feed/packages.git
6 months agophp8: Support for icu 75 24103/head
Hirokazu MORIKAWA [Thu, 9 May 2024 02:43:21 +0000 (11:43 +0900)]
php8: Support for icu 75

Preparing to update icu4c to 75.
Created a patch for build errors in php-intl.
```
In file included from /mnt/node/openwrt/staging_dir/target-aarch64_generic_musl/usr/include/unicode/unistr.h:39,
                 from ext/intl/intl_convertcpp.h:22,
                 from ext/intl/intl_convertcpp.cpp:17:
/mnt/node/openwrt/staging_dir/target-aarch64_generic_musl/usr/include/unicode/stringpiece.h:133:29: error: 'enable_if_t' in namespace 'std' does not name a template type
  133 |             typename = std::enable_if_t<
      |                             ^~~~~~~~~~~
/mnt/node/openwrt/staging_dir/target-aarch64_generic_musl/usr/include/unicode/stringpiece.h:133:24: note: 'std::enable_if_t' is only available from C++14 onwards
  133 |             typename = std::enable_if_t<
      |                        ^~~
/mnt/node/openwrt/staging_dir/target-aarch64_generic_musl/usr/include/unicode/stringpiece.h:133:40: error: expected '>' before '<' token
  133 |             typename = std::enable_if_t<
      |                                        ^
```
The FreeBSD ports patch was used as a reference.
https://github.com/freebsd/freebsd-ports/commit/e680bd98d34a86302db434c5be23d0cf9d23df23

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
6 months agov4l2rtspserver: update to v0.3.10
Michel Promonet [Mon, 6 May 2024 16:21:21 +0000 (18:21 +0200)]
v4l2rtspserver: update to v0.3.10

Signed-off-by: Michel Promonet <michel.promonet@free.fr>
6 months agokeepalived: add patch to remove log message on json output
Florian Eckert [Tue, 16 Apr 2024 07:11:11 +0000 (09:11 +0200)]
keepalived: add patch to remove log message on json output

The 'luci-app-keepalived' uses the status json output to parse this
information for the status page. The problem is that when the LuCI
status page is open in the browser, the query is logged every 3 second into
the syslog. This is not needed and can therefore be removed.

This patch was already merged upstream:
https://github.com/acassen/keepalived/commit/6cce75f4eb65551a61d2e4ba775637b288c1d592

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
6 months agonet-tools: Revert "net-tools: add netstat utiltiy"
Florian Eckert [Wed, 8 May 2024 06:18:05 +0000 (08:18 +0200)]
net-tools: Revert "net-tools: add netstat utiltiy"

This reverts commit d932a867e9445a54e49ecbff4e07bb2d1d0197be as this
changes has not been reviewed and must be reverted.

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
6 months agozerotier: update to 1.14.0
Moritz Warning [Mon, 6 May 2024 20:50:36 +0000 (22:50 +0200)]
zerotier: update to 1.14.0

Includes refreshed patches.

Signed-off-by: Moritz Warning <moritzwarning@web.de>
6 months agoMerge pull request #24088 from TDT-AG/pr/20240506-net-tools
Florian Eckert [Tue, 7 May 2024 11:55:36 +0000 (13:55 +0200)]
Merge pull request #24088 from TDT-AG/pr/20240506-net-tools

net-tools: add netstat utiltiy

6 months agoMerge pull request #24089 from TDT-AG/pr/20240506-stunnel
Florian Eckert [Tue, 7 May 2024 11:14:49 +0000 (13:14 +0200)]
Merge pull request #24089 from TDT-AG/pr/20240506-stunnel

stunnel: update to version 5.72

6 months agostrongswan: Add missing declarations in swanctl
Philip Prindeville [Mon, 6 May 2024 20:14:55 +0000 (14:14 -0600)]
strongswan: Add missing declarations in swanctl

Signed-off-by: Philip Prindeville <philipp@redfish-solutions.com>
6 months agonginx: QUIC: Fix SSL 3.0 deprecated function 24005/head
Sean Khan [Wed, 24 Apr 2024 22:02:02 +0000 (18:02 -0400)]
nginx: QUIC: Fix SSL 3.0 deprecated function

`EVP_CIPHER_CTX_cipher()` function was deprecated in OpenSSL 3.0.
As per OpenSSL's recommendation (https://www.openssl.org/docs/manmaster/man3/EVP_CIPHER_CTX_get0_cipher.html)
switch to using `EVP_CIPHER_CTX_get0_cipher()` instead.

With this change and recent commit to nginx-util #23935. We should now
be able to build nginx + modules with fully compliant calls to OpenSSL
3.0+ with legacy features disabled.

Signed-off-by: Sean Khan <datapronix@protonmail.com>
Link: https://github.com/openwrt/packages/pull/24005
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
6 months agoMerge pull request #24092 from nmav/tmp-fix-ocserv-ipcalc
Nikos Mavrogiannopoulos [Mon, 6 May 2024 20:21:25 +0000 (22:21 +0200)]
Merge pull request #24092 from nmav/tmp-fix-ocserv-ipcalc

ocserv: set ipcalc explicitly

6 months agoocserv: set ipcalc explicitly 24092/head
Nikos Mavrogiannopoulos [Mon, 6 May 2024 19:51:39 +0000 (21:51 +0200)]
ocserv: set ipcalc explicitly

This is a mandatory tool for the test suite, but we do not run it.
Fixes compilation.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
6 months agoopenssh-keygen: Make ssh-keygen as an alternative to dropbearkey 22861/head
Sergey Ponomarev [Sun, 3 Dec 2023 16:14:42 +0000 (18:14 +0200)]
openssh-keygen: Make ssh-keygen as an alternative to dropbearkey

The DropBear's dropbearkey tool is compatible with OpenSSH
ssh-keygen.
It was set by default as the /usr/bin/ssh-keygen program since
the PR https://github.com/openwrt/openwrt/pull/14174
Now if a user need for a full ssh-keygen the openssh-keygen package
should substitute it gracefully as an alternative.

