Re: [LEDE-DEV] [RFC] iproute2: update to v4.10.0

2017-03-20 Thread Kevin Darbyshire-Bryant
On 20/03/17 12:35, Yousong Zhou wrote: On 19 March 2017 at 20:38, Russell Senior wrote: Thanks to Syrone Wong for the pointer to UAPI fixes. This builds now, at least on x86/geode. It would be nice to have some testing. Signed-off-by: Russell Senior --- Tested-by: Yousong Zhou CC jo

Re: [LEDE-DEV] [RFC] iproute2: update to v4.10.0

2017-03-20 Thread Kevin Darbyshire-Bryant
On 20/03/17 19:54, Russell Senior wrote: Kevin> Was this tested on a 4.4 kernel? When I tried it wouldn't Kevin> compile (but it was a quick 5 seconds before I had to run out the Kevin> door type test, so I could have done summit stooopid) I tested ip-tiny on a Buffalo WZR600DHP (ar71xx):

Re: [LEDE-DEV] [RFC] iproute2: update to v4.10.0

2017-03-22 Thread Kevin Darbyshire-Bryant
On 22/03/17 07:13, Russell Senior wrote: "Syrone" == Syrone Wong writes: Syrone> either runtime dependency ``` DEPENDS:=+kmod-sched-core Syrone> +iptables ``` Syrone> or build-time dependency Syrone> ``` PKG_BUILD_DEPENDS:=iptables ``` Syrone> Don't add both of them. That does not fix th

Re: [LEDE-DEV] [PATCH v4] dnsmasq: also write /tmp/resolv.conf when UCI dhcp.dnsmasq.noresolv is '1'

2017-05-14 Thread Kevin Darbyshire-Bryant
On 14/05/17 17:48, Alberto Bursi wrote: On 05/14/2017 02:46 PM, Paul Oranje wrote: fixes FS#785 --- v4: place patch version info in annotation (not in commit message, afraid this is learning by practice) v3: corrected typo (noreolv) v2: also change guard in dnsmasq_stop() routine v

[LEDE-DEV] [PATCH] kernel: bump to 4.4.68

2017-05-15 Thread Kevin Darbyshire-Bryant
pped from LEDE. As it has now been reverted upstream it needs to be included again for LEDE. Run tested ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 +- .../525-MIPS-ath79-enable-qca-usb-quirks.patch | 8 +- .../601-

[LEDE-DEV] [PATCH] dropbear: bump to 2017.75

2017-05-19 Thread Kevin Darbyshire-Bryant
ch to work with new authorized_keys validation. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dropbear/Makefile | 6 +++--- .../dropbear/patches/100-pubkey_path.patch | 24 +- 2 files changed, 13 insertions(+), 17 deletions(-) diff --

[LEDE-DEV] [PATCH v2] dropbear: bump to 2017.75

2017-05-20 Thread Kevin Darbyshire-Bryant
_keys validation. Signed-off-by: Kevin Darbyshire-Bryant --- [v2] Update description to include CVE references package/network/services/dropbear/Makefile | 6 +++--- .../dropbear/patches/100-pubkey_path.patch | 24 +- 2 files changed, 13 insertions(+

[LEDE-DEV] [PATCH v3] dropbear: bump to 2017.75

2017-05-20 Thread Kevin Darbyshire-Bryant
_keys validation. Signed-off-by: Kevin Darbyshire-Bryant --- [v2] Update description to include CVE references [v3] Fix typo in one CVE reference package/network/services/dropbear/Makefile | 6 +++--- .../dropbear/patches/100-pubkey_path.patch | 24 +- 2

[LEDE-DEV] [PATCH] dropbear: limit max auth tries from 10 to 3

2017-05-27 Thread Kevin Darbyshire-Bryant
10 attempts at login before dropping connection is too many, 3 tries and you're out. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dropbear/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package/network/services/dropbear/Makefi

Re: [LEDE-DEV] [PATCH] dropbear: limit max auth tries from 10 to 3

2017-05-27 Thread Kevin Darbyshire-Bryant
On 27/05/17 18:22, Florian Fainelli wrote: > > > On 05/27/2017 04:11 AM, Kevin Darbyshire-Bryant wrote: >> 10 attempts at login before dropping connection is too many, 3 tries and >> you're out. > > This sounds like something we may want to be configured vi

Re: [LEDE-DEV] dnsmasq & gcc 7.1.0

2017-05-28 Thread Kevin Darbyshire-Bryant
On 28/05/17 08:02, e9hack wrote: Hi, if I select gcc 7.1.0 instead of gcc 6.3.0, anything seems to be work with exception of dropbear and dnsmasq. It does run two processes of dnsmasq. One runs as user root and the other as user dnsmasq. DHCP and name resolution does work. It occurs on all

Re: [LEDE-DEV] dropbear & gcc 7.1.0

2017-05-29 Thread Kevin Darbyshire-Bryant
On 29/05/17 16:54, e9hack wrote: Am 29.05.2017 um 10:13 schrieb Bastian Bittorf: * Syrone Wong [29.05.2017 10:03]: have you tried to '/etc/init.d/dropbear'? The problem is you cannot access the router, which means you cannot execute any commands. ok, maybe you can execute a command with Lu

Re: [LEDE-DEV] Archer c7 corrupted firmware bootloop - tftp aborting - serial not working

