RISCi_ATOM [Fri, 16 Feb 2018 17:21:02 +0000 (12:21 -0500)]
Add experimental Tor support to base libreCMC
Pulled in libcap and tor from upstream master.
Christopher Howard [Mon, 12 Feb 2018 19:01:16 +0000 (10:01 -0900)]
Minor edits to System Log doc for consistency
Christopher Howard [Mon, 12 Feb 2018 18:58:27 +0000 (09:58 -0900)]
System Log doc: Changes prompt for MD readability
Christopher Howard [Mon, 12 Feb 2018 18:55:40 +0000 (09:55 -0900)]
Tests markup keywords
Christopher Howard [Mon, 12 Feb 2018 18:54:40 +0000 (09:54 -0900)]
Fixes type in System Log documentation
Christopher Howard [Mon, 12 Feb 2018 18:51:57 +0000 (09:51 -0900)]
Fixes broken image links in System Log documentation
Christopher Howard [Mon, 12 Feb 2018 18:48:10 +0000 (09:48 -0900)]
Adds System Log documentation
RISCi_ATOM [Mon, 12 Feb 2018 17:48:04 +0000 (12:48 -0500)]
Add / fix carl9170 firmware
RISCi_ATOM [Mon, 5 Feb 2018 02:09:55 +0000 (21:09 -0500)]
Bump kernel to 4.4.115
RISCi_ATOM [Tue, 30 Jan 2018 11:28:54 +0000 (06:28 -0500)]
Fix CVE 2018-5332
The Linux kernel through 4.14.13, the rds_message_alloc_sgs() function does not
validate a value that is used during DMA page allocation, leading to a heap-based
out-of-bounds write (related to the rds_rdma_extra_size function in net/rds/rdma.c).
Patch based upon:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=
c095508770aebf1b9218e77026e48345d719b17c
RISCI_ATOM [Tue, 23 Jan 2018 19:51:53 +0000 (14:51 -0500)]
Merge branch 'fix_ar300m_flashing' of somenut/libreCMC into v1.4
hungrymonkey [Tue, 23 Jan 2018 17:39:54 +0000 (09:39 -0800)]
Fix flash as RISC_ATOM's sugguestions
change the last step to reflect the two buttons
RISCI_ATOM [Tue, 23 Jan 2018 17:21:00 +0000 (12:21 -0500)]
Merge branch 'v1.4' of somenut/libreCMC into v1.4
hungrymonkey [Tue, 23 Jan 2018 07:04:53 +0000 (23:04 -0800)]
Added GL-AR300M documentation.
The router is currently unsupported by Librecmc at the moment
RISCi_ATOM [Tue, 23 Jan 2018 00:25:31 +0000 (19:25 -0500)]
Merge branch 'v1.4' of https://gogs.librecmc.org/libreCMC/libreCMC into v1.4
RISCI_ATOM [Sun, 21 Jan 2018 07:20:39 +0000 (02:20 -0500)]
Fix broken link
Kevin Darbyshire-Bryant [Sat, 20 Jan 2018 08:46:28 +0000 (08:46 +0000)]
dnsmasq: backport validation fix in dnssec security fix
A DNSSEC validation error was introduced in the fix for CVE-2017-15107
Backport the upstream fix to the fix (a simple typo)
Signed-off-by: Kevin Darbyshire-Bryant <ldir@darbyshire-bryant.me.uk>
(backported from commit
adaf1cbcc8b253ea807dbe0416b4b04c33dceadf)
Kevin Darbyshire-Bryant [Fri, 19 Jan 2018 17:15:41 +0000 (17:15 +0000)]
dnsmasq: backport dnssec security fix for 17.01
CVE-2017-15107
An interesting problem has turned up in DNSSEC validation. It turns out
that NSEC records expanded from wildcards are allowed, so a domain can
include an NSEC record for *.example.org and an actual query reply could
expand that to anything in example.org and still have it signed by the
signature for the wildcard. So, for example
!.example.org NSEC zz.example.org
is fine.
The problem is that most implementers (your author included, but also
the Google public DNS people, powerdns and Unbound) then took that
record to prove the nothing exists between !.example.org and
zz.example.org, whereas in fact it only provides that proof between
*.example.org and zz.example.org.
