Re: xhci isochronous transfers

2019-03-16 Thread Nam Nguyen


> This procedure is sufficient when I use a USB 2 port.

I forgot to test USB 2 at the time of my original e-mail. There is
actually a regression and both USB 2 and USB 3 ports throw the same
error.

--8<---cut here---start->8---
uaudio0: can't get iface handle
uaudio0: can't get iface handle
audio1: failed to start playback
uaudio0: can't get iface handle
--8<---cut here---end--->8---



Re: xhci isochronous transfers

2019-03-16 Thread Nam Nguyen


Thank you for all the work that went into this.

I am testing USB 3 on a Thinkpad x230i for my headphone DAC, an
ODAC-revB. I tested a Youtube video, and it does not begin playback. The
relevant error is at the end of the pasted dmesg. I also tested this on
a Thinkpad X1 Carbon Gen 4 to the same result, but that dmesg is omitted
for brevity.

I tried setting sndiod to use the DAC, as described in the FAQs
(https://www.openbsd.org/faq/faq13.html#confaudio). This procedure is
sufficient when I use a USB 2 port.
--8<---cut here---start->8---
# rcctl set sndiod flags -f rsnd/1
# rcctl restart sndiod
--8<---cut here---end--->8---

full dmesg:
--8<---cut here---start->8---
OpenBSD 6.5-beta (GENERIC.MP) #798: Sat Mar 16 10:12:15 MDT 2019
dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 16872108032 (16090MB)
avail mem = 16350453760 (15593MB)
mpath0 at root
scsibus0 at mpath0: 256 targets
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 2.7 @ 0xdae9d000 (69 entries)
bios0: vendor LENOVO version "G2ET33WW (1.13 )" date 07/24/2012
bios0: LENOVO 2306CTO
acpi0 at bios0: rev 2
acpi0: sleep states S0 S3 S4 S5
acpi0: tables DSDT FACP SLIC TCPA SSDT SSDT SSDT HPET APIC MCFG ECDT FPDT ASF! 
UEFI UEFI POAT SSDT SSDT UEFI
acpi0: wakeup devices LID_(S4) SLPB(S3) IGBE(S4) EXP3(S4) XHCI(S3) EHC1(S3) 
EHC2(S3) HDEF(S4)
acpitimer0 at acpi0: 3579545 Hz, 24 bits
acpihpet0 at acpi0: 14318179 Hz
acpimadt0 at acpi0 addr 0xfee0: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz, 2494.75 MHz, 06-3a-09
cpu0: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,XSAVE,AVX,F16C,NXE,RDTSCP,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS,IBRS,IBPB,STIBP,L1DF,SSBD,SENSOR,ARAT,XSAVEOPT,MELTDOWN
cpu0: 256KB 64b/line 8-way L2 cache
cpu0: smt 0, core 0, package 0
mtrr: Pentium Pro MTRR support, 10 var ranges, 88 fixed ranges
cpu0: apic clock running at 99MHz
cpu0: mwait min=64, max=64, C-substates=0.2.1.1.2, IBE
cpu1 at mainbus0: apid 2 (application processor)
cpu1: Intel(R) Core(TM) i3-3120M CPU @ 2.50GHz, 2494.34 MHz, 06-3a-09
cpu1: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,XSAVE,AVX,F16C,NXE,RDTSCP,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS,IBRS,IBPB,STIBP,L1DF,SSBD,SENSOR,ARAT,XSAVEOPT,MELTDOWN
cpu1: 256KB 64b/line 8-way L2 cache
cpu1: smt 0, core 1, package 0
ioapic0 at mainbus0: apid 2 pa 0xfec0, version 20, 24 pins
acpimcfg0 at acpi0
acpimcfg0: addr 0xf800, bus 0-63
acpiec0 at acpi0
acpiprt0 at acpi0: bus 0 (PCI0)
acpiprt1 at acpi0: bus -1 (PEG_)
acpiprt2 at acpi0: bus 2 (EXP1)
acpiprt3 at acpi0: bus 3 (EXP2)
acpiprt4 at acpi0: bus -1 (EXP3)
acpicpu0 at acpi0: C2(350@80 mwait.1@0x20), C1(1000@1 mwait.1), PSS
acpicpu1 at acpi0: C2(350@80 mwait.1@0x20), C1(1000@1 mwait.1), PSS
acpipwrres0 at acpi0: PUBS, resource for XHCI, EHC1, EHC2
acpitz0 at acpi0: critical temperature is 103 degC
acpibtn0 at acpi0: LID_
acpibtn1 at acpi0: SLPB
acpipci0 at acpi0 PCI0: 0x 0x0011 0x0001
acpicmos0 at acpi0
tpm0 at acpi0: TPM_ addr 0xfed4/0x5000: device 0x104a rev 0x4e
acpibat0 at acpi0: BAT0 model "45N1023" serial  4025 type LION oem "SANYO"
acpiac0 at acpi0: AC unit online
acpithinkpad0 at acpi0
"PNP0C14" at acpi0 not configured
"PNP0C14" at acpi0 not configured
acpidock0 at acpi0: GDCK not docked (0)
acpivideo0 at acpi0: VID_
acpivout at acpivideo0 not configured
acpivideo1 at acpi0: VID_
cpu0: Enhanced SpeedStep 2494 MHz: speeds: 2500, 2400, 2300, 2200, 2100, 2000, 
1900, 1800, 1700, 1600, 1500, 1400, 1300, 1200 MHz
pci0 at mainbus0 bus 0
pchb0 at pci0 dev 0 function 0 "Intel Core 3G Host" rev 0x09
inteldrm0 at pci0 dev 2 function 0 "Intel HD Graphics 4000" rev 0x09
drm0 at inteldrm0
inteldrm0: msi
inteldrm0: 1366x768, 32bpp
wsdisplay0 at inteldrm0 mux 1: console (std, vt100 emulation)
wsdisplay0: screen 1-5 added (std, vt100 emulation)
xhci0 at pci0 dev 20 function 0 "Intel 7 Series xHCI" rev 0x04: msi, xHCI 1.0
usb0 at xhci0: USB revision 3.0
uhub0 at usb0 configuration 1 interface 0 "Intel xHCI root hub" rev 3.00/1.00 
addr 1
"Intel 7 Series MEI" rev 0x04 at pci0 dev 22 function 0 not configured
em0 at pci0 dev 25 function 0 "Intel 82579LM" rev 0x04: msi, address 
3c:97:0e:36:95:a5
ehci0 at pci0 dev 26 function 0 "Intel 7 Series USB" rev 0x04: apic 2 int 16
usb1 at ehci0: USB revision 2.0
uhub1 at usb1 configuration 1 interface 0 "Intel EHCI root hub" rev 2.00/1.00 
addr 1
azalia0 at pci0 dev 27 function 0 "Intel 7 Series HD Audio" rev 0x04: msi
azalia0: codecs: Realtek ALC269, 