2017-06-01 Thread Kevin Darbyshire-Bryant
On 01/06/17 09:27, QWeRKUS qwErkus wrote: Hello, Something went wrong with my last flash of an archer c7 v2, and now the device refuses to boot. I'm trying to unbrick it without success since. Wasted tons of hours on this, and would really be thankful for any advice/pointers. Advice that

[LEDE-DEV] [PATCH] dnsmasq: bump to 2.77

2017-06-01 Thread Kevin Darbyshire-Bryant
Bump to the 2.77 release after quite a few test & release candidates. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dnsmasq/Makefile | 8 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/package/network/services/dnsmasq/Makefile b/package/net

[LEDE-DEV] ATH10K-CT debug messages

2017-06-04 Thread Kevin Darbyshire-Bryant
FAO that nice Mr Greer, I'm getting (for free) a nice selection of ath10 debug messages when using the Ath10K-ct firmware & driver in LEDE. A small collection reproduced below. Are they of any interest/use? [ 60.808281] ath10k: []: 73060100 0500FC17 70201031 0800 8000 B8F74000

Re: [LEDE-DEV] ATH10K-CT debug messages

2017-06-06 Thread Kevin Darbyshire-Bryant
On 05/06/17 18:45, Ben Greear wrote: On 06/04/2017 03:40 AM, Kevin Darbyshire-Bryant wrote: FAO that nice Mr Greer, I'm getting (for free) a nice selection of ath10 debug messages when using the Ath10K-ct firmware & driver in LEDE. A small collection reproduced below. Are th

[LEDE-DEV] [PATCH] gcc: gcc 6.3.0 fix comparison between pointer and integer

2017-06-09 Thread Kevin Darbyshire-Bryant
nd integer [-fpermissive] || xloc.file == '\0' || xloc.file[0] == '\xff' ^~~~ make[5]: *** [Makefile:1085: ubsan.o] Error 1 https://www.viva64.com/en/b/0425/#ID0EMGCI Signed-off-by: Kevin Darbyshire-Bryant --- toolchain/gcc/patches/6.3.0/960-fix-ubsan-de

[LEDE-DEV] [PATCH] ar71xx: fixup ar71xx/ar933x_wmac_reset: remove indefinite wait for wmac reset

2017-06-11 Thread Kevin Darbyshire-Bryant
Fix malformed patch introduced by 296312fca13a4cab1d157e0474e1f0bcca6adf5c Signed-off-by: Kevin Darbyshire-Bryant --- .../linux/ar71xx/patches-4.4/200-MIPS-ath79-fix-ar933x-wmac-reset.patch | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/target/linux/ar71xx/patches-4.4/200

Re: [LEDE-DEV] [PATCH v2] ramips: add support for Ubiquiti EdgeRouter X-SFP

2017-06-13 Thread Kevin Darbyshire-Bryant
On 12/06/17 21:00, Toke Høiland-Jørgensen wrote: p.wa...@gmx.at writes: My SQM configuration was basically just using cake + piece_of_cake.qos, but that's clearly off topic for now. (I'm also CC'ing this mail to Toke, the maintainer of sqm-scripts). If you're crashing the box my guess would

[LEDE-DEV] [PATCH] dropbear: fix service trigger syntax error

2017-06-15 Thread Kevin Darbyshire-Bryant
The classic single '&' when double '&&' conditional was meant. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dropbear/files/dropbear.init | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/network/services/dropbea

[LEDE-DEV] [PATCH v2] dropbear: fix service trigger syntax error

2017-06-15 Thread Kevin Darbyshire-Bryant
The classic single '&' when double '&&' conditional was meant. Signed-off-by: Kevin Darbyshire-Bryant --- v2 - bump pkg release number - always forget that! package/network/services/dropbear/Makefile| 2 +- package/network/services/dropbear/fil

[LEDE-DEV] [PATCH] hostapd: add support for acs_chan_bias option

2017-06-15 Thread Kevin Darbyshire-Bryant
During auto channel selection we may wish to prefer certain channels over others. e.g. we can just squeeze 4 channels into europe so '1:0.8 5:0.8 9:0.8 13:0.8' does that. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/hostapd/Makefile | 2 +- packa

[LEDE-DEV] [PATCH v3] dropbear: fix service trigger syntax error

2017-06-15 Thread Kevin Darbyshire-Bryant
The classic single '&' when double '&&' conditional was meant. Signed-off-by: Kevin Darbyshire-Bryant --- v2 - bump the version v3 - bump the version correctly - this is what happens when you have 2 different tweaks for the same package in your work tree an

[LEDE-DEV] [PATCH] kmod-sched-cake: drop maintainer

2017-06-16 Thread Kevin Darbyshire-Bryant
Drop myself from maintainership of 'cake'. Signed-off-by: Kevin Darbyshire-Bryant --- I've tried to find someone to take over the maintainership but failed. package/kernel/kmod-sched-cake/Makefile | 1 - 1 file changed, 1 deletion(-) diff --git a/package/kernel/kmod-sched-c

[LEDE-DEV] [PATCH] linux: bump to 4.4.73

2017-06-17 Thread Kevin Darbyshire-Bryant
bump to 4.4.73 & refresh patches. Compile & run tested: ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk| 4 ++-- .../patches-4.4/202-MIPS-ath79-ar934x-wmac-revision.patch| 2 +- ...-MIPS-ath79-add-mac-

