From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hlBdL62W2z2xWm for ; Wed, 16 Sep 2026 08:19:50 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hlBdL5hJjz2xMD for ; Wed, 16 Sep 2026 08:19:50 +0000 (UTC) Received: from people01.haj.ipfire.org (people01.haj.ipfire.org [172.28.1.161]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bit raw public key) server-digest SHA256 client-signature ECDSA (secp384r1) client-digest SHA384) (Client CN "people01.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hlBdK31BQzFB for ; Wed, 16 Sep 2026 08:19:49 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1789546789; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc; bh=MxF8QmSxPGoRDCxdeIfC5oiK+oZXYZKSp1BUzMt5GR4=; b=5SFXioetrxfKzaMu5m5A9gq+lTMGMHzzam9ImbbjzVsI8YeSBsN1X5zBkQ4V3Hgng+GWta Pjq4FMpx2aLLPUAQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1789546789; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc; bh=MxF8QmSxPGoRDCxdeIfC5oiK+oZXYZKSp1BUzMt5GR4=; b=j23NPyoy8G+02pbVxQ4ZDTXWAVOvUqyuHmY5eoC++3r7lQE2Fg/zua5fVk7DU2OtgJfWbF IcL6zfR4REFUE4sM0GkzoaFc5arH+JvPkrtC3jg9HymPToXs3WXzPk0PZzZrXre8EyMmpC k4QFgZAOCywZYqxmOTcQ2B7keyO9N8n0JEo64p5WBRwzhc1rfHfDiCllkR9zzGrjvwR7p9 Tv/0rSGm1sXpJH/LCk63w/GI2B3glrvmyLTtyjtfAj5CoJCypx4K21T2dXkYS+UnfM7tOB GBK6u9tcYHCKso0ENiBzCOmsmoG4qIl9L/vLk4xoAwF7rNzG5IL+cSenwNRSeA== Received: by people01.haj.ipfire.org (Postfix, from userid 1000) id 4hlBdK00Psz2xKM; Wed, 16 Sep 2026 08:19:48 +0000 (UTC) To: ipfire-scm@lists.ipfire.org Subject: [git.ipfire.org] IPFire 2.x development tree branch, next, updated. 2420194ec36844538fe88068e28128d2711a9843 X-Git-Refname: refs/heads/next X-Git-Reftype: branch X-Git-Oldrev: 1b662c4d4c70ffecc728466a5cdfa5fd990f56ea X-Git-Newrev: 2420194ec36844538fe88068e28128d2711a9843 Message-Id: <4hlBdK00Psz2xKM@people01.haj.ipfire.org> Date: Wed, 16 Sep 2026 08:19:48 +0000 (UTC) From: Michael Tremer Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: This is an automated email from the git hooks/post-receive script. It was generated because a ref change was pushed to the repository containing the project "IPFire 2.x development tree". The branch, next has been updated via 2420194ec36844538fe88068e28128d2711a9843 (commit) via f26ef5bc5d1031a8aa2a13b9efbf88e593417b90 (commit) via d59a33eb2f13e98d942de5c888f4cb255c6dca66 (commit) via 2fdcb5d42fd102c04cd4f8f50310fbe2e0b835ac (commit) via edf262045f5e55453668038d14394762de0dbe8a (commit) from 1b662c4d4c70ffecc728466a5cdfa5fd990f56ea (commit) Those revisions listed above that are new to this repository have not appeared on any other notification email; so we list those revisions in full, below. - Log ----------------------------------------------------------------- commit 2420194ec36844538fe88068e28128d2711a9843 Author: Adolf Belka Date: Tue Sep 15 21:06:01 2026 +0200 cmake: Update to version 4.4.3 - Update from version 4.4.1 to 4.4.3 - No change in rootfile - Required for latest faad2 build - Changelog 4.4.3 * Swift policy :policy:`CMP0215`'s ``NEW`` behavior has been updated to require policies :policy:`CMP0157` and :policy:`CMP0195` to also be set to ``NEW``. 