diff --git a/.etckeeper b/.etckeeper
index e97c1608..d75fad63 100755
--- a/.etckeeper
+++ b/.etckeeper
@@ -1,14 +1,16 @@
# Generated by etckeeper. Do not edit.
mkdir -p './X11/xkb'
-mkdir -p './apache2/conf-available'
mkdir -p './apache2/mods-available'
mkdir -p './apt/auth.conf.d'
+mkdir -p './apt/listchanges.conf.d'
mkdir -p './apt/preferences.d'
+mkdir -p './apt/trusted.gpg.d'
mkdir -p './avahi/services'
mkdir -p './binfmt.d'
mkdir -p './dbus-1/session.d'
mkdir -p './dnsmasq.d'
+mkdir -p './gdb/gdbinit.d'
mkdir -p './gss/mech.d'
mkdir -p './initramfs-tools/conf.d'
mkdir -p './initramfs-tools/hooks'
@@ -24,6 +26,7 @@ mkdir -p './initramfs-tools/scripts/nfs-top'
mkdir -p './initramfs-tools/scripts/panic'
mkdir -p './kernel/install.d'
mkdir -p './libpaper.d'
+mkdir -p './lighttpd/conf-available'
mkdir -p './mysql/mariadb.conf.d'
mkdir -p './network/interfaces.d'
mkdir -p './nginx/conf.mail.d'
@@ -32,7 +35,6 @@ mkdir -p './nginx/modules-available'
mkdir -p './nginx/streams-available'
mkdir -p './nginx/streams-enabled'
mkdir -p './opt'
-mkdir -p './perl/CPAN'
mkdir -p './polkit-1/localauthority/10-vendor.d'
mkdir -p './polkit-1/localauthority/20-org.d'
mkdir -p './polkit-1/localauthority/30-site.d'
@@ -46,7 +48,6 @@ mkdir -p './security/namespace.d'
mkdir -p './ssh/ssh_config.d'
mkdir -p './ssh/sshd_config.d'
mkdir -p './systemd/system/docker.service.d'
-mkdir -p './systemd/user'
mkdir -p './tmpfiles.d'
mkdir -p './triggerhappy/triggers.d'
mkdir -p './udev/hwdb.d'
@@ -105,6 +106,7 @@ maybe chmod 0755 'alternatives'
maybe chmod 0644 'alternatives/README'
maybe chmod 0755 'apache2'
maybe chmod 0755 'apache2/conf-available'
+maybe chmod 0644 'apache2/conf-available/php7.4-cgi.conf'
maybe chmod 0755 'apache2/mods-available'
maybe chmod 0755 'apparmor'
maybe chmod 0755 'apparmor.d'
@@ -121,7 +123,7 @@ maybe chmod 0755 'apt'
maybe chmod 0755 'apt/apt.conf.d'
maybe chmod 0644 'apt/apt.conf.d/01autoremove'
maybe chmod 0444 'apt/apt.conf.d/01autoremove-kernels'
-maybe chmod 0644 'apt/apt.conf.d/01autoremove-postgresql'
+maybe chmod 0444 'apt/apt.conf.d/01autoremove-postgresql'
maybe chmod 0644 'apt/apt.conf.d/05etckeeper'
maybe chmod 0644 'apt/apt.conf.d/15update-stamp'
maybe chmod 0644 'apt/apt.conf.d/20listchanges'
@@ -129,6 +131,7 @@ maybe chmod 0644 'apt/apt.conf.d/50raspi'
maybe chmod 0644 'apt/apt.conf.d/70debconf'
maybe chmod 0755 'apt/auth.conf.d'
maybe chmod 0644 'apt/listchanges.conf'
+maybe chmod 0755 'apt/listchanges.conf.d'
maybe chmod 0644 'apt/preferences'
maybe chmod 0755 'apt/preferences.d'
maybe chmod 0644 'apt/sources.list'
@@ -139,10 +142,8 @@ maybe chmod 0644 'apt/sources.list.d/mosquitto-buster.list'
maybe chmod 0644 'apt/sources.list.d/nginx.list'
maybe chmod 0644 'apt/sources.list.d/nodesource.list'
maybe chmod 0644 'apt/sources.list.d/raspi.list'
-maybe chmod 0644 'apt/sources.list.d/vscode.list'
maybe chmod 0644 'apt/trusted.gpg'
maybe chmod 0755 'apt/trusted.gpg.d'
-maybe chmod 0644 'apt/trusted.gpg.d/microsoft.gpg'
maybe chmod 0755 'avahi'
maybe chmod 0644 'avahi/avahi-daemon.conf'
maybe chmod 0644 'avahi/hosts'
@@ -208,19 +209,18 @@ maybe chmod 0755 'containerd'
maybe chmod 0644 'containerd/config.toml'
maybe chmod 0755 'cron.d'
maybe chmod 0644 'cron.d/.placeholder'
+maybe chmod 0644 'cron.d/e2scrub_all'
maybe chmod 0644 'cron.d/php'
maybe chmod 0644 'cron.d/sysstat'
maybe chmod 0755 'cron.daily'
maybe chmod 0644 'cron.daily/.placeholder'
maybe chmod 0755 'cron.daily/apt-compat'
-maybe chmod 0755 'cron.daily/bsdmainutils'
maybe chmod 0755 'cron.daily/dpkg'
maybe chmod 0755 'cron.daily/etckeeper'
maybe chmod 0755 'cron.daily/exim4-base'
maybe chmod 0700 'cron.daily/logrotate'
maybe chmod 0755 'cron.daily/man-db'
maybe chmod 0755 'cron.daily/ntp'
-maybe chmod 0755 'cron.daily/passwd'
maybe chmod 0755 'cron.daily/sysstat'
maybe chmod 0755 'cron.hourly'
maybe chmod 0644 'cron.hourly/.placeholder'
@@ -245,7 +245,6 @@ maybe chmod 0644 'debian_version'
maybe chmod 0755 'default'
maybe chmod 0644 'default/avahi-daemon'
maybe chmod 0644 'default/bluetooth'
-maybe chmod 0644 'default/bsdmainutils'
maybe chmod 0600 'default/cacerts'
maybe chmod 0644 'default/console-setup'
maybe chmod 0644 'default/crda'
@@ -265,10 +264,10 @@ maybe chmod 0644 'default/nss'
maybe chmod 0644 'default/ntp'
maybe chmod 0644 'default/raspberrypi-kernel'
maybe chmod 0644 'default/redis-server'
-maybe chmod 0644 'default/rng-tools'
+maybe chmod 0644 'default/rng-tools-debian'
+maybe chmod 0644 'default/rpcbind'
maybe chmod 0644 'default/rpi-eeprom-update'
maybe chmod 0644 'default/rsync'
-maybe chmod 0644 'default/rsyslog'
maybe chmod 0644 'default/snmpd'
maybe chmod 0644 'default/ssh'
maybe chmod 0644 'default/sysstat'
@@ -284,7 +283,6 @@ maybe chmod 0644 'dhcp/dhclient-enter-hooks.d/resolvconf'
maybe chmod 0755 'dhcp/dhclient-exit-hooks.d'
maybe chmod 0644 'dhcp/dhclient-exit-hooks.d/ntp'
maybe chmod 0644 'dhcp/dhclient-exit-hooks.d/rfc3442-classless-routes'
-maybe chmod 0644 'dhcp/dhclient-exit-hooks.d/timesyncd'
maybe chmod 0644 'dhcp/dhclient.conf'
maybe chgrp 'netdev' 'dhcpcd.conf'
maybe chmod 0664 'dhcpcd.conf'
@@ -325,6 +323,7 @@ maybe chmod 0644 'dpkg/origins/debian'
maybe chmod 0644 'dpkg/origins/raspbian'
maybe chmod 0644 'dpkg/shlibs.default'
maybe chmod 0644 'dpkg/shlibs.override'
+maybe chmod 0644 'e2scrub.conf'
maybe chmod 0644 'email-addresses'
maybe chmod 0644 'environment'
maybe chmod 0755 'etckeeper'
@@ -376,6 +375,7 @@ maybe chmod 0755 'etckeeper/update-ignore.d/01update-ignore'
maybe chmod 0644 'etckeeper/update-ignore.d/README'
maybe chmod 0755 'etckeeper/vcs.d'
maybe chmod 0755 'etckeeper/vcs.d/50vcs-cmd'
+maybe chmod 0644 'ethertypes'
maybe chmod 0755 'exim4'
maybe chmod 0755 'exim4/conf.d'
maybe chmod 0755 'exim4/conf.d/acl'
@@ -439,6 +439,7 @@ maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-sans-mono.conf'
maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-sans.conf'
maybe chmod 0644 'fonts/conf.avail/20-unhint-small-dejavu-serif.conf'
maybe chmod 0644 'fonts/conf.avail/30-droid-noto-mono.conf'
+maybe chmod 0644 'fonts/conf.avail/30-droid-noto.conf'
maybe chmod 0644 'fonts/conf.avail/57-dejavu-sans-mono.conf'
maybe chmod 0644 'fonts/conf.avail/57-dejavu-sans.conf'
maybe chmod 0644 'fonts/conf.avail/57-dejavu-serif.conf'
@@ -454,6 +455,7 @@ maybe chmod 0644 'fuse.conf'
maybe chmod 0644 'gai.conf'
maybe chmod 0755 'gdb'
maybe chmod 0644 'gdb/gdbinit'
+maybe chmod 0755 'gdb/gdbinit.d'
maybe chmod 0755 'ghostscript'
maybe chmod 0755 'ghostscript/cidfmap.d'
maybe chmod 0644 'ghostscript/cidfmap.d/90gs-cjk-resource-cns1.conf'
@@ -473,6 +475,7 @@ maybe chmod 0644 'groff/man.local'
maybe chmod 0644 'groff/mdoc.local'
maybe chmod 0644 'group'
maybe chmod 0644 'group-'
+maybe chmod 0644 'group.org'
maybe chgrp 'shadow' 'gshadow'
maybe chmod 0640 'gshadow'
maybe chgrp 'shadow' 'gshadow-'
@@ -516,7 +519,7 @@ maybe chmod 0755 'init.d/procps'
maybe chmod 0755 'init.d/raspi-config'
maybe chmod 0755 'init.d/redis-server'
maybe chmod 0755 'init.d/resolvconf'
-maybe chmod 0755 'init.d/rng-tools'
+maybe chmod 0755 'init.d/rng-tools-debian'
maybe chmod 0755 'init.d/rpcbind'
maybe chmod 0755 'init.d/rsync'
maybe chmod 0755 'init.d/rsyslog'
@@ -532,7 +535,6 @@ maybe chmod 0755 'init.d/xinetd'
maybe chmod 0644 'init/docker.conf'
maybe chmod 0644 'init/paxctld.conf'
maybe chmod 0644 'init/php7.3-fpm.conf'
-maybe chmod 0644 'init/resolvconf.conf'
maybe chmod 0644 'init/tftpd-hpa.conf'
maybe chmod 0755 'initramfs-tools'
maybe chmod 0755 'initramfs-tools/conf.d'
@@ -806,6 +808,7 @@ maybe chmod 0644 'libnl-3/classid'
maybe chmod 0644 'libnl-3/pktloc'
maybe chmod 0755 'libpaper.d'
maybe chmod 0755 'lighttpd'
+maybe chmod 0755 'lighttpd/conf-available'
maybe chmod 0644 'lighttpd/external.conf'
maybe chmod 0644 'lighttpd/lighttpd.conf.orig'
maybe chmod 0644 'locale.alias'
@@ -813,10 +816,10 @@ maybe chmod 0644 'locale.gen'
maybe chmod 0755 'logcheck'
maybe chmod 0755 'logcheck/ignore.d.server'
maybe chmod 0644 'logcheck/ignore.d.server/gpg-agent'
-maybe chmod 0644 'logcheck/ignore.d.server/rng-tools'
+maybe chmod 0644 'logcheck/ignore.d.server/rng-tools-debian'
maybe chmod 0644 'logcheck/ignore.d.server/rsyslog'
maybe chmod 0755 'logcheck/violations.ignore.d'
-maybe chmod 0644 'logcheck/violations.ignore.d/rng-tools'
+maybe chmod 0644 'logcheck/violations.ignore.d/rng-tools-debian'
maybe chmod 0644 'login.defs'
maybe chmod 0644 'logrotate.conf'
maybe chmod 0755 'logrotate.d'
@@ -842,6 +845,7 @@ maybe chmod 0644 'mailname'
maybe chmod 0644 'manpath.config'
maybe chmod 0644 'mime.types'
maybe chmod 0644 'mke2fs.conf'
+maybe chmod 0644 'mkshrc'
maybe chmod 0755 'modprobe.d'
maybe chmod 0644 'modprobe.d/blacklist-8192cu.conf'
maybe chmod 0644 'modprobe.d/blacklist-rtl8xxxu.conf'
@@ -973,25 +977,21 @@ maybe chmod 0644 'pam.d/sshd'
maybe chmod 0644 'pam.d/su'
maybe chmod 0644 'pam.d/su-l'
maybe chmod 0644 'pam.d/sudo'
-maybe chmod 0644 'pam.d/systemd-user'
maybe chmod 0644 'papersize'
maybe chmod 0644 'passwd'
maybe chmod 0644 'passwd-'
+maybe chmod 0644 'passwd.org'
maybe chmod 0644 'paxctld.conf'
maybe chmod 0755 'perl'
-maybe chmod 0755 'perl/CPAN'
maybe chmod 0755 'perl/Net'
maybe chmod 0644 'perl/Net/libnet.cfg'
maybe chmod 0755 'php'
maybe chmod 0755 'php/7.3'
maybe chmod 0755 'php/7.3/cgi'
-maybe chmod 0755 'php/7.3/cgi/conf.d'
maybe chmod 0644 'php/7.3/cgi/php.ini'
maybe chmod 0755 'php/7.3/cli'
-maybe chmod 0755 'php/7.3/cli/conf.d'
maybe chmod 0644 'php/7.3/cli/php.ini'
maybe chmod 0755 'php/7.3/fpm'
-maybe chmod 0755 'php/7.3/fpm/conf.d'
maybe chmod 0644 'php/7.3/fpm/php-fpm.conf'
maybe chmod 0644 'php/7.3/fpm/php.ini'
maybe chmod 0755 'php/7.3/fpm/pool.d'
@@ -1029,6 +1029,40 @@ maybe chmod 0644 'php/7.3/mods-available/xml.ini'
maybe chmod 0644 'php/7.3/mods-available/xmlreader.ini'
maybe chmod 0644 'php/7.3/mods-available/xmlwriter.ini'
maybe chmod 0644 'php/7.3/mods-available/xsl.ini'
+maybe chmod 0755 'php/7.4'
+maybe chmod 0755 'php/7.4/cgi'
+maybe chmod 0755 'php/7.4/cgi/conf.d'
+maybe chmod 0644 'php/7.4/cgi/php.ini'
+maybe chmod 0755 'php/7.4/cli'
+maybe chmod 0755 'php/7.4/cli/conf.d'
+maybe chmod 0644 'php/7.4/cli/php.ini'
+maybe chmod 0755 'php/7.4/mods-available'
+maybe chmod 0644 'php/7.4/mods-available/calendar.ini'
+maybe chmod 0644 'php/7.4/mods-available/ctype.ini'
+maybe chmod 0644 'php/7.4/mods-available/exif.ini'
+maybe chmod 0644 'php/7.4/mods-available/ffi.ini'
+maybe chmod 0644 'php/7.4/mods-available/fileinfo.ini'
+maybe chmod 0644 'php/7.4/mods-available/ftp.ini'
+maybe chmod 0644 'php/7.4/mods-available/gettext.ini'
+maybe chmod 0644 'php/7.4/mods-available/iconv.ini'
+maybe chmod 0644 'php/7.4/mods-available/intl.ini'
+maybe chmod 0644 'php/7.4/mods-available/json.ini'
+maybe chmod 0644 'php/7.4/mods-available/mysqli.ini'
+maybe chmod 0644 'php/7.4/mods-available/mysqlnd.ini'
+maybe chmod 0644 'php/7.4/mods-available/opcache.ini'
+maybe chmod 0644 'php/7.4/mods-available/pdo.ini'
+maybe chmod 0644 'php/7.4/mods-available/pdo_mysql.ini'
+maybe chmod 0644 'php/7.4/mods-available/pdo_sqlite.ini'
+maybe chmod 0644 'php/7.4/mods-available/phar.ini'
+maybe chmod 0644 'php/7.4/mods-available/posix.ini'
+maybe chmod 0644 'php/7.4/mods-available/readline.ini'
+maybe chmod 0644 'php/7.4/mods-available/shmop.ini'
+maybe chmod 0644 'php/7.4/mods-available/sockets.ini'
+maybe chmod 0644 'php/7.4/mods-available/sqlite3.ini'
+maybe chmod 0644 'php/7.4/mods-available/sysvmsg.ini'
+maybe chmod 0644 'php/7.4/mods-available/sysvsem.ini'
+maybe chmod 0644 'php/7.4/mods-available/sysvshm.ini'
+maybe chmod 0644 'php/7.4/mods-available/tokenizer.ini'
maybe chmod 0644 'pip.conf'
maybe chmod 0755 'polkit-1'
maybe chmod 0700 'polkit-1/localauthority'
@@ -1040,8 +1074,6 @@ maybe chmod 0755 'polkit-1/localauthority/20-org.d'
maybe chmod 0755 'polkit-1/localauthority/30-site.d'
maybe chmod 0755 'polkit-1/localauthority/50-local.d'
maybe chmod 0755 'polkit-1/localauthority/90-mandatory.d'
-maybe chmod 0755 'polkit-1/nullbackend.conf.d'
-maybe chmod 0644 'polkit-1/nullbackend.conf.d/50-nullbackend.conf'
maybe chown 'postgres' 'postgresql'
maybe chgrp 'postgres' 'postgresql'
maybe chmod 0755 'postgresql'
@@ -1143,9 +1175,9 @@ maybe chmod 0644 'rsyslog.d/rsyslog-tls.conf'
maybe chmod 0755 'runit'
maybe chmod 0755 'runit/runsvdir'
maybe chmod 0755 'runit/runsvdir/default'
-maybe chmod 0644 'securetty'
maybe chmod 0755 'security'
maybe chmod 0644 'security/access.conf'
+maybe chmod 0644 'security/faillock.conf'
maybe chmod 0644 'security/group.conf'
maybe chmod 0644 'security/limits.conf'
maybe chmod 0755 'security/limits.d'
@@ -1166,6 +1198,7 @@ maybe chmod 0644 'shells'
maybe chmod 0755 'skel'
maybe chmod 0644 'skel/.bash_logout'
maybe chmod 0644 'skel/.bashrc'
+maybe chmod 0644 'skel/.mkshrc'
maybe chmod 0644 'skel/.profile'
maybe chmod 0755 'snmp'
maybe chmod 0755 'snmp-mibs-downloader'
@@ -1217,6 +1250,8 @@ maybe chmod 0644 'subgid'
maybe chmod 0644 'subgid-'
maybe chmod 0644 'subuid'
maybe chmod 0644 'subuid-'
+maybe chmod 0644 'sudo.conf'
+maybe chmod 0644 'sudo_logsrvd.conf'
maybe chmod 0440 'sudoers'
maybe chmod 0755 'sudoers.d'
maybe chmod 0440 'sudoers.d/010_at-export'
@@ -1237,7 +1272,6 @@ maybe chmod 0755 'sysctl.d'
maybe chmod 0644 'sysctl.d/30-postgresql-shm.conf'
maybe chmod 0644 'sysctl.d/98-rpi.conf'
maybe chmod 0644 'sysctl.d/README.sysctl'
-maybe chmod 0644 'sysctl.d/protect-links.conf'
maybe chmod 0755 'sysstat'
maybe chmod 0644 'sysstat/sysstat'
maybe chmod 0644 'sysstat/sysstat.ioconf'
@@ -1246,6 +1280,7 @@ maybe chmod 0644 'systemd/journald.conf'
maybe chmod 0644 'systemd/logind.conf'
maybe chmod 0755 'systemd/network'
maybe chmod 0644 'systemd/networkd.conf'
+maybe chmod 0644 'systemd/pstore.conf'
maybe chmod 0644 'systemd/resolved.conf'
maybe chmod 0644 'systemd/sleep.conf'
maybe chmod 0755 'systemd/system'
@@ -1256,6 +1291,7 @@ maybe chmod 0755 'systemd/system/bluetooth.target.wants'
maybe chmod 0644 'systemd/system/check-mk-agent-async.service'
maybe chmod 0644 'systemd/system/check-mk-agent.socket'
maybe chmod 0644 'systemd/system/check-mk-agent@.service'
+maybe chmod 0755 'systemd/system/default.target.wants'
maybe chmod 0755 'systemd/system/dhcpcd.service.d'
maybe chmod 0644 'systemd/system/dhcpcd.service.d/wait.conf'
maybe chmod 0755 'systemd/system/docker.service.d'
@@ -1273,10 +1309,11 @@ maybe chmod 0755 'systemd/system/reboot.target.wants'
maybe chmod 0755 'systemd/system/remote-fs.target.wants'
maybe chmod 0755 'systemd/system/sockets.target.wants'
maybe chmod 0755 'systemd/system/sysinit.target.wants'
+maybe chmod 0755 'systemd/system/systemd-resolved.service.wants'
maybe chmod 0755 'systemd/system/timers.target.wants'
-maybe chmod 0644 'systemd/timesyncd.conf'
maybe chmod 0755 'systemd/user'
maybe chmod 0644 'systemd/user.conf'
+maybe chmod 0755 'systemd/user/sockets.target.wants'
maybe chmod 0755 'terminfo'
maybe chmod 0644 'terminfo/README'
maybe chmod 0644 'timezone'
diff --git a/ImageMagick-6/coder.xml b/ImageMagick-6/coder.xml
index 4d2394fe..bd80a22d 100644
--- a/ImageMagick-6/coder.xml
+++ b/ImageMagick-6/coder.xml
@@ -1,6 +1,6 @@
+
+
diff --git a/ImageMagick-6/delegates.xml b/ImageMagick-6/delegates.xml
index ea0efd85..9e7434d4 100644
--- a/ImageMagick-6/delegates.xml
+++ b/ImageMagick-6/delegates.xml
@@ -64,10 +64,10 @@
-
-
-
-
+
+
+
+
@@ -85,23 +85,23 @@
-
-
-
+
+
-
-
-
+
+
+
+
-
-
-
+
+
+
-
+
@@ -109,14 +109,17 @@
-
+
+
+
-
-
-
+
+
+
-
-
+
+
+
diff --git a/ImageMagick-6/mime.xml b/ImageMagick-6/mime.xml
index 9530fc8d..3b768df4 100644
--- a/ImageMagick-6/mime.xml
+++ b/ImageMagick-6/mime.xml
@@ -827,6 +827,7 @@
+
diff --git a/ImageMagick-6/policy.xml b/ImageMagick-6/policy.xml
index 82a3d0b6..808fcf60 100644
--- a/ImageMagick-6/policy.xml
+++ b/ImageMagick-6/policy.xml
@@ -1,6 +1,6 @@
+
+ Use the default system font unless overwridden by the application:
+
+
+
Define arguments for the memory, map, area, width, height and disk resources
with SI prefixes (.e.g 100MB). In addition, resource policies are maximums
for each instance of ImageMagick (e.g. policy memory limit 1GB, -limit 2GB
@@ -52,17 +56,13 @@
-->
-
-
-
-
-
+
@@ -70,11 +70,14 @@
-
-
+
+
+
+
diff --git a/ImageMagick-6/type-urw-base35.xml b/ImageMagick-6/type-urw-base35.xml
index 2f70e723..1ddd50db 100644
--- a/ImageMagick-6/type-urw-base35.xml
+++ b/ImageMagick-6/type-urw-base35.xml
@@ -13,38 +13,38 @@
ImageMagick URW-base35 font configuration.
-->
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
+
diff --git a/ImageMagick-6/type.xml b/ImageMagick-6/type.xml
index a9c39bf9..8ac74904 100644
--- a/ImageMagick-6/type.xml
+++ b/ImageMagick-6/type.xml
@@ -13,5 +13,5 @@
ImageMagick font configuration.
-->
-
+
diff --git a/alternatives/dhcpcd b/alternatives/dhcpcd
deleted file mode 120000
index 981de745..00000000
--- a/alternatives/dhcpcd
+++ /dev/null
@@ -1 +0,0 @@
-/sbin/dhcpcd5
\ No newline at end of file
diff --git a/alternatives/dhcpcd.8.gz b/alternatives/dhcpcd.8.gz
deleted file mode 120000
index e8ddb349..00000000
--- a/alternatives/dhcpcd.8.gz
+++ /dev/null
@@ -1 +0,0 @@
-/usr/share/man/man8/dhcpcd5.8.gz
\ No newline at end of file
diff --git a/alternatives/js b/alternatives/js
new file mode 120000
index 00000000..043d0274
--- /dev/null
+++ b/alternatives/js
@@ -0,0 +1 @@
+/usr/bin/nodejs
\ No newline at end of file
diff --git a/alternatives/js.1.gz b/alternatives/js.1.gz
new file mode 120000
index 00000000..afe4150d
--- /dev/null
+++ b/alternatives/js.1.gz
@@ -0,0 +1 @@
+/usr/share/man/man1/nodejs.1.gz
\ No newline at end of file
diff --git a/alternatives/ksh b/alternatives/ksh
new file mode 120000
index 00000000..90e1a3b5
--- /dev/null
+++ b/alternatives/ksh
@@ -0,0 +1 @@
+/bin/mksh
\ No newline at end of file
diff --git a/alternatives/ksh.1.gz b/alternatives/ksh.1.gz
new file mode 120000
index 00000000..51313019
--- /dev/null
+++ b/alternatives/ksh.1.gz
@@ -0,0 +1 @@
+/usr/share/man/man1/mksh.1.gz
\ No newline at end of file
diff --git a/alternatives/open b/alternatives/open
new file mode 120000
index 00000000..2fcedcf8
--- /dev/null
+++ b/alternatives/open
@@ -0,0 +1 @@
+/usr/bin/run-mailcap
\ No newline at end of file
diff --git a/alternatives/open.1.gz b/alternatives/open.1.gz
new file mode 120000
index 00000000..b80da438
--- /dev/null
+++ b/alternatives/open.1.gz
@@ -0,0 +1 @@
+/usr/share/man/man1/run-mailcap.1.gz
\ No newline at end of file
diff --git a/alternatives/pager b/alternatives/pager
index cbce297b..a967155b 120000
--- a/alternatives/pager
+++ b/alternatives/pager
@@ -1 +1 @@
-/bin/less
\ No newline at end of file
+/usr/bin/less
\ No newline at end of file
diff --git a/alternatives/phar b/alternatives/phar
index b3b4ae71..0e07b6a3 120000
--- a/alternatives/phar
+++ b/alternatives/phar
@@ -1 +1 @@
-/usr/bin/phar7.3
\ No newline at end of file
+/usr/bin/phar7.4
\ No newline at end of file
diff --git a/alternatives/phar.1.gz b/alternatives/phar.1.gz
index f308505e..18909901 120000
--- a/alternatives/phar.1.gz
+++ b/alternatives/phar.1.gz
@@ -1 +1 @@
-/usr/share/man/man1/phar7.3.1.gz
\ No newline at end of file
+/usr/share/man/man1/phar7.4.1.gz
\ No newline at end of file
diff --git a/alternatives/phar.phar b/alternatives/phar.phar
index a03cf84f..955f4888 120000
--- a/alternatives/phar.phar
+++ b/alternatives/phar.phar
@@ -1 +1 @@
-/usr/bin/phar.phar7.3
\ No newline at end of file
+/usr/bin/phar.phar7.4
\ No newline at end of file
diff --git a/alternatives/phar.phar.1.gz b/alternatives/phar.phar.1.gz
index 74ee7f36..45648972 120000
--- a/alternatives/phar.phar.1.gz
+++ b/alternatives/phar.phar.1.gz
@@ -1 +1 @@
-/usr/share/man/man1/phar.phar7.3.1.gz
\ No newline at end of file
+/usr/share/man/man1/phar.phar7.4.1.gz
\ No newline at end of file
diff --git a/alternatives/php b/alternatives/php
index c890124a..36f459d4 120000
--- a/alternatives/php
+++ b/alternatives/php
@@ -1 +1 @@
-/usr/bin/php7.3
\ No newline at end of file
+/usr/bin/php7.4
\ No newline at end of file
diff --git a/alternatives/php-cgi b/alternatives/php-cgi
index c483401e..818aae00 120000
--- a/alternatives/php-cgi
+++ b/alternatives/php-cgi
@@ -1 +1 @@
-/usr/bin/php-cgi7.3
\ No newline at end of file
+/usr/bin/php-cgi.default
\ No newline at end of file
diff --git a/alternatives/php-cgi-bin b/alternatives/php-cgi-bin
index f945cd5b..d8bf9d66 120000
--- a/alternatives/php-cgi-bin
+++ b/alternatives/php-cgi-bin
@@ -1 +1 @@
-/usr/lib/cgi-bin/php7.3
\ No newline at end of file
+/usr/lib/cgi-bin/php.default
\ No newline at end of file
diff --git a/alternatives/php-cgi.1.gz b/alternatives/php-cgi.1.gz
index 6b146712..9156e952 120000
--- a/alternatives/php-cgi.1.gz
+++ b/alternatives/php-cgi.1.gz
@@ -1 +1 @@
-/usr/share/man/man1/php-cgi7.3.1.gz
\ No newline at end of file
+/usr/share/man/man1/php-cgi.default.1.gz
\ No newline at end of file
diff --git a/alternatives/php.1.gz b/alternatives/php.1.gz
index 4338797d..f5c48344 120000
--- a/alternatives/php.1.gz
+++ b/alternatives/php.1.gz
@@ -1 +1 @@
-/usr/share/man/man1/php7.3.1.gz
\ No newline at end of file
+/usr/share/man/man1/php7.4.1.gz
\ No newline at end of file
diff --git a/alternatives/regulatory.db b/alternatives/regulatory.db
new file mode 120000
index 00000000..1b8118c1
--- /dev/null
+++ b/alternatives/regulatory.db
@@ -0,0 +1 @@
+/lib/firmware/regulatory.db-debian
\ No newline at end of file
diff --git a/alternatives/regulatory.db.p7s b/alternatives/regulatory.db.p7s
new file mode 120000
index 00000000..c2bfd5e7
--- /dev/null
+++ b/alternatives/regulatory.db.p7s
@@ -0,0 +1 @@
+/lib/firmware/regulatory.db.p7s-debian
\ No newline at end of file
diff --git a/alternatives/rksh b/alternatives/rksh
new file mode 120000
index 00000000..90e1a3b5
--- /dev/null
+++ b/alternatives/rksh
@@ -0,0 +1 @@
+/bin/mksh
\ No newline at end of file
diff --git a/alternatives/rksh.1.gz b/alternatives/rksh.1.gz
new file mode 120000
index 00000000..51313019
--- /dev/null
+++ b/alternatives/rksh.1.gz
@@ -0,0 +1 @@
+/usr/share/man/man1/mksh.1.gz
\ No newline at end of file
diff --git a/alternatives/w b/alternatives/w
deleted file mode 120000
index 11c34c45..00000000
--- a/alternatives/w
+++ /dev/null
@@ -1 +0,0 @@
-/usr/bin/w.procps
\ No newline at end of file
diff --git a/alternatives/w.1.gz b/alternatives/w.1.gz
deleted file mode 120000
index 7391b640..00000000
--- a/alternatives/w.1.gz
+++ /dev/null
@@ -1 +0,0 @@
-/usr/share/man/man1/w.procps.1.gz
\ No newline at end of file
diff --git a/alternatives/write b/alternatives/write
index 121ab03a..84860897 120000
--- a/alternatives/write
+++ b/alternatives/write
@@ -1 +1 @@
-/usr/bin/bsd-write
\ No newline at end of file
+/usr/bin/write.ul
\ No newline at end of file
diff --git a/alternatives/write.1.gz b/alternatives/write.1.gz
index 9bcde455..170e75f2 120000
--- a/alternatives/write.1.gz
+++ b/alternatives/write.1.gz
@@ -1 +1 @@
-/usr/share/man/man1/bsd-write.1.gz
\ No newline at end of file
+/usr/share/man/man1/write.ul.1.gz
\ No newline at end of file
diff --git a/apache2/conf-available/php7.4-cgi.conf b/apache2/conf-available/php7.4-cgi.conf
new file mode 100644
index 00000000..ead55241
--- /dev/null
+++ b/apache2/conf-available/php7.4-cgi.conf
@@ -0,0 +1,32 @@
+# This file replaces old system MIME types and sets them only in the
+# Apache webserver
+
+# application/x-httpd-php phtml php
+
+ SetHandler application/x-httpd-php
+
+# application/x-httpd-php-source phps
+
+ SetHandler application/x-httpd-php-source
+ # Deny access to raw php sources by default
+ # To re-enable it's recommended to enable access to the files
+ # only in specific virtual host or directory
+ Require all denied
+
+# Deny access to files without filename (e.g. '.php')
+
+ Require all denied
+
+
+# To enable PHP CGI site-wide, just uncomment following lines, however
+# as a security measure, it's recommended to enable PHP just in the
+# specific virtual servers or just specific directories
+
+#ScriptAlias /cgi-bin/ /usr/lib/cgi-bin/
+#
+# AllowOverride None
+# Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch
+# Order allow,deny
+# Allow from all
+#
+#Action application/x-httpd-php /cgi-bin/php7.4
diff --git a/apparmor.d/usr.bin.man b/apparmor.d/usr.bin.man
index 569aec91..b6cd0be6 100644
--- a/apparmor.d/usr.bin.man
+++ b/apparmor.d/usr.bin.man
@@ -39,6 +39,12 @@
capability setuid,
capability setgid,
+ # Ordinary permission checks sometimes involve checking whether the
+ # process has this capability, which can produce audit log messages.
+ # Silence them.
+ deny capability dac_override,
+ deny capability dac_read_search,
+
signal peer=@{profile_name},
signal peer=/usr/bin/man//&man_groff,
signal peer=/usr/bin/man//&man_filter,
@@ -66,9 +72,12 @@ profile man_groff {
/usr/bin/vgrind rm,
/etc/groff/** r,
+ /etc/papersize r,
/usr/lib/groff/site-tmac/** r,
/usr/share/groff/** r,
+ /tmp/groff* rw,
+
signal peer=/usr/bin/man,
# @{profile_name} doesn't seem to work here.
signal peer=/usr/bin/man//&man_groff,
@@ -95,6 +104,9 @@ profile man_filter {
# do is feed data to the invoking man process.
/** r,
+ # Allow writing cat pages.
+ /var/cache/man/** w,
+
signal peer=/usr/bin/man,
# @{profile_name} doesn't seem to work here.
signal peer=/usr/bin/man//&man_filter,
diff --git a/apparmor.d/usr.sbin.ntpd b/apparmor.d/usr.sbin.ntpd
index 18ccc39e..0977d0d6 100644
--- a/apparmor.d/usr.sbin.ntpd
+++ b/apparmor.d/usr.sbin.ntpd
@@ -72,11 +72,8 @@
# to be able to check for running ntpdate
/run/lock/ntpdate wk,
- # samba4 ntp signing socket
- /{,var/}run/samba/ntp_signd/socket rw,
-
- # samba4 winbindd pipe
- /run/samba/winbindd/pipe rw,
+ # To sign replies to MS-SNTP clients by the smbd daemon /var/lib/samba
+ /var/lib/samba/ntp_signd/socket rw,
# For use with clocks that report via shared memory (e.g. gpsd),
# you may need to give ntpd access to all of shared memory, though
diff --git a/apt/apt.conf.d/01autoremove b/apt/apt.conf.d/01autoremove
index f9d9e85d..478c571e 100644
--- a/apt/apt.conf.d/01autoremove
+++ b/apt/apt.conf.d/01autoremove
@@ -10,31 +10,13 @@ APT
VersionedKernelPackages
{
- # linux kernels
- "linux-image";
- "linux-headers";
- "linux-image-extra";
- "linux-modules";
- "linux-modules-extra";
- "linux-signed-image";
- "linux-image-unsigned";
- # kfreebsd kernels
- "kfreebsd-image";
- "kfreebsd-headers";
- # hurd kernels
- "gnumach-image";
+ # kernels
+ "linux-.*";
+ "kfreebsd-.*";
+ "gnumach-.*";
# (out-of-tree) modules
".*-modules";
".*-kernel";
- "linux-backports-modules-.*";
- "linux-modules-.*";
- # tools
- "linux-tools";
- "linux-cloud-tools";
- # build info
- "linux-buildinfo";
- # source code
- "linux-source";
};
Never-MarkAuto-Sections
diff --git a/apt/apt.conf.d/01autoremove-postgresql b/apt/apt.conf.d/01autoremove-postgresql
index 3f473d1d..8de2f443 100644
--- a/apt/apt.conf.d/01autoremove-postgresql
+++ b/apt/apt.conf.d/01autoremove-postgresql
@@ -1,17 +1,16 @@
-// File installed by postgresql-common. Currently not updated automatically,
-// but might be in future releases.
