Revision: 7605 http://sourceforge.net/p/ipcop/svn/7605 Author: owes Date: 2014-06-17 14:48:14 +0000 (Tue, 17 Jun 2014) Log Message: ----------- Update linux kernel to 3.4.94
Modified Paths: -------------- ipcop/trunk/lfs/linux ipcop/trunk/updates/2.1.6/ROOTFILES.i486-2.1.6 ipcop/trunk/updates/2.1.6/information.xml Removed Paths: ------------- ipcop/trunk/src/patches/linux-3.4_netfilter-ipv4-defrag-set-local_df-flag-on-defragmented-skb.patch Modified: ipcop/trunk/lfs/linux =================================================================== --- ipcop/trunk/lfs/linux 2014-06-14 06:26:47 UTC (rev 7604) +++ ipcop/trunk/lfs/linux 2014-06-17 14:48:14 UTC (rev 7605) @@ -34,7 +34,7 @@ PKG_NAME = linux VER = 3.4 -PATCHLEVEL = 3.4.92 +PATCHLEVEL = 3.4.94 IPCOPKRELEASE = -3 HOST_ARCH = all OTHER_SRC = yes @@ -72,7 +72,7 @@ $(GRSECURITYPATCH) = http://ipcop-addons.mooo.com/misc/IPCop/$(GRSECURITYPATCH) $(DL_FILE)_MD5 = 967f72983655e2479f951195953e8480 -patch-$(PATCHLEVEL).xz_MD5 = d9433ff38cd191dd86ee7828617f7b0c +patch-$(PATCHLEVEL).xz_MD5 = 68dcfb6d22d0a40ed4405657057b8881 $(GRSECURITYPATCH)_MD5 = b15bb91a07aa2fb030e18c47c91940bb install : $(TARGET) @@ -118,9 +118,6 @@ # APU LEDs cd $(DIR_APP) && patch -Np1 -i $(DIR_PATCHES)/$(THISAPP)_leds-apu.patch - # MTU issue, queued for 3.4.93 - cd $(DIR_APP) && patch -Np1 -i $(DIR_PATCHES)/$(THISAPP)_netfilter-ipv4-defrag-set-local_df-flag-on-defragmented-skb.patch - ifeq "$(GRSEC)" "yes" cd $(DIR_APP) && patch -Np1 -i $(DIR_DL)/$(GRSECURITYPATCH) # Remove test for binutils version, --build-id does not work for us and we have binutils > 2.18 Deleted: ipcop/trunk/src/patches/linux-3.4_netfilter-ipv4-defrag-set-local_df-flag-on-defragmented-skb.patch =================================================================== --- ipcop/trunk/src/patches/linux-3.4_netfilter-ipv4-defrag-set-local_df-flag-on-defragmented-skb.patch 2014-06-14 06:26:47 UTC (rev 7604) +++ ipcop/trunk/src/patches/linux-3.4_netfilter-ipv4-defrag-set-local_df-flag-on-defragmented-skb.patch 2014-06-17 14:48:14 UTC (rev 7605) @@ -1,58 +0,0 @@ -From 895162b1101b3ea5db08ca6822ae9672717efec0 Mon Sep 17 00:00:00 2001 -From: Florian Westphal <f...@strlen.de> -Date: Fri, 2 May 2014 15:32:16 +0200 -Subject: netfilter: ipv4: defrag: set local_df flag on defragmented skb - -From: Florian Westphal <f...@strlen.de> - -commit 895162b1101b3ea5db08ca6822ae9672717efec0 upstream. - -else we may fail to forward skb even if original fragments do fit -outgoing link mtu: - -1. remote sends 2k packets in two 1000 byte frags, DF set -2. we want to forward but only see '2k > mtu and DF set' -3. we then send icmp error saying that outgoing link is 1500 - -But original sender never sent a packet that would not fit -the outgoing link. - -Setting local_df makes outgoing path test size vs. -IPCB(skb)->frag_max_size, so we will still send the correct -error in case the largest original size did not fit -outgoing link mtu. - -Reported-by: Maxime Bizon <mbi...