summaryrefslogtreecommitdiff
path: root/sbin
AgeCommit message (Collapse)Author
2010-08-04fixup keylength for aes-128-cbc in quickmodeTheo de Raadt
from mikeb
2010-08-03fix linecount bug with comments spanning multiple linesHenning Brauer
problem reported with the obvious fix for bgpd by Sebastian Benoit <benoit-lists at fb12.de>, also PR 6432 applied to all the others by yours truly. ok theo isn't it amazing how far this parser (and more) spread?
2010-08-03Group string comparisons and supply more helpful comments. AddKenneth R Westerback
"total sectors" to "boundstart" and "boundend" in the list of fields that are left alone during a RESTORE operation. ok deraadt@
2010-08-03Start with the default label when RESTORE'ing a saved ascii label.Kenneth R Westerback
This ensures that all physical fields are filled in with current values. Lack of values (boundstart, boundend in particular) noted by ray@. ok deraadt@
2010-07-29Print a column with the routing label if "netstat -vr" or "routeAlexander Bluhm
-v show" are called with the -v switch. ok markus@
2010-07-29some error cases returned 01 when they should have been returning -1Jonathan Gray
spotted by Mike Belopuhov.
2010-07-28Change back to the pre rev 1.11 behaviour of not treating unexpectedJonathan Gray
id payloads as errors. Lets interop with strongSwan which sends both IDi and IDr work again.
2010-07-27Align FFS filesystem start and end sectors so the start is on aKenneth R Westerback
bsize boundary and the end fills up the last bsize chunk. Don't change the start sector if it is the first sector of the OpenBSD portion of the disk. Don't attempt to align on SUN_CYLCHECK architectures. They are attempting a different alignment. This is an attempt to ensure that FFS i/o's are aligned for optimal performance on newer disks that lie about their sector size.
2010-07-27Nuke 'sectoffset'. A stub variable no longer used except to supplyKenneth R Westerback
the value 0 to one function call. Use 0 there, eliminate the variable and the pointless verbose verbiage that always displayed the same value. ok deraadt@ matthew@
2010-07-24mount -f doesn't help mfs, but it doesn't hurt, so stop warning about it.Ted Unangst
ok deraadt
2010-07-23Block all signals before sending SIGTERM to all non-system processes.Todd C. Miller
This ensures that we reach the call to reboot(2) without being killed by some other process. OK deraadt@ nicm@
2010-07-22Don't deref a NULL pointer if tap or tag are not specified in theJonathan Gray
config file.
2010-07-20opration -> operationMiod Vallat
2010-07-20two iterators should be u_int; ok jsgTheo de Raadt
2010-07-18get the markup right for [-]commandJason McIntyre
2010-07-16fix up the mini synopses in the subsections; fix from ingoJason McIntyre
2010-07-14handle printing of RTM_DESYNC in route monitor.David Gwynne
reviewed by deraadt@ written by sthen@ who said i should commit it cos he was going to sleep.
2010-07-13Fix (pflow) display in rule printing. Spotted by dhill@, ok henning@Stuart Henderson
2010-07-10Eliminate some unnecessary #include lines.Matthew Dempsky
"sure" marco@
2010-07-09kill redundant docheck() function; ok deraadt@Otto Moerbeek
2010-07-09Avoid crashes by using correct types for block numbers, which can growOtto Moerbeek
large on very large filesystems; reported by Benny Lofgren; partly from FreeBSD. ok deraadt@ beck@ millert@
2010-07-08802.1X is unsupported; from Christopher Zimmermann (tweakedJason McIntyre
version of his diff to tech@ committed);
2010-07-05improve description for -i; as a consequence of recent changes,Igor Sobrado
OpenBSD MBR partition does not span from sector 1 after MBR partition data is re-initialized. written with lot of good advice from deraadt@ and jmc@ ok deraadt@
2010-07-04make ^D handling consistant in fdisk by just bailing out instead ofAlexander Hall
returning a magic value that is not even handled as such by the caller ok krw@
2010-07-03Better non-debug logging messages when a session is established/closed.Reyk Floeter
2010-07-03Fix the naming of interfaces and variables for rdomains and rtablesPhilip Guenthe
