From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: ipfire-scm@lists.ipfire.org Subject: [git.ipfire.org] IPFire 2.x development tree branch, next, updated. bf62652ecfbe1331f0eef5d198b8ac6db417a4d4 Date: Wed, 08 May 2019 10:00:06 +0100 Message-ID: <20190508090006.C38BB84FDC0@people01.i.ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2056552047585083353==" List-Id: --===============2056552047585083353== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable This is an automated email from the git hooks/post-receive script. It was generated because a ref change was pushed to the repository containing the project "IPFire 2.x development tree". The branch, next has been updated via bf62652ecfbe1331f0eef5d198b8ac6db417a4d4 (commit) via e9dd6da5527766be474dfc057677acab7f756ed4 (commit) via 68f2b71778eebea13d17fd51172407c8030d7797 (commit) via 5737a22cf2feee68f4865683dff192e8c897e24f (commit) via 090af02e07889d6d62b346a3330f563ec6181ec4 (commit) via c818134f44ca937b288671e541a95d1bd662066d (commit) via 673db997cc5a359b59a223811c94a83df6eca9d2 (commit) via f302e31ae2dd296422a8685294e2aa1c18d0fb20 (commit) via 7f07bdb43f731d45ba4ff208c997e09f55adddd8 (commit) via 45e4d6af99d28d6453a9a29ab2fe7414aad016cb (commit) via 92f4652226e14ccbd7cf067928964d9b7d5c52e3 (commit) via 9177b69830974333ef0197ba4c94aa6c21366741 (commit) via bc78976cc6586c5f8e7c59ab3cb844fa56249c91 (commit) via 60bc3a4b7a60587d590517a167b80d624f0c86cb (commit) via b38710a1cd942f231ea16eafe62369e742b56d55 (commit) from a59052cec61a78357033f9a97d09f4f47625a2d2 (commit) Those revisions listed above that are new to this repository have not appeared on any other notification email; so we list those revisions in full, below. - Log ----------------------------------------------------------------- commit bf62652ecfbe1331f0eef5d198b8ac6db417a4d4 Author: Michael Tremer Date: Tue May 7 22:54:11 2019 +0100 squid: Link against libatomic on ARM =20 This package failed to build on ARM because atomic functions are being emulated on ARM32 and the required library was not linked. =20 Signed-off-by: Michael Tremer commit e9dd6da5527766be474dfc057677acab7f756ed4 Author: Michael Tremer Date: Tue May 7 21:19:53 2019 +0100 xfsprogs: Disable LTO on armv5tel =20 LTO fails on ARM, but since we do not require it, we can disable it here. =20 Signed-off-by: Michael Tremer commit 68f2b71778eebea13d17fd51172407c8030d7797 Author: Michael Tremer Date: Tue May 7 23:53:43 2019 +0100 core132: Ship updated pakfire files =20 Signed-off-by: Michael Tremer commit 5737a22cf2feee68f4865683dff192e8c897e24f Author: Alexander Koch Date: Sat Apr 27 21:26:46 2019 +0200 zabbix_agentd: Add UserParameter for Pakfire Status =20 Ship the UserParameter for monitoring the status of pakfire for keeping t= rack of available updates etc. =20 Signed-off-by: Alexander Koch Signed-off-by: Michael Tremer commit 090af02e07889d6d62b346a3330f563ec6181ec4 Author: Alexander Koch Date: Sat Apr 27 21:26:45 2019 +0200 Pakfire: Add new command line argument "status" =20 This enables Pakfire to return a Status-Summary for the Current Core-Upda= te-Level, time since last updates, the availability of a core-/packet-update = and if a reboot is required to complete an update. This can be used by monito= ring agents (e.g. zabbix_agentd) to monitor the update status of the IPFire d= evice. =20 Signed-off-by: Alexander Koch Signed-off-by: Michael Tremer commit c818134f44ca937b288671e541a95d1bd662066d Author: Alexander Koch Date: Sat Apr 27 21:26:44 2019 +0200 zabbix_agentd: update to 4.2.1 =20 Release notes: https://www.zabbix.com/rn/rn4.2.1 =20 Signed-off-by: Alexander Koch Signed-off-by: Michael Tremer commit 673db997cc5a359b59a223811c94a83df6eca9d2 Author: Michael Tremer Date: Tue May 7 23:50:26 2019 +0100 core132: Ship updated libedit =20 Signed-off-by: Michael Tremer commit