11537 Commits

Author SHA1 Message Date
Franco Fichtner
140f4ea03e unbound: speed up and safeguards for #4642 2021-02-22 14:30:27 +01:00
Franco Fichtner
a3bfcc2729 system: this looks better although not problematic 2021-02-22 14:23:59 +01:00
Martin Wasley
be12dd889f Correct the omission of the prefix when a dynamic interface v6 dhcpdv6 address is set as a static entry. The result is that only the suffix /64 gets added to the unbound host entries. This patch should sort that so a full address is created for unbound.
use existing call

update
2021-02-22 13:06:43 +01:00
Martin Wasley
4e3c6aa59b Correct dhcp6c.conf issue on pppoe link down
Moved v6 reconfigure to before v4.
2021-02-22 12:00:53 +01:00
Franco Fichtner
48c9b3b403 system: adapt lighttpd ssl.privkey approach #4728
While we need to hide the key we do not have to chmod the
certificate or the chain.  ;)
2021-02-22 09:22:31 +01:00
Ad Schellevis
13c4f8eab6 Reporting / Traffic: aggregate iftop results for https://github.com/opnsense/core/issues/4724
This is more or less a proof of concept, we probably best change the api endpoint data as well to push in/out in the same record so we can also ship the details underneath for those interested.
2021-02-21 13:23:13 +01:00
Gareth Owen
1b530ff38f
Unbound: Handle DHCP client expiring and returning (#4727)
Cleanup local data cache when a DHCP endpoint expires, so that it is
kept in sync with dynamic changes.  This ensures that if an expired DHCP
endpoint returns and is assigned the same IP address the local cache is
correct and doesn't block the entry being dynamically re-added to Unbound.

Also don't cache the blacklist entries, which aren't needed to manage
the DHCP DNS entries. There can easily be 1M+ blacklist entries, so
ignoring these improves startup speed and reduces memory footprint

Fixes #4714
2021-02-21 11:42:11 +01:00
Ad Schellevis
dd2231ee54 Interfaces / Diagnostics / arp,ndp table: slow manufacturer lookups, likely after upgrading netaddr to 0.8.0. for https://github.com/opnsense/core/issues/4666 2021-02-20 00:43:04 +01:00
Ad Schellevis
88e463c913 Netflow: prevent crash when interface number is missing. for https://github.com/opnsense/plugins/issues/2241 2021-02-19 23:16:50 +01:00
Franco Fichtner
889e24c965 firwarme: abstract LOCKFILE away
Now we only deal with LOCKFILE in the firmware scripts folder.
2021-02-19 13:20:48 +01:00
Franco Fichtner
99944f462e firmware: hide LOCKFILE behind small read script
One old bit of compat glue can kick the bucket as well.
2021-02-19 11:52:20 +01:00
Franco Fichtner
38b0e8ff6c firmware: get rid of old naming convention; closes #4718 2021-02-19 11:43:03 +01:00
Franco Fichtner
eb6cbc0164 firmware: single spot for update/upgrade code #4718 2021-02-19 11:29:38 +01:00
Franco Fichtner
dc883ebbba firmware: moving ahead with opnsense-update change for 21.1.2 2021-02-19 11:05:06 +01:00
Ad Schellevis
aa167350b2 System / Routes / Status: missing inet in route delete. closes https://github.com/opnsense/core/issues/4721 2021-02-19 09:44:01 +01:00
Franco Fichtner
89dbf25c35 openpn: break in default case 2021-02-18 20:14:39 +01:00
Franco Fichtner
4c9aa8492b firmware: remove frontend magic and implement validation #4500 2021-02-18 15:35:02 +01:00
Ad Schellevis
5c7d3251ac Interfaces / Overview: handle disabled interfaces. closes https://github.com/opnsense/core/issues/4719 2021-02-18 14:21:45 +01:00
Franco Fichtner
508a5fee04 firmware: settings validation messages to GUI #4500 2021-02-18 13:29:39 +01:00
Franco Fichtner
8c2ea1f344 firmware: for core that works, for crypto it does not
Since the fetch blocks some time and is not completely reliable
it doesn't really matter if we have it or not.

