openbsd
7 years agouse cmp in a loop instead of diff -N to compare directories. The former
dtucker [Mon, 11 Dec 2017 11:41:56 +0000 (11:41 +0000)]
use cmp in a loop instead of diff -N to compare directories. The former
works on more platforms for Portable.

7 years agobump to 2.7.0
bcook [Mon, 11 Dec 2017 11:04:04 +0000 (11:04 +0000)]
bump to 2.7.0

7 years agofix the description of delete-non-matching-lines;
jmc [Mon, 11 Dec 2017 07:27:07 +0000 (07:27 +0000)]
fix the description of delete-non-matching-lines;
from mazocomp

7 years agohttp://repzret.org/p/repzret/
deraadt [Mon, 11 Dec 2017 05:48:01 +0000 (05:48 +0000)]
http://repzret.org/p/repzret/
My read of this:  Long time ago (Think Conan, not dinasaurs) during the race
to make speedier processors, a cpu vendor built a pipeline with a bad stall,
and proposed a tremendously hasky workaround.  A wizard adopted this into his
perl scroll, and failed to reflect later when no compiler adopted the practice.
This relic remains at the tail end of some functions in OpenSSL as
".byte 0xf3,0xc3".  Banish it straight to hell.
ok mlarkin, others also stared blankly

7 years agoIn uvm Chuck decided backing store would not be allocated proactively
deraadt [Mon, 11 Dec 2017 05:27:40 +0000 (05:27 +0000)]
In uvm Chuck decided backing store would not be allocated proactively
for blocks re-fetchable from the filesystem.  However at reboot time,
filesystems are unmounted, and since processes lack backing store they
are killed. Since the scheduler is still running, in some cases init is
killed... which drops us to ddb [noted by bluhm].  Solution is to convert
filesystems to read-only [proposed by kettenis]. The tale follows:
sys_reboot() should pass proc * to MD boot() to vfs_shutdown() which
completes current IO with vfs_busy VB_WRITE|VB_WAIT, then calls VFS_MOUNT()
with MNT_UPDATE | MNT_RDONLY, soon teaching us that *fs_mount() calls a
copyin() late... so store the sizes in vfsconflist[] and move the copyin()
to sys_mount()... and notice nfs_mount copyin() is size-variant, so kill
legacy struct nfs_args3.  Next we learn ffs_mount()'s MNT_UPDATE code is
sharp and rusty especially wrt softdep, so fix some bugs adn add
~MNT_SOFTDEP to the downgrade.  Some vnodes need a little more help,
so tie them to &dead_vnops.

ffs_mount calling DIOCCACHESYNC is causing a bit of grief still but
this issue is seperate and will be dealt with in time.
couple hundred reboots by bluhm and myself, advice from guenther and
others at the hut

7 years agoSergey Bronnikov's code coverage analysis shows that a few more code paths
tb [Mon, 11 Dec 2017 01:11:12 +0000 (01:11 +0000)]
Sergey Bronnikov's code coverage analysis shows that a few more code paths
could be exercised. Add a few tests to do just that. The wDn test is
currently disabled, as it will only pass after a commit to jot.c.

7 years agoUse correct mask to derive portid from "reg" property in cpu_match.
kettenis [Mon, 11 Dec 2017 00:15:50 +0000 (00:15 +0000)]
Use correct mask to derive portid from "reg" property in cpu_match.
Use cpu_myid() since it makes the coe more obvious.

7 years agomore 0xcc, in data. There are i386 machines without NX, so this change
deraadt [Sun, 10 Dec 2017 21:44:07 +0000 (21:44 +0000)]
more 0xcc, in data. There are i386 machines without NX, so this change
isn't a no-op
ok mlarkin

7 years agoStop running iwm(4) devices in "continuous active mode (CAM)".
stsp [Sun, 10 Dec 2017 20:34:41 +0000 (20:34 +0000)]
Stop running iwm(4) devices in "continuous active mode (CAM)".

Instead, enable device-level power saving which apparently allows
Tx/Rx RF circuitry to be switched off while inactive to save some power.
Turns out CAM is meant for debugging purposes, not normal operation.

NB: This has nothing to do with 802.11 power saving.

Tested by myself and phessler. There is no visible behaviour change.
ok deraadt@ phessler@

7 years agossh/lib hasn't worked towards our code-sharing goals for a quit while,
deraadt [Sun, 10 Dec 2017 19:37:57 +0000 (19:37 +0000)]
ssh/lib hasn't worked towards our code-sharing goals for a quit while,
perhaps it is too verbose?  Change each */Makefile to specifying exactly
what sources that program requires, compiling it seperate.  Maybe we'll
iterate by sorting those into seperatable chunks, splitting up files
which contain common code + server/client specific code, or whatnot. But
this isn't one step, or we'd have done it a long time ago..
ok dtucker markus djm

7 years agoadd #ifndef SMALL to slaacd.c as needed to fix 'make release'
stsp [Sun, 10 Dec 2017 17:34:05 +0000 (17:34 +0000)]
add #ifndef SMALL to slaacd.c as needed to fix 'make release'

7 years agoAdd support for the internal PHY on the Allwinner H3. From Stephen Graf.
kettenis [Sun, 10 Dec 2017 12:28:37 +0000 (12:28 +0000)]
Add support for the internal PHY on the Allwinner H3.  From Stephen Graf.

7 years agoFix MDIO_CMD register bit definitions. From Stepen Graf.
kettenis [Sun, 10 Dec 2017 11:58:15 +0000 (11:58 +0000)]
Fix MDIO_CMD register bit definitions.  From Stepen Graf.

7 years agoMove SB_SPLICE, SB_WAIT and SB_SEL to `sb_flags', serialized by solock().
mpi [Sun, 10 Dec 2017 11:31:54 +0000 (11:31 +0000)]
Move SB_SPLICE, SB_WAIT and SB_SEL to `sb_flags', serialized by solock().

SB_KNOTE remains the only bit set on `sb_flagsintr' as it is set/unset in
contexts related to kqueue(2) where we'd like to avoid grabbing solock().

While here add some KERNEL_LOCK()/UNLOCK() dances around selwakeup() and
csignal() to mark which remaining functions need to be addressed in the
socket layer.

ok visa@, bluhm@

7 years agoRemove outdated comment and trailing spaces.
mpi [Sun, 10 Dec 2017 11:25:18 +0000 (11:25 +0000)]
Remove outdated comment and trailing spaces.

From kshe59@zoho.eu

7 years agoMove privileged initialization from frontend to main process.
florian [Sun, 10 Dec 2017 10:07:54 +0000 (10:07 +0000)]
Move privileged initialization from frontend to main process.
Needed for future work where we will spin up children via
fork - privdrop - exec. Child processes will no longer come
up with root privileges.

7 years ago- add max-count to SYNOPSIS
jmc [Sun, 10 Dec 2017 09:17:24 +0000 (09:17 +0000)]
- add max-count to SYNOPSIS
- list long options with short, where they have an equivalent
- sync usage()
- minor tweaks

7 years agoadd the zte mf831; from christoph r. murauer
jmc [Sun, 10 Dec 2017 07:40:04 +0000 (07:40 +0000)]
add the zte mf831; from christoph r. murauer
while here, a little less capitalisation

7 years agosort -r in the description list, and make its grammar match those
jmc [Sun, 10 Dec 2017 07:34:38 +0000 (07:34 +0000)]
sort -r in the description list, and make its grammar match those
of the other options in this page;

7 years agoPut remote client info back into the ClientAlive connection termination
dtucker [Sun, 10 Dec 2017 05:55:29 +0000 (05:55 +0000)]
Put remote client info back into the ClientAlive connection termination
message.  Based in part on diff from  lars.nooden at gmail, ok djm

7 years agoEnable the phy-supply regulator if present and use the phy id specified
jsg [Sun, 10 Dec 2017 04:21:55 +0000 (04:21 +0000)]
Enable the phy-supply regulator if present and use the phy id specified
in the device tree.

Patch from Artturi Alm who tested on a Miniand Hackberry.

7 years ago-r restricted mode blocks certain operations as ~ operations.
deraadt [Sun, 10 Dec 2017 01:03:46 +0000 (01:03 +0000)]
-r restricted mode blocks certain operations as ~ operations.
from Jan Klemkow
ok nicm

7 years agoAdd support for the non-standard grep -m extension.
pirofti [Sat, 9 Dec 2017 18:38:37 +0000 (18:38 +0000)]
Add support for the non-standard grep -m extension.

grep -m num stops after a maximum of num matches are found.
We support -m0 to match GNU behaviour, but we do not allow negative
numbers.

Manpage help from jmc@, OK deraadt@.

7 years agoMake tls_config_parse_protocols() work correctly when passed a NULL pointer
jsing [Sat, 9 Dec 2017 16:46:08 +0000 (16:46 +0000)]
Make tls_config_parse_protocols() work correctly when passed a NULL pointer
for a protocol string.

Issue found by semarie@, who also provided the diff.

7 years agoAdd a regress test for tls_config_parse_protocols().
jsing [Sat, 9 Dec 2017 16:43:09 +0000 (16:43 +0000)]
Add a regress test for tls_config_parse_protocols().

7 years agoAdd sizes for free() in the AMD PowerNow! K8 driver.
fcambus [Sat, 9 Dec 2017 16:39:54 +0000 (16:39 +0000)]
Add sizes for free() in the AMD PowerNow! K8 driver.

OK deraadt@, sthen@, visa@

7 years agoAdd ACTION_IGNORE and nuke ignored_options, ignored_option_count fields
krw [Sat, 9 Dec 2017 15:48:04 +0000 (15:48 +0000)]
Add ACTION_IGNORE and nuke ignored_options, ignored_option_count fields
in struct client_config.

7 years agoUse a test value that fits into a long on both 32-bit and 64-bit
jsing [Sat, 9 Dec 2017 14:34:09 +0000 (14:34 +0000)]
Use a test value that fits into a long on both 32-bit and 64-bit
architectures, so that the regress passes on both.

7 years agoNo need for the txb_used flag anymore
mikeb [Sat, 9 Dec 2017 14:00:21 +0000 (14:00 +0000)]
No need for the txb_used flag anymore

7 years agoIn the middle of CRYPTO_gcm128_finish() there is a complicated #ifdef
deraadt [Sat, 9 Dec 2017 07:16:51 +0000 (07:16 +0000)]
In the middle of CRYPTO_gcm128_finish() there is a complicated #ifdef
block which defines a variable late, after code.  Place this chunk into
a { subblock } to satisfy old compilers and old eyes.

7 years agoPlease variable decl before code.
deraadt [Sat, 9 Dec 2017 07:09:25 +0000 (07:09 +0000)]
Please variable decl before code.

7 years agoMore precision in pledge sysctl report
deraadt [Sat, 9 Dec 2017 06:50:32 +0000 (06:50 +0000)]
More precision in pledge sysctl report

7 years agorecognize .openbsd.randomdata section and indicate it roughly, so
deraadt [Sat, 9 Dec 2017 06:39:04 +0000 (06:39 +0000)]
recognize .openbsd.randomdata section and indicate it roughly, so
that objects within it are identified as being in read-only space.
ok guenther

7 years agoAdd a #define for the name of the .openbsd.randomdata section.
deraadt [Sat, 9 Dec 2017 06:35:08 +0000 (06:35 +0000)]
Add a #define for the name of the .openbsd.randomdata section.
ok guenther

7 years agoPullup the mbuf before accessing the version field in the IP header.
bluhm [Fri, 8 Dec 2017 22:10:34 +0000 (22:10 +0000)]
Pullup the mbuf before accessing the version field in the IP header.
Fix the pullup length of the shim header in mpls_do_error().
issue reported by Maxime Villard; OK deraadt@ claudio@

7 years agoUse m_freem() in error case. Found by Maxime Villard
claudio [Fri, 8 Dec 2017 21:59:05 +0000 (21:59 +0000)]
Use m_freem() in error case. Found by Maxime Villard
OK bluhm@

7 years agoThe adjttl functions use m_pullup(). In some cases m_pullup() can return
claudio [Fri, 8 Dec 2017 21:56:22 +0000 (21:56 +0000)]
The adjttl functions use m_pullup(). In some cases m_pullup() can return
a new mbuf chain and this chain needs to be returned to the caller else
a use after free may happen.
Issue reported by Maxime Villard
OK bluhm@ deraadt@

7 years agompls_shim_pop() can return NULL. Check it else we end up dereferencing NULL.
claudio [Fri, 8 Dec 2017 21:52:49 +0000 (21:52 +0000)]
mpls_shim_pop() can return NULL. Check it else we end up dereferencing NULL.
Issue reported by Maxime Villard
OK bluhm@ deraadt@

7 years agoAdd support for background scanning to net80211 and iwm(4).
stsp [Fri, 8 Dec 2017 21:16:01 +0000 (21:16 +0000)]
Add support for background scanning to net80211 and iwm(4).

The iwm(4) driver will now roam between access points which share an SSID.
Use 'ifconfig iwm0 debug' and 'tail -f /var/log/messages' to watch it do so.

Tested by several people in various iterations.
As usual, let me know if you run into issues.

ok phessler deraadt

7 years agoThe per-interface mpls flag should also also be tested on input before
deraadt [Fri, 8 Dec 2017 21:08:35 +0000 (21:08 +0000)]
The per-interface mpls flag should also also be tested on input before
proceeding, as described in ifconfig documentation.  Discussion with claudio.
Related to a report from maxime.
ok claudio bluhm

7 years agoMake iwm(4) restore the ic_bss channel after tweaking this channel as part
stsp [Fri, 8 Dec 2017 20:55:46 +0000 (20:55 +0000)]
Make iwm(4) restore the ic_bss channel after tweaking this channel as part
of passing the frame to ieee80211_input(). Fixes a race where auth frames
would be sent on the wrong channel during association.
Problem reported by florian@
ok deraadt@

7 years agoWhen accepting a BOOTP lease, do not leak offered values of lease
krw [Fri, 8 Dec 2017 20:17:28 +0000 (20:17 +0000)]
When accepting a BOOTP lease, do not leak offered values of lease
time, renewal time, rebinding time. Use the ACTION_DEFAULT mechanism
to set the default expiry time for any lease so gauche as to not
provide one. Use the DHCP default lease times for BOOTP leases instead
of, bizarrely, shorter times.

7 years agoMake sure we don't match (and attach) more than the maximum number of
kettenis [Fri, 8 Dec 2017 19:05:33 +0000 (19:05 +0000)]
Make sure we don't match (and attach) more than the maximum number of
supported CPUs.

7 years agoMake the r command filename obligatory, similar to what FreeBSD and NetBSD
martijn [Fri, 8 Dec 2017 18:41:59 +0000 (18:41 +0000)]
Make the r command filename obligatory, similar to what FreeBSD and NetBSD
do for several years.
While here make corresponding error message for missing read and write file
consistent between commands/flag, and shrink the the code of the w flag of
the s command by making it use the same code as the w command.

Prompted by a larger diff by kshe59 <at> zoho <dot> eu
OK millert@

7 years agorepair columns; from kshe59@zohu.eu
deraadt [Fri, 8 Dec 2017 17:51:26 +0000 (17:51 +0000)]
repair columns; from kshe59@zohu.eu

7 years agoAdd missing length checks to make sure we don't dereference a pointer
millert [Fri, 8 Dec 2017 17:26:42 +0000 (17:26 +0000)]
Add missing length checks to make sure we don't dereference a pointer
past the mmap(2)'d buffer.  Otherwise, locate will read a single
byte past the end of the buffer.  This is often harmless, but if
the length of the buffer is an even multiple of the page size,
locate will crash.  OK tb@ espie@ deraadt@

7 years agoConvert snprintf+write into dprintf. It is simply easier to read, and
deraadt [Fri, 8 Dec 2017 17:04:14 +0000 (17:04 +0000)]
Convert snprintf+write into dprintf.  It is simply easier to read, and
provides retry on short-write file descriptors.
ok florian, previous versions seen by millert

7 years agoremove description of 'at' field which was removed from vmstat.c -r1.21
jasper [Fri, 8 Dec 2017 09:45:05 +0000 (09:45 +0000)]
remove description of 'at' field which was removed from vmstat.c -r1.21

7 years agoDisable SMAP temporarily to display userland traces.
mpi [Fri, 8 Dec 2017 08:54:03 +0000 (08:54 +0000)]
Disable SMAP temporarily to display userland traces.

ok visa@, deraadt@, mlarkin@, jasper@

7 years agoalso cleanout ld.so.a
deraadt [Fri, 8 Dec 2017 05:30:16 +0000 (05:30 +0000)]
also cleanout ld.so.a

7 years agoEveryone knows this as ld.so, nor by the ancient name rtld.
deraadt [Fri, 8 Dec 2017 05:25:20 +0000 (05:25 +0000)]
Everyone knows this as ld.so, nor by the ancient name rtld.
ok guenther

7 years agotime_t printing needs %lld and (long long) casts
deraadt [Fri, 8 Dec 2017 03:45:52 +0000 (03:45 +0000)]
time_t printing needs %lld and (long long) casts
ok djm

7 years agofix ordering in previous to ensure errno isn't clobbered before
djm [Fri, 8 Dec 2017 02:14:33 +0000 (02:14 +0000)]
fix ordering in previous to ensure errno isn't clobbered before
logging.

7 years agofor some reason unix_listener() logged most errors twice with each
djm [Fri, 8 Dec 2017 02:13:02 +0000 (02:13 +0000)]
for some reason unix_listener() logged most errors twice with each
message containing only some of the useful information; merge these

7 years agoFix the return value of fwscanf(3) when encountering an early matching
kevlo [Fri, 8 Dec 2017 01:03:51 +0000 (01:03 +0000)]
Fix the return value of fwscanf(3) when encountering an early matching
failure.  This change brings fwscanf(3) back in line with fscanf(3).

From FreeBSD; ok deraadt@, millert@

7 years agoChange the SA payload parser to parse more than the first proposal. This
patrick [Thu, 7 Dec 2017 22:47:28 +0000 (22:47 +0000)]
Change the SA payload parser to parse more than the first proposal.  This
allows us to select one of the peer's proposals (and not only the first).

ok sthen@ hshoexer@

7 years agoadjust the "timeout" text, now that leases are no longer
jmc [Thu, 7 Dec 2017 21:47:22 +0000 (21:47 +0000)]
adjust the "timeout" text, now that leases are no longer
specified in dhclient.conf;

ok krw

7 years agocorrect indentation
deraadt [Thu, 7 Dec 2017 20:38:15 +0000 (20:38 +0000)]
correct indentation

7 years agoSet ifi->offer to NULL after free'ing it.
krw [Thu, 7 Dec 2017 19:17:13 +0000 (19:17 +0000)]
Set ifi->offer to NULL after free'ing it.

7 years agoNuke support for defining last-gasp leases in dhclient.conf.
krw [Thu, 7 Dec 2017 19:03:15 +0000 (19:03 +0000)]
Nuke support for defining last-gasp leases in dhclient.conf.

7 years agoInitialize tcp_secret in tcp_init
mikeb [Thu, 7 Dec 2017 16:52:21 +0000 (16:52 +0000)]
Initialize tcp_secret in tcp_init

The initialization of a secret SHA256 context for generating TCP
initial sequence numbers is moved out of tcp_set_iss_tsm used to
set up ISN for new connections and into tcp_init, sparing the
need for a global flag.

OK deraadt, visa, mpi

7 years ago* clean up macro usage: use .Ar for command arguments, .Cm for fixed
schwarze [Thu, 7 Dec 2017 15:43:03 +0000 (15:43 +0000)]
* clean up macro usage: use .Ar for command arguments, .Cm for fixed
strings to be used in commands, and .Li for example strings
* clarify what uses the two environment variables, and that only these
two are ignored for issetugid(2) programs
triggered by a question from Jan Stary <hans at stare dot cz>
feedback and OK ratchov@

7 years agoIn iwm(4), keep scanning if net80211 asks for a SCAN->SCAN transition
stsp [Thu, 7 Dec 2017 14:13:05 +0000 (14:13 +0000)]
In iwm(4), keep scanning if net80211 asks for a SCAN->SCAN transition
and the firmware is no longer busy scanning.

Fixes 'ifconfig iwm0 scan' returning no results after resume far away
from the currently configured AP.

ok phessler@

7 years agoMake iwm_newstate() recover from state transition errors.
stsp [Thu, 7 Dec 2017 14:12:39 +0000 (14:12 +0000)]
Make iwm_newstate() recover from state transition errors.

On error, we now schedule the init task which will whack the interface when
it gets to run, which prevents the driver from stalling in such situations.

ok phessler@

7 years agoSet the correct ENCAPSULATION_MODE when doing NAT-T.
mpi [Thu, 7 Dec 2017 11:44:02 +0000 (11:44 +0000)]
Set the correct ENCAPSULATION_MODE when doing NAT-T.

Fix at least interoperability with Cisco when isakmpd(8) is initiating
the connections, originally reported by sebastia@ in 2014.

Refreshed diff from and ok hshoexer@, ok sthen@, ok remi@

7 years agoMake the command formatting more consistent.
martijn [Thu, 7 Dec 2017 09:52:26 +0000 (09:52 +0000)]
Make the command formatting more consistent.
s/with/width type-O fix while here.

From kshe59 <at> zoho <dot> eu
OK jmc@

7 years agozap a few stray backslashes from the time thesse two were #defines; from
otto [Thu, 7 Dec 2017 06:34:05 +0000 (06:34 +0000)]
zap a few stray backslashes from the time thesse two were #defines; from
Ilya Kaliman

7 years agoNow that we have RB_NFIND, the canacar's trick with RB_INSERT+RB_NEXT
zhuk [Thu, 7 Dec 2017 05:21:57 +0000 (05:21 +0000)]
Now that we have RB_NFIND, the canacar's trick with RB_INSERT+RB_NEXT
is not needed anymore.

okay jmatthew@

7 years agoclient_addr_init() never fails and its return value is never checked,
zhuk [Thu, 7 Dec 2017 05:09:27 +0000 (05:09 +0000)]
client_addr_init() never fails and its return value is never checked,
so just make it void.

okay jmatthew@

7 years agoFix a potential fd leak in client_aldap_open().
zhuk [Thu, 7 Dec 2017 05:06:08 +0000 (05:06 +0000)]
Fix a potential fd leak in client_aldap_open().

okay jmatthew@

7 years agoLet it compile again.
krw [Thu, 7 Dec 2017 02:08:44 +0000 (02:08 +0000)]
Let it compile again.

7 years agoreorder some port numbers, no functional change.
mlarkin [Thu, 7 Dec 2017 01:54:39 +0000 (01:54 +0000)]
reorder some port numbers, no functional change.

7 years agoDrop the unused second argument from set_prompt(). It used to be used for
tb [Thu, 7 Dec 2017 01:54:33 +0000 (01:54 +0000)]
Drop the unused second argument from set_prompt(). It used to be used for
early special casing of ! and !! in the PS1 expansion. This was removed
from set_prompt() as part of the implementaion of the character count
toggles \[ and \] back in 2004.

ok jca

7 years agobe consistent in where we call fflush
espie [Wed, 6 Dec 2017 17:15:43 +0000 (17:15 +0000)]
be consistent in where we call fflush

okay millert@

7 years agoUpdate inaccurate comment: i386_has_xcrypt => amd64_has_xcrypt.
fcambus [Wed, 6 Dec 2017 16:26:12 +0000 (16:26 +0000)]
Update inaccurate comment: i386_has_xcrypt => amd64_has_xcrypt.

7 years agoImplement support for using interrupt cookies in vbus(4) and vpci(4) as
kettenis [Wed, 6 Dec 2017 16:20:53 +0000 (16:20 +0000)]
Implement support for using interrupt cookies in vbus(4) and vpci(4) as
introduced in version 3.0 of the Interrupt APIs group.  This makes it possible
boot OpenBSD on SPARC T7/M7 hardware (although there still may be issues with
the onboard mpii(4) controller).

7 years agoDisentangle dhclient.conf static lease handling from dynamic
krw [Wed, 6 Dec 2017 13:57:27 +0000 (13:57 +0000)]
Disentangle dhclient.conf static lease handling from dynamic
lease handling. Simplifies code and makes it easier to
consider excising this 'feature'.

7 years agostrdup -> bstrdup; from Michael W. Bombardieri
otto [Wed, 6 Dec 2017 13:48:05 +0000 (13:48 +0000)]
strdup -> bstrdup; from Michael W. Bombardieri

7 years agoMake vmd respect owner when starting non-disabled vms.
abieber [Wed, 6 Dec 2017 13:29:02 +0000 (13:29 +0000)]
Make vmd respect owner when starting non-disabled vms.

OK pd@, benno@

7 years agoIt's the imsg_compose(3) who accepts 'fd' argument, not imsg_create(3).
zhuk [Wed, 6 Dec 2017 12:07:08 +0000 (12:07 +0000)]
It's the imsg_compose(3) who accepts 'fd' argument, not imsg_create(3).

7 years agodon't accept junk after "yes" or "no" responses to hostkey prompts.
djm [Wed, 6 Dec 2017 05:06:21 +0000 (05:06 +0000)]
don't accept junk after "yes" or "no" responses to hostkey prompts.
bz#2803 reported by Maksim Derbasov; ok dtucker@

7 years agoReplace atoi and strtol conversions for integer arguments to config
dtucker [Tue, 5 Dec 2017 23:59:47 +0000 (23:59 +0000)]
Replace atoi and strtol conversions for integer arguments to config
keywords with a checking wrapper around strtonum.  This will prevent
and flag invalid and negative arguments to these keywords.  ok djm@

7 years agoAdd missing break for rdomain. Prevents spurious "Deprecated option"
dtucker [Tue, 5 Dec 2017 23:56:07 +0000 (23:56 +0000)]
Add missing break for rdomain.  Prevents spurious "Deprecated option"
warnings.  ok djm@

7 years agoregen
kettenis [Tue, 5 Dec 2017 22:27:54 +0000 (22:27 +0000)]
regen

7 years agoAdd SPARC-M7 PCIe; rename existing SPARC PCIe entries.
kettenis [Tue, 5 Dec 2017 22:26:31 +0000 (22:26 +0000)]
Add SPARC-M7 PCIe; rename existing SPARC PCIe entries.

7 years agoRemove DEF_STRONG(__cxa_thread_atexit_impl). This produces an unwanted
kettenis [Tue, 5 Dec 2017 21:11:10 +0000 (21:11 +0000)]
Remove DEF_STRONG(__cxa_thread_atexit_impl).  This produces an unwanted
_libc___cxa_thread_atexit_impl reference on gcc architectures that breaks
the build.

7 years agoHandle 64-bit-address Memory Space.
kettenis [Tue, 5 Dec 2017 21:04:32 +0000 (21:04 +0000)]
Handle 64-bit-address Memory Space.

7 years agoUse clock_gettime(CLOCK_MONOTONIC) to schedule timers
jca [Tue, 5 Dec 2017 20:31:45 +0000 (20:31 +0000)]
Use clock_gettime(CLOCK_MONOTONIC) to schedule timers

From Scott Cheloha, ok tb@

7 years agoadd missing blank before punctuation;
jmc [Tue, 5 Dec 2017 19:40:16 +0000 (19:40 +0000)]
add missing blank before punctuation;

7 years agosync
deraadt [Tue, 5 Dec 2017 18:36:02 +0000 (18:36 +0000)]
sync

7 years agodocument PORTS_PRIVSEP now that it's nearing completion
espie [Tue, 5 Dec 2017 17:58:10 +0000 (17:58 +0000)]
document PORTS_PRIVSEP now that it's nearing completion

7 years agoFix a case where we could go off the end of the buffer.
millert [Tue, 5 Dec 2017 17:47:09 +0000 (17:47 +0000)]
Fix a case where we could go off the end of the buffer.
Crash found by Sergey Bronnikov using afl-fuzz.
Based on a diff from and OK by espie@

7 years agoShow board ID and revision in dmesg to ease the identification
visa [Tue, 5 Dec 2017 15:39:26 +0000 (15:39 +0000)]
Show board ID and revision in dmesg to ease the identification
of system model. The early boot code already prints them, but
that output is not buffered and tends to be left out from
dmesg submissions.

7 years agoDrop cn30xxpow_intr_establish(), cn30xxpow_intr() and some other
visa [Tue, 5 Dec 2017 15:26:47 +0000 (15:26 +0000)]
Drop cn30xxpow_intr_establish(), cn30xxpow_intr() and some other
unused code. POW interrupts are now handled in if_cnmac.c.

7 years agoSeperate real and user timer interfaces
jca [Tue, 5 Dec 2017 15:02:06 +0000 (15:02 +0000)]
Seperate real and user timer interfaces

Use more descriptive names, and make it clearer that real and user
timers work on different static storage.  The end goal is to be able to
reuse those timer functions, instead of inlining other timer
implementations subject to clock jumps.

Discussed with Scott Cheloha

7 years agoWhen removing duplicate dynamic leases from the cache, compare the
krw [Tue, 5 Dec 2017 14:57:14 +0000 (14:57 +0000)]
When removing duplicate dynamic leases from the cache, compare the
SSID against ifi->ssid, not the SSID of the new lease. They
should be the same, but this makes the intent clearer and removes
an assumption about the contents of ifi->active.

7 years agostrip_comments is also called for dot lines, so sometimes the comment
espie [Tue, 5 Dec 2017 14:35:12 +0000 (14:35 +0000)]
strip_comments is also called for dot lines, so sometimes the comment
is all the line.

problem reported by Sergey Bronnikov

7 years agouse a global BN_CTX; from kshe with a twist from myself
otto [Tue, 5 Dec 2017 14:05:22 +0000 (14:05 +0000)]
use a global BN_CTX; from kshe with a twist from myself

7 years agoImplement __cxa_thread_atexit to support C++11 thread_local scope. The
kettenis [Tue, 5 Dec 2017 13:45:31 +0000 (13:45 +0000)]
Implement __cxa_thread_atexit to support C++11 thread_local scope.  The
interface is also made available as __cxa_thread_atexit_impl to satisfy the
needs of GNU libstdc++.

ok guenther@, millert@

7 years agoWhen sending out a proposal we create an SA/SPI for the Child SAs if we
patrick [Tue, 5 Dec 2017 09:06:53 +0000 (09:06 +0000)]
When sending out a proposal we create an SA/SPI for the Child SAs if we
are an initiator and store the information on the proposal, because we
only had one proposal so far.  This changes the code to only create one
SA on the first proposal and then apply the SPI to all other proposals
as well.

ok markus@