From: Michael Tremer <git@ipfire.org>
To: ipfire-scm@lists.ipfire.org
Subject: [git.ipfire.org] IPFire 2.x development tree branch, next, updated. 2420194ec36844538fe88068e28128d2711a9843
Date: Wed, 16 Sep 2026 08:19:48 +0000 (UTC) [thread overview]
Message-ID: <4hlBdK00Psz2xKM@people01.haj.ipfire.org> (raw)
This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "IPFire 2.x development tree".
The branch, next has been updated
via 2420194ec36844538fe88068e28128d2711a9843 (commit)
via f26ef5bc5d1031a8aa2a13b9efbf88e593417b90 (commit)
via d59a33eb2f13e98d942de5c888f4cb255c6dca66 (commit)
via 2fdcb5d42fd102c04cd4f8f50310fbe2e0b835ac (commit)
via edf262045f5e55453668038d14394762de0dbe8a (commit)
from 1b662c4d4c70ffecc728466a5cdfa5fd990f56ea (commit)
Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.
- Log -----------------------------------------------------------------
commit 2420194ec36844538fe88068e28128d2711a9843
Author: Adolf Belka <adolf.belka@ipfire.org>
Date: Tue Sep 15 21:06:01 2026 +0200
cmake: Update to version 4.4.3
- Update from version 4.4.1 to 4.4.3
- No change in rootfile
- Required for latest faad2 build
- Changelog
4.4.3
* Swift policy :policy:`CMP0215`'s ``NEW`` behavior has been updated
to require policies :policy:`CMP0157` and :policy:`CMP0195` to also
be set to ``NEW``.
4.4.2
* This version made no changes to documented features or interfaces.
Some implementation updates were made to support ecosystem changes
and/or fix regressions.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
commit f26ef5bc5d1031a8aa2a13b9efbf88e593417b90
Author: Adolf Belka <adolf.belka@ipfire.org>
Date: Tue Sep 15 21:06:00 2026 +0200
faad2: Update to version 2.11.3
- Update from version 2_10_0 (2020) to 2.11.3 (2026)
- Update of rootfile
- In version 2.11.0 (2023) unmaintained code was removed from faad2. This included all
the plugins, and therefore removed the mpegip4 plugin.
- The autotools build was removed in 2.11.0 and cmake and bazel build systems added.
- build changed from autotools to cmake
- faad2-2.11.3 required cmake-4.4.3 for the build
- 2 CVE fixes in 2.11.0
- 2.11.0 had a range of bug fixes which faad2 devlopers categorised as "Safe" bugs,
"Almost Safe" bugs & "Unsafe" bugs. The 2 CVE's are in the "Unsafe" bugs but there
are 15 additional bug fixes in that category that have not had CVE numbers assigned
- Changelog
2.11.3
Fix ISO C warning in libfaad/fixed.h
Check for mp4config.frame.nsclices == 0 in frontend/mp4read.c to fix Heap Buffer Overflow
SBR: prevent heap overflow in channel-pair reconstruction
Fix off-by-one frame index check in mp4read_seek
Fix integer overflow in stszin/stscin allocation size checks
Bound sscanf field width in option parsing
Fix out-of-bounds iq_table read in iquant for -32768
Prevent length_of_rvlc_sf underflow in rvlc_scale_factor_data
Fix out-of-bounds Xsbr write in hf_assembly sinusoid addition
Fix out-of-bounds X underflow in SBR low-power QMF assembly
Fix ssr_gc_function signature mismatch in ssr_gain_control
Fix signed overflow in estimate_current_envelope energy sum
Cap escape length in huffman_spectral_data_2
Prevent num_bits_left underflow in ps_data extension parsing
Fix signed overflow in fixed-point sample rounding before saturation
Add sanity checks on the width in libfaad/specrec.c
Check the last swb_offset value is valid in libfaad/specrec.c
Return early from NeAACDecInit when the object type can't be supported
Fix null pointer dereferences in intra channel and long term prediction
Increase the ASC buffer from 10 to 64 bytes in frontend/mp4read.h
2.11.2
Add option BUILD_FAAD_CLI
Add conditional build with DRC
Use adts_frame for adts header detection
Fix gapless calculation in frontend
Fix write_audio_* function heap buffer overflow
2.11.1
Build shared libraries and hide symbols by default.
