openbsd
2 years agoSend out dstid as initiator if configured. This makes it easier for
tobhe [Sat, 4 Dec 2021 13:07:17 +0000 (13:07 +0000)]
Send out dstid as initiator if configured. This makes it easier for
the responder to match the correct policy if multiple are available.

ok patrick@

2 years agoFree cert, key and ocsp_staple on exit of do_keypair_test().
tb [Sat, 4 Dec 2021 09:04:36 +0000 (09:04 +0000)]
Free cert, key and ocsp_staple on exit of do_keypair_test().

Reported by Ilya Shipitsine, discussed with jsing

2 years agoConvert main into single exit to appease asan.
tb [Sat, 4 Dec 2021 08:15:16 +0000 (08:15 +0000)]
Convert main into single exit to appease asan.

2 years agoExplicitly free EVP_MD_CTX to appease asan. Reported by Ilya Shipitsin.
tb [Sat, 4 Dec 2021 07:58:10 +0000 (07:58 +0000)]
Explicitly free EVP_MD_CTX to appease asan. Reported by Ilya Shipitsin.

2 years agolist backup files created by adduser; from leon fischer
jmc [Sat, 4 Dec 2021 07:31:38 +0000 (07:31 +0000)]
list backup files created by adduser; from leon fischer
adjust list width to make it all fit

2 years agoupdate the firmware file list, helped by stsp;
jmc [Sat, 4 Dec 2021 07:27:38 +0000 (07:27 +0000)]
update the firmware file list, helped by stsp;

2 years agoConsolidate error paths in usbd_new_device, shaving of 14 lines.
anton [Sat, 4 Dec 2021 07:01:59 +0000 (07:01 +0000)]
Consolidate error paths in usbd_new_device, shaving of 14 lines.

ok bluhm@

2 years agoDo not setup pipes between SERVER processes, they don't talk to each
florian [Sat, 4 Dec 2021 06:52:58 +0000 (06:52 +0000)]
Do not setup pipes between SERVER processes, they don't talk to each
other. Since this generates a full mesh, the amount of filedescriptors
needed grows quadratically with the amount of configured prefork
processes.

Might fix an out of filedescriptor bug that beck is seeing.
OK benno

2 years agoAdd regress for ECPKParameters ASN.1 encoding/decoding.
jsing [Sat, 4 Dec 2021 05:15:09 +0000 (05:15 +0000)]
Add regress for ECPKParameters ASN.1 encoding/decoding.

2 years agoRSA/SHA-1 is not used by default anymore on the server
naddy [Sat, 4 Dec 2021 00:05:39 +0000 (00:05 +0000)]
RSA/SHA-1 is not used by default anymore on the server

2 years agoadd Allwinner H6 support
uaa [Fri, 3 Dec 2021 19:22:42 +0000 (19:22 +0000)]
add Allwinner H6 support
ok kettenis@

2 years agosupport AXP805 PMIC
uaa [Fri, 3 Dec 2021 19:17:27 +0000 (19:17 +0000)]
support AXP805 PMIC
ok kettenis@

2 years ago- support I2C connected PMIC, add "early 1" to sxitwi.
uaa [Fri, 3 Dec 2021 19:16:29 +0000 (19:16 +0000)]
- support I2C connected PMIC, add "early 1" to sxitwi.
- support axppmic via iic

ok kettenis@

2 years agoAdd tdb_delete_locked() to replace duplicate tdb deletion code in
tobhe [Fri, 3 Dec 2021 19:04:49 +0000 (19:04 +0000)]
Add tdb_delete_locked() to replace duplicate tdb deletion code in
pfkey_flush().

ok bluhm@ mvs@

2 years agoPerform DMA address translation if required.
kettenis [Fri, 3 Dec 2021 18:23:41 +0000 (18:23 +0000)]
Perform DMA address translation if required.

ok patrick@

2 years agoReplace asn1_tlc_clear and asn1_tlc_clear_nc macros with a function.
jsing [Fri, 3 Dec 2021 17:27:34 +0000 (17:27 +0000)]
Replace asn1_tlc_clear and asn1_tlc_clear_nc macros with a function.

Call the replacement asn1_tlc_invalidate() since it does not actually
clear the ASN1_TLC.