Signed-off-by: Sergey Ponomarev <stokito@gmail.com>
Link: https://github.com/openwrt/packages/pull/22861
[ wrap to 80 columns ]
Link: https://github.com/openwrt/packages/pull/22861
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
6 months agostunnel: update to version 5.72 24089/head
Florian Eckert [Tue, 13 Feb 2024 11:30:54 +0000 (12:30 +0100)]
stunnel: update to version 5.72

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
6 months agonet-tools: add netstat utiltiy 24088/head
Florian Eckert [Tue, 16 Apr 2024 07:09:31 +0000 (09:09 +0200)]
net-tools: add netstat utiltiy

Some user may want or need the full fuctionality of the netstat tool.

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
6 months agoatlas-probe: fix version for APK
Florian Eckert [Mon, 6 May 2024 09:17:18 +0000 (11:17 +0200)]
atlas-probe: fix version for APK

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
6 months agofaad2: fix version for APK
Florian Eckert [Mon, 6 May 2024 09:16:17 +0000 (11:16 +0200)]
faad2: fix version for APK

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
6 months agozlog: fix version for APK
Florian Eckert [Mon, 6 May 2024 08:27:33 +0000 (10:27 +0200)]
zlog: fix version for APK

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
6 months agoocserv: updated to 1.3.0
Nikos Mavrogiannopoulos [Mon, 6 May 2024 06:30:19 +0000 (08:30 +0200)]
ocserv: updated to 1.3.0

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
6 months agospeedtest-go: update to 1.7.0
TeleostNaCl Dai [Mon, 6 May 2024 04:40:01 +0000 (12:40 +0800)]
speedtest-go: update to 1.7.0

Update speedtest-go version to 1.7.0

Signed-off-by: TeleostNaCl Dai <teleostnacl@gmail.com>
6 months agobanip: update 0.9.5-5
Dirk Brenken [Sun, 5 May 2024 19:57:28 +0000 (21:57 +0200)]
banip: update 0.9.5-5

* fix a processing race condition
* it's now possible to disable the icmp/syn/udp safeguards in pre-routing - set the threshold to '0'.

Signed-off-by: Dirk Brenken <dev@brenken.org>
6 months agolibs: glib2: fix provided pkg-config and always use host tools 23881/head
Christian Marangi [Thu, 11 Apr 2024 15:07:36 +0000 (17:07 +0200)]
libs: glib2: fix provided pkg-config and always use host tools

For the InstallDev target, the pkg-config should point to the glib2 host
tools for glib_compile_resources, gdbus_codegen, glib_genmarshal and
glib_mkenums instead of pointing to the targets ones as they are
unusable by the host machine (due to crosscompiling)

Fix the pkg-config to reference the host tools by replaying the entry
and use the prefix_hostpkg variable provided by our pkg-config.

Link: https://github.com/openwrt/packages/pull/23881
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
6 months agoMerge pull request #24081 from mhei/fix-buildbots-for-gensio
Michael Heimpold [Sun, 5 May 2024 14:17:16 +0000 (16:17 +0200)]
Merge pull request #24081 from mhei/fix-buildbots-for-gensio

gensio: add patch with workaround for buildbots (refs #24047)

6 months agorust: Update to 1.78.0
Tianling Shen [Sat, 4 May 2024 10:39:44 +0000 (18:39 +0800)]
rust: Update to 1.78.0

- Switch back to .gz tarball
- Replace local bootstrap cache hack with upstreamed option

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
6 months agogensio: add patch with workaround for buildbots (refs #24047) 24081/head
Michael Heimpold [Sat, 4 May 2024 19:54:50 +0000 (21:54 +0200)]
gensio: add patch with workaround for buildbots (refs #24047)

This should solve the issue found on the buildbots:

-snip-
...
checking consistency of all components of python development environment... yes
./configure: line 24172: test: =: unary operator expected
checking for pam_start in -lpam... (cached) no
...
-snap-

For still unknown reason, AX_PYTHON_DEVEL from the included
m4 file is not used which would set the variable the correct way.

Signed-off-by: Michael Heimpold <mhei@heimpold.de>
6 months agortty: update to 8.1.2
Jianhui Zhao [Sat, 4 May 2024 12:32:04 +0000 (20:32 +0800)]
rtty: update to 8.1.2

Signed-off-by: Jianhui Zhao <zhaojh329@gmail.com>
6 months agolua-eco: update to 3.5.0
Jianhui Zhao [Sat, 4 May 2024 12:00:54 +0000 (20:00 +0800)]
lua-eco: update to 3.5.0

MQTT code refactoring has been done since 3.5.0 that
mqtt.so no longer exists.

