W. van den Akker
1201cdcd5f
Shorewall: Bump to 5.2.3.5
...
Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl >
2020-01-18 22:49:07 +01:00
W. van den Akker
4cb0ff8314
Shorewall-lite: Bump to 5.2.3.5
...
Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl >
2020-01-18 22:48:35 +01:00
W. van den Akker
c2a5aa1a54
Shorewall-core: Bump to 5.2.3.5
...
Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl >
2020-01-18 22:48:13 +01:00
Stijn Tintel
995226d95d
strongswan: bump to 5.8.2
...
Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be >
2020-01-17 01:07:37 +02:00
Paul Fertser and Stijn Tintel
243673b2d0
strongswan: allow to specify per-connection reqid with UCI
...
This is useful to assign all traffic to a fw3 zone, e.g.:
/etc/config/ipsec:
config remote 'test'
list tunnel 'dev'
...
config 'tunnel' 'dev'
option reqid '33'
...
/etc/config/firewall:
config zone
option name wan
option extra_src "-m policy --pol none --dir in"
option extra_dest "-m policy --pol none --dir out"
...
config zone
option name vpn
# subnet needed for firewall3 before 22 Nov 2019, 8174814a
list subnet '0.0.0.0/0'
option extra_src "-m policy --pol ipsec --dir in --reqid 33"
option extra_dest "-m policy --pol ipsec --dir out --reqid 33"
...
Signed-off-by: Paul Fertser <fercerpav@gmail.com >
Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be >
2020-01-17 01:07:32 +02:00
Stijn Tintel
3880d65a07
strongswan: bump to 5.8.1
...
Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be >
2020-01-17 01:07:28 +02:00
Stan Grishin and Hannu Nyman
3030d0fc1a
vpn-policy-routing: bugfix: remove conflict with vpnbypass
...
Signed-off-by: Stan Grishin <stangri@melmac.net >
(cherry picked from commit 05603822d3 )
2020-01-16 20:00:31 +02:00
Eric Luehrsen and Hannu Nyman
8f3dcbcee6
unbound: fix TLS forwards with optional suffix
...
Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com >
(cherry picked from commit b101dd76fb )
2020-01-11 23:03:47 +02:00
Rosen Penev
670f336d79
transmission: Sync with master
...
Signed-off-by: Rosen Penev <rosenp@gmail.com >
2020-01-10 18:07:42 -08:00
Yousong Zhou
1f293771cd
openvswitch: bump PKG_RELEASE
...
Signed-off-by: Yousong Zhou <yszhou4tech@gmail.com >
2020-01-08 13:03:25 +08:00
Yousong Zhou
dc097661c5
openvswitch: backport patch to fix compilation
...
Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com >
Signed-off-by: Yousong Zhou <yszhou4tech@gmail.com >
2020-01-08 12:59:37 +08:00
Yousong Zhou
74e160df22
openvswitch: fix building failure caused by dst_ops api change
...
Ref: https://github.com/openwrt/packages/issues/10961
Reported-by: Sven Roederer <devel-sven@geroedel.de >
Signed-off-by: Yousong Zhou <yszhou4tech@gmail.com >
2020-01-08 12:56:32 +08:00
Yousong Zhou
a4a54d0f3b
openvswitch: bump to version 2.11.1
...
Signed-off-by: Yousong Zhou <yszhou4tech@gmail.com >
2020-01-08 11:57:17 +08:00
Rosen Penev and GitHub
26c23f3b9e
Merge pull request #10881 from mstorchak/stubby-19.07
...
[19.07] stubby: switch to ca-bundle
2020-01-05 15:38:13 -08:00
DENG Qingfang and Josef Schlehofer
e2bca1026b
nginx: update to 1.16.1
...
Fixes:
when using HTTP/2 a client might cause excessive memory
consumption and CPU usage (CVE-2019-9511, CVE-2019-9513,
CVE-2019-9516).
Signed-off-by: DENG Qingfang <dengqf6@mail2.sysu.edu.cn >
(cherry picked from commit 5ffc744018 )
2020-01-04 23:13:48 +01:00
Jan Pavlinec and Josef Schlehofer
74e9ca74fd
tor: add respawn to init script
...
Note:
In some cases when tor daemon starts before
than the router is connected to the Internet.
