Re: zzz, /dev/wsmouse

2014-07-23 Thread Mike Burns
On 2014-07-23 07.40.00 +0200, Martin Pieuchot wrote:
> On 22/07/14(Tue) 19:37, Mike Burns wrote:
> > On 2014-07-22 10.10.02 +0200, Martin Pieuchot wrote:
> > > > umass0 at uhub2 port 2 configuration 1 interface 0 "SanDisk Cruzer" rev
> > > > 2.00/2.00 addr 6
> > > > umass0: using SCSI over Bulk-Only
> > > > scsibus4 at umass0: 2 targets, initiator 0
> > > > sd2 at scsibus4 targ 1 lun 0:  SCSI0 0/direct
> > > > removable serial.0781553001117562C886
> > > > sd2: 30547MB, 512 bytes/sector, 62562239 sectors
> > > 
> > > In your previous dmesg your touchscreen attaches itself to uhub3, when
> > > you plug a device like this one, does it always attaches to uhub2?  In
> > > other words, does something, somehow, sometimes attach to uhub3?
> > 
> > I have two USB ports (at least, ones I can plug into): one is labeled
> > with a USB symbol and a battery symbol; that one works and shows up as
> > uhub2. The other is labeled with a SS followed by a USB symbol; this one
> > does not work and adds nothing to the dmesg.
> 
> Did you try the BIOS option USB 3.0?

Sorry for forgetting that earlier. With the USB 3.0 option turned off,
when I plug a USB stick into the other port:

OpenBSD 5.6-beta (GENERIC.MP) #1: Wed Jul 23 01:09:44 CEST 2014
m...@bellifortis.my.domain:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 8255762432 (7873MB)
avail mem = 8027205632 (7655MB)
mpath0 at root
scsibus0 at mpath0: 256 targets
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 2.7 @ 0xdae9d000 (71 entries)
bios0: vendor LENOVO version "G6ET93WW (2.53 )" date 02/04/2013
bios0: LENOVO 3444CUU
acpi0 at bios0: rev 2
acpi0: sleep states S0 S3 S4 S5
acpi0: tables DSDT FACP SLIC TCPA SSDT SSDT SSDT HPET APIC MCFG ECDT FPDT ASF! 
UEFI UEFI MSDM SSDT SSDT UEFI SSDT DBG2
acpi0: wakeup devices LID_(S4) SLPB(S3) IGBE(S4) EXP2(S4) XHCI(S3) EHC1(S3) 
EHC2(S3) HDEF(S4)
acpitimer0 at acpi0: 3579545 Hz, 24 bits
acpihpet0 at acpi0: 14318179 Hz
acpimadt0 at acpi0 addr 0xfee0: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1896.03 MHz
cpu0: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu0: 256KB 64b/line 8-way L2 cache
cpu0: smt 0, core 0, package 0
mtrr: Pentium Pro MTRR support, 10 var ranges, 88 fixed ranges
cpu0: apic clock running at 99MHz
cpu0: mwait min=64, max=64, C-substates=0.2.1.1.2, IBE
cpu1 at mainbus0: apid 1 (application processor)
cpu1: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1895.70 MHz
cpu1: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu1: 256KB 64b/line 8-way L2 cache
cpu1: smt 1, core 0, package 0
cpu2 at mainbus0: apid 2 (application processor)
cpu2: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1895.70 MHz
cpu2: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu2: 256KB 64b/line 8-way L2 cache
cpu2: smt 0, core 1, package 0
cpu3 at mainbus0: apid 3 (application processor)
cpu3: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1895.70 MHz
cpu3: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu3: 256KB 64b/line 8-way L2 cache
cpu3: smt 1, core 1, package 0
ioapic0 at mainbus0: apid 2 pa 0xfec0, version 20, 24 pins
acpimcfg0 at acpi0 addr 0xf800, bus 0-63
acpiec0 at acpi0
acpiprt0 at acpi0: bus 0 (PCI0)
acpiprt1 at acpi0: bus -1 (PEG_)
acpiprt2 at acpi0: bus 2 (EXP1)
acpiprt3 at acpi0: bus 3 (EXP2)
acpicpu0 at acpi0: C2, C1, PSS
acpicpu1 at acpi0: C2, C1, PSS
acpicpu2 at acpi0: C2, C1, PSS
acpicpu3 at acpi0: C2, C1, PSS
acpipwrres0 at acpi0: PUBS, resource for XHCI, EHC1, EHC2
acpitz0 at acpi0: critical temperature is 200 degC
acpibtn0 at acpi0: LID_
acpibtn1 at acpi0: SLPB
acpibat0 at acpi0: BAT0 model "45N1071" serial  1475 type LiP oem "SMP"
acpibat1 at acpi0: BAT1 not present
acpiac0 at acpi0: AC unit online
acpithinkpad0 at acpi0
cpu0: Enhanced SpeedStep 1896 MHz: speeds: 2001, 2000, 1900, 1800, 1700, 1600, 
1500, 1400, 1300, 1200, 1100, 1000, 900, 800 MHz
pci0 at mainbus0 bus 0
pchb0 at pci0 dev 0 function 0 "Intel Core 3G Host" rev 0x09
vga1 at pci0 dev 2 function 0 

Re: zzz, /dev/wsmouse

2014-07-23 Thread Martin Pieuchot
On 23/07/14(Wed) 03:07, Mike Burns wrote:
> On 2014-07-23 07.40.00 +0200, Martin Pieuchot wrote:
> > On 22/07/14(Tue) 19:37, Mike Burns wrote:
> > > On 2014-07-22 10.10.02 +0200, Martin Pieuchot wrote:
> > > > > umass0 at uhub2 port 2 configuration 1 interface 0 "SanDisk Cruzer" 
> > > > > rev
> > > > > 2.00/2.00 addr 6
> > > > > umass0: using SCSI over Bulk-Only
> > > > > scsibus4 at umass0: 2 targets, initiator 0
> > > > > sd2 at scsibus4 targ 1 lun 0:  SCSI0 0/direct
> > > > > removable serial.0781553001117562C886
> > > > > sd2: 30547MB, 512 bytes/sector, 62562239 sectors
> > > > 
> > > > In your previous dmesg your touchscreen attaches itself to uhub3, when
> > > > you plug a device like this one, does it always attaches to uhub2?  In
> > > > other words, does something, somehow, sometimes attach to uhub3?
> > > 
> > > I have two USB ports (at least, ones I can plug into): one is labeled
> > > with a USB symbol and a battery symbol; that one works and shows up as
> > > uhub2. The other is labeled with a SS followed by a USB symbol; this one
> > > does not work and adds nothing to the dmesg.
> > 
> > Did you try the BIOS option USB 3.0?
> 
> Sorry for forgetting that earlier. With the USB 3.0 option turned off,
> when I plug a USB stick into the other port:

But more importantly...