Signed-off-by: Jianhui Zhao <zhaojh329@gmail.com>
6 months agoflashrom: strip leading whitespace from PROGRAMMER_ARGS
Federico Capoano [Tue, 19 Mar 2024 13:52:31 +0000 (10:52 -0300)]
flashrom: strip leading whitespace from PROGRAMMER_ARGS

Newer version of meson do not allow empty arguments.

Signed-off-by: Federico Capoano <f.capoano@openwisp.io>
6 months agouspot: update to Git HEAD (2024-05-03)
Thibaut VARÈNE [Fri, 3 May 2024 14:57:38 +0000 (16:57 +0200)]
uspot: update to Git HEAD (2024-05-03)

5e2d15a110bb treewide: remove tip_mode
e2dbdef4cf1e treewide: rename spotfilter -> uspotfilter
ef0f5291365b uspot/uspotfilter: implement disconnect_delay
92d3356d3fb3 update README

Update the package Makefile to reflect the changes from the following
above-listed commit:

e2dbdef4cf1e treewide: rename spotfilter -> uspotfilter

Signed-off-by: Thibaut VARÈNE <hacks@slashdirt.org>
6 months agonano: update to 8.0
Hannu Nyman [Fri, 3 May 2024 13:24:09 +0000 (16:24 +0300)]
nano: update to 8.0

Update nano editor to version 8.0

Signed-off-by: Hannu Nyman <hannu.nyman@iki.fi>
6 months agov2ray-core: Update to 5.16.0
Tianling Shen [Fri, 3 May 2024 05:54:50 +0000 (13:54 +0800)]
v2ray-core: Update to 5.16.0

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
6 months agoalist: Update to 3.34.0
Tianling Shen [Fri, 3 May 2024 05:54:44 +0000 (13:54 +0800)]
alist: Update to 3.34.0

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
6 months agodnsproxy: Update to 0.71.1
Tianling Shen [Fri, 3 May 2024 05:54:32 +0000 (13:54 +0800)]
dnsproxy: Update to 0.71.1

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
6 months agospeedtest-go: add new package
TeleostNaCl Dai [Fri, 26 Apr 2024 07:59:12 +0000 (15:59 +0800)]
speedtest-go: add new package

This is a Command Line Interface (CLI) and pure Go API to
test internet speed using speedtest.net. Its upstream is
https://github.com/showwin/speedtest-go

Signed-off-by: TeleostNaCl Dai <teleostnacl@gmail.com>
6 months agoMerge pull request #24064 from G-M0N3Y-2503/docker-update 24070/head
Tianling Shen [Fri, 3 May 2024 05:45:10 +0000 (13:45 +0800)]
Merge pull request #24064 from G-M0N3Y-2503/docker-update

Docker: Update to 26.1.0

6 months agov2ray-geodata: Update to latest version
Tianling Shen [Fri, 3 May 2024 05:42:40 +0000 (13:42 +0800)]
v2ray-geodata: Update to latest version

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
6 months agoxray-core: Update to 1.8.11
Tianling Shen [Fri, 3 May 2024 05:42:35 +0000 (13:42 +0800)]
xray-core: Update to 1.8.11

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
6 months agodocker: Update to 26.1.0 24064/head
Gerard Ryan [Wed, 1 May 2024 11:51:07 +0000 (21:51 +1000)]
docker: Update to 26.1.0
* Removed unnecessary GO lang variables

Signed-off-by: Gerard Ryan <G.M0N3Y.2503@gmail.com>
6 months agodockerd: Update to 26.1.0
Gerard Ryan [Wed, 1 May 2024 11:50:47 +0000 (21:50 +1000)]
dockerd: Update to 26.1.0
* Removed unnecessary GO lang variables

Signed-off-by: Gerard Ryan <G.M0N3Y.2503@gmail.com>
6 months agocontainerd: Update to 1.7.15
Gerard Ryan [Wed, 1 May 2024 11:50:08 +0000 (21:50 +1000)]
containerd: Update to 1.7.15
* Explicitly list GO_PKG_INSTALL_EXTRA
* Removed unnecessary GO lang variables

Signed-off-by: Gerard Ryan <G.M0N3Y.2503@gmail.com>
6 months agognutls: Update to version 3.8.5
Pascal Ernster [Wed, 1 May 2024 17:49:31 +0000 (19:49 +0200)]
gnutls: Update to version 3.8.5

All patches automatically refreshed.

The most important changes are two "medium" CVEs fixed in GnuTLS 3.8.4:

- CVE-2024-28834 / GNUTLS-SA-2023-12-04
  A vulnerability was found that the deterministic ECDSA code leaks
  bit-length of random nonce which allows for full recovery of the
  private key used after observing a few hundreds to a few thousands of
  signatures on known messages, due to the application of lattice
  techniques.
  The issue was reported in the issue tracker as [#1516](https://gitlab.com/gnutls/gnutls/-/issues/1516).
- CVE-2024-28835 / GNUTLS-SA-2024-01-23
  When validating a certificate chain with more then 16 certificates
  GnuTLS applications crash with an assertion failure.
  The issue was reported in the issue tracker as [#1527](https://gitlab.com/gnutls/gnutls/-/issues/1527) and [#1525](https://gitlab.com/gnutls/gnutls/-/issues/1525).

