<feed xmlns='http://www.w3.org/2005/Atom'>
<title>staging/pepe2k/package, branch v21.02.3</title>
<subtitle>Staging tree of Piotr Dymacz</subtitle>
<id>https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v21.02.3</id>
<link rel='self' href='https://git.openwrt.org/openwrt/staging/pepe2k/atom?h=v21.02.3'/>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/'/>
<updated>2022-04-17T19:00:03Z</updated>
<entry>
<title>OpenWrt v21.02.3: adjust config defaults</title>
<updated>2022-04-17T19:00:03Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2022-04-17T19:00:03Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=42a15ca378e1bc52f125f894d748c31ce3c52903'/>
<id>urn:sha1:42a15ca378e1bc52f125f894d748c31ce3c52903</id>
<content type='text'>
Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>ath79: add support for Yuncore A930</title>
<updated>2022-04-16T12:48:45Z</updated>
<author>
<name>Thibaut VARÈNE</name>
</author>
<published>2022-04-15T11:17:53Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=2cc9ee8000597fe132071ec3ba6bf0ac9404ac94'/>
<id>urn:sha1:2cc9ee8000597fe132071ec3ba6bf0ac9404ac94</id>
<content type='text'>
Specification:

- QCA9533 (650 MHz), 64 or 128MB RAM, 16MB SPI NOR
- 2x 10/100 Mbps Ethernet, with 802.3at PoE support (WAN)
- 2T2R 802.11b/g/n 2.4GHz

Flash instructions:

If your device comes with generic QSDK based firmware, you can login
over telnet (login: root, empty password, default IP: 192.168.188.253),
issue first (important!) 'fw_setenv' command and then perform regular
upgrade, using 'sysupgrade -n -F ...' (you can use 'wget' to download
image to the device, SSH server is not available):

  fw_setenv bootcmd "bootm 0x9f050000 || bootm 0x9fe80000"
  sysupgrade -n -F openwrt-...-yuncore_...-squashfs-sysupgrade.bin

In case your device runs firmware with YunCore custom GUI, you can use
U-Boot recovery mode:

1. Set a static IP 192.168.0.141/24 on PC and start TFTP server with
   'tftp' image renamed to 'upgrade.bin'
2. Power the device with reset button pressed and release it after 5-7
   seconds, recovery mode should start downloading image from server
   (unfortunately, there is no visible indication that recovery got
   enabled - in case of problems check TFTP server logs)

Signed-off-by: Clemens Hopfer &lt;openwrt@wireloss.net&gt;
Signed-off-by: Thibaut VARÈNE &lt;hacks@slashdirt.org&gt;
(cherry-picked from commit a05dcb07241aa83a4416b56201e31b4af8518981)
[switch to mtd-mac-address instead of nvmem-cells]
</content>
</entry>
<entry>
<title>ath79: add support for Yuncore XD3200</title>
<updated>2022-04-16T12:48:29Z</updated>
<author>
<name>Thibaut VARÈNE</name>
</author>
<published>2022-04-15T11:17:49Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=06874171d125f0a69d6fb8cfd12213b7913d317e'/>
<id>urn:sha1:06874171d125f0a69d6fb8cfd12213b7913d317e</id>
<content type='text'>
Specification:

- QCA9563 (775MHz), 128MB RAM, 16MB SPI NOR
- 2T2R 802.11b/g/n 2.4GHz
- 2T2R 802.11n/ac 5GHz
- 2x 10/100/1000 Mbps Ethernet, with 802.3at PoE support (WAN port)

LED for 5 GHz WLAN is currently not supported as it is connected directly
to the QCA9882 radio chip.

Flash instructions:

If your device comes with generic QSDK based firmware, you can login
over telnet (login: root, empty password, default IP: 192.168.188.253),
issue first (important!) 'fw_setenv' command and then perform regular
upgrade, using 'sysupgrade -n -F ...' (you can use 'wget' to download
image to the device, SSH server is not available):

  fw_setenv bootcmd "bootm 0x9f050000 || bootm 0x9fe80000"
  sysupgrade -n -F openwrt-...-yuncore_...-squashfs-sysupgrade.bin

In case your device runs firmware with YunCore custom GUI, you can use
U-Boot recovery mode:

1. Set a static IP 192.168.0.141/24 on PC and start TFTP server with
   'tftp' image renamed to 'upgrade.bin'
2. Power the device with reset button pressed and release it after 5-7
   seconds, recovery mode should start downloading image from server
   (unfortunately, there is no visible indication that recovery got
   enabled - in case of problems check TFTP server logs)

Signed-off-by: Thibaut VARÈNE &lt;hacks@slashdirt.org&gt;
(cherry-picked from commit c91df224f54fdd44c9c0487a8c91876f5d273164)
</content>
</entry>
<entry>
<title>wolfssl: bump to 5.2.0</title>
<updated>2022-04-11T20:52:57Z</updated>
<author>
<name>Eneas U de Queiroz</name>
</author>
<published>2022-04-08T13:27:25Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=c5ef62a218455f5d60b8f76307784a90a77dda43'/>
<id>urn:sha1:c5ef62a218455f5d60b8f76307784a90a77dda43</id>
<content type='text'>
Fixes two high-severity vulnerabilities:

- CVE-2022-25640: A TLS v1.3 server who requires mutual authentication
  can be bypassed.  If a malicious client does not send the
  certificate_verify message a client can connect without presenting a
  certificate even if the server requires one.

- CVE-2022-25638: A TLS v1.3 client attempting to authenticate a TLS
  v1.3 server can have its certificate heck bypassed. If the sig_algo in
  the certificate_verify message is different than the certificate
  message checking may be bypassed.

Signed-off-by: Eneas U de Queiroz &lt;cotequeiroz@gmail.com&gt;
(cherry picked from commit e89f3e85eb1c1d81294e5d430a91b0ba625e2ec0)
</content>
</entry>
<entry>
<title>mac80211: Update to version 5.10.110-1</title>
<updated>2022-04-11T20:51:57Z</updated>
<author>
<name>Hauke Mehrtens</name>
</author>
<published>2022-04-10T22:26:29Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=99b00edf35bc11c3cd761762a5e880ac1daea067'/>
<id>urn:sha1:99b00edf35bc11c3cd761762a5e880ac1daea067</id>
<content type='text'>
This updates mac80211 to version 5.10.110-1 which is based on kernel
5.10.110.
The removed patches were applied upstream.

This new release contains many fixes which were merged into the upstream
Linux kernel.

Signed-off-by: Hauke Mehrtens &lt;hauke@hauke-m.de&gt;
</content>
</entry>
<entry>
<title>bpftools: fix feature override for masking clang</title>
<updated>2022-04-11T20:51:57Z</updated>
<author>
<name>Tony Ambardar</name>
</author>
<published>2021-04-12T23:46:22Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=91323444444d2c60b81ec5ba064c21609db83a84'/>
<id>urn:sha1:91323444444d2c60b81ec5ba064c21609db83a84</id>
<content type='text'>
Rename feature variable clang-bpf-global-var following upstream changes.
This restores the HAVE_CLANG feature override and should avoid rare build
errors where a recent host clang and BTF-enabled host kernel are present.

Fixes: 23be333401f0 ("bpftools: update to 5.10.10")
Signed-off-by: Tony Ambardar &lt;itugrok@yahoo.com&gt;
(cherry picked from commit cf20f1bb5f0479c2509dd651d08e235a3b9e8755)
</content>
</entry>
<entry>
<title>cypress-firmware: drop several packages</title>
<updated>2022-03-26T20:26:07Z</updated>
<author>
<name>Josef Schlehofer</name>
</author>
<published>2022-03-20T22:28:41Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=52de8bf86e616de1b86ec2ab5e874029339adb16'/>
<id>urn:sha1:52de8bf86e616de1b86ec2ab5e874029339adb16</id>
<content type='text'>
1. Drop package: cypress-firmware-4359-pcie
This binary is no longer provided and there are not many details what
happened.

2. Drop package: cypress-firmware-4359-sdio
This binary is no longer provided, but in this case, to compare it with
PCIe package mention as first, there was added
support in Linux-firmware [1], but no sign of firmware file.

4. Drop package: cypress-firmware-89459-pcie [2]
According to Infineon: "CYW89459 is an automotive Wi-Fi chip which is not
supported in the broad market community."

[1] https://patchwork.kernel.org/project/linux-wireless/patch/20191211235253.2539-6-smoch@web.de/

[2] https://community.infineon.com/t5/Wi-Fi-Bluetooth-for-Linux/the-wifi-driver-for-CYW89459-in-linux4-14-98-2-3-00/m-p/138971

Fixes: 7ca7e0b22de6e629f5df12b8a935a168073bcca3 ("cypress-firmware:
update it to version 5.4.18-2021_0812")

Signed-off-by: Josef Schlehofer &lt;pepe.schlehofer@gmail.com&gt;
(cherry picked from commit 8c66bf89d1e8e67d8a3537e164bb7d9669259c08)
</content>
</entry>
<entry>
<title>cypress-firmware: update it to version 5.4.18-2021_0812</title>
<updated>2022-03-26T20:26:07Z</updated>
<author>
<name>Josef Schlehofer</name>
</author>
<published>2022-03-16T12:14:57Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=41d36bb2d09503f95d08f8f48c2317fce30f017a'/>
<id>urn:sha1:41d36bb2d09503f95d08f8f48c2317fce30f017a</id>
<content type='text'>
- Binary files were renamed to cyfmac from brcmfmac, but the files needs
  to be on the router with the previous naming

[    6.656165] brcmfmac: brcmf_fw_alloc_request: using brcm/brcmfmac43455-sdio for chip BCM4345/6
[    6.665182] brcmfmac mmc1:0001:1: Direct firmware load for brcm/brcmfmac43455-sdio.bin failed with error -2
[    6.674928] brcmfmac mmc1:0001:1: Falling back to sysfs fallback for: brcm/brcmfmac43455-sdio.bin

- Cypress were acquired by Infineon Technologies
Thus change the project URL and switch to download files from their
GitHub repository. This is much better than the previous solution, which
requires finding new threads on their community forum about new driver
updates, and it will be necessary to change the URL each time.

Unfortunately, it seems that there is not published changelog, but
according to this forum thread [1], be careful by opening the link from
solution since it contains ending bracket ), it brings fixes for various
security vulnerabilities, which were fixed in 7_45_234.

Fixes:
- FragAttacks
- Kr00k

Also add LICENSE file

Run tested on Seeedstudio router powered by Raspberry Pi 4 CM with
package cypress-firmware-43455-sdio.

Before:
root@OpenWrt:~# dmesg | grep 'Firmware: BCM4345/6'
[    6.895050] brcmfmac: brcmf_c_preinit_dcmds: Firmware: BCM4345/6 wl0: Mar 23 2020 02:20:01 version 7.45.206 (r725000 CY) FWID 01-febaba43

After:
root@OpenWrt:~# dmesg | grep 'Firmware: BCM4345/6'
[    6.829805] brcmfmac: brcmf_c_preinit_dcmds: Firmware: BCM4345/6 wl0: Apr 15 2021 03:03:20 version 7.45.234 (4ca95bb CY) FWID 01-996384e2

[1] https://community.infineon.com/t5/Wi-Fi-Bluetooth-for-Linux/Outdated-brcmfmac-firmware-for-Raspberry-Pi-4-in-OpenWrt-21-02-1/m-p/331593#M2269

Signed-off-by: Josef Schlehofer &lt;pepe.schlehofer@gmail.com&gt;
(cherry picked from commit 7ca7e0b22de6e629f5df12b8a935a168073bcca3)
</content>
</entry>
<entry>
<title>zlib: backport security fix for a reproducible crash in compressor</title>
<updated>2022-03-24T08:40:12Z</updated>
<author>
<name>Petr Štetiar</name>
</author>
<published>2022-03-24T05:45:04Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=f65edc9b990c2bcc10c9e9fca29253adc6fe316d'/>
<id>urn:sha1:f65edc9b990c2bcc10c9e9fca29253adc6fe316d</id>
<content type='text'>
Tavis has just reported, that he was recently trying to track down a
reproducible crash in a compressor. Believe it or not, it really was a
bug in zlib-1.2.11 when compressing (not decompressing!) certain inputs.

Tavis has reported it upstream, but it turns out the issue has been
public since 2018, but the patch never made it into a release. As far as
he knows, nobody ever assigned it a CVE.

Suggested-by: Tavis Ormandy &lt;taviso@gmail.com&gt;
References: https://www.openwall.com/lists/oss-security/2022/03/24/1
Signed-off-by: Petr Štetiar &lt;ynezz@true.cz&gt;
(cherry picked from commit b3aa2909a79aeff20d594160b207a89dc807c033)
(cherry picked from commit 3965dda0fa70dc9408f1a2e55a3ddefde78bd50e)
</content>
</entry>
<entry>
<title>hostapd: add STA extended capabilities to get_clients</title>
<updated>2022-03-20T00:32:36Z</updated>
<author>
<name>David Bauer</name>
</author>
<published>2022-02-16T22:09:51Z</published>
<link rel='alternate' type='text/html' href='https://git.openwrt.org/openwrt/staging/pepe2k/commit/?id=180b750c02dd9dd066cf67ee7c3480eb0ec36b70'/>
<id>urn:sha1:180b750c02dd9dd066cf67ee7c3480eb0ec36b70</id>
<content type='text'>
Add the STAs extended capabilities to the ubus STA information. This
way, external daemons can be made aware of a STAs capabilities.

This field is of an array type and contains 0 or more bytes of a STAs
advertised extended capabilities.

Signed-off-by: David Bauer &lt;mail@david-bauer.net&gt;
(cherry picked from commit 6f787239771044ed7eeaf22301c543b699f25cb4)
</content>
</entry>
</feed>
