Commit Graph

54675 Commits

Author SHA1 Message Date
ACwifidude
1d2f3a46b1 rebase 2023-06-20 18:33:06 -04:00
ACwifidude
0b218d7536 set CPU to performance governor as the default 2023-06-20 16:14:53 -04:00
ACwifidude
bd87c250d8 Revert "kernel: remove obsolete netfilter tcp window size check bypass patch"
This reverts commit c2331038b2.
2023-06-19 15:45:05 -04:00
ACwifidude
392d81bf3e Update NSS source URLs 2023-06-19 15:45:05 -04:00
tishipp
85994b45a8 vlan panic fix. 2023-06-19 15:45:05 -04:00
tishipp
9f688e5abc l2tpv2 ops fix. 2023-06-19 15:45:05 -04:00
ACwifidude
5e55cd177b nlbwmon remove 2023-06-19 15:45:05 -04:00
tishipp
e50c0ffd33 add NEC Aterm WG2600HP support 2023-06-19 15:45:05 -04:00
tishipp
9ade26499e add L2TPV2 offloading 2023-06-19 15:45:05 -04:00
tishipp
d8c82b10f1 add DS-Lite offloading 2023-06-19 15:45:05 -04:00
tishipp
036265a6a5 back PPPoE offloading 2023-06-19 15:45:05 -04:00
ACwifidude
9d913a2197 iptables further changes 2023-06-19 15:45:05 -04:00
ACwifidude
e7f1c07aff attempt to remove iptables 2023-06-19 15:45:05 -04:00
ACwifidude
e560a49037 fix .dts patch 2023-06-19 15:45:05 -04:00
ACwifidude
006ec47965 fix rt4230w-rev6 dts patch 2023-06-19 15:45:04 -04:00
ACwifidude
8350163f9b fix pppoe patch 2023-06-19 15:45:04 -04:00
ACwifidude
4d35fd61fe ipq806x: NSS Hardware Offloading dts patch 2023-06-19 15:45:04 -04:00
ACwifidude
1142353c5c ipq806x: NSS Hardware Offloading mac80211 patch 2023-06-19 15:45:04 -04:00
ACwifidude
848508342b ipq806x: NSS Hardware Offloading iproute2 Patches 2023-06-19 15:45:04 -04:00
ricsc
d6a79733c5 nlbwmon fix 2023-06-19 15:45:04 -04:00
ACwifidude
21d9bfea59 ipq806x: add tx hw 802.11 encapsulation offloading support 2023-06-19 15:45:04 -04:00
ACwifidude
bcdc9b5bef ipq806x: Tweak CPU for max stability and performance 2023-06-19 15:45:04 -04:00
ACwifidude
2b006884f3 ipq806x: of net return patch 2023-06-19 15:45:04 -04:00
ACwifidude
06ccfc540e ipq806x: NSS Hardware Offloading qdisc support patch 2023-06-19 15:45:04 -04:00
ACwifidude
1f5a481167 ipq806x: NSS Hardware Offloading cfi support patch 2023-06-19 15:45:04 -04:00
ACwifidude
9b136bbe52 ipq806x: NSS Hardware Offloading pppoe patch 2023-06-19 15:45:04 -04:00
ACwifidude
7e5fd067b0 ipq806x: NSS Hardware Offloading Crypto patch 2023-06-19 15:45:04 -04:00
ACwifidude
e16388df8f ipq806x: NSS Hardware Offloading ECM patch 2023-06-19 15:45:04 -04:00
ACwifidude
6bc0b1bb66 ipq806x: NSS Hardware Offloading SFE patch 2023-06-19 15:45:04 -04:00
ACwifidude
dd59b6e68e ipq806x: Revert ARM dma mapping patch 2023-06-19 15:45:04 -04:00
ACwifidude
63a8a897c5 ipq806x: NSS Hardware Offloading Voltage Patch 2023-06-19 15:45:04 -04:00
ACwifidude
4d483115b4 ipq806x: NSS Hardware Offloading Chain Events Patch 2023-06-19 15:45:03 -04:00
ACwifidude
a80779177e ipq806x: NSS Hardware Offloading Config-5.10 2023-06-19 15:45:03 -04:00
ACwifidude
4d114e1911 ipq806x: NSS Hardware Offloading Target Files 2023-06-19 15:45:03 -04:00
ACwifidude
b84534106c ipq806x: NSS Hardware Offloading QCA Packages 2023-06-19 15:45:03 -04:00
Jitao Lu
70e3f4e94d openssl: passing cflags to configure
openssl sets additional cflags in its configuration script. We need to
make it aware of our custom cflags to avoid adding conflicting cflags.

Fixes: #12866
Signed-off-by: Jitao Lu <dianlujitao@gmail.com>
(cherry picked from commit 51f57e7c2d)
2023-06-17 12:56:58 +02:00
Hauke Mehrtens
287303b062 kernel: bump 5.10 to 5.10.184
Manually rebased:
generic/pending-5.10/851-0004-Revert-ata-ahci-mvebu-Make-SATA-PHY-optional-for-Arm.patch

All other patches automatically rebased.

