]> git.99rst.org Git - openwrt-packages.git/log
openwrt-packages.git
5 weeks agopython-uvicorn: bump to 0.52.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:07 +0000 (12:32 +0300)]
python-uvicorn: bump to 0.52.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-starlette: bump to 1.6.0
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:06 +0000 (12:32 +0300)]
python-starlette: bump to 1.6.0

Refresh sha256 from PyPI sdist. 1.6.0 switched its build backend from
setuptools to hatchling, so build-depend on python-hatchling/host.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopillow: drop the pybind11 build dependency
Alexandru Ardelean [Tue, 11 Aug 2026 06:22:14 +0000 (09:22 +0300)]
pillow: drop the pybind11 build dependency

Pillow uses pybind11 only for pybind11.setup_helpers.ParallelCompile,
which parallelises the C extension build; it ships no runtime bindings.
Patch setup.py to remove that import and call and drop pybind11 from
build-system.requires, then remove python-pybind11/host from
PKG_BUILD_DEPENDS. The C extensions are compiled serially instead, with
no functional change to the package.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-marshmallow: add test script
Alexandru Ardelean [Sun, 9 Aug 2026 09:40:50 +0000 (12:40 +0300)]
python-marshmallow: add test script

Add a CI test.sh exercising basic package functionality.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-platformdirs: bump to 4.11.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:46 +0000 (12:32 +0300)]
python-platformdirs: bump to 4.11.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-marshmallow: bump to 4.3.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:46 +0000 (12:32 +0300)]
python-marshmallow: bump to 4.3.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-mako: bump to 1.4.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:45 +0000 (12:32 +0300)]
python-mako: bump to 1.4.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-flit-core: revert to 3.12.0
Alexandru Ardelean [Tue, 11 Aug 2026 06:09:08 +0000 (09:09 +0300)]
python-flit-core: revert to 3.12.0

flit-core 4.0.2 breaks the whole python feed. flit-core is a host-only
build backend, but nearly everything built with it caps flit_core<4 (the
host tools wheel/installer/pyproject-hooks/typing-extensions and dozens of
leaf packages like marshmallow, click, pip), so their host builds fail with
"Missing dependencies: flit_core<4" against 4.0.2. Nothing needs
flit_core>=4; 3.12.0 satisfies every cap and has no runtime impact. Revert
until the ecosystem's upper bounds catch up.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agosqueezelite: add version test override
Kel Modderman [Sat, 8 Aug 2026 10:46:57 +0000 (20:46 +1000)]
squeezelite: add version test override

The generic package test greps executable output for PKG_VERSION, which
cannot match here: PKG_VERSION separates the build number with a dot for
apk, while squeezelite reports it with a hyphen.

Derive the expected string from PKG_VERSION rather than hardcoding it, so
the check keeps working on later updates.

Signed-off-by: Kel Modderman <redacted>
5 weeks agosqueezelite: update to 2.0.0.1584
Kel Modderman [Sat, 8 Aug 2026 07:07:44 +0000 (17:07 +1000)]
squeezelite: update to 2.0.0.1584

Refresh sound/squeezelite/patches/010-select_broadcast_interface.patch
and add the git headers required for 'git am' compatibility.

Signed-off-by: Kel Modderman <redacted>
5 weeks agoopenvpn: update to 2.7.6
Sander van Deijck [Mon, 10 Aug 2026 12:36:39 +0000 (14:36 +0200)]
openvpn: update to 2.7.6

Update to the latest version.

For changes, see:
https://github.com/OpenVPN/openvpn/blob/v2.7.6/Changes.rst

Signed-off-by: Sander van Deijck <redacted>
5 weeks agoovpn-dco: update to version 7.1.0.2026080300
Sander van Deijck [Mon, 10 Aug 2026 12:33:13 +0000 (14:33 +0200)]
ovpn-dco: update to version 7.1.0.2026080300

Update to the latest version.

Signed-off-by: Sander van Deijck <redacted>
5 weeks agotelegraf: update to 1.39.3
Niklas Thorild [Mon, 10 Aug 2026 21:27:29 +0000 (23:27 +0200)]
telegraf: update to 1.39.3

Release notes: https://github.com/influxdata/telegraf/releases/tag/v1.39.3

Signed-off-by: Niklas Thorild <redacted>
5 weeks agoredis: update to 8.8.0
Alexandru Ardelean [Sun, 9 Aug 2026 09:16:41 +0000 (12:16 +0300)]
redis: update to 8.8.0

Update from the 6.2.x series to the current 8.x line. The 8.x releases
are tri-licensed (RSALv2 / SSPLv1 / AGPL-3.0); set PKG_LICENSE to
AGPL-3.0-only and follow upstream renaming COPYING to LICENSE.txt.

Drop 020-fix-atomicvar.patch, no longer needed, and keep
030-skip-module-tests.patch. Add a functional test.sh.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-s3transfer: bump to 0.19.2
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:22 +0000 (12:32 +0300)]
python-s3transfer: bump to 0.19.2

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-botocore: bump to 1.43.67
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:22 +0000 (12:32 +0300)]
python-botocore: bump to 1.43.67

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-boto3: bump to 1.43.67
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:20 +0000 (12:32 +0300)]
python-boto3: bump to 1.43.67

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-msgpack: add test script
Alexandru Ardelean [Sun, 9 Aug 2026 09:40:50 +0000 (12:40 +0300)]
python-msgpack: add test script

Add a CI test.sh exercising basic package functionality.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-eventlet: bump to 0.41.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:04 +0000 (12:32 +0300)]
python-eventlet: bump to 0.41.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-msgpack: bump to 1.2.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:03 +0000 (12:32 +0300)]
python-msgpack: bump to 1.2.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-gmpy2: bump to 2.3.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:32:03 +0000 (12:32 +0300)]
python-gmpy2: bump to 2.3.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agobanip: fix cpu core calculation
Dirk Brenken [Mon, 10 Aug 2026 17:35:56 +0000 (19:35 +0200)]
banip: fix cpu core calculation

- only cap the cpu core count by available memory if it was auto-detected,
  a manually set 'ban_cores' is now authoritative and no longer lowered
- readme update: clarify that the auto-cap does not apply to a manually
  set core count

Signed-off-by: Dirk Brenken <redacted>
5 weeks agopython3-drf-nested-routers: update to 0.95.3
Wei-Ting Yang [Mon, 10 Aug 2026 14:25:23 +0000 (22:25 +0800)]
python3-drf-nested-routers: update to 0.95.3