Augmented copy/extract from upstream's NEWS file since GnuTLS 3.8.3:

- Version 3.8.5 (released 2024-04-04)
  - libgnutls: Due to majority of usages and implementations of
    RSA decryption with PKCS#1 v1.5 padding being incorrect,
    leaving them vulnerable to Marvin attack, the RSAES-PKCS1-v1_5
    is being deprecated (encryption and decryption) and will be
    disabled in the future. A new option `allow-rsa-pkcs1-encrypt`
    has been added into the system-wide library configuration which
    allows to enable/disable the RSAES-PKCS1-v1_5. Currently, the
    RSAES-PKCS1-v1_5 is enabled by default.
  - libgnutls: Added support for RIPEMD160 and PBES1-DES-SHA1 for
    backward compatibility with GCR.
  - libgnutls: A couple of memory related issues have been fixed in RSA PKCS#1
    v1.5 decryption error handling and deterministic ECDSA with earlier
    versions of GMP.  These were a regression introduced in the 3.8.4
    release. See [#1535](https://gitlab.com/gnutls/gnutls/-/issues/1535) and [!1827](https://gitlab.com/gnutls/gnutls/-/merge_requests/1827).
  - build: Fixed a bug where building gnutls statically failed due
    to a duplicate definition of `nettle_rsa_compute_root_tr()`.
  - API and ABI modifications:
    - `GNUTLS_PKCS_PBES1_DES_SHA1`: New enum member of `gnutls_pkcs_encrypt_flags_t`.
- Version 3.8.4 (released 2024-03-18)
  - libgnutls: RSA-OAEP encryption scheme is now supported
    To use it with an unrestricted RSA private key, one would need to
    initialize a `gnutls_x509_spki_t` object with necessary parameters
    for RSA-OAEP and attach it to the private key. It is also possible
    to import restricted private keys if they are stored in PKCS#8
    format.
  - libgnutls: Fix side-channel in the deterministic ECDSA.
    Reported by George Pantelakis ([#1516](https://gitlab.com/gnutls/gnutls/-/issues/1516)).
    [GNUTLS-SA-2023-12-04, CVSS: medium] [CVE-2024-28834]
  - libgnutls: Fixed a bug where certtool crashed when verifying a certificate
    chain with more than 16 certificates. Reported by William Woodruff ([#1525](https://gitlab.com/gnutls/gnutls/-/issues/1525))
    and yixiangzhike ([#1527](https://gitlab.com/gnutls/gnutls/-/issues/1527)).
    [GNUTLS-SA-2024-01-23, CVSS: medium] [CVE-2024-28835]
  - libgnutls: Compression libraries are now loaded dynamically as needed
    instead of all being loaded during gnutls library initialization.
    As a result, the library initialization should be faster.
  - build: The gnutls library can now be linked with the static library
    of GMP.  Note that in order for this to work libgmp.a needs to be
    compiled with -fPIC and libhogweed in Nettle also has to be linked
    to the static library of GMP.  This can be used to prevent custom
    memory allocators from being overriden by other applications.
  - API and ABI modifications:
    - `gnutls_x509_spki_get_rsa_oaep_params`: New function.
    - `gnutls_x509_spki_set_rsa_oaep_params`: New function.
    - `GNUTLS_PK_RSA_OAEP`: New enum member of `gnutls_pk_algorithm_t`.

Signed-off-by: Pascal Ernster <git@hardfalcon.net>
6 months agonextdns: Update to version 1.43.3
Olivier Poitrey [Mon, 29 Apr 2024 21:54:20 +0000 (21:54 +0000)]
nextdns: Update to version 1.43.3

Signed-off-by: Olivier Poitrey <rs@nextdns.io>
6 months agobanip: update 0.9.5-4
Dirk Brenken [Wed, 1 May 2024 13:02:44 +0000 (15:02 +0200)]
banip: update 0.9.5-4

* optimized adding suspicious IPs to Sets in the log monitor
* re-added ipblackhole feed

Signed-off-by: Dirk Brenken <dev@brenken.org>
6 months agohyperscan: fix broken build w/ external toolchain
John Audia [Sat, 20 Apr 2024 17:39:33 +0000 (13:39 -0400)]
hyperscan: fix broken build w/ external toolchain

If building with the project external toolchain, the gcc check
fails to set the correct value for TUNE_FLAG to allow the min
supported SSSE3 compiler support test to pass.  This patch hacks
the file to set to the correct value.

Links to upstream bug reports:
https://github.com/openwrt/openwrt/issues/15216
https://github.com/intel/hyperscan/issues/431

Build system: x86/64 (build system toolchain and x86/64 w/ external toolchain (18-Apr-2024 snapshot)
Build-tested: x86/64/AMD Cezanne
Run-tested: x86/64/AMD Cezanne

Signed-off-by: John Audia <therealgraysky@proton.me>
6 months agofrr: fix host build error on macOS
Georgi Valkov [Tue, 30 Apr 2024 14:37:11 +0000 (17:37 +0300)]
frr: fix host build error on macOS

Fixes:
lib/command_graph.c:16:1: error: argument to 'section' attribute is not valid for this target: mach-o section specifier requires a segment and section separated by a comma DEFINE_MTYPE_STATIC(LIB, CMD_TOKENS, "Command Tokens"); ^
./lib/memory.h:139:2: note: expanded from macro 'DEFINE_MTYPE_STATIC'
        DEFINE_MTYPE_ATTR(group, name, static, desc)                           \
        ^
./lib/memory.h:109:26: note: expanded from macro 'DEFINE_MTYPE_ATTR'
                __attribute__((section(".data.mtypes"))) = { {                 \