> uhidev0 at uhub3 port 3 configuration 1 interface 0 "eGalax Inc. eGalaxTouch 
> EXC7903-66v03_T1" rev 2.00/66.03 addr 3
> uhidev0: iclass 3/1, 7 report ids
> uhid0 at uhidev0 reportid 1: input=5, output=0, feature=0
> uhid1 at uhidev0 reportid 3: input=63, output=63, feature=0
> uhid2 at uhidev0 reportid 5: input=0, output=0, feature=2
> ums0 at uhidev0 reportid 6: 1 button, tip
> wsmouse1 at ums0 mux 0
> ums1 at uhidev0 reportid 7
> ums1: mouse has no X report

...your touchpad is back!

I'll try to dig into the wsmoused issue, please let me know if you have
any other problem.



Re: zzz, /dev/wsmouse

2014-07-23 Thread Mike Burns
On 2014-07-23 09.25.34 +0200, Martin Pieuchot wrote:
> ...your touchpad is back!

Wow! I honestly did not expect that. This is awesome.

It works perfectly before I suspend, but after I resume the touchscreen
is off in the X coordinates (and slightly off in the Y). I am not
running wsmoused. Known bug? dmesg below.

> I'll try to dig into the wsmoused issue, please let me know if you have
> any other problem.

Big thanks to you, Mike Larkin, and everyone else who helped make
suspend/resume more stable.

-Mike


OpenBSD 5.6-beta (GENERIC.MP) #1: Wed Jul 23 01:09:44 CEST 2014
m...@bellifortis.my.domain:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 8255762432 (7873MB)
avail mem = 8027205632 (7655MB)
mpath0 at root
scsibus0 at mpath0: 256 targets
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 2.7 @ 0xdae9d000 (71 entries)
bios0: vendor LENOVO version "G6ET93WW (2.53 )" date 02/04/2013
bios0: LENOVO 3444CUU
acpi0 at bios0: rev 2
acpi0: sleep states S0 S3 S4 S5
acpi0: tables DSDT FACP SLIC TCPA SSDT SSDT SSDT HPET APIC MCFG ECDT FPDT ASF! 
UEFI UEFI MSDM SSDT SSDT UEFI SSDT DBG2
acpi0: wakeup devices LID_(S4) SLPB(S3) IGBE(S4) EXP2(S4) XHCI(S3) EHC1(S3) 
EHC2(S3) HDEF(S4)
acpitimer0 at acpi0: 3579545 Hz, 24 bits
acpihpet0 at acpi0: 14318179 Hz
acpimadt0 at acpi0 addr 0xfee0: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1896.03 MHz
cpu0: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu0: 256KB 64b/line 8-way L2 cache
cpu0: smt 0, core 0, package 0
mtrr: Pentium Pro MTRR support, 10 var ranges, 88 fixed ranges
cpu0: apic clock running at 99MHz
cpu0: mwait min=64, max=64, C-substates=0.2.1.1.2, IBE
cpu1 at mainbus0: apid 1 (application processor)
cpu1: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1895.69 MHz
cpu1: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu1: 256KB 64b/line 8-way L2 cache
cpu1: smt 1, core 0, package 0
cpu2 at mainbus0: apid 2 (application processor)
cpu2: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1895.69 MHz
cpu2: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu2: 256KB 64b/line 8-way L2 cache
cpu2: smt 0, core 1, package 0
cpu3 at mainbus0: apid 3 (application processor)
cpu3: Intel(R) Core(TM) i7-3667U CPU @ 2.00GHz, 1895.69 MHz
cpu3: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu3: 256KB 64b/line 8-way L2 cache
cpu3: smt 1, core 1, package 0
ioapic0 at mainbus0: apid 2 pa 0xfec0, version 20, 24 pins
acpimcfg0 at acpi0 addr 0xf800, bus 0-63
acpiec0 at acpi0
acpiprt0 at acpi0: bus 0 (PCI0)
acpiprt1 at acpi0: bus -1 (PEG_)
acpiprt2 at acpi0: bus 2 (EXP1)
acpiprt3 at acpi0: bus 3 (EXP2)
acpicpu0 at acpi0: C2, C1, PSS
acpicpu1 at acpi0: C2, C1, PSS
acpicpu2 at acpi0: C2, C1, PSS
acpicpu3 at acpi0: C2, C1, PSS
acpipwrres0 at acpi0: PUBS, resource for XHCI, EHC1, EHC2
acpitz0 at acpi0: critical temperature is 200 degC
acpibtn0 at acpi0: LID_
acpibtn1 at acpi0: SLPB
acpibat0 at acpi0: BAT0 model "45N1071" serial  1475 type LiP oem "SMP"
acpibat1 at acpi0: BAT1 not present
acpiac0 at acpi0: AC unit online
acpithinkpad0 at acpi0
cpu0: Enhanced SpeedStep 1896 MHz: speeds: 2001, 2000, 1900, 1800, 1700, 1600, 
1500, 1400, 1300, 1200, 1100, 1000, 900, 800 MHz
pci0 at mainbus0 bus 0
pchb0 at pci0 dev 0 function 0 "Intel Core 3G Host" rev 0x09
vga1 at pci0 dev 2 function 0 "Intel HD Graphics 4000" rev 0x09
intagp at vga1 not configured
inteldrm0 at vga1
drm0 at inteldrm0
drm: Memory usable by graphics device = 2048M
inteldrm0: 1600x900
wsdisplay0 at vga1 mux 1: console (std, vt100 emulation)
wsdisplay0: screen 1-5 added (std, vt100 emulation)
"Intel 7 Series MEI" rev 0x04 at pci0 dev 22 function 0 not configured
puc0 at pci0 dev 22 function 3 "Intel 7 Series KT" rev 0x04: ports: 1 com
com4 at puc0 port 0 apic 2 int 19: ns16550a, 16 byte fifo
com4: probed fifo depth: 0 bytes
ehci0 at pci0 dev 26 function 0 "Intel 7 Series USB" rev 0x04: apic 2 int 16
usb0 at ehci0: USB revision 2.0
uhub0 at usb0 "Intel EHCI root hub" rev 2.00

Re: l2tp / ipsec issue

2014-07-23 Thread Bastien Ceriani
Daniel,

Good.
Did you try to connect an Windows (Seven or Eight ?) client. Your VPN
server is working on your frontend firewall/router or on a internal server
behind a firewall ?

