openbsd
13 months agoDocument X509v3_{addr,asid}_subset.3 take two (missed cvs add)
tb [Thu, 28 Sep 2023 12:36:36 +0000 (12:36 +0000)]
Document X509v3_{addr,asid}_subset.3 take two (missed cvs add)

First RFC 3779 page without a BUG section. It could have one, but I'm
in a lenient mood right now. Maybe it's just that this is bad but not
quite as bad as EVP.

13 months agoDocument X509v3_{addr,asid}_subset.3
tb [Thu, 28 Sep 2023 12:35:31 +0000 (12:35 +0000)]
Document X509v3_{addr,asid}_subset.3

First RFC 3779 page without a BUG section. It could have one, but I'm
in a lenient mood right now. Maybe it's just that this is bad but not
quite as bad as EVP.

13 months agoAdd more regress coverage for EVP_CIPHER_CTX_iv_length()
tb [Thu, 28 Sep 2023 11:39:35 +0000 (11:39 +0000)]
Add more regress coverage for EVP_CIPHER_CTX_iv_length()

Awesome: the IV length for GCM is only bounded by INT_MAX or malloc limits.

In the absence of an overflowing issue tracker, I'm labeling this
"good first issue", "help wanted" here.

13 months agoCheck that EVP_CIPHER_CTX_iv_length() matches what was set
tb [Thu, 28 Sep 2023 11:35:10 +0000 (11:35 +0000)]
Check that EVP_CIPHER_CTX_iv_length() matches what was set

This really only covers AES-GCM.

From beck

13 months agoFix EVP_CIPHER_CTX_iv_length()
tb [Thu, 28 Sep 2023 11:29:10 +0000 (11:29 +0000)]
Fix EVP_CIPHER_CTX_iv_length()

In today's episode of "curly nonsense from EVP land" we deal with a quite
harmless oversight and a not too bad suboptimal fix, relatively speaking.

At some point EVP_CIPHER_{CCM,GCM}_SET_IVLEN was added. It modified some
object hanging off of EVP_CIPHER. However, EVP_CIPHER_CTX_iv_length() wasn't
taught about this and kept returning the hardcoded default value on the
EVP_CIPHER. Once it transpired that a doc fix isn't going to cut it, this
was fixed. And of course it's easy to fix: you only have to dive through
about three layers of EVP, test and set a flag and handle a control in a
couple methods.

The upstream fix was done poorly and we begrudgingly have to match the API:
the caller is expected to pass a raw pointer next to a 0 length along with
EVP_CIPHER_GET_IV_LENGTH and the control handler goes *(int *)ptr = length
in full YOLO mode. That's never going to be an issue because of course the
caller will always pass a properly aligned pointer backing a sufficient
amount of memory. Yes, unlikely to be a real issue, but it could have been
done with proper semantics and checks without complicating the code. But
why do I even bother to complain? We're used to this.

Of note here is that there was some pushback painting other corners of a
bikeshed until the reviewer gave up with a resigned

  That kind of changes the semantics and is one extra complexity level,
  but [shrug] ok...

Anyway, the reason this matters now after so many years is that rust-openssl
has an assert, notably added in a +758 -84 commit with the awesome message
"Docs" that gets triggered by recent tests added to py-cryptography.

Thanks to Alex Gaynor for reporting this. Let me take the opportunity to
point out that pyca contributed to improve rust-openssl, in particular its
libressl support, quite a bit. That's much appreciated and very noticeable.

Regress coverage to follow in subsequent commits.

Based on OpenSSL PR #9499 and issue #8330.

ok beck jsing

PS: A few macros were kept internal for now to avoid impact on the release
cycle that is about to finish. They will be exposed after release.

