summaryrefslogtreecommitdiff
path: root/etc
AgeCommit message (Collapse)Author
2015-07-19Always source rc.subr to be able to use the rc.conf parsing routineRobert Peichaer
to get the network related vars from rc.conf. This is even necessary if netstart is run from within /etc/rc. Remove test of $INRC which unintentionally evaluated always to true. problem with previous change found by nigel@ OK sthen@ aja@ halex@
2015-07-19remove code from unbound's rc script that generates control keys/certs ifStuart Henderson
control-enable is used, our standard configuration is using unix domain sockets without certs. existing setups with already-created certificates are ok, if somebody needs remote+certs they can generate keys themself. ok florian@
2015-07-19change default unbound config to enable the control socket, without usingStuart Henderson
keys/certificates for auth. ok florian@
2015-07-19Revert 1.148 for now until I can talk to rpe@Antoine Jacoutot
It introduced a regression reported by nigel@
2015-07-19Replace test command with [].Robert Peichaer
OK halex@ krw@
2015-07-19Ensure, that we source rc.subr and parse rc.conf ONLY if we are notRobert Peichaer
inside /etc/rc. With help from and OK halex@, ajacoutot@
2015-07-18Put the opening curley brackets on the same line as the function name.Robert Peichaer
OK krw@ halex@
2015-07-18- remove trailing blanks introduced in previous commitRobert Peichaer
- no space in redirections like </foo or >$bar - few other minor whitespaces OK krw@
2015-07-18Improve commentsRobert Peichaer
- Add comments for functions - Start comments with capital letters - End comments with a full stop - Allow comments to extend up to column 80 OK krw@
2015-07-17Add _dpb, _pbuild, _pfetch users to make it easier for people doing dpbStuart Henderson
multi-user builds. Discussed with espie, ajacoutot, ok deraadt
2015-07-17Add an example for doas(1) logging and drop sudo and chat.Antoine Jacoutot
ok tedu@ rep@
2015-07-17enable exynosJonathan Gray
2015-07-15Drop comments; we already have a fully documented file underAntoine Jacoutot
/etc/examples/ntpd.conf ok deraadt@ benno@ schwarze@
2015-07-15Fix base rc.d scripts after the recent rc.subr change.Antoine Jacoutot
ok halex@
2015-07-15By default, require an exact match of the process name and argument list.Antoine Jacoutot
This allows running several instances of the same rc.d(8) script by just linking it to different name. e.g. ln -s ftpproxy ftpproxy6 echo 'ftpproxy6_flags=-6' >>/etc/rc.conf.local This is likely to break some rc.d scripts in ports. I will try and fix them all in the next few days but I'd appreciate reports if I missed some. ok halex@
2015-07-15Always use the default flags when running !start.Antoine Jacoutot
This is necessary so that rc.d scripts launched with `-f' can be properly stopped, checked and reloaded. ok schwarze@
2015-07-15Merge comments.Antoine Jacoutot
2015-07-07/var/unbound/db/root.key can be stored in plain text actually; that's justAntoine Jacoutot
the public key. prodded by semarie@ ok sthen@
2015-07-07Only store checksums for:Antoine Jacoutot
/var/nsd/etc/nsd.conf (may contain a key) /var/unbound/db/root.key (fix path as well) from Tim van der Molen ok millert@ sthen@
2015-07-03Remove sudoersTodd C. Miller
2015-06-29enable vexpressJonathan Gray
2015-06-28regenJonathan Matthew
2015-06-28add usb devicesJonathan Matthew
2015-06-23fix emacs pkg namesGiovanni Bechis
2015-06-21syncTheo de Raadt
2015-06-215.9 base keyTheo de Raadt
2015-06-19add 5.9 packages keyChristian Weisgerber
2015-06-18I'm afraid it will be a sunday.Miod Vallat
2015-06-18add 5.9 firmware keyStuart Henderson
2015-06-17crank to 5.8-betaTheo de Raadt
2015-06-17Really make daemon_class read-only; it's set to "daemon" of a matchingAntoine Jacoutot
login class.