Regards,


On Tue, Jul 22, 2014 at 8:16 PM, Daniel Polak  wrote:

> I got everything to work based on the Undeadly article and the
> information in this thread.
>
> A few remarks:
> - when connecting with an iPhone 3des in ipsec.conf should be replaced
> by aes
> - uncomment the line with net.pipex.enable=1 in sysctl.conf
> - add npppd_flags="" to rc.conf.local so npppd is started automatically
> at system boot
>
> And one question:
> Do we really need to allow ah in pf.conf? I have it working with just esp.
>
>
> Daniel
>  Original message from mxb at 22-7-2014 13:15
> > As been the original author of undeadly.org article I can state that
> info in is stil partially valid, except npppd.conf part.



Re: DVD & how to overcome mkisofs

2014-07-23 Thread Stuart Henderson
On 2014-07-22, Josh Grosse  wrote:
> On Tue, Jul 22, 2014 at 09:22:24AM +, Stuart Henderson wrote:
>> On 2014-07-21, Tuyosi Takesima  wrote:
>> > ...
>> >
>> > sudo mplayer  dvd://1 -dvd-device /dev/rcd0c -aid 129
>> >
>> > ...
>> I think it would be better to change permissions on the device -
>> mplayer code should not be run as root.
>  
> $ ls -l /dev/cd0c
> brw-r-  1 root  operator6,   2 Jul 19 17:36 /dev/cd0c
> $
>
> Perhaps tuyosi-san's user should be added to the operator group.  
>
> This will give the user read access to devices.  It may not
> be appropriate for all users, but certainly would be OK for one with
> wheel group or broad sudo authority.

I think it may be better to change the group ownership of the device
node instead - I don't see the need for mplayer to have access to the
other privileges that "operator" allows.



Re: DVD & how to overcome mkisofs

2014-07-23 Thread Josh Grosse
On Wed, Jul 23, 2014 at 08:31:57AM +, Stuart Henderson wrote:

> I think it may be better to change the group ownership of the device
> node instead - I don't see the need for mplayer to have access to the
> other privileges that "operator" allows.
 
That's something I have not previously considered, and should have.  

My standard "non-root" userid that I create on my systems I have always added
to both the wheel and operator groups as a matter of course, since I use
the same userid with dump(8). I had not considered that I had been giving 
every application I run the same access to /dev.  :(

I'll change my procedures, and remove the group from my standard userid on 
all my systems.

Thank you very much, stu@, for improving my practices.



Re: l2tp / ipsec issue

2014-07-23 Thread Daniel Polak
Bastien,

I just gave it a try with Windows 7 and it needs an ipsec.conf with
main auth "hmac-sha1" enc "3des" group modp2048 \
quick auth "hmac-sha1" enc "aes" \

I've only tested it locally on the same network so no NAT involved, I've
not tried it from the internet behind a firewall/router that is doing NAT.

Daniel
 Original message from Bastien Ceriani at 23-7-2014 9:41
> Daniel,
>
> Good.
> Did you try to connect an Windows (Seven or Eight ?) client. Your VPN
> server is working on your frontend firewall/router or on a internal server
> behind a firewall ?
>
> Regards,
>
>
> On Tue, Jul 22, 2014 at 8:16 PM, Daniel Polak  wrote:
>
>> I got everything to work based on the Undeadly article and the
>> information in this thread.
>>
>> A few remarks:
>> - when connecting with an iPhone 3des in ipsec.conf should be replaced
>> by aes
>> - uncomment the line with net.pipex.enable=1 in sysctl.conf
>> - add npppd_flags="" to rc.conf.local so npppd is started automatically
>> at system boot
>>
>> And one question:
>> Do we really need to allow ah in pf.conf? I have it working with just esp.
>>
>>
>> Daniel
>>  Original message from mxb at 22-7-2014 13:15
>>> As been the original author of undeadly.org article I can state that
>> info in is stil partially valid, except npppd.conf part.



Re: [OT] Commonwealth Games Ceremonies

2014-07-23 Thread Norman Gray
Craig, hello.

On 2014 Jul 22, at 13:17, Craig R. Skinner  wrote:

> Last night at a dress reversal of the 2014 Commonwealth Games Opening
> Ceremony, I thrilled to walk my New Zealand flag in to the packed
> stadium of 71 nations from the British Empire!!!

Welcome to Glasgow!

(I should probably confess that the weather isn't _always_ quite as good as 
this...)

Norman


-- 
Norman Gray  :  http://nxg.me.uk
SUPA School of Physics and Astronomy, University of Glasgow, UK



Re: [Bulk] Re: DVD & how to overcome mkisofs

2014-07-23 Thread Kevin Chadwick
previously on this list Kevin Chadwick contributed:

> > I think it may be better to change the group ownership of the device
> > node instead - I don't see the need for mplayer to have access to the
> > other privileges that "operator" allows.  
> 
> brw-r-  1 cdwrite  cdread6,   2 Jul 19 17:36 /dev/cd0c
> 
> How about having cdwrite and cdread groups by default for users to add
> to?

doh!, and the user can suid mplayer etc.. too

restrictive umask may cause issues but cdwrite can always be added to
groups too?

-- 
___

'Write programs that do one thing and do it well. Write programs to work
together. Write programs to handle text streams, because that is a
universal interface'

(Doug McIlroy)

In Other Words - Don't design like polkit or systemd
___



Re: [Bulk] Re: DVD & how to overcome mkisofs

2014-07-23 Thread Kevin Chadwick
previously on this list Stuart Henderson contributed:

> I think it may be better to change the group ownership of the device
> node instead - I don't see the need for mplayer to have access to the
> other privileges that "operator" allows.

brw-r-  1 cdwrite  cdread6,   2 Jul 19 17:36 /dev/cd0c

How about having cdwrite and cdread groups by default for users to add
to?

-- 
___

'Write programs that do one thing and do it well. Write programs to work
together. Write programs to handle text streams, because that is a
universal interface'

(Doug McIlroy)

In Other Words - Don't design like polkit or systemd
___



pfctl: DIOCADDQUEUE: No such process

2014-07-23 Thread Loïc Blot
Hi @misc,
This afternoon i got a very strange issue on a router/firewall. I added
a rule and then the following error appears:

> pfctl -nf /etc/pf.conf
> pfctl -f /etc/pf.conf
pfctl: DIOCADDQUEUE: No such process

I don't have any queue configured on the firewall.

I also tried pfctl -d; pfctl -e; pfctl -f /etc/pf.conf

On my second router firewall (which has exactly the same ruleset), there
isn't any error.

Here is the uname -a:
OpenBSD saumur.institutoptique.fr 5.5 GENERIC.MP#315 amd64

I cannot give you the dmesg output of the machine because the uptime
(dmesg was polluted by some carp messages :p), i cannot reboot it at
this time, it's a BGP router and the redundancy is in maintenance.

Please also note i modified rules 2 hours ago and i wasn't affected by
this issue.

have you got an idea ?

Thanks in advance

-- 
Best regards, 

Loïc BLOT, Engineering
UNIX Systems, Security and Network Engineer
http://www.unix-experience.fr



pkg_scripts continuation line in -current

2014-07-23 Thread Martin Brandenburg
current.html says pkg_scripts continuation lines such as

pkg_scripts="${pkg_scripts} somescript"

are no longer supported and must be replaced with one long pkg_scripts
line. But I cannot think of any reason why this wouldn't work.

What is the reasoning behind this?

I do appreciate examples/. That will save me from having /etc littered
with .orig files.

-- Martin



Re: pkg_scripts continuation line in -current

2014-07-23 Thread Theo de Raadt
>current.html says pkg_scripts continuation lines such as
>
>   pkg_scripts="${pkg_scripts} somescript"
>
>are no longer supported and must be replaced with one long pkg_scripts
>line. But I cannot think of any reason why this wouldn't work.
>
>What is the reasoning behind this?
>
>I do appreciate examples/. That will save me from having /etc littered
>with .orig files.

scripts (netstart, rc.local, rc.conf.*) are no longer "evaluated".  They
are run as seperate programs.

As a result, variables they set are no longer automatically propogated
into the sh variables of the sh parent.  We are blocking variable polution
for a number of reasons which will become clear in time.  It is understood
that this change will affect the practices some people have.



automatic installation with site.tgz

2014-07-23 Thread Waldemar Brodkorb
Hi OpenBSD Hackers,

what is the correct way to set a variable in install.conf
to automatically extract siteXX.tgz while doing automatic
installations?
We tried "Set Name = all", but this did not work.
All sets excluding site.tgz are installed.

Thanks
 Waldemar



Re: Problem with PPPoE

2014-07-23 Thread Giancarlo Razzolini
On 23-07-2014 00:04, Felipe Mesquita de Oliveira wrote:
> Maybe changing ethernet card, cloning MAC-Address, etc could make it
> work still in 5.4?
>
If your pppoe concentrator does any sort of mac address access list
control, then yes, you could try using the same mac address of your 4.9
installation that is working.

Cheers,

--
Giancarlo Razzolini
GPG: 4096R/77B981BC

[demime 1.01d removed an attachment of type application/pkcs7-signature which 
had a name of smime.p7s]



NIC hotplugging

2014-07-23 Thread Jeremy Hanmer
It looks to me like most or all of the available NIC drivers (em,
rtl8139 and vio, anyway) don't support hot plugging as recently as 5.4
and 5.5, is that correct?  If that's true, can anyone give me a
pointer to the related docs so
that support could be added?



Re: automatic installation with site.tgz

2014-07-23 Thread Peter Hessler
I just set this up on some systems at $work, and here is what I have

...
Set name(s) = +site*
Unverified sets: site55.tgz. Continue without verification = yes
...

and make sure you add it to install.txt



On 2014 Jul 23 (Wed) at 20:07:49 +0200 (+0200), Waldemar Brodkorb wrote:
:Hi OpenBSD Hackers,
:
:what is the correct way to set a variable in install.conf
:to automatically extract siteXX.tgz while doing automatic
:installations?
:We tried "Set Name = all", but this did not work.
:All sets excluding site.tgz are installed.
:
:Thanks
: Waldemar
:

-- 
I think pop music has done more for oral intercourse than anything else
that has ever happened, and vice versa.
-- Frank Zappa



Re: Interactive Unix System V/386 Release 3.2

2014-07-23 Thread Nicolas
Christopher Zimmermann  openbsd.org> writes:
> 
> 
> Hi,
> 
> I got two SunSoft Unix System V 3.2 of 1994. With still sealed
installation diskettes,  user's and
> maintenance Guides. Anyone interested? I could ship them from germany.
> 
> Christopher
> 
> --
> http://gmerlin.de
> OpenPGP: http://gmerlin.de/christopher.pub
> F190 D013 8F01 AA53 E080  3F3C F17F B0A1 D44E 4FEE
> iQJKBAEBCgA0BQJTVPsuLRxDaHJpc3RvcGhlciBaaW1tZXJtYW5uIDxtYWRyb2Fj
> aEBnbWVybGluLmRlPgAKCRB+JNGfNLgqKnjWD/4s0jxVeXH8nABEX6rjTCRelFR3
> XreMnh527KRV/T26O70HsMlNJZ2q6yXKOU4BsdCDWP2I7wHafky1l89sJhjBsFo2
> f8MYWYrEvkBPAlm6FwVFzOXhDngVT7wVbUIA2YhwaQ1GrsfocAH64NzqcJ1JANbr
> wht8z0Ra9SNzxXNmEZGBfMflKkjrpJIkc6FuiJdDgixCQyxzvLu5o72HN2nP7TCV
> iaUgoDPCdd7Y5hM0fyfg+SM4eXs+4dPZe6lpyYjFKgyWt9eCyHNWnE85YrK2oW7q
> YKXf5Ixzr/Jb8nV8yjj7OqnWS4jGBgXwRjzgtRnCQMxm34bBMAStWBNG/9fayicW
> aUsOFDSbnxuGU5Zabc2V6tZ+jDdAnZnwbKXcG2WtgatrE0m2wQdmmjOJY+vrm668
> VjoKrY0nSDkzmD/nc0G1BAEsvonnpaDEpDjo4hytVjyCBjLWsuCwTrZ+tpm5YfjV
> tf6cDXpJ8wcJhTYK6Ufu5LzIwQoUlUqFEIPvcDFpUkOBsC+rzRbuzUmDn989m3Tb
> pgjj7Pa/0xi1Yfibc4ORiG4kwg/kgzeeL5DwWImYJCBunLH9TdscveZ7RCQuD+Ag
> 2SFBubROZNHBGhD5OteZubxbGEEGFaMfRZil9+wg6tpdnr888a9pxcQlBU+wBeqc
> G8huTzyHcaHyxa+j5g==
> =pvcj
> -END PGP SIGNATURE-
> 
> 

Hi Christopher,

   Any chance that you still have those disks? I'm in particular looking for
the "INTERACTIVE Network Drivers extension" disk. 

   It's one final piece that I'd need to have networking in a PCIX VM.

The manual does say: "The INTERACTIVETM Network Drivers extension from
SunSoft is supplied with some SunSoftTM networking products, such as
INTERACTIVE TCPIIP."

Regards,
Nicolas



Trust chain: Trying to check certificates

2014-07-23 Thread Peer Janssen
(1)
The pkg_add man page sais that digitally signed packages are checked
against authorities in /etc/ssl/pkgca.pem.

I didn't find this pkgca.pem at said place, although pkg_add is indeed
installed.

I suppose checking of digitally signed packages will not be possible
without these certificates.
So where will that pkgca.pem come from?

And how is it constituted?
mozilla has a "CA policy", but I doubt it really works, since rogue CAs
already did bad things (to people) via mozilla's CAs.

How are things done in OpenBSD?

(2)
What I found in /etc/ssl was a cert.pem which apparently contained CAs.
Some question: Where did it come from? How was it constituted by the
OpenBSD team? Is there some kind of CA policy?

(3)
Displaying that certificate file with
openssl x509 -noout -in cert.pem -text [or -issuer or -subject]
yielded data of ONE certificate.

However, with "less cert.pem" it's quickly obvious that the file
contains lots of certificates from different CAs.
This seems quite strange to me. Not even a warning, nothing which tells
that the file contains many certificates.

There does not seem to be an option to list all the certificates in such
a cert.pem file.
Of course I can grep the somewhat cluttered fields.
But shouldn't it be easy to list the CAs contained in such file?
In fact, that cert.pem is a keyring. Which commands exist to examine
such a keyring?

Generally speaking (not especially on OpenBSD!), I find it difficult to
check certificates.
I did this exercise on a linux box and found hundrets of certificates in
different places.
The tools seem to be more or less useful to create certificates from
data, but not at all for easily getting an overview of where all the
trust they represent goes. It's useful to build a hierarchical system,
but not to clearly show it, and how it works, to the user. This seems
bad to me.

Peer



Re: Problem with PPPoE

2014-07-23 Thread Felipe Mesquita de Oliveira
Giancarlo,

After changing ports on the router, and clonning the MAC address with
lladdr it worked. Not sure which one solved the problem, but happy with the
results...

Thanks you all,
Felipe



On Wed, Jul 23, 2014 at 3:44 PM, Giancarlo Razzolini 
wrote:

> On 23-07-2014 00:04, Felipe Mesquita de Oliveira wrote:
> > Maybe changing ethernet card, cloning MAC-Address, etc could make it
> > work still in 5.4?
> >
> If your pppoe concentrator does any sort of mac address access list
> control, then yes, you could try using the same mac address of your 4.9
> installation that is working.
>
> Cheers,
>
> --
> Giancarlo Razzolini
> GPG: 4096R/77B981BC



Re: [Bulk] Trust chain: Trying to check certificates

2014-07-23 Thread Kevin Chadwick
previously on this list Peer Janssen contributed:

> The pkg_add man page sais that digitally signed packages are checked
> against authorities in /etc/ssl/pkgca.pem.
> 
> I didn't find this pkgca.pem at said place, although pkg_add is indeed
> installed.
> 
> I suppose checking of digitally signed packages will not be possible
> without these certificates.
> So where will that pkgca.pem come from?

I believe that file was created and used optionally by home made ports
when signing was manually enabled and depended on openssl, gpg would
be another option but not built into the ports system likely due to
it's license.

Signify is OpenBSDs newer and far more efficient and neat method now
used on all packages by default but if your still interested then see
pkg_sign(1)

 For X.509, the signer's certificate and the signer's private key
 should be generated using standard openssl x509 commands.
 This assumes the existence of a certificate authority (or several),
 whose public information is recorded as a /etc/ssl/pkgca.pem file.



-- 
___

'Write programs that do one thing and do it well. Write programs to work
together. Write programs to handle text streams, because that is a
universal interface'

(Doug McIlroy)

In Other Words - Don't design like polkit or systemd
___


___



Sound - Azalia Codecs

2014-07-23 Thread J. Scott Heppler

The recent change acpi(4) change regarding bogus interrupts allowed me
to install Current on an old Everex Stepnote VA1500V notebook.
Everything works with two small nits regarding the sound.
The more important one is that plugging in headphone to the green
line-out jack mutes the speaker but does not provide and sound.