+// NO NOT EDIT!
+// File maintained by /usr/share/postgresql-common/pg_updateaptconfig.
//
-// We mark all PostgreSQL packages as NeverAutoRemove because otherwise apt
-// would remove the old postgresql-NN package when the "postgresql" meta
-// package changes its dependencies to a new version, rendering the old
-// database cluster inaccessible. As access to the cluster might depend on
-// other modules (like datatypes), we use a pretty wide pattern here. We might
-// tighten this to match only actually used PostgreSQL versions in the future.
+// Mark all PostgreSQL packages as NeverAutoRemove for which PostgreSQL
+// clusters exist. This is especially important when the "postgresql" meta
+// package changes its dependencies to a new version, which might otherwise
+// trigger the old postgresql-NN package to be automatically removed, rendering
+// the old database cluster inaccessible.
APT
{
NeverAutoRemove
{
- "^postgresql-";
+ "^postgresql.*-11";
};
};
diff --git a/apt/apt.conf.d/20listchanges b/apt/apt.conf.d/20listchanges
index 17687351..4af5989d 100644
--- a/apt/apt.conf.d/20listchanges
+++ b/apt/apt.conf.d/20listchanges
@@ -1,3 +1,5 @@
DPkg::Pre-Install-Pkgs { "/usr/bin/apt-listchanges --apt || test $? -lt 10"; };
DPkg::Tools::Options::/usr/bin/apt-listchanges::Version "2";
DPkg::Tools::Options::/usr/bin/apt-listchanges::InfoFD "20";
+Dir::Etc::apt-listchanges-main "listchanges.conf";
+Dir::Etc::apt-listchanges-parts "listchanges.conf.d";
diff --git a/apt/sources.list.d/vscode.list b/apt/sources.list.d/vscode.list
deleted file mode 100644
index 7b602246..00000000
--- a/apt/sources.list.d/vscode.list
+++ /dev/null
@@ -1 +0,0 @@
-### Disabled by raspberrypi-sys-mods ###
diff --git a/apt/trusted.gpg.d/microsoft.gpg b/apt/trusted.gpg.d/microsoft.gpg
deleted file mode 100644
index e69de29b..00000000
diff --git a/avahi/avahi-daemon.conf b/avahi/avahi-daemon.conf
index ff9a4c58..f2eca083 100644
--- a/avahi/avahi-daemon.conf
+++ b/avahi/avahi-daemon.conf
@@ -57,6 +57,7 @@ publish-workstation=no
[reflector]
#enable-reflector=no
#reflect-ipv=no
+#reflect-filters=_airplay._tcp.local,_raop._tcp.local
[rlimits]
#rlimit-as=
diff --git a/bluetooth/main.conf b/bluetooth/main.conf
index 49d47c57..3e58c8c9 100644
--- a/bluetooth/main.conf
+++ b/bluetooth/main.conf
@@ -14,6 +14,11 @@
# 0 = disable timer, i.e. stay discoverable forever
#DiscoverableTimeout = 0
+# Always allow pairing even if there are no agent registered
+# Possible values: true, false
+# Default: false
+#AlwaysPairable = false
+
# How long to stay in pairable mode before going back to non-discoverable
# The value is in seconds. Default is 0.
# 0 = disable timer, i.e. stay pairable forever
@@ -26,9 +31,11 @@
#DeviceID = bluetooth:1234:5678:abcd
# Do reverse service discovery for previously unknown devices that connect to
-# us. This option is really only needed for qualification since the BITE tester
-# doesn't like us doing reverse SDP for some test cases (though there could in
-# theory be other useful purposes for this too). Defaults to 'true'.
+# us. For BR/EDR this option is really only needed for qualification since the
+# BITE tester doesn't like us doing reverse SDP for some test cases, for LE
+# this disables the GATT client functionally so it can be used in system which
+# can only operate as peripheral.
+# Defaults to 'true'.
#ReverseServiceDiscovery = true
# Enable name resolving after inquiry. Set it to 'false' if you don't need
@@ -66,6 +73,86 @@
# Defaults to "off"
# Privacy = off
+# Specify the policy to the JUST-WORKS repairing initiated by peer
+# Possible values: "never", "confirm", "always"
+# Defaults to "never"
+#JustWorksRepairing = never
+
+# How long to keep temporary devices around
+# The value is in seconds. Default is 30.
+# 0 = disable timer, i.e. never keep temporary devices
+#TemporaryTimeout = 30
+
+# Enables the device to issue an SDP request to update known services when
+# profile is connected. Defaults to true.
+#RefreshDiscovery = true
+
+[Controller]
+# The following values are used to load default adapter parameters. BlueZ loads
+# the values into the kernel before the adapter is powered if the kernel
+# supports the MGMT_LOAD_DEFAULT_PARAMETERS command. If a value isn't provided,
+# the kernel will be initialized to it's default value. The actual value will
+# vary based on the kernel version and thus aren't provided here.
+# The Bluetooth Core Specification should be consulted for the meaning and valid
+# domain of each of these values.
+
+# BR/EDR Page scan activity configuration
+#BRPageScanType=
+#BRPageScanInterval=
+#BRPageScanWindow=
+
+# BR/EDR Inquiry scan activity configuration
+#BRInquiryScanType=
+#BRInquiryScanInterval=
+#BRInquiryScanWindow=
+
+# BR/EDR Link supervision timeout
+#BRLinkSupervisionTimeout=
+
+# BR/EDR Page Timeout
+#BRPageTimeout=
+
+# BR/EDR Sniff Intervals
+#BRMinSniffInterval=
+#BRMaxSniffInterval=
+
+# LE advertisement interval (used for legacy advertisement interface only)
+#LEMinAdvertisementInterval=
+#LEMaxAdvertisementInterval=
+#LEMultiAdvertisementRotationInterval=
+
+# LE scanning parameters used for passive scanning supporting auto connect
+# scenarios
+#LEScanIntervalAutoConnect=
+#LEScanWindowAutoConnect=
+
+# LE scanning parameters used for passive scanning supporting wake from suspend
+# scenarios
+#LEScanIntervalSuspend=
+#LEScanWindowSuspend=
+
+# LE scanning parameters used for active scanning supporting discovery
+# proceedure
+#LEScanIntervalDiscovery=
+#LEScanWindowDiscovery=
+
+# LE scanning parameters used for passive scanning supporting the advertisement
+# monitor Apis
+#LEScanIntervalAdvMonitor=
+#LEScanWindowAdvMonitor=
+
+# LE scanning parameters used for connection establishment.
+#LEScanIntervalConnect=
+#LEScanWindowConnect=
+
+# LE default connection parameters. These values are superceeded by any
+# specific values provided via the Load Connection Parameters interface
+#LEMinConnectionInterval=
+#LEMaxConnectionInterval=
+#LEConnectionLatency=
+#LEConnectionSupervisionTimeout=
+#LEAutoconnecttimeout=
+
[GATT]
# GATT attribute cache.
# Possible values:
@@ -81,7 +168,17 @@
# Minimum required Encryption Key Size for accessing secured characteristics.
# Possible values: 0 and 7-16. 0 means don't care.
# Defaults to 0
-# MinEncKeySize = 0
+#KeySize = 0
+
+# Exchange MTU size.
+# Possible values: 23-517
+# Defaults to 517
+#ExchangeMTU = 517
+
+# Number of ATT channels
+# Possible values: 1-5 (1 disables EATT)
+# Default to 3
+#Channels = 3
[Policy]
#
diff --git a/ca-certificates.conf b/ca-certificates.conf
index b85102b9..9ab003ba 100644
--- a/ca-certificates.conf
+++ b/ca-certificates.conf
@@ -53,7 +53,7 @@ mozilla/DST_Root_CA_X3.crt
mozilla/D-TRUST_Root_Class_3_CA_2_2009.crt
mozilla/D-TRUST_Root_Class_3_CA_2_EV_2009.crt
mozilla/EC-ACC.crt
-mozilla/EE_Certification_Centre_Root_CA.crt
+!mozilla/EE_Certification_Centre_Root_CA.crt
mozilla/Entrust.net_Premium_2048_Secure_Server_CA.crt
mozilla/Entrust_Root_Certification_Authority.crt
mozilla/Entrust_Root_Certification_Authority_-_EC1.crt
@@ -65,7 +65,7 @@ mozilla/GDCA_TrustAUTH_R5_ROOT.crt
!mozilla/GeoTrust_Primary_Certification_Authority.crt
!mozilla/GeoTrust_Primary_Certification_Authority_-_G2.crt
!mozilla/GeoTrust_Primary_Certification_Authority_-_G3.crt
-mozilla/GeoTrust_Universal_CA_2.crt
+!mozilla/GeoTrust_Universal_CA_2.crt
!mozilla/GeoTrust_Universal_CA.crt
mozilla/Global_Chambersign_Root_-_2008.crt
mozilla/GlobalSign_ECC_Root_CA_-_R4.crt
@@ -84,11 +84,11 @@ mozilla/IdenTrust_Commercial_Root_CA_1.crt
mozilla/IdenTrust_Public_Sector_Root_CA_1.crt
mozilla/ISRG_Root_X1.crt
mozilla/Izenpe.com.crt
-mozilla/LuxTrust_Global_Root_2.crt
+!mozilla/LuxTrust_Global_Root_2.crt
mozilla/Microsec_e-Szigno_Root_CA_2009.crt
mozilla/NetLock_Arany_=Class_Gold=_FÅ‘tanúsÃtvány.crt
mozilla/Network_Solutions_Certificate_Authority.crt
-mozilla/OISTE_WISeKey_Global_Root_GA_CA.crt
+!mozilla/OISTE_WISeKey_Global_Root_GA_CA.crt
mozilla/OISTE_WISeKey_Global_Root_GB_CA.crt
mozilla/OISTE_WISeKey_Global_Root_GC_CA.crt
mozilla/QuoVadis_Root_CA_1_G3.crt
@@ -108,7 +108,7 @@ mozilla/SSL.com_EV_Root_Certification_Authority_RSA_R2.crt
mozilla/SSL.com_Root_Certification_Authority_ECC.crt
mozilla/SSL.com_Root_Certification_Authority_RSA.crt
mozilla/Staat_der_Nederlanden_EV_Root_CA.crt
-mozilla/Staat_der_Nederlanden_Root_CA_-_G2.crt
+!mozilla/Staat_der_Nederlanden_Root_CA_-_G2.crt
mozilla/Staat_der_Nederlanden_Root_CA_-_G3.crt
mozilla/Starfield_Class_2_CA.crt
mozilla/Starfield_Root_Certificate_Authority_-_G2.crt
@@ -116,7 +116,7 @@ mozilla/Starfield_Services_Root_Certificate_Authority_-_G2.crt
mozilla/SwissSign_Gold_CA_-_G2.crt
mozilla/SwissSign_Silver_CA_-_G2.crt
mozilla/SZAFIR_ROOT_CA2.crt
-mozilla/Taiwan_GRCA.crt
+!mozilla/Taiwan_GRCA.crt
mozilla/TeliaSonera_Root_CA_v1.crt
!mozilla/thawte_Primary_Root_CA.crt
!mozilla/thawte_Primary_Root_CA_-_G2.crt
@@ -132,7 +132,7 @@ mozilla/TWCA_Global_Root_CA.crt
mozilla/TWCA_Root_Certification_Authority.crt
mozilla/USERTrust_ECC_Certification_Authority.crt
mozilla/USERTrust_RSA_Certification_Authority.crt
-mozilla/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.crt
+!mozilla/Verisign_Class_3_Public_Primary_Certification_Authority_-_G3.crt
!mozilla/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G4.crt
!mozilla/VeriSign_Class_3_Public_Primary_Certification_Authority_-_G5.crt
!mozilla/VeriSign_Universal_Root_Certification_Authority.crt
@@ -150,3 +150,11 @@ mozilla/GTS_Root_R4.crt
mozilla/Hongkong_Post_Root_CA_3.crt
mozilla/UCA_Extended_Validation_Root.crt
mozilla/UCA_Global_G2_Root.crt
+mozilla/certSIGN_Root_CA_G2.crt
+mozilla/e-Szigno_Root_CA_2017.crt
+mozilla/Microsoft_ECC_Root_Certificate_Authority_2017.crt
+mozilla/Microsoft_RSA_Root_Certificate_Authority_2017.crt
+mozilla/NAVER_Global_Root_Certification_Authority.crt
+mozilla/Trustwave_Global_Certification_Authority.crt
+mozilla/Trustwave_Global_ECC_P256_Certification_Authority.crt
+mozilla/Trustwave_Global_ECC_P384_Certification_Authority.crt
diff --git a/cmk-update-agent.state b/cmk-update-agent.state
index 56211b27..3228c014 100644
--- a/cmk-update-agent.state
+++ b/cmk-update-agent.state
@@ -1 +1 @@
-{'protocol': 'http', 'installed_aghash': 'f6a96ac380071a09', 'last_error': None, 'site': 'realm', 'last_check': 1642080481.1709406, 'host_name': 'serviceraspi.realm.local', 'server': '192.168.0.99', 'last_update': 1639470832.6044304, 'host_secret': 'pntxhkgisefetedlluhmbneceelnviymvmrfcsaezocoirlcjurakqmfhjuunxlv', 'user': 'caelebfi'}
+{'protocol': 'http', 'installed_aghash': 'f6a96ac380071a09', 'last_error': None, 'site': 'realm', 'last_check': 1642087764.849196, 'host_name': 'serviceraspi.realm.local', 'server': '192.168.0.99', 'last_update': 1639470832.6044304, 'host_secret': 'pntxhkgisefetedlluhmbneceelnviymvmrfcsaezocoirlcjurakqmfhjuunxlv', 'user': 'caelebfi'}
diff --git a/cron.d/e2scrub_all b/cron.d/e2scrub_all
new file mode 100644
index 00000000..505d2566
--- /dev/null
+++ b/cron.d/e2scrub_all
@@ -0,0 +1,2 @@
+30 3 * * 0 root test -e /run/systemd/system || SERVICE_MODE=1 /usr/lib/arm-linux-gnueabihf/e2fsprogs/e2scrub_all_cron
+10 3 * * * root test -e /run/systemd/system || SERVICE_MODE=1 /sbin/e2scrub_all -A -r
diff --git a/cron.daily/bsdmainutils b/cron.daily/bsdmainutils
deleted file mode 100755
index e65cbd3b..00000000
--- a/cron.daily/bsdmainutils
+++ /dev/null
@@ -1,16 +0,0 @@
-#!/bin/sh
-# /etc/cron.daily/calendar: BSD mainutils calendar daily maintenance script
-# Written by Austin Donnelly
-
-. /etc/default/bsdmainutils
-
-[ x$RUN_DAILY = xtrue ] || exit 0
-
-[ -x /usr/sbin/sendmail ] || exit 0
-
-if [ ! -x /usr/bin/cpp ]; then
- echo "The cpp package is needed to run calendar."
- exit 1
-fi
-
-/usr/bin/calendar -a
diff --git a/cron.daily/dpkg b/cron.daily/dpkg
index 62da8172..11124f7d 100755
--- a/cron.daily/dpkg
+++ b/cron.daily/dpkg
@@ -4,33 +4,39 @@ dbdir=/var/lib/dpkg
# Backup the 7 last versions of dpkg databases containing user data.
if cd /var/backups ; then
- # We backup all relevant database files if any has changed, so that
- # the rotation number always contains an internally consistent set.
- dbchanged=no
- dbfiles="arch status diversions statoverride"
+ # We backup all relevant database files if any has changed, so that
+ # the rotation number always contains an internally consistent set.
+ dbchanged=no
+ dbfiles="arch status diversions statoverride"
+ for db in $dbfiles ; do
+ if ! [ -s "dpkg.${db}.0" ] && ! [ -s "$dbdir/$db" ]; then
+ # Special case the files not existing or being empty as being equal.
+ continue
+ elif ! cmp -s "dpkg.${db}.0" "$dbdir/$db"; then
+ dbchanged=yes
+ break
+ fi
+ done
+ if [ "$dbchanged" = "yes" ] ; then
for db in $dbfiles ; do
- if ! cmp -s "dpkg.${db}.0" "$dbdir/$db"; then
- dbchanged=yes
- break;
- fi
+ if [ -e "$dbdir/$db" ]; then
+ cp -p "$dbdir/$db" "dpkg.$db"
+ else
+ touch "dpkg.$db"
+ fi
+ savelog -c 7 "dpkg.$db" >/dev/null
done
- if [ "$dbchanged" = "yes" ] ; then
- for db in $dbfiles ; do
- [ -e "$dbdir/$db" ] || continue
- cp -p "$dbdir/$db" "dpkg.$db"
- savelog -c 7 "dpkg.$db" >/dev/null
- done
- fi
+ fi
- # The alternatives database is independent from the dpkg database.
- dbalt=alternatives
+ # The alternatives database is independent from the dpkg database.
+ dbalt=alternatives
- # XXX: Ideally we'd use --warning=none instead of discarding stderr, but
- # as of GNU tar 1.27.1, it does not seem to work reliably (see #749307).
- if ! test -e ${dbalt}.tar.0 ||
- ! tar -df ${dbalt}.tar.0 -C $dbdir $dbalt >/dev/null 2>&1 ;
- then
- tar -cf ${dbalt}.tar -C $dbdir $dbalt >/dev/null 2>&1
- savelog -c 7 ${dbalt}.tar >/dev/null
- fi
+ # XXX: Ideally we'd use --warning=none instead of discarding stderr, but
+ # as of GNU tar 1.27.1, it does not seem to work reliably (see #749307).
+ if ! test -e ${dbalt}.tar.0 ||
+ ! tar -df ${dbalt}.tar.0 -C $dbdir $dbalt >/dev/null 2>&1 ;
+ then
+ tar -cf ${dbalt}.tar -C $dbdir $dbalt >/dev/null 2>&1
+ savelog -c 7 ${dbalt}.tar >/dev/null
+ fi
fi
diff --git a/cron.daily/exim4-base b/cron.daily/exim4-base
index 9ee41406..0357a0e4 100755
--- a/cron.daily/exim4-base
+++ b/cron.daily/exim4-base
@@ -1,5 +1,12 @@
#!/bin/sh
+EX4SYSTEMDTIMER=$1
+
+# skip in favour of systemd timer if called from cron.daily
+if [ -d /run/systemd/system ] && [ "$EX4SYSTEMDTIMER" != "systemd-timer" ]; then
+ exit 0
+fi
+
if [ -n "$EX4DEBUG" ]; then
echo "now debugging $0 $@"
set -x
@@ -16,6 +23,7 @@ E4BCD_WATCH_PANICLOG="yes"
# Number of lines of paniclog quoted in warning email.
E4BCD_PANICLOG_LINES="10"
E4BCD_PANICLOG_NOISE=""
+E4BCD_PANICLOG_REPORT_TO=root
# Only do anything if exim4 is actually installed
if [ ! -x /usr/lib/exim4/exim4 ]; then
@@ -25,6 +33,13 @@ fi
[ -f /etc/default/exim4 ] && . /etc/default/exim4
SPOOLDIR="$(exim4 -bP spool_directory | sed 's/.*=[[:space:]]\(.*\)/\1/')"
+if [ -n "$E4BCD_DAILY_REPORT_TO" ] || [ "$E4BCD_WATCH_PANICLOG" != "no" ] ; then
+ # Only needed for mail subject.
+ if ! HOSTNAME=$(/usr/sbin/exim4 -be '${primary_hostname}'); then
+ HOSTNAME="$(hostname)"
+ fi
+fi
+
# The log processing code used in this cron script is not very
# sophisticated. It relies on this cron job being executed earlier than
@@ -43,11 +58,11 @@ if [ -n "$E4BCD_DAILY_REPORT_TO" ]; then
if [ "$(< /var/log/exim4/mainlog grep -v "$E4BCD_MAINLOG_NOISE" | wc -l)" -gt "0" ]; then
< /var/log/exim4/mainlog grep -v "$E4BCD_MAINLOG_NOISE" \
| eximstats $E4BCD_DAILY_REPORT_OPTIONS \
- | mail -s"$(hostname --fqdn) Daily e-mail activity report" \
+ | mail -s"${HOSTNAME} Daily e-mail activity report" \
$E4BCD_DAILY_REPORT_TO
else
echo "no mail activity in this interval" \
- | mail -s"$(hostname --fqdn) Daily e-mail activity report" \
+ | mail -s"${HOSTNAME} Daily e-mail activity report" \
$E4BCD_DAILY_REPORT_TO
fi
else
@@ -72,10 +87,10 @@ if [ "$E4BCD_WATCH_PANICLOG" != "no" ]; then
fi
if [ -z "$E4BCD_PANICLOG_NOISE" ] || grep -vq "$E4BCD_PANICLOG_NOISE" /var/log/exim4/paniclog; then
log_this "ALERT: exim paniclog /var/log/exim4/paniclog has non-zero size, mail system possibly broken"
- if ! printf "Subject: exim paniclog on %s has non-zero size\nTo: root\n\nexim paniclog /var/log/exim4/paniclog on %s has non-zero size, mail system might be broken. The last ${E4BCD_PANICLOG_LINES} lines are quoted below.\n\n%s\n" \
- "$(hostname --fqdn)" "$(hostname --fqdn)" \
- "$(tail -n "${E4BCD_PANICLOG_LINES}" /var/log/exim4/paniclog)" \
- | exim4 root; then
+ if ! printf "Subject: exim paniclog on %s has non-zero size\nTo: %s\n\nexim paniclog /var/log/exim4/paniclog on %s has non-zero size, mail system might be broken. Up to ${E4BCD_PANICLOG_LINES} lines are quoted below.\n\n%s\n" \
+ "${HOSTNAME}" "${E4BCD_PANICLOG_REPORT_TO}" "${HOSTNAME}" \
+ "$(if [ -z "$E4BCD_PANICLOG_NOISE" ] ; then tail -n "${E4BCD_PANICLOG_LINES}" /var/log/exim4/paniclog ; else grep -v "$E4BCD_PANICLOG_NOISE" /var/log/exim4/paniclog | tail -n "${E4BCD_PANICLOG_LINES}" ; fi)" \
+ | exim4 "${E4BCD_PANICLOG_REPORT_TO}"; then
log_this "PANIC: sending out e-mail warning has failed, exim has non-zero return code"
fi
if [ "$E4BCD_WATCH_PANICLOG" = "once" ]; then
diff --git a/cron.daily/passwd b/cron.daily/passwd
deleted file mode 100755
index 4778bf09..00000000
--- a/cron.daily/passwd
+++ /dev/null
@@ -1,9 +0,0 @@
-#!/bin/sh
-
-cd /var/backups || exit 0
-
-for FILE in passwd group shadow gshadow; do
- test -f /etc/$FILE || continue
- cmp -s $FILE.bak /etc/$FILE && continue
- cp -p /etc/$FILE $FILE.bak && chmod 600 $FILE.bak
-done
diff --git a/dbus-1/system.d/bluetooth.conf b/dbus-1/system.d/bluetooth.conf
index 66444515..d6e1c7a0 100644
--- a/dbus-1/system.d/bluetooth.conf
+++ b/dbus-1/system.d/bluetooth.conf
@@ -19,6 +19,7 @@
+
@@ -26,18 +27,8 @@
-
-
-
-
-
-
-
-
-
-
+
diff --git a/dbus-1/system.d/wpa_supplicant.conf b/dbus-1/system.d/wpa_supplicant.conf
index e375cdc2..a333302b 100644
--- a/dbus-1/system.d/wpa_supplicant.conf
+++ b/dbus-1/system.d/wpa_supplicant.conf
@@ -3,11 +3,6 @@
"http://www.freedesktop.org/standards/dbus/1.0/busconfig.dtd">
-
-
-
-
-
@@ -23,9 +18,6 @@
-
-
-
diff --git a/debian_version b/debian_version
index 7f0c091e..26d6dad9 100644
--- a/debian_version
+++ b/debian_version
@@ -1 +1 @@
-10.11
+11.2
diff --git a/default/bluetooth b/default/bluetooth
index 5b604a1f..2c310b9d 100644
--- a/default/bluetooth
+++ b/default/bluetooth
@@ -4,7 +4,7 @@
# compatibility note: if this variable is _not_ found bluetooth will start
BLUETOOTH_ENABLED=1
-# This setting used to switch HID devices (e.g mouse/keyboad) to HCI mode, that
+# This setting used to switch HID devices (e.g mouse/keyboard) to HCI mode, that
# is you will have bluetooth functionality from your dongle instead of only
# HID. This is accomplished for supported devices by udev in
# /lib/udev/rules.d/62-bluez-hid2hci.rules by invoking hid2hci with correct
diff --git a/default/bsdmainutils b/default/bsdmainutils
deleted file mode 100644
index e4ac0543..00000000
--- a/default/bsdmainutils
+++ /dev/null
@@ -1,4 +0,0 @@
-# Uncomment the following line if you'd like all of your users'
-# ~/calendar files to be checked daily. Calendar will send them mail
-# to remind them of upcoming events. See calendar(1) for more details.
-#RUN_DAILY=true
diff --git a/default/hwclock b/default/hwclock
index dcf5451f..44b04312 100644
--- a/default/hwclock
+++ b/default/hwclock
@@ -1,19 +1,2 @@
-# Defaults for the hwclock init script. See hwclock(5) and hwclock(8).
-
-# This is used to specify that the hardware clock incapable of storing
-# years outside the range of 1994-1999. Set to yes if the hardware is
-# broken or no if working correctly.
-#BADYEAR=no
-
-# Set this to yes if it is possible to access the hardware clock,
-# or no if it is not.
-#HWCLOCKACCESS=yes
-
-# Set this to any options you might need to give to hwclock, such
-# as machine hardware clock type for Alphas.
-#HWCLOCKPARS=
-
-# Set this to the hardware clock device you want to use, it should
-# probably match the CONFIG_RTC_HCTOSYS_DEVICE kernel config option.
-#HCTOSYS_DEVICE=rtc0
-
+# Settings for the hwclock init script.
+# See hwclock(5) for supported settings.
diff --git a/default/rng-tools b/default/rng-tools-debian
similarity index 62%
rename from default/rng-tools
rename to default/rng-tools-debian
index 5a756427..65d170dc 100644
--- a/default/rng-tools
+++ b/default/rng-tools-debian
@@ -1,7 +1,6 @@
-# Configuration for the rng-tools initscript
-# $Id: rng-tools.default,v 1.1.2.5 2008-06-10 19:51:37 hmh Exp $
-
-# This is a POSIX shell fragment
+# -*- mode: sh -*-
+#-
+# Configuration for the rng-tools-debian initscript
# Set to the input source for random data, leave undefined
# for the initscript to attempt auto-detection. Set to /dev/null
@@ -15,3 +14,9 @@
#RNGDOPTIONS="--hrng=intelfwh --fill-watermark=90% --feed-interval=1"
#RNGDOPTIONS="--hrng=viakernel --fill-watermark=90% --feed-interval=1"
#RNGDOPTIONS="--hrng=viapadlock --fill-watermark=90% --feed-interval=1"
+# For TPM (also add tpm-rng to /etc/initramfs-tools/modules or /etc/modules):
+#RNGDOPTIONS="--fill-watermark=90% --feed-interval=1"
+
+# If you need to configure which RNG to use, do it here:
+#HRNGSELECT="virtio_rng.0"
+# Use this instead of sysfsutils, which starts too late.
diff --git a/default/rpcbind b/default/rpcbind
new file mode 100644
index 00000000..67a9654e
--- /dev/null
+++ b/default/rpcbind
@@ -0,0 +1,12 @@
+# /etc/init.d/rpcbind
+
+OPTIONS=""
+
+# Cause rpcbind to do a "warm start" utilizing a state file (default)
+OPTIONS="-w"
+
+# Uncomment the following line to restrict rpcbind to localhost only for UDP requests
+# OPTIONS="${OPTIONS} -h 127.0.0.1 -h ::1"
+
+# Uncomment the following line to enable libwrap TCP-Wrapper connection logging
+# OPTIONS="${OPTIONS} -l "
diff --git a/default/rsyslog b/default/rsyslog
deleted file mode 100644
index 8ec3ea0b..00000000
--- a/default/rsyslog
+++ /dev/null
@@ -1,4 +0,0 @@
-# Options for rsyslogd
-# -x disables DNS lookups for remote messages
-# See rsyslogd(8) for more details
-RSYSLOGD_OPTIONS=""
diff --git a/default/snmpd b/default/snmpd
index eede856d..eff0d824 100644
--- a/default/snmpd
+++ b/default/snmpd
@@ -6,7 +6,7 @@
# Don't load any MIBs by default.
# You might comment this lines once you have the MIBs downloaded.
-export MIBS=
+# export MIBS=
-# snmpd options (use syslog, close stdin/out/err).
-#SNMPDOPTS='-Lsd -Lf /dev/null -u Debian-snmp -g Debian-snmp -I -smux,mteTrigger,mteTriggerConf -p /run/snmpd.pid'
+# snmpd options (use syslog priority warning, close stdin/out/err).
+#SNMPDOPTS='-LSwd -Lf /dev/null -u Debian-snmp -g Debian-snmp -I -smux,mteTrigger,mteTriggerConf -p /run/snmpd.pid'
diff --git a/dhcp/dhclient-exit-hooks.d/timesyncd b/dhcp/dhclient-exit-hooks.d/timesyncd
deleted file mode 100644
index 3cde9929..00000000
--- a/dhcp/dhclient-exit-hooks.d/timesyncd
+++ /dev/null
@@ -1,42 +0,0 @@
-TIMESYNCD_CONF=/run/systemd/timesyncd.conf.d/01-dhclient.conf
-
-timesyncd_servers_setup_remove() {
- if [ -e $TIMESYNCD_CONF ]; then
- rm -f $TIMESYNCD_CONF
- systemctl try-restart systemd-timesyncd.service || true
- fi
-}
-
-timesyncd_servers_setup_add() {
- if [ ! -d /run/systemd/system ]; then
- return
- fi
-
- if [ -e $TIMESYNCD_CONF ] && [ "$new_ntp_servers" = "$old_ntp_servers" ]; then
- return
- fi
-
- if [ -z "$new_ntp_servers" ]; then
- timesyncd_servers_setup_remove
- return
- fi
-
- mkdir -p $(dirname $TIMESYNCD_CONF)
- cat < ${TIMESYNCD_CONF}.new
-# NTP server entries received from DHCP server
-[Time]
-NTP=$new_ntp_servers
-EOF
- mv ${TIMESYNCD_CONF}.new ${TIMESYNCD_CONF}
- systemctl try-restart systemd-timesyncd.service || true
-}
-
-
-case $reason in
- BOUND|RENEW|REBIND|REBOOT)
- timesyncd_servers_setup_add
- ;;
- EXPIRE|FAIL|RELEASE|STOP)
- timesyncd_servers_setup_remove
- ;;
-esac
diff --git a/dpkg/origins/debian b/dpkg/origins/debian
index 91f6ed1d..3b623d25 100644
--- a/dpkg/origins/debian
+++ b/dpkg/origins/debian
@@ -1,3 +1,3 @@
Vendor: Debian
-Vendor-URL: http://www.debian.org/
+Vendor-URL: https://www.debian.org/
Bugs: debbugs://bugs.debian.org
diff --git a/e2scrub.conf b/e2scrub.conf
new file mode 100644
index 00000000..661fc13f
--- /dev/null
+++ b/e2scrub.conf
@@ -0,0 +1,25 @@
+# e2scrub configuration file
+
+# Uncomment to enable automatic periodic runs of e2scrub_all
+# (either via cron or via a systemd timer)
+# periodic_e2scrub=1
+
+# e-mail destination used by e2scrub_fail when problems are found with
+# the file system.
+# recipient=root
+
+# e-mail sender used by e2scrub_fail when problems are found with
+# the file system.
+# sender=e2scrub@host.domain.name
+
+# Snapshots will be created to run fsck; the snapshot will be of this size.
+# snap_size_mb=256
+
+# Set this to 1 to enable fstrim for everyone.
+# fstrim=0
+
+# Arguments passed into e2fsck.
+# e2fsck_opts="-vtt"
+
+# Set this to 1 to have e2scrub_all scrub all LVs, not just the mounted ones.
+# scrub_all=0
diff --git a/etckeeper/commit.d/50vcs-commit b/etckeeper/commit.d/50vcs-commit
index f970d3d5..ca024795 100755
--- a/etckeeper/commit.d/50vcs-commit
+++ b/etckeeper/commit.d/50vcs-commit
@@ -12,16 +12,15 @@ if [ -n "$1" ]; then
if [ "x$1" = "x--stdin" ]; then
cat > "$logfile"
else
- if [ "x$1" = "x-m" ]; then
- shift 1
- fi
- echo "$1" > "$logfile"
+ sed '1s/^-m \{0,1\}//' >"$logfile" <<-EOF
+ $*
+ EOF
fi
else
logfile=""
fi
-hostname=`hostname`
+hostname=`hostname 2>/dev/null || cat /etc/hostname`
hostname="${hostname%%.*}"
dnsdomainname=`dnsdomainname 2>/dev/null || true`
if [ -n "$dnsdomainname" ]; then
@@ -92,10 +91,18 @@ if [ "$VCS" = git ] && [ -d .git ]; then
export GIT_COMMITTER_EMAIL
fi
fi
+
+ # gc ten times more frequently than the default
+ # (unless some other config is set)
+ GIT_GC_OPTIONS=
+ if ! git config gc.auto >/dev/null; then
+ GIT_GC_OPTIONS="-c gc.auto=670"
+ fi
+
if [ -n "$logfile" ]; then
- git commit $GIT_COMMIT_OPTIONS -F "$logfile"
+ git $GIT_GC_OPTIONS commit $GIT_COMMIT_OPTIONS -F "$logfile"
else
- git commit $GIT_COMMIT_OPTIONS
+ git $GIT_GC_OPTIONS commit $GIT_COMMIT_OPTIONS
fi
elif [ "$VCS" = hg ] && [ -d .hg ]; then
if [ -n "$USER" ]; then
diff --git a/etckeeper/init.d/10restore-metadata b/etckeeper/init.d/10restore-metadata
index 9c2bf65b..b0c90492 100755
--- a/etckeeper/init.d/10restore-metadata
+++ b/etckeeper/init.d/10restore-metadata
@@ -6,7 +6,7 @@ set -e
# file won't do anything shady, because, as documented, etckeeper-init
# should only be run on repositories you trust.
if [ -e .metadata ]; then
- if which metastore >/dev/null; then
+ if command -v metastore >/dev/null; then
metastore --apply --mtime
else
echo "etckeeper warning: legacy .metastore file is present but metastore is not installed" >&2
diff --git a/etckeeper/init.d/40vcs-init b/etckeeper/init.d/40vcs-init
index 3c7a3bb9..27eba4e9 100755
--- a/etckeeper/init.d/40vcs-init
+++ b/etckeeper/init.d/40vcs-init
@@ -1,17 +1,18 @@
#!/bin/sh
set -e
+description="$(hostname 2>/dev/null || cat /etc/hostname) /etc repository"
if [ "$VCS" = git ] && [ ! -e .git ]; then
git init
- echo "$(hostname) /etc repository" > .git/description
+ echo "$description" > .git/description
elif [ "$VCS" = hg ] && [ ! -e .hg ]; then
hg init
echo "[web]" > .hg/hgrc
- echo "description = $(hostname) /etc repository" >> .hg/hgrc
+ echo "description = $description" >> .hg/hgrc
elif [ "$VCS" = bzr ] && [ ! -e .bzr ]; then
bzr init
- bzr nick "$(hostname) /etc repository"
+ bzr nick "$description"
elif [ "$VCS" = darcs ] && [ ! -e _darcs ]; then
darcs initialize
- echo "$(hostname) /etc repository" > _darcs/prefs/motd
+ echo "$description" > _darcs/prefs/motd
fi
diff --git a/etckeeper/list-installed.d/50list-installed b/etckeeper/list-installed.d/50list-installed
index d89b8cee..3b2ff6f9 100755
--- a/etckeeper/list-installed.d/50list-installed
+++ b/etckeeper/list-installed.d/50list-installed
@@ -7,6 +7,11 @@ if [ "$1" = fmt ]; then
echo ""
fi
else
+ # Keep the sort order the same at all times.