@freebox.fr> -Suggested-by: Maxime Bizon <mbi...@freebox.fr> -Fixes: 5f2d04f1f9 (ipv4: fix path MTU discovery with connection tracking) -Signed-off-by: Florian Westphal <f...@strlen.de> -Signed-off-by: Pablo Neira Ayuso <pa...@netfilter.org> -Cc: Jiri Slaby <jsl...@suse.cz> -Signed-off-by: Greg Kroah-Hartman <gre...@linuxfoundation.org> - ---- - net/ipv4/netfilter/nf_defrag_ipv4.c | 5 +++-- - 1 file changed, 3 insertions(+), 2 deletions(-) - ---- a/net/ipv4/netfilter/nf_defrag_ipv4.c -+++ b/net/ipv4/netfilter/nf_defrag_ipv4.c -@@ -22,7 +22,6 @@ - #endif - #include <net/netfilter/nf_conntrack_zones.h> - --/* Returns new sk_buff, or NULL */ - static int nf_ct_ipv4_gather_frags(struct sk_buff *skb, u_int32_t user) - { - int err; -@@ -33,8 +32,10 @@ static int nf_ct_ipv4_gather_frags(struc - err = ip_defrag(skb, user); - local_bh_enable(); - -- if (!err) -+ if (!err) { - ip_send_check(ip_hdr(skb)); -+ skb->local_df = 1; -+ } - - return err; - } Modified: ipcop/trunk/updates/2.1.6/ROOTFILES.i486-2.1.6 =================================================================== --- ipcop/trunk/updates/2.1.6/ROOTFILES.i486-2.1.6 2014-06-14 06:26:47 UTC (rev 7604) +++ ipcop/trunk/updates/2.1.6/ROOTFILES.i486-2.1.6 2014-06-17 14:48:14 UTC (rev 7605) @@ -103,7 +103,7 @@ /usr/lib/libjson-c.so.2 /usr/lib/libjson-c.so.2.0.1 ## -## linux-3.4-3 (3.4.92) +## linux-3.4-3 (3.4.94) /boot/vmlinuz /boot/vmlinuz-3.4-3 /boot/System.map-3.4-3 Modified: ipcop/trunk/updates/2.1.6/information.xml =================================================================== --- ipcop/trunk/updates/2.1.6/information.xml 2014-06-14 06:26:47 UTC (rev 7604) +++ ipcop/trunk/updates/2.1.6/information.xml 2014-06-17 14:48:14 UTC (rev 7605) @@ -6,7 +6,7 @@ <isoimages>yes</isoimages> <description>Language updates.<br /> Patch openssl for CVE-2010-5298.<br /> - Upgrade linux kernel to 3.4-3 (3.4.92).<br /> + Upgrade linux kernel to 3.4-3 (3.4.94).<br /> Upgrade bind to 9.9.5-P1, dnsmasq to 2.71, e2fsprogs to 1.42.10, fcron to 3.1.3, grep to 2.20, iproute2 to 3.15.0, mdadm to 3.3.1, openssl to 1.0.1h, openvpn to 2.3.4, rsyslog to 7.6.3, squid to 3.4.5, syslinux to 6.02, This was sent by the SourceForge.net collaborative development platform, the world's largest Open Source development site. ------------------------------------------------------------------------------ HPCC Systems Open Source Big Data Platform from LexisNexis Risk Solutions Find What Matters Most in Your Big Data with HPCC Systems Open Source. Fast. Scalable. Simple. Ideal for Dirty Data. Leverages Graph Analysis for Fast Processing & Easy Data Exploration http://p.sf.net/sfu/hpccsystems _______________________________________________ Ipcop-svn mailing list Ipcop-svn@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/ipcop-svn