Commit graph

5386 commits

Author SHA1 Message Date
Franco Fichtner
c1b5dfe2a3 net/upnp: switch from shell_exec() to shell_safe() with automatic trim() 2025-11-16 17:15:50 -05:00
Franco Fichtner
0916add402 security/acme-client: fix legacy inclusion 2025-11-15 18:46:23 -05:00
Franco Fichtner
20b507efeb net/upnp: minor transformation as mwexecf_bg() will be removed 2025-11-15 18:46:23 -05:00
Franco Fichtner
b92c2e631f dns/rfc2136: second iteration using mwexecfb(), no functional changes 2025-11-15 18:46:23 -05:00
Monviech
6fba852a9d
net/frr: Fix snmp ospfd and ospf6d flags (#5025) 2025-11-13 13:09:24 +01:00
Monviech
355309551b
net/frr: Fix STATIC template interface issue, use isEmpty() in validation (#5019)
* net/frr: Fix STATIC template interface issue, use isEmpty() in validation

* Properly safeguard optional parameters
2025-11-13 10:37:42 +01:00
Monviech
68505ed357
net/frr: Add hint about service reload (frr-reload) vs full restart requirement (#5022)
* net/frr: Add hint about service reload (frr-reload) vs full restart requirement

* Add missing translations
2025-11-12 19:05:42 +01:00
Monviech
6061da298b
net/ndp-proxy-go: Fix naming and add docs link (#5017) 2025-11-11 19:09:23 +01:00
Monviech
0152180865
www/caddy: Prevent sudo on startup via skip_install_trust (#5015)
This can happen when an internal domain has been added, e.g. example.internal. Caddy will then generate a self signed certificate via smallstep CA, and on startup it tries to install a root certificate for it into the FreeBSD trust store.

If running as www user, this causes sudo to appear at boot, because that is baked into smallstep CA.

https://github.com/smallstep/truststore/blob/master/truststore_freebsd.go

Via skip_install_trust, we prevent caddy from trying this.
2025-11-10 17:01:03 +01:00
Franco Fichtner
c4c5632a49 misc/theme-flexcolor: add rc file for handling default_scheme.css
Due to not overcomplicating this with a GUI do the lower end RC so that
we users can change this easily.

This works nicely, but the import statement is cached by the browser:

@import url('default_scheme.css');

and this needs to be fixed or the plugin split.
2025-11-07 13:03:29 +01:00
Maurice Walker
4518d481f5
net/tayga: fix typo in static mappings (#5010) 2025-11-07 06:55:03 +01:00
Franco Fichtner
e51e367336 net/igmp-proxy: remove the notion of a "realif"
Actually the last in the plugin code!
2025-11-06 11:09:05 +01:00
Franco Fichtner
124194c2fc dns/rfc2136: bump revision 2025-11-04 14:47:19 +01:00
Franco Fichtner
f7e1982bfe net/tayga: minimal polish 2025-11-04 14:44:07 +01:00
Franco Fichtner
001fa57d90 net/freeradius: cleanups for next version 2025-11-04 14:31:00 +01:00
Robert Resch
370bc89493
net/freeradius: add fallback Tunnel-Password field (#4983) 2025-11-04 14:28:39 +01:00
Franco Fichtner
1e8b6c8e0a README: sync 2025-11-04 14:17:27 +01:00
Franco Fichtner
04585ada9e net/ndp-proxy-go: minor adjustments 2025-11-04 14:16:26 +01:00
Monviech
e03666d614
net/frr: Bump version to 1.48 (#5003) 2025-11-03 15:08:45 +01:00
Monviech
1ce75bdc52
net/frr: Allow disabling enforce_first_as, which is a new default in frr10 (#5001) 2025-11-03 15:08:31 +01:00
Monviech
674f0a6fa5
net/frr: BGP add bestpath route selection options (#5002) 2025-11-03 15:07:52 +01:00
Franco Fichtner
b4f54361f0 README: sync 2025-11-03 14:06:16 +01:00
Monviech
f4b6ed6b80
net/ndp-proxy-go: Add initial plugin version (#4998) 2025-10-31 21:58:34 +01:00
Monviech
1b489c0a68
net/frr: Add BFD configuration detect-multiplier, transmit-interval, receive-interval (#5000)
* net/frr: Add BFD configuration detect-multiplier, transmit-interval, receive-interval

