- 10 10月, 2022 1 次提交
-
-
由 Hauke Mehrtens 提交于
Signed-off-by: NHauke Mehrtens <hauke@hauke-m.de>
-
- 09 10月, 2022 4 次提交
-
-
由 Christian Lamparter 提交于
Debian's changelog by Henrique de Moraes Holschuh <hmh@debian.org>: * New upstream microcode datafile 20220809 * Fixes INTEL-SA-00657, CVE-2022-21233 Stale data from APIC leaks SGX memory (AEPIC leak) * Fixes unspecified errata (functional issues) on Xeon Scalable * Updated Microcodes: sig 0x00050653, pf_mask 0x97, 2022-03-14, rev 0x100015e, size 34816 sig 0x00050654, pf_mask 0xb7, 2022-03-08, rev 0x2006e05, size 44032 sig 0x000606a6, pf_mask 0x87, 2022-04-07, rev 0xd000375, size 293888 sig 0x000706a1, pf_mask 0x01, 2022-03-23, rev 0x003c, size 75776 sig 0x000706a8, pf_mask 0x01, 2022-03-23, rev 0x0020, size 75776 sig 0x000706e5, pf_mask 0x80, 2022-03-17, rev 0x00b2, size 112640 sig 0x000806c2, pf_mask 0xc2, 2022-03-19, rev 0x0028, size 97280 sig 0x000806d1, pf_mask 0xc2, 2022-03-28, rev 0x0040, size 102400 sig 0x00090672, pf_mask 0x03, 2022-06-07, rev 0x0022, size 216064 sig 0x00090675, pf_mask 0x03, 2022-06-07, rev 0x0022, size 216064 sig 0x000906a3, pf_mask 0x80, 2022-06-15, rev 0x0421, size 216064 sig 0x000906a4, pf_mask 0x80, 2022-06-15, rev 0x0421, size 216064 sig 0x000a0671, pf_mask 0x02, 2022-03-17, rev 0x0054, size 103424 sig 0x000b06f2, pf_mask 0x03, 2022-06-07, rev 0x0022, size 216064 sig 0x000b06f5, pf_mask 0x03, 2022-06-07, rev 0x0022, size 216064 Signed-off-by: NChristian Lamparter <chunkeey@gmail.com> (cherry picked from commit bb73828b)
-
由 Nick Hainke 提交于
Changes: 9dc9c89 wireless-regdb: update regulatory database based on preceding changes 442bc25 wireless-regdb: update 5 GHz rules for PK and add 60 GHz rule daee7f3 wireless-regdb: add 5 GHz rules for GY Signed-off-by: NNick Hainke <vincent@systemli.org> (cherry picked from commit 1d2d69c8)
-
由 Stijn Tintel 提交于
902b321 wireless-regdb: Update regulatory rules for Israel (IL) 20f6f34 wireless-regdb: add missing spaces for US S1G rules 25652b6 wireless-regdb: Update regulatory rules for Australia (AU) 081873f wireless-regdb: update regulatory database based on preceding changes 166fbdd wireless-regdb: add db files missing from previous commit e3f03f9 Regulatory update for 6 GHz operation in Canada (CA) 888da5f Regulatory update for 6 GHz operation in United States (US) 647bcaa Regulatory update for 6 GHz operation in FI c6b079d wireless-regdb: update regulatory rules for Bulgaria (BG) on 6GHz 2ed39be wireless-regdb: Remove AUTO-BW from 6 GHz rules 7a6ad1a wireless-regdb: Unify 6 GHz rules for EU contries 68a8f2f wireless-regdb: update regulatory database based on preceding changes Signed-off-by: NStijn Tintel <stijn@linux-ipv6.be> (cherry picked from commit e3e9eb31)
-
由 Sungbo Eo 提交于
e061299 wireless-regdb: Raise DFS TX power limit to 250 mW (24 dBm) for the US 2ce78ed wireless-regdb: Update regulatory rules for Croatia (HR) on 6GHz 0d39f4c wireless-regdb: Update regulatory rules for South Korea (KR) acad231 wireless-regdb: Update regulatory rules for France (FR) on 6 and 60 GHz ea83a82 wireless-regdb: add support for US S1G channels 4408149 wireless-regdb: add 802.11ah bands to world regulatory domain 5f3cadc wireless-regdb: Update regulatory rules for Spain (ES) on 6GHz e0ac69b Revert "wireless-regdb: Update regulatory rules for South Korea (KR)" 40e5e80 wireless-regdb: Update regulatory rules for South Korea (KR) e427ff2 wireless-regdb: Update regulatory rules for China (CN) 0970116 wireless-regdb: Update regulatory rules for the Netherlands (NL) on 6GHz 4dac44b wireless-regdb: update regulatory database based on preceding changes Signed-off-by: NSungbo Eo <mans0n@gorani.run> (cherry picked from commit 19a90262)