4.4.2 * This version made no changes to documented features or interfaces. Some implementation updates were made to support ecosystem changes and/or fix regressions. Signed-off-by: Adolf Belka Signed-off-by: Michael Tremer commit f26ef5bc5d1031a8aa2a13b9efbf88e593417b90 Author: Adolf Belka Date: Tue Sep 15 21:06:00 2026 +0200 faad2: Update to version 2.11.3 - Update from version 2_10_0 (2020) to 2.11.3 (2026) - Update of rootfile - In version 2.11.0 (2023) unmaintained code was removed from faad2. This included all the plugins, and therefore removed the mpegip4 plugin. - The autotools build was removed in 2.11.0 and cmake and bazel build systems added. - build changed from autotools to cmake - faad2-2.11.3 required cmake-4.4.3 for the build - 2 CVE fixes in 2.11.0 - 2.11.0 had a range of bug fixes which faad2 devlopers categorised as "Safe" bugs, "Almost Safe" bugs & "Unsafe" bugs. The 2 CVE's are in the "Unsafe" bugs but there are 15 additional bug fixes in that category that have not had CVE numbers assigned - Changelog 2.11.3 Fix ISO C warning in libfaad/fixed.h Check for mp4config.frame.nsclices == 0 in frontend/mp4read.c to fix Heap Buffer Overflow SBR: prevent heap overflow in channel-pair reconstruction Fix off-by-one frame index check in mp4read_seek Fix integer overflow in stszin/stscin allocation size checks Bound sscanf field width in option parsing Fix out-of-bounds iq_table read in iquant for -32768 Prevent length_of_rvlc_sf underflow in rvlc_scale_factor_data Fix out-of-bounds Xsbr write in hf_assembly sinusoid addition Fix out-of-bounds X underflow in SBR low-power QMF assembly Fix ssr_gc_function signature mismatch in ssr_gain_control Fix signed overflow in estimate_current_envelope energy sum Cap escape length in huffman_spectral_data_2 Prevent num_bits_left underflow in ps_data extension parsing Fix signed overflow in fixed-point sample rounding before saturation Add sanity checks on the width in libfaad/specrec.c Check the last swb_offset value is valid in libfaad/specrec.c Return early from NeAACDecInit when the object type can't be supported Fix null pointer dereferences in intra channel and long term prediction Increase the ASC buffer from 10 to 64 bytes in frontend/mp4read.h 2.11.2 Add option BUILD_FAAD_CLI Add conditional build with DRC Use adts_frame for adts header detection Fix gapless calculation in frontend Fix write_audio_* function heap buffer overflow 2.11.1 Build shared libraries and hide symbols by default. Install man page by default. Check for lrintf() availability, link with -lm and define HAVE_LRINTF accordingly. Set a default build type if none was specified. Build DLL name with SOVERSION by default on Windows. Fix inlined lrintf() function signatures. 2.11.0 Fix incorrect variable initialization CI/CD, build, etc setup GitHub workflows; test build under MSVC, OSX, MSYS2, Linux add CMake build system additionally add Bazel build remove automake and MSVC project files add fuzzers that cover almost all decoder code setup fuzzing for various builds: (no-)FIXED_POINT / (no-)DRM remove dead code address differes compilers warnings move version to distingished place that different build systems can read "Safe" bugs "Safe" means that it is unlikely to be exploited; those affect the decoded result for (most likely) extreme inputs. Some fixes are useful only for "FIXED_POINT" build, since it has more restrictions on intermediate values. "negative range" in estimate_current_envelope integer overflow in channel downmixing integer overflow in estimate_envelope integer overflows caused by "practical infinite" gain integer overflows in HF adjustment code several "left shift of negative value" priming RNG to avoid using values that does not look random at all do not drop the first frame of output; other decoders don't do this touching uninitialized values in lt_update_state touching uninitialized values in bit-reader buffers "Almost Safe" bugs "Almost safe" means that those are unlinkly to be exploited; if those surface depends on build options / environment. division by zero in HF (noise?) generator and scale