Hotplug USB bug with pcscd

2020-10-08 Thread Tristan Pilat
@1 mwait.1), PSS
acpicpu7 at acpi0: C3(200@1034 mwait.1@0x60), C2(200@151 mwait.1@0x33), 
C1(1000@1 mwait.1), PSS
acpipwrres0 at acpi0: PUBS, resource for XHC_
acpitz0 at acpi0: critical temperature is 128 degC
acpivideo0 at acpi0: GFX0
acpivout0 at acpivideo0: DD1F
cpu0: using VERW MDS workaround (except on vmm entry)
cpu0: Enhanced SpeedStep 1334 MHz: speeds: 1801, 1800, 1700, 1600, 1500, 1400, 
1300, 1200, 1100, 1000, 900, 800, 700, 600, 500, 400 MHz
pci0 at mainbus0 bus 0
pchb0 at pci0 dev 0 function 0 "Intel Core 8G Host" rev 0x08
inteldrm0 at pci0 dev 2 function 0 "Intel UHD Graphics 620" rev 0x07
drm0 at inteldrm0
inteldrm0: msi, KABYLAKE, gen 9
"Intel Core 6G Thermal" rev 0x08 at pci0 dev 4 function 0 not configured
"Intel Core GMM" rev 0x00 at pci0 dev 8 function 0 not configured
xhci0 at pci0 dev 20 function 0 "Intel 100 Series xHCI" rev 0x21: msi, xHCI 1.0
usb0 at xhci0: USB revision 3.0
uhub0 at usb0 configuration 1 interface 0 "Intel xHCI root hub" rev 3.00/1.00 
addr 1
pchtemp0 at pci0 dev 20 function 2 "Intel 100 Series Thermal" rev 0x21
"Intel 100 Series MEI" rev 0x21 at pci0 dev 22 function 0 not configured
ppb0 at pci0 dev 28 function 0 "Intel 100 Series PCIE" rev 0xf1
pci1 at ppb0 bus 2
ppb1 at pci0 dev 28 function 2 "Intel 100 Series PCIE" rev 0xf1: msi
pci2 at ppb1 bus 59
iwm0 at pci2 dev 0 function 0 "Intel Dual Band Wireless-AC 8265" rev 0x78, msi
ppb2 at pci0 dev 28 function 4 "Intel 100 Series PCIE" rev 0xf1: msi
pci3 at ppb2 bus 60
nvme0 at pci3 dev 0 function 0 "Intel NVMe" rev 0x03: msix, NVMe 1.3
nvme0: INTEL SSDPEKKF256G8L, firmware L08P, serial BTHH83920940256B
scsibus1 at nvme0: 2 targets, initiator 0
sd0 at scsibus1 targ 1 lun 0: 
sd0: 244198MB, 512 bytes/sector, 500118192 sectors
pcib0 at pci0 dev 31 function 0 "Intel 200 Series LPC" rev 0x21
"Intel 100 Series PMC" rev 0x21 at pci0 dev 31 function 2 not configured
azalia0 at pci0 dev 31 function 3 "Intel 200 Series HD Audio" rev 0x21: msi
azalia0: codecs: Realtek/0x0257, Intel/0x280b, using Realtek/0x0257
audio0 at azalia0
ichiic0 at pci0 dev 31 function 4 "Intel 100 Series SMBus" rev 0x21: apic 2 int 
16
iic0 at ichiic0
em0 at pci0 dev 31 function 6 "Intel I219-V" rev 0x21: msi, address 
e8:6a:64:49:56:f5
isa0 at pcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5 irq 1 irq 12
pckbd0 at pckbc0 (kbd slot)
wskbd0 at pckbd0: console keyboard
pms0 at pckbc0 (aux slot)
wsmouse0 at pms0 mux 0
wsmouse1 at pms0 mux 0
pms0: Synaptics clickpad, firmware 8.16, 0x1e2b1 0x940300 0x373540 0xf002a3 
0x12e800
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
vmm0 at mainbus0: VMX/EPT
efifb at mainbus0 not configured
ugen0 at uhub0 port 3 "Generic EMV Smartcard Reader" rev 2.01/1.20 addr 2
umb0 at uhub0 port 6 configuration 1 interface 0 "FIBOCOM L830-EB-00" rev 
2.00/3.33 addr 3
umodem0 at uhub0 port 6 configuration 1 interface 2 "FIBOCOM L830-EB-00" rev 
2.00/3.33 addr 3
umodem0: data interface 3, has no CM over data, has break
umodem0: status change notification available
ucom0 at umodem0
uvideo0 at uhub0 port 8 configuration 1 interface 0 "Chicony Electronics Co.,Ltd. 
Integrated Camera" rev 2.01/0.27 addr 4
video0 at uvideo0
umass0 at uhub0 port 15 configuration 1 interface 0 "Generic USB3.0-CRW" rev 
3.00/2.04 addr 5
umass0: using SCSI over Bulk-Only
scsibus2 at umass0: 2 targets, initiator 0
sd1 at scsibus2 targ 1 lun 0:  removable 
serial.0bda031650103090
vscsi0 at root
scsibus3 at vscsi0: 256 targets
softraid0 at root
scsibus4 at softraid0: 256 targets
sd2 at scsibus4 targ 1 lun 0: 
sd2: 244197MB, 512 bytes/sector, 500116577 sectors
root on sd2a (1bb8f3f0118bc7f3.a) swap on sd2b dump on sd2b
inteldrm0: 1920x1080, 32bpp
wsdisplay0 at inteldrm0 mux 1: console (std, vt100 emulation), using wskbd0
wsdisplay0: screen 1-5 added (std, vt100 emulation)
iwm0: hw rev 0x230, fw ver 34.0.1, address 18:56:80:60:81:28

usbdevs:
Controller /dev/usb0:
addr 01: 8086: Intel, xHCI root hub
 super speed, self powered, config 1, rev 1.00
 driver: uhub0
addr 02: 20a0:4108 Nitrokey, Nitrokey Pro
 full speed, power 100 mA, config 1, rev 1.01, iSerial 
6D3A
 driver: uhidev0
 driver: ugen0
addr 03: 058f:9540 Generic, EMV Smartcard Reader
 full speed, power 50 mA, config 1, rev 1.20
 driver: ugen1
addr 04: 2cb7:0210 FIBOCOM, L830-EB-00
 high speed, self powered, config 1, rev 3.33, iSerial 00499901064
 driver: umb0
 driver: umodem0
addr 05: 04f2:b604 Chicony Electronics Co.,Ltd., Integrated Camera
 high speed, power 500 mA, config 1, rev 0.27, iSerial 0001
 driver: uvideo0
addr 06: 0bda:0316 Generic, USB3.0-CRW
 super speed, power 200 mA, config 1, rev 2.04, iSerial 
2012050103090
 driver: umass0
--
Tristan



Re: IKEv2 difference with 6.7

2020-06-16 Thread tristan
e records, I just took a copy of iked version 6.6 and used
that instead of 6.7 and all is good. I saved the 6.7 version.

gateway# ls -al /sbin/iked*
-r-xr-xr-x  1 root  bin  436584 Jun 15 20:42 /sbin/iked
-r-xr-xr-x  1 root  bin  448744 May  7 12:52 /sbin/iked.original

So it's definitely nothing else that is stopping it from working.

Just a new requirement for iked to use this new way and so far I am
coming short as to how to get this done right.


As a workaround, that did the trick for me too, thanks for the hint! At 
least it is fixed for now.


Cheers,
--
Tristan



Re: Realtek Edimax AC1750 USB gets properly detected but not configurable in ifconfig

2020-06-06 Thread Tristan
Oh sorry,  my mistake, I might need some sleep :)

Thanks for the list of USB adapters, that helps a lot.

> On Jun 6, 2020, at 9:35 PM, Stuart Henderson  wrote:
> 
> On 2020/06/06 19:14, Tristan wrote:
>> Ok thanks. Yes I’m looking for just using 11n.
> 
> You already replied saying that!
> 
> It doesn't matter if you only want to use 11n, OpenBSD does not have a
> driver for the controller used in that adapter.
> 
> For USB adapters look for a device using one of these:
> 
> bwfm(4) - Broadcom and Cypress IEEE 802.11a/ac/b/g/n wireless network device
> otus(4) - Atheros USB IEEE 802.11a/b/g/n wireless network device
> rsu(4) - Realtek RTL8188SU/RTL8192SU USB IEEE 802.11b/g/n wireless network 
> device
> run(4) - Ralink Technology/MediaTek USB IEEE 802.11a/b/g/n wireless network 
> device
> urtwn(4) - Realtek RTL8188CU/RTL8188EU/RTL8192CU/RTL8192EU USB IEEE 
> 802.11b/g/n wireless network device
> 
> (or there are some 11g-only ones but not much point looking for them).
> 
> 
>> 
>>>> On Jun 6, 2020, at 5:55 AM, Stuart Henderson  wrote:
>>> 
>>> On 2020-06-05, Tristan  wrote:
>>>> Just plugged in a Realtek Edimax AC1750 USB card into a ASRock B450M board.
>>>> I can see the card being detected and registered properly in dmesg and
>>>> usbdevs, but cannot configure it.
>>>> Is this card supported?
>>> 
>>> No. The only supported 11ac USB devices are the limited and fairly hard to 
>>> get
>>> hold of bwfm(4) devices. (Some PCIe 11ac are supported but not in 11ac 
>>> mode.)
>>> 
>>> 
>>> 
>> 
> 



Re: Realtek Edimax AC1750 USB gets properly detected but not configurable in ifconfig

2020-06-06 Thread Tristan
Ok thanks. Yes I’m looking for just using 11n.


> On Jun 6, 2020, at 5:55 AM, Stuart Henderson  wrote:
> 
> On 2020-06-05, Tristan  wrote:
>> Just plugged in a Realtek Edimax AC1750 USB card into a ASRock B450M board.
>> I can see the card being detected and registered properly in dmesg and 
>> usbdevs, but cannot configure it.
>> Is this card supported?
> 
> No. The only supported 11ac USB devices are the limited and fairly hard to get
> hold of bwfm(4) devices. (Some PCIe 11ac are supported but not in 11ac mode.)
> 
> 
> 



Realtek Edimax AC1750 USB gets properly detected but not configurable in ifconfig

2020-06-05 Thread Tristan

Hi,

Just plugged in a Realtek Edimax AC1750 USB card into a ASRock B450M board.
I can see the card being detected and registered properly in dmesg and 
usbdevs, but cannot configure it.

Is this card supported?

Thanks

usbdevs output:
Controller /dev/usb0:
addr 01: 1022: AMD, xHCI root hub
addr 02: 7392:a833 Realtek, Edimax AC1750 USB
Controller /dev/usb1:
addr 01: 1022: AMD, xHCI root hub
addr 02: 0bc2:ab24 Seagate, BUP Slim BK
Controller /dev/usb2:
addr 01: 1022: AMD, xHCI root hub

ifconfig only shows these:
lo0: flags=8049 mtu 32768
em0: flags=8b43 
mtu 1500
em1: flags=8b43 
mtu 1500
em2: flags=8b43 
mtu 1500
em3: flags=8b43 
mtu 1500

re0: flags=808843 mtu 1500
bridge0: flags=41
tun0: flags=8051 mtu 1420
vether0: flags=8943 mtu 1500
pflog0: flags=141 mtu 33136

if it's any use also my sysctl hw
hw.machine=amd64
hw.model=AMD Ryzen 5 3400G with Radeon Vega Graphics
hw.ncpu=8
hw.byteorder=1234
hw.pagesize=4096
hw.disknames=sd0:11f200d7c36ede5d,sd1:44046d966725a401,sd2:eb4c6024594010f9
hw.diskcount=3
hw.sensors.ksmn0.temp0=35.50 degC
hw.sensors.lm1.temp0=29.00 degC (MB Temperature)
hw.sensors.lm1.temp1=32.00 degC (CPU Temperature)
hw.sensors.lm1.temp2=93.00 degC (Aux Temp0)
hw.sensors.lm1.temp3=99.00 degC (Aux Temp1)
hw.sensors.lm1.temp4=22.50 degC (Aux Temp2)
hw.sensors.lm1.temp5=-20.00 degC (Aux Temp3)
hw.sensors.lm1.fan0=0 RPM (System Fan)
hw.sensors.lm1.fan1=2008 RPM (CPU Fan)
hw.sensors.lm1.fan2=0 RPM (Aux Fan0)
hw.sensors.lm1.fan3=1112 RPM (Aux Fan1)
hw.sensors.lm1.fan4=0 RPM (Aux Fan2)
hw.sensors.lm1.volt0=0.93 VDC (VCore)
hw.sensors.lm1.volt1=1.85 VDC (VIN1)
hw.sensors.lm1.volt2=3.42 VDC (AVCC)
hw.sensors.lm1.volt3=3.42 VDC (+3.3V)
hw.sensors.lm1.volt4=21.66 VDC (VIN0)
hw.sensors.lm1.volt5=1.06 VDC (VIN8)
hw.sensors.lm1.volt6=0.30 VDC (VIN4)
hw.sensors.lm1.volt7=3.46 VDC (+3.3VSB)
hw.sensors.lm1.volt8=0.00 VDC (VBAT)
hw.sensors.lm1.volt9=0.00 VDC (VTT)
hw.sensors.lm1.volt10=0.22 VDC (VIN5)
hw.sensors.lm1.volt11=1.06 VDC (VIN6)
hw.sensors.lm1.volt12=3.38 VDC (VIN2)
hw.sensors.lm1.volt13=5.08 VDC (VIN3)
hw.sensors.lm1.volt14=1.78 VDC (VIN7)
hw.cpuspeed=3693
hw.setperf=100
hw.vendor=ASRock
hw.product=B450M Steel Legend
hw.uuid=a8a1591a-3356---
hw.physmem=32120504320
hw.usermem=32120492032
hw.ncpufound=8
hw.allowpowerdown=1
hw.perfpolicy=manual
hw.smt=1
hw.ncpuonline=8


Find my current dmesg.

