public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* [PATCH] core205: Ship fribidi
@ 2026-09-21 14:09 Adolf Belka
  2026-09-21 14:09 ` [PATCH] core205: Ship fuse Adolf Belka
                   ` (8 more replies)
  0 siblings, 9 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/fribidi | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/fribidi

diff --git a/config/rootfiles/core/205/filelists/fribidi b/config/rootfiles/core/205/filelists/fribidi
new file mode 120000
index 000000000..1a17a37c9
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/fribidi
@@ -0,0 +1 @@
+../../../common/fribidi
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] core205: Ship fuse
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] core205: Ship logwatch Adolf Belka
                   ` (7 subsequent siblings)
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/fuse | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/fuse

diff --git a/config/rootfiles/core/205/filelists/fuse b/config/rootfiles/core/205/filelists/fuse
new file mode 120000
index 000000000..570edaade
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/fuse
@@ -0,0 +1 @@
+../../../common/fuse
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] core205: Ship logwatch
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
  2026-09-21 14:09 ` [PATCH] core205: Ship fuse Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] core205: Ship ntfs-3g Adolf Belka
                   ` (6 subsequent siblings)
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/logwatch | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/logwatch

diff --git a/config/rootfiles/core/205/filelists/logwatch b/config/rootfiles/core/205/filelists/logwatch
new file mode 120000
index 000000000..f14eabda9
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/logwatch
@@ -0,0 +1 @@
+../../../common/logwatch
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] core205: Ship ntfs-3g
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
  2026-09-21 14:09 ` [PATCH] core205: Ship fuse Adolf Belka
  2026-09-21 14:09 ` [PATCH] core205: Ship logwatch Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] core205: Ship pixman Adolf Belka
                   ` (5 subsequent siblings)
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/ntfs-3g | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/ntfs-3g

diff --git a/config/rootfiles/core/205/filelists/ntfs-3g b/config/rootfiles/core/205/filelists/ntfs-3g
new file mode 120000
index 000000000..d93adc2a1
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/ntfs-3g
@@ -0,0 +1 @@
+../../../common/ntfs-3g
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] core205: Ship pixman
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
                   ` (2 preceding siblings ...)
  2026-09-21 14:09 ` [PATCH] core205: Ship ntfs-3g Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] fribidi: Update to version 1.0.17 Adolf Belka
                   ` (4 subsequent siblings)
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/core/205/filelists/pixman | 1 +
 1 file changed, 1 insertion(+)
 create mode 120000 config/rootfiles/core/205/filelists/pixman

diff --git a/config/rootfiles/core/205/filelists/pixman b/config/rootfiles/core/205/filelists/pixman
new file mode 120000
index 000000000..fdb6346ae
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/pixman
@@ -0,0 +1 @@
+../../../common/pixman
\ No newline at end of file
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] fribidi: Update to version 1.0.17
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
                   ` (3 preceding siblings ...)
  2026-09-21 14:09 ` [PATCH] core205: Ship pixman Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] fuse: Update to version 3.18.3 Adolf Belka
                   ` (3 subsequent siblings)
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 1.0.16 to 1.0.17
- Update of rootfile
- Changelog
1.0.17
* Update Unicode character databases to v18.0.0
* Significant performance improvements: FSI base direction resolution,
  N0 bracket pairing, embedding-level resolution, and fribidi_reorder_line()
  no longer have quadratic worst-case behavior, giving large speedups on
  long paragraphs/lines.
* Fixed fribidi_set_reorder_nsm() and fribidi_set_mirroring() not taking
  effect when called before fribidi_log2vis().
* Fixed bracket pairing (N0) to match brackets by canonical equivalence
  only, per UAX #9 BD16.
* Fixed a stack buffer overflow when parsing character-set equivalence
  tables, and an out-of-bounds read on trailing '_' in charset data.
* fribidi-main: fixed truncation of lines/output containing embedded
  NUL bytes.
* Generate and install the fribidi(1) man page.
* Various build fixes (MSVC, MinGW, GCC 14 warnings).

