Matthias Fischer
fa088214bc
graphs.pl: Added translation for 'ACPI Thermal Zone'
...
This patchset is based on https://git.ipfire.org/?p=people/ms/ipfire-2.x.git;a=commitdiff;h=4bf0d000ffe961cdc5d9dbd27b3a11f900b3daed
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-19 19:10:29 +00:00
Stefan Schantl
2c35344dda
Language files: Clarify menu entries and page titles for VPN connections.
...
These pages for RW and N2N statistics only show handle for OpenVPN connections.
Fixes #12476 .
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-19 19:08:42 +00:00
Arne Fitzenreiter
3c48052ed1
core150: add graphs.pl
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-19 19:06:55 +00:00
Michael Tremer
6fc3625512
graphs: Fix rendering CPU graphs after number of cores decreased
...
Fixes : #12193 - cpu graphs cannot created if smt is disabled
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-19 19:05:46 +00:00
Arne Fitzenreiter
85de90ef9d
core150: add index.cgi
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-19 19:05:06 +00:00
Michael Tremer
947bd622a1
index.cgi: Fix CPU architecture check
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-19 19:04:18 +00:00
Matthias Fischer
74847444df
htop: Update to 3.0.2
...
For details see:
https://github.com/htop-dev/htop/blob/master/ChangeLog
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-19 19:04:05 +00:00
Arne Fitzenreiter
383eefc0ae
kernel: update aarch64 rootfile
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-18 05:28:26 +00:00
Arne Fitzenreiter
73f4e7b4c6
kernel: aarch64: disable SSDT_OVERLAYS
...
this option was visible by enabling ACPI and is enabled by default but adds
an attacking vector.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-18 05:23:18 +00:00
Matthias Fischer
b04f532f70
nano: Update to 5.2
...
For details see:
https://www.nano-editor.org/news.php
I wasn't sure about the 'extras' - if we need more, feel free to adjust the rootfile.
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-17 18:53:16 +00:00
Adolf Belka
ddad38e232
postfix: Update to 3.5.7
...
- Update postfix from version 3.5.6 to 3.5.7
see ftp://ftp.cs.uu.nl/mirror/postfix/postfix-release/official/postfix-3.5.7.RELEASE_NOTES
Supporting request from Peter Müller
Signed-off-by: Adolf Belka<ahb@ipfire@gmail.com
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-17 18:52:43 +00:00
Adolf Belka
ca673f8df6
nagios_nrpe: Fix for bug 12337
...
- added pid_file=/var/run to the configure statement
to give the required pid directory in the default nrpe.cfg file
Signed-off-by: Adolf Belka <ahb.ipfire@gmail.com >
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-17 18:51:53 +00:00
Mathew McBride
e29125d52f
kernel: enable ACPI support on ARM64
...
ACPI (with EFI) is used on ARM systems conforming to the
Server Base Boot Requirements (SBBR) and is an optional
on embedded systems (EBBR).
Up to now the ARM64 boards supported by IPFire use U-Boot and
device tree so ACPI was not turned on.
The immediate use case here is to run under virtualization,
using my muvirt project[1] I can run IPFire on our Traverse Ten64
system. For reasons I'll explain separately it is not
currently possible to run stock IPFire on this system.
This change also enables the EFI RTC driver which is presented
by the qemu arm64 virt machine.
Signed-off-by: Mathew McBride <matt@traverse.com.au >
[1] - https://gitlab.com/traversetech/muvirt
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-17 18:50:35 +00:00
Matthias Fischer
99804aaed7
clamav: Update to 0.103.0
...
For details see:
https://blog.clamav.net/2020/09/clamav-01030-released.html
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-17 18:49:44 +00:00
Arne Fitzenreiter
97f1bf4460
kernel: update to 4.14.198
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-12 23:47:49 +02:00
Arne Fitzenreiter
3a69555f90
kernel: add patch agains CVE-2020-14386
...
fixes #12483
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-12 09:38:10 +02:00
Arne Fitzenreiter
9dafa28a1c
Revert "kernel: add patch against CVE-2020-14386"
...
This reverts commit f04023b1ca .
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-11 22:16:27 +02:00
Arne Fitzenreiter
1d15fbd440
kernel: cleanup kirkwood patch apply lines
...
kirkwood support is removed long time ago and the patch already
removed from tree.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-11 21:30:15 +02:00
Arne Fitzenreiter
f04023b1ca
kernel: add patch against CVE-2020-14386
...
fixes #12483
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-11 21:27:15 +02:00
Arne Fitzenreiter
10d0489df2
kernel: update to 4.14.197
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-10 20:20:28 +02:00
Arne Fitzenreiter
207b38f1da
Kernel: update to 4.14.196
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-09-04 18:12:38 +02:00
Arne Fitzenreiter
0216f1ecdd
libvirt: add libtirpc to dependencies
...
libvirt is linked against libtirpc so this need to installed.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-08-31 18:39:01 +02:00
Arne Fitzenreiter
eefe8acbea
core150: start core150 and add kernel
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-08-31 07:06:41 +02:00
Arne Fitzenreiter
ce9f979c01
kernel: update to 4.14.195
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-08-31 06:58:32 +02:00
Arne Fitzenreiter
305baacbb8
core149: add vim to update
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-08-29 18:12:19 +00:00
Arne Fitzenreiter
2c8819992e
vim: update to 8.2 and fix crash with gcc-10
...
the configure.ac has a bug that detects gcc-10 as gcc-1 and so not use
some quirks. Also there is a bug with FORTIFY-SOURCE=2 that crash
if the matchparen plugin is used (enabled by default).
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-08-29 18:08:57 +00:00
Arne Fitzenreiter
5300e13516
core149: add files to exclude from older updates
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-08-26 13:58:02 +00:00
Stefan Schantl
0bb03f69ef
Core 148: Exclude location related settings files.
...
This prevents from overwriting existing files, with empty ones
and finally to lose the stored settings.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2020-08-25 19:13:17 +00:00
Michael Tremer
6f60b0d271
core149: Restart squid
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-24 09:48:36 +00:00
Matthias Fischer
9fa6a8d81d
squid: Update to 4.13
...
For details see:
http://www.squid-cache.org/Versions/v4/changesets/
and
http://lists.squid-cache.org/pipermail/squid-users/2020-August/022566.html
Fixes (excerpt):
"* SQUID-2020:8 HTTP(S) Request Splitting
(CVE-2020-15811)
This problem is serious because it allows any client, including
browser scripts, to bypass local security and poison the browser
cache and any downstream caches with content from an arbitrary
source.
* SQUID-2020:9 Denial of Service processing Cache Digest Response
(CVE pending allocation)
This problem allows a trusted peer to deliver to perform Denial
of Service by consuming all available CPU cycles on the machine
running Squid when handling a crafted Cache Digest response
message.
* SQUID-2020:10 HTTP(S) Request Smuggling
(CVE-2020-15810)
This problem is serious because it allows any client, including
browser scripts, to bypass local security and poison the proxy
cache and any downstream caches with content from an arbitrary
source.
* Bug 5051: Some collapsed revalidation responses never expire
* SSL-Bump: Support parsing GREASEd (and future) TLS handshakes
* Honor on_unsupported_protocol for intercepted https_port"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-24 09:47:40 +00:00
Michael Tremer
0e457b13ea
smt: Fix check to detect if a system is running virtually
...
/sys/hypervisor exists when a host has loaded the kvm modules.
Fixes : #12472
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-21 09:52:15 +00:00
Michael Tremer
087e302381
general-functions.pl: Do not check IPsec subnets for VTI/GRE connections
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-20 17:56:03 +00:00
Michael Tremer
9a62b6daac
libvirt: Depend on ebtables
...
libvirtd requires this to create some custom firewall rules
Reported-by: Daniel Weismüller <daniel.weismueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-19 14:08:54 +00:00
Michael Tremer
882ab515f9
libvirt: Ship all CPU maps
...
