summaryrefslogtreecommitdiff
path: root/etc
AgeCommit message (Collapse)Author
2024-11-02add the build user to the build login class now that enough time has passedRobert Nagy
since the addition of that class ok deraadt@
2024-11-02Update APNIC trust anchor constraintsJob Snijders
The IANA IPv6 Global Unicast Address Assignments registry has been updated to reflect the allocation of the following block to APNIC: 2410::/12 APNIC 2024-11-01 the registry is at: https://www.iana.org/assignments/ipv6-unicast-address-assignments/ OK sthen@
2024-10-31track dhcp6leased uuid; OK florianKlemens Nanni
2024-10-29Include cdXX.iso in MDEXT on arm64volker
ok deraadt@
2024-10-22rc: Use the correct path to sshd-auth's relink kitlucas
From Josiah Frentsos <jfrent AT tilde.team> OK tb
2024-10-15grow i386 media a bitTheo de Raadt
2024-10-14sshd-auth also has a relink kitTheo de Raadt
2024-10-12introduce a new build class to be used by the build userRobert Nagy
this class will be required for the upcoming llvm update that requires bumped datasize because of llvm-tblgen ok deraadt@
2024-10-09Get trust anchor via unbound-checkconf(8)Klemens Nanni
This tool knows our default config path and '-o auto-trust-anchor-file' prints the actually set path, if any, regardless of whether exists. Use that to generate it rather than a best-effort grep/hardcoded path. OK sthen
2024-09-30change release dateTheo de Raadt
2024-09-29sync synopsis and usage, sort commands, fix their spacingKlemens Nanni
OK input lucas
2024-09-23Replace `&&' with `if' for proper $? handling; OK lucasKlemens Nanni
iked and isakmpd guard against themselves with "return 0" as rc.subr(8) checks rc_pre()'s return code and aborts daemo start iff non-zero, but that isn't needed if we use ksh properly.
2024-09-23zap redundant "|| return 1"; OK lucasKlemens Nanni
unbound-checkconf(8) itself exits 1 on error already.
2024-09-18back to previous planTheo de Raadt
2024-09-18adjust dateTheo de Raadt
2024-09-03regenAlexander Bluhm
2024-09-03For AMD SEV create /dev/psp.Alexander Bluhm
To call ioctl(2) for the platform security processor (PSP), vmd(8) needs a device file. It is currently linked to the cryptographic co-processor ccp(4). We may split this into a separate psp(4) device. from hshoexer@; input jsg@
2024-08-29draft-ietf-v6ops-rfc3849-update turned into RFC9637, adjust commentClaudio Jeker
2024-08-26calendars are so hardTheo de Raadt
2024-08-21Import regenerated moduli.Darren Tucker
2024-08-16add 7.7 syspatch pubkeyRobert Nagy
2024-08-15add 77-fw pubkeyStuart Henderson
2024-08-12xkbcomp 1.7.0 moved its data files from lib/X11 to share/X11Matthieu Herrb
2024-08-097.7 packages keyChristian Weisgerber
2024-08-07old keys can go awayTheo de Raadt
2024-08-07add 7.7 base keyTheo de Raadt
2024-08-07crank to 7.6-beta, release date is vagueTheo de Raadt
2024-08-04bump datasize for armv7's pbuild user, some software has grown over the yearsPeter Hessler
OK jca@
2024-07-24Add 5f00::/16 segment routing SRv6 SIDs prefix to example bogon listJob Snijders
"In SRv6, SR source nodes initiate packets with a segment identifier in the Destination Address of the IPv6 header, and SR segment endpoint nodes process a local segment present in the Destination Address of an IPv6 header." https://www.iana.org/assignments/iana-ipv6-special-registry/ https://datatracker.ietf.org/doc/html/draft-ietf-6man-sids OK phessler@
2024-07-243fff::/20 has been set aside as an additional documentation prefixJob Snijders
Per https://www.iana.org/assignments/iana-ipv6-special-registry/ and https://datatracker.ietf.org/doc/html/draft-ietf-v6ops-rfc3849-update OK phessler@ claudio@
