We are no longer offering accounts on this server. Consider https://gitlab.freedesktop.org/ as a place to host projects.

    • Rafał Miłecki's avatar
      opkg: bump to version 2017-12-08 · 70d7fbb8
      Rafał Miłecki authored
      This updates package to the latest commit from the lede-17.01 branch. It
      contains few fixes backported from the master:
      1) SHA256 fix
      2) URL encoding which allows hosting packages on some more picky servers
      9f61f7a opkg_download: decode file:/ URLs
      3c46c88 file_util: implement urldecode_path()
      79908c2 file_util: consolidate hex/unhex routines
      793fbac opkg: encode archive filenames while constructing download URLs
      a6bb5cb file_util: implement urlencode_path() helper
      098e774 libopkg: fix SHA256 calculation for big endian system
      Signed-off-by: default avatarRafał Miłecki <rafal@milecki.pl>
    • Timo Sigurdsson's avatar
      hostapd: backport fix for wnm_sleep_mode=0 · eed4bd81
      Timo Sigurdsson authored
      wpa_disable_eapol_key_retries can't prevent attacks against the Wireless
      Network Management (WNM) Sleep Mode handshake. Currently, hostapd
      processes WNM Sleep Mode requests from clients regardless of the setting
      wnm_sleep_mode. Backport Jouni Malinen's upstream patch 114f2830 in
      order to ignore such requests by clients when wnm_sleep_mode is disabled
      (which is the default).
      Signed-off-by: default avatarTimo Sigurdsson <public_timo.s@silentcreek.de>
      [rewrite commit subject (<= 50 characters), bump PKG_RELEASE]
      Signed-off-by: default avatarStijn Tintel <stijn@linux-ipv6.be>
      (cherry picked from commit bd45e15d0afe64dfed5a02a50a634f7947b50144
       fixed PKG_RELEASE and renumbered patch)
    • Timo Sigurdsson's avatar
      hostapd: Expose the tdls_prohibit option to UCI · a2c34fc5
      Timo Sigurdsson authored
      wpa_disable_eapol_key_retries can't prevent attacks against the
      Tunneled Direct-Link Setup (TDLS) handshake. Jouni Malinen suggested
      that the existing hostapd option tdls_prohibit can be used to further
      complicate this possibility at the AP side. tdls_prohibit=1 makes
      hostapd advertise that use of TDLS is not allowed in the BSS.
      Note: If an attacker manages to lure both TDLS peers into a fake
      AP, hiding the tdls_prohibit advertisement from them, it might be
      possible to bypass this protection.
      Make this option configurable via UCI, but disabled by default.
      Signed-off-by: default avatarTimo Sigurdsson <public_timo.s@silentcreek.de>
      (cherry picked from commit 6515887ed9b3f312635409702113dca7c14043e5)
    • Hans Dedecker's avatar
      dnsmasq: backport infinite dns retries fix · 026f2935
      Hans Dedecker authored
      If all configured dns servers return refused in response to a query in
      strict mode; dnsmasq will end up in an infinite loop retransmitting the
      dns query resulting into high CPU load.
      Problem is fixed by checking for the end of a dns server list iteration
      in strict mode.
      Signed-off-by: default avatarHans Dedecker <dedeckeh@gmail.com>
    • Stijn Segers's avatar
      curl: apply CVE 2017-8816 and 2017-8817 security patches · 8db3fba3
      Stijn Segers authored
      This commit adds the upstream patches for CVE 2017-8816 and 2017-8817 to the 17.01
      Curl package.
      Compile-tested on ar71xx, ramips and x86.
      Signed-off-by: default avatarStijn Segers <foss@volatilesystems.org>
    • Felix Fietkau's avatar