OpenBSD 6.7 (GENERIC.MP) #2: Thu Jun  4 09:55:08 MDT 2020
r...@syspatch-67-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 32120504320 (30632MB)
avail mem = 31134412800 (29692MB)
mpath0 at root
scsibus0 at mpath0: 256 targets
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 3.2 @ 0xe6cc0 (29 entries)
bios0: vendor American Megatrends Inc. version "P2.90" date 11/27/2019
bios0: ASRock B450M Steel Legend
acpi0 at bios0: ACPI 6.0
acpi0: sleep states S0 S3 S4 S5
acpi0: tables DSDT FACP APIC FPDT FIDT SSDT SSDT SSDT MCFG AAFT HPET 
UEFI BGRT SSDT CRAT CDIT SSDT SSDT WSMT SSDT
acpi0: wakeup devices GPP0(S4) GPP2(S4) GPP3(S4) GPP4(S4) GPP5(S4) 
GPP6(S4) GP17(S4) XHC0(S4) XHC1(S4) GP18(S4) GPP1(S4) PTXH(S4)

acpitimer0 at acpi0: 3579545 Hz, 32 bits
acpimadt0 at acpi0 addr 0xfee0: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: AMD Ryzen 5 3400G with Radeon Vega Graphics, 3693.67 MHz, 17-18-01
cpu0: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,MMX,FXSR,SSE,SSE2,HTT,SSE3,PCLMUL,MWAIT,SSSE3,FMA3,CX16,SSE4.1,SSE4.2,MOVBE,POPCNT,AES,XSAVE,AVX,F16C,RDRAND,NXE,MMXX,FFXSR,PAGE1GB,RDTSCP,LONG,LAHF,CMPLEG,SVM,EAPICSP,AMCR8,ABM,SSE4A,MASSE,3DNOWP,OSVW,SKINIT,TCE,TOPEXT,CPCTR,DBKP,PCTRL3,MWAITX,ITSC,FSGSBASE,BMI1,AVX2,SMEP,BMI2,RDSEED,ADX,SMAP,CLFLUSHOPT,SHA,IBPB,XSAVEOPT,XSAVEC,XGETBV1,XSAVES
cpu0: 64KB 64b/line 4-way I-cache, 32KB 64b/line 8-way D-cache, 512KB 
64b/line 8-way L2 cache, 4MB 64b/line 16-way L3 cache
cpu0: ITLB 64 4KB entries fully associative, 64 4MB entries fully 
associative
cpu0: DTLB 64 4KB entries fully associative, 64 4MB entries fully 
associative

cpu0: smt 0, core 0, package 0
mtrr: Pentium Pro MTRR support, 8 var ranges, 88 fixed ranges
cpu0: apic clock running at 24MHz
cpu0: mwait min=64, max=64, C-substates=1.1, IBE
cpu1 at mainbus0: apid 2 (application processor)
cpu1: AMD Ryzen 5 3400G with Radeon Vega Graphics, 3693.02 MHz, 17-18-01
cpu1: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,MMX,FXSR,SSE,SSE2,HTT,SSE3,PCLMUL,MWAIT,SSSE3,FMA3,CX16,SSE4.1,SSE4.2,MOVBE,POPCNT,AES,XSAVE,AVX,F16C,RDRAND,NXE,MMXX,FFXSR,PAGE1GB,RDTSCP,LONG,LAHF,CMPLEG,SVM,EAPICSP,AMCR8,ABM,SSE4A,MASSE,3DNOWP,OSVW,SKINIT,TCE,TOPEXT,CPCTR,DBKP,PCTRL3,MWAITX,ITSC,FSGSBASE,BMI1,AVX2,SMEP,BMI2,RDSEED,ADX,SMAP,CLFLUSHOPT,SHA,IBPB,XSAVEOPT,XSAVEC,XGETBV1,XSAVES
cpu1: 64KB 64b/line 4-way I-cache, 32KB 64b/line 8-way D-cache, 512KB 
64b/line 8-way L2 cache, 4MB 64b/line 16-way L3 cache
cpu1: ITLB 64 4KB entries fully associative, 64 4MB entries fully 
associative
cpu1: DTLB 64 4KB entries fully ass

Re: Zoom meeting via chromium web app

2020-03-28 Thread Tristan Pilat
On March 28, 2020 11:40:25 AM GMT+01:00, Antoine Jacoutot 
 wrote:
>On Sat, Mar 28, 2020 at 10:00:28AM +0100, Alessandro De Laurenzis
>wrote:
>> Greetings,
>> 
>> I'm trying to use the Zoom meeting platform in OpenBSD through the
>Chromium
>> web app (-current, very recent snapshot, Chromium 80.0.3987.149,
>amd64).
>> 
>> When I click on the app icon, a new browser window opens and the
>sign-in web
>> page appears, but soon after the browser is killed:
>> 
>> Mar 28 09:52:43 theseus /bsd: chrome(36809): pledge sysctl 2: 6 2
>> Mar 28 09:52:43 theseus /bsd: chrome[36809]: pledge "", syscall 202
>> 
>> Starting chrome with --disable-unveil doesn't help (same error).
>> 
>> Anybody did succeed in using this (or a similar) platform?
>
>You can use --no-sandbox.
>But Zoom will not work anyway, at least for me it doesn't recognize my
>audio
>nor my camera.
>I use Windows for video conf.

Hello,

I haven't tried Zoom but I successfully used Jisti with Chromium on current. I 
just had to chown /dev/videoX. It was working nicely until my system hung after 
10 or 15 min though, likely because of the lack of hardware acceleration. You 
should give it a try.

Cheers,

-- 
Tristan



Re: IKEv2 OpenBSD client using X.509 Certificate Authentication

2019-10-16 Thread Tristan Pilat"
On 10/16/19 at 08:31P, Stuart Henderson wrote:
> On 2019-10-07, Tristan Pilat  wrote:
> > I'm trying to set up a IKEv2 VPN using X.509 Certificate Authentication with
> > iked(8). In the Virtual Private Networks (VPN) section of the FAQ there no
> > section about setting up this with an OpenBSD client. Is there anybody here
> > who's done that before?
> 
> Hoping someone will tell me that I'm wrong, but iked's client-side support is
> not very flexible and I don't think it supports this - it definitely doesn't
> support username/password auth as a client.

Does X.509 Certificate Authentication necessarily include the use of an
username/password auth mechanism?
 
> strongswan is in packages if that helps..

I'll use strongswan as a last resort but I'd really like to sort
this out and use iked instead.

I've actually gotten somewhere since I wrote this call for help.

So here's what I did. I put the last two blocks of my example.pem file in a
/etc/iked/ca/example.crt file and copied example.pem to
/etc/iked/certs/example.crt 

And after some research I ended up with this configuration file :

# cat /etc/iked.conf

local_ip="198.51.100.1"
local_network="192.0.2.0/24 "

remote_ip="198.51.100.2"
remote_network="203.0.113.0/24"

ikev2 'example' active esp \
from $local_network to $remote_network \
local $local_ip peer $remote_ip \
ikesa auth hmac-sha1 enc aes-256 prf hmac-sha1 group modp1536 \
childsa auth hmac-sha1 enc aes-256 group modp1536 \
srcid "/C=FR/O=XXX/OU=0002 479766842/OU=X/CN=XXX" \
dstid "/C=FR/O=XXX/OU=0002 479766842/OU=X/CN=YYY" \
ikelifetime 86400 lifetime 28800

But I'm still stuck here with an "ikev2_pld_notify: AUTHENTICATION_FAILED, 
closing SA"

Here's the full iked output:

# iked -dvvT 
local_ip = "198.51.100.1"
local_network = "192.0.2.0/24"
remote_ip = "198.51.100.2"
remote_network = "203.0.113.0/24"

  
set_policy_auth_method: using rfc7427 for peer
ikev2 "XXX" active esp inet from 192.0.2.0/24 to 203.0.113.0/24 local 
198.51.100.1 peer 198.51.100.2 ikesa enc aes-256 prf hmac-sha1 auth hmac-sha1 
group modp1536 childsa enc aes-256 auth hmac-sha1 group modp1536 srcid 
/C=FR/O=XXX/OU=0002 479766842/OU=X/CN=XXX dstid /C=FR/O=XXX/OU=0002 
479766842/OU=X/CN=YYY ikelifetime 86400 lifetime 28800 bytes 536870912 
rfc7427
/etc/iked.conf: loaded 1 configuration rules
ca_privkey_serialize: type RSA_KEY length 1191
ca_pubkey_serialize: type RSA_KEY length 270
ca_privkey_to_method: type RSA_KEY method RSA_SIG
ca_getkey: received private key type RSA_KEY length 1191
ca_getkey: received public key type RSA_KEY length 270
ca_dispatch_parent: config reset
ca_reload: loaded ca file example.crt
ca_reload: /C=FR/O=XXX/OU=0002 120061023/CN=X
ca_reload: /CN=XXX-ROOT/OU=0002 120061023/O=/C=FR
ca_reload: loaded 2 ca certificates
ca_reload: loaded cert file example.crt
ca_validate_cert: /C=FR/O=XXX/OU=0002 120061023/CN=AC XXX 2018 ok
ca_validate_cert: /C=FR/O=XXX/OU=0002 479766842/OU=X/CN=XXX ok
ca_validate_cert: /CN=XXX-ROOT/OU=0002 120061023/O=/C=FR ok
ca_reload: local cert type X509_CERT
config_getocsp: ocsp_url none
ikev2_dispatch_cert: updated local CERTREQ type X509_CERT length 40
ikev2_dispatch_cert: updated local CERTREQ type X509_CERT length 40
config_getpolicy: received policy
config_getpfkey: received pfkey fd 3
config_getcompile: compilation done
config_getsocket: received socket fd 4
config_getsocket: received socket fd 5
config_getmobike: mobike
ikev2_init_ike_sa: initiating "XXX"
ca_x509_name_parse: setting 'C' to 'FR'
ca_x509_name_parse: setting 'O' to 'XXX'
ca_x509_name_parse: setting 'OU' to '0002 479766842'
ca_x509_name_parse: setting 'OU' to 'X'
ca_x509_name_parse: setting 'CN' to 'XXX'
ikev2_policy2id: srcid ASN1_DN//C=FR/O=XXX/OU=0002 
479766842/OU=X/CN=XXX length 109
ikev2_add_proposals: length 44
ikev2_next_payload: length 48 nextpayload KE
ikev2_next_payload: length 200 nextpayload NONCE
ikev2_next_payload: length 36 nextpayload NOTIFY
ikev2_next_payload: length 14 nextpayload NONE
ikev2_pld_parse: header ispi 0x30eecb84950d6a8a rspi 0x 
nextpayload SA version 0x20 exchange IKE_SA_INIT flags 0x08 msgid 0 length 326 
response 0
ikev2_pld_payloads: payload SA nextpayload KE critical 0x00 length 48
ikev2_pld_sa: more 0 reserved 0 length 44 proposal #1 protoid IKE spisize 0 
xforms 4 spi 0
ikev2_pld_xform: more 3 reserved 0 length 8 type INTEGR id HMAC_SHA1_96
ikev2_pld_xform: more 3 reserved 

IKEv2 OpenBSD client using X.509 Certificate Authentication

2019-10-07 Thread Tristan Pilat
Hi guys,

I'm trying to set up a IKEv2 VPN using X.509 Certificate Authentication with 
iked(8). In the Virtual Private Networks (VPN) section of the FAQ there no 
section about setting up this with an OpenBSD client. Is there anybody here 
who's done that before?

In trying the achieve this, I first had to give a CSR to the other part so I 
used ikectl(8) to generate a ca and a certificate. To do so I followed the 
steps at the bottom of the ikectl(8) man page and I did this:

# ikectl ca example create
# ikectl ca example certificate 198.51.100.1 create
# ikectl ca example certificate 198.51.100.2 create

I then gave them the CSR file corresponding to the 198.51.100.2 certificate.

In return, they gave me a X.509 certificate like the following:

$ cat example.pem
subject=/C=FR/O=XXX/OU=0002 479766842/OU=X/CN=XXX
issuer=/C=FR/O=X/OU=0002 120061023/CN=XX
-BEGIN CERTIFICATE-

-END CERTIFICATE-
subject=/C=FR/O=XXX/OU=0002 120061023/CN=X
issuer=/CN=XXX-ROOT/OU=0002 120061023/O=/C=FR
-BEGIN CERTIFICATE-

-END CERTIFICATE-
subject=/CN=XXX-ROOT/OU=0002 120061023/O=X/C=FR
issuer=/CN=XXX-ROOT/OU=0002 120061023/O=/C=FR
-BEGIN CERTIFICATE-

-END CERTIFICATE-

I don't really know how to use that certificate with iked(8).

My configuration file look pretty much like this:

local_ip="198.51.100.1"
local_network="192.0.2.0/24 "

remote_ip="198.51.100.2"
remote_network="203.0.113.0/24"

ikev2 'example' active esp \
    from $local_network to $remote_network \
    local $local_ip peer $remote_ip \
    ikesa auth hmac-sha1 enc aes-256 prf hmac-sha2-256 group modp1536 \
    childsa auth hmac-sha1 enc aes-256 group modp1536 \
    ikelifetime 86400 lifetime 28800 \
dstid 198.51.100.2

What file do the directives srcid and dstid match to? I don't get how iked(8) 
make use of the certificates in that case. 

I made sure to have the following 2 files:

# cat /etc/iked/private/198.51.100.2.key  
-BEGIN RSA PRIVATE KEY-
XXX
-END RSA PRIVATE KEY-

# cat /etc/iked/certs/198.51.100.2.crt
subject=/C=FR/O=XXX/OU=0002 479766842/OU=X/CN=XXX
issuer=/C=FR/O=X/OU=0002 120061023/CN=XX
-BEGIN CERTIFICATE-

-END CERTIFICATE-
subject=/C=FR/O=XXX/OU=0002 120061023/CN=X
issuer=/CN=XXX-ROOT/OU=0002 120061023/O=/C=FR
-BEGIN CERTIFICATE-

-END CERTIFICATE-
subject=/CN=XXX-ROOT/OU=0002 120061023/O=X/C=FR
issuer=/CN=XXX-ROOT/OU=0002 120061023/O=/C=FR
-BEGIN CERTIFICATE-

-END CERTIFICATE-

But I get an error :

config_setkeys: failed to open private key: No such file or directory
parent: parent_configure: failed to send keys

I'm pretty sure I'm completely wrong here and I would be really grateful if 
anybody could explain to me what are the steps to take here.

Thank you!
-- 
Tristan



Iked and PKCS7

2019-09-09 Thread Tristan Pilat
Hello all,

It's the first time I'm trying to set up a site-to-site IKEv2 VPN with a non 
OpenBSD device at the other side. I've been asked to provide a CSR,  then they 
sent me a PKCS7 certificate in return.

Is there any way to install this kind of certificate with iked? If so, how do I 
proceed?

Thank you for your help.

Cheers,
-- 
Tristan



Re: Lenovo V330-14 touchpad is not working at all

2019-06-14 Thread Tristan
v 0x00
pchb6 at pci0 dev 24 function 3 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb7 at pci0 dev 24 function 4 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb8 at pci0 dev 24 function 5 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb9 at pci0 dev 24 function 6 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb10 at pci0 dev 24 function 7 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
isa0 at pcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5 irq 1 irq 12
pckbd0 at pckbc0 (kbd slot)
wskbd0 at pckbd0: console keyboard
pms0 at pckbc0 (aux slot)
wsmouse1 at pms0 mux 0
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
vmm0 at mainbus0: SVM/RVI
efifb0 at mainbus0: 1920x1080, 32bpp
wsdisplay0 at efifb0 mux 1: console (std, vt100 emulation), using wskbd0
wsdisplay0: screen 1-5 added (std, vt100 emulation)
uvideo0 at uhub0 port 1 configuration 1 interface 0 "Chicony Electronics 
Co.,Ltd. Integrated Camera" rev 2.01/0.27 addr 2
video0 at uvideo0
urtwn0 at uhub0 port 3 configuration 1 interface 0 "Realtek 802.11n NIC" rev 
2.00/0.00 addr 3
urtwn0: MAC/BB RTL8188EU, RF 6052 1T1R, address 50:3e:aa:e2:00:00
uhidev0 at uhub0 port 4 configuration 1 interface 0 "Primax Electronics DELL 
Laser Mouse" rev 2.00/7.17 addr 4
uhidev0: iclass 3/1
ums0 at uhidev0: 5 buttons, Z dir
wsmouse2 at ums0 mux 0
uhub2 at uhub1 port 2 configuration 1 interface 0 "Genesys Logic USB2.0 Hub" 
rev 2.00/88.32 addr 2
ugen0 at uhub2 port 2 "Atheros Communications product 0xe500" rev 2.01/0.01 
addr 3
vscsi0 at root
scsibus2 at vscsi0: 256 targets
softraid0 at root
scsibus3 at softraid0: 256 targets
root on sd0a (cfa379aacd19cf3f.a) swap on sd0b dump on sd0b
wsmouse2 detached
ums0 detached
uhidev0 detached
uhidev0 at uhub0 port 4 configuration 1 interface 0 "Primax Electronics DELL 
Laser Mouse" rev 2.00/7.17 addr 4
uhidev0: iclass 3/1
ums0 at uhidev0: 5 buttons, Z dir
wsmouse2 at ums0 mux 0
wsmouse2 detached
ums0 detached
uhidev0 detached
uhidev0 at uhub0 port 4 configuration 1 interface 0 "Primax Electronics DELL 
Laser Mouse" rev 2.00/7.17 addr 4
uhidev0: iclass 3/1
ums0 at uhidev0: 5 buttons, Z dir
wsmouse2 at ums0 mux 0

