Commit Graph

3806 Commits

Author SHA1 Message Date
Vincent Li
88c90aadcd ddos: add ddos init script
add ddos init to load/attach XDP DDoS main
program with empty tail call table as place
holder for tcp, udp, icmp...etc XDP DDoS program

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2025-04-01 13:38:02 -07:00
Vincent Li
0f9937c78f xdp-tools: Add XDP synproxy tailcall program
LoongArch does not support bpf trampoline, so
use tail call to call XDP synproxy program

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2025-03-25 19:41:42 -07:00
Vincent Li
04a4907087 loxicmd: add loxicmd for loongarch64
Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2025-01-29 08:36:00 -08:00
Vincent Li
beb7cdabf7 loxilb: add loxilb 0.9.8 addon for loongarch64
loxilb ebpf program relies on libbpf 0.8
which does not have loongarch64 support.
backported libbpf 1.2.3 loongarch support
to libbpf 0.8

loxilb 0.9.8 now load ebpf program through
libbpf, no external ntc command required, so
remove ntc

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2025-01-28 19:09:10 -08:00
Vincent Li
8c30bad8f8 xdp-tailcall: add xdp-tailcall init script
xdp-tailcall init script to start/stop XDP
tail call program DNS and TLS SNI on green0
interface

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2025-01-10 10:56:15 -08:00
Vincent Li
dec6a99c77 xdp-tools: add xdp-tailcall
Loongarch64 does not support bpf trampoline
and freplace, so we can't use libxdp to attach
multiple XDP program to same network interface.

Loongarch64 supports bpf tail call, so we can still
use xdp-loader to load XDP program, and use bpf tail
call to call each XDP program. now we can tail call
DNS and TLS SNI XDP program on green0 interface

change user space program to take bpf map path as
command line argument so X86 and Loongarch64 can share
same user space program

https://github.com/vincentmli/xdp-tools

commit d18f8a7b48094c861a8ee0d5c0d52e93a01edca4
Author: Vincent Li <vincent.mc.li@gmail.com>
Date:   Tue Jan 7 22:14:40 2025 -0800

    xdp-tools: add bpf map path as cmd line argument

    add XDP DNS and TLS SNI user space program command
    line argument for bpf map so X86 and Loongarch can
    share the same XDP user space program

commit 5d713b40dd2d0ce399f618179a2add6c07882e2a
Author: Vincent Li <vincent.mc.li@gmail.com>
Date:   Mon Jan 6 21:09:25 2025 -0800

    xdp-tailcall: add DNS XDP program

    add DNS XDP program as tail called program

commit ad2a4e600140f8bf7a577470566efcdf11f6e214
Author: Vincent Li <vincent.mc.li@gmail.com>
Date:   Mon Jan 6 20:36:43 2025 -0800

    xdp-tailcall: add XDP tailcall

    Loongarch64 does not support bpf trampoline and
    freplace, so use tail call to call XDP program.

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2025-01-07 15:41:25 -08:00
Vincent Li
304abcd541 tcpdump: move tcpdump strace to core package
Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-25 11:46:30 -08:00
Vincent Li
cfefb2a884 xdp-tools: add xdp-tools
Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-22 11:28:31 -08:00
Vincent Li
d88bdd74b3 perf: add linux perf tool
Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-21 18:00:47 -08:00
Vincent Li
51ff36eb32 bpftool: add bpftool
Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-21 17:57:09 -08:00
Vincent Li
708556b443 libbpf: add libbpf
Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-21 17:56:33 -08:00
Vincent Li
379faf9f47 suricata: enable compile and install suricata
add rust back and enable compile and install suricata

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-21 15:50:47 -08:00
Vincent Li
2e5f7966ac yt6801: add yt6801 driver for loongson NUC
yt6801 ethernet driver is out of kernel tree
add lfs/yt6801 to build yt6801 driver

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-20 14:05:08 -08:00
Vincent Li
342323fa0c initscripts: stop fireinfo startup during boot
fireinfo startup script requires user intervention
due to python error, remove it for now

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-19 12:42:27 -08:00
Vincent Li
23ae73dde4 loongarch64: major changes for flash image and iso
Initial list of changes required to build iso
and flash image successfully:

1 softwares require config.guess and config.stub
  update with loongarch support

2 no rust build and no suricata which depends on rust

3 comment out python 3.10 lib-dynload and config-3.10-xxxMACHINExxx-linux-gnu

4 lfs/cdrom lfs/Config loongarch seems requiring capital EFI boot image name
  to boot properly

5 comment out a few softwares that are not needed for now

iso can be installed to loongarch PC hard drive, but
fail to boot.

flash image can be dd to USB drive, then boot loongarch
PC from USB drive, then dd from USB drive to loongarch
PC hard drive

Signed-off-by: Vincent Li <vincent.mc.li@gmail.com>
2024-12-19 11:42:59 -08:00
Stefan Schantl
1a4d5cfd92 openssh: Introduce include directory for additional sshd config files
This patch adds the prosibility to place additional *.config files in /etc/ssh/sshd_config.d/
which will be included and loaded during the daemon startup process.

Because this files will not be overwritten by any update, they can be used to place custom
or other persistent settings.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-12-13 14:36:51 +00:00
Arne Fitzenreiter
1e2abd66fb linux-firmware: ship needed config txt files.
these files are parsed by the kernel at firmware load and are needed!
don't remove it again.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-11-26 12:02:50 +01:00
Arne Fitzenreiter
5380ebc7c3 kernel: rootfile update aarch64
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-11-20 15:51:39 +01:00
Arne Fitzenreiter
adb153f64f miniupnpc: change to addon pak
transmission need the lib at runtime.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-11-19 20:32:30 +01:00
Arne Fitzenreiter
28636c46cb collectd: fix errormessage on fresh installations
the /etc/collectd.d/ folder must have at least one file in it
so this add an file with a comment that custom configs should placed
there.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-11-09 09:46:53 +01:00
Matthias Fischer
ce45a76778 bind: Update to 9.20.3
For details see:
https://downloads.isc.org/isc/bind9/9.20.3/doc/arm/html/notes.html#notes-for-bind-9-20-3

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-11-05 09:17:29 +01:00
Matthias Fischer
07abe4e2f6 unbound: Update to 1.22.0
For details see:
https://nlnetlabs.nl/projects/unbound/download/#unbound-1-22-0

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-11-05 09:15:06 +01:00
Arne Fitzenreiter
06452d0db6 gdb: rootfile update
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-29 13:03:16 +01:00
Arne Fitzenreiter
61a8c7dcdb kernel: fix riscv64 rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-27 09:48:23 +01:00
Arne Fitzenreiter
461de40d1a kernel: update riscv64 config and rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-26 10:06:12 +02:00
Arne Fitzenreiter
187336d851 gdb: update rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-26 10:01:08 +02:00
Arne Fitzenreiter
30da3342c1 ruby: make rootfile arch independend
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-26 09:54:31 +02:00
Arne Fitzenreiter
2d4e78dd24 gdb: update aarch64 rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-24 08:22:54 +02:00
Arne Fitzenreiter
9aca5e215a whatmask: update rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-16 21:29:15 +02:00
Arne Fitzenreiter
68d79b957a pkg-config: update rootfile
:
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-16 21:28:27 +02:00
Arne Fitzenreiter
5b1ae54e57 perl-MIME-Tools: update rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-16 21:27:34 +02:00
Arne Fitzenreiter
26c3a972a7 perl-Archive-Zip: update rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-16 21:26:16 +02:00
Arne Fitzenreiter
5c1555e420 autoconf-archive: update rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-16 21:25:17 +02:00
Arne Fitzenreiter
a9ec615940 cmake: update rootfile
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-16 21:24:16 +02:00
Michael Tremer
522632655c kernel: Enable IO uring
This is a feature more and more tools start using now and will help to
keep performance of the OS up.