13 months agowhitespace
tb [Thu, 28 Sep 2023 08:21:43 +0000 (08:21 +0000)]
whitespace

13 months agoPrep for OpenBGPD 8.2
claudio [Thu, 28 Sep 2023 07:02:50 +0000 (07:02 +0000)]
Prep for OpenBGPD 8.2

13 months agoEnforce NUL termination of the neighbor shutdown reason sent from
claudio [Thu, 28 Sep 2023 07:01:26 +0000 (07:01 +0000)]
Enforce NUL termination of the neighbor shutdown reason sent from
bgpctl before calling strlcpy() with that string.
OK tb@ some long time ago

13 months agoplaform -> platform
jsg [Thu, 28 Sep 2023 03:34:32 +0000 (03:34 +0000)]
plaform -> platform

13 months agodon't mention what language functions are implemented in
jsg [Thu, 28 Sep 2023 01:51:00 +0000 (01:51 +0000)]
don't mention what language functions are implemented in
remove a line relating to the 2BSD libNS
ok schwarze@

13 months agoDon't register firmware already in /var/db/pkg
afresh1 [Thu, 28 Sep 2023 01:18:52 +0000 (01:18 +0000)]
Don't register firmware already in /var/db/pkg

If installing firmware with `make install` from a port, it doesn't register
properly by adding "@option firmware" to the packing list, this means we ignore
that it is installed and reinstall it over and over with the registration
ending up in a tmpdir named directory inside the existing directory in
/var/db/pkg.

Unfortunately I don't know of a good way to automatically clean up from that,
so we just print a message after installing the actual firmware.

Reported by job@
No complaints about the patch on tech@ for several weeks.

13 months agoExit successfully at the end of fw_update
afresh1 [Thu, 28 Sep 2023 00:52:16 +0000 (00:52 +0000)]
Exit successfully at the end of fw_update

Otherwise the exit status depends on whether we kept any firmware.

Reported by Brian Conway <bconway () rcesoftware ! com>
The clean solution suggested by guenther@

13 months agoDownload firmware to LOCALSRC when using filenames
afresh1 [Thu, 28 Sep 2023 00:45:22 +0000 (00:45 +0000)]
Download firmware to LOCALSRC when using filenames

Previously if you did: fw_update otus-firmware-1.0p1.tgz
and that firmware didn't exist in the current directory,
we would download that firmware into the current directory.
Which is not the expected outcome.

13 months agoFull rewrite of lang/ruby port module documentation
jeremy [Wed, 27 Sep 2023 21:46:17 +0000 (21:46 +0000)]
Full rewrite of lang/ruby port module documentation

Restructure so that the most important information is first.
Describe how it modifies bsd.port.mk variables.
Document all public variables set by the module.

Rewrite prompted by feedback from schwarze@
Multiple rounds of review and many fixes from schwarze@
OK schwarze@

13 months agoUse a dynamically-allocated line buffer and resize as needed.
millert [Wed, 27 Sep 2023 21:06:33 +0000 (21:06 +0000)]
Use a dynamically-allocated line buffer and resize as needed.
Fixes a buffer overflow for lines over 2048 bytes.
Problem reported by Crystal Kolipe.  OK deraadt@

13 months agofix punctuation and formatting in AUTHORS;
jmc [Wed, 27 Sep 2023 20:30:19 +0000 (20:30 +0000)]
fix punctuation and formatting in AUTHORS;

13 months agoWe're not interested in the core dump, so prevent it. Also catch
otto [Wed, 27 Sep 2023 17:06:42 +0000 (17:06 +0000)]
We're not interested in the core dump, so prevent it.  Also catch
SIGABRT, to avoid the "Abort trap" message, which confuses me sometimes
until I realize it's the purpose of this test to abort.

13 months agodisable POOL_DEBUG for release
deraadt [Wed, 27 Sep 2023 15:18:31 +0000 (15:18 +0000)]
disable POOL_DEBUG for release

13 months agodocument the obvious
espie [Wed, 27 Sep 2023 12:24:22 +0000 (12:24 +0000)]
document the obvious

13 months agoRFC 3779: stop pretending we support AFIs other than IPv4 and IPv6
tb [Wed, 27 Sep 2023 11:29:22 +0000 (11:29 +0000)]
RFC 3779: stop pretending we support AFIs other than IPv4 and IPv6

This code is a complete bug fest and using it with any other AFI is
downright dangerous. Such don't arise in this context in practice.