> On 14 Jun 2019, at 08:31, Tristan  wrote:
> 
> 
> 
>> On 14 Jun 2019, at 02:38, Tristan  wrote:
>> 
>> 
>> 
>>> On Jun 14, 2019, at 12:00 AM, Tristan  wrote:
>>> 
>>> 
>>> 
>>>> On 13 Jun 2019, at 23:47, Bryan Steele  wrote:
>>>> 
>>>> On Thu, Jun 13, 2019 at 11:38:24PM +0200, Tristan wrote:
>>>>> 
>>>>> 
>>>>>> On 13 Jun 2019, at 22:34, Tristan  wrote:
>>>>>> 
>>>>>> 
>>>>>> 
>>>>>>> On 13 Jun 2019, at 22:25, Bryan Steele  wrote:
>>>>>>> 
>>>>>>> On Thu, Jun 13, 2019 at 08:39:48PM +0200, Tristan wrote:
>>>>>>>> Hi there,
>>>>>>>> 
>>>>>>>> I got a new lenovo v330-14 it has an AMD Ryzen 5 2500U and Radeon RX 
>>>>>>>> Vega 8
>>>>>>>> and so was looking forward to using OpenBSD on this one. I'm currently 
>>>>>>>> running a
>>>>>>>> snapshot I grabbed today. To get the screen working I had to set 
>>>>>>>> machdep.allowaperture=2
>>>>>>>> unfortunately, but it works now and great as well. Video seems smooth. 
>>>>>>>> Audio works as well
>>>>>>> 
>>>>>>> You should avoid doing that -- see recent mailing lists post from Mark
>>>>>>> Kettenis.
>>>>>>> 
>>>>>>> https://marc.info/?l=openbsd-misc&m=156029398905090&w=2
>>>>>>> 
>>>>>>> For Vega graphics you need to recompile your kernel with the amdgpu
>>>>>>> driver lines uncommented, alternatively reinstall in UEFI mode to get 
>>>>>>> the
>>>>>>> efifb(4) driver instead. This is probably better as amdgpu support is
>>>>>>> still a WIP.
>>>>>>> 
>> This worked really good. Now using efifb without the machdep setting. So 
>> thanks for that pointer for sure.
>>>>>> 
>>>>>> OK yes, I remember seeing something about it. Will give that a try. Much 
>>>>>> better then opening up :)
>>>>>> 
>>>>>> 
>>>>>>>> but the touchpad is not working at all. Wireless card does not work 
>>>>>>>> either, but using the 
>>>>>>>> ethernet port on it for

Re: Lenovo V330-14 touchpad is not working at all

2019-06-13 Thread Tristan



> On 14 Jun 2019, at 02:38, Tristan  wrote:
> 
> 
> 
>> On Jun 14, 2019, at 12:00 AM, Tristan  wrote:
>> 
>> 
>> 
>>> On 13 Jun 2019, at 23:47, Bryan Steele  wrote:
>>> 
>>> On Thu, Jun 13, 2019 at 11:38:24PM +0200, Tristan wrote:
>>>> 
>>>> 
>>>>> On 13 Jun 2019, at 22:34, Tristan  wrote:
>>>>> 
>>>>> 
>>>>> 
>>>>>> On 13 Jun 2019, at 22:25, Bryan Steele  wrote:
>>>>>> 
>>>>>> On Thu, Jun 13, 2019 at 08:39:48PM +0200, Tristan wrote:
>>>>>>> Hi there,
>>>>>>> 
>>>>>>> I got a new lenovo v330-14 it has an AMD Ryzen 5 2500U and Radeon RX 
>>>>>>> Vega 8
>>>>>>> and so was looking forward to using OpenBSD on this one. I'm currently 
>>>>>>> running a
>>>>>>> snapshot I grabbed today. To get the screen working I had to set 
>>>>>>> machdep.allowaperture=2
>>>>>>> unfortunately, but it works now and great as well. Video seems smooth. 
>>>>>>> Audio works as well
>>>>>> 
>>>>>> You should avoid doing that -- see recent mailing lists post from Mark
>>>>>> Kettenis.
>>>>>> 
>>>>>> https://marc.info/?l=openbsd-misc&m=156029398905090&w=2
>>>>>> 
>>>>>> For Vega graphics you need to recompile your kernel with the amdgpu
>>>>>> driver lines uncommented, alternatively reinstall in UEFI mode to get the
>>>>>> efifb(4) driver instead. This is probably better as amdgpu support is
>>>>>> still a WIP.
>>>>>> 
> This worked really good. Now using efifb without the machdep setting. So 
> thanks for that pointer for sure.
>>>>> 
>>>>> OK yes, I remember seeing something about it. Will give that a try. Much 
>>>>> better then opening up :)
>>>>> 
>>>>> 
>>>>>>> but the touchpad is not working at all. Wireless card does not work 
>>>>>>> either, but using the 
>>>>>>> ethernet port on it for now until I get an USB dongle for it.
>>>>>>> 
>>>>>>> wsconsctl | grep mouse gives me only:
>>>>>>> mouse.type=ps2
>>>>>>> 
>>>>>>> In the dmesg output I can see only:
>>>>>>> wsmouse0 at pms0 mux 0
>>>>>> 
>>>>>> Indeed, there's no pms(4) compatible touchpad on your machine. :-(
>>>>>> 
>>>>>>> "AMDI0010" at acpi0 not configured
>>>>>>> "SYNA2B3F" at acpi0 not configured
>>>>>> 
>>>>>> And instead requires a driver to attach to the I2C HID controler. AMD's
>>>>>> implementation seems to be somewhat compatible with dwiic(4) written by
>>>>>> jcs@, however interrupts are not working-- hangs the machine. It does
>>>>>> work if polling mode is forced.
>>>>>> 
>>>>>> This diff made the touchscreen and touchpad work be detected and mostly
>>>>>> work on my Huawei MateBook D (AMD), however with the touchpad it seems
>>>>>> to be break Tap-To-Drag. I don't know if this is a side effect of the
>>>>>> drivers polling, unlike the pms(4) support-- which is working on that
>>>>>> machine. We have no way to prefer one driver over other, which is why
>>>>>> I haven't sent this diff yet.
>>>>>> 
>>>>>> Let me know if it works at all for you.
>>>>> 
>>>>> Much appreciated, will try this and report the outcome
>>>> 
>>>> Applying this patch gives me the following:
>>>> 
>>>> Hmm...  Looks like a unified diff to me...
>>>> The text leading up to this was:
>>>> --
>>>> |Index: dwiic_acpi.c
>>>> |===
>>>> |RCS file: /cvs/src/sys/dev/acpi/dwiic_acpi.c,v
>>>> |retrieving revision 1.8
>>>> |diff -u -p -u -r1.8 dwiic_acpi.c
>>>> |--- sys/dev/acpi/dwiic_acpi.c1 Jul 2018 11:37:11 -1.8
>>>> |+++ sys/dev/acpi/dwiic_acpi.c5 Jun 2019 00:25:29 -
>>>> --
>>>> Patching file dwii

Re: Lenovo V330-14 touchpad is not working at all

2019-06-13 Thread Tristan



> On Jun 14, 2019, at 12:00 AM, Tristan  wrote:
> 
> 
> 
>> On 13 Jun 2019, at 23:47, Bryan Steele  wrote:
>> 
>> On Thu, Jun 13, 2019 at 11:38:24PM +0200, Tristan wrote:
>>> 
>>> 
>>>> On 13 Jun 2019, at 22:34, Tristan  wrote:
>>>> 
>>>> 
>>>> 
>>>>> On 13 Jun 2019, at 22:25, Bryan Steele  wrote:
>>>>> 
>>>>> On Thu, Jun 13, 2019 at 08:39:48PM +0200, Tristan wrote:
>>>>>> Hi there,
>>>>>> 
>>>>>> I got a new lenovo v330-14 it has an AMD Ryzen 5 2500U and Radeon RX 
>>>>>> Vega 8
>>>>>> and so was looking forward to using OpenBSD on this one. I'm currently 
>>>>>> running a
>>>>>> snapshot I grabbed today. To get the screen working I had to set 
>>>>>> machdep.allowaperture=2
>>>>>> unfortunately, but it works now and great as well. Video seems smooth. 
>>>>>> Audio works as well
>>>>> 
>>>>> You should avoid doing that -- see recent mailing lists post from Mark
>>>>> Kettenis.
>>>>> 
>>>>> https://marc.info/?l=openbsd-misc&m=156029398905090&w=2
>>>>> 
>>>>> For Vega graphics you need to recompile your kernel with the amdgpu
>>>>> driver lines uncommented, alternatively reinstall in UEFI mode to get the
>>>>> efifb(4) driver instead. This is probably better as amdgpu support is
>>>>> still a WIP.
>>>>> 
This worked really good. Now using efifb without the machdep setting. So thanks 
for that pointer for sure.
>>>> 
>>>> OK yes, I remember seeing something about it. Will give that a try. Much 
>>>> better then opening up :)
>>>> 
>>>> 
>>>>>> but the touchpad is not working at all. Wireless card does not work 
>>>>>> either, but using the 
>>>>>> ethernet port on it for now until I get an USB dongle for it.
>>>>>> 
>>>>>> wsconsctl | grep mouse gives me only:
>>>>>> mouse.type=ps2
>>>>>> 
>>>>>> In the dmesg output I can see only:
>>>>>> wsmouse0 at pms0 mux 0
>>>>> 
>>>>> Indeed, there's no pms(4) compatible touchpad on your machine. :-(
>>>>> 
>>>>>> "AMDI0010" at acpi0 not configured
>>>>>> "SYNA2B3F" at acpi0 not configured
>>>>> 
>>>>> And instead requires a driver to attach to the I2C HID controler. AMD's
>>>>> implementation seems to be somewhat compatible with dwiic(4) written by
>>>>> jcs@, however interrupts are not working-- hangs the machine. It does
>>>>> work if polling mode is forced.
>>>>> 
>>>>> This diff made the touchscreen and touchpad work be detected and mostly
>>>>> work on my Huawei MateBook D (AMD), however with the touchpad it seems
>>>>> to be break Tap-To-Drag. I don't know if this is a side effect of the
>>>>> drivers polling, unlike the pms(4) support-- which is working on that
>>>>> machine. We have no way to prefer one driver over other, which is why
>>>>> I haven't sent this diff yet.
>>>>> 
>>>>> Let me know if it works at all for you.
>>>> 
>>>> Much appreciated, will try this and report the outcome
>>> 
>>> Applying this patch gives me the following:
>>> 
>>> Hmm...  Looks like a unified diff to me...
>>> The text leading up to this was:
>>> --
>>> |Index: dwiic_acpi.c
>>> |===
>>> |RCS file: /cvs/src/sys/dev/acpi/dwiic_acpi.c,v
>>> |retrieving revision 1.8
>>> |diff -u -p -u -r1.8 dwiic_acpi.c
>>> |--- sys/dev/acpi/dwiic_acpi.c1 Jul 2018 11:37:11 -1.8
>>> |+++ sys/dev/acpi/dwiic_acpi.c5 Jun 2019 00:25:29 -
>>> --
>>> Patching file dwiic_acpi.c using Plan A...
>>> patch:  malformed patch at line 9: };
>> 
>> Your mail client may have mangled it-- can you try grabbing it
>> from marc.info? If not, I'll send a direct link.
>> 
>> https://marc.info/?l=openbsd-misc&m=156045760827816&q=raw
>> 
> 
> Yes sorry about that false report :) my mistake.
> 
> Applied and recompiling at the moment. Will report back soon.
> 
This patch gave some life to my touchpad. Unfortunately its more like a slow 
stuttering zombie :) 
But yes it has some movement now, but just slow and then jumping forward. The 
touchpad touch click works as well. 
Cannot provide any output at the moment, but will send over the dmesg and 
wsconctl output tomorrow. In case you want to see if there are any other things 
we could try:

Thanks again for the help.



Re: Lenovo V330-14 touchpad is not working at all

2019-06-13 Thread Tristan



> On 13 Jun 2019, at 23:47, Bryan Steele  wrote:
> 
> On Thu, Jun 13, 2019 at 11:38:24PM +0200, Tristan wrote:
>> 
>> 
>>> On 13 Jun 2019, at 22:34, Tristan  wrote:
>>> 
>>> 
>>> 
>>>> On 13 Jun 2019, at 22:25, Bryan Steele  wrote:
>>>> 
>>>> On Thu, Jun 13, 2019 at 08:39:48PM +0200, Tristan wrote:
>>>>> Hi there,
>>>>> 
>>>>> I got a new lenovo v330-14 it has an AMD Ryzen 5 2500U and Radeon RX Vega 
>>>>> 8
>>>>> and so was looking forward to using OpenBSD on this one. I'm currently 
>>>>> running a
>>>>> snapshot I grabbed today. To get the screen working I had to set 
>>>>> machdep.allowaperture=2
>>>>> unfortunately, but it works now and great as well. Video seems smooth. 
>>>>> Audio works as well
>>>> 
>>>> You should avoid doing that -- see recent mailing lists post from Mark
>>>> Kettenis.
>>>> 
>>>> https://marc.info/?l=openbsd-misc&m=156029398905090&w=2
>>>> 
>>>> For Vega graphics you need to recompile your kernel with the amdgpu
>>>> driver lines uncommented, alternatively reinstall in UEFI mode to get the
>>>> efifb(4) driver instead. This is probably better as amdgpu support is
>>>> still a WIP.
>>>> 
>>> 
>>> OK yes, I remember seeing something about it. Will give that a try. Much 
>>> better then opening up :)
>>> 
>>> 
>>>>> but the touchpad is not working at all. Wireless card does not work 
>>>>> either, but using the 
>>>>> ethernet port on it for now until I get an USB dongle for it.
>>>>> 
>>>>> wsconsctl | grep mouse gives me only:
>>>>> mouse.type=ps2
>>>>> 
>>>>> In the dmesg output I can see only:
>>>>> wsmouse0 at pms0 mux 0
>>>> 
>>>> Indeed, there's no pms(4) compatible touchpad on your machine. :-(
>>>> 
>>>>> "AMDI0010" at acpi0 not configured
>>>>> "SYNA2B3F" at acpi0 not configured
>>>> 
>>>> And instead requires a driver to attach to the I2C HID controler. AMD's
>>>> implementation seems to be somewhat compatible with dwiic(4) written by
>>>> jcs@, however interrupts are not working-- hangs the machine. It does
>>>> work if polling mode is forced.
>>>> 
>>>> This diff made the touchscreen and touchpad work be detected and mostly
>>>> work on my Huawei MateBook D (AMD), however with the touchpad it seems
>>>> to be break Tap-To-Drag. I don't know if this is a side effect of the
>>>> drivers polling, unlike the pms(4) support-- which is working on that
>>>> machine. We have no way to prefer one driver over other, which is why
>>>> I haven't sent this diff yet.
>>>> 
>>>> Let me know if it works at all for you.
>>> 
>>> Much appreciated, will try this and report the outcome
>> 
>> Applying this patch gives me the following:
>> 
>> Hmm...  Looks like a unified diff to me...
>> The text leading up to this was:
>> --
>> |Index: dwiic_acpi.c
>> |===
>> |RCS file: /cvs/src/sys/dev/acpi/dwiic_acpi.c,v
>> |retrieving revision 1.8
>> |diff -u -p -u -r1.8 dwiic_acpi.c
>> |--- sys/dev/acpi/dwiic_acpi.c   1 Jul 2018 11:37:11 -   1.8
>> |+++ sys/dev/acpi/dwiic_acpi.c   5 Jun 2019 00:25:29 -
>> --
>> Patching file dwiic_acpi.c using Plan A...
>> patch:  malformed patch at line 9: };
> 
> Your mail client may have mangled it-- can you try grabbing it
> from marc.info? If not, I'll send a direct link.
> 
> https://marc.info/?l=openbsd-misc&m=156045760827816&q=raw
> 

Yes sorry about that false report :) my mistake.

