OPNSense/core 0a39c16 — src/etc/inc interfaces.inc, src/etc/rc.syshook.d/carp 20-ppp

interfaces: defer PPP to after bootup as an idea for #10936

This is just a sketch that may fix other bootup related issues with PPPoE
where it retriggers DHCPv6 too many times.  Maybe this way we can avoid
both and just need to add some glue for CARP support in the shell script.
DeltaFile
+22-8src/etc/inc/interfaces.inc
+10-0src/etc/rc.syshook.d/start/10-newwanip
+2-0src/etc/rc.syshook.d/carp/20-ppp
+34-83 files

OPNSense/core 256d278 — src/etc/inc interfaces.inc

interfaces: spurious return statement in interfaces_wlan_configure()
DeltaFile
+0-2src/etc/inc/interfaces.inc
+0-21 files

OPNSense/core f770a88 — src/etc/inc filter.lib.inc

Firewall: NAT: Destination NAT - minor cleanup in previous preventing int's causing deprecation warnings in development mode
DeltaFile
+1-1src/etc/inc/filter.lib.inc
+1-11 files

OPNSense/core 9da4d85 — src/etc/inc filter.lib.inc

Firewall: NAT: Destination NAT - add safety guards for calculated port ranges, closes https://github.com/opnsense/core/pull/10945

Minor cleanup ensuring proper handling of ranges for empty targets.

Reported by: @fa1k3
DeltaFile
+2-2src/etc/inc/filter.lib.inc
+2-21 files

OPNSense/core c310068 — src/etc/inc interfaces.inc, src/opnsense/scripts/interfaces apply_pending_if_changes.php

interfaces: add a new 'updateip' hook

'newwanip' is misused sometimes and never called in static configurations.
The only consumer is the RFC2136 plugin but maybe that changes in the
future.  The plugin also listens on "bootup" and "local" so simply making
a global event for use at the spots where it exists is enough.
DeltaFile
+1-2src/opnsense/scripts/interfaces/apply_pending_if_changes.php
+1-2src/etc/inc/interfaces.inc
+2-42 files

OPNSense/core 57bc18f — src/etc/inc filter.lib.inc, src/opnsense/mvc/app/library/OPNsense/Firewall ForwardRule.php

Firewall: NAT: Destination NAT - add safety guards for calculated port ranges, closes https://github.com/opnsense/core/pull/10945

As normalizedPort() is only used to pass values in nat rules, it's more consistent to replace 'any' with empty as that's what the firewall parser would also do.
Next we need to make sure only numeric values are being used in calculations and the upper bound [65535] is respected in all cases.
DeltaFile
+5-4src/etc/inc/filter.lib.inc
+3-0src/opnsense/mvc/app/models/OPNsense/Base/FieldTypes/PortField.php
+1-1src/opnsense/mvc/app/library/OPNsense/Firewall/ForwardRule.php
+2-0src/opnsense/mvc/tests/app/models/OPNsense/Base/FieldTypes/PortFieldTest.php
+11-54 files

OPNSense/core a37badb — src/opnsense/mvc/app/models/OPNsense/Base/FieldTypes PortField.php, src/opnsense/mvc/tests/app/models/OPNsense/Base/FieldTypes PortFieldTest.php

MVC: PortField - keep the first well-known service in the option list (#10947)
DeltaFile
+15-0src/opnsense/mvc/tests/app/models/OPNsense/Base/FieldTypes/PortFieldTest.php
+4-3src/opnsense/mvc/app/models/OPNsense/Base/FieldTypes/PortField.php
+19-32 files

OPNSense/core 397ee8a — Mk git.mk

make: repair full file matching introduced a while back
DeltaFile
+1-1Mk/git.mk
+1-11 files

OPNSense/core d7d7076 — src/opnsense/mvc/app/controllers/OPNsense/Base ApiMutableServiceControllerBase.php

mvc: dispatch failed message during reconfiguredAction()

We lose the stop result in start/reload case but it's not
missing critical.