-
- 06 10月, 2022 7 次提交
-
-
由 Oscar Molnar 提交于
python3.11 beta is out but fails to run the makefile currently this supports python versions from 3.6 to 3.99 with the python3 binary it also checks specifically for 3.11 as it is the latest version out Signed-off-by: NOscar Molnar <oscar@tymscar.com> (cherry picked from commit a9e8eec2) Signed-off-by: Michal Vasilek <michal.vasilek@nic.cz> [rebase for 21.02]
-
由 Hauke Mehrtens 提交于
Compile-tested: x86/64 Run-tested: x86/64 Signed-off-by: NHauke Mehrtens <hauke@hauke-m.de>
-
由 Petr Štetiar 提交于
As wolfSSL is having hard time maintaining ABI compatibility between releases, we need to manually force rebuild of packages depending on libwolfssl and thus force their upgrade. Otherwise due to the ABI handling we would endup with possibly two libwolfssl libraries in the system, including the patched libwolfssl-5.5.1, but still have vulnerable services running using the vulnerable libwolfssl-5.4.0. So in order to propagate update of libwolfssl to latest stable release done in commit ec8fb542 ("wolfssl: fix TLSv1.3 RCE in uhttpd by using 5.5.1-stable (CVE-2022-39173)") which fixes several remotely exploitable vulnerabilities, we need to bump PKG_RELEASE of all packages using wolfSSL library. Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit f1b7e143) (cherry picked from commit 562894b3)
-
由 Petr Štetiar 提交于
Fixes denial of service attack and buffer overflow against TLS 1.3 servers using session ticket resumption. When built with --enable-session-ticket and making use of TLS 1.3 server code in wolfSSL, there is the possibility of a malicious client to craft a malformed second ClientHello packet that causes the server to crash. This issue is limited to when using both --enable-session-ticket and TLS 1.3 on the server side. Users with TLS 1.3 servers, and having --enable-session-ticket, should update to the latest version of wolfSSL. Thanks to Max at Trail of Bits for the report and "LORIA, INRIA, France" for research on tlspuffin. Complete release notes https://github.com/wolfSSL/wolfssl/releases/tag/v5.5.1-stable Fixes: CVE-2022-39173 Fixes: https://github.com/openwrt/luci/issues/5962 References: https://github.com/wolfSSL/wolfssl/issues/5629Tested-by: NKien Truong <duckientruong@gmail.com> Reported-by: NKien Truong <duckientruong@gmail.com> Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit ec8fb542) (cherry picked from commit ce598436)
-
由 Ivan Pavlov 提交于
Remove upstreamed: 101-update-sp_rand_prime-s-preprocessor-gating-to-match.patch Some low severity vulnerabilities fixed OpenVPN compatibility fixed (broken in 5.4.0) Other fixes && improvements Signed-off-by: NIvan Pavlov <AuthorReflex@gmail.com> (cherry picked from commit 3d88f26d) (cherry picked from commit 0c8425bf)
-
由 Eneas U de Queiroz 提交于
This version fixes two vulnerabilities: -CVE-2022-34293[high]: Potential for DTLS DoS attack -[medium]: Ciphertext side channel attack on ECC and DH operations. The patch fixing x86 aesni build has been merged upstream. Signed-off-by: NEneas U de Queiroz <cotequeiroz@gmail.com> (cherry picked from commit 9710fe70) Signed-off-by: NChristian Marangi <ansuelsmth@gmail.com> (cherry picked from commit ade7c6db)
