aboutsummaryrefslogtreecommitdiff
path: root/net
Commit message (Collapse)AuthorAge
...
* gsocket: upstream update to 1.4.39Ralf Kaiser2023-02-11
| | | | Signed-off-by: Ralf Kaiser <skyper@thc.org>
* Merge pull request #20349 from turris-cz/unbound-1171Josef Schlehofer2023-02-10
|\ | | | | unbound: update to version 1.17.1
| * unbound: update to version 1.17.1Josef Schlehofer2023-02-10
| | | | | | | | | | | | | | - Refreshed one patch - Removed deprecated AUTORELEASE Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
* | sing-box: add new packageVan Waholtz2023-02-10
| | | | | | | | Signed-off-by: Van Waholtz <brvphoenix@gmail.com>
* | v2ray-geodata: Update to latest versionTianling Shen2023-02-10
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | v2ray-core: Update to 5.3.0Tianling Shen2023-02-10
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | xray-core: Update to 1.7.5Tianling Shen2023-02-10
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | cloudflared: Update to 2023.2.1Tianling Shen2023-02-09
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | dnscrypt-proxy2: update to version 2.1.4Fabian Lipken2023-02-08
| | | | | | | | Signed-off-by: Fabian Lipken <dynasticorpheus@gmail.com>
* | xl2tpd: bump to version 1.3.18Yousong Zhou2023-02-06
| | | | | | | | Signed-off-by: Yousong Zhou <yszhou4tech@gmail.com>
* | bind: bump PKG_RELEASENoah Meyerhans2023-02-05
| |
* | bind: add option to enable GSSAPI supportStijn Tintel2023-02-05
| | | | | | | | | | | | | | Samba4 running as Active Directory Domain Controller with the internal DNS backend requires the nsupdate binary with GSSAPI support. Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be>
* | bind: bump release numberRucke Teg2023-02-05
| | | | | | | | Signed-off-by: Rucke Teg <rucketeg@protonmail.com>
* | bind: Fix ipv6 detection logicRucke Teg2023-02-05
| | | | | | | | | | | | | | Bug was introduced in a7b770eec4370087a5ccd27887386dac9266214e and results in bind always stating with the `-4` flag. Signed-off-by: Rucke Teg <rucketeg@protonmail.com>
* | simple-adblock: update to 1.9.3-7Stan Grishin2023-02-04
| | | | | | | | | | | | | | | | * add boot() function which waits for network.interface to come up * switch oisd.nl hosts entry to domains * remove erroneous oisd substitution from config-update file Signed-off-by: Stan Grishin <stangri@melmac.ca>
* | tailscale: update to 1.36.0Oskari Rauta2023-02-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - Update tailscale to version 1.36.0 - Patch iptables support Tailscale does not (yet) support nftables. Tailscale allows running with --netfilter=off allowing end-user to create his own firewall rules, but this affects only tailscale cli, not tailscaled daemon, so connection cannot be made without error telling that tailscaled was unable to determine execute iptables for determining it's version. There is a work-around for those who do not want nft-iptables compatibility package; they can create a script to /usr/bin/iptables which responds to --version argument and echos fake version string and on any other arguments or no arguments, just exits. After this procedure and starting tailscale cli with netfilter off- it works. Openwrt has moved on to nftables, so iptables manipulation seems unnecessary. Especially for other reasons, on Openwrt, firewall should be configured on it's own, because firewall rules made by other software, such as tailscale, loose their firewalling rules when firewall restarts. So I patched it to allow "fake" iptables pointing to executable /bin/false and ignoring version request. And I also set cli to default to netfilter off setting. If still end-user wants to use iptables, this patch does not make it impossible; just install iptables, or nft-iptables, and run tailscale with argument --netfilter=on and it works out as it did before, tailscaled daemon still matches with iptables if it is found in $PATH. Signed-off-by: Oskari Rauta <oskari.rauta@gmail.com>
