Commit Graph

12338 Commits

Author SHA1 Message Date
Tianling Shen bd4e40fb04
dnsproxy: Update to 0.75.5
Add sysctl conf to increase UDP send/receive buffers for QUIC-GO.
Same as a920f9ec9c ("adguardhome: increase UDP send/receive buffers").

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-17 21:40:49 +08:00
Clair-Loup Sergent 87175e4ca3 wifi-presence: fix reading mqttID from config
Typo error in mqttID config value

Signed-off-by: Clair-Loup Sergent <sergent.cl@laposte.net>
2025-05-16 14:05:26 +01:00
Florian Eckert 0d18846dab xtables-addons: remove not needed iptables install dependency for RTSP helpers
The RTSP conntrack and nat does not dependent on iptables, but only on
nf_conntrack and nf_nat. The RTSP conntrack module is used as a helper in
firewall4 [1]. Previously, it was not possible to install RTSP kernel module
without also installing the not needed iptables modules. However, as firewall4
is based on nftables and not on iptables, this dependency is not necessary.

[1] https://github.com/openwrt/firewall4/blob/master/root/usr/share/firewall4/helpers#L89

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
2025-05-15 14:34:32 +02:00
Florian Eckert d221309637 modemmanager: backport fixes for version 1.24.0
The following commits were added shortly after the release of Modemmanager
version '1.24.0'.

Patch: 0002-modem-helpers-cinterion-allow-spaces-in-SXRAT-test-r.patch
Backport: 6b6997362b
Issue: https://gitlab.freedesktop.org/mobile-broadband/ModemManager/-/issues/974

Patch: 0003-modem-helpers-fix-checking-of-CDMA-EVDO-access-techn.patch
Backport: 9e205f4784
Issue: no

Patch: 0004-iface-modem-voice-recheck-call-state-polling-when-ca.patch
Backport: 92e666e1c9
Issue: no

Signed-off-by: Florian Eckert <fe@dev.tdt.de>
2025-05-15 14:33:22 +02:00
Wesley Gimenes c91e9322ce netbird: update to 0.43.3
changelog: https://github.com/netbirdio/netbird/releases/tag/v0.43.3

Signed-off-by: Wesley Gimenes <wehagy@proton.me>
2025-05-15 09:24:20 +02:00
Andris PE d63d5c202a net/bcp38: Add cgnat shared space to bcp38 list
Add CG-NAT address space to non-routable list
Mmake dhcp filter stricter

Signed-off-by: Andris PE <neandris@gmail.com>
2025-05-14 16:58:11 +02:00
Nikolay Manev 34c02108ce adblock-fast: improve the processing of combined list
Signed-off-by: Nikolay Manev <just.ops@proton.me>

adblock-fast: modify gawk statement

Signed-off-by: Nikolay Manev <just.ops@proton.me>
2025-05-13 09:42:43 -07:00
Stan Grishin aafff5ff98 https-dns-proxy: update to 2025.05.11
* update to 2025.05.11 from upstream: a34e20d6e2
* update default config with default value for procd_fw_src_interfaces

Signed-off-by: Stan Grishin <stangri@melmac.ca>
2025-05-12 15:53:36 -07:00
Toke Høiland-Jørgensen b3b67527c5 acme-acmesh: Bump to v3.1.1
Signed-off-by: Toke Høiland-Jørgensen <toke@toke.dk>
2025-05-12 16:11:14 +02:00
Tianling Shen 6e579e1a4e
dnsproxy: Update to 0.75.4
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-12 19:57:52 +08:00
Sander Schutten 1292d304ce wiki: openwrt naming fixes and contribution improvement
Signed-off-by: Sander Schutten <schutten@hotmail.com>
2025-05-11 21:22:01 +03:00
Joel Low 03088536db strongswan: preserve changed configuration files
After reinstalling the packages with the preserved configuration files
after a sysupgrade, the reinstalled package config files overwrite what
is on disk rather than being placed as conf-opkg. Defining these config
files will preserve them appropriately.