* Hide in advanced mode
2025-10-31 11:21:40 +01:00
Franco Fichtner
466c73a7b3 net/upnp: suggestion from #4629 2025-10-30 12:46:30 +01:00
Franco Fichtner
f658f82aa4 net/upnp: suggestion from @Self-Hosting-Group 2025-10-29 16:40:48 +01:00
Franco Fichtner
b6db17f7b0 net/miniupnpd: small updates as discussed 2025-10-29 15:02:58 +01:00
Self-Hosting-Group
f69ae0ecd9
net/upnp: Service improvements (#4629) 2025-10-29 10:05:50 +01:00
Franco Fichtner
d2940eb8af dns/rfc2136: mwexecf_bg, exec_safe and file_safe
PR: https://github.com/opnsense/core/issues/9325
2025-10-28 16:07:25 +01:00
Franco Fichtner
ad06910687 security/acme-client: use mwexec/file_safe
Although technically we shouldn't from classes inside MVC but it is what
it is.

PR: https://github.com/opnsense/core/issues/9325
2025-10-28 15:37:39 +01:00
Franco Fichtner
3af63008f9 net/igmp-proxy: use mwexecf and file_safe
PR: https://github.com/opnsense/core/issues/9325
2025-10-28 15:27:51 +01:00
Franco Fichtner
7ceccc441b www/nginx: use mwexecf
PR: https://github.com/opnsense/core/issues/9325
2025-10-28 15:26:04 +01:00
Franco Fichtner
5962dc7c18 net/upnp: switch to mwexecf variants
PR: https://github.com/opnsense/core/issues/9325
2025-10-28 15:24:47 +01:00
Franco Fichtner
4b8549f7dd plugins: sync and wording in advanced theme 2025-10-27 11:26:58 +01:00
Franco Fichtner
dcb2e4d7f1 misc/theme-flexcolor: automated style sweep and wording 2025-10-27 11:26:30 +01:00
Schnuffel2008
818440296f
This is my theme "flexcolor" (#4927) 2025-10-27 11:20:33 +01:00
Matthias Valvekens
3222e2e1f9
net/tayga: static mapping support (#4986)
Implement support for the 'map' directive in Tayga
that can be used to statically define one-to-one
maps between IPv4 and IPv6 prefixes.

Implements #4606.
2025-10-24 09:15:42 +02:00
Franco Fichtner
b31937c1ab make: allow multiple stable pull here too 2025-10-23 18:05:44 +02:00
Michael
8b3741f591
net/freeradius: Add LDAP Groups (#4989) 2025-10-22 17:02:44 +02:00
Franco Fichtner
095ab23c68 sysutils/git-backup: revision bump 2025-10-22 16:13:39 +02:00
Hleb Shauchenka
416712dbed
sysutils/git-backup: fix force push (#4988) 2025-10-22 15:35:52 +02:00
Franco Fichtner
a828890850 sysutils/git-backup: small model style updates 2025-10-21 14:57:55 +02:00
Franco Fichtner
7989a4fc8f sysutils/git-backup: new version 2025-10-21 14:54:32 +02:00
Franco Fichtner
443c7a65bf dns/ddclient: new version 2025-10-21 14:51:10 +02:00
Franco Fichtner
04a0f55879 www/squid: use short version as discussed 2025-10-21 08:36:32 +02:00
Franco Fichtner
3931aaaff4 security/q-feeds-connector: now fix style as lint works ;) 2025-10-21 08:35:06 +02:00
Franco Fichtner
765f8d80e6 security/q-feeds-connector: fix lint pass 2025-10-21 08:34:31 +02:00
Franco Fichtner
68c34f4f0b www/squid: annotate fix contribution 2025-10-20 16:15:34 +02:00
Michael
d9dea7f9cc
www/squid: add email_err_data off as static (#4987) 2025-10-20 15:08:50 +02:00
Franco Fichtner
2635f71fc1 vendory/sunnyvalley: bump revision for rebuild 2025-10-20 13:51:32 +02:00