The mic input jack also does not record anything using aucat - I
rarely record though.  The *wav file is generated for the appropriate
amount of time but has not discernible output on playback.
**
$ mixerctl -av
record.adc-0:1_mute=off [ off on ]
record.adc-0:1=120,120
inputs.mix_source=dac-0:1,mic,dac-4:5 { dac-0:1 mic dac-4:5 }
inputs.mix_dac-0:1=120,120
inputs.mix_mic=120,120
inputs.mix_dac-4:5=120,120
record.adc-0:1_source=mix [ mix mic ]
inputs.sel2_source= [ ]
outputs.sel2_mute=off [ off on ]
outputs.sel2=126,126
inputs.dac-2:3_mute=off [ off on ]
inputs.dac-2:3=126,126
inputs.dac-4:5_mute=off [ off on ]
inputs.dac-4:5=126,126
outputs.mic_source=dac-2:3 [ dac-2:3 ]
outputs.mic_dir=input-vr50 [ none output input input-vr50 ]
outputs.spkr_source=mix [ mix ]
outputs.spkr_mute=off [ off on ]
outputs.spkr=144,144
outputs.spkr_boost=off [ off on ]
outputs.master=135,135
outputs.master.mute=off [ off on ]
outputs.master.slaves=spkr { sel2 dac-2:3 dac-4:5 spkr }
record.volume=120,120
record.volume.mute=off [ off on ]
record.volume.slaves=adc-0:1 { adc-0:1 } 
***

I do not see any hp or line-out outputs and I am unsure what to make of
the empty sel2_source.

The notebook chipset is Via based
***
dmesg | grep azalia
azalia0 at pci4 dev 1 function 0 "VIA HD Audio" rev 0x10: apic 1 int 17
azalia0: codecs: VIA/0x1708
audio0 at azalia0 
***


The Windows drivers for the same notebook use the ALC 655 azalia codec.
The ALC 655 codec appears to be in OpenBSD only under auvia driver
instead of the azalia driver
From:
http://openbsd.7691.n7.nabble.com/VIA-chipsets-support-of-CN700-VT8237R-VT1708-A-td92231.html
***
auvia0 at pci0 dev 17 function 5 "VIA VT8233 AC97" rev 0x60: apic 2 int 22 (irq 
5)
ac97: codec id 0x414c4760 (Avance Logic ALC655 rev 0)
audio0 at auvia0 
***


I found the codec specs for both the VT1708A and Realtek ALC 655 sound
drivers and can provide those (browser crashed with both 60+ page *pdf's
open)

Is there some way to have either have azalia call up the ALC 655 codec
or change the device code to call up auvia?  In linux/alsa one can tweak
the codec in /etc/modprobe.d.

I debated sending this during the 5.6-beta freeze.  On one hand, it
would be good to fix, but on the other, I can't imagine this is a common
problem.

Any additional info, debug outputs and trials of patches I should be
able to provide. 





--
J. Scott Heppler

Penguin Innovations

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 



NOTICE: This e-mail message and any attachments may
contain legally privileged and confidential information intended
solely for the use of the intended recipients. If you are not an
intended recipient, you are hereby notified that you have
received this message in error and any review, dissemination,
distribution, copying, or other unauthorized use of this email
and any attachment is strictly prohibited. If you have received
this email in error, please notify the sender immediately and
delete the message and any attachments from your system.



l2tp / ipsec follow up

2014-07-23 Thread Gordon Turner

Hey all,

Based on the feedback from Daniel and others, I have successfully 
connected to my OpenBSD instance running behind my router / firewall 
from an iOS and OSX client on the Internet.  (Updated instructions 
below.)


The one issue that I have is that requests to the local private network 
are being lost.  My Packet Filter kung fu is a little rusty, the only 
entries in the pf.conf at the moment are:


```
pass quick proto { esp, ah } from any to any
pass in quick on egress proto udp from any to any port {500, 4500, 1701} 
keep state

pass on enc0 from any to any keep state (if-bound)
```

I am not sure what device to 'passs in' on at the end of the l2tp / 
ipsec to enable nat'ing and accessing internal network resources.


(There was feedback that `pool-address 10.0.0.1-10.0.0.100` and 
`:framed-ip-address=10.0.0.10:` had to be a different network then the 
private internal network.)


The router / firewall has a working dhcp server running.

```
ifconfig -a
lo0: flags=8049 mtu 33144
priority: 0
groups: lo
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x3
inet 127.0.0.1 netmask 0xff00
vio0: flags=8843 mtu 1500
lladdr 52:54:00:9b:3b:bc
priority: 0
groups: egress
media: Ethernet autoselect
status: active
inet6 fe80::5054:ff:fe9b:3bbc%vio0 prefixlen 64 scopeid 0x1
inet 192.168.2.232 netmask 0xff00 broadcast 192.168.2.255
enc0: flags=0<>
priority: 0
groups: enc
status: active
pflog0: flags=141 mtu 33144
priority: 0
groups: pflog
pppx0: flags=8051 mtu 1360
description: gturner
priority: 0
groups: pppx
inet 192.168.2.1 --> 10.0.0.97 netmask 0x
```

Again, any pointers appreciated.

Gord.





VPN OpenBSD L2TP-IPSEC (mostly working-ish)
===

Requirements
---
- Using OpenBSD 5.5 as an VPN end point for iOS 7.0 and OSX 10.9 
clients.

  - Support for iOS, preferably native VPN client
  - Support for OSX, preferably native VPN client

- VPN endpoint running on an internal server.
- Forwarding appropriate ports from a router.


Description
---
- Use npppd, IPsec and Packet Filter (pf).
  - Configuration files `/etc/npppd/npppd.conf`, 
`/etc/npppd/npppd-users`, `/etc/ipsec.conf` and `/etc/pf.conf`.


- Reference:
http://www.slideshare.net/GiovanniBechis/npppd-easy-vpn-with-openbsd
http://undeadly.org/cgi?action=article&sid=20120427125048
http://comments.gmane.org/gmane.os.openbsd.misc/209636
http://stackoverflow.com/questions/14967962/openbsd-ipsec-vpn-not-routing-traffic
http://www.packetmischief.ca/openbsd-ipsec-tunnel-guide/

- Claims to have it working, on internet facing machine:
https://www.mail-archive.com/misc@openbsd.org/msg125930.html

- Reference for supported protocols and authentication methods fo iOS:
http://support.apple.com/kb/HT1288


npppd Setup
---
- npppd is a Point-to-Point Protocol (PPP) and tunneling daemon capable 
of L2TP, PPTP, and PPPoE.