ok claudio jsing

13 months agoMatch GRACEFUL_SHUTDOWN only from ebgp sessions as specified by
claudio [Wed, 27 Sep 2023 10:49:21 +0000 (10:49 +0000)]
Match GRACEFUL_SHUTDOWN only from ebgp sessions as specified by
RFC8326 Section 4.1.
OK sthen@ phessler@ job@

13 months agoVarious small tweaks in the RFC 3779 docs
tb [Wed, 27 Sep 2023 08:46:46 +0000 (08:46 +0000)]
Various small tweaks in the RFC 3779 docs

Mention a few more bugs and unify manpage descriptions

13 months agoextent USE_LLD to Yes/No/ports values.
semarie [Wed, 27 Sep 2023 08:20:50 +0000 (08:20 +0000)]
extent USE_LLD to Yes/No/ports values.

'ports' permits to force the use of ld.lld from lang/clang module.

ok landry@

13 months agosync
phessler [Wed, 27 Sep 2023 07:52:48 +0000 (07:52 +0000)]
sync

13 months agoadd a manpage for the qcrng(4) driver
phessler [Wed, 27 Sep 2023 07:50:46 +0000 (07:50 +0000)]
add a manpage for the qcrng(4) driver

reminded by pamela@

13 months agoCope with progname now being present in vmd errors messages.
anton [Wed, 27 Sep 2023 05:18:40 +0000 (05:18 +0000)]
Cope with progname now being present in vmd errors messages.

13 months agosync
tb [Wed, 27 Sep 2023 04:54:49 +0000 (04:54 +0000)]
sync

13 months agosync
deraadt [Wed, 27 Sep 2023 02:13:18 +0000 (02:13 +0000)]
sync

13 months agoFix reference to x509v3.cnf(5) bis
tb [Tue, 26 Sep 2023 21:18:01 +0000 (21:18 +0000)]
Fix reference to x509v3.cnf(5) bis

13 months agoFix reference to x509v3.cnf(5)
tb [Tue, 26 Sep 2023 21:17:03 +0000 (21:17 +0000)]
Fix reference to x509v3.cnf(5)

13 months agosync
tb [Tue, 26 Sep 2023 20:44:16 +0000 (20:44 +0000)]
sync

13 months agoDocument X509v3_{addr,asid}_inherits(3)
tb [Tue, 26 Sep 2023 20:42:45 +0000 (20:42 +0000)]
Document X509v3_{addr,asid}_inherits(3)

Also note another bug in X509v3_asid_{canonize,is_canonical}(3).

13 months agoUse existing `audio_lock' mutex(9) to make `midi{read,write}_filtops' MP
mvs [Tue, 26 Sep 2023 19:55:24 +0000 (19:55 +0000)]
Use existing `audio_lock' mutex(9) to make `midi{read,write}_filtops' MP
safe. knote_locked(9) will not grab kernel lock, so call it directly from
interrupt handlers instead of scheduling software interrupts.

feedback and ok ratchov

13 months agosync
tb [Tue, 26 Sep 2023 18:36:33 +0000 (18:36 +0000)]
sync

13 months agoDocument X509v3_addr_get_{afi,range}(3)
tb [Tue, 26 Sep 2023 18:35:34 +0000 (18:35 +0000)]
Document X509v3_addr_get_{afi,range}(3)

13 months agosync
tb [Tue, 26 Sep 2023 15:39:06 +0000 (15:39 +0000)]
sync

13 months agoDocument the guts of RFC 3779 IPAddrBlocks
tb [Tue, 26 Sep 2023 15:34:23 +0000 (15:34 +0000)]
Document the guts of RFC 3779 IPAddrBlocks

Let's just say there's room for improvement...

13 months agoHave wg(4) copy the priority from the inner packet to the outer encrypted
sthen [Tue, 26 Sep 2023 15:16:44 +0000 (15:16 +0000)]
Have wg(4) copy the priority from the inner packet to the outer encrypted
packet, so that higher priority packets are picked from hfsc queues for
earlier transmission.

(Does not copy ToS bits from inner to outer packet headers sent on the
wire, which some may regard as secret).

tested by Andrew Lemin, ok dlg@

13 months agowe are heading out of -beta
deraadt [Tue, 26 Sep 2023 13:27:32 +0000 (13:27 +0000)]
we are heading out of -beta

13 months agoMissing variable name in prototype
tb [Tue, 26 Sep 2023 13:02:47 +0000 (13:02 +0000)]
Missing variable name in prototype

13 months agoFix section title of X.690 reference (missing article)
tb [Tue, 26 Sep 2023 09:36:22 +0000 (09:36 +0000)]
Fix section title of X.690 reference (missing article)

13 months agoDocument some barely usable parts of the ASIdentifiers API.
tb [Tue, 26 Sep 2023 08:56:18 +0000 (08:56 +0000)]
Document some barely usable parts of the ASIdentifiers API.

Someone clearly didn't actually use much of the code they wrote and exposed
and therefore didn't think it through properly.

13 months agoUse shared netlock to protect ifnet data within vmt_tclo_broadcastip().
mvs [Tue, 26 Sep 2023 08:30:13 +0000 (08:30 +0000)]
Use shared netlock to protect ifnet data within vmt_tclo_broadcastip().
Execute vmt_tclo_tick() timeout handler in process context to allow
context switch within vmt_tclo_broadcastip().

ok yasuoka

13 months agoUpdate APNIC's TA cert.
tb [Tue, 26 Sep 2023 06:49:30 +0000 (06:49 +0000)]
Update APNIC's TA cert.

The old one expired last night. noted by anton

13 months agovmd(8): disambiguate log messages per vm and device.
dv [Tue, 26 Sep 2023 01:53:54 +0000 (01:53 +0000)]
vmd(8): disambiguate log messages per vm and device.

The logging output from vmd(8) often specifies the function performing
the logging, but leaves which vm or vm device to guesswork and
reading tea leaves.

Change the logging formatting to prefix with information about the
specific vm and potentially the device subprocess. Most of this
logging is behind the "verbose" mode, but for warnings this will
clarify which vm or device logged the warning.

The format of vm/<name>/<device><index> is chosen to be concise and
less ugly than other approaches. This adjusts the process naming
for devices to match, dropping the use of brackets.

In the process of this change, updating log settings dynamically
via vmctl(8) is fixed by properly broadcasting that information to
the device subprocesses. The "vmm" process also now updates its own
state properly, so settings survive vm reboots.

ok mlarkin@

13 months agovmd(8): fix vm pause deadlock.
dv [Tue, 26 Sep 2023 01:23:02 +0000 (01:23 +0000)]
vmd(8): fix vm pause deadlock.

When vcpu threads pause, they are holding the run mutex lock. If
the event thread is asked to assert an irq on the pic and interrupts
are pending, it will try to take the run mutex lock on the vcpu.
This deadlocks.

Release the lock in the vcpu thread before waiting on the pause
condition variable.

ok mlarkin@

13 months agoImplement support for stream IDs.
kettenis [Mon, 25 Sep 2023 19:23:34 +0000 (19:23 +0000)]
Implement support for stream IDs.

ok tobhe@, patrick@

13 months agoadapt to new dir layout in dtb packages; ok deraadt
sthen [Mon, 25 Sep 2023 16:42:19 +0000 (16:42 +0000)]
adapt to new dir layout in dtb packages; ok deraadt

13 months agodocument Meinberg PZF180PEX; from Maurice Janssen
deraadt [Mon, 25 Sep 2023 15:39:12 +0000 (15:39 +0000)]
document Meinberg PZF180PEX; from Maurice Janssen

13 months agomatch on Meinberg PZF180PEX; from Maurice Janssen
deraadt [Mon, 25 Sep 2023 15:38:46 +0000 (15:38 +0000)]
match on Meinberg PZF180PEX; from Maurice Janssen

13 months agosync
deraadt [Mon, 25 Sep 2023 15:38:11 +0000 (15:38 +0000)]
sync

13 months agoadd Meinberg Funkuhren PZF180PEX; from Maurice Janssen
deraadt [Mon, 25 Sep 2023 15:37:36 +0000 (15:37 +0000)]
add Meinberg Funkuhren PZF180PEX; from Maurice Janssen

