From mboxrd@z Thu Jan 1 00:00:00 1970 From: git@ipfire.org To: ipfire-scm@lists.ipfire.org Subject: [git.ipfire.org] IPFire 2.x development tree branch, next, updated. 7e8d00649625a1f8f77e086d402e02b2ab2dce79 Date: Wed, 14 May 2014 21:32:51 +0200 Message-ID: <20140514193251.C8F4D21100@argus.ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============0436930369157199907==" List-Id: --===============0436930369157199907== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable This is an automated email from the git hooks/post-receive script. It was generated because a ref change was pushed to the repository containing the project "IPFire 2.x development tree". The branch, next has been updated via 7e8d00649625a1f8f77e086d402e02b2ab2dce79 (commit) via 6fde3230a88f633ec6358959626ca90c1ae3e1a3 (commit) via a50dadc229a4ad34be60e9fa24cf20c33e9d96c2 (commit) via f527e53f54c8d908340e2102d983297392db1938 (commit) via b7ca4506502a50776ddfb65b446ac73c85797cc3 (commit) via cf910b536ade7b4bc03267d0d04cb4ddda815d5f (commit) via d3782f77ba9f3d4ead14cf22ac4ffe608e3114d7 (commit) via 28f44b83c32f72074bc75817698a2958119020bd (commit) via 172c1f72c4034419063589ab83fa95df5e48ef70 (commit) via 0a511b76938a036a46446ca5cf35a47482c39382 (commit) via 6e8089a94f5cb8b9baafa1afd8dc01d3baa9fd6d (commit) via 03fa5cba13c77b0a4ee8a1e84bf895af113ecb26 (commit) from aab13a8d9d873c2ad83bb2454ca03d90bfecfd53 (commit) Those revisions listed above that are new to this repository have not appeared on any other notification email; so we list those revisions in full, below. - Log ----------------------------------------------------------------- commit 7e8d00649625a1f8f77e086d402e02b2ab2dce79 Author: Michael Tremer Date: Wed May 14 21:32:04 2014 +0200 core78: Add updated theme functions.pl. commit 6fde3230a88f633ec6358959626ca90c1ae3e1a3 Merge: a50dadc 6e8089a Author: Michael Tremer Date: Wed May 14 21:30:50 2014 +0200 Merge branch 'master' into next commit a50dadc229a4ad34be60e9fa24cf20c33e9d96c2 Author: Michael Tremer Date: Wed May 14 21:28:45 2014 +0200 openvpn: Remove RC2 as a cipher option. commit f527e53f54c8d908340e2102d983297392db1938 Author: Erik Kapfer Date: Wed May 14 19:37:15 2014 +0200 ovpn_fixes: Fixed some typos and strcture. =20 Fixes #10462#c21. =20 Conflicts: html/cgi-bin/ovpnmain.cgi langs/de/cgi-bin/de.pl langs/en/cgi-bin/en.pl commit b7ca4506502a50776ddfb65b446ac73c85797cc3 Author: Michael Tremer Date: Wed May 14 20:42:41 2014 +0200 core78: Add OpenVPN changes. commit cf910b536ade7b4bc03267d0d04cb4ddda815d5f Author: Michael Tremer Date: Wed May 14 20:39:36 2014 +0200 daq: Update to version 2.0.2. commit d3782f77ba9f3d4ead14cf22ac4ffe608e3114d7 Author: Michael Tremer Date: Wed May 14 20:33:33 2014 +0200 core78: Add all recently changes files and packages. commit 28f44b83c32f72074bc75817698a2958119020bd Author: Michael Tremer Date: Wed May 14 20:31:12 2014 +0200 core78: Don't remove the ipfire theme. commit 172c1f72c4034419063589ab83fa95df5e48ef70 Author: Michael Tremer Date: Wed May 14 20:20:36 2014 +0200 ppp: Import some more patches from Fedora. commit 0a511b76938a036a46446ca5cf35a47482c39382 Author: Michael Tremer Date: Wed May 14 20:02:55 2014 +0200 ppp: Try longer to connect via PPPoE (60 seconds). commit 6e8089a94f5cb8b9baafa1afd8dc01d3baa9fd6d Author: Michael Tremer Date: Sat May 10 14:25:36 2014 +0200 theme: Fix spacing of version string in footer. ----------------------------------------------------------------------- Summary of changes: config/rootfiles/common/daq | 2 +- .../{oldcore/44 =3D> core/78}/filelists/daq | 0 config/rootfiles/core/78/filelists/files | 10 + config/rootfiles/core/{77 =3D> 78}/filelists/openvpn | 0 .../{oldcore/39 =3D> core/78}/filelists/ppp | 0 .../{oldcore/28 =3D> core/78}/filelists/snort | 0 .../{oldcore/32 =3D> core/78}/filelists/squid | 0 config/rootfiles/core/78/filelists/vnstat | 1 + config/rootfiles/core/78/update.sh | 3 - doc/language_issues.de | 1 + doc/language_issues.en | 1 + doc/language_issues.es | 4 +- doc/language_issues.fr | 4 +- doc/language_issues.nl | 4 +- doc/language_issues.pl | 4 +- doc/language_issues.ru | 4 +- doc/language_issues.tr | 4 +- doc/language_missings | 12 + html/cgi-bin/ovpnmain.cgi | 275 +++++++++----------= -- html/html/themes/ipfire/include/functions.pl | 2 +- langs/de/cgi-bin/de.pl | 7 +- langs/en/cgi-bin/en.pl | 7 +- langs/tr/install/lang_tr.c | 22 +- lfs/daq | 4 +- lfs/ppp | 7 +- ...tilize-compiler-flags-handed-to-us-by-rpm.patch | 121 +++++++++ ...pd-we-don-t-want-to-accidentally-leak-fds.patch | 143 +++++++++++ .../ppp/0013-everywhere-O_CLOEXEC-harder.patch | 241 ++++++++++++++++++ ...ere-use-SOCK_CLOEXEC-when-creating-socket.patch | 174 +++++++++++++ .../ppp/ppp-2.4.6-increase-max-padi-attempts.patch | 13 + 30 files changed, 877 insertions(+), 193 deletions(-) copy config/rootfiles/{oldcore/44 =3D> core/78}/filelists/daq (100%) copy config/rootfiles/core/{77 =3D> 78}/filelists/openvpn (100%) copy config/rootfiles/{oldcore/39 =3D> core/78}/filelists/ppp (100%) copy config/rootfiles/{oldcore/28 =3D> core/78}/filelists/snort (100%) copy config/rootfiles/{oldcore/32 =3D> core/78}/filelists/squid (100%) create mode 120000 config/rootfiles/core/78/filelists/vnstat create mode 100644 src/patches/ppp/0003-build-sys-utilize-compiler-flags-han= ded-to-us-by-rpm.patch create mode 100644 src/patches/ppp/0012-pppd-we-don-t-want-to-accidentally-l= eak-fds.patch create mode 100644 src/patches/ppp/0013-everywhere-O_CLOEXEC-harder.patch create mode 100644 src/patches/ppp/0014-everywhere-use-SOCK_CLOEXEC-when-cre= ating-socket.patch create mode 100644 src/patches/ppp/ppp-2.4.6-increase-max-padi-attempts.patch Difference in files: diff --git a/config/rootfiles/common/daq b/config/rootfiles/common/daq index 4467545..b8a9fd4 100644 --- a/config/rootfiles/common/daq +++ b/config/rootfiles/common/daq @@ -21,7 +21,7 @@ usr/lib/daq #usr/lib/libdaq.la #usr/lib/libdaq.so usr/lib/libdaq.so.2 -usr/lib/libdaq.so.2.0.1 +usr/lib/libdaq.so.2.0.2 #usr/lib/libdaq_static.a #usr/lib/libdaq_static.la #usr/lib/libdaq_static_modules.a diff --git a/config/rootfiles/core/78/filelists/daq b/config/rootfiles/core/7= 8/filelists/daq new file mode 120000 index 0000000..d0e0956 --- /dev/null +++ b/config/rootfiles/core/78/filelists/daq @@ -0,0 +1 @@ +../../../common/daq \ No newline at end of file diff --git a/config/rootfiles/core/78/filelists/files b/config/rootfiles/core= /78/filelists/files index 409e5fe..91b624e 100644 --- a/config/rootfiles/core/78/filelists/files +++ b/config/rootfiles/core/78/filelists/files @@ -1,2 +1,12 @@ etc/system-release etc/issue +srv/web/ipfire/cgi-bin/logs.cgi/firewalllogcountry.dat +srv/web/ipfire/cgi-bin/logs.cgi/showrequestfromcountry.dat +srv/web/ipfire/cgi-bin/modem-status.cgi +srv/web/ipfire/cgi-bin/ovpnmain.cgi +srv/web/ipfire/cgi-bin/proxy.cgi +srv/web/ipfire/html/themes/ipfire/include/functions.pl +var/ipfire/langs +var/ipfire/menu.d/20-status.menu +var/ipfire/menu.d/70-log.menu +var/ipfire/ovpn/openssl/ovpn.cnf diff --git a/config/rootfiles/core/78/filelists/openvpn b/config/rootfiles/co= re/78/filelists/openvpn new file mode 120000 index 0000000..493f3f7 --- /dev/null +++ b/config/rootfiles/core/78/filelists/openvpn @@ -0,0 +1 @@ +../../../common/openvpn \ No newline at end of file diff --git a/config/rootfiles/core/78/filelists/ppp b/config/rootfiles/core/7= 8/filelists/ppp new file mode 120000 index 0000000..4844a9b --- /dev/null +++ b/config/rootfiles/core/78/filelists/ppp @@ -0,0 +1 @@ +../../../common/ppp \ No newline at end of file diff --git a/config/rootfiles/core/78/filelists/snort b/config/rootfiles/core= /78/filelists/snort new file mode 120000 index 0000000..9406ce0 --- /dev/null +++ b/config/rootfiles/core/78/filelists/snort @@ -0,0 +1 @@ +../../../common/snort \ No newline at end of file diff --git a/config/rootfiles/core/78/filelists/squid b/config/rootfiles/core= /78/filelists/squid new file mode 120000 index 0000000..2dc8372 --- /dev/null +++ b/config/rootfiles/core/78/filelists/squid @@ -0,0 +1 @@ +../../../common/squid \ No newline at end of file diff --git a/config/rootfiles/core/78/filelists/vnstat b/config/rootfiles/cor= e/78/filelists/vnstat new file mode 120000 index 0000000..2e2e610 --- /dev/null +++ b/config/rootfiles/core/78/filelists/vnstat @@ -0,0 +1 @@ +../../../common/vnstat \ No newline at end of file diff --git a/config/rootfiles/core/78/update.sh b/config/rootfiles/core/78/up= date.sh index 0d59761..cb9af9f 100644 --- a/config/rootfiles/core/78/update.sh +++ b/config/rootfiles/core/78/update.sh @@ -135,9 +135,6 @@ esac /etc/init.d/ipsec stop /etc/init.d/apache stop =20 -# Remove the old default theme -rm -rf /srv/web/ipfire/html/themes/ipfire - # rename /etc/modprobe.d files for i in $(find /etc/modprobe.d/* | grep -v ".conf"); do mv $i $i.conf diff --git a/doc/language_issues.de b/doc/language_issues.de index a00e97a..650d415 100644 --- a/doc/language_issues.de +++ b/doc/language_issues.de @@ -410,6 +410,7 @@ WARNING: translation string unused: outgoing firewall war= ning WARNING: translation string unused: override mtu WARNING: translation string unused: ovpn config WARNING: translation string unused: ovpn dl +WARNING: translation string unused: ovpn engines WARNING: translation string unused: ovpn log WARNING: translation string unused: ovpn reneg sec WARNING: translation string unused: ovpn_fastio diff --git a/doc/language_issues.en b/doc/language_issues.en index ba7f030..732e2aa 100644 --- a/doc/language_issues.en +++ b/doc/language_issues.en @@ -437,6 +437,7 @@ WARNING: translation string unused: outgoing firewall war= ning WARNING: translation string unused: override mtu WARNING: translation string unused: ovpn config WARNING: translation string unused: ovpn dl +WARNING: translation string unused: ovpn engines WARNING: translation string unused: ovpn log WARNING: translation string unused: ovpn reneg sec WARNING: translation string unused: ovpn_fastio diff --git a/doc/language_issues.es b/doc/language_issues.es index 54cb32e..e13636b 100644 --- a/doc/language_issues.es +++ b/doc/language_issues.es @@ -575,6 +575,7 @@ WARNING: untranslated string: ConnSched reboot WARNING: untranslated string: ConnSched shutdown WARNING: untranslated string: MB read WARNING: untranslated string: MB written +WARNING: untranslated string: MTU settings WARNING: untranslated string: Number of Countries for the pie chart WARNING: untranslated string: Scan for Songs WARNING: untranslated string: Set time on boot @@ -874,8 +875,9 @@ WARNING: untranslated string: outgoing firewall p2p allow WARNING: untranslated string: outgoing firewall p2p deny WARNING: untranslated string: ovpn crypt options WARNING: untranslated string: ovpn dh +WARNING: untranslated string: ovpn dh new key +WARNING: untranslated string: ovpn dh parameters WARNING: untranslated string: ovpn dh upload -WARNING: untranslated string: ovpn engines WARNING: untranslated string: ovpn errmsg green already pushed WARNING: untranslated string: ovpn errmsg invalid ip or mask WARNING: untranslated string: ovpn generating the root and host certificates diff --git a/doc/language_issues.fr b/doc/language_issues.fr index 0386f24..759c18d 100644 --- a/doc/language_issues.fr +++ b/doc/language_issues.fr @@ -586,6 +586,7 @@ WARNING: untranslated string: ConnSched reboot WARNING: untranslated string: ConnSched shutdown WARNING: untranslated string: MB read WARNING: untranslated string: MB written +WARNING: untranslated string: MTU settings WARNING: untranslated string: Number of Countries for the pie chart WARNING: untranslated string: Scan for Songs WARNING: untranslated string: addons @@ -885,8 +886,9 @@ WARNING: untranslated string: other WARNING: untranslated string: outgoing firewall access WARNING: untranslated string: ovpn crypt options WARNING: untranslated string: ovpn dh +WARNING: untranslated string: ovpn dh new key +WARNING: untranslated string: ovpn dh parameters WARNING: untranslated string: ovpn dh upload -WARNING: untranslated string: ovpn engines WARNING: untranslated string: ovpn generating the root and host certificates WARNING: untranslated string: ovpn ha WARNING: untranslated string: ovpn hmac diff --git a/doc/language_issues.nl b/doc/language_issues.nl index 7c6f729..c1173f7 100644 --- a/doc/language_issues.nl +++ b/doc/language_issues.nl @@ -644,6 +644,7 @@ WARNING: translation string unused: xtaccess all error WARNING: translation string unused: xtaccess bad transfert WARNING: translation string unused: year-graph WARNING: translation string unused: yearly firewallhits +WARNING: untranslated string: MTU settings WARNING: untranslated string: Number of Countries for the pie chart WARNING: untranslated string: Scan for Songs WARNING: untranslated string: atm device @@ -678,8 +679,9 @@ WARNING: untranslated string: monitor interface WARNING: untranslated string: not a valid dh key WARNING: untranslated string: ovpn crypt options WARNING: untranslated string: ovpn dh +WARNING: untranslated string: ovpn dh new key +WARNING: untranslated string: ovpn dh parameters WARNING: untranslated string: ovpn dh upload -WARNING: untranslated string: ovpn engines WARNING: untranslated string: ovpn generating the root and host certificates WARNING: untranslated string: ovpn ha WARNING: untranslated string: ovpn hmac diff --git a/doc/language_issues.pl b/doc/language_issues.pl index 54cb32e..e13636b 100644 --- a/doc/language_issues.pl +++ b/doc/language_issues.pl @@ -575,6 +575,7 @@ WARNING: untranslated string: ConnSched reboot WARNING: untranslated string: ConnSched shutdown WARNING: untranslated string: MB read WARNING: untranslated string: MB written +WARNING: untranslated string: MTU settings WARNING: untranslated string: Number of Countries for the pie chart WARNING: untranslated string: Scan for Songs WARNING: untranslated string: Set time on boot @@ -874,8 +875,9 @@ WARNING: untranslated string: outgoing firewall p2p allow WARNING: untranslated string: outgoing firewall p2p deny WARNING: untranslated string: ovpn crypt options WARNING: untranslated string: ovpn dh +WARNING: untranslated string: ovpn dh new key +WARNING: untranslated string: ovpn dh parameters WARNING: untranslated string: ovpn dh upload -WARNING: untranslated string: ovpn engines WARNING: untranslated string: ovpn errmsg green already pushed WARNING: untranslated string: ovpn errmsg invalid ip or mask WARNING: untranslated string: ovpn generating the root and host certificates diff --git a/doc/language_issues.ru b/doc/language_issues.ru index c7c39ec..0589067 100644 --- a/doc/language_issues.ru +++ b/doc/language_issues.ru @@ -579,6 +579,7 @@ WARNING: untranslated string: ConnSched shutdown WARNING: untranslated string: Edit an existing route WARNING: untranslated string: MB read WARNING: untranslated string: MB written +WARNING: untranslated string: MTU settings WARNING: untranslated string: Number of Countries for the pie chart WARNING: untranslated string: Scan for Songs WARNING: untranslated string: addons @@ -869,8 +870,9 @@ WARNING: untranslated string: outgoing firewall access WARNING: untranslated string: outgoing traffic in bytes per second WARNING: untranslated string: ovpn crypt options WARNING: untranslated string: ovpn dh +WARNING: untranslated string: ovpn dh new key +WARNING: untranslated string: ovpn dh parameters WARNING: untranslated string: ovpn dh upload -WARNING: untranslated string: ovpn engines WARNING: untranslated string: ovpn generating the root and host certificates WARNING: untranslated string: ovpn ha WARNING: untranslated string: ovpn hmac diff --git a/doc/language_issues.tr b/doc/language_issues.tr index 06cacf1..2d9ebf7 100644 --- a/doc/language_issues.tr +++ b/doc/language_issues.tr @@ -643,6 +643,7 @@ WARNING: translation string unused: xtaccess all error WARNING: translation string unused: xtaccess bad transfert WARNING: translation string unused: year-graph WARNING: translation string unused: yearly firewallhits +WARNING: untranslated string: MTU settings WARNING: untranslated string: Number of Countries for the pie chart WARNING: untranslated string: Scan for Songs WARNING: untranslated string: bytes @@ -674,8 +675,9 @@ WARNING: untranslated string: monitor interface WARNING: untranslated string: not a valid dh key WARNING: untranslated string: ovpn crypt options WARNING: untranslated string: ovpn dh +WARNING: untranslated string: ovpn dh new key +WARNING: untranslated string: ovpn dh parameters WARNING: untranslated string: ovpn dh upload -WARNING: untranslated string: ovpn engines WARNING: untranslated string: ovpn generating the root and host certificates WARNING: untranslated string: ovpn ha WARNING: untranslated string: ovpn hmac diff --git a/doc/language_missings b/doc/language_missings index d25ea40..7a55460 100644 --- a/doc/language_missings +++ b/doc/language_missings @@ -341,6 +341,7 @@ < modem sim information < modem status < most preferred +< MTU settings < never < no hardware random number generator < not a valid dh key @@ -364,6 +365,8 @@ < outgoing firewall access < ovpn crypt options < ovpn dh +< ovpn dh new key +< ovpn dh parameters < ovpn dh upload < ovpn engines < ovpn generating the root and host certificates @@ -853,6 +856,7 @@ < modem sim information < modem status < most preferred +< MTU settings < never < no hardware random number generator < not a valid dh key @@ -888,6 +892,8 @@ < outgoing firewall view group < ovpn crypt options < ovpn dh +< ovpn dh new key +< ovpn dh parameters < ovpn dh upload < ovpn engines < ovpn errmsg green already pushed @@ -1349,6 +1355,7 @@ < modem sim information < modem status < most preferred +< MTU settings < never < no hardware random number generator < not a valid dh key @@ -1370,6 +1377,8 @@ < outgoing firewall access < ovpn crypt options < ovpn dh +< ovpn dh new key +< ovpn dh parameters < ovpn dh upload < ovpn engines < ovpn errmsg green already pushed @@ -1837,6 +1846,7 @@ < modem status < month-graph < most preferred +< MTU settings < never < no hardware random number generator < not a valid dh key @@ -1859,6 +1869,8 @@ < outgoing traffic in bytes per second < ovpn crypt options < ovpn dh +< ovpn dh new key +< ovpn dh parameters < ovpn dh upload < ovpn engines < ovpn generating the root and host certificates diff --git a/html/cgi-bin/ovpnmain.cgi b/html/cgi-bin/ovpnmain.cgi index df5f9ec..a051b5d 100644 --- a/html/cgi-bin/ovpnmain.cgi +++ b/html/cgi-bin/ovpnmain.cgi @@ -19,6 +19,7 @@ # = # ############################################################################= ### ### +# Based on IPFireCore 77 ### use CGI; use CGI qw/:standard/; @@ -92,7 +93,6 @@ $cgiparams{'PMTU_DISCOVERY'} =3D ''; $cgiparams{'DCIPHER'} =3D ''; $cgiparams{'DAUTH'} =3D ''; $cgiparams{'TLSAUTH'} =3D ''; -$cgiparams{'ENGINES'} =3D ''; $routes_push_file =3D "${General::swroot}/ovpn/routes_push"; unless (-e $routes_push_file) { system("touch $routes_push_file"); } unless (-e "${General::swroot}/ovpn/ccd.conf") { system("touch ${General:= :swroot}/ovpn/ccd.conf"); } @@ -371,11 +371,6 @@ sub writeserverconf { if ($sovpnsettings{'TLSAUTH'} eq 'on') { print CONF "tls-auth ${General::swroot}/ovpn/ca/ta.key 0\n"; } - if ($sovpnsettings{ENGINES} eq 'disabled') { - print CONF ""; - } else { - print CONF "engine $sovpnsettings{ENGINES}\n"; - } if ($sovpnsettings{DCOMPLZO} eq 'on') { print CONF "comp-lzo\n"; } @@ -796,7 +791,6 @@ if ($cgiparams{'ACTION'} eq $Lang::tr{'save-adv-options'}= ) { $vpnsettings{'PMTU_DISCOVERY'} =3D $cgiparams{'PMTU_DISCOVERY'}; $vpnsettings{'DAUTH'} =3D $cgiparams{'DAUTH'}; $vpnsettings{'TLSAUTH'} =3D $cgiparams{'TLSAUTH'}; - $vpnsettings{'ENGINES'} =3D $cgiparams{'ENGINES'}; my @temp=3D(); =20 if ($cgiparams{'FRAGMENT'} eq '') { @@ -1008,12 +1002,6 @@ unless(-d "${General::swroot}/ovpn/n2nconf/$cgiparams{= 'NAME'}"){mkdir "${General print SERVERCONF "# HMAC algorithm\n"; print SERVERCONF "auth $cgiparams{'DAUTH'}\n"; } - if ($cgiparams{'ENGINES'} eq 'disabled') { - print SERVERCONF ""; - } else { - print SERVERCONF "# Crypto engine\n"; - print SERVERCONF "engine $cgiparams{'ENGINES'}\n"; - } if ($cgiparams{'COMPLZO'} eq 'on') { print SERVERCONF "# Enable Compression\n"; print SERVERCONF "comp-lzo\r\n"; @@ -1109,12 +1097,6 @@ unless(-d "${General::swroot}/ovpn/n2nconf/$cgiparams{= 'NAME'}"){mkdir "${General print CLIENTCONF "# HMAC algorithm\n"; print CLIENTCONF "auth $cgiparams{'DAUTH'}\n"; } - if ($cgiparams{'ENGINES'} eq 'disabled') { - print CLIENTCONF ""; - } else { - print CLIENTCONF "# Crypto engine\n"; - print CLIENTCONF "engine $cgiparams{'ENGINES'}\n"; - } if ($cgiparams{'COMPLZO'} eq 'on') { print CLIENTCONF "# Enable Compression\n"; print CLIENTCONF "comp-lzo\r\n"; @@ -1299,7 +1281,6 @@ SETTINGS_ERROR: - $Lang::tr{'capswarning'}<= /b>:=20 $Lang::tr{'capswarning'}<= /b>: $Lang::tr{'resetting the vpn configuration will remove the root ca, the = host certificate and all certificate based connections'} @@ -1343,7 +1324,7 @@ END print < - + $Lang::tr{'ovpn dh'}: @@ -2539,6 +2520,12 @@ ADV_ERROR: if ($cgiparams{'TLSAUTH'} eq '') { $cgiparams{'TLSAUTH'} =3D 'off'; } + if ($cgiparams{'DAUTH'} eq '') { + $cgiparams{'DAUTH'} =3D 'SHA1'; + } + if ($cgiparams{'TLSAUTH'} eq '') { + $cgiparams{'TLSAUTH'} =3D 'off'; + } $checked{'CLIENT2CLIENT'}{'off'} =3D ''; $checked{'CLIENT2CLIENT'}{'on'} =3D ''; $checked{'CLIENT2CLIENT'}{$cgiparams{'CLIENT2CLIENT'}} =3D 'CHECKED'; @@ -2571,13 +2558,7 @@ ADV_ERROR: $checked{'TLSAUTH'}{'off'} =3D ''; $checked{'TLSAUTH'}{'on'} =3D ''; $checked{'TLSAUTH'}{$cgiparams{'TLSAUTH'}} =3D 'CHECKED'; - $selected{'ENGINES'}{'cryptodev'} =3D ''; - $selected{'ENGINES'}{'dynamic'} =3D ''; - $selected{'ENGINES'}{'aesni'} =3D ''; - $selected{'ENGINES'}{'padlock'} =3D ''; - $selected{'ENGINES'}{'disabled'} =3D ''; - $selected{'ENGINES'}{$cgiparams{'ENGINES'}} =3D 'SELECTED'; - + =20 &Header::showhttpheaders(); &Header::openpage($Lang::tr{'status ovpn'}, 1, ''); &Header::openbigbox('100%', 'LEFT', '', $errormessage); =20 @@ -2719,18 +2700,6 @@ print < Default: SHA1 (160 $Lang::tr{'bit'}) - - $Lang::tr{'ovpn engines'} - - - Default: $Lang::tr{'disabled'} - =20 @@ -3301,8 +3270,7 @@ my @n2nremsub =3D split(/ /, (grep { /^route/ } @firen2= nconf)[0]); my @n2nmgmt =3D split(/ /, (grep { /^management/ } @firen2nconf)[0]); my @n2nlocalsub =3D split(/ /, (grep { /^# remsub/ } @firen2nconf)[0]); my @n2ncipher =3D split(/ /, (grep { /^cipher/ } @firen2nconf)[0]); -my @n2nauth =3D split(/ /, (grep { /^auth/ } @firen2nconf)[0]); -my @n2nengine =3D split(/ /, (grep { /^engine/ } @firen2nconf)[0]);; +my @n2nauth =3D split(/ /, (grep { /^auth/ } @firen2nconf)[0]);; =20 ### # m.a.d delete CR and LF from arrays for this chomp doesnt work @@ -3323,7 +3291,6 @@ $n2nmgmt[2] =3D~ s/\n|\r//g; $n2nmtudisc[1] =3D~ s/\n|\r//g; $n2ncipher[1] =3D~ s/\n|\r//g; $n2nauth[1] =3D~ s/\n|\r//g; -$n2nengine[1] =3D~ s/\n|\r//g; chomp ($complzoactive); chomp ($mssfixactive); =20 @@ -3542,7 +3509,6 @@ if ($confighash{$cgiparams{'KEY'}}) { $cgiparams{'DAUTH'} =3D $confighash{$cgiparams{'KEY'}}[39]; $cgiparams{'DCIPHER'} =3D $confighash{$cgiparams{'KEY'}}[40]; $cgiparams{'TLSAUTH'} =3D $confighash{$cgiparams{'KEY'}}[41]; - $cgiparams{'ENGINES'} =3D $confighash{$cgiparams{'KEY'}}[42]; } elsif ($cgiparams{'ACTION'} eq $Lang::tr{'save'}) { $cgiparams{'REMARK'} =3D &Header::cleanhtml($cgiparams{'REMARK'}); =09 @@ -4268,7 +4234,6 @@ if ($cgiparams{'TYPE'} eq 'net') { $confighash{$key}[38] =3D $cgiparams{'PMTU_DISCOVERY'}; $confighash{$key}[39] =3D $cgiparams{'DAUTH'}; $confighash{$key}[40] =3D $cgiparams{'DCIPHER'}; - $confighash{$key}[42] =3D $cgiparams{'ENGINES'}; =20 &General::writehasharray("${General::swroot}/ovpn/ovpnconfig", \%confighash= ); =09 @@ -4380,7 +4345,6 @@ if ($cgiparams{'TYPE'} eq 'net') { $cgiparams{'FRAGMENT'} =3D '1300'; $cgiparams{'PMTU_DISCOVERY'} =3D 'off'; $cgiparams{'DAUTH'} =3D 'SHA1'; - $cgiparams{'ENGINES'} =3D 'disabled'; ### # m.a.d n2n end ###=09 @@ -4457,10 +4421,7 @@ if ($cgiparams{'TYPE'} eq 'net') { $selected{'DCIPHER'}{'DES-EDE-CBC'} =3D ''; $selected{'DCIPHER'}{'CAST5-CBC'} =3D ''; $selected{'DCIPHER'}{'BF-CBC'} =3D ''; - $selected{'DCIPHER'}{'RC2-CBC'} =3D ''; $selected{'DCIPHER'}{'DES-CBC'} =3D ''; - $selected{'DCIPHER'}{'RC2-64-CBC'} =3D ''; - $selected{'DCIPHER'}{'RC2-40-CBC'} =3D ''; # If no cipher has been chossen yet, select # the old default (AES-256-CBC) for compatiblity reasons. if ($cgiparams{'DCIPHER'} eq '') { @@ -4479,18 +4440,6 @@ if ($cgiparams{'TYPE'} eq 'net') { } $selected{'DAUTH'}{$cgiparams{'DAUTH'}} =3D 'SELECTED'; =20 - $selected{'ENGINES'}{'disabled'} =3D ''; - $selected{'ENGINES'}{'cryptodev'} =3D ''; - $selected{'ENGINES'}{'dynamic'} =3D ''; - $selected{'ENGINES'}{'aesni'} =3D ''; - $selected{'ENGINES'}{'padlock'} =3D ''; - # If no engine has been choosen yet, select - # a default one (disabled). - if ($cgiparams{'ENGINES'} eq '') { - $cgiparams{'ENGINES'} =3D 'disabled'; - } - $selected{'ENGINES'}{$cgiparams{'ENGINES'}} =3D 'SELECTED'; - if (1) { &Header::showhttpheaders(); &Header::openpage($Lang::tr{'ovpn'}, 1, ''); @@ -4547,100 +4496,66 @@ if ($cgiparams{'TYPE'} eq 'net') { } print <  - - - - - - - - - - - - + =09 + + =20 - - + + + =20 - =20 - - + + =20 - - - + + + =20 - - - - - - + + =20 - - + + +=09 + + + =20 - + + + =20 - - - + +=09 + + + =20 - - - - + + + + =20 - - - - + + + + =20 - - - + + + =20 - - + + =20 + + + + + + + + + + + + + + END ; } @@ -5012,10 +4962,7 @@ END $selected{'DCIPHER'}{'DES-EDE-CBC'} =3D ''; $selected{'DCIPHER'}{'CAST5-CBC'} =3D ''; $selected{'DCIPHER'}{'BF-CBC'} =3D ''; - $selected{'DCIPHER'}{'RC2-CBC'} =3D ''; $selected{'DCIPHER'}{'DES-CBC'} =3D ''; - $selected{'DCIPHER'}{'RC2-64-CBC'} =3D ''; - $selected{'DCIPHER'}{'RC2-40-CBC'} =3D ''; $selected{'DCIPHER'}{$cgiparams{'DCIPHER'}} =3D 'SELECTED'; =20 $selected{'DAUTH'}{'whirlpool'} =3D ''; @@ -5025,13 +4972,6 @@ END $selected{'DAUTH'}{'SHA1'} =3D ''; $selected{'DAUTH'}{$cgiparams{'DAUTH'}} =3D 'SELECTED'; =20 - $selected{'ENGINES'}{'cryptodev'} =3D ''; - $selected{'ENGINES'}{'dynamic'} =3D ''; - $selected{'ENGINES'}{'aesni'} =3D ''; - $selected{'ENGINES'}{'padlock'} =3D ''; - $selected{'ENGINES'}{'disabled'} =3D ''; - $selected{'ENGINES'}{$cgiparams{'ENGINES'}} =3D 'SELECTED'; - $checked{'DCOMPLZO'}{'off'} =3D ''; $checked{'DCOMPLZO'}{'on'} =3D ''; $checked{'DCOMPLZO'}{$cgiparams{'DCOMPLZO'}} =3D 'CHECKED'; @@ -5107,10 +5047,11 @@ END + @@ -5519,22 +5456,32 @@ END =20 + + + + + + + + + - + + - - - - + +
 
$Lang::tr{'Act as'}$Lang::tr{'remote host/ip'}:
$Lang::tr{'local subnet'}$Lang::tr{'remote subnet'} -
 
$Lang::tr{'Act as'} +
$Lang::tr{'ovpn subnet'}
$Lang::tr{'remote host/ip'}:=
$Lang::tr{'protocol'}
$Lang::tr{'local subnet'}$Lang::tr{'destination port'}:
$Lang::tr{'remote subnet'}
$Lang::tr{'cipher'} - $Lang::tr{'ovpn ha'}: -
$Lang::tr{'ovpn subnet'}
$Lang::tr{'ovpn engines'} &n= bsp; - -
$Lang::tr{'protocol'}<= /td> +
$Lang::tr{'destination port'}:

Management Port ($Lang::tr{'openv= pn default'}: $Lang::tr{'destination port'}):  
Management Port ($Lang::tr{'= openvpn default'}: $Lang::tr{'destination port'}):  = ;

$Lang::tr{'MTU settings'}
$Lang::tr{'MTU'} = $Lang::tr{'openvpn default'}: udp/tcp 1500/1400
$Lang::tr{'MTU'} <= img src=3D'/blob.gif' />$Lang::tr{'openvpn default'}: udp/tcp 1500/1400
fragment  $Lang::tr{'openvpn default'}: 1300
fragment  $Lang::tr{'openvpn default'}: 1300
mssfix  <= /td> - $Lang::tr{'openvpn default'}: on
mssfix   + $Lang::tr{'openvpn default'}: on
$Lang::tr{'comp-lzo'} =   -
$Lang::tr{'comp-lzo'} &= nbsp; + =
$Lang::tr{'ovpn mtu-disc'} @@ -4650,6 +4565,41 @@ if ($cgiparams{'TYPE'} eq 'net') { $Lang::tr{'ovpn mtu-disc off'}

$Lang::tr{'ovpn crypt options'}:
$Lang::tr{'cipher'} + $Lang::tr{'ovpn ha'}: +

$Lang::tr{'MTU'}  $Lang::tr{'cipher'}
$Lang::tr{'comp-lzo'}

$Lang::tr{'ovpn dh parameters'}:
$Lang::tr{'ovpn dh upload'}:

$Lang::tr{'ovpn dh new key'}:
+=09 +
END ; =20 diff --git a/html/html/themes/ipfire/include/functions.pl b/html/html/themes/= ipfire/include/functions.pl index 0c47cd4..63740d4 100644 --- a/html/html/themes/ipfire/include/functions.pl +++ b/html/html/themes/ipfire/include/functions.pl @@ -194,7 +194,7 @@ sub openpagewithoutmenu { sub closepage () { open(FILE, "; - $system_release =3D~ s/core/Core Update/; + $system_release =3D~ s/core/Core Update /; close(FILE); =20 print < 'MB gelesen', 'MB written' =3D> 'MB geschrieben', 'MTU' =3D> 'MTU-Gr=C3=B6=C3=9Fe:', +'MTU settings' =3D> 'MTU-Einstellungen:', 'Number of Countries for the pie chart' =3D> 'Anzahl der angezeigten L=C3=A4= nder im Diagramm', 'Number of IPs for the pie chart' =3D> 'Anzahl der angezeigten IPs im Diagra= mm', 'Number of Ports for the pie chart' =3D> 'Anzahl der angezeigten Ports im Di= agramm', @@ -1123,7 +1124,7 @@ 'fwhost wo subnet' =3D> '(Ohne Subnetz)', 'gateway' =3D> 'Gateway', 'gateway ip' =3D> 'Gateway-IP', -'gen dh' =3D> 'Diffie-Hellman-Parameter erzeugen', +'gen dh' =3D> 'Neuen Diffie-Hellman-Parameter erzeugen', 'gen static key' =3D> 'Statischen Schl=C3=BCssel erzeugen', 'generate' =3D> 'Root/Host-Zertifikate generieren', 'generate a certificate' =3D> 'Erzeuge ein Zertifikat:', @@ -1659,7 +1660,9 @@ 'ovpn crypt options' =3D> 'Kryptografieoptionen', 'ovpn device' =3D> 'OpenVPN-Ger=C3=A4t', 'ovpn dh' =3D> 'Diffie-Hellman-Parameter-L=C3=A4nge', -'ovpn dh upload' =3D> 'Diffie-Hellman-Parameter hochladen', +'ovpn dh new key' =3D> 'Neuen Diffie-Hellman Parameter erstellen', +'ovpn dh parameters' =3D> 'Diffie-Hellman-Parameter-Optionen', +'ovpn dh upload' =3D> 'Neuen Diffie-Hellman-Parameter hochladen', 'ovpn dl' =3D> 'OVPN-Konfiguration downloaden', 'ovpn engines' =3D> 'Krypto Engine', 'ovpn errmsg green already pushed' =3D> 'Route f=C3=BCr gr=C3=BCnes Netzwerk= wird immer gesetzt', diff --git a/langs/en/cgi-bin/en.pl b/langs/en/cgi-bin/en.pl index 5ccad79..20e9db3 100644 --- a/langs/en/cgi-bin/en.pl +++ b/langs/en/cgi-bin/en.pl @@ -39,6 +39,7 @@ 'MB read' =3D> 'MB read', 'MB written' =3D> 'MB written', 'MTU' =3D> 'MTU size:', +'MTU settings' =3D> 'MTU settings:', 'Number of Countries for the pie chart' =3D> 'Number of Countries for the pi= e chart', 'Number of IPs for the pie chart' =3D> 'Number of IPs for the pie chart', 'Number of Ports for the pie chart' =3D> 'Number of ports for the pie chart', @@ -1152,7 +1153,7 @@ 'g.lite' =3D> 'TO BE REMOVED', 'gateway' =3D> 'Gateway', 'gateway ip' =3D> 'Gateway IP', -'gen dh' =3D> 'Generate Diffie-Hellman parameters', +'gen dh' =3D> 'Generate new Diffie-Hellman parameters', 'gen static key' =3D> 'Generate a static key', 'generate' =3D> 'Generate root/host zertifikate', 'generate a certificate' =3D> 'Generate a certificate:', @@ -1690,7 +1691,9 @@ 'ovpn crypt options' =3D> 'Cryptographic options', 'ovpn device' =3D> 'OpenVPN device:', 'ovpn dh' =3D> 'Diffie-Hellman parameters length', -'ovpn dh upload' =3D> 'Upload Diffie-Hellman parameters', +'ovpn dh new key' =3D> 'Generate new Diffie-Hellman parameters', +'ovpn dh parameters' =3D> 'Diffie-Hellman parameters options', +'ovpn dh upload' =3D> 'Upload new Diffie-Hellman parameters', 'ovpn dl' =3D> 'OVPN-Config Download', 'ovpn engines' =3D> 'Crypto engine', 'ovpn errmsg green already pushed' =3D> 'Route for green network is always s= et', diff --git a/langs/tr/install/lang_tr.c b/langs/tr/install/lang_tr.c index 3131dd1..814949a 100644 --- a/langs/tr/install/lang_tr.c +++ b/langs/tr/install/lang_tr.c @@ -54,7 +54,7 @@ char *tr_tr[] =3D { /* TR_JOURNAL_EXT3 */ "Ext3 i=C3=A7in g=C3=BCnl=C3=BCk olu=C5=9Fturuluyor...", /* TR_CHOOSE_NETCARD */ -"A=C5=9Fa=C4=9F=C4=B1daki ara birim i=C3=A7in bir a=C4=9F kart=C4=B1 se=C3= =A7in - %s.", +"A=C5=9Fa=C4=9F=C4=B1dan =C5=9Fu ara birim i=C3=A7in bir a=C4=9F kart=C4=B1 = se=C3=A7in - %s", /* TR_NETCARDMENU2 */ "Geni=C5=9Fletilmi=C5=9F A=C4=9F Listesi", /* TR_ERROR_INTERFACES */ @@ -132,7 +132,7 @@ char *tr_tr[] =3D { /* TR_DNS_AND_GATEWAY_SETTINGS */ "DNS ve A=C4=9F Ge=C3=A7idi ayarlar=C4=B1", /* TR_DNS_AND_GATEWAY_SETTINGS_LONG */ -"DNS ve a=C4=9F ge=C3=A7idi bilgilerini girin. Bu ayarlar sadece KIRMIZI ara= birim adres ayarlar=C4=B1nda Sabit se=C3=A7en=C4=9Fi se=C3=A7ilmi=C5=9Fse kul= lan=C4=B1l=C4=B1r. E=C4=9Fer KIRMIZI arabirim adres ayarlar=C4=B1nda DHCP se= =C3=A7ene=C4=9Fini se=C3=A7tiyseniz bu alan=C4=B1 bo=C5=9F