[LEDE-DEV] [PATCH 2/2] dropbear: limit max auth tries from 10 to 3

2017-06-25 Thread Kevin Darbyshire-Bryant
10 attempts at login before dropping connection is too many, 3 tries and you're out. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dropbear/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package/network/services/dropbear/Makefi

[LEDE-DEV] [PATCH 1/2] dropbear: server support option '-T' max auth tries

2017-06-25 Thread Kevin Darbyshire-Bryant
defaults to MAX_AUTH_TRIES for backwards compatibility. Signed-off-by: Kevin Darbyshire-Bryant --- This patch has been accepted upstream: https://github.com/mkj/dropbear/commit/e2551012993ea913e23012774330da926366487f .../patches/010-runtime-maxauthtries.patch | 130 +

[LEDE-DEV] [PATCH] kernel: update kernel 4.4 to version 4.4.80

2017-08-07 Thread Kevin Darbyshire-Bryant
refresh patches minor rework 704-phy-no-genphy-soft-reset.patch which was partially accepted upstream. Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk| 4 ++-- .../680-NET-skip-GRO-for-foreign-MAC-addresses.patch | 10 +- .../generic

[LEDE-DEV] [PATCH] kernel: update kernel 4.4 to version 4.4.81

2017-08-12 Thread Kevin Darbyshire-Bryant
refresh patches minor update 704-phy-no-genphy-soft-reset.patch which was partially accepted upstream. Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- ...80-NET-skip-GRO-for-foreign-MAC-addresses.patch | 10 +- .../generic/pending

[LEDE-DEV] [PATCH] kernel: update kernel 4.4 to version 4.4.82

2017-08-13 Thread Kevin Darbyshire-Bryant
refresh patches minor update 704-phy-no-genphy-soft-reset.patch which was partially accepted upstream. Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- .../pending-4.4/630-packet_socket_type.patch | 4 ++-- ...80-NET-skip-GRO-for

[LEDE-DEV] [PATCH] kernel: update kernel 4.4 to version 4.4.83

2017-08-17 Thread Kevin Darbyshire-Bryant
refresh patches minor update 704-phy-no-genphy-soft-reset.patch which was partially accepted upstream. CVE-2017-7533fixed 4.4.80 CVE-2017-1000111 fixed 4.4.82 CVE-2017-1000112 fixed 4.4.82 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4

[LEDE-DEV] [PATCH,v2] kernel: update kernel 4.4 to version 4.4.83

2017-08-17 Thread Kevin Darbyshire-Bryant
refresh patches minor update 704-phy-no-genphy-soft-reset.patch which was partially accepted upstream. CVE-2017-7533fixed 4.4.80 CVE-2017-1000111 fixed 4.4.82 CVE-2017-1000112 fixed 4.4.82 Signed-off-by: Kevin Darbyshire-Bryant --- v2 - rebased on master - cope with 4.9 bump include

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.83 17.01

2017-08-17 Thread Kevin Darbyshire-Bryant
Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- .../patches-4.4/0029-Add-dwc_otg-driver.patch | 2 +- .../0111-mm-Remove-the-PFN-busy-warning.patch | 2 +- ...elease_resource-against-resources-without.patch | 2 +- .../patches-4.4/630

[LEDE-DEV] [PATCH 2/2] toolchain: gcc: drop MIPS patch

2017-08-22 Thread Kevin Darbyshire-Bryant
2058628 O2-withpatch-dropbearworks.bin 11468804 Os-withoutpatch-dropbearworks.bin 11468804 Os-withpatch-dropbearfails.bin Signed-off-by: Kevin Darbyshire-Bryant --- .../7.2.0/300-mips_Os_cpu_rtx_cost_model.patch | 21 - 1 file changed, 21 deletions(-) delete mode 100644 too

[LEDE-DEV] [PATCH 1/2] toolchain: gcc: update 7.x to 7.2.0

2017-08-22 Thread Kevin Darbyshire-Bryant
Signed-off-by: Kevin Darbyshire-Bryant --- toolchain/gcc/Config.version | 2 +- toolchain/gcc/common.mk| 5 +- .../7.1.0/001-revert_register_mode_search.patch| 65 .../gcc/patches/7.1.0/002-case_insensitive.patch | 14 -- .../gcc/

Re: [LEDE-DEV] [PATCH 2/2] toolchain: gcc: drop MIPS patch

2017-08-23 Thread Kevin Darbyshire-Bryant
On 23/08/17 09:20, Felix Fietkau wrote: On 2017-08-22 12:01, Kevin Darbyshire-Bryant wrote: Drop 300-mips_Os_cpu_rtx_cost_model.patch for gcc 7.2 This was causing mis-compilation of dropbear with the default '-Os' size optimization as reported in FS#814 Tested on ar71xx, archer C

Re: [LEDE-DEV] [PATCH 2/2] toolchain: gcc: drop MIPS patch

2017-08-23 Thread Kevin Darbyshire-Bryant
On 23/08/17 09:20, Felix Fietkau wrote: On 2017-08-22 12:01, Kevin Darbyshire-Bryant wrote: Drop 300-mips_Os_cpu_rtx_cost_model.patch for gcc 7.2 This was causing mis-compilation of dropbear with the default '-Os' size optimization as reported in FS#814 Tested on ar71xx, archer C