This gives an attacker a way to prove that anything between
!.example.org and *.example.org doesn't exists, when it may well do so.
Signed-off-by: Kevin Darbyshire-Bryant <ldir@darbyshire-bryant.me.uk>
RISCI_ATOM [Thu, 18 Jan 2018 01:06:08 +0000 (20:06 -0500)]
Merge branch 'port-forwarding-doc' of pi31415/libreCMC-cmh into v1.4
Christopher Howard [Wed, 17 Jan 2018 19:03:17 +0000 (10:03 -0900)]
Minor edits to Port Forwards doc
Christopher Howard [Wed, 17 Jan 2018 18:51:29 +0000 (09:51 -0900)]
Adds images and corrections to Port Forwards doc
Christopher Howard [Mon, 15 Jan 2018 17:32:41 +0000 (08:32 -0900)]
Adds initial Port Forwarding doc
RISCI_ATOM [Sun, 14 Jan 2018 17:21:27 +0000 (12:21 -0500)]
Update 'docs/unbrick_with_uboot_mod.md'
Fix missing .1
RISCI_ATOM [Thu, 11 Jan 2018 19:47:15 +0000 (14:47 -0500)]
Fix table
RISCi_ATOM [Thu, 11 Jan 2018 19:38:44 +0000 (14:38 -0500)]
Testing Image_support.md page...
RISCI_ATOM [Wed, 10 Jan 2018 19:03:51 +0000 (14:03 -0500)]
Merge branch 'basic-wifi-settings' of pi31415/libreCMC-cmh into v1.4
Christopher Howard [Wed, 10 Jan 2018 17:38:00 +0000 (08:38 -0900)]
Adds images plus several edits to Basic Wireless Settings doc
Christopher Howard [Wed, 10 Jan 2018 17:07:04 +0000 (08:07 -0900)]
Fixes typo in Basic Wireless Settings doc
Christopher Howard [Wed, 10 Jan 2018 16:59:29 +0000 (07:59 -0900)]
Adds core content for Basic Wireless Settings doc
RISCI_ATOM [Fri, 5 Jan 2018 21:36:48 +0000 (16:36 -0500)]
Merge branch 'bridge-mode-doc' of pi31415/libreCMC-cmh into v1.4
Christopher Howard [Fri, 5 Jan 2018 17:22:14 +0000 (08:22 -0900)]
Fixes a small typo in Bridge Mode doc
Christopher Howard [Fri, 5 Jan 2018 17:14:50 +0000 (08:14 -0900)]
A correction to the last edit in Bridge Mode doc
Christopher Howard [Fri, 5 Jan 2018 17:12:05 +0000 (08:12 -0900)]
Moves a misplaced image in Bridge Mode doc
Christopher Howard [Fri, 5 Jan 2018 17:08:07 +0000 (08:08 -0900)]
Adds edits and more material for Bridge Mod doc
Christopher Howard [Fri, 5 Jan 2018 16:39:59 +0000 (07:39 -0900)]
Adds Bridge_Mode doc
Christopher Howard [Thu, 4 Jan 2018 18:25:36 +0000 (09:25 -0900)]
Adds images for planned bridging mode doc
RISCI_ATOM [Tue, 2 Jan 2018 20:41:51 +0000 (15:41 -0500)]
Merge branch 'v1.4' of pi31415/libreCMC-cmh into v1.4
Christopher Howard [Tue, 2 Jan 2018 20:07:57 +0000 (11:07 -0900)]
OpenVPN docs: converted to utf-8-unix encoding to remove DOS line endings
Christopher Howard [Tue, 2 Jan 2018 19:57:00 +0000 (10:57 -0900)]
OpenVPN docs: tweaks and additional material
