Commit Graph

11150 Commits

Author SHA1 Message Date
Fabrice Fontaine
ee71f6bfdb net/openssh: fix PKG_CPE_ID
openbsd:openssh is a better CPE ID than openssh:openssh as this CPE ID
has the latest CVEs (whereas openssh:openssh has no CVEs):
https://nvd.nist.gov/products/cpe/search/results?keyword=cpe:2.3:a:openbsd:openssh

Fixes: 299e5b0a9b (treewide: add PKG_CPE_ID for better cvescanner coverage)

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
(cherry picked from commit 4faf09cfb5)
2025-08-07 09:25:01 +08:00
George Sapkin
dc4dee5d30 tailscale: assign PKG_CPE_ID
Link: https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.2&orderBy=2.2&keyword=cpe%3A2.3%3Aa%3Atailscale%3Atailscale&status=FINAL
Link: https://github.com/openwrt/packages/issues/8534
Signed-off-by: George Sapkin <george@sapk.in>
(cherry picked from commit f6c7871464)
2025-08-07 09:25:01 +08:00
George Sapkin
c5c0c201ee adguardhome: assign PKG_CPE_ID
Link: https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&orderBy=2.3&keyword=cpe%3A2.3%3Aa%3Aadguard%3Aadguardhome
Link: https://github.com/openwrt/packages/issues/8534
Signed-off-by: George Sapkin <george@sapk.in>
(cherry picked from commit fd52fb6e3c)
2025-08-07 09:25:01 +08:00
Tianling Shen
72eba96f43 microsocks: Update to 1.0.5
Release note: https://github.com/rofl0r/microsocks/releases/tag/v1.0.5

Removed upstreamed patches.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit ab4b299591)
2025-07-29 17:09:50 +08:00
Tianling Shen
f0c296aadc v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 083f4ce617)
2025-07-25 13:48:28 +08:00
Gregory Gullin
8f71668a83 sing-box: Update to 1.11.15
changelog: https://github.com/SagerNet/sing-box/releases/tag/v1.11.15

Signed-off-by: Gregory Gullin <garuwex@gmail.com>
(cherry picked from commit b9ac3c5e7d)
2025-07-25 13:46:13 +08:00
Anton P.
43df63ce78 sing-box: Update to 1.11.13
changelog: https://github.com/SagerNet/sing-box/releases/tag/v1.11.13

Signed-off-by: Anton P. <dragunap@gmail.com>
(cherry picked from commit 24e3f2a4c8)
2025-07-25 13:46:10 +08:00
Anton P.
e5665a3a9c sing-box: Update to 1.11.9
changelog: https://github.com/SagerNet/sing-box/releases/tag/v1.11.9

Signed-off-by: Anton P. <dragunap@gmail.com>
[line break added after commit title, accidental line removal fixed]
(cherry picked from commit c0a996ddd9)
2025-07-25 13:46:07 +08:00
Mosney Strange
577564371e sing-box: Update to 1.11.3
Signed-off-by: Mosney Strange <Mosney@users.noreply.github.com>
(cherry picked from commit 2d51880e48)
2025-07-25 13:46:04 +08:00
Jan Hák
3fcb698a6c knot-resolver: update to version 5.7.4
Knot Resolver 5.7.4 (2024-07-23)
================================

Security
--------
- reduce buffering of transmitted data, especially TCP-based in userspace
  Also expose some of the new tweaks in lua:
   (require 'ffi').C.the_worker.engine.net.tcp.user_timeout = 1000
   (require 'ffi').C.the_worker.engine.net.listen_{tcp,udp}_buflens.{snd,rcv}

Improvements
------------
- add the fresh DNSSEC root key KSK-2024 already, Key ID 38696

Incompatible changes
--------------------
- libknot 3.0.x support is dropped
  Upstream last maintained 3.0.x in spring 2022.

Knot Resolver 5.7.3 (2024-05-30)
================================

Improvements
------------
- stats: add separate metrics for IPv6 and IPv4

Bugfixes
--------
- fix NSEC3 records missing in answer for positive wildcard expansion
  with the NSEC3 having over-limit iteration count

Knot Resolver 5.7.2 (2024-03-27)
================================

Bugfixes
--------
- fix on 32-bit systems with 64-bit time_t

Signed-off-by: Jan Hák <jan.hak@nic.cz>
(cherry picked from commit 6e208887e3)
2025-07-04 14:03:21 +02:00
Philip Prindeville
f88b618fe2 named: /var/run/named isn't being created with correct permissions
It needs to be group writable or session.key can't be written once
named drops privileges.