+ LC_COLLATE=C
+ export LC_COLLATE
+ unset LC_ALL
+
# Output to stdout a *sorted* list of all currently installed
# (or removed but still with config-files) packages, in the
# format "package version\n" (or something similar).
diff --git a/etckeeper/post-install.d/50vcs-commit b/etckeeper/post-install.d/50vcs-commit
index bc9cdf05..e8fa4fca 100755
--- a/etckeeper/post-install.d/50vcs-commit
+++ b/etckeeper/post-install.d/50vcs-commit
@@ -14,6 +14,43 @@ if ! [ -z "${ETCKEEPER_PID}" ]; then
ETCKEEPER_PARENT_COMMAND_LINE=$( ps --no-headers -o args "${ETCKEEPER_PPID}" )
fi
+get_changes () {
+ if [ "$VCS" = git ]; then
+ git diff --stat | grep '|' | cut -d'|' -f1 | cut -b2-
+ git ls-files --exclude-standard --others
+ fi
+ if [ "$VCS" = hg ]; then
+ hg status --no-status
+ fi
+ if [ "$VCS" = bzr ]; then
+ bzr status -S | cut -b5-
+ fi
+ if [ "$VCS" = darcs ]; then
+ # ignore ' file -> file' lines for moved files
+ # trim ' -M +N rP' from change summary
+ darcs whatsnew --summary | grep -v '^ .* -> ' | cut -d' ' -f2- | sed 's/ [-+r][0-9]\+//g;s/^\.\///'
+ # lines beginning with 'a' show unversioned files
+ darcs whatsnew --look-for-adds --boring --summary | grep '^a' | cut -d' ' -f2- | sed 's/^\.\///'
+ fi
+}
+
+get_changed_packages () {
+ if [ "$LOWLEVEL_PACKAGE_MANAGER" = dpkg ]; then
+ get_changes | sed 's/^/\/etc\//;s/\s*$//' | xargs -d '\n' dpkg 2>/dev/null -S | cut -d':' -f1 | sed 's/, /\n/g'
+ fi
+ if [ "$LOWLEVEL_PACKAGE_MANAGER" = rpm ]; then
+ # if output contains file path, file was not found
+ get_changes | sed 's/^/\/etc\//;s/\s*$//' | xargs -d '\n' rpm --qf '%{NAME}\n' -qf | grep -v "/etc/"
+ fi
+ # is it even possible to use pacmatic without pacman?
+ if [ "$LOWLEVEL_PACKAGE_MANAGER" = pacman -o "$LOWLEVEL_PACKAGE_MANAGER" = pacmatic ]; then
+ get_changes | sed 's/^/\/etc\//;s/\s*$//' | xargs -d '\n' pacman 2>/dev/null -Qo | rev | cut -d' ' -f1-2 | rev | cut -d' ' -f1
+ fi
+ if [ "$LOWLEVEL_PACKAGE_MANAGER" = pkgng ]; then
+ get_changes | sed 's/^/\/etc\//;s/\s*$//' | xargs -d '\n' pkg which --quiet | rev | cut -d'-' -f2- | rev
+ fi
+}
+
if etckeeper unclean; then
if [ -z "${ETCKEEPER_PARENT_COMMAND_LINE}" ]; then
message="committing changes in /etc after $HIGHLEVEL_PACKAGE_MANAGER run"
@@ -26,6 +63,16 @@ if etckeeper unclean; then
(
echo "$message"
echo
+ get_changed_packages | sort | uniq > $pl.found-pkgs
+ if [ -s $pl.found-pkgs ]; then
+ sed -i 's/^/^[-+]/;s/$/ /' $pl.found-pkgs
+ etckeeper list-installed | diff -U0 $pl.pre-install - | tail -n+4 | egrep '^[-+]' | grep -f $pl.found-pkgs > $pl.found-packages
+ if [ -s $pl.found-packages ]; then
+ echo "Packages with configuration changes:"
+ cat $pl.found-packages || true
+ echo
+ fi
+ fi
echo "Package changes:"
etckeeper list-installed | diff -U0 $pl.pre-install - | tail -n+4 | egrep '^[-+]' || true
) | etckeeper commit --stdin
@@ -41,3 +88,4 @@ if etckeeper unclean; then
fi
rm -f $pl.pre-install $pl.fmt
+rm -f $pl.found-pkgs $pl.found-packages
diff --git a/etckeeper/pre-commit.d/30store-metadata b/etckeeper/pre-commit.d/30store-metadata
index ce014d12..7c7f0558 100755
--- a/etckeeper/pre-commit.d/30store-metadata
+++ b/etckeeper/pre-commit.d/30store-metadata
@@ -1,9 +1,10 @@
#!/bin/sh
set -e
-# Make sure sort always sorts in same order.
-LANG=C
-export LANG
+# Keep the sort order the same at all times.
+LC_COLLATE=C
+export LC_COLLATE
+unset LC_ALL
filter_ignore() {
case "$VCS" in
@@ -56,11 +57,6 @@ generate_metadata() {
# printed!)
NOVCS='. -path ./.git -prune -o -path ./.bzr -prune -o -path ./.hg -prune -o -path ./_darcs -prune -o'
- # Keep the sort order the same at all times.
- LC_COLLATE=C
- export LC_COLLATE
- unset LC_ALL
-
if [ "$VCS" = git ] || [ "$VCS" = hg ]; then
# These version control systems do not track directories,
# so empty directories must be stored specially.
@@ -86,7 +82,7 @@ generate_metadata() {
}
maybe_chmod_chown() {
- if [ "$(which perl 2>/dev/null)" != "" ]; then
+ if command -v perl >/dev/null; then
perl -ne '
BEGIN { $q=chr(39) }
sub uidname {
diff --git a/etckeeper/uninit.d/50vcs-uninit b/etckeeper/uninit.d/50vcs-uninit
index 06317c56..10070693 100755
--- a/etckeeper/uninit.d/50vcs-uninit
+++ b/etckeeper/uninit.d/50vcs-uninit
@@ -21,10 +21,10 @@ if ! grep -q "$managed_by_etckeeper" "$file"; then
exit 0
else
realfile="$file"
- if which tempfile >/dev/null 2>&1 || type tempfile >/dev/null 2>&1; then
- tempfile="tempfile"
- elif which mktemp >/dev/null 2>&1 || type mktemp >/dev/null 2>&1; then
+ if command -v mktemp >/dev/null; then
tempfile="mktemp"
+ elif command -v tempfile >/dev/null; then
+ tempfile="tempfile"
else
echo "etckeeper warning: can't find tempfile or mktemp" >&2
exit 1
diff --git a/etckeeper/update-ignore.d/01update-ignore b/etckeeper/update-ignore.d/01update-ignore
index 8733a85f..78222524 100755
--- a/etckeeper/update-ignore.d/01update-ignore
+++ b/etckeeper/update-ignore.d/01update-ignore
@@ -175,14 +175,19 @@ if [ -e "$file" ]; then
fi
fi
realfile="$file"
- if which tempfile >/dev/null 2>&1 || type tempfile >/dev/null 2>&1; then
- tempfile="tempfile"
- elif which mktemp >/dev/null 2>&1 || type mktemp >/dev/null 2>&1; then
+ if command -v mktemp >/dev/null; then
tempfile="mktemp"
+ elif command -v tempfile >/dev/null; then
+ tempfile="tempfile"
else
echo "etckeeper warning: can't find tempfile or mktemp" >&2
fi
file=$($tempfile)
+
+ # preserve permissions and ownership
+ cp -fp "$realfile" "$file"
+ cat /dev/null >"$file"
+
(
skipping=
while read -r line; do
diff --git a/etckeeper/vcs.d/50vcs-cmd b/etckeeper/vcs.d/50vcs-cmd
index f515abbe..307f1e12 100755
--- a/etckeeper/vcs.d/50vcs-cmd
+++ b/etckeeper/vcs.d/50vcs-cmd
@@ -2,7 +2,7 @@
set -e
# check whether we can locate the vcs binary
-if [ -n "$VCS" ] && which "$VCS" > /dev/null; then
+if [ -n "$VCS" ] && command -v "$VCS" > /dev/null; then
# pass commands to the VCS application
$VCS "$@"
else
diff --git a/ethertypes b/ethertypes
new file mode 100644
index 00000000..caa9f56b
--- /dev/null
+++ b/ethertypes
@@ -0,0 +1,45 @@
+# Ethernet frame types
+#
+# The EtherType is a two-octet field of Ethernet frames used to indicate
+# which protocol is contained in their payload.
+#
+# More entries, mostly historical, can be found on:
+# https://www.iana.org/assignments/ieee-802-numbers/
+# http://standards-oui.ieee.org/ethertype/eth.txt
+#
+# ... # Comment
+#
+IPv4 0800 ip ip4 # IP (IPv4)
+X25 0805
+ARP 0806 ether-arp # Address Resolution Protocol
+FR_ARP 0808 # Frame Relay ARP [RFC1701]
+BPQ 08FF # G8BPQ AX.25 over Ethernet
+TRILL 22F3 # TRILL [RFC6325]
+L2-IS-IS 22F4 # TRILL IS-IS [RFC6325]
+TEB 6558 # Transparent Ethernet Bridging [RFC1701]
+RAW_FR 6559 # Raw Frame Relay [RFC1701]
+RARP 8035 # Reverse ARP [RFC903]
+ATALK 809B # Appletalk
+AARP 80F3 # Appletalk Address Resolution Protocol
+802_1Q 8100 8021q 1q 802.1q dot1q # VLAN tagged frame [802.1q]
+IPX 8137 # Novell IPX
+NetBEUI 8191 # NetBEUI
+IPv6 86DD ip6 # IP version 6
+PPP 880B # Point-to-Point Protocol
+MPLS 8847 # MPLS [RFC5332]
+MPLS_MULTI 8848 # MPLS with upstream-assigned label [RFC5332]
+ATMMPOA 884C # MultiProtocol over ATM
+PPP_DISC 8863 # PPP over Ethernet discovery stage
+PPP_SES 8864 # PPP over Ethernet session stage
+ATMFATE 8884 # Frame-based ATM Transport over Ethernet
+EAPOL 888E # EAP over LAN [802.1x]
+S-TAG 88A8 # QinQ Service VLAN tag identifier [802.1q]
+EAP_PREAUTH 88C7 # EAPOL Pre-Authentication [802.11i]
+LLDP 88CC # Link Layer Discovery Protocol [802.1ab]
+MACSEC 88E5 # Media Access Control Security [802.1ae]
+PBB 88E7 macinmac # Provider Backbone Bridging [802.1ah]
+MVRP 88F5 # Multiple VLAN Registration Protocol [802.1q]
+PTP 88F7 # Precision Time Protocol
+FCOE 8906 # Fibre Channel over Ethernet
+FIP 8914 # FCoE Initialization Protocol
+ROCE 8915 # RDMA over Converged Ethernet
diff --git a/exim4/conf.d/acl/30_exim4-config_check_rcpt b/exim4/conf.d/acl/30_exim4-config_check_rcpt
index b8bde1e3..c70d5159 100644
--- a/exim4/conf.d/acl/30_exim4-config_check_rcpt
+++ b/exim4/conf.d/acl/30_exim4-config_check_rcpt
@@ -130,9 +130,9 @@ acl_check_rcpt:
# to the smarthost.
.ifdef CHECK_RCPT_VERIFY_SENDER
deny
- message = Sender verification failed
!acl = acl_local_deny_exceptions
!verify = sender
+ message = Sender verification failed
.endif
# Verify senders listed in local_sender_callout with a callout.
@@ -147,6 +147,21 @@ acl_check_rcpt:
{}}
!verify = sender/callout
+ .ifndef CHECK_RCPT_NO_FAIL_TOO_MANY_BAD_RCPT
+ # Reject all RCPT commands after too many bad recipients
+ # This is partly a defense against spam abuse and partly attacker abuse.
+ # Real senders should manage, by the time they get to 10 RCPT directives,
+ # to have had at least half of them be real addresses.
+ #
+ # This is a lightweight check and can protect you against repeated
+ # invocations of more heavy-weight checks which would come after it.
+
+ deny condition = ${if and {\
+ {>{$rcpt_count}{10}}\
+ {<{$recipients_count}{${eval:$rcpt_count/2}}} }}
+ message = Rejected for too many bad recipients
+ logwrite = REJECT [$sender_host_address]: bad recipient count high [${eval:$rcpt_count-$recipients_count}]
+ .endif
# Accept if the message comes from one of the hosts for which we are an
# outgoing relay. It is assumed that such hosts are most likely to be MUAs,
@@ -183,8 +198,9 @@ acl_check_rcpt:
# Insist that a HELO/EHLO was accepted.
- require message = nice hosts say HELO first
- condition = ${if def:sender_helo_name}
+ require
+ condition = ${if def:sender_helo_name}
+ message = nice hosts say HELO first
# Insist that any other recipient address that we accept is either in one of
# our local domains, or is in a domain for which we explicitly allow
@@ -222,12 +238,12 @@ acl_check_rcpt:
# The explicit white lists are honored as well as negative items in
# the black list. See exim4-config_files(5) for details.
deny
- message = sender envelope address $sender_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
- log_message = sender envelope address is locally blacklisted.
!acl = acl_local_deny_exceptions
senders = ${if exists{CONFDIR/local_sender_blacklist}\
{CONFDIR/local_sender_blacklist}\
{}}
+ message = sender envelope address $sender_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
+ log_message = sender envelope address is locally blacklisted.
# deny bad sites (IP address)
@@ -239,12 +255,12 @@ acl_check_rcpt:
# The explicit white lists are honored as well as negative items in
# the black list. See exim4-config_files(5) for details.
deny
- message = sender IP address $sender_host_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
- log_message = sender IP address is locally blacklisted.
!acl = acl_local_deny_exceptions
hosts = ${if exists{CONFDIR/local_host_blacklist}\
{CONFDIR/local_host_blacklist}\
{}}
+ message = sender IP address $sender_host_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
+ log_message = sender IP address is locally blacklisted.
# Warn if the sender host does not have valid reverse DNS.
@@ -263,8 +279,7 @@ acl_check_rcpt:
.endif
- # Use spfquery to perform a pair of SPF checks (for details, see
- # http://www.openspf.org/)
+ # Use spfquery to perform a pair of SPF checks.
#
# This is quite costly in terms of DNS lookups (~6 lookups per mail). Do not
# enable if that's an issue. Also note that if you enable this, you must
@@ -273,13 +288,6 @@ acl_check_rcpt:
# SPF check" warning.
.ifdef CHECK_RCPT_SPF
deny
- message = [SPF] $sender_host_address is not allowed to send mail from \
- ${if def:sender_address_domain {$sender_address_domain}{$sender_helo_name}}. \
- Please see \
- http://www.openspf.org/Why?scope=${if def:sender_address_domain \
- {mfrom}{helo}};identity=${if def:sender_address_domain \
- {$sender_address}{$sender_helo_name}};ip=$sender_host_address
- log_message = SPF check failed.
!acl = acl_local_deny_exceptions
condition = ${run{/usr/bin/spfquery.mail-spf-perl --ip \
${quote:$sender_host_address} --identity \
@@ -287,11 +295,14 @@ acl_check_rcpt:
{--scope mfrom --identity ${quote:$sender_address}}\
{--scope helo --identity ${quote:$sender_helo_name}}}}\
{no}{${if eq {$runrc}{1}{yes}{no}}}}
+ message = [SPF] $sender_host_address is not allowed to send mail from \
+ ${if def:sender_address_domain {$sender_address_domain}{$sender_helo_name}}.
+ log_message = SPF check failed.
defer
- message = Temporary DNS error while checking SPF record. Try again later.
!acl = acl_local_deny_exceptions
condition = ${if eq {$runrc}{5}{yes}{no}}
+ message = Temporary DNS error while checking SPF record. Try again later.
warn
condition = ${if <={$runrc}{6}{yes}{no}}
@@ -306,8 +317,8 @@ acl_check_rcpt:
helo=$sender_helo_name
warn
- log_message = Unexpected error in SPF check.
condition = ${if >{$runrc}{6}{yes}{no}}
+ log_message = Unexpected error in SPF check.
.endif
diff --git a/exim4/conf.d/acl/40_exim4-config_check_data b/exim4/conf.d/acl/40_exim4-config_check_data
index 5b5c099c..ac198f99 100644
--- a/exim4/conf.d/acl/40_exim4-config_check_data
+++ b/exim4/conf.d/acl/40_exim4-config_check_data
@@ -12,9 +12,10 @@ acl_check_data:
# we should never receive one such via SMTP.
#
.ifndef IGNORE_SMTP_LINE_LENGTH_LIMIT
- deny message = maximum allowed line length is 998 octets, \
+ deny
+ condition = ${if > {$max_received_linelength}{998}}
+ message = maximum allowed line length is 998 octets, \
got $max_received_linelength
- condition = ${if > {$max_received_linelength}{998}}
.endif
# Deny if the headers contain badly-formed addresses.
@@ -32,9 +33,9 @@ acl_check_data:
# one of the "Sender:", "Reply-To:", or "From:" header lines.
.ifdef CHECK_DATA_VERIFY_HEADER_SENDER
deny
- message = No verifiable sender address in message headers
!acl = acl_local_deny_exceptions
!verify = header_sender
+ message = No verifiable sender address in message headers
.endif
@@ -77,9 +78,9 @@ acl_check_data:
# Reject spam messages (score >15.0).
# This breaks mailing list and forward messages.
# deny
- # message = Classified as spam (score $spam_score)
# condition = ${if <{$message_size}{120k}{1}{0}}
# condition = ${if >{$spam_score_int}{150}{true}{false}}
+ # message = Classified as spam (score $spam_score)
# This hook allows you to hook in your own ACLs without having to
diff --git a/exim4/conf.d/auth/30_exim4-config_examples b/exim4/conf.d/auth/30_exim4-config_examples
index b3b1ce69..4232a5b1 100644
--- a/exim4/conf.d/auth/30_exim4-config_examples
+++ b/exim4/conf.d/auth/30_exim4-config_examples
@@ -140,13 +140,13 @@
# This is now the (working!) example from
# http://www.exim.org/eximwiki/FAQ/Policy_controls/Q0730
-# Possible pitfall: access rights on /var/run/courier/authdaemon/socket.
+# Possible pitfall: access rights on /run/courier/authdaemon/socket.
# plain_courier_authdaemon:
# driver = plaintext
# public_name = PLAIN
# server_condition = \
# ${extract {ADDRESS} \
-# {${readsocket{/var/run/courier/authdaemon/socket} \
+# {${readsocket{/run/courier/authdaemon/socket} \
# {AUTH ${strlen:exim\nlogin\n$auth2\n$auth3\n}\nexim\nlogin\n$auth2\n$auth3\n} }} \
# {yes} \
# fail}
@@ -161,7 +161,7 @@
# server_prompts = Username:: : Password::
# server_condition = \
# ${extract {ADDRESS} \
-# {${readsocket{/var/run/courier/authdaemon/socket} \
+# {${readsocket{/run/courier/authdaemon/socket} \
# {AUTH ${strlen:exim\nlogin\n$auth1\n$auth2\n}\nexim\nlogin\n$auth1\n$auth2\n} }} \
# {yes} \
# fail}
diff --git a/exim4/conf.d/main/02_exim4-config_options b/exim4/conf.d/main/02_exim4-config_options
index abff1d8b..ab87fbdc 100644
--- a/exim4/conf.d/main/02_exim4-config_options
+++ b/exim4/conf.d/main/02_exim4-config_options
@@ -46,7 +46,7 @@ message_size_limit = MESSAGE_SIZE_LIMIT
# scanners. The second modification is in the acl_check_data access
# control list.
-# av_scanner = clamd:/var/run/clamav/clamd.ctl
+# av_scanner = clamd:/run/clamav/clamd.ctl
# For spam scanning, there is a similar option that defines the interface to
@@ -113,7 +113,11 @@ primary_hostname = MAIN_HARDCODE_PRIMARY_HOSTNAME
# Enable an efficiency feature. We advertise the feature; clients
# may request to use it. For multi-recipient mails we then can
# reject or accept per-user after the message is received.
-#
+# This supports recipient-dependent content filtering; without it
+# you have to temp-reject any recipients after the first that have
+# incompatible filtering, and do the filtering in the data ACL.
+# Even with this enabled, you must support the old style for peers
+# not flagging support for PRDR (visible via $prdr_requested).
prdr_enable = true
# When using an external relay tester (such as rt.njabl.org and/or the
@@ -220,3 +224,10 @@ keep_environment =
.ifdef MAIN_ADD_ENVIRONMENT
add_environment = MAIN_ADD_ENVIRONMENT
.endif
+
+.ifdef _OPT_MAIN_SMTPUTF8_ADVERTISE_HOSTS
+.ifndef MAIN_SMTPUTF8_ADVERTISE_HOSTS
+MAIN_SMTPUTF8_ADVERTISE_HOSTS =
+.endif
+smtputf8_advertise_hosts = MAIN_SMTPUTF8_ADVERTISE_HOSTS
+.endif
diff --git a/exim4/conf.d/main/03_exim4-config_tlsoptions b/exim4/conf.d/main/03_exim4-config_tlsoptions
index 86299e16..268c4c1d 100644
--- a/exim4/conf.d/main/03_exim4-config_tlsoptions
+++ b/exim4/conf.d/main/03_exim4-config_tlsoptions
@@ -75,11 +75,6 @@ tls_verify_hosts = MAIN_TLS_VERIFY_HOSTS
tls_try_verify_hosts = MAIN_TLS_TRY_VERIFY_HOSTS
.endif
-.ifdef _HAVE_GNUTLS
-tls_dhparam = historic
-.endif
-
.else
-# Don't advertise TLS if MAIN_TLS_ENABLE is not set.
-tls_advertise_hosts =
+# Use upstream defaults
.endif
diff --git a/exim4/conf.d/router/200_exim4-config_primary b/exim4/conf.d/router/200_exim4-config_primary
index 8b03ae7a..0022dc6c 100644
--- a/exim4/conf.d/router/200_exim4-config_primary
+++ b/exim4/conf.d/router/200_exim4-config_primary
@@ -19,9 +19,13 @@ dnslookup_relay_to_domains:
domains = ! +local_domains : +relay_to_domains
transport = remote_smtp
same_domain_copy_routing = yes
- dnssec_request_domains = *
no_more
+# ignore private rfc1918, loopback, APIPA/link-local, local broadcast, unspecified, unique local, linked-scoped unicast and discard-Only
+.ifndef ROUTER_DNSLOOKUP_IGNORE_TARGET_HOSTS
+ROUTER_DNSLOOKUP_IGNORE_TARGET_HOSTS = <; 0.0.0.0 ; 127.0.0.0/8 ; 192.168.0.0/16 ; 172.16.0.0/12 ; 10.0.0.0/8 ; 169.254.0.0/16 ; 255.255.255.255 ; ::/128 ; ::1/128 ; fc00::/7 ; fe80::/10 ; 100::/64
+.endif
+
# deliver mail directly to the recipient. This router is only reached
# for domains that we do not relay for. Since we most probably can't
# have broken MX records pointing to site local or link local IP
@@ -33,11 +37,7 @@ dnslookup:
domains = ! +local_domains
transport = remote_smtp
same_domain_copy_routing = yes
- # ignore private rfc1918 and APIPA addresses
- ignore_target_hosts = 0.0.0.0 : 127.0.0.0/8 : 192.168.0.0/16 :\
- 172.16.0.0/12 : 10.0.0.0/8 : 169.254.0.0/16 :\
- 255.255.255.255
- dnssec_request_domains = *
+ ignore_target_hosts = ROUTER_DNSLOOKUP_IGNORE_TARGET_HOSTS
no_more
.endif
diff --git a/exim4/conf.d/router/600_exim4-config_userforward b/exim4/conf.d/router/600_exim4-config_userforward
index 59259ca8..01fc0baf 100644
--- a/exim4/conf.d/router/600_exim4-config_userforward
+++ b/exim4/conf.d/router/600_exim4-config_userforward
@@ -25,7 +25,7 @@ userforward:
domains = +local_domains
check_local_user
file = $home/.forward
- require_files = $local_part:$home/.forward
+ require_files = $local_part_data:$home/.forward
no_verify
no_expn
check_ancestor
diff --git a/exim4/conf.d/router/700_exim4-config_procmail b/exim4/conf.d/router/700_exim4-config_procmail
index 8d827c7c..55d4eb6a 100644
--- a/exim4/conf.d/router/700_exim4-config_procmail
+++ b/exim4/conf.d/router/700_exim4-config_procmail
@@ -6,7 +6,7 @@ procmail:
check_local_user
transport = procmail_pipe
# emulate OR with "if exists"-expansion
- require_files = ${local_part}:\
+ require_files = ${local_part_data}:\
${if exists{/etc/procmailrc}\
{/etc/procmailrc}{${home}/.procmailrc}}:\
+/usr/bin/procmail
diff --git a/exim4/conf.d/router/800_exim4-config_maildrop b/exim4/conf.d/router/800_exim4-config_maildrop
index 0c57fc6a..0777f145 100644
--- a/exim4/conf.d/router/800_exim4-config_maildrop
+++ b/exim4/conf.d/router/800_exim4-config_maildrop
@@ -8,7 +8,7 @@ maildrop:
domains = +local_domains
check_local_user
transport = maildrop_pipe
- require_files = ${local_part}:${home}/.mailfilter:+/usr/bin/maildrop
+ require_files = ${local_part_data}:${home}/.mailfilter:+/usr/bin/maildrop
no_verify
no_expn
diff --git a/exim4/conf.d/transport/10_exim4-config_transport-macros b/exim4/conf.d/transport/10_exim4-config_transport-macros
index 449fb319..e185d405 100644
--- a/exim4/conf.d/transport/10_exim4-config_transport-macros
+++ b/exim4/conf.d/transport/10_exim4-config_transport-macros
@@ -14,3 +14,7 @@ REMOTE_SMTP_HELO_DATA==${lookup dnsdb {ptr=$sending_ip_address}{$value}{$primary
REMOTE_SMTP_HELO_DATA=${lookup dnsdb {ptr=$sending_ip_address}{$value}{$primary_hostname}}
.endif
.endif
+
+.ifndef REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS
+ REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS = *
+.endif
diff --git a/exim4/conf.d/transport/30_exim4-config_mail_spool b/exim4/conf.d/transport/30_exim4-config_mail_spool
index 21dfae4a..98dc64c9 100644
--- a/exim4/conf.d/transport/30_exim4-config_mail_spool
+++ b/exim4/conf.d/transport/30_exim4-config_mail_spool
@@ -7,7 +7,7 @@
mail_spool:
debug_print = "T: appendfile for $local_part@$domain"
driver = appendfile
- file = /var/mail/$local_part
+ file = /var/mail/$local_part_data
delivery_date_add
envelope_to_add
return_path_add
diff --git a/exim4/conf.d/transport/30_exim4-config_remote_smtp b/exim4/conf.d/transport/30_exim4-config_remote_smtp
index bbad5fd7..f9b3a3ae 100644
--- a/exim4/conf.d/transport/30_exim4-config_remote_smtp
+++ b/exim4/conf.d/transport/30_exim4-config_remote_smtp
@@ -24,6 +24,9 @@ remote_smtp:
.ifdef REMOTE_SMTP_HELO_DATA
helo_data=REMOTE_SMTP_HELO_DATA
.endif
+.ifdef REMOTE_SMTP_INTERFACE
+ interface = REMOTE_SMTP_INTERFACE
+.endif
.ifdef DKIM_DOMAIN
dkim_domain = DKIM_DOMAIN
.endif
@@ -42,6 +45,9 @@ dkim_strict = DKIM_STRICT
.ifdef DKIM_SIGN_HEADERS
dkim_sign_headers = DKIM_SIGN_HEADERS
.endif
+.ifdef DKIM_TIMESTAMPS
+dkim_timestamps = DKIM_TIMESTAMPS
+.endif
.ifdef TLS_DH_MIN_BITS
tls_dh_min_bits = TLS_DH_MIN_BITS
.endif
@@ -51,7 +57,9 @@ tls_certificate = REMOTE_SMTP_TLS_CERTIFICATE
.ifdef REMOTE_SMTP_PRIVATEKEY
tls_privatekey = REMOTE_SMTP_PRIVATEKEY
.endif
-.ifndef REMOTE_SMTP_DISABLE_DANE
-dnssec_request_domains = *
-hosts_try_dane = *
+.ifdef REMOTE_SMTP_HOSTS_REQUIRE_TLS
+ hosts_require_tls = REMOTE_SMTP_HOSTS_REQUIRE_TLS
+.endif
+.ifdef REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
+ headers_remove = REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
.endif
diff --git a/exim4/conf.d/transport/30_exim4-config_remote_smtp_smarthost b/exim4/conf.d/transport/30_exim4-config_remote_smtp_smarthost
index 8c6b757b..9db9c783 100644
--- a/exim4/conf.d/transport/30_exim4-config_remote_smtp_smarthost
+++ b/exim4/conf.d/transport/30_exim4-config_remote_smtp_smarthost
@@ -28,6 +28,12 @@ remote_smtp_smarthost:
.ifdef REMOTE_SMTP_SMARTHOST_HOSTS_REQUIRE_TLS
hosts_require_tls = REMOTE_SMTP_SMARTHOST_HOSTS_REQUIRE_TLS
.endif
+.ifdef REMOTE_SMTP_SMARTHOST_TLS_VERIFY_CERTIFICATES
+ tls_verify_certificates = REMOTE_SMTP_SMARTHOST_TLS_VERIFY_CERTIFICATES
+.endif
+.ifdef REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS
+ tls_verify_hosts = REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS
+.endif
.ifdef REMOTE_SMTP_HEADERS_REWRITE
headers_rewrite = REMOTE_SMTP_HEADERS_REWRITE
.endif
@@ -46,3 +52,6 @@ tls_certificate = REMOTE_SMTP_SMARTHOST_TLS_CERTIFICATE
.ifdef REMOTE_SMTP_SMARTHOST_PRIVATEKEY
tls_privatekey = REMOTE_SMTP_SMARTHOST_PRIVATEKEY
.endif
+.ifdef REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
+ headers_remove = REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
+.endif
diff --git a/exim4/exim4.conf.template b/exim4/exim4.conf.template
index 7ddb5293..39006b29 100644
--- a/exim4/exim4.conf.template
+++ b/exim4/exim4.conf.template
@@ -136,7 +136,7 @@ message_size_limit = MESSAGE_SIZE_LIMIT
# scanners. The second modification is in the acl_check_data access
# control list.
-# av_scanner = clamd:/var/run/clamav/clamd.ctl
+# av_scanner = clamd:/run/clamav/clamd.ctl
# For spam scanning, there is a similar option that defines the interface to
@@ -203,7 +203,11 @@ primary_hostname = MAIN_HARDCODE_PRIMARY_HOSTNAME
# Enable an efficiency feature. We advertise the feature; clients
# may request to use it. For multi-recipient mails we then can
# reject or accept per-user after the message is received.
-#
+# This supports recipient-dependent content filtering; without it
+# you have to temp-reject any recipients after the first that have
+# incompatible filtering, and do the filtering in the data ACL.
+# Even with this enabled, you must support the old style for peers
+# not flagging support for PRDR (visible via $prdr_requested).
prdr_enable = true
# When using an external relay tester (such as rt.njabl.org and/or the
@@ -310,6 +314,13 @@ keep_environment =
.ifdef MAIN_ADD_ENVIRONMENT
add_environment = MAIN_ADD_ENVIRONMENT
.endif
+
+.ifdef _OPT_MAIN_SMTPUTF8_ADVERTISE_HOSTS
+.ifndef MAIN_SMTPUTF8_ADVERTISE_HOSTS
+MAIN_SMTPUTF8_ADVERTISE_HOSTS =
+.endif
+smtputf8_advertise_hosts = MAIN_SMTPUTF8_ADVERTISE_HOSTS
+.endif
#####################################################
### end main/02_exim4-config_options
#####################################################
@@ -393,13 +404,8 @@ tls_verify_hosts = MAIN_TLS_VERIFY_HOSTS
tls_try_verify_hosts = MAIN_TLS_TRY_VERIFY_HOSTS
.endif
-.ifdef _HAVE_GNUTLS
-tls_dhparam = historic
-.endif
-
.else
-# Don't advertise TLS if MAIN_TLS_ENABLE is not set.
-tls_advertise_hosts =
+# Use upstream defaults
.endif
#####################################################
### end main/03_exim4-config_tlsoptions
@@ -641,9 +647,9 @@ acl_check_rcpt:
# to the smarthost.
.ifdef CHECK_RCPT_VERIFY_SENDER
deny
- message = Sender verification failed
!acl = acl_local_deny_exceptions
!verify = sender
+ message = Sender verification failed
.endif
# Verify senders listed in local_sender_callout with a callout.
@@ -658,6 +664,21 @@ acl_check_rcpt:
{}}
!verify = sender/callout
+ .ifndef CHECK_RCPT_NO_FAIL_TOO_MANY_BAD_RCPT
+ # Reject all RCPT commands after too many bad recipients
+ # This is partly a defense against spam abuse and partly attacker abuse.
+ # Real senders should manage, by the time they get to 10 RCPT directives,
+ # to have had at least half of them be real addresses.
+ #
+ # This is a lightweight check and can protect you against repeated
+ # invocations of more heavy-weight checks which would come after it.
+
+ deny condition = ${if and {\
+ {>{$rcpt_count}{10}}\
+ {<{$recipients_count}{${eval:$rcpt_count/2}}} }}
+ message = Rejected for too many bad recipients
+ logwrite = REJECT [$sender_host_address]: bad recipient count high [${eval:$rcpt_count-$recipients_count}]
+ .endif
# Accept if the message comes from one of the hosts for which we are an
# outgoing relay. It is assumed that such hosts are most likely to be MUAs,
@@ -694,8 +715,9 @@ acl_check_rcpt:
# Insist that a HELO/EHLO was accepted.
- require message = nice hosts say HELO first
- condition = ${if def:sender_helo_name}
+ require
+ condition = ${if def:sender_helo_name}
+ message = nice hosts say HELO first
# Insist that any other recipient address that we accept is either in one of
# our local domains, or is in a domain for which we explicitly allow
@@ -733,12 +755,12 @@ acl_check_rcpt:
# The explicit white lists are honored as well as negative items in
# the black list. See exim4-config_files(5) for details.
deny
- message = sender envelope address $sender_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
- log_message = sender envelope address is locally blacklisted.
!acl = acl_local_deny_exceptions
senders = ${if exists{CONFDIR/local_sender_blacklist}\
{CONFDIR/local_sender_blacklist}\
{}}
+ message = sender envelope address $sender_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
+ log_message = sender envelope address is locally blacklisted.
# deny bad sites (IP address)
@@ -750,12 +772,12 @@ acl_check_rcpt:
# The explicit white lists are honored as well as negative items in
# the black list. See exim4-config_files(5) for details.
deny
- message = sender IP address $sender_host_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
- log_message = sender IP address is locally blacklisted.
!acl = acl_local_deny_exceptions
hosts = ${if exists{CONFDIR/local_host_blacklist}\
{CONFDIR/local_host_blacklist}\
{}}
+ message = sender IP address $sender_host_address is locally blacklisted here. If you think this is wrong, get in touch with postmaster
+ log_message = sender IP address is locally blacklisted.
# Warn if the sender host does not have valid reverse DNS.
@@ -774,8 +796,7 @@ acl_check_rcpt:
.endif
- # Use spfquery to perform a pair of SPF checks (for details, see
- # http://www.openspf.org/)
+ # Use spfquery to perform a pair of SPF checks.
#
# This is quite costly in terms of DNS lookups (~6 lookups per mail). Do not
# enable if that's an issue. Also note that if you enable this, you must
@@ -784,13 +805,6 @@ acl_check_rcpt:
# SPF check" warning.
.ifdef CHECK_RCPT_SPF
deny
- message = [SPF] $sender_host_address is not allowed to send mail from \
- ${if def:sender_address_domain {$sender_address_domain}{$sender_helo_name}}. \
- Please see \
- http://www.openspf.org/Why?scope=${if def:sender_address_domain \
- {mfrom}{helo}};identity=${if def:sender_address_domain \
- {$sender_address}{$sender_helo_name}};ip=$sender_host_address
- log_message = SPF check failed.
