opensnitch.git
6 months agoMerge opensnitch (1.6.9-2+rpi1) import into refs/heads/workingbranch
Peter Michael Green [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Merge opensnitch (1.6.9-2+rpi1) import into refs/heads/workingbranch

6 months agoTell opensnitch daemon to not flush al TCP connections on restart.
Petter Reinholdtsen [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Tell opensnitch daemon to not flush al TCP connections on restart.

Bug-Debian: https://bugs.debian.org/1103496
Forwarded: not-needed
Last-update: 2025-05-26

This avoid killing connections like SSH and IRC when upgrading or restarting
the service.  See discussion in https://github.com/evilsocket/opensnitch/issues/1329 .
Last-update: 2025-05-26
Gbp-Pq: Name 2010-no-tcp-flush-on-restart.patch

6 months agoDo not propose use of pip on Debian
Petter Reinholdtsen [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Do not propose use of pip on Debian

Forwarded: not-needed
Last-Update: 2025-04-19

Dependencies should be fetched from the curated Debian archive.
Last-Update: 2025-04-19
Gbp-Pq: Name 2000-apt-not-pip.patch

6 months agoAdded ebpf build rule mapping for s390x to s390.
Petter Reinholdtsen [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Added ebpf build rule mapping for s390x to s390.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1333
Last-Update: 2025-04-25

This ensure the kernel headers are found during compilation.
Last-Update: 2025-04-25
Gbp-Pq: Name 1050-ebpf-s390x.patch

6 months agoStart firewall rules before network is brought up.
Petter Reinholdtsen [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Start firewall rules before network is brought up.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1019
Last-Update: 2025-04-20

Also protect the firewall daemon from the kernel OOM killer.  Partly
based on proposal from
https://github.com/evilsocket/opensnitch/pull/1019/.

Gbp-Pq: Name 1030-systemd-service-earlier.patch

6 months agoAdded ebpf build rule mapping for armv8 to work with more armhf machines.
Petter Reinholdtsen [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Added ebpf build rule mapping for armv8 to work with more armhf machines.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1326
Last-Update: 2025-04-20

Last-Update: 2025-04-20
Gbp-Pq: Name 1020-ebpf-armv8l.patch

6 months agoChanged how ebpf build find kernel headers from running to installed version.
Petter Reinholdtsen [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Changed how ebpf build find kernel headers from running to installed version.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1327
Last-Update: 2025-04-20

The installed kernel do not match running kernel in chroots and containers.
Last-Update: 2025-04-20
Gbp-Pq: Name 1000-installed-kernel-headers.patch

6 months agoopensnitch (1.6.9-2+rpi1) trixie-staging; urgency=medium
Peter Michael Green [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
opensnitch (1.6.9-2+rpi1) trixie-staging; urgency=medium

  * Remove linux-headers build-dependency.

[dgit import unpatched opensnitch 1.6.9-2+rpi1]

6 months agoImport opensnitch_1.6.9-2+rpi1.debian.tar.xz
Peter Michael Green [Tue, 20 May 2025 15:01:26 +0000 (15:01 +0000)]
Import opensnitch_1.6.9-2+rpi1.debian.tar.xz

[dgit import tarball opensnitch 1.6.9-2+rpi1 opensnitch_1.6.9-2+rpi1.debian.tar.xz]

7 months agoMerge opensnitch (1.6.9-2) import into refs/heads/workingbranch
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Merge opensnitch (1.6.9-2) import into refs/heads/workingbranch

7 months agoTell opensnitch daemon to not flush al TCP connections on restart.
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Tell opensnitch daemon to not flush al TCP connections on restart.