Applied and recompiling at the moment. Will report back soon.



Re: Lenovo V330-14 touchpad is not working at all

2019-06-13 Thread Tristan



> On 13 Jun 2019, at 22:34, Tristan  wrote:
> 
> 
> 
>> On 13 Jun 2019, at 22:25, Bryan Steele  wrote:
>> 
>> On Thu, Jun 13, 2019 at 08:39:48PM +0200, Tristan wrote:
>>> Hi there,
>>> 
>>> I got a new lenovo v330-14 it has an AMD Ryzen 5 2500U and Radeon RX Vega 8
>>> and so was looking forward to using OpenBSD on this one. I'm currently 
>>> running a
>>> snapshot I grabbed today. To get the screen working I had to set 
>>> machdep.allowaperture=2
>>> unfortunately, but it works now and great as well. Video seems smooth. 
>>> Audio works as well
>> 
>> You should avoid doing that -- see recent mailing lists post from Mark
>> Kettenis.
>> 
>> https://marc.info/?l=openbsd-misc&m=156029398905090&w=2
>> 
>> For Vega graphics you need to recompile your kernel with the amdgpu
>> driver lines uncommented, alternatively reinstall in UEFI mode to get the
>> efifb(4) driver instead. This is probably better as amdgpu support is
>> still a WIP.
>> 
> 
> OK yes, I remember seeing something about it. Will give that a try. Much 
> better then opening up :)
> 
> 
>>> but the touchpad is not working at all. Wireless card does not work either, 
>>> but using the 
>>> ethernet port on it for now until I get an USB dongle for it.
>>> 
>>> wsconsctl | grep mouse gives me only:
>>> mouse.type=ps2
>>> 
>>> In the dmesg output I can see only:
>>> wsmouse0 at pms0 mux 0
>> 
>> Indeed, there's no pms(4) compatible touchpad on your machine. :-(
>> 
>>> "AMDI0010" at acpi0 not configured
>>> "SYNA2B3F" at acpi0 not configured
>> 
>> And instead requires a driver to attach to the I2C HID controler. AMD's
>> implementation seems to be somewhat compatible with dwiic(4) written by
>> jcs@, however interrupts are not working-- hangs the machine. It does
>> work if polling mode is forced.
>> 
>> This diff made the touchscreen and touchpad work be detected and mostly
>> work on my Huawei MateBook D (AMD), however with the touchpad it seems
>> to be break Tap-To-Drag. I don't know if this is a side effect of the
>> drivers polling, unlike the pms(4) support-- which is working on that
>> machine. We have no way to prefer one driver over other, which is why
>> I haven't sent this diff yet.
>> 
>> Let me know if it works at all for you.
> 
> Much appreciated, will try this and report the outcome

Applying this patch gives me the following:

Hmm...  Looks like a unified diff to me...
The text leading up to this was:
--
|Index: dwiic_acpi.c
|===
|RCS file: /cvs/src/sys/dev/acpi/dwiic_acpi.c,v
|retrieving revision 1.8
|diff -u -p -u -r1.8 dwiic_acpi.c
|--- sys/dev/acpi/dwiic_acpi.c  1 Jul 2018 11:37:11 -   1.8
|+++ sys/dev/acpi/dwiic_acpi.c  5 Jun 2019 00:25:29 -
--
Patching file dwiic_acpi.c using Plan A...
patch:  malformed patch at line 9: };


>> 
>> -Bryan.
>> 
>> Index: dwiic_acpi.c
>> ===
>> RCS file: /cvs/src/sys/dev/acpi/dwiic_acpi.c,v
>> retrieving revision 1.8
>> diff -u -p -u -r1.8 dwiic_acpi.c
>> --- sys/dev/acpi/dwiic_acpi.c1 Jul 2018 11:37:11 -   1.8
>> +++ sys/dev/acpi/dwiic_acpi.c5 Jun 2019 00:25:29 -
>> @@ -66,6 +66,7 @@ struct cfattach dwiic_acpi_ca = {
>> };
>> 
>> const char *dwiic_hids[] = {
>> +"AMDI0010",
>>  "INT33C2",
>>  "INT33C3",
>>  "INT3432",
>> @@ -163,8 +164,11 @@ dwiic_acpi_attach(struct device *parent,
>>  dwiic_enable(sc, 0);
>>  dwiic_read(sc, DW_IC_CLR_INTR);
>> 
>> -/* try to register interrupt with apic, but not fatal without it */
>> -if (crs.irq_int > 0) {
>> +/* XXX: AMD i2c controllers have a problem with interrupts enabled */
>> +if (strcmp(sc->sc_hid, "AMDI0010") == 0)
>> +sc->sc_poll = 1;
>> +else if (crs.irq_int > 0) {
>> +/* try to register interrupt with apic, not fatal without it */
>>  printf(" irq %d", crs.irq_int);
>> 
>>  sc->sc_ih = acpi_intr_establish(crs.irq_int, crs.irq_flags,
>> @@ -294,6 +298,9 @@ dwiic_acpi_bus_scan(struct device *iic, 
>>  struct dwiic_softc *sc = (struct dwiic_softc *)aux;
>> 
>>  sc->sc_iic = iic;
>> +/* XXX: Workaround broken interrupts on AMD for i2c slave devices. */
>> +if (strcmp(sc->sc_hid, "AMDI0010") == 0)
>> +sc->sc_poll_ihidev = 1;
>>  aml_find_node(sc->sc_devnode, "_HID", dwiic_acpi_found_hid, sc);
>> }
>> 
>> 
> 



Re: Lenovo V330-14 touchpad is not working at all

2019-06-13 Thread Tristan



> On 13 Jun 2019, at 22:25, Bryan Steele  wrote:
> 
> On Thu, Jun 13, 2019 at 08:39:48PM +0200, Tristan wrote:
>> Hi there,
>> 
>> I got a new lenovo v330-14 it has an AMD Ryzen 5 2500U and Radeon RX Vega 8
>> and so was looking forward to using OpenBSD on this one. I'm currently 
>> running a
>> snapshot I grabbed today. To get the screen working I had to set 
>> machdep.allowaperture=2
>> unfortunately, but it works now and great as well. Video seems smooth. Audio 
>> works as well
> 
> You should avoid doing that -- see recent mailing lists post from Mark
> Kettenis.
> 
> https://marc.info/?l=openbsd-misc&m=156029398905090&w=2
> 
> For Vega graphics you need to recompile your kernel with the amdgpu
> driver lines uncommented, alternatively reinstall in UEFI mode to get the
> efifb(4) driver instead. This is probably better as amdgpu support is
> still a WIP.
> 

OK yes, I remember seeing something about it. Will give that a try. Much 
better then opening up :)


>> but the touchpad is not working at all. Wireless card does not work either, 
>> but using the 
>> ethernet port on it for now until I get an USB dongle for it.
>> 
>> wsconsctl | grep mouse gives me only:
>> mouse.type=ps2
>> 
>> In the dmesg output I can see only:
>> wsmouse0 at pms0 mux 0
> 
> Indeed, there's no pms(4) compatible touchpad on your machine. :-(
> 
>> "AMDI0010" at acpi0 not configured
>> "SYNA2B3F" at acpi0 not configured
> 
> And instead requires a driver to attach to the I2C HID controler. AMD's
> implementation seems to be somewhat compatible with dwiic(4) written by
> jcs@, however interrupts are not working-- hangs the machine. It does
> work if polling mode is forced.
> 
> This diff made the touchscreen and touchpad work be detected and mostly
> work on my Huawei MateBook D (AMD), however with the touchpad it seems
> to be break Tap-To-Drag. I don't know if this is a side effect of the
> drivers polling, unlike the pms(4) support-- which is working on that
> machine. We have no way to prefer one driver over other, which is why
> I haven't sent this diff yet.
> 
> Let me know if it works at all for you.

Much appreciated, will try this and report the outcome.

> 
> -Bryan.
> 
> Index: dwiic_acpi.c
> ===
> RCS file: /cvs/src/sys/dev/acpi/dwiic_acpi.c,v
> retrieving revision 1.8
> diff -u -p -u -r1.8 dwiic_acpi.c
> --- sys/dev/acpi/dwiic_acpi.c 1 Jul 2018 11:37:11 -   1.8
> +++ sys/dev/acpi/dwiic_acpi.c 5 Jun 2019 00:25:29 -
> @@ -66,6 +66,7 @@ struct cfattach dwiic_acpi_ca = {
> };
> 
> const char *dwiic_hids[] = {
> + "AMDI0010",
>   "INT33C2",
>   "INT33C3",
>   "INT3432",
> @@ -163,8 +164,11 @@ dwiic_acpi_attach(struct device *parent,
>   dwiic_enable(sc, 0);
>   dwiic_read(sc, DW_IC_CLR_INTR);
> 
> - /* try to register interrupt with apic, but not fatal without it */
> - if (crs.irq_int > 0) {
> + /* XXX: AMD i2c controllers have a problem with interrupts enabled */
> + if (strcmp(sc->sc_hid, "AMDI0010") == 0)
> + sc->sc_poll = 1;
> + else if (crs.irq_int > 0) {
> + /* try to register interrupt with apic, not fatal without it */
>   printf(" irq %d", crs.irq_int);
> 
>   sc->sc_ih = acpi_intr_establish(crs.irq_int, crs.irq_flags,
> @@ -294,6 +298,9 @@ dwiic_acpi_bus_scan(struct device *iic, 
>   struct dwiic_softc *sc = (struct dwiic_softc *)aux;
> 
>   sc->sc_iic = iic;
> + /* XXX: Workaround broken interrupts on AMD for i2c slave devices. */
> + if (strcmp(sc->sc_hid, "AMDI0010") == 0)
> + sc->sc_poll_ihidev = 1;
>   aml_find_node(sc->sc_devnode, "_HID", dwiic_acpi_found_hid, sc);
> }
> 
> 



Lenovo V330-14 touchpad is not working at all

2019-06-13 Thread Tristan
l 10821 type Li-Ion 
oem "3549453542849793363"
acpibat1 at acpi0: BAT2 not present
acpiac0 at acpi0: AC unit online
acpibtn0 at acpi0: LID_
acpibtn1 at acpi0: PWRB
"AMDI0030" at acpi0 not configured
"AMDI0010" at acpi0 not configured
"SYNA2B3F" at acpi0 not configured
acpivideo0 at acpi0: VGA_
acpivideo1 at acpi0: VGA_
acpivideo2 at acpi0: VGA_
cpu0: 1996 MHz: speeds: 2000 1700 1600 MHz
pci0 at mainbus0 bus 0
pchb0 at pci0 dev 0 function 0 "AMD AMD64 17h/1xh Root Complex" rev 0x00
"AMD AMD64 17h/1xh IOMMU" rev 0x00 at pci0 dev 0 function 2 not configured
pchb1 at pci0 dev 1 function 0 "AMD AMD64 17h PCIE" rev 0x00
ppb0 at pci0 dev 1 function 6 "AMD AMD64 17h/1xh PCIE" rev 0x00: msi
pci1 at ppb0 bus 1
re0 at pci1 dev 0 function 0 "Realtek 8168" rev 0x15: RTL8168H/8111H (0x5400), 
msi, address 98:29:a6:6f:84:b4
rgephy0 at re0 phy 7: RTL8251 PHY, rev. 0
ppb1 at pci0 dev 1 function 7 "AMD AMD64 17h/1xh PCIE" rev 0x00: msi
pci2 at ppb1 bus 2
vendor "Atheros", unknown product 0x0042 (class network subclass miscellaneous, 
rev 0x31) at pci2 dev 0 function 0 not configured
pchb2 at pci0 dev 8 function 0 "AMD AMD64 17h PCIE" rev 0x00
ppb2 at pci0 dev 8 function 1 "AMD AMD64 17h/1xh PCIE" rev 0x00
pci3 at ppb2 bus 3
vga1 at pci3 dev 0 function 0 "ATI Radeon Vega" rev 0xc4
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
azalia0 at pci3 dev 0 function 1 "ATI Radeon Vega HD Audio" rev 0x00: msi
azalia0: no supported codecs
ccp0 at pci3 dev 0 function 2 "AMD AMD64 17h/1xh Crypto" rev 0x00
xhci0 at pci3 dev 0 function 3 "AMD AMD64 17h/1xh xHCI" rev 0x00: msi, xHCI 1.10
usb0 at xhci0: USB revision 3.0
uhub0 at usb0 configuration 1 interface 0 "AMD xHCI root hub" rev 3.00/1.00 
addr 1
xhci1 at pci3 dev 0 function 4 "AMD AMD64 17h/1xh xHCI" rev 0x00: msi, xHCI 1.10
usb1 at xhci1: USB revision 3.0
uhub1 at usb1 configuration 1 interface 0 "AMD xHCI root hub" rev 3.00/1.00 
addr 1
azalia1 at pci3 dev 0 function 6 "AMD AMD64 17h/1xh HD Audio" rev 0x00: apic 34 
int 30
azalia1: codecs: Conexant/0x510f
audio0 at azalia1
ppb3 at pci0 dev 8 function 2 "AMD AMD64 17h/1xh PCIE" rev 0x00
pci4 at ppb3 bus 4
ahci0 at pci4 dev 0 function 0 "AMD FCH AHCI" rev 0x61: msi, AHCI 1.3.1
ahci0: port 0: 6.0Gb/s
scsibus1 at ahci0: 32 targets
sd0 at scsibus1 targ 0 lun 0:  SCSI3 0/direct 
fixed naa.5002538d42f7e15f
sd0: 244198MB, 512 bytes/sector, 500118192 sectors, thin
"AMD FCH SMBus" rev 0x61 at pci0 dev 20 function 0 not configured
pcib0 at pci0 dev 20 function 3 "AMD FCH LPC" rev 0x51
pchb3 at pci0 dev 24 function 0 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb4 at pci0 dev 24 function 1 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb5 at pci0 dev 24 function 2 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb6 at pci0 dev 24 function 3 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb7 at pci0 dev 24 function 4 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb8 at pci0 dev 24 function 5 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb9 at pci0 dev 24 function 6 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
pchb10 at pci0 dev 24 function 7 "AMD AMD64 17h/1xh Data Fabric" rev 0x00
isa0 at pcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5 irq 1 irq 12
pckbd0 at pckbc0 (kbd slot)
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pms0 at pckbc0 (aux slot)
wsmouse0 at pms0 mux 0
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
vmm0 at mainbus0: SVM/RVI
uvideo0 at uhub0 port 1 configuration 1 interface 0 "Chicony Electronics 
Co.,Ltd. Integrated Camera" rev 2.01/0.27 addr 2
video0 at uvideo0
uhub2 at uhub1 port 2 configuration 1 interface 0 "Genesys Logic USB2.0 Hub" 
rev 2.00/88.32 addr 2
ugen0 at uhub2 port 2 "Atheros Communications product 0xe500" rev 2.01/0.01 
addr 3
vscsi0 at root
scsibus2 at vscsi0: 256 targets
softraid0 at root
scsibus3 at softraid0: 256 targets
root on sd0a (0abcbdac634da197.a) swap on sd0b dump on sd0b

Thanks,
Tristan






Re: OpenBSD on thinkpad x280

2019-05-26 Thread Tristan Pilat
On 25 May 2019 17:04:54 CEST, Claudio Jeker  wrote:
>On Sat, May 25, 2019 at 03:53:03PM +0100, Maurice McCarthy wrote:
>> On 25/05/2019, Timo Myyrä  wrote:
>> > Tristan Pilat  writes:
>> >
>> >> Hi OpenBSD users and devs!
>> >>
>> >> I got a new laptop in January, a thinkpad x280. At that time my
>system
>> >> running 'current' was very slow and I assumed the video
>acceleration
>> >> wasn't working so I just sadly stuck with Debian for a while. I
>then
>> >> saw that an update of the inteldrm landed in current a month ago
>or so
>> >> so I tried yesterday to reinstall current. Unfortunately the
>system is
>> >> still barely usable. Could you guys tell me why the video
>acceleration
>> >> isn't handled? Isn't Kaby lake compatible for now? I saw this
>article
>> >> (https://jcs.org/2017/05/22/xiaomiair) which says it is.
>> >>
>> 
>> You may have to adjust the aperture
>> See /etc/examples/sysctl.conf
>> 
>> #machdep.allowaperture=2 # See xf86(4)
>> 
>
>Nope. That does not help. I bet the issue is not related to anything
>related to inteldrm. It is most probably an interrupt storm happening
>because of Thunderbolt 3. At least that seems to be something people
>complained about.