Re: [LEDE-DEV] [PATCH 2/2] toolchain: gcc: drop MIPS patch

2017-08-24 Thread Kevin Darbyshire-Bryant
On 23/08/17 18:25, Arjen de Korte wrote: While removing the MIPS patch fixes dropbear when using gcc 7.1.0 and '-Os', uhttpd goes tits up with a segfault in liblua. With '-O2' it's fine for both, so I'll probably stick with that for now. What about with gcc 7.2.0? _

Re: [LEDE-DEV] [PATCH] busybox: update to 1.27.2

2017-08-24 Thread Kevin Darbyshire-Bryant
ar71xx Archer c7 - nothing obvious has gone BOOOM! Signed-off-by: Kevin Darbyshire-Bryant ___ Lede-dev mailing list Lede-dev@lists.infradead.org http://lists.infradead.org/mailman/listinfo/lede-dev

Re: [LEDE-DEV] [PATCH 2/2] musl: bump to latest 1.1.16+ git HEAD

2017-08-24 Thread Kevin Darbyshire-Bryant
Run tested ar71xx Archer c7 - nothing obvious has gone BOOOM! Signed-off-by: Kevin Darbyshire-Bryant ___ Lede-dev mailing list Lede-dev@lists.infradead.org http://lists.infradead.org/mailman/listinfo/lede-dev

Re: [LEDE-DEV] [PATCH 2/2] samba36: Don't resolve interfaces.

2017-08-25 Thread Kevin Darbyshire-Bryant
local patch for exactly the same reasons, especially the buggy ipv6 subnet expansion. I tried a couple of times to get mine into LEDE but it got lost in the noise. So I'll add my voice to this in the hope it doesn't meet the same fate :-) LVGTM Acked-by

[LEDE-DEV] IPv6 link locals, vlans and bridging

2017-08-25 Thread Kevin Darbyshire-Bryant
Here's a 'fun' one that I'm trying to work who is doing what incorrectly. For 'reasons' I have a number of tagged vlan ethernet interfaces. I also have a similar number of wifi interfaces. These vlan ethernet interfaces and wifi interfaces are bridged together in pairs. The wifi interfaces

Re: [LEDE-DEV] IPv6 link locals, vlans and bridging

2017-08-25 Thread Kevin Darbyshire-Bryant
On 25/08/17 15:35, Matthew McClintock wrote: > On Fri, Aug 25, 2017 at 8:16 AM, Kevin Darbyshire-Bryant > wrote: >> Here's a 'fun' one that I'm trying to work who is doing what incorrectly. > Just a random bit of info, I've had dnsmasq issu

Re: [LEDE-DEV] IPv6 link locals, vlans and bridging

2017-08-26 Thread Kevin Darbyshire-Bryant
On 25/08/17 14:54, Baptiste Jonglez wrote: On 25-08-17, Kevin Darbyshire-Bryant wrote: Are you sure it's related to your complex bridging setup? Maybe dnsmasq just fails to answer on link-local IPv6 addresses in all cases? This was already reported before: https://bugs.lede-projec

[LEDE-DEV] [PATCH] dnsmasq: mitigate CVE-2017-13704

2017-08-28 Thread Kevin Darbyshire-Bryant
clear to end of buffer it is bigger than the request length. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dnsmasq/Makefile | 2 +- .../020-rfc1035-mitigate-CVE-2017-13704.patch | 35 ++ 2 files changed, 36 insertions(+), 1 deletion

[LEDE-DEV] [PATCH] dnsmasq: forward.c: fix CVE-2017-13704

2017-08-29 Thread Kevin Darbyshire-Bryant
size provided by the client is bounded by 512 and configured maximum as per RFC 6891 6.2.3 "Values lower than 512 MUST be treated as equal to 512" The client that exposed the problem provided a payload udp size of 0. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dn

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.85

2017-08-30 Thread Kevin Darbyshire-Bryant
Refresh patches Compile & run tested: ar71xx - Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk| 4 ++-- target/linux/ar71xx/patches-4.4/910-unaligned_access_hacks.patch | 2 +- 2 files changed, 3 insertions(+

[LEDE-DEV] [PATCH] kernel: refresh 4.4 phy drivers patch

2017-09-01 Thread Kevin Darbyshire-Bryant
Tidy up fuzz in 002-phy_drivers_backport.patch due to recent commits to out of tree phy drivers implementing get_port_stats() Phy driver commits: 0369e35, 3056d09, 4ddbc43, 4d8a66d Signed-off-by: Kevin Darbyshire-Bryant --- .../pending-4.4/002-phy_drivers_backport.patch | 34

[LEDE-DEV] [PATCH] mbedtls: update to 2.6.0 CVE-2017-14032

2017-09-01 Thread Kevin Darbyshire-Bryant
ven when it was not trusted. This could be triggered remotely on both the client and server side. (Note, with the authentication mode set by mbedtls_ssl_conf_authmode()to be 'required' (the default), the handshake was correctly aborted). Signed-off-by: Kevin Darbyshire-Bryant --- com

Re: [LEDE-DEV] [PATCH] dropbear: Link ssh and scp command to /bin instead of /usr/bin

2017-09-02 Thread Kevin Darbyshire-Bryant
On 02/09/17 02:39, Rosen Penev wrote: ssh and scp commands interfere with OpenSSH when installed in /usr/bin . One use case is when installing dropbear to get root access when only OpenSSH is available (OpenSSH disallows root password logins). Once dropbear installs, it replaces OpenSSH's ex