and make it possible to bind sockets (including listening sockets!) to rtables and not just rdomains. This changes the name of the system calls, socket option, and ioctl. After building with this you should remove the files /usr/share/man/cat2/[gs]etrdomain.0. Since this removes the existing [gs]etrdomain() system calls, the libc major is bumped. Written by claudio@, criticized^Wcritiqued by me
2010-07-03Fix a couple of problems with printing of anchors, in particular recursiveRyan Thomas McBride
printing, both of inline anchors and when requested explicitly with a '*' in the anchor. - Correct recursive printing of wildcard anchors (recurse into child anchors rather than rules, which don't exist) - Print multi-part anchor paths correctly (pr6065) - Fix comments and prevent users from specifying multi-component names for inline anchors. tested by phessler ok henning
2010-07-03Use our own enum here rather than abusing the PF rule type enums, whichRyan Thomas McBride
will be getting cleaned up soon. ok henning
2010-07-02make lint a bit happierTheo de Raadt
2010-07-02garbage collect an unused function; ok claudioTheo de Raadt
2010-07-02garbage collect an unused variableTheo de Raadt
2010-07-02some data structures were still present when NOKVM was definedTheo de Raadt
2010-07-02add missing header needed by ioctl()Charles Longeau
ok maja@
2010-07-02on error, getuint() will return UINT_MAX. Instead of actually usingAlexander Hall
that value, print an error message and repost the question ok krw@ deraadt@
2010-07-01Learn wsconsctl to handle more than the first keyboard, mouse and display.Mats O Jansson
E.g. if we have a /dev/wskbd1 keyboard1 will show up when doing a -a. wsconsctl keyboard1 will now show you all variables for keyboard1. feedback and ok miod@. -moj
2010-07-01Fix 'pfctl -a anchor -Fa' segfault introduced in r1.298.Stefan Sperling
ok mcbride
2010-07-01Use opendev(3) when handling key disks so that disklabel UIDs areJoel Sing
supported. ok marco@
2010-07-01Remove two useless nul characters. -mojMats O Jansson
2010-07-01add screen types and emulations to things to be shown for displays.Mats O Jansson
ok miod@. -moj
2010-07-01Add support for the tap extension (ikev2 ... tap "enc1") that willReyk Floeter
tell the kernel to send all IPsec traffic for derived SAs to the specified enc(4) interface instead of enc0.
2010-07-01support dumping the new SADB_X_EXT_TAP extension.Reyk Floeter
2010-06-30allow uppercase A-F in the uid inputAlexander Hall
ok krw@ jsing@
2010-06-30Make 'fdisk -i' start the OpenBSD partition on a power of 2 512-byteKenneth R Westerback
block boundary. In most modern (i.e. 'faked' geometry) situations this will start it at (0-based) block[64] rather than block[63] as now. This should help performance on disks which really have 4K sectors but report 512-byte sectors. Power of 2 idea from deraadt@. ok toby@ deraadt@
2010-06-30make the disklabel editor not crash when pressing ^D in the uid promptAlexander Hall
ok krw@
2010-06-29Replace enc(4) with a new implementation as a cloner device. We stillReyk Floeter
create enc0 by default, but it is possible to add additional enc interfaces. This will be used later to allow alternative encs per policy or to have an enc per rdomain when IPsec becomes rdomain-aware. manpage bits ok jmc@ input from henning@ deraadt@ toby@ naddy@ ok henning@ claudio@
2010-06-29add code to lookup the RSA public keys in /etc/iked/pubkeys/ as anReyk Floeter
alternative to X.509 CA verification. this will be needed to support public key authentication like isakmpd does; a few bits are still missing.
2010-06-29Replace the hand-crafted Diffie-Hellman implementation in isakmpd withReyk Floeter
the smaller implementation from iked that is using libcrypto instead. This allows to remove a lot of code (which is always good), get rid of some custom crypto code by using libcrypto, theoretically adds support for many new MODP and EC2N/ECP modes (but it is not configurable yet), and allows to share the dh.c/dh.h code in different codebases (it is identical in isakmpd and iked, but could also be used elsewhere). ok deraadt@
2010-06-29Add missing frees.Reyk Floeter
2010-06-29Fix use after free. Found by regress tests.Charles Longeau
ok henning@ krw@
2010-06-29list kern.rthreads as a knob you can but shouldn't turnTed Unangst