Signed-off-by: Philip Prindeville <philipp@redfish-solutions.com>
(cherry picked from commit b82574b31c)
2025-07-03 10:27:02 -04:00
Tianling Shen
75e3e5d327 v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 7d6535737c)
2025-06-16 18:31:13 +08:00
Tianling Shen
daba53947d v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit ed12bfe13c)
2025-06-16 18:31:13 +08:00
Tianling Shen
4b2429557d v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit a91d278804)
2025-06-16 18:31:13 +08:00
Liangbin Lian
2855313b1f transmission: add syscalls to seccomp filter
Add missing syscalls found with `/etc/init.d/transmission trace`.

fix crash on boot on x86_64 platform

Signed-off-by: Liangbin Lian <jjm2473@gmail.com>
(cherry picked from commit d827297546)
2025-06-07 15:08:43 +02:00
Serhii Ivanov
c6576f049e transmissision: remove build dependency on nodejs
Have no idea why such dependency was added.
No documentation from transmission that they need
such dependency on build time. On the other hand
saves vast of time during build

Signed-off-by: Serhii Ivanov <icegood1980@gmail.com>
(cherry picked from commit a06829b0a2)
2025-06-07 15:08:37 +02:00
Peter van Dijk
d6c912fc8e dnsdist: update to 1.9.10
fixes CVE-2025-30193

Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
(cherry picked from commit ec30d1e4f6)
2025-06-03 19:07:55 +02:00
Tianling Shen
840f3ac55a netavark: revert lock cargo dependencies
Now we have rust 1.85.0.

This reverts commit aba78031f5.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-29 17:51:52 +08:00
Noah Meyerhans
f1673cee7e bind: bump to 9.18.37
Signed-off-by: Noah Meyerhans <frodo@morgul.net>
2025-05-21 21:00:04 -04:00
Noah Meyerhans
72561be263 bind: bump to 9.18.36
Signed-off-by: Noah Meyerhans <frodo@morgul.net>
2025-05-20 08:01:53 +02:00
Peter van Dijk
be13825169 dnsdist: update to 1.9.9
fixes CVE-2025-30194

Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
2025-05-08 22:06:31 +03:00
Tianling Shen
c4add161e3 v2raya: Update to 2.2.6.7
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit aad793b6f4)
2025-04-22 22:18:33 +08:00
Tianling Shen
b40127d88b librespeed-go: add missing conffiles
Add missing uci configuration to conffiles.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit df9ba18578)
2025-04-22 22:18:03 +08:00
Tianling Shen
d31e306e47 v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 1d73b25ed8)
2025-04-22 22:17:57 +08:00
Glenn Strauss
eeeba7846c lighttpd: backport revert changed TLS defaults
Signed-off-by: Glenn Strauss <gstrauss@gluelogic.com>
2025-04-13 16:46:35 +08:00
Glenn Strauss
da7333559b lighttpd: update to lighttpd 1.4.79 release hash
Signed-off-by: Glenn Strauss <gstrauss@gluelogic.com>
(cherry picked from commit e800fc7e8c)
2025-04-13 16:46:35 +08:00
Tianling Shen
aba78031f5 netavark: lock cargo dependencies
rust-iptables 0.5.3+ requires rust 1.85.0 to build, use the version
defined in Cargo.toml instead.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-03-28 14:23:10 +08:00
Thiago Pereira Ricciardi
47ea48c09d pptpd: Fix secrets update
Clear pptp-server existing logins from CHAP_SECRETS file before adding new login data.

Signed-off-by: Thiago Pereira Ricciardi <thiago.ricciardi@gmail.com>
2025-03-20 16:19:40 +01:00
Tianling Shen
01338963f9 rsync: backport bug fixes
Including CVE fixes for:
CVE-2024-12084
CVE-2024-12085
CVE-2024-12086
CVE-2024-12087
CVE-2024-12088
CVE-2024-12747

