openbsd
7 years agorejname[] is also -r option buffer, and should be PATH_MAX
deraadt [Mon, 12 Jun 2017 14:23:26 +0000 (14:23 +0000)]
rejname[] is also -r option buffer, and should be PATH_MAX
ok millert

7 years agospecify free() size from the old allocation, not new allocation.
deraadt [Mon, 12 Jun 2017 13:45:39 +0000 (13:45 +0000)]
specify free() size from the old allocation, not new allocation.
fix from C Turt

7 years agodevice path should be PATH_MAX. Any NAME_MAX without +1 is suspect
deraadt [Mon, 12 Jun 2017 13:41:24 +0000 (13:41 +0000)]
device path should be PATH_MAX.  Any NAME_MAX without +1 is suspect
to begin with anyways.

7 years agoifq_start does OACTIVE and RUNNING checks for the driver
mikeb [Mon, 12 Jun 2017 12:35:07 +0000 (12:35 +0000)]
ifq_start does OACTIVE and RUNNING checks for the driver

Reminded by dlg@.

7 years agoNeed to flush out the linefeed after wrapper. GitHub issue 970.
nicm [Mon, 12 Jun 2017 10:57:35 +0000 (10:57 +0000)]
Need to flush out the linefeed after wrapper. GitHub issue 970.

7 years agoAdd explicit keys for the bracketed paste sequences, both to avoid mix
nicm [Mon, 12 Jun 2017 07:04:24 +0000 (07:04 +0000)]
Add explicit keys for the bracketed paste sequences, both to avoid mix
ups with other keys and to make logs clearer.

7 years agotypo; from bryan vyhmeister
deraadt [Mon, 12 Jun 2017 04:57:42 +0000 (04:57 +0000)]
typo; from bryan vyhmeister

7 years agoFrom FreeBSD (r227593, r307982):
kevlo [Mon, 12 Jun 2017 03:00:26 +0000 (03:00 +0000)]
From FreeBSD (r227593, r307982):
More and more RealTek controllers started to implement EEE feature.
Vendor driver seems to load a kind of firmware for EEE with
additional PHY fixups.  It is known that the EEE feature may need
ASPM support.  Unfortunately there is no documentation for EEE of
the controller so enabling ASPM may cause more problems.

The Realtek vendor drivers for FreeBSD and Linux also disable ASPM and
clock request.  While here, add a define for the ECPM (Enable Clock Power
Management) bit.

Tested by stsp@ and myself.
ok stsp@

7 years agomake vers.o not depend on gap.o using a trick, because it is piece of
deraadt [Sun, 11 Jun 2017 22:51:21 +0000 (22:51 +0000)]
make vers.o not depend on gap.o using a trick, because it is piece of
fiction participating only in the linkphase.
tricks from rpe and espie

7 years agoUse umask 077 instead of cp -p when installing the kernel as root.
bluhm [Sun, 11 Jun 2017 20:50:32 +0000 (20:50 +0000)]
Use umask 077 instead of cp -p when installing the kernel as root.
Otherwise owner of /bsd could be the build user with permissions
inherited from the compile directory.
OK deraadt@ tb@

7 years agoooops, fix a glitch in the previous commit...
schwarze [Sun, 11 Jun 2017 20:02:48 +0000 (20:02 +0000)]
ooops, fix a glitch in the previous commit...

7 years agoUse a common 'goto bad' style and set mp to NULL after freeing it
bluhm [Sun, 11 Jun 2017 19:59:57 +0000 (19:59 +0000)]
Use a common 'goto bad' style and set mp to NULL after freeing it
in ipip_input_gif().  This prevents a use-after-free if there is a
bug in the IP input functions.
OK mpi@

7 years agochurn caused by the new Mdocdate messages, no easy way to avoid this :(
schwarze [Sun, 11 Jun 2017 19:48:26 +0000 (19:48 +0000)]
churn caused by the new Mdocdate messages, no easy way to avoid this :(

7 years agoFix a test race, wait after kill in case writing the core dump takes
bluhm [Sun, 11 Jun 2017 19:43:16 +0000 (19:43 +0000)]
Fix a test race, wait after kill in case writing the core dump takes
a while.  Adjust wrong comments.  Mention regress- in program name
to make clear where violations seen in process accounting happend.