[LEDE-DEV] [PATCH] kernel: update 4.4 4.4.86

2017-09-04 Thread Kevin Darbyshire-Bryant
Refresh patches Compile & run tested: ar71xx - Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 +-- ...ky-CPU-port-fixes-for-devices-not-using-p.patch | 2 +- .../802-rtl8367r_fix_RGMII_support.patch

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.86 for 17.01

2017-09-04 Thread Kevin Darbyshire-Bryant
Refresh patches Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- ...backport_leds-convert-IDE-trigger-to-common-disk-trigger.patch | 2 +- target/linux/ar71xx/patches-4.4/910-unaligned_access_hacks.patch | 2 +- ...073

[LEDE-DEV] [PATCH] basefiles: allow suid coredumps

2017-09-04 Thread Kevin Darbyshire-Bryant
p happens without a pipe handler or fully qualifid path, a message will be emitted to syslog warning about the lack of a correct setting. Signed-off-by: Kevin Darbyshire-Bryant --- package/base-files/files/etc/sysctl.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/package/

[LEDE-DEV] [PATCH] dnsmasq: backport official fix for CVE-2017-13704

2017-09-06 Thread Kevin Darbyshire-Bryant
Remove LEDE partial fix for CVE-2017-13704. Backport official fix from upstream. Signed-off-by: Kevin Darbyshire-Bryant --- Please cherrypick to LEDE 17.01 .../patches/025-backport-fix-CVE-2017-13704.patch | 94 ++ .../dnsmasq/patches/025-fix-CVE-2017-13704.patch | 37

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.87

2017-09-07 Thread Kevin Darbyshire-Bryant
Fixes CVE-2017-11600 No patch refresh required Compile & run tested: ar71xx - Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/include/kernel-version.mk b/include/kernel-version.mk i

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.87 for 17.01

2017-09-07 Thread Kevin Darbyshire-Bryant
Fixes CVE-2017-11600 No patch refresh required Compile & run tested: ar71xx - Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/include/kernel-version.mk b/include/kernel-version.mk i

[LEDE-DEV] [PATCH] dnsmasq: backport arcount edns0 fix

2017-09-08 Thread Kevin Darbyshire-Bryant
Don't return arcount=1 if EDNS0 RR won't fit in the packet. Omitting the EDNS0 RR but setting arcount gives a malformed packet. Also, don't accept UDP packet size less than 512 in received EDNS0. Signed-off-by: Kevin Darbyshire-Bryant --- Please cherrypick for 17.01 .../

[LEDE-DEV] [PATCH] dnsmasq: backport arcount edns0 fix

2017-09-08 Thread Kevin Darbyshire-Bryant
Don't return arcount=1 if EDNS0 RR won't fit in the packet. Omitting the EDNS0 RR but setting arcount gives a malformed packet. Also, don't accept UDP packet size less than 512 in received EDNS0. Signed-off-by: Kevin Darbyshire-Bryant --- V2 - bump the makefile version th

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.88

2017-09-15 Thread Kevin Darbyshire-Bryant
Refresh patches. Compile & run tested: ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 +-- .../pending-4.4/002-phy_drivers_backport.patch | 34 +++--- .../811-pci_disable_usb_common_quirks.p

[LEDE-DEV] [PATCH] ramips: fix missing mediatek wdt

2017-09-20 Thread Kevin Darbyshire-Bryant
ux 4.9 Tested on: MIR3G Signed-off-by: Kevin Darbyshire-Bryant --- target/linux/ramips/dts/mt7621.dtsi | 2 +- target/linux/ramips/dts/mt7628an.dtsi | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/target/linux/ramips/dts/mt7621.dtsi b/target/linux/ramips/dts/mt7621.dts

[LEDE-DEV] [PATCH v2] ramips: fix missing mediatek wdt

2017-09-20 Thread Kevin Darbyshire-Bryant
der linux 4.9 Tested on: MIR3G Signed-off-by: Kevin Darbyshire-Bryant --- ha! classic typo in commit message, had incorrect 'changed to' value target/linux/ramips/dts/mt7621.dtsi | 2 +- target/linux/ramips/dts/mt7628an.dtsi | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) di

[LEDE-DEV] [PATCH] ramips: improve Xiaomi Mi Router 3G support

2017-09-25 Thread Kevin Darbyshire-Bryant
stem red light slowly blinking for a FAT formatted usb stick with a recovery image to be inserted. Press and hold the reset button for around 1 second. Status LED will turn yellow during recovery and blue when recovery complete. Signed-off-by: Kevin Darbyshire-Bryant --- package/boot/uboot-en

[LEDE-DEV] [PATCH] ramips: mt7621: fix failsafe mode networking

2017-09-25 Thread Kevin Darbyshire-Bryant
Disable VLANs on mt7621 boards with mt7530 switches on failsafe entry. Allows failsafe networking to work correctly. Signed-off-by: Kevin Darbyshire-Bryant --- .../ramips/base-files/lib/preinit/07_set_preinit_iface_ramips| 9 +++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff

[LEDE-DEV] [PATCH] ramips: add 'lwlll' portmap to mt7530 switch

2017-09-25 Thread Kevin Darbyshire-Bryant
The Xiaomi Mi Router 3G uses this deranged vlan portmap. Add support so that packets are not leaked across all switch ports when reset. Fix a whitespace nit while we're here. Signed-off-by: Kevin Darbyshire-Bryant --- target/linux/ramips/files-4.9/drivers/net/ethernet/mtk/mt7530.

