Re: Upgrade from snapshot to release.

2016-02-10 Thread Christian Weisgerber
On 2016-02-10, Ville Valkonen wrote: > On Feb 10, 2016 5:16 PM, "Paco Esteban" wrote: >> Is it possible to go from 5.8-current to 5.9 (when it's available) using >> the installer ? Sure. That's just a regular upgrade. > downgrading is not supported. True, but 5.8-current to 5.9 is not a down

Re: Need to swap partitions: /tmp amd /usr

2017-10-30 Thread Christian Weisgerber
On 2017-10-30, "Jay Hart" wrote: > Below is currently how I have my disk laid out partition wise. I have a > feeling I need to swap > /tmp and /usr in order to gain additional space for /usr. > > What is the best way to go about that? * Drop into single user mode. * Unmount the filesystems mou

Re: TRIM on SSD

2017-12-06 Thread Christian Weisgerber
On 2017-12-06, ti...@openmailbox.org wrote: > If TRIM would be implemented someday, one thing that would be > neat would be that crypto and other softraid would propagate the > TRIM. That would be a nice combination between wear level resiliency > and disk data safety. That runs counter to popul

Re: NTP issue on Lanner FW-7526B

2017-12-08 Thread Christian Weisgerber
On 2017-12-08, Darren Tucker wrote: > If your hardware doesn't have a clock (or the clock is bad) then it can > take ntpd a long time to adjust it back to the correct time (it uses > adjtime(), which I think adjusts at +/- 10%). Actually, 5000 parts per million, so 0.5%. -- Christian "naddy" W

Re: Manual to cd (change working directory)

2017-12-14 Thread Christian Weisgerber
On 2017-12-13, Ingo Schwarze wrote: > That is not a stand-alone command, but a shell built-in. > Actually, it is not even possible to implement it as a stand-alone > command because the effect of the intended change would end when > the command exits. I think there is/was a POSIX requirement, or

Re: Reinitializing software from hardware clock?

2018-01-10 Thread Christian Weisgerber
On 2018-01-10, Maximilian Pichler wrote: > * At boot the software clock (the value returned by gettimeofday) is > initialized from the hardware clock (the one with the coin-shaped > battery). ... from the RTC ("real-time clock"), yes. > My question is: Can OpenBSD be told initialize the softwar

Re: Meltdown workaround enabled?

2018-03-13 Thread Christian Weisgerber
On 2018-03-13, Brian Camp wrote: > Non-working (Celeron J3455) - > > bcamp@nuc6cayh:~ (OpenBSD 6.2) > $ cpuid 0x0 > eax = 0x001521"" > ebx = 0x756e65471970169159"Genu" > ecx = 0x6c65746e1818588270"ntel" > edx = 0x49656e691231384169"ineI" > bcamp@nuc

Re: Meltdown workaround enabled?

2018-03-14 Thread Christian Weisgerber
On 2018-03-14, "Robert Paschedag" wrote: > Errdo I get it right, that a possibly vulnerable CPU > (from 2016) is still vulnerable to MELTDOWN but a newer > BIOS *fakes* the CPU flags so the MELTDOWN "detection code" > says, "this CPU is NOT vulnerable" > > Is that right? The newer BIOS inclu

Re: minor too small - pkg_add

2018-03-19 Thread Christian Weisgerber
Patrick Marchand: > I updated to the latest snapshot yesterday and when I run > pkg_add -Dsnap -u a bunch of pkg will not upgrade because it cant find > ssl.44.9 > > It does find 44.8 and 45 but not that specific version, last week I had You updated from a base snapshot that had libssl.so.44.8

Re: Check if fsck will be run on a partition

2018-04-01 Thread Christian Weisgerber
On 2018-04-01, Mik J wrote: > How can I know if the partition needs to be checked by fsck, I'd like to test > that. Check the output of dumpfs. clean=0 means that the filesystem is dirty and fsck should be run. -- Christian "naddy" Weisgerber na...@mips.inka.de

Re: -current amd64 packages not updated? Impatient or broken?

2021-01-07 Thread Christian Weisgerber
Steve Williams: > I hesitate to send this because perhaps I'm just too impatient, but then > again, perhaps not.  This is not critical/time sensitive. > > I just thought I'd check if there a problem with the current packages folder > from the mirrors? No, the amd64 package builds have been sligh

Re: help needed with httpd.conf and rewrite directive

2021-01-07 Thread Christian Weisgerber
On 2021-01-07, John McGuigan wrote: > httpd's regex is based on Lua's, the following site will help you figure it > out: Or, you know, the patterns(7) man page. -- Christian "naddy" Weisgerber na...@mips.inka.de

Re: phonetics on OpenBSD: IPA transcription

2021-01-08 Thread Christian Weisgerber
On 2021-01-08, Jan Stary wrote: > How do I install a font that has glyphs for those symbols? > Is there anything for that in ports? The Dejavu font that is included by default covers IPA. It's unlikely that you need to install anything else. And if you do, just install the Noto fonts and be do