While here remove a bit of cruft.
2021-02-18 10:24:04 +01:00
Franco Fichtner
b2472f3c5e system: visibility for problematic LUA scripts #4717 2021-02-18 09:47:28 +01:00
Franco Fichtner
c05c0411cb firmware: small refactor for neatness 2021-02-18 09:02:52 +01:00
Ad Schellevis
ee002053da VPN / IPsec: calculatation error in 8b62109a61 , start at 31,127 to make sure both points can actually reach eachother. for https://github.com/opnsense/core/issues/4700 2021-02-17 19:46:37 +01:00
kulikov-a
819131b866
fw_log.volt: show with 'or' and empty filter (#4716) 2021-02-18 08:38:57 +01:00
Franco Fichtner
56f237a8d4 openvpn: better translations leaving command line args out of it 2021-02-18 08:28:15 +01:00
Franco Fichtner
23883ea879 system: fix syntax error 2021-02-18 08:09:32 +01:00
Christian Brueffer
a9185cc4dd
Make StartTLS work when retrieving LDAP authentication containers. (#4713)
Make StartTLS work when retrieving LDAP authentication containers.
The code did not set the LDAP connection properties as configured.
2021-02-17 17:47:20 +01:00
Ad Schellevis
8b62109a61 VPN / IPSec: calculate netmask for provided tunnel addresses when using VTI.
For IPv4 this should be backwards compatible with the previous code, since the netmask isn't really used to determine if the other end is reachable (it seems so at least), for ipv6 some consumers a valid netmask
seems to be required in order to function properly (frr). Since ipv6 doesn't seem to support setting a netmask in combination with a destination address and the other end apparantly doesn't really care, we just set an address with a mask in case it's an ipv6 tunnel.

for https://github.com/opnsense/core/issues/4700
2021-02-17 17:33:41 +01:00
Franco Fichtner
386e122339 firmware: fix action label 2021-02-17 15:42:47 +01:00
Franco Fichtner
2caeb508fc firmware: flush line for new package 2021-02-17 15:14:32 +01:00
Franco Fichtner
1e4aac005a firmware: use cannonical -p and -t update
opnsense-update can now handle it correctly and we save another
invoke from here.
2021-02-17 15:03:23 +01:00
Franco Fichtner
e321ab47a6 firmware: no, not going to fix this mess #4500 2021-02-17 14:02:04 +01:00
Franco Fichtner
8a6642c862 firmware: lock pkg when not upgrading it
It can be snatched from any mirror if given which is very
bad when FreeBSD repo is enabled.  A simple pkg-install
will pull in pkg and break the system.
2021-02-17 13:52:10 +01:00
Franco Fichtner
a55afaac12 firmware: add crypto package to health check #4500 2021-02-17 13:33:20 +01:00
Franco Fichtner
31ca550304 firmware: correct timestamp to reflect date(1) output 2021-02-17 09:47:01 +01:00
Franco Fichtner
74ab171e1d firmware: put back this one fa-cog that got greedy-replaced 2021-02-16 16:58:34 +01:00
Franco Fichtner
05b26a0f5b firmware: important indent fix 2021-02-16 16:56:46 +01:00
Franco Fichtner
2520f59669 firmwware: slight code updates for check #4500 2021-02-16 16:11:49 +01:00
Franco Fichtner
58b96bc114 firmware: third and last batch #4500 2021-02-16 15:59:37 +01:00
Franco Fichtner
d44a148899 firmware: second batch in check script #4500 2021-02-16 15:52:58 +01:00
Franco Fichtner
9a08ea91e9 firmware: settle on 4 spaces for indent, first batch, minor removals #4500 2021-02-16 15:44:04 +01:00
Franco Fichtner
0f1484b3a2 firmware: strict install policy using php version_compare() #4500
We have to see how this holds up in practice.  Reinstall was considered
as well for further protection but that might be even trickier depending
on what locking and version tricks the user did to their install to
retain a particular (working) state.
2021-02-16 15:08:26 +01:00
Franco Fichtner
e4392fb854 firmware: pin critical updates to our repo #4500
While testing pkg was snatched from FreeBSD mirror, which isn't
advisable (nevermind that FreeBSD mirror was enabled in the first
place).

Do the same for the release type shift to avoid pivoting towards
third party repos for any reason whatsoever.
2021-02-16 15:03:56 +01:00
Franco Fichtner
3f22ca2db4 firmware: simplify frontend #4500 2021-02-16 14:36:48 +01:00
Franco Fichtner
8a3b807f21 firmware: note in update log about the purpose #4500
The issue is that some users assume there is manual need for
file changes as prompted by FreeBSD package manager and its
ports, but that is generally not the case when using OPNsense.

For core functionality and plugins the GUI takes care of all
these manual maintenence steps.
2021-02-16 13:56:32 +01:00
Franco Fichtner
f1e72574b6 src: style sweep 2021-02-16 10:36:44 +01:00
Franco Fichtner
9a01e5399d firmware: UX and display tweaks 2021-02-16 10:31:04 +01:00
Franco Fichtner
31cefec61b firmware: when config.xml looks like a factory reset register plugins/release #4500
This way the build can do all sorts of funny things and we will end up
with a consistent config.xml after boot.  For people restoring other
config.xml that is not the case but in this scenario the user is likely
aware of what he or she is doing.
2021-02-16 10:05:27 +01:00
Franco Fichtner
ecad74072c firmware: fix a typo and improve wording #4500 2021-02-16 00:51:16 +01:00
Franco Fichtner
4cf0720b66 firmware: merge updates and release type result parsing #4500
With this we get as much visibility as pkg can offer us.  Merge
some code in the process as the release type shift is nothing
special anymore.
2021-02-16 00:40:20 +01:00