13 months agoenable mbg(4) at pci on amd64, from Maurice Janssen
deraadt [Mon, 25 Sep 2023 15:36:35 +0000 (15:36 +0000)]
enable mbg(4) at pci on amd64, from Maurice Janssen

13 months agorpki-client: mechanical rename of some variables
tb [Mon, 25 Sep 2023 15:33:08 +0000 (15:33 +0000)]
rpki-client: mechanical rename of some variables

The previous commit used suboptimal variable names for ease of review.
Fix this up now.

ok claudio

13 months agorpki-client: Refactor sbgp_assysnum() and sbgp_addrblk()
tb [Mon, 25 Sep 2023 14:56:20 +0000 (14:56 +0000)]
rpki-client: Refactor sbgp_assysnum() and sbgp_addrblk()

An upcoming diff requires the ability to convert ASIdentifiers and
IpAddrBlocks into rpki-client's internal structures.  Accordingly,
split already existing code into dedicated parsing functions . The
original functions now only extract the extension-specific data from
the X509_EXTENSION.

input/ok claudio

13 months agosync (zap trailing whitespace, pointed out by jsg)
tb [Mon, 25 Sep 2023 13:09:52 +0000 (13:09 +0000)]
sync (zap trailing whitespace, pointed out by jsg)

13 months agosort
tb [Mon, 25 Sep 2023 12:00:49 +0000 (12:00 +0000)]
sort

13 months agosync
tb [Mon, 25 Sep 2023 12:00:26 +0000 (12:00 +0000)]
sync

13 months agoNew manual page documenting the usual four ASN.1 functions for both
tb [Mon, 25 Sep 2023 11:59:10 +0000 (11:59 +0000)]
New manual page documenting the usual four ASN.1 functions for both
ASRange and ASIdOrRange

13 months agotweak wording and fix a typo
tb [Mon, 25 Sep 2023 11:12:08 +0000 (11:12 +0000)]
tweak wording and fix a typo

13 months agoAdjust regress for *_parse change
tb [Mon, 25 Sep 2023 11:09:30 +0000 (11:09 +0000)]
Adjust regress for *_parse change

13 months agoPass the talid to various parse functions
tb [Mon, 25 Sep 2023 11:08:45 +0000 (11:08 +0000)]
Pass the talid to various parse functions

This will be needed by an upcoming feature where we will need to know
what trust anchor a given cert chains to. This doesn't change anything
except the size of the diff.

ok claudio job

13 months agoTiny tweaks: missing article, capitalize a word and change an Xr
tb [Mon, 25 Sep 2023 10:34:44 +0000 (10:34 +0000)]
Tiny tweaks: missing article, capitalize a word and change an Xr

13 months agoIntroduce ip_addr_range_print() to avoid code repetition
job [Mon, 25 Sep 2023 08:48:14 +0000 (08:48 +0000)]
Introduce ip_addr_range_print() to avoid code repetition

OK tb@

13 months agoDocument the RFC 3779 extensions as supported
tb [Mon, 25 Sep 2023 07:47:52 +0000 (07:47 +0000)]
Document the RFC 3779 extensions as supported

13 months agoBetter document how REGRESS_FAIL_EARLY and REGRESS_LOG work together.
claudio [Mon, 25 Sep 2023 05:43:22 +0000 (05:43 +0000)]
Better document how REGRESS_FAIL_EARLY and REGRESS_LOG work together.
OK tb@

13 months agodrm/amdgpu: fix amdgpu_cs_p1_user_fence
jsg [Mon, 25 Sep 2023 03:19:38 +0000 (03:19 +0000)]
drm/amdgpu: fix amdgpu_cs_p1_user_fence

From Christian Koenig
4c6bb91581796d34466d85bc06c9393d27f83101 in linux-6.1.y/6.1.55
35588314e963938dfdcdb792c9170108399377d6 in mainline linux