Hi!

Thanks to you all, I just sent an email to bugs@ about this issue that seems to 
be related to an ACPI bug.

Cheers
-- 
Tristan Pilat
40 avenue des Chartreux
13004 Marseille
06 95 55 74 71



OpenBSD on thinkpad x280

2019-05-25 Thread Tristan Pilat
;softraid0 at root
>scsibus4 at softraid0: 256 targets
>sd2 at scsibus4 targ 1 lun 0:  SCSI2 0/direct
>fixed
>sd2: 244197MB, 512 bytes/sector, 500116577 sectors
>softraid0: volume sd2 is roaming, it used to be sd3, updating metadata
>root on sd2a (1bb8f3f0118bc7f3.a) swap on sd2b dump on sd2b
>drm:pid84047:csr_load_work_fn *NOTICE* Failed to load DMC firmware
>i915/kbl_dmc_ver1_04.bin. Disabling runtime power management.
>drm:pid84047:csr_load_work_fn *NOTICE* DMC firmware homepage:
>https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/tree/i915inteldrm0:
>1920x1080, 32bpp
>wsdisplay0 at inteldrm0 mux 1: console (std, vt100 emulation), using
>wskbd0
>wsdisplay0: screen 1-5 added (std, vt100 emulation)
>iwm0: could not read firmware iwm-8265-22 (error 2)
>iwm0: failed to load init firmware
>ugen0 detached
>umb0 detached
>ucom0 detached
>umodem0 detached
>sd1 detached
>scsibus2 detached
>umass0 detached
>uhub0 detached
>uhub1 detached
>uhub0 at usb0 configuration 1 interface 0 "Intel xHCI root hub" rev
>3.00/1.00 addr 1
>uhub1 at usb1 configuration 1 interface 0 "Intel xHCI root hub" rev
>3.00/1.00 addr 1
>ugen0 at uhub0 port 3 "Generic EMV Smartcard Reader" rev 2.01/1.20 addr
>2
>umass0 at uhub0 port 15 configuration 1 interface 0 "Generic
>USB3.0-CRW" rev 3.00/2.04 addr 3
>umass0: using SCSI over Bulk-Only
>scsibus2 at umass0: 2 targets, initiator 0
>sd1 at scsibus2 targ 1 lun 0:  SCSI4 0/direct
>removable serial.0bda031650103090
>umb0 at uhub0 port 6 configuration 1 interface 0 "FIBOCOM L830-EB-00"
>rev 2.00/3.33 addr 4
>umodem0 at uhub0 port 6 configuration 1 interface 2 "FIBOCOM
>L830-EB-00" rev 2.00/3.33 addr 4
>umodem0: data interface 3, has no CM over data, has break
>umodem0: status change notification available
>ucom0 at umodem0

Cheers,

-- 
Tristan



Re: Enabling BFD on a VLAN interface

2017-06-30 Thread Tristan Delsol
Hi Peter,

Thanks for the quick response. Sorry I thought it was enabled already, my 
mistake. 

Tristan
> On 30 Jun 2017, at 21:03, Peter Hessler  wrote:
> 
> Hi Tristan
> 
> BFD is not yet finished, so it is disabled.  It was not enabled for the
> 6.1-release, sorry.
> 
> 
> On 2017 Jun 30 (Fri) at 20:24:49 +0200 (+0200), Tristan Delsol wrote:
> :Hi all,
> :
> :I currently have BGP setup to our ISP using openBGPd, this works great. I 
> saw that the current stable 6.1 has BFD support added and wanted to enable 
> this using route -n change x.x.x.x -bfd, but seem to have an issue here. 
> :The route is using a VLAN interface and I don’t seem to reply to any BFD 
> messages. Is BFD also supported on VLAN interfaces? or am I waisting my time 
> debugging this.
> :
> :Thanks!
> :
> :Tristan
> : 
> :
> 
> -- 
> Drugs may be the road to nowhere, but at least they're the scenic route!



Enabling BFD on a VLAN interface

2017-06-30 Thread Tristan Delsol
Hi all,

I currently have BGP setup to our ISP using openBGPd, this works great. I saw 
that the current stable 6.1 has BFD support added and wanted to enable this 
using route -n change x.x.x.x -bfd, but seem to have an issue here. 
The route is using a VLAN interface and I don’t seem to reply to any BFD 
messages. Is BFD also supported on VLAN interfaces? or am I waisting my time 
debugging this.

Thanks!

Tristan
 



Re: Pflow granularity

2014-06-24 Thread Tristan PILAT
2014-06-24 13:50 GMT+02:00 Sebastian Benoit :

> Tristan PILAT(tristan.pi...@gmail.com) on 2014.06.24 11:04:35 +0200:
> > I noticed the same problems in my reports
> >
> > Why this diff was not imported ?
>
> you'll have to ask joerg. :)
>
> however right now some people are working on something similar.
>

Very happy to read that :)

Looking forward to know more about that.



Re: Pflow granularity

2014-06-24 Thread Tristan PILAT
2014-06-04 16:37 GMT+02:00 Stuart Henderson :

> On 2014-06-02, Andy  wrote:
> > I think you might have to try softflowd instead of the built-in sflowd..
> >
> > These guys had the same problem and moved to softflowd to allow them to
> > analyse DDOS traffic with netflow..
> >
> > https://ripe68.ripe.net/presentations/276-DDoS.pdf
>
> see also the video from UKNOF28, though my understanding was that a
> big part of the reason for softflowd was to capture stats from blocked
> packets.
>
> I noticed the same problems in my reports

Why this diff was not imported ?
http://marc.info/?l=openbsd-misc&m=124661838923498&w=2

After all, that was a great idea.



Re: Where is my memory?

2014-05-16 Thread Tristan PILAT
2014-05-16 11:45 GMT+02:00 Stuart Henderson :

> On 2014-05-15, Stuart Henderson  wrote:
> > On 2014-05-15, Tristan PILAT  wrote:
> >> So apps are using around 200M of RAM but where is the rest? vmstat is
> not
> >> very useful for me, or maybe i'm not able to understand it.
> >
> > The information might be in here but the line-wrapping makes it
> unreadable.
> > It would also be useful to include netstat -m. Can you try with a newer
> > OpenBSD version? 5.2 is a bit old ..
> >
> >
>
> A reader was nice enough to cut through the mangled formatting
> and point this out off-list:
>
> NameSize Requests FailInUse Pgreq Pgrel Npage Hiwat Minpg
> Maxpg Idle
> pfruleitempl  24 2224044085 933 50224416 303139 572 302567 302567   0
> 80
>
> Perhaps it could be the bug fixed by this commit:
>
> $ acvs log -r1.841 -N sys/net/pf.c
>
> RCS file: /cvs/src/sys/net/pf.c,v
> Working file: sys/net/pf.c
> head: 1.877
> branch:
> locks: strict
> access list:
> keyword substitution: kv
> total revisions: 936;   selected revisions: 1
> description:
> 
> revision 1.841
> date: 2013/10/09 09:32:01;  author: camield;  state: Exp;  lines: +7 -8;
> Don't leak ruleitems from match rules when hitting a per-rule max state
> limit.
>
> ok henning
>
> =
>

Ok, thanks for your reply. Will try to manage to upgrade as soon as
possible.



Re: Where is my memory?

2014-05-15 Thread Tristan PILAT
2014-05-15 18:36 GMT+02:00 Mike Jackson :

> Quoting Tristan PILAT :
>
>  Hi folks,
>>
>> I'm running out of memory on a server causing packets drop and out of
>> memory errors. I'm trying to found out what's exactly using the memory.
>> There are few apps running on it, mainly bgpd, bind, and pf with lots of
>> rules.
>>
>> Here is the top:
>>
>> load averages:  1.33,  1.46,  1.58
>> 42 processes:  41 idle, 1 on processor
>> CPU0 states:  1.5% user,  0.0% nice,  0.0% system,  6.2% interrupt, 92.3%
>> idle
>> CPU1 states:  0.0% user,  0.0% nice,  0.0% system,  0.0% interrupt,  100%
>> idle
>> CPU2 states:  6.1% user,  0.0% nice,  1.5% system,  0.0% interrupt, 92.4%
>> idle
>> CPU3 states:  1.5% user,  0.0% nice,  1.5% system,  0.0% interrupt, 97.0%
>> idle
>> Memory: Real: 240M/1925M act/tot Free: 44M Cache: 179M Swap: 0K/0K
>>
>
>
> Have you tried running without the mp kernel? I know, it sounds like a
> waste on an mp machine, but just sayin'...
>
>
The thing is that it's not possible to reboot the machine right now...
Maybe later.

netstat -m out :

190 mbufs allocated to data 6 mbufs allocated to packet headers 25 mbufs
allocated to socket names and addresses
189/1126/6144 mbuf 2048 byte clusters in use (current/peak/max)
0/8/6144 mbuf 4096 byte clusters in use (current/peak/max)
0/8/6144 mbuf 8192 byte clusters in use (current/peak/max)
0/8/6144 mbuf 9216 byte clusters in use (current/peak/max)
0/8/6144 mbuf 12288 byte clusters in use (current/peak/max)
0/8/6144 mbuf 16384 byte clusters in use (current/peak/max)
0/8/6144 mbuf 65536 byte clusters in use (current/peak/max)
2980 Kbytes allocated to network (14% in use)
0 requests for memory denied
0 requests for memory delayed
0 calls to protocol drain routines



Where is my memory?

2014-05-15 Thread Tristan PILAT
 88pfstateitempl 24 2313164000  019106  3947  3765   182
605 0 85pfruleitempl  24 2224044085 933 50224416 303139
572 302567 302567   0 80pfaltqpl 240  1440
0 2 0 2 2 0 82pfrktable   1312 5982
0  195   22136   185   190 0 86pfrke_plain  160
1062730 7347  3753  3411   342   600 0 88pfosfpen
   112126000  700   224   2042020 0 8
0pfosfp40 73800  410 5 0 5 5 0
80pffrent   40   37590500 1 0 1
 1 0 81pffrag   112   16883100 1 0
1 1 0291rtentpl  200 186878610   468323
81611 58007 23604 25024 0 88rttmrpl   64224070
   0 2 0 2 2 0 82tcpcbpl  560
20402570   32   775   7621375 0 88tcpqepl
 32   41424000 4 0 4 4 0 8
4sackhlpl  24 974000 1 0 1 1 0
81synpl248  186301200 3 0 3
 3 0 83plimitpl 152611180   21 3 0
3 3 0 82inpcbpl  352 170299788   0   78
10190 101741654 0 88bnxpkts   40  1640
 164 2 0 2 2 0 80pfsync72
358226600 1 0 1 1 0 81In use
1324320K, total allocated 1373396K; utilization 96.4%

So, is it pf, the kernel which eat all the memory? Could someone put me in
the picture?

Some crash logs :

May 15 14:19:58 vanbuyten /bsd: UVM: pid 22463 (wc), uid 556 killed:
out of swapMay 15 14:19:58 vanbuyten /bsd: UVM: pid 13869 (pgrep), uid
556 killed: out of swapMay 15 14:20:16 vanbuyten /bsd: UVM: pid 10626
(sshd), uid 0 killed: out of swapMay 15 14:20:17 vanbuyten /bsd: UVM:
pid 2295 (sshd), uid 0 killed: out of swapMay 15 14:20:27 vanbuyten
/bsd: UVM: pid 22501 (sshd), uid 27 killed: out of swapMay 15 14:20:27
vanbuyten /bsd: UVM: pid 21266 (sshd), uid 0 killed: out of swapMay 15
14:20:28 vanbuyten /bsd: UVM: pid 13938 (awk), uid 556 killed: out of
swapMay 15 14:20:28 vanbuyten /bsd: UVM: pid 25743 (awk), uid 556
killed: out of swapMay 15 14:20:28 vanbuyten /bsd: UVM: pid 5439
(login_passwd), uid 0 killed: out of swapMay 15 14:20:28 vanbuyten
/bsd: UVM: pid 32626 (sh), uid 556 killed: out of swapMay 15 14:20:28
vanbuyten /bsd: UVM: pid 21133 (awk), uid 556 killed: out of swapMay
15 14:20:28 vanbuyten /bsd: UVM: pid 15676 (top), uid 556 killed: out
of swapMay 15 14:20:28 vanbuyten /bsd: UVM: pid 2725 (awk), uid 556
killed: out of swap


Attached is the dmesg.

Thanks in advance for your help.
--
Tristan

Mar  8 16:57:37 firewall syslogd: startMar  8 16:57:37 firewall /bsd:
syncing disks... doneMar  8 16:57:37 firewall /bsd: rebooting...Mar  8
16:57:37 firewall /bsd: OpenBSD 5.2 (RAMDISK_CD) #119: Wed Aug  1
10:05:54 MDT 2012Mar  8 16:57:37 firewall /bsd:
dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/RAMDISK_CDMar
 8 16:57:37 firewall /bsd: real mem = 2136207360 (2037MB)Mar  8
16:57:37 firewall /bsd: avail mem = 2059395072 (1963MB)Mar  8 16:57:37
firewall /bsd: mainbus0 at rootMar  8 16:57:37 firewall /bsd: bios0 at
mainbus0: SMBIOS rev. 2.7 @ 0xe65d0 (57 entries)Mar  8 16:57:37
firewall /bsd: bios0: vendor Dell Inc. version "1.3.1" date
11/10/2011Mar  8 16:57:37 firewall /bsd: bios0: Dell Inc. PowerEdge
R210 IIMar  8 16:57:37 firewall /bsd: acpi0 at bios0: rev 2Mar  8
16:57:37 firewall /bsd: acpi0: sleep states S0 S4 S5Mar  8 16:57:37
firewall /bsd: acpi0: tables DSDT FACP SPMI ASF! HPET APIC MCFG BOOT
SSDT ASPT SSDT SSDT HEST ERST BERT EINJMar  8 16:57:37 firewall /bsd:
acpimadt0 at acpi0 addr 0xfee0: PC-AT compatMar  8 16:57:37
firewall /bsd: cpu0 at mainbus0: apid 0 (boot processor)Mar  8
16:57:37 firewall /bsd: cpu0: Intel(R) Core(TM) i3-2100 CPU @ 3.10GHz,
3093.49 MHzMar  8 16:57:37 firewall /bsd: cpu0:
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,SBF,SSE3,PCLMUL,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,SSE4.1,SSE4.2,POPCNT,XSAVE,AVX,NXE,LONG,LAHFMar
 8 16:57:37 firewall /bsd: cpu0: 256KB 64b/line 8-way L2 cacheMar  8
16:57:37 firewall /bsd: cpu0: apic clock running at 99MHzMar  8
16:57:37 firewall /bsd: cpu at mainbus0: not configuredMar  8 16:57:37
firewall last message repeated 2 timesMar  8 16:57:37 firewall /bsd:
ioapic0 at mainbus0: apid 0 pa 0xfec0, version 20, 24 pinsMar  8
16:57:37 firewall /bsd: acpiprt0 at acpi0: bus 0 (PCI0)Mar  8 16:57:37
firewall /bsd: acpiprt1 at acpi0: bus 6 (P0P1)Mar  8 16:57:37 firewall
/bsd: acpiprt2 at acpi0: bus 5 (RP01)Mar  8 16:57:37 firewall /bsd:
acpiprt3 at acpi0: bus -1 (RP02)Mar  8 16:57:37 firewall /bsd:
acpiprt4 at acpi0: bus -1 (RP03)Mar  8 16:57:37 firewall /bsd:
acpiprt5 at acpi0: bus -1 (RP04)Mar  8 16:57:37 fi

Re: firefox with H264

2014-05-13 Thread Tristan PILAT
Thanks Antoine, gstreamer-plugins-bad did the trick, but as the
performances are really bad i will keep using chromium. Maybe Firefox 29 is
not mature enough as well, I find it particularly slow.

