aboutsummaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAge
* node: July 7th 2022 Security ReleasesHirokazu MORIKAWA2022-07-10
| | | | | | | | | | | | | | | | Update to v16.16.0 Release for the following issues: HTTP Request Smuggling - Flawed Parsing of Transfer-Encoding (Medium)(CVE-2022-32213) HTTP Request Smuggling - Improper Delimiting of Header Fields (Medium)(CVE-2022-32214) HTTP Request Smuggling - Incorrect Parsing of Multi-line Transfer-Encoding (Medium)(CVE-2022-32215) DNS rebinding in --inspect via invalid IP addresses (High)(CVE-2022-32212) https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/ No vulnerabilities related with openssl (uses system openssl) Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
* elektra: fix compilation with external iconvRosen Penev2022-07-10
| | | | | | Patch mostly taken from hidapi. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* Merge pull request #18898 from mhei/ser2net-service-startMichael Heimpold2022-07-10
|\ | | | | ser2net: schedule start later during boot (fixes #18872)
| * ser2net: schedule start later during boot (fixes #18872)Michael Heimpold2022-07-09
|/ | | | | | | Usually, no other local service depends on the start of ser2net, so let's start it later in the boot process. Signed-off-by: Michael Heimpold <mhei@heimpold.de>
* clamav: fix compilation without libiconv-stubRosen Penev2022-07-08
| | | | | | Ported similar patch from hidapi. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* libmad: update to 0.16.2Rosen Penev2022-07-08
| | | | | | Backport aarch64 patch. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* liburing: Update to v2.2Christian Lachner2022-07-08
| | | | | | - Updated download URL and hash Signed-off-by: Christian Lachner <gladiac@gmail.com>
* python-requests: bump to version 2.28.1Alexandru Ardelean2022-07-07
| | | | Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
* python-lxml: bump to version 4.9.1Alexandru Ardelean2022-07-07
| | | | Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
* pillow: bump to version 9.2.0Alexandru Ardelean2022-07-07
| | | | Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
* python-chardet: bump to version 5.0.0Alexandru Ardelean2022-07-07
| | | | Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
* rsyslog: apply shellcheck SC3014 to initGiacomo Sanchietti2022-07-07
| | | | Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* rsyslog: replace spaces with tabs inside initGiacomo Sanchietti2022-07-07
| | | | Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* rsyslog: improve default configGiacomo Sanchietti2022-07-07
| | | | | | | Check also for config files containing comment lines starting with white spaces. Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* rsyslog: apply shellcheck suggestions to initGiacomo Sanchietti2022-07-07
| | | | Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* rsyslog: preserve existing configurationGiacomo Sanchietti2022-07-07
| | | | Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* rsyslog: include original config fileGiacomo Sanchietti2022-07-07
| | | | | | Allow advanced configurations from /etc/rsyslog.conf file Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* rsyslog: write config file to RAMGiacomo Sanchietti2022-07-07
| | | | | | Avoid wearing out flash storage Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* rsyslog: add uci supportGiacomo Sanchietti2022-07-07
| | | | Signed-off-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
* Merge pull request #18883 from jefferyto/python-cryptography-fix-buildAlexandru Ardelean2022-07-07
|\ | | | | python-cryptography: Fix failing build
| * python-cryptography: Fix failing buildJeffery To2022-07-07
|/ | | | | | | Fixes https://github.com/openwrt/packages/issues/18876. Fixes https://github.com/openwrt/packages/issues/18879. Signed-off-by: Jeffery To <jeffery.to@gmail.com>
* dnslookup: Update to 1.7.1Tianling Shen2022-07-07
| | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* cloudflared: Update to 2022.7.1Tianling Shen2022-07-07
| | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* travelmate: update 2.0.9Dirk Brenken2022-07-06
| | | | | | | * various vpn fixes/optimizations (run tested by forum users) * refine several log statements Signed-off-by: Dirk Brenken <dev@brenken.org>
* libarchive: fix ext2fs build race error conditionPetr Štetiar2022-07-05