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/fribidi | 1 +
 lfs/fribidi                     | 6 +++---
 2 files changed, 4 insertions(+), 3 deletions(-)

diff --git a/config/rootfiles/common/fribidi b/config/rootfiles/common/fribidi
index c19632203..d9b06140f 100644
--- a/config/rootfiles/common/fribidi
+++ b/config/rootfiles/common/fribidi
@@ -26,6 +26,7 @@
 usr/lib/libfribidi.so.0
 usr/lib/libfribidi.so.0.4.0
 #usr/lib/pkgconfig/fribidi.pc
+#usr/share/man/man1/fribidi.1
 #usr/share/man/man3/fribidi_charset_to_unicode.3
 #usr/share/man/man3/fribidi_debug_status.3
 #usr/share/man/man3/fribidi_get_bidi_type.3
diff --git a/lfs/fribidi b/lfs/fribidi
index 9e32b79d7..f215cc0ce 100644
--- a/lfs/fribidi
+++ b/lfs/fribidi
@@ -1,7 +1,7 @@
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007-2024  IPFire Team  <info@ipfire.org>                     #
+# Copyright (C) 2007-2026  IPFire Team  <info@ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 1.0.16
+VER        = 1.0.17
 
 THISAPP    = fribidi-$(VER)
 DL_FILE    = $(THISAPP).tar.xz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 9a0dce6152ba0f0ca4a42a83ca0f6d234fb9fef2a681d274aab6922e3394b70430e677fd549b17b13d928d733c0e72a7e3527cfb461971bbfd155ec1bd5e738c
+$(DL_FILE)_BLAKE2 = 5e2fdef3c47e12af85b2e8d7a9d421a3e9a0f1a92e36bee267a45960c8f3cdc0628011d301d9f0f02ce68bf7007ad14fa4520a41da4a8e3d09483b5e50e83a57
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] fuse: Update to version 3.18.3
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
                   ` (4 preceding siblings ...)
  2026-09-21 14:09 ` [PATCH] fribidi: Update to version 1.0.17 Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] logwatch: Update to version 7.15 Adolf Belka
                   ` (2 subsequent siblings)
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 3.18.1 to 3.18.3
- Update of rootfile
- Changelog
3.18.3
Security Fixes
	* ``fuse_session_custom_io()`` is disabled unless libfuse is built with
	  ``-Denable-custom-io=true``, and returns ``-ENOTSUP`` otherwise. The
	  ``hello_ll_uds`` example is built only with that option, and enabling it
	  warns at configure time.
	  Reason is a custom io peer might not be a kernel and can
	  forge requests that libfuse parses without bounds checks, crashing or
	  corrupting the filesystem process. See ``doc/README.custom-io``.
	* fusermount3: resolve the mountpoint once, through an ``O_PATH|O_NOFOLLOW``
	  descriptor. A symlink swapped in between the type check and the second
	  lookup could redirect the mount.
	* fusermount3: run the auto-unmount probe as the calling user. It opened the
	  caller-supplied mountpoint with elevated privileges before, so a symlink
	  could get an attacker-chosen path opened as root.
	* mount_util: terminate the ``/bin/mount`` and ``/bin/umount`` argument
	  vectors with ``--``. ``fsname`` reaches them straight from ``-ofsname=`` in
	  setuid-root fusermount3, and the child raises the real uid to 0 before
	  ``execle()``, so an unprivileged caller controlled a positional operand of a
	  mount(8) that was not in restricted mode.
	* mount_util: skip the mtab update entirely for option-like mount arguments.
	  BusyBox mount(8) does not honour ``--``.
	* fusermount3: unmount through ``unmount_fuse()`` when passing the device
	  descriptor to the caller fails, so that path drops privileges and runs the
	  ``fusermount3 -u`` checks instead of calling ``umount2()`` as root on a
	  caller-supplied path.
	* fusermount3 and lib: pass ``UMOUNT_NOFOLLOW`` on the kernel and non-setuid
	  unmount paths.
	* fusermount3: check the ``fstat()`` return value when validating the
	  communication file descriptor.
	* fusermount3: fix an out-of-bounds read at index -1 in ``get_mnt_opts()``
	  when the option string is empty, which a read-only mount with no further
	  options reaches.
	* util: avoid a pointer underflow when trimming ``fuse.conf`` lines.
	* fusermount3: reject a negative ``mount_max`` other than the documented -1.
	  A typo such as -2 made the limit comparison always true and blocked every
	  non-root mount.