While here, name the ASN1_TLC variables consistently as ctx, remove a
pointless comment and simplify ASN1_item_d2i() slightly.

ok inoguchi@ tb@

2 years agoGroup and sort includes.
jsing [Fri, 3 Dec 2021 17:23:16 +0000 (17:23 +0000)]
Group and sort includes.

2 years agoCall asn1_item_ex_d2i() directly from ASN1_item_d2i()
jsing [Fri, 3 Dec 2021 17:22:10 +0000 (17:22 +0000)]
Call asn1_item_ex_d2i() directly from ASN1_item_d2i()

ASN1_item_ex_d2i() is just a wrapper around the internal asn1_item_ex_d2i()
function, so call asn1_item_ex_d2i() directly.

ok inoguchi@ tb@

2 years agoAdd TDB reference counting to ipsp_spd_lookup(). If an output
bluhm [Fri, 3 Dec 2021 17:18:34 +0000 (17:18 +0000)]
Add TDB reference counting to ipsp_spd_lookup().  If an output
pointer is passed to the function, it will return a refcounted TDB.
The ref happens when ipsp_spd_inp() copies the pointer from
ipo->ipo_tdb.  The caller of ipsp_spd_lookup() has to unref after
using it.
tested by Hrvoje Popovski; OK mvs@ tobhe@

2 years agoConvert ASN1_PCTX_new() to calloc().
jsing [Fri, 3 Dec 2021 17:10:49 +0000 (17:10 +0000)]
Convert ASN1_PCTX_new() to calloc().

Rather than using malloc() and then initialising all struct members to zero
values, use calloc().

ok schwarze@ tb@

2 years agoUse calloc() for X509_CRL_METHOD_new() instead of malloc().
jsing [Fri, 3 Dec 2021 17:07:53 +0000 (17:07 +0000)]
Use calloc() for X509_CRL_METHOD_new() instead of malloc().

This ensures that if any members are added to this struct, they will be
initialised.

ok schwarze@ tb@

2 years agoRewrite ASN1_STRING_cmp().
jsing [Fri, 3 Dec 2021 17:03:54 +0000 (17:03 +0000)]
Rewrite ASN1_STRING_cmp().

This removes nested ifs and uses more sensible variable names.

ok schwarze@ tb@

2 years agoConvert ASN1_STRING_type_new() to calloc().
jsing [Fri, 3 Dec 2021 17:01:07 +0000 (17:01 +0000)]
Convert ASN1_STRING_type_new() to calloc().

Rather than using malloc() and then initialising all struct members, use
calloc() and only initialise the single non-zero value member.

ok schwarze@ tb@

2 years agoConvert ASN1_OBJECT_new() to calloc().
jsing [Fri, 3 Dec 2021 16:58:11 +0000 (16:58 +0000)]
Convert ASN1_OBJECT_new() to calloc().

Rather than using malloc() and then initialising all struct members, use
calloc() and only initialise the single non-zero value member.

ok schwarze@ tb@

2 years agoConvert {i2d,d2i}_{,EC_,DSA_,RSA_}PUBKEY{,_bio,_fp}() to templated ASN1
jsing [Fri, 3 Dec 2021 16:46:50 +0000 (16:46 +0000)]
Convert {i2d,d2i}_{,EC_,DSA_,RSA_}PUBKEY{,_bio,_fp}() to templated ASN1

These functions previously used the old ASN1_{d2i,i2d}_{bio,fp}()
interfaces.

ok inoguchi@ tb@

2 years agoFixed-size NOFILE_MAX (from sys/param.h of course) array is crazy, so
deraadt [Fri, 3 Dec 2021 15:15:22 +0000 (15:15 +0000)]
Fixed-size NOFILE_MAX (from sys/param.h of course) array is crazy, so
rewrite to expand the array as needed.
ok tb

2 years agoSwitch iwx(4) to new -67 firmware images.
stsp [Fri, 3 Dec 2021 14:32:08 +0000 (14:32 +0000)]
Switch iwx(4) to new -67 firmware images.

iwx-firmware-20211101 must be installed with fw_update(1) before
booting a new kernel. sysupgrade(8) will take care of this.

Intel has published a related security advisory:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00509.html

iwx(4) devices which are using the iwx-Qu-c0-hr-b0-63 image did
not receive a firmware update. I have no idea why.

