Re: Some NFS clients won't mount

2023-01-01 Thread Theo de Raadt
vitmau...@gmail.com wrote: > I did some tests and I'm now pretty sure the problem revolves around > the point naddy made: Kodi and VLC try to mount my NFS share through a > non-privileged port. As both Kodi and VLC use the same NFS client > library (libnfs), I tried to find out a bit more about h

TLS certs for open{bgpd,ntpd}.org expired

2023-01-01 Thread Matthias Schmidt
Hi, in case the admin is subscribed here or someone can deliver a ping. The certs for the above mentioned web sites expired on 20221225. Cheers Matthias

Re: Possible off-by-one bug in usr.sbin/rad/engine.c

2023-01-01 Thread Alejandro Colomar
Hello Florian, Ingo, On 1/1/23 08:24, Florian Obser wrote: On 2022-12-31 23:54 +01, Ingo Schwarze wrote: Hi Alejandro, Alejandro Colomar wrote on Sat, Dec 31, 2022 at 05:56:27PM +0100: I've started auditing the OpenBSD source code after the discussion on arc4random_uniform(3) and my suggest

Re: Possible off-by-one bug in usr.sbin/rad/engine.c

2023-01-01 Thread Alejandro Colomar
On 1/1/23 14:48, Alejandro Colomar wrote: Hello Florian, Ingo, On 1/1/23 08:24, Florian Obser wrote: On 2022-12-31 23:54 +01, Ingo Schwarze wrote: [...] With your change, the timeout could go up to 600.99, i.e. almost 601 seconds.  I don't know the protocol and can't say whether the

Re: Some NFS clients won't mount

2023-01-01 Thread vitmau...@gmail.com
Theo helped solve my main concern. In my mind, I was kinda comparing NFS and HTTP: no one requires a browser (which is essentially a HTTPclient) to be run as root, so why require a NFS client to be run this way? But the point is that we have securely written HTTP servers, so we don't need to be so

Re: Possible off-by-one bug in usr.sbin/rad/engine.c

2023-01-01 Thread Alejandro Colomar
Hello Rudolf, On 1/1/23 16:59, Rudolf Leitgeb wrote: Coming from a C/C++ background, I would assume, that a range from 200 to 600 comprises numbers would start at 200 and reach as far as 599. This would be in sync with all STL functions for iterating through collections or for extracting ranges.

Re: Possible off-by-one bug in usr.sbin/rad/engine.c

2023-01-01 Thread Rudolf Leitgeb
Coming from a C/C++ background, I would assume, that a range from 200 to 600 comprises numbers would start at 200 and reach as far as 599. This would be in sync with all STL functions for iterating through collections or for extracting ranges. As long as you need two random numbers to craft second

Re: [RFC v1 2/2] Use arc4random_range() instead of arc4random_uniform() when appropriate

2023-01-01 Thread Theo de Raadt
Your proposal is junk. Not going to happen. >From owner-misc+M195331=deraadt=cvs.openbsd@openbsd.org Sat Dec 31 >11:19:48 2022 >Delivered-To: dera...@cvs.openbsd.org >DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; s=selector1; bh=/JVUSEqVR3 > /k8gFGm9V8QDDc/a7fMpZ1djd/RE+G3ho=; h=