Release notes:
https://github.com/alanjds/drf-nested-routers/releases/tag/v0.95.2
https://github.com/alanjds/drf-nested-routers/releases/tag/v0.95.3

Signed-off-by: Wei-Ting Yang <redacted>
5 weeks agodjango-restframework: update to 3.18.0
Wei-Ting Yang [Mon, 10 Aug 2026 14:01:42 +0000 (22:01 +0800)]
django-restframework: update to 3.18.0

Release notes:
https://github.com/encode/django-rest-framework/releases/tag/3.18.0

Signed-off-by: Wei-Ting Yang <redacted>
5 weeks agodjango: update to 6.1
Wei-Ting Yang [Mon, 10 Aug 2026 13:52:16 +0000 (21:52 +0800)]
django: update to 6.1

Release notes:
https://docs.djangoproject.com/en/6.1/releases/6.1/

Signed-off-by: Wei-Ting Yang <redacted>
5 weeks agopython-asgiref: update to 3.12.1
Wei-Ting Yang [Mon, 10 Aug 2026 14:18:35 +0000 (22:18 +0800)]
python-asgiref: update to 3.12.1

Release notes:
https://github.com/django/asgiref/blob/main/CHANGELOG.txt

Signed-off-by: Wei-Ting Yang <redacted>
5 weeks agouradvd: fix the version check override
Josef Schlehofer [Sun, 9 Aug 2026 10:18:45 +0000 (12:18 +0200)]
uradvd: fix the version check override

The script greps for "uradvd $PKG_SOURCE_DATE", but the test harness
only exports PKG_NAME, PKG_VERSION and CI_HELPERS. PKG_SOURCE_DATE is a
build time Makefile variable and is empty in the test container, so the
grep -Fx pattern is "uradvd " and never matches.

The binary is built with VERSION=$(PKG_SOURCE_DATE) and prints
"uradvd 2025-09-20", while PKG_VERSION is 2025.09.20~<short hash>, so
derive the date from the version instead.

Rename it to test-version.sh in the process: the generic probe looks for
PKG_VERSION verbatim and cannot match the dashed date either, and uradvd
is the only executable in the package, so without an override the whole
package fails. The shebang goes back to /bin/sh, which is what the
harness runs the script with.

Signed-off-by: Josef Schlehofer <redacted>
5 weeks agosyncthing: bump to 2.1.3
George Sapkin [Mon, 10 Aug 2026 12:50:43 +0000 (15:50 +0300)]
syncthing: bump to 2.1.3

Changes: https://github.com/syncthing/syncthing/releases/tag/v2.1.3
Signed-off-by: George Sapkin <redacted>
5 weeks agosudo: add test-version.sh and stop running sudo in tests
Alexandru Ardelean [Mon, 10 Aug 2026 09:41:17 +0000 (12:41 +0300)]
sudo: add test-version.sh and stop running sudo in tests

PKG_VERSION substitutes p->_p (1.9.17_p2) for a valid apk version, but the
binaries print the real 1.9.17p2, so the generic per-executable version
probe reports "no executables provided version" and fails. Add a
test-version.sh that matches the version string compiled into the binary.

Executing sudo under QEMU emulation (e.g. mips_24kc) hangs indefinitely, so
neither test-version.sh nor test.sh runs it any more: the version is read
from the binary and test.sh only checks the installed files.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agosudo: drop 020-no-owner-change.patch for a make override
Alexandru Ardelean [Sun, 9 Aug 2026 10:00:37 +0000 (13:00 +0300)]
sudo: drop 020-no-owner-change.patch for a make override

The patch blanked INSTALL_OWNER in Makefile.in so the staged install does
not chown to install_uid/install_gid, which fails when building as an
unprivileged user. sudo already supports this: the top-level install rule
recurses with "INSTALL_OWNER=$(INSTALL_OWNER)" into every sub-make, and
sudo's own "package" target does "make install INSTALL_OWNER=" for exactly
this fakeroot case. Pass INSTALL_OWNER= via MAKE_INSTALL_FLAGS instead of
carrying a patch.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-installer: allow flit_core 4.x as the build backend
Alexandru Ardelean [Mon, 10 Aug 2026 12:15:27 +0000 (15:15 +0300)]
python-installer: allow flit_core 4.x as the build backend

installer caps flit_core<4 in its build-system, so its /host build fails
with "Missing dependencies: flit_core<4" against flit-core 4.0.2. flit_core
4 builds it unchanged; relax the upper bound.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-pyproject-hooks: allow flit_core 4.x as the build backend
Alexandru Ardelean [Mon, 10 Aug 2026 12:15:26 +0000 (15:15 +0300)]
python-pyproject-hooks: allow flit_core 4.x as the build backend

pyproject-hooks caps flit_core<4 in its build-system, so its /host build
fails with "Missing dependencies: flit_core<4" against flit-core 4.0.2.
flit_core 4 builds it unchanged; relax the upper bound.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agoadblock: fix cpu core calculation
Dirk Brenken [Mon, 10 Aug 2026 17:15:09 +0000 (19:15 +0200)]
adblock: fix cpu core calculation

- only cap the cpu core count by available memory if it was auto-detected,
  a manually set 'adb_cores' is now authoritative and no longer lowered
- readme update: clarify that the auto-cap does not apply to a manually
  set core count

Signed-off-by: Dirk Brenken <redacted>
5 weeks agosamba4: bump to 4.24.5
Aditya Nugraha [Tue, 30 Jun 2026 21:04:47 +0000 (04:04 +0700)]
samba4: bump to 4.24.5

https://www.samba.org/samba/history/samba-4.24.5.html

Patch removed due to fixed in Makefile:
  012-fix-gnutls-version-check.patch

Patch removed because of no longer needed:
  005-musl_uintptr.patch

Makefile:
  Fixed gnutls sed related things.
  Fixed compile_et & asn1_compile linkage at build time to fixes build error
  Dropped NONE from bundled-libraries as to fix compilation errors, NONE
  now seems meaning not to bundle any libraries.
  Added RSTRIP from gcc Makefile to reduce compiled samba4 binaries and
  libraries filesize by around 15%, tested, --private-libraries rpath
  seems intact or identical with not-stripped binaries and libraries
  one.
  samba's cross_answer() returns on the *first* message matching a check in
  cross-answers.txt, and Build/Configure copies the per-arch answers file
  before appending its own answers.  Up to samba 4.16 the check message
  itself carried a "setting/geting hints" typo, which the generated answers
  files inherited; samba fixed its spelling later, so the file entries
  stopped matching and configure started aborting with

  Cross answers file ... is incomplete

  The 'Checking whether fcntl supports setting/getting hints: OK' line
  appended by Build/Configure was added to paper over that, not because the
  targets answer OK.