| | | | | | | | | | | | | | | | libarchive looks for ext2fs headers during configure, and if it finds them it will expect to find them during compile, or on the rare occasion when they aren't it will fail: libarchive/archive_entry.c:59:55: fatal error: ext2fs/ext2_fs.h: No such file or directory As we just need headers for some type constants, let's re-use headers from tools/e2fsprogs package which are always available. Reported-by: Adam Dov <adov@maxlinear.com> Suggested-by: Paul Eggleton <paul.eggleton@linux.intel.com> References: https://git.yoctoproject.org/poky/commit/?id=f0b9a7cf9f80be1917e45266fa201f464a28c1e5 Signed-off-by: Petr Štetiar <ynezz@true.cz>
* xfrpc: update to 1.06.579Dengfeng Liu2022-07-05
| | | | Signed-off-by: Dengfeng Liu <liudf0716@gmail.com>
* xfrpc: set xfrpc's disabled default value to 0Dengfeng Liu2022-07-05
| | | | | | change this to satisfy luci-app-xfrpc's need Signed-off-by: Dengfeng Liu <liudf0716@gmail.com>
* modemmanager: explicitly disconnect even if no bearers foundAleksander Morgado2022-07-05
| | | | | | | | | | | | | | | | | A network restart where netifd is cleanly restarted involves bringing the network interfaces down. The 'modemmanager' protocol handler will run a mmcli --simple-disconnect in this case, but only if there are bearer objects found. If the network restart happened *during* the connection attempt procedure, while the modem is e.g. being registered in the network, no bearer objects exist yet, and so, we would skip doing anything during the interface teardown operation. This would lead to the original connection attempt succeeding, so leaving the modem in ModemManager in connected state, while the associated interface in netifd is reported down. Signed-off-by: Aleksander Morgado <aleksander@aleksander.es>
* kea: create /var/run/kea in init scriptStijn Tintel2022-07-05
| | | | | | | | Kea expects /var/run/kea to exist. Without it, errors occur: Mon Jun 13 10:31:45 2022 daemon.err kea-dhcp6[2977]: Unable to use interprocess sync lockfile (No such file or directory): /var/run/kea/logger_lockfile Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be>
* ncdu: update to 1.17 and add blue optionJohn Audia2022-07-05
| | | | | | | | | | | | Upstream bump and add a patch to use a blue highlight color for the dark color scheme (--color dark) as some users find the default bright green is too intense. Note that invoking ncdu without the --color switch at use uses the upstream default bright green, so users will need to call ncdu with --color dark in order to get the blue color. Signed-off-by: John Audia <therealgraysky@proton.me>
* tor: bump to 0.4.7.8 stableRui Salvaterra2022-07-05
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | From the changelog… o Major bugfixes (congestion control, TROVE-2022-001): - Fix a scenario where RTT estimation can become wedged, seriously degrading congestion control performance on all circuits. This impacts clients, onion services, and relays, and can be triggered remotely by a malicious endpoint. Tracked as CVE-2022-33903. Fixes bug 40626; bugfix on 0.4.7.5-alpha. o Minor features (fallbackdir): - Regenerate fallback directories generated on June 17, 2022. o Minor features (geoip data): - Update the geoip files to match the IPFire Location Database, as retrieved on 2022/06/17. o Minor bugfixes (linux seccomp2 sandbox): - Allow the rseq system call in the sandbox. This solves a crash issue with glibc 2.35 on Linux. Patch from pmu-ipf. Fixes bug 40601; bugfix on 0.3.5.11. o Minor bugfixes (logging): - Demote a harmless warn log message about finding a second hop to from warn level to info level, if we do not have enough descriptors yet. Leave it at notice level for other cases. Fixes bug 40603; bugfix on 0.4.7.1-alpha. - Demote a notice log message about "Unexpected path length" to info level. These cases seem to happen arbitrarily, and we likely will never find all of them before the switch to arti. Fixes bug 40612; bugfix on 0.4.7.5-alpha. o Minor bugfixes (relay, logging): - Demote a harmless XOFF log message to from notice level to info level. Fixes bug 40620; bugfix on 0.4.7.5-alpha. Signed-off-by: Rui Salvaterra <rsalvaterra@gmail.com>
* autossh: improve uci and procd supportJaymin Patel2022-07-05