Tested:
ax200: jmc, stsp, Matthias Schmidt
ax201: fkr, stsp

2 years agoUse calloc() in EVP_PKEY_meth_new() instead of malloc() and setting
tb [Fri, 3 Dec 2021 14:19:57 +0000 (14:19 +0000)]
Use calloc() in EVP_PKEY_meth_new() instead of malloc() and setting
almost all members to 0. Just set the two things that need setting.

ok jsing

2 years agoFix EVP_PKEY_{asn1,meth}_copy once and for all
tb [Fri, 3 Dec 2021 14:18:06 +0000 (14:18 +0000)]
Fix EVP_PKEY_{asn1,meth}_copy once and for all

It is very easy to forget to copy over newly added methods. Everyone
working in this corner has run into this. Instead, preserve what needs
preserving and use a struct copy, so all methods get copied from src
to dest.

tweak/ok jsing

2 years agoRevert previous
kn [Fri, 3 Dec 2021 14:15:07 +0000 (14:15 +0000)]
Revert previous

Those scripts are not hooked up to the build yet;
I assumed they were without checking, my bad.

Reminded by deraadt

2 years agoDisable probe requests during scans in iwx(4) again.
stsp [Fri, 3 Dec 2021 13:17:32 +0000 (13:17 +0000)]
Disable probe requests during scans in iwx(4) again.

While this is working well for many, some people see device timeouts
when using the device unless we disable probe requests during scans.

The issue was a lot more visible on iwx(4) with earlier firmware.
In fact, iwx(4) did ship with probe requests disabled for most of its
existence. I re-enabled them along with a firmware upgrade since I no
longer saw the problem. However, the issue prevails for other people.

I still have no idea what is causing this. I have already spent enough
time trying to track down a proper fix. Unless we receive help from
someone who knows about firmware internals the best we can do is trial
and error. The problem also existed on iwm(4) 9k devices which we now
run with probe requests disabled, too.

The only upside of probe requests is that scans can complete faster, with
the downside of a potential privacy leak (the previously selected SSID is
exposed). So, overall, we do not lose much here.

Patch tested for a week by Laurence Tratt who is no longer seeing device
timeouts which were relatively frequent before.

2 years agoApply the same MAX_IP_SIZE limit to ROA files as it is done on certificates.
claudio [Fri, 3 Dec 2021 12:56:19 +0000 (12:56 +0000)]
Apply the same MAX_IP_SIZE limit to ROA files as it is done on certificates.
OK job@ tb@

2 years agoImplement a bgscan_done() handler for iwm(4).
stsp [Fri, 3 Dec 2021 12:43:17 +0000 (12:43 +0000)]
Implement a bgscan_done() handler for iwm(4).

Required to prevent breakage of roaming with new Intel firmware on 9k devices.

Tested:
8265: Aaron Poffenberger, stsp
9260: florian
9560: sthen

2 years agoImplement a bgscan_done() handler for iwx(4).
stsp [Fri, 3 Dec 2021 12:42:39 +0000 (12:42 +0000)]
Implement a bgscan_done() handler for iwx(4).

Fixes roaming-related hangs observed by jmc@.

Tested:
ax200: jmc, stsp

2 years agoIntroduce an optional driver-specific bgscan_done() handler which
stsp [Fri, 3 Dec 2021 12:41:36 +0000 (12:41 +0000)]
Introduce an optional driver-specific bgscan_done() handler which
allows the driver to take control of the roaming teardown sequence.
This handler allows drivers to ensure that race conditions between
firmware state and net80211 state are avoided, and will be used by
the iwm(4) and iwx(4) drivers soon.

Split the existing roaming teardown sequence into two steps, one step
for tearing down Tx block ack sessions which sends a DELBA frame, and a
second step for flushing Tx rings followed by sending a DEAUTH frame.
We used to queue both frames, expecting to switch APs once both were sent.
Now we effectively expect everything to be sent before we queue a final
DEAUTH frame, and wait for just this frame to be sent before switching.
This already made issues on iwm/iwx less frequent but by itself this was
not enough to close all races for those drivers. It should however help
when adding background scan support to a non-firmware device driver.

Tested, with driver patches:
iwm 8265: Aaron Poffenberger, stsp
iwm 9260: florian
iwm 9560: sthen
iwx ax200: jmc, stsp

2 years agoIgnore ADDBA requests from our AP while we are roaming away from it.
stsp [Fri, 3 Dec 2021 12:40:15 +0000 (12:40 +0000)]
Ignore ADDBA requests from our AP while we are roaming away from it.

Noticed while testing iwm/iwx roaming patches, where my AP would request
a new Rx BA session when we had already decided to roam away. There is no
need to set up a new Rx BA session with our old AP which we would have to
immediately tear down again anyway.

2 years agoShip mpi's helpers, see share/btrace/Makefile r1.1:
kn [Fri, 3 Dec 2021 11:47:23 +0000 (11:47 +0000)]
Ship mpi's helpers, see share/btrace/Makefile r1.1:
---
Provide common btrace(8) scripts

. kprofile.bt - to save kernel stackframces and produce flamegraphs
. runqlat.bt  - to measure the latency of the scheduler runqueues

2 years agoClarify manpage
job [Fri, 3 Dec 2021 08:40:07 +0000 (08:40 +0000)]
Clarify manpage

OK claudio@

2 years agoDump more data in the hopes of figuring out why this test occasionally
anton [Fri, 3 Dec 2021 06:44:46 +0000 (06:44 +0000)]
Dump more data in the hopes of figuring out why this test occasionally
fails.

2 years agoBring back the recently reverted change, this time without the inverted
anton [Fri, 3 Dec 2021 06:34:38 +0000 (06:34 +0000)]
Bring back the recently reverted change, this time without the inverted
conditional. Repeating the previous commit messsage:

Assert that at least one report id is claimed during multiple report ids
attachment. Should prevent uhidev drivers from doing the wrong thing in their
corresponding match routine.

Tested by dv@

2 years agohash full host:port when asked to hash output, fixes hashes for non-
djm [Thu, 2 Dec 2021 23:45:36 +0000 (23:45 +0000)]
hash full host:port when asked to hash output, fixes hashes for non-
default ports. bz3367 ok dtucker@

2 years agoimprove the testing of credentials against inserted FIDO keys a little
djm [Thu, 2 Dec 2021 23:23:13 +0000 (23:23 +0000)]
improve the testing of credentials against inserted FIDO keys a little
more: ask the token whether a particular key belongs to it in cases
where the token support on-token user- verification (e.g. biometrics)
rather than just assuming that it will accept it.

Will reduce spurious "Confirm user presence" notifications for key
handles that relate to FIDO keys that are not currently inserted in at
least some cases.

Motivated by bz3366; by Pedro Martelletto

2 years agomove check_sk_options() up so we can use it earlier
djm [Thu, 2 Dec 2021 22:40:05 +0000 (22:40 +0000)]
move check_sk_options() up so we can use it earlier

2 years agossh-rsa is no longer in the default for PubkeyAcceptedAlgorithms.
dtucker [Thu, 2 Dec 2021 22:35:05 +0000 (22:35 +0000)]
ssh-rsa is no longer in the default for PubkeyAcceptedAlgorithms.

2 years agobsearch(3): support arrays with more than INT_MAX elements
cheloha [Thu, 2 Dec 2021 20:58:01 +0000 (20:58 +0000)]
bsearch(3): support arrays with more than INT_MAX elements

The "lim" variable needs to be a size_t to match nmemb, otherwise we
get undefined behavior when nmemb exceeds INT_MAX.

Prompted by a blog post by Joshua Bloch:

https://ai.googleblog.com/2006/06/extra-extra-read-all-about-it-nearly.html

Fixed by Chris Torek a long time ago:

https://svnweb.freebsd.org/csrg/lib/libc/stdlib/bsearch.c?revision=51742&view=markup

ok millert@

2 years agounmount real root partition from /mnt before the cgi/random actions
deraadt [Thu, 2 Dec 2021 17:18:39 +0000 (17:18 +0000)]
unmount real root partition from /mnt before the cgi/random actions
which run asyncronously and can grab vnodes race to make the umount fail
spuriously
problem seen and diagnosed by Yuichiro NAITO
ok florian

2 years agoTell testers which packages to install right away (and why)
kn [Thu, 2 Dec 2021 17:10:53 +0000 (17:10 +0000)]
Tell testers which packages to install right away (and why)

Other regress tests do it differently;  just fix/thouch those that did not
mention any package name at all.