Re: pppoe(4) and vlan(4)

2019-03-16 Thread Thomas Huber
Hi,

I just setup two of the mentioned xDSL-modem and now everything works
almost fine now.
It took a while to find proper modem settings (VPI,VCI, VLAN, VLAN-Prio)
for my ISP, donĀ“t know if it is import for the OP.
If someone is interested I can provide further details.
Now i do the pppoe in OpenBSD and everything else like VLAN-tagging etc.
with the modem in bridge-mode.

Thanks again for your help
Thomas


On Tue, 5 Mar 2019 at 22:22, Thomas Huber  wrote:

> I hooked two ADSLlinks now with a modem-router (aka. Fritzbox) which do
> the pppoe part for now.
> I also orderd a newer version of my xDSL-Modem (ALLNET BM200VDSL2V), that
> should be able to do the vlan tagging.
> I let you know how things work out when everything is in place.
>
> I start  a new thread about pf load-blancer configuration...
>
> Thanks again for your support.
> Thomas
>
>
> On Tue, 26 Feb 2019 at 22:13, Thomas Huber  wrote:
>
>> hmmm just played around and for ADSL-link 1 and 2 which are provided by
>> the Deutsche Telekom it is not important if it is chap or pap, works both.
>>
>>
>>
>>
>> On Tue, 26 Feb 2019 at 16:59, Stuart Henderson 
>> wrote:
>>
>>> On 2019/02/26 16:38, Sebastian Benoit wrote:
>>> > Thomas Huber(miracu...@gmail.com) on 2019.02.26 14:22:33 +0100:
>>> > > with chap the tcpdump looks like this:
>>> > >
>>> > > #tcpdump -nevvs1500 -i vlan0
>>> > > tcpdump: listening on vlan0, link-type EN10MB
>>> > > 13:54:44.118903 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>>> PPPoE-Session
>>> > > code Session, version 1, type 1, id 0x00a9, length 16
>>> > > LCP Configure-Request Id=0x24: Magic-Number=98519
>>> > > Max-Rx-Unit=1492
>>> > > 13:54:49.120414 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>>> PPPoE-Session
>>> > > code Session, version 1, type 1, id 0x00a9, length 16
>>> > > LCP Configure-Request Id=0x25: Magic-Number=98519
>>> > > Max-Rx-Unit=1492
>>> > > 13:54:55.122239 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>>> PPPoE-Session
>>> > > code Session, version 1, type 1, id 0x00a9, length 16
>>> > > LCP Configure-Request Id=0x26: Magic-Number=98519
>>> > > Max-Rx-Unit=1492
>>> > > 13:55:02.124396 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>>> PPPoE-Session
>>> > > code Session, version 1, type 1, id 0x00a9, length 16
>>> > > LCP Configure-Request Id=0x27: Magic-Number=98519
>>> > > Max-Rx-Unit=1492
>>> > > 
>>> > >
>>> > > but no connection esblished.
>>> > >
>>> > > On Tue, 26 Feb 2019 at 13:02, Stuart Henderson 
>>> wrote:
>>> > >
>>> > > > On 2019/02/26 12:36, Thomas Huber wrote:
>>> > > > > Hi Stuart,
>>> > > > >
>>> > > > > and thanks for your help.
>>> > > > > I tried yout suggestion but didn??t solve the problem.
>>> > > > > here is the tcpdump output (i just stripped the account
>>> credentials) but
>>> > > > I can not read it.
>>> > > > > Maybe you can spot something here:
>>> > > > >
>>> > > > > # tcpdump -nevvs1500 -i em0
>>> > > > > tcpdump: listening on em0, link-type EN10MB
>>> > > >
>>> > > > Reformatted a bit:
>>> > > >
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xf6:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > JUNIPER -> OPENBSD: LCP Configure-Request Id=0xab: Max-Rx-Unit=1492
>>> > > > Auth-Prot=PAP Magic-Number=526788746
>>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xf6:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Ack Id=0xab: Max-Rx-Unit=1492
>>> > > > Auth-Prot=PAP Magic-Number=526788746