7 years agoStyle message about legacy man(7) date format in mdoc(7) documents
schwarze [Sun, 11 Jun 2017 19:36:31 +0000 (19:36 +0000)]
Style message about legacy man(7) date format in mdoc(7) documents
and operating system dependent messages about missing or unexpected
Mdocdate; inspired by mdoclint(1).

7 years agorequest -> promises; from scott cheloha
jmc [Sun, 11 Jun 2017 18:56:09 +0000 (18:56 +0000)]
request -> promises; from scott cheloha

7 years agousr/bin/ktrace: replace snprintf(3)/write(2) with dprintf(3)
awolk [Sun, 11 Jun 2017 17:32:19 +0000 (17:32 +0000)]
usr/bin/ktrace: replace snprintf(3)/write(2) with dprintf(3)

Brought to attention by BlackFrog on #openbsd-daily

OK deraadt@

7 years agostyle message about missing .Fn markup; inspired by mdoclint
schwarze [Sun, 11 Jun 2017 17:16:36 +0000 (17:16 +0000)]
style message about missing .Fn markup; inspired by mdoclint

7 years agomissing .Fn macros; found with mandoc -Tlint
schwarze [Sun, 11 Jun 2017 17:06:27 +0000 (17:06 +0000)]
missing .Fn macros; found with mandoc -Tlint

7 years agomissing .Fn markup for main(); found with mandoc -Tlint
schwarze [Sun, 11 Jun 2017 16:58:49 +0000 (16:58 +0000)]
missing .Fn markup for main(); found with mandoc -Tlint

7 years agoAdd missing .Fn markup to in() and out(); found with mandoc -Tlint.
schwarze [Sun, 11 Jun 2017 16:43:18 +0000 (16:43 +0000)]
Add missing .Fn markup to in() and out(); found with mandoc -Tlint.
Delete useless \*(Gt and \*(Lt while here.

7 years agoContinue the flattening of the pledge logic started in r1.184 and place
tb [Sun, 11 Jun 2017 14:38:52 +0000 (14:38 +0000)]
Continue the flattening of the pledge logic started in r1.184 and place
a blank space somewhere else.

suggested by and ok jsing

7 years agoDo not issue the message "no blank before trailing delimiter" for .No.
schwarze [Sun, 11 Jun 2017 14:10:24 +0000 (14:10 +0000)]
Do not issue the message "no blank before trailing delimiter" for .No.
In practice, that message only matters inside .Bf, and even there, it
can occasionally be a false positive.  In all other cases, it usually
is a false positive, so it is better to drop it outright.
Suggested by jmc@.

7 years agomake two macros more semantic
schwarze [Sun, 11 Jun 2017 14:03:46 +0000 (14:03 +0000)]
make two macros more semantic

7 years agoSimple style(9) fixes from Juuso Lapinlampi, mostly whitespace and
tb [Sun, 11 Jun 2017 10:53:07 +0000 (10:53 +0000)]
Simple style(9) fixes from Juuso Lapinlampi, mostly whitespace and
omitting parentheses in return statements. Binary change because of
return instead of exit(3) from main and because help() is now __dead.

ok awolk

7 years agoDefine register_splx_handler() in one place.
visa [Sun, 11 Jun 2017 10:01:23 +0000 (10:01 +0000)]
Define register_splx_handler() in one place.

7 years agoFix TLB size computation on OCTEON II and III. The CPUs have utilized
visa [Sun, 11 Jun 2017 03:35:30 +0000 (03:35 +0000)]
Fix TLB size computation on OCTEON II and III. The CPUs have utilized
the whole TLB space even before this. However, TLB initialization on
boot and TLB flush on ASID wraparound have been incomplete. These have
caused crashes of processes.

7 years agoAdd a memory barrier to ensure that stores become visible
visa [Sun, 11 Jun 2017 03:03:05 +0000 (03:03 +0000)]
Add a memory barrier to ensure that stores become visible
in a proper order.

7 years agointeger overflow for two range checks
deraadt [Sun, 11 Jun 2017 02:06:36 +0000 (02:06 +0000)]
integer overflow for two range checks
fix from C Turt, ok miod

7 years agoIf -P and -c were given, a second pledge call tried to add "rpath" to the
tb [Sat, 10 Jun 2017 18:14:10 +0000 (18:14 +0000)]
If -P and -c were given, a second pledge call tried to add "rpath" to the
first pledge promises, so nc exited with EPERM. To fix this, merge the
pledge of the Pflag && usetls case into the first pledge block. This
allows us to get rid of the second pledge block and thus to simplify the
logic a bit. While there, add a missing blank to an error string.