Tor will exit and you have to run it manually.
This should fix this case.
Signed-off-by: Jan Pavlinec <jan.pavlinec@nic.cz >
(cherry picked from commit 5bce9c3e1d )
2020-01-04 20:53:01 +01:00
Jan Pavlinec and Josef Schlehofer
b85cbaf7e5
tor: update to version 0.4.2.5
...
Signed-off-by: Jan Pavlinec <jan.pavlinec@nic.cz >
(cherry picked from commit a339e0ede3 )
2020-01-04 20:52:49 +01:00
Rosen Penev and GitHub
9ec8652533
Merge pull request #10940 from Andy2244/samba-4.11.4-(19.07)
...
[19.07] samba4: update to 4.11.4 (python3 version), add rpcsvc-proto, add libasn1 host build
2020-01-03 16:32:02 -08:00
Rosen Penev and GitHub
7472cc7427
Merge pull request #10938 from Andy2244/smbd-rename-3.0.1-(19.07)
...
[19.07] smbd: rename from cifsd, update to 3.0.1
2020-01-03 16:15:54 -08:00
Andy Walsh
85066d81d0
samba4: update to 4.11.4 (python3 version), add rpcsvc-proto, add libasn1 host build
...
* update to 4.11.4 (python3 version)
* re-enable AD-DC option
* add 'samba_nice' UCI option via "config procd 'extra'"
* restructure buildsteps (don't rely on waf --targets logic)
* move quota option into VFS
* move ACL option into AC-DC
* add more admin-tools
* use rpath_install for libs
* fix rpath + rstrip
extra:
* add rpcsvc-proto package _(don't rely on nfs-utils/host for headers, rpcgen anymore)_
* add libasn1 host build _(samba4 is looking for the bins)_
Signed-off-by: Andy Walsh <andy.walsh44+github@gmail.com >
2020-01-04 01:08:11 +01:00
Andy Walsh
28e84aacf7
wsdd2: update to git (2019-12-15), bind to 'lan' only, update init for smbd
...
* update to git (2019-12-15)
* bind to 'lan' interface only
* update init for renamed cifsd->smbd
* make smbd/samba compatible _(avoid testparm dependency)_
* only start if needed
* add meta data _(vendor, model, sku)_
* update smb.conf procd location
* lower restart delay
* remove outdated patch
Signed-off-by: Andy Walsh <andy.walsh44+github@gmail.com >
2020-01-04 01:01:43 +01:00
Andy Walsh
8bc58d175e
smbd: rename from cifsd, update to 3.0.1
...
* follow upstream rename to 'smbd' and 'smbd-tools'
* config is '/config/smbd' and '/etc/smbd/smb.conf'
* smbd: update to 3.0.1
* smbd: fixes delete access on readonly shares
* smbd: add patch to keep version metadata in kmod
* smbd: remove synchrous kill_server patches
* smbd-tools: update to 3.0.1
* smbd-tools: userspace service is now 'usmbd'
* smbd-tools: userspace tools are: 'smbuseradd', 'smbshareadd' with /etc/smbd/smbdpwd.db
* smbd-tools: split package into server/utils (reduce size)
* smbd-tools: fix init (luci save&apply)
* smbd-tools: remove kill_server related timeouts
* smbd-tools: add low memory options to template, to prevent oom
Signed-off-by: Andy Walsh <andy.walsh44+github@gmail.com >
2020-01-04 00:55:40 +01:00
Stan Grishin
86b48645fa
vpn-policy-routing: initial release
...
Signed-off-by: Stan Grishin <stangri@melmac.net >
2019-12-30 07:40:38 -07:00
Hannu Nyman and GitHub
8df00a88e7
Merge pull request #10892 from cshoredaniel/pr-19.07-radicale2-doc-passlib-bcrypt
...
[19.07] radicale2: Document suggested use of passlib and bcrypt
2019-12-28 23:52:37 +02:00
Daniel F. Dickinson
64d4fc6e6c
radicale2: Document suggested use of passlib and bcrypt
...
PKG_RELEASE not bumped because this only affects package description.
We document that passlib and bcrypt are needed if one wishes to use
bcrypt encryption of passwords. These have not been added as dependencies
as Radicale2 can have a frontend webserver authenticate users rather than
radicale itself.