Re: libreoffice package broken in -current 3.509

2021-01-17 Thread Christian Weisgerber
On 2021-01-17, "Nicola Dell'Uomo" wrote: > after upgarding packages from 3.507 to 3.509 in -current, libreoffice > crashes when it starts. This should be fixed with the next amd64 packages snapshot, which will appear sometime on Monday (UTC). -- Christian "naddy" Weisgerber

Re: Help with ssh(1) between OpenBSD and iSH/Alpine on iOS

2021-02-06 Thread Christian Weisgerber
Erling Westenvik: > I can ssh FROM any OpenBSD box INTO iSH on my iPhone, and once > authenticated I can ssh back from there to the OpenBSD box or to any > other OpenBSD or Linux box, but! -- From iSH itself (ie. "directly" from > my iPhone) I can only successfully ssh to Linux boxes; if I ssh fro

Re: Another potential awk or xargs bug?

2021-04-15 Thread Christian Weisgerber
Jordan Geoghegan: > --- /tmp/bad.txt  Wed Apr 14 21:06:51 2021 > +++ /tmp/good.txt  Wed Apr 14 21:06:41 2021 I'll note that no characters have been lost between the two files. Only the order is different. > The only thing that changed between these runs was me using either xargs -P 1 > or -P 2.

Re: default Offset to 1MB boundaries for improved SSD (and Raid Virtual Disk) partition alignment

2021-04-20 Thread Christian Weisgerber
Tom Smyth: > just installing todays snapshot and the default offset on amd64 is 64, > (as it has been for as long as I can remember) It was changed from 63 in 2010. > Is it worth while updating the defaults so that OpenBSD partition > layout will be optimal for SSD or other Virtualized RAID env

Re: default Offset to 1MB boundaries for improved SSD (and Raid Virtual Disk) partition alignment

2021-04-21 Thread Christian Weisgerber
Tom Smyth: > if you were to have a 1MB file or a database that needed to read 1MB > of data, i > f the partitions are not aligned then > your underlying storage system need to load 2 chunks or write 2 > chunks for 1 MB of data, written, You seem to assume that FFS2 would align a 1MB file on an

Re: Firefox: glxteset:libpci missing

2021-05-04 Thread Christian Weisgerber
"Peter N. M. Hansteen": > $ Crash Annotation GraphicsCriticalError: |[0][GFX1-]: glxtest: libpci > missing (t=0.395391) [GFX1-]: glxtest: libpci missing > > firefox runs, so it's not fatal. I suspect it's a misclassified > dependency in the package (build vs runtime). FWIW, I see the same warnin

Re: reposync:host key verification failed

2021-06-06 Thread Christian Weisgerber
On 2021-06-06, Avon Robertson wrote: > reposync: host key verification failed - see > /var/db/reposync/known_hosts > > The same error was then recorded in my log on the 3rd, 4th, 5th, and > 6th of June. The above known_hosts file does not exist on this machine. > The FILES section of reposync(1)

DHCP non-issues

2021-07-19 Thread Christian Weisgerber
Look guys, it's simple. If you want IPv6 (SLAAC) autoconfiguration, you set "inet6 autoconf" for that interface. slaacd(8) will then automatically handle things. If you want IPv4 (DHCP) autoconfiguration, you set "inet autoconf" for that interface. dhcpleased(8) will then automatically handle t

Re: DHCP non-issues

2021-07-19 Thread Christian Weisgerber
Peter J. Philipp: > Would OpenBSD be interested in a daemon that gets nameserver information from > pppoe0 and passes this nameserver information to resolvd(8)? Currently there > is no way to do that, so a userland daemon that uses a bpf device to spy on > pppoe(4) may be worthwhile to write? Is

Re: Problem with nsd not being reloaded.

2023-08-12 Thread Christian Weisgerber
WATANABE Takeo: > I am using nsd, which runs by default on OpenBSD 7.2 amd64. > To update the zone file after changes have been made. > > As far as I could find, restarting the host seems to be > the only way to update the zone information. nsd-control(8) -- Christian "naddy" Weisgerber

Re: SSH from old Mac fail to login via ssh rsa key

2023-10-08 Thread Christian Weisgerber
"Daniele B.": > I went to my Mac (SSH -V: OpenSSH 6.9p1 LibreSSL 2.1.8) and launched > ssh-keygen produced for my my user a nice RSA key. I grabbed it and I > went on my > cloud server (SSH -V: OpenSSH 9.2p1 OpenSSL 3.0.9) and appended it in > my .ssh/authorized_keys. While RSA _keys_ are still s

Re: ETA for 7.4 packages-stable for aarch64?

2023-10-17 Thread Christian Weisgerber
Stephan Somogyi: > aarch64 packages-stable has historically been available; for 7.4 it's > populated for only for amd64, i386, and sparc64 on cdn.openbsd.org and > assorted mirrors. > > Is there an ETA for 7.4 aarch64 packages-stable? Uh, right. They were delayed because of a problem with the m

Re: Reptar aka CVE-2023-23583

2023-11-15 Thread Christian Weisgerber
not jacinda ardern: > I saw something about a new intel microcode coming out (subject line) for a > goofy new bug somebody found. Do you guys package that up into the fw_update > (firmware.openbsd.org) magic or does it only come via the oem's bios updates? Whatever Intel releases. Yesterday th

Re: Why is BRE still around? (Re: Porting shell scripts from Tiny Tools)

2023-11-17 Thread Christian Weisgerber
Marc Chantreux: > But is there another good reason for BRE to be still alive? > (perfomance, simplicity, or anything else). I think it is mostly for historical reasons, but note that BREs are not a strict subset of EREs: BREs allow back-references, EREs do not. The GNU project turned BREs and ER

Re: Why is BRE still around? (Re: Porting shell scripts from Tiny Tools)

2023-11-17 Thread Christian Weisgerber
Marc Chantreux: > I the same mood: I realized recently that no implementation of awk > seems to implement quantifiers which is really desapointing. Awk uses EREs, so if by quantifiers you mean {n,m}, then awk most certainly supports this. -- Christian "naddy" Weisgerber

Re: time keeping fallback mechanics during reboot on octeon

2024-01-12 Thread Christian Weisgerber
Otto Moerbeek: > http://man.openbsd.org/octrtc seems to suggest EdgeRouter does not have > an RTC. A dmesg should give more certainty. I think the original poster is aware of this. If I understand correctly, he expects that on reboot the system clock is restored to the last value from before the

Re: cvs revert specific commit

2024-01-18 Thread Christian Weisgerber
Hrvoje Popovski: > I would like to revert only if_em.c rev. 1.369, but would like to leave > TSO stuff if_em.c rev. 1.370 and if_em.h rev 1.81. > > is this somehow possible? $ cd /sys/dev/pci $ cvs diff -kk -r1.369 -r1.368 if_em.c | patch -p0 -- Christian "naddy" Weisgerber

Re: Entry in the list of UNIX and OpenBSD providers

2024-02-06 Thread Christian Weisgerber
"Theobald, Gerd": > C Germany > P Baden-Wuerttemberg > T Nuremberg > Z D-90411 Nuremberg is not in Baden-Wuerttemberg. -- Christian "naddy" Weisgerber na...@mips.inka.de

Re: lcamtuf on the recent xz debacle

2024-04-04 Thread Christian Weisgerber
Katherine Mcmillan: > Just for clarity, does anyone know what "Unix-like operating systems" > would be affected by this? None. TLDR: The build process of the backdoor explicitly aborts on platforms other than Linux x86-64. As the maintainer of the archivers/xz port, I took a look at the build s

Re: "set -o multiline" in ksh?

2022-08-08 Thread Christian Weisgerber
On 2022-08-08, Federico Giannici wrote: > What I really miss is multiline editing of current (very long) commands > (ksh simply horizontally "scrolls", showing only a part of the command > line). > > I know that in standard ksh this functionality is activated with "set -o > multiline", but und

dump(8) is slow

2022-08-09 Thread Christian Weisgerber
Moving 9TB with dump|restore from an old hard disk to a bigger one reminded me again that dump(8) is, well, slow: DUMP: 9104433830 tape blocks DUMP: Date of this level 0 dump: Sat Aug 6 16:36:52 2022 ... DUMP: Date this dump completed: Tue Aug 9 13:51:01 2022 DUMP: Average transfer ra

Re: cdio(1): cdplay with next and prev

2022-08-09 Thread Christian Weisgerber
On 2022-08-08, Lucian Popescu wrote: > lucian-pc# cdio cdplay > track 1 'a' 0200/00018053 1% > > From another terminal I issue the following command to play the next > song: > > lucian-pc# cdio next #exit code is 0 > > However this does not work. Can I use next and prev with cdplay? The ma

Re: dump(8) is slow

2022-08-09 Thread Christian Weisgerber
Kenneth Gober: > Are you certain that dump(8) is the big bottleneck here? My recollection > is that restore(8) is significantly slower, so of course if restore(8) is systat's default vmstat display shows you the time spend in disk accesses. Typical figures during the dump-restore run were 1.0 f

Re: dump(8) is slow

2022-08-11 Thread Christian Weisgerber
On 2022-08-10, Tomasz Rola wrote: >> DUMP: Date this dump completed: Tue Aug 9 13:51:01 2022 >> DUMP: Average transfer rate: 36530 KB/s >> >> That is far below the read-write speed of a modern SATA drive. > > Ok. But what is a theoretic speed limit for this device? The data sheet claims 2