	* lib: relay the KILLPRIV_V2 kill-suidgid flags to the filesystem in the new
	  ``fuse_file_info::kill_suidgid``. Only ``setattr`` saw them before, so a
	  filesystem that had taken over clearing suid/sgid never learned of it on
	  ``O_TRUNC`` open and on write, and the bits survived.
	Note: ``fuse_file_info::kill_suidgid`` is new in 3.18.3 and ``FUSE_VERSION``
	carries no patch level. A filesystem built against these headers but running
	against an older 3.18 library finds the field permanently zero, so require
	3.18.3 at run time as well.
Important Fixes
	* Fixed a hang on ``statx`` in builds without ``HAVE_STATX``: ``_do_statx()``
	  never replied, so the kernel waited forever.
	* io-uring: the CQE dispatch validated the opcode against ``fuse_ll_ops[]``
	  but called through ``fuse_ll_ops2[]``, so an opcode with no handler there
	  was called as a null function pointer.
	* io-uring: fixed the notify-retrieve reply buffer handling. The
	  ``fuse_notify_retrieve_in`` header sits at the start of the payload buffer,
	  not in the ring header.
	* io-uring: fixed the ``req_header_sz`` calculation, which sized the header
	  buffer from the wrong struct.
	* io-uring: create the rings with ``IORING_SETUP_SUBMIT_ALL``, so one failing
	  commit SQE no longer leaves the rest of the batch unsubmitted.
	* io-uring: ``fuse_reply_none()`` commits the ring entry. A FORGET answered
	  that way leaked the entry and left the kernel-side request outstanding.
	* fusermount3: treat ``ECONNABORTED`` like ``ENOTCONN`` when deciding whether
	  to auto-unmount, so a daemon that dies with io-uring registered no longer
	  leaves the mount behind.
	* ``receive_fd()``: check ``CMSG_FIRSTHDR()`` for NULL before dereferencing it.
	* ``fuse_session_loop_mt_312()`` no longer destroys ``se->mt_lock`` before
	  ``fuse_session_destroy()`` destroys it again, which was undefined behaviour
	  on every multi-threaded shutdown.
	* ``fuse_loop_cfg_create()`` returning NULL is checked before the config is
	  dereferenced in ``fuse_session_loop_mt_312()`` and
	  ``fuse_session_loop_mt_31()``.
	* iconv: the error check after opening the ``fromfs`` descriptor tested
	  ``tofs``, so a failed ``iconv_open()`` was ignored and left an invalid
	  descriptor behind.
	* mount.fuse: a failure to clear ``FD_CLOEXEC`` went undetected, because the
	  result was compared against 1 rather than -1.
	* ``grow_pipe_to_max()`` opens ``/proc/sys/fs/pipe-max-size`` with
	  ``O_CLOEXEC``; a concurrent fork+exec leaked the descriptor into the child.
	* Fixed a build failure for ``FUSE_USE_VERSION`` 312 and newer without symbol
	  versioning, where ``fuse_loop_mt()`` expanded to an undeclared
	  ``fuse_loop_mt_312()``.
	* Fixed a Clang 21 build failure in ``ST_MTIM_NSEC``.
	* Fixed leaks: the pipe when its size cannot be grown, the mountpoint in
	  ``fuse_session_mount()`` and ``fuse_session_destroy()``, the pipe
	  descriptors when ``fork()`` or ``setsid()`` fail in ``fuse_daemonize()``,
	  the context when ``pthread_setspecific()`` fails, ``print_module_help()``,
	  and a ``fuse_pollhandle`` in ``fuse_lib_poll()``.
	* Examples: ``update_fs()`` uses ``localtime_r()``. ``localtime()`` returns a
	  shared static ``struct tm``, so it raced with the session threads and
	  ``strftime()`` could format a half-overwritten time.
	* Examples: ``cuse_client`` caps the transfer size at 16 MiB. ``do_rw()``
	  passed the SIZE argument straight to ``calloc()``.
	* Examples: memfs_ll locking, refcounting and bounds fixes, including a
	  use-after-free on rename overwrite and on a concurrent forget.
	* Examples: passthrough_hp lock-order and lifetime fixes. The directory
	  stream is protected by a per-handle lock, ``fs.mutex`` is taken before
	  ``Inode::m`` and when ``link()`` raises nlookup, and no inode lock is held
	  across a syscall or a reply.
Documentation
	* The fuse-devel mailing list moved to lists.linux.dev.
	* Man page and README corrections.
3.18.2
	* Fix two io-uring issues that might be security critical
	  * fuse-io-uring: Fix UAF and NULL deref in startup error path
	  * fuse-io-uring: Fix NULL deref and memory leak in fuse_uring_init_queue