  Now that the spelling in the answers files is fixed, the generated
  (-11, "") entry matches first and the appended OK is dead code.  Keep the
  generated answer -- samba's test uses F_SET_FILE_RW_HINT/F_GET_FILE_RW_HINT,
  which the kernel no longer implements, so the check legitimately fails on
  every target -- and drop the unreachable echo so each check has exactly
  one answer.

smb.conf.template:
  Added SMB2 as default minimum protocol for client, also enabled server
  & client encryption by default. Use smbpasswd -a username to add a
  username & password for samba. To connect into samba from Windows 10
  and above, it need to be done by this guide : https://www.asus.com/support/faq/1054736/ .

Build system: x86/64
Build-tested: x86/64-glibc
Build-tested: x86/64-musl
Run-tested: x86/64-glibc

Signed-off-by: Aditya Nugraha <redacted>
5 weeks agopython-typing-extensions: allow flit_core 4.x as the build backend
Alexandru Ardelean [Mon, 10 Aug 2026 12:13:35 +0000 (15:13 +0300)]
python-typing-extensions: allow flit_core 4.x as the build backend

Like python-wheel, typing-extensions caps its build backend at
"flit_core >=3.11,<4", so python-typing-extensions/host fails with
"Missing dependencies: flit_core<4,>=3.11" now that the feed ships
flit-core 4.0.2. flit_core 4 builds it unchanged; relax the upper bound.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-vcs-versioning: bump to 2.2.4
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:53 +0000 (12:31 +0300)]
python-vcs-versioning: bump to 2.2.4

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-setuptools-rust: bump to 1.13.0
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:52 +0000 (12:31 +0300)]
python-setuptools-rust: bump to 1.13.0

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-setuptools: bump to 84.0.0
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:52 +0000 (12:31 +0300)]
python-setuptools: bump to 84.0.0

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-wheel: allow flit_core 4.x as the build backend
Alexandru Ardelean [Mon, 10 Aug 2026 08:21:25 +0000 (11:21 +0300)]
python-wheel: allow flit_core 4.x as the build backend

wheel 0.47.0 caps its build requirement at "flit_core >=3.11,<4", but the
feed now ships flit-core 4.0.2, so python-wheel/host (and the whole python
host build-chain that depends on it) fails with "Missing dependencies:
flit_core<4,>=3.11". flit_core 4 builds wheel unchanged, so relax the upper
bound.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agolibmpc: update to 1.4.1 and drop only-src patch
Alexandru Ardelean [Sun, 9 Aug 2026 17:59:24 +0000 (20:59 +0300)]
libmpc: update to 1.4.1 and drop only-src patch

1.4.1 ships as a .tar.xz (the .tar.gz is gone), so switch PKG_SOURCE to
.tar.xz; the @GNU mirror still serves it. Replace 001-only-src.patch
(SUBDIRS = src) with PKG_SUBDIRS:=src so tests/doc/tools stay unbuilt.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agolibrespeed-cli-rust: add new package
Josef Schlehofer [Mon, 10 Aug 2026 02:07:12 +0000 (04:07 +0200)]
librespeed-cli-rust: add new package

Rust port of librespeed-cli for 32-bit PowerPC targets not supported by
the Go implementation, such as CZ.NIC Turris 1.x.

The CLI output of --list and --csv-header matches the Go client, so it
can be used as a drop-in replacement. Both implementations install
/usr/bin/librespeed-cli and therefore PROVIDES/CONFLICTS are set
accordingly.

Use libopenssl instead of rustls' ring backend, which has significantly
better AES-GCM performance on big-endian PowerPC.

Signed-off-by: Josef Schlehofer <redacted>
5 weeks agosscep: rename test.sh to test-version.sh
Josef Schlehofer [Wed, 29 Jul 2026 05:47:46 +0000 (07:47 +0200)]
sscep: rename test.sh to test-version.sh

The script only performs a version check, which is what test-version.sh
is meant for. As a version check override it also replaces the generic
per-executable probing, which warns about mkrequest not reporting the
version.

Signed-off-by: Josef Schlehofer <redacted>
5 weeks agotree-wide: remove quiet mode from grep in test version checks
Josef Schlehofer [Wed, 29 Jul 2026 05:47:42 +0000 (07:47 +0200)]
tree-wide: remove quiet mode from grep in test version checks

Remove the quiet mode flag (-q) from grep in version check commands
to ensure that their stdout output is visible.

While at it, switch the remaining regex matches (perl, sscep, awscli) to
fixed-string matching where appropriate, so that special characters in the
version string are matched literally.

For libzip, the zipcmp and zipmerge branches ran grep and then
unconditionally exited 0, so a version mismatch was never reported and
the version check override always passed.

Signed-off-by: Josef Schlehofer <redacted>
5 weeks agolibsndfile: drop cmake4 patch for a policy override
Alexandru Ardelean [Sun, 9 Aug 2026 17:20:27 +0000 (20:20 +0300)]
libsndfile: drop cmake4 patch for a policy override

001-cmake4.patch backported the unreleased upstream commit 52b803f. The
buildroot's CMake 4 only needs the raised minimum (FindPythonInterp still
resolves), so replace it with -DCMAKE_POLICY_VERSION_MINIMUM=3.5.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-protobuf: add test script
Alexandru Ardelean [Sun, 9 Aug 2026 09:14:15 +0000 (12:14 +0300)]
python-protobuf: add test script

Add a CI test.sh that imports google.protobuf and round-trips the
Timestamp and Struct well-known types through SerializeToString and
ParseFromString, covering the descriptor pool, encoder and decoder
without needing a compiled .proto. Modelled on python-rpds-py's test.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-rpds-py: bump to 2026.6.3
Alexandru Ardelean [Wed, 3 Jun 2026 00:32:32 +0000 (03:32 +0300)]
python-rpds-py: bump to 2026.6.3

Refresh sha256 from the PyPI sdist. Upstream moved to a CalVer scheme.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-protobuf: bump to 7.35.1
Alexandru Ardelean [Wed, 3 Jun 2026 00:32:32 +0000 (03:32 +0300)]
python-protobuf: bump to 7.35.1

Refresh sha256 from the PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-pybind11: bump to 3.1.0
Alexandru Ardelean [Wed, 3 Jun 2026 00:32:32 +0000 (03:32 +0300)]
python-pybind11: bump to 3.1.0

Refresh sha256 from the PyPI sdist. Package is HOST_ONLY, so no target
runtime test is exercised.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-setuptools-scm: bump to 10.2.1
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:46 +0000 (12:31 +0300)]
python-setuptools-scm: bump to 10.2.1

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-hatchling: bump to 1.31.0
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:46 +0000 (12:31 +0300)]
python-hatchling: bump to 1.31.0

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-flit-core: bump to 4.0.2
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:45 +0000 (12:31 +0300)]
python-flit-core: bump to 4.0.2

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-packaging: bump to 26.3
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:03 +0000 (12:31 +0300)]
python-packaging: bump to 26.3

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-argcomplete: bump to 3.7.2
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:03 +0000 (12:31 +0300)]
python-argcomplete: bump to 3.7.2

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
5 weeks agopython-anyio: bump to 4.14.2
Alexandru Ardelean [Sun, 9 Aug 2026 09:31:02 +0000 (12:31 +0300)]
python-anyio: bump to 4.14.2

Refresh sha256 from PyPI sdist.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agohev-socks5-tunnel: allow multiple instances
Sergei S. [Sun, 2 Aug 2026 15:56:02 +0000 (19:56 +0400)]
hev-socks5-tunnel: allow multiple instances

Add support for running multiple service instances.
- switch UCI config from a single named section to "instance" sections
- update the procd init script to start multiple instances
- migrate existing single-instance configurations during package upgrade (uci-defaults script)
- bump PKG_RELEASE

Signed-off-by: Sergei S. <redacted>
6 weeks agopython-cffi: fix cross-compilation on macOS hosts
Josef Schlehofer [Fri, 7 Aug 2026 11:19:31 +0000 (13:19 +0200)]
python-cffi: fix cross-compilation on macOS hosts

setup.py picks the macOS-only -iwithsysroot/usr/include/ffi flag from
sys.platform, which describes the interpreter running the build rather than
the target, so cross-compiling from a macOS host hands an Apple clang flag to
the GNU cross compiler and the build fails. Use sysconfig.get_platform(),
which honours the _PYTHON_HOST_PLATFORM that python3-package.mk exports.

Signed-off-by: Josef Schlehofer <redacted>
6 weeks agoprosody: add test-version.sh
Josef Schlehofer [Sun, 9 Aug 2026 05:38:35 +0000 (07:38 +0200)]
prosody: add test-version.sh

Neither prosody nor prosodyctl reports its version on any flag the
generic tests probe, so the version check fails without an override.
Drop the now duplicate check from the functional test.sh.

Signed-off-by: Josef Schlehofer <redacted>
6 weeks agozabbix: bump version to 7.0.29
Daniel F. Dickinson [Sat, 8 Aug 2026 16:43:53 +0000 (12:43 -0400)]
zabbix: bump version to 7.0.29

July 28, 2026 LTS release: https://www.zabbix.com/rn/rn7.0.29

Patches refreshed (no changes required).

Signed-off-by: Daniel F. Dickinson <redacted>
6 weeks agoradicale3: bump to v3.7.8
Daniel F. Dickinson [Sat, 8 Aug 2026 22:09:46 +0000 (18:09 -0400)]
radicale3: bump to v3.7.8

This is a bugfix and enhancement release: https://github.com/Kozea/Radicale/releases/tag/v3.7.8

It is intended to be the last of the 3.7.x series.

Signed-off-by: Daniel F. Dickinson <redacted>
6 weeks agotravelmate: update 2.4.7-3
Dirk Brenken [Sat, 8 Aug 2026 15:50:24 +0000 (17:50 +0200)]
travelmate: update 2.4.7-3

- fixed the shipped captive portal login scripts,
  corrected the curl call to 'trm_fetchcmd'
- fixed the return code handling within the login scripts
- added a generic portal login script recipe to the readme

Signed-off-by: Dirk Brenken <redacted>
6 weeks agotailscale: update to 1.102.2
Sandro Jäckel [Sun, 26 Jul 2026 22:43:32 +0000 (00:43 +0200)]
tailscale: update to 1.102.2

Changelog: https://tailscale.com/changelog#2026-05-28
Changelog: https://tailscale.com/changelog#2026-06-01
Changelog: https://tailscale.com/changelog#2026-06-29
Changelog: https://tailscale.com/changelog#2026-07-14
Changelog: https://tailscale.com/changelog#2026-07-28
Changelog: https://tailscale.com/changelog#2026-08-03
Changelog: https://tailscale.com/changelog#2026-08-04
Signed-off-by: Sandro Jäckel <redacted>
6 weeks agotravelmate: treat an unresolvable captive portal as an error
Dirk Brenken [Sat, 8 Aug 2026 12:20:50 +0000 (14:20 +0200)]
travelmate: treat an unresolvable captive portal as an error

'trm_netcheck' only ever fired on "net nok", but f_net() reports a detected
portal as "net cp" regardless of 'trm_captive' - the option gates the portal
handling, not the detection. With 'trm_captive' disabled travelmate neither
adds the portal domain to the dhcp rebind allowlist nor runs a login script,
so that state can never resolve on its own: the uplink stayed connected as
"net cp '<domain>'" forever, the vpn was never brought up (it requires "net
ok") and 'trm_netcheck' never kicked in - travelmate stuck to exactly the
uplink the option is meant to get rid of.

Downgrade "net cp" to "net nok" in f_net() when the portal handling is off.
With 'trm_captive' enabled nothing changes.

Signed-off-by: Dirk Brenken <redacted>
6 weeks agoopenssh: reindent Package/<name> metadata blocks to 2 spaces
Michael Pfeifroth [Fri, 7 Aug 2026 11:28:22 +0000 (13:28 +0200)]
openssh: reindent Package/<name> metadata blocks to 2 spaces

FormalityCheck expects package metadata lines inside 'define Package/<name>'
blocks to be indented with exactly 2 spaces. Historically this file used
tabs, which triggers the audit on any newly-touched line. Convert all
metadata lines in the plain 'define Package/<name>' blocks to 2 spaces so
future edits don't repeatedly trip the check.

No functional change: recipe blocks (/install, /conffiles, /description)
retain their tab indentation as required by make.

Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agoopenssh: make libfido2 dependency conditional on sk-helper
Michael Pfeifroth [Mon, 20 Jul 2026 11:28:01 +0000 (13:28 +0200)]
openssh: make libfido2 dependency conditional on sk-helper

The openssh-sk-helper package unconditionally depends on libfido2,
which causes the build system to pull in libfido2 and its dependencies
(libcbor, libudev) even when openssh-sk-helper is not selected.

Use the PACKAGE_openssh-sk-helper:libfido2 conditional dependency
pattern so libfido2 is only required when the sk-helper sub-package
is actually selected.

Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agoliblo: update to 0.36
Alexandru Ardelean [Tue, 28 Jul 2026 11:55:03 +0000 (14:55 +0300)]
liblo: update to 0.36

Update to the latest upstream stable release.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agolibidn: update to 1.44
Alexandru Ardelean [Tue, 28 Jul 2026 11:55:03 +0000 (14:55 +0300)]
libidn: update to 1.44

Update to the latest upstream stable release.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agogpsd: run as dedicated 'gpsd' system user
Michael Pfeifroth [Tue, 4 Aug 2026 16:18:38 +0000 (18:18 +0200)]
gpsd: run as dedicated 'gpsd' system user

Create a dedicated 'gpsd' system user at package-install time (via
USERID) and pin gpsd's built-in privilege-separation identity to it
via the SConstruct 'gpsd_user' option.

Background: gpsd needs to start as root to open the underlying tty /
serial device but then internally setuid()s to a configured
unprivileged identity for the rest of its lifetime -- a built-in
privilege-separation feature of the daemon.

The current package leaves 'gpsd_user' at scons' default 'nobody'.
Sharing 'nobody' across daemons is a hardening anti-pattern:
a compromise of any one 'nobody'-owned process can trivially
interfere with any other, and audit trails become ambiguous.

Group choice: gpsd_group is a device-access knob rather than an
identity knob -- once gpsd has setuid()d away from root it still
needs to open() tty / serial nodes, which OpenWrt exposes as
root:dialout mode 0660 (see procd hotplug.json and base-files
/etc/group).  What actually keeps that access working post-drop is
the setgid() target that gpsd_group selects: gpsd calls
setgroups(0, NULL) immediately before dropping privileges, so any
supplementary groups on the target user are discarded and cannot
carry the permission.

scons' gpsd_group default is not 'nobody' but 'dialout' (uucp on
Gentoo build hosts), so on OpenWrt buildbots the daemon already
lands in 'dialout' today.  Pin gpsd_group=dialout explicitly so the
resulting binary no longer depends on the builder's /etc/gentoo-release:
a Gentoo builder would otherwise bake in 'uucp', a group base-files
does not ship, and gpsd's getgrnam() fallback silently keeps root's
gid in that case.

USERID's third field ('dialout=20') still adds the gpsd user to the
dialout group in /etc/group.  This does not affect the running
daemon (setgroups() strips it) but matches Debian's gpsd packaging
and lets an operator run gpsdctl / gpsmon as 'gpsd' by hand against
device nodes.  GID 20 is the value already frozen into base-files.

Giving gpsd its own primary user:

  * confines a hypothetical gpsd RCE (there have been NMEA / UBX
    parsing bugs historically) to files owned by 'gpsd' rather than
    to the shared 'nobody' identity;
  * matches the long-standing Debian gpsd packaging convention
    (adduser --system gpsd, member of dialout);
  * is a no-op for correctly-configured installations that never
    referenced 'nobody' as an intentional identity.

No numeric UID is pinned for the primary 'gpsd' user -- dynamic
assignment via USERID is sufficient here since no cross-distro
NFS/sudoers-style muscle memory depends on a specific number.

Bump PKG_RELEASE.

Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agoperl: fix arch in powerpc64 config
Michael Pfeifroth [Thu, 28 May 2026 12:51:48 +0000 (14:51 +0200)]
perl: fix arch in powerpc64 config

The powerpc64.config file incorrectly sets arch=powerpc instead of
arch=powerpc64. This causes Perl to misidentify the architecture on
64-bit PowerPC targets.

Fixes: efc7ce461577 ("perl: add powerpc64 support")
Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agorsyslog: track config files for procd restart
Michael Pfeifroth [Fri, 29 May 2026 08:34:54 +0000 (10:34 +0200)]
rsyslog: track config files for procd restart

Add 'procd_set_param file' for both the base config and the generated
config file so procd detects config changes and restarts rsyslogd.

Without this, procd_add_reload_trigger fires on config changes but
procd does not restart the service because the command line is
identical. This leaves stale configuration active until a manual
restart.

Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agosudo: create sudo group
Michael Pfeifroth [Tue, 4 Aug 2026 15:25:32 +0000 (17:25 +0200)]
sudo: create sudo group

Add a 'sudo' system group at package-install time using the USERID
mechanism.

Rationale: sudoers configurations that grant privileges to the 'sudo'
group -- the near-universal Debian/Ubuntu idiom, e.g.

    %sudo ALL=(ALL:ALL) NOPASSWD: ALL

-- fail silently on OpenWrt today because no 'sudo' group exists in
/etc/group.  sudo(8) logs 'unknown group: sudo' and the rule is skipped.
Users also cannot 'usermod -aG sudo <user>' without the group present,
so there is no straightforward way to delegate root without hand-editing
/etc/group or writing per-user sudoers snippets.

Seeding the group here matches how OpenWrt already handles other
service accounts (chrony, dbus, ntpd, ...): the USERID mechanism
creates them lazily via add_group_and_user in the postinst script.

No privileges are granted by default -- an administrator still has to
add users to the group and ship a sudoers rule that references it.

No numeric GID is pinned. The group name is what sudoers, addgroup(1),
and getgrnam() operate on; the numeric GID is invisible to sudo's
authorisation path and matters only for on-disk group ownership
metadata (e.g. 'chgrp sudo' persisted to shared storage) -- something
this package does not do. Letting add_group_and_user pick a dynamic
GID in the 32768+ range keeps sudo out of base-files' reserved
low-range group space and avoids any name-vs-number collision debate.

Bump PKG_RELEASE.

Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agoerlang: remove quiet mode from grep in test version checks
Josef Schlehofer [Thu, 6 Aug 2026 18:48:25 +0000 (20:48 +0200)]
erlang: remove quiet mode from grep in test version checks

Remove the quiet mode flag (-q) from grep in version check commands
to ensure that their stdout output is visible.

Signed-off-by: Josef Schlehofer <redacted>
6 weeks agoerlang: stop shipping sasl in the base package
Josef Schlehofer [Thu, 6 Aug 2026 18:48:19 +0000 (20:48 +0200)]
erlang: stop shipping sasl in the base package

Package/erlang/install copies erts, kernel, sasl and stdlib into
/usr/lib/erlang/lib, and BuildModule builds erlang-sasl from the very
same sasl directory, so both packages own
usr/lib/erlang/lib/sasl-*/ebin/*.beam.

apk refuses to overwrite files owned by another package, so installing
erlang-sasl next to erlang fails:

  ERROR: erlang-sasl-28.5-r1: trying to overwrite
  usr/lib/erlang/lib/sasl-4.3.2/ebin/alarm_handler.beam
  owned by erlang-28.5-r1.

That also takes down erlang-os-mon and erlang-reltool, which depend on
erlang-sasl. The overlap dates back to the import from the old packages
feed and only surfaced once CI started run-testing the subpackages.

Leave sasl to erlang-sasl, which is what that subpackage is for. The
base package keeps bin/start_sasl.boot: it is inert while the runtime
boots via start_clean, and it is needed once erlang-sasl is installed.

Signed-off-by: Josef Schlehofer <redacted>
6 weeks agohev-socks5-tproxy: update to 2.13.0
Ray Wang [Fri, 7 Aug 2026 05:32:16 +0000 (13:32 +0800)]
hev-socks5-tproxy: update to 2.13.0

Upstream changelog:
https://github.com/heiher/hev-socks5-tproxy/releases/tag/2.13.0

Signed-off-by: Ray Wang <redacted>
6 weeks agohev-socks5-server: update to 2.13.0
Ray Wang [Fri, 7 Aug 2026 05:32:05 +0000 (13:32 +0800)]
hev-socks5-server: update to 2.13.0

Upstream changelog:
https://github.com/heiher/hev-socks5-server/releases/tag/2.13.0

Signed-off-by: Ray Wang <redacted>
6 weeks agohev-socks5-tunnel: update to 2.17.0
Ray Wang [Fri, 7 Aug 2026 05:32:21 +0000 (13:32 +0800)]
hev-socks5-tunnel: update to 2.17.0

Upstream changelog:
https://github.com/heiher/hev-socks5-tunnel/releases/tag/2.17.0

Signed-off-by: Ray Wang <redacted>
6 weeks agoimagemagick: add test-version.sh version override
Alexandru Ardelean [Wed, 5 Aug 2026 06:51:17 +0000 (09:51 +0300)]
imagemagick: add test-version.sh version override

The binaries print the version as X.Y.Z-R while PKG_VERSION is X.Y.Z.R,
so the generic per-executable version probe never matches and the job
fails. Add a test-version.sh override that greps for the dashed form,
mirroring the conversion the runtime test.sh already does.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agographicsmagick: expand test.sh coverage
Alexandru Ardelean [Tue, 4 Aug 2026 18:26:20 +0000 (21:26 +0300)]
graphicsmagick: expand test.sh coverage

Exercise more gm subcommands and codecs on top of the existing PNG/JPEG,
resize, pixel, draw and composite checks: TIFF round-trip, PPM and GIF
encoders, crop, 90-degree rotate, horizontal append and in-place mogrify.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agoimagemagick: expand test.sh coverage
Alexandru Ardelean [Tue, 4 Aug 2026 18:26:20 +0000 (21:26 +0300)]
imagemagick: expand test.sh coverage

Exercise more of the toolchain on top of the existing PNG/JPEG/BMP,
resize, pixel-sampling, grayscale and composite checks: TIFF round-trip,
PPM and GIF encoders, crop, 90-degree rotate, horizontal append, the IM7
'magick' driver and in-place mogrify.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agographicsmagick: update to 1.3.48
Alexandru Ardelean [Tue, 28 Jul 2026 12:47:37 +0000 (15:47 +0300)]
graphicsmagick: update to 1.3.48

Update to the latest upstream stable release.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agoimagemagick: update to 7.1.2.29
Alexandru Ardelean [Tue, 28 Jul 2026 12:47:37 +0000 (15:47 +0300)]
imagemagick: update to 7.1.2.29

Update to the latest upstream stable release. Also fix PKG_SOURCE_URL:
imagemagick.org/archive no longer serves the release tarballs (404),
they live under download.imagemagick.org/archive/releases now.

Signed-off-by: Alexandru Ardelean <redacted>
6 weeks agochecksec: remove package
Josef Schlehofer [Thu, 6 Aug 2026 15:07:54 +0000 (17:07 +0200)]
checksec: remove package

The package ships checksec.bash, which upstream has discontinued. When
asked about the version the script reports, upstream answered that the
bash implementation is legacy, will be removed entirely in an upcoming
release and has been rewritten in Go:
https://github.com/slimm609/checksec.sh/issues/352

Signed-off-by: Josef Schlehofer <redacted>
6 weeks agosimple-captive-portal: update to 2026.08.06 / use port 80
Etienne Champetier [Fri, 7 Aug 2026 00:49:31 +0000 (20:49 -0400)]
simple-captive-portal: update to 2026.08.06 / use port 80

No issue reported but this is a bit cleaner.

Signed-off-by: Etienne Champetier <redacted>
6 weeks agobanip: report the last run timestamp as ISO 8601
Dirk Brenken [Thu, 6 Aug 2026 19:26:44 +0000 (21:26 +0200)]
banip: report the last run timestamp as ISO 8601

The runtime status reported the last run as DD/MM/YYYY, which reads as a
different date entirely for anyone used to month first ordering.

Use YYYY-MM-DD instead for the frontpage and the Set reporting.
The new ISO 8601 format is unambiguous regardless of the reader's locale.

Signed-off-by: Dirk Brenken <redacted>
6 weeks agotravelmate: release 2.4.7-1
Dirk Brenken [Thu, 6 Aug 2026 13:56:40 +0000 (15:56 +0200)]
travelmate: release 2.4.7-1

* harden the connectivity check in f_net()
* drop the ineffective 'trm_netcheck' term from the minimum signal
  quality branch in f_check()
* reset 'trm_connection' explicitly in the netcheck exit path
* log the affected uplink in the netcheck messages
* update and restructure the readme

Signed-off-by: Dirk Brenken <redacted>
6 weeks agoadblock: report the last run timestamp as ISO 8601
Dirk Brenken [Wed, 5 Aug 2026 16:27:10 +0000 (18:27 +0200)]
adblock: report the last run timestamp as ISO 8601

The runtime status reported the last run as DD/MM/YYYY, which reads as a
different date entirely for anyone used to month first ordering.

Use YYYY-MM-DD instead. The DNS report already derives its timestamps from
tcpdump -tttt and is ISO 8601, so both views now agree, and the format is
unambiguous regardless of the reader's locale.

Signed-off-by: Dirk Brenken <redacted>
6 weeks agostrongswan: swanctl.init: remove invalid privkeys option
Florian Eckert [Tue, 4 Aug 2026 11:47:33 +0000 (13:47 +0200)]
strongswan: swanctl.init: remove invalid privkeys option

The 'swanctl.conf' has no 'privkeys' option in
'connections.<conn>.local<suffix>'. The only local-round keys documented
for authentication are 'certs', 'cert<suffix>' and 'pubkeys'. Strongswan
does not let a connection reference a private key by name at all - swanctl
auto-selects the matching private key from '/etc/swanctl/private'
(or rsa/ecdsa/pkcs8) by comparing it against the certificate configured
via 'certs' when credentials are loaded.

Writing 'privkeys = $local_key' into the generated swanctl.conf is
therefore a no-op at best: the option is unknown to the parser and
gets silently dropped, so it never had any effect on which key was
used.

Drop the bogus assignment. The existing local_key validation making
sure the referenced file exists under '/etc/swanctl/private'. Since that's
still useful to catch misconfiguration early, and add a comment explaining
why nothing is written to swanctl.conf for it.

Signed-off-by: Florian Eckert <redacted>
6 weeks agoovpn-dco: fix build on 6.18.40
Qingfang Deng [Tue, 4 Aug 2026 10:56:32 +0000 (18:56 +0800)]
ovpn-dco: fix build on 6.18.40

6.18.40 commit 073d95725269 changed the prototype of proto::recvmsg.
Update the ifdef.

Signed-off-by: Qingfang Deng <redacted>
6 weeks agocligen: fix depends
Andy Chiang [Mon, 3 Aug 2026 05:42:14 +0000 (12:42 +0700)]
cligen: fix depends

fixes: https://github.com/openwrt/openwrt/pull/24247#issuecomment-5139402966

Signed-off-by: Andy Chiang <redacted>
6 weeks agocryptsetup: update to 2.8.7
Rosen Penev [Sat, 1 Aug 2026 00:17:17 +0000 (17:17 -0700)]
cryptsetup: update to 2.8.7

Use OpenSSL now as AF_ALG has been deprecated.

Signed-off-by: Rosen Penev <redacted>
6 weeks agoci: bump lewagon/wait-on-check-action from 1.8.1 to 1.9.0
dependabot[bot] [Sat, 1 Aug 2026 21:15:29 +0000 (21:15 +0000)]
ci: bump lewagon/wait-on-check-action from 1.8.1 to 1.9.0

Bumps [lewagon/wait-on-check-action](https://github.com/lewagon/wait-on-check-action) from 1.8.1 to 1.9.0.
- [Release notes](https://github.com/lewagon/wait-on-check-action/releases)
- [Changelog](https://github.com/lewagon/wait-on-check-action/blob/master/CHANGELOG.md)
- [Commits](https://github.com/lewagon/wait-on-check-action/compare/v1.8.1...v1.9.0)

---
updated-dependencies:
- dependency-name: lewagon/wait-on-check-action
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <redacted>
6 weeks agotrafficshaper: avoid recursive dependency
Dharmik Parmar [Mon, 20 Jul 2026 03:03:37 +0000 (08:33 +0530)]
trafficshaper: avoid recursive dependency

The conditional nftables dependency causes Kconfig to select
PACKAGE_nftables-nojson from itself:

  symbol PACKAGE_nftables-nojson is selected by PACKAGE_nftables-nojson

Split the firewall dependencies into nftables and iptables variants. Keep
trafficshaper as the default nftables variant and provide
trafficshaper-iptables for older systems.

Fixes: 2e945de232bd ("trafficshaper: add nftables firewall backend")
Signed-off-by: Dharmik Parmar <redacted>
6 weeks agonano: update to 9.2
Hannu Nyman [Mon, 3 Aug 2026 15:10:36 +0000 (18:10 +0300)]
nano: update to 9.2

Update nano editor to version 9.2.
https://www.nano-editor.org/news.php

Signed-off-by: Hannu Nyman <redacted>
6 weeks agomodemmanager: skip virtual net devices in hotplug script
Michael Pfeifroth [Mon, 3 Aug 2026 09:13:18 +0000 (11:13 +0200)]
modemmanager: skip virtual net devices in hotplug script

Every net uevent - eth ports, USB hubs, bridges, taps, SQM IFB,
GRE tunnels, veth, tun/tap - is handed to mmcli via
25-modemmanager-net's mm_report_event call, so ModemManager logs a
'not supported by any plugin' notice per device on every boot and
hotplug replay:

  ModemManager[15132]: <msg> [base-manager] couldn't check support
    for device '.../fsl-ehci.0/usb1/1-1/1-1.1':
    not supported by any plugin

mm_report_event() already discards virtual devices internally, but
only after mm_log "info" has written a "hotplug: add network
interface XXX: event processed" line to daemon.info for every one
of them.

Mirror the same guard in the hotplug script by exiting early when
DEVPATH points under /devices/virtual/*, which covers SQM IFB, GRE,
bridges, veth, tun/tap.  This never rejects a physical modem port
(kernel wwan, MHI, USB CDC/RNDIS/QMI/MBIM are all under real bus
subtrees).

Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agomodemmanager: skip live report when the service isn't up yet
Michael Pfeifroth [Fri, 31 Jul 2026 12:05:38 +0000 (14:05 +0200)]
modemmanager: skip live report when the service isn't up yet

At boot procd replays every previously-seen uevent before
/etc/init.d/modemmanager starts.  Each replay walks the hotplug.d/
tree, which calls mm_report_event() in modemmanager.common.  That
helper does two independent things:

  1) appends the event to ${MODEMMANAGER_EVENTS_CACHE}, and
  2) runs 'mmcli --report-kernel-event=...' to notify a live MM.

Step 1 is what matters for boot; step 2 exists so events fired
after MM is running get reported without waiting for the next
cache replay.  The cache path is intentional: ModemManager-wrapper
starts MM, then mm_report_events_from_cache() polls 'mmcli -L'
until the bus is available and replays every cached event.

At boot the modemmanager service instance hasn't been spawned by
procd yet, so step 2 always fails with:

  daemon.err ModemManager[NNN]: hotplug: Couldn't report kernel
    event: error: couldn't get bus: Could not connect: No such
    file or directory

That's one daemon.err line per hotplug script per port, per boot.
On a dual-modem board that's a dozen spurious errors before the
service even starts.  Nothing is lost -- the wrapper's cache
replay picks them all up seconds later -- but the log noise makes
real ModemManager errors harder to spot.

Guard the live call with a cheap pidfile-based liveness check.
The pidfile is procd's, so it proves the service instance has
been spawned, not that MM is already reachable on the bus; the
brief wrapper-startup window (procd spawns the wrapper -> wrapper
execs MM -> MM reaches the bus) is not covered.  In practice no
fresh uevents fire in that window on the boards this was tested
on, and events that do arrive there are still cached.  If the
service hasn't been spawned yet, the event is silently cached and
the wrapper handles it.  If it has, behavior is unchanged.

Signed-off-by: Michael Pfeifroth <redacted>
6 weeks agostrongswan: bump PKG_RELEASE by one
Florian Eckert [Mon, 27 Jul 2026 08:43:22 +0000 (10:43 +0200)]
strongswan: bump PKG_RELEASE by one

Update 'PKG_RELEASE'.

Signed-off-by: Florian Eckert <redacted>
6 weeks agostrongswan: write local_key to swanctl.conf
Florian Eckert [Mon, 27 Jul 2026 13:47:59 +0000 (15:47 +0200)]
strongswan: write local_key to swanctl.conf

The 'local_key' UCI option was validated (checked for existence
under /etc/swanctl/private/) but never written to the generated
'swanctl.conf'. As a result, setting 'local_key' had no actual effect
on which private key was used for local authentication.

Add the corresponding "privkeys" line to the local{} section,
mirroring how local_cert is already written as "certs", so that
swanctl explicitly uses the configured private key.

Signed-off-by: Florian Eckert <redacted>
6 weeks agostrongswan: rename 'local_sourceip' to 'vips'
Florian Eckert [Mon, 27 Jul 2026 12:00:24 +0000 (14:00 +0200)]
strongswan: rename 'local_sourceip' to 'vips'

The name 'local_sourceip' was misleading, since the option actually
refers to virtual IP addresses (VIPs) used for routing/binding,
not just a single local source IP. Renaming it to 'vips' better
reflects its purpose and makes the configuration more intuitive
for users, especially in setups with multiple virtual IPs.

Add a uci-defaults migration script to convert existing 'local_sourceip'
entries (whether stored as a plain option or as a list) to a
'vips' list on upgrade.

Signed-off-by: Florian Eckert <redacted>
6 weeks agostrongswan: rename 'local_ip' to 'local_addrs'
Florian Eckert [Thu, 23 Jul 2026 14:18:18 +0000 (16:18 +0200)]
strongswan: rename 'local_ip' to 'local_addrs'

Rename the 'local_ip' UCI option to 'local_addrs' to match the
'swanctl.conf' 'local_addrs' directive, which accepts one or more
local addresses rather than implying a single fixed IP. The
previous name suggested only one address could be configured.

Store the option as a UCI list to allow specifying multiple local
addresses, consistent with how 'remote_addrs' is already handled.
If left empty, no 'local_addrs' line is written to 'swanctl.conf',
so strongswan falls back to its own default of '%any'.

Add a uci-defaults migration script to convert existing 'local_ip'
entries (whether stored as a plain option or as a list) to a
'local_addrs' list on upgrade.

Signed-off-by: Florian Eckert <redacted>
6 weeks agostrongswan: rename 'remote_gateway' to 'remote_addrs'
Florian Eckert [Thu, 23 Jul 2026 13:30:23 +0000 (15:30 +0200)]
strongswan: rename 'remote_gateway' to 'remote_addrs'

Rename the 'remote_gateway' UCI option to 'remote_addrs' to match
the 'swanctl.conf' 'remote_addrs' directive, which accepts one or
more peer addresses rather than a single gateway. The previous
name implied a single value and did not reflect that multiple
remote addresses can be configured for a connection.

Store the option as a UCI list to allow specifying multiple
remote addresses, consistent with how 'local_subnet' and
'remote_subnet' are already handled.

Add a uci-defaults migration script to convert existing
'remote_gateway' entries (whether stored as a plain option or as
a list) to a 'remote_addrs' list on upgrade.

If the 'remote_addrs' option is empty, strongswan implicitly uses the value
'%any'. In the `swanctl.conf` documentation, '%any' is already the default
value for 'remote_addrs' if the directive is not specified at all.

Signed-off-by: Florian Eckert <redacted>
6 weeks agostrongswan: rename 'gateway' to 'remote_gateway'
Florian Eckert [Thu, 23 Jul 2026 12:25:53 +0000 (14:25 +0200)]
strongswan: rename 'gateway' to 'remote_gateway'

The UCI option 'gateway' in the ipsec config (consumed by
/etc/init.d/swanctl) is ambiguous. It is not clear from the name
alone whether it refers to the local or the remote IKE/IPsec
peer address, which has repeatedly led to misconfiguration.

Rename it to "remote_gateway" to make the direction explicit and
to match the existing "remote_subnet" naming. If the option is
unset, the init script now falls back to the strongSwan default
of '%any', so connections that accept any remote peer no longer
require an explicit placeholder value.

Add a uci-defaults migration script to rename existing 'gateway'
entries to 'remote_gateway' and remove the value 'any' on upgrade. This
is new default if 'remote_gateway' is not set.

Signed-off-by: Florian Eckert <redacted>
git clone https://git.99rst.org/PROJECT