f302e31ae2dd296422a8685294e2aa1c18d0fb20 Author: Matthias Fischer Date: Wed May 1 19:32:15 2019 +0200 libedit: Update to 20190324-3.1 =20 For details see: https://thrysoee.dk/editline/ =20 Signed-off-by: Matthias Fischer Signed-off-by: Michael Tremer commit 7f07bdb43f731d45ba4ff208c997e09f55adddd8 Author: Michael Tremer Date: Tue May 7 23:49:47 2019 +0100 core132: Ship updated knot =20 Signed-off-by: Michael Tremer commit 45e4d6af99d28d6453a9a29ab2fe7414aad016cb Author: Matthias Fischer Date: Wed May 1 19:28:16 2019 +0200 knot: Update to 2.8.1 =20 For details see: https://www.knot-dns.cz/2019-04-09-version-281.html =20 Signed-off-by: Matthias Fischer Signed-off-by: Michael Tremer commit 92f4652226e14ccbd7cf067928964d9b7d5c52e3 Author: Michael Tremer Date: Tue May 7 23:48:41 2019 +0100 core132: Ship updated bind =20 Signed-off-by: Michael Tremer commit 9177b69830974333ef0197ba4c94aa6c21366741 Author: Matthias Fischer Date: Sat Apr 27 02:19:34 2019 +0200 bind: Update to 9.11.6-P1 =20 For details see: http://ftp.isc.org/isc/bind9/9.11.6-P1/RELEASE-NOTES-bind-9.11.6-P1.html =20 "Security Fixes =20 The TCP client quota set using the tcp-clients option could be exceeded = in some cases. This could lead to exhaustion of file descriptors. This flaw is disclose= d in CVE-2018-5743. [GL #615]" =20 Signed-off-by: Matthias Fischer Signed-off-by: Michael Tremer commit bc78976cc6586c5f8e7c59ab3cb844fa56249c91 Author: Michael Tremer Date: Tue May 7 23:46:36 2019 +0100 core132: Ship updated dhcpcd =20 Signed-off-by: Michael Tremer commit 60bc3a4b7a60587d590517a167b80d624f0c86cb Author: Matthias Fischer Date: Sat May 4 21:59:15 2019 +0200 dhcpcd: Update to 7.2.2 =20 For details see: https://roy.marples.name/ =20 Signed-off-by: Matthias Fischer Signed-off-by: Michael Tremer commit b38710a1cd942f231ea16eafe62369e742b56d55 Author: Michael Tremer Date: Tue May 7 23:44:44 2019 +0100 firewall: Allow SNAT rules with RED interface =20 Signed-off-by: Michael Tremer ----------------------------------------------------------------------- Summary of changes: config/rootfiles/common/bind | 2 +- config/rootfiles/common/libedit | 2 +- .../{oldcore/100 =3D> core/132}/filelists/bind | 0 .../{oldcore/125 =3D> core/132}/filelists/dhcpcd | 0 config/rootfiles/core/132/filelists/files | 3 ++ .../{oldcore/128 =3D> core/132}/filelists/knot | 0 .../{oldcore/128 =3D> core/132}/filelists/libedit | 0 config/rootfiles/packages/zabbix_agentd | 1 + config/zabbix_agentd/sudoers | 8 ++-- config/zabbix_agentd/userparameter_pakfire.conf | 2 + html/cgi-bin/firewall.cgi | 1 + lfs/bind | 4 +- lfs/dhcpcd | 6 +-- lfs/knot | 4 +- lfs/libedit | 4 +- lfs/squid | 7 ++- lfs/xfsprogs | 10 ++++- lfs/zabbix_agentd | 8 ++-- src/pakfire/lib/functions.pl | 52 ++++++++++++++++++++= ++ src/pakfire/pakfire | 2 + 20 files changed, 96 insertions(+), 20 deletions(-) copy config/rootfiles/{oldcore/100 =3D> core/132}/filelists/bind (100%) copy config/rootfiles/{oldcore/125 =3D> core/132}/filelists/dhcpcd (100%) copy config/rootfiles/{oldcore/128 =3D> core/132}/filelists/knot (100%) copy config/rootfiles/{oldcore/128 =3D> core/132}/filelists/libedit (100%) create mode 100644 config/zabbix_agentd/userparameter_pakfire.conf Difference in files: diff --git a/config/rootfiles/common/bind b/config/rootfiles/common/bind index 8c8a55d19..9164ff740 100644 --- a/config/rootfiles/common/bind +++ b/config/rootfiles/common/bind @@ -274,7 +274,7 @@ usr/lib/libdns.so.1105.0.0 #usr/lib/libisc.la #usr/lib/libisc.so usr/lib/libisc.so.1100 -usr/lib/libisc.so.1100.0.1 +usr/lib/libisc.so.1100.1.0 #usr/lib/libisccc.la #usr/lib/libisccc.so usr/lib/libisccc.so.161 diff --git a/config/rootfiles/common/libedit b/config/rootfiles/common/libedit index 65b3b86a9..c9a20fc01 100644 --- a/config/rootfiles/common/libedit +++ b/config/rootfiles/common/libedit @@ -4,7 +4,7 @@ #usr/lib/libedit.la #usr/lib/libedit.so usr/lib/libedit.so.0 -usr/lib/libedit.so.0.0.59 +usr/lib/libedit.so.0.0.60 #usr/lib/pkgconfig/libedit.pc #usr/share/man/man3/editline.3 #usr/share/man/man3/el_deletestr.3 diff --git a/config/rootfiles/core/132/filelists/bind b/config/rootfiles/core= /132/filelists/bind new file mode 120000 index 000000000..48a0ebaef --- /dev/null +++ b/config/rootfiles/core/132/filelists/bind @@ -0,0 +1 @@ +../../../common/bind \ No newline at end of file diff --git a/config/rootfiles/core/132/filelists/dhcpcd b/config/rootfiles/co= re/132/filelists/dhcpcd new file mode 120000 index 000000000..1e799dabb --- /dev/null +++ b/config/rootfiles/core/132/filelists/dhcpcd @@ -0,0 +1 @@ +../../../common/dhcpcd \ No newline at end of file diff --git a/config/rootfiles/core/132/filelists/files b/config/rootfiles/cor= e/132/filelists/files index 875dd3048..1411d6c90 100644 --- a/config/rootfiles/core/132/filelists/files +++ b/config/rootfiles/core/132/filelists/files @@ -3,7 +3,10 @@ etc/issue etc/mime.types etc/rc.d/init.d/suricata etc/suricata/suricata.yaml +opt/pakfire/lib/functions.pl +opt/pakfire/pakfire srv/web/ipfire/cgi-bin/credits.cgi +srv/web/ipfire/cgi-bin/firewall.cgi srv/web/ipfire/cgi-bin/proxy.cgi usr/lib/firewall/rules.pl usr/sbin/convert-snort diff --git a/config/rootfiles/core/132/filelists/knot b/config/rootfiles/core= /132/filelists/knot new file mode 120000 index 000000000..28e96f878 --- /dev/null +++ b/config/rootfiles/core/132/filelists/knot @@ -0,0 +1 @@ +../../../common/knot \ No newline at end of file diff --git a/config/rootfiles/core/132/filelists/libedit b/config/rootfiles/c= ore/132/filelists/libedit new file mode 120000 index 000000000..03fc483da --- /dev/null +++ b/config/rootfiles/core/132/filelists/libedit @@ -0,0 +1 @@ +../../../common/libedit \ No newline at end of file diff --git a/config/rootfiles/packages/zabbix_agentd b/config/rootfiles/packa= ges/zabbix_agentd index eaecf2644..4420bda05 100644 --- a/config/rootfiles/packages/zabbix_agentd +++ b/config/rootfiles/packages/zabbix_agentd @@ -5,6 +5,7 @@ etc/zabbix_agentd etc/zabbix_agentd/scripts etc/zabbix_agentd/zabbix_agentd.conf etc/zabbix_agentd/zabbix_agentd.d +etc/zabbix_agentd/zabbix_agentd.d/userparameter_pakfire.conf usr/bin/zabbix_get usr/bin/zabbix_sender usr/lib/modules diff --git a/config/zabbix_agentd/sudoers b/config/zabbix_agentd/sudoers index f4e4321cc..1b362a4fd 100644 --- a/config/zabbix_agentd/sudoers +++ b/config/zabbix_agentd/sudoers @@ -8,10 +8,10 @@ # Some hints: # - It is strongly recommended to edit this file only using the visudo -f command. If you mess up this file, # you might end up locking yourself out of your system! -# - Append the full path to each command, using "," as separator. +# - Append the full path incl. parameters to each command, using "," as sepa= rator. # - Only add commands you really need. Zabbix should not have more rights th= an it has to. # -# Uncomment the following two lines and edit the example of commands to fit = your needs: +# Append / edit the following list of commands to fit your needs: # -#Defaults:zabbix !requiretty -#zabbix ALL=3D(ALL) NOPASSWD: , +Defaults:zabbix !requiretty +zabbix ALL=3D(ALL) NOPASSWD: /opt/pakfire/pakfire status diff --git a/config/zabbix_agentd/userparameter_pakfire.conf b/config/zabbix_= agentd/userparameter_pakfire.conf new file mode 100644 index 000000000..aa2e80f5c --- /dev/null +++ b/config/zabbix_agentd/userparameter_pakfire.conf @@ -0,0 +1,2 @@ +### Parameter for monitoring pakfire status +UserParameter=3Dpakfire.status,sudo /opt/pakfire/pakfire status diff --git a/html/cgi-bin/firewall.cgi b/html/cgi-bin/firewall.cgi index fb1c25dfd..45f740322 100644 --- a/html/cgi-bin/firewall.cgi +++ b/html/cgi-bin/firewall.cgi @@ -1718,6 +1718,7 @@ END $Lang::tr{'snat= new source ip address'}: