openbsd
3 years agoMerge documentation for i2d_re_X509*_tbs(3) from OpenSSL 1.1
tb [Tue, 26 Oct 2021 23:37:56 +0000 (23:37 +0000)]
Merge documentation for i2d_re_X509*_tbs(3) from OpenSSL 1.1

3 years agoupdate to libfido2 1.8.0; ok sthen@ "timing is fine" deraadt@
djm [Tue, 26 Oct 2021 21:36:23 +0000 (21:36 +0000)]
update to libfido2 1.8.0; ok sthen@ "timing is fine" deraadt@

3 years agospelling fixes;
jmc [Tue, 26 Oct 2021 18:50:38 +0000 (18:50 +0000)]
spelling fixes;

3 years agosync
tb [Tue, 26 Oct 2021 18:17:09 +0000 (18:17 +0000)]
sync

3 years agoinstall X509_get_extension_flags.3 and X509_SIG_get0.3
tb [Tue, 26 Oct 2021 18:11:04 +0000 (18:11 +0000)]
install X509_get_extension_flags.3 and X509_SIG_get0.3

3 years agoRemove a line documenting that X509_get_X509_PUBKEY(3) is missing
tb [Tue, 26 Oct 2021 18:05:07 +0000 (18:05 +0000)]
Remove a line documenting that X509_get_X509_PUBKEY(3) is missing

discussed with schwarze

3 years agoDocument X509_get0_pubkey.3
tb [Tue, 26 Oct 2021 18:04:24 +0000 (18:04 +0000)]
Document X509_get0_pubkey.3

3 years agoDocument new signature of X509_get_X509_PUBKEY() and remove claim
tb [Tue, 26 Oct 2021 18:01:00 +0000 (18:01 +0000)]
Document new signature of X509_get_X509_PUBKEY() and remove claim
that the API is implemented as a macro. This will change in an
upcoming bump.

3 years agoAdd tlsfeature NID
job [Tue, 26 Oct 2021 17:35:38 +0000 (17:35 +0000)]
Add tlsfeature NID

OK beck@ tb@

3 years agoMake proto config option accept a list to allow specifying multiple
tobhe [Tue, 26 Oct 2021 17:31:22 +0000 (17:31 +0000)]
Make proto config option accept a list to allow specifying multiple
protocols for a single policy, e.g. "proto { ipencap, ipv6 }".

feedback and ok benno@
ok patrick@

3 years agoAdjust regress to the new BIO-free world order.
claudio [Tue, 26 Oct 2021 16:59:54 +0000 (16:59 +0000)]
Adjust regress to the new BIO-free world order.

3 years agoMove load_file() to encoding.c so that regress can use the function.
claudio [Tue, 26 Oct 2021 16:59:19 +0000 (16:59 +0000)]
Move load_file() to encoding.c so that regress can use the function.

3 years agoAdd a new TEMPerHUM device id. style tweak deraadt@, ok mlarkin@
matthieu [Tue, 26 Oct 2021 16:49:12 +0000 (16:49 +0000)]
Add a new TEMPerHUM device id. style tweak deraadt@, ok mlarkin@

3 years agoImprove unhibernate performance (30% on some machines, another upcoming diff
deraadt [Tue, 26 Oct 2021 16:29:49 +0000 (16:29 +0000)]
Improve unhibernate performance (30% on some machines, another upcoming diff
shows gains up to 50%) by skipping attach of irrelevant devices, which are
tagged CD_SKIPHIBERNATE in the per-driver cfdriver.  In particular, usb devices
are not attached, so they don't need to detach during the suspend-unpack-resume.
New bootblocks are required (which tell the kernel it's job is unhibernate
before configure runs)
tested by various

3 years agoRefactor the tal parsing code to use the same load_file() and buffer
claudio [Tue, 26 Oct 2021 16:12:54 +0000 (16:12 +0000)]
Refactor the tal parsing code to use the same load_file() and buffer
passing as done for the other parsers.
OK job@ tb@

3 years agoGeneralise "nameserver" workings
kn [Tue, 26 Oct 2021 15:48:25 +0000 (15:48 +0000)]
Generalise "nameserver" workings

The generated route message is not at all resolvd(8) specific.
Mention how unwind(8) reacts to proposals as well.

"Broadcast" wording deraadt jmc
OK millert

3 years agoAdd RFC 3779 checks to both legacy and new verifier
job [Tue, 26 Oct 2021 15:14:18 +0000 (15:14 +0000)]
Add RFC 3779 checks to both legacy and new verifier

OK beck@

3 years agoFree memory on text exit to make asan quieter
beck [Tue, 26 Oct 2021 14:34:02 +0000 (14:34 +0000)]
Free memory on text exit to make asan quieter

ok tb@

3 years agoEnable vmx(4) on arm64. Tested using VMware Fusion on the Apple M1.
patrick [Tue, 26 Oct 2021 14:20:47 +0000 (14:20 +0000)]
Enable vmx(4) on arm64.  Tested using VMware Fusion on the Apple M1.

ok kettenis@

3 years agosync
deraadt [Tue, 26 Oct 2021 14:15:02 +0000 (14:15 +0000)]
sync

3 years agoOnly flush freshly mapped uncached/device mappings if we have a vm_page for it,
patrick [Tue, 26 Oct 2021 14:13:57 +0000 (14:13 +0000)]
Only flush freshly mapped uncached/device mappings if we have a vm_page for it,
meaning we make sure it is indeed managed memory/RAM and not some MMIO.  Fixes
booting on VMware Fusion (and an older QEMU diff for HVF acceleration).

ok kettenis@

3 years agoAllocate fresh memory to put our device tree into, to make sure we have least
patrick [Tue, 26 Oct 2021 14:10:02 +0000 (14:10 +0000)]
Allocate fresh memory to put our device tree into, to make sure we have least
one page of free space for us to extend into.  Fixes booting on VMware Fusion.

ok kettenis@

3 years agoAlso move the cert parser code away from using BIO.
claudio [Tue, 26 Oct 2021 13:31:05 +0000 (13:31 +0000)]
Also move the cert parser code away from using BIO.
OK beck@

3 years agorpki-client supports RFC8630 TAL files.
claudio [Tue, 26 Oct 2021 13:26:53 +0000 (13:26 +0000)]
rpki-client supports RFC8630 TAL files.

3 years agonew manual page X509_REQ_add1_attr(3) documenting nine functions
schwarze [Tue, 26 Oct 2021 12:56:48 +0000 (12:56 +0000)]
new manual page X509_REQ_add1_attr(3) documenting nine functions
for X.501 Attributes in PKCS#10 certification requests

3 years agocorrect a wrong function name below RETURN VALUES
schwarze [Tue, 26 Oct 2021 12:45:31 +0000 (12:45 +0000)]
correct a wrong function name below RETURN VALUES

3 years agoAccept some emacs control keys in vi normal mode, from Alexis
nicm [Tue, 26 Oct 2021 12:29:41 +0000 (12:29 +0000)]
Accept some emacs control keys in vi normal mode, from Alexis
Hildebrandt in GitHub issue 2922.

3 years agoDo not allow inline styles to replace mode-style for the selected item,
nicm [Tue, 26 Oct 2021 12:22:23 +0000 (12:22 +0000)]
Do not allow inline styles to replace mode-style for the selected item,
from Alexis Hildebrandt in GitHub issue 2946.

3 years agoChange CMS and CRL d2i functions from their BIO version to passing the
claudio [Tue, 26 Oct 2021 10:52:49 +0000 (10:52 +0000)]
Change CMS and CRL d2i functions from their BIO version to passing the
der buffer instead. The file are loaded early in the entity processing
loop.
OK tb@

3 years agodocument X509_REQ_dup(3)
schwarze [Tue, 26 Oct 2021 10:50:08 +0000 (10:50 +0000)]
document X509_REQ_dup(3)

3 years agoRemove more occurences of O_RDONLY in our bootloaders.
patrick [Tue, 26 Oct 2021 10:45:55 +0000 (10:45 +0000)]
Remove more occurences of O_RDONLY in our bootloaders.

"just do it" deraadt@

3 years agodocument d2i_X509_PUBKEY(3) and i2d_X509_PUBKEY(3);
schwarze [Tue, 26 Oct 2021 10:01:23 +0000 (10:01 +0000)]
document d2i_X509_PUBKEY(3) and i2d_X509_PUBKEY(3);
while here, apply the usual conventions for naming d2i and i2d arguments

3 years agoValidate Subject Alternate Names when they are being added to certificates.
beck [Tue, 26 Oct 2021 09:09:53 +0000 (09:09 +0000)]
Validate Subject Alternate Names when they are being added to certificates.

With this change we will reject adding SAN DNS, EMAIL, and IP addresses
that are malformed at certificate creation time.

ok jsing@ tb@

3 years agoRevise regress for removal of SSL_SESSION_INTERNAL.
jsing [Tue, 26 Oct 2021 06:24:47 +0000 (06:24 +0000)]
Revise regress for removal of SSL_SESSION_INTERNAL.

3 years agoThe implementation of ipsp_spd_inp() is side effect free. It may
bluhm [Mon, 25 Oct 2021 22:20:47 +0000 (22:20 +0000)]
The implementation of ipsp_spd_inp() is side effect free.  It may
set the error output parameter or return a tdb.  Both are ignored
in in_pcbconnect().  Remove the code that does nothing.
OK tobhe@ jca@ mvs@

3 years agoAdd a way to force a colour to RGB and a format to display it.
nicm [Mon, 25 Oct 2021 21:21:16 +0000 (21:21 +0000)]
Add a way to force a colour to RGB and a format to display it.

3 years agoMissing Pp, from Alexis Hildebrandt.
nicm [Mon, 25 Oct 2021 20:32:42 +0000 (20:32 +0000)]
Missing Pp, from Alexis Hildebrandt.

3 years agoZap unused variables/functions under /usr/src/*bin/
kn [Mon, 25 Oct 2021 19:54:29 +0000 (19:54 +0000)]
Zap unused variables/functions under /usr/src/*bin/

OK deraadt

3 years agoremove dtp_mtx which protected dtp_ref; the code is always called with KERNEL_LOCK...
millert [Mon, 25 Oct 2021 19:51:12 +0000 (19:51 +0000)]
remove dtp_mtx which protected dtp_ref; the code is always called with KERNEL_LOCK() held

3 years agoRefactor the proc_parser code, move the processing of enities into its
claudio [Mon, 25 Oct 2021 18:25:22 +0000 (18:25 +0000)]
Refactor the proc_parser code, move the processing of enities into its
own function and make a few vars global to simplify the code.
OK tb@

3 years agoCall a locked variant of tdb_unlink() from tdb_walk(). Fixes a
bluhm [Mon, 25 Oct 2021 18:25:01 +0000 (18:25 +0000)]
Call a locked variant of tdb_unlink() from tdb_walk().  Fixes a
mutex locking against myself panic introduced by my previous commit.
OK beck@ patrick@

3 years agoremove dtp_mtx which protected dtp_ref; the code is always called with KERNEL_LOCK...
jasper [Mon, 25 Oct 2021 17:15:29 +0000 (17:15 +0000)]
remove dtp_mtx which protected dtp_ref; the code is always called with KERNEL_LOCK() held

discussed with and OK mpi@

3 years agoProtect the tdb hashes with a mutex. Move initialization out of
bluhm [Mon, 25 Oct 2021 16:00:12 +0000 (16:00 +0000)]
Protect the tdb hashes with a mutex.  Move initialization out of
the processing path.  If rehashing fails due to low memory, just
keep the old hash buckets.
OK tobhe@

3 years agoRemove unused variables to silence clang.
patrick [Mon, 25 Oct 2021 15:59:46 +0000 (15:59 +0000)]
Remove unused variables to silence clang.

ok kettenis@

3 years agosort
tb [Mon, 25 Oct 2021 15:23:50 +0000 (15:23 +0000)]
sort

3 years agosync
tb [Mon, 25 Oct 2021 15:19:12 +0000 (15:19 +0000)]
sync

3 years agosort. alphanumerics have lower ASCII values than '_'
tb [Mon, 25 Oct 2021 15:16:35 +0000 (15:16 +0000)]
sort. alphanumerics have lower ASCII values than '_'

3 years agoInstall SSL_read_early_data.3. I should have done this during the last
tb [Mon, 25 Oct 2021 15:13:52 +0000 (15:13 +0000)]
Install SSL_read_early_data.3. I should have done this during the last
libssl bump.

3 years ago- add regression tests for pfctl '$rn' macro expansion
sashan [Mon, 25 Oct 2021 14:56:47 +0000 (14:56 +0000)]
- add regression tests for pfctl '$rn' macro expansion

OK @bluhm

3 years agotypos in comments, from jj, reported by Elyes Haouas on irc
sthen [Mon, 25 Oct 2021 14:53:15 +0000 (14:53 +0000)]
typos in comments, from jj, reported by Elyes Haouas on irc

3 years ago- pfctl $nr incorrect macro expansion
sashan [Mon, 25 Oct 2021 14:50:29 +0000 (14:50 +0000)]
- pfctl $nr incorrect macro expansion

Issue reported by Kristof Provost from FreeBSD.
[ https://reviews.freebsd.org/D32488 ]

In order to fix the issue we must delay '$nr' macro
expansion after optimizer collapses ruleset.

OK kn@

3 years agoRevert accidental change.
jca [Mon, 25 Oct 2021 14:41:09 +0000 (14:41 +0000)]
Revert accidental change.

Dunno why this ended up here, cvs is always full of surprises.

3 years agoMake brk() and sbrk() weak again as intended.
jca [Mon, 25 Oct 2021 14:38:10 +0000 (14:38 +0000)]
Make brk() and sbrk() weak again as intended.

Apparently spotted by mortimer@ while working on clang 13 and amd64.
No actual change on sparc64 as this architecture still uses ld.bfd.
ok kettenis@

3 years agoMake brk() and sbrk() weak again as intended.
kettenis [Mon, 25 Oct 2021 14:19:51 +0000 (14:19 +0000)]
Make brk() and sbrk() weak again as intended.

ok jca@

3 years agovi(1): fix use after free with unsaved buffer
dv [Mon, 25 Oct 2021 14:17:24 +0000 (14:17 +0000)]
vi(1): fix use after free with unsaved buffer

Issuing a zero-arg ex_edit command (:e) while using a named buffer
with no backing file caused vi(1)/ex(1) to free the strings
representing the buffer name and the name of the temporary file.
This change detects the situation and only frees the newly allocated
EXF structure (ep).

Reported on bugs@ by kn@.

OK millert@

3 years agoHook up the print.c functions in rpki-client
claudio [Mon, 25 Oct 2021 14:08:34 +0000 (14:08 +0000)]
Hook up the print.c functions in rpki-client

3 years agoRemove unused variables
claudio [Mon, 25 Oct 2021 14:07:56 +0000 (14:07 +0000)]
Remove unused variables

3 years agoNuke a bunch of pointless #ifndef _<.h file>/#endif guards.
krw [Mon, 25 Oct 2021 13:51:25 +0000 (13:51 +0000)]
Nuke a bunch of pointless #ifndef _<.h file>/#endif guards.

3 years agonew manual page EVP_PKCS82PKEY(3), also documenting EVP_PKEY2PKCS8(3)
schwarze [Mon, 25 Oct 2021 13:48:12 +0000 (13:48 +0000)]
new manual page EVP_PKCS82PKEY(3), also documenting EVP_PKEY2PKCS8(3)

3 years agonew manual page PKCS8_pkey_set0(3)
schwarze [Mon, 25 Oct 2021 12:25:14 +0000 (12:25 +0000)]
new manual page PKCS8_pkey_set0(3)
documenting four PKCS#8 PrivateKeyInfo accessors

3 years agoAdd missing RCS markers
tb [Mon, 25 Oct 2021 11:55:27 +0000 (11:55 +0000)]
Add missing RCS markers

3 years agoZap two unused includes
jca [Mon, 25 Oct 2021 11:48:24 +0000 (11:48 +0000)]
Zap two unused includes

Spotted by egcc.  ok tb@

3 years agoGarbage collect another unused variable.
jca [Mon, 25 Oct 2021 11:47:39 +0000 (11:47 +0000)]
Garbage collect another unused variable.

Spotted by egcc and probably clang 13.  ok tb@

3 years agoIf we use type to SNMP_V2 we should check against that.
martijn [Mon, 25 Oct 2021 11:21:32 +0000 (11:21 +0000)]
If we use type to SNMP_V2 we should check against that.

Reported by Johan Huldtgren (jhuldtgren <at> gmail <dot> com) via sthen@

OK sthen@

3 years agodocument ASN1_STRING_set0(3)
schwarze [Mon, 25 Oct 2021 10:26:21 +0000 (10:26 +0000)]
document ASN1_STRING_set0(3)

3 years agoRevert commitid: ufM9BcSbXqfLpzBH;
claudio [Mon, 25 Oct 2021 10:24:54 +0000 (10:24 +0000)]
Revert commitid: ufM9BcSbXqfLpzBH;
Move vfs_stall_barrier() from the fd layer into vn_lock() and the vfs layer.
In some cases it can result in a deadlock while suspending.
Discussed with mpi@ and deraadt@

3 years agoAdd record processing limit to DTLS code.
jsing [Mon, 25 Oct 2021 10:14:48 +0000 (10:14 +0000)]
Add record processing limit to DTLS code.

This is effectively the same record processing limit that was previously
added to the legacy TLS stack - without this a single session can be made
to spin on a stream of alerts or other similar records.

ok beck@ tb@

3 years agoUse ssl_force_want_read() in the DTLS code.
jsing [Mon, 25 Oct 2021 10:09:28 +0000 (10:09 +0000)]
Use ssl_force_want_read() in the DTLS code.

Also mop up some mostly unhelpful comments while here.

ok beck@ tb@

3 years agoopen() flags never contain O_CREAT, so variatic mode_t can be removed here also
deraadt [Mon, 25 Oct 2021 10:08:26 +0000 (10:08 +0000)]
open() flags never contain O_CREAT, so variatic mode_t can be removed here also

3 years agodo not need a temporary one time use variable which befuddles
deraadt [Mon, 25 Oct 2021 10:07:12 +0000 (10:07 +0000)]
do not need a temporary one time use variable which befuddles

3 years agoFold SSL_SESSION_INTERNAL back into SSL_SESSION.
jsing [Mon, 25 Oct 2021 10:01:46 +0000 (10:01 +0000)]
Fold SSL_SESSION_INTERNAL back into SSL_SESSION.

ok beck@ tb@

3 years agoFix use of uninitialized variable 'rpl'.
tobhe [Mon, 25 Oct 2021 09:47:02 +0000 (09:47 +0000)]
Fix use of uninitialized variable 'rpl'.

Found by jsg@
ok patrick@

3 years agoAdd -s and -S to display-popup to set popup and border style, from
nicm [Mon, 25 Oct 2021 09:38:36 +0000 (09:38 +0000)]
Add -s and -S to display-popup to set popup and border style, from
Alexis Hildebrandt in GitHub issue 2931.

3 years agoInstead of setting the popup default colours in the draw callback, set
nicm [Mon, 25 Oct 2021 09:22:17 +0000 (09:22 +0000)]
Instead of setting the popup default colours in the draw callback, set
it up in popup_display and follow the same routine as panes in the draw
and init_ctx callbacks - use the palette if the option value is default.
Allows application-set fg and bg to work in panes again.

3 years agoDrop two uses of the terrible asn1 kludge spotted by anton
tb [Mon, 25 Oct 2021 07:17:14 +0000 (07:17 +0000)]
Drop two uses of the terrible asn1 kludge spotted by anton

3 years agoUse EXPECTED_FAIL instead of DISABLED.
mbuhl [Mon, 25 Oct 2021 00:48:49 +0000 (00:48 +0000)]
Use EXPECTED_FAIL instead of DISABLED.

3 years agoMerge esp_input_cb() intp esp_input().
tobhe [Sun, 24 Oct 2021 23:33:37 +0000 (23:33 +0000)]
Merge esp_input_cb() intp esp_input().

ok bluhm@

3 years agoRemove code duplication by merging the v4 and v6 input functions
bluhm [Sun, 24 Oct 2021 22:59:47 +0000 (22:59 +0000)]
Remove code duplication by merging the v4 and v6 input functions
for ah, esp, and ipcomp.  Move common code into ipsec_protoff()
which finds the offset of the next protocol field in the previous
header.
OK tobhe@

3 years agoRefactor ah_input() and ah_output() for new crypto API.
tobhe [Sun, 24 Oct 2021 22:34:19 +0000 (22:34 +0000)]
Refactor ah_input() and ah_output() for new crypto API.

ok bluhm@

3 years agoFor open/openat, if the flags parameter does not contain O_CREAT, the
deraadt [Sun, 24 Oct 2021 21:37:49 +0000 (21:37 +0000)]
For open/openat, if the flags parameter does not contain O_CREAT, the
3rd (variadic) mode_t parameter is irrelevant.  Many developers in the past
have passed mode_t (0, 044, 0644, or such), which might lead future people
to copy this broken idiom, and perhaps even believe this parameter has some
meaning or implication or application. Delete them all.
This comes out of a conversation where tb@ noticed that a strange (but
intentional) pledge behaviour is to always knock-out high-bits from
mode_t on a number of system calls as a safety factor, and his bewilderment
that this appeared to be happening against valid modes (at least visually),
but no sorry, they are all irrelevant junk.  They could all be 0xdeafbeef.
ok millert

3 years agoWhat kind of Sun idiot called open() with flags of "2".
deraadt [Sun, 24 Oct 2021 21:27:07 +0000 (21:27 +0000)]
What kind of Sun idiot called open() with flags of "2".

3 years agoFor open/openat, if the flags parameter does not contain O_CREAT, the
deraadt [Sun, 24 Oct 2021 21:24:15 +0000 (21:24 +0000)]
For open/openat, if the flags parameter does not contain O_CREAT, the
3rd (variadic) mode_t parameter is irrelevant.  Many developers in the past
have passed mode_t (0, 044, 0644, or such), which might lead future people
to copy this broken idiom, and perhaps even believe this parameter has some
meaning or implication or application. Delete them all.
This comes out of a conversation where tb@ noticed that a strange (but
intentional) pledge behaviour is to always knock-out high-bits from
mode_t on a number of system calls as a safety factor, and his bewilderment
that this appeared to be happening against valid modes (at least visually),
but no sorry, they are all irrelevant junk.  They could all be 0xdeafbeef.
ok millert

3 years agoRefactor ipcomp_input() and ipcomp_output(). Remove obsolete code related
tobhe [Sun, 24 Oct 2021 18:15:58 +0000 (18:15 +0000)]
Refactor ipcomp_input() and ipcomp_output(). Remove obsolete code related
to old crypto API.

ok bluhm@

3 years agoEven though AgentX supports null-oids and incidentally has a valid usecase
martijn [Sun, 24 Oct 2021 18:03:27 +0000 (18:03 +0000)]
Even though AgentX supports null-oids and incidentally has a valid usecase
for them, they don't map on ber, which needs a minimum of 2 identifiers.
Enforce this minimum in libagentx.

While here add some additional checks where they were lacking.

OK claudio@

3 years agoUse the print.c file which is now shipped in rpki-client to print
claudio [Sun, 24 Oct 2021 17:54:28 +0000 (17:54 +0000)]
Use the print.c file which is now shipped in rpki-client to print
the cert, gbr, mft, roa and tal file contents. No real functional change.
OK tb@

3 years agoMove the various print functions from the regress tests into print.c.
claudio [Sun, 24 Oct 2021 17:53:07 +0000 (17:53 +0000)]
Move the various print functions from the regress tests into print.c.
OK tb@

3 years agoConstify struct cfattach.
mpi [Sun, 24 Oct 2021 17:52:26 +0000 (17:52 +0000)]
Constify struct cfattach.

ok visa@ a long time ago, ok patrick@

3 years ago#define open O_* flags in libsa/stand.h, so that bootblocks can use
deraadt [Sun, 24 Oct 2021 17:49:19 +0000 (17:49 +0000)]
#define open O_* flags in libsa/stand.h, so that bootblocks can use
O_RDONLY rather using 0
ok beck

3 years agoInitialize OID print buffer, even when oidlen is 0.
martijn [Sun, 24 Oct 2021 17:43:38 +0000 (17:43 +0000)]
Initialize OID print buffer, even when oidlen is 0.
Fix printing old garbage from previous conversions.

OK tb@

3 years agoSome more whitespace cleanup
patrick [Sun, 24 Oct 2021 17:20:06 +0000 (17:20 +0000)]
Some more whitespace cleanup

3 years agoAdd $OpenBSD$ header and add a licence to rrdp.h which was lacking it.
claudio [Sun, 24 Oct 2021 17:16:09 +0000 (17:16 +0000)]
Add $OpenBSD$ header and add a licence to rrdp.h which was lacking it.

3 years agoThere are more m_pullup() in IPsec input. Pass down the pointer
bluhm [Sun, 24 Oct 2021 17:08:27 +0000 (17:08 +0000)]
There are more m_pullup() in IPsec input.  Pass down the pointer
to the mbuf to update it globally.  At the end it will reach
ip_deliver() which expects a pointer to an mbuf.
OK sashan@

3 years agoConstify struct cfattach.
mpi [Sun, 24 Oct 2021 17:05:03 +0000 (17:05 +0000)]
Constify struct cfattach.

ok visa@ a long time ago

3 years agoAdd my copyright to some files
claudio [Sun, 24 Oct 2021 16:59:14 +0000 (16:59 +0000)]
Add my copyright to some files
OK job@

3 years agoConstify struct cfattach.
mpi [Sun, 24 Oct 2021 16:57:30 +0000 (16:57 +0000)]
Constify struct cfattach.

ok visa@ a long time ago, ok krw@

3 years agotiny little whitespace fixes
patrick [Sun, 24 Oct 2021 16:02:44 +0000 (16:02 +0000)]
tiny little whitespace fixes

3 years agoAdd httpd custom error page facility. Adapted by me from
ian [Sun, 24 Oct 2021 16:01:04 +0000 (16:01 +0000)]
Add httpd custom error page facility. Adapted by me from
https://github.com/mpfr/httpd-plus.
Improvements from & (earlier version) reads fine to tracey@;
improvements & OK this version benno@, florian@. Thanks.

3 years agoUse braces in config examples
kn [Sun, 24 Oct 2021 15:57:17 +0000 (15:57 +0000)]
Use braces in config examples

We document them as explicitly required, `unwind -dnvf...' spits them
out like this and the last `force' example uses them as well.

3 years agoRemove 'struct tdb_crypto' allocations from esp_input() and esp_output().
tobhe [Sun, 24 Oct 2021 15:47:39 +0000 (15:47 +0000)]
Remove 'struct tdb_crypto' allocations from esp_input() and esp_output().
This was needed to pass arguments to the callback function, but is no longer
necessary after the API makeover.

ok bluhm@

3 years agoA tiny bit of cleanup.
patrick [Sun, 24 Oct 2021 15:41:47 +0000 (15:41 +0000)]
A tiny bit of cleanup.