From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4j09786cFHz32fl for ; Wed, 07 Oct 2026 10:57:08 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4j09752sRkz32MR for ; Wed, 07 Oct 2026 10:57:05 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4j097223thzG9; Wed, 07 Oct 2026 10:57:02 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1791370622; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=TG4Q0wJv9SM8evlAyPkzDMXBoNfXORry/F6bJiQDIoM=; b=jgoHQTpaWQk89j6MPqZZq7pe58gFFDK6GNJyleOdv3BvBbtvCYcZi7XX76TQ4O6C4i7cXA 2ZWNhXYh7+0P6ICw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1791370622; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=TG4Q0wJv9SM8evlAyPkzDMXBoNfXORry/F6bJiQDIoM=; b=qGyW7u6a7d1s2uMTa2lnNXurwBQIyUP5cstTeJ/gx3AYGU871cIPqt6c7bCPpxMi/pLrLD Ghbrb/ddvCmMchOhhSS77rvYYhj/SNub4tuvZ45B1Bz06Elp539OecikQOhNnZcFG+tfgO baVw6vB71Jw/xSdHOjy/K1lFwa/34z78Y5EykHF7uh3j8J4RasHPvEx2qkaW0cyf8UX1mR 0Hunc9HwEmeCGpYD2Q+P91BP6lLCd1dDDv5uxpfhPCNDz5RXBHMpPO2Dcr7YKPNYsgYUCN pPNf4dAxVQg4QF7btD8tS0xaIyYB6LmGHlHnEMOaFX/rHQ1I0g3UPyhbC8rR/w== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] bird: Update to version 3.3.3 Date: Wed, 7 Oct 2026 12:56:49 +0200 Message-ID: <20261007105658.104404-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit - Update from version 2.15.1 to 3.3.3 - No change in rootfile - Although there are no CVE's mentioned some of the bug fixes look to be security related - Changelog 3.3.3 o BMP/Nest: No refeed after listener or protocol restart o BMP: Fix crash on sending routes o BMP: Fix route sending when no import table is configured o EVPN: Improve tunnel and bridge intarface handling o Netlink: Fix handling of interface attributes for slave interfaces o OSPF: Fix LSA length overflow o RAdv: Add hop limit validation o RPKI: Fix socket close detection during rx_hook o Proto: Fix VRF settings o MPLS: Fix crash on reconfiguring label ranges o Tools: Fix version script for Git 2.55+ o Conf: Fix use-after-free in cf_include() error path o Lib: Fix bvsnprintf() on too long net_addr values o Lib: Fix endptr in bstrtoul16() 3.3.2 o BGP: Fix stack buffer overflow in Flowspec NLRI decoder o BGP: Minor improvements in Flowspec parsing o BGP: Fix minor issues with send hold timer o Fix null byte handling in authentication keys o Pipe, L3VPN: Fix hostentry stripping o Filter: Fix zero arg handling o Logging: Fix use-after-free on failed rotation o CLI: Fix crashes in show route o Allocator: Pre-fill hot pages when entering RCU critical section o Fix obstacle cleanup o Update bird-users mailing list links 3.3.1 o BGP: Fix crash when incoming connection for disabled protocol arrives o BGP: Fix parsing labelled NLRIs with no next hop o BGP: Fix cork behavior in collision with graceful restart o BGP: Fix crash on dumping pending export statistics o BGP: Fix several issues in Flowspec handling o BMP/Nest: No refeed after listener or protocol restart o MPLS: Fix crash on reconfiguring CS_DOWN channel o OSPF: Fix handling of LLS data length field o OSPF: Fix OOB read in authentication check o OSPF: Fix OOB read in Router-LSA validation o Proto: Fix regression in protocol enabling o Channel: Fix refeeds and reloads during graceful restart o Export: Mitigate duplicate withdrawals o Filters: Fix crash when setting gateway on recursive nexthops o Filters: Fix path matching when AS path is too long. o Table: Fix RCU double-anchor o Table: Propagate thread group config into aux o RCU: Catch leaks sooner 3.3.0 o BGP: Export memory consumption optimization o BGP: Fix hostentry handling of MPLS and EVPN routes