aboutsummaryrefslogtreecommitdiff
path: root/net
Commit message (Collapse)AuthorAge
* Merge pull request #7278 from neheb/seafileHannu Nyman2018-11-03
|\ | | | | seafile-ccnet: Update to 6.3.4
| * seafile-ccnet: Update to 6.3.4Rosen Penev2018-10-29
| | | | | | | | | | | | Switched to codeload for easier package bumping. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | Merge pull request #6811 from Robby-/master-freeradius3-eap-pwdHannu Nyman2018-11-03
|\ \ | | | | | | freeradius3: Enable the EAP-PWD module.
| * | freeradius3: Enable the EAP-PWD module.Robby K2018-08-20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This enables the EAP-PWD module, which allows for logging in with only a username and password, while still being secure (see the links below for the details of this EAP method, if interested). https://en.wikipedia.org/wiki/Extensible_Authentication_Protocol#EAP_Password_(EAP-PWD) Also found this blog post which talks about EAP-PWD and its benefits: https://dustri.org/b/eap-pwd-wifi-security-done-right.html Signed-off-by: Robby K <robbyke@gmail.com>
* | | haproxy: Update all patches for HAProxy v1.8.14Christian Lachner2018-11-02
| | | | | | | | | | | | | | | | | | | | | - Add new patches (see https://www.haproxy.org/bugs/bugs-1.8.14.html) - Raise PKG_RELEASE to 4 Signed-off-by: Christian Lachner <gladiac@gmail.com>
* | | Merge pull request #7267 from neheb/hapHannu Nyman2018-11-02
|\ \ \ | | | | | | | | haproxy: Remove unnecessary OpenSSL depends
| * | | haproxy: Remove unnecessary OpenSSL dependsRosen Penev2018-10-30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | All of these are either not needed or not valid. Added a patch to remove the OPENSSL_WITH_DEPRECATED dependency. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | | | Shorewall6: Bump to version 5.2.1.1W. van den Akker2018-11-01
| | | | | | | | | | | | | | | | Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl>
* | | | Shorewall: Bump to version 5.2.1.1W. van den Akker2018-11-01
| | | | | | | | | | | | | | | | Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl>
* | | | Shorewall6-lite: Bump to version 5.2.1.1W. van den Akker2018-11-01
| | | | | | | | | | | | | | | | Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl>
* | | | Shorewall-lite: Bump to version 5.2.1.1W. van den Akker2018-11-01
| | | | | | | | | | | | | | | | Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl>
* | | | Shorewall-core: Bump to version 5.2.1.1W. van den Akker2018-11-01
| | | | | | | | | | | | | | | | Signed-off-by: W. van den Akker <wvdakker@wilsoft.nl>
* | | | oor: Add OpenOverlayRouter (oor) packageAlbert Lopez2018-10-31
|/ / / | | | | | | | | | | | | | | | lispmob: OOR is a rename of LISPmob and replace the package Signed-off-by: Albert Lopez <alopez@ac.upc.edu>
* | / travelmate: update 1.3.0Dirk Brenken2018-10-30
| |/ |/| | | | | | | | | | | | | | | | | | | * proactively scan and switch to a higher prioritized uplink, despite of an already existing connection, this is configurable via 'trm_proactive' option (default '1', enabled) * fix some minor list trim issues * optimize wlan scanning behavior * refine debug messages Signed-off-by: Dirk Brenken <dev@brenken.org>
* | bind: Update bind.keysNoah Meyerhans2018-10-29
| | | | | | | | | | | | | | | | | | A multi-year DNSSEC root key update is in progress, as described at https://www.isc.org/downloads/bind/bind-keys/. This change refreshes the bind.keys file, ensuring that the new key, in place as of 2018-10-11, will be recognized and trusted. Signed-off-by: Noah Meyerhans <frodo@morgul.net>
* | bind: Include delv in the bind-tools packageNoah Meyerhans2018-10-29