[LEDE-DEV] [PATCH v2] ramips: improve Xiaomi Mi Router 3G support

2017-09-25 Thread Kevin Darbyshire-Bryant
overy image to be inserted. Press and hold the reset button for around 1 second. Status LED will turn yellow during recovery and blue when recovery complete. Signed-off-by: Kevin Darbyshire-Bryant --- v2 - split out vlan switch definition & failsafe fix into separate patches package/boot/u

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.89

2017-09-28 Thread Kevin Darbyshire-Bryant
Refresh patches. Compile & run tested on ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- ...alloc_node_mem_map-with-ARCH_PFN_OFFSET-calcu.patch | 2 +- ...w-rejecting-with-source-address-failed-policy.patch

[LEDE-DEV] [PATCH] dnsmasq: bump to v2.78

2017-10-02 Thread Kevin Darbyshire-Bryant
From: Kevin Darbyshire-Bryant Fixes CVE-2017-14491, 14492, 14493, 14494, 14495, 14496 Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dnsmasq/Makefile | 6 +- ...10-Tweak-ICMP-ping-check-logic-for-DHCPv4.patch | 25 -- ...ove-ping-check-of-configured-DHCP

[LEDE-DEV] [PATCH] dnsmasq: bump to v2.78

2017-10-02 Thread Kevin Darbyshire-Bryant
Fixes CVE-2017-14491, 14492, 14493, 14494, 14495, 14496 For lede-17.01 Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/dnsmasq/Makefile | 6 +- ...10-Tweak-ICMP-ping-check-logic-for-DHCPv4.patch | 25 -- ...ove-ping-check-of-configured-DHCP-address.patch | 28

Re: [LEDE-DEV] [PATCH] firewall3: Enable TCP_ECN by default.

2017-10-03 Thread Kevin Darbyshire-Bryant
On 03/10/17 08:16, Rosen Penev wrote: ECN is used by fq_codel and other AQMs. Kernel 4.2 added a fallback in case of failure, so adjust to kernel default. The kernel default is 2, which is what you've set the firewall3 default to be now as well. 2 accepts ECN on incoming connections but does

[LEDE-DEV] [PATCH] generic: swconfig: add mode led attribute

2017-10-04 Thread Kevin Darbyshire-Bryant
that may be applicable. e.g. if an LED is configured to indicate 1Gbit link speed and mode is set to 'link rx tx' but the port is connected at 100Mbit then the LED will not light/blink. Attribute is 'link tx rx' by default for backwards compatible behaviour. Signed-off-by: Kevi

[LEDE-DEV] [PATCH v2] generic: swconfig: add mode led attribute

2017-10-05 Thread Kevin Darbyshire-Bryant
e rate (if configured) This maintains compatibility with existing behaviour. Attribute is 'link tx rx' by default for backwards compatible behaviour. Many thanks to Thibaut Varene for providing a more sensible led_event routine after I had mangled the original, and other coding style hints. Sig

Re: [LEDE-DEV] [PATCH] firewall3: Enable TCP_ECN by default.

2017-10-05 Thread Kevin Darbyshire-Bryant
On 03/10/17 18:22, David Lang wrote: On Tue, 3 Oct 2017, Kevin Darbyshire-Bryant wrote: It's tempting to set it to 1 (like I have for the past year+) and be damned :-) So what is the failure mode and how will people who experience failures know what they need to change? David Lang

[LEDE-DEV] [PATCH] kernel: update 4.4 to 4.4.90

2017-10-05 Thread Kevin Darbyshire-Bryant
No patch refresh required. Compile & run tested: ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/include/kernel-version.mk b/include/kernel-version.mk index 3d32017..bf38d86 10

[LEDE-DEV] [PATCH] kernel: bump 4.4 to 4.4.91

2017-10-08 Thread Kevin Darbyshire-Bryant
Refresh patches. Compile-tested for: ar71xx Archer C7 v2 Run-tested on: ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- target/linux/ar71xx/patches-4.4/930-chipidea-pullup.patch | 2 +- .../680-NET

Re: [LEDE-DEV] [PATCH 0/4] ar71xx: add support for kernel 4.9

2017-10-09 Thread Kevin Darbyshire-Bryant
On 07/10/17 22:20, Hauke Mehrtens wrote: This adds support for kernel 4.9. Please test this, I am lacking especially NAND devices. The most recent version of these patches can be found here: https://git.lede-project.org/?p=lede/hauke/staging.git;a=shortlog;h=refs/heads/ar71xx Tried your late

[LEDE-DEV] [PATCH] kernel: bump 4.4 to 4.4.92

2017-10-12 Thread Kevin Darbyshire-Bryant
No patch refresh changes required. Compile tested for: ar71xx Archer C7 v2 Run tested: ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/include/kernel-version.mk b/include/kernel

Re: [LEDE-DEV] [PATCH] kernel: bump 4.9 to 4.9.56

2017-10-17 Thread Kevin Darbyshire-Bryant
On 15/10/17 03:52, Magnus Kroken wrote: Various fixes inlcuding CVE-2017-7518, CVE-2017-0786 and CVE-2017-1000255. Patches refreshed. Signed-off-by: Magnus Kroken --- Runtime tested on mpc85xx and x86_64. Tested-by: Kevin Darbyshire-Bryant ar71xx: Archer C7 v2

Re: [LEDE-DEV] [PATCH] ag71xx: Add back napi_complete_done.