>>> > > > OPENBSD -> JUNIPER: PAP Authenticate-Request Id=0xf7: Peer-Id=
>>> > > > Passwd=
>>> > > > OPENBSD -> JUNIPER: PAP Authenticate-Request Id=0xf8: Peer-Id=
>>> > > > Passwd=
>>> > > > JUNIPER -> OPENBSD: LCP Configure-Request Id=0x02: Max-Rx-Unit=1492
>>> > > > Auth-Prot=CHAP/MD5 Magic-Number=3828540274
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Nak Id=0x02: Auth-Prot=PAP
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xf9:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xf9:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfa:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfa:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfb:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfb:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfc:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfc:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfd:
>>> Magic-Number=1818005467
>>> > > > Max-Rx-Unit=1492
>>> > > > JUNIPER -> 

Re: xhci isochronous transfers (was: Re: CVS: cvs.openbsd.org: src)

2019-03-16 Thread Solene Rapenne
On Sat, Mar 16, 2019 at 12:38:09PM -, Christian Weisgerber wrote:
> On 2019-03-15, Patrick Wildt  wrote:
> 
> > CVSROOT:/cvs
> > Module name:src
> > Changes by: patr...@cvs.openbsd.org 2019/03/15 17:20:35
> >
> > Modified files:
> > sys/dev/usb: xhci.c 
> >
> > Log message:
> > Improve and enable isochronous transfers in xhci(4). [...]
> 
> Wow, that appears to be the crucial step many people have been
> waiting for.  With this, I can now play sound through my USB audio
> dongle connected to a "new" (~5-year old) machine:
> 
> usb0 at xhci0: USB revision 3.0
> uhub0 at usb0 configuration 1 interface 0 "Intel xHCI root hub" rev 3.00/1.00 
> addr 1
> ..
> uaudio0 at uhub0 port 9 configuration 1 interface 1 "C-Media INC. USB Sound 
> Device" rev 1.10/0.10 addr 4
> uaudio0: class v1, full-speed, sync, channels: 2 play, 0 rec, 4 ctls audio1 
> at uaudio0
> 
> -- 
> Christian "naddy" Weisgerber  na...@mips.inka.de
> 

On my T480 with usb3 only, I can now:

- use the built in webcam
- use an usb webcam
- use the usb phone tethering (lineageos) with urndis0

Thanks!



Re: iked road warrior setup with multiple clients connecting

2019-03-16 Thread Michael Lam
Hi,

Just want to give a pump here to see if anyone get this resolved.

Rgds,

Michael

> On 1 Mar 2019, at 8:24 PM, Michael Lam  wrote:
> 
> 
> 
>> On 1 Mar 2019, at 6:42 AM, Stuart Henderson  wrote:
>> 
>> On 2019-02-28, Michael Lam  wrote:
>>> Just want to highlight that there is a FAQ document checked in that
>>> provides some samples of iked configurations for road-warrior setup.
>>> 
>>> I am using almost the same setup provided in the sample, and I can only
>>> have one client connected at a time. Once the 2nd client connects it
>>> will stop the first client from working.
>>> 
>>> Hope this helps with others until it is fixed.
>> 
>> Note that the new FAQ page for VPNs is still a work in progress.
>> (In particular I think that the "OpenBSD as client" section which
>> tries to work around iked's lack of client side mode-config support
>> is not entirely correct yet).
> 
> Unfortunately in my setup OpenBSD is the server so probably mode-config
> support doesn't matter to me. Guess I still have to wait. With 6.5 coming
> maybe I will have to wait for 6.6 or pull from CVS when this get fixed (
> If it is a bug not my misconfiguration). 
> 
>> 
 Also responding to another user (due to some issue I can only get the
 mailing list emails fixed.) 
 