Install man page by default.
Check for lrintf() availability, link with -lm and define HAVE_LRINTF accordingly.
Set a default build type if none was specified.
Build DLL name with SOVERSION by default on Windows.
Fix inlined lrintf() function signatures.
2.11.0
Fix incorrect variable initialization
CI/CD, build, etc
setup GitHub workflows; test build under MSVC, OSX, MSYS2, Linux
add CMake build system
additionally add Bazel build
remove automake and MSVC project files
add fuzzers that cover almost all decoder code
setup fuzzing for various builds: (no-)FIXED_POINT / (no-)DRM
remove dead code
address differes compilers warnings
move version to distingished place that different build systems can read
"Safe" bugs
"Safe" means that it is unlikely to be exploited; those affect the decoded
result for (most likely) extreme inputs. Some fixes are useful only for
"FIXED_POINT" build, since it has more restrictions on intermediate values.
"negative range" in estimate_current_envelope
integer overflow in channel downmixing
integer overflow in estimate_envelope
integer overflows caused by "practical infinite" gain
integer overflows in HF adjustment code
several "left shift of negative value"
priming RNG to avoid using values that does not look random at all
do not drop the first frame of output; other decoders don't do this
touching uninitialized values in lt_update_state
touching uninitialized values in bit-reader buffers
"Almost Safe" bugs
"Almost safe" means that those are unlinkly to be exploited; if those surface
depends on build options / environment.
division by zero in HF (noise?) generator and scale factor adjustment
division by zero gen_rand_vector
"Unsafe" bugs
"Unsafe" means that those can cause crash, or could somehow else be exploited.
CLI: accessing unallocated memory in mp4info (corrupted / zero-samples input)
(CVE-2023-38857)
CLI: out-of-bounds when parsing mp4 header
CLI: crash because of wrong mp4 frame offset calculation (CVE-2023-38857)
error handling rvlc_decode_scale_factors (CPU bomb?)
null pointer dereference (in DRM + PS build)
index-out-of-bounds / stack-buffer-overflow in decode_sce_lfe
(for streams with PCE)
stack-buffer-overflow in pns_decode
null pointer derefernce (when channels change their type in the middle
of the stream)
infinite loop on currupted stream
add practial limits for scale factors; otherwise calculated NaN/Inf values
could confuse further logic, resulting in access-out-of-bounds
check sf_index in window_grouping_info to avoid access-out-of-bounds
clamp bs_pointer values to avoid access-out-of-bounds
infinite loop in fill_element
sanitize input values in ps_mix_phase to avoid access-out-of-bounds
fix internal decoder buffer size calculation to avoid heap-out-of-bounds
calculate channel length multiplier even if main channel is already allocated
to avoid heap-out-of-bounds
reserve enough slots for channels in decode_sce_lfe
to avoid heap-out-of-bounds
Fuzzing integration with oss-fuzz
Add define option to disable SBR/PS support
Fix coefficient table selection in tns_decode_coef
2.10.1
Reject buffers of zero size.
Fix 7.1 with PCE mapping.
Have proper version string in faad.h.