b=C4=B1rakabilirsi= niz.", +"DNS ve a=C4=9F ge=C3=A7idi bilgilerini girin. Bu ayarlar sadece KIRMIZI ara= birim adres ayarlar=C4=B1nda Statik se=C3=A7en=C4=9Fi se=C3=A7ilmi=C5=9Fse k= ullan=C4=B1l=C4=B1r. E=C4=9Fer KIRMIZI ara birim adres ayarlar=C4=B1nda DHCP = se=C3=A7ene=C4=9Fini se=C3=A7tiyseniz bu alan=C4=B1 bo=C5=9F b=C4=B1rakabilir= siniz.", /* TR_DNS_GATEWAY_WITH_GREEN */ "Yap=C4=B1land=C4=B1rman=C4=B1z KIRMIZI ara birim i=C3=A7in ethernet adapt= =C3=B6r=C3=BCn=C3=BC kullanamaz. DNS ve =C3=87evirmeli a=C4=9F kullan=C4=B1c= =C4=B1lar=C4=B1 i=C3=A7in a=C4=9F ge=C3=A7idi bilgisi =C3=A7evirmeli a=C4=9Fd= a otomatik olarak yap=C4=B1land=C4=B1r=C4=B1l=C4=B1r.", /* TR_DOMAINNAME */ @@ -164,7 +164,7 @@ char *tr_tr[] =3D { /* TR_ENTER_ADDITIONAL_MODULE_PARAMS */ "Baz=C4=B1 ISDN kartlar=C4=B1 (=C3=B6zellikle ISA olanlar) IRQ ve G=C3=87 ad= res bilgilerini ayarlamak i=C3=A7in ek mod=C3=BCl parametrelerine ihtiya=C3= =A7 duyar.B=C3=B6yle bir ISDN kart=C4=B1n=C4=B1z varsa burada bu ek parametre= leri girin. =C3=96rne=C4=9Fin: \"io =3D 0x280 irq =3D 9 \". Bunlar kart alg= =C4=B1lama s=C4=B1ras=C4=B1nda kullan=C4=B1lacakt=C4=B1r.", /* TR_ENTER_ADMIN_PASSWORD */ -"%s 'admin' kullan=C4=B1c=C4=B1 parolas=C4=B1n=C4=B1 giriniz. Bu, %s web y= =C3=B6netimi sayfalar=C4=B1n=C4=B1n kay=C4=B1tlar=C4=B1na eri=C5=9Febilen kul= lan=C4=B1c=C4=B1d=C4=B1r.", +"%s 'admin' kullan=C4=B1c=C4=B1 parolas=C4=B1n=C4=B1 girin. Bu, %s web y=C3= =B6netimi sayfalar=C4=B1n=C4=B1n kay=C4=B1tlar=C4=B1na eri=C5=9Febilen kullan= =C4=B1c=C4=B1d=C4=B1r.", /* TR_ENTER_DOMAINNAME */ "Alan ad=C4=B1n=C4=B1 girin", /* TR_ENTER_HOSTNAME */ @@ -228,7 +228,7 @@ char *tr_tr[] =3D { /* TR_INTERFACE_FAILED_TO_COME_UP */ "Ara birim y=C3=BCkseltmesi ba=C5=9Far=C4=B1s=C4=B1z oldu.", /* TR_INVALID_FIELDS */ -"A=C5=9Fa=C4=9F=C4=B1daki alan ge=C3=A7ersizdir:\n\n", +"A=C5=9Fa=C4=9F=C4=B1daki alan ge=C3=A7ersiz:\n\n", /* TR_INVALID_IO */ "Girilen G=C3=87 ba=C4=9Flant=C4=B1 noktas=C4=B1 detaylar=C4=B1 ge=C3=A7ersi= z. ", /* TR_INVALID_IRQ */ @@ -354,7 +354,7 @@ char *tr_tr[] =3D { /* TR_PHONENUMBER_CANNOT_BE_EMPTY */ "Telefon numaras=C4=B1 bo=C5=9F olamaz.", /* TR_PREPARE_HARDDISK */ -"Sabit disk kurulum program=C4=B1 /dev/sda =C3=BCzerindeki %s sabit diski ha= z=C4=B1rlayacak. =C4=B0lk olarak diskiniz b=C3=B6l=C3=BCmlendirilir ve daha s= onra bu b=C3=B6l=C3=BCme dosya sistemleri olu=C5=9Fturulur.\n\nD=C4=B0SKTEK= =C4=B0 T=C3=9CM VER=C4=B0LER S=C4=B0L=C4=B0NECEKT=C4=B0R. Kabul ediyor musunu= z?", +"Sabit disk kurulum program=C4=B1 %s =C3=BCzerindeki sabit diski haz=C4=B1rl= ayacak. =C4=B0lk olarak diskiniz b=C3=B6l=C3=BCmlendirilir ve daha sonra bu b= =C3=B6l=C3=BCme dosya sistemleri olu=C5=9Fturulur.\n\nD=C4=B0SKTEK=C4=B0 T=C3= =9CM VER=C4=B0LER S=C4=B0L=C4=B0NECEKT=C4=B0R. Kabul ediyor musunuz?", /* TR_PRESS_OK_TO_REBOOT */ "Yeniden Ba=C5=9Flat", /* TR_PRIMARY_DNS */ @@ -428,7 +428,7 @@ char *tr_tr[] =3D { /* TR_SETTING_SETUP_PASSWORD */ "KALDIRILACAK", /* TR_SETUP_FINISHED */ -"Kurulum tamamland=C4=B1. Tamam tu=C5=9Funa bas=C4=B1n.", +"Kurulum tamamland=C4=B1. Tamam se=C3=A7ne=C4=9Fi ile ilerleyin.", /* TR_SETUP_NOT_COMPLETE */ "Ba=C5=9Flang=C4=B1=C3=A7 kurulumu tamamlanamad=C4=B1. =C5=9Eimdi kurulumu t= ekrar =C3=A7al=C4=B1=C5=9Ft=C4=B1rarak ayarlar=C4=B1n=C4=B1z=C4=B1n d=C3=BCzg= =C3=BCn yap=C4=B1lm=C4=B1=C5=9F oldu=C4=9Fundan emin olun.", /* TR_SETUP_PASSWORD */ @@ -444,7 +444,7 @@ char *tr_tr[] =3D { /* TR_START_ADDRESS_CR */ "Ba=C5=9Flang=C4=B1=C3=A7 adresi\n", /* TR_STATIC */ -"Sabit", +"Statik", /* TR_SUGGEST_IO */ "(=C3=B6neri %x)", /* TR_SUGGEST_IRQ */ @@ -546,7 +546,7 @@ char *tr_tr[] =3D { /* TR_WARNING */ "UYARI", /* TR_WARNING_LONG */ -"Bu IP adresini de=C4=9Fi=C5=9Ftiriseniz %s makinesi ile uzak oturum ba=C4= =9Flant=C4=B1s=C4=B1 kopar ve yeniden IP adresi girmeniz gerekir. Bu riskli b= ir i=C5=9Flemdir. Bu i=C5=9Flem s=C4=B1ras=C4=B1nda bir =C5=9Feyler ters gide= rse d=C3=BCzeltmek i=C3=A7in makineye fiziksel eri=C5=9Fiminiz varsa denemeli= siniz.", +"Bu IP adresini de=C4=9Fi=C5=9Ftiriseniz %s makinesi ile uzak oturum ba=C4= =9Flant=C4=B1s=C4=B1 kopar ve yeniden IP adresi girmeniz gerekir. Bu riskli b= ir i=C5=9Flemdir. Bu i=C5=9Flem s=C4=B1ras=C4=B1nda bir =C5=9Feyler ters gide= rse d=C3=BCzeltmek i=C3=A7in makineye fiziksel eri=C5=9Fiminiz olmal=C4=B1d= =C4=B1r. Makineye fiziksel eri=C5=9Fiminiz varsa bu i=C5=9Flemi ger=C3=A7ekle= =C5=9Ftirin.", /* TR_WELCOME */ "%s kurulum program=C4=B1na ho=C5=9F geldiniz. Sonraki ekranlar=C4=B1n herha= ngi birinde =C4=B0ptal se=C3=A7ene=C4=9Fini se=C3=A7ti=C4=9Finizde bilgisayar= yeniden ba=C5=9Flat=C4=B1lacakt=C4=B1r.", /* TR_YOUR_CONFIGURATION_IS_SINGLE_GREEN_ALREADY_HAS_DRIVER */ @@ -588,9 +588,9 @@ char *tr_tr[] =3D { /* TR_DHCP_FORCE_MTU */ "DHCP mtu zorla:", /* TR_IDENTIFY */ -"Identify", +"Belirle", /* TR_IDENTIFY_SHOULD_BLINK */ -"Selected port should blink now ...", +"Se=C3=A7ilen ba=C4=9Flant=C4=B1 noktas=C4=B1n=C4=B1n =C5=9Fimdi yan=C4=B1p = s=C3=B6nmesi gerekir...", /* TR_IDENTIFY_NOT_SUPPORTED */ -"Function is not supported by this port.", +"=C4=B0=C5=9Flev bu ba=C4=9Flant=C4=B1 noktas=C4=B1 taraf=C4=B1ndan destekle= nmiyor.", }; diff --git a/lfs/daq b/lfs/daq index e6fd8fb..fa8f2a8 100644 --- a/lfs/daq +++ b/lfs/daq @@ -24,7 +24,7 @@ =20 include Config =20 -VER =3D 2.0.1 +VER =3D 2.0.2 =20 THISAPP =3D daq-$(VER) DL_FILE =3D $(THISAPP).tar.gz @@ -40,7 +40,7 @@ objects =3D $(DL_FILE) =20 $(DL_FILE) =3D $(DL_FROM)/$(DL_FILE) =20 -$(DL_FILE)_MD5 =3D 044aa3663d44580d005293eeb8ccf175 +$(DL_FILE)_MD5 =3D 865bf9b750a2a2ca632591a3c70b0ea0 =20 install : $(TARGET) =20 diff --git a/lfs/ppp b/lfs/ppp index ba72f4c..3c60938 100644 --- a/lfs/ppp +++ b/lfs/ppp @@ -73,9 +73,14 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) @$(PREBUILD) @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE) cd $(DIR_APP) && rm -f include/pcap-int.h include/linux/if_pppol2tp.h + cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/ppp/0003-build-sys-ut= ilize-compiler-flags-handed-to-us-by-rpm.patch + cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/ppp/0012-pppd-we-don-= t-want-to-accidentally-leak-fds.patch + cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/ppp/0013-everywhere-O= _CLOEXEC-harder.patch + cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/ppp/0014-everywhere-u= se-SOCK_CLOEXEC-when-creating-socket.patch + cd $(DIR_APP) && patch -Np1 -i $(DIR_SRC)/src/patches/ppp/ppp-2.4.6-increas= e-max-padi-attempts.patch cd $(DIR_APP) && sed -i -e "s+/etc/ppp/connect-errors+/var/log/connect-erro= rs+" pppd/pathnames.h cd $(DIR_APP) && ./configure --prefix=3D/usr --disable-nls - cd $(DIR_APP) && make $(MAKETUNING) CC=3D"gcc $(CFLAGS)" + cd $(DIR_APP) && make $(MAKETUNING) CC=3D"gcc" RPM_OPT_FLAGS=3D"$(CFLAGS)" cd $(DIR_APP) && make install cd $(DIR_APP) && make install-etcppp touch /var/log/connect-errors diff --git a/src/patches/ppp/0003-build-sys-utilize-compiler-flags-handed-to-= us-by-rpm.patch b/src/patches/ppp/0003-build-sys-utilize-compiler-flags-hande= d-to-us-by-rpm.patch new file mode 100644 index 0000000..4a43d44 --- /dev/null +++ b/src/patches/ppp/0003-build-sys-utilize-compiler-flags-handed-to-us-by-r= pm.patch @@ -0,0 +1,121 @@ +From d729b06f0ac7a5ebd3648ef60bef0499b59bf82d Mon Sep 17 00:00:00 2001 +From: Michal Sekletar +Date: Fri, 4 Apr 2014 11:29:39 +0200 +Subject: [PATCH 03/25] build-sys: utilize compiler flags handed to us by + rpmbuild + +--- + chat/Makefile.linux | 2 +- + pppd/Makefile.linux | 3 +-- + pppd/plugins/Makefile.linux | 2 +- + pppd/plugins/pppoatm/Makefile.linux | 2 +- + pppd/plugins/radius/Makefile.linux | 2 +- + pppd/plugins/rp-pppoe/Makefile.linux | 2 +- + pppdump/Makefile.linux | 2 +- + pppstats/Makefile.linux | 2 +- + 8 files changed, 8 insertions(+), 9 deletions(-) + +diff --git a/chat/Makefile.linux b/chat/Makefile.linux +index 1065ac5..848cd8d 100644 +--- a/chat/Makefile.linux ++++ b/chat/Makefile.linux +@@ -10,7 +10,7 @@ CDEF3=3D -UNO_SLEEP # Use the usleep function + CDEF4=3D -DFNDELAY=3DO_NDELAY # Old name value + CDEFS=3D $(CDEF1) $(CDEF2) $(CDEF3) $(CDEF4) +=20 +-COPTS=3D -O2 -g -pipe ++COPTS=3D $(RPM_OPT_FLAGS) + CFLAGS=3D $(COPTS) $(CDEFS) +=20 + INSTALL=3D install +diff --git a/pppd/Makefile.linux b/pppd/Makefile.linux +index 5a44d30..63872eb 100644 +--- a/pppd/Makefile.linux ++++ b/pppd/Makefile.linux +@@ -32,8 +32,7 @@ endif +=20 + CC =3D gcc + # +-COPTS =3D -O2 -pipe -Wall -g +-LIBS =3D ++COPTS =3D -Wall $(RPM_OPT_FLAGS) +=20 + # Uncomment the next 2 lines to include support for Microsoft's + # MS-CHAP authentication protocol. Also, edit plugins/radius/Makefile.linu= x. +diff --git a/pppd/plugins/Makefile.linux b/pppd/plugins/Makefile.linux +index 0a7ec7b..e09a369 100644 +--- a/pppd/plugins/Makefile.linux ++++ b/pppd/plugins/Makefile.linux +@@ -1,5 +1,5 @@ + #CC =3D gcc +-COPTS =3D -O2 -g ++COPTS =3D $(RPM_OPT_FLAGS) + CFLAGS =3D $(COPTS) -I.. -I../../include -fPIC + LDFLAGS =3D -shared + INSTALL =3D install +diff --git a/pppd/plugins/pppoatm/Makefile.linux b/pppd/plugins/pppoatm/Make= file.linux +index 20f62e6..5a81447 100644 +--- a/pppd/plugins/pppoatm/Makefile.linux ++++ b/pppd/plugins/pppoatm/Makefile.linux +@@ -1,5 +1,5 @@ + #CC =3D gcc +-COPTS =3D -O2 -g ++COPTS =3D $(RPM_OPT_FLAGS) + CFLAGS =3D $(COPTS) -I../.. -I../../../include -fPIC + LDFLAGS =3D -shared + INSTALL =3D install +diff --git a/pppd/plugins/radius/Makefile.linux b/pppd/plugins/radius/Makefi= le.linux +index 24ed3e5..45b3b8d 100644 +--- a/pppd/plugins/radius/Makefile.linux ++++ b/pppd/plugins/radius/Makefile.linux +@@ -12,7 +12,7 @@ VERSION =3D $(shell awk -F '"' '/VERSION/ { print $$2; }' = ../../patchlevel.h) + INSTALL =3D install +=20 + PLUGIN=3Dradius.so radattr.so radrealms.so +-CFLAGS=3D-I. -I../.. -I../../../include -O2 -fPIC -DRC_LOG_FACILITY=3DLOG_D= AEMON ++CFLAGS=3D-I. -I../.. -I../../../include $(RPM_OPT_FLAGS) -DRC_LOG_FACILITY= =3DLOG_DAEMON +=20 + # Uncomment the next line to include support for Microsoft's + # MS-CHAP authentication protocol. +diff --git a/pppd/plugins/rp-pppoe/Makefile.linux b/pppd/plugins/rp-pppoe/Ma= kefile.linux +index 5d7a271..352991a 100644 +--- a/pppd/plugins/rp-pppoe/Makefile.linux ++++ b/pppd/plugins/rp-pppoe/Makefile.linux +@@ -25,7 +25,7 @@ INSTALL =3D install + # Version is set ONLY IN THE MAKEFILE! Don't delete this! + RP_VERSION=3D3.8p +=20 +-COPTS=3D-O2 -g ++COPTS=3D$(RPM_OPT_FLAGS) + CFLAGS=3D$(COPTS) -I../../../include '-DRP_VERSION=3D"$(RP_VERSION)"' + all: rp-pppoe.so pppoe-discovery +=20 +diff --git a/pppdump/Makefile.linux b/pppdump/Makefile.linux +index ac028f6..d0a5032 100644 +--- a/pppdump/Makefile.linux ++++ b/pppdump/Makefile.linux +@@ -2,7 +2,7 @@ DESTDIR =3D $(INSTROOT)@DESTDIR@ + BINDIR =3D $(DESTDIR)/sbin + MANDIR =3D $(DESTDIR)/share/man/man8 +=20 +-CFLAGS=3D -O -I../include/net ++CFLAGS=3D $(RPM_OPT_FLAGS) -I../include/net + OBJS =3D pppdump.o bsd-comp.o deflate.o zlib.o +=20 + INSTALL=3D install +diff --git a/pppstats/Makefile.linux b/pppstats/Makefile.linux +index cca6f0f..42aba73 100644 +--- a/pppstats/Makefile.linux ++++ b/pppstats/Makefile.linux +@@ -10,7 +10,7 @@ PPPSTATSRCS =3D pppstats.c + PPPSTATOBJS =3D pppstats.o +=20 + #CC =3D gcc +-COPTS =3D -O ++COPTS =3D $(RPM_OPT_FLAGS) + COMPILE_FLAGS =3D -I../include + LIBS =3D +=20 +--=20 +1.8.3.1 + diff --git a/src/patches/ppp/0012-pppd-we-don-t-want-to-accidentally-leak-fds= .patch b/src/patches/ppp/0012-pppd-we-don-t-want-to-accidentally-leak-fds.pat= ch new file mode 100644 index 0000000..90bb2d1 --- /dev/null +++ b/src/patches/ppp/0012-pppd-we-don-t-want-to-accidentally-leak-fds.patch @@ -0,0 +1,143 @@ +From 82cd789df0f022eb6f3d28646e7a61d1d0715805 Mon Sep 17 00:00:00 2001 +From: Michal Sekletar +Date: Mon, 7 Apr 2014 12:23:36 +0200 +Subject: [PATCH 12/25] pppd: we don't want to accidentally leak fds + +--- + pppd/auth.c | 20 ++++++++++---------- + pppd/options.c | 2 +- + pppd/sys-linux.c | 4 ++-- + 3 files changed, 13 insertions(+), 13 deletions(-) + +diff --git a/pppd/auth.c b/pppd/auth.c +index 4271af6..9e957fa 100644 +--- a/pppd/auth.c ++++ b/pppd/auth.c +@@ -428,7 +428,7 @@ setupapfile(argv) + option_error("unable to reset uid before opening %s: %m", fname); + return 0; + } +- ufile =3D fopen(fname, "r"); ++ ufile =3D fopen(fname, "re"); + if (seteuid(euid) =3D=3D -1) + fatal("unable to regain privileges: %m"); + if (ufile =3D=3D NULL) { +@@ -1413,7 +1413,7 @@ check_passwd(unit, auser, userlen, apasswd, passwdlen,= msg) + filename =3D _PATH_UPAPFILE; + addrs =3D opts =3D NULL; + ret =3D UPAP_AUTHNAK; +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + if (f =3D=3D NULL) { + error("Can't open PAP password file %s: %m", filename); +=20 +@@ -1512,7 +1512,7 @@ null_login(unit) + if (ret <=3D 0) { + filename =3D _PATH_UPAPFILE; + addrs =3D NULL; +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + if (f =3D=3D NULL) + return 0; + check_access(f, filename); +@@ -1559,7 +1559,7 @@ get_pap_passwd(passwd) + } +=20 + filename =3D _PATH_UPAPFILE; +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + if (f =3D=3D NULL) + return 0; + check_access(f, filename); +@@ -1597,7 +1597,7 @@ have_pap_secret(lacks_ipp) + } +=20 + filename =3D _PATH_UPAPFILE; +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + if (f =3D=3D NULL) + return 0; +=20 +@@ -1642,7 +1642,7 @@ have_chap_secret(client, server, need_ip, lacks_ipp) + } +=20 + filename =3D _PATH_CHAPFILE; +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + if (f =3D=3D NULL) + return 0; +=20 +@@ -1684,7 +1684,7 @@ have_srp_secret(client, server, need_ip, lacks_ipp) + struct wordlist *addrs; +=20 + filename =3D _PATH_SRPFILE; +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + if (f =3D=3D NULL) + return 0; +=20 +@@ -1740,7 +1740,7 @@ get_secret(unit, client, server, secret, secret_len, a= m_server) + addrs =3D NULL; + secbuf[0] =3D 0; +=20 +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + if (f =3D=3D NULL) { + error("Can't open chap secret file %s: %m", filename); + return 0; +@@ -1797,7 +1797,7 @@ get_srp_secret(unit, client, server, secret, am_server) + filename =3D _PATH_SRPFILE; + addrs =3D NULL; +=20 +- fp =3D fopen(filename, "r"); ++ fp =3D fopen(filename, "re"); + if (fp =3D=3D NULL) { + error("Can't open srp secret file %s: %m", filename); + return 0; +@@ -2203,7 +2203,7 @@ scan_authfile(f, client, server, secret, addrs, opts, = filename, flags) + */ + if (word[0] =3D=3D '@' && word[1] =3D=3D '/') { + strlcpy(atfile, word+1, sizeof(atfile)); +- if ((sf =3D fopen(atfile, "r")) =3D=3D NULL) { ++ if ((sf =3D fopen(atfile, "re")) =3D=3D NULL) { + warn("can't open indirect secret file %s", atfile); + continue; + } +diff --git a/pppd/options.c b/pppd/options.c +index 45fa742..1d754ae 100644 +--- a/pppd/options.c ++++ b/pppd/options.c +@@ -427,7 +427,7 @@ options_from_file(filename, must_exist, check_prot, priv) + option_error("unable to drop privileges to open %s: %m", filename); + return 0; + } +- f =3D fopen(filename, "r"); ++ f =3D fopen(filename, "re"); + err =3D errno; + if (check_prot && seteuid(euid) =3D=3D -1) + fatal("unable to regain privileges"); +diff --git a/pppd/sys-linux.c b/pppd/sys-linux.c +index 72a7727..8a12fa0 100644 +--- a/pppd/sys-linux.c ++++ b/pppd/sys-linux.c +@@ -1412,7 +1412,7 @@ static char *path_to_procfs(const char *tail) + /* Default the mount location of /proc */ + strlcpy (proc_path, "/proc", sizeof(proc_path)); + proc_path_len =3D 5; +- fp =3D fopen(MOUNTED, "r"); ++ fp =3D fopen(MOUNTED, "re"); + if (fp !=3D NULL) { + while ((mntent =3D getmntent(fp)) !