 I use a Letsencrypt certificate by doing the following:
 1. Copying the root certificate file from /etc/ssl/cert.pem (provided by
 OpenBSD into "ca" folder.
 2. Putting the certificate file obtained from Letsencrypt into "cert" 
 folder
 under iked folder.
 3. Putting the full chain certificate file into the "ca" folder.
>> 
>> Interesting. I guess Apple works a bit differently to strongswan
>> in this respect then, perhaps it auto-fetches intermediates (like
>> gui web browsers do for https, but curl/etc don't).
>> 
>> The problem I'm having with a Let's Encrypt cert (or indeed any cert
>> that requires an intermediate - before I tried LE I was using an
>> internal "VPN CA" chained off my main internal CA) is that iked
>> doesn't present the chain alongside its own certificate. You can
>> have it send the chain cert along with CAs by including it in the
>> ca/ directory but clients aren't looking there to validate the
>> server cert.
>> 
>> I think that's just missing from the implementation for now,
>> but I was interested to hear that you had it working anyway.
>> 
>> Including the entirety of /etc/ssl/cert.pem in the ca/ folder isn't
>> doing anything useful, this is just meant to be the CA you are using,
>> and is used to provide a hint to the client about which client cert
>> would be acceptable. With a big list that's a big chunk of UDP
>> fragments, and for EAP-MSCHAPv2 (which doesn't even use a client
>> cert) it doesn't help.
>> 
>> 
> To this particular point (copying /etc/ssl/cert.pem into ca/ folder),
> If I recall correctly without this I couldn't get it working as iked
> will complaint that my letsencrypt certificate is not valid.
> 
> However I couldn't confirm for sure at the moment as I've already
> reverted to a IPSec/L2TP VPN using napped.
> 
> And yes I only tested iOS devices (that's all I got). The problem
> still exist is that I can't have more than 1 client connected at
> one time.



xhci isochronous transfers (was: Re: CVS: cvs.openbsd.org: src)

2019-03-16 Thread Christian Weisgerber
On 2019-03-15, Patrick Wildt  wrote:

> CVSROOT:  /cvs
> Module name:  src
> Changes by:   patr...@cvs.openbsd.org 2019/03/15 17:20:35
>
> Modified files:
>   sys/dev/usb: xhci.c 
>
> Log message:
> Improve and enable isochronous transfers in xhci(4). [...]

Wow, that appears to be the crucial step many people have been
waiting for.  With this, I can now play sound through my USB audio
dongle connected to a "new" (~5-year old) machine:

usb0 at xhci0: USB revision 3.0
uhub0 at usb0 configuration 1 interface 0 "Intel xHCI root hub" rev 3.00/1.00 
addr 1
...
uaudio0 at uhub0 port 9 configuration 1 interface 1 "C-Media INC. USB Sound 
Device" rev 1.10/0.10 addr 4
uaudio0: class v1, full-speed, sync, channels: 2 play, 0 rec, 4 ctls audio1 at 
uaudio0

-- 
Christian "naddy" Weisgerber  na...@mips.inka.de



Re: Creation of fifth dev/tun fails

2019-03-16 Thread Paul de Weerd
On Sat, Mar 16, 2019 at 12:46:36PM +0100, Florian wrote:
| Good afternoon,
| 
| I tried to add a fifth tun interface. ifconfig tun4 create creates a new
| interface visible via ifconfig, however there is no device node under
| dev. Is there a limitation of tun devices? I was able to create tun0 to
| tun3 without any issues.

cd /dev && doas sh MAKEDEV tun4

Cheers,

Paul 'WEiRD' de Weerd

| Thank you for you help.
| 
| Kind regards,
| 
| Florian
| 
| 

-- 
>[<++>-]<+++.>+++[<-->-]<.>+++[<+
+++>-]<.>++[<>-]<+.--.[-]
 http://www.weirdnet.nl/ 



Creation of fifth dev/tun fails

2019-03-16 Thread Florian
Good afternoon,

I tried to add a fifth tun interface. ifconfig tun4 create creates a new
interface visible via ifconfig, however there is no device node under
dev. Is there a limitation of tun devices? I was able to create tun0 to
tun3 without any issues.


Thank you for you help.

Kind regards,

Florian