- Reference: 
http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/npppd.8?&manpath=OpenBSD-current&sec=8&query=npppd

http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/npppd.conf.5?&manpath=OpenBSD-current&sec=5&query=npppd.conf

- NOTE: Private network is 192.168.2.x.
- NOTE: Using local file authentication.

- Example npppd.conf file, `/etc/npppd/npppd.conf`:
```
authentication LOCAL type local {
users-file "/etc/npppd/npppd-users"
}

tunnel L2TP_ipv4 protocol l2tp {
listen on 0.0.0.0
}

ipcp IPCP {
pool-address 10.0.0.1-10.0.0.100
dns-servers 8.8.8.8
}

interface pppx0 address 192.168.2.1 ipcp IPCP
bind tunnel from L2TP_ipv4 authenticated by LOCAL to pppx0
```
- NOTE: `pool-address` valus should be a block of addresses in the same 
subnet of the internal network.
- NOTE: `dns-servers 8.8.8.8` is Google's public dns, local local DNS 
servers should be used if available.



- Example npppd-users file, `/etc/npppd/npppd-users`:
```
jtest: \
:password=SEEKRIT:\
:framed-ip-address=10.0.0.10:
```
- NOTE: Replace `SEEKRIT` with your password.
- NOTE: The `framed-ip-address` value should be in the `pool-address` 
block from `/etc/npppd/npppd.conf`.



IPsec Setup
---
- IPsec is a pair of protocols, Encapsulating Security Payload (ESP) and 
Authentication Header (AH), which provide security services for IP 
datagrams.


- Reference:
http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/ipsec.4?&manpath=OpenBSD-current&query=ipsec

- NOTE: Private network is 192.168.2.x.

- Example ipsec.conf file, `/etc/ipsec.conf`:
```
public_ip = "192.168.2.2"

ike passive esp transport \
  proto udp from $public_ip to any port 1701 \
  main auth "hmac-sha1" enc "aes" group modp1024 \
  quick auth "hmac-sha1" enc "aes" \
  psk "SEEKRIT"
```
- NOTE: Replace `192.168.2.2` with the ip of the server.
- NOTE: Replace SEEKRIT with your password

Re: Trust chain: Trying to check certificates

2014-07-23 Thread Ted Unangst
On Wed, Jul 23, 2014 at 22:39, Peer Janssen wrote:
> (1)
> The pkg_add man page sais that digitally signed packages are checked
> against authorities in /etc/ssl/pkgca.pem.
> 
> I didn't find this pkgca.pem at said place, although pkg_add is indeed
> installed.
> 
> I suppose checking of digitally signed packages will not be possible
> without these certificates.
> So where will that pkgca.pem come from?

That's rather outdated information. I would ignore it. pkg_add will
verify the pkg was signed with a key in /etc/signify/. You shouldn't
need to do anything about this. pkg_add will not by default install
unsigned packages.


> (2)
> What I found in /etc/ssl was a cert.pem which apparently contained CAs.
> Some question: Where did it come from? How was it constituted by the
> OpenBSD team? Is there some kind of CA policy?

>From time to time, somebody will send a patch that adds a CA or
removes a CA from that file. Sometimes it's applied, sometimes it's
not. I would describe the current CA policy as "the CA system is
broken."



dump W output

2014-07-23 Thread Robert Carleton
Using "dump W" doesn't seem to be showing the filesystems. This is what I'm 
seeing:

$ dump W  
Last dump(s) done (Dump '>' file systems):
  /dev/rwd0a(  ) Last dump: Level 9, Date Wed Jul 23 02:30
  /dev/rwd0e(  ) Last dump: Level 9, Date Wed Jul 23 02:30
  /dev/rwd0f(  ) Last dump: Level 9, Date Wed Jul 23 02:30
  /dev/rwd0h(  ) Last dump: Level 9, Date Wed Jul 23 02:30
  /dev/rwd0k(  ) Last dump: Level 9, Date Wed Jul 23 02:30
$ cat /etc/dumpdates  
/dev/rwd0e   0 Sat Jul 19 14:25:18 2014
/dev/rwd0a   0 Sat Jul 19 14:23:41 2014
/dev/rwd0k   0 Sat Jul 19 14:23:51 2014
/dev/rwd0f   0 Sat Jul 19 14:23:55 2014
/dev/rwd0h   0 Sat Jul 19 14:25:16 2014
/dev/rwd0a   9 Wed Jul 23 02:30:03 2014
/dev/rwd0k   9 Wed Jul 23 02:30:06 2014
/dev/rwd0f   9 Wed Jul 23 02:30:14 2014
/dev/rwd0h   9 Wed Jul 23 02:30:17 2014
/dev/rwd0e   9 Wed Jul 23 02:30:21 2014
$ cat /etc/fstab  
80275b07ee014dac.b none swap sw
80275b07ee014dac.a / ffs rw 1 1
80275b07ee014dac.k /home ffs rw,nodev,nosuid 1 2
80275b07ee014dac.d /tmp ffs rw,nodev,nosuid 1 2
80275b07ee014dac.f /usr ffs rw,nodev 1 2
80275b07ee014dac.h /usr/local ffs rw,nodev 1 2
80275b07ee014dac.j /usr/obj ffs rw,nodev,nosuid 1 2
80275b07ee014dac.i /usr/src ffs rw,nodev,nosuid 1 2
80275b07ee014dac.e /var ffs rw,nodev,nosuid 1 2
$ 


I guess this is because dump can't read the DUIDs in the fstab? I'm running 
OpenBSD 5.5-stable, patch 8, compiled from source.

Best,

--Bruce


Robert "Bruce" Carleton
r...@rbcarleton.com



Re: pfctl: DIOCADDQUEUE: No such process

2014-07-23 Thread Eric Lalonde
> I cannot give you the dmesg output of the machine because the uptime
> (dmesg was polluted by some carp messages :p), i cannot reboot it at
> this time, it's a BGP router and the redundancy is in maintenance.


try ‘cat /var/run/dmesg.boot'



Re: pfctl: DIOCADDQUEUE: No such process

2014-07-23 Thread Loïc Blot
Hi,
thanks for the tip.