-
由 Eneas U de Queiroz 提交于
This is mostly a bug fix release, including two that were already patched here: - 300-fix-SSL_get_verify_result-regression.patch - 400-wolfcrypt-src-port-devcrypto-devcrypto_aes.c-remove-.patch Signed-off-by: NEneas U de Queiroz <cotequeiroz@gmail.com> (cherry picked from commit 73c1fe28) (cherry picked from commit 6f8db8fe)
-
- 04 10月, 2022 1 次提交
-
-
由 Rafał Miłecki 提交于
Fixes: edf33639 ("kernel: backport mtd dynamic partition patch") Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit a5265497)
-
- 03 10月, 2022 1 次提交
-
-
由 Rafał Miłecki 提交于
Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 77d9cce6)
-
- 30 9月, 2022 2 次提交
-
-
由 Chris Osgood 提交于
Fixes build warnings when using newer versions of grep. Signed-off-by: NChris Osgood <chris_github@functionalfuture.com> Tested-by: NGeorgi Valkov <gvalkov@gmail.com> (cherry picked from commit c5e167e0) [ fix conflict error ] Signed-off-by: NChristian Marangi <ansuelsmth@gmail.com>
-
由 Nick Hainke 提交于
We simply grep for "/usr". So no need for "-E" or "\/". Furthermore, in the new grep versions this creates warnings. As written in the grep-3.8 announcement: Regular expressions with stray backslashes now cause warnings, as their unspecified behavior can lead to unexpected results. For example, '\a' and 'a' are not always equivalent <https://bugs.gnu.org/39678>. Fixes warnings in the form of: grep: warning: stray \ before / Signed-off-by: NNick Hainke <vincent@systemli.org> (cherry picked from commit a29d3bc4) [ fix conflict error ] Signed-off-by: NChristian Marangi <ansuelsmth@gmail.com>
-
- 25 9月, 2022 3 次提交
-
-
由 Federico Capoano 提交于
Fixes following missing kernel config symbol after adding GPIO watchdog: Software watchdog (SOFT_WATCHDOG) [M/n/y/?] m Watchdog device controlled through GPIO-line (GPIO_WATCHDOG) [Y/n/m/?] y Register the watchdog as early as possible (GPIO_WATCHDOG_ARCH_INITCALL) [N/y/?] (NEW) Fixes: 1a97c03d ("rampis: feed zbt-we1026 external watchdog") Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit fb2801b8) [adapted to config-5.4] Signed-off-by: NFederico Capoano <f.capoano@openwisp.io>
-
由 Federico Capoano 提交于
Without feeding the gpio watchdog, the board will reset after 90 seconds Signed-off-by: NArvid E. Picciani <aep@exys.org> (cherry picked from commit 1a97c03d) [adapted to config-5.4] Signed-off-by: NFederico Capoano <f.capoano@openwisp.io>
-
由 Alexey Smirnov 提交于
This patch adds support for creation heartbeat led trigger with, for example, this command: ucidef_set_led_heartbeat "..." "..." "..." from /etc/board.d/01_leds. Signed-off-by: NAlexey Smirnov <s.alexey@gmail.com> (cherry picked from commit 66071729)
-
- 21 9月, 2022 13 次提交
-
-
由 Petr Štetiar 提交于
Several users of wget for downloads (curl is not available in the system) have reported broken download functionality: wget --tries=5 --timeout=20 --output-document=- https://cdn.kernel.org/pub/linux/kernel/v5.x/linux-5.10.142.tar.xz http://: Invalid host name. Thats all happening due to '' was passed as an argument, which got later expanded to http://. In the context of a list constructor '' is not nothing, it is an empty string element. So fix it by using () as it will yield "nothing" and thus not introduce an empty string element. Fixes: #10692 Fixes: 90c6e3ae ("scripts: always check certificates") Signed-off-by: Jo-Philipp Wich <jo@mein.io> [shellwords() -> ()] Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit 50a48faa)