Signed-off-by: Daniel F. Dickinson <cshored@thecshore.com >
2019-12-28 16:18:22 -05:00
Moritz Warning
479b45b8ab
zerotier: update to 1.4.6
...
Signed-off-by: Moritz Warning <moritzwarning@web.de >
2019-12-28 14:48:33 +01:00
Moritz Warning
f0c5a95a4f
zerotier: make sure the /var/lib exists
...
Signed-off-by: Moritz Warning <moritzwarning@web.de >
2019-12-28 14:48:33 +01:00
Moritz Warning
38a3ed1c75
zerotier: change license to BSL 1.1
...
Business Source License.
Signed-off-by: Moritz Warning <moritzwarning@web.de >
2019-12-28 14:48:33 +01:00
Moritz Warning
e42648f3c8
zerotier: update to release 1.4.4
...
Also allow path to local.conf to be set and enable linker optimisations
to save a few bytes.
Signed-off-by: Moritz Warning <moritzwarning@web.de >
2019-12-28 14:48:33 +01:00
Moritz Warning
70f4c1d197
zerotier: udpate to 1.4.2
...
Signed-off-by: Moritz Warning <moritzwarning@web.de >
2019-12-28 14:48:33 +01:00
DENG Qingfang and Moritz Warning
61291196d3
zerotier: fix linking to libnatpmp and build with uclibc
...
Makefile always checks the existence of host's NAT-PMP header,
which results in internal NAT-PMP code being used if it's missing.
Add a patch to make it check targets' header instead.
Use aligned_alloc() instead of valloc() in case of uclibc.
Signed-off-by: DENG Qingfang <dengqf6@mail2.sysu.edu.cn >
2019-12-28 14:48:33 +01:00
Moritz Warning
1961985f86
zerotier: update to zerotier 1.4.0
...
Signed-off-by: Moritz Warning <moritzwarning@web.de >
2019-12-28 14:48:33 +01:00
Moritz Warning
7b5cc70faa
zerotier: keep configuration file on update
...
Signed-off-by: Moritz Warning <moritzwarning@web.de >
2019-12-28 14:48:33 +01:00
Maxim Storchak
ed6e1024b7
stubby: switch to ca-bundle in 19.07
...
Signed-off-by: Maxim Storchak <m.storchak@gmail.com >
2019-12-27 19:31:13 +02:00
Rosen Penev and GitHub
b710855ef1
Merge pull request #10762 from leonghui/wiki-link-update-19.07
...
[19.07] treewide: replace old wiki links
2019-12-22 21:43:53 -08:00
Christian Lachner
02985327b8
haproxy: Update HAProxy to v2.0.12
...
- Update haproxy download URL and hash
- Remove @neheb's obsolete-ssl patch as it was upstreamed, see:
(http://git.haproxy.org/?p=haproxy-2.0.git;a=commit;h=6445d988ec8def9d0f80de0eda9c5763d39facc1 )
Signed-off-by: Christian Lachner <gladiac@gmail.com >
2019-12-22 10:36:04 +01:00
Eric Luehrsen and Josef Schlehofer
ef82bba488
unbound: update to 1.9.6
...
Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com >
(cherry picked from commit 173f2d6c9f )
2019-12-21 23:35:37 +01:00
Josef Schlehofer
c9cb6a0b18
dnscrypt-proxy2: Update to version 2.0.34
...
Repository was renamed to github.com/DNSCrypt/dnscrypt-proxy
Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com >
(cherry picked from commit cddf39cbd1 )
2019-12-21 21:57:59 +01:00
DENG Qingfang and Josef Schlehofer
b8bd94ef81
mtr: update to 0.93
...
Update mtr to 0.93
Add size optimization options
ath79 ipk size: 31.9k -> 31.4k
Signed-off-by: DENG Qingfang <dengqf6@mail2.sysu.edu.cn >
(cherry picked from commit ad5615737a )
2019-12-21 21:54:33 +01:00
Jan Hak and Josef Schlehofer
5fe674a86e
knot: update to version 2.9.2
...
Signed-off-by: Jan Hak <jan.hak@nic.cz >
(cherry picked from commit ca729cd43c )
2019-12-21 21:53:34 +01:00
Rosen Penev and GitHub
198d01f78e
Merge pull request #10852 from gekmihesg/19.07-restic-rest-server
...