No pfpurge process is running :(

Here is dmesg.boot

OpenBSD 5.5 (GENERIC.MP) #315: Wed Mar  5 09:37:46 MST 2014
dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 17082220544 (16290MB)
avail mem = 16618885120 (15849MB)
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 2.7 @ 0xcf42c000 (77 entries)
bios0: vendor Dell Inc. version "1.4.6" date 10/26/2012
bios0: Dell Inc. PowerEdge R320
acpi0 at bios0: rev 2
acpi0: sleep states S0 S4 S5
acpi0: tables DSDT FACP APIC SPCR HPET DMAR MCFG WD__ SLIC ERST HEST
BERT EINJ TCPA PC__ SRAT SSDT
acpi0: wakeup devices PCI0(S5) EHC1(S3) EHC2(S3) PCI1(S5)
acpitimer0 at acpi0: 3579545 Hz, 24 bits
acpimadt0 at acpi0 addr 0xfee0: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Xeon(R) CPU E5-2407 0 @ 2.20GHz, 2200.34 MHz
cpu0:
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,DCA,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,NXE,LONG,LAHF,PERF,ITSC
cpu0: 256KB 64b/line 8-way L2 cache
cpu0: smt 0, core 0, package 0
mtrr: Pentium Pro MTRR support, 10 var ranges, 88 fixed ranges
cpu0: apic clock running at 99MHz
cpu0: mwait min=64, max=64, C-substates=0.2.1.1.2, IBE
cpu1 at mainbus0: apid 2 (application processor)
cpu1: Intel(R) Xeon(R) CPU E5-2407 0 @ 2.20GHz, 2200.00 MHz
cpu1:
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,DCA,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,NXE,LONG,LAHF,PERF,ITSC
cpu1: 256KB 64b/line 8-way L2 cache
cpu1: smt 0, core 1, package 0
cpu2 at mainbus0: apid 4 (application processor)
cpu2: Intel(R) Xeon(R) CPU E5-2407 0 @ 2.20GHz, 2200.00 MHz
cpu2:
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,DCA,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,NXE,LONG,LAHF,PERF,ITSC
cpu2: 256KB 64b/line 8-way L2 cache
cpu2: smt 0, core 2, package 0
cpu3 at mainbus0: apid 6 (application processor)
cpu3: Intel(R) Xeon(R) CPU E5-2407 0 @ 2.20GHz, 2200.00 MHz
cpu3:
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,SMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,DCA,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,NXE,LONG,LAHF,PERF,ITSC
cpu3: 256KB 64b/line 8-way L2 cache
cpu3: smt 0, core 3, package 0
ioapic0 at mainbus0: apid 0 pa 0xfec0, version 20, 24 pins
ioapic1 at mainbus0: apid 1 pa 0xfec3f000, version 20, 24 pins
ioapic1: misconfigured as apic 15, remapped to apid 1
acpihpet0 at acpi0: 14318179 Hz
acpimcfg0 at acpi0 addr 0xe000, bus 0-255
acpiprt0 at acpi0: bus 0 (PCI0)
acpiprt1 at acpi0: bus 1 (PEX1)
acpiprt2 at acpi0: bus -1 (PEX2)
acpiprt3 at acpi0: bus 8 (PEX3)
acpiprt4 at acpi0: bus -1 (PEX4)
acpiprt5 at acpi0: bus -1 (PEX5)
acpiprt6 at acpi0: bus 10 (PEX6)
acpiprt7 at acpi0: bus 2 (PEX7)
acpiprt8 at acpi0: bus -1 (PEX8)
acpiprt9 at acpi0: bus 3 (PEX9)
acpicpu0 at acpi0
acpicpu1 at acpi0
acpicpu2 at acpi0
acpicpu3 at acpi0
ipmi at mainbus0 not configured
pci0 at mainbus0 bus 0
pchb0 at pci0 dev 0 function 0 "Intel E5 Host" rev 0x07
ppb0 at pci0 dev 1 function 0 "Intel E5 PCIE" rev 0x07
pci1 at ppb0 bus 1
mfi0 at pci1 dev 0 function 0 "Symbios Logic MegaRAID SAS2008" rev 0x03:
apic 1 int 2
mfi0: "PERC H310 Mini", firmware 20.11.0-0002
scsibus0 at mfi0: 16 targets
sd0 at scsibus0 targ 0 lun 0:  SCSI3 0/direct
fixed naa.690b11c032dcc20018c237a20522edfe
sd0: 285568MB, 512 bytes/sector, 584843264 sectors
scsibus1 at mfi0: 256 targets
ppb1 at pci0 dev 3 function 0 "Intel E5 PCIE" rev 0x07: msi
pci2 at ppb1 bus 8
em0 at pci2 dev 0 function 0 "Intel I350" rev 0x01: msi, address
a0:36:9f:10:43:ac
em1 at pci2 dev 0 function 1 "Intel I350" rev 0x01: msi, address
a0:36:9f:10:43:ad
"Intel E5 Address Map" rev 0x07 at pci0 dev 5 function 0 not configured
"Intel E5 Error Reporting" rev 0x07 at pci0 dev 5 function 2 not
configured
ppb2 at pci0 dev 17 function 0 "Intel C600 Virtual PCIE" rev 0x05
pci3 at ppb2 bus 9
"Intel C600 MEI" rev 0x05 at pci0 dev 22 function 0 not configured
"Intel C600 MEI" rev 0x05 at pci0 dev 22 function 1 not configured
ehci0 at pci0 dev 26 function 0 "Intel C600 USB" rev 0x05: apic 0 int 23
usb0 at ehci0: USB revision 2.0
uhub0 at usb0 "Intel EHCI root hub" rev 2.00/1.00 addr 1
ppb3 at pci0 dev 28 function 0 "Intel C600 PCIE" rev 0xb5: msi
pci4 at ppb3 bus 10
em2 at pci4 dev 0 function 0 "Intel I350" rev 0x01: msi, address
a0:36:9f:12:bf:14
em3 at pci4 dev 0 function 1 "Intel I350" rev 0x01: msi, address
a0:36:9f:12:bf:15
ppb4 at pci0 dev 28 function 4 "Intel C600 PCIE" rev 0xb5
pci5 at ppb4 bus 2
bge0 at pci5 dev 0 funct