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/fuse | 2 +-
 lfs/fuse                     | 4 ++--
 2 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/config/rootfiles/common/fuse b/config/rootfiles/common/fuse
index db16cea63..19f90b618 100644
--- a/config/rootfiles/common/fuse
+++ b/config/rootfiles/common/fuse
@@ -11,7 +11,7 @@ usr/bin/fusermount3
 #usr/include/fuse3/fuse_opt.h
 #usr/include/fuse3/libfuse_config.h
 #usr/lib/libfuse3.so
-usr/lib/libfuse3.so.3.18.1
+usr/lib/libfuse3.so.3.18.3
 usr/lib/libfuse3.so.4
 #usr/lib/pkgconfig/fuse3.pc
 usr/lib/udev/rules.d/99-fuse3.rules
diff --git a/lfs/fuse b/lfs/fuse
index aa6e3103c..cb393f06d 100644
--- a/lfs/fuse
+++ b/lfs/fuse
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 3.18.1
+VER        = 3.18.3
 
 THISAPP    = fuse-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = b0a38794b8eb932f7b23314afdaeacbdd302e9f9037794f5dceb87b22f19de8d125ec0112ee28751b94063324c872e03c26e3128c6cd817858245f7df5acd7ef
+$(DL_FILE)_BLAKE2 = d6d1312484bce853b8ad3df2be9ddc4fb9be237948cac48f4d76c1a303d2cc7dcc2c98faf1ca51093d663512040f12cd73376ec92e3f6974eaf0206f853abea3
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] logwatch: Update to version 7.15
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
                   ` (5 preceding siblings ...)
  2026-09-21 14:09 ` [PATCH] fuse: Update to version 3.18.3 Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] ntfs-3g: Update to version 2026.7.7 Adolf Belka
  2026-09-21 14:09 ` [PATCH] pixman: Update to version 0.46.4 Adolf Belka
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 7.11 to 7.15
- Patch for openssh-9.8 has been removed as fixes are part of tarball now.
- Location for symlink for logwatch changed from /usr/sbin/ to /usr/bin/. Patch added
   to revert this as there are saeveral places in IPFire that will have the location
   hardcoded.
- No changelog provided. Only option is to review the git commits.
   https://sourceforge.net/p/logwatch/git/ci/master/tree/

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/logwatch              |  7 ++++
 lfs/logwatch                                  |  8 ++--
 ...SSH-9.8-sshd-session-and-port-number.patch | 39 -------------------
 ...watch-7.15-Revert_sbin_to_bin_change.patch | 13 +++++++
 4 files changed, 24 insertions(+), 43 deletions(-)
 delete mode 100644 src/patches/logwatch/logwatch-7.11-Added-support-for-OpenSSH-9.8-sshd-session-and-port-number.patch
 create mode 100644 src/patches/logwatch/logwatch-7.15-Revert_sbin_to_bin_change.patch