- Adds introductory material and warnings
- Removes references to LEDE project
Christopher Howard [Mon, 1 Jan 2018 19:13:23 +0000 (10:13 -0900)]
Link fix in TPE-R1100 documentation
Christopher Howard [Mon, 1 Jan 2018 17:36:41 +0000 (08:36 -0900)]
Adds more material to OpenVPN Layer 2 Server doc
RISCi_ATOM [Mon, 1 Jan 2018 15:34:16 +0000 (10:34 -0500)]
Add README.md to /docs
RISCi_ATOM [Mon, 1 Jan 2018 02:50:55 +0000 (21:50 -0500)]
Fix uboot-ar71xx uboot pkg. version
RISCi_ATOM [Sun, 31 Dec 2017 16:21:40 +0000 (11:21 -0500)]
Bump openvpn and wireguard
RISCi_ATOM [Sun, 31 Dec 2017 16:03:56 +0000 (11:03 -0500)]
Add basic unbrick inst. for u-boot_mod
RISCi_ATOM [Sun, 31 Dec 2017 03:33:15 +0000 (22:33 -0500)]
Revert package feed back to v1.4
RISCi_ATOM [Sat, 30 Dec 2017 17:43:36 +0000 (12:43 -0500)]
update kmod-sched-cake and iproute2
RISCi_ATOM [Sat, 30 Dec 2017 17:30:29 +0000 (12:30 -0500)]
Merge branch 'v1.4' of https://gogs.librecmc.org/libreCMC/libreCMC into v1.4
RISCi_ATOM [Sat, 30 Dec 2017 17:30:14 +0000 (12:30 -0500)]
Bump kernel to 4.4.108
libreCMC [Fri, 29 Dec 2017 19:16:10 +0000 (14:16 -0500)]
Merge branch 'v1.4' of pi31415/libreCMC-cmh into v1.4
Christopher Howard [Fri, 29 Dec 2017 19:04:57 +0000 (10:04 -0900)]
Seed commit of OpenVPN Layer 2 Server documention
RISCi_ATOM [Fri, 29 Dec 2017 18:53:17 +0000 (13:53 -0500)]
Testing markdown
RISCi_ATOM [Fri, 29 Dec 2017 18:51:40 +0000 (13:51 -0500)]
Testing markdown
RISCi_ATOM [Fri, 29 Dec 2017 18:50:32 +0000 (13:50 -0500)]
Testing markdown
RISCi_ATOM [Fri, 29 Dec 2017 18:49:07 +0000 (13:49 -0500)]
Testing markdown
RISCi_ATOM [Fri, 29 Dec 2017 18:48:11 +0000 (13:48 -0500)]
Testing markdown
RISCi_ATOM [Thu, 28 Dec 2017 18:46:38 +0000 (13:46 -0500)]
Fix LINUX_KERNEL_HASH to reflect version bump
RISCi_ATOM [Wed, 27 Dec 2017 19:23:22 +0000 (14:23 -0500)]
Bump kernel to 4.4.107
RISCi_ATOM [Wed, 20 Dec 2017 23:17:21 +0000 (18:17 -0500)]
Fixes GL AR150 (breaks GL USB150) Fix later...
RISCi_ATOM [Tue, 19 Dec 2017 22:51:39 +0000 (17:51 -0500)]
Bump openssl to 1.0.2n
RISCi_ATOM [Thu, 14 Dec 2017 22:43:08 +0000 (17:43 -0500)]
Add ath9k_htc firmware
RISCi_ATOM [Wed, 13 Dec 2017 19:55:15 +0000 (14:55 -0500)]
Remove linux-libre-firmware until rework
RISCi_ATOM [Wed, 13 Dec 2017 17:43:08 +0000 (12:43 -0500)]
Add ath9k_htc and carl9170fw firmware to librecmc (does not build on some distros)
RISCI_ATOM [Tue, 12 Dec 2017 18:30:55 +0000 (13:30 -0500)]
Update 'docs/Ben_Nanonote.md'
Start cleaning up Ben Nanonote page.