Reported-by: Daniel Weismüller <daniel.weismueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-19 14:08:53 +00:00
Michael Tremer
17d01f0138
core149: Ship zstd which is now part of the base system
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-19 12:12:08 +00:00
Michael Tremer
0e45bb1734
zstd: Do not ship libstd.so
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-19 12:11:43 +00:00
Matthias Fischer
9a2685f326
rsync: Update to 3.2.3
...
For details see:
https://download.samba.org/pub/rsync/NEWS#3.2.3
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-19 12:02:51 +00:00
Michael Tremer
f43ee38550
core149: Fix typo in apache initscript
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-19 11:56:56 +00:00
Matthias Fischer
9ac5418613
zstd 1.4.5: Deleted obsolete files from '/src/paks/'
...
No longer needed => deleted because of:
https://git.ipfire.org/?p=ipfire-2.x.git;a=commit;h=c67ff7d72c2232b6994e1ff97277d4040711f97d
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-18 15:42:12 +00:00
Erik Kapfer
3caa418097
tshark: Update to version 3.2.6
...
The version jump from 3.2.3 to 3.2.6 includes several changes.
3.2.4 includes only bugfixes.
3.2.5 includes bugfixes and updated protocols.
3.2.6 includes also bugfixes and updated protocols.
For a full overview, the release notes can be found in here -->
https://www.wireshark.org/docs/relnotes/ .
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-18 15:42:05 +00:00
Peter Müller
10771d94ad
Postfix: update to 3.5.6
...
Please refer to http://www.postfix.org/announcements/postfix-3.5.6.html
for release announcements.
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-18 10:19:49 +00:00
Michael Tremer
c67ff7d72c
zstd: Make this part of the core distributions
...
Many packages link against it and we should make use of it
when we have it.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-18 10:13:01 +00:00
Michael Tremer
f8a54e1961
qemu: Update rootfile
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-18 10:11:33 +00:00
Michael Tremer
5a918d828f
rsync: Update rootfile
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-18 10:10:13 +00:00
Michael Tremer
bef8b9c027
core149: Ship popt
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-17 17:55:55 +00:00
Matthias Fischer
7dcea61621
popt: Update to 1.18
...
Recommended for 'rsync 3.2.1'.
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-17 17:55:35 +00:00
Matthias Fischer
73202b3976
rsync: Update to 3.2.1
...
For details see:
https://download.samba.org/pub/rsync/NEWS#3.2.1
Although 3.2.2 is in "release testing", I decided to push this release now to get things running.
I activated zstd-support and added 'DEPS = zstd'.
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-17 17:55:26 +00:00
Matthias Fischer
6b264af51b
zstd 1.4.5: New package
...
This packages adds a "lossless compression algorithm" - supported by 'rsync 3.2.1'.
For details see:
https://github.com/facebook/zstd/releases/tag/v1.4.5
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-17 17:54:55 +00:00
Matthias Fischer
112d36f00e
qemu: Update to 5.0.0
...
For details see:
https://wiki.qemu.org/ChangeLog/5.0
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-17 17:53:41 +00:00
Matthias Fischer
665261f56f
usbredir: Update to 0.8.0
...
For details see:
https://gitlab.freedesktop.org/spice/usbredir/-/blob/master/ChangeLog
"-Source code and bug tracker hosted in Freedesktop's instance of Gitlab
-https://gitlab.freedesktop.org/spice/usbredir
-usbredirfilter
-Fix busy wait due endless recursion when interface_count is zero
-usbredirhost:
-Fix leak on error
-usbredirserver:
-Use 'busnum-devnum' instead of 'usbbus-usbaddr'
-Add support for bind specific address -4 for ipv4, -6 for ipv6
-Reject empty vendorid from command line
-Enable TCP keepalive"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2020-08-17 17:53:40 +00:00