aboutsummaryrefslogtreecommitdiff
path: root/net
Commit message (Collapse)AuthorAge
...
| * | sing-box: update to 1.8.0Anya Lin2024-01-07
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | New features for v1.8.0: 1. Migrate cache file from Clash API to independent options 2. Introducing Rule Set 3. Add `sing-box geoip`, `sing-box geosite` and `sing-box rule-set` commands 4. Allow nested logical rules 5. Independent `source_ip_is_private` and `ip_is_private` rules 6. Add context to JSON decode error message 7. Reject internal fake-ip queries 8. Add GSO support for TUN and WireGuard system interface 9. The legacy LWIP stack has been deprecated and removed 10. Add `idle_timeout` for URLTest outbound 11. Added some new uTLS fingerprints ... Release notes: https://github.com/SagerNet/sing-box/releases/tag/v1.8.0 The new version has some breaking changes and may stop working after upgrading if use the original config. Please see the migration manual to migrate the config: https://sing-box.sagernet.org/migration/ Signed-off-by: Anya Lin <hukk1996@gmail.com>
* | | openssh: fix build failure on powerpc_8548Sibren Vasse2024-01-06
| | | | | | | | | | | | | | | | | | https://github.com/openssh/openssh-portable/commit/1036d77b34a5fa15e56f516b81b9928006848cbd Signed-off-by: Sibren Vasse <github@sibrenvasse.nl>
* | | openssh: bump to 9.6p1Rucke Teg2024-01-06
| | | | | | | | | | | | | | | | | | Release notes: https://www.openssh.com/txt/release-9.6 Signed-off-by: Rucke Teg <rucketeg@protonmail.com>
* | | travelmate: release 2.1.2-1Dirk Brenken2024-01-06
|/ / | | | | | | | | | | * fix a station scanning issue on single radio units (mainly a LuCI/JS issue) reported in the forum by multiple users Signed-off-by: Dirk Brenken <dev@brenken.org>
* | nfdump: add dependency on libzstdW. Michael Petullo2024-01-05
| | | | | | | | Signed-off-by: W. Michael Petullo <mike@flyn.org>
* | nginx: update to 1.25.3Tiago Gaspar2024-01-04
| | | | | | | | | | | | Update nginx to the latest version. Signed-off-by: Tiago Gaspar <tiagogaspar8@gmail.com>
* | wifi_schedule: fix startup problemsRani Hod2024-01-03
| | | | | | | | | | | | | | | | | | | | | | | | | | Fixes: e0d7181a6 Closes: #22973 Closes: #22988 1. Make the new `startup()` function in `/usr/bin/wifi_schedule.sh` respect the global `enabled` config flag; in particular, make no changes to `/etc/config/wireless` when wifi_schedule is disabled. 2. Make the new `/etc/init.d/wifi_schedule` service script executable. Signed-off-by: Rani Hod <rani.hod@gmail.com>
* | dhtd: update to 1.0.1Moritz Warning2024-01-03
| | | | | | | | Signed-off-by: Moritz Warning <moritzwarning@web.de>
* | dnsproxy: Update to 0.61.1Tianling Shen2024-01-03
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | v2ray-geodata: Update to latest versinTianling Shen2024-01-03
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | v2raya: Update to 2.2.4.6Tianling Shen2024-01-03
| | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | Merge pull request #23047 from neheb/fuNikos Mavrogiannopoulos2024-01-03
|\ \ | | | | | | openconnect: update to 9.12
| * | openconnect: update to 9.12Rosen Penev2024-01-02
| | | | | | | | | | | | | | | | | | Remove upstream backport and fix libxml 1.12 compilation. Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | | snort: remove packageW. Michael Petullo2024-01-03
| | | | | | | | | | | | | | | | | | Replaced with snort3. Signed-off-by: W. Michael Petullo <mike@flyn.org>
* | | hs20: fix compilation with libxml 2.12Rosen Penev2024-01-02
|/ / | | | | | | Signed-off-by: Rosen Penev <rosenp@gmail.com>
* | netbird: update to version 0.25.2Misha Bragin2024-01-02
| | | | | | Signed-off-by: Misha Bragin <bangvalo@gmail.com>
* | snort3: add missing action-override optionEric Fahlgren2024-01-02