RISCi_ATOM [Tue, 12 Dec 2017 17:09:01 +0000 (12:09 -0500)]
Add back cve2017-16544 busybox patch from master
RISCi_ATOM [Tue, 12 Dec 2017 17:01:05 +0000 (12:01 -0500)]
Add cjdns, sqm-scripts and adblock to core
RISCi_ATOM [Tue, 12 Dec 2017 02:09:53 +0000 (21:09 -0500)]
Fix uboot-envtools and mkimage
Rafał Miłecki [Fri, 8 Dec 2017 12:57:46 +0000 (13:57 +0100)]
opkg: bump to version 2017-12-08
This updates package to the latest commit from the lede-17.01 branch. It
contains few fixes backported from the master:
1) SHA256 fix
2) URL encoding which allows hosting packages on some more picky servers
Changes:
9f61f7a opkg_download: decode file:/ URLs
3c46c88 file_util: implement urldecode_path()
79908c2 file_util: consolidate hex/unhex routines
793fbac opkg: encode archive filenames while constructing download URLs
a6bb5cb file_util: implement urlencode_path() helper
098e774 libopkg: fix SHA256 calculation for big endian system
Signed-off-by: Rafał Miłecki <rafal@milecki.pl>
Timo Sigurdsson [Tue, 14 Nov 2017 20:41:30 +0000 (21:41 +0100)]
hostapd: backport fix for wnm_sleep_mode=0
wpa_disable_eapol_key_retries can't prevent attacks against the Wireless
Network Management (WNM) Sleep Mode handshake. Currently, hostapd
processes WNM Sleep Mode requests from clients regardless of the setting
wnm_sleep_mode. Backport Jouni Malinen's upstream patch
114f2830 in
order to ignore such requests by clients when wnm_sleep_mode is disabled
(which is the default).
Signed-off-by: Timo Sigurdsson <public_timo.s@silentcreek.de>
[rewrite commit subject (<= 50 characters), bump PKG_RELEASE]
Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be>
(cherry picked from commit
bd45e15d0afe64dfed5a02a50a634f7947b50144
fixed PKG_RELEASE and renumbered patch)
Conflicts:
package/network/services/hostapd/Makefile
Timo Sigurdsson [Tue, 14 Nov 2017 20:41:29 +0000 (21:41 +0100)]
hostapd: Expose the tdls_prohibit option to UCI
wpa_disable_eapol_key_retries can't prevent attacks against the
Tunneled Direct-Link Setup (TDLS) handshake. Jouni Malinen suggested
that the existing hostapd option tdls_prohibit can be used to further
complicate this possibility at the AP side. tdls_prohibit=1 makes
hostapd advertise that use of TDLS is not allowed in the BSS.
Note: If an attacker manages to lure both TDLS peers into a fake
AP, hiding the tdls_prohibit advertisement from them, it might be
possible to bypass this protection.
Make this option configurable via UCI, but disabled by default.
Signed-off-by: Timo Sigurdsson <public_timo.s@silentcreek.de>
(cherry picked from commit
6515887ed9b3f312635409702113dca7c14043e5)
Hans Dedecker [Wed, 6 Dec 2017 13:22:59 +0000 (14:22 +0100)]
dnsmasq: backport infinite dns retries fix
If all configured dns servers return refused in response to a query in
strict mode; dnsmasq will end up in an infinite loop retransmitting the
dns query resulting into high CPU load.
Problem is fixed by checking for the end of a dns server list iteration
in strict mode.
Signed-off-by: Hans Dedecker <dedeckeh@gmail.com>
Stijn Segers [Sun, 3 Dec 2017 11:09:20 +0000 (12:09 +0100)]
curl: apply CVE 2017-8816 and 2017-8817 security patches
This commit adds the upstream patches for CVE 2017-8816 and 2017-8817 to the 17.01
Curl package.
Compile-tested on ar71xx, ramips and x86.
Signed-off-by: Stijn Segers <foss@volatilesystems.org>
Felix Fietkau [Mon, 4 Dec 2017 08:56:32 +0000 (09:56 +0100)]
samba36: backport an upstream fix for an information leak (CVE-2017-15275)
Signed-off-by: Felix Fietkau <nbd@nbd.name>
RISCi_ATOM [Wed, 6 Dec 2017 15:48:43 +0000 (10:48 -0500)]
Add patch from domino-team to add support for later rev. gl-ar300M (spi nand flash)
RISCi_ATOM [Tue, 5 Dec 2017 13:38:35 +0000 (08:38 -0500)]
Fix toolchain and other branding bugs
RISCi_ATOM [Tue, 5 Dec 2017 13:32:00 +0000 (08:32 -0500)]
fix branding in package/base-files
RISCi_ATOM [Sat, 2 Dec 2017 23:30:23 +0000 (18:30 -0500)]
Remove omap support
RISCi_ATOM [Sat, 2 Dec 2017 23:25:25 +0000 (18:25 -0500)]
Move wiki docs to /docs
RISCi_ATOM [Sat, 2 Dec 2017 01:56:22 +0000 (20:56 -0500)]
Remove r8169
RISCi_ATOM [Sat, 2 Dec 2017 00:34:28 +0000 (19:34 -0500)]
Remove ramips/0063-set-CM_GCR_BASE_CMDEFTGT_MEM-according-to-datasheet.patch : broken fix later
RISCi_ATOM [Fri, 1 Dec 2017 20:42:01 +0000 (15:42 -0500)]
Fix default package set
RISCi_ATOM [Fri, 1 Dec 2017 20:38:21 +0000 (15:38 -0500)]
Fix base-files librecmc-keyring dep.