!acl = acl_local_deny_exceptions
condition = ${run{/usr/bin/spfquery.mail-spf-perl --ip \
${quote:$sender_host_address} --identity \
@@ -798,11 +812,14 @@ acl_check_rcpt:
{--scope mfrom --identity ${quote:$sender_address}}\
{--scope helo --identity ${quote:$sender_helo_name}}}}\
{no}{${if eq {$runrc}{1}{yes}{no}}}}
+ message = [SPF] $sender_host_address is not allowed to send mail from \
+ ${if def:sender_address_domain {$sender_address_domain}{$sender_helo_name}}.
+ log_message = SPF check failed.
defer
- message = Temporary DNS error while checking SPF record. Try again later.
!acl = acl_local_deny_exceptions
condition = ${if eq {$runrc}{5}{yes}{no}}
+ message = Temporary DNS error while checking SPF record. Try again later.
warn
condition = ${if <={$runrc}{6}{yes}{no}}
@@ -817,8 +834,8 @@ acl_check_rcpt:
helo=$sender_helo_name
warn
- log_message = Unexpected error in SPF check.
condition = ${if >{$runrc}{6}{yes}{no}}
+ log_message = Unexpected error in SPF check.
.endif
@@ -904,9 +921,10 @@ acl_check_data:
# we should never receive one such via SMTP.
#
.ifndef IGNORE_SMTP_LINE_LENGTH_LIMIT
- deny message = maximum allowed line length is 998 octets, \
+ deny
+ condition = ${if > {$max_received_linelength}{998}}
+ message = maximum allowed line length is 998 octets, \
got $max_received_linelength
- condition = ${if > {$max_received_linelength}{998}}
.endif
# Deny if the headers contain badly-formed addresses.
@@ -924,9 +942,9 @@ acl_check_data:
# one of the "Sender:", "Reply-To:", or "From:" header lines.
.ifdef CHECK_DATA_VERIFY_HEADER_SENDER
deny
- message = No verifiable sender address in message headers
!acl = acl_local_deny_exceptions
!verify = header_sender
+ message = No verifiable sender address in message headers
.endif
@@ -969,9 +987,9 @@ acl_check_data:
# Reject spam messages (score >15.0).
# This breaks mailing list and forward messages.
# deny
- # message = Classified as spam (score $spam_score)
# condition = ${if <{$message_size}{120k}{1}{0}}
# condition = ${if >{$spam_score_int}{150}{true}{false}}
+ # message = Classified as spam (score $spam_score)
# This hook allows you to hook in your own ACLs without having to
@@ -1077,9 +1095,13 @@ dnslookup_relay_to_domains:
domains = ! +local_domains : +relay_to_domains
transport = remote_smtp
same_domain_copy_routing = yes
- dnssec_request_domains = *
no_more
+# ignore private rfc1918, loopback, APIPA/link-local, local broadcast, unspecified, unique local, linked-scoped unicast and discard-Only
+.ifndef ROUTER_DNSLOOKUP_IGNORE_TARGET_HOSTS
+ROUTER_DNSLOOKUP_IGNORE_TARGET_HOSTS = <; 0.0.0.0 ; 127.0.0.0/8 ; 192.168.0.0/16 ; 172.16.0.0/12 ; 10.0.0.0/8 ; 169.254.0.0/16 ; 255.255.255.255 ; ::/128 ; ::1/128 ; fc00::/7 ; fe80::/10 ; 100::/64
+.endif
+
# deliver mail directly to the recipient. This router is only reached
# for domains that we do not relay for. Since we most probably can't
# have broken MX records pointing to site local or link local IP
@@ -1091,11 +1113,7 @@ dnslookup:
domains = ! +local_domains
transport = remote_smtp
same_domain_copy_routing = yes
- # ignore private rfc1918 and APIPA addresses
- ignore_target_hosts = 0.0.0.0 : 127.0.0.0/8 : 192.168.0.0/16 :\
- 172.16.0.0/12 : 10.0.0.0/8 : 169.254.0.0/16 :\
- 255.255.255.255
- dnssec_request_domains = *
+ ignore_target_hosts = ROUTER_DNSLOOKUP_IGNORE_TARGET_HOSTS
no_more
.endif
@@ -1296,7 +1314,7 @@ userforward:
domains = +local_domains
check_local_user
file = $home/.forward
- require_files = $local_part:$home/.forward
+ require_files = $local_part_data:$home/.forward
no_verify
no_expn
check_ancestor
@@ -1334,7 +1352,7 @@ procmail:
check_local_user
transport = procmail_pipe
# emulate OR with "if exists"-expansion
- require_files = ${local_part}:\
+ require_files = ${local_part_data}:\
${if exists{/etc/procmailrc}\
{/etc/procmailrc}{${home}/.procmailrc}}:\
+/usr/bin/procmail
@@ -1357,7 +1375,7 @@ maildrop:
domains = +local_domains
check_local_user
transport = maildrop_pipe
- require_files = ${local_part}:${home}/.mailfilter:+/usr/bin/maildrop
+ require_files = ${local_part_data}:${home}/.mailfilter:+/usr/bin/maildrop
no_verify
no_expn
@@ -1481,6 +1499,10 @@ REMOTE_SMTP_HELO_DATA==${lookup dnsdb {ptr=$sending_ip_address}{$value}{$primary
REMOTE_SMTP_HELO_DATA=${lookup dnsdb {ptr=$sending_ip_address}{$value}{$primary_hostname}}
.endif
.endif
+
+.ifndef REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS
+ REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS = *
+.endif
#####################################################
### end transport/10_exim4-config_transport-macros
#####################################################
@@ -1543,7 +1565,7 @@ address_reply:
mail_spool:
debug_print = "T: appendfile for $local_part@$domain"
driver = appendfile
- file = /var/mail/$local_part
+ file = /var/mail/$local_part_data
delivery_date_add
envelope_to_add
return_path_add
@@ -1664,6 +1686,9 @@ remote_smtp:
.ifdef REMOTE_SMTP_HELO_DATA
helo_data=REMOTE_SMTP_HELO_DATA
.endif
+.ifdef REMOTE_SMTP_INTERFACE
+ interface = REMOTE_SMTP_INTERFACE
+.endif
.ifdef DKIM_DOMAIN
dkim_domain = DKIM_DOMAIN
.endif
@@ -1682,6 +1707,9 @@ dkim_strict = DKIM_STRICT
.ifdef DKIM_SIGN_HEADERS
dkim_sign_headers = DKIM_SIGN_HEADERS
.endif
+.ifdef DKIM_TIMESTAMPS
+dkim_timestamps = DKIM_TIMESTAMPS
+.endif
.ifdef TLS_DH_MIN_BITS
tls_dh_min_bits = TLS_DH_MIN_BITS
.endif
@@ -1691,9 +1719,11 @@ tls_certificate = REMOTE_SMTP_TLS_CERTIFICATE
.ifdef REMOTE_SMTP_PRIVATEKEY
tls_privatekey = REMOTE_SMTP_PRIVATEKEY
.endif
-.ifndef REMOTE_SMTP_DISABLE_DANE
-dnssec_request_domains = *
-hosts_try_dane = *
+.ifdef REMOTE_SMTP_HOSTS_REQUIRE_TLS
+ hosts_require_tls = REMOTE_SMTP_HOSTS_REQUIRE_TLS
+.endif
+.ifdef REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
+ headers_remove = REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
.endif
#####################################################
### end transport/30_exim4-config_remote_smtp
@@ -1731,6 +1761,12 @@ remote_smtp_smarthost:
.ifdef REMOTE_SMTP_SMARTHOST_HOSTS_REQUIRE_TLS
hosts_require_tls = REMOTE_SMTP_SMARTHOST_HOSTS_REQUIRE_TLS
.endif
+.ifdef REMOTE_SMTP_SMARTHOST_TLS_VERIFY_CERTIFICATES
+ tls_verify_certificates = REMOTE_SMTP_SMARTHOST_TLS_VERIFY_CERTIFICATES
+.endif
+.ifdef REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS
+ tls_verify_hosts = REMOTE_SMTP_SMARTHOST_TLS_VERIFY_HOSTS
+.endif
.ifdef REMOTE_SMTP_HEADERS_REWRITE
headers_rewrite = REMOTE_SMTP_HEADERS_REWRITE
.endif
@@ -1749,6 +1785,9 @@ tls_certificate = REMOTE_SMTP_SMARTHOST_TLS_CERTIFICATE
.ifdef REMOTE_SMTP_SMARTHOST_PRIVATEKEY
tls_privatekey = REMOTE_SMTP_SMARTHOST_PRIVATEKEY
.endif
+.ifdef REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
+ headers_remove = REMOTE_SMTP_TRANSPORTS_HEADERS_REMOVE
+.endif
#####################################################
### end transport/30_exim4-config_remote_smtp_smarthost
#####################################################
@@ -2004,13 +2043,13 @@ begin authenticators
# This is now the (working!) example from
# http://www.exim.org/eximwiki/FAQ/Policy_controls/Q0730
-# Possible pitfall: access rights on /var/run/courier/authdaemon/socket.
+# Possible pitfall: access rights on /run/courier/authdaemon/socket.
# plain_courier_authdaemon:
# driver = plaintext
# public_name = PLAIN
# server_condition = \
# ${extract {ADDRESS} \
-# {${readsocket{/var/run/courier/authdaemon/socket} \
+# {${readsocket{/run/courier/authdaemon/socket} \
# {AUTH ${strlen:exim\nlogin\n$auth2\n$auth3\n}\nexim\nlogin\n$auth2\n$auth3\n} }} \
# {yes} \
# fail}
@@ -2025,7 +2064,7 @@ begin authenticators
# server_prompts = Username:: : Password::
# server_condition = \
# ${extract {ADDRESS} \
-# {${readsocket{/var/run/courier/authdaemon/socket} \
+# {${readsocket{/run/courier/authdaemon/socket} \
# {AUTH ${strlen:exim\nlogin\n$auth1\n$auth2\n}\nexim\nlogin\n$auth1\n$auth2\n} }} \
# {yes} \
# fail}
diff --git a/fonts/conf.avail/30-droid-noto.conf b/fonts/conf.avail/30-droid-noto.conf
new file mode 100644
index 00000000..04703bed
--- /dev/null
+++ b/fonts/conf.avail/30-droid-noto.conf
@@ -0,0 +1,16 @@
+
+
+
+
+ Droid Sans
+
+ Noto Sans
+
+
+
+ Droid Serif
+
+ Noto Serif
+
+
+
diff --git a/fonts/conf.avail/57-dejavu-sans-mono.conf b/fonts/conf.avail/57-dejavu-sans-mono.conf
index cc42561e..2c75b5cf 100644
--- a/fonts/conf.avail/57-dejavu-sans-mono.conf
+++ b/fonts/conf.avail/57-dejavu-sans-mono.conf
@@ -45,18 +45,4 @@
DejaVu Sans Mono
-
-
- DejaVu Sans Mono
-
- monospace
-
-
-
-
- monospace
-
- DejaVu Sans Mono
-
-
diff --git a/fonts/conf.avail/57-dejavu-sans.conf b/fonts/conf.avail/57-dejavu-sans.conf
index 565cab5f..cff7a842 100644
--- a/fonts/conf.avail/57-dejavu-sans.conf
+++ b/fonts/conf.avail/57-dejavu-sans.conf
@@ -70,18 +70,4 @@
DejaVu Sans
-
-
- DejaVu Sans
-
- sans-serif
-
-
-
-
- sans-serif
-
- DejaVu Sans
-
-
diff --git a/fonts/conf.avail/57-dejavu-serif.conf b/fonts/conf.avail/57-dejavu-serif.conf
index a922e9b2..10ae70fd 100644
--- a/fonts/conf.avail/57-dejavu-serif.conf
+++ b/fonts/conf.avail/57-dejavu-serif.conf
@@ -52,18 +52,4 @@
DejaVu Serif
-
-
- DejaVu Serif
-
- serif
-
-
-
-
- serif
-
- DejaVu Serif
-
-
diff --git a/fonts/conf.d/61-urw-bookman.conf b/fonts/conf.d/61-urw-bookman.conf
new file mode 120000
index 00000000..b69766f3
--- /dev/null
+++ b/fonts/conf.d/61-urw-bookman.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-bookman.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-c059.conf b/fonts/conf.d/61-urw-c059.conf
new file mode 120000
index 00000000..b04adf45
--- /dev/null
+++ b/fonts/conf.d/61-urw-c059.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-c059.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-d050000l.conf b/fonts/conf.d/61-urw-d050000l.conf
new file mode 120000
index 00000000..9354e6e1
--- /dev/null
+++ b/fonts/conf.d/61-urw-d050000l.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-d050000l.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-fallback-backwards.conf b/fonts/conf.d/61-urw-fallback-backwards.conf
new file mode 120000
index 00000000..0620e3c8
--- /dev/null
+++ b/fonts/conf.d/61-urw-fallback-backwards.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-fallback-backwards.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-fallback-generics.conf b/fonts/conf.d/61-urw-fallback-generics.conf
new file mode 120000
index 00000000..f5eb2125
--- /dev/null
+++ b/fonts/conf.d/61-urw-fallback-generics.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-fallback-generics.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-gothic.conf b/fonts/conf.d/61-urw-gothic.conf
new file mode 120000
index 00000000..5ca7b683
--- /dev/null
+++ b/fonts/conf.d/61-urw-gothic.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-gothic.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-nimbus-mono-ps.conf b/fonts/conf.d/61-urw-nimbus-mono-ps.conf
new file mode 120000
index 00000000..507c5da8
--- /dev/null
+++ b/fonts/conf.d/61-urw-nimbus-mono-ps.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-nimbus-mono-ps.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-nimbus-roman.conf b/fonts/conf.d/61-urw-nimbus-roman.conf
new file mode 120000
index 00000000..d41b7a1a
--- /dev/null
+++ b/fonts/conf.d/61-urw-nimbus-roman.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-nimbus-roman.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-nimbus-sans.conf b/fonts/conf.d/61-urw-nimbus-sans.conf
new file mode 120000
index 00000000..b091be27
--- /dev/null
+++ b/fonts/conf.d/61-urw-nimbus-sans.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-nimbus-sans.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-p052.conf b/fonts/conf.d/61-urw-p052.conf
new file mode 120000
index 00000000..ae0c8528
--- /dev/null
+++ b/fonts/conf.d/61-urw-p052.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-p052.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-standard-symbols-ps.conf b/fonts/conf.d/61-urw-standard-symbols-ps.conf
new file mode 120000
index 00000000..923d4497
--- /dev/null
+++ b/fonts/conf.d/61-urw-standard-symbols-ps.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-standard-symbols-ps.conf
\ No newline at end of file
diff --git a/fonts/conf.d/61-urw-z003.conf b/fonts/conf.d/61-urw-z003.conf
new file mode 120000
index 00000000..2f24680c
--- /dev/null
+++ b/fonts/conf.d/61-urw-z003.conf
@@ -0,0 +1 @@
+/usr/share/fontconfig/conf.avail/urw-z003.conf
\ No newline at end of file
diff --git a/fonts/fonts.conf b/fonts/fonts.conf
index e908e5a0..f0f908e0 100644
--- a/fonts/fonts.conf
+++ b/fonts/fonts.conf
@@ -29,7 +29,7 @@
/usr/share/fonts
- /usr/X11R6/lib/X11/fonts /usr/local/share/fonts
+ /usr/local/share/fonts
fonts
~/.fonts
diff --git a/group.org b/group.org
new file mode 100644
index 00000000..3bc7fd4c
--- /dev/null
+++ b/group.org
@@ -0,0 +1,71 @@
+root:x:0:
+daemon:x:1:
+bin:x:2:
+sys:x:3:
+adm:x:4:pi
+tty:x:5:iobroker
+disk:x:6:
+lp:x:7:
+mail:x:8:
+news:x:9:
+uucp:x:10:
+man:x:12:
+proxy:x:13:
+kmem:x:15:
+dialout:x:20:pi,iobroker
+fax:x:21:
+voice:x:22:
+cdrom:x:24:pi
+floppy:x:25:
+tape:x:26:
+sudo:x:27:pi
+audio:x:29:pi,iobroker
+dip:x:30:
+www-data:x:33:
+backup:x:34:
+operator:x:37:
+list:x:38:
+irc:x:39:
+src:x:40:
+gnats:x:41:
+shadow:x:42:
+utmp:x:43:
+video:x:44:pi,iobroker
+sasl:x:45:
+plugdev:x:46:pi
+staff:x:50:
+games:x:60:pi
+users:x:100:pi
+nogroup:x:65534:
+systemd-journal:x:101:
+systemd-timesync:x:102:
+systemd-network:x:103:
+systemd-resolve:x:104:
+input:x:105:pi
+kvm:x:106:
+render:x:107:
+crontab:x:108:
+netdev:x:109:pi
+pi:x:1000:
+messagebus:x:110:
+ssh:x:111:
+bluetooth:x:112:iobroker
+avahi:x:113:
+spi:x:999:pi
+i2c:x:998:pi,iobroker
+gpio:x:997:pi,iobroker
+systemd-coredump:x:996:
+redis:x:114:iobroker
+mosquitto:x:116:
+Debian-snmp:x:117:
+plex:x:994:
+git:x:118:
+ssl-cert:x:119:postgres
+postgres:x:120:
+puppet:x:121:
+ntp:x:122:
+tftp:x:123:
+Debian-exim:x:124:
+iobroker:x:1001:
+ghost:x:993:
+docker:x:995:
diff --git a/init.d/alsa-utils b/init.d/alsa-utils
index e6a6e921..f1174e53 100755
--- a/init.d/alsa-utils
+++ b/init.d/alsa-utils
@@ -62,13 +62,13 @@ restore_levels()
# then it failed somehow. This works around the fact
# that alsactl doesn't return nonzero status when it
# can't restore settings for the card
- if MSG="$(alsactl -E HOME="$ALSACTLHOME" restore $CARD 2>&1 >/dev/null)" && [ ! "$MSG" ] ; then
+ if MSG="$(alsactl -E HOME="$ALSACTLHOME" -E XDG_RUNTIME_DIR="${ALSACTLRUNTIME}" restore $CARD 2>&1 >/dev/null)" && [ ! "$MSG" ] ; then
return 0
else
# Retry with the "force" option. This restores more levels
# but it results in much longer error messages.
- alsactl -F restore $CARD >/dev/null 2>&1
- log_action_cont_msg "warning: 'alsactl -E HOME="$ALSACTLHOME" restore${CARD:+ $CARD}' failed with error message '$MSG'"
+ alsactl -E HOME="$ALSACTLHOME" -E XDG_RUNTIME_DIR="${ALSACTLRUNTIME}" -F restore $CARD >/dev/null 2>&1
+ log_action_cont_msg "warning: 'alsactl -E HOME="$ALSACTLHOME" -E XDG_RUNTIME_DIR="${ALSACTLRUNTIME}" restore${CARD:+ $CARD}' failed with error message '$MSG'"
return 1
fi
}
@@ -78,11 +78,11 @@ store_levels()
{
CARD="$1"
[ "$1" = all ] && CARD=""
- if MSG="$(alsactl -E HOME="$ALSACTLHOME" store $CARD 2>&1)" ; then
+ if MSG="$(alsactl -E HOME="$ALSACTLHOME" -E XDG_RUNTIME_DIR="${ALSACTLRUNTIME}" store $CARD 2>&1)" ; then
sleep 1
return 0
else
- log_action_cont_msg "warning: 'alsactl store${CARD:+ $CARD}' failed with error message '$MSG'"
+ log_action_cont_msg "warning: 'alsactl store${CARD:+ $CARD}' -E HOME="$ALSACTLHOME" -E XDG_RUNTIME_DIR=@alsactlruntime@ failed with error message '$MSG'"
return 1
fi
}
diff --git a/init.d/dbus b/init.d/dbus
index 4f41293f..105c83b8 100755
--- a/init.d/dbus
+++ b/init.d/dbus
@@ -67,6 +67,13 @@ start_it_up()
create_machineid
+ # Force libnss-systemd to avoid trying to communicate via D-Bus, which
+ # is never going to work well from within dbus-daemon. systemd
+ # special-cases this internally, but we might need to do the same when
+ # booting with sysvinit if libnss-systemd is still installed.
+ # (Workaround for #940971)
+ export SYSTEMD_NSS_BYPASS_BUS=1
+
log_daemon_msg "Starting $DESC" "$NAME"
start-stop-daemon --start --quiet --pidfile $PIDFILE \
--exec $DAEMON -- --system $PARAMS
diff --git a/init.d/dhcpcd b/init.d/dhcpcd
index f0b24ac9..48797975 100755
--- a/init.d/dhcpcd
+++ b/init.d/dhcpcd
@@ -13,7 +13,7 @@
### END INIT INFO
PATH=/sbin:/bin:/usr/sbin:/usr/bin
-DHCPCD=/sbin/dhcpcd
+DHCPCD=/usr/sbin/dhcpcd
NAME=dhcpcd
PIDFILE=/var/run/dhcpcd.pid
diff --git a/init.d/exim4 b/init.d/exim4
index 61f2affe..815ce831 100755
--- a/init.d/exim4
+++ b/init.d/exim4
@@ -95,13 +95,13 @@ start_exim()
separate)
start_daemon -p "$PIDFILE" \
"$DAEMON" -bd \
- ${COMMONOPTIONS} \
+ ${COMMONOPTIONS} -oY \
${SMTPLISTENEROPTIONS}
log_progress_msg "exim4_listener"
start_daemon -p "$QRPIDFILE" \
"$DAEMON" -oP $QRPIDFILE \
"-q${QFLAGS}${QUEUEINTERVAL}" \
- ${COMMONOPTIONS} \
+ ${COMMONOPTIONS} -oY \
${QUEUERUNNEROPTIONS}
log_progress_msg "exim4_queuerunner"
;;
diff --git a/init.d/hwclock.sh b/init.d/hwclock.sh
index 208ca2d5..a9872b64 100755
--- a/init.d/hwclock.sh
+++ b/init.d/hwclock.sh
@@ -1,43 +1,27 @@
#!/bin/sh
-# hwclock.sh Set and adjust the CMOS clock.
-#
-# Version: @(#)hwclock.sh 2.00 14-Dec-1998 miquels@cistron.nl
-#
-# Patches:
-# 2000-01-30 Henrique M. Holschuh
-# - Minor cosmetic changes in an attempt to help new
-# users notice something IS changing their clocks
-# during startup/shutdown.
-# - Added comments to alert users of hwclock issues
-# and discourage tampering without proper doc reading.
-# 2012-02-16 Roger Leigh
-# - Use the UTC/LOCAL setting in /etc/adjtime rather than
-# the UTC setting in /etc/default/rcS. Additionally
-# source /etc/default/hwclock to permit configuration.
### BEGIN INIT INFO
# Provides: hwclock
-# Required-Start: mountdevsubfs
+# Required-Start:
# Required-Stop: mountdevsubfs
# Should-Stop: umountfs
# Default-Start: S
-# X-Start-Before: checkroot
# Default-Stop: 0 6
-# Short-Description: Sync hardware and system clock time.
+# Short-Description: Save system clock to hardware on shutdown.
### END INIT INFO
-# These defaults are user-overridable in /etc/default/hwclock
-BADYEAR=no
-HWCLOCKACCESS=yes
-HWCLOCKPARS=
-HCTOSYS_DEVICE=rtc0
+# Note: this init script and related code is only useful if you
+# run a sysvinit system, without NTP synchronization.
+
+if [ -e /run/systemd/system ] ; then
+ exit 0
+fi
-# We only want to use the system timezone or else we'll get
-# potential inconsistency at startup.
unset TZ
hwclocksh()
{
+ HCTOSYS_DEVICE=rtc0
[ ! -x /sbin/hwclock ] && return 0
[ ! -r /etc/default/rcS ] || . /etc/default/rcS
[ ! -r /etc/default/hwclock ] || . /etc/default/hwclock
@@ -45,75 +29,28 @@ hwclocksh()
. /lib/lsb/init-functions
verbose_log_action_msg() { [ "$VERBOSE" = no ] || log_action_msg "$@"; }
- case "$BADYEAR" in
- no|"") BADYEAR="" ;;
- yes) BADYEAR="--badyear" ;;
- *) log_action_msg "unknown BADYEAR setting: \"$BADYEAR\""; return 1 ;;
- esac
-
case "$1" in
- start)
- # If the admin deleted the hwclock config, create a blank
- # template with the defaults.
- if [ -w /etc ] && [ ! -f /etc/adjtime ] && [ ! -e /etc/adjtime ]; then
- printf "0.0 0 0.0\n0\nUTC\n" > /etc/adjtime
- fi
-
- if [ -d /run/udev ] || [ -d /dev/.udev ]; then
- return 0
- fi
-
- if [ "$HWCLOCKACCESS" != no ]; then
- log_action_msg "Setting the system clock"
-
- # Just for reporting.
- if sed '3!d' /etc/adjtime | grep -q '^UTC$'; then
- UTC="--utc"
- else
- UTC=
- fi
- # Copies Hardware Clock time to System Clock using the correct
- # timezone for hardware clocks in local time, and sets kernel
- # timezone. DO NOT REMOVE.
- if /sbin/hwclock --rtc=/dev/$HCTOSYS_DEVICE --hctosys $HWCLOCKPARS $BADYEAR; then
- # Announce the local time.
- verbose_log_action_msg "System Clock set to: `date $UTC`"
- else
- log_warning_msg "Unable to set System Clock to: `date $UTC`"
- fi
- else
- verbose_log_action_msg "Not setting System Clock"
- fi
- ;;
- stop|restart|reload|force-reload)
- #
- # Updates the Hardware Clock with the System Clock time.
- # This will *override* any changes made to the Hardware Clock.
- #
- # WARNING: If you disable this, any changes to the system
- # clock will not be carried across reboots.
- #
-
- if [ "$HWCLOCKACCESS" != no ]; then
- log_action_msg "Saving the system clock"
- if /sbin/hwclock --rtc=/dev/$HCTOSYS_DEVICE --systohc $HWCLOCKPARS $BADYEAR; then
- verbose_log_action_msg "Hardware Clock updated to `date`"
- fi
- else
- verbose_log_action_msg "Not saving System Clock"
- fi
- ;;
- show)
- if [ "$HWCLOCKACCESS" != no ]; then
- /sbin/hwclock --rtc=/dev/$HCTOSYS_DEVICE --show $HWCLOCKPARS $BADYEAR
- fi
- ;;
- *)
- log_success_msg "Usage: hwclock.sh {start|stop|reload|force-reload|show}"
- log_success_msg " start sets kernel (system) clock from hardware (RTC) clock"
- log_success_msg " stop and reload set hardware (RTC) clock from kernel (system) clock"
- return 1
- ;;
+ start)
+ # start is handled by /usr/lib/udev/rules.d/85-hwclock.rules.
+ return 0
+ ;;
+ stop|restart|reload|force-reload)
+ # Updates the Hardware Clock with the System Clock time.
+ # This will *override* any changes made to the Hardware Clock,
+ # for example by the Linux kernel when NTP is in use.
+ log_action_msg "Saving the system clock to /dev/$HCTOSYS_DEVICE"
+ if /sbin/hwclock --rtc=/dev/$HCTOSYS_DEVICE --systohc; then
+ verbose_log_action_msg "Hardware Clock updated to `date`"
+ fi
+ ;;
+ show)
+ /sbin/hwclock --rtc=/dev/$HCTOSYS_DEVICE --show
+ ;;
+ *)
+ log_success_msg "Usage: hwclock.sh {stop|reload|force-reload|show}"
+ log_success_msg " stop and reload set hardware (RTC) clock from kernel (system) clock"
+ return 1
+ ;;
esac
}
diff --git a/init.d/networking b/init.d/networking
index b5380511..a4cc3427 100755
--- a/init.d/networking
+++ b/init.d/networking
@@ -103,9 +103,9 @@ ifup_hotplug () {
then
ifaces=$(for iface in $(ifquery --list --allow=hotplug)
do
- link=${iface##:*}
- link=${link##.*}
- if [ -e "/sys/class/net/$link" ]
+ link=${iface%%:*}
+ link=${link%%.*}
+ if [ -e "/sys/class/net/$link" ] && ! ifquery --state "$iface" >/dev/null
then
echo "$iface"
fi
diff --git a/init.d/resolvconf b/init.d/resolvconf
index c478014a..51b88b4b 100755
--- a/init.d/resolvconf
+++ b/init.d/resolvconf
@@ -26,7 +26,7 @@
[ -x /sbin/resolvconf ] || exit 0
PATH=/sbin:/bin
-RUN_DIR=/etc/resolvconf/run
+RUN_DIR=/run/resolvconf
ENABLE_UPDATES_FLAGFILE="${RUN_DIR}/enable-updates"
POSTPONED_UPDATE_FLAGFILE="${RUN_DIR}/postponed-update"
@@ -54,16 +54,17 @@ create_runtime_directories()
{
umask 022
if [ ! -d "$RUN_DIR" ] ; then
- [ -L "$RUN_DIR" ] || log_action_end_msg_and_exit 1 "$RUN_DIR is neither a directory nor a symbolic link"
- # It's a symlink. Its target is not a dir.
- { RUN_CANONICALDIR="$(readlink -f "$RUN_DIR")" && [ "$RUN_CANONICALDIR" ] ; } || log_action_end_msg_and_exit 1 "Canonical path of the run directory could not be determined"
# Create directory at the target
- mkdir "$RUN_CANONICALDIR" || log_action_end_msg_and_exit 1 "Error creating directory $RUN_CANONICALDIR"
+ mkdir "$RUN_DIR" || log_action_end_msg_and_exit 1 "Error creating directory $RUN_DIR"
fi
+ [ -x /sbin/restorecon ] && /sbin/restorecon "$RUN_CANONICALDIR"
+
# The resolvconf run directory now exists.
if [ ! -d "${RUN_DIR}/interface" ] ; then
mkdir "${RUN_DIR}/interface" || log_action_end_msg_and_exit 1 "Error creating directory ${RUN_DIR}/interface"
fi
+ [ -x /sbin/restorecon ] && /sbin/restorecon "${RUN_DIR}/interface" "${RUN_DIR}/resolv.conf "${RUN_DIR}/enable-updates
+
# The interface directory now exists. We are done.
return
}
diff --git a/init.d/rng-tools b/init.d/rng-tools
deleted file mode 100755
index e66cc2ce..00000000
--- a/init.d/rng-tools
+++ /dev/null
@@ -1,96 +0,0 @@
-#! /bin/sh
-#
-# rng-tools initscript for the rng-tools package
-# Copr. 2003 by Henrique de Moraes Holschuh
-# Copr. 2002 by Viral Shah
-#
-### BEGIN INIT INFO
-# Provides: rng-tools
-# Required-Start: $remote_fs $syslog
-# Required-Stop: $remote_fs $syslog
-# Default-Start: 2 3 4 5
-# Default-Stop: 0 1 6
-### END INIT INFO
-#
-#
-# $Id: rng-tools.init,v 1.6.2.10 2008-06-10 19:51:37 hmh Exp $
-
-PATH=/sbin:/bin:/usr/sbin:/usr/bin
-DAEMON=/usr/sbin/rngd
-NAME=rngd
-DESC="Hardware RNG entropy gatherer daemon"
-PIDFILE=/var/run/rngd.pid
-
-DEVICELIST="hwrng hw_random hwrandom intel_rng i810_rng"
-
-HRNGDEVICE=/dev/hwrng
-RNGDOPTIONS=
-[ -r /etc/default/rng-tools ] && . /etc/default/rng-tools
-
-test -f ${DAEMON} || exit 0
-
-set -e
-
-finddevice () {
- [ -c "${HRNGDEVICE}" ] && return 0
- for i in ${DEVICELIST} ; do
- if [ -c "/dev/$i" ] ; then
- HRNGDEVICE="/dev/$i"
- return 0
- fi
- if [ -c "/dev/misc/$i" ] ; then
- HRNGDEVICE="/dev/misc/$i"
- return 0
- fi
- done
-
- echo "(Hardware RNG device inode not found)"
- echo "$0: Cannot find a hardware RNG device to use." >&2
- exit 1
-}
-
-START="--start --quiet --pidfile ${PIDFILE} --startas ${DAEMON} --name ${NAME}"
-case "$1" in
- start)
- echo -n "Starting $DESC: "
- finddevice
- START="${START} -- -r ${HRNGDEVICE} ${RNGDOPTIONS}"
- if start-stop-daemon ${START} >/dev/null 2>&1 ; then
- echo "${NAME}."
- else
- if start-stop-daemon --test ${START} >/dev/null 2>&1; then
- echo "(failed)."
- exit 1
- else
- echo "${DAEMON} already running."
- exit 0
- fi
- fi
- ;;
- stop)
- echo -n "Stopping $DESC: "
- if start-stop-daemon --stop --quiet --pidfile ${PIDFILE} \
- --startas ${DAEMON} --retry 10 --name ${NAME} \
- >/dev/null 2>&1 ; then
- echo "${NAME}."
- else
- if start-stop-daemon --test ${START} >/dev/null 2>&1; then
- echo "(not running)."
- exit 0
- else
- echo "(failed)."
- exit 1
- fi
- fi
- ;;
- restart|force-reload)
- $0 stop
- exec $0 start
- ;;
- *)
- echo "Usage: $0 {start|stop|restart|force-reload}" 1>&2
- exit 1
- ;;
-esac
-
-exit 0
diff --git a/init.d/rng-tools-debian b/init.d/rng-tools-debian
new file mode 100755
index 00000000..f29f1398
--- /dev/null
+++ b/init.d/rng-tools-debian
@@ -0,0 +1,175 @@
+#!/bin/sh
+### BEGIN INIT INFO
+# Provides: rng-tools-debian rng-tools
+# Required-Start: $remote_fs $syslog
+# Required-Stop: $remote_fs $syslog
+# Default-Start: 2 3 4 5
+# Default-Stop: 0 1 6
+# Short-Description: rng-tools (Debian variant)
+# Description: The rng-tools daemon bridges between a hardware
+# TRNG and the kernel PRNG, verifying input data.
+### END INIT INFO
+
+# absolute basics
+LC_ALL=C PATH=/sbin:/usr/sbin:/bin:/usr/bin
+export LC_ALL PATH
+unset LANGUAGE
+
+# exit cleanly if disabled or not installed
+test -x /usr/sbin/rngd || exit 0
+
+# Debian/LSB init script foobar
+DESC='Hardware RNG entropy gatherer daemon'
+NAME=rngd
+. /lib/init/vars.sh
+test -t 0 && VERBOSE=yes
+. /lib/lsb/init-functions
+
+# read options
+HRNGDEVICE=
+HRNGSELECT=
+RNGDOPTIONS=
+test -r /etc/default/rng-tools-debian && . /etc/default/rng-tools-debian
+
+finddevice() {
+ if test -n "$HRNGDEVICE" && test -c "$HRNGDEVICE"; then
+ # use it unseen
+ return 0
+ fi
+ # list of devices to try/auto-detect
+ for x in hwrng hw_random hwrandom intel_rng i810_rng; do
+ for y in /dev /dev/misc; do
+ test -c "$y/$x" || continue
+ if timeout -k 1s 5s \
+ dd if="$y/$x" bs=1 count=1 >/dev/null 2>&1; then
+ HRNGDEVICE=$y/$x
+ return 0
+ fi
+ logger -t rng-tools-debian \
+ "found $y/$x but could not use it"
+ done
+ done
+ return 1
+}
+
+# prepare for actions
+case $1 in
+(start|restart|try-restart|force-reload)
+ test -z "$HRNGSELECT" || printf '%s' "$HRNGSELECT" \
+ >/sys/devices/virtual/misc/hw_random/rng_current
+ if ! finddevice; then
+ logger -t rng-tools-debian \
+ "not starting: no hardware RNG device found"
+ log_daemon_msg "Configuring $DESC"
+ log_progress_msg "no hardware RNG device found!"
+ log_end_msg 1
+ test -e /run/rngd.installing || exit 0
+ # during postinst run, inform user more
+ cat <<-\EOF
+
+ !!! no hardware RNG device found !!!
+ rng-tools-debian will SILENTLY not start the daemon!
+
+ To fix this, edit /etc/default/rng-tools-debian to
+ set options suitable for your hardware random device;
+ possibly load some kernel module first, ideally from
+ initramfs (add to /etc/initramfs-tools/modules), so
+ it is available early enough during boot.