Signed-off-by: Joel Low <joel@joelsplace.sg>
2025-05-11 21:18:37 +03:00
Peter van Dijk 4ba4a69f88 pdns: update to 4.9.5
Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
2025-05-11 21:08:50 +03:00
Nikolay Manev 3d9eb08f8e adblock-fast: Fixed non-printable characters and bump PKG_VERSION
Signed-off-by: Nikolay Manev <just.ops@proton.me>
2025-05-11 10:04:26 -07:00
John Audia c851cf35c5 nfs-kernel-server: update to v2.8.3
Update to v2.8.3
Removed upstreamed: 210-patch-for-broken-libnfsimapd-static-and-regex-plugins.patch
Added: 210-nfsdctl.c-add-missing-basename.patch

Build system: x86/64
Build-tested: x86/64
Run-tested: x86/64

Signed-off-by: John Audia <therealgraysky@proton.me>
2025-05-10 09:00:41 +03:00
John Audia f2030e6256 nfs-kernel-server: update to v2.8.2
Update to latest release and change URL to official upstream mirror.

Removed upstreamed patch: 130-musl-svcgssd-sysconf.patch

Added new patch to correct host build error as we do not build with
gss enabled anyway: 100-fix-host-build.patch

Build system: x86/64
Build-tested: bcm27xx/bcm2712
Run-tested: bcm27xx/bcm2712

Signed-off-by: John Audia <therealgraysky@proton.me>
2025-05-10 09:00:41 +03:00
Eric Luehrsen a0df926a01 unbound: update to 1.23.0
Signed-off-by: Eric Luehrsen <ericluehrsen@gmail.com>
2025-05-09 21:52:16 +03:00
Tianling Shen 12b3f62910
cloudflared: Update to 2025.4.2
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-09 16:17:27 +08:00
Tianling Shen a91d278804
v2ray-geodata: Update to latest version
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-09 16:17:19 +08:00
Tianling Shen 051fdf7cab
v2ray-core: Update to 5.31.0
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-09 16:14:36 +08:00
Tianling Shen 72fafd38ea
xray-core: Update to 25.4.30
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-09 16:13:45 +08:00
Tianling Shen d2c2a47ff0
rclone: Update to 1.69.2
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-05-09 16:12:12 +08:00
Wesley Gimenes cef2fb9d8e netbird: update to 0.43.2
changelog: https://github.com/netbirdio/netbird/releases/tag/v0.43.2

Signed-off-by: Wesley Gimenes <wehagy@proton.me>
2025-05-09 10:11:54 +02:00
Stan Grishin 650fe4d62f pbr: bugfix: no errors on negated values
* do not display errors on negated values
* improved output in verbose mode

Signed-off-by: Stan Grishin <stangri@melmac.ca>
2025-05-08 19:36:22 -07:00
Lunatic Kochiya 2a1b4a2035 aria2: fix aira2-openssl install failed
Description: fix in full compile a firmware

    pkg_hash_check_unresolved: cannot find dependency aria2-openssl for aria2
    pkg_hash_fetch_best_installation_candidate: Packages for aria2 found, but incompatible with the architectures configured
    satisfy_dependencies_for: Cannot satisfy the following dependencies for luci-app-aria2:
    aria2-openssl
    opkg_install_cmd: Cannot install package luci-app-aria2.

Signed-off-by: Lunatic Kochiya <125438787@qq.com>
2025-05-04 01:51:25 +08:00
Dirk Brenken 52b51e30f4
adblock: update 4.4.1-2
* init improvements
* jail mode fixes and improvements
* small code cleanups
* update the readme

Signed-off-by: Dirk Brenken <dev@brenken.org>
2025-05-03 14:39:07 +02:00
Paul Donald 8102674b6d freeradius3: bump to 3.2.7
Changed source URL to github (faster/geo-redundancy).

build: x86_64
run tested: x86_64

```
 # radiusd -v
radiusd: FreeRADIUS Version 3.2.7, for host x86_64-openwrt-linux-gnu, built on Apr 18 2025 at 00:10:48
FreeRADIUS Version 3.2.7
```

Signed-off-by: Paul Donald <newtwen+github@gmail.com>
2025-05-02 09:19:18 +03:00
Rosen Penev ffe0cea2ff ntpd: update to 4.2.8p18
Add small patch fixing compilation with GCC14.

Remove inactive maintainer.

Signed-off-by: Rosen Penev <rosenp@gmail.com>
2025-05-01 23:10:30 +02:00
Rosen Penev 4014c0207e xfrpc: update to 4.04.856
Fixes compilation with GCC14.

Switch to local tarballs instead of codeload. Smaller archives.