[19.07] restic-rest-server: add package
2019-12-21 07:03:10 -08:00
Markus Weippert
a018b51492
restic-rest-server: add package
...
Signed-off-by: Markus Weippert <markus@gekmihesg.de >
2019-12-21 10:19:26 +01:00
Rosen Penev and GitHub
fff198e7ff
Merge pull request #10753 from stangri/19.07-https-dns-proxy
...
[19.07] https-dns-proxy: switch to https-dns-proxy package name
2019-12-18 16:14:44 -08:00
Jan Pavlinec and Josef Schlehofer
90ef9c18ce
git: update to version 2.24.1 (security fix)
...
Fixes
CVE-2019-1348, CVE-2019-1349, CVE-2019-1350, CVE-2019-1351,
CVE-2019-1352, CVE-2019-1353, CVE-2019-1354, CVE-2019-1387, and
CVE-2019-19604
And fix deprecated PKG_CPE_ID
Signed-off-by: Jan Pavlinec <jan.pavlinec@nic.cz >
(cherry picked from commit 06d36ca794 )
2019-12-19 00:22:59 +01:00
Josef Schlehofer
dc2c25ccf4
git: Update to version 2.24.0
...
Refresh patch
Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com >
(cherry picked from commit 887b4e90e6 )
2019-12-19 00:22:54 +01:00
Nikos Mavrogiannopoulos
ceeac3b37d
vpnc-script: bumped release version
...
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com >
2019-12-18 21:25:14 +01:00
Nikos Mavrogiannopoulos
b46f4ecd37
vpnc-script: enable reconnect
...
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com >
2019-12-18 21:21:37 +01:00
Jo-Philipp Wich
f57ca519ac
cgi-io: close pipe descriptors early
...
In the command read side, close the superfluous write end of the pipe
early to ensure that EOF is reliably detected. Without that change, splice
calls to read from the pipe will occasionally hang until the CGI process
is eventually killed due to timeout.
Signed-off-by: Jo-Philipp Wich <jo@mein.io >
(cherry picked from commit dde503da13 )
2019-12-18 17:11:14 +01:00
Jo-Philipp Wich
9e434da4e0
cgi-io: implement exec action
...
Implement a new "cgi-exec" applet which allows to invoke remote commands
and stream their stdandard output back to the client via HTTP. This is
needed in cases where large amounts of data or binary encoded contents
such as tar archives need to be transferred, which are unsuitable to be
transported via ubus directly.
The exec call is guarded by the same ACL semantics as rpcd's file plugin,
means in order to be able to execute a command remotely, the ubus session
identified by the given session ID must have read access to the "exec"
function of the "cgi-io" scope and an explicit "exec" permission rule for
the invoked command in the "file" scope.
In order to initiate a transfer, a POST request in x-www-form-urlencoded
format must be sent to the applet, with one field "sessionid" holding
the login session and another field "command" specifiying the commandline
to invoke.
Further optional fields are "filename" which - if present - will cause
the download applet to set a Content-Dispostition header and "mimetype"
which allows to let the applet respond with a specific type instead of
the default "application/octet-stream".
Below is an example for the required ACL rules to grant exec access to
both the "date" and "iptables" commands. The "date" rule specifies the
base name of the executable and thus allows invocation with arbitrary
parameters while the latter "iptables" rule merely allows one specific
set of arguments which must appear exactly in the given order.
ubus call session grant '{
"ubus_rpc_session": "...",
"scope": "cgi-io",
"objects": [
[ "exec", "read" ]
]
}'
ubus call session grant '{
"ubus_rpc_session": "...",
"scope": "file",
"objects": [
[ "/bin/date", "exec" ],
[ "/usr/sbin/iptables -n -v -L", "exec" ]
]
}'
Signed-off-by: Jo-Philipp Wich <jo@mein.io >
(cherry picked from commit b2a890f6ad )
2019-12-18 17:11:11 +01:00
Stan Grishin
a84d8ddcef
https-dns-proxy: switch to https-dns-proxy package name
...
Signed-off-by: Stan Grishin <stangri@melmac.net >
2019-12-17 14:49:00 -07:00