summaryrefslogtreecommitdiff
path: root/usr.sbin
AgeCommit message (Collapse)Author
2017-11-27Add a DPRINTF() in relay_error() that helped me out way too many times.Claudio Jeker
2017-11-27Use file descriptor passing to load certificates into the relays. EspeciallyClaudio Jeker
the ca file (having all the trusted certs in them) can be so big that loading via imsg fails. OK beck@
2017-11-27Do not rip out the output buffer of the bufferevent. Instead just use anClaudio Jeker
initial bufferevent_write_buffer() to write out the queued up HTTP request. OK benno@
2017-11-27lenght->length, mostly in commentsStuart Henderson
2017-11-27rfc 7230 mandates that a "204 No Content" http status must not come with aSebastian Benoit
Content-Lenght Header. Of course some servers still so it and send Content-Lenght: 0. Adjust accordingly. ok claudio@
2017-11-27Show correct command execution status by checking against updateSunil Nimmagadda
operation return value. Issue reported by 'Zelest' (Jesper Wallin). Suggestions and ok eric@ gilles@.
2017-11-27relay_tls_connected() is playing with the inner bowels of bufferevents.Claudio Jeker
Be more careful and remove the events before resetting them to the new backends. This is also what some of the bufferevent functions are doing. OK benno@
2017-11-27Simplify relay_close_http(), make relay_httpdesc_free() accept and ignoreClaudio Jeker
a NULL pointer argument (like free()). Also switch a !size to size == 0. OK benno@
2017-11-27typo in comments "optionel" -> "optional"Mike Larkin
2017-11-27Deprecate agreement url config option and get the information from theFlorian Obser
directory call. This way we don't need to update the acme-client.conf file every time it changes. Still parse the option, ignore and warn about it for a release. Sysmerge should be able to handle the removal. "nice" deraadt@ OK benno
2017-11-24Revert my change to ignore EIO errors when writing to log files.Alexander Bluhm
Syslogd continued logging messages to a file that had an EIO error. This could slow down the whole system. File system errors may cause huge delays at every access. This prevented debugging the issue. Now syslogd will log a warning and shut down logging to this file until restart or SIGHUP. OK deraadt@ espie@ millert@
2017-11-23simplify imsg handler.Eric Faurot
ok sunil@ gilles@
2017-11-21no need to check the sending process in imsg handlers when there is noEric Faurot
ambiguity: just use a single switch. ok gilles@ sunil@
2017-11-21The call to setegid(2) was replaced with setresgid(2) a while ago.Theo Buehler
Adjust error message accordingly.
2017-11-18merge the masquerade and missing domain header callbacks into one function.Eric Faurot
ok gilles@
2017-11-17Use explicit_bzero to erase secretsJeremie Courreges-Anglas
from Scott Cheloa, ok tb@
2017-11-16Check that http options are only configured in http protocols.Alexander Bluhm
OK benno@
2017-11-15make the maximum size of http headers configurable in the protocol.Sebastian Benoit
ok bluhm@, >8k makes sense claudio@
2017-11-14Inverse logic, issue found by henning@. MPLS VPN is still broken though.Claudio Jeker
2017-11-11reads better as *an* rdomain, i think;Jason McIntyre
2017-11-11update switch handling in vmd(8). vmd now gets switch information (rdomain,Mike Larkin
etc) from underlying switch interface instead of handling this on its own. Diff from carlos cardenas, Thanks! ok reyk@
2017-11-09/usr/share/compile -> /usr/share/relink/kernelAntoine Jacoutot
from semarie I meant to do that at p2k17 but totally forgot...
