Commit Graph

12864 Commits

Author SHA1 Message Date
Stéphane Pautrel
6af131d714 Update of French translation
Loads of strings have been translated for the first time
and others have been improved.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-26 15:59:31 +00:00
Matthias Fischer
fe5e64997a nano: Update to 3.2
Hi,

Changed archive to 'xz' - this saves about 1.4MB (thanks Marcel ;-))

For further details see:
https://www.nano-editor.org/news.php

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-25 14:10:50 +00:00
Michael Tremer
380350300f openssl: Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-25 13:45:11 +00:00
Michael Tremer
22aefdbe83 docker: Install wget in docker environment
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-23 22:23:27 +00:00
Arne Fitzenreiter
fad2f37646 kernel: update to 4.14.83
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-23 22:05:14 +01:00
Michael Tremer
4e4327994d docker: Add Debian image with basic build environment
By running "./make.sh docker" the current build environment
will be mounted into a Debian-based docker container.

This clean build environment can be used to compile the
toolchain or something...

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-23 19:48:16 +00:00
Arne Fitzenreiter
000ece0135 kernel: update to 4.14.82
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-21 23:55:54 +01:00
Michael Tremer
928b3cbf66 openssl: Update to 1.1.0j
*) Timing vulnerability in DSA signature generation

     The OpenSSL DSA signature algorithm has been shown to be vulnerable to a
     timing side channel attack. An attacker could use variations in the signing
     algorithm to recover the private key.

     This issue was reported to OpenSSL on 16th October 2018 by Samuel Weiser.
     (CVE-2018-0734)
     [Paul Dale]

  *) Timing vulnerability in ECDSA signature generation

     The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a
     timing side channel attack. An attacker could use variations in the signing
     algorithm to recover the private key.

     This issue was reported to OpenSSL on 25th October 2018 by Samuel Weiser.
     (CVE-2018-0735)
     [Paul Dale]

  *) Add coordinate blinding for EC_POINT and implement projective
     coordinate blinding for generic prime curves as a countermeasure to
     chosen point SCA attacks.
     [Sohaib ul Hassan, Nicola Tuveri, Billy Bob Brumley]

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-21 11:21:42 +00:00
Michael Tremer
5ca47910a7 openssl-compat: Update to 1.0.2q
*) Microarchitecture timing vulnerability in ECC scalar multiplication

     OpenSSL ECC scalar multiplication, used in e.g. ECDSA and ECDH, has been
     shown to be vulnerable to a microarchitecture timing side channel attack.
     An attacker with sufficient access to mount local timing attacks during
     ECDSA signature generation could recover the private key.

     This issue was reported to OpenSSL on 26th October 2018 by Alejandro
     Cabrera Aldaya, Billy Brumley, Sohaib ul Hassan, Cesar Pereida Garcia and
     Nicola Tuveri.
     (CVE-2018-5407)
     [Billy Brumley]

  *) Timing vulnerability in DSA signature generation

     The OpenSSL DSA signature algorithm has been shown to be vulnerable to a
     timing side channel attack. An attacker could use variations in the signing
     algorithm to recover the private key.

     This issue was reported to OpenSSL on 16th October 2018 by Samuel Weiser.
     (CVE-2018-0734)
     [Paul Dale]

  *) Resolve a compatibility issue in EC_GROUP handling with the FIPS Object
     Module, accidentally introduced while backporting security fixes from the
     development branch and hindering the use of ECC in FIPS mode.
     [Nicola Tuveri]

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-20 16:28:52 +00:00
Michael Tremer
6170b25363 Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-19 18:58:48 +00:00
Arne Fitzenreiter
67640833a2 kernel: arm32 bit fix config and update rootfile
Some drivers was disabled by oldconfig because i had
arm multiarch patchsed. This commit reenable it.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-18 20:24:43 +01:00
Alexander Rudolf Gruber
4684118009 kernel: enable HW of clearfog
clearfog base need MARVELL Phy and SDHCI Xenon enabled.
2018-11-18 17:36:44 +01:00
Arne Fitzenreiter
5ed864857a kernel: disable FW_LOADER_USER_HELPER_FALLBACK
newer (e)udev has dropped the support for this.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-18 14:33:45 +01:00
Arne Fitzenreiter
16c18024bb kernel: compress kernel modules with xz
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-18 14:30:14 +01:00
Arne Fitzenreiter
668f91c37c kernel: update to 4.14.81 2018-11-18 14:29:44 +01:00
Michael Tremer
e91ceed69a alac: New package
This adds the Apple ALAC audio decoder