[1] https://github.com/FRRouting/frr/pull/6032
[2] https://github.com/FRRouting/frr/pull/15890

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agolibideviceactivation: add package from git
Georgi Valkov [Tue, 23 Apr 2024 23:38:31 +0000 (02:38 +0300)]
libideviceactivation: add package from git

Manage the activation of Apple iOS devices

There have been no releases since 2020-06-16.
Use the latest git 6925d58ef7994168fb9585aa6f48421149982329

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agoideviceinstaller: add package from git
Georgi Valkov [Tue, 23 Apr 2024 22:24:11 +0000 (01:24 +0300)]
ideviceinstaller: add package from git

Manage apps and app archives on iOS devices

There have been no releases since 2020-06-16.
Use the latest git 22872c3571b8d2646a9fbb74ec1d7e186941053d

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agoifuse: add package from git
Georgi Valkov [Tue, 23 Apr 2024 21:25:30 +0000 (00:25 +0300)]
ifuse: add package from git

Fuse filesystem access to iOS devices

There have been no releases since 2020-06-16.
Use the latest git 814a0e38050850937debd697fcfe6eca3de1b66f

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agoidevicerestore: update to the latest git version
Georgi Valkov [Tue, 23 Apr 2024 19:00:49 +0000 (22:00 +0300)]
idevicerestore: update to the latest git version

There have been no releases since 2020-06-16.
Update to the latest git 6d40d0ab626eb0ffee4f005b7fdc915bc561deb9

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agolibirecovery: update to 1.2.0
Georgi Valkov [Tue, 23 Apr 2024 17:34:29 +0000 (20:34 +0300)]
libirecovery: update to 1.2.0

Switched to GitHub tarballs as they are now available.

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agousbmuxd: update to the latest git version
Georgi Valkov [Mon, 22 Apr 2024 12:07:12 +0000 (15:07 +0300)]
usbmuxd: update to the latest git version

There have been no releases since 2020-06-16.
Update to the latest git 360619c5f721f93f0b9d8af1a2df0b926fbcf281
Fix: --version did not print the version.

[1] changes to mode 3 CDC NCM by default. Revert back to mode 1:
Originally mode 1 was used, where a tethered iPhone appears as an
Ethernet interface, handled by the ipheth driver. This has been the
default for many years and is known to work on iPhone 3G, 4S, 7 Plus,
11 and newer. Since [2] ipheth supports CDC NCM in mode 1, and
configures the iPhone to use it.

In mode 3, the Ethernet interface is handled by kmod-usb-net-cdc-ncm.
This driver has better performance, but now the iPhone does not
provide DHCP or Internet connectivity, so we should revert to mode 1.

Analysing the network traffic, shows that both the iPhone and OpenWRT
are DHCP clients. The iPhone does not act as a DHCP server. I can set
a static IP on OpenWRT and lease 172.20.10.1 to the iPhone. Then I can
ping the iPhone and I have IPv4 connectivity. However the iPhone does
not provide Internet connectivity to OpenWRT. Maybe in mode 3, the
iPhone is a client meant to receive Internet over USB and therefore
it is not a gateway?

Attempts to switch old iPhones, such as 3G and 4S to mode 3 fail.
They remain in mode 1 and work correctly using the ipheth driver.

Comparison, tested on iPhone 7 Plus and 11
- mode 1 eth0 kmod-usb-net-ipheth  264 Mbit/s DHCP server, Internet
- mode 3 usb0 kmod-usb-net-cdc-ncm 304 Mbit/s DHCP client, no Internet

[1] https://github.com/libimobiledevice/usbmuxd/commit/c7a0dd9b82633ea347497626282e3051a469ef50
[2] https://github.com/openwrt/openwrt/commit/680f8738d02a1876ae4cd11aacf9cd56e520fadf

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agolibimobiledevice: update to the latest git version
Georgi Valkov [Mon, 22 Apr 2024 11:52:22 +0000 (14:52 +0300)]
libimobiledevice: update to the latest git version

There have been no releases since 2020-06-16.
Update to the latest git 5f083426b4ede24b2576f3a56eaf8ac3632c02f7

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agolibusbmuxd: update to 2.1.0
Georgi Valkov [Mon, 22 Apr 2024 11:34:05 +0000 (14:34 +0300)]
libusbmuxd: update to 2.1.0

Switched to GitHub tarballs as they are now available.

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agolibimobiledevice-glue: add package 1.2.0
Georgi Valkov [Mon, 22 Apr 2024 11:29:10 +0000 (14:29 +0300)]
libimobiledevice-glue: add package 1.2.0

A library with common code used by the libimobiledevice project.

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agolibplist: update to 2.4.0
Georgi Valkov [Mon, 22 Apr 2024 11:10:56 +0000 (14:10 +0300)]
libplist: update to 2.4.0

Switched to GitHub tarballs as they are now available.