This helps grepping logs for SKIPPED to find instructions for the next run.

2 years agoLog that kern.allowdt=1 is needed and where
kn [Thu, 2 Dec 2021 17:09:46 +0000 (17:09 +0000)]
Log that kern.allowdt=1 is needed and where

This helps grepping logs for SKIPPED to find instructions for the next run.

2 years agoTell testers which packages to install right away
kn [Thu, 2 Dec 2021 15:56:15 +0000 (15:56 +0000)]
Tell testers which packages to install right away

OK bluhm

2 years agolist uppercase options along with lower in SYNOPSIS/options list/usage;
jmc [Thu, 2 Dec 2021 15:15:29 +0000 (15:15 +0000)]
list uppercase options along with lower in SYNOPSIS/options list/usage;
suggested by/ok deraadt

2 years agofirstc() and nextc() use an int of global static storage. Make this
deraadt [Thu, 2 Dec 2021 15:13:49 +0000 (15:13 +0000)]
firstc() and nextc() use an int of global static storage.  Make this
a pointer to a local variable to allow concurrent use if that ever
needs to happen in the future.
ok mpi kettenis

2 years agoipsec_common_input_cb() extracted the inner IP header of IPsec
bluhm [Thu, 2 Dec 2021 13:46:42 +0000 (13:46 +0000)]
ipsec_common_input_cb() extracted the inner IP header of IPsec
tunnels.  It is never used, so this is useless code.  Remove ipn
and ip6n IP header variables and the m_copydata() to fill them.
OK mvs@ kn@ sthen@

2 years agoAllow to build kernel without IPSEC or INET6 defines.
bluhm [Thu, 2 Dec 2021 12:39:15 +0000 (12:39 +0000)]
Allow to build kernel without IPSEC or INET6 defines.
OK mpi@ mvs@

2 years agodon't put the tty into raw mode when SessionType=none, avoids ^c being
djm [Thu, 2 Dec 2021 02:44:44 +0000 (02:44 +0000)]
don't put the tty into raw mode when SessionType=none, avoids ^c being
unable to kill such a session. bz3360; ok dtucker@

2 years agoRemove the MBR_init() "#ifdef defined(__macppc__) ||
krw [Wed, 1 Dec 2021 22:37:30 +0000 (22:37 +0000)]
Remove the MBR_init() "#ifdef defined(__macppc__) ||
defined(__mips__)" chunk that rounded the start of the default
OpenBSD partition to a cylinder boundary. The value has been
immediately re-rounded to a power of 2 block since r1.25 in 2009.

Eliminates wasted space when no /usr/mdec/mbr partition
0 information is available.

'-b' becomes available to architectures other than amd64 and
i386, taking precedence over /usr/mdec/mbr partition 0
information. The latter being present only in macppc and loongson
/usr/mdec/mbr files.

2 years agoReintroduce the TDBF_DELETED flag. Checking next pointer to figure
bluhm [Wed, 1 Dec 2021 22:34:31 +0000 (22:34 +0000)]
Reintroduce the TDBF_DELETED flag.  Checking next pointer to figure
out whether the TDB is linked to the hash bucket does not work.
This fixes removal of SAs that could not be flushed with ipsecctl -F.
OK tobhe@

2 years agomention that the "flags" field in the enchdr is uses m_flags values
deraadt [Wed, 1 Dec 2021 21:48:00 +0000 (21:48 +0000)]
mention that the "flags" field in the enchdr is uses m_flags values
(see mbuf.h)

2 years agosys/core.h is not needed by these files, therefore sys/param.h isn't
deraadt [Wed, 1 Dec 2021 21:45:19 +0000 (21:45 +0000)]
sys/core.h is not needed by these files, therefore sys/param.h isn't
needed for MAXCOMLEN either

2 years agowe do not need 'struct mbuf; struct rtentry;' to satisfy some ancient unix
deraadt [Wed, 1 Dec 2021 18:28:45 +0000 (18:28 +0000)]
we do not need 'struct mbuf; struct rtentry;' to satisfy some ancient unix
variant that made a header file mistake.
ok jsg

2 years agofurther improvements in sys/param.h annotation and removal.
deraadt [Wed, 1 Dec 2021 18:21:23 +0000 (18:21 +0000)]
further improvements in sys/param.h annotation and removal.

2 years agoFix booting from an IDE block device on the Sun Blade 100. Apparently
kettenis [Wed, 1 Dec 2021 17:25:35 +0000 (17:25 +0000)]
Fix booting from an IDE block device on the Sun Blade 100.  Apparently
writing to disk using the Open Firmware interfaces is buggy and causes
corruption of the disk.  While it isn't entirely clear what versions
of Open Firmware are affected, but it seems to only affect IDE drives.
So if we detect an IDE drive, disable writing to it.  This results in
a small lose of bootloader functionality (bsd.upgrade loop prevention
and flagging /etc/random.seed re-use) but that is better than losing
the ability to run OpenBSD at all.

Based on a diff by Ted Bullock (who did all the hard work of debugging
this and coming up with a viable fix).

ok deraadt@

2 years agolate allocation of clist in putc() and b_to_q() hasn't been required in
deraadt [Wed, 1 Dec 2021 17:04:26 +0000 (17:04 +0000)]
late allocation of clist in putc() and b_to_q() hasn't been required in
a decade, because all tty drivers preallocate.
ok kettenis

2 years agoReduce use of sys/param.h, or annotate the reason why it is needed
deraadt [Wed, 1 Dec 2021 16:53:28 +0000 (16:53 +0000)]
Reduce use of sys/param.h, or annotate the reason why it is needed
(pretty much MAXCOMLEN for struct process or struct core), and remove
sys/vnode.h where not needed

2 years agoUse system _ALIGN to reduce the reasons why this uses sys/param.h
deraadt [Wed, 1 Dec 2021 16:51:57 +0000 (16:51 +0000)]
Use system _ALIGN to reduce the reasons why this uses sys/param.h

2 years agowhitespace cleanup during review read
deraadt [Wed, 1 Dec 2021 16:42:12 +0000 (16:42 +0000)]
whitespace cleanup during review read

2 years agoLet ipsp_spd_lookup() return an error instead of a TDB. The TDB
bluhm [Wed, 1 Dec 2021 12:51:09 +0000 (12:51 +0000)]
Let ipsp_spd_lookup() return an error instead of a TDB.  The TDB
is not always needed, but the error value is necessary for the
caller.  As TDB should be refcounted, it makes not sense to always
return it.  Pass an output pointer for the TDB which can be NULL.
OK mvs@ tobhe@

2 years agodrm/amdgpu/gfx9: switch to golden tsc registers for renoir+
jsg [Wed, 1 Dec 2021 10:50:23 +0000 (10:50 +0000)]
drm/amdgpu/gfx9: switch to golden tsc registers for renoir+

From Alex Deucher
45b42cd05391197d5426a9097043d5e77bdbefc9 in linux 5.10.y/5.10.83
53af98c091bc42fd9ec64cfabc40da4e5f3aae93 in mainline linux

2 years agodrm/amd/display: Set plane update flags for all planes in reset
jsg [Wed, 1 Dec 2021 10:47:39 +0000 (10:47 +0000)]
drm/amd/display: Set plane update flags for all planes in reset

From Nicholas Kazlauskas
3187623096091d8c60231de5ca0e020bfa5e6ee9 in linux 5.10.y/5.10.83
21431f70f6014f81b0d118ff4fcee12b00b9dd70 in mainline linux

2 years agoMake `sun' global variable. It used by threads and could be corrupted
mvs [Wed, 1 Dec 2021 10:24:40 +0000 (10:24 +0000)]
Make `sun' global variable. It used by threads and could be corrupted
when main() thread exited.

2 years agoRemove dead code.
jsing [Wed, 1 Dec 2021 09:06:30 +0000 (09:06 +0000)]
Remove dead code.

2 years agoAdd some RRDP specific regress tests.
claudio [Wed, 1 Dec 2021 09:03:19 +0000 (09:03 +0000)]
Add some RRDP specific regress tests.
OK benno@

2 years agoBuild libfido2 after all other libraries, as it links against one of
patrick [Wed, 1 Dec 2021 07:36:03 +0000 (07:36 +0000)]
Build libfido2 after all other libraries, as it links against one of
the other libraries, so we have to build those first.

Initial report and diff from uaa@
ok anton@ deraadt@ millert@

2 years agoImproved error handling in config parser.
tobias [Tue, 30 Nov 2021 20:08:15 +0000 (20:08 +0000)]
Improved error handling in config parser.

- Escaped newlines confused column counter
- An unclosed quote could have been logged multiple times
- Signed data types could overflow, which is undefined behavior

ok tedu

2 years agoAdd missing const qualifiers in a number of BN_* manuals.
tb [Tue, 30 Nov 2021 18:34:35 +0000 (18:34 +0000)]
Add missing const qualifiers in a number of BN_* manuals.

ok schwarze

2 years agolast whitespace diff for now.
tb [Tue, 30 Nov 2021 18:32:55 +0000 (18:32 +0000)]
last whitespace diff for now.

2 years agoKNF for BF_KEY
tb [Tue, 30 Nov 2021 18:31:36 +0000 (18:31 +0000)]
KNF for BF_KEY

2 years agoFix some annoying whitespace inconsistencies.
tb [Tue, 30 Nov 2021 18:27:04 +0000 (18:27 +0000)]
Fix some annoying whitespace inconsistencies.

2 years agoProvide EVP_CTRL_AEAD_* defines.
tb [Tue, 30 Nov 2021 18:20:06 +0000 (18:20 +0000)]
Provide EVP_CTRL_AEAD_* defines.

This commit adds generic EVP_CTRL_AEAD_{SET,GET}_TAG and _SET_IVLEN
defines and aliases the GCM and CCM versions to those.

This is the publicly visible part of OpenSSL's e640fa02005.

ok inoguchi jsing

2 years agoAlign ssl_kex_derive_ecdhe_ecp() with ssl_kex_derive_dhe()
tb [Tue, 30 Nov 2021 18:17:03 +0000 (18:17 +0000)]
Align ssl_kex_derive_ecdhe_ecp() with ssl_kex_derive_dhe()

sk is commonly used for a STACK_OF(), so call the shared key simply key.

ok jsing

2 years agoisakmpd: convert modp_init() for opaque DH.
tb [Tue, 30 Nov 2021 18:12:44 +0000 (18:12 +0000)]
isakmpd: convert modp_init() for opaque DH.

ok jsing

2 years agowhitespace
tobhe [Tue, 30 Nov 2021 17:47:30 +0000 (17:47 +0000)]
whitespace

2 years agoadd ixl(4)
deraadt [Tue, 30 Nov 2021 17:05:59 +0000 (17:05 +0000)]
add ixl(4)

2 years agos/ECDHE/ECDH/
jsing [Tue, 30 Nov 2021 15:58:08 +0000 (15:58 +0000)]
s/ECDHE/ECDH/

If we can provide an EC key that is used, then it is by definition
non-ephemeral.

ok tb@

2 years agoFix indentation of return in yy_try_NUL_trans().
millert [Tue, 30 Nov 2021 15:50:06 +0000 (15:50 +0000)]
Fix indentation of return in yy_try_NUL_trans().
M4_YY_NOOP_GUTS_VAR is a no-op in most cases but its indentation
remains, leading to double indentation of the return statement.
This fixes "misleading indentation" warnings from clang.  OK tb@

2 years agoRemove unused parameter from ipsp_spd_inp().
bluhm [Tue, 30 Nov 2021 13:17:43 +0000 (13:17 +0000)]
Remove unused parameter from ipsp_spd_inp().
OK mvs@ yasuoka@

2 years agoAdd regress for {d2i,i2d}_{,DSA_,EC_,RSA_}PUBKEY{,_bio}().
jsing [Tue, 30 Nov 2021 07:34:29 +0000 (07:34 +0000)]
Add regress for {d2i,i2d}_{,DSA_,EC_,RSA_}PUBKEY{,_bio}().

2 years agoPrevent select(2) from blocking if registering found pending events.
visa [Tue, 30 Nov 2021 02:58:33 +0000 (02:58 +0000)]
Prevent select(2) from blocking if registering found pending events.

OK mpi@

2 years agoenable uhid/fido
deraadt [Tue, 30 Nov 2021 02:13:55 +0000 (02:13 +0000)]
enable uhid/fido
from Ashton Fagg

2 years agoUse nanosleep(3) instead of select(2) for test run time delay. Use ~10
mvs [Mon, 29 Nov 2021 21:25:09 +0000 (21:25 +0000)]
Use nanosleep(3) instead of select(2) for test run time delay. Use ~10
years interval as operational infinity.