| | | | | | | | | | | | | | delv is a tool for sending DNS queries and validating the results, using the same internal resolver and validator logic as named. Signed-off-by: Noah Meyerhans <frodo@morgul.net>
* | bind: Update to 9.11.5Noah Meyerhans2018-10-29
| | | | | | | | | | | | | | | | | | This includes the fix for CVE-2018-5738: When recursion is enabled but the allow-recursion and allow-query-cache ACLs are not specified, they should be limited to local networks, but they were inadvertently set to match the default allow-query, thus allowing remote queries. Signed-off-by: Noah Meyerhans <frodo@morgul.net>
* | openvswitch: bump to version 2.10.1Yousong Zhou2018-10-29
| | | | | | | | Signed-off-by: Yousong Zhou <yszhou4tech@gmail.com>
* | bind: Remove OpenSSL deprecated APIs dependencyRosen Penev2018-10-28
| | | | | | | | | | | | It seems to not be needed anymore. Tested on mvebu and ar71xx. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | isc-dhcp: drop .conf suffix on dhcrelay config filePhilip Prindeville2018-10-28
| | | | | | | | | | | | Resolves issue #7235 Signed-off-by: Philip Prindeville <philipp@redfish-solutions.com>
* | Merge pull request #7213 from gladiac1337/feature-haproxy-v1.8.14-updatesThomas Heil2018-10-28
|\ \ | | | | | | haproxy: Update all patches for HAProxy v1.8.14
| * | haproxy: Update all patches for HAProxy v1.8.14Christian Lachner2018-10-17
| | | | | | | | | | | | | | | | | | | | | - Add new patches (see https://www.haproxy.org/bugs/bugs-1.8.14.html) - Raise PKG_RELEASE to 2 Signed-off-by: Christian Lachner <gladiac@gmail.com>
* | | Merge pull request #7063 from neheb/patch-38Hannu Nyman2018-10-28
|\ \ \ | | | | | | | | libsearpc: Update to 3.1.0
| * | | libsearpc: Update to 3.1.0Rosen Penev2018-10-14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Switch to codeload for simplicity. Rearranged Makefile a bit for consistency between Makefiles. Removed version dependency for seafile-server to avoid breaking builds. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | | | Merge pull request #7176 from neheb/joolHannu Nyman2018-10-28
|\ \ \ \ | | | | | | | | | | jool: Backport two fixes for newer kernels.
| * | | | jool: Backport two fixes for newer kernels.Rosen Penev2018-10-11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The first is needed for 4.14 (maybe the relevant parts got packported and the second is for when OpenWrt migrates to 4.19. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | | | | Merge pull request #7177 from neheb/patch-44Hannu Nyman2018-10-28
|\ \ \ \ \ | | | | | | | | | | | | spoofer: Update to 1.4.0
| * | | | | spoofer: Update to 1.4.0Rosen Penev2018-10-11
| |/ / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Added PKG_USE_MIPS16 as it seems not to build under mipsel. Error: opcode not supported on this processor: mips32r2 (mips32r2) `sync' Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | | | | Merge pull request #7215 from jsiverskog/mdnsresponder_878_70_2Hannu Nyman2018-10-28
|\ \ \ \ \ | | | | | | | | | | | | mdnsresponder: bump to 878.70.2 and refresh patches
| * | | | | mdnsresponder: remove Steven Barth as maintainerJacob Siverskog2018-10-19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | https://github.com/openwrt/packages/pull/7215#issuecomment-431281385 Signed-off-by: Jacob Siverskog <jacob@teenage.engineering>
| * | | | | mdnsresponder: bump to 878.70.2 and refresh patchesJacob Siverskog2018-10-18
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: Jacob Siverskog <jacob@teenage.engineering>
* | | | | | Merge pull request #7251 from brvphoenix/masterDirk Brenken2018-10-25
|\ \ \ \ \ \ | | | | | | | | | | | | | | aria2: fixed the spelling for rpc-passwd and rpc-user.