This was enabled on riscv64 already.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-10-14 09:03:23 +00:00
Arne Fitzenreiter
019f139b20 kernel: update to 6.6.56
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-11 13:17:53 +02:00
Arne Fitzenreiter
c45abd5f1c rtl8812au: add missing rootfile.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2024-10-11 13:15:23 +02:00
Adolf Belka
5fd4ca19a8 mpfire: removal as discussed in Conf call 7th Oct
- removal of lfs, rootfile, backup, paks, misc-progs, mpfire perl, language file
   content, mpfire.cgi, mpfire menu references and files, mpfire specific image,
   web-user-interface references and references in manualpages.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-10-09 18:25:53 +00:00
Adolf Belka
8e33ca3246 ppp: Update to version 2.5.1
- Update from version commit e1266c7 to 2.5.1
- Version 2.5.1 has around 34 additional commits from e1266c7. To me all look minor
   changes, some related to other system types such as Solaris that we don't use.
- Update of rootfile
- They have added example to the configuration files to prevent accidental overwriting
   of configuration systems.
- Changelog - There is no longer any changelog provided. Even the one that used to
   exist for version 2.5.0 has been removed. The only option now is to look through the
   commits - https://github.com/ppp-project/ppp/commits/master/?before=d5aeec65752d4a9b3bb46771d0b221c4a4a6539e+35
- Some of the patches had to be updated as the changes were enough that some hunks did
   not get found for patching. Patch file number 6 has been removed as the sed lines are
   no longer to be found in the configure file. The other files that patched successfully
   were renamed to 2.5.1

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-10-09 18:25:03 +00:00
Michael Tremer
e28cb28628 Merge branch 'master' into next 2024-10-07 10:23:22 +00:00
Michael Tremer
7eec7e2c8b ncat: Make this package part of the core system
The nc command is required for the Unbound/DHCP leases bridge.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-10-07 10:19:14 +00:00
Michael Tremer
388802662f Merge branch 'master' into next 2024-10-07 09:15:04 +00:00
Matthias Fischer
b38609d64d unbound: Update to 1.21.1
For details see:
https://nlnetlabs.nl/projects/unbound/download/#unbound-1-21-1

"Fix CVE-2024-8508, unbounded name compression could lead to denial of service."

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-10-04 11:45:37 +00:00
Adolf Belka
c2cd03024f miniupnpc: Required for build of transmission to replace bundled version
- miniupnpc is required for the build of transmiossion but the bundled version was not
   working properly with version 4.0.6 and we prefer to not use bundled versions.
- Only used for the build so rootfile is 100% commented out. No miniupnpc installed
   on IPFire.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-09-24 10:03:22 +00:00
Jonatan Schlag
a070e76010 Ship Compress/Raw/Zlib.pm
This is needed for the captive portal. This was maybe caused by
008eca2c2f .

Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-09-24 09:59:59 +00:00
Michael Tremer
6ca5fb74ab Merge branch 'master' into next 2024-09-24 08:54:50 +00:00
Michael Tremer
17887e69a8 suricata: Add a watcher to restart on unexpected termination
This patch adds a watcher process that will restart suricata when it is
being killed by SIGKILL (e.g. by the OOM killer) or after a SEGV.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-09-24 08:42:32 +00:00
Adolf Belka
853e1e41e9 curl: Update to version 8.10.0
- Update from vesion 8.9.1 to 8.10.0
- Update of rootfile
- In previous versions if libpsl was not found then the build excluded it. Now it needs
   to be explicitly disabled otherwise the build will stop with a warning that it could
   not be found.
- Changelog
    8.10.0
      changes:
	 o autotools: add `--enable-windows-unicode` option [103]
	 o curl: --help [option] displays documentation for given cmdline option [19]
	 o curl: add --skip-existing [54]
	 o curl: for -O, use "default" as filename when the URL has none [34]
	 o curl: make --rate accept "number of units" [4]
	 o curl: make --show-headers the same as --include [6]
	 o curl: support --dump-header % to direct to stderr [31]
	 o curl: support embedding a CA bundle and --dump-ca-embed [20]
	 o curl: support repeated use of the verbose option; -vv etc [35]
	 o curl: use libuv for parallel transfers with --test-event [82]
	 o getinfo: add CURLINFO_POSTTRANSFER_TIME_T [87]
	 o mbedtls: add CURLOPT_TLS13_CIPHERS support [78]
	 o rustls: add support for setting TLS version and ciphers [113]
	 o vtls: stop offering alpn http/1.1 for http2-prior-knowledge [53]
	 o wolfssl: add CURLOPT_TLS13_CIPHERS support [76]
	 o wolfssl: add support for ssl cert blob / ssl key blob options [50]
      bugfixes:
	 o asyn-thread: stop using GetAddrInfoExW on Windows [241]
	 o autotools: fix MS-DOS builds [249]
	 o autotools: fix typo in tests/data target [30]
	 o aws_sigv4: fix canon order for headers with same prefix [74]
	 o bearssl: fix setting tls version [203]
	 o bearssl: improve shutdown handling [45]
	 o BINDINGS: add zig binding [100]
	 o build: add `iphlpapi` lib for libssh on Windows [166]
	 o build: add `poll()` detection for cross-builds [244]
	 o build: add options to disable SHA-512/256 hash algo [239]
	 o build: check OS-native IDN first, then libidn2 [223]
	 o build: delete unused `REQUIRE_LIB_DEPS` [226]
	 o build: drop unused `NROFF` reference [253]
	 o build: drop unused feature-detection code for Apple `poll()` [227]
	 o build: generate `buildinfo.txt` for test logs [256]
	 o build: improve compiler version detection portability
	 o build: make `CURL_FORMAT_CURL_OFF_T[U]` work with mingw-w64 <=7.0.0 [207]
	 o build: silence C4232 MSVC warnings in vcpkg ngtcp2 builds [137]
	 o build: use -Wno-format-overflow [195]
	 o buildconf.bat: fix tool_hugehelp.c generation [173]
	 o cf-socket: fix pollset for listening [179]
	 o cf-socket: prevent KEEPALIVE_FACTOR being set to 1000 for Windows [185]
	 o cfilters: send flush [13]
	 o CHANGES: rename to CHANGES.md, no longer generated [40]
	 o CI: enable parallel testing in CI builds [18]
	 o ci: Update actions/upload-artifact digest to 89ef406 [24]
	 o cmake: `Libs.private` improvements [215]
	 o cmake: add `CURL_USE_PKGCONFIG` option [138]
	 o cmake: add Linux CI job, fix pytest with cmake [71]
	 o cmake: add math library when using wolfssl and ngtcp2 [66]
	 o cmake: add missing `pkg-config` hints to Find modules [158]
	 o cmake: add missing version detection to Find modules [170]
	 o cmake: add rustls [116]
	 o cmake: add support for versioned symbols option [51]
	 o cmake: add wolfSSH support [117]
	 o cmake: allow `pkg-config` in more envs [147]
	 o cmake: cleanup header paths [59]
	 o cmake: default `CURL_DISABLE_LDAPS` to the value of `CURL_DISABLE_LDAP` [231]
	 o cmake: delete MSVC warning suppression for tests/server [101]
	 o cmake: detect `nghttp2` via `pkg-config`, enable by default [21]
	 o cmake: detect and show VCPKG in platform flags [84]
	 o cmake: distcheck for files in CMake subdir [9]
	 o cmake: drop custom `CMakeOutput.log`/`CMakeError.log` logs [27]
	 o cmake: drop libssh CONFIG-style detection [167]
	 o cmake: drop no-op `tests/data/CMakeLists.txt` [26]
	 o cmake: drop reference to undefined variable [25]
	 o cmake: drop unused `HAVE_IDNA_STRERROR` [62]
	 o cmake: drop unused internal variable [22]
	 o cmake: exclude tests/http/clients builds by default [110]
	 o cmake: fix `GSS_VERSION` for Heimdal found via pkg-config [77]
	 o cmake: fix `pkg-config`-based detection in `FindGSS.cmake` [94]
	 o cmake: fix and tidy up c-ares builds, enable in more CI jobs [156]
	 o cmake: fix find rustls [148]
	 o cmake: fixup linking libgsasl when detected via CMake-native
	 o cmake: honor custom `CMAKE_UNITY_BUILD_BATCH_SIZE` [163]
	 o cmake: limit `pkg-config` to UNIX and MSVC+vcpkg by default [188]
	 o cmake: limit libidn2 `pkg-config` detection to `UNIX` [109]
	 o cmake: migrate dependency detections to Find modules [183]
	 o cmake: more small tidy-ups and fixes [80]
	 o cmake: rename wolfSSL and zstd config variables to uppercase [151]
