Re: sd0-n vs wd0-n

2020-10-30 Thread Chris Cappuccio
Amelia A Lewis [amyz...@talsever.com] wrote: > > Can anyone suggest why a machine, with no activity but ssh logins and > then a syspatch of patches 2-3 on 6.8 would spontaneously start > considering the SATA disks in the machine (which were previously loaded > as sd0-sd2) as IDE (wd0-wd2)?

Re: sd0-n vs wd0-n

2020-10-30 Thread Amelia A Lewis
On Fri, 30 Oct 2020 16:42:18 -0700, Chris Cappuccio wrote: > Amelia A Lewis [amyz...@talsever.com] wrote: [snip] > > Perhaps the CMOS battery failed and the BIOS reverted to a default setting. -and- On Fri, 30 Oct 2020 15:05:23 -0700, obs...@loopw.com wrote: > My guess is that the nvram of the

Re: sd0-n vs wd0-n

2020-10-30 Thread obsdml
My guess is that the nvram of the bios somehow reset its configuration back to default. (corruption, power loss, etc. - these are cheap parts made with failure rates after all) The default of most x86 bioses up until the last few years was to bring up SATA ports in IDE compatible mode, which

Re: 6.8 hppa build problem

2020-10-30 Thread Stuart Henderson
On 2020-10-30, Christian Groessler wrote: > I want to build "screen" from ports (/usr/ports/misc/screen). > > I'm getting an error because of undefined '__sync_val_compare_and_swap_4': > > > libtool: link: ar cru .libs/libgettextsrc.a libgettextsrc_la-message.o Since binary packages are no

Are relayd and httpd my future buddy?

2020-10-30 Thread Lars Bonnesen
I have been using a combination of Apache, mod_proxy and letsencrypt to set up different loadbalancing/https offload solution like this: https://URL1[Apache http_1] ---| https://URL2 [Apache https, mod_proxy, and letsencrypt] --- [Apache http_2}

6.8 hppa build problem

2020-10-30 Thread Christian Groessler
I want to build "screen" from ports (/usr/ports/misc/screen). I'm getting an error because of undefined '__sync_val_compare_and_swap_4': libtool: link: ar cru .libs/libgettextsrc.a libgettextsrc_la-message.o libgettextsrc_la-po-error.o libgettextsrc_la-po-xerror.o

Re: sd0-n vs wd0-n

2020-10-30 Thread John McGuigan
> I remember Theo(?) mentioning this about a MacBookAir some time ago. Oops, that was jsg, sorry Theo: http://www.undeadly.org/cgi?action=article=20130608064453

Re: sd0-n vs wd0-n

2020-10-30 Thread Amelia A Lewis
On Fri, 30 Oct 2020 14:43:12 -0600, John McGuigan wrote: > Two things that jump to mind are weirdness with Apple hardware (not sure > this is the case or not) but I recall that in Bootcamp mode the EFI displays > IDE devices instead of SATA in some cases. I remember Theo(?) mentioning > this about

Re: sd0-n vs wd0-n

2020-10-30 Thread John McGuigan
Ahoy! Two things that jump to mind are weirdness with Apple hardware (not sure this is the case or not) but I recall that in Bootcamp mode the EFI displays IDE devices instead of SATA in some cases. I remember Theo(?) mentioning this about a MacBookAir some time ago. The other is if you've

sd0-n vs wd0-n

2020-10-30 Thread Amelia A Lewis
Heylas again, So, I have a working machine again, after copying a kernel over from a working machine, verifying it, and generating a new hash (I have a whole long saga of investigation, but I'll spare you). Can anyone suggest why a machine, with no activity but ssh logins and then a syspatch

Re: Routing between VPNs broken

2020-10-30 Thread Axel Rau
After rebooting the client, everything works as expected. Until next re-keeing, where it stops working. Axel --- PGP-Key: CDE74120 ☀ computing @ chaos claudius signature.asc Description: Message signed with OpenPGP

Re: syspatch -> no partition found ; any simple fix?