Tristan


2014-05-12 18:11 GMT+02:00 Antoine Jacoutot :

> On Mon, May 12, 2014 at 06:08:50PM +0200, Tristan PILAT wrote:
> > Hi,
> >
> > So far i'm using both firefox and chromium, because only chromium brings
> me
> > H264. I would like to know if there is a way to get the patented
> multimedia
> > codecs working in firefox like the chromium-proprietary flavor ?
>
> Try installing gstreamer-ffmpeg and/or gstreamer-plugins-bad
>
> --
> Antoine



firefox with H264

2014-05-12 Thread Tristan PILAT
Hi,

So far i'm using both firefox and chromium, because only chromium brings me
H264. I would like to know if there is a way to get the patented multimedia
codecs working in firefox like the chromium-proprietary flavor ?
--
Tristan



Re: Automatic console locking at system suspend

2014-05-07 Thread Tristan PILAT
> On Mon, Apr 21, 2014 at 4:51 PM, Alessandro DE LAURENZIS <
> just22@gmail.com> wrote:
>
> > Hello,
> >
> > I google-ed a lot, but it seems that there is no trivial solution to
> > this point.
> >
> > I extensively use console (and tmux), ending up with a lot of
> > simultaneously open shells; I normally suspend my laptop when I leave,
> > so it would be a security enhancement to automatically lock all of them.
> >
>

I advice you to install slock and autolock and then add something like for
example
"exec xautolock -time 10 -locker 'slock' &" to your .xinirc or .xsession
--
Tristan



Re: BGP - IP Blackhole

2014-04-22 Thread Tristan PILAT
2014-04-22 17:54 GMT+02:00 Laurent CARON :

> On 22/04/2014 17:41, Tristan PILAT wrote:
>
>> Yes but how to do that without hard coded the network of the customer like
>> in this rule;
>> allow from group "customers" community 64514:888 prefix
>> 192.0.33.0/24prefixlen = 32 set nexthope blackhole
>>
>
> Don't you already filter your customers announcements ?
>

That's just a template to show how to use RTBH so the configuration is very
simple.

#BGP1

AS 64514
router-id 172.0.0.2
listen on 172.0.0.2
network 192.0.32.0/24

group "customers" {
remote-as 64515
neighbor 172.0.0.3 {
descr   "AS 64515"
announce all
}
}

deny from any
allow from group "customers" community 64514:888 inet prefix
192.0.33.0/24prefixlen = 32 set nexthope blackhole
#allow from group "customers" community 64514:999 prefixlen = 32 set
pftable dos
allow from any inet prefixlen 8 - 24


#BGP2

AS 64515
router-id 172.0.0.3
listen on 172.0.0.3
network 192.0.33.0/24

group "providers" {
remote-as 64514
neighbor 172.0.0.2 {
descr   "AS 64514"
announce all
}
}

deny from any
allow from any inet prefixlen 8 - 24



Re: BGP - IP Blackhole

2014-04-22 Thread Tristan PILAT
2014-04-17 18:01 GMT+02:00 Laurent CARON :

> On 17/04/2014 11:24, Tristan PILAT wrote:
>
>> Is there a way to make this work with "allow from any inet prefixlen 8 -
>> 24" to accept /32 only for the blackhole ?
>>
>
>
> Please pay attention of not allowing one of your customers to blackhole
> addresses from YOUR nets ;)
>

Yes but how to do that without hard coded the network of the customer like
in this rule;
allow from group "customers" community 64514:888 prefix
192.0.33.0/24prefixlen = 32 set nexthope blackhole



Re: BGP - IP Blackhole

2014-04-18 Thread Tristan PILAT
2014-04-18 16:34 GMT+02:00 Marios Makassikis :

>
>
>
> On 18 April 2014 16:29, Tristan PILAT  wrote:
>
>> 2014-04-18 10:23 GMT+02:00 Tristan PILAT :
>>
>> > 2014-04-17 19:27 GMT+02:00 Tristan Pilat :
>> >
>> >>
>> >>
>> >> On 17 avril 2014 19:02:14 CEST, Claudio Jeker <
>> cje...@diehard.n-r-g.com>
>> >> wrote:
>> >> >You can't use rtlabels for matching the source, at least I think it
>> >> >does
>> >> >not work.  I would try to use the "set pftable dos" in bgpd and
>> >> >"block quick drop from " in pf.
>> >>
>> >> Ok i will try this tomorrow thanks. But if it does not work. How can I
>> >> set up blockhole based on source address as described in RFC5635 with
>> >> OpenBSD ?
>> >> --
>> >> Tristan
>> >>
>> >
>> > Me again.
>> >
>> > This slide from a presentation by Henning Brauer is very interesting...
>> > http://quigon.bsws.de/papers/2014/asiabsdcon/mgp00031.html
>> >
>> > i'm keep digging :-)
>> > --
>> > Tristan
>> >
>>
>> Thanks Claudio, I just tested it and it works with "set pftable dos" in
>> bgpd.conf and "block drop quick from " in pf.conf but there still a
>> small thing. In my lab i tried this, sending icmp, and it works only if i
>> stop the ping command and i relaunch it. I mean, if i'm pinging an IP
>> address and set the "bgpctl network add..." it don't hang ping.
>>
>> How can I stop the flow immediatly with PF ?
>>
>>
> Sounds like your traffic is matching an existing state which is why it's
> still passing.
> Look at pfctl manpage, and more specifically the -k switch.
>
>
Yes it works with pfctl -k. Now I need to find a way to use "flush" in
pf.conf to kill the states.



Re: BGP - IP Blackhole

2014-04-18 Thread Tristan PILAT
2014-04-18 10:23 GMT+02:00 Tristan PILAT :

> 2014-04-17 19:27 GMT+02:00 Tristan Pilat :
>
>>
>>
>> On 17 avril 2014 19:02:14 CEST, Claudio Jeker 
>> wrote:
>> >You can't use rtlabels for matching the source, at least I think it
>> >does
>> >not work.  I would try to use the "set pftable dos" in bgpd and
>> >"block quick drop from " in pf.
>>
>> Ok i will try this tomorrow thanks. But if it does not work. How can I
>> set up blockhole based on source address as described in RFC5635 with
>> OpenBSD ?
>> --
>> Tristan
>>
>
> Me again.
>
> This slide from a presentation by Henning Brauer is very interesting...
> http://quigon.bsws.de/papers/2014/asiabsdcon/mgp00031.html
>
> i'm keep digging :-)
> --
> Tristan
>

Thanks Claudio, I just tested it and it works with "set pftable dos" in
bgpd.conf and "block drop quick from " in pf.conf but there still a
small thing. In my lab i tried this, sending icmp, and it works only if i
stop the ping command and i relaunch it. I mean, if i'm pinging an IP
address and set the "bgpctl network add..." it don't hang ping.

How can I stop the flow immediatly with PF ?

--
Tristan



Re: BGP - IP Blackhole

2014-04-18 Thread Tristan PILAT
2014-04-17 19:27 GMT+02:00 Tristan Pilat :

>
>
> On 17 avril 2014 19:02:14 CEST, Claudio Jeker 
> wrote:
> >You can't use rtlabels for matching the source, at least I think it
> >does
> >not work.  I would try to use the "set pftable dos" in bgpd and
> >"block quick drop from " in pf.
>
> Ok i will try this tomorrow thanks. But if it does not work. How can I set
> up blockhole based on source address as described in RFC5635 with OpenBSD ?
> --
> Tristan


Me again.

This slide from a presentation by Henning Brauer is very interesting...
http://quigon.bsws.de/papers/2014/asiabsdcon/mgp00031.html

i'm keep digging :-)
--
Tristan



Re: BGP - IP Blackhole

2014-04-17 Thread Tristan Pilat
On 17 avril 2014 19:02:14 CEST, Claudio Jeker  wrote:
>On Thu, Apr 17, 2014 at 05:17:15PM +0200, Tristan PILAT wrote:
>> 2014-04-17 15:23 GMT+02:00 Tristan PILAT :
>> 
>> > 2014-04-17 13:20 GMT+02:00 Tristan PILAT :
>> >
>> > 2014-04-17 12:25 GMT+02:00 Gregory Edigarov :
>> >>
>> >>> On 04/17/2014 12:24 PM, Tristan PILAT wrote:
>> >>>
>> >>>  2014-04-15 18:42 GMT+02:00 Laurent Caron (Mobile) <
>> >>>> lca...@unix-scripts.info>
>> >>>> :
>> >>>>
>> >>>>  On 14 avril 2014 17:57:53 CEST, Tristan PILAT
>> >>>>> >
>> >>>>> wrote:
>> >>>>>
>> >>>>>> match from any community 64514:888 set nexthop blackhole
>> >>>>>>
>> >>>>>>  Hi,
>> >>>>>
>> >>>>> Make sure you dont accept from any but eg from group customers,
>make
>> >>>>> sure
>> >>>>> the address *does* belong to your customers space (to avoid a
>customer
>> >>>>> installing a blackhole route on a route you advertise).
>> >>>>> Make sure you do strip 64514:888 from other peers.
>> >>>>> ...
>> >>>>>
>> >>>>>  And what about the client side ? Which command should he enter
>if he
>> >>>>>> wishes
>> >>>>>> to blackhole ip 1.2.3.4 eg
>> >>>>>>
>> >>>>>> Is it something like that ? bgpctl network add 1.2.3.4/32
>community
>> >>>>>> 64514:888
>> >>>>>>
>> >>>>> Exactly.
>> >>>>>
>> >>>>> Hi,
>> >>>>>
>> >>>> Thanks for your reply ! I just tested this in my lab and it's
>working
>> >>>> like
>> >>>> a charm but only if I set "allow from any inet prefixlen 8 - 32"
>and
>> >>>> this
>> >>>> is annoying.
>> >>>>
>> >>>> Is there a way to make this work with "allow from any inet
>prefixlen 8 -
>> >>>> 24" to accept /32 only for the blackhole ?
>> >>>>
>> >>>> --
>> >>>> Tristan
>> >>>>
>> >>> like this:
>> >>>
>> >>>
>> >>> allow from any inet prefixlen 8 - 24
>> >>> allow from any inet prefixlen 32 community 64514:888
>> >>>
>> >>>
>> >> That goes without saying after all :-) Thanks !
>> >>
>> >> --
>> >> Tristan
>> >>
>> >
>> > Another question... Anyone knows if there is a way to do Source
>> > Base Remotely-Triggered Black Hole with OpenBGPd ? eg If I am
>attacked by a
>> > single IP and i want to blackhole it.
>> >
>> 
>> I found something to do Source Base Remotely-Triggered Black Hole.
>> 
>> On the provider side, i can set labels like that :
>> In bgpd.conf --> match from any community 64514:999 set rtlabel dos
>> In pf.conf --> block drop from route dos
>> 
>> On the client side, if we want to black 4.3.2.1/32 source ip :
>> bgpctl network add 4.3.2.1/32 community 64514:999
>> 
>> Unfortunaly this is not working, i certainly missed something !
>Please give
>> me hints :-)
>
>You can't use rtlabels for matching the source, at least I think it
>does
>not work.  I would try to use the "set pftable dos" in bgpd and
>"block quick drop from " in pf.

Ok i will try this tomorrow thanks. But if it does not work. How can I set up 
blockhole based on source address as described in RFC5635 with OpenBSD ?
-- 
Tristan



Re: BGP - IP Blackhole

2014-04-17 Thread Tristan PILAT
2014-04-17 15:23 GMT+02:00 Tristan PILAT :

> 2014-04-17 13:20 GMT+02:00 Tristan PILAT :
>
> 2014-04-17 12:25 GMT+02:00 Gregory Edigarov :
>>
>>> On 04/17/2014 12:24 PM, Tristan PILAT wrote:
>>>
>>>  2014-04-15 18:42 GMT+02:00 Laurent Caron (Mobile) <
>>>> lca...@unix-scripts.info>
>>>> :
>>>>
>>>>  On 14 avril 2014 17:57:53 CEST, Tristan PILAT >>>> >
>>>>> wrote:
>>>>>
>>>>>> match from any community 64514:888 set nexthop blackhole
>>>>>>
>>>>>>  Hi,
>>>>>
>>>>> Make sure you dont accept from any but eg from group customers, make
>>>>> sure
>>>>> the address *does* belong to your customers space (to avoid a customer
>>>>> installing a blackhole route on a route you advertise).
>>>>> Make sure you do strip 64514:888 from other peers.
>>>>> ...
>>>>>
>>>>>  And what about the client side ? Which command should he enter if he
>>>>>> wishes
>>>>>> to blackhole ip 1.2.3.4 eg
>>>>>>
>>>>>> Is it something like that ? bgpctl network add 1.2.3.4/32 community
>>>>>> 64514:888
>>>>>>
>>>>> Exactly.
>>>>>
>>>>> Hi,
>>>>>
>>>> Thanks for your reply ! I just tested this in my lab and it's working
>>>> like
>>>> a charm but only if I set "allow from any inet prefixlen 8 - 32" and
>>>> this
>>>> is annoying.
>>>>
>>>> Is there a way to make this work with "allow from any inet prefixlen 8 -
>>>> 24" to accept /32 only for the blackhole ?
>>>>
>>>> --
>>>> Tristan
>>>>
>>> like this:
>>>
>>>
>>> allow from any inet prefixlen 8 - 24
>>> allow from any inet prefixlen 32 community 64514:888
>>>
>>>
>> That goes without saying after all :-) Thanks !
>>
>> --
>> Tristan
>>
>
> Another question... Anyone knows if there is a way to do Source
> Base Remotely-Triggered Black Hole with OpenBGPd ? eg If I am attacked by a
> single IP and i want to blackhole it.
>

I found something to do Source Base Remotely-Triggered Black Hole.