diff --git a/config/rootfiles/common/logwatch b/config/rootfiles/common/logwatch
index 026757b52..adacb6b6a 100644
--- a/config/rootfiles/common/logwatch
+++ b/config/rootfiles/common/logwatch
@@ -82,6 +82,7 @@ usr/share/logwatch/default.conf/services/amavis.conf
 #usr/share/logwatch/default.conf/services/autorpm.conf
 #usr/share/logwatch/default.conf/services/barracuda.conf
 #usr/share/logwatch/default.conf/services/bfd.conf
+#usr/share/logwatch/default.conf/services/chronyd.conf
 #usr/share/logwatch/default.conf/services/cisco.conf
 #usr/share/logwatch/default.conf/services/citadel.conf
 usr/share/logwatch/default.conf/services/clam-update.conf
@@ -92,7 +93,9 @@ usr/share/logwatch/default.conf/services/cron.conf
 #usr/share/logwatch/default.conf/services/denyhosts.conf
 usr/share/logwatch/default.conf/services/dhcpd.conf
 #usr/share/logwatch/default.conf/services/dirsrv.conf
+#usr/share/logwatch/default.conf/services/dnf-automatic.conf
 #usr/share/logwatch/default.conf/services/dnf-rpm.conf
+#usr/share/logwatch/default.conf/services/dnf5.conf
 #usr/share/logwatch/default.conf/services/dnssec.conf
 #usr/share/logwatch/default.conf/services/dovecot.conf
 #usr/share/logwatch/default.conf/services/dpkg.conf
@@ -123,6 +126,7 @@ usr/share/logwatch/default.conf/services/kernel.conf
 #usr/share/logwatch/default.conf/services/lvm.conf
 #usr/share/logwatch/default.conf/services/mailscanner.conf
 usr/share/logwatch/default.conf/services/mdadm.conf
+#usr/share/logwatch/default.conf/services/mdadm.conf.orig
 #usr/share/logwatch/default.conf/services/mod_security2.conf
 usr/share/logwatch/default.conf/services/modprobe.conf
 #usr/share/logwatch/default.conf/services/mountd.conf
@@ -231,6 +235,7 @@ usr/share/logwatch/scripts/services/amavis
 #usr/share/logwatch/scripts/services/autorpm
 #usr/share/logwatch/scripts/services/barracuda
 #usr/share/logwatch/scripts/services/bfd
+#usr/share/logwatch/scripts/services/chronyd
 #usr/share/logwatch/scripts/services/cisco
 #usr/share/logwatch/scripts/services/citadel
 usr/share/logwatch/scripts/services/clam-update
@@ -242,7 +247,9 @@ usr/share/logwatch/scripts/services/cron
 usr/share/logwatch/scripts/services/dhcpd
 usr/share/logwatch/scripts/services/dialup
 #usr/share/logwatch/scripts/services/dirsrv
+#usr/share/logwatch/scripts/services/dnf-automatic
 #usr/share/logwatch/scripts/services/dnf-rpm
+#usr/share/logwatch/scripts/services/dnf5
 #usr/share/logwatch/scripts/services/dnssec
 #usr/share/logwatch/scripts/services/dovecot
 #usr/share/logwatch/scripts/services/dpkg
diff --git a/lfs/logwatch b/lfs/logwatch
index b2452e21e..cbfa139f1 100644
--- a/lfs/logwatch
+++ b/lfs/logwatch
@@ -1,7 +1,7 @@
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007-2024  IPFire Team  <info@ipfire.org>                     #
+# Copyright (C) 2007-2026  IPFire Team  <info@ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 7.11
+VER        = 7.15
 
 THISAPP    = logwatch-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 074b9b1d58bd199c82edc6fb40703b71f9488966e2acb8afc015fde93806740d11a3c8705303139716bbc50c353f3e8c3f4c0e9cf1d5f870cbb8599fbdd526d1
+$(DL_FILE)_BLAKE2 = 25e0b84301a6a7e2011fe107bb87b2deddeda9b263ff83c96fe5d65f67c8a7cecd304c1e10c4b5b11eca83be604201235ee1b4c54ec789385bd966c23e9990cb
 
 install : $(TARGET)
 
@@ -75,7 +75,7 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 	cd $(DIR_APP)/lib && patch -i $(DIR_SRC)/src/patches/logwatch/logwatch-7.11-date_manip6.patch
 	cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/logwatch/logwatch-7.11-disable_iptables.patch
 	cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/logwatch/logwatch-7.11-enable-mdadm-sudo.patch
-	cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/logwatch/logwatch-7.11-Added-support-for-OpenSSH-9.8-sshd-session-and-port-number.patch
+	cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/logwatch/logwatch-7.15-Revert_sbin_to_bin_change.patch
 