The patch list is based on rsync_3.2.7-1+deb12u2 from Debian.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-03-11 02:58:02 +08:00
Ray Wang
d812d91706 natmap: update to 20250221
Signed-off-by: Ray Wang <r@hev.cc>
(cherry picked from commit 2db5fca2d8)
2025-02-26 16:46:53 +08:00
Tianling Shen
58aa6bddea v2raya: Update to 2.2.6.6
Remove unneeded reload_service func while at it.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 39c5d7f851)
2025-02-20 16:25:39 +08:00
Tianling Shen
a9fc87fd96 v2raya: Update to 2.2.6.3
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit a5a9140870)
2025-02-20 16:25:36 +08:00
Tianling Shen
6f31ce4d40 v2raya: Update to 2.2.6.2
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit a08614a047)
2025-02-20 16:25:33 +08:00
Tianling Shen
3e52392b27 v2raya: Update to 2.2.6
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit fd5546fc1f)
2025-02-20 16:25:29 +08:00
Tianling Shen
96e049c9f7 rclone: Update to 1.69.1
Remove unneeded reload_service func while at it.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 944d48241c)
2025-02-20 16:24:22 +08:00
Olivier Poitrey
bf07cf79ef nextdns: Update to version 1.45.0
Signed-off-by: Olivier Poitrey <rs@nextdns.io>
2025-02-18 16:38:30 +02:00
Olivier Poitrey
e82e68cc05 nextdns: Update to version 1.44.6
Signed-off-by: Olivier Poitrey <rs@nextdns.io>
2025-02-15 10:34:33 +02:00
Milinda Brantini
b3cde11f68 sing-box: Update to 1.11.1
Signed-off-by: Milinda Brantini <C_A_T_T_E_R_Y@outlook.com>
(cherry picked from commit 8eecd2e5a0)
2025-02-06 16:51:12 +08:00
Milinda Brantini
86b0feae6c sing-box: Update to 1.11.0
Signed-off-by: Milinda Brantini <C_A_T_T_E_R_Y@outlook.com>
(cherry picked from commit 2c7b8ef5a2)
2025-02-06 16:51:12 +08:00
Tianling Shen
0db4466a0f Revert "xray-core: Update to 25.1.30"
xray-core v24.12.31 is the last version that supports Go 1.21.

This reverts commit 0eb7153990.

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-02-05 16:01:13 +08:00
Tianling Shen
acf92e4ab4 rclone: Update to 1.69.0
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 35b614c437)
2025-02-05 15:57:49 +08:00
Liangbin Lian
2c55293f2a rclone: fix configuration saving
The following error occurs when creating storage configuration in WEBUI:
```
Failed to save config after 10 tries: failed to create temp file for new config: open /etc/rclone/rclone.conf4258227003: permission denied
```

we should set the owner of the parent directory of the configuration
file to rclone.

Signed-off-by: Liangbin Lian <jjm2473@gmail.com>
[split chown command, wrap commit message]
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit bcd87dd8b6)
2025-02-05 15:57:46 +08:00
Ryan Keane
610ebcbb98 rclone: Bump to 1.68.2
Release notes in links below.

Link: https://rclone.org/changelog/#v1-68-2-2024-11-15

Signed-off-by: Ryan Keane <the.ra2.ifv@gmail.com>
(cherry picked from commit c342279eb6)
2025-02-05 15:57:41 +08:00
Tianling Shen
01ea206ea4 v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit cec4103bbc)
2025-02-05 15:55:56 +08:00
Tianling Shen
581de9db6a v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit d750bb3182)
2025-02-05 15:55:53 +08:00
Tianling Shen
0eb7153990 xray-core: Update to 25.1.30
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit e9a86e1809)
2025-02-05 15:55:31 +08:00
Tianling Shen
2e114a7a63 xray-core: Update to 24.12.31
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 1166a25311)
2025-02-05 15:55:30 +08:00
Lucian CRISTIAN
928799f853 frr: 10.2.1 fixes
add mgmtd and pim6d

Signed-off-by: Lucian CRISTIAN <lucian.cristian@gmail.com>
2025-02-03 20:20:57 +08:00
Noah Meyerhans
91b9dd598d bind: bump to 9.18.33
Fixes CVEs:
- CVE-2024-12705: DNS-over-HTTPS flooding
- CVE-2024-11187: Limit additional section processing for large RDATA sets

Signed-off-by: Noah Meyerhans <frodo@morgul.net>
2025-01-31 14:15:54 -05:00
Matthias Schiffer
fdde39f878 fastd: update to v23
Signed-off-by: Matthias Schiffer <mschiffer@universe-factory.net>
(cherry picked from commit 2434806621)
2025-01-26 15:15:03 +01:00