+
+ EOF
+ exit 0
+ fi
+ ;;
+(stop|status)
+ ;;
+(reload|*)
+ # not supported
+ echo >&2 "Usage: $0 {start|stop|restart|try-restart|force-reload|status}"
+ exit 3
+ ;;
+esac
+
+# take action
+rv=0
+case $1 in
+(status)
+ status_of_proc -p /var/run/rngd.pid /usr/sbin/rngd rngd
+ exit $?
+ ;;
+(start)
+ test x"$VERBOSE" = x"no" || log_daemon_msg "Starting $DESC"
+ if start-stop-daemon --start --quiet \
+ --pidfile /var/run/rngd.pid \
+ --startas /usr/sbin/rngd --name rngd \
+ --exec /usr/sbin/rngd --test; then
+ test x"$VERBOSE" = x"no" || log_progress_msg "rngd"
+ start-stop-daemon --start --quiet \
+ --pidfile /var/run/rngd.pid \
+ --startas /usr/sbin/rngd --name rngd \
+ --exec /usr/sbin/rngd -- -r $HRNGDEVICE $RNGDOPTIONS
+ rv=$?
+ else
+ test x"$VERBOSE" = x"no" || \
+ log_progress_msg "rngd already running"
+ fi
+ ;;
+(stop)
+ test x"$VERBOSE" = x"no" || log_daemon_msg "Stopping $DESC"
+ test x"$VERBOSE" = x"no" || log_progress_msg "rngd"
+ start-stop-daemon --stop --quiet --retry=10 \
+ --pidfile /var/run/rngd.pid \
+ --name rngd --exec /usr/sbin/rngd
+ rc=$?
+ if test $rc -gt 1; then
+ rv=$rc
+ else
+ start-stop-daemon --stop --quiet --oknodo \
+ --retry=0/30/KILL/5 --exec /usr/sbin/rngd
+ rc=$?
+ test $rc -gt 1 && test $rv -lt $rc && rv=$rc
+ fi
+ rm -f /var/run/rngd.pid
+ ;;
+(restart|force-reload)
+ test x"$VERBOSE" = x"no" || log_daemon_msg "Restarting $DESC"
+ test x"$VERBOSE" = x"no" || log_progress_msg "rngd"
+ start-stop-daemon --stop --quiet --retry=10 \
+ --pidfile /var/run/rngd.pid \
+ --name rngd --exec /usr/sbin/rngd
+ if test $? -lt 2; then
+ start-stop-daemon --stop --quiet --oknodo \
+ --retry=0/30/KILL/5 --exec /usr/sbin/rngd
+ fi
+ rm -f /var/run/rngd.pid
+ start-stop-daemon --start --quiet \
+ --pidfile /var/run/rngd.pid \
+ --startas /usr/sbin/rngd --name rngd \
+ --exec /usr/sbin/rngd -- -r $HRNGDEVICE $RNGDOPTIONS
+ rv=$?
+ ;;
+(try-restart)
+ test x"$VERBOSE" = x"no" || log_daemon_msg "Trying to restart $DESC"
+ if ! status_of_proc -p /var/run/rngd.pid \
+ /usr/sbin/rngd rngd >/dev/null 2>&1; then
+ test x"$VERBOSE" = x"no" || log_progress_msg "is not running."
+ test x"$VERBOSE" = x"no" || log_end_msg 1
+ exit 0
+ fi
+ test x"$VERBOSE" = x"no" || log_progress_msg "rngd"
+ start-stop-daemon --stop --quiet --retry=10 \
+ --pidfile /var/run/rngd.pid \
+ --name rngd --exec /usr/sbin/rngd
+ if test $? -lt 2; then
+ start-stop-daemon --stop --quiet --oknodo \
+ --retry=0/30/KILL/5 --exec /usr/sbin/rngd
+ fi
+ rm -f /var/run/rngd.pid
+ start-stop-daemon --start --quiet \
+ --pidfile /var/run/rngd.pid \
+ --startas /usr/sbin/rngd --name rngd \
+ --exec /usr/sbin/rngd -- -r $HRNGDEVICE $RNGDOPTIONS
+ rv=$?
+ ;;
+esac
+test x"$VERBOSE" = x"no" || log_end_msg $rv
+exit $rv
diff --git a/init.d/rpcbind b/init.d/rpcbind
index e36578ae..4f56d0f0 100755
--- a/init.d/rpcbind
+++ b/init.d/rpcbind
@@ -3,7 +3,7 @@
# start/stop rpcbind daemon.
### BEGIN INIT INFO
-# Provides: rpcbind
+# Provides: rpcbind portmap
# Required-Start: $network $local_fs
# Required-Stop: $network $local_fs
# Default-Start: S
@@ -39,7 +39,7 @@ start ()
chown _rpc:root $STATEDIR
chmod 0755 $STATEDIR
fi
- if [ "$(LC_ALL=C stat -c '%U %g %a %F' "$STATEDIR")" != "_rpc 0 755 directory" ] ; then
+ if [ `ls -dl "$STATEDIR" | grep -cE '^drwxr-xr-x [0-9]+ _rpc root '` -lt 1 ] ; then
log_begin_msg "$STATEDIR not owned by root"
log_end_msg 1
exit 1
@@ -48,7 +48,7 @@ start ()
pid=$( pidofproc /sbin/rpcbind )
if [ -n "$pid" ]
then
- log_action_msg "Already running: rcpbind"
+ log_action_msg "Already running: rpcbind"
exit 0
fi
log_daemon_msg "Starting RPC port mapper daemon" "rpcbind"
@@ -64,7 +64,7 @@ start ()
stop ()
{
log_daemon_msg "Stopping RPC port mapper daemon" "rpcbind"
- start-stop-daemon --stop --quiet --oknodo --exec /sbin/rpcbind
+ start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --oknodo --exec /sbin/rpcbind
rm -f "$PIDFILE"
log_end_msg $?
}
diff --git a/init.d/snmpd b/init.d/snmpd
index 8bc98561..d77e5871 100755
--- a/init.d/snmpd
+++ b/init.d/snmpd
@@ -20,18 +20,24 @@ DESC="SNMP Services"
DAEMON=/usr/sbin/snmpd
PIDFILE="/run/snmpd.pid"
-# Defaults
-OLD_MIBS_DIR="/usr/share/mibs/site:/usr/share/snmp/mibs:/usr/share/mibs/iana:/usr/share/mibs/ietf:/usr/share/mibs/netsnmp"
-MIBS_DIR="/usr/share/snmp/mibs:/usr/share/snmp/mibs/iana:/usr/share/snmp/mibs/ietf"
-export MIBDIRS="$MIBS_DIR:$OLD_MIBS_DIR"
+DEFAULT_SNMPDOPTS="-LSwd -Lf /dev/null -u Debian-snmp -g Debian-snmp -I -smux,mteTrigger,mteTriggerConf"
-DEFAULT_SNMPDOPTS="-Lsd -Lf /dev/null -u Debian-snmp -g Debian-snmp -I -smux,mteTrigger,mteTriggerConf"
-[ -z "$SNMPDOPTS" ] && SNMPDOPTS=$DEFAULT_SNMPDOPTS
+set_daemon_options()
+{
+ [ -z "$SNMPDOPTS" ] && SNMPDOPTS=$DEFAULT_SNMPDOPTS
+ DAEMON_ARGS="$SNMPDOPTS -p $PIDFILE"
-DAEMON_ARGS="$SNMPDOPTS -p $PIDFILE"
+}
+
+do_restart_prepare()
+{
+ set_daemon_options
+}
do_start_prepare()
{
+ set_daemon_options
+
# remove old symlink with previous version
if [ -L /var/run/agentx ]; then
rm -f /var/run/agentx
diff --git a/init.d/udev b/init.d/udev
index a10a586c..bb54f610 100755
--- a/init.d/udev
+++ b/init.d/udev
@@ -253,4 +253,3 @@ case "$1" in
esac
exit 0
-
diff --git a/init/resolvconf.conf b/init/resolvconf.conf
deleted file mode 100644
index 93460111..00000000
--- a/init/resolvconf.conf
+++ /dev/null
@@ -1,19 +0,0 @@
-# upstart script for resolvconf
-
-description "Initialize or finalize resolvconf"
-
-start on mounted MOUNTPOINT=/run
-
-stop on runlevel [06]
-
-pre-start script
- mkdir -p /run/resolvconf/interface
- # Request a postponed update (needed in case the base file has content).
- touch /run/resolvconf/postponed-update
- # Enable updates and perform the postponed update.
- resolvconf --enable-updates
-end script
-
-post-stop script
- resolvconf --disable-updates
-end script
diff --git a/initramfs-tools/initramfs.conf b/initramfs-tools/initramfs.conf
index dd76996c..01bdd853 100644
--- a/initramfs-tools/initramfs.conf
+++ b/initramfs-tools/initramfs.conf
@@ -38,15 +38,11 @@ BUSYBOX=auto
KEYMAP=n
#
-# COMPRESS: [ gzip | bzip2 | lz4 | lzma | lzop | xz ]
+# COMPRESS: [ gzip | bzip2 | lz4 | lzma | lzop | xz | zstd ]
#
COMPRESS=gzip
-#
-# NFS Section of the config.
-#
-
#
# DEVICE: ...
#
@@ -70,3 +66,12 @@ NFSROOT=auto
#
RUNSIZE=10%
+
+#
+# FSTYPE: ...
+#
+# The filesystem type(s) to support, or "auto" to use the current root
+# filesystem type
+#
+
+FSTYPE=auto
diff --git a/iproute2/rt_protos b/iproute2/rt_protos
index b3a0ec8f..7cafddc1 100644
--- a/iproute2/rt_protos
+++ b/iproute2/rt_protos
@@ -14,7 +14,8 @@
13 dnrouted
14 xorp
15 ntk
-16 dhcp
+16 dhcp
+18 keepalived
42 babel
186 bgp
187 isis
diff --git a/issue b/issue
index 0ecbda47..4a44e234 100644
--- a/issue
+++ b/issue
@@ -1,2 +1,2 @@
-Raspbian GNU/Linux 10 \n \l
+Raspbian GNU/Linux 11 \n \l
diff --git a/issue.net b/issue.net
index 588f12ac..97379988 100644
--- a/issue.net
+++ b/issue.net
@@ -1 +1 @@
-Raspbian GNU/Linux 10
+Raspbian GNU/Linux 11
diff --git a/kernel/postinst.d/apt-auto-removal b/kernel/postinst.d/apt-auto-removal
index 2c32b0c9..eef550a5 100755
--- a/kernel/postinst.d/apt-auto-removal
+++ b/kernel/postinst.d/apt-auto-removal
@@ -1,82 +1,15 @@
#!/bin/sh
set -e
-# Mark as not-for-autoremoval those kernel packages that are:
-# - the currently booted version
-# - the kernel version we've been called for
-# - the latest kernel version (as determined by debian version number)
-# - the second-latest kernel version
-#
-# In the common case this results in two kernels saved (booted into the
-# second-latest kernel, we install the latest kernel in an upgrade), but
-# can save up to four. Kernel refers here to a distinct release, which can
-# potentially be installed in multiple flavours counting as one kernel.
eval $(apt-config shell APT_CONF_D Dir::Etc::parts/d)
test -n "${APT_CONF_D}" || APT_CONF_D="/etc/apt/apt.conf.d"
config_file="${APT_CONF_D}/01autoremove-kernels"
-eval $(apt-config shell DPKG Dir::bin::dpkg/f)
-test -n "$DPKG" || DPKG="/usr/bin/dpkg"
-
-list="$("${DPKG}" -l | awk '/^[ih][^nc][ ]+(linux|kfreebsd|gnumach)-image-[0-9]+\./ && $2 !~ /-dbg(:.*)?$/ && $2 !~ /-dbgsym(:.*)?$/ { print $2,$3; }' \
- | sed -e 's#^\(linux\|kfreebsd\|gnumach\)-image-##' -e 's#:[^:]\+ # #')"
-debverlist="$(echo "$list" | cut -d' ' -f 2 | sort --unique --reverse --version-sort)"
-
-if [ -n "$1" ]; then
- installed_version="$(echo "$list" | awk "\$1 == \"$1\" { print \$2;exit; }")"
-fi
-unamer="$(uname -r | tr '[A-Z]' '[a-z]')"
-if [ -n "$unamer" ]; then
- running_version="$(echo "$list" | awk "\$1 == \"$unamer\" { print \$2;exit; }")"
-fi
-# ignore the currently running version if attempting a reproducible build
-if [ -n "${SOURCE_DATE_EPOCH}" ]; then
- unamer=""
- running_version=""
-fi
-latest_version="$(echo "$debverlist" | sed -n 1p)"
-previous_version="$(echo "$debverlist" | sed -n 2p)"
-
-debkernels="$(echo "$latest_version
-$installed_version
-$running_version
-$previous_version" | sort -u | sed -e '/^$/ d')"
-kernels="$( (echo "$1
-$unamer"; for deb in $debkernels; do echo "$list" | awk "\$2 == \"$deb\" { print \$1; }"; done; ) \
- | sed -e 's#\([\.\+]\)#\\\1#g' -e '/^$/ d' | sort -u)"
-
generateconfig() {
cat < "${config_file}.dpkg-new"
mv -f "${config_file}.dpkg-new" "$config_file"
diff --git a/kernel/postinst.d/initramfs-tools b/kernel/postinst.d/initramfs-tools
index 5d02e570..6b6fef39 100755
--- a/kernel/postinst.d/initramfs-tools
+++ b/kernel/postinst.d/initramfs-tools
@@ -33,4 +33,4 @@ fi
# we're good - create initramfs. update runs do_bootloader
# shellcheck disable=SC2086
-INITRAMFS_TOOLS_KERNEL_HOOK=1 update-initramfs -c -k "${version}" ${bootopt} >&2
+update-initramfs -c -k "${version}" ${bootopt} >&2
diff --git a/kernel/postrm.d/initramfs-tools b/kernel/postrm.d/initramfs-tools
index 471da863..c340beb1 100755
--- a/kernel/postrm.d/initramfs-tools
+++ b/kernel/postrm.d/initramfs-tools
@@ -33,4 +33,4 @@ fi
# delete initramfs
# shellcheck disable=SC2086
-INITRAMFS_TOOLS_KERNEL_HOOK=1 update-initramfs -d -k "${version}" ${bootopt} >&2
+update-initramfs -d -k "${version}" ${bootopt} >&2
diff --git a/ldap/ldap.conf b/ldap/ldap.conf
index 42d42b0d..635114a6 100644
--- a/ldap/ldap.conf
+++ b/ldap/ldap.conf
@@ -6,7 +6,7 @@
# This file should be world readable but not world writable.
#BASE dc=example,dc=com
-#URI ldap://ldap.example.com ldap://ldap-master.example.com:666
+#URI ldap://ldap.example.com ldap://ldap-provider.example.com:666
#SIZELIMIT 12
#TIMELIMIT 15
diff --git a/logcheck/ignore.d.server/gpg-agent b/logcheck/ignore.d.server/gpg-agent
index a2f21307..6de7991d 100644
--- a/logcheck/ignore.d.server/gpg-agent
+++ b/logcheck/ignore.d.server/gpg-agent
@@ -1,11 +1,11 @@
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Listening on GnuPG cryptographic agent and passphrase cache\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Listening on GnuPG network certificate management daemon\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Listening on GnuPG cryptographic agent and passphrase cache \(restricted\)\.$
-^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Listening on GnuPG cryptographic agent \(access for web browsers\)\.$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Listening on GnuPG cryptographic agent and passphrase cache \(access for web browsers\)\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Listening on GnuPG cryptographic agent \(ssh-agent emulation\)\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Closed GnuPG network certificate management daemon\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Closed GnuPG cryptographic agent and passphrase cache\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Closed GnuPG cryptographic agent and passphrase cache \(restricted\)\.$
^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Closed GnuPG cryptographic agent \(ssh-agent emulation\)\.$
-^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Closed GnuPG cryptographic agent \(access for web browsers\)\.$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ systemd\[[[:digit:]]+\]: Closed GnuPG cryptographic agent and passphrase cache \(access for web browsers\)\.$
diff --git a/logcheck/ignore.d.server/rng-tools b/logcheck/ignore.d.server/rng-tools
deleted file mode 100644
index 8bfb6b87..00000000
--- a/logcheck/ignore.d.server/rng-tools
+++ /dev/null
@@ -1,5 +0,0 @@
-rngd\[[0-9]+\]: +stats:
-rngd\[[0-9]+\]: .* starting up\.\.\.
-rngd\[[0-9]+\]: +Exiting\.\.\.
-rngd\[[0-9]+\]: +entropy feed to the kernel ready
-rngd\[[0-9]+\]: +Activating Linux kernel 2.4 entropy accounting bug workaround
diff --git a/logcheck/ignore.d.server/rng-tools-debian b/logcheck/ignore.d.server/rng-tools-debian
new file mode 100644
index 00000000..01ddf1c8
--- /dev/null
+++ b/logcheck/ignore.d.server/rng-tools-debian
@@ -0,0 +1,9 @@
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: rngd [-.[:alnum:]]+ starting up\.\.\.$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: (bits received from HRNG source|bits sent to kernel pool|entropy added to kernel pool): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: FIPS 140-2 (successes|failures): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: FIPS 140-2\(2001-10-10\) (Monobit|Poker|Runs|Long run|Continuous run): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: (HRNG source|FIPS tests) speed: \(min=[.[[:digit:]]+; avg=[.[:digit:]]+; max=[.[:digit:]]+\)(K|M)ibits/s$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: (Lowest ready-buffers level|Entropy starvations): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: Time spent starving for entropy: \(min=[.[:digit:]]+; avg=[.[:digit:]]+; max=[.[:digit:]]+\)us$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: entropy feed to the kernel ready$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: Exiting\.\.\.$
diff --git a/logcheck/ignore.d.server/rsyslog b/logcheck/ignore.d.server/rsyslog
index 171f20ee..c29d5bf4 100644
--- a/logcheck/ignore.d.server/rsyslog
+++ b/logcheck/ignore.d.server/rsyslog
@@ -1,5 +1,5 @@
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ kernel: imklog [0-9.]+, log source = /proc/kmsg started.$
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ kernel: Kernel logging \(proc\) stopped.$
-^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] start$
-^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] exiting on signal [0-9]+.$
-^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" swVersion="[0-9.]+" x-pid="[0-9]+" x-info="http://www.rsyslog.com"\] rsyslogd was HUPed$
+^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" swVersion="[0-9.]+" x-pid="[0-9]+" x-info="https://www.rsyslog.com"\] start$
+^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" swVersion="[0-9.]+" x-pid="[0-9]+" x-info="https://www.rsyslog.com"\] exiting on signal [0-9]+.$
+^\w{3} [ :0-9]{11} [._[:alnum:]-]+ rsyslogd: \[origin software="rsyslogd" swVersion="[0-9.]+" x-pid="[0-9]+" x-info="https://www.rsyslog.com"\] rsyslogd was HUPed$
diff --git a/logcheck/violations.ignore.d/rng-tools b/logcheck/violations.ignore.d/rng-tools
deleted file mode 100644
index 8bfb6b87..00000000
--- a/logcheck/violations.ignore.d/rng-tools
+++ /dev/null
@@ -1,5 +0,0 @@
-rngd\[[0-9]+\]: +stats:
-rngd\[[0-9]+\]: .* starting up\.\.\.
-rngd\[[0-9]+\]: +Exiting\.\.\.
-rngd\[[0-9]+\]: +entropy feed to the kernel ready
-rngd\[[0-9]+\]: +Activating Linux kernel 2.4 entropy accounting bug workaround
diff --git a/logcheck/violations.ignore.d/rng-tools-debian b/logcheck/violations.ignore.d/rng-tools-debian
new file mode 100644
index 00000000..01ddf1c8
--- /dev/null
+++ b/logcheck/violations.ignore.d/rng-tools-debian
@@ -0,0 +1,9 @@
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: rngd [-.[:alnum:]]+ starting up\.\.\.$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: (bits received from HRNG source|bits sent to kernel pool|entropy added to kernel pool): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: FIPS 140-2 (successes|failures): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: FIPS 140-2\(2001-10-10\) (Monobit|Poker|Runs|Long run|Continuous run): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: (HRNG source|FIPS tests) speed: \(min=[.[[:digit:]]+; avg=[.[:digit:]]+; max=[.[:digit:]]+\)(K|M)ibits/s$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: (Lowest ready-buffers level|Entropy starvations): [[:digit:]]+$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: stats: Time spent starving for entropy: \(min=[.[:digit:]]+; avg=[.[:digit:]]+; max=[.[:digit:]]+\)us$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: entropy feed to the kernel ready$
+^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ rngd\[[[:digit:]]+\]: Exiting\.\.\.$
diff --git a/logrotate.d/exim4-base b/logrotate.d/exim4-base
index ac31dd44..3b325833 100644
--- a/logrotate.d/exim4-base
+++ b/logrotate.d/exim4-base
@@ -5,5 +5,5 @@
compress
delaycompress
notifempty
- create 640 Debian-exim adm
+ nocreate
}
diff --git a/logrotate.d/exim4-paniclog b/logrotate.d/exim4-paniclog
index dd36d687..185b9a06 100644
--- a/logrotate.d/exim4-paniclog
+++ b/logrotate.d/exim4-paniclog
@@ -5,6 +5,6 @@
compress
delaycompress
notifempty
- create 640 Debian-exim adm
+ nocreate
}
diff --git a/mailcap b/mailcap
index b8f1b311..01f8752d 100644
--- a/mailcap
+++ b/mailcap
@@ -25,11 +25,11 @@
###############################################################################
-text/plain; less '%s'; needsterminal
-application/x-troff-man; /usr/bin/man -X100 -l '%s'; test=test -n "$DISPLAY" -a -e /usr/bin/gxditview; description=Man page
-text/troff; /usr/bin/man -X100 -l '%s'; test=test -n "$DISPLAY" -a -e /usr/bin/gxditview; description=Man page
-application/x-troff-man; /usr/bin/man -l '%s'; needsterminal; description=Man page
-text/troff; /usr/bin/man -l '%s'; needsterminal; description=Man page
+text/plain; less %s; needsterminal
+application/x-troff-man; /usr/bin/man -X100 -l %s; test=test -n "$DISPLAY" -a -e /usr/bin/gxditview; description=Man page
+text/troff; /usr/bin/man -X100 -l %s; test=test -n "$DISPLAY" -a -e /usr/bin/gxditview; description=Man page
+application/x-troff-man; /usr/bin/man -l %s; needsterminal; description=Man page
+text/troff; /usr/bin/man -l %s; needsterminal; description=Man page
text/html; /usr/bin/sensible-browser %s; description=HTML Text; nametemplate=%s.html
application/x-troff-man; /usr/bin/nroff -mandoc -Tutf8; copiousoutput; print=/usr/bin/nroff -mandoc -Tutf8 | print text/plain:-
text/troff; /usr/bin/nroff -mandoc -Tutf8; copiousoutput; print=/usr/bin/nroff -mandoc -Tutf8 | print text/plain:-
@@ -53,14 +53,14 @@ text/x-c++; vim %s; needsterminal
text/plain; view %s; edit=vim %s; compose=vim %s; test=test -x /usr/bin/vim; needsterminal
application/zip; unzip -l %s; nametemplate=%s.zip; copiousoutput
text/plain; view %s; edit=vi %s; compose=vi %s; needsterminal
-application/x-troff-man; /usr/bin/man -Tascii -l '%s' | col -b; copiousoutput; description=Man page
-text/troff; /usr/bin/man -Tascii -l '%s' | col -b; copiousoutput; description=Man page
-text/*; less '%s'; needsterminal
+application/x-troff-man; /usr/bin/man -Tascii -l %s | col -b; copiousoutput; description=Man page
+text/troff; /usr/bin/man -Tascii -l %s | col -b; copiousoutput; description=Man page
+text/*; less %s; needsterminal
text/*; view %s; edit=vim %s; compose=vim %s; test=test -x /usr/bin/vim; needsterminal
application/x-info; /usr/bin/info --subnodes -o /dev/stdout -f '%s' 2>/dev/null; copiousoutput; description=GNU Info document
-application/x-tar; /bin/tar tvf '%s'; print=/bin/tar tvf - | print text/plain:-; copiousoutput
-application/x-gtar; /bin/tar tvf '%s'; print=/bin/tar tvf - | print text/plain:-; copiousoutput
-application/x-ustar; /bin/tar tvf '%s'; print=/bin/tar tvf - | print text/plain:-; copiousoutput
+application/x-tar; /bin/tar tvf %s; print=/bin/tar tvf - | print text/plain:-; copiousoutput
+application/x-gtar; /bin/tar tvf %s; print=/bin/tar tvf - | print text/plain:-; copiousoutput
+application/x-ustar; /bin/tar tvf %s; print=/bin/tar tvf - | print text/plain:-; copiousoutput
text/*; more %s; needsterminal
text/*; view %s; edit=vi %s; compose=vi %s; needsterminal
application/vnd.debian.binary-package; /usr/lib/mime/debian-view %s; needsterminal; description=Debian GNU/Linux Package; nametemplate=%s.deb
diff --git a/manpath.config b/manpath.config
index 722a52d6..7c2792e9 100644
--- a/manpath.config
+++ b/manpath.config
@@ -69,6 +69,7 @@ MANDB_MAP /usr/local/man /var/cache/man/oldlocal
MANDB_MAP /usr/local/share/man /var/cache/man/local
MANDB_MAP /usr/X11R6/man /var/cache/man/X11R6
MANDB_MAP /opt/man /var/cache/man/opt
+MANDB_MAP /snap/man /var/cache/man/snap
#
#---------------------------------------------------------
# Program definitions. These are commented out by default as the value
diff --git a/mime.types b/mime.types
index 6e3eabb8..ec6469d7 100644
--- a/mime.types
+++ b/mime.types
@@ -1,16 +1,16 @@
###############################################################################
#
-# MIME media types and the extensions that represent them.
+# Media (MIME) types and the extensions that represent them.
