Commit Graph

6042 Commits

Author SHA1 Message Date
Stefan Schantl
dfee7582f9 Increase performance of the squidclamav redirector.
To boost up the performance, now we trust the proxy cache.

I add some changes to the proxy.cgi to configure the proxy and the
squidclamav in the right way.

I also add a hook that allows us to generate a new configuration
if the cgi script will be launched from the shell.

Fixes #10367.
2013-06-30 11:21:42 +02:00
Arne Fitzenreiter
a08dc91970 transmission: update to 2.80. 2013-06-30 10:25:03 +02:00
Arne Fitzenreiter
ddafd799ce kernel: update to 3.2.48. 2013-06-30 00:04:32 +02:00
Arne Fitzenreiter
f691d2ca97 alsa: update to 1.0.27.1. 2013-06-27 06:36:38 +02:00
Arne Fitzenreiter
801674282b swatch: fix rootfiles for arm build. 2013-06-25 10:30:39 +02:00
Arne Fitzenreiter
1f06c5f84e iw: update to 3.8. 2013-06-24 23:25:25 +02:00
Arne Fitzenreiter
57648683a3 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2013-06-24 15:05:43 +02:00
Arne Fitzenreiter
3baa74d41a wireless-regdb: update to 2013.2.13. 2013-06-24 15:04:26 +02:00
Arne Fitzenreiter
3530dc9bf3 crda: update to 1.1.3. 2013-06-24 15:03:46 +02:00
Michael Tremer
057dbeebb2 Consider 100.64.0.0/10 as private address space.
http://tools.ietf.org/html/rfc6598
  http://forum.ipfire.org/index.php?topic=7504.0
2013-06-24 11:46:23 +02:00
Michael Tremer
1d19cd87ec Don't package packlists for perl packages. 2013-06-24 10:39:35 +02:00
Michael Tremer
bca7488392 Merge remote-tracking branch 'jlentfer/swatch' into next
Conflicts:
	make.sh
2013-06-24 10:36:21 +02:00
Jan Lentfer
85981472c3 new addon: swatch - Simple log file watcher
http://sourceforge.net/projects/swatch/

With swatch you can easily monitor (growing) log files
in realtime and create email alerts based on log file content.

e.g. with a config file like this:
watchfor /Priority\: ([1|2])/
echo=normal
mail=alerts@your.domain,subject=[SNORT] Priority $1 Alert

and a swatch command like this:
swatch --daemon -c /var/ipfire/snort/swatchrc --input-record-separator='\n\n' -t /var/log/snort/alert

you can setup email alerts for SNORT alerts.

This still needs an active MTA (e.g. dma or postfix).
2013-06-23 23:16:21 +02:00
Arne Fitzenreiter
f3d1635fdd Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2013-06-23 23:14:23 +02:00
Arne Fitzenreiter
f416ef19bb mc: update to 4.8.8. 2013-06-23 22:46:50 +02:00
Arne Fitzenreiter
5a4f046605 htop: update to 1.0.2. 2013-06-23 22:46:24 +02:00
Michael Tremer
0aa0cdcde0 DNS check: Only use the IPv4 version. 2013-06-23 22:42:04 +02:00
Arne Fitzenreiter
dc735c40c3 e1000e: disabled vendor modul on kirkwood.
e1000e vendor driver does not build with a error at power management. So we use the default kernel driver on this platform.
2013-06-23 08:37:06 +02:00
Arne Fitzenreiter
6a9fcb7a73 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2013-06-22 11:29:18 +02:00
Arne Fitzenreiter
e2f6d3f449 igb: updated to 4.3.0. 2013-06-22 11:28:38 +02:00
Arne Fitzenreiter
101f32a99f e1000e: updated to 2.4.14. 2013-06-22 11:28:04 +02:00
Arne Fitzenreiter
561e31c4a7 kernel: arm rootfile update. 2013-06-22 08:49:13 +02:00
Arne Fitzenreiter
dd8565044b buildsystem: remove linux-xen from logs to check.
This log was always listed because parsing problems.
2013-06-21 23:20:05 +02:00
Arne Fitzenreiter
39e56fae74 buildsystem: add a check for wrong "etc/init.d/..." entries.
This will destroy the symlink from /etc/init.d to /etc/rc.d/init.d at unpack.
2013-06-21 23:17:46 +02:00
Arne Fitzenreiter
b843030f09 core70: fix destroing the /etc/init.d symlink.
Never put /etc/init/* to a rootfile !!!
2013-06-21 20:02:45 +02:00
Arne Fitzenreiter
4d638d5ec9 samba: update to 3.6.16. 2013-06-20 15:24:17 +02:00
Michael Tremer
e8c070037f Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2013-06-20 11:02:27 +02:00
Michael Tremer
f4c3f51441 outgoing firewall: Reload firewall.local when changing outgoing fw. 2013-06-20 10:59:31 +02:00
Arne Fitzenreiter
5aef2fe3bd core70: add kernel images to update. 2013-06-19 20:41:13 +02:00
Arne Fitzenreiter
a7094642fe core70: add kernel update to script.
and remove not update files from updater.
2013-06-19 18:04:09 +02:00
Arne Fitzenreiter
2a224f6c10 kernel: update to 3.2.47 and kernel-xen to 2.6.32.61. 2013-06-19 17:18:13 +02:00
Arne Fitzenreiter
445338405f kernel: intel rootfile update.
(arm is still outdated).
2013-06-19 17:15:28 +02:00
Michael Tremer
8216295be4 kernel: Update xen kernel config (IPVS changes). 2013-06-19 12:33:13 +02:00
Michael Tremer
9ba3456954 ipvsadm: New package. 2013-06-19 11:49:34 +02:00
Michael Tremer
3e894e4c02 kernels: Enhance support for IPVS. 2013-06-19 11:38:22 +02:00
Arne Fitzenreiter
383390866c core70: fix rename realtek modules. 2013-06-18 20:43:07 +02:00
Michael Tremer
eb9f4587df Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2013-06-18 16:49:30 +02:00
Michael Tremer
c050a22433 postfix: Do proper configuration.
Adds LDAP support because the libs are always installed.
Disables IPv6, because IPFire 2 does not support IPv6.
The rest is cleanup stuff.
2013-06-18 16:48:31 +02:00
Michael Tremer
49c7cb2328 squid: Include /etc/squid/squid.conf.pre.local.
This configuration file is included _before_ the
default IPFire configuration.
2013-06-18 15:59:03 +02:00
Arne Fitzenreiter
d0196acc90 motion: rootfile update. 2013-06-16 20:12:26 +02:00
Arne Fitzenreiter
22358c0672 r81xx: switch realtek lan module from vendor to kernel.
some users has reported problems with the realtek vendor modules.
-problems at link detection with r8101.
-problems with igmpproxy with r8169.