* | pdns-recursor: update to 4.8.2Peter van Dijk2023-02-03
| | | | | | | | Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
* | openssh: actually build openssh-server-pam with pam supportSibren Vasse2023-02-03
| | | | | | | | Signed-off-by: Sibren Vasse <github@sibrenvasse.nl>
* | openssh: update to 9.2p1Sibren Vasse2023-02-03
| | | | | | | | Signed-off-by: Sibren Vasse <github@sibrenvasse.nl>
* | crowdsec-firewall-bouncer: update to 0.0.25S. Brusch2023-02-03
| | | | | | | | | | | | | | | | | | | | | | | | | | Update crowdsec-firewall-bouncer to latest upstream release version 0.0.25 Signed-off-by: S. Brusch <ne20002@gmx.ch> Maintainer: Kerma GĂ©rald <gandalf@gk2.net> Run tested: ipq40xx/generic, Fritzbox 4040, Openwrt 22.03.3 Rework: - now based on uci config file - create nftables tables and chains in initd script
* | stunnel: update version to 5.67Florian Eckert2023-02-01
| | | | | | | | Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* | shadowsocks-libev: ss-rules: Add 'auto-merge' flag to avoid conflictsLi Xin2023-01-28
| | | | | | | | | | | | | | Link: https://github.com/openwrt/packages/pull/19872 Signed-off-by: Li Xin <i@crzidea.com> (squash commits) Signed-off-by: Yousong Zhou <yszhou4tech@gmail.com>
* | haproxy: update to v2.6.8Christian Lachner2023-01-28
| | | | | | | | | | | | - Update haproxy download URL and hash Signed-off-by: Christian Lachner <gladiac@gmail.com>
* | bind: update to 9.18.11Noah Meyerhans2023-01-28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes CVEs: - CVE-2022-3924: Fix serve-stale crash when recursive clients soft quota is reached. - CVE-2022-3736: Handle RRSIG lookups when serve-stale is active. - CVE-2022-3094: An UPDATE message flood could cause named to exhaust all available memory. This flaw was addressed by adding a new "update-quota" statement that controls the number of simultaneous UPDATE messages that can be processed or forwarded. The default is 100. A stats counter has been added to record events when the update quota is exceeded, and the XML and JSON statistics version numbers have been updated. Signed-off-by: Noah Meyerhans <frodo@morgul.net>
* | snort3: update to 3.1.53.0John Audia2023-01-28
| | | | | | | | | | | | | | | | | | | | Upstream bump Build system: x86_64 Build-tested: bcm2711/RPi4B Run-tested: bcm2711/RPi4B Signed-off-by: John Audia <therealgraysky@proton.me>
* | nextdns: Update to version 1.39.4Olivier Poitrey2023-01-28
| | | | | | | | Signed-off-by: Olivier Poitrey <rs@nextdns.io>
* | nextdns: Update to version 1.39.0Olivier Poitrey2023-01-26
| | | | | | | | Signed-off-by: Olivier Poitrey <rs@nextdns.io>
* | snowflake: update to v2.5.1Nick Hainke2023-01-24
| | | | | | | | | | | | | | | | | | Changes in version v2.4.3 - 2023-01-16 - Fix version number in version.go (Changes for v2.5.1 are missing) Signed-off-by: Nick Hainke <vincent@systemli.org>
* | pdns-recursor: update to 4.8.1Peter van Dijk2023-01-24
| | | | | | | | Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
* | treewide: bump PKG_RELEASE for libiwinfo dependant packagesChristian Marangi2023-01-23
| | | | | | | | | | | | Bump PKG_RELEASE for libiwinfo dependant packages. Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
* | pbr: bugfix: fix is_domain()Stan Grishin2023-01-22
| | | | | | | | | | | | * fixes https://github.com/openwrt/packages/issues/20352 Signed-off-by: Stan Grishin <stangri@melmac.ca>
* | tcpreplay: bump to version 4.4.3Alexandru Ardelean2023-01-22
| | | | | | | | Signed-off-by: Alexandru Ardelean <ardeleanalex@gmail.com>
* | xfrpc: update to version 2.1.606Dengfeng Liu2023-01-22
| | | | | | | | Signed-off-by: Dengfeng Liu <liudf0716@gmail.com>
* | cloudflared: Update to 2023.1.0Tianling Shen2023-01-22
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | atlas-sw-probe: add more binariesJosef Schlehofer2023-01-21