2 years agoCreate socket within current directory instead of /tmp. Also remove it
mvs [Mon, 29 Nov 2021 21:21:26 +0000 (21:21 +0000)]
Create socket within current directory instead of /tmp. Also remove it
with "make clean".

2 years agoCrank the number of rounds of Miller-Rabin from 50 to 64
tb [Mon, 29 Nov 2021 20:13:25 +0000 (20:13 +0000)]
Crank the number of rounds of Miller-Rabin from 50 to 64
for DSA key generation.

From Kurt Roeckx, OpenSSL 74ee3796

ok bcook inoguchi jsing

2 years agoClean up DH_check_pub_key() and ensure that y^q (mod p) == 1.
tb [Mon, 29 Nov 2021 20:02:14 +0000 (20:02 +0000)]
Clean up DH_check_pub_key() and ensure that y^q (mod p) == 1.

This aligns our behavior with OpenSSL 1.1.1 which includes a mitigation
for small subgroup attacks. This did not affect LibreSSL since we do
not support X9.42 style parameter files or RFC 5114.

The meat of this commit is from Matt Caswell, OpenSSL b128abc3

ok inoguchi jsing

2 years agoIncrease number of iterations in Miller-Rabin checks for DH.
tb [Mon, 29 Nov 2021 19:54:07 +0000 (19:54 +0000)]
Increase number of iterations in Miller-Rabin checks for DH.

BN_prime_checks is only to be used for random input. Here, the
input isn't random, so increase the number of checks. According
to https://eprint.iacr.org/2019/032, 64 rounds is suitable.

From Jake Massimo, OpenSSL 1.1.1, af6ce3b4

ok inoguchi jsing

2 years agoSynchronize DH_check() mostly with OpenSSL 1.1.1 with some
tb [Mon, 29 Nov 2021 19:47:47 +0000 (19:47 +0000)]
Synchronize DH_check() mostly with OpenSSL 1.1.1 with some
simplifications and readability tweaks.  This ensures in
particular that dh->q is suitable if present.

Based on work by Stephen Henson and Bernd Edlinger in OpenSSL.

Issues with the current implementation found via regression
tests in py-cryptography.

ok inoguchi jsing

2 years agoProvide a version of DH_check_params() for internal use.
tb [Mon, 29 Nov 2021 19:41:02 +0000 (19:41 +0000)]
Provide a version of DH_check_params() for internal use.

Based on the version in OpenSSL 1.1.1l with minor tweaks.

ok inoguchi jsing

2 years agoProvide a number of flags for DH_check and DH_check_pubkey
tb [Mon, 29 Nov 2021 19:34:51 +0000 (19:34 +0000)]
Provide a number of flags for DH_check and DH_check_pubkey
that will be used in subsequent commits.

ok inoguchi jsing

2 years agoThe network stack currently uses IPL_SOFTNET. Consistently initialize
bluhm [Mon, 29 Nov 2021 19:19:00 +0000 (19:19 +0000)]
The network stack currently uses IPL_SOFTNET.  Consistently initialize
the TDB sadb mutex with that.  The old IPL_NET was chosen by accident.
OK mpi@

2 years agotcpdump: convert print-ipsec to a EVP_CIPHER_CTX on the heap.
tb [Mon, 29 Nov 2021 18:50:16 +0000 (18:50 +0000)]
tcpdump: convert print-ipsec to a EVP_CIPHER_CTX on the heap.

Fix and add some error checking while there.

ok deraadt

2 years agoFirst pass of converting ssl_kex.c to opaque DH.
tb [Mon, 29 Nov 2021 18:48:22 +0000 (18:48 +0000)]
First pass of converting ssl_kex.c to opaque DH.

Assign the result of BN_dup() and BN_bn2bin() to local BIGNUMs, then
set the factors and pubkey on the dh using DH_set0_{pqg,key}().

A second pass will be done during the upcoming bump.

ok jsing

2 years agoHide BIO_s_file_internal() from internal view.
tb [Mon, 29 Nov 2021 18:37:34 +0000 (18:37 +0000)]
Hide BIO_s_file_internal() from internal view.

ok jsing