-
由 Petr Štetiar 提交于
When running build in verbose mode `make V=s` we can see a lot of following warnings when curl is not available in the system: Can't exec "curl": No such file or directory at scripts/download.pl line 77. So lets fix it by redirecting of the stderr to null hole. Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit c836ca84)
-
由 Josh Roys 提交于
Remove flags from wget and curl instructing them to ignore bad server certificates. Although other mechanisms can protect against malicious modifications of downloads, other vectors of attack may be available to an adversary. TLS certificate verification can be disabled by turning oof the "Enable TLS certificate verification during package download" option enabled by default in the "Global build settings" in "make menuconfig" Signed-off-by: NJosh Roys <roysjosh@gmail.com> [ add additional info on how to disable this option ] Signed-off-by: NChristian Marangi <ansuelsmth@gmail.com> Signed-off-by: Petr Štetiar <ynezz@true.cz> [backport] (cherry picked from commit 90c6e3ae)
-
由 Petr Štetiar 提交于
It shouldn't be needed anymore as we've now `scripts/xxdi.pl`, which should be self contained and fully compatible `xxd -i` replacement. Fixes: #10555 Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit 88c9056a)
-
由 Petr Štetiar 提交于
Dependency on xxd was added in commit c4dd2441 ("tools: add xxd (from vim)") as U-Boot requires xxd to create the default environment from an external file. Later in commit 2b94aac7 ("tools: xxd: use more convenient source tarball"), xxd from another source was used instead, but that source is currently unavailable, so let's fix it by using simple xxdi.pl Perl script instead. Fixes: #10555 Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit eae2fb80)
-
由 Petr Štetiar 提交于
So it can serve as a standalone drop in replacement for xxd utility used currently mostly in U-Boot packages with `xxd -i` mode which outputs C include file style, with aim for byte to byte identical output, so the eventual difference in the generated output is easily spottable. Fixes: #10555 Signed-off-by: NPetr Štetiar <ynezz@true.cz> Signed-off-by: Jo-Philipp Wich <jo@mein.io> [perl-fu] (cherry picked from commit 06e01e81)
-
由 Jo-Philipp Wich 提交于
In order to make it more portable. Signed-off-by: NJo-Philipp Wich <jo@mein.io> Signed-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit 8b278a76)
-
由 Petr Štetiar 提交于
xxdi.pl is a Perl script that implements vim's 'xxd -i' mode so that packages do not have to use all of vim just to get this functionality. References: #10555 Source: https://github.com/gregkh/xxdi/blob/97a6bd5cee05d1b15851981ec38ef5a460ddfcb1/xxdi.plSigned-off-by: NPetr Štetiar <ynezz@true.cz> (cherry picked from commit 2117d04a)
-
由 Rafał Miłecki 提交于
Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 1722e23f)
-
由 Rafał Miłecki 提交于
1. Fix casting 2. Support DT-defined variables Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 5652f378)
-
由 Rafał Miłecki 提交于
Broadcom's U-Boot contains environment data blocks. They need to be found (offsets aren't predefined) to access env variables. Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 13714984)
-
由 Rafał Miłecki 提交于
Include support for NVMEM cells. Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 2f50c53f)
