interfaces: defer PPP to after bootup as an idea for #10936
This is just a sketch that may fix other bootup related issues with PPPoE
where it retriggers DHCPv6 too many times. Maybe this way we can avoid
both and just need to add some glue for CARP support in the shell script.
interfaces: add a new 'updateip' hook
'newwanip' is misused sometimes and never called in static configurations.
The only consumer is the RFC2136 plugin but maybe that changes in the
future. The plugin also listens on "bootup" and "local" so simply making
a global event for use at the spots where it exists is enough.
Firewall: NAT: Destination NAT - add safety guards for calculated port ranges, closes https://github.com/opnsense/core/pull/10945
As normalizedPort() is only used to pass values in nat rules, it's more consistent to replace 'any' with empty as that's what the firewall parser would also do.
Next we need to make sure only numeric values are being used in calculations and the upper bound [65535] is respected in all cases.
mvc: dispatch failed message during reconfiguredAction()
We lose the stop result in start/reload case but it's not
missing critical.
Suggested by: @Monviech
firewall: stop mentioning outbound NAT in settings page
Also avoid the "inbound NAT" now that outbound NAT is no longer a thing
it seems displaced. There's no such think anywhere else in the GUI.
PR: https://forum.opnsense.org/index.php?topic=53063.0
system: switch password hashing from bcrypt to argon2id
A bit unfortunate both spots exist, but maybe that can change later on.
(cherry picked from commit 97e503079cc685a51ebf793d0d904fc5bb0dadfe)
system: installer as a real user on demand (#10888)
This allows the installer to use authenticated integration
and SSH keys as a full root user overlay.
VPN: IPsec: Add replay_window to children (#10938)
* VPN: IPsec: Add replay_window to children
Co-authored-by: Franco Fichtner <franco at opnsense.org>
---------
Co-authored-by: Franco Fichtner <franco at opnsense.org>
system: bring installer remove code closer together actually
livemode script is unconditional before login prompt so we can
do the proper cleanup at the last possible point in time.
system: add latency_avg as sanity check for running dpinger; closes #10937
The check was introduced in 0df1c0d so there's no technical background
to take into account. Indeed, latency_avg is probably the reading that
would least likely be 0 in this case.
Suggested by: @mbccd
system: add latency_avg as sanity check for running dpinger; closes #10937
The check was introduced in 0df1c0d so there's no technical background
to take into account. Indeed, latency_avg is probably the reading that
would least likely be 0 in this case.
Suggested by: @mbccd