2017-10-17 Thread Kevin Darbyshire-Bryant
On 17/10/17 17:51, Rosen Penev wrote: This should have no impact on the recently discovered performance regression. Signed-off-by: Rosen Penev --- With the greatest will in the world, should isn't the same as doesn't :-) Any testing? Cheers, Kevin ___

Re: [LEDE-DEV] [PATCH] ag71xx: Add back napi_complete_done.

2017-10-17 Thread Kevin Darbyshire-Bryant
On 17/10/17 21:52, ros...@gmail.com wrote: I'll take your word for it since I have no hardware to test on. I'd say it has a huge impact on performance irrespective of hardware 'cos the patch as supplied doesn't actually compile ;-) CC drivers/net/ethernet/atheros/ag71xx/ag71xx_main

[LEDE-DEV] [PATCH] kernel: bump 4.9 to 4.9.57

2017-10-18 Thread Kevin Darbyshire-Bryant
Refresh patches. Upstream CVEs: CVE-2017-7518 CVE-2017-0786 CVE-2017-1000255 CVE-2017-12188 CVE-2017-15265 Compile tested for: ar71xx Run tested on: ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 +- ...d-firmware

[LEDE-DEV] [PATCH] kernel: bump 4.9 to 4.9.57

2017-10-18 Thread Kevin Darbyshire-Bryant
Refresh patches. Compile-tested for ar71xx - Archer C7 v2 Runtime-tested on ar71xx - Archer C7 v2 Fixes the following CVEs: - CVE-2017-7518 - CVE-2017-0786 - CVE-2017-1000255 - CVE-2017-12188 - CVE-2017-15265 Signed-off-by: Kevin Darbyshire-Bryant --- v2 - reword commit message - no content

[LEDE-DEV] [PATCH v2] kernel: bump 4.9 to 4.9.57

2017-10-18 Thread Kevin Darbyshire-Bryant
Refresh patches. Compile-tested for ar71xx - Archer C7 v2 Runtime-tested on ar71xx - Archer C7 v2 Fixes the following CVEs: - CVE-2017-7518 - CVE-2017-0786 - CVE-2017-1000255 - CVE-2017-12188 - CVE-2017-15265 Signed-off-by: Kevin Darbyshire-Bryant --- v2 - reword commit message - no content

[LEDE-DEV] [PATCH] kernel: bump 4.4 to 4.4.93

2017-10-18 Thread Kevin Darbyshire-Bryant
No patch refresh required. Compile-tested for ar71xx - Archer C7 v2 Runtime-tested on ar71xx - Archer C7 v2 Fixes the following CVEs: - CVE-2017-15265 - CVE-2017-0786 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions

[LEDE-DEV] [PATCH v2] kernel: bump 4.4 to 4.4.93

2017-10-18 Thread Kevin Darbyshire-Bryant
No patch refresh required. Compile-tested for ar71xx - Archer C7 v2 Runtime-tested on ar71xx - Archer C7 v2 Fixes the following CVEs: - CVE-2017-15265 - CVE-2017-0786 Signed-off-by: Kevin Darbyshire-Bryant --- v2 - resend as v1 accidentally deleted from patchwork. No content change

[LEDE-DEV] [PATCH] kernel: bump 4.4 to 4.4.93 for 17.01

2017-10-18 Thread Kevin Darbyshire-Bryant
Refresh patches. Compile-tested for ar71xx - Archer C7 v2 Runtime-tested on ar71xx - Archer C7 v2 Fixes the following CVEs: - CVE-2017-15265 - CVE-2017-0786 Signed-off-by: Kevin Darbyshire-Bryant --- include/kernel-version.mk | 4 ++-- .../0069-hid

[LEDE-DEV] [PATCH] ramips: remove erroneous "wdt rst" DTS entries

2017-10-25 Thread Kevin Darbyshire-Bryant
Remove reference to non-existant pinmux group "wdt rst" on EW1200, ZBT-WG2626 & ZBT-WG3526 devices. Signed-off-by: Kevin Darbyshire-Bryant --- target/linux/ramips/dts/EW1200.dts | 2 +- target/linux/ramips/dts/ZBT-WG2626.dts | 2 +- target/linux/ramips/dts/ZBT-WG3526.dtsi |

[LEDE-DEV] [PATCH] lantiq: xway: script style nit

2017-10-25 Thread Kevin Darbyshire-Bryant
Fix missing space style nit. Signed-off-by: Kevin Darbyshire-Bryant --- package/network/config/ltq-adsl-app/files/10-adsl_rename | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package/network/config/ltq-adsl-app/files/10-adsl_rename b/package/network/config/ltq-adsl-app

[LEDE-DEV] [PATCH] generic: swconfig: add mode led attribute

2017-10-25 Thread Kevin Darbyshire-Bryant
e rate (if configured) This maintains compatibility with existing behaviour. Attribute is 'link tx rx' by default for backwards compatible behaviour. Many thanks to Thibaut Varene for providing a more sensible led_event routine after I had mangled the original, and other coding style hints. Sig

