ESF 7.6.2 - Release

Eurotech Everyware Software Framework ESF 7.6.2 (Eclipse Kura - 5.6.2) - June 2026

Description:

This patch release of ESF, compatible with Java 8 and OSGi R7 includes:

  • improvements to the connection status led behavior on the ReliaGATE 15A-12 platform
  • important bug fixes related to the serial port configurator on the ReliaGATE 15A-12 platform
  • bug fixes related to firewall flooding protection configuration and fail2ban integration
  • improved support for Boltgate 20-25 and Boltgate 20-31 platforms

Features (ESF):

  • 1c32798339 - [distrib] Set connection led for dg1014 (#2731) (Pierantonio Merlino)
  • 4b8f441cd2 - Updated connection status led for the 15a-12 (#2709) (Pierantonio Merlino)

Features (Kura):

  • 378f7f327f - [nm] prevent unnecessary network deactivation and configuration updates [backport release-5.6] (#6254) (Pierantonio Merlino)
  • f961ca425e - [linux.gpio.libgpiod] Added support to multiple pin listeners (#6197) (Pierantonio Merlino)

Target Environments:

  • ESF supports the following Devices and Everyware Linux (EL) versions:
    • ReliaGATE 10-12;
      • EL 27.0.1
      • EL 27.1.0
    • ReliaGATE 10-20;
      • EL 27.0.0
    • ReliaGATE 20-25;
      • EL 23.0.0
    • BoltGATE 20-25;
      • EL 21.4.0
    • ReliaGATE 10-14;
      • EL 27.0.3
      • EL 27.1.0
      • EL 40.2.0 (generic-arm64 profile)
    • DynaGATE 10-14;
      • EL 33.0.0 (generic-arm64 profile)
      • EL 40.2.0 (generic-arm64 profile)
    • BoltGATE 20-31;
      • EL 20.1.0
    • DynaGATE 20-30;
      • EL 20.1.0
    • DynaCOR 44-11;
      • Ubuntu 22.04 LTS (generic-x86-64 profile)
    • ReliaCOR 40-13;
      • Ubuntu 22.04 LTS (generic-x86-64 profile)
    • ReliaCOR 54-13;
      • Ubuntu 22.04 LTS (generic-x86-64 profile)
    • ReliaCOR 31-11;
      • Ubuntu 20.04 LTS (generic-arm64 profile)
    • ReliaCOR 33-11;
      • Ubuntu 20.04 LTS (generic-arm64 profile)
    • ReliaGATE 15A-12;
      • EL 50.0.0 (generic-arm64 profile)
    • ReliaGATE 15A-14;
      • EL 40.2.0 (generic-arm64 profile)
    • Generic profiles;
      • generic-arm32
      • generic-arm64
      • generic-x86_64
      • generic-arm32-nn
      • generic-arm64-nn
      • generic-x86_64-nn
        ESF no longer provides a dedicated installer for the following platforms, but support is still provided through the Generic profiles:
    • Raspberry Pi 2/3/4 with Raspberry Pi OS 32bit (Bookworm tested)
    • Raspberry Pi 3/4 with Raspberry Pi OS 64bit (Bookworm tested)
  • ESF is also available as a pre-built Docker container based on:
    • Rocky Linux latest x86_64 and aarch64
    • ubi-minimal latest x86_64 and aarch64

Bug Fixes (ESF):