	 o cmake: respect cflags/libdirs of native pkg-config detections [175]
	 o cmake: show CMake platform/compiler flags [63]
	 o cmake: show warning if libpsl is not found [154]
	 o cmake: sync code between test/example targets [234]
	 o cmake: sync up formatting in Find modules [129]
	 o cmake: TLS 1.3 warning only for bearssl and sectranp [118]
	 o cmake: update `curl-config.cmake.in` template var list
	 o cmake: update list of "advanced" variables [119]
	 o cmake: use numeric comparison for `HAVE_WIN32_WINNT` [69]
	 o cmdline-opts: language fix for expect100-timeout.md and max-time.md [192]
	 o configure: delete unused `CURL_DEFINE_UNQUOTED` function [224]
	 o configure: delete unused `HAVE_OPENSSL3` macro [225]
	 o configure: delete unused `m4/xc-translit.m4` [114]
	 o configure: detect AppleIDN [70]
	 o configure: fail if PSL is not disabled but not found [46]
	 o configure: fix WinIDN builds targeting old Windows [210]
	 o configure: remove USE_EXPLICIT_LIB_DEPS [199]
	 o configure: replace nonportable grep -o with awk [111]
	 o connect: always prefer ipv6 in IP eyeballing [209]
	 o connect: limit update IP info [191]
	 o cookie.md: try to articulate the two different uses this option has [92]
	 o curl: allow 500MB data URL encode strings [38]
	 o curl: find curlrc in XDG_CONFIG_HOME without leading dot [186]
	 o curl: fix --proxy-pinnedpubkey [91]
	 o curl: fix the -w urle.* variables [153]
	 o curl: make the progress bar detect terminal width changes [169]
	 o curl: warn on unsupported SSL options [106]
	 o Curl_rand_bytes to control env override [17]
	 o curl_sha512_256: fix symbol collisions with nettle library [131]
	 o CURLMOPT_SOCKETFUNCTION.md: expand on the easy argument [216]
	 o CURLOPT_XFERINFOFUNCTION: clarify the callback return codes [141]
	 o dist: add missing `docs/examples/CMakeLists.txt` [58]
	 o dist: add missing `FindNettle.cmake` [11]
	 o dist: add missing `lib/optiontable.pl` [115]
	 o dist: add missing `test_*.py` scripts [102]
	 o dist: drop buildconf [65]
	 o dist: fix reproducible build from release tarball [36]
	 o dmaketgz: only run 'make distclean' if Makefile exists
	 o docs/SSLCERTS: rewrite [174]
	 o docs: add description of effect of --location-trusted on cookie [157]
	 o docs: document the (weak) random value situation in rustls builds [252]
	 o docs: fix some examples in man pages
	 o docs: improve cipher options documentation [159]
	 o docs: mention "@-" in more places [67]
	 o docs: remove ALTSVC.md, HSTS.md, HTTP2.md and PARALLEL-TRANSFERS.md [105]
	 o docs: update CIPHERS.md [140]
	 o doh-url.md: point out DOH server IP pinning [37]
	 o doh: remove redundant checks [242]
	 o easy: fix curl_easy_upkeep for shared connection caches [52]
	 o escape: allow curl_easy_escape to generate 3*input length output [39]
	 o FEATURES.md: fix typo [180]
	 o ftp: always offer line end conversions [219]
	 o ftp: flush pingpong before response [73]
	 o getinfo: return zero for unsupported options (when disabled) [189]
	 o GHA/windows: enable MulitSSL in an MSVC job [2]
	 o GHA: scan git repository and detect unvetted binary files [3]
	 o gnutls/wolfssl: improve error message when certificate fails [125]
	 o gnutls: send all data [230]
	 o gtls: fix OCSP stapling management [206]
	 o haproxy: send though next filter [222]
	 o hash: provide asserts to verify API use [96]
	 o http/2: simplify eos/blocked handling [90]
	 o http2+h3 filters: fix ctx init [142]
	 o http2: fix GOAWAY message sent to server [171]
	 o http2: improve rate limiting of downloads [33]
	 o http2: improved upload eos handling [41]
	 o http3.md: mention how the fallback can be h1 or h2 [194]
	 o hyper: call Curl_req_set_upload_done() [126]
	 o idn: more strictly check AppleIDN errors [98]
	 o idn: support non-UTF-8 input under AppleIDN [99]
	 o INSTALL.md: MultiSSL and QUIC are mutually exclusive [7]
	 o KNOWN_BUGS: "special characers" in URL works with aws-sigv4 [81]
	 o krb5: add Linux/macOS CI tests, fix cmake GSS detection [83]
	 o krb5: fix `-Wcast-align` [95]
	 o lib: add eos flag to send methods [14]
	 o lib: avoid macro collisions between wolfSSL and GnuTLS headers [133]
	 o lib: convert some debugf()s into traces [8]
	 o lib: delete stray undefs for `vsnprintf`, `vsprintf` [152]
	 o lib: fix AIX build issues [112]
	 o lib: fix building with wolfSSL without DES support [134]
	 o lib: make SSPI global symbols use Curl_ prefix [251]
	 o lib: prefer `CURL_SHA256_DIGEST_LENGTH` over the unprefixed name [132]
	 o lib: remove the final strncpy() calls [240]
	 o lib: remove use of RANDOM_FILE [235]
	 o libcurl.def: move from / into lib [238]
	 o libcurl.pc: add `Cflags.private` [10]
	 o libcurl.pc: add reference to `libgsasl` [150]
	 o libcurl/docs: expand on redirect following and secrets to other hosts [85]
	 o llist: remove direct struct accesses, use only functions [72]
	 o Makefile.dist: fix `ca-firefox` target [254]
	 o Makefile.mk: fixup enabling libidn2 [61]
	 o Makefile: remove 'scripts' duplicate from DIST_SUBDIRS
	 o maketgz: accept option to include latest commit hash [5]