| | | | | | | | | | | | | | | | | | Allow use of rules as-defined, and don't override their actions. This is generally the best way to use the ruleset, and overriding their actions should only be undertaken when you fully understand how it affects their use. Signed-off-by: Eric Fahlgren <ericfahlgren@gmail.com>
* | snort3: compile with lzma supportJohn Audia2024-01-02
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This PR adds the ability of snort to process rules that target swf and pdf files requiring lzma decompression to look for malicious payloads therein. This change only increases the size of the snort3 executable by a fraction of a KB and the added dependency of liblzma (based on currently offered 5.4.4-1) is only a 169 KB shared object. Based on CPU requirements of snort, x86 users likely represent the majority user-base and space their rootfs is not an issue as it may be for lower-powered SoCs. Size of snort3-3.1.76.0-2: 7354403 bytes Size of snort3-3.1.76.0-3: 7354435 bytes Build system: x86/64 Build-tested: x86/64/AMD Cezanne Run-tested: x86/64/AMD Cezanne Signed-off-by: John Audia <therealgraysky@proton.me>
* | Openvpn: add missing script event optionsErik Conijn2024-01-02
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Maintainer: @mkrkn @neheb Compile tested: aarch64, cortex-a53, OpenWRT Master Run tested: Dynalink DL-WRX36 Description: [A previous commit](https://github.com/openwrt/packages/commit/f8a8b71e26b9bdbf86fbb7d4d1482637af7f3ba4) has added more script event options. However it looked like that commit was not complete as it stops the use of the script events route-up, route-pre-down, and ipchange when those are placed in the openvpn config file. This PR fixes a regression that makes it problematic to specify certain event options in the OpenVPN configuration file. Discussion in [this thread](https://forum.openwrt.org/t/openvpn-custom-route-up-script-in-23-05-rc2/167105/13) and [here](https://forum.openwrt.org/t/openvpn-route-up-and-route-pre-down-broken-in-23-05/176568) Please have a look and consider implementing or make it possible to use all script event options in the openvpn config file in another way. Pull request has been discussed and improved with the help of @AuthorReflex, see: https://github.com/openwrt/packages/pull/21732 Signed-off-by: Erik Conijn <egc112@msn.com>
* | nqptp: Add new port nqptp for use with shairport-syncBen Klang2024-01-02
| | | | | | | | Signed-off-by: Ben Klang <bklang@wirehack.net>
* | nfdump: update to 1.7.3W. Michael Petullo2024-01-02
| | | | | | | | Signed-off-by: W. Michael Petullo <mike@flyn.org>
* | krb5: update to 1.21.2W. Michael Petullo2024-01-02
| | | | | | | | Signed-off-by: W. Michael Petullo <mike@flyn.org>
* | snowflake: update to 2.8.1Nick Hainke2024-01-02
| | | | | | | | | | | | | | Changelog: https://gitlab.torproject.org/tpo/anti-censorship/pluggable-transports/snowflake/-/blob/v2.8.1/ChangeLog Signed-off-by: Nick Hainke <vincent@systemli.org>
* | sing-box: Update to 1.7.7Anya Lin2023-12-30
| | | | | | | | Signed-off-by: Anya Lin <hukk1996@gmail.com>
* | dnsdist: Enable custom load-balancing policies in the light versionRemi Gacogne2023-12-28
| | | | | | | | Signed-off-by: Remi Gacogne <remi.gacogne@powerdns.com>
* | banip: update 0.9.3-3Dirk Brenken2023-12-28
| | | | | | | | | | | | * more init fixes Signed-off-by: Dirk Brenken <dev@brenken.org>
* | banip: update 0.9.3-2Dirk Brenken2023-12-28
| | | | | | | | | | | | | | | | | | | | * rework the device/interface auto-detection (only layer-3 network devices will be detetcted correctly), disable the auto-detection e.g. for special tunnel interfaces * supports now full gawk (preferred, if installed) and busybox awk * raise the default boot timeout to 20 seconds (if 'ban_triggerdelay' is not set) * various small fixes and improvements * readme update Signed-off-by: Dirk Brenken <dev@brenken.org>