Re: sndio and bit perfect playback

2022-10-25 Thread Christian Weisgerber
Andre Smagin: > There is possibly one more use case for "bit-perfect". I have a small > collection of surround sound (5.1, 4.1, quad, etc) recordings extracted > from various DVDs, SACDs, and other sources. Yup. I even have a commercially released DTS-CD lying around somewhere, which is basically

Re: less prints superfluous characters with --no-init

2022-11-18 Thread Christian Weisgerber
"Richard Ulmer": > I find this behaviour unexpected: > > $ printf foo | less --no-init | xxd > : 666f 6f1b 5b41 1b5b 4b foo.[A.[K > > less prints ANSI escape codes for 'cursor up' and 'erase in line' at the > end of my message. I cannot reproduce this. $ printf foo |

Re: less prints superfluous characters with --no-init

2022-11-20 Thread Christian Weisgerber
On 2022-11-20, Reuben mac Saoidhea wrote: >> It is a builtin, so it is documented inside ksh. > > i think the 4.3BSD manual allowed for example `man while' for `man sh'? FreeBSD has a builtin(1) man page that attempts to list the csh(1) and sh(1) builtins and points to the respective man pages:

Re: Some NFS clients won't mount

2022-12-29 Thread Christian Weisgerber
"vitmau...@gmail.com": > My /var/log/daemon regarding the issue: > mountd[91001]: Refused mount RPC from host 192.168.1.4 port 57264 The client's mount request didn't come from a reserved port, i.e. <1024. OpenBSD's mountd(8) does not accept this. -- Christian "naddy" Weisgerber

Re: xsnow bitmap include in base?

2023-02-11 Thread Christian Weisgerber
David Rinehart: > After 7.2  install, I see this include file: > >     /usr/X11R6/include/X11/bitmaps/xsnow > > Just curious - With xsnow removed, is this file used for anything? Well, you could use it for something, e.g.: $ xsetroot -bitmap /usr/X11R6/include/X11/bitmaps/xsnow -- Christian

Re: disabling horizontal scroll in ksh

2023-03-19 Thread Christian Weisgerber
sewn: > hi, i've recently switched to ksh and i've been very annoyed by the > horizontal scroll feature (happens when a commmand is longer than the > terminal's width) is there anyway to disable this feature? i would > prefer > to see the whole command, like in bash or ash. That's just the way t

Re: hw RNG on APUs

2023-04-19 Thread Christian Weisgerber
Jan Stary: > Does OpenBSD use any hardware RNG on the PC Engines APUs? ccp0 at pci0 dev 8 function 0 "AMD 16h Crypto" rev 0x00 ccp(4) attaches, so presumably it is used as a source of entropy. Whether the hardware actually provides random output, I don't know. -- Christian "naddy" Weisgerber

Re: hw RNG on APUs

2023-04-19 Thread Christian Weisgerber
Christian Weisgerber: > ccp(4) attaches, so presumably it is used as a source of entropy. > Whether the hardware actually provides random output, I don't know. I built a kernel with an instrumented driver. Unfortunately, no entropy is provided: ccp: rng ccp: rng 00

Re: hw RNG on APUs

2023-04-21 Thread Christian Weisgerber
Christian Weisgerber: > I built a kernel with an instrumented driver. Unfortunately, no > entropy is provided: FWIW, it appears to work on the SoftIron OverDrive 1000: ccp: rng 058f9dad ccp: rng f0a495ba ccp: rng a757bdf7 ccp: rng 31b21d19 ccp: rng d1ce1c78 ccp: rng 863c9199 -- Chr

Re: curl-8.0.1 exists in two non-comparable versions (Someone forgot to bump a REVISION)

2023-04-22 Thread Christian Weisgerber
Andrew Daugherity: > This happened when I ran 'pkg_add -u' after upgrading an i386 system > from 7.2 to 7.3: > Error: curl-8.0.1 exists in two non-comparable versions > Someone forgot to bump a REVISION > It seems that it succeeded in the end, but what happened? Is there a > 7.3-stable curl pkg

Re: hw RNG on APUs

2023-04-23 Thread Christian Weisgerber
Theo de Raadt: > That was in 2022. Lots of people will have machines without new BIOS. I have the latest firmware and the ccp(4) RNG returns nothing but 0. > I wonder if our kernel should have similar code to enable the registers. I tried that yesterday to no effect... but I'm not certain that

Re: sysctl ddb.trigger

2023-05-30 Thread Christian Weisgerber
Paul de Weerd: > Indeed, `sysctl kern.securelevel=-1` allows entering DDB with `sysctl > ddb.trigger=1`. (Yes, I am logged in over serial, and that works > well). That was not clear from the ddb manpage, nor from the > securelevel manpage It's in sysctl(2): DBCTL_TRIGGER (ddb.trigger)

Re: Thinkpad X230t convertible and openbsd

2013-05-24 Thread Christian Weisgerber
Thanos Tsouanas wrote: > > FWIW, the "Intel Centrino Ultimate-N 6300" iwn(4) in my non-t X230 > > works just fine. That's the "3x3" card on their order site. > > Could you please check the exact model and FCC ID of that card? > > "Intel Centrino Ultimate-N 6300" card > (model: 633ANHMW, FCC ID

Re: OpenBSD Doesn't Support 64-Bit Intel

2013-07-03 Thread Christian Weisgerber
Zeljko Jovanovic wrote: > > Is there floating-point hardware for 486 or higher that isn't > "Intel-compatible"? > > > > This text seems superfluous. > > I remember some Weitek floating-point coprocessors from those times - I > suppose > they were not x87 compatible? They weren't. http://www.

Re: luit and crashing xterm

2013-07-03 Thread Christian Weisgerber
Jan Stary wrote: > I understand that the support for the XTerm*locale: ISO8859-2 setting > is achieved by using luit(1). If I comment the locale setting out > (and so don't launch luit and lose the locale support), > these problems disappear. > > This leads me to suspect luit, or the way xterm c

Re: 5.4-beta#20 xterm(1)/luit(1) in cwm, CM-Return random defunc

2013-07-09 Thread Christian Weisgerber
Jan Stary wrote: > > 1) running cwm(1) with having > > 2) ``XTerm*locale:ISO8859-1'' in ~/.Xresources > > 3) hitting CM-Return starts xterm(1) after differing amounts of retries > >(between 1 and 9 up to now). > > http://marc.info/?l=openbsd-misc&m=137287894132390&w=2 > This exact problem w

Re: DVD Video Ripping Tools

2013-07-14 Thread Christian Weisgerber
James Griffin wrote: > I want to rip some DVD's to my hard disk for viewing later. I've > searched and found some old threads going back a few years which have > some good suggestions and examples. As some of this stuff is a bit > dated, can anyone recommend some decent software from packages/por

Re: OpenBSD ipsec performance on modern HW

2013-07-14 Thread Christian Weisgerber
Evgeniy Sudyr wrote: > I need to figure if I can improve isakmpd / ipsec performance in my setup > on openbsd -current > > I have two boxes connected to each other via 1Gbit link and I'm using iperf > to test performance with default ipsec.conf between these two servers: > > # cat ipsec.conf: >

Re: 5.4-beta#20 xterm(1)/luit(1) in cwm, CM-Return random defunc

2013-07-15 Thread Christian Weisgerber
Philip Guenther wrote: > Ha! I believe this bug is a result of posix_openpt() being > implemented in 5.3 and the luit configure script picking that instead > of openpty(), as the code for the former results in the client side > being opened (by PTMGET), then closed, then reopened by name, which

Re: Empty from address confusing MTA/MUA

2013-07-18 Thread Christian Weisgerber
Martin Brandenburg wrote: > I thought it would be appropriate to change OpenSMTPD to reject empty > addresses; however, line 1513 of smtp_session.c specifically accepts > empty addresses. What is the use case of that? Error replies. If the error message cannot be delivered, it will not trigger

Re: 4k-sector drives

2013-07-21 Thread Christian Weisgerber
David Vasek wrote: > I met quite a few flaws when working with 4k-sector drives. I am not sure > if such drives are supported. If they are not supported yet They are supported and I wouldn't expect any "flaws". > Simply put: shall I send any reports concerning 4k-sectors on -cuurent? Yes. --

Re: Hardware backdoors in Lenovo?

2013-07-26 Thread Christian Weisgerber
Tyler Mace wrote: > Do any of you feel like this is a non-story? Or should I reconsider > purchasing Lenovo hardware in the future? > > http://www.afr.com/p/technology/spy_agencies_ban_lenovo_pcs_on_security_HVgcKTHp4bIA4ulCPqC7SL (1) Rumor monging. "Alleged proof that the earth is flat remains

Re: Default software in the base

2013-07-31 Thread Christian Weisgerber
Martin Brandenburg wrote: > xterm supports two terminals, DEC VT100 and Tektronix 4014. Actually, xterm's main emulation target has been the VT220 for many years, and about a year ago the default emulation level has been switched to VT420. -- Christian "naddy" Weisgerber

i386 vs. amd64 OpenSSL performance

2013-08-06 Thread Christian Weisgerber
This came up on soekris-tech, but since I have the figures I might as well post them here, too. If you do lots of crypto by way of OpenSSL's libcrypto, a number of popular algorithms (AES, SHA256, RSA, DSA, ECDSA, ECDH) are significantly faster in amd64 mode than in i386 mode on the same hardware.