	 o maketgz: fix RELEASE-TOOLS.md for daily tarballs [243]
	 o maketgz: move from / into scripts [237]
	 o managen: fix superfluous leading blank line in quoted sections [211]
	 o managen: in man output, remove the leading space from examples [198]
	 o managen: wordwrap long example lines in ASCII output [143]
	 o manpage: ensure a maximum width for the text version [75]
	 o max-filesize.md: mention zero disables the limit [93]
	 o mbedtls: add more informative logging [162]
	 o mbedtls: fix setting tls version [200]
	 o mbedtls: no longer use MBEDTLS_SSL_VERIFY_OPTIONAL [181]
	 o mime: avoid inifite loop in client reader [155]
	 o mk-ca-bundle.pl: include a link to the caextract webpage [68]
	 o multi: make the "general" list of easy handles a Curl_llist [97]
	 o multi: on socket callback error, remove socket hash entry nonetheless [149]
	 o ngtcp2/osslq: remove NULL pointer dereferences [213]
	 o ngtcp2: use NGHTTP3 prefix instead of NGTCP2 for errors in h3 callbacks [79]
	 o openssl quic: fix memory leak [229]
	 o openssl: certinfo errors now fail correctly [250]
	 o openssl: fix the data race when sharing an SSL session between threads [221]
	 o openssl: improve shutdown handling [44]
	 o pingpong: drain the input buffer when reading responses [193]
	 o POP3: fix multi-line responses [168]
	 o pop3: use the protocol handler ->write_resp [220]
	 o printf: fix mingw-w64 format checks [228]
	 o progress: ratelimit/progress tweaks [32]
	 o pytests: add tests for HEAD requests in all HTTP versions [42]
	 o rand: only provide weak random when needed [233]
	 o runtests: if DISABLED cannot be read, error out [56]
	 o runtests: log ignored but passed tests [130]
	 o runtests: remove "has_textaware" [217]
	 o rustls: fix setting tls version [202]
	 o rustls: make all tests pass [1]
	 o schannel: avoid malloc for CAinfo_blob_digest [247]
	 o scorecard: tweak request measurements [139]
	 o sectransp: fix setting tls version [204]
	 o SECURITY: mention OpenSSF best practices gold badge [161]
	 o setopt: allow CURLOPT_INTERFACE to be set to NULL [165]
	 o setopt: let CURLOPT_ECH set to NULL reset to default [187]
	 o setopt: make CURLOPT_TFTP_BLKSIZE accept bad values [184]
	 o sha256: fix symbol collision between nettle (GnuTLS) and OpenSSL [135]
	 o share: don't reinitialize conncache [214]
	 o sigpipe: init the struct so that first apply ignores [49]
	 o smb: convert superflous assign into assert [246]
	 o smtp: add tracing feature [120]
	 o splay: use access functions, add asserts, use Curl_timediff [121]
	 o spnego_gssapi: implement TLS channel bindings for openssl [146]
	 o src: delete `curlx_m*printf()` aliases [197]
	 o src: fix potential macro confusion in cmake unity builds [208]
	 o src: namespace symbols clashing with lib [248]
	 o src: replace copy of printf mappings with an include [190]
	 o ssh: deduplicate SSH backend includes (and fix libssh cmake unity build) [177]
	 o system_win32: fix typo
	 o test httpd: tweak cipher list [124]
	 o test1521: verify setting options to NULL better [182]
	 o test1707: output diff more for debugging differences in CI outputs
	 o test556: improve robustness [64]
	 o test579: improve robustness [60]
	 o test587: improve robustness [123]
	 o test649: improve robustness [122]
	 o test677: improve robustness [47]
	 o tests/runner: only allow [!A-Za-z0-9_-] in %if feature names [55]
	 o tests: constrain http pytest to tests/http directory [205]
	 o tests: don't mangle output if hostname or type unknown
	 o tests: ignore QUIT from FTP protocol comparisons [108]
	 o tests: provide docs as curldown, not nroff [12]
	 o tidy-up: misc build, tests, `lib/macos.c` [172]
	 o tidy-up: OS names [57]
	 o tool_operhlp: fix  "potentially uninitialized local variable 'pc' used" [48]
	 o tool_paramhlp: bump maximum post data size in memory to 16GB [128]
	 o transfer: Curl_sendrecv() and event related improvements [164]
	 o transfer: remove comments, add asserts [218]
	 o transfer: skip EOS read when download done [196]
	 o url: dns_entry related improvements [16]
	 o url: fix connection reuse for HTTP/2 upgrades [236]
	 o urlapi: verify URL *decoded* hostname when set [160]
	 o urldata: introduce `data->mid`, a unique identifier inside a multi [127]
	 o urldata: remove 'scratch' from the UrlState struct [86]
	 o urldata: remove crlf_conversions counter [232]
	 o urldata: remove proxy_connect_closed bit [178]
	 o verify-release: shell script that verifies a release tarball [29]
	 o version: fix shadowing a `libssh.h` symbol [176]
	 o vtls: add SSLSUPP_CIPHER_LIST [107]
	 o vtls: fix MSVC 'cast truncates constant value' warning [23]
	 o vtls: fix static function name collisions between TLS backends [136]
	 o vtls: init ssl peer only once [15]
	 o websocket: introduce blocking sends [145]
	 o wolfssl: avoid taking cached x509 store ref if sslctx already using it [88]
	 o wolfssl: fix CURLOPT_SSLVERSION [144]
	 o wolfssl: fix setting tls version [201]
	 o wolfssl: improve shutdown handling [43]
	 o ws: flags to opcodes should ignore CURLWS_CONT flag [104]
	 o x509asn1: raise size limit for x509 certification information [28]