Signed-off-by: Rosen Penev <rosenp@gmail.com>
2025-05-01 22:02:22 +02:00
Miroslav Lichvar 10e8e2bbe7 chrony: enable support for non-MD5 keys in nts variant
gnutls and nettle are already required for NTS. Enable their use for
authentication with non-MD5 symmetric keys as the SECHASH feature
printed by the configure script.

Also drop the --enable,nts (typo) configure option. It's enabled by
default.

Signed-off-by: Miroslav Lichvar <mlichvar0@gmail.com>
2025-05-01 20:12:04 +02:00
Peter van Dijk 7bc8022190 dnsdist: update to 1.9.9
fixes CVE-2025-30194

Signed-off-by: Peter van Dijk <peter.van.dijk@powerdns.com>
2025-05-01 17:16:38 +03:00
Anton P. c0a996ddd9 sing-box: Update to 1.11.9
changelog: https://github.com/SagerNet/sing-box/releases/tag/v1.11.9

Signed-off-by: Anton P. <dragunap@gmail.com>
[line break added after commit title, accidental line removal fixed]
2025-05-01 11:11:18 +03:00
Paul Donald 1f9afbf80d chrony: add configuration parameters
The existing config sections were anonymous, implying multiple can
coexist. Those are now named so that only one shall exist.

Added:
- smoothtime (in case of large frequency offsets)
- systemclock parameters
- logchange (increase awareness of clock drift in syslog)
- maxsources (for peers; internal default: 4)
- prefer (one server over others)
- interleave (xleave - more accurate transmit timestamps - good to have)

Refactored handle_allow() to handle 'list interface' instead of option.
Then only a single section is required.

Signed-off-by: Paul Donald <newtwen+github@gmail.com>
2025-05-01 11:00:14 +03:00
Antonio Pastor 7cd8b345e4 netatalk: update to 4.2.2
As of netatalk-4.2.0 the iniparser library is a prerequisite.

Signed-off-by: Antonio Pastor <antonio.pastor@gmail.com>
2025-05-01 10:57:32 +03:00
Antonio Pastor fa2eb8bf78 netatalk: fix small issues with sample config and config generation
Small issues with sample configureation caused services not to start
or flood log with errors.

Signed-off-by: Antonio Pastor <antonio.pastor@gmail.com>
2025-05-01 10:57:32 +03:00
Wesley Gimenes af32ef43f8 netbird: update to 0.43.1
changelog: https://github.com/netbirdio/netbird/releases/tag/v0.43.1

Signed-off-by: Wesley Gimenes <wehagy@proton.me>
2025-05-01 12:57:10 +08:00
Stijn Tintel a21eb339b3 keepalived: bump to 2.3.3
Remove backport patches that are included in this release.

Signed-off-by: Stijn Tintel <stijn@linux-ipv6.be>
2025-04-30 20:42:05 +02:00
Tianling Shen abec214201
v2ray-core: Update to 5.30.0
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-04-30 18:34:53 +08:00
Tianling Shen 9a3aef6f2c
dnsproxy: Update to 0.75.3
Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
2025-04-30 18:34:12 +08:00
Christian Korber dcad31d88c net-snmp: add system to trigger
In a previous commit (0b12bee) hostname was added to
snmpd.init. To track changes in system, the init file
needs to add 'system' to the trigger.
Therefore it is added in this commit.

Fixes: 0b12bee66a ("net-snmp: set hostname as sysname")

Signed-off-by: Christian Korber <ck@dev.tdt.de>
2025-04-30 13:20:23 +03:00
Rosen Penev 288836fe89 kea: update to 2.6.2
Add upstream backport for compatibility with Boost 1.87

Signed-off-by: Rosen Penev <rosenp@gmail.com>
2025-04-30 14:52:07 +08:00
Dirk Brenken 5402f8eea1
banIP: update 1.5.6-2
* add an uci-defaults script for housekeeping and option migration from former versions
* small fixes and improvements

Signed-off-by: Dirk Brenken <dev@brenken.org>
2025-04-29 21:55:55 +02:00
Daniel Golle 21744903b6 gnunet-fuse: update to 0.24.0
Update gnunet-fuse for the GNUnet 0.24.x major release.

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
2025-04-29 02:05:33 +01:00
Daniel Golle bbef797cda gnunet: update to 0.24.1
This is a new major release. It breaks protocol compatibility with the
0.23.x versions.