factor adjustment division by zero gen_rand_vector "Unsafe" bugs "Unsafe" means that those can cause crash, or could somehow else be exploited. CLI: accessing unallocated memory in mp4info (corrupted / zero-samples input) (CVE-2023-38857) CLI: out-of-bounds when parsing mp4 header CLI: crash because of wrong mp4 frame offset calculation (CVE-2023-38857) error handling rvlc_decode_scale_factors (CPU bomb?) null pointer dereference (in DRM + PS build) index-out-of-bounds / stack-buffer-overflow in decode_sce_lfe (for streams with PCE) stack-buffer-overflow in pns_decode null pointer derefernce (when channels change their type in the middle of the stream) infinite loop on currupted stream add practial limits for scale factors; otherwise calculated NaN/Inf values could confuse further logic, resulting in access-out-of-bounds check sf_index in window_grouping_info to avoid access-out-of-bounds clamp bs_pointer values to avoid access-out-of-bounds infinite loop in fill_element sanitize input values in ps_mix_phase to avoid access-out-of-bounds fix internal decoder buffer size calculation to avoid heap-out-of-bounds calculate channel length multiplier even if main channel is already allocated to avoid heap-out-of-bounds reserve enough slots for channels in decode_sce_lfe to avoid heap-out-of-bounds Fuzzing integration with oss-fuzz Add define option to disable SBR/PS support Fix coefficient table selection in tns_decode_coef 2.10.1 Reject buffers of zero size. Fix 7.1 with PCE mapping. Have proper version string in faad.h. Add conditional build with DRC. Signed-off-by: Adolf Belka Signed-off-by: Michael Tremer commit d59a33eb2f13e98d942de5c888f4cb255c6dca66 Author: Michael Tremer Date: Wed Sep 16 08:17:52 2026 +0000 core205: Ship suricata Signed-off-by: Michael Tremer commit 2fdcb5d42fd102c04cd4f8f50310fbe2e0b835ac Author: Matthias Fischer Date: Tue Sep 15 18:04:29 2026 +0200 suricata: Update to 8.0.7 For details see: https://redmine.openinfosecfoundation.org/versions/236 Excerpt from changelog: "8.0.7 -- 2026-09-13 Security #9002: lua/hashlib: use after free when using gc (8.0.x backport) Security #8881: lua/hashlib: null dereference attempting to use hash after finalize call (8.0.x backport) Security #8801: ike: memory exhaustion from unbounded recursion (8.0.x backport) Security #8982: dnp3: link-layer events before first transaction are dropped (8.0.x backport) Security #8938: dhcp: detection bypass parsing DHCP Pad option (code 0) (8.0.x backport) Security #8922: detect/inspect: infinite loop with too large response-body-limit and stream.reassembly.depth (8.0.x backport) Security #8971: pgsql: detection bypass post gap recovery (8.0.x backport) Security #8870: htp: unbounded memory exhaustion in logging (8.0.x backport) Security #8769: datasets: buffer overread with too small hashes (8.0.x backport) Security #8930: detect: heap OOB read on byte_test with nbytes from byte_extract/byte_math (8.0.x backport) Security #8909: ftp: global memuse counter leak (8.0.x backport) Security #8986: rdp: detection bypass due to infinite loop in MCS/CS processing T.123 TPKT payload (8.0.x backport) Security #8947: htp: detection bypass of files due to mishandling of FHCRC field by gzip decompressor (8.0.x backport) Security #9000: jsonbuilder: exposed endpoints for JSON injection (8.0.x backport) Security #8981: dnp3: framing errors stop transaction inspection for the flow (8.0.x backport) Security #8732: rfb: too long strings can cause log flooding (8.0.x backport) Security #8877: dnp3: DoS via huge fixed-size object structs like G70Vx/G120Vx (8.0.x backport) Security #8794: ldap: unbounded recursion in ldap-parser crate (8.0.x backport) Security #8937: tls: detection bypass due to X.509 SubjectAltName count truncation (8.0.x backport) Security #8921: pcap/log: heap out-of-bounds read with oversized TCP packets (8.0.x backport) Security #8965: http2: Host-only requests bypass host inspection and inline policy (8.0.x backport) Security #8810: enip: parser bypass with tcp data splicing (8.0.x backport) Security #8758: enip: quadratic complexity in parse_cip_reqresp_multiple (8.0.x backport) Security #8985: swf: excessive memory allocation from attacker controlled traffic (8.0.x backport) Security #8927: ssl: integer underflow due to miscalculation in SSLv2 CLIENT_HELLO (8.0.x backport) Security #8906: lua: type mismatch crashes Suricata (8.0.x backport) Security #8998: defrag: fragments bypass the layer limit and exhaust the worker stack (8.0.x backport) Security #8946: http2: parser desync on HEADERS frame without END_HEADERS flag (8.0.x backport) Security #8977: ike: detection bypass in case of invalid major version in header (8.0.x backport) Security #8677: pgsql: unbounded backend responses (8.0.x backport) Security #9009: http: brotli compression bomb (8.0.x backport) Security #8875: defrag/ipv6: detection bypass due to integer overflow (8.0.x backport) Security #8792: nfs: unbounded read/write data queuing (8.0.x backport) Security #8933: detect: heap OOB read on byte_test with nbytes from a runtime variable (8.0.x backport) Security #8920: doh: dns inspection uses the wrong transaction for progress (8.0.x backport) Security #8963: http2: IPv6 authority truncation bypasses normalized host policy (8.0.x backport) Security #8984: detect/file: detection bypass with multiple file keywords on a transaction (8.0.x backport) Security #8808: lua/datasets: heap OOB due to improper string length handling (8.0.x backport) Security #8756: http2: unbounded dynamic table growith with header size update (8.0.x backport) Security #8989: pgsql: row_description/consolidated_data_row never reconciled against msg length (8.0.x backport) Security #8925: lua/flowvar: heap buffer overflow with unverified length (8.0.x backport) Security #8898: lua/dns: heap buffer overflow due to unbounded Lua stack (8.0.x backport) Security #8945: flow: ESP SPI omission from flow hash (8.0.x backport) Security #9005: swf: unlimited decompress-depth leads to detection bypass due to truncated buffer (8.0.x backport) Security #8872: smtp: NULL pointer deref on MIME processing if internal file malloc fails (8.0.x backport) Security #8790: smb1: unbounded read/write data queuing (8.0.x backport) Security #8932: output: remote DoS with tcp-data/http-body-data in case of file handling errors (8.0.x backport) Security #8913: detect/tx: heap buffer overflow with post-rule-match prefilter (8.0.x backport) Security #8957: threshold: decision cache can grow without bound and terminate Suricata (8.0.x backport) Security #8746: lua/smtp: infinite loop in get_mime_list (8.0.x backport) Security #8988: ftp: lines following an over-long command or reply in the same stream slice are never parsed (8.0.x backport) Security #8983: stream: inspection bypass due to erroneous wiping of TCP session flags (8.0.x backport) Security #8806: lua: sandbox memory limit bypass (8.0.x backport) Security #8751: nfs: v3 READ attr_follows=0 file-data inspection bypass (8.0.x backport) Security #8924: nfs: detection bypass due to incorrect handling of SECINFO_NO_NAME (8.0.x backport) Security #8883: dns: detection bypass at resync post gap (8.0.x backport) Security #9004: detect/http2: use after