On the provider side, i can set labels like that :
In bgpd.conf --> match from any community 64514:999 set rtlabel dos
In pf.conf --> block drop from route dos

On the client side, if we want to black 4.3.2.1/32 source ip :
bgpctl network add 4.3.2.1/32 community 64514:999

Unfortunaly this is not working, i certainly missed something ! Please give
me hints :-)



Re: BGP - IP Blackhole

2014-04-17 Thread Tristan PILAT
2014-04-17 13:20 GMT+02:00 Tristan PILAT :

> 2014-04-17 12:25 GMT+02:00 Gregory Edigarov :
>
>> On 04/17/2014 12:24 PM, Tristan PILAT wrote:
>>
>>  2014-04-15 18:42 GMT+02:00 Laurent Caron (Mobile) <
>>> lca...@unix-scripts.info>
>>> :
>>>
>>>  On 14 avril 2014 17:57:53 CEST, Tristan PILAT 
>>>> wrote:
>>>>
>>>>> match from any community 64514:888 set nexthop blackhole
>>>>>
>>>>>  Hi,
>>>>
>>>> Make sure you dont accept from any but eg from group customers, make
>>>> sure
>>>> the address *does* belong to your customers space (to avoid a customer
>>>> installing a blackhole route on a route you advertise).
>>>> Make sure you do strip 64514:888 from other peers.
>>>> ...
>>>>
>>>>  And what about the client side ? Which command should he enter if he
>>>>> wishes
>>>>> to blackhole ip 1.2.3.4 eg
>>>>>
>>>>> Is it something like that ? bgpctl network add 1.2.3.4/32 community
>>>>> 64514:888
>>>>>
>>>> Exactly.
>>>>
>>>> Hi,
>>>>
>>> Thanks for your reply ! I just tested this in my lab and it's working
>>> like
>>> a charm but only if I set "allow from any inet prefixlen 8 - 32" and this
>>> is annoying.
>>>
>>> Is there a way to make this work with "allow from any inet prefixlen 8 -
>>> 24" to accept /32 only for the blackhole ?
>>>
>>> --
>>> Tristan
>>>
>> like this:
>>
>>
>> allow from any inet prefixlen 8 - 24
>> allow from any inet prefixlen 32 community 64514:888
>>
>>
> That goes without saying after all :-) Thanks !
>
> --
> Tristan
>

Another question... Anyone knows if there is a way to do Source
Base Remotely-Triggered Black Hole with OpenBGPd ? eg If I am attacked by a
single IP and i want to blackhole it.



Re: BGP - IP Blackhole

2014-04-17 Thread Tristan PILAT
2014-04-17 12:25 GMT+02:00 Gregory Edigarov :

> On 04/17/2014 12:24 PM, Tristan PILAT wrote:
>
>> 2014-04-15 18:42 GMT+02:00 Laurent Caron (Mobile) <
>> lca...@unix-scripts.info>
>> :
>>
>>  On 14 avril 2014 17:57:53 CEST, Tristan PILAT 
>>> wrote:
>>>
>>>> match from any community 64514:888 set nexthop blackhole
>>>>
>>>>  Hi,
>>>
>>> Make sure you dont accept from any but eg from group customers, make sure
>>> the address *does* belong to your customers space (to avoid a customer
>>> installing a blackhole route on a route you advertise).
>>> Make sure you do strip 64514:888 from other peers.
>>> ...
>>>
>>>  And what about the client side ? Which command should he enter if he
>>>> wishes
>>>> to blackhole ip 1.2.3.4 eg
>>>>
>>>> Is it something like that ? bgpctl network add 1.2.3.4/32 community
>>>> 64514:888
>>>>
>>> Exactly.
>>>
>>> Hi,
>>>
>> Thanks for your reply ! I just tested this in my lab and it's working like
>> a charm but only if I set "allow from any inet prefixlen 8 - 32" and this
>> is annoying.
>>
>> Is there a way to make this work with "allow from any inet prefixlen 8 -
>> 24" to accept /32 only for the blackhole ?
>>
>> --
>> Tristan
>>
> like this:
>
>
> allow from any inet prefixlen 8 - 24
> allow from any inet prefixlen 32 community 64514:888
>
>
That goes without saying after all :-) Thanks !

--
Tristan



Re: BGP - IP Blackhole

2014-04-17 Thread Tristan PILAT
2014-04-15 18:42 GMT+02:00 Laurent Caron (Mobile) 
:

> On 14 avril 2014 17:57:53 CEST, Tristan PILAT 
> wrote:
> >match from any community 64514:888 set nexthop blackhole
> >
>
> Hi,
>
> Make sure you dont accept from any but eg from group customers, make sure
> the address *does* belong to your customers space (to avoid a customer
> installing a blackhole route on a route you advertise).
> Make sure you do strip 64514:888 from other peers.
> ...
>
> >And what about the client side ? Which command should he enter if he
> >wishes
> >to blackhole ip 1.2.3.4 eg
> >
> >Is it something like that ? bgpctl network add 1.2.3.4/32 community
> >64514:888
>
> Exactly.
>
> Hi,

Thanks for your reply ! I just tested this in my lab and it's working like
a charm but only if I set "allow from any inet prefixlen 8 - 32" and this
is annoying.

Is there a way to make this work with "allow from any inet prefixlen 8 -
24" to accept /32 only for the blackhole ?

--
Tristan



BGP - IP Blackhole

2014-04-14 Thread Tristan PILAT
Hi,

I am trying to set up OpenBGPD with blackhole support in order to be able
to receive /32 announce from my neighbors with a specific community.

The man page didn't help me much or maybe i missed something. Is it this
rule that is the right one ?

match from any community 64514:888 set nexthop blackhole

And what about the client side ? Which command should he enter if he wishes
to blackhole ip 1.2.3.4 eg

Is it something like that ? bgpctl network add 1.2.3.4/32 community
64514:888

I hope to be clear enough in my explaination

Thanks in advance

--
Tristan



Re: Left USB port are not working on Thinkpad X230

2014-04-14 Thread Tristan PILAT
2014-04-12 18:58 GMT+02:00 Robert Blacquiere :

> On Sat, Apr 12, 2014 at 06:48:23PM +0200, Tristan PILAT wrote:
> > Hi all,
> >
> > I'm under current (2014-04-08) and i noticed that my two left USB ports
> are
> > not working anymore on my Thinkpad X230. Did anyone else notice that ?
> >
> 
>
> Hi,
>
> I have a thinkpad w530 with current of last weekend. I have changed
> bios for USB-3.0 settings because the default caused 2 of the 4 ports to
> be none functional. With changed settings it works as normal.
>
> Maybe this is because some of the work on usb 3.0 improvements?
>
> Regards
>
> Robert
>
>
That did the trick ! Thanks to all of you :-)

--
Tristan



Left USB port are not working on Thinkpad X230

2014-04-12 Thread Tristan PILAT
;Intel 7 Series PCIE" rev 0xc4: msi
pci2 at ppb1 bus 3
iwn0 at pci2 dev 0 function 0 "Intel Centrino Ultimate-N 6300" rev 0x3e:
msi, MIMO 3T3R, MoW, address 3c:a9:f4:7e:0d:fc
ppb2 at pci0 dev 28 function 2 "Intel 7 Series PCIE" rev 0xc4: msi
pci3 at ppb2 bus 4
ehci1 at pci0 dev 29 function 0 "Intel 7 Series USB" rev 0x04: apic 2 int 23
usb1 at ehci1: USB revision 2.0
uhub1 at usb1 "Intel EHCI root hub" rev 2.00/1.00 addr 1
pcib0 at pci0 dev 31 function 0 "Intel QM77 LPC" rev 0x04
ahci0 at pci0 dev 31 function 2 "Intel 7 Series AHCI" rev 0x04: msi, AHCI
1.3
scsibus1 at ahci0: 32 targets
sd0 at scsibus1 targ 0 lun 0:  SCSI3 0/direct
fixed naa.50025385
sd0: 122104MB, 512 bytes/sector, 250069680 sectors, thin
sd1 at scsibus1 targ 2 lun 0:  SCSI3 0/direct
fixed naa.500a07510943d82b
sd1: 114473MB, 512 bytes/sector, 234441648 sectors, thin
ichiic0 at pci0 dev 31 function 3 "Intel 7 Series SMBus" rev 0x04: apic 2
int 18
iic0 at ichiic0
spdmem0 at iic0 addr 0x50: 4GB DDR3 SDRAM PC3-12800 SO-DIMM
spdmem1 at iic0 addr 0x51: 4GB DDR3 SDRAM PC3-12800 SO-DIMM
isa0 at pcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pms0 at pckbc0 (aux slot)
pckbc0: using irq 12 for aux slot
wsmouse0 at pms0 mux 0
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
uhub2 at uhub0 port 1 "Intel Rate Matching Hub" rev 2.00/0.00 addr 2
uhub3 at uhub1 port 1 "Intel Rate Matching Hub" rev 2.00/0.00 addr 2
vscsi0 at root
scsibus2 at vscsi0: 256 targets
softraid0 at root
scsibus3 at softraid0: 256 targets
root on sd0a (557f61f2da19e69f.a) swap on sd0b dump on sd0b
iwn0: radio is disabled by hardware switch

--
Tristan



Re: Kernel error with March 20th amd64 snapshot

2014-03-22 Thread Tristan PILAT
2014-03-22 18:31 GMT+01:00 Martin Pieuchot :

> On 22/03/14(Sat) 02:30, Shawn K. Quinn wrote:
> > On Fri, Mar 21, 2014, at 07:34 PM, Tristan PILAT wrote:
> > > Hello,
> > >
> > > I noticed a crash with the March 20th amd64 snapshot. When I
> > > unplug my USB wireless mouse receiver, i get this;
> > >
> > > wskbd1: disconnecting from wsdisplay0
> > > wskbd1 detached
> > > ukbd0 detached
> > > uhidev0 detached
> > > uvm_faut(0x81dc6f00, 0x24, 0, 1) -> e
> > > kernel: page faut trap, code=0
> > > Stopper at  strlcpy+0x16movzbl  0(%rcx), %eax
> > > ddb1{1}>
> > >
> > > I own a thinkpad x230 and only the right side USB port is working
> > > after the upgrade, the two left side USB port are not working
> > > anymore. Find attached my dmesg.
> >
> > A similar crash happened with the March 19th snapshot here as well when
> > switching computers on my USB KVM switch. My backtrace also indicates a
> > kernel trap in strlcpy. I was about to upgrade to the March 20th
> > snapshot to see if it was still there.
>
> It is likely to be there since it's the first time I here about such
> regression and sadly there's not enough information in your bug report
> to do anything :(
>
> Could you provide a dmesg with the USB keyboard (or whatever device
> causing the problem) plugged in and a trace when the panic occurs.
>
>
That's the error with the trace;

siocGIFADDR: Can't assign requested address
sI0CGIFADDR: Can't assign requested address
ehei idone: ex-tx 8085ca00 is done!
wskbd18 disconnecting fron wsdisplay0
wskbd1 detached
ukbd0 detached
uhidev0 detached
uvn au
(0xf f f f f ff f 81de6 00, 0x24, 0, 1) -> e
kernel: page fault trap, codes0
Stopped at   str lepy+0x168 novzbl 0 (Zrcx), Zeax
ddb 10 > trace
stricpyo at stricpy+0x16
config detach at config detach+0x97
config detach at config detache0x143
usb disconnect porto at usb disconnect port+0x6a
uhub explore at uhub explore 0x12b
uhub lore at uhub explore 0x97
usb explore at usb explore+0xcf
usb-task-thread at usb-task-thread+0xb2
end trace frame: 0x0, count -8
ddb 101 >

Attached is the dmesg with the USB receiver plugged.

I hope this will help.
OpenBSD 5.5-current (GENERIC.MP) #10: Thu Mar 20 23:09:39 MDT 2014
dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 8254586880 (7872MB)
avail mem = 8026124288 (7654MB)
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 2.7 @ 0xdae9d000 (68 entries)
bios0: vendor LENOVO version "G2ET96WW (2.56 )" date 08/27/2013
bios0: LENOVO 2324CTO
acpi0 at bios0: rev 2
acpi0: sleep states S0 S3 S4 S5
acpi0: tables DSDT FACP TCPA SSDT SSDT SSDT HPET APIC MCFG ECDT FPDT ASF! UEFI 
UEFI MSDM SSDT SSDT UEFI DBG2
acpi0: wakeup devices LID_(S4) SLPB(S3) IGBE(S4) EXP3(S4) XHCI(S3) EHC1(S3) 
EHC2(S3) HDEF(S4)
acpitimer0 at acpi0: 3579545 Hz, 24 bits
acpihpet0 at acpi0: 14318179 Hz
acpimadt0 at acpi0 addr 0xfee0: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.48 MHz
cpu0: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu0: 256KB 64b/line 8-way L2 cache
cpu0: smt 0, core 0, package 0
mtrr: Pentium Pro MTRR support, 10 var ranges, 88 fixed ranges
cpu0: apic clock running at 99MHz
cpu0: mwait min=64, max=64, C-substates=0.2.1.1.2, IBE
cpu1 at mainbus0: apid 1 (application processor)
cpu1: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.12 MHz
cpu1: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu1: 256KB 64b/line 8-way L2 cache
cpu1: smt 1, core 0, package 0
cpu2 at mainbus0: apid 2 (application processor)
cpu2: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.12 MHz
cpu2: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu2: 256KB 64b/line 8-way L2 cache
cpu2: smt 0, core 1, package 0
cpu3 at mainbus0: apid 3 (application processor)
cpu3: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.12 MHz
cpu3: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTE

Kernel error with March 20th amd64 snapshot

2014-03-22 Thread Tristan PILAT
Hello,

I noticed a crash with the March 20th amd64 snapshot. When I
unplug my USB wireless mouse receiver, i get this;

wskbd1: disconnecting from wsdisplay0
wskbd1 detached
ukbd0 detached
uhidev0 detached
uvm_faut(0x81dc6f00, 0x24, 0, 1) -> e
kernel: page faut trap, code=0
Stopper at  strlcpy+0x16movzbl  0(%rcx), %eax
ddb1{1}>

I own a thinkpad x230 and only the right side USB port is working
after the upgrade, the two left side USB port are not working
anymore. Find attached my dmesg.