Add conditional build with DRC.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
commit d59a33eb2f13e98d942de5c888f4cb255c6dca66
Author: Michael Tremer <michael.tremer@ipfire.org>
Date: Wed Sep 16 08:17:52 2026 +0000
core205: Ship suricata
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
commit 2fdcb5d42fd102c04cd4f8f50310fbe2e0b835ac
Author: Matthias Fischer <matthias.fischer@ipfire.org>
Date: Tue Sep 15 18:04:29 2026 +0200
suricata: Update to 8.0.7
For details see:
https://redmine.openinfosecfoundation.org/versions/236
Excerpt from changelog:
"8.0.7 -- 2026-09-13
Security #9002: lua/hashlib: use after free when using gc (8.0.x backport)
Security #8881: lua/hashlib: null dereference attempting to use hash after finalize call (8.0.x backport)
Security #8801: ike: memory exhaustion from unbounded recursion (8.0.x backport)
Security #8982: dnp3: link-layer events before first transaction are dropped (8.0.x backport)
Security #8938: dhcp: detection bypass parsing DHCP Pad option (code 0) (8.0.x backport)
Security #8922: detect/inspect: infinite loop with too large response-body-limit and stream.reassembly.depth (8.0.x backport)
Security #8971: pgsql: detection bypass post gap recovery (8.0.x backport)
Security #8870: htp: unbounded memory exhaustion in logging (8.0.x backport)
Security #8769: datasets: buffer overread with too small hashes (8.0.x backport)
Security #8930: detect: heap OOB read on byte_test with nbytes from byte_extract/byte_math (8.0.x backport)
Security #8909: ftp: global memuse counter leak (8.0.x backport)
Security #8986: rdp: detection bypass due to infinite loop in MCS/CS processing T.123 TPKT payload (8.0.x backport)
Security #8947: htp: detection bypass of files due to mishandling of FHCRC field by gzip decompressor (8.0.x backport)
Security #9000: jsonbuilder: exposed endpoints for JSON injection (8.0.x backport)
Security #8981: dnp3: framing errors stop transaction inspection for the flow (8.0.x backport)
Security #8732: rfb: too long strings can cause log flooding (8.0.x backport)
Security #8877: dnp3: DoS via huge fixed-size object structs like G70Vx/G120Vx (8.0.x backport)
Security #8794: ldap: unbounded recursion in ldap-parser crate (8.0.x backport)
Security #8937: tls: detection bypass due to X.509 SubjectAltName count truncation (8.0.x backport)
Security #8921: pcap/log: heap out-of-bounds read with oversized TCP packets (8.0.x backport)
Security #8965: http2: Host-only requests bypass host inspection and inline policy (8.0.x backport)
Security #8810: enip: parser bypass with tcp data splicing (8.0.x backport)
Security #8758: enip: quadratic complexity in parse_cip_reqresp_multiple (8.0.x backport)
Security #8985: swf: excessive memory allocation from attacker controlled traffic (8.0.x backport)
Security #8927: ssl: integer underflow due to miscalculation in SSLv2 CLIENT_HELLO (8.0.x backport)
Security #8906: lua: type mismatch crashes Suricata (8.0.x backport)
Security #8998: defrag: fragments bypass the layer limit and exhaust the worker stack (8.0.x backport)
Security #8946: http2: parser desync on HEADERS frame without END_HEADERS flag (8.0.x backport)
Security #8977: ike: detection bypass in case of invalid major version in header (8.0.x backport)
Security #8677: pgsql: unbounded backend responses (8.0.x backport)
Security #9009: http: brotli compression bomb (8.0.x backport)
Security #8875: defrag/ipv6: detection bypass due to integer overflow (8.0.x backport)
Security #8792: nfs: unbounded read/write data queuing (8.0.x backport)