13 months agodrm/amd/display: fix the white screen issue when >= 64GB DRAM
jsg [Mon, 25 Sep 2023 03:16:49 +0000 (03:16 +0000)]
drm/amd/display: fix the white screen issue when >= 64GB DRAM

From Yifan Zhang
4422080e777e3fa740e2920fe4de53cfad7fcef2 in linux-6.1.y/6.1.55
ef064187a9709393a981a56cce1e31880fd97107 in mainline linux

13 months agoRevert "drm/amd: Disable S/G for APUs when 64GB or more host memory"
jsg [Mon, 25 Sep 2023 03:13:45 +0000 (03:13 +0000)]
Revert "drm/amd: Disable S/G for APUs when 64GB or more host memory"

From Hamza Mahfooz
216eae7d7dea5fdd854d7decb44fcf3b719548a0 in linux-6.1.y/6.1.55
169ed4ece8373f02f10642eae5240e3d1ef5c038 in mainline linux

13 months agodrm/amd/display: Blocking invalid 420 modes on HDMI TMDS for DCN314
jsg [Mon, 25 Sep 2023 03:09:43 +0000 (03:09 +0000)]
drm/amd/display: Blocking invalid 420 modes on HDMI TMDS for DCN314

From Leo Chen
a101b1bdd24acf648a55b86d8b429b76e1bd202b in linux-6.1.y/6.1.55
4c6107a653ccf361cb1b6ba35d558a1a5e6e57ac in mainline linux

13 months agodrm/amd/display: Blocking invalid 420 modes on HDMI TMDS for DCN31
jsg [Mon, 25 Sep 2023 03:08:12 +0000 (03:08 +0000)]
drm/amd/display: Blocking invalid 420 modes on HDMI TMDS for DCN31

From Leo Chen
2c0f5b6972ebfd6224065fd3c59d04f85a8af795 in linux-6.1.y/6.1.55
026a71babf48efb6b9884a3a66fa31aec9e1ea54 in mainline linux

13 months agodrm/amd/display: Use DTBCLK as refclk instead of DPREFCLK
jsg [Mon, 25 Sep 2023 03:06:20 +0000 (03:06 +0000)]
drm/amd/display: Use DTBCLK as refclk instead of DPREFCLK

From Austin Zheng
506d2ee72af2ffc4173537eb001d7d4d57781ec7 in linux-6.1.y/6.1.55
4a30cc2bd281fa176a68b5305cd3695d636152ad in mainline linux

13 months agodrm/amd/display: Fix underflow issue on 175hz timing
jsg [Mon, 25 Sep 2023 03:04:40 +0000 (03:04 +0000)]
drm/amd/display: Fix underflow issue on 175hz timing

From Leo Ma
2ec715bf881696b23caa06953c8c9309c2ce5224 in linux-6.1.y/6.1.55
735688eb905db529efea0c78466fccc1461c3fde in mainline linux

13 months agodrm/edid: Add quirk for OSVR HDK 2.0
jsg [Mon, 25 Sep 2023 03:03:01 +0000 (03:03 +0000)]
drm/edid: Add quirk for OSVR HDK 2.0

From Ralph Campbell
766cc11e854eae64d1bb35a3d34d091f5b85afa9 in linux-6.1.y/6.1.55
98d4cb705bc00afd4a9a71cc1e84f7111682639a in mainline linux

13 months agosync
tb [Mon, 25 Sep 2023 01:17:36 +0000 (01:17 +0000)]
sync

13 months agoAdd initial documentation for the RFC 3779 API
tb [Mon, 25 Sep 2023 01:14:34 +0000 (01:14 +0000)]
Add initial documentation for the RFC 3779 API

This documents the part of the API that allows building the two
extensions. It is all very complicated and the bug density is
quite high. Surely there's lots of room for improvement, but
I've been sitting way too long on versions of these. I'll never
finish. Let's fix and improve in tree.