--
Tristan
OpenBSD 5.5-current (GENERIC.MP) #10: Thu Mar 20 23:09:39 MDT 2014
dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP
real mem = 8254586880 (7872MB)
avail mem = 8026124288 (7654MB)
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 2.7 @ 0xdae9d000 (68 entries)
bios0: vendor LENOVO version "G2ET96WW (2.56 )" date 08/27/2013
bios0: LENOVO 2324CTO
acpi0 at bios0: rev 2
acpi0: sleep states S0 S3 S4 S5
acpi0: tables DSDT FACP TCPA SSDT SSDT SSDT HPET APIC MCFG ECDT FPDT ASF! UEFI 
UEFI MSDM SSDT SSDT UEFI DBG2
acpi0: wakeup devices LID_(S4) SLPB(S3) IGBE(S4) EXP3(S4) XHCI(S3) EHC1(S3) 
EHC2(S3) HDEF(S4)
acpitimer0 at acpi0: 3579545 Hz, 24 bits
acpihpet0 at acpi0: 14318179 Hz
acpimadt0 at acpi0 addr 0xfee0: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.48 MHz
cpu0: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu0: 256KB 64b/line 8-way L2 cache
cpu0: smt 0, core 0, package 0
mtrr: Pentium Pro MTRR support, 10 var ranges, 88 fixed ranges
cpu0: apic clock running at 99MHz
cpu0: mwait min=64, max=64, C-substates=0.2.1.1.2, IBE
cpu1 at mainbus0: apid 1 (application processor)
cpu1: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.11 MHz
cpu1: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu1: 256KB 64b/line 8-way L2 cache
cpu1: smt 1, core 0, package 0
cpu2 at mainbus0: apid 2 (application processor)
cpu2: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.11 MHz
cpu2: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu2: 256KB 64b/line 8-way L2 cache
cpu2: smt 0, core 1, package 0
cpu3 at mainbus0: apid 3 (application processor)
cpu3: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz, 2594.11 MHz
cpu3: 
FPU,VME,DE,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,MTRR,PGE,MCA,CMOV,PAT,PSE36,CFLUSH,DS,ACPI,MMX,FXSR,SSE,SSE2,SS,HTT,TM,PBE,SSE3,PCLMUL,DTES64,MWAIT,DS-CPL,VMX,EST,TM2,SSSE3,CX16,xTPR,PDCM,PCID,SSE4.1,SSE4.2,x2APIC,POPCNT,DEADLINE,AES,XSAVE,AVX,F16C,RDRAND,NXE,LONG,LAHF,PERF,ITSC,FSGSBASE,SMEP,ERMS
cpu3: 256KB 64b/line 8-way L2 cache
cpu3: smt 1, core 1, package 0
ioapic0 at mainbus0: apid 2 pa 0xfec0, version 20, 24 pins
acpimcfg0 at acpi0 addr 0xf800, bus 0-63
acpiec0 at acpi0
acpiprt0 at acpi0: bus 0 (PCI0)
acpiprt1 at acpi0: bus -1 (PEG_)
acpiprt2 at acpi0: bus 2 (EXP1)
acpiprt3 at acpi0: bus 3 (EXP2)
acpiprt4 at acpi0: bus 4 (EXP3)
acpicpu0 at acpi0: C2, C1, PSS
acpicpu1 at acpi0: C2, C1, PSS
acpicpu2 at acpi0: C2, C1, PSS
acpicpu3 at acpi0: C2, C1, PSS
acpipwrres0 at acpi0: PUBS, resource for XHCI, EHC1, EHC2
acpitz0 at acpi0: critical temperature is 103 degC
acpibtn0 at acpi0: LID_
acpibtn1 at acpi0: SLPB
acpibat0 at acpi0: BAT0 model "45N1175" serial 14096 type LION oem "SANYO"
acpibat1 at acpi0: BAT1 not present
acpiac0 at acpi0: AC unit online
acpithinkpad0 at acpi0
acpidock0 at acpi0: GDCK not docked (0)
cpu0: Enhanced SpeedStep 2594 MHz: speeds: 2601, 2600, 2500, 2400, 2300, 2200, 
2100, 2000, 1900, 1800, 1700, 1600, 1500, 1400, 1300, 1200 MHz
pci0 at mainbus0 bus 0
pchb0 at pci0 dev 0 function 0 "Intel Core 3G Host" rev 0x09
vga1 at pci0 dev 2 function 0 "Intel HD Graphics 4000" rev 0x09
intagp0 at vga1
agp0 at intagp0: aperture at 0xe000, size 0x1000
inteldrm0 at vga1
drm0 at inteldrm0
inteldrm0: 1366x768
wsdisplay0 at vga1 mux 1: console (std, vt100 emulation)
wsdisplay0: screen 1-5 added (std, vt100 emulation)
"Intel 7 Series xHCI" rev 0x04 at pci0 dev 20 function 0 not configured
"Intel 7 Series MEI" rev 0x04 at pci0 dev 22 function 0 not configured
em0 at pci0 dev 25 function 0 "Intel 82579LM" rev 0x04: msi, address 
3c:97:0e:d8:5d:b4
ehci0 at pci0 dev 26 function 0 "Intel 7 Se

USB problem after time_t change

2013-08-21 Thread Tristan Le Guern
int 16
usb0 at ehci0: USB revision 2.0
uhub0 at usb0 "Intel EHCI root hub" rev 2.00/1.00 addr 1
azalia0 at pci0 dev 27 function 0 "Intel 3400 HD Audio" rev 0x05: msi
azalia0: codecs: IDT 92HD81B1X, Intel/0x2804, using IDT 92HD81B1X
audio0 at azalia0
ppb0 at pci0 dev 28 function 0 "Intel 3400 PCIE" rev 0x05: msi
pci1 at ppb0 bus 1
ppb1 at pci0 dev 28 function 1 "Intel 3400 PCIE" rev 0x05: msi
pci2 at ppb1 bus 2
iwn0 at pci2 dev 0 function 0 "Intel Centrino Advanced-N 6200" rev
0x35: msi, MIMO 2T2R, MoW, address 18:3d:a2:11:a8:c8
ppb2 at pci0 dev 28 function 2 "Intel 3400 PCIE" rev 0x05: msi
pci3 at ppb2 bus 3
cbb0 at pci3 dev 0 function 0 vendor "Ricoh", unknown product 0xe476
rev 0x02: apic 2 int 18
sdhc0 at pci3 dev 0 function 1 "Ricoh 5U822 SD/MMC" rev 0x03: apic 2 int 19
sdmmc0 at sdhc0
"Ricoh 5U832 Firewire" rev 0x03 at pci3 dev 0 function 4 not configured
cardslot0 at cbb0 slot 0 flags 0
cardbus0 at cardslot0: bus 4 device 0 cacheline 0x0, lattimer 0x20
pcmcia0 at cardslot0
ppb3 at pci0 dev 28 function 3 "Intel 3400 PCIE" rev 0x05: msi
pci4 at ppb3 bus 5
ppb4 at pci0 dev 28 function 5 "Intel 3400 PCIE" rev 0x05: msi
pci5 at ppb4 bus 11
bge0 at pci5 dev 0 function 0 "Broadcom BCM5761E" rev 0x10, BCM5761 A1
(0x5761100): apic 2 int 17, address 78:2b:cb:cc:e7:f1
brgphy0 at bge0 phy 1: BCM5761 10/100/1000baseT PHY, rev. 0
ehci1 at pci0 dev 29 function 0 "Intel 3400 USB" rev 0x05: apic 2 int 17
usb1 at ehci1: USB revision 2.0
uhub1 at usb1 "Intel EHCI root hub" rev 2.00/1.00 addr 1
ppb5 at pci0 dev 30 function 0 "Intel 82801BAM Hub-to-PCI" rev 0xa5
pci6 at ppb5 bus 12
pcib0 at pci0 dev 31 function 0 "Intel HM55 LPC" rev 0x05
ahci0 at pci0 dev 31 function 2 "Intel 3400 AHCI" rev 0x05: msi, AHCI 1.3
scsibus0 at ahci0: 32 targets
sd0 at scsibus0 targ 0 lun 0:  SCSI3 0/direct
fixed naa.5000c5002f6bb427
sd0: 238475MB, 512 bytes/sector, 488397168 sectors
cd0 at scsibus0 targ 1 lun 0:  ATAPI
5/cdrom removable
ichiic0 at pci0 dev 31 function 3 "Intel 3400 SMBus" rev 0x05: apic 2 int 18
iic0 at ichiic0
lisa0 at iic0 addr 0x1d: lis331dl
spdmem0 at iic0 addr 0x50: 2GB DDR3 SDRAM PC3-10600 SO-DIMM
spdmem1 at iic0 addr 0x52: 2GB DDR3 SDRAM PC3-10600 SO-DIMM
itherm0 at pci0 dev 31 function 6 "Intel 3400 Thermal" rev 0x05
isa0 at pcib0
isadma0 at isa0
pckbc0 at isa0 port 0x60/5
pckbd0 at pckbc0 (kbd slot)
pckbc0: using irq 1 for kbd slot
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pms0 at pckbc0 (aux slot)
pckbc0: using irq 12 for aux slot
wsmouse0 at pms0 mux 0
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
pci7 at mainbus0 bus 63
pchb1 at pci7 dev 0 function 0 "Intel QuickPath" rev 0x02
pchb2 at pci7 dev 0 function 1 "Intel QuickPath" rev 0x02
pchb3 at pci7 dev 2 function 0 "Intel QPI Link" rev 0x02
pchb4 at pci7 dev 2 function 1 "Intel QPI Physical" rev 0x02
pchb5 at pci7 dev 2 function 2 "Intel Reserved" rev 0x02
pchb6 at pci7 dev 2 function 3 "Intel Reserved" rev 0x02
mtrr: Pentium Pro MTRR support
uhub2 at uhub0 port 1 "Intel Rate Matching Hub" rev 2.00/0.00 addr 2
uvideo0 at uhub2 port 4 configuration 1 interface 0
"CN0VWKTR7248712IA1D4A00 Laptop_Integrated_Webcam_2M" rev 2.00/9c.17
addr 3
video0 at uvideo0
uhub3 at uhub1 port 1 "Intel Rate Matching Hub" rev 2.00/0.00 addr 2
uhidev0 at uhub3 port 3 configuration 1 interface 0 "Logitech USB-PS/2
Optical Mouse" rev 2.00/20.00 addr 3
uhidev0: iclass 3/1
ums0 at uhidev0: 3 buttons, Z dir
wsmouse1 at ums0 mux 0
vscsi0 at root
scsibus1 at vscsi0: 256 targets
softraid0 at root
scsibus2 at softraid0: 256 targets
root on sd0a (6d20ff977a075eb7.a) swap on sd0b dump on sd0b

usbdevs -dv:
Controller /dev/usb0:
addr 1: high speed, self powered, config 1, EHCI root hub(0x),
Intel(0x8086), rev 1.00
  uhub0
 port 1 addr 2: high speed, self powered, config 1, Rate Matching
Hub(0x0020), Intel(0x8087), rev 0.00
   uhub2
  port 1 powered
  port 2 powered
  port 3 powered
  port 4 addr 3: high speed, power 168 mA, config 1,
Laptop_Integrated_Webcam_2M(0x6419), CN0VWKTR7248712IA1D4A00(0x0c45),
rev 9c.17
uvideo0
  port 5 powered
  port 6 powered
 port 2 powered
Controller /dev/usb1:
addr 1: high speed, self powered, config 1, EHCI root hub(0x),
Intel(0x8086), rev 1.00
  uhub1
 port 1 addr 2: high speed, self powered, config 1, Rate Matching
Hub(0x0020), Intel(0x8087), rev 0.00
   uhub3
  port 1 powered
  port 2 powered
  port 3 powered
  port 4 addr 3: low speed, power 98 mA, config 1, USB-PS/2 Optical
Mouse(0xc03e), Logitech(0x046d), rev 20.00
uhidev0
  port 5 powered
  port 6 powered
  port 7 powered
  port 8 powered
 port 2 powered

-- 
Tristan Le Guern
Epitech 2013



Re: X11 on Dell Latitude E5410

2013-04-10 Thread Tristan Le Guern
On Fri, Mar 22, 2013 at 10:07 PM, Matthieu Herrb  wrote:
> Try a -current snapshot.  There is support for recent Intel HD graphics now.
Hi,

I have just updated and it works well, there is no more segfault of X
at startup and I can watch movies, launch Xephyr or play high
resolution Nethack in console.

Thanks :)
--
Tristan Le Guern



Re: X11 on Dell Latitude E5410

2013-03-18 Thread Tristan Le Guern
Hi,

I can have a working system using a striped down xorg.conf with the
vesa(4) driver, but it doesn't explain all the mess I had.

Sorry for the noise anyway.
---8<---
Section "Device"
Identifier  "Card0"
Driver  "vesa"
BusID   "PCI:0:2:0"
EndSection

Section "Monitor"
Identifier   "Monitor0"
VendorName   "Monitor Vendor"
ModelName"Monitor Model"
EndSection

Section "Screen"
Identifier "Screen0"
Device "Card0"
Monitor"Monitor0"
SubSection "Display"
Viewport   0 0
Depth 1
EndSubSection
SubSection "Display"
Viewport   0 0
Depth 4
EndSubSection
SubSection "Display"
Viewport   0 0
Depth 8
EndSubSection
SubSection "Display"
Viewport   0 0
Depth 15
EndSubSection
SubSection "Display"
Viewport   0 0
        Depth 16
EndSubSection
SubSection "Display"
Viewport   0 0
Depth 24
EndSubSection
EndSection
---8<---
--
Tristan Le Guern



Re: Help neede for 'pkgin'

2012-07-10 Thread Tristan Le Guern
On Tue, Jul 10, 2012 at 12:00 PM, srimanta kundu
 wrote:
> Hello Sir,
>
> I have installed netBSD 5.1.2 via VMWare Player. But I cannot use
> the 'pkgin' command there. It is shown the command not found.
> Please tell how
> can get that command in my netBSD?
pkgin is not in NetBSD base system, you have to install it with pkg_add first.

> After installing that I want to update the
> openSSL from 0.9.9 to 1.0.1 using pkgin. So what will be the exact command to
> do that.
man pkgin

> With best regards.
You should ask question on the good mailing list.

-- 
Tristan Le Guern
Epitech 2013



urndis

2011-07-22 Thread Tristan Le Guern
I tested it on my loongson with my HTC Legend and it works well :)

[...]
umass1 at uhub1 port 3 configuration 1 interface 0 "HTC Android Phone"
rev 2.00/2.26 addr 4
umass1: using SCSI over Bulk-Only
scsibus3 at umass1: 1 targets
sd1 at scsibus3 targ 0 lun 0:  SCSI2
0/direct removable serial.0bb40ff9SH0AGNX00011
sd1 detached
scsibus3 detached
umass1 detached
urndis0 at uhub1 port 3 configuration 1 interface 0 "HTC Android
Phone" rev 2.00/2.26 addr 4
urndis0: address d2:0e:6f:45:ab:58
[...]

-- 
Tristan Le Guern



Re: How does OpenBSD compare to Ubuntu Server?

2011-07-13 Thread Tristan Le Guern
On Thu, Jul 7, 2011 at 3:02 PM, Juan Miscaro  wrote:
> Was wondering what advantages OpenBSD has over a progressive Linux
> distribution such as Ubuntu (Server edition).  One thing I noticed is
> that they're having a hell of a time transitioning away from the
> traditional sysvinit-based system to the Upstart event-based init
> daemon system.
>
Advantages ? You don't fear to upgrade OpenBSD.

--
Tristan Le Guern
Epitech 2013



Re: problem with www.openbsd.org/spamd/SBL.cidr.gz

2005-06-13 Thread Tristan Delsol

Ahh.. I see. cool thanks. :).

Todd C. Miller wrote:

In message <[EMAIL PROTECTED]>
so spake Tristan Delsol (tdelsol):



OK. Do I need to change the URL in the spamd.conf or will you use another sou
rce pretty soon?



Bob is back from camping so this is fixed now ;-)

 - todd




Re: problem with www.openbsd.org/spamd/SBL.cidr.gz

2005-06-12 Thread Tristan Delsol
Quoting "Todd C. Miller" <[EMAIL PROTECTED]>:

> In message <[EMAIL PROTECTED]>
>   so spake Tristan Delsol (tdelsol):
>
> > Noticed crond sending me some errors from spamd-setup.
> > "spamd-setup: Could not add blacklist spamhaus: Input/output error"
> >
> > That's all I'm getting. Tried to get the file
> > www.openbsd.org/spamd/SBL.cidr.gz and it seems kind of empty.
> > OpenBSD 3.6 3.6 GENERIC#0 i386
> >
> > Anyone know about this? Thanks.
>
> The openrbl.org domain name expired and that's who we were
> getting the spamhaus list from.
>
>  - todd
>
OK. Do I need to change the URL in the spamd.conf or will you use another 
source pretty soon?
THanks for the help.

Tristan



problem with www.openbsd.org/spamd/SBL.cidr.gz

2005-06-11 Thread Tristan Delsol

Hi,

Noticed crond sending me some errors from spamd-setup.
"spamd-setup: Could not add blacklist spamhaus: Input/output error"

That's all I'm getting. Tried to get the file 
www.openbsd.org/spamd/SBL.cidr.gz and it seems kind of empty.

OpenBSD 3.6 3.6 GENERIC#0 i386

Anyone know about this? Thanks.

Tristan