Security #8933: detect: heap OOB read on byte_test with nbytes from a runtime variable (8.0.x backport)
Security #8920: doh: dns inspection uses the wrong transaction for progress (8.0.x backport)
Security #8963: http2: IPv6 authority truncation bypasses normalized host policy (8.0.x backport)
Security #8984: detect/file: detection bypass with multiple file keywords on a transaction (8.0.x backport)
Security #8808: lua/datasets: heap OOB due to improper string length handling (8.0.x backport)
Security #8756: http2: unbounded dynamic table growith with header size update (8.0.x backport)
Security #8989: pgsql: row_description/consolidated_data_row never reconciled against msg length (8.0.x backport)
Security #8925: lua/flowvar: heap buffer overflow with unverified length (8.0.x backport)
Security #8898: lua/dns: heap buffer overflow due to unbounded Lua stack (8.0.x backport)
Security #8945: flow: ESP SPI omission from flow hash (8.0.x backport)
Security #9005: swf: unlimited decompress-depth leads to detection bypass due to truncated buffer (8.0.x backport)
Security #8872: smtp: NULL pointer deref on MIME processing if internal file malloc fails (8.0.x backport)
Security #8790: smb1: unbounded read/write data queuing (8.0.x backport)
Security #8932: output: remote DoS with tcp-data/http-body-data in case of file handling errors (8.0.x backport)
Security #8913: detect/tx: heap buffer overflow with post-rule-match prefilter (8.0.x backport)
Security #8957: threshold: decision cache can grow without bound and terminate Suricata (8.0.x backport)
Security #8746: lua/smtp: infinite loop in get_mime_list (8.0.x backport)
Security #8988: ftp: lines following an over-long command or reply in the same stream slice are never parsed (8.0.x backport)
Security #8983: stream: inspection bypass due to erroneous wiping of TCP session flags (8.0.x backport)
Security #8806: lua: sandbox memory limit bypass (8.0.x backport)
Security #8751: nfs: v3 READ attr_follows=0 file-data inspection bypass (8.0.x backport)
Security #8924: nfs: detection bypass due to incorrect handling of SECINFO_NO_NAME (8.0.x backport)
Security #8883: dns: detection bypass at resync post gap (8.0.x backport)
Security #9004: detect/http2: use after free with http.request_header keyword (8.0.x backport)
Security #9013: pgsql: JSON corruption with crafted malicious traffic (8.0.x backport)
Security #8972: pgsql: unbound Copy Responses lead to parser desync (8.0.x backport)
Security #8941: mqtt: memory exhaustion due to unbounded unknown property parsing (8.0.x backport)
Security #8871: detect: abrupt termination if a pcre flowvar capture matches on a packet with no flow (8.0.x backport)
Security #8788: http2: header detection bypass due to wrong padding handling (8.0.x backport)
Security #8931: datasets: bypass of save/state paths sandbox on Windows (8.0.x backport)
Security #8910: ftp: invalid command buffer after long line truncation (8.0.x backport)
Security #8974: detect: DoS due to type confused free upgrading protocols http1 to http2 to doh2 (8.0.x backport)
Security #8950: ldap: detection bypass at resync post gap (8.0.x backport)
Security #8987: ssh: miscalculation due to oversized KEXINIT causes parser desync (8.0.x backport)
Bug #9035: sip: protocol detection incorrectly matches ssdp traffic (8.0.x backport)
Bug #9033: threads: fix pthread attribute leak in TmThreadSpawn (8.0.x backport)
Bug #9024: pgsql: use message type for transaction actions (8.0.x backport)
Bug #9018: output: Double-free of prefix/sensor_name in threaded LogFileCtx teardown (8.0.x backport)