Bug-Debian: https://bugs.debian.org/1103496
Forwarded: not-needed
Last-update: 2025-05-26

This avoid killing connections like SSH and IRC when upgrading or restarting
the service.  See discussion in https://github.com/evilsocket/opensnitch/issues/1329 .
Last-update: 2025-05-26
Gbp-Pq: Name 2010-no-tcp-flush-on-restart.patch

7 months agoDo not propose use of pip on Debian
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Do not propose use of pip on Debian

Forwarded: not-needed
Last-Update: 2025-04-19

Dependencies should be fetched from the curated Debian archive.
Last-Update: 2025-04-19
Gbp-Pq: Name 2000-apt-not-pip.patch

7 months agoAdded ebpf build rule mapping for s390x to s390.
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Added ebpf build rule mapping for s390x to s390.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1333
Last-Update: 2025-04-25

This ensure the kernel headers are found during compilation.
Last-Update: 2025-04-25
Gbp-Pq: Name 1050-ebpf-s390x.patch

7 months agoStart firewall rules before network is brought up.
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Start firewall rules before network is brought up.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1019
Last-Update: 2025-04-20

Also protect the firewall daemon from the kernel OOM killer.  Partly
based on proposal from
https://github.com/evilsocket/opensnitch/pull/1019/.

Gbp-Pq: Name 1030-systemd-service-earlier.patch

7 months agoAdded ebpf build rule mapping for armv8 to work with more armhf machines.
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Added ebpf build rule mapping for armv8 to work with more armhf machines.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1326
Last-Update: 2025-04-20

Last-Update: 2025-04-20
Gbp-Pq: Name 1020-ebpf-armv8l.patch

7 months agoChanged how ebpf build find kernel headers from running to installed version.
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Changed how ebpf build find kernel headers from running to installed version.

Forwarded: https://github.com/evilsocket/opensnitch/pull/1327
Last-Update: 2025-04-20

The installed kernel do not match running kernel in chroots and containers.
Last-Update: 2025-04-20
Gbp-Pq: Name 1000-installed-kernel-headers.patch

7 months agoopensnitch (1.6.9-2) unstable; urgency=medium
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
opensnitch (1.6.9-2) unstable; urgency=medium

  * Team upload.

  * Told lintian to accept EBPF objects in package.

[dgit import unpatched opensnitch 1.6.9-2]

7 months agoImport opensnitch_1.6.9-2.debian.tar.xz
Petter Reinholdtsen [Sat, 3 May 2025 03:50:32 +0000 (05:50 +0200)]
Import opensnitch_1.6.9-2.debian.tar.xz

[dgit import tarball opensnitch 1.6.9-2 opensnitch_1.6.9-2.debian.tar.xz]

7 months agoImport opensnitch_1.6.9.orig.tar.gz
Petter Reinholdtsen [Tue, 29 Apr 2025 05:35:00 +0000 (07:35 +0200)]
Import opensnitch_1.6.9.orig.tar.gz

[dgit import orig opensnitch_1.6.9.orig.tar.gz]

2 years agoopensnitch (1.5.8.1-1) unstable; urgency=medium
Gustavo Iñiguez Goya [Mon, 6 Mar 2023 11:37:24 +0000 (12:37 +0100)]
opensnitch (1.5.8.1-1) unstable; urgency=medium

  * New upstream release.
  * Upload sponsored by Petter Reinholdtsen.

[dgit import unpatched opensnitch 1.5.8.1-1]

2 years agoImport opensnitch_1.5.8.1.orig.tar.gz
Gustavo Iñiguez Goya [Mon, 6 Mar 2023 11:37:24 +0000 (12:37 +0100)]
Import opensnitch_1.5.8.1.orig.tar.gz

[dgit import orig opensnitch_1.5.8.1.orig.tar.gz]

2 years agoImport opensnitch_1.5.8.1-1.debian.tar.xz
Gustavo Iñiguez Goya [Mon, 6 Mar 2023 11:37:24 +0000 (12:37 +0100)]
Import opensnitch_1.5.8.1-1.debian.tar.xz

[dgit import tarball opensnitch 1.5.8.1-1 opensnitch_1.5.8.1-1.debian.tar.xz]