 	@cd $(DIR_APP) && chmod 755 install_logwatch.sh
 	cd $(DIR_APP) && yes "" | ./install_logwatch.sh
diff --git a/src/patches/logwatch/logwatch-7.11-Added-support-for-OpenSSH-9.8-sshd-session-and-port-number.patch b/src/patches/logwatch/logwatch-7.11-Added-support-for-OpenSSH-9.8-sshd-session-and-port-number.patch
deleted file mode 100644
index 816f6b4e8..000000000
--- a/src/patches/logwatch/logwatch-7.11-Added-support-for-OpenSSH-9.8-sshd-session-and-port-number.patch
+++ /dev/null
@@ -1,39 +0,0 @@
-diff -Naur logwatch-7.11.orig/conf/services/secure.conf logwatch-7.11/conf/services/secure.conf
---- logwatch-7.11.orig/conf/services/secure.conf	2016-03-09 21:14:35.000000000 +0100
-+++ logwatch-7.11/conf/services/secure.conf	2024-08-27 14:48:48.453853293 +0200
-@@ -24,7 +24,7 @@
- # Use this to ignore certain services in the secure log.
- # You can ignore as many services as you would like.
- # (we ignore sshd because its entries are processed by the sshd script)
--$ignore_services = sshd Pluto stunnel proftpd saslauthd imapd postfix/smtpd
-+$ignore_services = sshd sshd-session Pluto stunnel proftpd saslauthd imapd postfix/smtpd
- 
- # For these services, summarize only (i.e. don't least each IP, just
- # list the number of connections total)
-diff -Naur logwatch-7.11.orig/conf/services/sshd.conf logwatch-7.11/conf/services/sshd.conf
---- logwatch-7.11.orig/conf/services/sshd.conf	2020-09-20 23:38:32.000000000 +0200
-+++ logwatch-7.11/conf/services/sshd.conf	2024-08-27 14:49:08.077782387 +0200
-@@ -19,7 +19,7 @@
- LogFile = messages
- 
- # Only give lines pertaining to the sshd service...
--*OnlyService = sshd
-+*OnlyService = (sshd|sshd-session)
- *RemoveHeaders
- 
- # Variable $sshd_ignore_host is used to filter out hosts that login
-diff -Naur logwatch-7.11.orig/scripts/services/sshd logwatch-7.11/scripts/services/sshd
---- logwatch-7.11.orig/scripts/services/sshd	2022-12-29 01:34:28.000000000 +0100
-+++ logwatch-7.11/scripts/services/sshd	2024-08-27 14:49:21.908202288 +0200
-@@ -246,9 +246,9 @@
-       $NoIdent{$name}++;
-    } elsif (
-       ($ThisLine =~ m/^(?:error:.*|fatal:) Connection closed by remote host/ ) or
--      ($ThisLine =~ m/^(|fatal: )Read error from remote host(| [^ ]+): Connection reset by peer/ ) or
-+      ($ThisLine =~ m/^(|fatal: )Read error from remote host(| [^ ]+)(| port \d+): Connection reset by peer/ ) or
-       ($ThisLine =~ m/^error: .*: read: Connection reset by peer/ ) or
--      ($ThisLine =~ m/^Read error from remote host [^ ]+: (Connection timed out|No route to host)/ ) or
-+      ($ThisLine =~ m/^Read error from remote host [^ ]+(| port \d+): (Connection timed out|No route to host)/ ) or
-       ($ThisLine =~ m/^fatal: Read from socket failed: No route to host/) or
-       ($ThisLine =~ m/^fatal: Write failed: Network is unreachable/ ) or
-       ($ThisLine =~ m/^fatal: Write failed: Broken pipe/) or
diff --git a/src/patches/logwatch/logwatch-7.15-Revert_sbin_to_bin_change.patch b/src/patches/logwatch/logwatch-7.15-Revert_sbin_to_bin_change.patch
new file mode 100644
index 000000000..55f0b2cda
--- /dev/null
+++ b/src/patches/logwatch/logwatch-7.15-Revert_sbin_to_bin_change.patch
@@ -0,0 +1,13 @@
+--- logwatch-7.15/install_logwatch.sh.orig	2026-09-21 12:24:58.939788088 +0200
++++ logwatch-7.15/install_logwatch.sh	2026-09-21 12:27:56.745789515 +0200
+@@ -326,8 +326,8 @@
+ fi
+ 
+ #Symlink
+-ln -f -s $BASEDIR/scripts/logwatch.pl /usr/bin/logwatch
+-printf "Created symlink for /usr/bin/logwatch \n"
++ln -f -s $BASEDIR/scripts/logwatch.pl /usr/sbin/logwatch
++printf "Created symlink for /usr/sbin/logwatch \n"
+ 
+ #Cron or Systemd timer
+ if [ $systemd -eq 1 ]; then
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] ntfs-3g: Update to version 2026.7.7
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
                   ` (6 preceding siblings ...)
  2026-09-21 14:09 ` [PATCH] logwatch: Update to version 7.15 Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  2026-09-21 14:09 ` [PATCH] pixman: Update to version 0.46.4 Adolf Belka
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 2026.2.25 to 2026.7.7
- Update of rootfile
- Fixes for 9 CVE's
- Changelog
2026.7.7
(ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted
	filesystem. (CVE-2026-42616)
Fix heap memory corruption when copying index data from root to an index block in a
	corrupt or maliciously crafted filesystem. (CVE-2026-42617)
Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed
	file data. (CVE-2026-42618)
Fix heap buffer overflow when copying the tail data of an index block to a freshly
	allocated block. (CVE-2026-46569)
Fix out-of-bounds read when processing symlink reparse data in a corrupt or
	maliciously crafted filesystem. (CVE-2026-46571)
Fix heap memory corruption for maliciously crafted or corrupt index data descending to
	an out-of-bounds tree depth. (CVE-2026-46570)
Fix heap buffer overflow for maliciously crafted or corrupt index data during a node
	split. (CVE-2026-46572)
Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135)
Fix out of bounds access when clearing an index root in maliciously crafted or corrupt
	index data. (CVE-2026-56136)