o BGP: Block connections on explicitly disabled instances o Proto/CLI: Lock show-commands o Proto: Loop persists through down state o Nest/CLI: Show only the longest prefix match in 'show route for' o Nest: Lockless attribute cache o Removed locking in random number generation o ASPA: Fix downstream validation o BMP: Fix route sending o BGP: Fix route refresh after restart o BGP: Fix dynamic peer connection o Filters: Fix string attributes o Filters: Fix ROA check autoreload reconfiguration o Logging: Fix error handling o Kernel: Fix graceful recovery o Pipe: Fix rare collision bug o Config: Allow keyword redefinition o Merged 2.19 3.2.0 o BGP: Listening socket rework o IGP metric: Split out local_metric again o Table: Optimal and Any Export refactoring o Various race condition fixes o All fixes included in 3.1.0 -- 3.1.5 o Merged 2.18 3.1.0 o CLI v2 compatibility layer for show route o Thread configuration rework o Merged 2.17 3.0.2 o Multiple route propagation crash fixes o BGP export table route source leak o Kernel export of source.specific routes fix o Filter gw setting fix o Merged 2.16.2 3.0.1 o BGP: Fixed crash in dynamic spawn o BGP: Fixed crash in graceful recovery o BGP: Fixed crash with deterministic med o BGP: Renamed the otc attribute to bgp_otc o BFD: Fixed crash in session reconfiguration o Kernel: Fixed crash with merged paths o Kernel: Simplified initial scan o Tables: Fixed old best route propagation o Tables: Fixed debug configuration propagation o Tables: Fixed initial feeds o CLI: Fixed buffer allocation heap bloating o Reduced route attribute normalization heap bloating o Merged 2.16.1 3.0.0 o Multithreaded execution o Decoupled exports from imports o Unified route attribute names o Slightly different log format o Separate reload command for filters and protocols o BGP: Export tables show the state as on wire o Lots of internal changes o Merged changes from 2.16 o BMP and MRT converted to the new API and working o Internal protocol state journal o Optimized table journal cleanup o Fixed "show route export" o Fixed minor bugs 3.0.alpha3 o Merged 2.15.1 o Fixed major issues with channel reloads o Fixed data inconsistencies in many corner cases o Fixed internal scheduler corner cases o MRT and BMP still switched off o Expected one more alpha before stable 3.0.alpha2 o Fixed memory leaks and use-after free bugs o Simple thread work balancing o MRT switched off o Slow kernel route synchronization to be fixed later 3.0.alpha1 o Worker threads for BGP, Pipe, RPKI and BFD o Configurable number of threads o Asynchronous route export o Flat attribute structure o Inline import tables o Export tables merged with BGP prefix / attribute buckets o Fixed ROA check locking inversion in route table dumps o MRT switched off 3.0.alpha0 o Removal of fixed protocol-specific route attributes o Asynchronous route export o Explicit table import / export hooks o Partially lockless route attribute cache o Thread-safe resource management o Thread-safe interface notifications o Thread-safe protocol API o Adoption of BFD IO loop for general use o Parallel Pipe protocol o Parallel RPKI protocol o Parallel BGP protocol o Lots of refactoring o Bugfixes and improvements as they came along 2.19.0 o BGP/MPLS Ethernet VPNs using VXLAN tunnels o BGP: PMSI tunnel attribute o Linux Netlink implementation for bridge interfaces o BGP: Automatic peering based on discovered neighbors o RAdv: Router discovery based on incoming Router Advertisments o Nest: Add message when attempting to reload protocol that is not UP o BMP: Fix off-by-one buffer