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | They were added in these commits [1] [2] and if they are not included, the RIPE Atlas SW Probe does not work correctly. This should also prevent this from happening in the future as it now. We include all files with .sh extension file type. [1] https://github.com/RIPE-NCC/ripe-atlas-software-probe/commit/70ced29fc3217dd8d61e2b78506b6103ded100aa [2] https://github.com/RIPE-NCC/ripe-atlas-software-probe/commit/71a4ff0e68c55464f766ddb9f1dfe21b22e530db Fixes: https://github.com/openwrt/packages/issues/20338 Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
* | snort3: update to 3.1.52.0John Audia2023-01-21
| | | | | | | | | | | | | | | | | | | | Upstream bump Build system: x86_64 Build-tested: bcm2711/RPi4B Run-tested: bcm2711/RPi4B Signed-off-by: John Audia <therealgraysky@proton.me>
* | snort3: update to 3.1.51.0John Audia2023-01-21
| | | | | | | | | | | | | | | | | | | | Upstream bump Build system: x86_64 Build-tested: bcm2711/RPi4B Run-tested: bcm2711/RPi4B Signed-off-by: John Audia <therealgraysky@proton.me>
* | treewide: quote CC and CXXPaul Fertser2023-01-20
| | | | | | | | | | | | | | When CC is set to e.g. "ccache mips-openwrt-linux-musl-gcc" it needs to be quoted to avoid word splitting on substitution. Signed-off-by: Paul Fertser <fercerpav@gmail.com>
* | udphp-client: bump to latest git HEADTianling Shen2023-01-19
| | | | | | | | | | | | Fix build with gcc12. Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | Merge pull request #20337 from bdrung/hosting.deFlorian Eckert2023-01-19
|\ \ | |/ |/| ddns-scripts: add hosting.de provider
| * ddns-scripts: add hosting.de providerBenjamin Drung2023-01-18
| | | | | | | | | | | | | | | | | | | | | | Add hosting.de provider. To use dynamic DNS you have to create a DDNS host with a separate DDNS user. Note: As of 2023-01-17 hosting.de does not work with wget which will fail with `400: Bad Request` (it will work with `--auth-no-challenge`). You should use curl instead. I have reported that to the provider. Signed-off-by: Benjamin Drung <bdrung@bdrung.de>
* | git: update to 2.34.6Michal Vasilek2023-01-18
| | | | | | | | | | | | | | | | | | | | Fixes CVE-2022-23521 Fixes CVE-2022-41903 Fixes CVE-2022-39260 Fixes CVE-2022-39253 Fixes CVE-2022-29187 Signed-off-by: Michal Vasilek <michal.vasilek@nic.cz>
* | v2ray-core: Update to 5.2.1Tianling Shen2023-01-18
|/ | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* Merge pull request #20317 from stangri/master-simple-adblockStan Grishin2023-01-16
|\ | | | | simple-adblock: update sed for allowing domains
| * simple-adblock: update sed for allowing domainsStan Grishin2023-01-14
| | | | | | | | Signed-off-by: Stan Grishin <stangri@melmac.ca>
* | pbr: update to 1.0.1-14Stan Grishin2023-01-17
| | | | | | | | | | | | | | | | * improve install/uninstall messages * fix ips add command * add boot() to init file Signed-off-by: Stan Grishin <stangri@melmac.ca>
* | Merge pull request #20213 from stangri/master-pbrStan Grishin2023-01-16
|\ \ | | | | | | pbr: update to 1.0.1-10
| * | pbr: update to 1.0.1-10Stan Grishin2023-01-16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bugfixes: * better error information for empty tid/mark and failure to resolve domains * better handling of entries in /etc/iproute2/rt_tables * update packages definitions and descriptions * remove firewall4 from dependencies to prevent dependency recursion Updates: * introduce nft_user_set_policy and nft_user_set_counter to control options for user nft sets this service creares * use counters in internal nft sets Signed-off-by: Stan Grishin <stangri@melmac.ca>
* | | atlas-sw-probe: update to version 5080Josef Schlehofer2023-01-16
| | | | | | | | | | | | Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
* | | Merge pull request #20326 from neheb/14Florian Eckert2023-01-16
|\ \ \ | | | | | | | | xinetd: fix URL