Bug #9017: erf/file: ERF PAD and META type records and extension headers are not supported (8.0.x backport)
Bug #9016: erf/file: sets packet length from unvalidated wlen, causing OOB heap read in decoder (8.0.x backport)
Bug #9015: erf/file: Heap buffer overflow in ERF file reader via untrusted rlen field (8.0.x backport)
Bug #9014: util: undefined behavior in fallback memrchr implementation (8.0.x backport)
Bug #9011: detect: NULL deref in alert output when reference keyword uses undefined key (8.0.x backport)
Bug #8996: smtp: rejected BDAT reply leaves parser in data mode (8.0.x backport)
Bug #8976: unwind: OOB write in case of deep call stack (8.0.x backport)
Bug #8955: firewall: action scope not validated when inherited in multi-action rules (8.0.x backport)
Bug #8952: engine-analysis: packet:filter policy is hardcoded to drop:packet (8.0.x backport)
Bug #8942: setting variables with --set leads to segfault (8.0.x backport)
Bug #8936: dhcp: parser never reports malformed options (8.0.x backport)
Bug #8935: dhcp: parser ignores the declared length of time options (8.0.x backport)
Bug #8934: nfs: large attacker-controlled memory allocation parsing NFSv4 LAYOUTGET reply (8.0.x backport)
Bug #8929: reject: DoS by non-Ethernet capture packet in autofp mode due to stale context caching (8.0.x backport)
Bug #8928: smb1: unbounded vector growth in NEGOTIATE dialect list (8.0.x backport)
Bug #8926: tls: use-after-free of JA3 elliptic-curve buffers on malloc failure (8.0.x backport)
Bug #8923: stream: SIGSEGV in SYN queue rotation helper (8.0.x backport)
Bug #8912: frame: incorrect debug assertion triggered (8.0.x backport)
Bug #8911: flow/rate: underflow due to incorrect flushing of the ring (8.0.x backport)
Bug #8902: detect: undefined behavior on OOB rvalue with byte_math (8.0.x backport)
Bug #8901: detect/iponly: detection bypass with ipv6 ranges (8.0.x backport)
Bug #8876: smtp: complete BDAT transactions at LAST (8.0.x backport)
Bug #8869: ippair: Memory leak caused by ippair processing (8.0.x backport)
Bug #8868: expectations: IPPair mutex/reference leak on malloc failure (8.0.x backport)
Bug #8804: dag: Infinite loop in DAG record processing when rlen < dag_record_size (8.0.x backport)
Bug #8796: tls: incorrect looping logic leads to extensions pollution (8.0.x backport)
Bug #8773: defrag: memuse reported incorrectly (8.0.x backport)
Bug #8765: smtp: assertion on DATA reply without owning transaction (8.0.x backport)
Bug #8761: http2: content-encoding are case insensitive (8.0.x backport)
Bug #8730: smtp: trailing quit can create an empty transaction (8.0.x backport)
Bug #8716: smtp: subsequent helo/ehlo should be treated like a rset (8.0.x backport)
Bug #8706: util/file: fix integer overflow in file inspection window comparison (8.0.x backport)
Bug #8705: af-packet: eBPF map location error never printed (8.0.x backport)
Bug #8618: threshold: seed only partially applied in IPv6 hash (8.0.x backport)
Bug #8474: flow: bypass manager checks for initializer instead of actual fn (8.0.x backport)
Bug #8314: firewall: rule language can't accept ARP (8.0.x)
Optimization #8786: mqtt: eve json corruption by crafted traffic (8.0.x backport)
Feature #9019: firewall: allow single packet rule to accept tcp connection (8.0.x backport)
Feature #8904: firewall: support SMTP hook states for firewall rule evaluation (8.0.x backport)
Feature #8879: datasets: add support for subdomain match (8.0.x backport)
Feature #8770: firewall: add default app policy options (8.0.x backport)