#
# The format of this file is a media type on the left and zero or more
# filename extensions on the right. Programs using this file will map
# files ending with those extensions to the associated type.
#
-# This file is part of the "mime-support" package. Please report a bug using
+# This file is part of the "media-types" package. Please report a bug using
# the "reportbug" command of the "reportbug" package if you would like new
# types or extensions to be added.
#
-# The reason that all types are managed by the mime-support package instead
+# The reason that all types are managed by the media-types package instead
# allowing individual packages to install types in much the same way as they
# add entries in to the mailcap file is so these types can be referenced by
# other programs (such as a web server) even if the specific support package
@@ -22,213 +22,820 @@
#
###############################################################################
-
+application/1d-interleaved-parityfec
+application/3gpdash-qoe-report+xml
+application/3gpp-ims+xml
+application/A2L a2l
application/activemessage
+application/activity+json
+application/alto-costmapfilter+json
+application/alto-costmap+json
+application/alto-directory+json
+application/alto-endpointcost+json
+application/alto-endpointcostparams+json
+application/alto-endpointprop+json
+application/alto-endpointpropparams+json
+application/alto-error+json
+application/alto-networkmapfilter+json
+application/alto-networkmap+json
+application/alto-updatestreamcontrol+json
+application/alto-updatestreamparams+json
+application/AML aml
application/andrew-inset ez
application/annodex anx
application/applefile
-application/atom+xml atom
+application/ATF atf
+application/ATFX atfx
application/atomcat+xml atomcat
+application/atomdeleted+xml atomdeleted
application/atomicmail
application/atomserv+xml atomsrv
+application/atomsvc+xml atomsvc
+application/atom+xml atom
+application/atsc-dwd+xml dwd
+application/atsc-dynamic-event-message
+application/atsc-held+xml held
+application/atsc-rdt+json
+application/atsc-rsat+xml rsat
+application/ATXML atxml
+application/auth-policy+xml apxml
+application/bacnet-xdd+zip xdd
application/batch-SMTP
application/bbolin lin
application/beep+xml
+application/calendar+json
+application/calendar+xml xcs
+application/call-completion
application/cals-1840
+application/cap+xml
+application/cbor cbor
+application/cbor-seq
+application/cccex c3ex
+application/ccmp+xml ccmp
+application/ccxml+xml ccxml
+application/CDFX+XML cdfx
+application/cdmi-capability cdmia
+application/cdmi-container cdmic
+application/cdmi-domain cdmid
+application/cdmi-object cdmio
+application/cdmi-queue cdmiq
+application/cdni
+application/CEA cea
+application/cea-2018+xml
+application/cellml+xml cellml cml
+application/cfw
+application/clue_info+xml clue
+application/clue+xml
+application/cms cmsc
+application/cnrp+xml
+application/coap-group+json
+application/coap-payload
application/commonground
+application/conference-info+xml
+application/cose
+application/cose-key
+application/cose-key-set
+application/cpl+xml cpl
+application/csrattrs csrattrs
+application/CSTAdata+xml
+application/csta+xml
+application/csvm+json
application/cu-seeme cu
+application/cwt
application/cybercash
+application/dashdelta mpdd
+application/dash+xml mpd
application/davmount+xml davmount
application/dca-rft
+application/DCD dcd
application/dec-dx
+application/dialog-info+xml
application/dicom dcm
+application/dicom+json
+application/dicom+xml
+application/DII dii
+application/DIT dit
+application/dns
+application/dns+json
+application/dns-message
application/docbook+xml
+application/dots+cbor
+application/dskpp+xml xmls
application/dsptype tsp
-application/dvcs
+application/dssc+der dssc
+application/dssc+xml xdssc
+application/dvcs dvc
application/ecmascript es
application/edi-consent
-application/edi-x12
+application/EDI-Consent
application/edifact
+application/EDIFACT
+application/edi-x12
+application/EDI-X12
+application/efi efi
+application/EmergencyCallData.Comment+xml
+application/EmergencyCallData.Control+xml
+application/EmergencyCallData.DeviceInfo+xml
+application/EmergencyCallData.eCall.MSD
+application/EmergencyCallData.ProviderInfo+xml
+application/EmergencyCallData.ServiceInfo+xml
+application/EmergencyCallData.SubscriberInfo+xml
+application/EmergencyCallData.VEDS+xml
+application/emma+xml emma
+application/emotionml+xml emotionml
+application/encaprtp
+application/epp+xml
application/epub+zip epub
application/eshop
-application/font-sfnt otf ttf
+application/exi exi
+application/expect-ct-report+json
+application/fastinfoset finf
+application/fastsoap
+application/fdt+xml fdt
+application/fhir+json
+application/fhir+xml
+application/fits
+application/flexfec
application/font-tdpfr pfr
-application/font-woff woff
+application/framework-attributes+xml
application/futuresplash spl
+application/geo+json geojson
+application/geo+json-seq
+application/geopackage+sqlite3 gpkg
+application/geoxacml+xml
application/ghostview
+application/gltf-buffer glbin glbuf
+application/gml+xml gml
application/gzip gz
+application/H224
+application/held+xml
application/hta hta
application/http
-application/hyperstudio
+application/hyperstudio stk
+application/ibe-key-request+xml
+application/ibe-pkg-reply+xml
+application/ibe-pp-data
application/iges
+application/im-iscomposing+xml
application/index
application/index.cmd
application/index.obj
application/index.response
application/index.vnd
+application/inkml+xml ink inkml
application/iotp
+application/ipfix ipfix
application/ipp
application/isup
+application/its+xml its
application/java-archive jar
+application/javascript js mjs
application/java-serialized-object ser
application/java-vm class
-application/javascript js
+application/jf2feed+json
+application/jose
+application/jose+json
+application/jrd+json jrd
application/json json
+application/json-patch+json json-patch
+application/json-seq
+application/jwk+json
+application/jwk-set+json
+application/jwt
+application/kpml-request+xml
+application/kpml-response+xml
+application/ld+json jsonld
+application/lgr+xml lgr
+application/link-format wlnk
+application/load-control+xml
+application/lostsync+xml lostsyncxml
+application/lost+xml lostxml
+application/lpf+zip lpf
+application/LXF lxf
application/m3g m3g
application/mac-binhex40 hqx
application/mac-compactpro cpt
application/macwriteii
-application/marc
-application/mathematica nb nbp
+application/mads+xml mads
+application/marc mrc
+application/marcxml+xml mrcx
+application/mathematica ma mb
+application/mathml-content+xml
+application/mathml-presentation+xml
+application/mathml+xml mml
+application/mbms-associated-procedure-description+xml
+application/mbms-deregister+xml
+application/mbms-envelope+xml
+application/mbms-msk-response+xml
+application/mbms-msk+xml
+application/mbms-protection-description+xml
+application/mbms-reception-report+xml
+application/mbms-register-response+xml
+application/mbms-register+xml
+application/mbms-schedule+xml
+application/mbms-user-service-description+xml
application/mbox mbox
-application/ms-tnef
+application/media_control+xml
+application/media-policy-dataset+xml
+application/mediaservercontrol+xml
+application/merge-patch+json
+application/metalink4+xml meta4
+application/mets+xml mets
+application/MF4 mf4
+application/mikey
+application/mmt-aei+xml maei
+application/mmt-usd+xml musd
+application/mods+xml mods
+application/mosskey-data
+application/mosskey-request
+application/moss-keys
+application/moss-signature
+application/mp21 m21 mp21
+application/mp4
+application/mpeg4-generic
+application/mpeg4-iod
+application/mpeg4-iod-xmt
+application/mrb-consumer+xml
+application/mrb-publish+xml
application/msaccess mdb
-application/msword doc dot
+application/msc-ivr+xml
+application/msc-mixer+xml
+application/ms-tnef
+application/msword doc
+application/mud+json
+application/multipart-core
application/mxf mxf
+application/nasdata
+application/news-checkgroups
+application/news-groupinfo
application/news-message-id
application/news-transmission
-application/ocsp-request
-application/ocsp-response
+application/nlsml+xml
+application/node
+application/n-quads nq
+application/nss
+application/n-triples nt
+application/ocsp-request orq
+application/ocsp-response ors
application/octet-stream bin deploy msu msp
application/oda oda
+application/odm+xml
+application/ODX odx
application/oebps-package+xml opf
application/ogg ogx
application/onenote one onetoc2 onetmp onepkg
+application/oscore
+application/oxps oxps
+application/p2p-overlay+xml relo
application/parityfec
+application/passport
+application/patch-ops-error+xml
application/pdf pdf
+application/PDX pdx
+application/pem-certificate-chain pem
application/pgp-encrypted pgp
-application/pgp-keys key
+application/pgp-keys asc key
application/pgp-signature sig
application/pics-rules prf
-application/pkcs10
-application/pkcs7-mime
-application/pkcs7-signature
-application/pkix-cert
-application/pkix-crl
-application/pkixcmp
+application/pidf-diff+xml
+application/pidf+xml
+application/pkcs10 p10
+application/pkcs12 p12 pfx
+application/pkcs7-mime p7m p7c p7z
+application/pkcs7-signature p7s
+application/pkcs8 p8
+application/pkcs8-encrypted p8e
+application/pkix-attr-cert ac
+application/pkix-cert cer
+application/pkixcmp pki
+application/pkix-crl crl
+application/pkix-pkipath pkipath
+application/pls+xml
+application/poc-settings+xml
application/postscript ps ai eps epsi epsf eps2 eps3
+application/ppsp-tracker+json
+application/problem+json
+application/problem+xml
+application/provenance+xml provx
application/prs.alvestrand.titrax-sheet
-application/prs.cww
-application/prs.nprend
+application/prs.cww cw cww
+application/prs.hpub+zip hpub
+application/prs.nprend rnd rct
+application/prs.plucker
+application/prs.rdf-xml-crypt rdf-crypt
+application/prs.xsf+xml xsf
+application/pskc+xml pskcxml
+application/pvd+json
application/qsig
-application/rar rar
+application/raptorfec
+application/rdap+json
application/rdf+xml rdf
+application/reginfo+xml rif
+application/relax-ng-compact-syntax rnc
application/remote-printing
+application/reputon+json
+application/resource-lists-diff+xml rld
+application/resource-lists+xml rl
+application/rfc+xml rfcxml
application/riscos
+application/rlmi+xml
+application/rls-services+xml rs
+application/route-apd+xml rapd
+application/route-s-tsid+xml sls
+application/route-usd+xml rusd
+application/rpki-ghostbusters gbr
+application/rpki-manifest mft
+application/rpki-publication
+application/rpki-roa roa
+application/rpki-updown
application/rtf rtf
-application/sdp
+application/rtploopback
+application/rtx
+application/samlassertion+xml
+application/samlmetadata+xml
+application/sbe
+application/sbml+xml
+application/scaip+xml
+application/scim+json scim
+application/scvp-cv-request scq
+application/scvp-cv-response scs
+application/scvp-vp-request spq
+application/scvp-vp-response spp
+application/sdp sdp
+application/secevent+jwt
+application/senml+cbor senmlc
+application/senml-etch+cbor senml-etchc
+application/senml-etch+json senml-etchj
+application/senml-exi senmle
+application/senml+json senml
+application/senml+xml senmlx
+application/sensml+cbor sensmlc
+application/sensml-exi sensmle
+application/sensml+json sensml
+application/sensml+xml sensmlx
+application/sep-exi
+application/sep+xml
+application/session-info
application/set-payment
application/set-payment-initiation
application/set-registration
application/set-registration-initiation
application/sgml
-application/sgml-open-catalog
-application/sieve
-application/sla stl
+application/sgml-open-catalog soc
+application/shf+xml shf
+application/sieve siv sieve
+application/simple-filter+xml cl
+application/simple-message-summary
+application/simpleSymbolContainer
application/slate
-application/smil+xml smi smil
-application/timestamp-query
-application/timestamp-reply
+application/smil+xml smil smi sml
+application/smpte336m
+application/soap+fastinfoset
+application/soap+xml
+application/sparql-query rq
+application/sparql-results+xml srx
+application/spirits-event+xml
+application/sql sql
+application/srgs gram
+application/srgs+xml grxml
+application/sru+xml sru
+application/ssml+xml ssml
+application/stix+json stix
+application/swid+xml swidtag
+application/tamp-apex-update tau
+application/tamp-apex-update-confirm auc
+application/tamp-community-update tcu
+application/tamp-community-update-confirm cuc
+application/tamp-error ter
+application/tamp-sequence-adjust tsa
+application/tamp-sequence-adjust-confirm sac
+application/tamp-status-query
+application/tamp-status-response
+application/tamp-update tur
+application/tamp-update-confirm tuc
+application/taxii+json
+application/td+json jsontd
+application/tei+xml tei teiCorpus odd
+application/TETRA_ISI
+application/thraud+xml tfi
+application/timestamped-data tsd
+application/timestamp-query tsq
+application/timestamp-reply tsr
+application/tlsrpt+gzip
+application/tlsrpt+json
+application/tnauthlist
+application/trickle-ice-sdpfrag
+application/trig trig
+application/ttml+xml ttml
+application/tve-trigger
+application/tzif
+application/tzif-leap
+application/ulpfec
+application/urc-grpsheet+xml gsheet
+application/urc-ressheet+xml rsheet
+application/urc-targetdesc+xml td
+application/urc-uisocketdesc+xml uis
+application/vcard+json
+application/vcard+xml
application/vemmi
-application/wasm wasm
-application/whoispp-query
-application/whoispp-response
-application/wita
-application/x400-bp
-application/xhtml+xml xhtml xht
-application/xml xml xsd
-application/xml-dtd
-application/xml-external-parsed-entity
-application/xslt+xml xsl xslt
-application/xspf+xml xspf
-application/zip zip
-application/vnd.3M.Post-it-Notes
-application/vnd.accpac.simply.aso
-application/vnd.accpac.simply.imp
-application/vnd.acucobol
+application/vnd.1000minds.decision-model+xml 1km
+application/vnd.3gpp2.bcmcsinfo+xml
+application/vnd.3gpp2.sms sms
+application/vnd.3gpp2.tcap tcap
+application/vnd.3gpp.access-transfer-events+xml
+application/vnd.3gpp.bsf+xml
+application/vnd.3gpp.GMOP+xml
+application/vnd.3gpp.mcdata-affiliation-command+xml
+application/vnd.3gpp.mcdata-info+xml
+application/vnd.3gpp.mcdata-signalling
+application/vnd.3gpp.mcdata-ue-config+xml
+application/vnd.3gpp.mcdata-user-profile+xml
+application/vnd.3gpp.mcptt-affiliation-command+xml
+application/vnd.3gpp.mcptt-floor-request+xml
+application/vnd.3gpp.mcptt-info+xml
+application/vnd.3gpp.mcptt-location-info+xml
+application/vnd.3gpp.mcptt-mbms-usage-info+xml
+application/vnd.3gpp.mcptt-service-config+xml
+application/vnd.3gpp.mcptt-signed+xml
+application/vnd.3gpp.mcptt-ue-config+xml
+application/vnd.3gpp.mcptt-ue-init-config+xml
+application/vnd.3gpp.mcptt-user-profile+xml
+application/vnd.3gpp.mc-signalling-ear
+application/vnd.3gpp.mcvideo-affiliation-command+xml
+application/vnd.3gpp.mcvideo-info+xml
+application/vnd.3gpp.mcvideo-location-info+xml
+application/vnd.3gpp.mcvideo-mbms-usage-info+xml
+application/vnd.3gpp.mcvideo-service-config+xml
+application/vnd.3gpp.mcvideo-transmission-request+xml
+application/vnd.3gpp.mcvideo-ue-config+xml
+application/vnd.3gpp.mcvideo-user-profile+xml
+application/vnd.3gpp.mid-call+xml
+application/vnd.3gpp.pic-bw-large plb
+application/vnd.3gpp.pic-bw-small psb
+application/vnd.3gpp.pic-bw-var pvb
+application/vnd.3gpp-prose-pc3ch+xml
+application/vnd.3gpp-prose+xml
+application/vnd.3gpp.sms
+application/vnd.3gpp.sms+xml
+application/vnd.3gpp.srvcc-ext+xml
+application/vnd.3gpp.SRVCC-info+xml
+application/vnd.3gpp.state-and-event-info+xml
+application/vnd.3gpp.ussd+xml
+application/vnd.3gpp-v2x-local-service-information
+application/vnd.3lightssoftware.imagescal imgcal
+application/vnd.3M.Post-it-Notes pwn
+application/vnd.accpac.simply.aso aso
+application/vnd.accpac.simply.imp imp
+application/vnd.acucobol acu
+application/vnd.acucorp atc acutc
+application/vnd.adobe.flash.movie swf
+application/vnd.adobe.formscentral.fcdt fcdt
+application/vnd.adobe.fxp fxp fxpl
+application/vnd.adobe.partial-upload
+application/vnd.adobe.xdp+xml xdp
+application/vnd.adobe.xfdf xfdf
application/vnd.aether.imp
+application/vnd.afpc.afplinedata
+application/vnd.afpc.afplinedata-pagedef
+application/vnd.afpc.foca-charset
+application/vnd.afpc.foca-codedfont
+application/vnd.afpc.foca-codepage
+application/vnd.afpc.modca list3820 listafp afp pseg3820
+application/vnd.afpc.modca-formdef
+application/vnd.afpc.modca-mediummap
+application/vnd.afpc.modca-objectcontainer
+application/vnd.afpc.modca-overlay ovl
+application/vnd.afpc.modca-pagesegment psg
+application/vnd.ah-barcode
+application/vnd.ahead.space ahead
+application/vnd.airzip.filesecure.azf azf
+application/vnd.airzip.filesecure.azs azs
+application/vnd.amadeus+json
+application/vnd.amazon.mobi8-ebook azw3
+application/vnd.americandynamics.acc acc
+application/vnd.amiga.ami ami
+application/vnd.amundsen.maze+xml
+application/vnd.android.ota ota
application/vnd.android.package-archive apk
-application/vnd.anser-web-certificate-issue-initiation
-application/vnd.anser-web-funds-transfer-initiation
-application/vnd.audiograph
-application/vnd.bmi
-application/vnd.businessobjects
+application/vnd.anki apkg
+application/vnd.anser-web-certificate-issue-initiation cii
+application/vnd.anser-web-funds-transfer-initiation fti
+application/vnd.antix.game-component
+application/vnd.apache.thrift.binary
+application/vnd.apache.thrift.compact
+application/vnd.apache.thrift.json
+application/vnd.api+json
+application/vnd.aplextor.warrp+json
+application/vnd.apothekende.reservation+json
+application/vnd.apple.installer+xml dist distz pkg mpkg
+application/vnd.apple.keynote keynote
+application/vnd.apple.mpegurl m3u8
+application/vnd.apple.numbers numbers
+application/vnd.apple.pages pages
+application/vnd.aristanetworks.swi swi
+application/vnd.artisan+json artisan
+application/vnd.artsquare
+application/vnd.astraea-software.iota iota
+application/vnd.audiograph aep
+application/vnd.autopackage package
+application/vnd.avalon+json
+application/vnd.avistar+xml
+application/vnd.balsamiq.bmml+xml bmml
+application/vnd.balsamiq.bmpr bmpr
+application/vnd.banana-accounting ac2
+application/vnd.bbf.usp.error
+application/vnd.bbf.usp.msg
+application/vnd.bbf.usp.msg+json
+application/vnd.bekitzur-stech+json
+application/vnd.bint.med-content
+application/vnd.biopax.rdf+xml
+application/vnd.blink-idb-value-wrapper
+application/vnd.blueice.multipass mpm
+application/vnd.bluetooth.ep.oob ep
+application/vnd.bluetooth.le.oob le
+application/vnd.bmi bmi
+application/vnd.bpf
+application/vnd.bpf3
+application/vnd.businessobjects rep
+application/vnd.byu.uapi+json
+application/vnd.cab-jscript
application/vnd.canon-cpdl
application/vnd.canon-lips
-application/vnd.cinderella cdy
-application/vnd.claymore
-application/vnd.commerce-battelle
-application/vnd.commonspace
+application/vnd.capasystems-pg+json
+application/vnd.cendio.thinlinc.clientconf tlclient
+application/vnd.century-systems.tcp_stream
+application/vnd.chemdraw+xml cdxml
+application/vnd.chess-pgn pgn
+application/vnd.chipnuts.karaoke-mmd mmd
+application/vnd.ciedi
+application/vnd.cinderella cdy
+application/vnd.cirpack.isdn-ext
+application/vnd.citationstyles.style+xml csl
+application/vnd.claymore cla
+application/vnd.cloanto.rp9 rp9
+application/vnd.clonk.c4group c4g c4d c4f c4p c4u
+application/vnd.cluetrust.cartomobile-config c11amc
+application/vnd.cluetrust.cartomobile-config-pkg c11amz
+application/vnd.coffeescript coffee
+application/vnd.collabio.xodocuments.document xodt
+application/vnd.collabio.xodocuments.document-template xott
+application/vnd.collabio.xodocuments.presentation xodp
+application/vnd.collabio.xodocuments.presentation-template xotp
+application/vnd.collabio.xodocuments.spreadsheet xods
+application/vnd.collabio.xodocuments.spreadsheet-template xots
+application/vnd.collection.doc+json
+application/vnd.collection+json
+application/vnd.collection.next+json
+application/vnd.comicbook-rar cbr
+application/vnd.comicbook+zip cbz
+application/vnd.commerce-battelle icf icd ic0 ic1 ic2 ic3 ic4 ic5 ic6 ic7 ic8
+application/vnd.commonspace csp cst
application/vnd.comsocaller
-application/vnd.contact.cmsg
-application/vnd.cosmocaller
-application/vnd.ctc-posml
+application/vnd.contact.cmsg cdbcmsg
+application/vnd.coreos.ignition+json ign ignition
+application/vnd.cosmocaller cmc
+application/vnd.crick.clicker clkx
+application/vnd.crick.clicker.keyboard clkk
+application/vnd.crick.clicker.palette clkp
+application/vnd.crick.clicker.template clkt
+application/vnd.crick.clicker.wordbank clkw
+application/vnd.criticaltools.wbs+xml wbs
+application/vnd.cryptii.pipe+json
+application/vnd.crypto-shade-file ssvc
+application/vnd.ctc-posml pml
+application/vnd.ctct.ws+xml
+application/vnd.cups-pdf
application/vnd.cups-postscript
+application/vnd.cups-ppd ppd
application/vnd.cups-raster
application/vnd.cups-raw
+application/vnd.curl
+application/vnd.cyan.dean.root+xml
application/vnd.cybank
-application/vnd.debian.binary-package deb ddeb udeb
-application/vnd.dna
-application/vnd.dpgraph
+application/vnd.d2l.coursepackage1p0+zip
+application/vnd.dart dart
+application/vnd.datapackage+json
+application/vnd.dataresource+json
+application/vnd.data-vision.rdz rdz
+application/vnd.dbf dbf
+application/vnd.debian.binary-package deb ddeb udeb
+application/vnd.dece.data uvf uvvf uvd uvvd
+application/vnd.dece.ttml+xml uvt uvvt
+application/vnd.dece.unspecified uvx uvvx
+application/vnd.dece.zip uvz uvvz
+application/vnd.denovo.fcselayout-link fe_launch
+application/vnd.desmume.movie dsm
+application/vnd.dir-bi.plate-dl-nosuffix
+application/vnd.dm.delegation+xml
+application/vnd.dna dna
+application/vnd.document+json docjson
+application/vnd.dolby.mobile.1
+application/vnd.dolby.mobile.2
+application/vnd.doremir.scorecloud-binary-document scld
+application/vnd.dpgraph dpg mwc dpgraph
+application/vnd.dreamfactory dfac
+application/vnd.drive+json
+application/vnd.dtg.local
+application/vnd.dtg.local.flash fla
+application/vnd.dtg.local.html
+application/vnd.dvb.ait ait
+application/vnd.dvb.dvbisl+xml
+application/vnd.dvb.dvbj
+application/vnd.dvb.esgcontainer
+application/vnd.dvb.ipdcdftnotifaccess
+application/vnd.dvb.ipdcesgaccess
+application/vnd.dvb.ipdcesgaccess2
+application/vnd.dvb.ipdcesgpdd
+application/vnd.dvb.ipdcroaming
+application/vnd.dvb.iptv.alfec-base
+application/vnd.dvb.iptv.alfec-enhancement
+application/vnd.dvb.notif-aggregate-root+xml
+application/vnd.dvb.notif-container+xml
+application/vnd.dvb.notif-generic+xml
+application/vnd.dvb.notif-ia-msglist+xml
+application/vnd.dvb.notif-ia-registration-request+xml
+application/vnd.dvb.notif-ia-registration-response+xml
+application/vnd.dvb.notif-init+xml
+application/vnd.dvb.pfr
+application/vnd.dvb.service svc
application/vnd.dxr
+application/vnd.dynageo geo
+application/vnd.dzr dzr
+application/vnd.easykaraoke.cdgdownload
application/vnd.ecdis-update
-application/vnd.ecowin.chart
+application/vnd.ecip.rlp
+application/vnd.ecowin.chart mag
application/vnd.ecowin.filerequest
application/vnd.ecowin.fileupdate
application/vnd.ecowin.series
application/vnd.ecowin.seriesrequest
application/vnd.ecowin.seriesupdate
-application/vnd.enliven
-application/vnd.epson.esf
-application/vnd.epson.msf
-application/vnd.epson.quickanime
-application/vnd.epson.salt
-application/vnd.epson.ssf
-application/vnd.ericsson.quickcall
+application/vnd.efi-img
+application/vnd.efi-iso
+application/vnd.emclient.accessrequest+xml
+application/vnd.enliven nml
+application/vnd.enphase.envoy
+application/vnd.eprints.data+xml
+application/vnd.epson.esf esf
+application/vnd.epson.msf msf
+application/vnd.epson.quickanime qam
+application/vnd.epson.salt slt
+application/vnd.epson.ssf ssf
+application/vnd.ericsson.quickcall qcall qca
+application/vnd.espass-espass+zip espass
+application/vnd.eszigno3+xml es3 et3
+application/vnd.etsi.aoc+xml
+application/vnd.etsi.asic-e+zip asice sce
+application/vnd.etsi.asic-s+zip asics
+application/vnd.etsi.cug+xml
+application/vnd.etsi.iptvcommand+xml
+application/vnd.etsi.iptvdiscovery+xml
+application/vnd.etsi.iptvprofile+xml
+application/vnd.etsi.iptvsad-bc+xml
+application/vnd.etsi.iptvsad-cod+xml
+application/vnd.etsi.iptvsad-npvr+xml
+application/vnd.etsi.iptvservice+xml
+application/vnd.etsi.iptvsync+xml
+application/vnd.etsi.iptvueprofile+xml
+application/vnd.etsi.mcid+xml
+application/vnd.etsi.mheg5
+application/vnd.etsi.overload-control-policy-dataset+xml
+application/vnd.etsi.pstn+xml
+application/vnd.etsi.sci+xml
+application/vnd.etsi.simservs+xml
+application/vnd.etsi.timestamp-token tst
+application/vnd.etsi.tsl.der
+application/vnd.etsi.tsl+xml
application/vnd.eudora.data
-application/vnd.fdf
+application/vnd.evolv.ecig.profile ecigprofile
+application/vnd.evolv.ecig.settings ecig
+application/vnd.evolv.ecig.theme ecigtheme
+application/vnd.exstream-empower+zip mpw
+application/vnd.exstream-package pub
+application/vnd.ezpix-album ez2
+application/vnd.ezpix-package ez3
+application/vnd.fastcopy-disk-image dim
+application/vnd.fdf fdf
+application/vnd.fdsn.mseed msd mseed
+application/vnd.fdsn.seed seed dataless
application/vnd.ffsns
+application/vnd.ficlab.flb+zip flb
+application/vnd.filmit.zfc zfc
+application/vnd.fints
+application/vnd.firemonkeys.cloudcell
application/vnd.flographit
-application/vnd.font-fontforge-sfd sfd
-application/vnd.framemaker
-application/vnd.fsc.weblaunch
-application/vnd.fujitsu.oasys
-application/vnd.fujitsu.oasys2
-application/vnd.fujitsu.oasys3
-application/vnd.fujitsu.oasysgp
-application/vnd.fujitsu.oasysprs
-application/vnd.fujixerox.ddd
-application/vnd.fujixerox.docuworks
-application/vnd.fujixerox.docuworks.binder
+application/vnd.FloGraphIt gph
+application/vnd.fluxtime.clip ftc
+application/vnd.font-fontforge-sfd sfd
+application/vnd.framemaker fm
+application/vnd.fsc.weblaunch fsc
+application/vnd.f-secure.mobile
+application/vnd.fujitsu.oasys oas
+application/vnd.fujitsu.oasys2 oa2
+application/vnd.fujitsu.oasys3 oa3
+application/vnd.fujitsu.oasysgp fg5
+application/vnd.fujitsu.oasysprs bh2
+application/vnd.fujixerox.ART4
+application/vnd.fujixerox.ART-EX
+application/vnd.fujixerox.ddd ddd
+application/vnd.fujixerox.docuworks xdw
+application/vnd.fujixerox.docuworks.binder xbd
+application/vnd.fujixerox.docuworks.container xct
+application/vnd.fujixerox.HBPL
application/vnd.fut-misnet
-application/vnd.google-earth.kml+xml kml
-application/vnd.google-earth.kmz kmz
-application/vnd.grafeq
-application/vnd.groove-account
-application/vnd.groove-identity-message
-application/vnd.groove-injector
-application/vnd.groove-tool-message
-application/vnd.groove-tool-template
-application/vnd.groove-vcard
-application/vnd.hhe.lesson-player
-application/vnd.hp-HPGL
-application/vnd.hp-PCL
+application/vnd.futoin+cbor
+application/vnd.futoin+json
+application/vnd.fuzzysheet fzs
+application/vnd.genomatix.tuxedo txd
+application/vnd.gentics.grd+json
+application/vnd.geogebra.file ggb
+application/vnd.geogebra.tool ggt
+application/vnd.geometry-explorer gex gre
+application/vnd.geonext gxt
+application/vnd.geoplan g2w
+application/vnd.geospace g3w
+application/vnd.gerber
+application/vnd.globalplatform.card-content-mgt
+application/vnd.globalplatform.card-content-mgt-response
+application/vnd.google-earth.kml+xml kml
+application/vnd.google-earth.kmz kmz
+application/vnd.gov.sk.e-form+xml
+application/vnd.gov.sk.e-form+zip
+application/vnd.gov.sk.xmldatacontainer+xml
+application/vnd.grafeq gqf gqs
+application/vnd.gridmp
+application/vnd.groove-account gac
+application/vnd.groove-help ghf
+application/vnd.groove-identity-message gim
+application/vnd.groove-injector grv
+application/vnd.groove-tool-message gtm
+application/vnd.groove-tool-template tpl
+application/vnd.groove-vcard vcg
+application/vnd.hal+json
+application/vnd.hal+xml hal
+application/vnd.HandHeld-Entertainment+xml zmm
+application/vnd.hbci hbci hbc kom upa pkd bpd
+application/vnd.hc+json
+application/vnd.hcl-bireports
+application/vnd.hdt hdt
+application/vnd.heroku+json
+application/vnd.hhe.lesson-player les
+application/vnd.hp-HPGL hpgl
+application/vnd.hp-hpid hpi hpid
+application/vnd.hp-hps hps
+application/vnd.hp-jlyt jlt
+application/vnd.hp-PCL pcl
application/vnd.hp-PCLXL
-application/vnd.hp-hpid
-application/vnd.hp-hps
application/vnd.httphone
+application/vnd.hydrostatix.sof-data sfd-hdstx
+application/vnd.hyperdrive+json
+application/vnd.hyper-item+json
+application/vnd.hyper+json
application/vnd.hzn-3d-crossword
-application/vnd.ibm.MiniPay
-application/vnd.ibm.afplinedata
-application/vnd.ibm.modcap
-application/vnd.informix-visionary
-application/vnd.intercon.formnet
+application/vnd.ibm.electronic-media emm
+application/vnd.ibm.MiniPay mpy
+application/vnd.ibm.rights-management irm
+application/vnd.ibm.secure-container sc
+application/vnd.iccprofile icc icm
+application/vnd.ieee.1905 1905.1
+application/vnd.igloader igl
+application/vnd.imagemeter.folder+zip imf
+application/vnd.imagemeter.image+zip imi
+application/vnd.immervision-ivp ivp
+application/vnd.immervision-ivu ivu
+application/vnd.ims.imsccv1p1 imscc
+application/vnd.ims.imsccv1p2
+application/vnd.ims.imsccv1p3
+application/vnd.ims.lis.v2.result+json
+application/vnd.ims.lti.v2.toolconsumerprofile+json
+application/vnd.ims.lti.v2.toolproxy.id+json
+application/vnd.ims.lti.v2.toolproxy+json
+application/vnd.ims.lti.v2.toolsettings+json
+application/vnd.ims.lti.v2.toolsettings.simple+json
+application/vnd.informedcontrol.rms+xml
+application/vnd.infotech.project
+application/vnd.infotech.project+xml
+application/vnd.innopath.wamp.notification
+application/vnd.insors.igm igm
+application/vnd.intercon.formnet xpw xpx
+application/vnd.intergeo i2g
application/vnd.intertrust.digibox
application/vnd.intertrust.nncp
-application/vnd.intu.qbo
-application/vnd.intu.qfx
-application/vnd.irepository.package+xml
-application/vnd.is-xpr
+application/vnd.intu.qbo qbo
+application/vnd.intu.qfx qfx
+application/vnd.iptc.g2.catalogitem+xml
+application/vnd.iptc.g2.conceptitem+xml
+application/vnd.iptc.g2.knowledgeitem+xml
+application/vnd.iptc.g2.newsitem+xml
+application/vnd.iptc.g2.newsmessage+xml
+application/vnd.iptc.g2.packageitem+xml
+application/vnd.iptc.g2.planningitem+xml
+application/vnd.ipunplugged.rcprofile rcprofile
+application/vnd.irepository.package+xml irp
+application/vnd.isac.fcs fcs
+application/vnd.iso11783-10+zip
+application/vnd.is-xpr xpr
+application/vnd.jam jam
application/vnd.japannet-directory-service
application/vnd.japannet-jpnstore-wakeup
application/vnd.japannet-payment-wakeup
@@ -237,25 +844,77 @@ application/vnd.japannet-registration-wakeup
application/vnd.japannet-setstore-wakeup
application/vnd.japannet-verification
application/vnd.japannet-verification-wakeup
-application/vnd.koan
-application/vnd.lotus-1-2-3
-application/vnd.lotus-approach
-application/vnd.lotus-freelance
-application/vnd.lotus-notes
-application/vnd.lotus-organizer
-application/vnd.lotus-screencam
-application/vnd.lotus-wordpro
-application/vnd.mcd
-application/vnd.mediastation.cdkey
+application/vnd.jcp.javame.midlet-rms rms
+application/vnd.jisp jisp
+application/vnd.joost.joda-archive joda
+application/vnd.jsk.isdn-ngn
+application/vnd.kahootz ktz ktr
+application/vnd.kde.karbon karbon
+application/vnd.kde.kchart chrt
+application/vnd.kde.kformula kfo
+application/vnd.kde.kivio flw
+application/vnd.kde.kontour kon
+application/vnd.kde.kpresenter kpr kpt
+application/vnd.kde.kspread ksp
+application/vnd.kde.kword kwd kwt
+application/vnd.kenameaapp htke
+application/vnd.kidspiration kia
+application/vnd.Kinar kne knp sdf
+application/vnd.koan skp skd skm skt
+application/vnd.kodak-descriptor sse
+application/vnd.las.las+json lasjson
+application/vnd.las.las+xml lasxml
+application/vnd.laszip
+application/vnd.leap+json
+application/vnd.liberty-request+xml
+application/vnd.llamagraphics.life-balance.desktop lbd
+application/vnd.llamagraphics.life-balance.exchange+xml lbe
+application/vnd.logipipe.circuit+zip lcs lca
+application/vnd.loom loom
+application/vnd.lotus-1-2-3 123 wk4 wk3 wk1
+application/vnd.lotus-approach apr vew
+application/vnd.lotus-freelance prz pre
+application/vnd.lotus-notes nsf ntf ndl ns4 ns3 ns2 nsh nsg
+application/vnd.lotus-organizer or3 or2 org
+application/vnd.lotus-screencam scm
+application/vnd.lotus-wordpro lwp sam
+application/vnd.macports.portpkg portpkg
+application/vnd.mapbox-vector-tile mvt
+application/vnd.marlin.drm.actiontoken+xml
+application/vnd.marlin.drm.conftoken+xml
+application/vnd.marlin.drm.license+xml
+application/vnd.marlin.drm.mdcf mdc
+application/vnd.mason+json
+application/vnd.maxmind.maxmind-db mmdb
+application/vnd.mcd mcd
+application/vnd.medcalcdata mc1
+application/vnd.mediastation.cdkey cdkey
application/vnd.meridian-slingshot
-application/vnd.mif
+application/vnd.MFER mwf
+application/vnd.mfmp mfm
+application/vnd.micrografx.flo flo
+application/vnd.micrografx.igx igx
+application/vnd.micro+json
+application/vnd.microsoft.portable-executable
+application/vnd.microsoft.windows.thumbnail-cache
+application/vnd.miele+json
+application/vnd.mif mif
application/vnd.minisoft-hp3000-save
application/vnd.mitsubishi.misty-guard.trustweb
application/vnd.mobius.daf
+application/vnd.Mobius.DAF daf
application/vnd.mobius.dis
+application/vnd.Mobius.DIS dis
+application/vnd.Mobius.MBK mbk
+application/vnd.Mobius.MQY mqy
application/vnd.mobius.msl
+application/vnd.Mobius.MSL msl
application/vnd.mobius.plc
+application/vnd.Mobius.PLC plc
application/vnd.mobius.txf
+application/vnd.Mobius.TXF txf
+application/vnd.mophun.application mpn
+application/vnd.mophun.certificate mpc
application/vnd.motorola.flexsuite
application/vnd.motorola.flexsuite.adsi
application/vnd.motorola.flexsuite.fis
@@ -263,47 +922,103 @@ application/vnd.motorola.flexsuite.gotap
application/vnd.motorola.flexsuite.kmr
application/vnd.motorola.flexsuite.ttc
application/vnd.motorola.flexsuite.wem
-application/vnd.mozilla.xul+xml xul
-application/vnd.ms-artgalry
-application/vnd.ms-asf
-application/vnd.ms-excel xls xlb xlt
-application/vnd.ms-excel.addin.macroEnabled.12 xlam
-application/vnd.ms-excel.sheet.binary.macroEnabled.12 xlsb
-application/vnd.ms-excel.sheet.macroEnabled.12 xlsm
-application/vnd.ms-excel.template.macroEnabled.12 xltm
-application/vnd.ms-fontobject eot
-application/vnd.ms-lrm
-application/vnd.ms-officetheme thmx
-application/vnd.ms-pki.seccat cat
+application/vnd.motorola.iprm
+application/vnd.mozilla.xul+xml xul
+application/vnd.ms-3mfdocument 3mf
+application/vnd.msa-disk-image msa
+application/vnd.ms-artgalry cil
+application/vnd.ms-asf asf
+application/vnd.ms-cab-compressed cab
+application/vnd.mseq mseq
+application/vnd.ms-excel xls xlm xla xlc xlt xlw
+application/vnd.ms-excel.addin.macroEnabled.12 xlam
+application/vnd.ms-excel.sheet.binary.macroEnabled.12 xlsb
+application/vnd.ms-excel.sheet.macroEnabled.12 xlsm
+application/vnd.ms-excel.template.macroEnabled.12 xltm
+application/vnd.ms-fontobject eot
+application/vnd.ms-htmlhelp chm
+application/vnd.msign
+application/vnd.ms-ims ims
+application/vnd.ms-lrm lrm
+application/vnd.ms-office.activeX+xml
+application/vnd.ms-officetheme thmx
+application/vnd.ms-pki.seccat cat
#application/vnd.ms-pki.stl stl
+application/vnd.ms-playready.initiator+xml
application/vnd.ms-powerpoint ppt pps
application/vnd.ms-powerpoint.addin.macroEnabled.12 ppam
application/vnd.ms-powerpoint.presentation.macroEnabled.12 pptm
application/vnd.ms-powerpoint.slide.macroEnabled.12 sldm
application/vnd.ms-powerpoint.slideshow.macroEnabled.12 ppsm
application/vnd.ms-powerpoint.template.macroEnabled.12 potm
-application/vnd.ms-project
-application/vnd.ms-tnef
+application/vnd.ms-PrintDeviceCapabilities+xml
+application/vnd.ms-PrintSchemaTicket+xml
+application/vnd.ms-project mpp mpt
+application/vnd.ms-tnef tnef tnf
+application/vnd.ms-windows.devicepairing
+application/vnd.ms-windows.nwprinting.oob
+application/vnd.ms-windows.printerpairing
+application/vnd.ms-windows.wsd.oob
+application/vnd.ms-wmdrm.lic-chlg-req
+application/vnd.ms-wmdrm.lic-resp
+application/vnd.ms-wmdrm.meter-chlg-req
+application/vnd.ms-wmdrm.meter-resp
application/vnd.ms-word.document.macroEnabled.12 docm
application/vnd.ms-word.template.macroEnabled.12 dotm
-application/vnd.ms-works
-application/vnd.mseq
-application/vnd.msign
+application/vnd.ms-works wcm wdb wks wps
+application/vnd.ms-wpl wpl
+application/vnd.ms-xpsdocument xps
+application/vnd.multiad.creator crtr
+application/vnd.multiad.creator.cif cif
+application/vnd.musician mus
application/vnd.music-niff
-application/vnd.musician
+application/vnd.muvee.style msty
+application/vnd.mynfc taglet
+application/vnd.ncd.control
+application/vnd.ncd.reference
+application/vnd.nearst.inv+json
+application/vnd.nervana entity request bkm kcm
application/vnd.netfpx
-application/vnd.noblenet-directory
-application/vnd.noblenet-sealer
-application/vnd.noblenet-web
-application/vnd.novadigm.EDM
-application/vnd.novadigm.EDX
-application/vnd.novadigm.EXT
+application/vnd.neurolanguage.nlu nlu
+application/vnd.nimn nimn
+application/vnd.nintendo.nitro.rom nds
+application/vnd.nintendo.snes.rom sfc smc
+application/vnd.nitf nitf
+application/vnd.noblenet-directory nnd
+application/vnd.noblenet-sealer nns
+application/vnd.noblenet-web nnw
+application/vnd.nokia.catalogs
+application/vnd.nokia.conml+wbxml
+application/vnd.nokia.conml+xml
+application/vnd.nokia.iptv.config+xml
+application/vnd.nokia.iSDS-radio-presets
+application/vnd.nokia.landmarkcollection+xml
+application/vnd.nokia.landmark+wbxml
+application/vnd.nokia.landmark+xml
+application/vnd.nokia.ncd
+application/vnd.nokia.n-gage.ac+xml
+application/vnd.nokia.n-gage.data ngdat
+application/vnd.nokia.pcd+wbxml
+application/vnd.nokia.pcd+xml
+application/vnd.nokia.radio-preset rpst
+application/vnd.nokia.radio-presets rpss
