espie [Mon, 15 Mar 2021 09:32:04 +0000 (09:32 +0000)]
tweaks to system version handling:
- create an element that accumulates version values for when we have
several
- actually use compare on version values instead of hardcoding the
difference
no functional change
jsg [Mon, 15 Mar 2021 09:29:51 +0000 (09:29 +0000)]
spelling
espie [Mon, 15 Mar 2021 09:26:29 +0000 (09:26 +0000)]
add a check for system-version, since I tend to reverse comparisons
claudio [Mon, 15 Mar 2021 08:56:31 +0000 (08:56 +0000)]
Allocate the repo structs individually linked by a SLIST instead of using
an array that is reallocated during runtime. With this the entityq can
move back into struct repo.
OK tb@
tobhe [Sun, 14 Mar 2021 20:23:43 +0000 (20:23 +0000)]
Log errors with log level info and SPI.
florian [Sun, 14 Mar 2021 16:05:50 +0000 (16:05 +0000)]
Since we are doing getifaddrs() anyway we can get the rdomain out of
AF_LINK and skip one ioctl.
OK benno
patrick [Sun, 14 Mar 2021 14:46:52 +0000 (14:46 +0000)]
msi-map-mask is a pasto and should be iommu-map-mask.
From Jared McNeill at NetBSD
ok kettenis@
jmc [Sun, 14 Mar 2021 10:08:38 +0000 (10:08 +0000)]
add HISTORY; from maxim vuets
jan [Sun, 14 Mar 2021 01:10:35 +0000 (01:10 +0000)]
regen
jan [Sun, 14 Mar 2021 01:09:29 +0000 (01:09 +0000)]
Add ID for Intel SSD DC
ok jsg@
tobhe [Sat, 13 Mar 2021 23:01:49 +0000 (23:01 +0000)]
Use EXFLAG_INVALID to handle out of memory and parse errors in
x509v3_cache_extensions().
ok tb@
kn [Sat, 13 Mar 2021 21:23:29 +0000 (21:23 +0000)]
Remove "deletetunnel" (deprecated with 6.4)
OK deraadt
kn [Sat, 13 Mar 2021 21:21:36 +0000 (21:21 +0000)]
Move all rdomain bits under SMALL
"[-]rdomain" commands are ignored under SMALL but their prototypes,
the global and therefore dead print logic are still in.
OK deraadt
kn [Sat, 13 Mar 2021 21:14:15 +0000 (21:14 +0000)]
Move MPLS related function prototypes under SMALL
OK deraadt
deraadt [Sat, 13 Mar 2021 21:11:56 +0000 (21:11 +0000)]
because the kernel has been replaced after last boot, run kvm_mkdb
before the first consumer of kvm_bsd.db
sthen [Sat, 13 Mar 2021 16:41:47 +0000 (16:41 +0000)]
sync usb_device_info with usb.h, spotted by Enrik Berkhan, and millert@
noticed another change
kettenis [Sat, 13 Mar 2021 14:02:02 +0000 (14:02 +0000)]
Advertise 30-bit color support.
ok matthieu@, jsg@
sthen [Sat, 13 Mar 2021 11:36:31 +0000 (11:36 +0000)]
only try to set timestamps on files; avoids error with ftp -o /dev/null
ok jca robert
kettenis [Sat, 13 Mar 2021 10:09:40 +0000 (10:09 +0000)]
We can use memory marked as EfiBootServicesCode or EfiBootServicesData
as well.
ok drahn@, kn@
dtucker [Sat, 13 Mar 2021 01:52:16 +0000 (01:52 +0000)]
Add TEST_SSH_MODULI_FILE variable to allow overriding of the moduli file
used during the test run.
kettenis [Fri, 12 Mar 2021 23:42:50 +0000 (23:42 +0000)]
Add WSDISPLAYIO_DEPTH_30 in order to support 30-bit color support.
ok jsg@
deraadt [Fri, 12 Mar 2021 19:58:47 +0000 (19:58 +0000)]
sync
sthen [Fri, 12 Mar 2021 19:45:27 +0000 (19:45 +0000)]
merge unbound-1.13.1
sthen [Fri, 12 Mar 2021 19:44:11 +0000 (19:44 +0000)]
update to unbound-1.13.1, tested by gnezdo@
florian [Fri, 12 Mar 2021 19:35:43 +0000 (19:35 +0000)]
INET6_NOPRIVACY is called AUTOCONF6TEMP now, missed during rename.
stsp [Fri, 12 Mar 2021 17:54:50 +0000 (17:54 +0000)]
In ipw(4), ensure that net80211 is in ASSOC state while we are expecting
an assoc response from the AP during the association sequence. Otherwise
net80211 would ignore the auth response, resulting in a state mismatch
between firmware and net80211. A symptom of this was that WPA didn't work.
Problem reported and fix tested by Ricardo Mottola
florian [Fri, 12 Mar 2021 17:25:02 +0000 (17:25 +0000)]
Add deprecation warning for autoconfprivacy.
While here check address family for 'temporary' option, only inet6 is
allowed.
OK kn
stsp [Fri, 12 Mar 2021 16:27:27 +0000 (16:27 +0000)]
Use RA instead of MiRA in iwn(4).
Tested by:
iwn 6200: stsp
iwn 6205: cwen, Jeremy O'Brien
iwn 6300: okan
stsp [Fri, 12 Mar 2021 16:27:10 +0000 (16:27 +0000)]
Use RA instead of MiRA in iwm(4).
Tested by:
iwm 7260: florian
iwm 7265: TronDD, Aaron Miller, stsp
iwm 8260: bket
iwm 8265: matthieu, tracey, naddy, Dave Voutila, jcs, Mathieu Kerjouan,
Matthias Schmidt, stsp
iwm 9260: matthieu, phessler, Darren VanBuren
iwm 9560: Uwe Werler
stsp [Fri, 12 Mar 2021 16:26:27 +0000 (16:26 +0000)]
Add RA, a new 11n Tx rate adaptation module for net80211.
Written by Christian Ehrhardt and myself, based on ieee80211_mira.c
but with significant changes.
The main difference is that RA does not attempt to precisely measure
actual throughput but simply deducts a loss percentage from the
theoretical throughput which can be achieved by a given MCS.
Unlike MiRa, RA does not use timeouts to trigger probing.
Probing is triggered only by changes in measured throughput.
Unlike MiRA, RA doesn't care whether a frame was part of an A-MPDU.
RA simply collects statistics for individual subframes. This makes reporting
very easy for drivers and seems to work well enough in practice.
Another difference is that drivers can report multi-rate retries properly
via ieee80211_ra_add_stats_ht(mcs, total, fail) which can be called
several times before ieee80211_ra_choose() selects a new Tx rate.
There is no reason any issues could not be fixed in ieee8011_mira.c but
I felt it was a good moment to burn the house down and start over.
And since this code diverges from how MiRA is described in the research
paper applying the "MiRA" label becomes inappropriate.
tb [Fri, 12 Mar 2021 15:57:30 +0000 (15:57 +0000)]
Zap a useless variable.
suggested by jsing
tb [Fri, 12 Mar 2021 15:55:26 +0000 (15:55 +0000)]
Missing void in function definition
ok jsing
tb [Fri, 12 Mar 2021 15:53:38 +0000 (15:53 +0000)]
Fix checks of memory caps of constraints names
x509_internal.h defines caps on the number of name constraints and
other names (such as subjectAltNames) that we want to allocate per
cert chain. These limits are checked too late. In a particularly
silly cert that jan found on ugos.ugm.ac.id 443, we ended up
allocating six times 2048 x509_constraint_name structures before
deciding that these are more than 512.
Fix this by adding a names_max member to x509_constraints_names which
is set on allocation against which each addition of a name is checked.
cluebat/ok jsing
ok inoguchi on earlier version
fcambus [Fri, 12 Mar 2021 14:39:37 +0000 (14:39 +0000)]
Update Spleen kernel fonts to version 1.9.0, bringing the following
improvements:
- Enlarge vertical line for consistency with other small sizes (5x8 version)
- Add full support for the Latin-1 Supplement Unicode block (6x12 version)
jsg [Fri, 12 Mar 2021 14:15:49 +0000 (14:15 +0000)]
spelling
ok mpi@
kn [Fri, 12 Mar 2021 11:32:03 +0000 (11:32 +0000)]
Emulate "[inet] autoconf" hostname.if(5) lines with "dhcp"
With dhcpleased(8) in base, netstart(8) and ifconfig(8) understand both
"autoconf" and "inet autoconf" lines in hostname.if(5) files to signal the
new daemon.
The installer however currently has only dhclient(8), hence manual upgrades
with "[inet] autoconf" instead of "dhcp" in hostname.if files would fail to
establish IPv4 connectivity.
Make install.sub's netstart clone treat autoconf lines like old fashioned
dhcp lines such users^Wearly testers of the new approach don't get stuck in
nyetwork land.
Note that this is only relevant for manual upgrades; installation always
creates working hostname.if files and automated upgrades with sysupgrade(8)
do not care about network/hostname.if files.
Idea from deraadt
OK deraadt krw ajacoutot
jsg [Fri, 12 Mar 2021 10:22:46 +0000 (10:22 +0000)]
spelling
mpi [Fri, 12 Mar 2021 10:13:28 +0000 (10:13 +0000)]
Kill SINGLE_PTRACE and use SINGLE_SUSPEND which has almost the same semantic
single_thread_set() is modified to explicitly indicated when waiting until
sibling threads are parked is required. This is obviously not required if
a traced thread is switching away from a CPU after handling a STOP signal.
ok claudio@
nicm [Fri, 12 Mar 2021 08:39:17 +0000 (08:39 +0000)]
Fix so tmux correctly sends the cvvis (cursor very visible) capability
rather than sending it and then immediately undoing it with cnorm. Also
turn it off when the cursor shape is changed like xterm.
jsg [Fri, 12 Mar 2021 07:24:49 +0000 (07:24 +0000)]
fix previous
jmc [Fri, 12 Mar 2021 07:05:35 +0000 (07:05 +0000)]
spelling: refenece -> reference
jsg [Fri, 12 Mar 2021 05:18:00 +0000 (05:18 +0000)]
spelling
dtucker [Fri, 12 Mar 2021 04:08:19 +0000 (04:08 +0000)]
Add ModuliFile keyword to sshd_config to specify the location of the
"moduli" file containing the groups for DH-GEX. This will allow us to
run tests against arbitrary moduli files without having to install them.
ok djm@
djm [Fri, 12 Mar 2021 03:43:40 +0000 (03:43 +0000)]
pwcopy() struct passwd that we're going to reuse across a bunch of
library calls; bz3273 ok dtucker@
millert [Fri, 12 Mar 2021 02:10:25 +0000 (02:10 +0000)]
Provide definition of CTRL in vi.c like we do for emacs.c.
Fixes a portability issue. From Benjamin Baier
naddy [Thu, 11 Mar 2021 21:18:25 +0000 (21:18 +0000)]
quiz: handle line continuation in data files correctly, switch to getline(3)
Specifically, the following quiz.db line
foo:\
bar
was parsed into "foo:bar\n", which made it impossible to answer correctly.
Bug reported and inital fix from Alex Karle, partially reworked by
yours truly, further input from millert@
jmc [Thu, 11 Mar 2021 21:07:16 +0000 (21:07 +0000)]
fix a double space and a macro error;
florian [Thu, 11 Mar 2021 19:53:39 +0000 (19:53 +0000)]
When RFC 8981 obsoleted RFC 4941 the terminology changed from
"privacy extensions" to "temporary address extensions"
Change ifconfig(8) to output temporary after temporary addresses and
add "temporary" option which is an alias for autoconfprivacy for now.
Also make AUTOCONF6TEMP a positiv flag that is set by default.
Previously the negative flag "INET6_NOPRIVACY" was set when privacy
addresses were disabled. This makes the flags output less ugly and
will allow us to disable autoconf addresses while having temporary
addresses enabled in the future.
More work is needed in slaacd.
input benno, jmc, deraadt
previous verison OK benno
OK jmc, kn
kn [Thu, 11 Mar 2021 18:12:41 +0000 (18:12 +0000)]
Use unveil(2)
Pledge is not possible due to the ioctls, but as apmd hoists both the
control socket and apm device early at startup and only ever possibly
executes scripts under /etc/apm/, hiding the rest of the filesystem
becomes easy.
Technically, only "x" is required to traverse the directory and run
scripts, but apmd carefully access(2) each script, which requires
the read bit regardless of the permission bits being tested.
OK mestre
jsing [Thu, 11 Mar 2021 17:14:46 +0000 (17:14 +0000)]
Remove ssl_downgrade_max_version().
Now that we store our maximum TLS version at the start of the handshake,
we can check against that directly.
ok inoguchi@ tb@
florian [Thu, 11 Mar 2021 16:48:47 +0000 (16:48 +0000)]
There is no need to try to attach IPv6 to an interface when the
AUTOCONF6 flag is already set.
This is likely a leftover from when we sent router solicitations from
the kernel. This was a way to trigger sending a solicitation from
userland.
OK kn
deraadt [Thu, 11 Mar 2021 15:56:27 +0000 (15:56 +0000)]
If the AUTOCONF4 or AUTOCONF6 flags get enabled, force the interface up.
ok florian claudio
krw [Thu, 11 Mar 2021 15:30:49 +0000 (15:30 +0000)]
Use timespec timers to determine when select-timeout and timeout intervals
are exceeded.
Feedback from otto@, cheloha@
jsg [Thu, 11 Mar 2021 13:31:35 +0000 (13:31 +0000)]
spelling
claudio [Thu, 11 Mar 2021 11:57:45 +0000 (11:57 +0000)]
Revert rev 1.116
The repo structs are reallocated during runtime and so the back pointers to
the head element of the TAILQ get corrupted.
Noticed by tb@
tb [Thu, 11 Mar 2021 11:57:33 +0000 (11:57 +0000)]
Check for the existence of p5-IO-Socket-SSL by checking for its SSL.pm
instead of running pkg_add which may block due to its locking mechanism.
Precise file to check for suggested by sthen
ok kn deraadt on previous version
jsg [Thu, 11 Mar 2021 11:16:54 +0000 (11:16 +0000)]
spelling
kettenis [Thu, 11 Mar 2021 10:40:22 +0000 (10:40 +0000)]
Add SMP support.
ok patrick@
kn [Thu, 11 Mar 2021 10:12:51 +0000 (10:12 +0000)]
Remove unhelpful sentence from TPMR
with dlg
kn [Thu, 11 Mar 2021 10:09:48 +0000 (10:09 +0000)]
Document veb(4)
All text is copied from other already existing sections, i.e. link flag
handling from TPMR and the rest from BIDGE.
Contrary to BRIDGE, add a synopsis for VEB such that there's a simple
overwiew, especially since veb(4) currently does not explain *how* to use
the described features.
NB: While TPMR and VEB use the same wording for link flags, their semantics
are different, i.e. both different flags and swapped polarity for those
flags.
Feedback jmc dlg
OK dlg
kn [Thu, 11 Mar 2021 09:57:39 +0000 (09:57 +0000)]
Link to sh(1) and use the same wording and markup for EXTRACT_CASES code
"good idea" sthen
claudio [Thu, 11 Mar 2021 09:21:16 +0000 (09:21 +0000)]
There is no need to revisit a file in the repo, so if the RB_INSERT fails
just drop the entity queue element.
OK benno@ tb@
claudio [Thu, 11 Mar 2021 09:19:16 +0000 (09:19 +0000)]
There is no need for a global enity queue, instead use per repo queues.
Simplifies the code a fair bit.
OK tb@
patrick [Thu, 11 Mar 2021 09:15:25 +0000 (09:15 +0000)]
Make sure to skip attaching disabled I2C devices. This can happen on
hardware which include a common parent block in their device trees and
only enable the components that were actually implemented, as seen on
e.g. the NanoPi R4S.
patrick [Thu, 11 Mar 2021 08:55:59 +0000 (08:55 +0000)]
Make sure to skip attaching disabled I2C devices. This can happen on
hardware which include a common parent block in their device trees and
only enable the components that were actually implemented, as seen on
e.g. the NanoPi R4S.
ok kettenis@
deraadt [Thu, 11 Mar 2021 07:57:18 +0000 (07:57 +0000)]
grow media a little
deraadt [Thu, 11 Mar 2021 07:43:34 +0000 (07:43 +0000)]
that 0 should be NULL
nicm [Thu, 11 Mar 2021 07:08:18 +0000 (07:08 +0000)]
Tidy old jobs every hour instead of every 30 seconds.
jmc [Thu, 11 Mar 2021 07:04:12 +0000 (07:04 +0000)]
groff complains about the word "An" in an Rs/Re block, believing it a macro,
so escape it;
nicm [Thu, 11 Mar 2021 06:41:04 +0000 (06:41 +0000)]
Add an "absolute-centre" alignment to use the centre of the total space
instead of only the available space. From Magnus Gross in GitHub issue 2578.
nicm [Thu, 11 Mar 2021 06:31:05 +0000 (06:31 +0000)]
Add split-window -Z to start the pane zoomed, GitHub issue 2591.
jsg [Wed, 10 Mar 2021 22:52:28 +0000 (22:52 +0000)]
Build install media with -fno-asynchronous-unwind-tables to further
reduce size. Allows a clang 11 amd64 release to complete without
overflowing the floppy image.
ok kettenis@ deraadt@
tobhe [Wed, 10 Mar 2021 22:20:44 +0000 (22:20 +0000)]
Handle named references in acpi_getdevlist(). Fixes a regression in acpitz
caused by the reference handling change from December.
ok kettenis@ patrick@
millert [Wed, 10 Mar 2021 21:55:22 +0000 (21:55 +0000)]
zlib functions take a gzFile not gzFile * (gzFile is already a pointer).
From Josh Rickmar.
patrick [Wed, 10 Mar 2021 21:49:55 +0000 (21:49 +0000)]
Our ACPI namerefs are pointers to the byte structures for ACPI names.
These are not in a printable format, hence printing them as string is
wrong. Additionally, aml_searchrel()/aml_searchname() expect the name
to be passed in a printable format as well. Passing a nameref can lead
to an out-of-bounds read, and the comparison can fail. Hence make sure
that namerefs are passed to aml_getname() first, which returns printable
strings. Note that aml_getname() uses a static buffer, so there are a
few restrictions how the string can be used.
ok kettenis@
millert [Wed, 10 Mar 2021 20:17:33 +0000 (20:17 +0000)]
Add support for ^R (redraw) in insert mode too.
From gotroyb127, OK tb@
millert [Wed, 10 Mar 2021 20:16:08 +0000 (20:16 +0000)]
Don't return ERR if resize didn't change size
This is a backport of the ncurses 5.9
20120707 patch.
Previously, getch() would return ERR if SIGWINCH was received but
the window didn't actually change size. This can happen, for
example, when the xterm font is changed. OK tb@
millert [Wed, 10 Mar 2021 20:06:04 +0000 (20:06 +0000)]
Fix redrawing of a multiline PS1 prompt in vi mode.
From gotroyb127 OK tb@
kn [Wed, 10 Mar 2021 19:19:04 +0000 (19:19 +0000)]
Typofix previous
jsing [Wed, 10 Mar 2021 18:32:38 +0000 (18:32 +0000)]
Guard TLS1_get_{client_,}version() macros with #ifndef LIBRESSL_INTERNAL.
These are no longer used (and should not be used) internally.
jsing [Wed, 10 Mar 2021 18:28:01 +0000 (18:28 +0000)]
Revise TLS extension regress to match version handling changes.
jsing [Wed, 10 Mar 2021 18:27:01 +0000 (18:27 +0000)]
Improve internal version handling.
Add handshake fields for our minimum TLS version, our maximum TLS version
and the TLS version negotiated during the handshake. Initialise our min/max
versions at the start of the handshake and leave these unchanged. The
negotiated TLS version is set in the client once we receive the ServerHello
and in the server at the point we select the highest shared version.
Provide an ssl_effective_version() function that returns the negotiated TLS
version if known, otherwise our maximum TLS version - this is effectively
what is stored in s->version currently.
Convert most of the internal code to use one of these three version fields,
which greatly simplifies code (especially in the TLS extension handling
code).
ok tb@
eric [Wed, 10 Mar 2021 17:25:59 +0000 (17:25 +0000)]
do not request client certificate unless required
issue hit by florian@
diff by jsing@
ok tb@
deraadt [Wed, 10 Mar 2021 17:03:58 +0000 (17:03 +0000)]
The ktrace record for recvmsg/recvfrom could contain extract bits in
msg_flags (they get set internally). Correct the record to only contain
what the caller requested.
deraadt [Wed, 10 Mar 2021 17:00:16 +0000 (17:00 +0000)]
cleanup the 3 ways (2 for ipv4, 1 for ipv6) of doing dynamic address
allocation. not the perfect text yet, but it is better.
discussed with florian and jmc
kettenis [Wed, 10 Mar 2021 15:56:06 +0000 (15:56 +0000)]
Let MAIR comment catch up with reality.
patrick [Wed, 10 Mar 2021 12:49:24 +0000 (12:49 +0000)]
Fix typo for ATS attribute member in IORT root complex struct.
yasuoka [Wed, 10 Mar 2021 10:51:10 +0000 (10:51 +0000)]
Expand the maximum length for CHAP challenge to 96 octets. npppd
couldn't handle ICCN message which has a ProxyAuthenChallenge AVP
longer than 24 octets. Juniper actually send such challenges.
Reported and tested by Ryan Freeman.
patrick [Wed, 10 Mar 2021 10:29:26 +0000 (10:29 +0000)]
Fix "phone number" spelling.
ok yasuoka@
jsg [Wed, 10 Mar 2021 10:21:47 +0000 (10:21 +0000)]
spelling
ok gnezdo@ semarie@ mpi@
ratchov [Wed, 10 Mar 2021 08:22:25 +0000 (08:22 +0000)]
sndiod: When a slot structure is recycled allocate new control
Trying to rename the program level control is not needed anymore.
When a slot is given to another program, the new ctl_{new,del}()
functions can be used to delete the control of the old program and
create a new one for the new program. Cleaner, simpler.
ratchov [Wed, 10 Mar 2021 08:21:27 +0000 (08:21 +0000)]
sndiod: Style tweak: swap if/else code blocks in slot_new()
claudio [Wed, 10 Mar 2021 08:09:41 +0000 (08:09 +0000)]
When adding files from the manifest only the .crl need to be first, after
that the order does not matter so simplify the code and just walk the
list twice. Add the .crl first and then in the second round all other files.
OK job@
deraadt [Wed, 10 Mar 2021 07:28:19 +0000 (07:28 +0000)]
pmap_avail_setup() is the only place physmem is calculated, delete a bunch
of code which thinks it could be done elsewhere.
ok kurt
dtucker [Wed, 10 Mar 2021 06:32:27 +0000 (06:32 +0000)]
Import regenerated moduli file.
djm [Wed, 10 Mar 2021 04:58:45 +0000 (04:58 +0000)]
no need to reset buffer after send_msg() as that is done for us;
patch from Mike Frysinger
tobhe [Tue, 9 Mar 2021 22:51:28 +0000 (22:51 +0000)]
Also log transforms on IKE SA rekey.
kettenis [Tue, 9 Mar 2021 21:11:24 +0000 (21:11 +0000)]
Node without a "status" property should be considered enabled as well.
ok patrick@
anton [Tue, 9 Mar 2021 20:05:14 +0000 (20:05 +0000)]
Issuing FIOSETOWN and TIOCSPGRP ioctl commands on a tun(4) device leaks
device references causing a hang while trying to remove the same
interface since the reference count will never reach zero. Instead of
returning, break out of the switch in order to ensure that tun_put()
gets called.
ok deraadt@ mvs@
Reported-by: syzbot+2ca11c73711a1d0b5c6c@syzkaller.appspotmail.com
anton [Tue, 9 Mar 2021 20:03:50 +0000 (20:03 +0000)]
Shorten the if_cloners_lock name preventing it from being truncated in
the top(1) wait column.
ok mvs@