overflow o OSPF: Fix infinite loop in OSPF Graceful Restart o ASPA: Fix downstream validation o Filters: Fix string attributes o Logging: Fix error handling o Minor filter improvements o Various documentation fixes 2.18 o BGP: Support for dynamic onlink and link-local connections o BGP: Listening socket refactoring o BGP: Fix restart behavior on outgoing next hop setting o BGP: Configuring global/link-local IPv6 nexthop o BGP: Disallow AS Sets by default o L3VPN: Support for import/export target none and import target all o RAdv: P-flag to prefer prefix delegation in DHCPv6 o Filter: Merging of case intervals o Filter: Append operator o ASPA: Paths containing AS_SET are invalid o Doc: Update website to bird.nic.cz o CI: Upstream packaging cleanup and reproducible builds o Various minor fixes in code, comments, documentation and tooling 2.17.1 o BSD: Fix build on NetBSD o BGP: Fix crash when incoming connection for disabled protocol arrives o Documentation fixes 2.17 o Babel: next hop control for IPv4 o BGP: link-local next hop format configuration o TCP-AO implementation for Linux 2.16.2 o BFD: password reconfiguration crash fix o L3VPN attribute fix o Table removal rare crash fix o Logging minor fix 2.16.1 o ASPA: fixed parser bug in static protocol o ASPA: fixed static protocol reconfiguration o Babel: fixed seqno comparison o BSD: fixed onlink flag assumption with Netlink o Fixed memory alignment issues o Fixed possible rte src collisions in L3VPN 2.16 o BFD: Set password per session o BFD: Accept zero checksum for IPv6-UDP o BMP: Refactoring and optimizations o OSPF: Allow loopback nexthop in OSPFv3-IPv4 o RPKI: TCP-MD5 authentication option o Filters: Add enum types to filter grammar o CLI: Configurable additional control sockets o CLI: Timeformat command o CLI: Dump commands need a target file o ASPA support in filters, Static and RPKI o Formalized contributions and credits policy o Many bugfixes and improvements Signed-off-by: Adolf Belka --- lfs/bird | 18 ++++++++---------- 1 file changed, 8 insertions(+), 10 deletions(-) diff --git a/lfs/bird b/lfs/bird index be78593c3..d5d582ab9 100644 --- a/lfs/bird +++ b/lfs/bird @@ -1,7 +1,7 @@ ############################################################################### # # # IPFire.org - A linux based firewall # -# Copyright (C) 2007-2024 IPFire Team # +# Copyright (C) 2007-2026 IPFire Team # # # # This program is free software: you can redistribute it and/or modify # # it under the terms of the GNU General Public License as published by # @@ -26,7 +26,7 @@ include Config SUMMARY = The BIRD Internet Routing Daemon -VER = 2.15.1 +VER = 3.3.3 THISAPP = bird-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = bird -PAK_VER = 14 +PAK_VER = 15 DEPS = @@ -48,7 +48,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = c3fe95ae2b8a3dca036278c8014f3ce2d1fd224c65c10abcc77b2cc1dbdfaa1b5766e8643b873a12ac33f00cd5e866aa7ce853ead78150ec4314b53457ad554a +$(DL_FILE)_BLAKE2 = 0e3218b343c55787eec300155c6c96205f6c433e4fb3d8e38a96919b1e2cbb92d80dec43f5548d22d33ad90f05dcd64fe093d09c0aa23c7fd882cbe48e17a0d0 install : $(TARGET) @@ -81,12 +81,10 @@ $(subst %,%_BLAKE2,$(objects)) : $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) @$(PREBUILD) @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE) - $(UPDATE_AUTOMAKE) - cd $(DIR_APP) && \ - ./configure \ - --prefix=/usr \ - --sysconfdir=/etc \ - --localstatedir=/var + cd $(DIR_APP) && ./configure \ + --prefix=/usr \ + --sysconfdir=/etc \ + --localstatedir=/var cd $(DIR_APP) && make $(MAKETUNING) cd $(DIR_APP) && make install -- 2.55.0