2017-11-08Since r1.41 the extensions are included in the CSR. Thus ca_request()Patrick Wildt
already sets the extension values and returns. ca_sign() re-uses the information to write out the extension file. Since ca_request() uses strings stored on the stack, on return the pointers to those strings will be unusable. To fix this, strdup() the strings passed ca_setenv() so we can re-use them in another scope. And free() them when we clear the environment in ca_clrenv(). Initial report and diff from Andrei-Marius Radu. ok markus@
2017-11-07Revert previous, it breaks ports/infrastructure/bin/resolve-lib (I think)Antoine Jacoutot
with at least python and ruby. ok naddy@
2017-11-07Add support for client-specific directories (named after the client address)Jeremie Courreges-Anglas
tftpd -i will look up the requested path the directory named after the client's IP address. For read requests, if the file is not found, there's a fall back to its root directory. From Jan Klemkow with input and tweaks from at least jmc@, bluhm@, deraadt@, sthen@, semarie@ and myself. ok bluhm@
2017-11-07typo in previousMike Larkin
2017-11-07comment function vm_checkpermMike Larkin
2017-11-07document how ospfd interacts with carpremi
improvement from jmc@ ok phessler@ jca@ benno@ for previous version ok jmc@
2017-11-07Tweak the man page and warning message, revert the comma.YASUOKA Masahiko
2017-11-06typo, surprised nobody noticed yetMarc Espie
2017-11-05Add minimal DHCP support to vmd's built-in DHCP/BOOTP server.Reyk Floeter
This fixes "local interface" mode with the udhcpc client. udhcpc, a DHCP client that is used by busybox and many embedded Linux distributions, does not support BOOTP which is the predecessor and a valid subset of DHCP. OK mlarkin@, Carlos Cardenas
2017-11-05Mention that "reload" is disabled; ok jmc@Jeremie Courreges-Anglas
2017-11-05Disable config reload, ospf6d just exits on reload with simple setups.Jeremie Courreges-Anglas
And fixing this doesn't appear trivial. Discussed with a bunch at p2k17, ok phessler@ denis@ benno@
2017-11-05Kill dead assignement.Jeremie Courreges-Anglas
2017-11-05Consolidate lib.so.*.a, ld.so.a and the kernel relink kit intoRobert Peichaer
one location under /usr/share/relink. Be more specific in src/etc/rc reorder_libs() what filesystems need r/w remount and ensure that their mount state is restored. Idea and positive feedback from deraadt@ OK aja@ tb@
2017-11-04whitespaceMike Larkin
2017-11-04Remove a debug message that has outlived its usefulness.Mike Larkin
From Carlos Cardenas, who discussed this with reyk@ also. Thanks!
2017-11-03properly cleanup the controller after closing the cmdfh.Marc Espie
don't call exit, since grab_object is only used within a fork and parent does exit. this prevents signal cleanup from fucking up and trying to close the fhs a second time. somewhat long-standing problem, as seen by jeremy@ and I. okay jeremy@
2017-11-02Use emalloc, like in the rest of makefsJeremie Courreges-Anglas
From Michael W. Bombardieri
2017-11-01don't look directly at PKG_CACHE, but ask the state, so that onlyMarc Espie
pkg_add actually looks at the env variable, and it doesn't affect other tools. buglet noticed by Lari Rasku
2017-11-01Extra space in previousJeremie Courreges-Anglas
2017-11-01Make ip-transparent option work by using SO_BINDANY.Florian Obser
OK jca, benno jca also points out that Delan Azabani (delan _AT_ azabani.com) wrote exactly the same diff in 2016. It was OK bluhm but apparently never commited.
2017-11-01Make ip-transparent option work by using SO_BINDANY.Florian Obser
OK jca, benno
2017-10-31Replace usage of WSMUX_{ADD,REMOVE}_DEVICE compat macros.anton
ok deraadt@, mpi@
2017-10-31Add platform-id for EFI.YASUOKA Masahiko
seem fine deraadt
2017-10-31Fix a bug which made the boot entries' order reverse, introduced at 1.8 onYASUOKA Masahiko
NetBSD. seem fine deraadt
2017-10-31Initialize boot_catalog_entry's entry_type properly. This had beenYASUOKA Masahiko
missing but the type was used in cd9660_setup_boot(). seem fine deraadt
2017-10-30Kill <net/slip.h>.Martin Pieuchot
The ioctl(2) it defines is not supported since a long time and most of its defines are already present in tcpdump(8). ok jca@
2017-10-30vmd no longer creates bridges by default. users should create bridges inMike Larkin
/etc/hostname.bridge* files, and specify which bridge to use for a given virtual switch in vm.conf. diff from Carlos Cardenas, thanks
2017-10-29Allow keys to be specified on the command line in list mode, forTodd C. Miller
looking up specific keys. OK phessler@ jmc@