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
6 months agoqemu: update to 9.0.0
Vladimir Ermakov [Wed, 24 Apr 2024 10:57:36 +0000 (12:57 +0200)]
qemu: update to 9.0.0

- update version: 9.0.0
- refresh patches

Signed-off-by: Vladimir Ermakov <vooon341@gmail.com>
6 months agoser2net: update to 4.6.2
Yegor Yefremov [Tue, 30 Apr 2024 07:02:36 +0000 (09:02 +0200)]
ser2net: update to 4.6.2

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
6 months agogensio: update to 2.8.4
Yegor Yefremov [Tue, 30 Apr 2024 07:01:47 +0000 (09:01 +0200)]
gensio: update to 2.8.4

Remove the upstreamed patches.

Signed-off-by: Yegor Yefremov <yegorslists@googlemail.com>
6 months agoncdu: update to 1.20
John Audia [Tue, 30 Apr 2024 18:27:05 +0000 (14:27 -0400)]
ncdu: update to 1.20

Upstream bump

Build system: x86/64
Build-tested: x86/64/AMD Cezanne
Run-tested: x86/64/AMD Cezanne

Signed-off-by: John Audia <therealgraysky@proton.me>
6 months agopdns-recursor: update to 5.0.4, fixes CVE-2024-25583
Peter van Dijk [Wed, 24 Apr 2024 13:53:04 +0000 (15:53 +0200)]
pdns-recursor: update to 5.0.4, fixes CVE-2024-25583

Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
6 months agodnsproxy: add three new features
Emily H. [Tue, 30 Apr 2024 11:03:38 +0000 (11:03 +0000)]
dnsproxy: add three new features

This commit adds the following features:
1. UCI support for local DNS over HTTPS/TLS/QUIC server.
2. UCI support for using private reverse DNS.
3. procd jail with CAP_NET_BIND_SERVICE, allowing
   dnsproxy to serve on standard ports directly.

Signed-off-by: Emily H. <battery_tag708@simplelogin.com>
6 months agomsmtp: update to version 1.8.25
Josef Schlehofer [Fri, 26 Apr 2024 13:35:52 +0000 (15:35 +0200)]
msmtp: update to version 1.8.25

Release notes:
https://marlam.de/msmtp/news/msmtp-1-8-25/

Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
6 months agotransmission: update to version 4.0.5
Josef Schlehofer [Fri, 26 Apr 2024 08:38:20 +0000 (10:38 +0200)]
transmission: update to version 4.0.5

Release notes:
https://github.com/transmission/transmission/releases/tag/4.0.5

Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
6 months agosing-box: update to 1.8.12
brvphoenix [Mon, 29 Apr 2024 09:08:50 +0000 (17:08 +0800)]
sing-box: update to 1.8.12

Signed-off-by: brvphoenix <brvphoenix@gmail.com>
6 months agoapk: move package to core
Paul Spooren [Wed, 20 Mar 2024 23:03:43 +0000 (00:03 +0100)]
apk: move package to core

This will become part of openwrt.git and used within the build system.

Signed-off-by: Paul Spooren <mail@aparcar.org>
6 months agoMerge pull request #23901 from M95D/m95d-audit2
Florian Eckert [Mon, 29 Apr 2024 05:59:47 +0000 (07:59 +0200)]
Merge pull request #23901 from M95D/m95d-audit2

audit: move from packages to openwrt

6 months agoMerge pull request #24034 from rs/nextdns-1.43.1-master
Stan Grishin [Mon, 29 Apr 2024 00:35:30 +0000 (17:35 -0700)]
Merge pull request #24034 from rs/nextdns-1.43.1-master

nextdns: Update to version 1.43.1

6 months agonmap: add patch fixing compilation error with no OpenSSL DTLS
Christian Marangi [Sun, 28 Apr 2024 10:33:19 +0000 (12:33 +0200)]
nmap: add patch fixing compilation error with no OpenSSL DTLS

Add patch fixing compilation error with no OpenSSL DTLS support.

Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
6 months agonmap: update to version 7.95
Josef Schlehofer [Sat, 27 Apr 2024 10:19:45 +0000 (12:19 +0200)]
nmap: update to version 7.95

- Remove patch 010-Build-based-on-OpenSSL-version.patch
since it was backported and now it is included in 7.95 release
- Patch 030-ncat-drop-ca-bundle.patch was refreshed

Release notes:
https://nmap.org/changelog.html#7.95

Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
6 months agonmap: use git as source and bump to PCRE2 support commit
Christian Marangi [Wed, 25 Oct 2023 03:51:57 +0000 (05:51 +0200)]
nmap: use git as source and bump to PCRE2 support commit

Use git as source and bump version to PCRE2 support commit.

Move nmap to PCRE2 library as PCRE is EOL and won't receive any security
update in the future.

Patch 001-Use-correct-HAVE_-macros-for-Lua-5.4.-Fixes-2648.patch has
been merged upstream and can be dropped.

Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
6 months agonmap: bump to version 7.94
Christian Marangi [Wed, 25 Oct 2023 03:41:55 +0000 (05:41 +0200)]
nmap: bump to version 7.94

Bump to version 7.94.
Nmap now require lua 5.4.

Patch 020-Python3-port-of-ndiff.patch has been merged upstream and can
be dropped.
Patch 001-Use-correct-HAVE_-macros-for-Lua-5.4.-Fixes-2648.patch is now
required to fix a problem with header inclusion for lua 5.4.

Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
7 months agonextdns: Update to version 1.43.1 24034/head
Olivier Poitrey [Sun, 28 Apr 2024 13:06:30 +0000 (13:06 +0000)]
nextdns: Update to version 1.43.1

Signed-off-by: Olivier Poitrey <rs@nextdns.io>
7 months agolua: add new package with version 5.4
Christian Marangi [Wed, 25 Oct 2023 03:36:53 +0000 (05:36 +0200)]
lua: add new package with version 5.4

Add new lua version 5.4 required by new version of nmap.

Patches are copied from lua 5.3.
- Readline patch has to be reworked as lua 5.4 now supports
no readline for Linux but still needs some tweaks for macOS
and bsd systems.
- Patch shared lib required some rework.

Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
7 months agonextdns: Update to version 1.43.0
Olivier Poitrey [Sun, 28 Apr 2024 00:47:37 +0000 (00:47 +0000)]
nextdns: Update to version 1.43.0

Signed-off-by: Olivier Poitrey <rs@nextdns.io>
7 months agohev-socks5-server: add new package
Ray Wang [Thu, 25 Apr 2024 13:36:14 +0000 (21:36 +0800)]
hev-socks5-server: add new package

HevSocks5Server is a high-performance socks5 server for Unix.

More details: https://github.com/heiher/hev-socks5-server

Signed-off-by: Ray Wang <r@hev.cc>
7 months agosnort3: fix bug with unset variable
Eric Fahlgren [Tue, 9 Apr 2024 14:23:46 +0000 (07:23 -0700)]
snort3: fix bug with unset variable

  - Parameter not set in two places:
    /usr/bin/snort-mgr: eval: line 125: options: parameter not set

Reported-by: @klingon888
Signed-off-by: Eric Fahlgren <ericfahlgren@gmail.com>
7 months agosnort3: add patch and move to PCRE2
Christian Marangi [Tue, 7 Nov 2023 00:17:25 +0000 (01:17 +0100)]
snort3: add patch and move to PCRE2

Add experimental patch and move package to PCRE2 as PCRE is EOL and
won't receive any security updates anymore.

Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
7 months agocloudflared: Update to 2024.4.1
Tianling Shen [Sat, 27 Apr 2024 05:18:55 +0000 (13:18 +0800)]
cloudflared: Update to 2024.4.1

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
7 months agolibrespeed-go: improve the description
Nathan Friedly [Thu, 25 Apr 2024 17:19:33 +0000 (13:19 -0400)]
librespeed-go: improve the description

This swaps the order of the lines in the description so that when LuCI displays only the first line, it still offers some helpful information.

Signed-off-by: Nathan Friedly <nathan@nfriedly.com>
7 months agop910nd: set bidi only if not already set
Paul Donald [Sun, 31 Mar 2024 18:25:17 +0000 (20:25 +0200)]
p910nd: set bidi only if not already set

Closes #23774

Signed-off-by: Paul Donald <newtwen+github@gmail.com>
7 months agobanip: update 0.9.5-3
Dirk Brenken [Fri, 26 Apr 2024 15:03:14 +0000 (17:03 +0200)]
banip: update 0.9.5-3

* allow multiple protocol/port definitions per feed, e.g. 'tcp udp 80 443 50000'
* removed the default protocol/port limitation from asn feed

Signed-off-by: Dirk Brenken <dev@brenken.org>
7 months agosyslog-ng: update to version 4.7.1
Josef Schlehofer [Fri, 26 Apr 2024 09:24:57 +0000 (11:24 +0200)]
syslog-ng: update to version 4.7.1

Release notes:
- https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-4.7.0
- https://github.com/syslog-ng/syslog-ng/releases/tag/syslog-ng-4.7.1

Also bump version in the config file to avoid warning

Signed-off-by: Josef Schlehofer <pepe.schlehofer@gmail.com>
7 months agoMerge pull request #13619 from aparcar/no-circle
Josef Schlehofer [Fri, 26 Apr 2024 08:47:43 +0000 (10:47 +0200)]
Merge pull request #13619 from aparcar/no-circle

CI: remove CircleCI for now

7 months agoCI: remove CircleCI for now 13619/head
Paul Spooren [Sat, 10 Oct 2020 01:31:01 +0000 (15:31 -1000)]
CI: remove CircleCI for now

The GitHub CI offers currenlty more architecture and the Signed-of-by
test is covered via the DOC CI test. In case GitHub ever changes
policies, we can simply switch back.

Signed-off-by: Paul Spooren <mail@aparcar.org>
7 months agojool: update documentation
Goetz Goerisch [Fri, 19 Apr 2024 16:34:19 +0000 (18:34 +0200)]
jool: update documentation

* corrected the documentation links for upstream
* fixed style to be correctly rendered
* add reference to OpenWrt tutorial

Signed-off-by: Goetz Goerisch <ggoerisch@gmail.com>
7 months agoMerge pull request #23984 from stangri/master-adblock-fast
Stan Grishin [Thu, 25 Apr 2024 21:33:57 +0000 (14:33 -0700)]
Merge pull request #23984 from stangri/master-adblock-fast

adblock-fast: bugfix: unbound-related fixes

7 months agodocker-compose: Update to version 2.27.0
Javier Marcet [Thu, 25 Apr 2024 17:25:35 +0000 (19:25 +0200)]
docker-compose: Update to version 2.27.0

Release notes:
https://github.com/docker/compose/releases/tag/v2.27.0

Signed-off-by: Javier Marcet <javier@marcet.info>
7 months agoMerge pull request #23991 from friendly-bits/master-geoip-shell
Dirk Brenken [Thu, 25 Apr 2024 17:20:47 +0000 (19:20 +0200)]
Merge pull request #23991 from friendly-bits/master-geoip-shell

geoip-shell: update to v0.5.2

7 months agolibqmi: add missing PKG_VERSION for APK
Florian Eckert [Thu, 25 Apr 2024 14:35:33 +0000 (16:35 +0200)]
libqmi: add missing PKG_VERSION for APK

The 'PKG_VERSION' string was missing and only 'PKG_SOURCE_VERSION' string
was used.