  • e2de7ec6c5 - wrong com1 path for 15a-12 serial port configurator (#2743) (Matteo Maiero)
  • fa139baad6 - [rg15a12] handle IllegalArgumentException when GPIO pin is not found on activate (#2742) (Matteo Maiero)
  • ec95d18f9e - [distrib] override fail2ban firewalld banaction with iptables for generic profiles (#2740) (Matteo Maiero)
  • 2a537be74c - [distrib] port path traversal fix from esf-hardening and update sudoers hash [backport release-7.6.0] (#2736) (Matteo Maiero)
  • 619c5e8fa7 - Fixed cacerts.ks default password [backport release-7.6.0] (#2734) (Salvatore Coppola)
  • d6579b7ba2 - [distrib] added patch to remove conflicting flooding protection rules from firewall_cust (#2730) (Marcello Rinaldo Martina)
  • 9e3ac185d3 - [network.threat.manager] Update fail2ban kura-filter file (#2726) (Pierantonio Merlino)
  • 3ed79882d2 - [distrib] updated sha256 checksum in 010_esf-hardening (#2727) (Pierantonio Merlino)
  • 367fb08df4 - Serial port configurator 15a12 version update (#2725) (Pierantonio Merlino)
  • 4864fe6077 - update network threat manager version and build properties (#2724) (Matteo Maiero)
  • 52033c73e9 - Update connection limit to work only for new connections (#2713) (Matteo Maiero)
  • de68e6b28b - [distrib] set watchdog device path to /dev/watchdog for boltgate2025 and boltgate2031 on generic profiles [backport release-7.6.0] (#2712) (Matteo Maiero)
  • c6762c7425 - [distrib] prevent path traversal in manage_sshd_files.sh [backport release 7.6.0] (#2703) (Matteo Maiero)
  • b9572e87d3 - Remove enabling the 10-14 linux provider as not needed for 15a-14 (#2705) (Matteo Maiero)
  • 15c3c2a1c0 - [fail2ban] REST auth fails are not banned [backport release-7.6.0] (#2704) (Marcello Rinaldo Martina)
  • 66fc83b04a - serial configurator to not trigger update-initramfs (#2701) (Matteo Maiero)
  • b49e554c86 - Missing lifecycle-mapping plugin for Eclipse IDE in bundles/pom (#2669) (Matteo Maiero)

Bug Fixes (Kura):

  • c0a8fb3e9a - [distrib] wrong version number for installed BC artifacts (#6268) (Marcello Rinaldo Martina)
  • 7c24725b6b - [core.keystore] prevent CRL downloads from blocking UI load [backport release-5.6.0] (#6264) (Pierantonio Merlino)
  • e5be465135 - [core.keystore] Fixed the addition of EC keypair [backport release-5.6.0] (#6253) (Salvatore Coppola)
  • 6bea317e29 - Fixed cacerts.ks default password [backport release-5.6.0] (#6262) (Salvatore Coppola)
  • c17b44004a - [ai.triton.server] Fixed feature version mismatch causing distrib build failure (#6258) (Matteo Maiero)
  • b90190b42f - [rest] map unhandled exceptions so failed requests are audited (#6246) (Marcello Rinaldo Martina)
  • 5706b1d779 - misalignment between metatype and code in eclipseiot.mqtt bundle [backport release-5.6.0] (#6244) (github-actions[bot])
  • 723ef076b8 - [core.keystore] Improve CRL management (#6230) [backport release-5.6.0] (#6237) (Salvatore Coppola)
  • 0ba7612f99 - [target-platform] Updated Kura version in target-platform config (#6239) (Pierantonio Merlino)
  • 35c65ff6d9 - Correctly handle X-Forwarded-For header for audit logging [backport release-5.6.0] (#6218) (Matteo Maiero)
  • a669473c20 - [linux.gpio.libgpiod] Fix GPIO events behavior in libgpiod v1 (#6184) (Pierantonio Merlino)
  • f7456aca86 - Fixed password encryption in ConfigurationService.createFactoryConfiguration [backport release-5.6.0] (#6182) (nicolatimeus)
  • 255b68934d - Fixed placeholder handling for password defaults [backport release-5.6.0] (#6189) (nicolatimeus)

Target Platform Updates (ESF):

  • 3ab8222bf8 - updated bouncycastle from 1.78.1 to 1.84 (#2732) (Marcello Rinaldo Martina)

Known Issues (ESF):

  • On certain systems (i.e. RG15A-14 and RG10-14) the IPv6 rt match module (-m rt) is not available, causing ESF to fail when applying IPv6 mangle table rules related to Routing Header Type 0 filtering.
    When this occurs, IPv6 Routing Header Type 0 packets will not be explicitly dropped on affected systems.
  • Specific per-gateway limitations (GATEWAY CONFIGURATIONS section) are described and continuously updated in the official ESF documentation (https://esf.eurotech.com)
  • [ECESF-5133] Bluetooth LE beacon advertisement does not work on DynaCOR 44-11
  • [ECESF-7383] - Ansible: Possible OutOfMemory error if executed playbooks produce large log entries
  • [ECESF-6641] The installation of the com.eurotech.framework.fuse bundle causes an error in the log file. However, the bundle works correctly.
  • [ECESF-3394] Non-existent unsaved changes in UI preserved after update from 7.0.2
  • ReliaCELL Dual SIM option not supported
  • Hardware watchdog: not implemented on all platforms
  • On Reliagate 10-20 the watchdog cannot be disabled ("watchdog no-way-out")
  • During ESF shutdown, an error stacktrace can be shown in the log from the Jetty server. This does not affect the success of the procedure
  • #872: Provisioning Service: provisioned flag not reset if provisioning is re-enabled
  • #786: Connection Failed on Snapshot Rollback
  • #624: [Serial] RXTX fails to set 38400 bauds
  • #509: [ESF 5.2.0 QA] Check message verification failed with diagnostics ping
  • #423: [Terminal Services] socat resets the tty configuration on TCP client disconnect
  • #395: ESF on RG 20-25 reports wwan0 interface with LE910 V1 modem.
  • #358: [20-25] jdk.dio.properties digital in/out gpio numbers are incorrect
  • #81: [Security - Message Signing] ESF verifies the signature of every control message
  • #64: Message signature propagated to application bundles

Known Issues (Kura):

  • Watchdog service not working on Ubuntu 24.04 because /dev/watchdog is not available on a clean installation (verified on Zimaboard).
  • On certain systems the IPv6 rt match module (-m rt) is not available, causing Kura to fail when applying IPv6 mangle table rules related to Routing Header Type 0 filtering.
    When this occurs, IPv6 Routing Header Type 0 packets will not be explicitly dropped on affected systems.
  • During a wifi scan, some access points with the WPA/WPA2 wifi security are recognized as WPA.
  • On devices with Ubuntu 20.04, the DHCP server provided by isc-dhcp-server may not assign an IP address to the clients. Use dnsmasq instead.
  • Different GNSS Type retrieved from different Position Providers (see #5409 for details)
  • Snapshot rollback operation may fail processing factory component configurations.
  • The firewall rule applied by the network threat manager that block uncommon TCP MSS values is not applied in the Nvidia Jetson Nano.
  • When the IPv6 network threat manager is disabled, the filtering on TCP fragments is disabled only after a reboot.
  • The republish.mqtt.birth.cert.on.modem.detect property in the CloudService configuration is not supported for devices that use NetworkManager. The property value is ignored.
  • When dnsmasq is used as DHCP server, only one file is used to store the leases.
  • When dnsmasq is used as DHCP server, the DHCP List field in the DHCP and NAT tab shows the leases for all the interfaces.
  • The system reboot command cannot be issued even with a privileged user in Debian Bookworm due to an OS issue related to the CAP_SYS_BOOT capability.
  • The Wi-Fi AP scanning may fail in Debian Bookworm on the first scanning attempt in the specific Raspberry PI profile. A forced rescan can succeed and properly display the available APs.
  • The nvidia-jetson-nano installer disables FAN protocol support due to compatibility issues (see #4593)
  • The nvidia-jetson-nano doesn't support the Unprivileged Command Service (see #3598)
  • isc-dhcp-server fails upon first Kura installation on Raspberry Pi Bullseye. This is due to how the isc-dhcp-server installer package is
    built and run immediately after installation.
  • An update to the sslmanagerservice where the pid of the keystoreservice is updated can lead to an error in the following reconnection.
    The issue impact is limited, if the dataservice reconnect option is enabled.
  • The implementation of the CryptoService performs encryption using a
    password that is hardcoded and published.
  • Modem: Ublox Lisa U201 may not be able to establish PPP connection when CHAP/PAP authentication is required.
  • WiFi on Raspberry Pi 2 has only been tested with WiPi WiFi Dongle (Realink RT5370 chipset) and official Pi USB WiFi Dongle (Broadcom BCM43143 chipset).
    AccessPoint WiFi mode not working for Broadcom chipset.
  • Hardware watchdog: not implemented on all platforms
  • Only one WAN interface is currently supported with old networking. A warning in displayed
    in the WEB UI if the user attempts to enable more than one WAN interface
  • #4212: Wrong order of BIRTH/APPLICATION certificates for custom APP IDs registration
  • #3972: Topic name validation: issue with names containing "//" (Cloud Subscriber)
  • #4141: Sometimes user is not logged in after changing password
  • #3796: Server manager does not close properly
  • #3211: Kura Docker | Bluetooth error in log during starting service
  • #3005: Kura Gets Stuck in Loading View if Services Clicked Too Fast
  • #2843: Access Banner Content All in One Line
  • #2747: No Spacing Between "Wire Components" and Error in Wire Graph
  • #2728: WireGraph Component Description Windows Too Wide
  • #2725: Different Pop-up Windows for Warnings
  • #2702: Error Message For Long Item Names Not Displayed Properly
  • #2696: Component Name Inteferes With Wire Graph Border
  • #2695: Component Names in Wires Not Limited
  • #2410: Deployment handler and URLs with many query parameters
  • #2038: [Kura 3.2.0 QA] Package uninstallation log
  • #1993: Search Domains Are Not Supported
  • #1663: Authentication Issue with Deploy V2
  • #1572: serial modbus has errors on some hardware
  • #1529: OSGI console is not redirected to Eclipse IDE with Kura 3.0
  • #1161: Incorrectly configuring a component can be irreversable.
  • #1128: [Kura 3.0.0 M1 QA] Unable to delete manually added CamelFactory services
  • #1016: ConfigurationServiceImpl creates duplicate instances
  • #797: Design of ServiceUtil is broken
  • #771: Web UI fails with INTERNAL_ERROR when WireHelperService is not registered
  • #654: Clean up static initialization around "modem" functionality
  • #645: Clean up internal dependencies in Kura
  • #522: [Net] Modem monitor should monitor interfaces, not modems
  • #486: Build environment broken on Windows
  • #406: Replace System.get* with calls to SystemService.getProperties
  • #329: [DEPLOY-V2] Review/refactoring needed
  • #297: [Status led] What connection instance controls the status led?
  • #253: Check if bundle contexes correctly unget services after invoking getService
  • #222: CloudConnectionStatusServiceImpl does not cancel workers on component deactivation

Changelog (ESF):

  • e2de7ec6c5 - fix: wrong com1 path for 15a-12 serial port configurator (#2743) (Matteo Maiero)
  • fa139baad6 - fix(rg15a12): handle IllegalArgumentException when GPIO pin is not found on activate (#2742) (Matteo Maiero)
  • 87edf783e7 - chore: add ESF 7.6.2 release notes (#2741) (github-actions[bot])
  • ec95d18f9e - fix(distrib): override fail2ban firewalld banaction with iptables for generic profiles (#2740) (Matteo Maiero)
  • 05d74e6671 - chore: add ESF 7.6.2 release notes (#2738) (github-actions[bot])
  • 2a537be74c - fix(distrib): port path traversal fix from esf-hardening and update sudoers hash [backport release-7.6.0] (#2736) (Matteo Maiero)
  • 4b23b88b6c - chore: add ESF 7.6.2 release notes (#2735) (github-actions[bot])
  • 619c5e8fa7 - fix: Fixed cacerts.ks default password [backport release-7.6.0] (#2734) (Salvatore Coppola)
  • 3ab8222bf8 - build(deps): updated bouncycastle from 1.78.1 to 1.84 (#2732) (Marcello Rinaldo Martina)
  • 1c32798339 - feat(distrib): Set connection led for dg1014 (#2731) (Pierantonio Merlino)
  • d6579b7ba2 - fix(distrib): added patch to remove conflicting flooding protection rules from firewall_cust (#2730) (Marcello Rinaldo Martina)
  • 9e3ac185d3 - fix(network.threat.manager): Update fail2ban kura-filter file (#2726) (Pierantonio Merlino)
  • 3ed79882d2 - fix(distrib): updated sha256 checksum in 010_esf-hardening (#2727) (Pierantonio Merlino)
  • 367fb08df4 - fix: Serial port configurator 15a12 version update (#2725) (Pierantonio Merlino)
  • 4864fe6077 - fix: update network threat manager version and build properties (#2724) (Matteo Maiero)
  • 85e3470124 - ci: Added sonar branch parameters [backport release-7.6.0] (#2721) (github-actions[bot])
  • 75d6bef670 - chore: add ESF 7.6.2 release notes (#2720) (github-actions[bot])
  • 8016da0e62 - ci(automation): avoid branch name collision on Release Notes workflow [backport release-7.6.0] (#2717) (github-actions[bot])
  • 8d419b4ce0 - chore: automated uptick to 7.6.2 (#2715) (github-actions[bot])
  • 52033c73e9 - fix: Update connection limit to work only for new connections (#2713) (Matteo Maiero)
  • de68e6b28b - fix(distrib): set watchdog device path to /dev/watchdog for boltgate2025 and boltgate2031 on generic profiles [backport release-7.6.0] (#2712) (Matteo Maiero)
  • c6762c7425 - fix(distrib): prevent path traversal in manage_sshd_files.sh [backport release 7.6.0] (#2703) (Matteo Maiero)
  • 4b8f441cd2 - feat: Updated connection status led for the 15a-12 (#2709) (Pierantonio Merlino)
  • fb6d5ef448 - ci: Pin sonar version (#2706) [backport] (#2707) (Pierantonio Merlino)
  • b9572e87d3 - fix: Remove enabling the 10-14 linux provider as not needed for 15a-14 (#2705) (Matteo Maiero)
  • 15c3c2a1c0 - fix(fail2ban): REST auth fails are not banned [backport release-7.6.0] (#2704) (Marcello Rinaldo Martina)
  • 66fc83b04a - fix: serial configurator to not trigger update-initramfs (#2701) (Matteo Maiero)
  • 80e657d809 - ci: pin versions of Actions and Reusable Workflows [backport release-7.6.0] (#2698) (Mattia Dal Ben)
  • b49e554c86 - fix: Missing lifecycle-mapping plugin for Eclipse IDE in bundles/pom (#2669) (Matteo Maiero)
  • 2e89257aa4 - ci: Specified sonar plugin info in JenkinsFile [backport release-7.6.0] (#2626) (Pierantonio Merlino)
  • 185ca89786 - ci(Jenkinsfile): auto SBOM upload (#2657) (Mattia Dal Ben)
  • 504e5889a8 - ci(Jenkinsfile): disable concurrent builds [backport release-7.6.0] (#2650) (github-actions[bot])
  • 48fd9b4a4b - ci: SBOM generation using Eclipse cbi-sbom (#2641) (Marcello Rinaldo Martina)
  • 408bf8606a - ci: fix brach detection for SBOM generation (#2638) (Mattia Dal Ben)
  • 3d4e022206 - ci(Jenkinsfile): generate SBOM with Snyk (#2629) (Mattia Dal Ben)
  • d5938b7b11 - ci(Jenkinsfile): skip build for documentation-only changes [backport release-7.6.0] (#2614) (github-actions[bot])
  • e11af8fd27 - chore: automated uptick to 7.6.2-SNAPSHOT (#2611) (github-actions[bot])

Changelog (Kura):

  • c0a8fb3e9a - fix(distrib): wrong version number for installed BC artifacts (#6268) (Marcello Rinaldo Martina)
  • 501e6d4c10 - build: Updated io.netty version to 4.1.135.Final (#6265) (Pierantonio Merlino)
  • 7c24725b6b - fix(core.keystore): prevent CRL downloads from blocking UI load [backport release-5.6.0] (#6264) (Pierantonio Merlino)
  • e5be465135 - fix(core.keystore): Fixed the addition of EC keypair [backport release-5.6.0] (#6253) (Salvatore Coppola)
  • 6bea317e29 - fix: Fixed cacerts.ks default password [backport release-5.6.0] (#6262) (Salvatore Coppola)
  • c17b44004a - fix(ai.triton.server): Fixed feature version mismatch causing distrib build failure (#6258) (Matteo Maiero)
  • 98131d6050 - build(deps): updated bouncycastle from 1.78.1 to 1.84 (#6251) (Marcello Rinaldo Martina)
  • 378f7f327f - feat(nm): prevent unnecessary network deactivation and configuration updates [backport release-5.6] (#6254) (Pierantonio Merlino)
  • 56be0dcfb5 - build: Updated io.netty version to 4.1.134.Final (#6250) (Pierantonio Merlino)
  • b90190b42f - fix(rest): map unhandled exceptions so failed requests are audited (#6246) (Marcello Rinaldo Martina)
  • 5706b1d779 - fix: misalignment between metatype and code in eclipseiot.mqtt bundle [backport release-5.6.0] (#6244) (github-actions[bot])
  • b992922034 - chore: Updated SSLKeystore with the latest Eclipse Marketplace certificate [backport release-5.6.0] (#6245) (Salvatore Coppola)
  • 63938fc7ff - chore: update Kura 5.6.2 release notes (#6240) (eclipse-kura-bot)
  • 723ef076b8 - fix(core.keystore): Improve CRL management (#6230) [backport release-5.6.0] (#6237) (Salvatore Coppola)
  • 0ba7612f99 - fix(target-platform): Updated Kura version in target-platform config (#6239) (Pierantonio Merlino)
  • 7179d2fa8c - ci(automation): avoid branch name collision on Release Notes workflow [backport release-5.6.0] (#6238) (Mattia Dal Ben)
  • d1a611ef47 - chore: add Kura 5.6.2 release notes (#6235) (Pierantonio Merlino)
  • 1ef6e8c141 - chore: automated uptick to 5.6.2 (#6232) (eclipse-kura-bot)
  • 35c65ff6d9 - fix: Correctly handle X-Forwarded-For header for audit logging [backport release-5.6.0] (#6218) (Matteo Maiero)
  • 745cd6df2d - chore: update netty to 4.1.132.Final [backport release-5.6.0] (#6216) (Matteo Maiero)
  • d3a52a7c9a - chore: Updated Jetty to 9.4.58.v20250814 [backport release-5.6.0] (#6217) (Matteo Maiero)
  • 1e53ce4c63 - ci: pin sonar-maven-plugin to 5.5.0.6356 and narrow binaries path (#6227) (Matteo Maiero)
  • 56decab7f2 - ci: pin versions of Actions and Reusable Workflows [backport release-5.6.0] (#6212) (Mattia Dal Ben)
  • f961ca425e - feat(linux.gpio.libgpiod): Added support to multiple pin listeners (#6197) (Pierantonio Merlino)
  • a669473c20 - fix(linux.gpio.libgpiod): Fix GPIO events behavior in libgpiod v1 (#6184) (Pierantonio Merlino)
  • f7456aca86 - fix: Fixed password encryption in ConfigurationService.createFactoryConfiguration [backport release-5.6.0] (#6182) (nicolatimeus)
  • 255b68934d - fix: Fixed placeholder handling for password defaults [backport release-5.6.0] (#6189) (nicolatimeus)
  • fcfc8699b6 - test: Improved CloudConnectionEndpointsTest [backport release-5.6.0] (#6186) (nicolatimeus)
  • d9285a638a - ci: Specified sonar plugin version in JenkinsFile [backport release 5.6.0] (#6141) (Pierantonio Merlino)
  • 26382c4b00 - chore: automated uptick to 5.6.2-SNAPSHOT (#6115) (eclipse-kura-bot)
  • a1031da8c4 - ci(workflows): backport shared workflow to release 5.6.0 (#6117) (Mattia Dal Ben)