Joint effort by the #openbsd-daily code reading group, problem found and
initial patch by <rain1 openmailbox org>.

ok awolk

7 years agoNuke unused field bootp_policy and associated enum{}.
krw [Sat, 10 Jun 2017 18:03:50 +0000 (18:03 +0000)]
Nuke unused field bootp_policy and associated enum{}.

7 years agoNuke unused global warnings_occurred.
krw [Sat, 10 Jun 2017 17:56:29 +0000 (17:56 +0000)]
Nuke unused global warnings_occurred.

7 years agoReduce false positives for the "no blank before trailing delimiter" message.
schwarze [Sat, 10 Jun 2017 16:53:58 +0000 (16:53 +0000)]
Reduce false positives for the "no blank before trailing delimiter" message.
This brings us down to one false positive for about every 18 pages.

7 years agominor markup simplifications
schwarze [Sat, 10 Jun 2017 16:32:08 +0000 (16:32 +0000)]
minor markup simplifications

7 years agoimprove semantic markup for __attribute__
schwarze [Sat, 10 Jun 2017 16:00:27 +0000 (16:00 +0000)]
improve semantic markup for __attribute__

7 years agomissing blank before full stop, found with mandoc -Tlint
schwarze [Sat, 10 Jun 2017 15:39:43 +0000 (15:39 +0000)]
missing blank before full stop, found with mandoc -Tlint

7 years agoadd missing blanks before several delimiters; found with mandoc -Tlint
schwarze [Sat, 10 Jun 2017 14:54:42 +0000 (14:54 +0000)]
add missing blanks before several delimiters; found with mandoc -Tlint

7 years agomissing space before trailing punctuation; found with mandoc -Tlint
schwarze [Sat, 10 Jun 2017 14:38:29 +0000 (14:38 +0000)]
missing space before trailing punctuation; found with mandoc -Tlint

7 years agoremove lots of bogus escaping, some of which even broke the output;
schwarze [Sat, 10 Jun 2017 14:31:59 +0000 (14:31 +0000)]
remove lots of bogus escaping, some of which even broke the output;
found with mandoc -Tlint

7 years agofix imprecise .Fa markup; found with mandoc -Tlint
schwarze [Sat, 10 Jun 2017 14:15:52 +0000 (14:15 +0000)]
fix imprecise .Fa markup; found with mandoc -Tlint

7 years agoFix broken markup of function pointer invocations; found
schwarze [Sat, 10 Jun 2017 14:07:23 +0000 (14:07 +0000)]
Fix broken markup of function pointer invocations; found
with mandoc -Tlint.  While here, delete .Tn macros.

7 years agofix broken markup of callback arguments; found with mandoc -Tlint
schwarze [Sat, 10 Jun 2017 13:58:59 +0000 (13:58 +0000)]
fix broken markup of callback arguments; found with mandoc -Tlint

7 years agoFix broken escaping: "\." is almost never what you want; found with
schwarze [Sat, 10 Jun 2017 13:31:45 +0000 (13:31 +0000)]
Fix broken escaping: "\." is almost never what you want; found with
mandoc -Tlint.  While here, make macro usage more consistent.

7 years agofix a sentence that used unusual terminology, the wrong macro,
schwarze [Sat, 10 Jun 2017 13:24:03 +0000 (13:24 +0000)]
fix a sentence that used unusual terminology, the wrong macro,
and broken delimiter syntax; found with mandoc -Tlint

7 years agorepair broken markup of callback argument; found with mandoc -Tlint
schwarze [Sat, 10 Jun 2017 13:10:52 +0000 (13:10 +0000)]
repair broken markup of callback argument; found with mandoc -Tlint

7 years agoPass M_CANFAIL to malloc(9) calls which use M_WAITOK but are tested
kevlo [Sat, 10 Jun 2017 12:58:37 +0000 (12:58 +0000)]
Pass M_CANFAIL to malloc(9) calls which use M_WAITOK but are tested
for failure.

ok armani@

7 years agoUse software interrupt to process TX/RX data between sio and tty(4)
aoyama [Sat, 10 Jun 2017 12:23:00 +0000 (12:23 +0000)]
Use software interrupt to process TX/RX data between sio and tty(4)
layer.