2020-10-30 Thread Amelia A Lewis
Heylas again, On Thu, 29 Oct 2020 21:40:05 -0700, Greg Thomas wrote: > On Thu, Oct 29, 2020 at 8:42 PM Amelia A Lewis wrote: [snip] > > If you were just running syspatch I'd be worried that a hardware failure > showed up on reboot. I'm way out of practice for troubleshooting OpenBSD > but

Re: Impact of 002_icmp6.patch

2020-10-30 Thread pipus
he is real ... but from the Linux side :) but maybe the second troll of the thread. I cannot imagine anyone being that ignorant. Sent with ProtonMail Secure Email. ‐‐‐ Original Message ‐‐‐ On Friday, 30 October 2020 13:36, Florian Obser wrote: > On Fri, Oct 30, 2020 at 11:58:41AM

Re: help me to create hostname.wg

2020-10-30 Thread Sonic
On Fri, Oct 30, 2020 at 12:07 PM kasak wrote: > $ wg showconf wg0 > [Interface] > ListenPort = 9022 > > why the keys is not configured? You're not root.

Re: help me to create hostname.wg

2020-10-30 Thread kasak
30.10.2020 19:18, Josh Grosse пишет: On Fri, Oct 30, 2020 at 07:05:51PM +0300, kasak wrote: hello misc. I'm trying to create wg interface, but have no luck. Here is my /etc/hostname.wg0: $ cat /etc/hostname.wg0 inet 10.0.0.1/24 wgkey wgpeer wgaip 10.0.0.2 after running doas sh

help me to create hostname.wg

2020-10-30 Thread kasak
hello misc. I'm trying to create wg interface, but have no luck. Here is my /etc/hostname.wg0: $ cat /etc/hostname.wg0 inet 10.0.0.1/24 wgkey wgpeer wgaip 10.0.0.2 after running doas sh /etc/netstart wg0 i have: $ ifconfig wg0 wg0: flags=80c3 mtu 1420     index 6 priority 0 llprio 3    

Re: Impact of 002_icmp6.patch

2020-10-30 Thread pipus
we battered the IETF, and even government interest, on this for years back in late 2007, and beyond ... any remember IPv5? :) IPv6 is a massive security risk in so many ways. No real NAT so you are distributed into the worldwide even if billions of addresses there is no protection. There

Re: IPsec and MTU / fragmentation

2020-10-30 Thread Brian Brombacher
> On Oct 30, 2020, at 11:44 AM, Brian Brombacher wrote: > >  > >>> On Oct 29, 2020, at 11:56 PM, David Diggles wrote: >>> >>> On Mon, Feb 10, 2020 at 05:15:00PM +, Peter M??ller wrote: >>> Hello Lucas, >>> >>> as far as I understood, setting MTU on encN interfaces is not supported

Re: IPsec and MTU / fragmentation

2020-10-30 Thread Brian Brombacher
> On Oct 29, 2020, at 11:56 PM, David Diggles wrote: > > On Mon, Feb 10, 2020 at 05:15:00PM +, Peter M??ller wrote: >> Hello Lucas, >> >> as far as I understood, setting MTU on encN interfaces is not supported >> since it is not mentioned by enc(4) and setting it manually fails: >> >>>

Re: Impact of 002_icmp6.patch

2020-10-30 Thread Martin Schröder
Am Fr., 30. Okt. 2020 um 13:36 Uhr schrieb Florian Obser : > On Fri, Oct 30, 2020 at 11:58:41AM +0100, Martin Schröder wrote: > > I'd much prefer that the project adopted a" v6 first, vintage ip > > second" approach. > > But I'm not a dev. > > ... you are saying if you were a dev things would be

Re: Impact of 002_icmp6.patch

2020-10-30 Thread Florian Obser
On Fri, Oct 30, 2020 at 11:58:41AM +0100, Martin Schröder wrote: > Am Fr., 30. Okt. 2020 um 11:54 Uhr schrieb Denis Fondras > : > > Please, fix your tweet. The default install answer for IPv6 is 'none'. > > This borders on "switch off v6 for security reasons", which would be just > wrong.

Re: Impact of 002_icmp6.patch

2020-10-30 Thread Paul de Weerd
On Fri, Oct 30, 2020 at 11:15:31AM +0100, js-openbsd-m...@webkeks.org wrote: | What about link-local IPv6? That's active by default, isn't it? It is not. You need to enable IPv6 on an interface to get a link-local address on it, only the loopback interface is special in this sense that it gets

Re: Impact of 002_icmp6.patch

2020-10-30 Thread Denis Fondras
On Fri, Oct 30, 2020 at 11:58:41AM +0100, Martin Schröder wrote: > Am Fr., 30. Okt. 2020 um 11:54 Uhr schrieb Denis Fondras > : > > Please, fix your tweet. The default install answer for IPv6 is 'none'. > > This borders on "switch off v6 for security reasons", which would be just > wrong. > >

Re: Impact of 002_icmp6.patch

2020-10-30 Thread Martin Schröder
Am Fr., 30. Okt. 2020 um 11:54 Uhr schrieb Denis Fondras : > Please, fix your tweet. The default install answer for IPv6 is 'none'. This borders on "switch off v6 for security reasons", which would be just wrong. I'd much prefer that the project adopted a" v6 first, vintage ip second" approach.