Re: Accept two vlans

2013-08-07 Thread Christian Weisgerber
lilit-aibolit wrote: > I'd like to setup guest Wi-Fi in my LAN to prevent access to local > resources. > I have OpenBSD gateway with em NIC connected to LAN. > LAN based on switches with VLAN support. > Suppose I have created two VLANs and added ports from my network > to vlan1 and wi-fi AP to v

Re: 10GbE (Intel X540) performance on OpenBSD 5.3

2013-08-07 Thread Christian Weisgerber
Maxim Khitrov wrote: > What did surprise me is that netstat -ss (output below) shows that all > received packets were hardware-checksummed, but this value is 0 for > sent packets. Does this mean that ix supports checksum offloading, but > only for inbound packets? Obviously, yes. That's exactly

Re: Post-quantum cryptography

2013-08-10 Thread Christian Weisgerber
Mirco Richter wrote: > one may think, if it's time to implement a post quantum asymetric key > cryptographic system. > > Are there any attemptes to do this? Are there discussions which of the > mathematical possible > systems are best in practice and so forth? Are there even implementations, >

Re: ssh/sftp performance

2013-08-21 Thread Christian Weisgerber
Darren Tucker wrote: > > I noticed my CPU supports AES, but not AESNI, so at first, I though that > > that might be using up all my CPU, but that only accounts for for 48% of > > CPU usage. Is there anything else I can do to improve performance? > > Try one of the faster MACs (umac...@openssh.co

Re: ssh/sftp performance

2013-08-22 Thread Christian Weisgerber
Hugo Osvaldo Barrera wrote: > Sadly, my hardware doesn't support AESNI. > Would something like a Soekris 1401(hifn) make up for that, or am I mixing > stuff up? Crypto devices outside the CPU aren't that great. For each en-/decryption, the device needs to be set up, the data moved to and the re

Re: Patch for a little install.sub bug

2013-08-24 Thread Christian Weisgerber
Loïc BLOT wrote: > if [[ $resp == y ]]; then > ask_which "speed" "should $_d use" \ > "9600 19200 38400 57600 115200" $CSPEED > case $resp in > done) defcons=n ;; >

Re: Compiling BOINC/Seti@Home for OpenBSD 5.3 Sparc64

2013-08-29 Thread Christian Weisgerber
Richard Thornton wrote: > My Sun Blade 100, has a fresh install of 5.3, and its very good, much > better than 5.1; XFCE is very stable and R is much better than prior > ports. you guys did a great job! Now this computer sits running actively, > with nothing to do! Use apm -L or -C and save 10

Re: cvsync, rsync

2013-09-14 Thread Christian Weisgerber
wrote: > Does rsync suppose that a part of a file in the server is equal to > a part of a file in the client, if a hash value of these parts are > equal? Yes. > Does cvsync do the same? (Embarrassingly, I don't actually remember how cvsync works in detail.) > Is this reliable? In practice, y

Re: cvsync, rsync

2013-09-16 Thread Christian Weisgerber
Raimo Niskanen wrote: > A resembling application is the Git version control system that is > based on the assumption that all content blobs can be uniquely > decribed by their 128-bit SHA1 hash value. ^ ... 160-bit SHA1 hash... -- Christian "naddy" Weisgerber

Re: ipsec outgoing address translation question

2013-09-16 Thread Christian Weisgerber
Christoph Leser wrote: > with ipsecctl I can configure outgoing address translation in > ipsec.conf like this: > > ike esp from 10.10.10.1 (192.168.1.0/24) to 192.168.2.0/24 > peer 10.10.20.1 > > Is there an equivalent syntax for isakmpd.conf? All that ipsecctl does with ike rules i

Re: cvsync, rsync

2013-09-19 Thread Christian Weisgerber
Since I mentioned the likelihood of a non-recoverable disk error, here's a terrific paper that should make everbody sleep very poorly: "An Analysis of Data Corruption in the Storage Stack" http://www.cs.toronto.edu/~bianca/papers/fast08.pdf -- Christian "naddy" Weisgerber

Re: cvsync, rsync

2013-09-19 Thread Christian Weisgerber
Mihai Popescu wrote: > > "An Analysis of Data Corruption in the Storage Stack" > > http://www.cs.toronto.edu/~bianca/papers/fast08.pdf > > They claim the paper is based on 1.53 million disk drives. > It is interesting they were able to access such a number. The paper is based on NetApp data. -

Re: key precedence in ssh

2013-10-01 Thread Christian Weisgerber
Lars Noodén wrote: > Is there a way in ssh(1) to get the identity specified by -i to take > precedence over what is already in the agent? IdentitiesOnly, see ssh_config(5). -- Christian "naddy" Weisgerber na...@mips.inka.de

Re: why icmp timestamping is enabled by default ?

