Re: [OpenWrt-Devel] usign race?

2018-09-18 Thread Mike McCormack
On 15/09/18 21:15, Daniel Golle wrote: For now, this is acceptable. In the long run we should store keys in their native fixed-length binary representation rather than using usign's base64 encoded text strings -- however, that requires changes to usign as well, so for now fixing ucert to work wi

[OpenWrt-Devel] [PATCH] wireguard: bump to 0.0.20180918

2018-09-18 Thread Jason A. Donenfeld
* blake2s-x86_64: fix whitespace errors * crypto: do not use compound literals in selftests * crypto: make sure UML is properly disabled * kconfig: make NEON depend on CPU_V7 * poly1305: rename finish to final * chacha20: add constant for words in block * curve25519-x86_64: remove useless define *

[OpenWrt-Devel] [PATCH 3/6] dropbear: Install /etc/config as 600

2018-09-18 Thread Rosen Penev
/etc/config/dropbear is used by the init script which only runs as root. Small whitespace change. Signed-off-by: Rosen Penev --- package/network/services/dropbear/Makefile | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package/network/services/dropbear/Makefile b/pac

[OpenWrt-Devel] [PATCH 1/6] mdadm: Install /etc/config file as 600

2018-09-18 Thread Rosen Penev
/etc/config/mdadm is only used by the init script which is ran as root. There is no need for it to be readable by anything else. Added PKG_CPE_ID for proper CVE tracking. Small reorganization for consistency between Makefiles. Signed-off-by: Rosen Penev --- package/utils/mdadm/Makefile | 9 +++

[OpenWrt-Devel] [PATCH 2/6] lldpd: Install /etc/config file as 600

2018-09-18 Thread Rosen Penev
/etc/config/lldpd is only used by the init script, which only runs as root Adjusted homepage and download URLs to use HTTPS. -std=c99 is useful for GCC versions less than 6. Current OpenWrt uses 7. Signed-off-by: Rosen Penev --- package/network/services/lldpd/Makefile | 10 -- 1 file c

[OpenWrt-Devel] [PATCH 4/6] trelay: Install hotplug and config files as 600

2018-09-18 Thread Rosen Penev
The hotplug file is ran by procd, which runs as root. The config file is used by the init script, which also runs as root. Signed-off-by: Rosen Penev --- package/kernel/trelay/Makefile | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package/kernel/trelay/Makefile b/pack

[OpenWrt-Devel] [PATCH 5/6] usbmode: Update modeswitch data to 20170806

2018-09-18 Thread Rosen Penev
Changed hotplug file to 600 as it is only read by procd, which runs as root. Signed-off-by: Rosen Penev --- package/utils/usbmode/Makefile | 10 +- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/package/utils/usbmode/Makefile b/package/utils/usbmode/Makefile index e229c791

[OpenWrt-Devel] [PATCH 6/6] fstools: Install mount.hotplug and 10-fstab.defaults as 600

2018-09-18 Thread Rosen Penev
Both of these are used by programs that run as root and nothing else. Signed-off-by: Rosen Penev --- package/system/fstools/Makefile | 8 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/package/system/fstools/Makefile b/package/system/fstools/Makefile index 440f187394..281

[OpenWrt-Devel] ath79: RouterStation Pro build failure

2018-09-18 Thread Weedy
I have build system that adds a couple packages (qos-scripts, munin, iptables modules, etc) to the default list and builds images for my systems. For the purposes of the bug report the differences are: echo 'CONFIG_TARGET_ath79=y CONFIG_TARGET_ath79_generic=y CONFIG_TARGET_ath79_generic_DEVICE_tp