Re: Impact of 002_icmp6.patch

2020-10-30 Thread Denis Fondras
On Fri, Oct 30, 2020 at 11:36:33AM +0100, js-openbsd-m...@webkeks.org wrote: > To close this thread, I found this: > https://twitter.com/m00nbsd/status/1321524807473782784 > Please, fix your tweet. The default install answer for IPv6 is 'none'.

Routing between VPNs broken

2020-10-30 Thread Axel Rau
Hi all, I have 3 firewalls, all running OpenBSD 6.7, 2 are IPsec-clients one is the server. After installing (unrelated?) syspatches (67-19, 67-20, 67-23 und 67-24) on the server and rebooting it after 2 months of uptime, I noticed, that routing between VPNs has been broken: fw1# ipsecctl -s

Re: Impact of 002_icmp6.patch

2020-10-30 Thread js-openbsd-misc
> Honestly, as one of the devs involved with this security fix, I can tell > you that I don't know. It is a use-after-free in some situations. > Is it reachable from remote? I don't know. > Is it reachable from local? Maybe. > Is the use-after-free exploitable? Damn hard to tell, it is for sure

Re: Impact of 002_icmp6.patch

2020-10-30 Thread Claudio Jeker
On Fri, Oct 30, 2020 at 11:15:31AM +0100, js-openbsd-m...@webkeks.org wrote: > > Am 30.10.2020 um 01:28 schrieb Theo de Raadt : > > > > js-openbsd-m...@webkeks.org wrote: > > > >> I just saw > >> https://ftp.openbsd.org/pub/OpenBSD/patches/6.8/common/002_icmp6.patch.sig, > >> however, it's

Re: Impact of 002_icmp6.patch

2020-10-30 Thread js-openbsd-misc
To close this thread, I found this: https://twitter.com/m00nbsd/status/1321524807473782784 > Am 30.10.2020 um 11:15 schrieb js-openbsd-m...@webkeks.org: > >> Am 30.10.2020 um 01:28 schrieb Theo de Raadt : >> >> js-openbsd-m...@webkeks.org wrote: >> >>> I just saw >>>

Re: suggestion for the installer

2020-10-30 Thread Harald Dunkel
On 10/29/20 3:38 PM, Nick Holland wrote: On 2020-10-29 08:00, Harald Dunkel wrote: Hi folks, do you think it would be possible for the installer to show an eye-catching warning, if "ifconfig" reports "no carrier" for the network port to configure? Just a suggestion, of course Harri Why?

Re: Can't cron sct.

2020-10-30 Thread Erling Westenvik
On Thu, Oct 29, 2020 at 11:04:59PM +0100, avv. Nicola Dell'Uomo wrote: > I tried to pass DISPLAY env to cron without success: how is it done? 35 19 * * * export DISPLAY=:0; /usr/local/bin/sct 5000 > sctd is not a viable answer as it works just with fixed increments or > decrements; and from man

Re: Impact of 002_icmp6.patch

2020-10-30 Thread js-openbsd-misc
> Am 30.10.2020 um 01:28 schrieb Theo de Raadt : > > js-openbsd-m...@webkeks.org wrote: > >> I just saw >> https://ftp.openbsd.org/pub/OpenBSD/patches/6.8/common/002_icmp6.patch.sig, >> however, it's unclear from the description and the context around the >> patch if this is a read after free or

Re: syspatch -> no partition found ; any simple fix?

2020-10-30 Thread Stuart Henderson
On 2020-10-30, Amelia A Lewis wrote: > It won't start the boot, but displays "No active partition". Checking > online, this message seems to indicate a failed upgrade, with the > bootloader load incomplete, and (because I was distracted, and running > three updates in a state of fatigue), it's

Re: Can't cron sct.

2020-10-30 Thread avv. Nicola Dell'Uomo
Hi, many thanks to both of you for your replies. I tried to pass DISPLAY env to cron without success: how is it done? sctd is not a viable answer as it works just with fixed increments or decrements; and from man sct:  "sct samples the color ramp in interval steps of 500 with temp values