+application/vnd.novadigm.EDM edm
+application/vnd.novadigm.EDX edx
+application/vnd.novadigm.EXT ext
+application/vnd.ntt-local.content-share
+application/vnd.ntt-local.file-transfer
+application/vnd.ntt-local.ogw_remote-access
+application/vnd.ntt-local.sip-ta_remote
+application/vnd.ntt-local.sip-ta_tcp_stream
application/vnd.oasis.opendocument.chart odc
+application/vnd.oasis.opendocument.chart-template otc
application/vnd.oasis.opendocument.database odb
application/vnd.oasis.opendocument.formula odf
+application/vnd.oasis.opendocument.formula-template
application/vnd.oasis.opendocument.graphics odg
application/vnd.oasis.opendocument.graphics-template otg
application/vnd.oasis.opendocument.image odi
+application/vnd.oasis.opendocument.image-template oti
application/vnd.oasis.opendocument.presentation odp
application/vnd.oasis.opendocument.presentation-template otp
application/vnd.oasis.opendocument.spreadsheet ods
@@ -312,37 +1027,261 @@ application/vnd.oasis.opendocument.text odt
application/vnd.oasis.opendocument.text-master odm
application/vnd.oasis.opendocument.text-template ott
application/vnd.oasis.opendocument.text-web oth
+application/vnd.obn
+application/vnd.ocf+cbor
+application/vnd.oci.image.manifest.v1+json
+application/vnd.oftn.l10n+json
+application/vnd.oipf.contentaccessdownload+xml
+application/vnd.oipf.contentaccessstreaming+xml
+application/vnd.oipf.cspg-hexbinary
+application/vnd.oipf.dae.svg+xml
+application/vnd.oipf.dae.xhtml+xml
+application/vnd.oipf.mippvcontrolmessage+xml
+application/vnd.oipf.pae.gem
+application/vnd.oipf.spdiscovery+xml
+application/vnd.oipf.spdlist+xml
+application/vnd.oipf.ueprofile+xml
+application/vnd.oipf.userprofile+xml
+application/vnd.olpc-sugar xo
+application/vnd.oma.bcast.associated-procedure-parameter+xml
+application/vnd.oma.bcast.drm-trigger+xml
+application/vnd.oma.bcast.imd+xml
+application/vnd.oma.bcast.ltkm
+application/vnd.oma.bcast.notification+xml
+application/vnd.oma.bcast.provisioningtrigger
+application/vnd.oma.bcast.sgboot
+application/vnd.oma.bcast.sgdd+xml
+application/vnd.oma.bcast.sgdu
+application/vnd.oma.bcast.simple-symbol-container
+application/vnd.oma.bcast.smartcard-trigger+xml
+application/vnd.oma.bcast.sprov+xml
+application/vnd.oma.bcast.stkm
+application/vnd.oma.cab-address-book+xml
+application/vnd.oma.cab-feature-handler+xml
+application/vnd.oma.cab-pcc+xml
+application/vnd.oma.cab-subs-invite+xml
+application/vnd.oma.cab-user-prefs+xml
+application/vnd.oma.dcd
+application/vnd.oma.dcdc
+application/vnd.oma.dd2+xml dd2
+application/vnd.oma.drm.risd+xml
+application/vnd.omads-email+xml
+application/vnd.omads-file+xml
+application/vnd.omads-folder+xml
+application/vnd.oma.group-usage-list+xml
+application/vnd.omaloc-supl-init
+application/vnd.oma.lwm2m+json
+application/vnd.oma.lwm2m+tlv
+application/vnd.oma.pal+xml
+application/vnd.oma.poc.detailed-progress-report+xml
+application/vnd.oma.poc.final-report+xml
+application/vnd.oma.poc.groups+xml
+application/vnd.oma.poc.invocation-descriptor+xml
+application/vnd.oma.poc.optimized-progress-report+xml
+application/vnd.oma.push
+application/vnd.oma.scidm.messages+xml
+application/vnd.oma-scws-config
+application/vnd.oma-scws-http-request
+application/vnd.oma-scws-http-response
+application/vnd.oma.xcap-directory+xml
+application/vnd.onepager tam
+application/vnd.onepagertamp tamp
+application/vnd.onepagertamx tamx
+application/vnd.onepagertat tat
+application/vnd.onepagertatp tatp
+application/vnd.onepagertatx tatx
+application/vnd.openblox.game-binary obg
+application/vnd.openblox.game+xml obgx
+application/vnd.openeye.oeb oeb
+application/vnd.openofficeorg.extension oxt
+application/vnd.openstreetmap.data+xml osm
+application/vnd.openxmlformats-officedocument.custom-properties+xml
+application/vnd.openxmlformats-officedocument.customXmlProperties+xml
+application/vnd.openxmlformats-officedocument.drawingml.chartshapes+xml
+application/vnd.openxmlformats-officedocument.drawingml.chart+xml
+application/vnd.openxmlformats-officedocument.drawingml.diagramColors+xml
+application/vnd.openxmlformats-officedocument.drawingml.diagramData+xml
+application/vnd.openxmlformats-officedocument.drawingml.diagramLayout+xml
+application/vnd.openxmlformats-officedocument.drawingml.diagramStyle+xml
+application/vnd.openxmlformats-officedocument.drawing+xml
+application/vnd.openxmlformats-officedocument.extended-properties+xml
+application/vnd.openxmlformats-officedocument.presentationml.commentAuthors+xml
+application/vnd.openxmlformats-officedocument.presentationml.comments+xml
+application/vnd.openxmlformats-officedocument.presentationml.handoutMaster+xml
+application/vnd.openxmlformats-officedocument.presentationml.notesMaster+xml
+application/vnd.openxmlformats-officedocument.presentationml.notesSlide+xml
application/vnd.openxmlformats-officedocument.presentationml.presentation pptx
+application/vnd.openxmlformats-officedocument.presentationml.presentation.main+xml
+application/vnd.openxmlformats-officedocument.presentationml.presProps+xml
application/vnd.openxmlformats-officedocument.presentationml.slide sldx
+application/vnd.openxmlformats-officedocument.presentationml.slideLayout+xml
+application/vnd.openxmlformats-officedocument.presentationml.slideMaster+xml
application/vnd.openxmlformats-officedocument.presentationml.slideshow ppsx
+application/vnd.openxmlformats-officedocument.presentationml.slideshow.main+xml
+application/vnd.openxmlformats-officedocument.presentationml.slideUpdateInfo+xml
+application/vnd.openxmlformats-officedocument.presentationml.slide+xml
+application/vnd.openxmlformats-officedocument.presentationml.tableStyles+xml
+application/vnd.openxmlformats-officedocument.presentationml.tags+xml
application/vnd.openxmlformats-officedocument.presentationml.template potx
+application/vnd.openxmlformats-officedocument.presentationml.template.main+xml
+application/vnd.openxmlformats-officedocument.presentationml.viewProps+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.calcChain+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.chartsheet+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.comments+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.connections+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.dialogsheet+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.externalLink+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.pivotCacheDefinition+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.pivotCacheRecords+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.pivotTable+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.queryTable+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.revisionHeaders+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.revisionLog+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.sharedStrings+xml
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet xlsx
+application/vnd.openxmlformats-officedocument.spreadsheetml.sheet.main+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.sheetMetadata+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.styles+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.tableSingleCells+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.table+xml
application/vnd.openxmlformats-officedocument.spreadsheetml.template xltx
+application/vnd.openxmlformats-officedocument.spreadsheetml.template.main+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.userNames+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.volatileDependencies+xml
+application/vnd.openxmlformats-officedocument.spreadsheetml.worksheet+xml
+application/vnd.openxmlformats-officedocument.themeOverride+xml
+application/vnd.openxmlformats-officedocument.theme+xml
+application/vnd.openxmlformats-officedocument.vmlDrawing
+application/vnd.openxmlformats-officedocument.wordprocessingml.comments+xml
application/vnd.openxmlformats-officedocument.wordprocessingml.document docx
+application/vnd.openxmlformats-officedocument.wordprocessingml.document.glossary+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.document.main+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.endnotes+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.fontTable+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.footer+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.footnotes+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.numbering+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.settings+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.styles+xml
application/vnd.openxmlformats-officedocument.wordprocessingml.template dotx
-application/vnd.osa.netdeploy
-application/vnd.palm
-application/vnd.pg.format
-application/vnd.pg.osasli
-application/vnd.powerbuilder6
+application/vnd.openxmlformats-officedocument.wordprocessingml.template.main+xml
+application/vnd.openxmlformats-officedocument.wordprocessingml.webSettings+xml
+application/vnd.openxmlformats-package.core-properties+xml
+application/vnd.openxmlformats-package.digital-signature-xmlsignature+xml
+application/vnd.openxmlformats-package.relationships+xml
+application/vnd.oracle.resource+json
+application/vnd.orange.indata
+application/vnd.osa.netdeploy ndc
+application/vnd.osgeo.mapguide.package mgp
+application/vnd.osgi.bundle
+application/vnd.osgi.dp dp
+application/vnd.osgi.subsystem esa
+application/vnd.otps.ct-kip+xml
+application/vnd.oxli.countgraph oxlicg
+application/vnd.pagerduty+json
+application/vnd.palm prc pdb pqa oprc
+application/vnd.panoply plp
+application/vnd.paos+xml
+application/vnd.patentdive dive
+application/vnd.patientecommsdoc
+application/vnd.pawaafile paw
+application/vnd.pcos
+application/vnd.pg.format str
+application/vnd.pg.osasli ei6
+application/vnd.piaccess.application-license pil
+application/vnd.picsel efif
+application/vnd.pmi.widget wg
+application/vnd.poc.group-advertisement+xml
+application/vnd.pocketlearn plf
+application/vnd.powerbuilder6 pbd
application/vnd.powerbuilder6-s
application/vnd.powerbuilder7
-application/vnd.powerbuilder7-s
application/vnd.powerbuilder75
application/vnd.powerbuilder75-s
-application/vnd.previewsystems.box
-application/vnd.publishare-delta-tree
-application/vnd.pvi.ptid1
+application/vnd.powerbuilder7-s
+application/vnd.preminet preminet
+application/vnd.previewsystems.box box vbox
+application/vnd.proteus.magazine mgz
+application/vnd.psfs psfs
+application/vnd.publishare-delta-tree qps
+application/vnd.pvi.ptid1 ptid
+application/vnd.pwg-multiplexed
application/vnd.pwg-xhtml-print+xml
+application/vnd.qualcomm.brew-app-res bar
+application/vnd.quarantainenet
+application/vnd.Quark.QuarkXPress qxd qxt qwd qwt qxl qxb
+application/vnd.quobject-quoxdocument quox quiz
+application/vnd.radisys.moml+xml
+application/vnd.radisys.msml-audit-conf+xml
+application/vnd.radisys.msml-audit-conn+xml
+application/vnd.radisys.msml-audit-dialog+xml
+application/vnd.radisys.msml-audit-stream+xml
+application/vnd.radisys.msml-audit+xml
+application/vnd.radisys.msml-conf+xml
+application/vnd.radisys.msml-dialog-base+xml
+application/vnd.radisys.msml-dialog-fax-detect+xml
+application/vnd.radisys.msml-dialog-fax-sendrecv+xml
+application/vnd.radisys.msml-dialog-group+xml
+application/vnd.radisys.msml-dialog-speech+xml
+application/vnd.radisys.msml-dialog-transform+xml
+application/vnd.radisys.msml-dialog+xml
+application/vnd.radisys.msml+xml
+application/vnd.rainstor.data tree
application/vnd.rapid
+application/vnd.rar rar
+application/vnd.realvnc.bed bed
+application/vnd.recordare.musicxml mxl
+application/vnd.recordare.musicxml+xml
+application/vnd.RenLearn.rlprint
+application/vnd.restful+json
+application/vnd.rig.cryptonote cryptonote
application/vnd.rim.cod cod
+application/vnd.route66.link66+xml link66
+application/vnd.rs-274x
+application/vnd.ruckus.download
application/vnd.s3sms
-application/vnd.seemail
-application/vnd.shana.informed.formdata
-application/vnd.shana.informed.formtemplate
-application/vnd.shana.informed.interchange
-application/vnd.shana.informed.package
-application/vnd.smaf mmf
+application/vnd.sailingtracker.track st
+application/vnd.sar SAR
+application/vnd.sbm.cid
+application/vnd.sbm.mid2
+application/vnd.scribus scd sla slaz
+application/vnd.sealed.3df s3df
+application/vnd.sealed.csf scsf
+application/vnd.sealed.doc sdoc sdo s1w
+application/vnd.sealed.eml seml sem
+application/vnd.sealedmedia.softseal.html stml s1h
+application/vnd.sealedmedia.softseal.pdf spdf spd s1a
+application/vnd.sealed.mht smht smh
+application/vnd.sealed.net
+application/vnd.sealed.ppt sppt s1p
+application/vnd.sealed.tiff stif
+application/vnd.sealed.xls sxls sxl s1e
+application/vnd.seemail see
+application/vnd.sema sema
+application/vnd.semd semd
+application/vnd.semf semf
+application/vnd.shade-save-file ssv
+application/vnd.shana.informed.formdata ifm
+application/vnd.shana.informed.formtemplate itp
+application/vnd.shana.informed.interchange iif
+application/vnd.shana.informed.package ipk
+application/vnd.shootproof+json
+application/vnd.shopkick+json
+application/vnd.shp shp
+application/vnd.shx shx
+application/vnd.sigrok.session sr
+application/vnd.SimTech-MindMapper twd twds
+application/vnd.siren+json
+application/vnd.smaf mmf
+application/vnd.smart.notebook notebook
+application/vnd.smart.teacher teacher
+application/vnd.snesdev-page-table ptrom pt
+application/vnd.software602.filler.form+xml fo
+application/vnd.software602.filler.form-xml-zip zfo
+application/vnd.solent.sdkm+xml sdkm sdkd
+application/vnd.spotfire.dxp dxp
+application/vnd.spotfire.sfs sfs
+application/vnd.sqlite3 sqlite sqlite3
application/vnd.sss-cod
application/vnd.sss-dtf
application/vnd.sss-ntf
@@ -350,10 +1289,13 @@ application/vnd.stardivision.calc sdc
application/vnd.stardivision.chart sds
application/vnd.stardivision.draw sda
application/vnd.stardivision.impress sdd
-application/vnd.stardivision.math sdf
+application/vnd.stardivision.math
application/vnd.stardivision.writer sdw
application/vnd.stardivision.writer-global sgl
+application/vnd.stepmania.package smzip
+application/vnd.stepmania.stepchart sm
application/vnd.street-stream
+application/vnd.sun.wadl+xml wadl
application/vnd.sun.xml.calc sxc
application/vnd.sun.xml.calc.template stc
application/vnd.sun.xml.draw sxd
@@ -364,15 +1306,39 @@ application/vnd.sun.xml.math sxm
application/vnd.sun.xml.writer sxw
application/vnd.sun.xml.writer.global sxg
application/vnd.sun.xml.writer.template stw
+application/vnd.sus-calendar sus susp
application/vnd.svd
application/vnd.swiftview-ics
application/vnd.symbian.install sis
-application/vnd.tcpdump.pcap cap pcap
-application/vnd.triscape.mxs
-application/vnd.trueapp
+application/vnd.syncml.dmddf+wbxml
+application/vnd.syncml.dmddf+xml ddf
+application/vnd.syncml.dm.notification
+application/vnd.syncml.dmtnds+wbxml
+application/vnd.syncml.dmtnds+xml
+application/vnd.syncml.dm+wbxml bdm
+application/vnd.syncml.dm+xml xdm
+application/vnd.syncml.ds.notification
+application/vnd.syncml+xml xsm
+application/vnd.tableschema+json
+application/vnd.tao.intent-module-archive tao
+application/vnd.tcpdump.pcap pcap cap dmp
+application/vnd.theqvd qvd
+application/vnd.think-cell.ppttc+json ppttc
+application/vnd.tmd.mediaflex.api+xml
+application/vnd.tml vfr viaframe
+application/vnd.tmobile-livetv tmo
+application/vnd.trid.tpt tpt
+application/vnd.tri.onesource
+application/vnd.triscape.mxs mxs
+application/vnd.trueapp tra
application/vnd.truedoc
application/vnd.tve-trigger
-application/vnd.ufdl
+application/vnd.ubisoft.webplayer
+application/vnd.ufdl ufdl ufd frm
+application/vnd.uiq.theme utz
+application/vnd.umajin umj
+application/vnd.unity unityweb
+application/vnd.uoml+xml uoml uo
application/vnd.uplanet.alert
application/vnd.uplanet.alert-wbxml
application/vnd.uplanet.bearer-choice
@@ -382,55 +1348,113 @@ application/vnd.uplanet.cacheop-wbxml
application/vnd.uplanet.channel
application/vnd.uplanet.channel-wbxml
application/vnd.uplanet.list
-application/vnd.uplanet.list-wbxml
application/vnd.uplanet.listcmd
application/vnd.uplanet.listcmd-wbxml
+application/vnd.uplanet.list-wbxml
application/vnd.uplanet.signal
-application/vnd.vcx
-application/vnd.vectorworks
-application/vnd.vidsoft.vidconference
-application/vnd.visio vsd vst vsw vss
+application/vnd.uri-map urim urimap
+application/vnd.valve.source.material vmt
+application/vnd.vcx vcx
+application/vnd.vd-study mxi study-inter model-inter
+application/vnd.vectorworks vwx
+application/vnd.vel+json
+application/vnd.verimatrix.vcas
+application/vnd.veryant.thin istc isws
+application/vnd.ves.encrypted VES
+application/vnd.vidsoft.vidconference vsc
+application/vnd.visio vsd vst vsw vss
+application/vnd.visionary vis
application/vnd.vividence.scriptfile
-application/vnd.wap.sic
-application/vnd.wap.slc
-application/vnd.wap.wbxml wbxml
-application/vnd.wap.wmlc wmlc
-application/vnd.wap.wmlscriptc wmlsc
-application/vnd.webturbo
-application/vnd.wordperfect wpd
+application/vnd.vsf vsf
+application/vnd.wap.sic sic
+application/vnd.wap.slc slc
+application/vnd.wap.wbxml wbxml
+application/vnd.wap.wmlc wmlc
+application/vnd.wap.wmlscriptc wmlsc
+application/vnd.webturbo wtb
+application/vnd.wfa.p2p p2p
+application/vnd.wfa.wsc wsc
+application/vnd.windows.devicepairing
+application/vnd.wmc wmc
+application/vnd.wmf.bootstrap
+application/vnd.wolfram.mathematica nb
+application/vnd.wolfram.mathematica.package m
+application/vnd.wolfram.player nbp
+application/vnd.wordperfect wpd
application/vnd.wordperfect5.1 wp5
+application/vnd.wqd wqd
application/vnd.wrq-hp3000-labelled
-application/vnd.wt.stf
-application/vnd.xara
-application/vnd.xfdl
-application/vnd.yellowriver-custom-menu
-application/zlib
+application/vnd.wt.stf stf
+application/vnd.wv.csp+wbxml wv
+application/vnd.wv.csp+xml
+application/vnd.wv.ssp+xml
+application/vnd.xacml+json
+application/vnd.xara xar
+application/vnd.xfdl xfdl xfd
+application/vnd.xfdl.webform
+application/vnd.xmi+xml
+application/vnd.xmpie.cpkg cpkg
+application/vnd.xmpie.dpkg dpkg
+application/vnd.xmpie.plan
+application/vnd.xmpie.ppkg ppkg
+application/vnd.xmpie.xlim xlim
+application/vnd.yamaha.hv-dic hvd
+application/vnd.yamaha.hv-script hvs
+application/vnd.yamaha.hv-voice hvp
+application/vnd.yamaha.openscoreformat osf
+application/vnd.yamaha.openscoreformat.osfpvg+xml
+application/vnd.yamaha.remote-setup
+application/vnd.yamaha.smaf-audio saf
+application/vnd.yamaha.smaf-phrase spf
+application/vnd.yamaha.through-ngn
+application/vnd.yamaha.tunnel-udpencap
+application/vnd.yaoweme yme
+application/vnd.yellowriver-custom-menu cmp
+application/vnd.zul zir zirz
+application/vnd.zzazz.deck+xml zaz
+application/voicexml+xml vxml
+application/voucher-cms+json vcj
+application/vq-rtcp-xr
+application/wasm wasm
+application/watcherinfo+xml wif
+application/webpush-options+json
+application/whoispp-query
+application/whoispp-response
+application/widget wgt
+application/wita
+application/wordperfect5.1
+application/wsdl+xml wsdl
+application/wspolicy+xml wspolicy
application/x-123 wk
+application/x400-bp
application/x-7z-compressed 7z
application/x-abiword abw
+application/xacml+xml
application/x-apple-diskimage dmg
application/x-bcpio bcpio
application/x-bittorrent torrent
-application/x-cab cab
-application/x-cbr cbr
-application/x-cbz cbz
+application/xcap-att+xml xav
+application/xcap-caps+xml xca
+application/xcap-diff+xml xdf
+application/xcap-el+xml xel
+application/xcap-error+xml xer
+application/xcap-ns+xml xns
application/x-cdf cdf cda
application/x-cdlink vcd
-application/x-chess-pgn pgn
application/x-comsol mph
+application/xcon-conference-info-diff+xml
+application/xcon-conference-info+xml
application/x-core
application/x-cpio cpio
application/x-csh csh
-application/x-debian-package deb udeb
application/x-director dcr dir dxr
-application/x-dms dms
application/x-doom wad
application/x-dvi dvi
+application/xenc+xml
application/x-executable
application/x-font pfa pfb gsf
application/x-font-pcf pcf pcf.Z
application/x-freemind mm
-application/x-futuresplash spl
application/x-ganttproject gan
application/x-gnumeric gnumeric
application/x-go-sgf sgf
@@ -438,52 +1462,54 @@ application/x-graphing-calculator gcf
application/x-gtar gtar
application/x-gtar-compressed tgz taz
application/x-hdf hdf
+application/xhtml+xml xhtml xhtm xht
+
#application/x-httpd-eruby rhtml
#application/x-httpd-php phtml pht php
-#application/x-httpd-php-source phps
#application/x-httpd-php3 php3
#application/x-httpd-php3-preprocessed php3p
#application/x-httpd-php4 php4
#application/x-httpd-php5 php5
+#application/x-httpd-php-source phps
+
application/x-hwp hwp
application/x-ica ica
application/x-info info
application/x-internet-signup ins isp
application/x-iphone iii
application/x-iso9660-image iso
-application/x-jam jam
application/x-java-applet
application/x-java-bean
application/x-java-jnlp-file jnlp
application/x-jmol jmz
-application/x-kchart chrt
application/x-kdelnk
application/x-killustrator kil
-application/x-koan skp skd skt skm
-application/x-kpresenter kpr kpt
-application/x-kspread ksp
-application/x-kword kwd kwt
application/x-latex latex
application/x-lha lha
+application/xliff+xml xlf
application/x-lyx lyx
application/x-lzh lzh
application/x-lzx lzx
application/x-maker frm maker frame fm fb book fbdoc
-application/x-mif mif
-application/x-mpegURL m3u8
+application/xml xml
+application/xml-dtd dtd mod
+application/xml-external-parsed-entity ent
+application/xml-patch+xml
+application/xmpp+xml
application/x-ms-application application
+application/x-msdos-program com exe bat dll
+application/x-msi msi
application/x-ms-manifest manifest
application/x-ms-wmd wmd
application/x-ms-wmz wmz
-application/x-msdos-program com exe bat dll
-application/x-msi msi
application/x-netcdf nc
application/x-ns-proxy-autoconfig pac
application/x-nwc nwc
application/x-object o
+application/xop+xml xop
application/x-oz-application oza
application/x-pkcs7-certreqresp p7r
-application/x-pkcs7-crl crl
+application/x-pki-message
application/x-python-code pyc pyo
application/x-qgis qgs shp shx
application/x-quicktimeplayer qtl
@@ -497,74 +1523,213 @@ application/x-scilab-xcos xcos
application/x-sh sh
application/x-shar shar
application/x-shellscript
-application/x-shockwave-flash swf swfl
application/x-silverlight scr
-application/x-sql sql
+application/xslt+xml xsl xslt
+application/xspf+xml xspf
application/x-stuffit sit sitx
application/x-sv4cpio sv4cpio
application/x-sv4crc sv4crc
application/x-tar tar
application/x-tcl tcl
application/x-tex-gf gf
-application/x-tex-pk pk
application/x-texinfo texinfo texi
+application/x-tex-pk pk
application/x-trash ~ % bak old sik
-application/x-troff t tr roff
application/x-troff-man man
application/x-troff-me me
application/x-troff-ms ms
application/x-ustar ustar
application/x-videolan
+application/xv+xml mxml xhvml xvml xvm
application/x-wais-source src
application/x-wingz wz
+application/x-www-form-urlencoded
application/x-x509-ca-cert crt
+application/x-x509-ca-ra-cert
+application/x-x509-next-ca-cert
application/x-xcf xcf
application/x-xfig fig
application/x-xpinstall xpi
application/x-xz xz
+application/yang yang
+application/yang-data+json
+application/yang-data+xml
+application/yang-patch+json
+application/yang-patch+xml
+application/yin+xml yin
+application/zip zip
+application/zlib
+application/zstd zst
-audio/32kadpcm
+audio/1d-interleaved-parityfec
+audio/32kadpcm 726
audio/3gpp
-audio/amr amr
-audio/amr-wb awb
+audio/3gpp2
+audio/aac adts aac ass
+audio/ac3 ac3
+audio/AMR amr AMR
+audio/AMR-WB awb AWB
+audio/amr-wb+
audio/annodex axa
+audio/aptx
+audio/asc acn
+audio/ATRAC3 at3 aa3 omg
+audio/ATRAC-ADVANCED-LOSSLESS aal
+audio/ATRAC-X atx
audio/basic au snd
+audio/BV16
+audio/BV32
+audio/clearmode
+audio/CN
audio/csound csd orc sco
+audio/DAT12
+audio/dls dls
+audio/dsr-es201108
+audio/dsr-es202050
+audio/dsr-es202211
+audio/dsr-es202212
+audio/DV
+audio/DVI4
+audio/eac3
+audio/encaprtp
+audio/EVRC evc
+audio/EVRC-QCP qcp QCP
+audio/EVRC0
+audio/EVRC1
+audio/EVRCB evb
+audio/EVRCB0
+audio/EVRCB1
+audio/EVRCNW enw
+audio/EVRCNW0
+audio/EVRCNW1
+audio/EVRC-QCP
+audio/EVRCWB evw
+audio/EVRCWB0
+audio/EVRCWB1
+audio/EVS
+audio/example
audio/flac flac
+audio/flexfec
+audio/fwdred
+audio/G711-0
+audio/G719
+audio/G722
audio/g.722.1
-audio/l16
-audio/midi mid midi kar
+audio/G7221
+audio/G723
+audio/G726-16
+audio/G726-24
+audio/G726-32
+audio/G726-40
+audio/G728
+audio/G729
+audio/G7291
+audio/G729D
+audio/G729E
+audio/GSM
+audio/GSM-EFR
+audio/GSM-HR-08
+audio/iLBC lbc
+audio/ip-mr_v2.5
+audio/L16 l16
+audio/L20
+audio/L24
+audio/L8
+audio/LPC
+audio/MELP
+audio/MELP1200
+audio/MELP2400
+audio/MELP600
+audio/mhas mhas
+audio/mobile-xmf mxmf
+audio/mp4
audio/mp4a-latm
+audio/MP4A-LATM
+audio/MPA
audio/mpa-robust
-audio/mpeg mpga mpega mp2 mp3 m4a
+audio/mpeg mpga mpega mp1 mp2 mp3 m4a
+audio/mpeg4-generic
audio/mpegurl m3u
audio/ogg oga ogg opus spx
+audio/opus
audio/parityfec
-audio/prs.sid sid
+audio/PCMA
+audio/PCMA-WB
+audio/PCMU
+audio/PCMU-WB
+audio/prs.sid sid psid
+audio/qcelp
+audio/raptorfec
+audio/RED
+audio/rtp-enc-aescm128
+audio/rtploopback
+audio/rtp-midi
+audio/rtx
+audio/SMV smv
+audio/SMV0
+audio/SMV-QCP
+audio/sofa sofa
+audio/speex
+audio/sp-midi mid
+audio/t140c
+audio/t38
audio/telephone-event
+audio/TETRA_ACELP
+audio/TETRA_ACELP_BB
audio/tone
+audio/TSVCIS
+audio/UEMCLIP
+audio/ulpfec
+audio/usac loas xhe
+audio/VDVI
+audio/VMR-WB
+audio/vnd.3gpp.iufp
+audio/vnd.4SB
+audio/vnd.audiokoz koz
+audio/vnd.CELP
audio/vnd.cisco.nse
+audio/vnd.cmles.radio-events
audio/vnd.cns.anp1
audio/vnd.cns.inf1
-audio/vnd.digital-winds
-audio/vnd.everad.plj
-audio/vnd.lucent.voice
-audio/vnd.nortel.vbk
-audio/vnd.nuera.ecelp4800
-audio/vnd.nuera.ecelp7470
-audio/vnd.nuera.ecelp9600
+audio/vnd.dece.audio uva uvva
+audio/vnd.digital-winds eol
+audio/vnd.dlna.adts
+audio/vnd.dolby.heaac.1
+audio/vnd.dolby.heaac.2
+audio/vnd.dolby.mlp mlp
+audio/vnd.dolby.mps
+audio/vnd.dolby.pl2
+audio/vnd.dolby.pl2x
+audio/vnd.dolby.pl2z
+audio/vnd.dolby.pulse.1
+audio/vnd.dra
+audio/vnd.dts dts
+audio/vnd.dts.hd dtshd
+audio/vnd.dts.uhd
+audio/vnd.dvb.file
+audio/vnd.everad.plj plj
+audio/vnd.hns.audio
+audio/vnd.lucent.voice lvp
+audio/vnd.ms-playready.media.pya pya
+audio/vnd.nokia.mobile-xmf
+audio/vnd.nortel.vbk vbk
+audio/vnd.nuera.ecelp4800 ecelp4800
+audio/vnd.nuera.ecelp7470 ecelp7470
+audio/vnd.nuera.ecelp9600 ecelp9600
audio/vnd.octel.sbc
-audio/vnd.qcelp
+audio/vnd.presonus.multitrack multitrack
audio/vnd.rhetorex.32kadpcm
+audio/vnd.rip rip
+audio/vnd.sealedmedia.softseal.mpeg smp3 smp s1m
audio/vnd.vmx.cvsd
+audio/vorbis
+audio/vorbis-config
audio/x-aiff aif aiff aifc
audio/x-gsm gsm
-audio/x-mpegurl m3u
-audio/x-ms-wma wma
audio/x-ms-wax wax
-audio/x-pn-realaudio-plugin
+audio/x-ms-wma wma
audio/x-pn-realaudio ra rm ram
-audio/x-realaudio ra
+audio/x-pn-realaudio-plugin
audio/x-scpls pls
audio/x-sd2 sd2
audio/x-wav wav
@@ -574,7 +1739,7 @@ chemical/x-cache cac cache
chemical/x-cache-csf csf
chemical/x-cactvs-binary cbin cascii ctab
chemical/x-cdx cdx
-chemical/x-cerius cer
+chemical/x-cerius
chemical/x-chem3d c3d
chemical/x-chemdraw chm
chemical/x-cif cif
@@ -600,7 +1765,7 @@ chemical/x-isostar istr ist
chemical/x-jcamp-dx jdx dx
chemical/x-kinemage kin
chemical/x-macmolecule mcm
-chemical/x-macromodel-input mmd mmod
+chemical/x-macromodel-input mmod
chemical/x-mdl-molfile mol
chemical/x-mdl-rdfile rd
chemical/x-mdl-rxnfile rxn
@@ -615,10 +1780,10 @@ chemical/x-mopac-input mop mopcrt mpc zmt
chemical/x-mopac-out moo
chemical/x-mopac-vib mvb
chemical/x-ncbi-asn1 asn
-chemical/x-ncbi-asn1-ascii prt ent
+chemical/x-ncbi-asn1-ascii prt
chemical/x-ncbi-asn1-binary val aso
chemical/x-ncbi-asn1-spec asn
-chemical/x-pdb pdb ent
+chemical/x-pdb pdb
chemical/x-rosdal ros
chemical/x-swissprot sw
chemical/x-vamas-iso14976 vms
@@ -627,42 +1792,86 @@ chemical/x-xtel xtel
chemical/x-xyz xyz
font/collection ttc
-font/otf ttf otf
-font/sfnt ttf otf
-font/ttf ttf otf
+font/otf otf
+font/sfnt
+font/ttf ttf
font/woff woff
font/woff2 woff2
-image/cgm
+image/aces exr
+image/avci avci
+image/avcs avcs
+image/bmp bmp
+image/cgm cgm
+image/dicom-rle drle
+image/emf emf
+image/example
+image/fits fits fit fts
image/g3fax
image/gif gif
+image/heic heic
+image/heic-sequence heics
+image/heif heif
+image/heif-sequence heifs
+image/hej2k hej2
+image/hsj2 hsj2
image/ief ief
+image/jls jls
image/jp2 jp2 jpg2
-image/jpeg jpeg jpg jpe
-image/jpm jpm
+image/jpeg jpeg jpg jpe jfif
+image/jph jph
+image/jphc jhc jphc
+image/jpm jpm jpgm
image/jpx jpx jpf
+image/jxr jxr
+image/jxrA jxra
+image/jxrS jxrs
+image/jxs jxs
+image/jxsc jxsc
+image/jxsi jxsi
+image/jxss jxss
+image/ktx ktx
+image/ktx2 ktx2
image/naplps
-image/pcx pcx
image/png png
-image/prs.btif
-image/prs.pti
+image/prs.btif btif btf
+image/prs.pti pti
+image/pwg-raster
image/svg+xml svg svgz
+image/t38 t38 T38
image/tiff tiff tif
+image/tiff-fx tfx
+image/vnd.adobe.photoshop psd
+image/vnd.airzip.accelerator.azv azv
image/vnd.cns.inf2
+image/vnd.dece.graphic uvi uvvi uvg uvvg
image/vnd.djvu djvu djv
-image/vnd.dwg
-image/vnd.dxf
-image/vnd.fastbidsheet
-image/vnd.fpx
-image/vnd.fst
-image/vnd.fujixerox.edmics-mmr
-image/vnd.fujixerox.edmics-rlc
+image/vnd.dvb.subtitle
+image/vnd.dwg dwg
+image/vnd.dxf dxf
+image/vnd.fastbidsheet fbs
+image/vnd.fpx fpx
+image/vnd.fst fst
+image/vnd.fujixerox.edmics-mmr mmr
+image/vnd.fujixerox.edmics-rlc rlc
+image/vnd.globalgraphics.pgb PGB pgb
image/vnd.microsoft.icon ico
image/vnd.mix
+image/vnd.mozilla.apng apng
+image/vnd.ms-modi mdi
image/vnd.net-fpx
+image/vnd.pco.b16 b16
+image/vnd.radiance hdr rgbe xyze
+image/vnd.sealedmedia.softseal.gif sgif sgi s1g
+image/vnd.sealedmedia.softseal.jpg sjpg sjp s1j
+image/vnd.sealed.png spng spn s1n
image/vnd.svf
+image/vnd.tencent.tap tap
+image/vnd.valve.source.texture vtf
image/vnd.wap.wbmp wbmp
-image/vnd.xiff
+image/vnd.xiff xif
+image/vnd.zbrush.pcx pcx
+image/wmf wmf
image/x-canon-cr2 cr2
image/x-canon-crw crw
image/x-cmu-raster ras
@@ -674,10 +1883,8 @@ image/x-epson-erf erf
image/x-icon
image/x-jg art
image/x-jng jng
-image/x-ms-bmp bmp
image/x-nikon-nef nef
image/x-olympus-orf orf
-image/x-photoshop psd
image/x-portable-anymap pnm
image/x-portable-bitmap pbm
image/x-portable-graymap pgm
@@ -687,35 +1894,61 @@ image/x-xbitmap xbm
image/x-xpixmap xpm
image/x-xwindowdump xwd
-inode/chardevice
inode/blockdevice
-inode/directory-locked
+inode/chardevice
inode/directory
+inode/directory-locked
inode/fifo
inode/socket
+message/CPIM
message/delivery-status
message/disposition-notification
+message/example
message/external-body
+message/feedback-report
+message/global u8msg
+message/global-delivery-status u8dsn
+message/global-disposition-notification u8mdn
+message/global-headers u8hdr
message/http
-message/s-http
-message/news
+message/imdn+xml
message/partial
-message/rfc822 eml
+message/rfc822 eml mail art
+message/s-http
+message/sip
+message/sipfrag
+message/tracking-status
+message/vnd.wfa.wsc
+model/3mf
+model/example
+model/gltf-binary glb
+model/gltf+json gltf
model/iges igs iges
model/mesh msh mesh silo
-model/vnd.dwf
+model/mtl mtl
+model/obj obj
+model/stl stl
+model/vnd.collada+xml dae
+model/vnd.dwf dwf
model/vnd.flatland.3dml
-model/vnd.gdl
+model/vnd.gdl gdl gsm win dor lmp rsm msm ism
model/vnd.gs-gdl
-model/vnd.gtw
-model/vnd.mts
-model/vnd.vtu
+model/vnd.gtw gtw
+model/vnd.moml+xml moml
+model/vnd.mts mts
+model/vnd.opengex ogex
+model/vnd.parasolid.transmit.binary x_b xmt_bin
+model/vnd.parasolid.transmit.text x_t xmt_txt
+model/vnd.rosette.annotated-data-model
+model/vnd.usdz+zip usdz
+model/vnd.valve.source.compiled-map bsp
+model/vnd.vtu vtu
model/vrml wrl vrml
-model/x3d+vrml x3dv
+model/x3d+fastinfoset x3db
+model/x3d+vrml x3dv x3dvz
model/x3d+xml x3d
-model/x3d+binary x3db
multipart/alternative
multipart/appledouble
@@ -725,72 +1958,114 @@ multipart/encrypted
multipart/form-data
multipart/header-set
multipart/mixed
+multipart/multilingual
multipart/parallel
multipart/related
multipart/report
multipart/signed
-multipart/voice-message
+multipart/vnd.bint.med-plus bmed
+multipart/voice-message vpm
+multipart/x-mixed-replace
-text/cache-manifest appcache
-text/calendar ics icz
+text/1d-interleaved-parityfec
+text/cache-manifest appcache manifest
+text/calendar ics ifb
text/css css
text/csv csv
-text/directory
+text/csv-schema csvs
+text/dns soa zone
+text/encaprtp
text/english
text/enriched
+text/example
+text/flexfec
+text/fwdred
+text/grammar-ref-list
text/h323 323
text/html html htm shtml
text/iuls uls
-text/mathml mml
-text/markdown md markdown
+text/jcr-cnd cnd
+text/markdown md markdown
+text/mizar miz
+text/n3 n3
+text/parameters
text/parityfec
-text/plain asc txt text pot brf srt
-text/prs.lines.tag
+text/plain txt text pot brf srt
+text/provenance-notation provn
+text/prs.fallenstein.rst rst
+text/prs.lines.tag tag dsc
+text/prs.prop.logic
+text/raptorfec
+text/RED
text/rfc822-headers
text/richtext rtx
text/rtf
-text/scriptlet sct wsc
+text/rtp-enc-aescm128
+text/rtploopback
+text/rtx
+text/scriptlet sct
+text/sgml sgml sgm
+text/strings
text/t140
-text/texmacs tm
text/tab-separated-values tsv
+text/texmacs tm
+text/troff t tr roff
text/turtle ttl
-text/uri-list
+text/ulpfec
+text/uri-list uris uri
text/vcard vcf vcard
-text/vnd.abc
-text/vnd.curl
-text/vnd.debian.copyright
-text/vnd.DMClientScript
+text/vnd.a a
+text/vnd.abc abc
+text/vnd.ascii-art ascii
+text/vnd.curl curl
+text/vnd.debian.copyright copyright
+text/vnd.DMClientScript dms
+text/vnd.dvb.subtitle
+text/vnd.esmertec.theme-descriptor jtd
+text/vnd.ficlab.flt flt
text/vnd.flatland.3dml
-text/vnd.fly
-text/vnd.fmi.flexstor
-text/vnd.in3d.3dml
-text/vnd.in3d.spot
+text/vnd.fly fly
+text/vnd.fmi.flexstor flx
+text/vnd.gml
+text/vnd.graphviz gv dot
+text/vnd.hgl hgl
+text/vnd.in3d.3dml 3dml 3dm
+text/vnd.in3d.spot spot spo
text/vnd.IPTC.NewsML
text/vnd.IPTC.NITF
text/vnd.latex-z
text/vnd.motorola.reflex
-text/vnd.ms-mediapackage
+text/vnd.ms-mediapackage mpf
+text/vnd.net2phone.commcenter.command ccc
+text/vnd.radisys.msml-basic-layout
+text/vnd.senx.warpscript mc2
+text/vnd.sosi sos
text/vnd.sun.j2me.app-descriptor jad
-text/vnd.wap.si
-text/vnd.wap.sl
+text/vnd.trolltech.linguist ts
+text/vnd.wap.si si
+text/vnd.wap.sl sl
text/vnd.wap.wml wml
text/vnd.wap.wmlscript wmls
+text/vtt vtt
text/x-bibtex bib
text/x-boo boo
text/x-c++hdr h++ hpp hxx hh
-text/x-c++src c++ cpp cxx cc
text/x-chdr h
text/x-component htc
text/x-crontab
text/x-csh csh
+text/x-c++src c++ cpp cxx cc
text/x-csrc c
-text/x-dsrc d
text/x-diff diff patch
+text/x-dsrc d
text/x-haskell hs
text/x-java java
text/x-lilypond ly
text/x-literate-haskell lhs
text/x-makefile
+text/xml
+text/xml-dtd
+text/xml-external-parsed-entity
text/x-moc moc
text/x-pascal p pas
text/x-pcs-gcd gcd
@@ -805,41 +2080,108 @@ text/x-tcl tcl tk
text/x-tex tex ltx sty cls
text/x-vcalendar vcs
-video/3gpp 3gp
+video/1d-interleaved-parityfec
+video/3gpp
+video/3gpp2
+video/3gpp-tt
video/annodex axv
+video/BMPEG
+video/BT656
+video/CelB
video/dl dl
+video/DV
video/dv dif dv
+video/encaprtp
+video/example
+video/flexfec
video/fli fli
video/gl gl
-video/mpeg mpeg mpg mpe
-video/MP2T ts
-video/mp4 mp4
-video/quicktime qt mov
+video/H261
+video/H263
+video/H263-1998
+video/H263-2000
+video/H264
+video/H264-RCDO
+video/H264-SVC
+video/H265
+video/iso.segment m4s
+video/JPEG
+video/jpeg2000
+video/mj2 mj2 mjp2
+video/MP1S
+video/MP2P
+video/MP2T
+video/mp4 mp4 mpg4 m4v
video/mp4v-es
+video/MP4V-ES
+video/mpeg mpeg mpg mpe m1v m2v
+video/mpeg4-generic
+video/MPV
+video/nv
video/ogg ogv
video/parityfec
video/pointer
-video/webm webm
-video/vnd.fvt
+video/quicktime qt mov
+video/raptorfec
+video/raw
+video/rtp-enc-aescm128
+video/rtploopback
+video/rtx
+video/smpte291
+video/SMPTE292M
+video/ulpfec
+video/vc1
+video/vc2
+video/vnd.CCTV
+video/vnd.dece.hd uvh uvvh
+video/vnd.dece.mobile uvm uvvm
+video/vnd.dece.mp4 uvu uvvu
+video/vnd.dece.pd uvp uvvp
+video/vnd.dece.sd uvs uvvs
+video/vnd.dece.video uvv uvvv
+video/vnd.directv.mpeg
+video/vnd.directv.mpeg-tts
+video/vnd.dlna.mpeg-tts
+video/vnd.dvb.file dvb
+video/vnd.fvt fvt
+video/vnd.hns.video
+video/vnd.iptvforum.1dparityfec-1010
+video/vnd.iptvforum.1dparityfec-2005
+video/vnd.iptvforum.2dparityfec-1010
+video/vnd.iptvforum.2dparityfec-2005
+video/vnd.iptvforum.ttsavc
+video/vnd.iptvforum.ttsmpeg2
video/vnd.motorola.video
video/vnd.motorola.videop
-video/vnd.mpegurl mxu
+video/vnd.mpegurl mxu m4u
+video/vnd.ms-playready.media.pyv pyv
video/vnd.mts
-video/vnd.nokia.interleaved-multimedia
-video/vnd.vivo
+video/vnd.nokia.interleaved-multimedia nim
+video/vnd.nokia.mp4vr
+video/vnd.nokia.videovoip
+video/vnd.objectvideo
+video/vnd.radgamettools.bink bik bk2
+video/vnd.radgamettools.smacker smk
+video/vnd.sealedmedia.softseal.mov smov smo s1q
+video/vnd.sealed.mpeg1 smpg s11
+video/vnd.sealed.mpeg4 s14
+video/vnd.sealed.swf sswf ssw
+video/vnd.uvvu.mp4
+video/vnd.vivo viv
+video/vnd.youtube.yt yt
+video/VP8
+video/webm webm
video/x-flv flv
video/x-la-asf lsf lsx
+video/x-matroska mpv mkv
video/x-mng mng
-video/x-ms-asf asf asx
+video/x-msvideo avi
video/x-ms-wm wm
video/x-ms-wmv wmv
video/x-ms-wmx wmx
video/x-ms-wvx wvx
-video/x-msvideo avi
video/x-sgi-movie movie
-video/x-matroska mpv mkv
x-conference/x-cooltalk ice
-
x-epoc/x-sisx-app sisx
x-world/x-vrml vrm vrml wrl
diff --git a/mkshrc b/mkshrc
new file mode 100644
index 00000000..240ee2f1
--- /dev/null
+++ b/mkshrc
@@ -0,0 +1,717 @@
+# $Id$
+# $MirOS: src/bin/mksh/dot.mkshrc,v 1.136 2021/01/24 20:38:30 tg Exp $
+#-
+# Copyright (c) 2002, 2003, 2004, 2006, 2007, 2008, 2009, 2010,
+# 2011, 2012, 2013, 2014, 2015, 2016, 2017, 2019,
+# 2020, 2021
+# mirabilos
+#
+# Provided that these terms and disclaimer and all copyright notices
+# are retained or reproduced in an accompanying document, permission
+# is granted to deal in this work without restriction, including un-
+# limited rights to use, publicly perform, distribute, sell, modify,
+# merge, give away, or sublicence.