| | | | | | | | | | - convert autossh into procd instances - add new uci config options to handle local and remote port forwarding - remove hotplug down actions causing service to stop on any interface down event Signed-off-by: Jaymin Patel <jem.patel@gmail.com>
* netifyd: Updated to v4.2.0.Darryl Sokoloski2022-07-05
| | | | Signed-off-by: Darryl Sokoloski <darryl@sokoloski.ca>
* Merge pull request #18868 from PolynomialDivision/fix-gnutlsNikos Mavrogiannopoulos2022-07-05
|\ | | | | gnutls: adjust to new configure.ac syntax
| * gnutls: disable brotliNick Hainke2022-07-05
| | | | | | | | | | | | | | Disable the brotli library by default. It is not used and may prevent linking issues in the future. Signed-off-by: Nick Hainke <vincent@systemli.org>
| * gnutls: fix disable zstdNick Hainke2022-07-05
| | | | | | | | | | | | | | | | | | | | | | Configure.ac syntax changed to: Old: --without-libbrotli --without-libzstd (also --with-*) New: --without-brotli --without-zstd (also --with-*) https://github.com/gnutls/gnutls/commit/6b794e49d1a14e43f9e08023f958364712c3c89a Fixes: 6385813ddfb4 ("gnutls: update to 3.7.5") Signed-off-by: Nick Hainke <vincent@systemli.org>
* | zerotier: update to 1.10.1Moritz Warning2022-07-04
|/ | | | Signed-off-by: Moritz Warning <moritzwarning@web.de>
* gnutls: update to 3.7.6Nick Hainke2022-07-04
| | | | Signed-off-by: Nick Hainke <vincent@systemli.org>
* gnutls: update to 3.7.5Nick Hainke2022-07-04
| | | | Signed-off-by: Nick Hainke <vincent@systemli.org>
* gnutls: cleanup MakefileNick Hainke2022-07-04
| | | | | | | | - Add PKG_LICENSE_FILES - Use SPDX - Rearrange Signed-off-by: Nick Hainke <vincent@systemli.org>
* Merge pull request #18858 from PolynomialDivision/update-radcliNikos Mavrogiannopoulos2022-07-04
|\ | | | | radcli: uptdate to 1.3.0
| * radcli: uptdate to 1.3.0Nick Hainke2022-07-03
| | | | | | | | | | | | | | | | | | | | | | | | | | - Removed duplicate function definition from util.h - Increased size of dictionary vendor and values to 32-bits from 16; this breaks the ABI from the previous release. - Corrected a string termination issue in rc_avpair_tostr() - Added functions to create dictionary without a file: rc_dict_addattr rc_dict_addval rc_dict_addvend Signed-off-by: Nick Hainke <vincent@systemli.org>
* | radsecproxy: update to 1.9.1Nick Hainke2022-07-04
|/ | | | | | | | | | | | | | | | | | | | | | | Remove upstreamed patches: - 100-fix-setstacksize-for-glibc-2.34.patch Refresh patches: - 200-logdest-on-foreground.patch Changes: Misc: - OpenSSL 3.0 compatibility Bug Fixes: - Fix refused startup with openssl <1.1 - Fix compiler issue for Fedora 33 on s390x - Fix small memory leak in config parser - Fix lazy certificate check when connecting to TLS servers - Fix connect is aborted if first host in list has invalid certificate - Fix setstacksize for glibc 2.34 - Fix system defaults/settings for TLS version not honored Signed-off-by: Nick Hainke <vincent@systemli.org>
* totem-pl-parser: depend on shared-mime-infoW. Michael Petullo2022-07-02
| | | | | | | | The totem-pl-parser library seems to rely on freedesktop.org's MIME-type definitions to parse playlist files. Without them, parsing will produce a TOTEM_PL_PARSER_RESULT_IGNORED error. Signed-off-by: W. Michael Petullo <mike@flyn.org>
* usteer: bump to git HEADStijn Tintel2022-07-02
| | | | | | | | | | 5be6819 policy: allow disabling load balancing 80b0b65 main: disable load balancing by default fca4b87 policy: improve readability 73c424b usteer: add option for probe steering 87de1ab main: disable probe steering by default Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be>
* sudo: bump to verison 1.9.11p3Alexandru Ardelean2022-07-01
| | | | Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
* python-jsonschema: Update to 4.6.1Javier Marcet2022-07-01
| | | | | | | | | | What's Changed: - Type annotate format checker methods by @sirosen - Fix fuzzer to include instrumentation by @DavidKorczynski - [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci Signed-off-by: Javier Marcet <javier@marcet.info>
* tgt: update to 1.0.83Maxim Storchak2022-07-01
| | | | Signed-off-by: Maxim Storchak <m.storchak@gmail.com>
* tmux: update to 3.3aMaxim Storchak2022-07-01
| | | | Signed-off-by: Maxim Storchak <m.storchak@gmail.com>
* Merge pull request #18510 from nemesisdesign/openwisp-monitoringFlorian Eckert2022-06-29
|\ | | | | openwisp-monitoring: added 0.1.1