2015-06-16Typos in comments; Ville ValkonenMiod Vallat
2015-06-13add miniroot to MDEXTJasper Lievisse Adriaanse
2015-06-09miniroot for octeon; tested on edgerouter lite with local usb storageJasper Lievisse Adriaanse
ok jmatthew@ miod@
2015-06-06Allow rtsol keyword in hostname.if(5) with net.inet6.ip6.forwarding=1.Florian Obser
"inet6 autoconf" was working before and rtsol should behave the same. OK phessler
2015-06-02Rename the imx miniroot to nitrogen as it creates "6x_bootscript".Jonathan Gray
Add a miniroot for the CuBox-i which needs u-boot at a particular offset in the sd image to boot. Based on changes made by Patrick Wildt in bitrig.
2015-05-28Remove 1k bit groups. ok deraadt@, markus@Darren Tucker
2015-05-26Create aliases.db from the installed aliases file, so we get the correctChristian Weisgerber
owner and group. Reported by Mark Patruck. ok deraadt@ miod@
2015-05-22Update DH groupsDarren Tucker
2015-05-22Remove 6k and 8k bit moduli fragments since they are now kept inDarren Tucker
usr.bin/ssh/moduli-gen.
2015-05-20Now all the socs use the same va entry point and don't have anyJonathan Gray
conflicting symbols we can combine the configs. Multiple umg files are still required however. The bsd.umg target in the kernel is replaced by targets for bsd.IMX.umg, bsd.OMAP.umg and bsd.SUNXI.umg.
2015-05-19use the same va entry point on all armv7 socsJonathan Gray
Similiar changes were made in bitrig by Patrick Wildt. As part of this change the physical load address for imx and sunxi have changed. Any u-boot settings that include it will need to be modified. imx: 0x10800000 -> 0x10300000 sunxi: 0x40800000 -> 0x40300000 Tested by bmercer, canacar and myself. ok bmercer@
2015-05-18Change spamd to use divert-to instead of rdr-to.Reyk Floeter
divert-to has many advantages over rdr-to for proxies. For example, it is much easier to use, requires less code, does not depend on /dev/pf, works in-band without the asynchronous lookup (DIOCNATLOOK ioctl), saves us from additional port allocations by the rdr/NAT code, and even avoids potential collisions and race conditions that could theoretically happen with the lookup. Heads up: users will have to update their spamd PF rules from rdr-to to divert-to. spamd now also listens to 127.0.0.1 instead of "any" (0.0.0.0) by default which should be fine with most setups but has to be considered for some special configurations. Based on a diff is almost two years old but got delayed several times ... beck@: "now is the time to get it in" :) Tested by many With help from okan@ OK okan@ beck@ millert@
2015-05-18Put ntpd.conf in MUTABLE so it's installed with 0644 mode.Antoine Jacoutot
discussed by deraadt@
2015-05-18enable ntpd by default at install time. We use pools and a reliableTheo de Raadt
constraint to keep them in check. in the worst case of being on a dark net, nothing changes. this is being enabled by default to allow gathering of more operational information from users. and if the operational heuristics in ntpd can be suitable refined, this may stay the default into the future. if not, ntpd will become even more awesome along the way. with reyk rpe
2015-05-18Simplify example constraints URL to reduce load on the server side.Darren Tucker
ok henning@, reyk@
2015-05-04fix numbers for pppx, vscsi and diskmapJonathan Matthew
ok dlg@
2015-05-04Remove comments about default daemon_flags; most are empty, thoseIngo Schwarze
that aren't are redundant because they can be found in the rc.d(8) scripts themselves, and they risk getting out of sync. While here, sort the daemons alphabetically. No functional change. Triggered by a much smaller nameserver-only patch from stephan@. OK ajacoutot@ rpe@ stephan@ and looks good to sthen@.
2015-05-02No more pf_rules ipsec_rules.Antoine Jacoutot
2015-05-02Drop pf_rules and ipsec_rules from rc.conf(5); it shouldn't have been madeAntoine Jacoutot
tweakable: there's no real point and these files support the 'include' option so one can always get its config from whatever path... especially useful when testing a new ruleset. man page inputs from schwarze@ ok halex@ schwarze@ rpe@ deraadt@