Please be aware that Git master is thus henceforth (and has been for a
while) INCOMPATIBLE with the 0.23.x GNUnet network, and interactions
between old and new peers will result in issues.

In terms of usability, users should be aware that there are still a
number of known open issues in particular with respect to ease of use,
but also some critical privacy issues especially for mobile users.

Also, the nascent network is tiny and thus unlikely to provide good
anonymity or extensive amounts of interesting information.
As a result, the 0.24.1 release is still only suitable for early
adopters with some reasonable pain tolerance. 

v0.24.1:

  - Fix crash in libgnunetpq when Postgresql database was restarted

  - Add configure and make functionality for new meson build
    (https://www.gnu.org/prep/standards/html_node/Configuration.html)

v0.24.0:

  - Meson is new default build system

  - JSON: split off libgnunetmhd from libgnunetjson, renaming various
    GNUNET_JSON_-symbols to GNUNET_MHD_-. Removes dependency of
    libgnunetjson on libmicrohttpd

OpenWrt package maintainer note:
Meson build is not yet fit for use in OpenWrt's cross build system.

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
2025-04-29 02:05:33 +01:00
Wesley Gimenes c3692c601e netbird: update to 0.43.0
changelog: https://github.com/netbirdio/netbird/releases/tag/v0.43.0

Signed-off-by: Wesley Gimenes <wehagy@proton.me>
2025-04-28 17:20:11 +08:00
Liangbin Lian d60028116d aria2: fix openssl legacy load failed
```
Mon Apr 21 13:30:56 2025 daemon.info aria2c[13301]: jail: exec-ing /usr/bin/aria2c
Mon Apr 21 13:30:56 2025 daemon.err aria2c[13301]: Exception caught
Mon Apr 21 13:30:56 2025 daemon.err aria2c[13301]: Exception: [Platform.cc:125] errorCode=1 OSSL_PROVIDER_load 'legacy' failed.
Mon Apr 21 13:30:56 2025 daemon.err aria2c[13301]:
Mon Apr 21 13:30:56 2025 daemon.info procd: Instance aria2::aria2.main s in a crash loop 6 crashes, 0 seconds since last crash
Mon Apr 21 13:30:56 2025 daemon.info aria2c[13301]: jail: jail (13302) exited with exit: 1

```

Links:
- https://github.com/aria2/aria2/issues/2152

Co-authored-by: Tianling Shen <cnsztl@gmail.com>
Signed-off-by: Liangbin Lian <jjm2473@gmail.com>
2025-04-28 13:13:42 +08:00
Kevin Locke e7aa0272db strongswan: swanctl: make overtime local
$overtime has been used since swanctl.init was added in f9d91f1f47.
However, there's no need for it to be global.  Make it local like the
other config variables to avoid polluting the global namespace and make
the code easier to reason about.

Fixes: f9d91f1f47 ("strongswan: migrate to swanctl configs")
Signed-off-by: Kevin Locke <kevin@kevinlocke.name>
2025-04-27 13:40:39 -06:00
Kevin Locke 62032567d3 strongswan: swanctl: make send_cert local
When support for send_cert was added in 4b9453b9a4, the $send_cert
variable was inadvertently global.  Make it local to avoid polluting the
global namespace and make the code easier to reason about.

Fixes: 4b9453b9a4 ("strongswan: Add support for send_cert option")
Signed-off-by: Kevin Locke <kevin@kevinlocke.name>
2025-04-27 13:40:39 -06:00
Kevin Locke c1cfb36e50 strongswan: swanctl: Add support for encap
Support the [encap] connection configuration option to force UDP
encapsulation of ESP packets to work around connectivity issues with
middleboxes which block ESP packets.

This work is based on a patch by @aleks-mariusz in
https://forum.openwrt.org/t/confusion-regarding-setting-up-ikev2-vpn-service-with-strongswan-using-ipsec-and-swanctl/169587/9

[encap]: https://docs.strongswan.org/docs/latest/swanctl/swanctlConf.html#_connections

Signed-off-by: Kevin Locke <kevin@kevinlocke.name>
2025-04-27 13:35:50 -06:00
Ignas Poklad cfb0de859f openfortivpn: upgrade to 1.23.1
add saml login support

Signed-off-by: Ignas Poklad <ignas2526@gmail.com>
2025-04-25 21:27:05 +08:00