-
由 Christian Marangi 提交于
Backport upstream solution that permits to declare nvmem cells with dynamic partition defined by special parser. This provide an OF node for NVMEM and connect it to the defined dynamic partition. Signed-off-by: NChristian Marangi <ansuelsmth@gmail.com> Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 1a9ee367)
-
- 17 9月, 2022 1 次提交
-
-
由 Hauke Mehrtens 提交于
Manually adapted: layerscape/patches-5.4/820-usb-0009-usb-dwc3-Add-workaround-for-host-mode-VBUS-glitch-wh.patch Compile-tested: x86/64 Run-tested: x86/64 Signed-off-by: NHauke Mehrtens <hauke@hauke-m.de>
-
- 13 9月, 2022 1 次提交
-
-
由 Rafał Miłecki 提交于
This fixes: [ 0.292536] ns-pinmux 1800c100.cru:pinctrl: invalid resource [ 0.298322] ns-pinmux 1800c100.cru:pinctrl: Failed to map pinctrl regs [ 0.305578] ns-pinmux: probe of 1800c100.cru:pinctrl failed with error -22 Linux 5.4.157 included commit 6d0b30784fcd9 ("Revert "pinctrl: bcm: ns: support updated DT binding as syscon subnode"") which makes pinctrl driver expect the old DT syntax. Drop downstream patch switching pinctrl node to the invalidated syntax. Fixes: 0b731130 ("kernel: bump 5.4 to 5.4.158") Signed-off-by: NRafał Miłecki <rafal@milecki.pl>
-
- 05 9月, 2022 3 次提交
-
-
由 Rafał Miłecki 提交于
It's needed for devices with U-Boot bootloader. Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit fb47b9fa)
-
由 Rafał Miłecki 提交于
It parses U-Boot env data into NVMEM cells. Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 34cf3104)
-
由 Rafał Miłecki 提交于
This is required for non-parser drivers handling MTD devices. Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 41e1e838)
-
- 04 9月, 2022 1 次提交
-
-
由 Hauke Mehrtens 提交于
Similar version was upstreamed: bcm27xx/patches-5.4/950-0392-tty-amba-pl011-Add-un-throttle-support.patch Manually adapted: ipq806x/patches-5.4/0063-2-tsens-support-configurable-interrupts.patch layerscape/patches-5.4/301-arch-0008-arm-add-new-non-shareable-ioremap.patch Compile-tested: x86/64 Run-tested: x86/64 Signed-off-by: NHauke Mehrtens <hauke@hauke-m.de>
-
- 02 9月, 2022 2 次提交
-
-
由 Rafał Miłecki 提交于
Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 372ee191)
-
由 Rafał Miłecki 提交于
Without packet steering NAT masquarade speed on BCM4908 /jumps/ between two speeds: 1. 826 Mb/s (±3 Mb/s) 2. 909 Mb/s (±8 Mb/s) and it never reaches ~940 Mb/s. Proper packet steering can improve it. Below are testing results for running iperf TCP traffic from LAN to WAN. They were used to pick up golden values. ┌──────────┬──────────┬───────────┐ │ eth0 │ br-lan │ speed │ │ rps_cpus │ rps_cpus │ [Mbps] │ ├──────────┼──────────┼───────────┤ │ 0 │ 0 │ 743 / 804 │ │ 0 │ 1 │ 738 / 821 │ │ 0 │ 2 │ ✓ 940 │ │ 0 │ 4 │ ✓ 938 │ │ 0 │ 8 │ ✓ 941 │ ├──────────┼──────────┼───────────┤ │ 1 │ 0 │ 829 │ │ 1 │ 1 │ 829 │ │ 1 │ 2 │ ✓ 942 │ │ 1 │ 4 │ ✓ 941 │ │ 1 │ 8 │ ✓ 941 │ ├──────────┼──────────┼───────────┤ │ 2 │ 0 │ ✓ 942 │ │ 2 │ 1 │ 926 │ │ 2 │ 2 │ ✓ 942 │ │ 2 │ 4 │ ✓ 942 │ │ 2 │ 8 │ ✓ 941 │ ├──────────┼──────────┼───────────┤ │ 4 │ 0 │ ✓ 941 │ │ 4 │ 1 │ 925 │ │ 4 │ 2 │ ✓ 941 │ │ 4 │ 4 │ ✓ 941 │ │ 4 │ 8 │ ✓ 941 │ ├──────────┼──────────┼───────────┤ │ 8 │ 0 │ ✓ 942 │ │ 8 │ 1 │ 925 │ │ 8 │ 2 │ ✓ 941 │ │ 8 │ 4 │ ✓ 942 │ │ 8 │ 8 │ ✓ 942 │ └──────────┴──────────┴───────────┘ Ref: fcbd3968 ("bcm53xx: enable & setup packet steering") Signed-off-by: NRafał Miłecki <rafal@milecki.pl> (cherry picked from commit 57cad53f)
-