free with http.request_header keyword (8.0.x backport) Security #9013: pgsql: JSON corruption with crafted malicious traffic (8.0.x backport) Security #8972: pgsql: unbound Copy Responses lead to parser desync (8.0.x backport) Security #8941: mqtt: memory exhaustion due to unbounded unknown property parsing (8.0.x backport) Security #8871: detect: abrupt termination if a pcre flowvar capture matches on a packet with no flow (8.0.x backport) Security #8788: http2: header detection bypass due to wrong padding handling (8.0.x backport) Security #8931: datasets: bypass of save/state paths sandbox on Windows (8.0.x backport) Security #8910: ftp: invalid command buffer after long line truncation (8.0.x backport) Security #8974: detect: DoS due to type confused free upgrading protocols http1 to http2 to doh2 (8.0.x backport) Security #8950: ldap: detection bypass at resync post gap (8.0.x backport) Security #8987: ssh: miscalculation due to oversized KEXINIT causes parser desync (8.0.x backport) Bug #9035: sip: protocol detection incorrectly matches ssdp traffic (8.0.x backport) Bug #9033: threads: fix pthread attribute leak in TmThreadSpawn (8.0.x backport) Bug #9024: pgsql: use message type for transaction actions (8.0.x backport) Bug #9018: output: Double-free of prefix/sensor_name in threaded LogFileCtx teardown (8.0.x backport) Bug #9017: erf/file: ERF PAD and META type records and extension headers are not supported (8.0.x backport) Bug #9016: erf/file: sets packet length from unvalidated wlen, causing OOB heap read in decoder (8.0.x backport) Bug #9015: erf/file: Heap buffer overflow in ERF file reader via untrusted rlen field (8.0.x backport) Bug #9014: util: undefined behavior in fallback memrchr implementation (8.0.x backport) Bug #9011: detect: NULL deref in alert output when reference keyword uses undefined key (8.0.x backport) Bug #8996: smtp: rejected BDAT reply leaves parser in data mode (8.0.x backport) Bug #8976: unwind: OOB write in case of deep call stack (8.0.x backport) Bug #8955: firewall: action scope not validated when inherited in multi-action rules (8.0.x backport) Bug #8952: engine-analysis: packet:filter policy is hardcoded to drop:packet (8.0.x backport) Bug #8942: setting variables with --set leads to segfault (8.0.x backport) Bug #8936: dhcp: parser never reports malformed options (8.0.x backport) Bug #8935: dhcp: parser ignores the declared length of time options (8.0.x backport) Bug #8934: nfs: large attacker-controlled memory allocation parsing NFSv4 LAYOUTGET reply (8.0.x backport) Bug #8929: reject: DoS by non-Ethernet capture packet in autofp mode due to stale context caching (8.0.x backport) Bug #8928: smb1: unbounded vector growth in NEGOTIATE dialect list (8.0.x backport) Bug #8926: tls: use-after-free of JA3 elliptic-curve buffers on malloc failure (8.0.x backport) Bug #8923: stream: SIGSEGV in SYN queue rotation helper (8.0.x backport) Bug #8912: frame: incorrect debug assertion triggered (8.0.x backport) Bug #8911: flow/rate: underflow due to incorrect flushing of the ring (8.0.x backport) Bug #8902: detect: undefined behavior on OOB rvalue with byte_math (8.0.x backport) Bug #8901: detect/iponly: detection bypass with ipv6 ranges (8.0.x backport) Bug #8876: smtp: complete BDAT transactions at LAST (8.0.x backport) Bug #8869: ippair: Memory leak caused by ippair processing (8.0.x backport) Bug #8868: expectations: IPPair mutex/reference leak on malloc failure (8.0.x backport) Bug #8804: dag: Infinite loop in DAG record processing when rlen < dag_record_size (8.0.x backport) Bug #8796: tls: incorrect looping logic leads to