2013-10-11 Thread Christian Weisgerber
wrote: > actually, I'm not going to block icmp at all, I was curious why > net.inet.icmp.tstamprepl=1 by default. So you can run timed, of course. As others have said, the time is not a secret. -- Christian "naddy" Weisgerber na...@mips.inka.de

Re: Chromium package missing from amd64 snapshots

2013-10-19 Thread Christian Weisgerber
Fred wrote: > chromium seems to have disappeared from amd64 snapshots packages directory. > Is this a known issue? Speaking as the amd64 package builder: It appears to not have been built during the latest snapshot build. There is no obvious reason in the logs. It should reappear with the next

Re: RJ11 on Alix 2d13 with OpenBSD

2013-11-06 Thread Christian Weisgerber
Chris Cappuccio wrote: > Mr. Pugsley, an ethernet NIC includes a Modulator and Demodulator for > any of 10BaseT, 100BaseTX, 1000BaseT, 1BaseThingies, fiber versions > of the same, and so on. Wait, wait, Ethernet is baseband, so there is no (de)modulator. -- Christian "naddy" Weisgerber

Re: Mount CD/DVD and playback DVD as normal user

2013-11-13 Thread Christian Weisgerber
Laurence Rochfort wrote: > What are the consequences of putting myself in the operator group? Members of group operator may * run shutdown(8), * read disk devices--intended for backups with dump(8), but of course it means that members can bypass any filesystem-permission-based read restricti

Re: [OT] Loongson hardware in Europe

2013-11-13 Thread Christian Weisgerber
ropers wrote: > Having long wanted to run http://www.openbsd.org/loongson.html, I've > just seen that the main EU vendor of Loongson/Lemote/Yeeloong has > finally -temporarily, they say- significantly cut the hitherto > relatively high cost of these machines. > I'm not going to spam the URL, but

Re: CARP with a single public IP address

2008-12-05 Thread Christian Weisgerber
Paul de Weerd <[EMAIL PROTECTED]> wrote: > So I'd disagree with your 'by definition' (given the counterexample), > but sadly there is not enough native v6 around and we have to resort > to nasty hacks (tunneling). As much as I appreciate the likes of > SixXS, I really wish they were not required a

Re: ahci questions

2008-12-05 Thread Christian Weisgerber
frantisek holop <[EMAIL PROTECTED]> wrote: > "Implementation of the Advanced Host Controller Interface > Specification requires a license from Intel." If you build a chipset with an AHCI interface, you need a license. Chip design is outside the purview of OpenBSD, I think. > my last

Re: CARP with a single public IP address

2008-12-05 Thread Christian Weisgerber
Paul de Weerd <[EMAIL PROTECTED]> wrote: > | In a world where PPP-over-Ethernet-over-ATM is the norm, adding an > | "IPv6 transport protocol" layer isn't all that absurd. > > Please tell ISP's ;) I meant "IPv6 transport protocol" == IPv4. -- Christian "naddy" Weisgerber

Re: pf drops fragged IPv6 unconditionally

2008-12-05 Thread Christian Weisgerber
Todd T. Fries <[EMAIL PROTECTED]> wrote: > but .. the bottom line is, 'pf' only has support for reassembling > IPv4 fragments, not IPv6. And yes, this renderes a stateful filtering > firewall mostly moot until this is fixed for IPv6, to be clear. If you can get by with TCP... > Theory suggests

Re: slow read/write performance with compact flash at PCMCIA

2008-12-11 Thread Christian Weisgerber
Michael wrote: > I've got me a PCMICA adapter for compact flash cards. It is recognized > and basically works, but the read/write performance is really bad. Yes. These purely mechanical adapters don't support DMA and all data must be transferred by the CPU with very, very slow accesses (8 MHz I

azalia: >16-bit audio?

2008-12-14 Thread Christian Weisgerber
Something of an idle question: According to audioctl, my azalia device only supports 16-bit audio, but according to the data sheet the codec also offers 20- and 24-bit audio. Are there any plans to add support for this? No, I have no idea what you would actually use this for. In particular, I do

Re: package integrity, security and checks. .... where are they ?

2008-12-17 Thread Christian Weisgerber
Jacob Yocom-Piatt wrote: > the next best option i can think of is to have the hashes (sha256 and/or > others) fetched via ssh from a trusted site, e.g. your nearest anoncvs > server. it avoids the gnupg requirement but is still susceptible to mitm > on key fingerprints, etc. if you can't trust

pppoe not reconnecting

2008-12-20 Thread Christian Weisgerber
Every few weeks...months, the PPPoE session for my ADSL line goes away (some time during the night) and is not reestablished. The corresponding pppoe interface is down, state "initial", a number of PADIs have been sent, but no further retries seem to be happening. When I become aware of the proble