* | sshtunnel: update to v5.2Sergey Ponomarev2023-12-27
| | | | | | | | Signed-off-by: Sergey Ponomarev <stokito@gmail.com>
* | sshtunnel: simplify command compositionSergey Ponomarev2023-12-27
| | | | | | | | | | | | | | | | | | | | | | | | Remove append_params and use shell expressions instead e.g. ${port:+-p $port}. Note that we can't do that with ProxyCommand because it has to be quoted. The order of options was changed from more important like hostname to just static -nN. The CompressionLevel option is removed from SSH2. Signed-off-by: Sergey Ponomarev <stokito@gmail.com>
* | sshtunnel: ProxyCommand optionSergey Ponomarev2023-12-27
| | | | | | | | | | | | | | | | | | | | The ProxyCommand may have spaces so it must be quoted. So we must use the procd_append_param. Currently the option is not supported by Dropbear. But it has -J instead which in OpenSSH means ProxyJump. So we can't use it to avoid conflict. Signed-off-by: Sergey Ponomarev <stokito@gmail.com>
* | nebula: update to 1.8.1Stan Grishin2023-12-26
| | | | | | | | | | | | * https://github.com/slackhq/nebula/releases/tag/v1.8.1 Signed-off-by: Stan Grishin <stangri@melmac.ca>
* | tailscale: Update to 1.56.1Shi JiaYang2023-12-25
| | | | | | | | Signed-off-by: Shi JiaYang <shi05275@163.com>
* | Merge pull request #22898 from lowjoel/strongswan-fix-no-instancesPhilip Prindeville2023-12-24
|\ \ | | | | | | strongswan: trigger reload when interfaces are specified
| * | strongswan: trigger reload when interfaces are specifiedJoel Low2023-12-18
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Fixes #20848 Add interface triggers if interfaces to listen to are specified in `/etc/config/ipsec`. This fixes the "running with no instances" scenario after rebooting a router. Signed-off-by: Joel Low <joel@joelsplace.sg>
* | | snort3: update to 3.1.77.0John Audia2023-12-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Changelog: https://github.com/snort3/snort3/releases/tag/3.1.77.0 ,,_ -*> Snort++ <*- o" )~ Version 3.1.77.0 '''' By Martin Roesch & The Snort Team http://snort.org/contact#team Copyright (C) 2014-2023 Cisco and/or its affiliates. All rights reserved. Copyright (C) 1998-2013 Sourcefire, Inc., et al. Using DAQ version 3.0.13 Using LuaJIT version 2.1.0-beta3 Using OpenSSL 3.0.12 24 Oct 2023 Using libpcap version 1.10.4 (with TPACKET_V3) Using PCRE version 8.45 2021-06-15 Using ZLIB version 1.3 Using Hyperscan version 5.4.2 2023-12-20 Build system: x86/64 Build-tested: x86/64/AMD Cezanne Run-tested: x86/64/AMD Cezanne Signed-off-by: John Audia <therealgraysky@proton.me>
* | | gnunet: update to version 0.20.0Daniel Golle2023-12-22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | v0.20.0: - GNUNET_TESTING_get_testname_from_underscore renamed to GNUNET_STRINGS_get_suffix_from_binary_name and moved from libgnunettesting to libgnuneutil - Move GNUNET_s into libgnunetutil. - re-introduce compiler annotation for array size in signature - function-signature adjustment due to compiler error - GNUNET_PQ_get_oid removed, GNUNET_PQ_get_oid_by_name improved - Added GNUNET_PQ_get_oid_by_name - added GNUNET_PQ_get_oid() - Added new CCA-secure KEM and use in IDENTITY encryption - Add KEM API to avoid ephemeral private key management - Add new GNUNET_PQ_event_do_poll() API to gnunet_pq_lib.h - Added API to support arrays in query results - Improve PQ API documentation. - API for array types extended for times - API extended for array query types - relevant array-types in queries (not results) in postgresql added - just style fixes, int to enum - initial steps towards support of array-types in posgresql - adds GNUNET_JSON_spec_object_const() and GNUNET_JSON_spec_array_const() Signed-off-by: Daniel Golle <daniel@makrotopia.org>
* | | Merge pull request #22941 from TDT-AG/pr/20231220-openvpnFlorian Eckert2023-12-22