Suggested by: @Monviech
DeltaFile
+18-12src/opnsense/mvc/app/controllers/OPNsense/Base/ApiMutableServiceControllerBase.php
+18-121 files

OPNSense/core debc632 — src/opnsense/www/js opnsense_ui.js

ui: do not add the spinner again when it fails
DeltaFile
+3-3src/opnsense/www/js/opnsense_ui.js
+3-31 files

OPNSense/core f695486 — src/opnsense/mvc/app/controllers/OPNsense/Base ApiMutableServiceControllerBase.php

mvc: fix
DeltaFile
+1-1src/opnsense/mvc/app/controllers/OPNsense/Base/ApiMutableServiceControllerBase.php
+1-11 files

OPNSense/core 9c0ee87 — src/opnsense/mvc/app/controllers/OPNsense/Base ApiMutableServiceControllerBase.php

mvc: align some more and avoid $result overwrite

We lose the stop result in start/reload case but it's not
missing critical.
DeltaFile
+4-4src/opnsense/mvc/app/controllers/OPNsense/Base/ApiMutableServiceControllerBase.php
+4-41 files

OPNSense/core 3ee5c50 — src/opnsense/mvc/app/controllers/OPNsense/Base ApiMutableServiceControllerBase.php

mvc: dispatch failed message during reconfiguredAction()

Suggested by: @Monviech
DeltaFile
+16-10src/opnsense/mvc/app/controllers/OPNsense/Base/ApiMutableServiceControllerBase.php
+16-101 files

OPNSense/core 44c6e66 — src/opnsense/mvc/app/controllers/OPNsense/Base ApiMutableServiceControllerBase.php

mvc: dispatch failed message during reconfiguredAction()

Suggested by: @Monviech
DeltaFile
+16-10src/opnsense/mvc/app/controllers/OPNsense/Base/ApiMutableServiceControllerBase.php
+16-101 files

OPNSense/core 1cf816d — src/www system_advanced_firewall.php

firewall: stop mentioning outbound NAT in settings page

Also avoid the "inbound NAT" now that outbound NAT is no longer a thing
it seems displaced.  There's no such think anywhere else in the GUI.

PR: https://forum.opnsense.org/index.php?topic=53063.0
DeltaFile
+6-6src/www/system_advanced_firewall.php
+6-61 files

OPNSense/core 791286d — src/etc/inc auth.inc, src/opnsense/mvc/app/models/OPNsense/Auth User.php

system: switch password hashing from bcrypt to argon2id

A bit unfortunate both spots exist, but maybe that can change later on.

(cherry picked from commit 97e503079cc685a51ebf793d0d904fc5bb0dadfe)
DeltaFile
+1-1src/opnsense/mvc/app/models/OPNsense/Auth/User.php
+1-1src/etc/inc/auth.inc
+2-22 files

OPNSense/core 291af34 — . plist, src/opnsense/service/templates/OPNsense/Auth +TARGETS webgui.pam

system: add webgui PAM config to test with opnsense-login

(cherry picked from commit c4ebe6d0867a2edc2921e1cc9031438a38a7c3f8)
DeltaFile
+2-0src/opnsense/service/templates/OPNsense/Auth/webgui.pam
+1-0src/opnsense/service/templates/OPNsense/Auth/+TARGETS
+1-0plist
+4-03 files

OPNSense/core 4311c5a — src/etc/inc auth.inc, src/etc/rc.subr.d recover livemode

system: installer as a real user on demand (#10888)

This allows the installer to use authenticated integration
and SSH keys as a full root user overlay.
DeltaFile
+61-29src/etc/rc.subr.d/livemode
+24-17src/etc/inc/auth.inc
+11-6src/opnsense/mvc/app/models/OPNsense/Auth/FieldTypes/UidField.php
+10-0src/opnsense/mvc/app/library/OPNsense/Auth/Services/WebGui.php
+2-2src/opnsense/mvc/app/models/OPNsense/Auth/User.php
+0-2src/etc/rc.subr.d/recover
+108-561 files not shown
+109-577 files

OPNSense/core 97e5030 — src/etc/inc auth.inc, src/opnsense/mvc/app/models/OPNsense/Auth User.php

system: switch password hashing from bcrypt to argon2id

A bit unfortunate both spots exist, but maybe that can change later on.
DeltaFile
+1-1src/opnsense/mvc/app/models/OPNsense/Auth/User.php
+1-1src/etc/inc/auth.inc
+2-22 files

OPNSense/core 417f7e5 — src/opnsense/mvc/app/controllers/OPNsense/IPsec/forms dialogChild.xml, src/opnsense/mvc/app/models/OPNsense/IPsec Swanctl.xml

VPN: IPsec: Add replay_window to children (#10938)