13 months agoddb(4): clockintr: print cl_arg address when displaying a clockintr
cheloha [Mon, 25 Sep 2023 00:29:31 +0000 (00:29 +0000)]
ddb(4): clockintr: print cl_arg address when displaying a clockintr

13 months agoDrop PTE check in pmap_fault_fixup(). Since pmap_enter() doesn't
jca [Sun, 24 Sep 2023 18:49:29 +0000 (18:49 +0000)]
Drop PTE check in pmap_fault_fixup().  Since pmap_enter() doesn't
add PTE's for pages that haven't been accessed yet, the check would
skip the fixup on such pages and force us to go through uvm_fault()
just for the sake of MOD/REF bit emulation.  Since we already check
the PTE descriptor, dropping the check should be safe.  Doing so
gives us a nice 10% performance gain when building a kernel.

Original commit for arch/arm64/arm64/pmap.c:
date: 2021/05/16 17:41:30;  author: kettenis;  state: Exp;  lines: +1 -8;  commitid: yBzyZzIKRLyAkuDY;

ok drahn@ kettenis@

13 months agosync
deraadt [Sun, 24 Sep 2023 15:53:40 +0000 (15:53 +0000)]
sync

13 months agokern_clockintr.c: remove extra newline
cheloha [Sun, 24 Sep 2023 12:27:16 +0000 (12:27 +0000)]
kern_clockintr.c: remove extra newline

13 months agobsd.port.mk.5: GC the misp64 *pic.a fragment handling documentation
op [Sun, 24 Sep 2023 09:15:43 +0000 (09:15 +0000)]
bsd.port.mk.5: GC the misp64 *pic.a fragment handling documentation

More than ten years ago, bsd.lib.mk stopped creating lib*_pic.a files
and the corresponding PFRAG.no_mips64 were removed from the ports tree.
Last year the -Dno_mips64 handling in bsd.port.mk was GC'd too, but the
note in the bsd.port.mk manpage was left.

ok espie@

13 months agoMake REGRESS_LOG more useful again
tb [Sun, 24 Sep 2023 08:28:20 +0000 (08:28 +0000)]
Make REGRESS_LOG more useful again

Enabling REGRESS_FAIL_EARLY made REGRESS_LOG error out at the first error,
which is pointless. So default to no if REGRESS_LOG is set unless the user
explicitly enabled it.

Requested by claudio
ok bluhm

13 months agoREGRESS_FAIL_EARLY defaults to yes now. So no need to overload the
claudio [Sun, 24 Sep 2023 08:14:13 +0000 (08:14 +0000)]
REGRESS_FAIL_EARLY defaults to yes now. So no need to overload the
value here anymore.
OK tb@ bluhm@

13 months agoBreak two ridiculously long lines in ec_pub_cmp() and ec_cmp_parameters()
tb [Sun, 24 Sep 2023 08:08:54 +0000 (08:08 +0000)]
Break two ridiculously long lines in ec_pub_cmp() and ec_cmp_parameters()

13 months agoRefactor eckey_{param2type,type2param}()
tb [Sun, 24 Sep 2023 07:58:31 +0000 (07:58 +0000)]
Refactor eckey_{param2type,type2param}()

EC key parameters can be determined by an OID or they can be explicitly
encoded. The confusingly named eckey_{param2type,type2param}() decode a
new EC key from either form of parameters, or they encode a given key's
parameters in the proper way. Signature and semantics are all over the
place. It also features an inlined version of EC_KEY_new_by_curve_name().
This commit brings some order into this mess.

Parameters are given by a pair (ptype, pval), where the ptype is either
V_ASN1_OBJECT for OID encoding or V_ASN1_SEQUENCE for explicit encoding.
Accordingly, the void pointer pval is an ASN1_OBJECT or an ASN1_STRING.
These pairs are abstracted away in the X509_ALGOR object.

The library decides whether a given EC key uses OID or explicit parameter
encoding using the asn1_flag on the EC key's internal EC_GROUP, i.e., the
object representing its curve. If this flag is set, the OID is determined
by the nid returned by EC_GROUP_get_curve_name().

Add 'mutually inverse' pairs of functions eckey_{to,from}_params() which
wrap eckey_{to,from}_object() and eckey_{to,from}_explicit_params(). This
way the EC ameth pub and priv key de/encoding functions can transparently
translate from/to an X509_ALGOR object.