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2023-06-15 14:26:41 +02:00
Hauke Mehrtens
920f2d9237 kernel: bump 5.10 to 5.10.183
All patches automatically rebased.

Deactivate new option CONFIG_DRM_RCAR_USE_LVDS by default.

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2023-06-15 14:26:12 +02:00
Hauke Mehrtens
ac5e37f832 kernel: bump 5.10 to 5.10.182
All patches automatically rebased.

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2023-06-15 14:26:10 +02:00
Álvaro Fernández Rojas
4b44bfe591 bcm63xx: fix NETGEAR DGND3700v2 boot loop
The DGND3700v2 renames the cferam bootloader from cferam to cfeXXX, where XXX
is the number of firmware upgrades performed by the bootloader. Other bcm63xx
devices rename cferam.000 to cferam.XXX, but this device is special because
the cferam name isn't changed on the first firmware flashing but it's changed
on the subsequent ones.
Therefore, we need to look for "cfe" instead of "cferam" to properly detect
the cferam partition and fix the bootlop.

Signed-off-by: Álvaro Fernández Rojas <noltari@gmail.com>
(cherry picked from commit cdfcac6e24)
2023-06-15 11:56:04 +02:00
Álvaro Fernández Rojas
1a5e7d3f1c bmips: fix NETGEAR DGND3700v2 boot loop
The DGND3700v2 renames the cferam bootloader from cferam to cfeXXX, where XXX
is the number of firmware upgrades performed by the bootloader. Other bcm63xx
devices rename cferam.000 to cferam.XXX, but this device is special because
the cferam name isn't changed on the first firmware flashing but it's changed
on the subsequent ones.
Therefore, we need to look for "cfe" instead of "cferam" to properly detect
the cferam partition and fix the bootlop.

Signed-off-by: Álvaro Fernández Rojas <noltari@gmail.com>
(cherry picked from commit 915e914cfa)
2023-06-15 11:55:58 +02:00
Álvaro Fernández Rojas
e908856c43 kernel: mtd: bcm-wfi: add cferam name support
Some devices rename cferam bootloader using specific patterns and don't follow
broadcom standards for renaming cferam files. This requires supporting
different cferam file names.

Signed-off-by: Álvaro Fernández Rojas <noltari@gmail.com>
(cherry picked from commit 8813edd8d9)
2023-06-15 11:55:51 +02:00
Christian Marangi
17f6001853 restool: update source.codeaurora.org repository link
source.codeaurora.org project has been shut down and the nxp
repositories has been moved to github. Update the repository
link to the new location.

Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
(cherry picked from commit 0a1ee53235)
2023-06-11 18:58:49 +02:00
Christian Marangi
ca669b7c07 ls-dpl: update source.codeaurora.org repository link
source.codeaurora.org project has been shut down and the nxp
repositories has been moved to github. Update the repository
link to the new location.

Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
(cherry picked from commit 52fd8d8ba3)
2023-06-11 18:58:43 +02:00
Hannu Nyman
4a9eb94b5f bpf-headers: fix compilation with LLVM_IAS=1
Linux 5.10.178 includes backported commits that break the compilation
of bpf-headers, as the compilation gets confused which assembler to use.
Caused by Linux upstream commits just before the .178 tag:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/log/?h=v5.10.178

2023-04-20	kbuild: check CONFIG_AS_IS_LLVM instead of LLVM_IAS
2023-04-20	kbuild: Switch to 'f' variants of integrated assembler flag
2023-04-20	kbuild: check the minimum assembler version in Kconfig

Explicitly use LLVM_IAS=1 to fix things.

Fixes #12748

Signed-off-by: Hannu Nyman <hannu.nyman@iki.fi>
2023-06-10 15:52:19 +02:00
Hauke Mehrtens
afb4422702 openssl: bump to 1.1.1u
Major changes between OpenSSL 1.1.1t and OpenSSL 1.1.1u [30 May 2023]

    o Mitigate for very slow `OBJ_obj2txt()` performance with gigantic
      OBJECT IDENTIFIER sub-identities.  (CVE-2023-2650)
    o Fixed documentation of X509_VERIFY_PARAM_add0_policy() (CVE-2023-0466)
    o Fixed handling of invalid certificate policies in leaf certificates
      (CVE-2023-0465)
    o Limited the number of nodes created in a policy tree ([CVE-2023-0464])

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2023-06-07 22:40:46 +02:00
Hauke Mehrtens
171b515192 kernel: bump 5.10 to 5.10.181
All patches automatically rebased.

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2023-06-03 14:31:38 +02:00
Hauke Mehrtens
6bca11f496 kernel: bump 5.10 to 5.10.180
Deleted because it was applied upstream
ipq806x/patches-5.10/103-ARM-dts-qcom-reduce-pci-IO-size-to-64K.patch

Signed-off-by: Hauke Mehrtens <hauke@hauke-m.de>
2023-06-03 14:31:38 +02:00
Alexey Bartenev
656e411454 ramips: add support for Keenetic Lite III rev. A
General specification:
SoC Type: MediaTek MT7620N (580MHz)
ROM: 8 MB SPI-NOR (W25Q64FV)
RAM: 64 MB DDR (EM6AB160TSD-5G)
Switch: MediaTek MT7530
Ethernet: 5 ports - 5×100MbE (WAN, LAN1-4)
Wireless: 2.4 GHz (MediaTek RT5390): b/g/n
Buttons: 3 button (POWER, RESET, WPS)
Slide switch: 4 position (BASE, ADAPTER, BOOSTER, ACCESS POINT)
Bootloader: U-Boot 1.1.3
Power: 9 VDC, 0.6 A

MAC in stock:
|-	+			|
| LAN 	| RF-EEPROM + 0x04	|
| WLAN	| RF-EEPROM + 0x04	|
| WAN 	| RF-EEPROM + 0x28	|

OEM easy installation
1. Use a PC to browse to http://my.keenetic.net.
2. Go to the System section and open the Files tab.
3. Under the Files tab, there will be a list of system
files. Click on the Firmware file.
4. When a modal window appears, click on the Choose File
button and upload the firmware image.
5. Wait for the router to flash and reboot.

OEM installation using the TFTP method
1. Download the latest firmware image and rename it to
klite3_recovery.bin.
2. Set up a Tftp server on a PC (e.g. Tftpd32) and place the
firmware image to the root directory of the server.
3. Power off the router and use a twisted pair cable to connect
the PC to any of the router's LAN ports.
4. Configure the network adapter of the PC to use IP address
192.168.1.2 and subnet mask 255.255.255.0.
5. Power up the router while holding the reset button pressed.
6. Wait approximately for 5 seconds and then release the
reset button.
7. The router should download the firmware via TFTP and
complete flashing in a few minutes.
After flashing is complete, use the PC to browse to
http://192.168.1.1 or ssh to proceed with the configuration.

Signed-off-by: Alexey Bartenev <41exey@proton.me>
(cherry picked from commit dc79b51533)
2023-06-03 11:49:04 +02:00
Tianling Shen
ce32068bf2 ca-certificates: Update to version 20230311
Update the ca-certificates and ca-bundle package from version 20211016 to
version 20230311.

Use TAR_OPTIONS instead of hacking Build/Prepare, refresh patches.

Debian change-log entry [1]:
|[...]
|[ Đoàn Trần Công Danh ]
|* ca-certificates: compat with non-GNU mktemp (closes: #1000847)
|
|[ Ilya Lipnitskiy ]
|* certdata2pem.py: use UTC time when checking cert validity
|
|[ Julien Cristau ]
|* Update Mozilla certificate authority bundle to version 2.60
|   The following certificate authorities were added (+):
|   + "Autoridad de Certificacion Firmaprofesional CIF A62634068"
|   + "Certainly Root E1"
|   + "Certainly Root R1"
|   + "D-TRUST BR Root CA 1 2020"
|   + "D-TRUST EV Root CA 1 2020"
|   + "DigiCert TLS ECC P384 Root G5"
|   + "DigiCert TLS RSA4096 Root G5"
|   + "E-Tugra Global Root CA ECC v3"
|   + "E-Tugra Global Root CA RSA v3"
|   + "HARICA TLS ECC Root CA 2021"
|   + "HARICA TLS RSA Root CA 2021"
|   + "HiPKI Root CA - G1"
|   + "ISRG Root X2"
|   + "Security Communication ECC RootCA1"
|   + "Security Communication RootCA3"
|   + "Telia Root CA v2"
|   + "TunTrust Root CA"
|   + "vTrus ECC Root CA"
|   + "vTrus Root CA"
|  The following certificate authorities were removed (-):
|  - "Cybertrust Global Root" (expired)
|  - "EC-ACC"
|  - "GlobalSign Root CA - R2" (expired)
|  - "Hellenic Academic and Research Institutions RootCA 2011"
|  - "Network Solutions Certificate Authority"
|  - "Staat der Nederlanden EV Root CA" (expired)
|* Drop trailing space from debconf template causing misformatting
|  (closes: #980821)
|
|[ Wataru Ashihara ]
|* Make certdata2pem.py compatible with cryptography >= 35 (closes: #1008244)
|[...]

[1]: https://metadata.ftp-master.debian.org/changelogs/main/c/ca-certificates/ca-certificates_20230311_changelog

Signed-off-by: Tianling Shen <cnsztl@immortalwrt.org>
(cherry picked from commit 7c83b6ac86)
2023-05-28 19:51:52 +02:00