summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2014-07-11Use uint32_t instead of uint16_t for pr_timeout_sec of structYASUOKA Masahiko
pipex_session_req.
2014-07-11adapt addapt spelling to adapt; request from miodTheo de Raadt
2014-07-11Huge documentation update for libcrypto and libssl, mostly from Matt Caswell,Miod Vallat
Jeff Trawick, Jean-Paul Calderone, Michal Bozon, Jeffrey Walton and Rich Salz, via OpenSSL trunk (with some parts not applying to us, such as SSLv2 support, at least partially removed).
2014-07-11Fix dryrun for remote relayd test.Alexander Bluhm
2014-07-11new dinode format for big-endian conversion routinesMartin Pelikan
2014-07-11make dump support DUIDs for command line arguments and /etc/dumpdates (usingAlexander Hall
the new shiny -U switch) dumpdates part originating from, and discussed with, Maximilian Fillinger seems reasonable to krw@, "get it in" deraadt@
2014-07-11Prevent division by zero on erroneous file systems.Tobias Stoeckmann
ok pelikan@
2014-07-11If the application uses tls_session_secret_cb for session resumption, setMiod Vallat
the CCS_OK flag. From OpenSSL trunk.
2014-07-11Avoid invoking EVP_CIPHER_CTX_cleanup() on uninitialized memory; fromMiod Vallat
Coverity via OpenSSL trunk
2014-07-11Fix a memory leak in BIO_free() which no current BIO can trigger; OpenSSLMiod Vallat
PR #3439 via OpenSSL trunk
2014-07-11Add a time.log file that accumulates timing information about theAlexander Bluhm
executed tests. This allows to micro benchmark relayd. based on a diff from andre@; OK reyk@
2014-07-11add some more register definitionsJasper Lievisse Adriaanse
2014-07-11Prevent infinite loop during configuration file parsing; OpenSSL PR #2985Miod Vallat
via OpenSSL trunk.
2014-07-11Bring in man.cgi(8) to maintain it in our tree together with mandoc.Ingo Schwarze
It will not be enabled in the build nor installed by default. A comment in the Makefile lists the three simple steps needed to build, install, and run it on the two machines worldwide that are going to run it. deraadt@ agrees with having the code in the tree.
2014-07-11Missing bounds check in do_PVK_body(); OpenSSL RT #2277, from OpenSSL trunk,Miod Vallat
but without a memory leak.
2014-07-11__dead for finish()Florian Obser
OK benno@
2014-07-11Silence compiler warning and build with -Wall etc.Florian Obser
OK benno@
2014-07-11OPENSSL_ALGORITHM_DEFINES has been removed from conf.h, no need for it nowTed Unangst
2014-07-11Silence a compiler warning and build with -Wall etc.Florian Obser
While here check that our buffer is big enough. OK benno@
2014-07-11use optval for setsockopt; sync with ping6Florian Obser
OK benno@
2014-07-11use optval for setsockopt consistentlyFlorian Obser
OK benno@
2014-07-11in_proto_cksum_out: zero the icmp cksum before going on so that we do notHenning Brauer
require the caller to do so. lteo needs that for divert soon, and is in line with tcp/udp and the general approach that the rest of the stack should not need to do anything regarding the cksums but setting the "needs it" flag. ok lteo
2014-07-11In RSA_eay_private_encrypt(), correctly return the smaller BN; OpenSSLMiod Vallat
PR #3418 via OpenSSL trunk
2014-07-11In ssl3_get_cert_verify(), allow for larger messages to accomodate keysMiod Vallat
larger than 4096-bit RSA which the most paranoid of us are using; OpenSSL PR #319 via OpenSSL trunk.
2014-07-11fix dacl->size_hi header changeMartin Pelikan
2014-07-11it has been 4888 days since the transient feature to define short macrosTed Unangst
for apps that haven't had time to make the appropriate changes was added. time's up.
2014-07-11split ext2fs_read for the upcoming ext4 extent bits, like FreeBSD has doneMartin Pelikan
ok guenther
2014-07-11move IPv6 prefix adding from workq to taskq; as a happy benefit, weBret Lambert
can delete 2 dozen or so lines that check to see if we've queued up a prefix addition multiple times. ok stsp@
2014-07-11Apparently better fix for OpenSSL PR #3397 (Joyent bug #7704), from OpenSSLMiod Vallat
trunk
2014-07-11Also make these files parsable by pod2man..Bob Beck
ok bcook@
2014-07-11Make this file parsable by pod2man without errors.Bob Beck
ok bcook@
2014-07-11In ASN1_get_object(), reject primitive encodings using the indefinite lengthMiod Vallat
constructed form. OpenSSL PR #2438 via OpenSSL trunk
2014-07-11Use the correct type, found by naddy@.Martin Pieuchot
2014-07-11missing prototypesFlorian Obser
OK tedu@ but don't ask him questions about mrouted, ever
2014-07-11Fix copy for CCM, GCM and XTS.Miod Vallat
Internal pointers in CCM, GCM and XTS contexts should either be NULL or set to point to the appropriate key schedule. This needs to be adjusted when copying contexts. OpenSSL PR #3272 with further fixes, from OpenSSL trunk
2014-07-11reboot(9): Add MI reboot entry functionMasao Uebayashi
Now, for kernel to "reboot" (reboot, halt, or shutdown), MD boot(9) is called in some places. This change introduces a new MI function reboot(9) which is simply a wrapper to call MD boot(9). OK kettenis@ deraadt@
2014-07-11Remove redundant check and wrong fix: fat.c checks already take careTobias Stoeckmann
about cluster chains. If the user didn't want to fix them at that time, he asks for trouble -- and these checks didn't help in all cases either. discussed with and ok krw@
2014-07-11Fix invocation of _OSC. We were passing the capabilities in the wrong DWORDMark Kettenis
and specifyig the wrong DWORD count. Moreover we should not evaluate _PDC if _OSC is present. Might not be perfect yet, but what we had previously was uterrly and totally wrong. ok guenther@
2014-07-11i'm a dumbdumb. fix build.Ted Unangst
2014-07-11determine and use maximum file size instead of magical constantsMartin Pelikan
ok guenther
2014-07-11In asn1_get_length(), tolerate leading zeroes in BER encoding.Miod Vallat
OpenSSL PR #2746 via OpenSSL trunk
2014-07-11In EVP_PBE_alg_add don't use the underlying NID for the cipherMiod Vallat
as it may have a non-standard key size; OpenSSL PR #3206 via OpenSSL trunk.
2014-07-11make the __cxa_call_terminate() proto match the definitionJonathan Gray
From dt71 at gmx.com via FreeBSD Required to build with recent versions of clang.
2014-07-11additional features: no buffer freelists and no heartbleedTed Unangst
2014-07-11no compression is also a feature of libresslTed Unangst
2014-07-11move all the feature settings to a common header.Ted Unangst
probably ok beck jsing miod
2014-07-11Tolerate critical AKID in CRLs; OpenSSL PR #3014 via OpenSSL trunk, andMiod Vallat
also update the comments to reflect what the code now does.
2014-07-11by popular demand, add back hamc-sha1 to server proposal for better compatTed Unangst
with many clients still in use. ok deraadt
2014-07-11tweak previous;Jason McIntyre
ok krw yasuoka
2014-07-11Remove some duplicate directories.Ingo Schwarze
This doesn't change the directory structure being defined. ok deraadt@