Feature #8729: firewall: allow single rule to accept protocol detection in progress and the final protocol (8.0.x backport)
Task #8688: psl: crate should be updated on every release (8.0.x backport)
Documentation #8345: doc: update Rust install instructions (8.0.x backport)"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
commit edf262045f5e55453668038d14394762de0dbe8a
Author: Adolf Belka <adolf.belka@ipfire.org>
Date: Tue Sep 15 11:43:38 2026 +0200
samba: Update to version 4.24.7
- Update from version 4.24.5 to 4.24.7
- Update of rootfiles for all architectures
- Changelog
4.24.7
* BUG 16097: POSIX ACL backend silently discards erros when processing NT
ACLs with non-canonical ordering
* BUG 16225: dns client problems related to EDNS usage
* BUG 15988: Samba internal DNS service doesn't handle switch from UDP to TCP
when packet is larger than 4k
* BUG 15988: Samba internal DNS service doesn't handle switch from UDP to TCP
when packet is larger than 4k
* BUG 16194: autobuild failures need to be reported in a more verbose way
* BUG 16223: DNS scavenging happens even if fAging is FALSE
* BUG 16226: samba-tool dns zoneoptions $DC_SERVER_IP
_msdcs.addom.samba.example.com -P --aging=1 gives
WERR_INTERNAL_DB_ERROR
* BUG 16144: Incorrect behavior on stream create-disposition when prior
handle is closed
* BUG 16082: An inactive node can run recovery resulting in inconsistent
databases
* BUG 16225: dns client problems related to EDNS usage
* BUG 16225: dns client problems related to EDNS usage
4.24.6
* BUG 15978: leases torture test flappy (marked flappy)
* BUG 16065: Memory leak in DRS when replication fails
* BUG 16176: vfs_ceph_snapshots: smbd panics on snapshot access for a share
mounted at the CephFS root ("/")
* BUG 16191: race condition in pthreadpool when forking
* BUG 16065: Memory leak in DRS when replication fails
* BUG 16077: witness test flappy needs to be fixed
* BUG 16093: temporary read of unrelated or non-existing memory in s3 dfs
server
* BUG 16094: source4/dsdb/samdb/cracknames.c doesn't use
ldb_binary_encode_string() consistently
* BUG 16153: dsgetdcname() may not detect an active directory domain if the
netbios domain name is given and nmbd nor the nbt service is
available
* BUG 16199: ndr_{push,pull,print}_{timeval,timespec} encode/decode the value
twice
* BUG 16186: vfs_ceph_new: smbd crashes when mixing proxy and non-proxy
CephFS shares
* BUG 15994: CTDB doesn't send tickle ACKs when taking over a released IP
* BUG 16152: CTDB can run nested elections, in rare circumstances
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
-----------------------------------------------------------------------
Summary of changes:
.../{oldcore/131 => core/205}/filelists/suricata | 0
config/rootfiles/core/205/update.sh | 1 +
config/rootfiles/packages/aarch64/samba | 2 +-
config/rootfiles/packages/faad2 | 6 ++---
config/rootfiles/packages/riscv64/samba | 2 +-
config/rootfiles/packages/x86_64/samba | 2 +-
lfs/cmake | 4 ++--
lfs/faad2 | 26 +++++++++-------------
lfs/samba | 6 ++---
lfs/suricata | 4 ++--
10 files changed, 24 insertions(+), 29 deletions(-)
copy config/rootfiles/{oldcore/131 => core/205}/filelists/suricata (100%)
Difference in files:
diff --git a/config/rootfiles/core/205/filelists/suricata b/config/rootfiles/core/205/filelists/suricata
new file mode 120000
index 000000000..f671f6993
--- /dev/null
+++ b/config/rootfiles/core/205/filelists/suricata
@@ -0,0 +1 @@
+../../../common/suricata
\ No newline at end of file
diff --git a/config/rootfiles/core/205/update.sh b/config/rootfiles/core/205/update.sh
