summaryrefslogtreecommitdiff
path: root/etc
AgeCommit message (Collapse)Author
2017-12-03Disallow the _pbuild user from making TCP/UDP connections in the defaultStuart Henderson
PF ruleset. This is not a complete block on _pbuild being able to communicate (e.g. non-TCP/UDP protocols don't have a PCB with userid, so PF can't restrict in those cases) but avoids some cases, and in particular makes it more obvious when a port does things like download extra distfiles or dependencies as part of the build process. Slight tweak from a diff by espie@.
2017-11-29Import updated moduli.Darren Tucker
2017-11-29Document NAT and DNS forwarding rules for vmd(8)Mike Larkin
discussed at length with benno, beck, deraadt, and florian
2017-11-27Remove deprecated agreement url.Florian Obser
"nice" deraadt@ OK benno
2017-11-15Update agreement URL; pointed out by sthen.Florian Obser
OK benno, sthen
2017-11-14syncChristian Weisgerber
2017-11-14Remove /dev/arandom symlink. Nothing in base, xenocara, or ports usesChristian Weisgerber
/dev/arandom any longer. ok deraadt@
2017-11-12Remove HN_DIR variable and expand it in the only place it was used. ItTheo Buehler
currently serves no purpose. ok rpe, agreement from deraadt and halex
2017-11-11update switch handling in vmd(8). vmd now gets switch information (rdomain,Mike Larkin
etc) from underlying switch interface instead of handling this on its own. Diff from carlos cardenas, Thanks! ok reyk@
2017-11-09kill trailing whitespace introduced in previous commitTheo Buehler
2017-11-06Use a variable for /usr/share/relinkRobert Peichaer
OK tb@
2017-11-05Remove the ':' at the beginning of ksh.kshrc.Robert Peichaer
prodded by Raf Czlonka OK tb@
2017-11-05Consolidate lib.so.*.a, ld.so.a and the kernel relink kit intoRobert Peichaer
one location under /usr/share/relink. Be more specific in src/etc/rc reorder_libs() what filesystems need r/w remount and ensure that their mount state is restored. Idea and positive feedback from deraadt@ OK aja@ tb@
2017-11-02syncMartin Pieuchot
2017-11-02Switch DEC 3000 (TURBOchannel) alpha serial code to MI z8530 code.Martin Pieuchot
ttyB* minor numbers change; be sure to rerun MAKEDEV if you do not upgrade with bsd.rd Adapted from NetBSD by miod@
2017-11-02Replace ps | grep with pgrep and use && instead of if-then-fi.Theo Buehler
From Raf Czlonka. ok halex
2017-10-25Partially revert rev 1.457 of /etc/rc. The pipe introduced inAlexander Bluhm
sysctl_conf() spawns a subshell. This prevents that the new process limits affect the daemons started during boot. OK rpe@ halex@
2017-10-16Remove stray, pointless and potentially confusing line.Kenneth R Westerback
2017-10-16syncChristian Weisgerber
2017-10-16Make it explicit that there is only one type of random device:Christian Weisgerber
Create only /dev/urandom as device. Create /dev/random and /dev/arandom as symlinks. Drop /dev/srandom, which has been unused for a long time. /dev/arandom will go away at a later point. Discussed with guenther@, ok deraadt@
2017-10-12The testprogram for ld.so reordering is executed in tmpdir.Robert Peichaer
Move tmpdir for reordering library from /tmp to /usr/lib. This allows to have /tmp mounted noexec. prompted by reports on misc@ OK deraadt@ tj@ tb@
2017-10-10Move comment line and spacing.Robert Peichaer
2017-10-08Make cacheflush(3) and get_fpc_csr(3) manual pages available on octeon.Visa Hankala
OK deraadt@
2017-09-29SPI values 0-255 are reserved, so change the example to use a valid one.Peter Hessler
fixes parsing of the example configuration OK benno@
2017-09-22fix the example neighbor configurationsPeter Hessler
noticed by Alex Holst OK henning@
2017-09-01Remove the miniroot for the OMAP3 BeagleBoards. Ethernet is on USB andJonathan Gray
USB isn't supported. The installer turns out to have been broken on BeagleBoard for over a year and no one noticed. The existing support for OMAP3 in the kernel remains though it isn't clear if anyone has tried it after the fdt changes went in. ok patrick@ tom@ kettenis@ matthieu@
2017-08-29Based on previous work from deraadt, add relinking of ld.so toRobert Peichaer
reorder_libs() resulting in a unique ld.so on every system start. Idea from and OK deraadt@ OK tb@
2017-08-28Display that we are running the upgrade scripts when they exist. On slowishAntoine Jacoutot
machines, running sysmerge(8) can take a little while so don't let people wonder about why the output seems stuck. ok sthen@ tb@ rpe@
2017-08-25Sync emacs package versionJeremie Courreges-Anglas
(again...)
2017-08-25add new firmware keyStuart Henderson
2017-08-22add 6.3 packages keyChristian Weisgerber
2017-08-21Move the kernel relinking code from /etc/rc into a seperate scriptRobert Peichaer
/usr/libexec/reorder_kernel. Requested by ajacoutot@ to be able to relink the kernel from within syspatch(8). OK deraadt@ tb@
2017-08-21add basedir of the kernel link-kitRobert Peichaer
requested by ajacoutot@ OK tb@
2017-08-215.9 pubkeys no longer neededTheo de Raadt
2017-08-21add 6.3 base keyTheo de Raadt
2017-08-20Simplify the code for stopping daemons listed in pkg_scripts inRobert Peichaer
reverse order on shutdown. OK aja@ tb@
2017-08-20crank to 6.2-betaTheo de Raadt
2017-08-16crank memory limitsTheo de Raadt
2017-08-12Add manpage update for new grouping feature '{from,to} {i,e}bgp'job
OK phessler@
2017-08-05add /usr/X11R6/share/libdrm for recent libdrm versionsJonathan Gray
2017-07-25Finally remove backwards compat code to support the 'rtsol' keywordRobert Peichaer
in hostname.if(5) OK mpi@ deraadt@ florian@ OK jmc@ from doc perspective
2017-07-21Align ifstart() in netstart and install.sub.Robert Peichaer
- in netstart, rename _file to _hn referencing hostname.if files - in install.sub switch ifstart() to be used with _if instead of _hn as parameter ok krw@ tb@
2017-07-21syncMike Belopuhov
2017-07-21Multiple virtualization layers may be available at the same timeMike Belopuhov
reachable through different pvbus device nodes. Suggestion and OK deraadt, OK reyk
2017-07-18Use a bit better idiom to get most recent version of the libraryVadim Zhukov
being reordered. okay tb@ deraadt@
2017-07-18Use numerical sysctl output to check for nfs mounts.Robert Peichaer
OK tb@
2017-07-17Tweak previous.Robert Peichaer
2017-07-17Use a more compact way to compose the initial pf ruleset.Robert Peichaer
Diff from Klemens Nanni OK tb@ zhuk@
2017-07-17Now that choosing the library versions is much faster, we can doTheo Buehler
it after remounting the filesystem containing /usr/lib as rw: the former is pointless if the latter should happen to fail. From Klemens Nanni ok rpe
2017-07-17Optimize and simplify the selection of the latest library version inTheo Buehler
reorder_libs(). From Klemens Nanni with input from rpe. ok rpe, zhuk