=3D NULL) { + if (strcmp(mntent->mnt_type, MNTTYPE_IGNORE) =3D=3D 0) +@@ -1472,7 +1472,7 @@ static int open_route_table (void) + close_route_table(); +=20 + path =3D path_to_procfs("/net/route"); +- route_fd =3D fopen (path, "r"); ++ route_fd =3D fopen (path, "re"); + if (route_fd =3D=3D NULL) { + error("can't open routing table %s: %m", path); + return 0; +--=20 +1.8.3.1 + diff --git a/src/patches/ppp/0013-everywhere-O_CLOEXEC-harder.patch b/src/pat= ches/ppp/0013-everywhere-O_CLOEXEC-harder.patch new file mode 100644 index 0000000..e3608a0 --- /dev/null +++ b/src/patches/ppp/0013-everywhere-O_CLOEXEC-harder.patch @@ -0,0 +1,241 @@ +From 302c1b736cb656c7885a0cba270fd953a672d8a8 Mon Sep 17 00:00:00 2001 +From: Michal Sekletar +Date: Mon, 7 Apr 2014 13:56:34 +0200 +Subject: [PATCH 13/25] everywhere: O_CLOEXEC harder + +--- + pppd/eap.c | 2 +- + pppd/main.c | 4 ++-- + pppd/options.c | 4 ++-- + pppd/sys-linux.c | 22 +++++++++++----------- + pppd/tdb.c | 4 ++-- + pppd/tty.c | 4 ++-- + pppd/utils.c | 6 +++--- + 7 files changed, 23 insertions(+), 23 deletions(-) + +diff --git a/pppd/eap.c b/pppd/eap.c +index 6ea6c1f..faced53 100644 +--- a/pppd/eap.c ++++ b/pppd/eap.c +@@ -1226,7 +1226,7 @@ mode_t modebits; +=20 + if ((path =3D name_of_pn_file()) =3D=3D NULL) + return (-1); +- fd =3D open(path, modebits, S_IRUSR | S_IWUSR); ++ fd =3D open(path, modebits, S_IRUSR | S_IWUSR | O_CLOEXEC); + err =3D errno; + free(path); + errno =3D err; +diff --git a/pppd/main.c b/pppd/main.c +index 6d50d1b..4880377 100644 +--- a/pppd/main.c ++++ b/pppd/main.c +@@ -420,7 +420,7 @@ main(argc, argv) + die(0); +=20 + /* Make sure fds 0, 1, 2 are open to somewhere. */ +- fd_devnull =3D open(_PATH_DEVNULL, O_RDWR); ++ fd_devnull =3D open(_PATH_DEVNULL, O_RDWR | O_CLOEXEC); + if (fd_devnull < 0) + fatal("Couldn't open %s: %m", _PATH_DEVNULL); + while (fd_devnull <=3D 2) { +@@ -1679,7 +1679,7 @@ device_script(program, in, out, dont_wait) + if (log_to_fd >=3D 0) + errfd =3D log_to_fd; + else +- errfd =3D open(_PATH_CONNERRS, O_WRONLY | O_APPEND | O_CREAT, 0600); ++ errfd =3D open(_PATH_CONNERRS, O_WRONLY | O_APPEND | O_CREAT | O_CLOEXEC, = 0600); +=20 + ++conn_running; + pid =3D safe_fork(in, out, errfd); +diff --git a/pppd/options.c b/pppd/options.c +index 1d754ae..8e62635 100644 +--- a/pppd/options.c ++++ b/pppd/options.c +@@ -1544,9 +1544,9 @@ setlogfile(argv) + option_error("unable to drop permissions to open %s: %m", *argv); + return 0; + } +- fd =3D open(*argv, O_WRONLY | O_APPEND | O_CREAT | O_EXCL, 0644); ++ fd =3D open(*argv, O_WRONLY | O_APPEND | O_CREAT | O_EXCL | O_CLOEXEC, = 0644); + if (fd < 0 && errno =3D=3D EEXIST) +- fd =3D open(*argv, O_WRONLY | O_APPEND); ++ fd =3D open(*argv, O_WRONLY | O_APPEND | O_CLOEXEC); + err =3D errno; + if (!privileged_option && seteuid(euid) =3D=3D -1) + fatal("unable to regain privileges: %m"); +diff --git a/pppd/sys-linux.c b/pppd/sys-linux.c +index 8a12fa0..00a2cf5 100644 +--- a/pppd/sys-linux.c ++++ b/pppd/sys-linux.c +@@ -459,7 +459,7 @@ int generic_establish_ppp (int fd) + goto err; + } + dbglog("using channel %d", chindex); +- fd =3D open("/dev/ppp", O_RDWR); ++ fd =3D open("/dev/ppp", O_RDWR | O_CLOEXEC); + if (fd < 0) { + error("Couldn't reopen /dev/ppp: %m"); + goto err; +@@ -619,7 +619,7 @@ static int make_ppp_unit() + dbglog("in make_ppp_unit, already had /dev/ppp open?"); + close(ppp_dev_fd); + } +- ppp_dev_fd =3D open("/dev/ppp", O_RDWR); ++ ppp_dev_fd =3D open("/dev/ppp", O_RDWR | O_CLOEXEC); + if (ppp_dev_fd < 0) + fatal("Couldn't open /dev/ppp: %m"); + flags =3D fcntl(ppp_dev_fd, F_GETFL); +@@ -693,7 +693,7 @@ int bundle_attach(int ifnum) + if (!new_style_driver) + return -1; +=20 +- master_fd =3D open("/dev/ppp", O_RDWR); ++ master_fd =3D open("/dev/ppp", O_RDWR | O_CLOEXEC); + if (master_fd < 0) + fatal("Couldn't open /dev/ppp: %m"); + if (ioctl(master_fd, PPPIOCATTACH, &ifnum) < 0) { +@@ -1715,7 +1715,7 @@ int sifproxyarp (int unit, u_int32_t his_adr) + if (tune_kernel) { + forw_path =3D path_to_procfs("/sys/net/ipv4/ip_forward"); + if (forw_path !=3D 0) { +- int fd =3D open(forw_path, O_WRONLY); ++ int fd =3D open(forw_path, O_WRONLY | O_CLOEXEC); + if (fd >=3D 0) { + if (write(fd, "1", 1) !=3D 1) + error("Couldn't enable IP forwarding: %m"); +@@ -2030,7 +2030,7 @@ int ppp_available(void) + sscanf(utsname.release, "%d.%d.%d", &osmaj, &osmin, &ospatch); + kernel_version =3D KVERSION(osmaj, osmin, ospatch); +=20 +- fd =3D open("/dev/ppp", O_RDWR); ++ fd =3D open("/dev/ppp", O_RDWR | O_CLOEXEC); + if (fd >=3D 0) { + new_style_driver =3D 1; +=20 +@@ -2208,7 +2208,7 @@ void logwtmp (const char *line, const char *name, cons= t char *host) + #if __GLIBC__ >=3D 2 + updwtmp(_PATH_WTMP, &ut); + #else +- wtmp =3D open(_PATH_WTMP, O_APPEND|O_WRONLY); ++ wtmp =3D open(_PATH_WTMP, O_APPEND|O_WRONLY|O_CLOEXEC); + if (wtmp >=3D 0) { + flock(wtmp, LOCK_EX); +=20 +@@ -2394,7 +2394,7 @@ int sifaddr (int unit, u_int32_t our_adr, u_int32_t hi= s_adr, + int fd; +=20 + path =3D path_to_procfs("/sys/net/ipv4/ip_dynaddr"); +- if (path !=3D 0 && (fd =3D open(path, O_WRONLY)) >=3D 0) { ++ if (path !=3D 0 && (fd =3D open(path, O_WRONLY | O_CLOEXEC)) >=3D 0) { + if (write(fd, "1", 1) !=3D 1) + error("Couldn't enable dynamic IP addressing: %m"); + close(fd); +@@ -2570,7 +2570,7 @@ get_pty(master_fdp, slave_fdp, slave_name, uid) + /* + * Try the unix98 way first. + */ +- mfd =3D open("/dev/ptmx", O_RDWR); ++ mfd =3D open("/dev/ptmx", O_RDWR | O_CLOEXEC); + if (mfd >=3D 0) { + int ptn; + if (ioctl(mfd, TIOCGPTN, &ptn) >=3D 0) { +@@ -2581,7 +2581,7 @@ get_pty(master_fdp, slave_fdp, slave_name, uid) + if (ioctl(mfd, TIOCSPTLCK, &ptn) < 0) + warn("Couldn't unlock pty slave %s: %m", pty_name); + #endif +- if ((sfd =3D open(pty_name, O_RDWR | O_NOCTTY)) < 0) ++ if ((sfd =3D open(pty_name, O_RDWR | O_NOCTTY | O_CLOEXEC)) < 0) + warn("Couldn't open pty slave %s: %m", pty_name); + } + } +@@ -2592,10 +2592,10 @@ get_pty(master_fdp, slave_fdp, slave_name, uid) + for (i =3D 0; i < 64; ++i) { + slprintf(pty_name, sizeof(pty_name), "/dev/pty%c%x", + 'p' + i / 16, i % 16); +- mfd =3D open(pty_name, O_RDWR, 0); ++ mfd =3D open(pty_name, O_RDWR | O_CLOEXEC, 0); + if (mfd >=3D 0) { + pty_name[5] =3D 't'; +- sfd =3D open(pty_name, O_RDWR | O_NOCTTY, 0); ++ sfd =3D open(pty_name, O_RDWR | O_NOCTTY | O_CLOEXEC, 0); + if (sfd >=3D 0) { + fchown(sfd, uid, -1); + fchmod(sfd, S_IRUSR | S_IWUSR); +diff --git a/pppd/tdb.c b/pppd/tdb.c +index bdc5828..c7ab71c 100644 +--- a/pppd/tdb.c ++++ b/pppd/tdb.c +@@ -1724,7 +1724,7 @@ TDB_CONTEXT *tdb_open_ex(const char *name, int hash_si= ze, int tdb_flags, + goto internal; + } +=20 +- if ((tdb->fd =3D open(name, open_flags, mode)) =3D=3D -1) { ++ if ((tdb->fd =3D open(name, open_flags | O_CLOEXEC, mode)) =3D=3D -1) { + TDB_LOG((tdb, 5, "tdb_open_ex: could not open file %s: %s\n", + name, strerror(errno))); + goto fail; /* errno set by open(2) */ +@@ -1967,7 +1967,7 @@ int tdb_reopen(TDB_CONTEXT *tdb) + } + if (close(tdb->fd) !=3D 0) + TDB_LOG((tdb, 0, "tdb_reopen: WARNING closing tdb->fd failed!\n")); +- tdb->fd =3D open(tdb->name, tdb->open_flags & ~(O_CREAT|O_TRUNC), 0); ++ tdb->fd =3D open(tdb->name, (tdb->open_flags & ~(O_CREAT|O_TRUNC)) | O_CLO= EXEC, 0); + if (tdb->fd =3D=3D -1) { + TDB_LOG((tdb, 0, "tdb_reopen: open failed (%s)\n", strerror(errno))); + goto fail; +diff --git a/pppd/tty.c b/pppd/tty.c +index d571b11..bc96695 100644 +--- a/pppd/tty.c ++++ b/pppd/tty.c +@@ -569,7 +569,7 @@ int connect_tty() + status =3D EXIT_OPEN_FAILED; + goto errret; + } +- real_ttyfd =3D open(devnam, O_NONBLOCK | O_RDWR, 0); ++ real_ttyfd =3D open(devnam, O_NONBLOCK | O_RDWR | O_CLOEXEC, 0); + err =3D errno; + if (prio < OPRIO_ROOT && seteuid(0) =3D=3D -1) + fatal("Unable to regain privileges"); +@@ -723,7 +723,7 @@ int connect_tty() + if (connector =3D=3D NULL && modem && devnam[0] !=3D 0) { + int i; + for (;;) { +- if ((i =3D open(devnam, O_RDWR)) >=3D 0) ++ if ((i =3D open(devnam, O_RDWR | O_CLOEXEC)) >=3D 0) + break; + if (errno !=3D EINTR) { + error("Failed to reopen %s: %m", devnam); +diff --git a/pppd/utils.c b/pppd/utils.c +index 29bf970..6051b9a 100644 +--- a/pppd/utils.c ++++ b/pppd/utils.c +@@ -918,14 +918,14 @@ lock(dev) + slprintf(lock_file, sizeof(lock_file), "%s/LCK..%s", LOCK_DIR, dev); + #endif +=20 +- while ((fd =3D open(lock_file, O_EXCL | O_CREAT | O_RDWR, 0644)) < 0) { ++ while ((fd =3D open(lock_file, O_EXCL | O_CREAT | O_RDWR | O_CLOEXEC, 0= 644)) < 0) { + if (errno !