Re: pppoe not reconnecting

2008-12-23 Thread Christian Weisgerber
Toni Mueller wrote: > I have installed cron jobs, though, which detect the situation and > try to speed up recovery by killing the (probably) wegded pppoe and ppp > programs, and run this every one or two minutes. I guess I should have been clearer, but I've been talking about pppoe(4), i.e., ke

Re: Transport Mode ipsec(4) and inet6(4) gre(4)

2008-12-25 Thread Christian Weisgerber
Brian A. Seklecki wrote: > I haven't looked if we have support, but gre(4) w/ ipv6 address and stf(4) > seem to be best options out there for secure v6 tunnels. That sounds... bizarre. > I'm wondering if a tranditional ipv6 isakmp(8) ipsec tunnel (using IPv4 > enpoints?!) is a safe alternativ

Re: uxterm and backspace

2008-12-29 Thread Christian Weisgerber
Jan Johansson wrote: > start an "uxterm" > > I then run cat and type four swedish characters and then try to > backspace two of them. The display is updated correctly but > hitting enter shows that only one of the characters was erased. Yes. Those "Swedish characters" are encoded as two-byte s

SSH cipher preference change (was: Re: CVS: cvs.openbsd.org: src)

2009-01-23 Thread Christian Weisgerber
Damien Miller wrote: > Modified files: > usr.bin/ssh: myproposal.h > > Log message: > prefer CTR modes and revised arcfour (i.e w/ discard) modes to CBC > modes; ok markus@ This means that ssh's default cipher will no longer profit from hifn(4) or glxsb(4) acceleration. People relyi

Re: isakmpd does not initiate quick mode after main mode is established

2009-01-25 Thread Christian Weisgerber
Christoph Leser wrote: > I'm still struggling to keep my ipsec vpns running smoothly. FWIW, I mostly use IPsec on my home WLAN and I observe a similar lack of reliability. My laptop sets up two IPsec associations, one IPv4 and one IPv6, and from time to time one of these or both fail inexplicab

Re: packer for C++ Executbales

2009-01-28 Thread Christian Weisgerber
new_guy wrote: > I searched the packages list, but did not see any. Does anyone use a packer > such as UPX on OpenBSD? 1. No. 2. There is gzexe(1). -- Christian "naddy" Weisgerber na...@mips.inka.de

Re: ntp strangeness

2009-01-30 Thread Christian Weisgerber
Steve Laurie wrote: > I have one machine setup as a NTP server and another setup as couple of > others setup as NTP clients. > > I ran tcpdump on the server listening for packets from 224.0.1.1 to know > when it's transmitting, on the default router machine that's running pf as > well > as on t

Re: ntp strangeness

2009-01-30 Thread Christian Weisgerber
Alexander Yurchenko: > > > I ran tcpdump on the server listening for packets from 224.0.1.1 to know > > > when it's transmitting, > > > > OpenBSD's ntpd doesn't use multicast. What the heck are you talking > > about? > > may be PTP. No, 224.0.1.1 is NTP, alright. PTP defaults to 224.0.1.129.

Re: Vlan Tag on Vlan Tag (l2tunneling)

2009-02-18 Thread Christian Weisgerber
Sam Fourman Jr. wrote: > > here is another approach defining QinQ-compliant interfaces as a new > > cloner type; so you can stack 0x88a8 devices as you wish and it > > doesn't need a new button in ifconfig. > > I have looked in the cvs commit logs, and I am unable to determine if > this patch wa

Re: VLAN Priority/802.1p

2009-02-26 Thread Christian Weisgerber
Insan Praja SW wrote: > I understand that we can have vlan priority on vlan interfaces. Yes. It should work, but it has seen little testing. > My question is, can OpenBSD process these 802.1p tags for CoS/QoS purposes? > In PF we can mark/tag/process traffic by its DSCP code. Can we do >

Re: nroff -mandoc alternative

2009-03-01 Thread Christian Weisgerber
Kristaps DE>onsons wrote: > Hello, if anybody's interested in an alternative to groff for viewing > BSD "mdoc" manual pages, I'm actively looking for patches and problem > reports for mdocml. From the site : Does this also handle man(7) or only mdoc(7)? -- Christian "na

Re: Parallel build in ports - make -j4

2009-03-26 Thread Christian Weisgerber
Marc Espie wrote: > > > export PARALLEL_BUILD=Yes > > > export MAKE_JOBS=4 > > > > N.B. this does not work with all ports. > > Yep, does not work with all ports. And I still have stuff I need to fix > in make itself before we even think of fixing the ports that don't work I'm not happy with th

Re: European orders

2009-03-31 Thread Christian Weisgerber
Daniel Seuffert wrote: > Isn't there any OpenBSD guy defending Mr. Wim Vandeputte, a man > having promoted OpenBSD year in and year out and having supported the > project in Europe like nobody else probably? As you probably know, I've been behind the counter at Wim's booth many times. All this

<    1   2   3   4   5   6   7   8   9   >