so we switch to the original kernel modul. (vendor drivers are used for
xen because r8169 crash here)
2013-06-16 15:14:41 +02:00
Michael Tremer
9515a14ef4 bitstream: This is not a package.
This is not a package, because it does not provide
any files and therefore should not exist.
2013-06-15 13:48:57 +02:00
Michael Tremer
3142f133bb New package: keepalived 2013-06-14 13:37:59 +02:00
Michael Tremer
3037bccd0f core 70: Add updated VLAN script. 2013-06-14 13:13:36 +02:00
Michael Tremer
97f0fdd5f3 Merge remote-tracking branch 'jlentfer/multicat' into next
Conflicts:
	make.sh
2013-06-14 13:12:47 +02:00
Michael Tremer
3de19c87ca vlans: Allow RED to be a virtual network device. 2013-06-14 13:10:46 +02:00
Jan Lentfer
0a21ce42e1 multicat: add a new addon package "multicat" - The multicast swiss knife
Very useful for analyzing multicast traffic directly on the router/
firewall without the need for a large software like vlc or the like.

http://www.videolan.org/projects/multicat.html

Simple and efficient multicast and transport stream manipulation

The multicat package contains a set of tools designed to easily and
efficiently manipulate multicast streams in general, and MPEG-2
Transport Streams (ISO/IEC 13818-1) in particular.

The multicat suite of applications is very lightweight and designed
to operate in tight environments. Memory and CPU usages are kept to
a minimum, and they feature only one thread of execution.

multicat needs bitstream as a build dependency
http://www.videolan.org/developers/bitstream.html
2013-06-14 13:07:02 +02:00
Michael Tremer
ad4ce45ae2 Add libjpeg to core update 70. 2013-06-13 15:05:12 +02:00
Michael Tremer
a606377ea8 Merge remote-tracking branch 'jlentfer/igmpproxy' into next 2013-06-13 13:49:04 +02:00
Jan Lentfer
4bc434b8ad igmpproxy: Import patches from open-wrt / Telekom Labs
Major change in these patches for the user is the addition
of a whitelist item for up and downstream interfaces.

Excerpt from one of patches:

Defines a whitelist for multicast groups. The network address must be in the following
format 'a.b.c.d/n'. If you want to allow one single group use a network mask of /32,
i.e. 'a.b.c.d/32'.

By default all multicast groups are allowed on any downstream interface. If at least one
whitelist entry is defined, all igmp membership reports for not explicitly whitelisted
multicast groups will be ignored and therefore not be served by igmpproxy. This is especially
useful, if your provider does only allow a predefined set of multicast groups. These whitelists
are only obeyed by igmpproxy itself, they won't prevent any other igmp client running on the
same machine as igmpproxy from requesting 'unallowed' multicast groups.

You may specify as many whitelist entries as needed. Although you should keep it as simple as
possible, as this list is parsed for every membership report and therefore this increases igmp
response times. Often used or large groups should be defined first, as parsing ends as soon as
a group matches an entry.
2013-06-13 13:44:42 +02:00