extensions pollution (8.0.x backport) Bug #8773: defrag: memuse reported incorrectly (8.0.x backport) Bug #8765: smtp: assertion on DATA reply without owning transaction (8.0.x backport) Bug #8761: http2: content-encoding are case insensitive (8.0.x backport) Bug #8730: smtp: trailing quit can create an empty transaction (8.0.x backport) Bug #8716: smtp: subsequent helo/ehlo should be treated like a rset (8.0.x backport) Bug #8706: util/file: fix integer overflow in file inspection window comparison (8.0.x backport) Bug #8705: af-packet: eBPF map location error never printed (8.0.x backport) Bug #8618: threshold: seed only partially applied in IPv6 hash (8.0.x backport) Bug #8474: flow: bypass manager checks for initializer instead of actual fn (8.0.x backport) Bug #8314: firewall: rule language can't accept ARP (8.0.x) Optimization #8786: mqtt: eve json corruption by crafted traffic (8.0.x backport) Feature #9019: firewall: allow single packet rule to accept tcp connection (8.0.x backport) Feature #8904: firewall: support SMTP hook states for firewall rule evaluation (8.0.x backport) Feature #8879: datasets: add support for subdomain match (8.0.x backport) Feature #8770: firewall: add default app policy options (8.0.x backport) Feature #8729: firewall: allow single rule to accept protocol detection in progress and the final protocol (8.0.x backport) Task #8688: psl: crate should be updated on every release (8.0.x backport) Documentation #8345: doc: update Rust install instructions (8.0.x backport)" Signed-off-by: Matthias Fischer Signed-off-by: Michael Tremer commit edf262045f5e55453668038d14394762de0dbe8a Author: Adolf Belka Date: Tue Sep 15 11:43:38 2026 +0200 samba: Update to version 4.24.7 - Update from version 4.24.5 to 4.24.7 - Update of rootfiles for all architectures - Changelog 4.24.7 * BUG 16097: POSIX ACL backend silently discards erros when processing NT ACLs with non-canonical ordering * BUG 16225: dns client problems related to EDNS usage * BUG 15988: Samba internal DNS service doesn't handle switch from UDP to TCP when packet is larger than 4k * BUG 15988: Samba internal DNS service doesn't handle switch from UDP to TCP when packet is larger than 4k * BUG 16194: autobuild failures need to be reported in a more verbose way * BUG 16223: DNS scavenging happens even if fAging is FALSE * BUG 16226: samba-tool dns zoneoptions $DC_SERVER_IP _msdcs.addom.samba.example.com -P --aging=1 gives WERR_INTERNAL_DB_ERROR * BUG 16144: Incorrect behavior on stream create-disposition when prior handle is closed * BUG 16082: An inactive node can run recovery resulting in inconsistent databases * BUG 16225: dns client problems related to EDNS usage * BUG 16225: dns client problems related to EDNS usage 4.24.6 * BUG 15978: leases torture test flappy (marked flappy) * BUG 16065: Memory leak in DRS when replication fails * BUG 16176: vfs_ceph_snapshots: smbd panics on snapshot access for a share mounted at the CephFS root ("/") * BUG 16191: race condition in pthreadpool when forking * BUG 16065: Memory leak in DRS when replication fails * BUG 16077: witness test flappy needs to be fixed * BUG 16093: temporary read of unrelated or non-existing memory in s3 dfs server * BUG 16094: source4/dsdb/samdb/cracknames.c doesn't use ldb_binary_encode_string() consistently * BUG 16153: dsgetdcname() may not detect an active directory domain if the netbios domain name is given and nmbd nor the nbt service is available * BUG 16199: ndr_{push,pull,print}_{timeval,timespec} encode/decode the value twice * BUG 16186: vfs_ceph_new: smbd crashes when mixing proxy and non-proxy CephFS