| * | | | | | aria2: fixed the spelling for rpc-passwd and rpc-user.brv phoenix2018-10-25
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: brv phoenix <feixuekaka1@gmail.com>
* | | | | | | Merge pull request #7249 from EricLuehrsen/unbound_axfrDirk Brenken2018-10-25
|\ \ \ \ \ \ \ | | | | | | | | | | | | | | | | unbound: fix odhcpd and axfr script functions
| * | | | | | | unbound: fix odhcpd link and axfr zone scriptsEric Luehrsen2018-10-24
| |/ / / / / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - fix AXFR zones to delay a potentially large download with ntp-hotplug - fix odhcpd link script to properly delete expired lease data from DNS Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
* | | | | | | Merge pull request #7247 from TDT-AG/pr/20181023-mwan3Dirk Brenken2018-10-25
|\ \ \ \ \ \ \ | |/ / / / / / |/| | | | | | net/mwan3: improvements
| * | | | | | net/mwan3: update version to 2.7.5Florian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | | | | net/mwan3: add online_metric for local_source noneFlorian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | If we set the option "local_source" in the globals mwan3 section to "none", traffic generated by the router it self will always use the default route from the wan interface with the lowest metric. If this interface is down the router traffic still uses the connection with the lowest metric but this is disconnected. Load balancing and failover from the lan site is still possible. Only router generated traffic is not load balanced and could not use failover. To solve this issue with router initiated traffic add the additional option "online_metric" to the mwan3 interface section. If the interface is connected then this lower "online metric" is set in the default routing table. With this change we have at least a failover with router initiated traffic. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | | | | net/mwan3: add dynamic ipsets to mwan3_connected ipsetsFlorian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | During runntime of mwan3 we could add dynamicly networks to this ipset which would then treated as connected networks by mwan3. This is also usefull for ipsec. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | | | | net/mwan3: add custom address from ip tables to connected ipsetFlorian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | With the list param "rt_table_lookup" in the mwan3 section globals, it is now possible to add a additional routing table numbers which would get also parsed and will be added to the connected network. So mwan3 will treat them as they are directly connected to this device. This could be usefull if we use ipsec. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | | | | net/mwan3: cleanup egrep ipv6 regexFlorian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The IPv6 egrep regex is confusing and hard to maintain. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | | | | net/mwan3: enhance ipset status generationFlorian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This change should optimize and speed up the status output generation. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | | | | net/mwan3: reduce duplicate codeFlorian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The generation for reporting the policies uses the same code add a common function to reduce duplication. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | | | | net/mwan3: cleanup/prettify 80 characters code boundaryFlorian Eckert2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Prettify and cleanup source Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* | | | | | | gnunet: adapt uci-defaults to renamed namestore-flat -> -heapDaniel Golle2018-10-25
|/ / / / / / | | | | | | | | | | | | | | | | | | Signed-off-by: Daniel Golle <daniel@makrotopia.org>
* | | | | | clamav: Update to 0.100.2Rosen Penev2018-10-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes CVE-2018-15378. Added PKG_CPE_ID for proper CVE tracking. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | | | | | gnunet: update sourceDaniel Golle2018-10-21
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: Daniel Golle <daniel@makrotopia.org>
* | | | | | openssh: fixes issues with some openssl optionsPeter Wagner2018-10-20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a couple of patches when setting some openssl options: * ECDSA code in openssh-compat.h and libressl-api-compat.c needs to be be guarded by OPENSSL_HAS_ECC; otherwise, it will not build with openssl compiled without ECC support. * Fix openssl version number in openbsd-compat/openssl-compat.c which failed to compile --with-ssl-engine; this option is used when CONFIG_OPENSSL_ENGINE_CRYPTO=y Signed-off-by: Eneas U de Queiroz <cote2004-github@yahoo.com> Signed-off-by: Peter Wagner <tripolar@gmx.at>
* | | | | | strongswan: bump to 5.7.1Stijn Tintel2018-10-19
| | | | | | | | | | | | | | | | | | | | | | | | Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be>
* | | | | | openssh: update to 7.9p1Peter Wagner2018-10-19
|/ / / / / | | | | | | | | | | | | | | | Signed-off-by: Peter Wagner <tripolar@gmx.at>