2024-07-14Add /usr/X11R6/include/va. ok tb@Matthieu Herrb
2024-07-12Recommend veb(4) instead of bridge(4).Florian Obser
bridge(4) has weird interactions with traffic crossing the bridge. Missing change after updating the faq pointed out by ajacoutot OK dv
2024-07-04Revert "Make daily(8) reporting services that are running"Bjorn Ketelaars
Stop daily(8) mails with false information on rogue services. OK florian@, solene@
2024-06-30delete dhclient(8). ipv4 dhcp leases have been acquired by theTheo de Raadt
always-running-in-background dhcpleased(8) for a while, which is activated per-interface with "ifconfig $if autoconf', or "ifconfig $if inet autoconf", or with "inet autoconf" in /etc/hostname.$if dhclient(8) has done execve(3) of ifconfig(8) to handle this for a while, so everyone has moved to the dhcpleased(8) method ok florian
2024-06-04services: add matrix-fed tcp port 8448Landry Breuil
registered at IANA since last august for Matrix Federation Protocol https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=8448 ok djm@ solene@
2024-06-03Track changes to dhcp6leased.confFlorian Obser
looks correct to deraadt
2024-06-03etc bits for dhcp6leasedFlorian Obser
looks correct to deraadt
2024-06-02user, group & /var/db/dhcp6leased for dhcpleased(8)Florian Obser
typo spotted by ccappuc Input & OK deraadt
2024-05-30sem_open() uses /tmp/*.sem files. Exclude them from /tmp daily cleanupStuart Henderson
like is already done for /tmp/*.shm used by libc. ok millert@ tb@, same diff landry@
2024-05-17run the sshd-session link kit alsoTheo de Raadt
2024-05-16Make daily(8) reporting services that are runningSolene Rapenne
but not enabled in rc.conf.local(8) wording by jmc@ ok schwarze@ florian@
2024-05-08- for pwraction, point to acpibtn(4)Jason McIntyre
- for lidaction, document the value 0 - for lidaction, adjust the description to a format similar to that of pwraction ok kettenis deraadt
2024-04-17Sync RPKI Trust Anchor constraints to nro-delegated-statsJob Snijders
Turns out that registry at https://www.iana.org/assignments/as-numbers/as-numbers.xml is an incomplete one, where only 'new' assignments are listed. In the past this registry used to list all ASNs, but the RIRs asked IANA to revert to not being very detailed... There is another source of truth, the 'nro-delegated-stats' file at https://ftp.ripe.net/pub/stats/ripencc/nro-stats/latest/nro-delegated-stats this is updated daily and composed of information from each RIR. Summary of changes: * LACNIC manages a more ASNs than previously known: - allow those ASNs for LACNIC - deny those for RIPE, APNIC, ARIN * AFRINIC's allow list was good (compared to nro-delegated-stats), but the full set of AfriNIC ASNs wasn't denylisted for RIPE, ARIN, APNIC. OK tb@
2024-04-09Remove the "cubie" miniroot. There are far more popular armv7 boardsMark Kettenis
with Allwinner SoCs and the presence of this particular miniroot is making it hard to update U-Boot. ok jsg@
2024-04-02also relink ssh-agentTheo de Raadt
2024-03-31RegenMiod Vallat
2024-03-31Fix /dev/bio major.Miod Vallat
2024-03-30program relinking currently uses a Makefile.relink inside the re-link kit.Theo de Raadt
For sshd (the only relinked program at the moment), this file is created in an extremely nasty way. It'll be better if we have a proper clean install.sh script, which I've built for sshd. But let's first commit the change to /etc/rc which will handle that in the near future. ok djm
2024-03-26Import regenerated moduli.Darren Tucker
2024-03-23Expand ASN range for LACNICJob Snijders
LACNIC received a new block of ASNs from IANA https://mail.lacnic.net/pipermail/lacnog/2024-March/009690.html OK tb@