shares * BUG 15994: CTDB doesn't send tickle ACKs when taking over a released IP * BUG 16152: CTDB can run nested elections, in rare circumstances Signed-off-by: Adolf Belka Signed-off-by: Michael Tremer ----------------------------------------------------------------------- Summary of changes: .../{oldcore/131 => core/205}/filelists/suricata | 0 config/rootfiles/core/205/update.sh | 1 + config/rootfiles/packages/aarch64/samba | 2 +- config/rootfiles/packages/faad2 | 6 ++--- config/rootfiles/packages/riscv64/samba | 2 +- config/rootfiles/packages/x86_64/samba | 2 +- lfs/cmake | 4 ++-- lfs/faad2 | 26 +++++++++------------- lfs/samba | 6 ++--- lfs/suricata | 4 ++-- 10 files changed, 24 insertions(+), 29 deletions(-) copy config/rootfiles/{oldcore/131 => core/205}/filelists/suricata (100%) Difference in files: diff --git a/config/rootfiles/core/205/filelists/suricata b/config/rootfiles/core/205/filelists/suricata new file mode 120000 index 000000000..f671f6993 --- /dev/null +++ b/config/rootfiles/core/205/filelists/suricata @@ -0,0 +1 @@ +../../../common/suricata \ No newline at end of file diff --git a/config/rootfiles/core/205/update.sh b/config/rootfiles/core/205/update.sh index f297448b2..93593050c 100644 --- a/config/rootfiles/core/205/update.sh +++ b/config/rootfiles/core/205/update.sh @@ -66,6 +66,7 @@ gpgconf --kill all /etc/init.d/openvpn-rw restart /etc/init.d/openvpn-n2n restart /etc/init.d/sshd restart +/etc/init.d/suricata restart # This update needs a reboot... touch /var/run/need_reboot diff --git a/config/rootfiles/packages/aarch64/samba b/config/rootfiles/packages/aarch64/samba index cda6d85b7..53f1263b1 100644 --- a/config/rootfiles/packages/aarch64/samba +++ b/config/rootfiles/packages/aarch64/samba @@ -146,7 +146,7 @@ usr/lib/libndr-standard.so.0 usr/lib/libndr-standard.so.0.0.1 usr/lib/libndr.so usr/lib/libndr.so.6 -usr/lib/libndr.so.6.0.0 +usr/lib/libndr.so.6.1.0 usr/lib/libnetapi.so usr/lib/libnetapi.so.1 usr/lib/libnetapi.so.1.0.0 diff --git a/config/rootfiles/packages/faad2 b/config/rootfiles/packages/faad2 index aa1d8a347..0264b6398 100644 --- a/config/rootfiles/packages/faad2 +++ b/config/rootfiles/packages/faad2 @@ -1,13 +1,11 @@ usr/bin/faad #usr/include/faad.h #usr/include/neaacdec.h -#usr/lib/libfaad.la usr/lib/libfaad.so usr/lib/libfaad.so.2 -usr/lib/libfaad.so.2.0.0 -#usr/lib/libfaad_drm.la +usr/lib/libfaad.so.2.11.3 usr/lib/libfaad_drm.so usr/lib/libfaad_drm.so.2 -usr/lib/libfaad_drm.so.2.0.0 +usr/lib/libfaad_drm.so.2.11.3 #usr/lib/pkgconfig/faad2.pc #usr/share/man/man1/faad.1 diff --git a/config/rootfiles/packages/riscv64/samba b/config/rootfiles/packages/riscv64/samba index e98e473cd..8fe9cdeff 100644 --- a/config/rootfiles/packages/riscv64/samba +++ b/config/rootfiles/packages/riscv64/samba @@ -146,7 +146,7 @@ usr/lib/libndr-standard.so.0 usr/lib/libndr-standard.so.0.0.1 usr/lib/libndr.so usr/lib/libndr.so.6 -usr/lib/libndr.so.6.0.0 +usr/lib/libndr.so.6.1.0 usr/lib/libnetapi.so usr/lib/libnetapi.so.1 usr/lib/libnetapi.so.1.0.0 diff --git a/config/rootfiles/packages/x86_64/samba b/config/rootfiles/packages/x86_64/samba index 0823fe881..31677eb84 100644 --- a/config/rootfiles/packages/x86_64/samba +++ b/config/rootfiles/packages/x86_64/samba @@ -146,7 +146,7 @@ usr/lib/libndr-standard.so.0 usr/lib/libndr-standard.so.0.0.1 usr/lib/libndr.so usr/lib/libndr.so.6 -usr/lib/libndr.so.6.0.0 +usr/lib/libndr.so.6.1.0 usr/lib/libnetapi.so usr/lib/libnetapi.so.1 usr/lib/libnetapi.so.1.0.0 diff --git a/lfs/cmake b/lfs/cmake index 3f10b5ac2..fa7a71dcc 100644 --- a/lfs/cmake +++ b/lfs/cmake @@ -24,7 +24,7 @@ include Config -VER = 4.4.1 +VER = 4.4.3 THISAPP = cmake-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -42,7 +42,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = caa1043626e4c0b1898cac198fb643efdf417ad8b471a46256c39fbe07a39666b8f95853e0ef8413d58af4ca400555774f8a7c6e2ccd250ea6f4937fe9874688 +$(DL_FILE)_BLAKE2 = d30fc821adf3a8ba1dd2b64a62a4245ab0a4f97fc2295db8abfae3cffec566a7eee621fd722c5041df44b0bd767051c78b2f0898dec92c65ed3cf66ad9a59506 install : $(TARGET) diff --git a/lfs/faad2 b/lfs/faad2 index 5a5218a7c..ec8a344d3 100644 --- a/lfs/faad2 +++ b/lfs/faad2 @@ -1,7 +1,7 @@ ############################################################################### # # # IPFire.org - A linux based firewall # -# Copyright (C) 2007-2020 IPFire Team # +# Copyright (C) 2007-2026 IPFire Team # # # # This program is free software: you can redistribute it and/or modify # # it under the terms of the GNU General Public License as published by # @@ -26,7 +26,7 @@ include Config SUMMARY = C library and frontend for decoding MPEG2/4 AAC -VER = 2_10_0 +VER = 2.11.3 THISAPP = faad2-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = faad2 -PAK_VER = 3 +PAK_VER = 4 DEPS = @@ -48,7 +48,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 73ecbcbb3fce93e8ceb88f6f7669bb681d2329935018cc2a23929cf6672959a0678b47c830cfdcf8e716709ce5252a02178737a7af09de373f7c8b54f38f3d9d +$(DL_FILE)_BLAKE2 = da9f96c30653e5bfa41eb0c01b04128cb1a070d8fd46ac0a297cbfddef9d0f895f8f26e525521d7093949dc4f96b66b401d39b318192cfc3127c48e1f307e202 install : $(TARGET) @@ -82,16 +82,12 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) @$(PREBUILD) @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar zxf $(DIR_DL)/$(DL_FILE) $(UPDATE_AUTOMAKE) - - cd $(DIR_APP) && autoupdate - cd $(DIR_APP) && autoreconf -fvi - cd $(DIR_APP) && ./configure \ - --prefix=/usr \ - --enable-shared \ - --disable-static \ - --with-mpeg4ip - - cd $(DIR_APP) && make $(MAKETUNING) - cd $(DIR_APP) && make install + cd $(DIR_APP) && mkdir build + cd $(DIR_APP)/build && cmake .. \ + -D CMAKE_INSTALL_PREFIX=/usr \ + -D CMAKE_BUILD_TYPE=Release \ + -D BUILD_SHARED_LIBS=on + cd $(DIR_APP)/build && make $(MAKETUNING) + cd $(DIR_APP)/build && make install @rm -rf $(DIR_APP) @$(POSTBUILD) diff --git a/lfs/samba b/lfs/samba index c21e8bbc0..c5220fc11 100644 --- a/lfs/samba +++ b/lfs/samba @@ -24,7 +24,7 @@ include Config -VER = 4.24.5 +VER = 4.24.7 SUMMARY = A SMB/CIFS File, Print, and Authentication Server THISAPP = samba-$(VER) @@ -33,7 +33,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = samba -PAK_VER = 123 +PAK_VER = 124 DEPS = avahi libtalloc perl-Parse-Yapp wsdd @@ -47,7 +47,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 4796e3ae5e70c1d11d9326566677f0909423c5aad140309bfd9b3f8a3dedefe49660d0a0d502a681726ed7a961779587c33c9da29ecf69664b00a2ca958e64af +$(DL_FILE)_BLAKE2 = 79f5093db219798081eddadf1c81c0337d97563bbd3f9047f14538c557c61b6d58dd57d97bde957a7d84f61f1fbe547cd85a4f6f1e4bff6fe4b86d0772223501 install : $(TARGET) diff --git a/lfs/suricata b/lfs/suricata index 018209bac..d671d8596 100644 --- a/lfs/suricata +++ b/lfs/suricata @@ -24,7 +24,7 @@ include Config -VER = 8.0.6 +VER = 8.0.7 THISAPP = suricata-$(VER) DL_FILE = $(THISAPP).tar.gz @@ -40,7 +40,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 37ceed6b6ac608df628bda315f2e864d82424b66d6e8e64e1b7cebcb306fe90679b0ca2a19f0be98274aaade5d0c6986619182c56a353b93d71bce9d58892f19 +$(DL_FILE)_BLAKE2 = eb6bda943779f0353a74aa8d783c037f3f08ab311a679962b0742df57c37e2d926a37002085dbff3463212f708f9baf128c4dc15905a0a42458c8a69bcea9e30 install : $(TARGET) hooks/post-receive -- IPFire 2.x development tree