Of course, this is just an intermediate step and if you look closely you
notice const weirdness (due to the fact that the carefully planned and
executed const rampage missed the ECParameters API) and all sorts of other
things that need to be fixed. Who would bat an eye lid? It wouldn't be
visible amid all the twitching anyway.

ok jsing

13 months agoopenssl-ruby tests: remove fallback to ruby31
tb [Sun, 24 Sep 2023 07:01:40 +0000 (07:01 +0000)]
openssl-ruby tests: remove fallback to ruby31

13 months agoStrip realm part for bsdauth. This is required and an exmaple usage of
yasuoka [Sun, 24 Sep 2023 06:09:35 +0000 (06:09 +0000)]
Strip realm part for bsdauth.  This is required and an exmaple usage of
new radius_standard module.

13 months agoThe stage queue should be freeed when wg_peer is destroyed.
yasuoka [Sun, 24 Sep 2023 05:56:06 +0000 (05:56 +0000)]
The stage queue should be freeed when wg_peer is destroyed.
diff from IIJ.

ok bluhm mvs

13 months agosync
deraadt [Sun, 24 Sep 2023 01:08:24 +0000 (01:08 +0000)]
sync

13 months agostfrng(4)
kettenis [Sat, 23 Sep 2023 19:11:00 +0000 (19:11 +0000)]
stfrng(4)

13 months agoAdd stfrng(4), a driver for the random number generator on the JH7110 SoC.
kettenis [Sat, 23 Sep 2023 18:29:55 +0000 (18:29 +0000)]
Add stfrng(4), a driver for the random number generator on the JH7110 SoC.

ok joel@, jca@

13 months agofully deprecate SITES0...9, I will convert the few (200) ports still using
espie [Sat, 23 Sep 2023 16:08:46 +0000 (16:08 +0000)]
fully deprecate SITES0...9, I will convert the few (200) ports still using
it as soon as my test bulk finishes.

13 months agoexplicitly says that's a script
espie [Sat, 23 Sep 2023 16:06:10 +0000 (16:06 +0000)]
explicitly says that's a script

13 months agosync
deraadt [Sat, 23 Sep 2023 15:38:27 +0000 (15:38 +0000)]
sync

13 months agoUse shared netlock to protect if_list and ifa_list walkthrough and ifnet
mvs [Sat, 23 Sep 2023 13:01:12 +0000 (13:01 +0000)]
Use shared netlock to protect if_list and ifa_list walkthrough and ifnet
data access within kvp_get_ip_info().

ok bluhm

13 months agovmd(8): correct log messages, no functional change.
dv [Sat, 23 Sep 2023 12:31:41 +0000 (12:31 +0000)]
vmd(8): correct log messages, no functional change.

Some log messages incorrectly said "vionet" or "vioblk". Fix based
on the context.

13 months agovmd(8): log vmd's vm id, not vmm's in vcpu_run_loop.
dv [Sat, 23 Sep 2023 12:27:21 +0000 (12:27 +0000)]
vmd(8): log vmd's vm id, not vmm's in vcpu_run_loop.

Some guests cause a warning message during a shutdown. Log the vmd
vm id and not the kernel vmm id as it's next to useless to the end
user. This has annoyed me too much.

13 months agoFix unreliable sys_setsockopt() with consistent use of M_WAIT
jan [Sat, 23 Sep 2023 09:17:21 +0000 (09:17 +0000)]
Fix unreliable sys_setsockopt() with consistent use of M_WAIT

Also remove useless NULL check.

ok bluhm@

13 months agosync
deraadt [Fri, 22 Sep 2023 23:49:47 +0000 (23:49 +0000)]
sync

13 months agoIntroduce `hotplug_mtx' mutex(9) and make `hotplugread_filtops' MP safe.
mvs [Fri, 22 Sep 2023 22:12:32 +0000 (22:12 +0000)]
Introduce `hotplug_mtx' mutex(9) and make `hotplugread_filtops' MP safe.
Use this mutex(9) to protect `evqueue_head', `evqueue_tail' and
`evqueue_count'.

ok bluhm