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-09-23 21:22:09 +00:00
Michael Tremer
8ce034f7d2 core189: Ship libfdt (from dtc)
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-09-23 17:43:35 +00:00
Peter Müller
578b22e4d7 apr: Update to 1.7.5
Full changelog of this release:

  *) SECURITY: CVE-2023-49582: Apache Portable Runtime (APR):
     Unexpected lax shared memory permissions (cve.mitre.org)
     Lax permissions set by the Apache Portable Runtime library on
     Unix platforms would allow local users read access to named
     shared memory segments, potentially revealing sensitive
     application data.
     This issue does not affect non-Unix platforms, or builds with
     APR_USE_SHMEM_SHMGET=1 (apr.h)
     Users are recommended to upgrade to APR version 1.7.5, which
     fixes this issue.
     Credits: Thomas Stangner

  *) Unix: Implement apr_shm_perms_set() for the "POSIX shm_open()"
     and "classic mmap" shared memory implementations.  [Joe Orton,
     Ruediger Pluem]

  *) Fix missing ';' for XML/HTML hex entities from apr_escape_entity().
     [Yann Ylavic]

  *) Fix crash in apr_pool_create() with --enable-pool-debug=all|owner.
     [Yann Ylavic]

  *) Improve platform detection by updating config.guess and config.sub.
     [Rainer Jung]

  *) CMake: Add support for CMAKE_WARNING_AS_ERROR. [Ivan Zhakov]

  *) CMake: Enable support for MSVC runtime library selection by abstraction.
     [Ivan Zhakov]

  *) CMake: Export installed targets (libapr-1, apr-1, libaprapp-1, aprapp-1)
     to apr:: namespace. [Ivan Zhakov]

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2024-09-22 14:38:08 +00:00