+#
+# This work is provided "AS IS" and WITHOUT WARRANTY of any kind, to
+# the utmost extent permitted by applicable law, neither express nor
+# implied; without malicious intent or gross negligence. In no event
+# may a licensor, author or contributor be held liable for indirect,
+# direct, other damage, loss, or other issues arising in any way out
+# of dealing in the work, even if advised of the possibility of such
+# damage or existence of a defect, except proven that it results out
+# of said person's immediate fault when using the work as intended.
+#-
+# ${ENV:-~/.mkshrc}: mksh initialisation file for interactive shells
+
+# catch non-mksh, non-lksh, trying to run this file
+case ${KSH_VERSION:-} in
+*LEGACY\ KSH*|*MIRBSD\ KSH*) ;;
+*) \return 0 ;;
+esac
+
+# give MidnightBSD's laffer1 a bit of csh feeling
+function setenv {
+ if (( $# )); then
+ \\builtin eval '\\builtin export "$1"="${2:-}"'
+ else
+ \\builtin typeset -x
+ fi
+}
+
+# internal helper function to cat all arguments if necessary
+function _dot_mkshrc_wrapped_cat {
+ \\builtin typeset fn=$1
+ \\builtin shift
+
+ if [[ $# = 0 || $#,$1 = 1,- ]]; then
+ "$fn"
+ else
+ \cat "$@" | "$fn"
+ fi
+}
+function _dot_mkshrc_cat_for_readN {
+ \\builtin typeset fn=$1
+ \\builtin shift
+
+ if (( $# )); then
+ \\builtin print -nr -- "$*" | "$fn"
+ elif [[ -t 0 ]]; then
+ \cat | "$fn"
+ else
+ "$fn"
+ fi
+}
+
+# pager (not control character safe)
+function smores {
+ \_dot_mkshrc_wrapped_cat _dot_mkshrc_smores "$@"
+}
+function _dot_mkshrc_smores {
+ \\builtin set +e
+ \\builtin typeset line llen curlin=0 x
+
+ while IFS= \\builtin read -r line; do
+ llen=${%line}
+ (( llen != -1 )) || llen=${#line}
+ (( llen = llen ? (llen + COLUMNS - 1) / COLUMNS : 1 ))
+ if (( (curlin += llen) >= LINES )); then
+ \\builtin print -nr -- $'\e[7m--more--\e[0m'
+ \\builtin read -u1 x || \\builtin return $?
+ [[ $x != [Qq]* ]] || \\builtin return 0
+ curlin=$llen
+ fi
+ \\builtin print -r -- "$line"
+ done
+}
+
+# customise your favourite editor here; the first one found is used
+for EDITOR in "${EDITOR:-}" jupp jstar mcedit ed vi; do
+ EDITOR=$(\\builtin whence -p "$EDITOR") || EDITOR=
+ [[ -n $EDITOR && -x $EDITOR ]] && break
+ EDITOR=
+done
+
+\\builtin alias ls=ls l='ls -F' la='l -a' ll='l -l' lo='l -al'
+\: "${EDITOR:=/bin/ed}${TERM:=vt100}${USER:=$(\\builtin ulimit -c 0; id -un \
+ 2>/dev/null)}${HOSTNAME:=$(\\builtin ulimit -c 0; hostname 2>/dev/null)}"
+[[ $HOSTNAME = ?(?(ip6-)localhost?(6)) ]] && HOSTNAME=nil; \\builtin unalias ls
+\\builtin export EDITOR HOSTNAME TERM USER="${USER:-?}"
+
+# minimal support for lksh users
+if [[ $KSH_VERSION = *LEGACY\ KSH* ]]; then
+ PS1='$USER@${HOSTNAME%%.*}:$PWD>'
+ \\builtin return 0
+fi
+
+# mksh-specific from here
+\: "${MKSH:=$(\\builtin whence -p mksh)}${MKSH:=/bin/mksh}"
+\\builtin export MKSH
+
+# prompts
+PS4='[$EPOCHREALTIME] '; PS1='#'; (( USER_ID )) && PS1='$'; PS1=$'\001\r''${|
+ \\builtin typeset e=$? hn=${HOSTNAME:-nil}
+
+ (( !!e )) || REPLY+="$e|"
+ REPLY+=${USER:-?}@${hn%%.*}:
+
+ \\builtin typeset d=${PWD:-?}/ p=~; [[ $p = ?(*/) ]] || d=${d/#$p\//\~/}
+ d=${d%/}; \\builtin typeset m=${%d} n p=...; (( m > 0 )) || m=${#d}
+ (( m > (n = (COLUMNS/3 < 7 ? 7 : COLUMNS/3)) )) && d=${d:(-n)} || p=
+ REPLY+=$p$d
+
+ \\builtin return $e
+} '"$PS1 "
+
+# utilities
+\\builtin alias doch='sudo mksh -c "$(\\builtin fc -ln -1)"'
+\\builtin command -v rot13 >/dev/null || \\builtin alias rot13='tr \
+ abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ \
+ nopqrstuvwxyzabcdefghijklmNOPQRSTUVWXYZABCDEFGHIJKLM'
+if \\builtin command -v hd >/dev/null; then
+ \:
+elif \\builtin command -v hexdump >/dev/null; then
+ function hd {
+ \hexdump -e '"%08.8_ax " 8/1 "%02X " " - " 8/1 "%02X "' \
+ -e '" |" "%_p"' -e '"|\n"' "$@"
+ }
+else
+ function hd {
+ # cannot use _dot_mkshrc_wrapped_cat as hd_mksh sets stdin raw
+ \cat "$@" | \hd_mksh
+ }
+fi
+
+# NUL-safe and EBCDIC-safe hexdump (from stdin)
+function hd_mksh {
+ \\builtin typeset -Uui16 -Z11 pos=0
+ \\builtin typeset -Uui16 -Z5 hv=2147483647
+ \\builtin typeset dasc dn line i
+ \\builtin set +Ue
+
+ while \\builtin read -arn 512 line; do
+ \\builtin typeset -i1 'line[*]'
+ i=0
+ while (( i < ${#line[*]} )); do
+ dn=
+ (( (hv = line[i++]) != 0 )) && dn=${line[i-1]#1#}
+ if (( (pos & 15) == 0 )); then
+ (( pos )) && \
+ \\builtin print -r -- "$dasc|"
+ \\builtin print -nr "${pos#16#} "
+ dasc=' |'
+ fi
+ \\builtin print -nr "${hv#16#} "
+ if [[ $dn = [[:print:]] ]]; then
+ dasc+=$dn
+ else
+ dasc+=.
+ fi
+ (( (pos++ & 15) == 7 )) && \
+ \\builtin print -nr -- '- '
+ done
+ done
+ while (( pos & 15 )); do
+ \\builtin print -nr ' '
+ (( (pos++ & 15) == 7 )) && \
+ \\builtin print -nr -- '- '
+ done
+ (( hv == 2147483647 )) || \\builtin print -r -- "$dasc|"
+}
+
+function which {
+ \\builtin typeset p x c
+ \\builtin typeset -i a=0 rv=2 e
+ \\builtin set +e
+ \\builtin set -o noglob
+
+ while \\builtin getopts "a" x; do
+ case $x {
+ (a) a=1 ;;
+ (+a) a=0 ;;
+ (*) \\builtin print -ru2 'Usage: which [-a] name [...]'
+ \\builtin return 255 ;;
+ }
+ done
+ \\builtin shift $((OPTIND - 1))
+
+ # vvvvvvvvvvvvvvvvvvvv should be def_path
+ p=${PATH-/usr/bin$PATHSEP/bin}
+ # ^ no colon!
+
+ # trailing PATHSEP vs field splitting
+ [[ $p = *"$PATHSEP" ]] && p+=.
+
+ IFS=$PATHSEP
+ \\builtin set -A p -- ${p:-.}
+ IFS=$' \t\n'
+
+ for x in "$@"; do
+ if (( !a )) || [[ $x = */* ]]; then
+ \\builtin whence -p -- "$x"
+ e=$?
+ else
+ e=1
+ for c in "${p[@]}"; do
+ PATH=${c:-.} \\builtin whence -p -- "$x" && e=0
+ done
+ fi
+ (( rv = (e == 0) ? (rv & ~2) : (rv == 2 ? 2 : 1) ))
+ done
+ \\builtin return $rv
+}
+
+# Berkeley C shell compatible dirs, popd, and pushd functions
+# Z shell compatible chpwd() hook, used to update DIRSTACK[0]
+DIRSTACKBASE=$(\\builtin realpath ~/. 2>/dev/null || \
+ \\builtin print -nr -- "${HOME:-/}")
+\\builtin set -A DIRSTACK
+function chpwd {
+ DIRSTACK[0]=$(\\builtin realpath . 2>/dev/null || \
+ \\builtin print -nr -- "$PWD")
+ [[ $DIRSTACKBASE = ?(*/) ]] || \
+ DIRSTACK[0]=${DIRSTACK[0]/#$DIRSTACKBASE/\~}
+ \:
+}
+\chpwd .
+cd() {
+ \\builtin cd "$@" || \\builtin return $?
+ \chpwd "$@"
+}
+function cd_csh {
+ \\builtin typeset d t=${1/#\~/$DIRSTACKBASE}
+
+ if ! d=$(\\builtin cd "$t" 2>&1); then
+ \\builtin print -ru2 "${1}: ${d##*cd: $t: }."
+ \\builtin return 1
+ fi
+ \cd "$t"
+}
+function dirs {
+ \\builtin set +e
+ \\builtin typeset d dwidth
+ \\builtin typeset -i fl=0 fv=0 fn=0 cpos=0
+
+ while \\builtin getopts ":lvn" d; do
+ case $d {
+ (l) fl=1 ;;
+ (v) fv=1 ;;
+ (n) fn=1 ;;
+ (*) \\builtin print -ru2 'Usage: dirs [-lvn].'
+ \\builtin return 1 ;;
+ }
+ done
+ \\builtin shift $((OPTIND - 1))
+ if (( $# > 0 )); then
+ \\builtin print -ru2 'Usage: dirs [-lvn].'
+ \\builtin return 1
+ fi
+ if (( fv )); then
+ fv=0
+ while (( fv < ${#DIRSTACK[*]} )); do
+ d=${DIRSTACK[fv]}
+ (( fl )) && d=${d/#\~/$DIRSTACKBASE}
+ \\builtin print -r -- "$fv $d"
+ (( ++fv ))
+ done
+ else
+ fv=0
+ while (( fv < ${#DIRSTACK[*]} )); do
+ d=${DIRSTACK[fv]}
+ (( fl )) && d=${d/#\~/$DIRSTACKBASE}
+ (( dwidth = (${%d} > 0 ? ${%d} : ${#d}) ))
+ if (( fn && (cpos += dwidth + 1) >= 79 && \
+ dwidth < 80 )); then
+ \\builtin print
+ (( cpos = dwidth + 1 ))
+ fi
+ \\builtin print -nr -- "$d "
+ (( ++fv ))
+ done
+ \\builtin print
+ fi
+ \\builtin return 0
+}
+function popd {
+ \\builtin typeset d fa
+ \\builtin typeset -i n=1
+
+ while \\builtin getopts ":0123456789lvn" d; do
+ case $d {
+ (l|v|n) fa+=" -$d" ;;
+ (+*) n=2
+ \\builtin break ;;
+ (*) \\builtin print -ru2 'Usage: popd [-lvn] [+].'
+ \\builtin return 1 ;;
+ }
+ done
+ \\builtin shift $((OPTIND - n))
+ n=0
+ if (( $# > 1 )); then
+ \\builtin print -ru2 popd: Too many arguments.
+ \\builtin return 1
+ elif [[ $1 = ++([0-9]) && $1 != +0 ]]; then
+ if (( (n = ${1#+}) >= ${#DIRSTACK[*]} )); then
+ \\builtin print -ru2 popd: Directory stack not that deep.
+ \\builtin return 1
+ fi
+ elif [[ -n $1 ]]; then
+ \\builtin print -ru2 popd: Bad directory.
+ \\builtin return 1
+ fi
+ if (( ${#DIRSTACK[*]} < 2 )); then
+ \\builtin print -ru2 popd: Directory stack empty.
+ \\builtin return 1
+ fi
+ \\builtin unset DIRSTACK[n]
+ \\builtin set -A DIRSTACK -- "${DIRSTACK[@]}"
+ \cd_csh "${DIRSTACK[0]}" || \\builtin return 1
+ \dirs $fa
+}
+function pushd {
+ \\builtin typeset d fa
+ \\builtin typeset -i n=1
+
+ while \\builtin getopts ":0123456789lvn" d; do
+ case $d {
+ (l|v|n) fa+=" -$d" ;;
+ (+*) n=2
+ \\builtin break ;;
+ (*) \\builtin print -ru2 'Usage: pushd [-lvn] [|+].'
+ \\builtin return 1 ;;
+ }
+ done
+ \\builtin shift $((OPTIND - n))
+ if (( $# == 0 )); then
+ if (( ${#DIRSTACK[*]} < 2 )); then
+ \\builtin print -ru2 pushd: No other directory.
+ \\builtin return 1
+ fi
+ d=${DIRSTACK[1]}
+ DIRSTACK[1]=${DIRSTACK[0]}
+ \cd_csh "$d" || \\builtin return 1
+ elif (( $# > 1 )); then
+ \\builtin print -ru2 pushd: Too many arguments.
+ \\builtin return 1
+ elif [[ $1 = ++([0-9]) && $1 != +0 ]]; then
+ if (( (n = ${1#+}) >= ${#DIRSTACK[*]} )); then
+ \\builtin print -ru2 pushd: Directory stack not that deep.
+ \\builtin return 1
+ fi
+ while (( n-- )); do
+ d=${DIRSTACK[0]}
+ \\builtin unset DIRSTACK[0]
+ \\builtin set -A DIRSTACK -- "${DIRSTACK[@]}" "$d"
+ done
+ \cd_csh "${DIRSTACK[0]}" || \\builtin return 1
+ else
+ \\builtin set -A DIRSTACK -- placeholder "${DIRSTACK[@]}"
+ \cd_csh "$1" || \\builtin return 1
+ fi
+ \dirs $fa
+}
+
+# base64 encoder and decoder, RFC compliant, NUL safe, not EBCDIC safe
+function Lb64decode {
+ \\builtin set +Ue
+ \\builtin typeset c s t
+ if (( $# )); then
+ s="$*"
+ elif [[ -t 0 ]]; then
+ s=$(\cat || \\builtin exit $?; \\builtin print x) || \
+ \\builtin return $?
+ s=${s%x}
+ else
+ \\builtin read -rN-1 s || \\builtin return $?
+ fi
+ \\builtin typeset -i i=0 j=0 n=${#s} p=0 v x
+ \\builtin typeset -i16 o
+
+ while (( i < n )); do
+ c=${s:(i++):1}
+ case $c {
+ (=) \\builtin break ;;
+ ([A-Z]) (( v = 1#$c - 65 )) ;;
+ ([a-z]) (( v = 1#$c - 71 )) ;;
+ ([0-9]) (( v = 1#$c + 4 )) ;;
+ (+) v=62 ;;
+ (/) v=63 ;;
+ (*) \\builtin continue ;;
+ }
+ (( x = (x << 6) | v ))
+ case $((p++)) {
+ (0) \\builtin continue ;;
+ (1) (( o = (x >> 4) & 255 )) ;;
+ (2) (( o = (x >> 2) & 255 )) ;;
+ (3) (( o = x & 255 ))
+ p=0
+ ;;
+ }
+ t+=\\x${o#16#}
+ (( ++j & 4095 )) && \\builtin continue
+ \\builtin print -n -- "$t"
+ t=
+ done
+ \\builtin print -n -- "$t"
+}
+function Lb64encode {
+ \_dot_mkshrc_cat_for_readN _dot_mkshrc_b64encode "$@"
+}
+function _dot_mkshrc_b64encode {
+ \\builtin set +Ue
+ \\builtin typeset c s t table
+ \\builtin set -A table -- A B C D E F G H I J K L M N O P Q R S T U V W X Y Z \
+ a b c d e f g h i j k l m n o p q r s t u v w x y z 0 1 2 3 4 5 6 7 8 9 + /
+ \\builtin read -raN-1 s || \\builtin return $?
+ \\builtin typeset -i i=0 n=${#s[*]} v
+
+ while (( i < n )); do
+ (( v = s[i++] << 16 ))
+ (( v |= s[i++] << 8 ))
+ (( v |= s[i++] ))
+ t+=${table[v >> 18]}${table[v >> 12 & 63]}
+ c=${table[v >> 6 & 63]}
+ if (( i <= n )); then
+ t+=$c${table[v & 63]}
+ elif (( i == n + 1 )); then
+ t+=$c=
+ else
+ t+===
+ fi
+ if (( ${#t} == 76 || i >= n )); then
+ \\builtin print -r -- "$t"
+ t=
+ fi
+ done
+ \:
+}
+
+# Better Avalanche for the Jenkins Hash
+\\builtin typeset -Z11 -Uui16 Lbafh_v
+function Lbafh_init {
+ Lbafh_v=0
+}
+function Lbafh_add {
+ \_dot_mkshrc_cat_for_readN _dot_mkshrc_bafh_add "$@"
+}
+function _dot_mkshrc_bafh_add {
+ \\builtin set +Ue
+ \\builtin typeset s
+ \\builtin read -raN-1 s || \\builtin return $?
+ \\builtin typeset -i i=0 n=${#s[*]}
+
+ while (( i < n )); do
+ ((# Lbafh_v = (Lbafh_v + s[i++] + 1) * 1025 ))
+ ((# Lbafh_v ^= Lbafh_v >> 6 ))
+ done
+ \:
+}
+function Lbafh_finish {
+ \\builtin set +e
+ \\builtin typeset -Ui t
+
+ ((# t = (((Lbafh_v >> 7) & 0x01010101) * 0x1B) ^ \
+ ((Lbafh_v << 1) & 0xFEFEFEFE) ))
+ ((# Lbafh_v = t ^ (t ^> 8) ^ (Lbafh_v ^> 8) ^ \
+ (Lbafh_v ^> 16) ^ (Lbafh_v ^> 24) ))
+ \:
+}
+
+# strip comments (and leading/trailing whitespace if IFS is set) from
+# any file(s) given as argument, or stdin if none, and spew to stdout
+function Lstripcom {
+ \_dot_mkshrc_wrapped_cat _dot_mkshrc_stripcom "$@"
+}
+function _dot_mkshrc_stripcom {
+ \\builtin typeset line x
+ \\builtin set -o noglob
+ while \\builtin read -r line; do
+ while [[ $line = *\\ && $line != *'#'* ]] && \
+ \\builtin read -r x; do
+ line=${line%\\}$x
+ done
+ line=${line%%#*}
+ [[ -z $line ]] || \\builtin print -r -- $line
+ done
+ \:
+}
+
+# toggle built-in aliases and utilities, and aliases and functions from mkshrc
+function enable {
+ \\builtin typeset doprnt=0 mode=1 x y z rv=0
+ \\builtin typeset b_alias i_alias i_func nalias=0 nfunc=0 i_all
+ \\builtin set -A b_alias
+ \\builtin set -A i_alias
+ \\builtin set -A i_func
+
+ # accumulate mksh built-in aliases, in ASCIIbetical order
+ i_alias[nalias]=autoload; b_alias[nalias++]='\\builtin typeset -fu'
+ i_alias[nalias]=functions; b_alias[nalias++]='\\builtin typeset -f'
+ i_alias[nalias]=hash; b_alias[nalias++]='\\builtin alias -t'
+ i_alias[nalias]=history; b_alias[nalias++]='\\builtin fc -l'
+ i_alias[nalias]=integer; b_alias[nalias++]='\\builtin typeset -i'
+ i_alias[nalias]=local; b_alias[nalias++]='\\builtin typeset'
+ i_alias[nalias]=login; b_alias[nalias++]='\\builtin exec login'
+ i_alias[nalias]=nameref; b_alias[nalias++]='\\builtin typeset -n'
+ i_alias[nalias]=nohup; b_alias[nalias++]='nohup '
+ i_alias[nalias]=r; b_alias[nalias++]='\\builtin fc -e -'
+ i_alias[nalias]=type; b_alias[nalias++]='\\builtin whence -v'
+
+ # accumulate mksh built-in utilities, in definition order, even ifndef
+ i_func[nfunc++]=.
+ i_func[nfunc++]=:
+ i_func[nfunc++]='['
+ i_func[nfunc++]=alias
+ i_func[nfunc++]=break
+ # \\builtin cannot, by design, be overridden
+ i_func[nfunc++]=builtin
+ i_func[nfunc++]=cd
+ i_func[nfunc++]=chdir
+ i_func[nfunc++]=command
+ i_func[nfunc++]=continue
+ i_func[nfunc++]=echo
+ i_func[nfunc++]=eval
+ i_func[nfunc++]=exec
+ i_func[nfunc++]=exit
+ i_func[nfunc++]=export
+ i_func[nfunc++]=false
+ i_func[nfunc++]=fc
+ i_func[nfunc++]=getopts
+ i_func[nfunc++]=jobs
+ i_func[nfunc++]=kill
+ i_func[nfunc++]=let
+ i_func[nfunc++]=print
+ i_func[nfunc++]=pwd
+ i_func[nfunc++]=read
+ i_func[nfunc++]=readonly
+ i_func[nfunc++]=realpath
+ i_func[nfunc++]=rename
+ i_func[nfunc++]=return
+ i_func[nfunc++]=set
+ i_func[nfunc++]=shift
+ i_func[nfunc++]=source
+ i_func[nfunc++]=suspend
+ i_func[nfunc++]=test
+ i_func[nfunc++]=times
+ i_func[nfunc++]=trap
+ i_func[nfunc++]=true
+ i_func[nfunc++]=typeset
+ i_func[nfunc++]=ulimit
+ i_func[nfunc++]=umask
+ i_func[nfunc++]=unalias
+ i_func[nfunc++]=unset
+ i_func[nfunc++]=wait
+ i_func[nfunc++]=whence
+ i_func[nfunc++]=bg
+ i_func[nfunc++]=fg
+ i_func[nfunc++]=bind
+ i_func[nfunc++]=mknod
+ i_func[nfunc++]=printf
+ i_func[nfunc++]=extproc
+
+ # accumulate aliases from dot.mkshrc, in definition order
+ i_alias[nalias]=l; b_alias[nalias++]='ls -F'
+ i_alias[nalias]=la; b_alias[nalias++]='l -a'
+ i_alias[nalias]=ll; b_alias[nalias++]='l -l'
+ i_alias[nalias]=lo; b_alias[nalias++]='l -al'
+ i_alias[nalias]=doch; b_alias[nalias++]='sudo mksh -c "$(\\builtin fc -ln -1)"'
+ i_alias[nalias]=rot13; b_alias[nalias++]='tr abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ nopqrstuvwxyzabcdefghijklmNOPQRSTUVWXYZABCDEFGHIJKLM'
+ i_alias[nalias]=cls; b_alias[nalias++]='\\builtin print -n \\ec'
+
+ # accumulate functions from dot.mkshrc, in definition order
+ i_func[nfunc++]=setenv
+ i_func[nfunc++]=smores
+ i_func[nfunc++]=hd
+ i_func[nfunc++]=hd_mksh
+ i_func[nfunc++]=which
+ i_func[nfunc++]=chpwd
+ i_func[nfunc++]=cd
+ i_func[nfunc++]=cd_csh
+ i_func[nfunc++]=dirs
+ i_func[nfunc++]=popd
+ i_func[nfunc++]=pushd
+ i_func[nfunc++]=Lb64decode
+ i_func[nfunc++]=Lb64encode
+ i_func[nfunc++]=Lbafh_init
+ i_func[nfunc++]=Lbafh_add
+ i_func[nfunc++]=Lbafh_finish
+ i_func[nfunc++]=Lstripcom
+ i_func[nfunc++]=enable
+
+ # collect all identifiers, sorted ASCIIbetically
+ \\builtin set -sA i_all -- "${i_alias[@]}" "${i_func[@]}"
+
+ # handle options, we don't do dynamic loading
+ while \\builtin getopts "adf:nps" x; do
+ case $x {
+ (a)
+ mode=-1
+ ;;
+ (d)
+ # deliberately causing an error, like bash-static
+ ;|
+ (f)
+ \\builtin print -ru2 enable: dynamic loading not available
+ \\builtin return 2
+ ;;
+ (n)
+ mode=0
+ ;;
+ (p)
+ doprnt=1
+ ;;
+ (s)
+ \\builtin set -sA i_all -- . : break continue eval \
+ exec exit export readonly return set shift times \
+ trap unset
+ ;;
+ (*)
+ \\builtin print -ru2 enable: usage: \
+ "enable [-adnps] [-f filename] [name ...]"
+ \\builtin return 2
+ ;;
+ }
+ done
+ \\builtin shift $((OPTIND - 1))
+
+ # display builtins enabled/disabled/all/special?
+ if (( doprnt || ($# == 0) )); then
+ for x in "${i_all[@]}"; do
+ y=$(\\builtin alias "$x") || y=
+ [[ $y = "$x='\\\\builtin whence -p $x >/dev/null || (\\\\builtin print -r mksh: $x: not found; \\\\builtin exit 127) && \$(\\\\builtin whence -p $x)'" ]]; z=$?
+ case $mode:$z {
+ (-1:0|0:0)
+ \\builtin print -r -- "enable -n $x"
+ ;;
+ (-1:1|1:1)
+ \\builtin print -r -- "enable $x"
+ ;;
+ }
+ done
+ \\builtin return 0
+ fi
+
+ for x in "$@"; do
+ z=0
+ for y in "${i_alias[@]}" "${i_func[@]}"; do
+ [[ $x = "$y" ]] || \\builtin continue
+ z=1
+ \\builtin break
+ done
+ if (( !z )); then
+ \\builtin print -ru2 enable: "$x": not a shell builtin
+ rv=1
+ \\builtin continue
+ fi
+ if (( !mode )); then
+ # disable this
+ \\builtin alias "$x=\\\\builtin whence -p $x >/dev/null || (\\\\builtin print -r mksh: $x: not found; \\\\builtin exit 127) && \$(\\\\builtin whence -p $x)"
+ else
+ # find out if this is an alias or not, first
+ z=0
+ y=-1
+ while (( ++y < nalias )); do
+ [[ $x = "${i_alias[y]}" ]] || \\builtin continue
+ z=1
+ \\builtin break
+ done
+ if (( z )); then
+ # re-enable the original alias body
+ \\builtin alias "$x=${b_alias[y]}"
+ else
+ # re-enable the original utility/function
+ \\builtin unalias "$x"
+ fi
+ fi
+ done
+ \\builtin return $rv
+}
+
+\: place customisations below this line
+
+# some defaults / samples which you are supposed to adjust to your
+# liking; by default we add ~/.etc/bin and ~/bin (whichever exist)
+# to $PATH, set $SHELL to mksh, set some defaults for man and less
+# and show a few more possible things for users to begin moving in
+
+for p in ~/.etc/bin ~/bin; do
+ [[ -d $p/. ]] || \\builtin continue
+ [[ $PATHSEP$PATH$PATHSEP = *"$PATHSEP$p$PATHSEP"* ]] || \
+ PATH=$p$PATHSEP$PATH
+done
+
+\\builtin export SHELL=$MKSH MANWIDTH=80 LESSHISTFILE=-
+\\builtin alias cls='\\builtin print -n \\ec'
+
+#\\builtin unset LC_ADDRESS LC_COLLATE LC_CTYPE LC_IDENTIFICATION \
+# LC_MEASUREMENT LC_MESSAGES LC_MONETARY LC_NAME LC_NUMERIC LC_PAPER \
+# LC_TELEPHONE LC_TIME LANGUAGE LANG LC_ALL
+#p=en_GB.UTF-8
+#\\builtin export LANG=C LC_CTYPE=$p LC_MEASUREMENT=$p LC_MESSAGES=$p LC_PAPER=$p
+#\\builtin export LANG=C.UTF-8 LC_CTYPE=C.UTF-8
+#\\builtin export LC_ALL=C.UTF-8
+#\\builtin set -U
+#[[ ${LC_ALL:-${LC_CTYPE:-${LANG:-}}} = *[Uu][Tt][Ff]?(-)8* ]] || \\builtin set +U
+
+\\builtin unset p
+
+\: place customisations above this line
diff --git a/mysql/mariadb.cnf b/mysql/mariadb.cnf
index 94d8f107..62b4ea8f 100644
--- a/mysql/mariadb.cnf
+++ b/mysql/mariadb.cnf
@@ -1,6 +1,7 @@
# The MariaDB configuration file
#
# The MariaDB/MySQL tools read configuration files in the following order:
+# 0. "/etc/mysql/my.cnf" symlinks to this file, reason why all the rest is read.
# 1. "/etc/mysql/mariadb.cnf" (this file) to set global defaults,
# 2. "/etc/mysql/conf.d/*.cnf" to set global options.
# 3. "/etc/mysql/mariadb.conf.d/*.cnf" to set MariaDB-only options.
@@ -11,12 +12,17 @@
# One can use all long options that the program supports.
# Run program with --help to get a list of available options and with
# --print-defaults to see which it would actually understand and use.
+#
+# If you are new to MariaDB, check out https://mariadb.com/kb/en/basic-mariadb-articles/
#
-# This group is read both both by the client and the server
+# This group is read both by the client and the server
# use it for options that affect everything
#
[client-server]
+# Port or socket location where to connect
+# port = 3306
+socket = /run/mysqld/mysqld.sock
# Import all .cnf files from configuration directory
!includedir /etc/mysql/conf.d/
diff --git a/nanorc b/nanorc
index 427801ab..1f515c10 100644
--- a/nanorc
+++ b/nanorc
@@ -1,22 +1,15 @@
## Sample initialization file for GNU nano.
##
-## Please note that you must have configured nano with --enable-nanorc
-## for this file to be read! Also note that this file should not be in
-## DOS or Mac format, and that characters specially interpreted by the
-## shell should not be escaped here.
+## For the options that take parameters, the default value is shown.
+## Other options are unset by default. To make sure that an option
+## is disabled, you can use "unset