=3D EEXIST) { + error("Can't create lock file %s: %m", lock_file); + break; + } +=20 + /* Read the lock file to find out who has the device locked. */ +- fd =3D open(lock_file, O_RDONLY, 0); ++ fd =3D open(lock_file, O_RDONLY | O_CLOEXEC, 0); + if (fd < 0) { + if (errno =3D=3D ENOENT) /* This is just a timing problem. */ + continue; +@@ -1004,7 +1004,7 @@ relock(pid) +=20 + if (lock_file[0] =3D=3D 0) + return -1; +- fd =3D open(lock_file, O_WRONLY, 0); ++ fd =3D open(lock_file, O_WRONLY | O_CLOEXEC, 0); + if (fd < 0) { + error("Couldn't reopen lock file %s: %m", lock_file); + lock_file[0] =3D 0; +--=20 +1.8.3.1 + diff --git a/src/patches/ppp/0014-everywhere-use-SOCK_CLOEXEC-when-creating-s= ocket.patch b/src/patches/ppp/0014-everywhere-use-SOCK_CLOEXEC-when-creating-= socket.patch new file mode 100644 index 0000000..3475f09 --- /dev/null +++ b/src/patches/ppp/0014-everywhere-use-SOCK_CLOEXEC-when-creating-socket.p= atch @@ -0,0 +1,174 @@ +From 2a97ab28ee00586e5f06b3ef3a0e43ea0c7c6499 Mon Sep 17 00:00:00 2001 +From: Michal Sekletar +Date: Mon, 7 Apr 2014 14:21:41 +0200 +Subject: [PATCH 14/25] everywhere: use SOCK_CLOEXEC when creating socket + +--- + pppd/plugins/pppoatm/pppoatm.c | 2 +- + pppd/plugins/pppol2tp/openl2tp.c | 2 +- + pppd/plugins/pppol2tp/pppol2tp.c | 2 +- + pppd/plugins/rp-pppoe/if.c | 2 +- + pppd/plugins/rp-pppoe/plugin.c | 6 +++--- + pppd/plugins/rp-pppoe/pppoe-discovery.c | 2 +- + pppd/sys-linux.c | 10 +++++----- + pppd/tty.c | 2 +- + 8 files changed, 14 insertions(+), 14 deletions(-) + +diff --git a/pppd/plugins/pppoatm/pppoatm.c b/pppd/plugins/pppoatm/pppoatm.c +index d693350..c31bb34 100644 +--- a/pppd/plugins/pppoatm/pppoatm.c ++++ b/pppd/plugins/pppoatm/pppoatm.c +@@ -135,7 +135,7 @@ static int connect_pppoatm(void) +=20 + if (!device_got_set) + no_device_given_pppoatm(); +- fd =3D socket(AF_ATMPVC, SOCK_DGRAM, 0); ++ fd =3D socket(AF_ATMPVC, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (fd < 0) + fatal("failed to create socket: %m"); + memset(&qos, 0, sizeof qos); +diff --git a/pppd/plugins/pppol2tp/openl2tp.c b/pppd/plugins/pppol2tp/openl2= tp.c +index 9643b96..1099575 100644 +--- a/pppd/plugins/pppol2tp/openl2tp.c ++++ b/pppd/plugins/pppol2tp/openl2tp.c +@@ -83,7 +83,7 @@ static int openl2tp_client_create(void) + int result; +=20 + if (openl2tp_fd < 0) { +- openl2tp_fd =3D socket(PF_UNIX, SOCK_DGRAM, 0); ++ openl2tp_fd =3D socket(PF_UNIX, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (openl2tp_fd < 0) { + error("openl2tp connection create: %m"); + return -ENOTCONN; +diff --git a/pppd/plugins/pppol2tp/pppol2tp.c b/pppd/plugins/pppol2tp/pppol2= tp.c +index a7e3400..e64a778 100644 +--- a/pppd/plugins/pppol2tp/pppol2tp.c ++++ b/pppd/plugins/pppol2tp/pppol2tp.c +@@ -208,7 +208,7 @@ static void send_config_pppol2tp(int mtu, + struct ifreq ifr; + int fd; +=20 +- fd =3D socket(AF_INET, SOCK_DGRAM, 0); ++ fd =3D socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (fd >=3D 0) { + memset (&ifr, '\0', sizeof (ifr)); + strlcpy(ifr.ifr_name, ifname, sizeof(ifr.ifr_name)); +diff --git a/pppd/plugins/rp-pppoe/if.c b/pppd/plugins/rp-pppoe/if.c +index 91e9a57..72aba41 100644 +--- a/pppd/plugins/rp-pppoe/if.c ++++ b/pppd/plugins/rp-pppoe/if.c +@@ -116,7 +116,7 @@ openInterface(char const *ifname, UINT16_t type, unsigne= d char *hwaddr) + stype =3D SOCK_PACKET; + #endif +=20 +- if ((fd =3D socket(domain, stype, htons(type))) < 0) { ++ if ((fd =3D socket(domain, stype | SOCK_CLOEXEC, htons(type))) < 0) { + /* Give a more helpful message for the common error case */ + if (errno =3D=3D EPERM) { + fatal("Cannot create raw socket -- pppoe must be run as root."); +diff --git a/pppd/plugins/rp-pppoe/plugin.c b/pppd/plugins/rp-pppoe/plugin.c +index a8c2bb4..24bdf8f 100644 +--- a/pppd/plugins/rp-pppoe/plugin.c ++++ b/pppd/plugins/rp-pppoe/plugin.c +@@ -137,7 +137,7 @@ PPPOEConnectDevice(void) + /* server equipment). = */ + /* Opening this socket just before waitForPADS in the discovery() = */ + /* function would be more appropriate, but it would mess-up the code = */ +- conn->sessionSocket =3D socket(AF_PPPOX, SOCK_STREAM, PX_PROTO_OE); ++ conn->sessionSocket =3D socket(AF_PPPOX, SOCK_STREAM | SOCK_CLOEXEC, PX= _PROTO_OE); + if (conn->sessionSocket < 0) { + error("Failed to create PPPoE socket: %m"); + return -1; +@@ -148,7 +148,7 @@ PPPOEConnectDevice(void) + lcp_wantoptions[0].mru =3D conn->mru; +=20 + /* Update maximum MRU */ +- s =3D socket(AF_INET, SOCK_DGRAM, 0); ++ s =3D socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (s < 0) { + error("Can't get MTU for %s: %m", conn->ifName); + goto errout; +@@ -320,7 +320,7 @@ PPPoEDevnameHook(char *cmd, char **argv, int doit) + } +=20 + /* Open a socket */ +- if ((fd =3D socket(PF_PACKET, SOCK_RAW, 0)) < 0) { ++ if ((fd =3D socket(PF_PACKET, SOCK_RAW | SOCK_CLOEXEC, 0)) < 0) { + r =3D 0; + } +=20 +diff --git a/pppd/plugins/rp-pppoe/pppoe-discovery.c b/pppd/plugins/rp-pppoe= /pppoe-discovery.c +index 3d3bf4e..c0d927d 100644 +--- a/pppd/plugins/rp-pppoe/pppoe-discovery.c ++++ b/pppd/plugins/rp-pppoe/pppoe-discovery.c +@@ -121,7 +121,7 @@ openInterface(char const *ifname, UINT16_t type, unsigne= d char *hwaddr) + stype =3D SOCK_PACKET; + #endif +=20 +- if ((fd =3D socket(domain, stype, htons(type))) < 0) { ++ if ((fd =3D socket(domain, stype | SOCK_CLOEXEC, htons(type))) < 0) { + /* Give a more helpful message for the common error case */ + if (errno =3D=3D EPERM) { + rp_fatal("Cannot create raw socket -- pppoe must be run as root."); +diff --git a/pppd/sys-linux.c b/pppd/sys-linux.c +index 00a2cf5..0690019 100644 +--- a/pppd/sys-linux.c ++++ b/pppd/sys-linux.c +@@ -308,12 +308,12 @@ static int modify_flags(int fd, int clear_bits, int se= t_bits) + void sys_init(void) + { + /* Get an internet socket for doing socket ioctls. */ +- sock_fd =3D socket(AF_INET, SOCK_DGRAM, 0); ++ sock_fd =3D socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (sock_fd < 0) + fatal("Couldn't create IP socket: %m(%d)", errno); +=20 + #ifdef INET6 +- sock6_fd =3D socket(AF_INET6, SOCK_DGRAM, 0); ++ sock6_fd =3D socket(AF_INET6, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (sock6_fd < 0) + sock6_fd =3D -errno; /* save errno for later */ + #endif +@@ -1857,7 +1857,7 @@ get_if_hwaddr(u_char *addr, char *name) + struct ifreq ifreq; + int ret, sock_fd; +=20 +- sock_fd =3D socket(AF_INET, SOCK_DGRAM, 0); ++ sock_fd =3D socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (sock_fd < 0) + return 0; + memset(&ifreq.ifr_hwaddr, 0, sizeof(struct sockaddr)); +@@ -2067,7 +2067,7 @@ int ppp_available(void) + /* + * Open a socket for doing the ioctl operations. + */ +- s =3D socket(AF_INET, SOCK_DGRAM, 0); ++ s =3D socket(AF_INET, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if (s < 0) + return 0; +=20 +@@ -2860,7 +2860,7 @@ ether_to_eui64(eui64_t *p_eui64) + int skfd; + const unsigned char *ptr; +=20 +- skfd =3D socket(PF_INET6, SOCK_DGRAM, 0); ++ skfd =3D socket(PF_INET6, SOCK_DGRAM | SOCK_CLOEXEC, 0); + if(skfd =3D=3D -1) + { + warn("could not open IPv6 socket"); +diff --git a/pppd/tty.c b/pppd/tty.c +index bc96695..8e76a5d 100644 +--- a/pppd/tty.c ++++ b/pppd/tty.c +@@ -896,7 +896,7 @@ open_socket(dest) + *sep =3D ':'; +=20 + /* get a socket and connect it to the other end */ +- sock =3D socket(PF_INET, SOCK_STREAM, 0); ++ sock =3D socket(PF_INET, SOCK_STREAM | SOCK_CLOEXEC, 0); + if (sock < 0) { + error("Can't create socket: %m"); + return -1; +--=20 +1.8.3.1 + diff --git a/src/patches/ppp/ppp-2.4.6-increase-max-padi-attempts.patch b/src= /patches/ppp/ppp-2.4.6-increase-max-padi-attempts.patch new file mode 100644 index 0000000..b09a9b5 --- /dev/null +++ b/src/patches/ppp/ppp-2.4.6-increase-max-padi-attempts.patch @@ -0,0 +1,13 @@ +diff --git a/pppd/plugins/rp-pppoe/pppoe.h b/pppd/plugins/rp-pppoe/pppoe.h +index 9ab2eee..86762bd 100644 +--- a/pppd/plugins/rp-pppoe/pppoe.h ++++ b/pppd/plugins/rp-pppoe/pppoe.h +@@ -148,7 +148,7 @@ extern UINT16_t Eth_PPPOE_Session; + #define STATE_TERMINATED 4 +=20 + /* How many PADI/PADS attempts? */ +-#define MAX_PADI_ATTEMPTS 3 ++#define MAX_PADI_ATTEMPTS 12 +=20 + /* Initial timeout for PADO/PADS */ + #define PADI_TIMEOUT 5 hooks/post-receive -- IPFire 2.x development tree --===============0436930369157199907==--