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-13 14:28:00 +00:00
Michael Tremer
3a7dd58834 core126: Ship libconfig
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-12 00:16:23 +00:00
Michael Tremer
93aa56a698 Start Core Update 126
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-12 00:15:28 +00:00
Michael Tremer
9fbbf3fda2 shairport-sync: Add install/uninstall scripts
These scripts will install symlinks to start the service
at boot time.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 18:57:55 +00:00
Michael Tremer
6dc7b04bea shairport-sync: Add initscript
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 18:55:35 +00:00
Michael Tremer
b7dbcd158d shairport-sync: Explicitely link against soxr
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 18:52:10 +00:00
Michael Tremer
63dc6532d1 shairport-sync: Add backup include file
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 17:34:11 +00:00
Michael Tremer
c708fa157f shairport-sync: New package
Shairport Sync is an AirPlay audio player - it plays audio streamed
from iTunes, iOS, Apple TV and macOS devices and AirPlay sources
such as Quicktime Player and ForkedDaapd, among others.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 17:26:35 +00:00
Michael Tremer
f3e6230125 libconfig: New package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 17:23:20 +00:00
Michael Tremer
41f8d64284 soxr: New package (0.1.3)
The SoX Resampler library `libsoxr' performs one-dimensional sample-rate
conversion -- it may be used, for example, to resample PCM-encoded audio.
For higher-dimensional resampling, such as for visual-image processing, you
should look elsewhere.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 16:21:01 +00:00
Michael Tremer
5187740ed2 mpd: Depends on avahi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-11 15:44:17 +00:00
Arne Fitzenreiter
8e68bb83c6 xen-image: enlarge partitions and remove extra /var partition
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-10 11:03:37 +01:00
Arne Fitzenreiter
a0f3748747 core125: finish update
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-09 21:12:02 +01:00
Arne Fitzenreiter
f52ef2ce5a core125: restart init after glibc uodate
without restart remount of / will fail and may result in
a filesystem corruption at next boot.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-09 21:09:06 +01:00
Michael Tremer
db6b40500c lang: Show the full untranslated string
This will help translators to add missing strings easier

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-09 15:03:27 +00:00
Michael Tremer
014b235a06 dehydrated: New package
This is a light client for Let's Encrypt which is implemented
in bash and does not have any other dependencies apart from
openssl and curl.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-09 14:29:04 +00:00
Michael Tremer
524dae818f update accelerator: Do not attempt to cache IPFire updates any more
We do not deliver anything via HTTP or FTP any more and therefore
nothing can be cached any more.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-08 16:46:11 +00:00
Michael Tremer
01a3c346dd update accelerator: Cache .msp files for Adobe
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-08 16:45:30 +00:00
Michael Tremer
f9e4f4dcdf Update list of contributors
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-08 16:42:37 +00:00
Michael Tremer
492b0b7c18 backupiso: Add support for aarch64
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-08 16:02:17 +00:00
Michael Tremer
8a0bc03450 backupiso: Fix order of variables
Some values in variables were corrected but used before.

Reported-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-08 15:58:58 +00:00
Michael Tremer
47bb9dd1e8 observium-agent: Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-08 15:07:17 +00:00
Michael Tremer
95c60d31aa udev: Do not try to change kernel hotplug handler any more
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:27:35 +00:00
Michael Tremer
e300a3d138 udev: Do no try to install any device nodes any more
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:26:34 +00:00
Michael Tremer
85759cc973 core125: Ship syslog changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:17:08 +00:00
Peter Müller
5f0726b560 Tor: update to 0.3.4.9
For details and release announcement, see:
https://blog.torproject.org/new-release-tor-0349

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:14:49 +00:00
Matthias Fischer
f4b6cdfbe7 bind: Update to 9.11.5
For details see:
http://ftp.isc.org/isc/bind9/9.11.5/RELEASE-NOTES-bind-9.11.5.html

Security fixes:
"named could crash during recursive processing of DNAME records when
deny-answer-aliases was in use. This flaw is disclosed in CVE-2018-5740. [GL #387]

When recursion is enabled but the allow-recursion and allow-query-cache ACLs are
not specified, they should be limited to local networks, but they were
inadvertently set to match the default allow-query, thus allowing
remote queries. This flaw is disclosed in CVE-2018-5738. [GL #309]"

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:07:53 +00:00
Michael Tremer
01c2ea6b83 observium-agent: New package
This ships the observium agent including a couple of
modules.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:07:53 +00:00
Michael Tremer
c19d29f701 Revert "haproxy: Make /dev/log available in chroot"
This reverts commit 699f0aa710.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:07:53 +00:00
Michael Tremer
9f60aa9679 syslog: Listen to network and block access from anywhere but localhost
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-11-07 20:07:53 +00:00
Arne Fitzenreiter
6104f2e816 backupiso: fix boot on EFI
the grub on EFI serch the config on volume "IPFire 2.21 arch"
so the custom "ipfire backup ..." volume name is not working
anymore.
This is now fixed and a backup-version.media tag will added.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-07 19:16:57 +01:00
Arne Fitzenreiter
84902aa499 backup: fix backupiso mastering
fixes: #11916

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-04 10:16:26 +01:00
Arne Fitzenreiter
912c590bb6 clamav: fix rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-04 08:41:43 +01:00
Arne Fitzenreiter
e9dbafa8a1 freeradius: rootfile update
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-11-03 21:08:52 +01:00
Arne Fitzenreiter
582775709f clamav: rootfile update 2018-11-03 21:08:30 +01:00