index f297448b2..93593050c 100644
--- a/config/rootfiles/core/205/update.sh
+++ b/config/rootfiles/core/205/update.sh
@@ -66,6 +66,7 @@ gpgconf --kill all
/etc/init.d/openvpn-rw restart
/etc/init.d/openvpn-n2n restart
/etc/init.d/sshd restart
+/etc/init.d/suricata restart
# This update needs a reboot...
touch /var/run/need_reboot
diff --git a/config/rootfiles/packages/aarch64/samba b/config/rootfiles/packages/aarch64/samba
index cda6d85b7..53f1263b1 100644
--- a/config/rootfiles/packages/aarch64/samba
+++ b/config/rootfiles/packages/aarch64/samba
@@ -146,7 +146,7 @@ usr/lib/libndr-standard.so.0
usr/lib/libndr-standard.so.0.0.1
usr/lib/libndr.so
usr/lib/libndr.so.6
-usr/lib/libndr.so.6.0.0
+usr/lib/libndr.so.6.1.0
usr/lib/libnetapi.so
usr/lib/libnetapi.so.1
usr/lib/libnetapi.so.1.0.0
diff --git a/config/rootfiles/packages/faad2 b/config/rootfiles/packages/faad2
index aa1d8a347..0264b6398 100644
--- a/config/rootfiles/packages/faad2
+++ b/config/rootfiles/packages/faad2
@@ -1,13 +1,11 @@
usr/bin/faad
#usr/include/faad.h
#usr/include/neaacdec.h
-#usr/lib/libfaad.la
usr/lib/libfaad.so
usr/lib/libfaad.so.2
-usr/lib/libfaad.so.2.0.0
-#usr/lib/libfaad_drm.la
+usr/lib/libfaad.so.2.11.3
usr/lib/libfaad_drm.so
usr/lib/libfaad_drm.so.2
-usr/lib/libfaad_drm.so.2.0.0
+usr/lib/libfaad_drm.so.2.11.3
#usr/lib/pkgconfig/faad2.pc
#usr/share/man/man1/faad.1
diff --git a/config/rootfiles/packages/riscv64/samba b/config/rootfiles/packages/riscv64/samba
index e98e473cd..8fe9cdeff 100644
--- a/config/rootfiles/packages/riscv64/samba
+++ b/config/rootfiles/packages/riscv64/samba
@@ -146,7 +146,7 @@ usr/lib/libndr-standard.so.0
usr/lib/libndr-standard.so.0.0.1
usr/lib/libndr.so
usr/lib/libndr.so.6
-usr/lib/libndr.so.6.0.0
+usr/lib/libndr.so.6.1.0
usr/lib/libnetapi.so
usr/lib/libnetapi.so.1
usr/lib/libnetapi.so.1.0.0
diff --git a/config/rootfiles/packages/x86_64/samba b/config/rootfiles/packages/x86_64/samba
index 0823fe881..31677eb84 100644
--- a/config/rootfiles/packages/x86_64/samba
+++ b/config/rootfiles/packages/x86_64/samba
@@ -146,7 +146,7 @@ usr/lib/libndr-standard.so.0
usr/lib/libndr-standard.so.0.0.1
usr/lib/libndr.so
usr/lib/libndr.so.6
-usr/lib/libndr.so.6.0.0
+usr/lib/libndr.so.6.1.0
usr/lib/libnetapi.so
usr/lib/libnetapi.so.1
usr/lib/libnetapi.so.1.0.0
diff --git a/lfs/cmake b/lfs/cmake
index 3f10b5ac2..fa7a71dcc 100644
--- a/lfs/cmake
+++ b/lfs/cmake
@@ -24,7 +24,7 @@
include Config
-VER = 4.4.1
+VER = 4.4.3
THISAPP = cmake-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -42,7 +42,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = caa1043626e4c0b1898cac198fb643efdf417ad8b471a46256c39fbe07a39666b8f95853e0ef8413d58af4ca400555774f8a7c6e2ccd250ea6f4937fe9874688
+$(DL_FILE)_BLAKE2 = d30fc821adf3a8ba1dd2b64a62a4245ab0a4f97fc2295db8abfae3cffec566a7eee621fd722c5041df44b0bd767051c78b2f0898dec92c65ed3cf66ad9a59506
install : $(TARGET)
diff --git a/lfs/faad2 b/lfs/faad2
index 5a5218a7c..ec8a344d3 100644
--- a/lfs/faad2
+++ b/lfs/faad2
@@ -1,7 +1,7 @@
###############################################################################
# #
# IPFire.org - A linux based firewall #
-# Copyright (C) 2007-2020 IPFire Team <info@ipfire.org> #