* VPN: IPsec: Add replay_window to children

Co-authored-by: Franco Fichtner <franco at opnsense.org>

---------

Co-authored-by: Franco Fichtner <franco at opnsense.org>
DeltaFile
+7-0src/opnsense/mvc/app/controllers/OPNsense/IPsec/forms/dialogChild.xml
+5-0src/opnsense/mvc/app/models/OPNsense/IPsec/Swanctl.xml
+12-02 files

OPNSense/core 410ebe4 — src/opnsense/mvc/app/library/OPNsense/Auth/Services WebGui.php

system: prevent installer user from loggin in

This works in testing, but opnsense-login doesn't agree
at first glance.  Need to see why.
DeltaFile
+10-0src/opnsense/mvc/app/library/OPNsense/Auth/Services/WebGui.php
+10-01 files

OPNSense/core 42f457e — src/etc/inc auth.inc, src/opnsense/mvc/app/models/OPNsense/Auth User.php

system: switch password hashing from bcrypt to argon2id

A bit unfortunate both spots exist, but maybe that can change later on.
DeltaFile
+1-1src/opnsense/mvc/app/models/OPNsense/Auth/User.php
+1-1src/etc/inc/auth.inc
+2-22 files

OPNSense/core 1fa5f7c — src/etc/inc config.inc, src/etc/rc.subr.d recover livemode

system: bring installer remove code closer together actually

livemode script is unconditional before login prompt so we can
do the proper cleanup at the last possible point in time.
DeltaFile
+9-0src/etc/rc.subr.d/livemode
+0-8src/etc/inc/config.inc
+0-2src/etc/rc.subr.d/recover
+9-103 files

OPNSense/core 8e3e77c — src/etc/rc.subr.d livemode

system: fix and reindent previous
DeltaFile
+20-22src/etc/rc.subr.d/livemode
+20-221 files

OPNSense/core b0b2df1 — src/etc/inc config.inc auth.inc, src/etc/rc.subr.d livemode

system: make the installer user a real user

This allows the installer to use authenticated integration
and SSH keys as a root overlay.
DeltaFile
+46-20src/etc/rc.subr.d/livemode
+24-17src/etc/inc/auth.inc
+11-6src/opnsense/mvc/app/models/OPNsense/Auth/FieldTypes/UidField.php
+8-0src/etc/inc/config.inc
+2-2src/opnsense/mvc/app/models/OPNsense/Auth/User.php
+1-1src/opnsense/scripts/auth/sync_user.php
+92-466 files

OPNSense/core a6a3685 — src/etc/rc.subr.d livemode

system: not sure if the lock is even necessary
DeltaFile
+2-3src/etc/rc.subr.d/livemode
+2-31 files

OPNSense/core c4ebe6d — . plist, src/opnsense/service/templates/OPNsense/Auth +TARGETS webgui.pam

system: add webgui PAM config to test with opnsense-login
DeltaFile
+2-0src/opnsense/service/templates/OPNsense/Auth/webgui.pam
+1-0src/opnsense/service/templates/OPNsense/Auth/+TARGETS
+1-0plist
+4-03 files

OPNSense/core 353a42b — src/opnsense/mvc/app/models/OPNsense/IPsec Swanctl.xml

Update src/opnsense/mvc/app/models/OPNsense/IPsec/Swanctl.xml

Co-authored-by: Franco Fichtner <franco at opnsense.org>
DeltaFile
+1-1src/opnsense/mvc/app/models/OPNsense/IPsec/Swanctl.xml
+1-11 files

OPNSense/core a2aeeaf — src/etc/inc/plugins.inc.d dpinger.inc

system: add latency_avg as sanity check for running dpinger; closes #10937

The check was introduced in 0df1c0d so there's no technical background
to take into account.  Indeed, latency_avg is probably the reading that
would least likely be 0 in this case.

Suggested by: @mbccd
DeltaFile
+1-1src/etc/inc/plugins.inc.d/dpinger.inc
+1-11 files

OPNSense/core 7eee576 — src/etc/inc/plugins.inc.d dpinger.inc

system: add latency_avg as sanity check for running dpinger; closes #10937

The check was introduced in 0df1c0d so there's no technical background
to take into account.  Indeed, latency_avg is probably the reading that
would least likely be 0 in this case.

Suggested by: @mbccd
DeltaFile
+1-1src/etc/inc/plugins.inc.d/dpinger.inc
+1-11 files