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/ntfs-3g | 9 ++-------
 lfs/ntfs-3g                     | 4 ++--
 2 files changed, 4 insertions(+), 9 deletions(-)

diff --git a/config/rootfiles/common/ntfs-3g b/config/rootfiles/common/ntfs-3g
index e187cbfaa..65d958495 100644
--- a/config/rootfiles/common/ntfs-3g
+++ b/config/rootfiles/common/ntfs-3g
@@ -1,8 +1,8 @@
 bin/lowntfs-3g
 bin/ntfs-3g
 #lib/libntfs-3g.so
-lib/libntfs-3g.so.89
-lib/libntfs-3g.so.89.0.0
+lib/libntfs-3g.so.90
+lib/libntfs-3g.so.90.0.0
 sbin/mkfs.ntfs
 sbin/mount.lowntfs-3g
 sbin/mount.ntfs-3g
@@ -84,10 +84,5 @@ usr/sbin/ntfsundelete
 #usr/share/man/man8/ntfslabel.8
 #usr/share/man/man8/ntfsls.8
 #usr/share/man/man8/ntfsprogs.8
-#usr/share/man/man8/ntfsrecover.8
 #usr/share/man/man8/ntfsresize.8
-#usr/share/man/man8/ntfssecaudit.8
-#usr/share/man/man8/ntfstruncate.8
 #usr/share/man/man8/ntfsundelete.8
-#usr/share/man/man8/ntfsusermap.8
-#usr/share/man/man8/ntfswipe.8
diff --git a/lfs/ntfs-3g b/lfs/ntfs-3g
index fa8dcaf52..d7c4eb20c 100644
--- a/lfs/ntfs-3g
+++ b/lfs/ntfs-3g
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 2026.2.25
+VER        = 2026.7.7
 