|\ \ \ | | | | | | | | openvpn: start openvpn connection located under '/etc/openvpn' not only on system start
| * | | openvpn: bump PKG_RELEASEFlorian Eckert2023-12-20
| | | | | | | | | | | | | | | | Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | openvpn: Added option to not start the native OpenVPN configurations on bootFlorian Eckert2023-12-20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | OpenVPN configurations that have a uci entry, the enable/enabled option can be used to control whether the OpenVPN connection should be started at system startup or not. OpenVPN configurations that are located under '/etc/openvpn/' are always started at system boot. To ensure that these connections can also be started later, they must 'not' be started automatically during system boot. This can be prevented with the following entry in the OpenVPN configuration. config globals 'globals' option autostart '0' These OpenVPN configurations can then be started later with the command. '/etc/init.d/openvpn start <name>' Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | openvpn: add possibility to start openvpn_path_instance on requestFlorian Eckert2023-12-20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This commit adds the possibility that an OpenVPN instance located under '/etc/openvpn' can also be started with the command. '/etc/init.d/openvpn start <name>' Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | openvpn: add start_path_instance functionFlorian Eckert2023-12-20
| | | | | | | | | | | | | | | | | | | | | | | | This commit moves the part for starting an instance to a sub function. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | openvpn: move path instances call to sub functionFlorian Eckert2023-12-20
| | | | | | | | | | | | | | | | | | | | | | | | Move the start of the OpenVPN configurations in '/etc/openvpn' in a function. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
| * | | openvpn: rename start_instance to start_uci_instanceFlorian Eckert2023-12-20
| | | | | | | | | | | | | | | | | | | | | | | | Preparation commit to make it clear that this is a uci configuration. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* | | | alist: add new packageTianling Shen2023-12-22
| | | | | | | | | | | | | | | | | | | | | | | | | | | | AList is a file list/WebDAV program that supports multiple storages, powered by Gin and Solidjs. Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
* | | | wsdd2: update to 2023-12-21Alan Luck2023-12-21
| | | | | | | | | | | | | | | | Signed-off-by: Alan Luck <luckyhome2008@gmail.com>
* | | | pdns: update to 4.8.4Peter van Dijk2023-12-21
| | | | | | | | | | | | | | | | Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
* | | | dnsdist: update to 1.8.3Peter van Dijk2023-12-21
| | | | | | | | | | | | | | | | Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
* | | | mdio-tools: update to 1.3.1Robert Marko2023-12-21
|/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Update the mdio-netlink kmod and userspace mdio-tools to version 1.3.1. [v1.3.1] - 2023-12-02 --------------------- Fixes mvls to work with kernels 6.2 and onwards. - mdio: Multiple registers can now be dumped at once, via the generic dump operation. - mvls: Relax the driver matching to accept the strings used in kernels 6.2 and newer. Signed-off-by: Robert Marko <robimarko@gmail.com>
* | | libcurl-gnutls: update to version 8.5.0Daniel Golle2023-12-20
| | | | | | | | | | | | | | | | | | | | | | | | | | | https://curl.se/changes.html#8_5_0 Pick upstream patch to fix build with gnuTLS and verbose strings removed. The patch should be removed with the next version bump. Signed-off-by: Daniel Golle <daniel@makrotopia.org>
* | | dnsproxy: Update to 0.61.0Tianling Shen2023-12-20
| | | | | | | | | | | | Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>