempfile is used: the discardbuffer command, ^Q.  It
also has translation updates for fifteen languages, and
a small fix in the softwrap code."

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-17 18:52:09 +00:00
Michael Tremer
037cf8d20d core97: Ship updated openssh
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-17 18:51:47 +00:00
Matthias Fischer
43e5fe9ded openssh: Update to 7.1p2
Fixes CVE-2016-0777

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-17 18:49:38 +00:00
Michael Tremer
64285d23eb Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2016-01-17 18:49:03 +00:00
Arne Fitzenreiter
9b4f0e6397 toolchain: bump version number
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-15 07:20:34 +01:00
Arne Fitzenreiter
3da3ac9856 gcc: remove gdb python files also in root build.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-14 16:08:24 +01:00
Arne Fitzenreiter
8f2ac12a87 toolchain: move *.py remove to correct pass.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-14 03:55:54 +01:00
Arne Fitzenreiter
6e96dd142a toolchain: enable bootstrap and remove *.py files from lib.
only with bootstrap the gcc pass2 build works on arm.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-13 19:04:56 +01:00
Arne Fitzenreiter
905d1afd4e kernel: disable RANDSTRUCT
RANDSRUCT is incompatible with ccache build.

fixes #10905
fixes #11012

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-13 07:24:34 +01:00
Michael Tremer
cfdeb28050 core97: Ship updated ntp
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 21:20:49 +00:00
Matthias Fischer
db017b4b6e ntp 4.2.8p5: removed obsolete patch file
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 21:18:22 +00:00
Matthias Fischer
c1de76704a ntp: Update to 4.2.8p5
"...addresses 1 medium-severity security issue, 14 bugfixes,
and contains other improvements over 4.2.8p4."

For a complete list, see:
http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 21:18:20 +00:00
Michael Tremer
b75b6382ab grub: Disable hardening for grub-script-check
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-10 19:35:42 +00:00
Michael Tremer
1d9be34e2a ccache: Include hash of compiler specs in hashing
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-09 19:48:48 +00:00
Michael Eitelwein
43638be58b No code changes, fixed formatting by replacing spaces with tabs 2016-01-09 20:09:58 +01:00
Michael Tremer
cec5c724f5 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2016-01-09 14:56:33 +00:00
Michael Tremer
16260e2c69 timectrl: Stop ntp daemon when disabled
Fixes #11000

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-07 23:47:39 +00:00
Michael Eitelwein
1b5b6c91da Fixed detection of firewall chain when bridge is used for ipv6
Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
2016-01-07 19:40:24 +01:00
Michael Eitelwein
a249e865bd Firewall chain was not extracted correctly when ipv6 uses bridge
Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
2016-01-07 19:26:46 +01:00
Arne Fitzenreiter
764a3f1ff2 toolchain: fix full toolchain crossbuild
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-07 17:41:43 +01:00
Arne Fitzenreiter
2eb67894ef binutils: update to 2.24
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2016-01-07 17:41:16 +01:00
Michael Eitelwein
f97c6774ef Fix regex to extract firewall chain for ipv6 in showrequestfrom*.dat
If bridged ipv6 is used, $iface is taken from PHYSIN
In the log line the order of fields is "... IN=XY OUT=XY PHYSIN=XY ..."

Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
2016-01-07 15:24:13 +01:00
Michael Eitelwein
9877d28d9e Enable correct display of ipv6 entries in Firewall log pages of web UI.
3 main changes:
 - Fill $iface and $out from PHYSIN and PHYSOUT when looking at bridged packets, othwerwise fill from IN and OUT
 - Recognize ipv4 and ipv6 address style for $srcaddr and $dstaddr
 - Match color coding of tables to pie charts (see seperate patch sent earlier)

I am using the bridged ipv6 setup as proposed in the wiki. I do not think this breaks anything when not using ipv6. So it would be nice to include this even if ipv6 is not officially supported yet. It is quite useful when using the ipv6 setup.

Signed-off-by: Michael Eitelwein <michael@eitelwein.net>
---
2016-01-07 14:00:01 +01:00
Daniel Weismüller
820a4ab564 owncloud: updated to version 7.0.11
Signed-off-by: Daniel Weismüller <daniel.weismueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-06 15:09:16 +00:00
Michael Tremer
f81e27e1c8 dnsdist: Don't build on ARM
There seem to be some serious C++ issues in this so that
it won't build on ARM.

At the moment I do not have any resources to look further
into this, so I just disable building this package for
all ARM architectures.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2016-01-06 15:05:37 +00:00
Michael Tremer
b0a014b7f8 QoS: Improve saving enabled/disable state
It was reported that the QoS did not stop when
the user clicked the "stop" button. This patch
fixes that.

Fixes #10664

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
Acked-by: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org>
2016-01-05 21:04:05 +00:00