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
7 months agolibmbim: add missing PKG_VERSION for APK
Florian Eckert [Thu, 25 Apr 2024 14:35:01 +0000 (16:35 +0200)]
libmbim: add missing PKG_VERSION for APK

The 'PKG_VERSION' string was missing and only 'PKG_SOURCE_VERSION' string
was used.

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
7 months agolua-eco: update to 3.4.1
Jianhui Zhao [Wed, 24 Apr 2024 09:55:40 +0000 (17:55 +0800)]
lua-eco: update to 3.4.1

Signed-off-by: Jianhui Zhao <zhaojh329@gmail.com>
7 months agoMerge pull request #23911 from qosmio/nebula-fix-release-number
Stan Grishin [Thu, 25 Apr 2024 00:04:42 +0000 (17:04 -0700)]
Merge pull request #23911 from qosmio/nebula-fix-release-number

nebula: Use APK style release number

7 months agoMerge pull request #23907 from qosmio/nghttp3-fix-release-number
Stan Grishin [Thu, 25 Apr 2024 00:01:09 +0000 (17:01 -0700)]
Merge pull request #23907 from qosmio/nghttp3-fix-release-number

nghttp3: Use APK style release number

7 months agoMerge pull request #23908 from qosmio/ngtcp2-fix-release-number
Stan Grishin [Thu, 25 Apr 2024 00:00:56 +0000 (17:00 -0700)]
Merge pull request #23908 from qosmio/ngtcp2-fix-release-number

ngtcp2: Use APK style release number

7 months agoshairport-sync: support mqtt based remote control
David Andreoletti [Sat, 9 Mar 2024 15:08:04 +0000 (23:08 +0800)]
shairport-sync: support mqtt based remote control

Enable MQTT support to control shairport-sync remotely

Signed-off-by: David Andreoletti <david@andreoletti.net>
7 months agonatmap: add log_std{out,err} options
Ray Wang [Sat, 20 Apr 2024 14:53:03 +0000 (22:53 +0800)]
natmap: add log_std{out,err} options

Introduce `log_stdout` and `log_stderr` options for managing logging output.

Signed-off-by: Ray Wang <r@hev.cc>
7 months agonode: bump to v20.12.2
Hirokazu MORIKAWA [Wed, 24 Apr 2024 01:38:27 +0000 (10:38 +0900)]
node: bump to v20.12.2

This is a security release.

Notable Changes
* CVE-2024-27980 - Command injection via args parameter of child_process.spawn without shell option enabled on Windows

Signed-off-by: Hirokazu MORIKAWA <morikw2@gmail.com>
7 months agoperl: fix not a Mach-O file on macOS
Georgi Valkov [Sat, 20 Apr 2024 15:46:18 +0000 (18:46 +0300)]
perl: fix not a Mach-O file on macOS

Reverts [1] to resolve the following build error on macOS:

/Volumes/wrt3200/openwrt/staging_dir/hostpkg/usr/bin/perl installperl --destdir=/Volumes/wrt3200/openwrt/build_dir/target-arm_cortex-a9+vfpv3-d16_musl_eabi/perl/perl-5.38.2/ipkg-install
WARNING: You've never run 'make test' or some tests failed! (Installing anyway.)
  /usr/bin/perl5.38.2
error: /Applications/Xcode.app/Contents/Developer/Toolchains/XcodeDefault.xctoolchain/usr/bin/install_name_tool: input file: /Volumes/wrt3200/openwrt/build_dir/target-arm_cortex-a9+vfpv3-d16_musl_eabi/perl/perl-5.38.2/ipkg-install/usr/bin/perl5.38.2 is not a Mach-O file

[1] https://github.com/Perl/perl5/commit/88efce38149481334db7ddb932f9b74eaaa9765b

Signed-off-by: Georgi Valkov <gvalkov@gmail.com>
7 months agocni-plugins-nft: use local tarballs
Rosen Penev [Fri, 19 Apr 2024 23:13:45 +0000 (16:13 -0700)]
cni-plugins-nft: use local tarballs

Avoids having to override PKG_UNPACK.

Signed-off-by: Rosen Penev <rosenp@gmail.com>
7 months agocni-plugins: use local tarballs
Rosen Penev [Fri, 19 Apr 2024 23:17:56 +0000 (16:17 -0700)]
cni-plugins: use local tarballs

Avoids having to override PKG_UNPACK.

Signed-off-by: Rosen Penev <rosenp@gmail.com>
7 months agosnort3: use local tarballs
Rosen Penev [Sun, 21 Apr 2024 20:54:45 +0000 (13:54 -0700)]
snort3: use local tarballs

Avoids having a bad tarball name with just the version.

Signed-off-by: Rosen Penev <rosenp@gmail.com>