[LEDE-DEV] [PATCH v2] lantiq: xway: script style nit

2017-10-25 Thread Kevin Darbyshire-Bryant
Fix missing space style nit. Signed-off-by: Kevin Darbyshire-Bryant --- v2 - turns out there was another script with the same nit package/network/config/ltq-adsl-app/files/10-adsl_rename | 2 +- package/network/config/ltq-vdsl-app/files/10-xdsl_rename | 2 +- 2 files changed, 2 insertions

[LEDE-DEV] [PATCH v1] wireguard: version bump to 0.0.20171101

2017-11-03 Thread Kevin Darbyshire-Bryant
er C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- package/network/services/wireguard/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package/network/services/wireguard/Makefile b/package/network/services/wireguard/Makefile index e1b60e2b1a..4a732abc98 100644

Re: [LEDE-DEV] [PATCH v1] wireguard: version bump to 0.0.20171101

2017-11-05 Thread Kevin Darbyshire-Bryant
> On 4 Nov 2017, at 17:16, Hans Dedecker wrote: > > On Fri, Nov 3, 2017 at 6:01 PM, Kevin Darbyshire-Bryant > wrote: >> Update wireguard to latest snapshot: >> > Patch applied in trunk > > Thanks > Hans Hi Hans, Thanks for that - could you also ch

[LEDE-DEV] [PATCH v1] wireguard: bump to 0.0.20171111

2017-11-16 Thread Kevin Darbyshire-Bryant
: Kevin Darbyshire-Bryant --- Please cherry-pick for 17.01 package/network/services/wireguard/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package/network/services/wireguard/Makefile b/package/network/services/wireguard/Makefile index 9be2a4c197..9c0e075a17

Re: [LEDE-DEV] [PATCH] base-files: do not backup unchanged files

2017-11-16 Thread Kevin Darbyshire-Bryant
> On 17 Nov 2017, at 00:41, luizl...@gmail.com wrote: > > From: Luiz Angelo Daros de Luca > > Only backup /aaa/bbb/ccc if /rom/aaa/bbb/ccc does not exist > or /aaa/bbb/ccc is different from /rom/aaa/bbb/ccc. > > Signed-off-by: Luiz Angelo Daros de Luca > --- > package/base-files/files/sbin

Re: [LEDE-DEV] [PATCH 4/4] toolchain: musl: update to current HEAD

2017-11-22 Thread Kevin Darbyshire-Bryant
> On 22 Nov 2017, at 11:07, Koen Vandeputte > wrote: > > Tested-by: Koen Vandeputte > > Targets: cns3xxx, imx6 > > Also > > Tested-by: Kevin Darbyshire-Bryant > > ar71xx > ___ > Lede-dev mailing

Re: [LEDE-DEV] [PATCH] kernel: bump 4.9 to 4.9.64

2017-11-23 Thread Kevin Darbyshire-Bryant
89,7 @@ void __init setup_arch(char **cmdline_p) > +@@ -962,6 +961,7 @@ void __init setup_arch(char **cmdline_p) > > cpu_cache_init(); > paging_init(); > -- > 2.7.4 > Let’s see if I’ve persuaded mac mail to behave…doubt it. No. Ma

[LEDE-DEV] [PATCH v1] wireguard: bump to 20171122

2017-11-24 Thread Kevin Darbyshire-Bryant
C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- Please cherry-pick for 17.01 package/network/services/wireguard/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package/network/services/wireguard/Makefile b/package/network/services/wireguard/Makefile index

Re: [LEDE-DEV] [PATCH odhcpd] dhcpv4: notify DHCP ack messages via ubus

2017-11-24 Thread Kevin Darbyshire-Bryant
> On 24 Nov 2017, at 10:56, Borja Salazar wrote: > > Signed-off-by: Borja Salazar > --- > src/dhcpv4.c | 8 > src/odhcpd.h | 1 + > src/ubus.c | 19 +++ > 3 files changed, 28 insertions(+) I suspect people are going to want to see a patch description as well as a r

[LEDE-DEV] [PATCH v1] wireguard: bump to snapshot 20171127

2017-11-27 Thread Kevin Darbyshire-Bryant
y on doing package bumps on ad-hoc basis without the 'official' title. Run-tested: ar71xx Archer C7 v2 Signed-off-by: Kevin Darbyshire-Bryant --- Please cherry-pick for 17.01 package/network/services/wireguard/Makefile | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --g

[LEDE-DEV] [PATCH v1] dnsmasq: fix dhcp-host entries with empty macs

2017-11-28 Thread Kevin Darbyshire-Bryant
tags" helper variables in dhcp_host_add() local, avoiding the need for explicitely resetting them with each invocation. Reported-by: Russell Senior Tested-by: Kevin Darbyshire-Bryant Signed-off-by: Jo-Philipp Wich --- jow has this patch lurking in his tree but not yet made it to master, this

Re: [LEDE-DEV] Adding firewall extensions for xt_geoip usage

2017-12-09 Thread Kevin Darbyshire-Bryant
> On 9 Dec 2017, at 01:15, Philip Prindeville > wrote: > > > config rule > option name kaspersky_servers > option prototcp > option dest_port 25 > list src81.176.69.118 > list src81.176.230.4 > list src91.103.66.246 > l

  1   2   3   >