RISCi_ATOM [Fri, 1 Dec 2017 19:31:02 +0000 (14:31 -0500)]
Fix default IP address
RISCi_ATOM [Fri, 1 Dec 2017 19:17:43 +0000 (14:17 -0500)]
Fresh pull from upstream lede-17.01 branch @ commit
d77fe9219af17dce2d00147d904267d4489ae841
RISCi_ATOM [Tue, 28 Nov 2017 23:17:39 +0000 (18:17 -0500)]
iw: fix build on musl host
RISCi_ATOM [Tue, 28 Nov 2017 22:38:53 +0000 (17:38 -0500)]
Update tools/cmake from upstream
RISCi_ATOM [Tue, 28 Nov 2017 19:50:47 +0000 (14:50 -0500)]
tools/mkimage: fix musl build
RISCi_ATOM [Sun, 26 Nov 2017 18:41:29 +0000 (13:41 -0500)]
Fix target/linux/ar71xx Makefile
RISCi_ATOM [Sun, 26 Nov 2017 18:38:59 +0000 (13:38 -0500)]
Package cleanup first round..
RISCi_ATOM [Sun, 26 Nov 2017 18:20:28 +0000 (13:20 -0500)]
Bump version to v1.4.2 and add small-router cat.
RISCi_ATOM [Mon, 20 Nov 2017 20:08:54 +0000 (15:08 -0500)]
Bump busybox pkg revision
RISCi_ATOM [Mon, 20 Nov 2017 16:44:51 +0000 (11:44 -0500)]
Remove mislabeled patch
RISCi_ATOM [Mon, 20 Nov 2017 16:42:40 +0000 (11:42 -0500)]
Merge branch 'master' of https://gogs.librecmc.org/libreCMC/libreCMC
RISCi_ATOM [Mon, 20 Nov 2017 16:41:06 +0000 (11:41 -0500)]
Fix Busybox CVE-2017-16544 issue
RISCi_ATOM [Mon, 20 Nov 2017 16:29:36 +0000 (11:29 -0500)]
Fix Busybox CVE-2017-16544 issue
Peter Wagner [Thu, 9 Nov 2017 23:35:35 +0000 (00:35 +0100)]
openssl: update to 1.0.2m
don't set no-ssl3-method when CONFIG_OPENSSL_WITH_SSL3 di disabled otherwise the compile breaks with this error:
../libssl.so: undefined reference to `SSLv3_client_method'
Fixes CVE: CVE-2017-3735, CVE-2017-3736
Signed-off-by: Peter Wagner <tripolar@gmx.at>
RISCI_ATOM [Fri, 3 Nov 2017 15:53:14 +0000 (11:53 -0400)]
Merge branch 'spi-reset' of ldpinney/GnuBee-libreCMC into master
L. D. Pinney [Fri, 3 Nov 2017 15:06:42 +0000 (23:06 +0800)]
ramips: restore the mediatek-4-byte-spi-reset.patch
patch was dropped in commit
447cf1a2b7efa3949c8562d08bddcfaba3a5d809
Signed-off-by: L. D. Pinney <ldpinney@gmail.com>
RISCi_ATOM [Fri, 27 Oct 2017 21:06:40 +0000 (17:06 -0400)]
Add GL-AR300M NAND Flash support
This was based upon commit :
333ccb0e158edaf80cb1ca696e328f9435f7d3eb in repo. github.com/domino-team/lede-ar300m
RISCi_ATOM [Fri, 27 Oct 2017 18:08:45 +0000 (14:08 -0400)]
Fix omitted gl-ar150