 THISAPP    = ntfs-3g-$(VER)
 DL_FILE    = ntfs-3g_ntfsprogs-$(VER).tgz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = e7f7a47ef8178e26dae04a1b8943756629f562d6e98a3500402958b952d21f9f9306070eccf9940b4070454a60883c521f55932f4bccaebe723dafe11d189d8f
+$(DL_FILE)_BLAKE2 = 2cdeeeb00a9274282e3455bd2827f388b11a5f69b06f85c7655e175e493269b4e9447843de4ef69748d406e58df5d3bf5832086337d74dfd5a9bcf3e47e49b2f
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PATCH] pixman: Update to version 0.46.4
  2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
                   ` (7 preceding siblings ...)
  2026-09-21 14:09 ` [PATCH] ntfs-3g: Update to version 2026.7.7 Adolf Belka
@ 2026-09-21 14:09 ` Adolf Belka
  8 siblings, 0 replies; 10+ messages in thread
From: Adolf Belka @ 2026-09-21 14:09 UTC (permalink / raw)
  To: development; +Cc: Adolf Belka

- Update from version 0.46.2 to 0.46.4
- Update of rootfile
- Changelog
0.46.4
	RISC-V: Use hwprobe interface to check for RVV 1.0

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/common/pixman | 2 +-
 lfs/pixman                     | 6 +++---
 2 files changed, 4 insertions(+), 4 deletions(-)

diff --git a/config/rootfiles/common/pixman b/config/rootfiles/common/pixman
index 913b860eb..5aa676077 100644
--- a/config/rootfiles/common/pixman
+++ b/config/rootfiles/common/pixman
@@ -3,5 +3,5 @@
 #usr/include/pixman-1/pixman.h
 #usr/lib/libpixman-1.so
 usr/lib/libpixman-1.so.0
-usr/lib/libpixman-1.so.0.46.2
+usr/lib/libpixman-1.so.0.46.4
 #usr/lib/pkgconfig/pixman-1.pc
diff --git a/lfs/pixman b/lfs/pixman
index ca195cec3..cd520eee5 100644
--- a/lfs/pixman
+++ b/lfs/pixman
@@ -1,7 +1,7 @@
 ###############################################################################
 #                                                                             #
 # IPFire.org - A linux based firewall                                         #
-# Copyright (C) 2007-2025  IPFire Team  <info@ipfire.org>                     #
+# Copyright (C) 2007-2026  IPFire Team  <info@ipfire.org>                     #
 #                                                                             #
 # This program is free software: you can redistribute it and/or modify        #
 # it under the terms of the GNU General Public License as published by        #
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 0.46.2
+VER        = 0.46.4
 
 THISAPP    = pixman-$(VER)
 DL_FILE    = $(THISAPP).tar.xz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 6d51d4f33f48a1cc991085b5e62e7537b738df78c4efcbce15c37533f24a1d87263401550530d123de86bd72a856d3fd0b1543188c76f074ea3e44d384f1116f
+$(DL_FILE)_BLAKE2 = b00041009aeed3cd2548251489df6fcb5efb0415a8279451306558b2e736e2b012b11335b4ed3361e0126cad861873c0675dae24eb031b2434e45a7d39e087d8
 
 install : $(TARGET)
 
-- 
2.55.0



^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-09-21 14:10 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-21 14:09 [PATCH] core205: Ship fribidi Adolf Belka
2026-09-21 14:09 ` [PATCH] core205: Ship fuse Adolf Belka
2026-09-21 14:09 ` [PATCH] core205: Ship logwatch Adolf Belka
2026-09-21 14:09 ` [PATCH] core205: Ship ntfs-3g Adolf Belka
2026-09-21 14:09 ` [PATCH] core205: Ship pixman Adolf Belka
2026-09-21 14:09 ` [PATCH] fribidi: Update to version 1.0.17 Adolf Belka
2026-09-21 14:09 ` [PATCH] fuse: Update to version 3.18.3 Adolf Belka
2026-09-21 14:09 ` [PATCH] logwatch: Update to version 7.15 Adolf Belka
2026-09-21 14:09 ` [PATCH] ntfs-3g: Update to version 2026.7.7 Adolf Belka
2026-09-21 14:09 ` [PATCH] pixman: Update to version 0.46.4 Adolf Belka

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox