openbsd
18 months agoSwitch K&R function definition to ANSI to make clang 15 happier
tb [Tue, 2 May 2023 09:51:22 +0000 (09:51 +0000)]
Switch K&R function definition to ANSI to make clang 15 happier

18 months agoUnwrap a line
tb [Tue, 2 May 2023 09:38:33 +0000 (09:38 +0000)]
Unwrap a line

18 months agoSimplify slightly and use i2d_PKCS7_bio_stream()
tb [Tue, 2 May 2023 09:30:37 +0000 (09:30 +0000)]
Simplify slightly and use i2d_PKCS7_bio_stream()

This is a wrapper of i2d_ASN1_bio_stream() that doesn't require us to
pass in PKCS7_it.

18 months agoadd Brussels South Charleroi airport
stsp [Tue, 2 May 2023 08:48:06 +0000 (08:48 +0000)]
add Brussels South Charleroi airport

18 months agosync with userland
tb [Tue, 2 May 2023 08:05:18 +0000 (08:05 +0000)]
sync with userland

18 months agoSync with upstream
tb [Tue, 2 May 2023 08:03:54 +0000 (08:03 +0000)]
Sync with upstream

Update some links in the README, remove a duplicate word in a zlib.h doc
comment. The only code change is guarded by #if defined(_WIN32).

18 months agoCall nd6_ns_output() without kernel lock from nd6_resolve().
bluhm [Tue, 2 May 2023 06:06:13 +0000 (06:06 +0000)]
Call nd6_ns_output() without kernel lock from nd6_resolve().
OK kn@

18 months agostray whitespace
tb [Mon, 1 May 2023 21:15:26 +0000 (21:15 +0000)]
stray whitespace

18 months agoBump to 8.0
claudio [Mon, 1 May 2023 19:44:42 +0000 (19:44 +0000)]
Bump to 8.0

18 months agoAdd a missing pair of braces.
tb [Mon, 1 May 2023 17:53:01 +0000 (17:53 +0000)]
Add a missing pair of braces.

18 months agoUse uppercase for the CURVE_LIST_LENGTH macro
tb [Mon, 1 May 2023 17:49:33 +0000 (17:49 +0000)]
Use uppercase for the CURVE_LIST_LENGTH macro

18 months agoConsistently use lowercase hex digits for curve parameters
tb [Mon, 1 May 2023 17:31:15 +0000 (17:31 +0000)]
Consistently use lowercase hex digits for curve parameters

18 months agoNow that we have C99 initializers, garbage collect some comments
tb [Mon, 1 May 2023 17:29:36 +0000 (17:29 +0000)]
Now that we have C99 initializers, garbage collect some comments

18 months agoRework the curve list to use actual structs instead of a custom
tb [Mon, 1 May 2023 17:28:03 +0000 (17:28 +0000)]
Rework the curve list to use actual structs instead of a custom
serialized format.

ok jsing

18 months agoDrop the now unnecessary and unused field_type from the curve data
tb [Mon, 1 May 2023 13:49:26 +0000 (13:49 +0000)]
Drop the now unnecessary and unused field_type from the curve data

ok jsing

18 months agoConvert EC_CURVE_DATA to C99 initializers
tb [Mon, 1 May 2023 13:14:00 +0000 (13:14 +0000)]
Convert EC_CURVE_DATA to C99 initializers

Also clean up the definition of EC_CURVE_DATA a bit.

ok jsing

18 months agoSimplify ec_group_new_from_data() further
tb [Mon, 1 May 2023 12:39:38 +0000 (12:39 +0000)]
Simplify ec_group_new_from_data() further

We have a BN_CTX available, so we may as well use it. This simplifies
the cleanup path at the cost of a bit more code in the setup. Also use
an extra BIGNUM for the cofactor. Reusing x for this is just silly. If
you were really going to avoid extra allocations, this entire function
could easily have been written with three BIGNUMs.

ok jsing

18 months agoMake warnings more precise
job [Mon, 1 May 2023 11:02:23 +0000 (11:02 +0000)]
Make warnings more precise

18 months agoImport regenerated moduli.
dtucker [Mon, 1 May 2023 08:57:29 +0000 (08:57 +0000)]
Import regenerated moduli.

18 months agoThe built-in 10G Ethernet on Apple arm64 hardware does not have a MAC
kettenis [Mon, 1 May 2023 08:25:55 +0000 (08:25 +0000)]
The built-in 10G Ethernet on Apple arm64 hardware does not have a MAC
address programmed into the hardware.  Get it from the device tree instead.

ok dlg@, jmatthew@

18 months agoDrop some dead code
tb [Mon, 1 May 2023 08:16:17 +0000 (08:16 +0000)]
Drop some dead code

No member of the curve_list[] table has a method set. Thus, curve.meth
is always NULL and we never take the EC_GROUP_new(meth) code path.

ok jsing

18 months agoRemove pointless/wrong .meth = 0 entries from curves_list[]
tb [Mon, 1 May 2023 07:58:34 +0000 (07:58 +0000)]
Remove pointless/wrong .meth = 0 entries from curves_list[]

18 months agoMechanically convert curve_list[] to C99 initializers
tb [Mon, 1 May 2023 07:56:05 +0000 (07:56 +0000)]
Mechanically convert curve_list[] to C99 initializers

ok jsing

18 months agoClean up handling of nist_curves[]
tb [Mon, 1 May 2023 07:54:08 +0000 (07:54 +0000)]
Clean up handling of nist_curves[]

There's no point in introducing a typedef only for two sizeof() calls.
We might as well use an anonymous struct for this list. Make it const
while there, drop some braces and compare strcmp() return value to 0.

ok jsing

18 months agoRemove ASN1_item_ndef_i2d(3) documentation
tb [Mon, 1 May 2023 07:37:45 +0000 (07:37 +0000)]
Remove ASN1_item_ndef_i2d(3) documentation

This was the last public API explicitly named ndef/NDEF for indefinite
length encoding, so remove that explanation as well.

18 months agosync
tb [Mon, 1 May 2023 07:29:12 +0000 (07:29 +0000)]
sync

18 months agoFirst pass of removing low-level ASN.1 streaming docs
tb [Mon, 1 May 2023 07:28:11 +0000 (07:28 +0000)]
First pass of removing low-level ASN.1 streaming docs

18 months agoregen
dlg [Mon, 1 May 2023 07:24:20 +0000 (07:24 +0000)]
regen

18 months agoIntel Braswell SDIO
dlg [Mon, 1 May 2023 07:24:04 +0000 (07:24 +0000)]
Intel Braswell SDIO

18 months agospelling
jsg [Mon, 1 May 2023 07:04:38 +0000 (07:04 +0000)]
spelling

18 months agoadd acpi(4) listing; ok miod
jmc [Mon, 1 May 2023 06:04:46 +0000 (06:04 +0000)]
add acpi(4) listing; ok miod

18 months agodrm/fb-helper: set x/yres_virtual in drm_fb_helper_check_var
jsg [Mon, 1 May 2023 01:24:02 +0000 (01:24 +0000)]
drm/fb-helper: set x/yres_virtual in drm_fb_helper_check_var

From Daniel Vetter
d27acf15c8fac00a251e2a24da09fcc1bb3337dd in linux-6.1.y/6.1.27
1935f0deb6116dd785ea64d8035eab0ff441255b in mainline linux

18 months agoavoid use after free
jsg [Sun, 30 Apr 2023 23:49:14 +0000 (23:49 +0000)]
avoid use after free
ok jmatthew@

18 months agoavoid use after free
jsg [Sun, 30 Apr 2023 23:46:52 +0000 (23:46 +0000)]
avoid use after free
ok florian@

18 months agoregen
jsg [Sun, 30 Apr 2023 23:40:12 +0000 (23:40 +0000)]
regen

18 months agoadd Ryzen 7040 "Phoenix" APU device id
jsg [Sun, 30 Apr 2023 23:38:52 +0000 (23:38 +0000)]
add Ryzen 7040 "Phoenix" APU device id

spotted in notebookcheck review of
Asus ROG Zephyrus G14 (2023) GA402XY, Ryzen 9 7940HS (Radeon 780M)

18 months agoadjust ftruncate() logic to handle servers that reorder requests.
djm [Sun, 30 Apr 2023 22:54:22 +0000 (22:54 +0000)]
adjust ftruncate() logic to handle servers that reorder requests.

sftp/scp will ftruncate the destination file after a transfer completes,
to deal with the case where a longer destination file already existed.
We tracked the highest contiguous block transferred to deal with this
case, but our naive tracking doesn't deal with servers that reorder
requests - a misfeature strictly permitted by the protocol but seldom
implemented.

Adjust the logic to ftruncate() at the highest absolute block received
when the transfer is successful. feedback deraadt@ ok markus@

prompted by https://github.com/openssh/openssh-portable/commit/9b733#commitcomment-110679778

18 months agoFSSIZE was not updated when 'fakeramdisk' was enlarged from 5760
krw [Sun, 30 Apr 2023 22:44:18 +0000 (22:44 +0000)]
FSSIZE was not updated when 'fakeramdisk' was enlarged from 5760
blocks to 6080 blocks with etc.alpha/disktab r1.24.

Noticed by deraadt@

18 months agoFix typo in MRDISKTYPE.
krw [Sun, 30 Apr 2023 22:28:27 +0000 (22:28 +0000)]
Fix typo in MRDISKTYPE.

'rdroot' (size 10,240 blocks) is not the same as 'rdboot' (size
2,048 blocks).

Noticed by deraadt@

18 months agox509_asn1: make this test pass again after reinstating DER preservation
tb [Sun, 30 Apr 2023 21:31:16 +0000 (21:31 +0000)]
x509_asn1: make this test pass again after reinstating DER preservation

18 months agocheck_complete.pl: update for recent changes in bn
tb [Sun, 30 Apr 2023 20:33:31 +0000 (20:33 +0000)]
check_complete.pl: update for recent changes in bn

18 months agomandoc -Tlint tells me I forgot to zap a comma
tb [Sun, 30 Apr 2023 20:17:59 +0000 (20:17 +0000)]
mandoc -Tlint tells me I forgot to zap a comma

18 months agodocument that - with recent changes - the -A option now also excludes
benno [Sun, 30 Apr 2023 20:10:38 +0000 (20:10 +0000)]
document that - with recent changes - the -A option now also excludes
the ASPA data from the JSON output.
ok claudio@

18 months agosync
tb [Sun, 30 Apr 2023 19:41:01 +0000 (19:41 +0000)]
sync

18 months agoRemove most documentation pertaining to proxy certificates.
tb [Sun, 30 Apr 2023 19:40:23 +0000 (19:40 +0000)]
Remove most documentation pertaining to proxy certificates.

Update EXFLAG_PROXY and X509_V_FLAG_ALLOW_PROXY_CERTS documentation since
we need to keep them for the time being.

18 months agoRemove proxy cert api remmnants
tb [Sun, 30 Apr 2023 19:31:05 +0000 (19:31 +0000)]
Remove proxy cert api remmnants

18 months agoRemove documentation of BN_generate_prime(), BN_is_prime{,_fasttest}()
tb [Sun, 30 Apr 2023 19:24:42 +0000 (19:24 +0000)]
Remove documentation of BN_generate_prime(), BN_is_prime{,_fasttest}()

18 months agoRemove documentation of BN_zero_ex() and update BN_one() and BN_zero()
tb [Sun, 30 Apr 2023 19:23:54 +0000 (19:23 +0000)]
Remove documentation of BN_zero_ex() and update BN_one() and BN_zero()
which are no longer macros (and the latter is no longer deprecated and
no longer attempts to allocate memory).

18 months agoGarbage collect BN_zero_ex()
tb [Sun, 30 Apr 2023 19:15:48 +0000 (19:15 +0000)]
Garbage collect BN_zero_ex()

18 months agoRemove the EFI RTC implementation on amd64. Since all amd64 systems we
kettenis [Sun, 30 Apr 2023 17:24:24 +0000 (17:24 +0000)]
Remove the EFI RTC implementation on amd64.  Since all amd64 systems we
know have a MC146818A compatible RTC this code isn't actually used.  But
there are systems that have a buggy EFI implementation that blows up when
we call the GetTime runtime service to check whether the RTC functionality
is implemented.

ok mlarkin@, dlg@

18 months agomsdosfs: Never allocate clusters outside the volume
sf [Sun, 30 Apr 2023 17:16:36 +0000 (17:16 +0000)]
msdosfs: Never allocate clusters outside the volume

- Assert that usemap_alloc() and usemap_free() cluster number argument
  is valid.
- In chainlength(), return 0 if cluster start is after the max cluster.
- In chainlength(), cut the calculated cluster chain length at the max
  cluster.

Adapted from FreeBSD commit 097a1d5fbb7990980f8f806c6878537c964adf32

ok miod@

18 months agoRemove __dead again. Apparently this causes issues for some upstreams.
tb [Sun, 30 Apr 2023 17:07:46 +0000 (17:07 +0000)]
Remove __dead again. Apparently this causes issues for some upstreams.

Thanks to orbea for the report

18 months agoRevert disablement of the encoding cache
job [Sun, 30 Apr 2023 16:46:49 +0000 (16:46 +0000)]
Revert disablement of the encoding cache

Without the cache, we verify CRL signatures on bytes that have been
pulled through d2i_ -> i2d_, this can cause reordering, which in turn
invalidates the signature. for example if in the original CRL revocation
entries were sorted by date instead of ascending serial number order.

There are probably multiple things we can do here, but they will need
careful consideration and planning.

OK jsing@

18 months agoSend x509_subject_cmp() to the attic
tb [Sun, 30 Apr 2023 14:59:52 +0000 (14:59 +0000)]
Send x509_subject_cmp() to the attic

This helper has been inside #if 0 for nearly 25 years. Let it go. If we
should ever need it, I'm quite confident that we will be able to come up
with its one line body on our own.

18 months agosync
tb [Sun, 30 Apr 2023 14:50:28 +0000 (14:50 +0000)]
sync

18 months agoThe policy tree is no more
tb [Sun, 30 Apr 2023 14:49:47 +0000 (14:49 +0000)]
The policy tree is no more

Mop up documentation mentioning it or any of its numerous accessors that
almost nothing ever used.

18 months agoZap extra blank line
tb [Sun, 30 Apr 2023 14:43:04 +0000 (14:43 +0000)]
Zap extra blank line

18 months agoMake the descriptions of BIO_get_retry_BIO(3) and BIO_get_retry_reason(3)
schwarze [Sun, 30 Apr 2023 14:03:47 +0000 (14:03 +0000)]
Make the descriptions of BIO_get_retry_BIO(3) and BIO_get_retry_reason(3)
more precise.  Among other improvements, describe the three BIO_RR_*
constants serving as reason codes.

18 months agoSlightly improve the documentation of the "oper" parameter by
schwarze [Sun, 30 Apr 2023 13:57:29 +0000 (13:57 +0000)]
Slightly improve the documentation of the "oper" parameter by
explicitly listing the valid arguments, i.e. the BIO_CB_* constants.

18 months agoDocument the eight BIO_CONN_S_* constants that are passed to BIO_info_cb(3)
schwarze [Sun, 30 Apr 2023 13:53:54 +0000 (13:53 +0000)]
Document the eight BIO_CONN_S_* constants that are passed to BIO_info_cb(3)
as the "state" argument.  Document them here because connect BIOs are
the only built-in BIO type using these constants.

18 months agoMark the five BIO_GHBN_* constants as intentionally undocumented.
schwarze [Sun, 30 Apr 2023 13:38:48 +0000 (13:38 +0000)]
Mark the five BIO_GHBN_* constants as intentionally undocumented.
They are intended to be used by BIO_gethostbyname(), which is deprecated
in OpenSSL and already marked as intentionally undocumented in LibreSSL.
Besides, these constants are completely unused by anything.

18 months agoRemove artifical limit of 2 hours on a PIO lifetime, as recommended by
phessler [Sun, 30 Apr 2023 13:08:40 +0000 (13:08 +0000)]
Remove artifical limit of 2 hours on a PIO lifetime, as recommended by
draft-ietf-6man-slaac-renum-05 and implemented by Linux in 2020.

OK florian@

18 months agowhitespace
tb [Sun, 30 Apr 2023 05:21:20 +0000 (05:21 +0000)]
whitespace

18 months agoSort alphabetically
tb [Sun, 30 Apr 2023 05:02:59 +0000 (05:02 +0000)]
Sort alphabetically

18 months agoRemove unnecessary target
tb [Sun, 30 Apr 2023 04:59:20 +0000 (04:59 +0000)]
Remove unnecessary target

18 months agopolicy test: simplify Makefile
tb [Sun, 30 Apr 2023 04:55:30 +0000 (04:55 +0000)]
policy test: simplify Makefile

18 months agoFix that atactl sd0 readattr didn't work for some disks. Change it to
yasuoka [Sun, 30 Apr 2023 00:58:38 +0000 (00:58 +0000)]
Fix that atactl sd0 readattr didn't work for some disks.  Change it to
check the cksums of the attribute values instead of comparing the
revisions.  diff from NetBSD through naito.yuichiro at gmail.com. test
by kolipe.c at exoticsilicon.com.

ok kevlo miod deraadt

18 months agobump version to 8.4
benno [Sat, 29 Apr 2023 18:53:11 +0000 (18:53 +0000)]
bump version to 8.4

18 months agoNew manual page written by Ted Bullock,
schwarze [Sat, 29 Apr 2023 15:38:14 +0000 (15:38 +0000)]
New manual page written by Ted Bullock,
dropping the empty RETURN VALUES section
and adding the missing "#include <stdilib.h>" below EXAMPLES.

18 months agoProvide function prototypes for macros that take arguments,
schwarze [Sat, 29 Apr 2023 13:37:03 +0000 (13:37 +0000)]
Provide function prototypes for macros that take arguments,
rename the "ev" argument to "event" to make some text read better,
and get rid of colons at the ends of list tags.

OK jmc@ and Ted Bullock.

18 months agoMention a few standard BIO_ctrl(3) command constants
schwarze [Sat, 29 Apr 2023 13:06:10 +0000 (13:06 +0000)]
Mention a few standard BIO_ctrl(3) command constants
that provide type-specific functionality here.
While here, fix some wrong return types in the SYNOPSIS.

18 months agoMention a few standard BIO_ctrl(3) command constants
schwarze [Sat, 29 Apr 2023 12:22:08 +0000 (12:22 +0000)]
Mention a few standard BIO_ctrl(3) command constants
that provide type-specific functionality here,
and add the missing return type to one function prototype.

18 months agoAdd "counter-timer" to openboot_special[] in order to not mention it as
miod [Sat, 29 Apr 2023 12:10:08 +0000 (12:10 +0000)]
Add "counter-timer" to openboot_special[] in order to not mention it as
unconfigured during boot, now that timer(4) is gone.

18 months agoMention the type-specific BIO_ctrl(3) command constants
schwarze [Sat, 29 Apr 2023 12:04:54 +0000 (12:04 +0000)]
Mention the type-specific BIO_ctrl(3) command constants
in the manual pages of the respective BIO types.

18 months agoMention the type-specific BIO_ctrl(3) command constants
schwarze [Sat, 29 Apr 2023 12:01:53 +0000 (12:01 +0000)]
Mention the type-specific BIO_ctrl(3) command constants
in the manual pages of the respective BIO type.
While here, fix some wrong return types in the SYNOPSIS.

18 months agoRemove net lock from DIOCGETQUEUE
kn [Sat, 29 Apr 2023 10:25:32 +0000 (10:25 +0000)]
Remove net lock from DIOCGETQUEUE

Same logic and argument as for the parent *S ioctl unlocked in r1.400,
might as well have committed them together:

  Both ticket and number of queues stem from the pf_queues_active list which
  is effectively static to pf_ioctl.c and fully protected by the pf lock.

OK sashan

18 months agoremove some 19 year old #if 0 code
mlarkin [Sat, 29 Apr 2023 10:18:06 +0000 (10:18 +0000)]
remove some 19 year old #if 0 code

ok deraadt

18 months agowhitespace
mlarkin [Sat, 29 Apr 2023 10:12:33 +0000 (10:12 +0000)]
whitespace

18 months agoas noticed by sdk@, a package with an exact numbers of 64K chunks would
espie [Sat, 29 Apr 2023 10:08:18 +0000 (10:08 +0000)]
as noticed by sdk@, a package with an exact numbers of 64K chunks would
produce a spurious error (so 1 chance in 2^26)

It's like read/write: we need to recognize 0 as EOF and not try to checksum
a non-existing block.

while there, also make sure that we got all the signed blocks at EOF
before exit(0)

Note that none of those two bugs affect the actual security of signed
packages: the basic assertion that only signed data gets written
through the pipe is still 100% valid !

but it's a good idea to not emit spurious messages for valid files, and also
to recognize truncated files !

okay tb@ (thanks a lot)

18 months agoPrint VHE feature in dmesg.
kettenis [Sat, 29 Apr 2023 08:50:53 +0000 (08:50 +0000)]
Print VHE feature in dmesg.

ok mlarkin@, patrick@

18 months agoRun open rsync and ports rsync programs against each other using
bluhm [Sat, 29 Apr 2023 00:20:46 +0000 (00:20 +0000)]
Run open rsync and ports rsync programs against each other using
the --rsync-path option.  So we can see whether the tests pass in
all interoperability combinations.
Suggested by claudio@

18 months agoMark OpenSSLDie() as __dead
tb [Fri, 28 Apr 2023 21:40:14 +0000 (21:40 +0000)]
Mark OpenSSLDie() as __dead

This tells gcc that OPENSSL_assert() will not return and thus avoids a
silly warning that triggers scary gentoo QA warnings.

From claudio

18 months agovmd(8): fix specifying boot image in vm.conf
dv [Fri, 28 Apr 2023 21:22:20 +0000 (21:22 +0000)]
vmd(8): fix specifying boot image in vm.conf

Previous change to allow overriding changed the way we parsed and
stored the boot image path. The lifetime of the path was...much too
short. Heap allocate the kernel path.

Found by Mischa Peters.

ok mlarkin@

18 months agoadjust after man_validate.c rev. 1.128 improved the error messages
schwarze [Fri, 28 Apr 2023 20:34:26 +0000 (20:34 +0000)]
adjust after man_validate.c rev. 1.128 improved the error messages

18 months agoMake LLVM 15 happier by changing from K&R to ANSI prototypes
tb [Fri, 28 Apr 2023 20:22:35 +0000 (20:22 +0000)]
Make LLVM 15 happier by changing from K&R to ANSI prototypes

18 months agoDo not rewrite MAN_LP and MAN_P to MAN_PP because doing that causes
schwarze [Fri, 28 Apr 2023 20:14:19 +0000 (20:14 +0000)]
Do not rewrite MAN_LP and MAN_P to MAN_PP because doing that causes
confusing warning messages complaining about macros that don't even
appear in the input file.
As a welcome side effect, this also shortens the code...

Fixing a minibug
reported by Alejandro Colomar <alx dot manpages at gmail dot com>.

18 months agoClarify -b usage by `vmctl start`.
dv [Fri, 28 Apr 2023 20:13:56 +0000 (20:13 +0000)]
Clarify -b usage by `vmctl start`.

18 months agoAdd rtentry refcnt type to dt(4).
mvs [Fri, 28 Apr 2023 20:03:13 +0000 (20:03 +0000)]
Add rtentry refcnt type to dt(4).

ok bluhm@

18 months agovmd(8)/vmctl(8): allow vm owners to override boot kernel.
dv [Fri, 28 Apr 2023 19:46:41 +0000 (19:46 +0000)]
vmd(8)/vmctl(8): allow vm owners to override boot kernel.

vmd allows non-root users to "own" a vm defined in vm.conf(5). While
the user can start/stop the vm, if they break their filesystem they
have no means of booting recovery media like a ramdisk kernel.

This change opens the provided boot kernel via vmctl and passes the
file descriptor through the control channel to vmd. The next boot
of the vm will use the provided file descriptor as boot kernel/bios.
Subsequent boots (e.g. a reboot) will return to using behavior
defined in vm.conf or the default bios image.

ok mlarkin@

18 months agoExecute each test as make target. Remove the shell wrapper. Mark
bluhm [Fri, 28 Apr 2023 19:41:07 +0000 (19:41 +0000)]
Execute each test as make target.  Remove the shell wrapper.  Mark
failing test so that claudio@ can fix them.

18 months agoRemove unneeded header includes in vmd.
dv [Fri, 28 Apr 2023 18:52:22 +0000 (18:52 +0000)]
Remove unneeded header includes in vmd.

No functional change. virtio block/networking emulation do not need
to know about vmm or any kernel types.

18 months agobump MAXDSIZ to 128G on amd64 and 64G on arm64
robert [Fri, 28 Apr 2023 18:33:22 +0000 (18:33 +0000)]
bump MAXDSIZ to 128G on amd64 and 64G on arm64
discussed with kettenis@, ok deraadt@

18 months agoFree all libcrypto global state memory before returning
job [Fri, 28 Apr 2023 18:32:40 +0000 (18:32 +0000)]
Free all libcrypto global state memory before returning

Found with the help of Otto's malloc memory leak detector!

18 months agoReturn a non-zero error exit code on any DER cache discrepancies
job [Fri, 28 Apr 2023 18:31:34 +0000 (18:31 +0000)]
Return a non-zero error exit code on any DER cache discrepancies

18 months agotimer(4/sparc64): remove driver
cheloha [Fri, 28 Apr 2023 18:27:55 +0000 (18:27 +0000)]
timer(4/sparc64): remove driver

The timer(4/sparc64) driver was effectively disabled during the
previous release.  Nobody has come forward asking for it to be adapted
to work with the new clockintr framework, so it's time to remove the
driver from the tree.

As of today, if you want to run OpenBSD on SPARC v9 hardware, that
hardware needs to sport either %tick and %tick_compare (%asr23), or
%stick (%asr24) and %stick_compare (%asr25).

All Sun/Oracle SPARC v9 hardware meets these conditions, from the
UltraSPARC I onward.

Most HAL/Fujitsu SPARC v9 hardware meets these conditions, from the
SPARC64 III onward.  The only HAL/Fujitsu hardware that might not have
%tick_compare are the HAL SPARC64 I and SPARC64 II, for which I can
find no documentation.  However, those processors are currently
unsupported by OpenBSD for other reasons, so their support status is
unchanged by the removal of this driver.

With help from miod@.

Link: https://marc.info/?l=openbsd-tech&m=167898759928206&w=2
"after unlock" deraadt@, ok mlarkin@ miod@

18 months agoFix leaks reported by ASAN
tb [Fri, 28 Apr 2023 18:27:49 +0000 (18:27 +0000)]
Fix leaks reported by ASAN

debugged with job

18 months agoRevert amd64/i386 floppy change. Missing diff to vnconfig broke
krw [Fri, 28 Apr 2023 18:14:59 +0000 (18:14 +0000)]
Revert amd64/i386 floppy change. Missing diff to vnconfig broke
installboot'ing due to incorrect d_type (must be 'floppy' not
'vnd') in disklabel.

Noticed by deraadt@ and sthen@

18 months agoToo many stupid things whine about these being used uninitialized
tb [Fri, 28 Apr 2023 18:14:59 +0000 (18:14 +0000)]
Too many stupid things whine about these being used uninitialized
(which they aren't), so appease them.

18 months agoRemove preservation and use of cached DER/BER encodings in the d2i/i2d paths
job [Fri, 28 Apr 2023 17:59:53 +0000 (17:59 +0000)]
Remove preservation and use of cached DER/BER encodings in the d2i/i2d paths

A long time ago a workflow was envisioned for X509, X509_CRL, and X509_REQ
structures in which only fields modified after deserialization would need to
be re-encoded upon serialization.

Unfortunately, over the years, authors would sometimes forget to add code in
setter functions to trigger invalidation of previously cached DER encodings.

The presence of stale versions of structures can lead to very hard-to-debug
issues and cause immense sorrow.

Fully removing the concept of caching DER encodings ensures stale versions
of structures can never rear their ugly heads again.

OK tb@ jsing@

18 months agoSome wording tweaks to finish the polishing.
schwarze [Fri, 28 Apr 2023 17:31:58 +0000 (17:31 +0000)]
Some wording tweaks to finish the polishing.
While here, also correct the HISTORY section.
OK jmc@