This is a straightforwad port of current NetBSD/luna68k implementation
by Izumi Tsutsui.  Tested on both LUNA-88K and LUNA-88K2.

7 years agoReport processes that were killed due to pledge or memory access
bluhm [Sat, 10 Jun 2017 11:28:30 +0000 (11:28 +0000)]
Report processes that were killed due to pledge or memory access
violations in the daily mail.
OK millert@ jmc@

7 years agoperl(1)'s ...
espie [Sat, 10 Jun 2017 10:13:10 +0000 (10:13 +0000)]
perl(1)'s ...

7 years agouse mandoc annotations for flags and such
espie [Sat, 10 Jun 2017 10:12:06 +0000 (10:12 +0000)]
use mandoc annotations for flags and such

7 years agoDon't describe AppleTalk's output format and bugs.
akfaew [Sat, 10 Jun 2017 06:52:28 +0000 (06:52 +0000)]
Don't describe AppleTalk's output format and bugs.

OK claudio@
jmc@ doesn't object

7 years agoprint '?' instead of incorrect link count (that the protocol doesn't
djm [Sat, 10 Jun 2017 06:36:46 +0000 (06:36 +0000)]
print '?' instead of incorrect link count (that the protocol doesn't
provide) for remote listings. bz#2710 ok dtucker@

7 years agoimplement sorting for globbed ls; bz#2649 ok dtucker@
djm [Sat, 10 Jun 2017 06:33:34 +0000 (06:33 +0000)]
implement sorting for globbed ls; bz#2649 ok dtucker@

7 years agostyle message about missing blank before trailing delimiter;
schwarze [Sat, 10 Jun 2017 01:48:31 +0000 (01:48 +0000)]
style message about missing blank before trailing delimiter;
inspired by mdoclint(1), and jmc@ considers it useful

7 years agodo not break the line between Bsx/Bx/Fx/Nx/Ox/Dx and its arguments
schwarze [Sat, 10 Jun 2017 01:27:44 +0000 (01:27 +0000)]
do not break the line between Bsx/Bx/Fx/Nx/Ox/Dx and its arguments

7 years agoFill RX ring during init and bail early on send if OACTIVE is set
mikeb [Fri, 9 Jun 2017 20:38:48 +0000 (20:38 +0000)]
Fill RX ring during init and bail early on send if OACTIVE is set
or IFF_RUNNING is not.

7 years ago- pfsync_input() must grab PF_LOCK
sashan [Fri, 9 Jun 2017 17:43:06 +0000 (17:43 +0000)]
- pfsync_input() must grab PF_LOCK
  reported and patch tested by Hrvoje Popovski

O.K. bluhm@

7 years agomention that the config file is created at first run, since it doesn't
tedu [Fri, 9 Jun 2017 16:46:57 +0000 (16:46 +0000)]
mention that the config file is created at first run, since it doesn't
exist on a default install (thus making it impossible to read and study)

7 years agoExtend filters (f key) to buffer and client mode and add -f flag to
nicm [Fri, 9 Jun 2017 16:01:39 +0000 (16:01 +0000)]
Extend filters (f key) to buffer and client mode and add -f flag to
specify to command.

7 years agoCorrect number of players, the program enforces a range from 2 to 9.
fcambus [Fri, 9 Jun 2017 15:32:40 +0000 (15:32 +0000)]
Correct number of players, the program enforces a range from 2 to 9.

OK tb@, jmc@

7 years agoAdd -O option to choose-* to set initial sort order.
nicm [Fri, 9 Jun 2017 15:29:15 +0000 (15:29 +0000)]
Add -O option to choose-* to set initial sort order.

7 years agoDefault sort for buffer mode should be time not name.
nicm [Fri, 9 Jun 2017 15:17:20 +0000 (15:17 +0000)]
Default sort for buffer mode should be time not name.

7 years agoRemove a WAITOK that has sneaked in
mikeb [Fri, 9 Jun 2017 14:36:43 +0000 (14:36 +0000)]
Remove a WAITOK that has sneaked in

7 years agoConvert to ifq_dequeue and perform m_defrag if the mbuf doesn't fit
mikeb [Fri, 9 Jun 2017 14:34:10 +0000 (14:34 +0000)]
Convert to ifq_dequeue and perform m_defrag if the mbuf doesn't fit

With suggestions from and OK dlg

7 years agoUse brackets around prompts which looks better and matches the other modes.
nicm [Fri, 9 Jun 2017 14:00:46 +0000 (14:00 +0000)]
Use brackets around prompts which looks better and matches the other modes.

7 years agoIntroduce iwm_nic_assert_locked() to verify that the driver has correctly
stsp [Fri, 9 Jun 2017 13:47:26 +0000 (13:47 +0000)]
Introduce iwm_nic_assert_locked() to verify that the driver has correctly
requested MAC access before accessing certain registers, as required
by the hardware.

Use it to assert that hardware is still in an accessible state before
reading or writing such a register. For now, panic if that check fails.
The long term goal is to make this a non-fatal error and handle it properly
in all code paths that end up reading or writing such a register.

Fix a missing NIC lock on 8000 hardware, found by this new assertion.

Also, grab the NIC lock early during hardware init and keep it until init
is done. The previous code relinquished and reacquired the NIC lock several
times during the init sequence. It seems this is what was causing some random
errors when the interface was brought up, such as "could not enable Tx queue",
"could not add aux station", and "could not add phy context".
For some reason, bsd.rd kernels were suffering particularly hard from such
problems, to the point where some machines could not be upgraded over iwm(4).
This change does not eliminate such problems entirely but is a step forward.

Prodded by deraadt@
This change has already been in snaps for a while.

7 years agoFix the resume code path in iwm(4) to no longer call iwm_stop() before
stsp [Fri, 9 Jun 2017 13:46:15 +0000 (13:46 +0000)]
Fix the resume code path in iwm(4) to no longer call iwm_stop() before
initializing the hardware. Prevents "acquiring device failed" messages
during resume. Also, start the hardware up in DVACT_RESUME already and
verify that it has started by the time we reach DVACT_WAKEUP, before
scheduling the iwm_init_task which loads firmware etc.
With help from deraadt@
test & ok tb@

7 years agoIf we receive a router solicitation with a source link-layer address
florian [Fri, 9 Jun 2017 13:31:03 +0000 (13:31 +0000)]
If we receive a router solicitation with a source link-layer address
option respond with a unicast advertisement. This improves air time on
wireless networks and reduces energy consumption on battery powered
devices. For details see RFC 7772 "Reducing Energy Consumption of
Router Advertisements" aka BCP 202.
Input & OK bluhm@

7 years agoReplace rtrequest(RTM_DELETE...) rtrequest_delete() and do not even
mpi [Fri, 9 Jun 2017 12:56:43 +0000 (12:56 +0000)]
Replace rtrequest(RTM_DELETE...) rtrequest_delete() and do not even
try to remove a route from the table if it is and invalid cache.

This is a step towards decoupling code dealing with userland and kernel
inserted routes.

ok bluhm@

7 years agoAdd a hook when the clipboard is set.
nicm [Fri, 9 Jun 2017 09:21:24 +0000 (09:21 +0000)]
Add a hook when the clipboard is set.

7 years agoDrop uneeded return from rollback_patch().
ajacoutot [Fri, 9 Jun 2017 07:37:38 +0000 (07:37 +0000)]
Drop uneeded return from rollback_patch().

7 years ago/etc/mtree/BSD.x11.dist is part of base, not X; so check for
ajacoutot [Fri, 9 Jun 2017 07:32:26 +0000 (07:32 +0000)]
/etc/mtree/BSD.x11.dist is part of base, not X; so check for
/var/sysmerge/xetc.tgz to detect whether we have the x sets installed.

7 years agoreturn failure rather than fatal() for more cases during mux
djm [Fri, 9 Jun 2017 06:47:13 +0000 (06:47 +0000)]
return failure rather than fatal() for more cases during mux
negotiations. Causes the session to fall back to a non-mux connection
if they occur. bz#2707 ok dtucker@

7 years agoin description of public key authentication, mention that the server
djm [Fri, 9 Jun 2017 06:43:01 +0000 (06:43 +0000)]
in description of public key authentication, mention that the server
will send debug messages to the client for some error conditions
after authentication has completed. bz#2709 ok dtucker

7 years agobetter translate libcrypto errors by looking deeper in the accursed
djm [Fri, 9 Jun 2017 06:40:24 +0000 (06:40 +0000)]
better translate libcrypto errors by looking deeper in the accursed
error stack for codes that indicate the wrong passphrase was supplied
for a PEM key. bz#2699 ok dtucker@

7 years agoAdd comments referring to the relevant RFC sections for rekeying
dtucker [Fri, 9 Jun 2017 04:40:04 +0000 (04:40 +0000)]
Add comments referring to the relevant RFC sections for rekeying
behaviour.

7 years agoturns out the case on 802.1 suffixes is significant. fix 802.1Q
dlg [Fri, 9 Jun 2017 01:39:07 +0000 (01:39 +0000)]
turns out the case on 802.1 suffixes is significant. fix 802.1Q

pointed out by jsg@

7 years agoturns out the case of 802.1 suffixes is significant. fix up 802.1X and Q.
dlg [Fri, 9 Jun 2017 01:36:05 +0000 (01:36 +0000)]
turns out the case of 802.1 suffixes is significant. fix up 802.1X and Q.

pointed out by jsg@

7 years agoAdd a missing header file.
aoyama [Thu, 8 Jun 2017 21:30:26 +0000 (21:30 +0000)]
Add a missing header file.

ok deraadt@

7 years agoRemove esym (.data) patching. Thanks to Mark we stopped requiring this
patrick [Thu, 8 Jun 2017 19:40:49 +0000 (19:40 +0000)]
Remove esym (.data) patching.  Thanks to Mark we stopped requiring this
and with the random-order kernel we shouldn't be doing that anyway.

ok kettenis@

7 years agoProperly reinitialize roffce_node between parses,
schwarze [Thu, 8 Jun 2017 19:35:34 +0000 (19:35 +0000)]
Properly reinitialize roffce_node between parses,
or this may crash with use-after-free in makewhatis(8);
reported by jmc@, thanks!

7 years agoremove the timeslot code, it was only for now deleted T1 devices.
tedu [Thu, 8 Jun 2017 19:23:39 +0000 (19:23 +0000)]
remove the timeslot code, it was only for now deleted T1 devices.
ok sthen

7 years agoPass CC and CXX to make depend as well. As soon as we support
patrick [Thu, 8 Jun 2017 18:33:08 +0000 (18:33 +0000)]
Pass CC and CXX to make depend as well.  As soon as we support
dependencies in the clang makefiles we need to make sure to use
a compiler that supports C++11.

7 years agodelete -e and -l, now covered by mandoc; OK jmc@ wiz@
schwarze [Thu, 8 Jun 2017 18:25:16 +0000 (18:25 +0000)]
delete -e and -l, now covered by mandoc; OK jmc@ wiz@

7 years agoImplement w layout specifier (minimum column width).
schwarze [Thu, 8 Jun 2017 18:11:15 +0000 (18:11 +0000)]
Implement w layout specifier (minimum column width).
Improve width calculation of text blocks.
Reduces the groff/mandoc diff in Base+Xenocara by about 800 lines.

7 years agoLink lastcomm regress to build.
bluhm [Thu, 8 Jun 2017 17:33:21 +0000 (17:33 +0000)]
Link lastcomm regress to build.

7 years agoStart with a clean /var/account/acct accounting file and turn on
bluhm [Thu, 8 Jun 2017 17:29:33 +0000 (17:29 +0000)]
Start with a clean /var/account/acct accounting file and turn on
process accounting with accton(8).  Each test executes a command
with a unique name and checks the flags in the lastcomm(1) output.
Run tests with fork, su, core, xsig, pledge, trap accounting.

7 years agoASLR, W^X, and guard pages trigger processor traps that result in
bluhm [Thu, 8 Jun 2017 17:14:02 +0000 (17:14 +0000)]
ASLR, W^X, and guard pages trigger processor traps that result in
SIGILL, SIGBUS, SIGSEGV signals.  Make such memory violations visible
in lastcomm(1).  This also works if a programm tries to hide them
with a signal handler.  Manual kill -SEGV does not generate false
positives.
OK deraadt@

7 years agoupdate permissions info to match recent changes
millert [Thu, 8 Jun 2017 17:13:39 +0000 (17:13 +0000)]
update permissions info to match recent changes

7 years agoAdd logging for when we find a non-file in the at spool that was
millert [Thu, 8 Jun 2017 16:23:39 +0000 (16:23 +0000)]
Add logging for when we find a non-file in the at spool that was
a file when we scanned the at spool earlier.

7 years agoclarify set prio: the second prio given applies to
henning [Thu, 8 Jun 2017 15:39:38 +0000 (15:39 +0000)]
clarify set prio: the second prio given applies to
1) TCP ACKs
2) packets with ToS=lowdelay
and not TCP ACKs that have ToS=lowdelay
confusion discovered during bsdcan pf tutorial

7 years agoStart syslogd with -rr. With different timing the order of messages
bluhm [Thu, 8 Jun 2017 14:38:35 +0000 (14:38 +0000)]
Start syslogd with -rr.  With different timing the order of messages
changed.  Then a "last message repeated" confused the test.

7 years agoNotify userland when a new ND is reachable.
mpi [Thu, 8 Jun 2017 13:28:03 +0000 (13:28 +0000)]
Notify userland when a new ND is reachable.

The same notification is already present in ARP.

From Jan Klemkow, ok bluhm@

7 years agomake the internal a2roffsu() interface more powerful by returning
schwarze [Thu, 8 Jun 2017 12:54:40 +0000 (12:54 +0000)]
make the internal a2roffsu() interface more powerful by returning
a pointer to the end of the parsed data, making it easier to
parse subsequent bytes

7 years agowrec.org is dead. Use working links instead.
tb [Thu, 8 Jun 2017 12:37:14 +0000 (12:37 +0000)]
wrec.org is dead. Use working links instead.
patch from jj, found by "Norrland" on icb. Thanks!

7 years agoWrap startup code with .ent and .end for proper disassembly.
visa [Thu, 8 Jun 2017 12:11:46 +0000 (12:11 +0000)]
Wrap startup code with .ent and .end for proper disassembly.

7 years agoMove loongson/octeon/sgi unmap_startup() under arch/mips64.
visa [Thu, 8 Jun 2017 12:02:52 +0000 (12:02 +0000)]
Move loongson/octeon/sgi unmap_startup() under arch/mips64.

7 years agoSplit early startup code out of locore.S into locore0.S. Adjust link
visa [Thu, 8 Jun 2017 11:47:24 +0000 (11:47 +0000)]
Split early startup code out of locore.S into locore0.S.  Adjust link
run so that this locore0.o is always at the start of the executable.
But randomize the link order of all other .o files in the kernel, so
that their exec/rodata/data/bss segments land all over the place.

Late during kernel boot, smash the startup code with traps so that
it does not point to the other randomly placed code.  It has be smashed,
because sgi runs in the kseg0 or xkphys space.

As a result, the internal layout of every newly build bsd kernel is
different from past kernels.  Internal relative offsets are not known
to an outside attacker.

Ramdisk kernels cannot be compiled like this, because they are gzip'd.
When the internal pointer references change, the compression dictionary
bloats and results in poorer compression.

7 years agoInvoke openssl with -passin file rather than -key in ca_revoke().
jsg [Thu, 8 Jun 2017 11:45:44 +0000 (11:45 +0000)]
Invoke openssl with -passin file rather than -key in ca_revoke().
From Andrei-Marius Radu via sthen@

7 years agoSplit early startup code out of locore.S into locore0.S. Adjust link
visa [Thu, 8 Jun 2017 11:44:00 +0000 (11:44 +0000)]
Split early startup code out of locore.S into locore0.S.  Adjust link
run so that this locore0.o is always at the start of the executable.
But randomize the link order of all other .o files in the kernel, so
that their exec/rodata/data/bss segments land all over the place.

Late during kernel boot, smash the startup code with traps so that
it does not point to the other randomly placed code.  It has be smashed,
because loongson runs in the kseg0 space.

As a result, the internal layout of every newly build bsd kernel is
different from past kernels.  Internal relative offsets are not known
to an outside attacker.

Ramdisk kernels cannot be compiled like this, because they are gzip'd.
When the internal pointer references change, the compression dictionary
bloats and results in poorer compression.