+# Copyright (C) 2007-2026 IPFire Team <info@ipfire.org> #
# #
# This program is free software: you can redistribute it and/or modify #
# it under the terms of the GNU General Public License as published by #
@@ -26,7 +26,7 @@ include Config
SUMMARY = C library and frontend for decoding MPEG2/4 AAC
-VER = 2_10_0
+VER = 2.11.3
THISAPP = faad2-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE)
DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = faad2
-PAK_VER = 3
+PAK_VER = 4
DEPS =
@@ -48,7 +48,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 73ecbcbb3fce93e8ceb88f6f7669bb681d2329935018cc2a23929cf6672959a0678b47c830cfdcf8e716709ce5252a02178737a7af09de373f7c8b54f38f3d9d
+$(DL_FILE)_BLAKE2 = da9f96c30653e5bfa41eb0c01b04128cb1a070d8fd46ac0a297cbfddef9d0f895f8f26e525521d7093949dc4f96b66b401d39b318192cfc3127c48e1f307e202
install : $(TARGET)
@@ -82,16 +82,12 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
@$(PREBUILD)
@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE)
$(UPDATE_AUTOMAKE)
-
- cd $(DIR_APP) && autoupdate
- cd $(DIR_APP) && autoreconf -fvi
- cd $(DIR_APP) && ./configure \
- --prefix=/usr \
- --enable-shared \
- --disable-static \
- --with-mpeg4ip
-
- cd $(DIR_APP) && make $(MAKETUNING)
- cd $(DIR_APP) && make install
+ cd $(DIR_APP) && mkdir build
+ cd $(DIR_APP)/build && cmake .. \
+ -D CMAKE_INSTALL_PREFIX=/usr \
+ -D CMAKE_BUILD_TYPE=Release \
+ -D BUILD_SHARED_LIBS=on
+ cd $(DIR_APP)/build && make $(MAKETUNING)
+ cd $(DIR_APP)/build && make install
@rm -rf $(DIR_APP)
@$(POSTBUILD)
diff --git a/lfs/samba b/lfs/samba
index c21e8bbc0..c5220fc11 100644
--- a/lfs/samba
+++ b/lfs/samba
@@ -24,7 +24,7 @@
include Config
-VER = 4.24.5
+VER = 4.24.7
SUMMARY = A SMB/CIFS File, Print, and Authentication Server
THISAPP = samba-$(VER)
@@ -33,7 +33,7 @@ DL_FROM = $(URL_IPFIRE)
DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = samba
-PAK_VER = 123
+PAK_VER = 124
DEPS = avahi libtalloc perl-Parse-Yapp wsdd
@@ -47,7 +47,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 4796e3ae5e70c1d11d9326566677f0909423c5aad140309bfd9b3f8a3dedefe49660d0a0d502a681726ed7a961779587c33c9da29ecf69664b00a2ca958e64af
+$(DL_FILE)_BLAKE2 = 79f5093db219798081eddadf1c81c0337d97563bbd3f9047f14538c557c61b6d58dd57d97bde957a7d84f61f1fbe547cd85a4f6f1e4bff6fe4b86d0772223501
install : $(TARGET)
diff --git a/lfs/suricata b/lfs/suricata
index 018209bac..d671d8596 100644
--- a/lfs/suricata
+++ b/lfs/suricata
@@ -24,7 +24,7 @@
include Config
-VER = 8.0.6
+VER = 8.0.7
THISAPP = suricata-$(VER)
DL_FILE = $(THISAPP).tar.gz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 37ceed6b6ac608df628bda315f2e864d82424b66d6e8e64e1b7cebcb306fe90679b0ca2a19f0be98274aaade5d0c6986619182c56a353b93d71bce9d58892f19
+$(DL_FILE)_BLAKE2 = eb6bda943779f0353a74aa8d783c037f3f08ab311a679962b0742df57c37e2d926a37002085dbff3463212f708f9baf128c4dc15905a0a42458c8a69bcea9e30
install : $(TARGET)
hooks/post-receive
--
IPFire 2.x development tree
reply other threads:[~2026-09-16 8:19 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4hlBdK00Psz2xKM@people01.haj.ipfire.org \
--to=git@ipfire.org \
--cc=ipfire-scm@lists.ipfire.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox